最近 VMware 公司核心产品 vSphere 爆出多个高危安全漏洞,一些使用 vSphere 6.7 的旧版本用户,需要尽快更新到 6.7.U3l 以修复漏洞,这里提供目前最新的 6.7.U3l 下载。

详见官网安全通告:VMSA-2021-0002

国内厂商通告:

高危漏洞(critical)影响的产品和修复版本

Response Matrix:

Product

Version

Running On

CVE Identifier

CVSSv3

Severity

Fixed Version

Workarounds

Additional Documentation

vCenter Server

7.0

Any

CVE-2021-21972

9.8

critical

7.0 U1c

KB82374

None

vCenter Server

6.7

Any

CVE-2021-21972

9.8

critical

6.7 U3l

KB82374

None

vCenter Server

6.5

Any

CVE-2021-21972

9.8

critical

6.5 U3n

KB82374

None

Impacted Product Suites that Deploy Response Matrix 3a Components:

Product

Version

Running On

CVE Identifier

CVSSv3

Severity

Fixed Version

Workarounds

Additional Documentation

Cloud Foundation (vCenter Server)

4.x

Any

CVE-2021-21972

9.8

critical

4.2

KB82374

None

Cloud Foundation (vCenter Server)

3.x

Any

CVE-2021-21972

9.8

critical

3.10.1.2

KB82374

None

更新说明

详见官方 VMware vCenter Server 6.7 Update 3l 发行说明

下载地址

百度网盘链接: https://sysin.org/article/vmware-vcenter-6-7/