VMware vSphere ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-21972£©

Ðû²¼Ê±¼ä 2021-02-24

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2021-21972

ʱ  ¼ä

2021-02-24

Àà  ÐÍ

RCE

µÈ  ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


 

0x01 Îó²îÏêÇé

image.png

 

VMware vCenter ServerÊǸ߼¶·þÎñÆ÷ÖÎÀíÈí¼þ  £¬ÆäÌṩÁËÒ»¸ö¼¯ÖÐʽƽ̨À´¿ØÖƵÄVMware vSphere ÇéÐÎ  £¬Ê¹Óû§Äܹ»ÔÚÕû¸ö»ìÏýÔÆÖÐ×Ô¶¯°²ÅŲ¢½»¸¶ÐéÄâ»ù´¡¼Ü¹¹¡£

2021Äê02ÔÂ23ÈÕ  £¬VmwareÐû²¼ÁËvCenter ServerÇå¾²¸üР £¬ÐÞ¸´ÁËvSphere Client (HTML5) ÔÚvCenter Server²å¼þvRealize Operations£¨vROps£©ÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-21972£©  £¬ÆäCVSSÆÀ·ÖΪ9.8¡£Äܹ»»á¼ûÍøÂç¶Ë¿Ú443µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÔÚÍйÜvCenter ServerµÄ²Ù×÷ϵͳÉÏÒÔ²»ÊÜÏÞÖÆµÄȨÏÞÖ´ÐÐÏÂÁî¡£±ðµÄ  £¬ÓÉÓÚÊÜÓ°ÏìµÄ²å¼þ±£´æÓÚËùÓÐĬÈÏ×°ÖÃÖÐ  £¬¼øÓÚ´ËÎó²îµÄÑÏÖØÐÔ  £¬VMwareÇ¿ÁÒ½¨ÒéÓû§¾¡¿ìÉý¼¶¡£

±ðµÄ  £¬VMware»¹ÐÞ¸´ÁËVMware ESXiÖÐÒ»¸öÖ÷ÒªµÄ¶ÑÒç³öÎó²î£¨CVE-2021-21974£©  £¬ÆäCVSSÆÀ·Ö8.8¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£

2020Äê4Ô  £¬VMware½â¾öÁËÁíÒ»¸öÑÏÖØµÄvCenter ServerÎó²î  £¬¸ÃÎó²î¿ÉÄÜʹ¹¥»÷ÕßÄܹ»»á¼ûÃô¸ÐÐÅÏ¢  £¬²¢¿ÉÄÜ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£

 

Ó°Ïì¹æÄ£

vCenter Server 6.5

vCenter Server 6.7

vCenter Server 7.0

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ¸ÃÎó²îÒѾ­ÐÞ¸´  £¬½¨Òé²Î¿¼Ï±íʵʱÉý¼¶¡£

Ó°Ïì°æ±¾

ÐÞ¸´°æ±¾

²Î¿¼Á´½Ó£¨ÔÝʱÐÞ¸´£©

vCenter Server 6.5

6.5 U3n

https://kb.vmware.com/s/article/82374

vCenter Server 6.7

6.7 U3l

vCenter Server 7.0

7.0 U1c

 

ÏÂÔØÁ´½Ó£º

vCenter Server 6.5 U3n

https://docs.vmware.com/en/VMware-vSphere/6.5/rn/vsphere-vcenter-server-65u3n-release-notes.html

 

vCenter Server 6.7 U3l

https://docs.vmware.com/en/VMware-vSphere/6.7/rn/vsphere-vcenter-server-67u3l-release-notes.html

 

vCenter Server 7.0 U1c

https://docs.vmware.com/en/VMware-vSphere/7.0/rn/vsphere-vcenter-server-70u1c-release-notes.html

 

0x03 ²Î¿¼Á´½Ó

https://www.vmware.com/security/advisories/VMSA-2021-0002.html

https://www.bleepingcomputer.com/news/security/vmware-fixes-critical-rce-bug-in-all-default-vcenter-installs/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21972

 

0x04 ʱ¼äÏß

2021-02-23  VmwareÐû²¼Çå¾²¸üÐÂ

2021-02-24  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png