目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2021-21985 PoC — Vmware vSphere Client 输入验证错误漏洞

来源
关联漏洞
标题: Vmware vSphere Client 输入验证错误漏洞 (CVE-2021-21985)
Description:Vmware vSphere Client是美国威睿(Vmware)公司的一个应用软件。提供虚拟化管理。 Vmware vSphere Client 存在输入验证错误漏洞,该漏洞由于vCenter Server默认启用的虚拟SAN健康检查插件缺乏输入验证,导致攻击者可以在底层操作系统上以不受限制的权限执行命令。
Description
VMWARE VCENTER SERVER VIRTUAL SAN HEALTH CHECK PLUG-IN RCE (CVE-2021-21985) 
介绍
# Vulnerability Details

## VMWARE VCENTER SERVER VIRTUAL SAN HEALTH CHECK PLUG-IN RCE (CVE-2021-21985)
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U2b, 6.7 before 6.7 U3n, and 6.5 before 6.5 U3p) and VMware Cloud Foundation (4.x before 4.2.1 and 3.x before 3.10.2.1).

### This tool help you to explore the vulnerability above.

### Use:
```bash
> git clone https://github.com/sknux/CVE-2021-21985_PoC
> cd CVE-2021-21985_PoC
> chmod +x cve-2021-21985_PoC
> ./cve-2021-21985_PoC
$ Usage: ./poc Target-IP Class/Method(s). To list all class/methods, please use -l option.
> ./cve-2021-21985_PoC -l
$ getClusterCapabilityData
                 getHostCapabilityData
                 getHostsCapabilitiyData
                 getIsDeduplicationSupported
                 getIsEncryptionSupported
                 getIsLocalDataProtectionSupportedOnVc
                 getIsLocalDataProtectionSupportedOnCluster
                 getIsRemoteDataProtectionSupported
                 getIsObjectIdentitiesSupportedOnCluster
                 getIsHistoricalCapacitySupported
                 getIsPerfVerboseModeSupported
                 getIsPerfNetworkDiagnosticModeSupported
                 getIsPerfDiagnosticsFeedbackSupportedOnVc
                 getIsAdvancedClusterSettingsSupported
                 getIsRecreateDiskGroupSupported
                 getIsPurgeInaccessibleVmSwapObjectsSupported
                 getIsUpdateVumReleaseCatalogOfflineSupported
                 getIsVitOnlineResizeSupported
                 getIsImprovedCapacityMonitoringSupportedOnVc
                 getIsVmLevelCapacityMonitoringSupported
                 getIsWhatIfCapacitySupported
                 getIsHostReservedCapacitySupported
                 getIsUnmountWithMaintenanceModeSupported
                 getIsEvacuationStatusSupportedOnCluster
...
...
```

### Credits: https://github.com/alt3kx/CVE-2021-21985_PoC
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →