VMware vCenter ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-21985£©
Ðû²¼Ê±¼ä 2021-05-260x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-21985 | ʱ ¼ä | 2021-05-26 |
Àà ÐÍ | RCE | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ©¶´ÏêÇé
vCenter ServerÊÇVMware¹«Ë¾µÄÒ»ÖÖ·þÎñÆ÷¹ÜÀí½â¾ö·½°¸£¬¿É×ÊÖúIT¹ÜÀíԱͨ¹ýµ¥¸ö¿ØÖÆÌ¨¹ÜÀíÆóÒµ»·¾³ÖеÄÐéÄâ»úºÍÐéÄ⻯Ö÷»ú¡£
2021Äê05ÔÂ25ÈÕ£¬VMwareÐû²¼ÁËvCenter ServerÄþ¾²¸üУ¬ÐÞ¸´ÁËvSphere ClientÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-21985£©ºÍÒ»¸öÉí·ÝÑé֤©¶´£¨CVE-2021-21986£©£¬ÆäCVSSv3»ù±¾µÃ·Ö·Ö±ðΪ9.8ºÍ6.5¡£
vCenter ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-21985£©
¸Ã©¶´´æÔÚÓÚvSphere Client£¨HTML5£©ÖУ¬ÓÉÓÚvCenter ServerÖÐĬÈÏÆôÓõÄVirtual SAN Health Check²å¼þȱ·¦ÊäÈëÑéÖ¤£¬ÓµÓÐ443¶Ë¿ÚÍøÂç·ÃÎÊȨÏ޵Ĺ¥»÷Õß¿ÉÒÔÀûÓôË©¶´ÔÚ³ÐÔØvCenter ServerµÄ²Ù×÷ϵͳÉÏÔ¶³ÌÖ´ÐÐÈÎÒâÃüÁî¡£
ÐèҪעÒâµÄÊÇ£¬Virtual SAN Health Check²å¼þÔÚËùÓÐvCenter ServerÖж¼Ä¬ÈÏÆôÓã¬ÈκÎÄܹ»Í¨¹ýÍøÂç·ÃÎÊvCenter ServerµÄδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¶¼¿ÉÒÔÀûÓÃÕâ¸ö©¶´£¬¶øÎÞÂÛÊÇ·ñʹÓÃvSAN£¬¶øÇҸé¶´ÎÞÐèÓû§½»»¥¼´¿ÉÔ¶³ÌÀûÓá£
vCenter ServerÉí·ÝÑé֤©¶´£¨CVE-2021-21986£©
¸Ã©¶´´æÔÚÓÚvSphere Client (HTML5)µÄVirtual SAN Health Check¡¢Site Recovery¡¢vSphere Lifecycle ManagerºÍVMware Cloud Director Availability²å¼þµÄvSphereÈÏÖ¤»úÖÆÖУ¬¾ßÓÐ vCenter Server É쵀 443 ¶Ë¿ÚÍøÂç·ÃÎÊȨÏ޵Ĺ¥»÷Õß¿ÉÒÔÀûÓôË©¶´Ö´ÐÐÊÜÓ°Ïì²å¼þËùÔÊÐíµÄ²Ù×÷£¬¶øÎÞÐè½øÐÐÉí·ÝÑéÖ¤¡£
Ó°Ï췶Χ
vCenter Server 7.0
vCenter Server 6.7
vCenter Server 6.5
Cloud Foundation (vCenter Server) 4.x
Cloud Foundation (vCenter Server) 3.x
0x02 ´¦Öý¨Òé
ĿǰVMwareÒѾÐÞ¸´ÁËÕâЩ©¶´£¬½¨Ò龡¿ìÉý¼¶µ½ÒÔÏÂÐÞ¸´°æ±¾»ò¼°Ê±Ó¦Óûº½â´ëÊ©£º
vCenter Server 7.0 U2b
vCenter Server 6.7 U3n
vCenter Server 6.5 U3p
Cloud Foundation (vCenter Server) 4.2.1
Cloud Foundation (vCenter Server) 3.10.2.1
ÏÂÔØÁ´½Ó£º
https://www.vmware.com/security/advisories/VMSA-2021-0010.html
0x03 ²Î¿¼Á´½Ó
https://docs.vmware.com/en/VMware-vSphere/7.0/rn/vsphere-vcenter-server-70u2b-release-notes.html
https://kb.vmware.com/s/article/83829
https://core.vmware.com/resource/vmsa-2021-0010-faq
https://www.bleepingcomputer.com/news/security/vmware-warns-of-critical-bug-affecting-all-vcenter-server-installs/
0x04 ʱ¼äÏß
2021-05-25 VMwareÐû²¼Äþ¾²Í¨¸æ
2021-05-26 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/