VMware Carbon Black App ControlÉí·ÝÑéÖ¤Èƹý©¶´(CVE-2021-21998)

Ðû²¼Ê±¼ä 2021-06-23

0x00 ©¶´¸ÅÊö

CVE     ID

CVE-2021-21998

ʱ      ¼ä

2021-06-17

Àà       ÐÍ

Éí·ÝÑéÖ¤Èƹý

µÈ      ¼¶

ÑÏÖØ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


¹¥»÷ÅÓ´ó¶È

µÍ

¿ÉÓÃÐÔ

µÍ

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ©¶´ÏêÇé

image.png

VMware Carbon Black ? App Control ?(AppC)ÊÇÊг¡ÉϳÉÊìÇÒ¿ÉÀ©Õ¹µÄÓ¦Ó÷¨Ê½¿ØÖƽâ¾ö·½°¸Ö®Ò»¡£Carbon Black App ControlÓÃÓÚËø¶¨·þÎñÆ÷ºÍÒªº¦ÏµÍ³£¬·ÀÖ¹ÒâÍâ¸ü¸Ä²¢È·±£Á¬Ðø×ñÊؼà¹ÜÒªÇó¡£ÀûÓÃÔÆÐÅÓþ·þÎñ¡¢»ùÓÚIT µÄÐÅÈμÆıºÍÀ´×Ô VMware Carbon Black Cloud TM µÄ¶à¸öÍþвÇ鱨À´Ô´£¬È·±£Ö»ÔÊÐíÊÜÐÅÈκÍÅú×¼µÄÈí¼þÔÚ×éÖ¯µÄÒªº¦ÏµÍ³ºÍ¶ËµãÉÏÖ´ÐС£

2021Äê06ÔÂ22ÈÕ£¬VMwareÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËCarbon Black App ControlÖеÄÒ»¸öÉí·ÝÑéÖ¤Èƹý©¶´£¨CVE-2021-21998)£¬ÆäCVSSv3 ÆÀ·ÖΪ9.4¡£Äܹ»ÍøÂç·ÃÎÊVMware Carbon Black App Control¹ÜÀí·þÎñÆ÷µÄÔ¶³Ì¹¥»÷ÕßÎÞÐè¾­¹ýÉí·ÝÑéÖ¤¼´¿É»ñµÃ¸Ã²úÎïµÄ¹ÜÀí·ÃÎÊȨÏÞ¡£

´ËÍ⣬VMware»¹ÐÞ¸´ÁËVMware Tools for Windows¡¢VMRC for Windows ºÍ VMware App VolumesÖеÄÒ»¸öµ±µØÌáȨ©¶´£¨CVE-2021-21999£©£¬ÆäCVSSv3ÆÀ·ÖΪ7.8£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚÒ»¸ö²»ÊÜÏÞÖƵÄĿ¼ÖзÅÖÃÖØÃüÃûΪ "openssl.cnf "µÄ¶ñÒâÎļþÀ´ÀûÓôË©¶´£¬ÒÔÌáÉýȨÏÞ²¢Ö´ÐдúÂ롣ĿǰVMwareÒѾ­ÔÚVMware Tools for Windows 11.2.6¡¢VMRC for Windows 12.0.1¡¢App Volumes 2103ºÍ2.18.10ÖÐÐÞ¸´ÁË´Ë©¶´¡£

 

Ó°Ï췶Χ

VMware Carbon Black App Control 8.6.x£¨Windows£©< 8.6.2

VMware Carbon Black App Control 8.5.x£¨Windows£©< 8.5.8

VMware Carbon Black App Control 8.1.x¡¢8.0.x£¨Windows£©£ºÎ´°²×°HotfixµÄ

 

0x02 ´¦Öý¨Òé

Ä¿Ç°´Ë©¶´ÒѾ­ÐÞ¸´£¬½¨Ò鼰ʱ¸üÐÂÖÁ×îа汾£º

VMware Carbon Black App Control 8.6.x£¨Windows£©8.6.2

VMware Carbon Black App Control 8.5.x£¨Windows£©8.5.8

VMware Carbon Black App Control 8.1.x¡¢8.0.x£¨Windows£©Hotfix

ÏÂÔØÁ´½Ó£º

https://www.vmware.com/security/advisories/VMSA-2021-0012.html

 

0x03 ²Î¿¼Á´½Ó

https://www.vmware.com/security/advisories/VMSA-2021-0012.html

https://www.vmware.com/security/advisories/VMSA-2021-0013.html

https://community.carbonblack.com/t5/App-Control-Documents/Critical-App-Control-Server-Patch-Announcement/ta-p/104906

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3044

 

0x04 ʱ¼äÏß

2021-06-22  VMwareÐû²¼Äþ¾²Í¨¸æ

2021-06-23  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png