¡¾Îó²îͨ¸æ¡¿VMware Workstationí§ÒâÎļþɾ³ýÎó²î£¨CVE-2023-20854£©
Ðû²¼Ê±¼ä 2023-02-030x00 Îó²î¸ÅÊö
CVE ID | CVE-2023-20854 | ·¢Ã÷ʱ¼ä | 2023-02-03 |
Àà ÐÍ | Îļþɾ³ý | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ·ñ | ËùÐèȨÏÞ | µÍ |
¹¥»÷ÖØÆ¯ºó | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | ÔÚҰʹÓà |
0x01 Îó²îÏêÇé
VMware WorkstationÊÇÒ»¿î¹¦Ð§Ç¿Ê¢µÄ×ÀÃæÐéÄâÅÌËã»úÈí¼þ£¬£¬Óû§¿Éͨ¹ý¸ÃÈí¼þÔÚ¼òµ¥µÄ×ÀÃæÉÏͬʱÔËÐвî±ðµÄ²Ù×÷ϵͳ£¬£¬ÒÔ¾ÙÐпª·¢¡¢²âÊÔ ¡¢°²ÅÅеÄÓ¦ÓóÌÐòµÈ¡£¡£¡£
2ÔÂ2ÈÕ£¬£¬VMwareÐû²¼Ç徲ͨ¸æ£¬£¬ÐÞ¸´ÁËVMware Workstation ÖеÄÒ»¸öÎļþɾ³ýÎó²î£¨CVE-2023-20854£©£¬£¬¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.8¡£¡£¡£
VMware Workstation °æ±¾17.x±£´æÎļþɾ³ýÎó²î£¬£¬¿ÉÔÚÓµÓÐÍâµØÓû§È¨ÏÞµÄÇéÐÎÏÂʹÓøÃÎó²î´Ó×°ÖÃÁËWorkstation µÄÖ÷»úµÄϵͳÖÐɾ³ýí§ÒâÎļþ¡£¡£¡£
Ó°Ïì¹æÄ£
VMware Workstation °æ±¾17.x£¨Windowsƽ̨£©
0x02 Çå¾²½¨Òé
ÏÖÔÚ¸ÃÎó²îÒѾÐÞ¸´£¬£¬ÊÜÓ°ÏìÓû§¿ÉʵʱÉý¼¶µ½VMware Workstation °æ±¾17.0.1¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://customerconnect.vmware.com/en/downloads/info/slug/desktop_end_user_computing/vmware_workstation_pro/17_0
0x03 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2023-0003.html
https://docs.vmware.com/en/VMware-Workstation-Pro/17.0.1/rn/vmware-workstation-1701-pro-release-notes/index.html
0x04 °æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2023-02-03 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
ÈËÉú¾ÍÊDz©¼ò½é
ÈËÉú¾ÍÊDz©½¨ÉèÓÚ1996Ä꣬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÈËÉú¾ÍÊDz©´óÏ㬣¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬ÈËÉú¾ÍÊDz©ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£
¹ØÓÚÈËÉú¾ÍÊDz©
ÈËÉú¾ÍÊDz©Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£
¹Ø×¢ÒÔϹ«Öںţ¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ