VMwareÔ½½ç¶ÁдÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-06

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5521 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.3-7.7 £¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-5684 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.5 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

 

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Îó²î¸ÅÊö


VMware ESXiµÈ¶¼ÊÇÃÀ¹úÍþ¨VMware£©¹«Ë¾µÄ²úÆ·¡£VMware ESXiÊÇÒ»Ì׿ÉÖ±½Ó×°ÖÃÔÚÎïÀí·þÎñÆ÷ÉϵķþÎñÆ÷ÐéÄ⻯ƽ̨¡£VMware WorkstationÊÇÒ»Ì×ÐéÄâ»úÈí¼þ¡£VMware Workstation PlayerÊÇÒ»Ì×Ãâ·Ñ¿ªÔ´µÄÇÒ¹¦Ð§½Ï¼òÆÓµÄÐéÄâ»úÈí¼þ¡£VMware FusionÊÇÒ»Ì×רÓÃÓÚÔÚÆ»¹û»ú£¨Mac£©ÉÏÔËÐÐWindowsÓ¦ÓóÌÐòµÄµÄÐéÄâ»úÈí¼þ¡£NVIDIA graphics driverµÈ¶¼ÊÇÃÀ¹úӢΰ´ï£¨NVIDIA£©¹«Ë¾µÄ²úÆ·¡£NVIDIA graphics driverÊÇÒ»¿îͼÐÎÇý¶¯Æ÷¡£


Vmware ESXi¡¢WorkstationºÍFusionÖб£´æÈçÏÂÎó²î¡£Ê¹ÓÃÕâЩÎó²îÐèÒª¹¥»÷Õß»á¼ûÆôÓÃÁË3DͼÐεÄÐéÄâ»ú¡£Ä¬ÈÏÇéÐÎÏ £¬Ëü²»ÔÚESXiÉÏÆôÓà £¬Ä¬ÈÏÇéÐÎÏÂÔÚWorkstationºÍFusionÉÏÆôÓá£


CVE-2019-5521 - Ô½½ç¶ÁÈ¡Îó²î

ÀÖ³ÉʹÓÃÔ½½ç¶ÁÈ¡ÎÊÌâ¿ÉÄܻᵼÖÂÐÅϢй¶ £¬»òÕß¿ÉÄÜÔÊÐí¾ßÓÐÕý³£Óû§È¨Ï޵Ĺ¥»÷ÕßÔÚÖ÷»úÉϽ¨Éè¾Ü¾ø·þÎñÌõ¼þ¡£


CVE-2019-5684 - Ô½½çдÈëÎó²î

½öµ±Ö÷»ú¾ßÓÐÊÜÓ°ÏìµÄNVIDIAͼÐÎÇý¶¯³ÌÐòʱ £¬²Å»ªÊ¹ÓÃÔ½½çдÈëÎÊÌâ¡£ÀÖ³ÉʹÓôËÎÊÌâ¿ÉÄܻᵼÖÂÖ÷»úÉϵĴúÂëÖ´ÐС£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î £¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://www.vmware.com/security/advisories/VMSA-2019-0012.html¡£


Ò²¿ÉÒÔͨ¹ý×°ÖøüеÄNVIDIAͼÐÎÇý¶¯³ÌÐòÀ´ÐÞ¸´CVE-2019-5684£ºhttps://nvidia.custhelp.com/app/answers/detail/a_id/4841¡£


²Î¿¼Á´½Ó


https://www.vmware.com/security/advisories/VMSA-2019-0012.html