VMware½¨¸´¶à¸ö°²È«·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-01-17

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-3941£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.8£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-3940£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.8£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


CVE-2020-3941

VMware Tools for Windows 10.x.y


CVE-2020-3940

Workspace ONE SDK

Workspace ONE Boxer

Workspace ONE Content

Workspace ONE SDK Plugin for Apache Cordova

Workspace ONE Intelligent Hub

Workspace ONE Notebook

Workspace ONE People

Workspace ONE PIV-D

Workspace ONE Web

Workspace ONE SDK Plugin for Xamarin


·ì϶¸ÅÊö


VMwareÒѰ䲼°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´ÁËVMware ToolsºÍWorkspace ONE SDKÖеķì϶¡£¡£¡£¡£¡£¡£¡£¡£


VMware½¨¸´ÁËWindows VMware Tools°æ±¾10.xyÖеı¾µØÌáȨ·ì϶£¨CVE-2020-3941£©¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»¹éÀàΪ¾ºÕùǰÌá·ì϶£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶ÔÚÐé¹¹»úÖÐÌáÉýÌØÈ¨¡£¡£¡£¡£¡£¡£¡£¡£


VMware»¹½¨¸´ÁËWorkspace ONE SDKÖеÄÐÅϢй¶·ì϶£¨CVE-2020-3940£©£¬£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìÁËÓйصÄiOSºÍAndroid APP¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý°²È«²¼¸æ£¬£¬£¬£¬£¬£¬ÈôÊÇÆôÓÃÁËSSL Pinning£¬£¬£¬£¬£¬£¬ÔòÔÚÊÜÓ°ÏìµÄÒÆ¶¯APPºÍWorkspace ONE UEMÉ豸·þÎñÖ®¼äµÄÖÐÑëÈË£¨MITM£©¹¥»÷Õß¿ÉÄܲ¶»ñ´«ÊäÖеÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó¼û²Î¿¼Á´½Ó¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.vmware.com/security/advisories/VMSA-2020-0002.html

https://www.vmware.com/security/advisories/VMSA-2020-0001.html