VMware Carbon Black App ControlÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶(CVE-2021-21998)
°ä²¼¹¦·ò 2021-06-230x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-21998 | ʱ ¼ä | 2021-06-17 |
Àà ÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | µÈ ¼¶ | ÑϳÁ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
¹¥»÷¸´ÔÓ¶È | µÍ | ¿ÉÓÃÐÔ | µÍ |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ·ì϶ÏêÇé

VMware Carbon Black ? App Control ?(AppC)ÊÇÊг¡ÉϳÉÊìÇÒ¿ÉÀ©´óµÄÀûÓ÷¨Ê½½ÚÔì½â¾ö¹æ»®Ö®Ò»¡£Carbon Black App ControlÓÃÓÚËø¶¨·þÎñÆ÷ºÍ¹Ø¼üϵͳ£¬Ô¤·ÀÒâ±í¸ü¸Ä²¢È·Î¬³ÖÐø×ñÊØ¼à¹ÜÒªÇó¡£ÀûÓÃÔÆÅµÑÔ·þÎñ¡¢»ùÓÚIT µÄÐÅÀµÕ½ÊõºÍÀ´×Ô VMware Carbon Black Cloud TM µÄ¶à¸öÍþвµý±¨ÆðÔ´£¬È·±£Ö»ÔÊÐíÊÜÐÅÀµºÍºË×¼µÄÈí¼þÔÚ×éÖ¯µÄ¹Ø¼üϵͳºÍ¶ËµãÉÏÖ´ÐС£
2021Äê06ÔÂ22ÈÕ£¬VMware°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËCarbon Black App ControlÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2021-21998)£¬ÆäCVSSv3 ÆÀ·ÖΪ9.4¡£¿ÉÄÜÍøÂç½Ó¼ûVMware Carbon Black App ControlÖÎÀí·þÎñÆ÷µÄÔ¶³Ì¹¥»÷ÕßÎÞÐè¾¹ýÉí·ÝÑéÖ¤¼´¿É»ñµÃ¸Ã²úÆ·µÄÖÎÀí½Ó¼ûȨÏÞ¡£
´Ë±í£¬VMware»¹½¨¸´ÁËVMware Tools for Windows¡¢VMRC for Windows ºÍ VMware App VolumesÖеÄÒ»¸ö±¾µØÌáȨ·ì϶£¨CVE-2021-21999£©£¬ÆäCVSSv3ÆÀ·ÖΪ7.8£¬¹¥»÷ÕßÄܹ»Í¨¹ýÔÚÒ»¸ö²»ÊÜÏ޶ȵÄĿ¼ÖиéÖóÁ¶¨ÃûΪ "openssl.cnf "µÄ¶ñÒâÎļþÀ´ÀûÓô˷ì϶£¬ÒÔÌáÉýȨÏÞ²¢Ö´ÐдúÂ롣ĿǰVMwareÒѾÔÚVMware Tools for Windows 11.2.6¡¢VMRC for Windows 12.0.1¡¢App Volumes 2103ºÍ2.18.10Öн¨¸´ÁË´Ë·ì϶¡£
Ó°ÏìÁìÓò
VMware Carbon Black App Control 8.6.x£¨Windows£©< 8.6.2
VMware Carbon Black App Control 8.5.x£¨Windows£©< 8.5.8
VMware Carbon Black App Control 8.1.x¡¢8.0.x£¨Windows£©£ºÎ´×°ÖÃHotfixµÄ
0x02 ´ëÖý¨Òé
Ŀǰ´Ë·ì϶ÒѾ½¨¸´£¬½¨Òéʵʱ¸üÐÂÖÁ×îа汾£º
VMware Carbon Black App Control 8.6.x£¨Windows£©8.6.2
VMware Carbon Black App Control 8.5.x£¨Windows£©8.5.8
VMware Carbon Black App Control 8.1.x¡¢8.0.x£¨Windows£©Hotfix
ÏÂÔØÁ´½Ó£º
https://www.vmware.com/security/advisories/VMSA-2021-0012.html
0x03 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2021-0012.html
https://www.vmware.com/security/advisories/VMSA-2021-0013.html
https://community.carbonblack.com/t5/App-Control-Documents/Critical-App-Control-Server-Patch-Announcement/ta-p/104906
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3044
0x04 ¹¦·òÏß
2021-06-22 VMware°ä²¼°²È«²¼¸æ
2021-06-23 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ