¡¾Îó²îͨ¸æ¡¿VMware vCenter ServerÈÏÖ¤ÏÂÁîÖ´ÐÐÎó²î(CVE-2025-41225)

Ðû²¼Ê±¼ä 2025-05-22

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

VMware vCenter ServerÈÏÖ¤ÏÂÁîÖ´ÐÐÎó²î

CVE   ID

CVE-2025-41225

Îó²îÀàÐÍ

ÏÂÁîÖ´ÐÐ

·¢Ã÷ʱ¼ä

2025-05-22

Îó²îÆÀ·Ö

8.8

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍâµØ

ËùÐèȨÏÞ

µÍ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


vCenterÊÇVMwareÌṩµÄ¼¯ÖÐÖÎÀíÆ½Ì¨£¬£¬£¬£¬£¬£¬ÓÃÓÚÖÎÀíVMware vSphereÇéÐÎÖеÄÐéÄ⻯×ÊÔ´ ¡£¡£¡£¡£¡£¡£ËüÔÊÐíÖÎÀíÔ±¶ÔÐéÄâ»ú¡¢Ö÷»ú¡¢´æ´¢ºÍÍøÂç¾ÙÐÐͳһÖÎÀíºÍ¼à¿Ø ¡£¡£¡£¡£¡£¡£vCenterÌṩ¹¦Ð§ÈçÐéÄâ»ú°²ÅÅ¡¢×Ô¶¯»¯ÖÎÀí¡¢×ÊÔ´ÓÅ»¯ºÍ¸ß¿ÉÓÃÐÔ£¬£¬£¬£¬£¬£¬×ÊÖúÆóÒµÌá¸ßÐéÄ⻯ÇéÐεÄЧÂʺÍÎÞаÐÔ ¡£¡£¡£¡£¡£¡£vCenterÊÇ´ó¹æÄ£Êý¾ÝÖÐÐĺÍÔÆÇéÐÎÖв»¿É»òȱµÄÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬£¬Ö§³Ö¼¯ÈºÖÎÀí¡¢¸ºÔØÆ½ºâºÍ¹ÊÕϻָ´µÈ¸ß¼¶ÌØÕ÷ ¡£¡£¡£¡£¡£¡£


2025Äê5ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬918²©ÌìÌü¯ÍÅVSRC¼à²âµ½VMwareÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬Ö¸³öVMware vCenter±£´æÈÏÖ¤ÏÂÁîÖ´ÐÐÎó²î ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔھ߱¸½¨Éè»òÐ޸ľ¯±¨ÒÔ¼°Ö´Ðо籾²Ù×÷ȨÏÞʱ£¬£¬£¬£¬£¬£¬¿ÉÄÜʹÓøÃÎó²îÔÚvCenter ServerÉÏÖ´ÐÐí§ÒâÏÂÁî ¡£¡£¡£¡£¡£¡£Èô¸ÃÎó²î±»ÀÖ³ÉʹÓ㬣¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»ñµÃϵͳ¿ØÖÆÈ¨ÏÞ»òÀÄÓÃϵͳ£¬£¬£¬£¬£¬£¬´øÀ´ÑÏÖØµÄÇ徲Σº¦ ¡£¡£¡£¡£¡£¡£Îó²î¼¶±ð¸ßΣ£¬£¬£¬£¬£¬£¬Îó²îÆÀ·Ö8.8·Ö ¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


vCenter Server 8.0 < 8.0 U3e
vCenter Server 7.0 < 7.0 U3v
VMware Cloud Foundation (vCenter) = 5.x
VMware Cloud Foundation (vCenter) = 4.5.x
VMware Telco Cloud Platform (vCenter) 5.x/4.x/3.x/2.x < 8.0 U3e
VMware Telco Cloud Infrastructure (vCenter) 3.x < 8.0 U3e
VMware Telco Cloud Infrastructure (vCenter) 2.x < 7.0 U3v


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìÉý¼¶ ¡£¡£¡£¡£¡£¡£
vCenter Server 8.0 >= 8.0 U3e
vCenter Server 7.0 >= 7.0 U3v
VMware Telco Cloud Platform (vCenter) 5.x/4.x/3.x/2.x >= 8.0 U3e
VMware Telco Cloud Infrastructure (vCenter) 3.x >= 8.0 U3e
VMware Telco Cloud Infrastructure (vCenter) 2.x >= 7.0 U3v


3.2 ÔÝʱ²½·¥


ÔÝÎÞ ¡£¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ ¡£¡£¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ ¡£¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ ¡£¡£¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È ¡£¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐÞ¸Ä ¡£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25717