΢ÈíRDPÔ¶³Ì×ÀÃæ·þÎñ¶à¸öRCE·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-08-14? ·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-1182£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1222£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1226£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
? Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
Windows 7 SP1¡¢Windows Server 2008 R2 SP1¡¢ Windows Server 2012¡¢Windows 8.1¡¢Windows Server 2012 R2ºÍËùÓÐÊÜÖ§³ÖµÄÔ̺¬·þÎñÆ÷°æ±¾ÔÚÄÚµÄWindows 10 °æ±¾
²»ÊÜÓ°ÏìµÄ°æ±¾
? ·ì϶¸ÅÊö
΢ÈíÐÇÆÚ¶þ°ä²¼ÁËÀýÐв¹¶¡½¨¸´¹æ»®£¬ÆäÖÐÔ̺¬4¸öÑϳÁµÄÔ¶³Ì×ÀÃæ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâÌØÊâµÄRDPÒªÇó´¥·¢·ì϶£¬»ñÈ¡ÔÚÖ¸±êϵͳÉϵÄÔ¶³Ì´úÂëÖ´ÐÐȨÏÞ¡£´Ó΢Èí²¼¸æÖÐÀ´¿´£¬¸Ã·ì϶ΪԤÉí·ÝÑéÖ¤£¬¼´ÎÞÐèÓû§½»»¥£¬ÕâÒâζן÷ì϶ÓпÉÄܱ»È䳿ËùÀûÓá£
Ä¿Ç°ÍøÂçÉÏÊ¢¿ªRDP·þÎñµÄ·þÎñÆ÷ÊýÁ¿¾Þ´ó£¬Ó°ÏìÃæ¼«´ó¡£
? ·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
? ½¨¸´½¨Òé
Ŀǰ£¬Î¢Èí¹Ù·½ÒѾ°ä²¼²¹¶¡½¨¸´ÁËÉÏÊö·ì϶£¬½¨ÒéÓû§¾¡¿ì²ÉÈ¡½¨²¹´ëÊ©£¬ÒÔÔ¤·ÀDZÔڵݲȫÍþв¡£ÏëÒª½øÐиüУ¬Ö»Ðèתµ½ÉèÖáú¸üкͰ²È«¡úWindows ¸üСú²é³¸üУ¬»òÕßÒ²Äܹ»Í¨¹ýÊÖ¶¯½øÐиüС£
»º½â´ëÊ©£¬Õë¶ÔCVE-2019-1181/CVE-2019-1182£º
1. ÔÚϵͳÉÏÆôÓÃÍøÂç¼°Éí·ÝÈÏÖ¤£¨NLA£©ÒÔÁÙʱ¶ã±Ü¸Ã·ì϶ӰÏì
2. ÔÚÆóÒµ±íΧ·À»ðǽ×è¶ÏTCP¶Ë¿Ú3389µÄÁ´½Ó
3. ÈçÎÞÐèÒª£¬¿É½ûÓÃÓйØÔ¶³Ì×ÀÃæ·þÎñ
? ²Î¿¼Á´½Ó
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1182
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1222
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1226


¾©¹«Íø°²±¸11010802024551ºÅ