VMwareȨÏÞÌáÉý·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-03-18

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-3950£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.3£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


VMware Fusion < 11.5.2

VMware Remote Console for Mac <= 11.x

VMware Horizon Client for Mac < 5.4.0


·ì϶¸ÅÊö


½üÈÕ£¬£¬£¬£¬£¬£¬£¬VMware¹Ù·½°ä²¼±àºÅΪVMSA-2020-0005µÄ°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁË´æÔÚÓÚVMware Fusion£¬£¬£¬£¬£¬£¬£¬VMRC for Mac ºÍHorizon Client for MacÖеÄȨÏÞÌáÉý·ì϶CVE-2020-3950£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚVMwareÃýÎóµÄʹÓÃÁËsetuid£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓô˷ì϶¿É½«Ö¸±êϵͳÖеÄͨ³£Óû§È¨ÏÞÌáÉýÖÁÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°PoCÒѹ«¿ª£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓйØÓû§Éý¼¶°æ±¾½øÐзÀ»¤¡£¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


PoC£ºhttps://github.com/mirchr/security-research/blob/master/vulnerabilities/CVE-2020-3950.sh¡£¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ¹Ù·½ÒѰ䲼×îа汾½¨¸´¸Ã·ì϶£¬£¬£¬£¬£¬£¬£¬ÊµÊ±¸üÐÂÊÜÓ°ÏìµÄVmware²úÆ·µ½Èçϰ汾£º


VMware Fusion 11.5.2

Downloads and Documentation:

https://www.vmware.com/go/downloadfusion

https://docs.vmware.com/en/VMware-Fusion/index.html


VMware Horizon Client 5.4.0

Downloads and Documentation:

https://my.vmware.com/web/vmware/info/slug/desktop_end_user_computing/vmware_horizon_clients/5_0

https://docs.vmware.com/en/VMware-Horizon-Client/index.html


VMware Remote Console for Mac 11.0.1

Downloads and Documentation:

https://my.vmware.com/web/vmware/details?downloadGroup=VMRC1101&productId=742

https://docs.vmware.com/en/VMware-Remote-Console/index.html


²Î¿¼Á´½Ó


https://www.vmware.com/security/advisories/VMSA-2020-0005.html