VMwareÐÞ¸´¶à¸öÇå¾²Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-01-17

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-3941 £¬£¬ £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.8 £¬£¬ £¬ £¬£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2020-3940 £¬£¬ £¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬£¬ £¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º6.8 £¬£¬ £¬ £¬£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


CVE-2020-3941

VMware Tools for Windows 10.x.y


CVE-2020-3940

Workspace ONE SDK

Workspace ONE Boxer

Workspace ONE Content

Workspace ONE SDK Plugin for Apache Cordova

Workspace ONE Intelligent Hub

Workspace ONE Notebook

Workspace ONE People

Workspace ONE PIV-D

Workspace ONE Web

Workspace ONE SDK Plugin for Xamarin


Îó²î¸ÅÊö


VMwareÒÑÐû²¼Çå¾²¸üР£¬£¬ £¬ £¬£¬ £¬£¬ÐÞ¸´ÁËVMware ToolsºÍWorkspace ONE SDKÖеÄÎó²î¡£¡£¡£¡£¡£


VMwareÐÞ¸´ÁËWindows VMware Tools°æ±¾10.xyÖеÄÍâµØÌáȨÎó²î£¨CVE-2020-3941£©¡£¡£¡£¡£¡£¸ÃÎó²î±»¹éÀàΪ¾ºÕùÌõ¼þÎó²î £¬£¬ £¬ £¬£¬ £¬£¬¹¥»÷Õß¿ÉÄÜʹÓôËÎó²îÔÚÐéÄâ»úÖÐÌáÉýÌØÈ¨¡£¡£¡£¡£¡£


VMware»¹ÐÞ¸´ÁËWorkspace ONE SDKÖеÄÐÅϢй¶Îó²î£¨CVE-2020-3940£© £¬£¬ £¬ £¬£¬ £¬£¬¸ÃÎó²îÓ°ÏìÁËÏà¹ØµÄiOSºÍAndroid APP¡£¡£¡£¡£¡£Æ¾Ö¤Ç徲ͨ¸æ £¬£¬ £¬ £¬£¬ £¬£¬ÈôÊÇÆôÓÃÁËSSL Pinning £¬£¬ £¬ £¬£¬ £¬£¬ÔòÔÚÊÜÓ°ÏìµÄÒÆ¶¯APPºÍWorkspace ONE UEM×°±¸Ð§ÀÍÖ®¼äµÄÖÐÐÄÈË£¨MITM£©¹¥»÷Õß¿ÉÄܲ¶»ñ´«ÊäÖеÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î £¬£¬ £¬ £¬£¬ £¬£¬²¹¶¡»ñÈ¡Á´½Ó¼û²Î¿¼Á´½Ó¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.vmware.com/security/advisories/VMSA-2020-0002.html

https://www.vmware.com/security/advisories/VMSA-2020-0001.html