¸ÅÊö
΢Èí¹Ù·½ÔÚ6Ô²¹¶¡ÈÕÖУ¬£¬Ðû²¼ÁËÒ»Ã¶ÖØ°õÎó²îCVE-2019-1040µÄÇå¾²²¹¶¡¡£¸ÃÎó²î±£´æÓÚWindows´ó²¿·Ö°æ±¾ÖУ¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î¿ÉÈÆ¹ýNTLM MICµÄ·À»¤»úÖÆ£¬£¬Á¬ÏµÆäËûÎó²îºÍ»úÖÆ£¬£¬Ä³Ð©³¡¾°Ï¿ÉÒÔµ¼ÖÂÓòÄÚµÄͨË×Óû§Ö±½Ó»ñÈ¡¹ØÓÚÓò¿Ø·þÎñÆ÷µÄ¿ØÖÆ¡£
¿ËÈÕ£¬£¬¹ØÓÚ´ËÎó²îµÄʹÓÃϸ½Ú±»Çå¾²Ñо¿Ö°Ô±Ðû²¼³öÀ´£¬£¬Ê¹ÓôËÎó²î»ñÈ¡ÄÚÍøµÄ¿ØÖƱäµÃ·Ç³£¿£¿£¿ÉÐУ¬£¬¿°³ÆÄÚÍø´óɱÆ÷£¬£¬ÐγÉÏÖʵµÄÖØ´óÍþв¡£
µ±ÖÐÐÄÈ˹¥»÷ÕßÄܹ»ÀÖ³ÉÈÆ¹ýNTLM MIC£¨ÐÂÎÅÍêÕûÐÔ¼ì²é£©±£»£»¤Ê±£¬£¬Windows±£´æ¸Ä¶¯Îó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃ½µ¼¶NTLMÇå¾²¹¦Ð§µÄÄÜÁ¦¡£ÒªÊ¹ÓôËÎó²î£¬£¬¹¥»÷ÕßÐèÒª¸Ä¶¯NTLM½»Á÷£¬£¬È»ºó¹¥»÷Õß¿ÉÒÔÐÞ¸ÄNTLMÊý¾Ý°üµÄ±ê¼Ç£¬£¬¶ø²»»áʹÊðÃûÎÞЧ¡£
¸ÃÎó²îµÄCVSS 3.0µÄÆÀ·ÖËäȻֻÓÐ5.9£¬£¬µ«ÓëÆäËûÇå¾²ÎÊÌâÁ¬ÏµÆðÀ´Ê¹Ó㬣¬½«µ¼ÖÂÖØ´óµÄÇå¾²Íþв¡£
×îÑÏÖØµÄ¹¥»÷³¡¾°Ï£¬£¬¹¥»÷Õß½öÐèÒªÓµÓÐÒ»¸öͨË×ÓòÕ˺ţ¬£¬¼´¿ÉÔ¶³Ì¿ØÖÆ Windows ÓòÄÚµÄËùÓлúе£¬£¬°üÀ¨Óò¿Ø·þÎñÆ÷¡£
Ó°Ïìϵͳ
Windows 7 sp1 ÖÁWindows 10 1903
Windows Server 2008 ÖÁWindows Server 2019
´¦Àí½¨Òé
¼øÓÚÏÖÔÚÇå¾²Ñо¿Ö°Ô±ÒѾÅû¶ÁËÎó²îÏêÇéºÍʹÓ÷½Ê½£¬£¬²¢ÔÚ²©¿ÍÖй«¿ªÁ˺¬POC´úÂëµÄGithubµØµã£¬£¬´ËÎó²îʵÄËÄÚÍø´óɱÆ÷£¬£¬Ç¿ÁÒ½¨ÒéÊܰ汾ӰÏìµÄÓû§½ôÆÈ¾ÙÐÐÐÞ¸´ÒÔÏû³ýÍþв¡£
ÐÞ¸´·½°¸
΢Èí¹Ù·½ÒÑÍÆ³ö¸üв¹¶¡£¬£¬ÇëÔÚËùÓÐÊÜÓ°ÏìµÄ Windows ¿Í»§¶Ë¡¢·þÎñÆ÷ÏÂÔØ×°Öøüв¢ÖØÆôÅÌËã»ú¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1040
×¢ÖØ£º´ËÎó²î±£´æ¶àÖÖ²î±ðµÄʹÓ÷½°¸£¬£¬Ç¿ÁÒ½¨Òéͨ¹ý×°Öùٷ½²¹¶¡µÄ·½Ê½¶Ô´ËÎó²î¾ÙÐÐÍêÈ«ÐÞ¸´¡£ÈçÎÞ·¨ÊµÏÖÔÚËùÓзþÎñÆ÷ÉÏ×°Öøò¹¶¡£¬£¬ÇëÓÅÏȰü¹ÜÔÚÖ÷ÒªµÄ·þÎñÆ÷£¨ÈçËùÓеÄÓò¿ØÖÆÆ÷¡¢ËùÓÐµÄ Exchange·þÎñÆ÷£©ÉÏ×°Öøò¹¶¡¡£
ÆäËû¼Ó¹Ì²½·¥
¹ØÓÚÎÞ·¨×°Öò¹¶¡µÄ·þÎñÆ÷£¬£¬¿Éͨ¹ýÒÔϼӹ̲½·¥¶Ô´ËÎó²îµÄijЩʹÓ÷½Ê½¾ÙÐÐÊʵ±»º½â¡£×¢ÖØ£¬£¬ÕâЩ¼Ó¹Ì²½·¥²¢Ã»ÓÐÐÞ¸´Îó²î£¬£¬Ö»ÊÇÕë¶Ô¸ÃÎó²î¿ÉÄܱ£´æµÄһЩʹÓ÷½Ê½¾ÙÐлº½â¡£ÕâЩ»º½â²½·¥ÓпÉÄܱ»¸ß¼¶±ðµÄ¹¥»÷ÕßÈÆ¹ý¡£
¿ªÆôËùÓÐÖ÷Òª·þÎñÆ÷µÄÇ¿ÖÆ SMB ÊðÃû¹¦Ð§
£¨ÔÚ Windows ÓòÇéÐÎÏ£¬£¬Ä¬ÈÏÖ»ÓÐÓò¿Ø·þÎñÆ÷¿ªÆôÁËÇ¿ÖÆ SMB ÊðÃû£©
ÆôÓÃËùÓÐÓò¿Ø·þÎñÆ÷µÄÇ¿ÖÆ LDAPS Channel Binding ¹¦Ð§
£¨´Ë¹¦Ð§Ä¬Èϲ»ÆôÓá£ÆôÓúóÓпÉÄÜÔì³É¼æÈÝÐÔÎÊÌâ¡££©
ÆôÓÃËùÓÐÓò¿Ø·þÎñÆ÷µÄÇ¿ÖÆ LDAP Signing ¹¦Ð§
£¨´Ë¹¦Ð§Ä¬Èϲ»ÆôÓá£ÆôÓúóÓпÉÄÜÔì³É¼æÈÝÐÔÎÊÌâ¡££©
¿ªÆôËùÓÐÖ÷Òª·þÎñÆ÷£¨ºÃ±ÈËùÓÐ Exchange ·þÎñÆ÷£©ÉÏÏà¹ØÓ¦ÓõÄChannel Binding ¹¦Ð§£¨Èç IIS µÄChannel Binding ¹¦Ð§£©
ÏêÇéÇë¿´£ºhttps://mp.weixin.qq.com/s/nV8bY6JBbzTNjnd9XEcxYA
ÍøÂçÖÎÀíÖÐÐÄ
2019Äê6ÔÂ16ÈÕ