English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23346
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ VMware Workstation ¹öÀüÀÌ 17.6.3 ÀÌÀüÀÇ 17.x ¹öÀüÀÔ´Ï´Ù. µû¶ó¼­ ´ÙÀ½°ú °°Àº ¿©·¯ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.

- VMware ESXi ¹× Workstation¿¡´Â °æ°è ÀÌÅ» ¾²±â(out-of-bounds write)¸¦ À¯¹ßÇÏ´Â TOCTOU(Time-of-Check Time-of-Use) Ãë¾àÁ¡ÀÌ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù. °¡»ó ¸Ó½Å¿¡ ´ëÇÑ ·ÎÄà °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø ¾ÇÀÇÀûÀÎ ÇàÀ§ÀÚ°¡ ÀÌ ¹®Á¦¸¦ ¾Ç¿ëÇÏ¿© È£½ºÆ®¿¡¼­ ½ÇÇàµÇ´Â °¡»ó ¸Ó½ÅÀÇ VMX ÇÁ·Î¼¼½º·Î Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2025-22224)

- VMware ESXi, Workstation ¹× Fusion¿¡´Â HGFSÀÇ °æ°è ÀÌÅ» Àбâ(out-of-bounds read)·Î ÀÎÇÑ Á¤º¸ À¯Ãâ Ãë¾àÁ¡ÀÌ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù. °¡»ó ¸Ó½Å¿¡ ´ëÇÑ °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø ¾ÇÀÇÀûÀÎ ÇàÀ§ÀÚ°¡ ÀÌ ¹®Á¦¸¦ ¾Ç¿ëÇÏ¿© vmx ÇÁ·Î¼¼½º¿¡¼­ ¸Þ¸ð¸®¸¦ À¯ÃâÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2025-22226)

* Âü°í »çÀÌÆ®:
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25390

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
VMware Workstation 17.6.3 ÀÌÇÏÀÇ ¹öÀüµé
Linux Any version
Microsoft Windows Any version
ÇØ°áÃ¥ VMware ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://www.vmware.com/download/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â ¿µÇâÀ» ¹Þ´Â ¾îÇø®ÄÉÀ̼ǵéÀÇ °¡Àå ÃֽйöÀü(VMware Workstation 17.6.3 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2025-22224,CVE-2025-22226 (CVE)
°ü·Ã URL 105986 (SecurityFocus)
°ü·Ã URL (ISS)