《黑暗角落:一个失败的补丁如何让 VMware ESXi 虚拟机暴露长达两年之久.pdf》由会员分享,可在线阅读,更多相关《黑暗角落:一个失败的补丁如何让 VMware ESXi 虚拟机暴露长达两年之久.pdf(55页珍藏版)》请在三个皮匠报告上搜索。
1、#BHUSA BlackHatEventsDark Corners:How a Failed Patch Dark Corners:How a Failed Patch Left VMware ESXi VM Escapes Left VMware ESXi VM Escapes Open for Two YearsOpen for Two YearsYuhao Jiang,0 x140ce,Ezrak1e#BHUSA BlackHatEvents Security researchers at Ant Group Light-Year Security Lab Escaped from vi
2、rtual machine many times Won the Pwnie Awardsin 2023Who are we?#BHUSA BlackHatEvents Introduction Escape VM First Escape ESXi Sandbox DemoTalk Roadmap#BHUSA BlackHatEventsIntroduction#BHUSA BlackHatEventsVMware announced a 0day which has occurred in the wild.We exploited VMware ESXi on Tianfu Cup 20
3、23.Lets share some interesting things behind that story.The Wake-Up Call#BHUSA BlackHatEvents Pretty same as VMware Workstation But the host OS is replaced as VMkernel Has sandboxESXi Architecture Overview#BHUSA BlackHatEventsEscape VM First#BHUSA BlackHatEventsAttack SurfaceVirtual DeviceHard DiskL
4、SI LogicPVSCSIPwn2Own 2025 Workstation(CVE-2025-41238)NVMENetwork AdapterE1000/E1000eVMXNET3Pwn2Own 2025 ESXi(CVE-2025-41236)USB ControllerUHCI(USB 1)Tianfu Cup 2021 Workstation(CVE-2021-22041),Tianfu Cup 2023 Workstation(CVE-2024-22253,CVE-22255)EHCI(USB 2)GeekPwn 2022 Fusion(CVE-2022-31705)XHCI(US
5、B 3)Tianfu Cup 2021 ESXi(CVE-2021-22040),Tianfu Cup 2023 ESXi(CVE-2024-22252)USB DeviceHID(mouse)BluetoothPwn2Own 2023 Workstation(CVE-2023-20869,CVE-2023-20870),Pwn2Own 2024 Workstation(CVE-2024-22267,CVE-2024-22269)GPUSVGA 2DSVGA 3DSound CardES1371TPMvTPMVMCIVMCIOccurred in the wild(CVE-2025-22224
6、),Pwn2Own 2025 ESXi(CVE-2025-41237)GuestRPCBackdoorHGFSPwn2Own 2024 Workstation(CVE-2024-22270),Occurred in the wild(CVE-2025-22226)VMM#BHUSA BlackHatEventsCVE-2021-22040(Found by Wei of Kunlun Lab on Tianfu Cup 2021).The“Ancient”VulnerabilityDiff the PatchWe diffed v16.2.1 with v16.2.0.Good,only 7