VirtualBoxºÍVMware ESXiÐé¹¹»úÌÓÒÝ·ì϶

°ä²¼¹¦·ò 2018-11-13
11Ô£¬Î¬ËûÃüÔÚÒ»ÖÜÄÚ°ä²¼ÁË2Ìõ¹ØÓÚÐé¹¹»úÌÓÒÝ·ì϶µÄ°²È«¼òѶ£¬±ðÀëÉæ¼°Á½´óÈí¼þ²úÆ·£ºVirtualBoxºÍVMwareϵÁУ¬·ì϶ӰÏìÁìÓò½Ï¹ã£¬½¨Òé¸÷È˹Ø×¢¡£


VirtualBoxÐé¹¹»úÌÓÒÝ·ì϶


1¡¢²¼¾°ÃèÊö


11ÔÂ7ÈÕ,¶íÂÞ˹·ì϶×êÑÐÈËÔ±ÔÚGitHubÉÏÅû¶һVirtualBoxÐé¹¹»úÌÓÒÝ0day·ì϶µÄ¾ßÌåÐÅÏ¢£¬¹¥»÷ÕßÀûÓø÷ì϶ÌÓÀëVirtualBoxÐé¹¹»ú£¨·Ã¿Í²Ù×÷ϵͳ£©£¬ÔڵײãϵͳÉÏÖ´ÐС£Ò»µ©ÍÑÀëÁËVirtualBoxÐé¹¹»ú£¬¶ñÒâ´úÂ뽫ÔڵײãϵͳµÄÓÐÏÞÓû§¿Õ¼ä£¨ÄÚºËRing 3£©ÖÐÔËÐУ¬ÉõÖÁ¹¥»÷ÕßÄܹ»ÀûÓúܶàÒÑÖªµÄȨÏÞÌáÉý·ì϶À´»ñµÃÄں˼¶½Ó¼ûȨÏÞ£¨Ring 0£©¡£


2¡¢Ó°ÏìÁìÓò


Ó°Ïì°æ±¾£ºVirtualBox 5.2.20¼°ÔçÆÚ°æ±¾
Ö÷»úϵͳ£ºËÁÒâ
¿Í»§ÏµÍ³£ºËÁÒâ
Ðé¹¹»úÅäÖãºÄ¬ÈÏ£¨Íø¿¨ÎªIntel Pro/1000 MT ×ÀÃæ°æ£¨82540EM£©ÍøÂçģʽΪNAT£©

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


3¡¢½¨¸´¹æ»®


½«Ðé¹¹»úÍø¿¨ÉèÖÃΪPCnet»ò°ëÐé¹¹ÍøÂçģʽ


4¡¢²Î¿¼Á´½Ó


https://github.com/MorteNoir1/virtualbox\_e1000_0day
https://www.bleepingcomputer.com/news/security/virtualbox-zero-day-vulnerability-details-and-exploit-are-publicly-available/


VMware ESXiÐé¹¹»úÌÓÒÝ·ì϶


1¡¢·ìϼûèÊö


11ÔÂ9ÈÕ£¬VMware¹Ù·½°ä²¼°²È«¹«¸æ£¬½¨¸´ÁËÁ½¸öÐé¹¹»úÌÓÒÝ·ì϶£¨CVE-2018-6981ºÍCVE-2018-6982£©¡£VMware ESXi¡¢Fusion ºÍ Workstation ÔÚvmxnet3Ðé¹¹ÍøÂçÊÊÅäÆ÷ÖдæÔÚδ³õʼ»¯µÄÕ»ÄÚ´æÊ¹Ó᣸ÃÎÊÌâ¿ÉÄܵ¼ÖÂguestÐé¹¹»úÔÚËÞÖ÷»úÉÏÖ´ÐдúÂë¡£µ±ÆôÓÃÁËvmxnet3£¬Ôò»á³öÏÖ´ËÎÊÌ⡣δʹÓÃvmxnet3Íø¿¨µÄÐé¹¹»ú²»ÊÜ´Ë·ì϶µÄÓ°Ïì¡£

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2¡¢Ó°ÏìÁìÓò


VMware vSphere ESXi (ESXi)
VMware Workstation Pro/Player (Workstation)
VMware Fusion Pro, Fusion (Fusion)




3¡¢½¨¸´¹æ»®


VMwareÒѰ䲼²úÆ·Óйذ汾µÄ²¹¶¡£º


ESXi 6.0
https://my.vmware.com/group/vmware/patch
https://docs.vmware.com/en/VMware-vSphere/6.0/rn/esxi600-201811001.html


ESXi 6.5
https://my.vmware.com/group/vmware/patch
https://docs.vmware.com/en/VMware-vSphere/6.5/rn/esxi650-201811001.html


ESXi 6.7
https://my.vmware.com/group/vmware/patch
https://docs.vmware.com/en/VMware-vSphere/6.7/rn/esxi670-201811001.html


VMware Workstation Pro 14.1.3
https://www.vmware.com/go/downloadworkstation
https://docs.vmware.com/en/VMware-Workstation-Pro/index.html


VMware Workstation Player 14.1.3
https://www.vmware.com/go/downloadplayer
https://docs.vmware.com/en/VMware-Workstation-Player/index.html


VMware Fusion Pro / Fusion 10.1.3
https://www.vmware.com/go/downloadfusion
https://docs.vmware.com/en/VMware-Fusion/index.html


4¡¢²Î¿¼Á´½Ó


https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6981 
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6982


ÉêÃ÷£º±¾×ÊѶÓɱ¦ÔËÀ³¹Ù·½ÍøÕ¾Î¬ËûÃü°²È«Ó××é±àÒëºÍÕû¶Ù