VMware vSphere ServerÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-21972£©

°ä²¼¹¦·ò 2021-02-24

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2021-21972

ʱ  ¼ä

2021-02-24

Àà  ÐÍ

RCE

µÈ  ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


 

0x01 ·ì϶ÏêÇé

image.png

 

VMware vCenter ServerÊǸ߼¶·þÎñÆ÷ÖÎÀíÈí¼þ£¬ÆäÌṩÁËÒ»¸ö¼¯ÖÐʽƽ̨À´½ÚÔìµÄVMware vSphere »·¾³£¬Ê¹Óû§¿ÉÄÜÔÚÕû¸ö»ìºÏÔÆÖÐ×Ô¶¯²¿Êð²¢½»¸¶Ðé¹¹»ù´¡¼Ü¹¹¡£

2021Äê02ÔÂ23ÈÕ£¬Vmware°ä²¼ÁËvCenter Server°²È«¸üУ¬½¨¸´ÁËvSphere Client (HTML5) ÔÚvCenter Server²å¼þvRealize Operations£¨vROps£©ÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-21972£©£¬ÆäCVSSÆÀ·ÖΪ9.8¡£¿ÉÄܽӼûÍøÂç¶Ë¿Ú443µÄ¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓô˷ì϶ÔÚÍйÜvCenter ServerµÄ²Ù×÷ϵͳÉÏÒÔ²»ÊÜÏ޶ȵÄȨÏÞÖ´ÐкÅÁî¡£´Ë±í£¬ÓÉÓÚÊÜÓ°ÏìµÄ²å¼þ´æÔÚÓÚËùÓÐĬÈÏ×°ÖÃÖУ¬¼øÓÚ´Ë·ì϶µÄÑϳÁÐÔ£¬VMwareÇ¿ÁÒ½¨ÒéÓû§¾¡¿ìÉý¼¶¡£

´Ë±í£¬VMware»¹½¨¸´ÁËVMware ESXiÖÐÒ»¸ö³ÁÒªµÄ¶ÑÒç¶Âí½Å£¨CVE-2021-21974£©£¬ÆäCVSSÆÀ·Ö8.8¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£

2020Äê4Ô£¬VMware½â¾öÁËÁíÒ»¸öÑϳÁµÄvCenter Server·ì϶£¬¸Ã·ì϶¿ÉÄÜʹ¹¥»÷Õß¿ÉÄܽӼûÃô¸ÐÐÅÏ¢£¬²¢¿ÉÄܽÚÔìÊÜÓ°ÏìµÄϵͳ¡£

 

Ó°ÏìÁìÓò

vCenter Server 6.5

vCenter Server 6.7

vCenter Server 7.0

 

0x02 ´ëÖý¨Òé

Ŀǰ¸Ã·ì϶ÒѾ­½¨¸´£¬½¨Òé²Î¿¼Ï±íʵʱÉý¼¶¡£

Ó°Ïì°æ±¾

½¨¸´°æ±¾

²Î¿¼Á´½Ó£¨Ò»Ê±½¨¸´£©

vCenter Server 6.5

6.5 U3n

https://kb.vmware.com/s/article/82374

vCenter Server 6.7

6.7 U3l

vCenter Server 7.0

7.0 U1c

 

ÏÂÔØÁ´½Ó£º

vCenter Server 6.5 U3n

https://docs.vmware.com/en/VMware-vSphere/6.5/rn/vsphere-vcenter-server-65u3n-release-notes.html

 

vCenter Server 6.7 U3l

https://docs.vmware.com/en/VMware-vSphere/6.7/rn/vsphere-vcenter-server-67u3l-release-notes.html

 

vCenter Server 7.0 U1c

https://docs.vmware.com/en/VMware-vSphere/7.0/rn/vsphere-vcenter-server-70u1c-release-notes.html

 

0x03 ²Î¿¼Á´½Ó

https://www.vmware.com/security/advisories/VMSA-2021-0002.html

https://www.bleepingcomputer.com/news/security/vmware-fixes-critical-rce-bug-in-all-default-vcenter-installs/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21972

 

0x04 ¹¦·òÏß

2021-02-23  Vmware°ä²¼°²È«¸üÐÂ

2021-02-24  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png