Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | VMware VMXNET3ÕûÊýÒç³öÎó²î |
CVE ID | CVE-2025-41236 |
Îó²îÀàÐÍ | ÕûÊýÒç³ö | ·¢Ã÷ʱ¼ä | 2025-07-17 |
Îó²îÆÀ·Ö | 9.3 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍâµØ | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
VMXNET3ÊÇVMwareÌṩµÄ¸ßÐÔÄÜÐéÄâÍøÂçÊÊÅäÆ÷£»VMCI£¨Virtual Machine Communication Interface£©ÓÃÓÚÐéÄâ»úÓëËÞÖ÷»úÖ®¼äµÄ¸ßЧͨѶ£»PVSCSIÊÇÃæÏò¸ßÐÔÄÜ´æ´¢µÄÐéÄ⻯SCSI¿ØÖÆÆ÷£»vSocketsÌṩÐéÄâ»úÓëËÞÖ÷»ú»òÐéÄâ»úÖ®¼äµÄÌ×½Ó×ÖͨѶ»úÖÆ£¬ÓÃÓÚµÍÑÓ³ÙÊý¾Ý´«Êä¡£
2025Äê7ÔÂ17ÈÕ£¬×ðÁú¿Ê±¼¯ÍÅVSRC¼à²âµ½VMware¹Ù·½Åû¶Æä¶à¸ö²úÆ·Öб£´æËĸö¸ßΣÎó²î£¬Éæ¼°VMXNET3¡¢VMCI¡¢PVSCSIºÍvSocketsµÈÒªº¦ÐéÄ⻯×é¼þ£¬»®·ÖΪVMware VMXNET3ÕûÊýÒç³öÎó²î£¨CVE-2025-41236£©¡¢VMware VMCIÕûÊýÏÂÒçÎó²î£¨CVE-2025-41237£©¡¢VMware PVSCSI¶ÑÒç³öÎó²î£¨CVE-2025-41238£©ÒÔ¼°VMware vSocketsÐÅϢй¶Îó²î£¨CVE-2025-41239£©¡£ÆäÖУ¬Ç°Èý¸öÎó²î¿É±»¾ß±¸ÍâµØÖÎÀíԱȨÏ޵Ĺ¥»÷ÕßÔÚÐéÄâ»úÄÚʹÓã¬×îÖÕÒÔVMXÀú³ÌȨÏÞÔÚËÞÖ÷»úÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬ÑÏÖØÍþвÐéÄ⻯ƽ̨µÄϵͳÇå¾²£»CVE-2025-41239ÔòÓÉÓÚvSockets×é¼þ±£´æÎ´³õʼ»¯ÄÚ´æÊ¹ÓÃÎÊÌ⣬¿ÉÄܵ¼Ö¹¥»÷Õßй¶ÓëÆäͨѶÀú³ÌµÄÃô¸ÐÄÚ´æÐÅÏ¢¡£
¶þ¡¢Ó°Ïì¹æÄ£
VMware Cloud Foundation ESX = 9.0.0.0 VMware Workstation = 17.x VMware Cloud Foundation = 4.5.x VMware Cloud Foundation = 5.x VMware Telco Cloud Platform = 2.x VMware Telco Cloud Platform = 3.x VMware Telco Cloud Platform = 4.x VMware Telco Cloud Platform = 5.x VMware Telco Cloud Infrastructure = 2.x VMware Telco Cloud Infrastructure = 3.x
CVE-2025-41237Ó°Ïì¹æÄ£
VMware vSphere Foundation ESX = 9.0.0.0VMware Workstation = 17.xVMware Cloud Foundation ESX = 9.0.0.0VMware Cloud Foundation = 4.5.xVMware Cloud Foundation = 5.xVMware Telco Cloud Platform = 2.xVMware Telco Cloud Platform = 3.xVMware Telco Cloud Platform = 4.xVMware Telco Cloud Platform = 5.xVMware Telco Cloud Infrastructure = 2.xVMware Telco Cloud Infrastructure = 3.x
CVE-2025-41238Ó°Ïì¹æÄ£
VMware Cloud Foundation ESX = 9.0.0.0VMware Workstation = 17.xVMware Cloud Foundation = 4.5.xVMware Cloud Foundation = 5.xVMware Telco Cloud Platform = 2.xVMware Telco Cloud Platform = 3.xVMware Telco Cloud Platform = 4.xVMware Telco Cloud Platform = 5.xVMware Telco Cloud Infrastructure = 2.xVMware Telco Cloud Infrastructure = 3.x
CVE-2025-41239Ó°Ïì¹æÄ£
VMware Cloud Foundation ESX = 9.0.0.0VMware vSphere Foundation ESX = 9.0.0.0VMware Cloud Foundation VMware Tools for Windows = 13.0.0.0VMware vSphere Foundation VMware Tools for Windows = 13.0.0.0VMware Workstation = 17.xVMware Cloud Foundation = 4.5.xVMware Cloud Foundation = 5.xVMware Telco Cloud Platform = 2.xVMware Telco Cloud Platform = 3.xVMware Telco Cloud Platform = 4.xVMware Telco Cloud Platform = 5.xVMware Telco Cloud Infrastructure = 2.xVMware Telco Cloud Infrastructure = 3.xVMware Tools for Windows = 11.x.xVMware Tools for Windows = 12.x.xVMware Tools for Windows = 13.x.xVMware Tools for Linux = 11.x.xVMware Tools for Linux = 12.x.xVMware Tools for Linux = 13.x.xVMware Tools for macOS = 11.x.xVMware Tools for macOS = 12.x.xVMware Tools for macOS = 13.x.x
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´°æ±¾£¬½¨Ò龡¿ìÉý¼¶ÖÁ×îа汾VMware vSphere Foundation ESX 9.0.0.0 Éý¼¶ÖÁESXi-9.0.0.0100-24813472VMware Tools 13.0.0.0£¨Windows£©Éý¼¶ÖÁ13.0.1.0VMware ESXi 8.0£ºÉý¼¶ÖÁESXi80U3f-24784735»òÉý¼¶ÖÁESXi80U2e-24789317VMware ESXi 7.0£ºÉý¼¶ÖÁESXi70U3w-24784741VMware Workstation 17.x£ºÉý¼¶ÖÁ 17.6.4VMware Fusion 13.xÉý¼¶ÖÁ13.6.4VMware Cloud Foundation°æ±¾ 5.x£ºÒì²½²¹¶¡ÖÁESXi80U3f-24784735VMware Cloud Foundation°æ±¾ 4.5.x£ºÒì²½²¹¶¡ÖÁESXi70U3w-24784741VMware Telco Cloud Platform°æ±¾ 5.x / 4.x£ºÉý¼¶ÖÁESXi80U3f-24784735VMware Telco Cloud Platform°æ±¾ 3.x / 2.x£ºÉý¼¶ÖÁESXi70U3w-24784741VMware Telco Cloud Infrastructure£¨3.x / 2.x£©Éý¼¶ÖÁESXi70U3w-24784741VMware Tools Windows 13.xx£ºÉý¼¶ÖÁ13.0.1.0VMware Tools Windows 12.xx / 11.xx£ºÉý¼¶ÖÁ12.5.3
ÏÂÔØÁ´½Ó£º
VMware Cloud Foundation 9.0.0.0.0https://support.broadcom.com/group/ecx/productfiles?displayGroup=VMware%20Cloud%20Foundation%209&release=9.0.0.0&os=&servicePk=&language=EN&groupId=529537&viewGroup=true
VMware vSphere Foundation 9.0.0.0.0
https://support.broadcom.com/group/ecx/productfiles?displayGroup=VMware%20vSphere%20Foundation%209&release=9.0.0.0&os=&servicePk=&language=EN&groupId=529542&viewGroup=true
VMware ESXi 8.0 ESXi80U3f-24784735
https://support.broadcom.com/web/ecx/solutiondetails?patchId=15938https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/8-0/release-notes/esxi-update-and-patch-release-notes/vsphere-esxi-80u3f-release-notes.html
VMware ESXi 8.0 ESXi80U2e-24789317
https://support.broadcom.com/web/ecx/solutiondetails?patchId=15939https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/8-0/release-notes/esxi-update-and-patch-release-notes/vsphere-esxi-80u2e-release-notes.html
VMware ESXi 7.0 ESXi70U3w-24784741
https://support.broadcom.com/web/ecx/solutiondetails?patchId=15940https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/7-0/release-notes/esxi-update-and-patch-release-notes/vsphere-esxi-70u3w-release-notes.html
VMware Workstation 17.6.4
https://support.broadcom.com/group/ecx/productdownloads?subfamily=VMware%20Workstation%20Pro&freeDownloads=truehttps://techdocs.broadcom.com/us/en/vmware-cis/desktop-hypervisors/workstation-pro/17-0/release-notes/vmware-workstation-1764-pro-release-notes.html
VMware Fusion 13.6.4
https://support.broadcom.com/group/ecx/productdownloads?subfamily=VMware%20Fusion&freeDownloads=truehttps://techdocs.broadcom.com/us/en/vmware-cis/desktop-hypervisors/fusion-pro/13-0/release-notes/vmware-fusion-1364-release-notes.html
VMware Cloud Foundation 5.x, 4.5.x
https://knowledge.broadcom.com/external/article?legacyId=88287
VMware Tools 13.0.1.0
https://support.broadcom.com/group/ecx/productfiles?subFamily=VMware%20Tools&displayGroup=VMware%20Tools%2013.x&release=13.0.1.0&os=&servicePk=&language=EN&freeDownloads=truehttps://techdocs.broadcom.com/us/en/vmware-cis/vsphere/tools/13-0-0/release-notes/vmware-tools-1301-release-notes.html
VMware Tools 12.5.3
https://support.broadcom.com/group/ecx/productfiles?subFamily=VMware%20Tools&displayGroup=VMware%20Tools%2012.x&release=12.5.3&os=&servicePk=&language=EN&freeDownloads=truehttps://techdocs.broadcom.com/us/en/vmware-cis/vsphere/tools/12-5-0/release-notes/vmware-tools-1253-release-notes.html
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
?°´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£?ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔ̽«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£?ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£?ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£?ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/35877