VMware vSphere ServerÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-21972£©
°ä²¼¹¦·ò 2021-02-240x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-21972 | ʱ ¼ä | 2021-02-24 |
Àà ÐÍ | RCE | µÈ ¼¶ | ÑϳÁ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò |
0x01 ·ì϶ÏêÇé

VMware vCenter ServerÊǸ߼¶·þÎñÆ÷ÖÎÀíÈí¼þ£¬ÆäÌṩÁËÒ»¸ö¼¯ÖÐʽƽ̨À´½ÚÔìµÄVMware vSphere »·¾³£¬Ê¹Óû§¿ÉÄÜÔÚÕû¸ö»ìºÏÔÆÖÐ×Ô¶¯²¿Êð²¢½»¸¶Ðé¹¹»ù´¡¼Ü¹¹¡£
2021Äê02ÔÂ23ÈÕ£¬Vmware°ä²¼ÁËvCenter Server°²È«¸üУ¬½¨¸´ÁËvSphere Client (HTML5) ÔÚvCenter Server²å¼þvRealize Operations£¨vROps£©ÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-21972£©£¬ÆäCVSSÆÀ·ÖΪ9.8¡£¿ÉÄܽӼûÍøÂç¶Ë¿Ú443µÄ¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓô˷ì϶ÔÚÍйÜvCenter ServerµÄ²Ù×÷ϵͳÉÏÒÔ²»ÊÜÏ޶ȵÄȨÏÞÖ´ÐкÅÁî¡£´Ë±í£¬ÓÉÓÚÊÜÓ°ÏìµÄ²å¼þ´æÔÚÓÚËùÓÐĬÈÏ×°ÖÃÖУ¬¼øÓÚ´Ë·ì϶µÄÑϳÁÐÔ£¬VMwareÇ¿ÁÒ½¨ÒéÓû§¾¡¿ìÉý¼¶¡£
´Ë±í£¬VMware»¹½¨¸´ÁËVMware ESXiÖÐÒ»¸ö³ÁÒªµÄ¶ÑÒç¶Âí½Å£¨CVE-2021-21974£©£¬ÆäCVSSÆÀ·Ö8.8¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£
2020Äê4Ô£¬VMware½â¾öÁËÁíÒ»¸öÑϳÁµÄvCenter Server·ì϶£¬¸Ã·ì϶¿ÉÄÜʹ¹¥»÷Õß¿ÉÄܽӼûÃô¸ÐÐÅÏ¢£¬²¢¿ÉÄܽÚÔìÊÜÓ°ÏìµÄϵͳ¡£
Ó°ÏìÁìÓò
vCenter Server 6.5
vCenter Server 6.7
vCenter Server 7.0
0x02 ´ëÖý¨Òé
Ŀǰ¸Ã·ì϶ÒѾ½¨¸´£¬½¨Òé²Î¿¼Ï±íʵʱÉý¼¶¡£
Ó°Ïì°æ±¾ | ½¨¸´°æ±¾ | ²Î¿¼Á´½Ó£¨Ò»Ê±½¨¸´£© |
vCenter Server 6.5 | 6.5 U3n | https://kb.vmware.com/s/article/82374 |
vCenter Server 6.7 | 6.7 U3l | |
vCenter Server 7.0 | 7.0 U1c |
ÏÂÔØÁ´½Ó£º
vCenter Server 6.5 U3n
https://docs.vmware.com/en/VMware-vSphere/6.5/rn/vsphere-vcenter-server-65u3n-release-notes.html
vCenter Server 6.7 U3l
https://docs.vmware.com/en/VMware-vSphere/6.7/rn/vsphere-vcenter-server-67u3l-release-notes.html
vCenter Server 7.0 U1c
https://docs.vmware.com/en/VMware-vSphere/7.0/rn/vsphere-vcenter-server-70u1c-release-notes.html
0x03 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2021-0002.html
https://www.bleepingcomputer.com/news/security/vmware-fixes-critical-rce-bug-in-all-default-vcenter-installs/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21972
0x04 ¹¦·òÏß
2021-02-23 Vmware°ä²¼°²È«¸üÐÂ
2021-02-24 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ