Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | VMware vCenter ServerÈÏÖ¤ÏÂÁîÖ´ÐÐÎó²î |
CVE ID | CVE-2025-41225 |
Îó²îÀàÐÍ | ÏÂÁîÖ´ÐÐ | ·¢Ã÷ʱ¼ä | 2025-05-22 |
Îó²îÆÀ·Ö | 8.8 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍâµØ | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
vCenterÊÇVMwareÌṩµÄ¼¯ÖÐÖÎÀíÆ½Ì¨£¬ÓÃÓÚÖÎÀíVMware vSphereÇéÐÎÖеÄÐéÄ⻯×ÊÔ´¡£ËüÔÊÐíÖÎÀíÔ±¶ÔÐéÄâ»ú¡¢Ö÷»ú¡¢´æ´¢ºÍÍøÂç¾ÙÐÐͳһÖÎÀíºÍ¼à¿Ø¡£vCenterÌṩ¹¦Ð§ÈçÐéÄâ»ú°²ÅÅ¡¢×Ô¶¯»¯ÖÎÀí¡¢×ÊÔ´ÓÅ»¯ºÍ¸ß¿ÉÓÃÐÔ£¬×ÊÖúÆóÒµÌá¸ßÐéÄ⻯ÇéÐεÄЧÂʺÍÎÞаÐÔ¡£vCenterÊÇ´ó¹æÄ£Êý¾ÝÖÐÐĺÍÔÆÇéÐÎÖв»¿É»òȱµÄÖÎÀí¹¤¾ß£¬Ö§³Ö¼¯ÈºÖÎÀí¡¢¸ºÔØÆ½ºâºÍ¹ÊÕϻָ´µÈ¸ß¼¶ÌØÕ÷¡£
2025Äê5ÔÂ22ÈÕ£¬×ðÁú¿Ê±¼¯ÍÅVSRC¼à²âµ½VMwareÐû²¼µÄÇ徲ͨ¸æ£¬Ö¸³öVMware vCenter±£´æÈÏÖ¤ÏÂÁîÖ´ÐÐÎó²î¡£¹¥»÷ÕßÔھ߱¸½¨Éè»òÐ޸ľ¯±¨ÒÔ¼°Ö´Ðо籾²Ù×÷ȨÏÞʱ£¬¿ÉÄÜʹÓøÃÎó²îÔÚvCenter ServerÉÏÖ´ÐÐí§ÒâÏÂÁî¡£Èô¸ÃÎó²î±»ÀÖ³ÉʹÓ㬹¥»÷Õß¿ÉÄÜ»ñµÃϵͳ¿ØÖÆÈ¨ÏÞ»òÀÄÓÃϵͳ£¬´øÀ´ÑÏÖØµÄÇ徲Σº¦¡£Îó²î¼¶±ð¸ßΣ£¬Îó²îÆÀ·Ö8.8·Ö¡£
¶þ¡¢Ó°Ïì¹æÄ£
vCenter Server 8.0 < 8.0 U3evCenter Server 7.0 < 7.0 U3vVMware Cloud Foundation (vCenter) = 5.xVMware Cloud Foundation (vCenter) = 4.5.xVMware Telco Cloud Platform (vCenter) 5.x/4.x/3.x/2.x < 8.0 U3eVMware Telco Cloud Infrastructure (vCenter) 3.x < 8.0 U3eVMware Telco Cloud Infrastructure (vCenter) 2.x < 7.0 U3v
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìÉý¼¶¡£vCenter Server 8.0 >= 8.0 U3evCenter Server 7.0 >= 7.0 U3vVMware Telco Cloud Platform (vCenter) 5.x/4.x/3.x/2.x >= 8.0 U3eVMware Telco Cloud Infrastructure (vCenter) 3.x >= 8.0 U3eVMware Telco Cloud Infrastructure (vCenter) 2.x >= 7.0 U3v
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔ̽«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25717