CVE-2020-3960 | VMware¶à¸ö²úÆ·ÐÅϢй¶·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-06-11

0x00 ·ì϶¸ÅÊö


²úÆ·

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Ó°ÏìÁìÓò

VMware vSphere ESXi (ESXi)

CVE-2020-3960

ROB

ÑϳÁ

ÊÇ

ESXi 6.5¡¢6.7

VMware Workstation Pro / Player (Workstation)

CVE-2020-3960

ROB

ÑϳÁ

ÊÇ

Workstation 15.x

VMware Fusion Pro / Fusion (Fusion)

CVE-2020-3960

ROB

ÑϳÁ

ÊÇ

Fusion 11.x


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

VMwareÐé¹¹»úÈí¼þ£¬ÊÇÈ«Çò×ÀÃæµ½Êý¾ÝÖÐÐÄÐé¹¹»¯½â¾ö¹æ»®µÄ¸¨µ¼³§ÉÌ¡£È«Çò·ÖÆç¹æÄ£µÄ¿Í»§ÒÀ¸½VMwareÀ´½µµÍ³É±¾ºÍÔËÓªÓöȡ¢È·±£ÒµÎñ³ÖÐøÐÔ¡¢¼ÓÇ¿°²È«ÐÔ²¢×ßÏòÂÌÉ«¡£

2020Äê6ÔÂ9ÈÕVMware°ä²¼°²È«¸üУ¬½¨¸´ÁËVMware ESXi¡¢WorkstationºÍFusion²úÆ·ÖеĶà¸ö°²È«·ì϶£¬¾ßÌåÐÅÏ¢ÈçÏ£º

Vmware ESXi¡¢WorkstationºÍFusion²úÆ·ÖеÄNVMeÖ°ÄÜÖÐÔ̺¬Ô½½ç¶ÁÈ¡·ì϶£¨CVE-2020-3960£©¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ÒÔ·ÇÖÎÀíÔ±Éí·Ý½Ó¼ûÐé¹¹»ú²¢´ÓÄÚ´æÖжÁÈ¡ÌØÈ¨ÐÅÏ¢¡£

NVMe£¨Nonvolatile Memory Express£¬·ÇÒ×ʧÐÔÄÚ´æ³ß¶È£©ÊÇÒ»ÖÖÉÁ´æºÍÏÂÒ»´ú¹Ì̬Çý¶¯Æ÷ (SSD) µÄȫд洢½Ó¼ûºÍ´«ÊäºÍ̸£¬¿ÉΪËùÓÐÀàÐÍµÄÆóÒµ¹¤×÷¸ºÔØÌṩ×î¸ßµÄÍÌÍÂÁ¿ºÍ×î¿ìµÄÏìÓ¦¿ìÂÊ¡£


0x02 ´ëÖý¨Òé


VMwareÒѾ­°ä²¼ÉÏÊö·ì϶µÄ²¹¶¡£¬µ«ÊÇûÓÐÌṩ½â¾ö²½Öè¡£

ESXi 6.7²¹¶¡·¨Ê½ESXi670-202006401-SG

https://my.vmware.com/group/vmware/patch

https://docs.vmware.com/en/VMware-vSphere/6.7/rn/ESXi670-202006401-SG.html


ESXi 6.5²¹¶¡·¨Ê½ESXi650-202005401-SG

https://my.vmware.com/group/vmware/patch

https://docs.vmware.com/en/VMware-vSphere/6.5/rn/ESXi650-202005401-SG.html


VMware Workstation Pro 15.5.5

https://www.vmware.com/go/downloadworkstation

https://docs.vmware.com/cn/VMware-Workstation-Pro/index.html


VMware Fusion 11.5.5

https://www.vmware.com/go/downloadfusion

https://docs.vmware.com/cn/VMware-Fusion/index.html

 

0x03 ÓйØÐÂÎÅ


https://securityaffairs.co/wordpress/104579/security/vmware-products-flaw.html?utm_source=rss&utm_medium=rss&utm_campaign=vmware-products-flaw


0x04 ²Î¿¼Á´½Ó


https://www.vmware.com/security/advisories/VMSA-2020-0012.html


0x05 ¹¦·òÏß


2020-06-09 VMware°ä²¼·ì϶²¼¸æ

2020-06-11 VSRC°ä²¼·ì϶¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾