漏洞信息详情
Vmware vSphere Client 权限许可和访问控制问题漏洞
漏洞简介
Vmware vSphere Client是美国威睿(Vmware)公司的一个应用软件。提供虚拟化管理。
VMware vSphere Client存在一个安全漏洞,未授权的攻击者可以通过开放443端口的服务器向vCenter Server发送精心构造的请求,从而在目标系统上远程执行恶意代码。以下产品和版本受到影响:vSphere Client 6.5、vSphere Client 6.7、vSphere Client 7.0、VMware Cloud Foundation(vCenter Server)3.x、VMware Cloud Foundation(vCenter Server)4.x。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://www.vmware.com/security/advisories/VMSA-2021-0002.html
参考网址
来源:MISC
链接:https://packetstormsecurity.com/files/161590/VMware-vCenter-Server-7.0-Arbitrary-File-Upload.html
来源:MISC
链接:https://packetstormsecurity.com/files/163268/VMware-vCenter-6.5-6.7-7.0-Remote-Code-Execution.html
来源:CONFIRM
链接:https://www.vmware.com/security/advisories/VMSA-2021-0002.html
来源:MISC
链接:https://packetstormsecurity.com/files/161695/VMware-vCenter-Server-File-Upload-Remote-Code-Execution.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163268/VMware-vCenter-6.5-6.7-7.0-Remote-Code-Execution.html
来源:www.exploit-db.com
链接:https://www.exploit-db.com/exploits/50056
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/161590/VMware-vCenter-Server-7.0-Arbitrary-File-Upload.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/161527/VMware-vCenter-6.5-7.0-Remote-Code-Execution-Proof-Of-Concept.html
来源:cxsecurity.com
链接:https://cxsecurity.com/issue/WLB-2021030001
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1201
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/VMware-ESXi-vCenter-Server-multiple-vulnerabilities-34663
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-21972
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/161695/VMware-vCenter-Server-File-Upload-Remote-Code-Execution.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0677
来源:cxsecurity.com
链接:https://cxsecurity.com/issue/WLB-2021060144
来源:www.exploit-db.com
链接:https://www.exploit-db.com/exploits/49602
受影响实体
暂无
补丁
- Vmware vSphere Client 权限许可和访问控制问题漏洞的修复措施<!--2021-2-24-->
还没有评论,来说两句吧...