ãVMware vCenter Serverãã«è¤æ°ã®èå¼±æ§ãå¤æããåé¡ã§ãBroadcomã¯ãããèå¼±æ§ãæªç¨ããã¦ãããã¨ãæããã«ããã å社ã¯ç¾å°æé11æ18æ¥ã«ã¢ããã¤ã¶ãªãæ´æ°ãããCVE-2024-38812ããCVE-2024-38813ããå®éã«æªç¨ããã¦ãããã¨ãæããã«ãããã®ã ãCVE-2024-38812ãã¯ããVMware vCenter Serverãã«ããããDCERPCãããã³ã«ãã®å®è£ ã«èµ·å ãããã¼ããªã¼ãã¼ããã¼ãçããèå¼±æ§ããªã¢ã¼ãããã³ã¼ããå®è¡ãããã¨ãå¯è½ã¨ãªãã å社ã§ã¯ãç¾å°æé9æ17æ¥ã«ã¢ããã¤ã¶ãªãå ¬éããã¢ãããã¼ãããªãªã¼ã¹ãããã®ã®ãå½åã®ããããä¸å®å ¨ã ã£ããã¨ãå ¬è¡¨ã10æ21æ¥ã権éææ ¼ã®èå¼±æ§ãCVE-2024-38813ãã¨ã¨ãã«å度修æ£ãè¡ã£ã¦ããã å ±éèå¼±æ§è©ä¾¡ã·ã¹ãã ãCVSSv3.1ãã«ããã¦ãã¼ã¹ã¹
ã©ã³ãµã ã¦ã§ã¢ãç¨ããè¤æ°ã®æ»æè ããVMware ESXiãã®èå¼±æ§ãCVE-2024-37085ããæªç¨ãã¦ãããã¨ãããã£ãã6æã®ã¢ããã¤ã¶ãªå ¬è¡¨æç¹ã§æªç¨ã«é¢ããè¨åã¯ãªããéè¦åº¦ããä¸ãã¨ããã¦ãããã2024å¹´ã¯ããã«ã¯ã¼ããã¤æ»æã«æªç¨ããã¦ããã¨ããã åé¡ã®ãCVE-2024-37085ãã¯ããã¡ã¤ã³ã«åå ãããESXiãã«ããã¦ãç¹å®ãã¡ã¤ã³ã°ã«ã¼ãåã«å¯¾ããé©åãªæ¤è¨¼ãè¡ã£ã¦ããããèªè¨¼ã®ãã¤ãã¹ãå¯è½ã¨ãªãèå¼±æ§ã æ»æè ããActive Directoryãã§ã°ã«ã¼ããä½æã§ãã権éãæã¤å ´åããESX Adminsãã¨ã®å称ãæã¤ã°ã«ã¼ããä½æãããã¨ã§ãåã°ã«ã¼ãã«åå ããã¡ã³ãã¼ããESXiãã¤ãã¼ãã¤ã¶ã¼ãã®ç®¡çè 権éãåå¾ãããã¨ãå¯è½ã¨ãªãã 2024å¹´ã¯ããã«ãã¤ã¯ãã½ãããå ±åããBroadcomã§ã¯ç¾å°æé6æ25æ¥ã«åèå¼±æ§ã«é¢ããã»ãã¥ãªã
Broadcomã¯ããVMware ESXiããVMware vCenter Serverãã«èå¼±æ§ãè¦ã¤ãã£ãåé¡ã§ã»ãã¥ãªãã£ã¢ããã¤ã¶ãªãæ´æ°ããããVMware Cloud Foundationãåãã«ã¢ãããã¼ããæä¾ãã¦ããã å社ã¯ããVMware ESXiãã«ãCVE-2024-37085ããCVE-2024-37086ããããVMware vCenter Serverãã«DoSæ»æãå¯è½ã¨ãªããCVE-2024-37087ããå¤æããåé¡ã§ãç¾å°æé6æ25æ¥ã«ã¢ããã¤ã¶ãªããªãªã¼ã¹ã ç¾å°æé7æ24æ¥ã«åã¢ããã¤ã¶ãªãæ´æ°ãããVMware Cloud Foundationãã«ãããä¿®æ£çãå5.2ãããã³ãå7.0 U3qãã®æä¾ã«ã¤ãã¦ã¢ãã¦ã³ã¹ããã ãªãããVMware ESXiãã«å¯¾ãã¦ã¯ãESXi80U3-24022510ããESXi70U3sq-2379
注éï¼è¿½è¨ãã¹ãæ å ±ãããå ´åã«ã¯ããã®é½åº¦ãã®ãã¼ã¸ãæ´æ°ããäºå®ã§ãã æ¦è¦ Broadcom ãæä¾ãã VMware vCenter Server ã¯ãä»®æ³åç°å¢ã®ç®¡çéç¨ãã¼ã«ã§ãã ãã® VMware vCenter Server ã«ããã¦ãDCE/RPC ãããã³ã«ã®å®è£ ã«èµ·å ãããã¼ããã¼ã¹ã®ãããã¡ãªã¼ãã¼ããã¼ã®èå¼±æ§ (CVE-2024-37079ãCVE-2024-37080) ããè¤æ°ã®ãã¼ã«ã«æ¨©éææ ¼ã®èå¼±æ§ (CVE-2024-37081) ã確èªããã¦ãã¾ãã æ¬èå¼±æ§ãæªç¨ãããå ´åãvCenter Server ã¸ã®ã¢ã¯ã»ã¹æ¨©ãæã¤ç¬¬ä¸è ã«ãã£ã¦ä»»æã®ã³ã¼ããå®è¡ããããã管çè 権éãæããªãã¦ã¼ã¶ã«ãã£ã¦ root 権éã«ææ ¼ããããããå¯è½æ§ãããã¾ãã ä»å¾è¢«å®³ãæ¡å¤§ããããããããããã製åéçºè ãå ¬è¡¨ãã¦ããæé ã«å¾ããä¿®æ£ããã°ã©ã ãé©ç¨ãã¦
ä»®æ³åç°å¢ã®ç®¡çéç¨ãã¼ã«ãVMware vCenter Serverãã«ããã¦ãè¤æ°ã®æ·±å»ãªèå¼±æ§ãæããã¨ãªã£ããå製åãæä¾ããBroadcomã¯ãéè¦åº¦ããã£ã¨ãé«ããã¯ãªãã£ã«ã«ï¼Criticalï¼ãã¨ããå©ç¨è ã«æ³¨æãå¼ã³ããã¦ããã ç¾å°æé6æ17æ¥ã«ã»ãã¥ãªãã£ã¢ããã¤ã¶ãªãå ¬éãããVMware vCenter Serverãã«é¢ãã3件ã®èå¼±æ§ãCVE-2024-37079ããCVE-2024-37080ããCVE-2024-37081ãã«ã¤ãã¦æããã«ãããã®ã ã¢ããã¤ã¶ãªã®éè¦åº¦ã4段éä¸ãã£ã¨ãé«ããã¯ãªãã£ã«ã«ï¼Criticalï¼ãã¨ãã¦æ³¨æãåèµ·ããããããèå¼±æ§ã¯å¤é¨ããå ±åãåããã¨ãã¦ãããã»ãã¥ãªãã£ã¢ããã¤ã¶ãªããªãªã¼ã¹ããæç¹ã§æªç¨ã¯ç¢ºèªããã¦ããªãã¨ãã¦ããã ãCVE-2024-37079ããCVE-2024-37080ãã®2件ã¯ããDCE
Broadcomã¯ç¾å°æé5æ21æ¥ãã»ãã¥ãªãã£ã¢ããã¤ã¶ãªãå ¬éãããVMware ESXiããã¯ãããåä¸ã®VMwareãã©ã³ãã§å±éããè¤æ°è£½åã«èå¼±æ§ãè¦ã¤ãã£ããã¨ãæããã«ããã ãVMware ESXiããVMware WorkstationããVMware FusionããVMware vCenter Serverããªã©è¤æ°è£½åã«èå¼±æ§ãæããã¨ãªã£ããã®ãéè¦åº¦ã¯4段éä¸ã2çªç®ã«é«ããéè¦ï¼Importantï¼ãã¨ã¬ã¼ãã£ã³ã°ãã¦ããã ãCVE-2024-22273ãã¯ãåå¤ã®ã¡ã¢ãªã«æ¸ãè¾¼ã¿ãè¡ãããããããèå¼±æ§ãä»®æ³ãã·ã³ã«ããã¦ãã¹ãã¬ã¼ã¸ã³ã³ããã¼ã©ã¼ããæå¹åãã¦ãããVMware ESXiããVMware WorkstationããVMware Fusionããå½±é¿ãåããã æ»æè ããã¹ãã¬ã¼ã¸ã³ã³ããã¼ã©ã¼ãã«ã¢ã¯ã»ã¹ã§ããå ´åããµã¼ãã¹æå¦ãå¼ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}