Ò¼ºÅÓéÀÖAPP

  • ban1-500
  • banner3

֪ͨͨ¸æ

Ä¿½ñλÖÃ: Ê×Ò³ >> ÐÅÏ¢¶¯Ì¬ >> ֪ͨͨ¸æ >> ÕýÎÄ

Ô¤¾¯×ª´ï--CVE-2019-1040Îó²îÖÕ¶¿Ö²ÀÃæÄ¿£¬£¬ÄÚÍø´óɱÆ÷ʹÓÃÆØ¹â£¡

Ðû²¼ÈÕÆÚ£º2019-06-16        ÈªÔ´£ºÍøÂçÖÎÀíÖÐÐÄ     µã»÷£º

¸ÅÊö

΢Èí¹Ù·½ÔÚ6Ô²¹¶¡ÈÕÖУ¬£¬Ðû²¼ÁËÒ»Ã¶ÖØ°õÎó²îCVE-2019-1040µÄÇå¾²²¹¶¡¡£¸ÃÎó²î±£´æÓÚWindows´ó²¿·Ö°æ±¾ÖУ¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î¿ÉÈÆ¹ýNTLM MICµÄ·À»¤»úÖÆ£¬£¬Á¬ÏµÆäËûÎó²îºÍ»úÖÆ£¬£¬Ä³Ð©³¡¾°Ï¿ÉÒÔµ¼ÖÂÓòÄÚµÄͨË×Óû§Ö±½Ó»ñÈ¡¹ØÓÚÓò¿Ø·þÎñÆ÷µÄ¿ØÖÆ¡£

¿ËÈÕ£¬£¬¹ØÓÚ´ËÎó²îµÄʹÓÃϸ½Ú±»Çå¾²Ñо¿Ö°Ô±Ðû²¼³öÀ´£¬£¬Ê¹ÓôËÎó²î»ñÈ¡ÄÚÍøµÄ¿ØÖƱäµÃ·Ç³£¿£¿£¿ÉÐУ¬£¬¿°³ÆÄÚÍø´óɱÆ÷£¬£¬ÐγÉÏÖʵµÄÖØ´óÍþв¡£

µ±ÖÐÐÄÈ˹¥»÷ÕßÄܹ»ÀÖ³ÉÈÆ¹ýNTLM MIC£¨ÐÂÎÅÍêÕûÐÔ¼ì²é£©±£»£»¤Ê±£¬£¬Windows±£´æ¸Ä¶¯Îó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃ½µ¼¶NTLMÇå¾²¹¦Ð§µÄÄÜÁ¦¡£ÒªÊ¹ÓôËÎó²î£¬£¬¹¥»÷ÕßÐèÒª¸Ä¶¯NTLM½»Á÷£¬£¬È»ºó¹¥»÷Õß¿ÉÒÔÐÞ¸ÄNTLMÊý¾Ý°üµÄ±ê¼Ç£¬£¬¶ø²»»áʹÊðÃûÎÞЧ¡£

¸ÃÎó²îµÄCVSS 3.0µÄÆÀ·ÖËäȻֻÓÐ5.9£¬£¬µ«ÓëÆäËûÇå¾²ÎÊÌâÁ¬ÏµÆðÀ´Ê¹Ó㬣¬½«µ¼ÖÂÖØ´óµÄÇå¾²Íþв¡£

×îÑÏÖØµÄ¹¥»÷³¡¾°Ï£¬£¬¹¥»÷Õß½öÐèÒªÓµÓÐÒ»¸öͨË×ÓòÕ˺Å£¬£¬¼´¿ÉÔ¶³Ì¿ØÖÆ Windows ÓòÄÚµÄËùÓлúе£¬£¬°üÀ¨Óò¿Ø·þÎñÆ÷¡£

Ó°Ïìϵͳ

Windows 7 sp1 ÖÁWindows 10 1903

Windows Server 2008 ÖÁWindows Server 2019

´¦Àí½¨Òé

¼øÓÚÏÖÔÚÇå¾²Ñо¿Ö°Ô±ÒѾ­Åû¶ÁËÎó²îÏêÇéºÍʹÓ÷½Ê½£¬£¬²¢ÔÚ²©¿ÍÖй«¿ªÁ˺¬POC´úÂëµÄGithubµØµã£¬£¬´ËÎó²îʵÄËÄÚÍø´óɱÆ÷£¬£¬Ç¿ÁÒ½¨ÒéÊܰ汾ӰÏìµÄÓû§½ôÆÈ¾ÙÐÐÐÞ¸´ÒÔÏû³ýÍþв¡£

ÐÞ¸´·½°¸

΢Èí¹Ù·½ÒÑÍÆ³ö¸üв¹¶¡£¬£¬ÇëÔÚËùÓÐÊÜÓ°ÏìµÄ Windows ¿Í»§¶Ë¡¢·þÎñÆ÷ÏÂÔØ×°Öøüв¢ÖØÆôÅÌËã»ú¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1040

×¢ÖØ£º´ËÎó²î±£´æ¶àÖÖ²î±ðµÄʹÓ÷½°¸£¬£¬Ç¿ÁÒ½¨Òéͨ¹ý×°Öùٷ½²¹¶¡µÄ·½Ê½¶Ô´ËÎó²î¾ÙÐÐÍêÈ«ÐÞ¸´¡£ÈçÎÞ·¨ÊµÏÖÔÚËùÓзþÎñÆ÷ÉÏ×°Öøò¹¶¡£¬£¬ÇëÓÅÏȰü¹ÜÔÚÖ÷ÒªµÄ·þÎñÆ÷£¨ÈçËùÓеÄÓò¿ØÖÆÆ÷¡¢ËùÓÐµÄ Exchange·þÎñÆ÷£©ÉÏ×°Öøò¹¶¡¡£

ÆäËû¼Ó¹Ì²½·¥

¹ØÓÚÎÞ·¨×°Öò¹¶¡µÄ·þÎñÆ÷£¬£¬¿Éͨ¹ýÒÔϼӹ̲½·¥¶Ô´ËÎó²îµÄijЩʹÓ÷½Ê½¾ÙÐÐÊʵ±»º½â¡£×¢ÖØ£¬£¬ÕâЩ¼Ó¹Ì²½·¥²¢Ã»ÓÐÐÞ¸´Îó²î£¬£¬Ö»ÊÇÕë¶Ô¸ÃÎó²î¿ÉÄܱ£´æµÄһЩʹÓ÷½Ê½¾ÙÐлº½â¡£ÕâЩ»º½â²½·¥ÓпÉÄܱ»¸ß¼¶±ðµÄ¹¥»÷ÕßÈÆ¹ý¡£

¿ªÆôËùÓÐÖ÷Òª·þÎñÆ÷µÄÇ¿ÖÆ SMB ÊðÃû¹¦Ð§

£¨ÔÚ Windows ÓòÇéÐÎÏ£¬£¬Ä¬ÈÏÖ»ÓÐÓò¿Ø·þÎñÆ÷¿ªÆôÁËÇ¿ÖÆ SMB ÊðÃû£©

ÆôÓÃËùÓÐÓò¿Ø·þÎñÆ÷µÄÇ¿ÖÆ LDAPS Channel Binding ¹¦Ð§

£¨´Ë¹¦Ð§Ä¬Èϲ»ÆôÓá£ÆôÓúóÓпÉÄÜÔì³É¼æÈÝÐÔÎÊÌâ¡££©

ÆôÓÃËùÓÐÓò¿Ø·þÎñÆ÷µÄÇ¿ÖÆ LDAP Signing ¹¦Ð§

£¨´Ë¹¦Ð§Ä¬Èϲ»ÆôÓá£ÆôÓúóÓпÉÄÜÔì³É¼æÈÝÐÔÎÊÌâ¡££©

¿ªÆôËùÓÐÖ÷Òª·þÎñÆ÷£¨ºÃ±ÈËùÓÐ Exchange ·þÎñÆ÷£©ÉÏÏà¹ØÓ¦ÓõÄChannel Binding ¹¦Ð§£¨Èç IIS µÄChannel Binding ¹¦Ð§£©

ÏêÇéÇë¿´£ºhttps://mp.weixin.qq.com/s/nV8bY6JBbzTNjnd9XEcxYA


                                           ÍøÂçÖÎÀíÖÐÐÄ

                                           2019Äê6ÔÂ16ÈÕ


¡¾ÍøÕ¾µØÍ¼¡¿