Microsoft ExchangeÄÚ´æ·ÛËé·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-08-15·ì϶±àºÅºÍ¼¶±ð
CVE-2018-8302£¬ÑϳÁ£¬CVSS·ÖÖµ¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 23
Microsoft Exchange Server 2013 Cumulative Update 20
Microsoft Exchange Server 2013 Cumulative Update 21
Microsoft Exchange Server 2016 Cumulative Update 10
Microsoft Exchange Server 2016 Cumulative Update 9
·ì϶¸ÅÊö
·ì϶µÄÔ´ÓÚÊÕ¼þÏäÎļþ¼ÐÊôÐÔ½Ó¼ûµÄTopNWords.Data¡£ÕâЩÊý¾Ý´æ´¢ÔÚExchange·þÎñÆ÷ÉÏ£¬²¢ÇÒÊÇÒ»¸ö¹«¹²ÊôÐÔ£¬Óû§Äܹ»Í¨¹ýExchange Web Services (EWS)¸ü¸ÄËü¡£Exchange Web Services ÊÇÒ»×é¿Í»§¶ËÓë Exchange ·þÎñÆ÷ͨѶµÄ½Ó¿Ú¡£
µ±ÊÕµ½ÓïÒôÓʼþʱ£¬Exchange»áÊÔͼ½«Æäת»»³ÉÎı¾£¬ÏÔʾÔÚÊÕ¼þÈ˵ÄÊÕ¼þÏäÖС£ÔÚUnified Messaging(UM)ĬÈÏÆôÓõÄÇé¿öÏ£¬×ªÂ¼»á×Ô¶¯½øÐС£Exchange»á¶ÁÈ¡TopNWords.DataµÄÊôÐÔÀ´ÅäÖÃÓû§µÄÊÕ¼þÏ䣬²¢Ê¹ÓÃ.NET BinaryFormatter¶ÔÆä½øÐз´ÐòÁл¯£¬ÒÔ»ñµÃÎı¾µ½ÓïÒôµÄ×é¼þ¡£
·ì϶ÑéÖ¤
ÀûÓô˷ì϶µÄǰÌ᣺
1.Exchange·þÎñÆ÷Ð轫Unified Messaging (UM)ÅäÖÃΪÆôÓÃ״̬£»
2.¹¥»÷Õß±ØÒªÒ»¸öʹÓÃUMÓïÒôÓÊÏäÉèÖõÄÓÊÏäÕÊ»§¡£
¹¥»÷ÕßÀûÓÃExchange·þÎñ½«.NETÐòÁл¯µÄpayloadÉÏ´«ÖÁ·þÎñÆ÷ÖÐ,ͬʱÀûÓÃÍøÂç´¹µö·½Ê½ÓÕʹÆäËûÕ˺ŵÄʹÓÃÕß´ò¿ªÓïÒôÓʼþ£¬×îÖÕÒÔϵͳ¼¶È¨ÏÞÖ´ÐÐËÁÒâ´úÂë¡£
¹úÄÚµÄÊÜÓ°Ïì×ʲúÉ¢²¼Çé¿ö
½¨¸´½¨Òé
Microsoft ¹Ù·½ÒѾÔÚ8Ô·ݵĹؼü°²È«²¹¶¡¸üÐÂÖн¨¸´Á˸÷ì϶£¬ÇëÊÜÓ°ÏìÓû§ÊµÊ±Ç°ÍùÏÂÔØ¡£
²Î¿¼Á´½Ó
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2018-8302
https://www.symantec.com/security-center/vulnerabilities/writeup/104973?om_rssid=sr-advisories


¾©¹«Íø°²±¸11010802024551ºÅ