VMware½¨¸´¶à¸ö°²È«·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-01-17·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-3941£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.8£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-3940£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.8£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
CVE-2020-3941
VMware Tools for Windows 10.x.y
CVE-2020-3940
Workspace ONE SDK
Workspace ONE Boxer
Workspace ONE Content
Workspace ONE SDK Plugin for Apache Cordova
Workspace ONE Intelligent Hub
Workspace ONE Notebook
Workspace ONE People
Workspace ONE PIV-D
Workspace ONE Web
Workspace ONE SDK Plugin for Xamarin
·ì϶¸ÅÊö
VMwareÒѰ䲼°²È«¸üУ¬½¨¸´ÁËVMware ToolsºÍWorkspace ONE SDKÖеķì϶¡£
VMware½¨¸´ÁËWindows VMware Tools°æ±¾10.xyÖеı¾µØÌáȨ·ì϶£¨CVE-2020-3941£©¡£¸Ã·ì϶±»¹éÀàΪ¾ºÕùǰÌá·ì϶£¬¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶ÔÚÐé¹¹»úÖÐÌáÉýÌØÈ¨¡£
VMware»¹½¨¸´ÁËWorkspace ONE SDKÖеÄÐÅϢй¶·ì϶£¨CVE-2020-3940£©£¬¸Ã·ì϶ӰÏìÁËÓйصÄiOSºÍAndroid APP¡£Æ¾¾Ý°²È«²¼¸æ£¬ÈôÊÇÆôÓÃÁËSSL Pinning£¬ÔòÔÚÊÜÓ°ÏìµÄÒÆ¶¯APPºÍWorkspace ONE UEMÉ豸·þÎñÖ®¼äµÄÖÐÑëÈË£¨MITM£©¹¥»÷Õß¿ÉÄܲ¶»ñ´«ÊäÖеÄÃô¸ÐÊý¾Ý¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó¼û²Î¿¼Á´½Ó¡£
²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2020-0002.html
https://www.vmware.com/security/advisories/VMSA-2020-0001.html


¾©¹«Íø°²±¸11010802024551ºÅ