΢ÈíRDPÔ¶³Ì×ÀÃæ·þÎñ¶à¸öRCE·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-08-14

? ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1181 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1182 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1222 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1226 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Windows 7 SP1¡¢Windows Server 2008 R2 SP1¡¢ Windows Server 2012¡¢Windows 8.1¡¢Windows Server 2012 R2ºÍËùÓÐÊÜÖ§³ÖµÄÔ̺¬·þÎñÆ÷°æ±¾ÔÚÄÚµÄWindows 10 °æ±¾


²»ÊÜÓ°ÏìµÄ°æ±¾


Windows XP¡¢Windows Server 2003ºÍ Windows Server 2008 ¾ù²»ÊÜÓ°Ïì £¬ÒÔ¼°Ô¶³Ì×ÀÃæºÍ̸ (RDP) ×ÔÉí²¢²»ÊÜÓ°Ïì


·ì϶¸ÅÊö


΢ÈíÐÇÆÚ¶þ°ä²¼ÁËÀýÐв¹¶¡½¨¸´¹æ»® £¬ÆäÖÐÔ̺¬4¸öÑϳÁµÄÔ¶³Ì×ÀÃæ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâÌØÊâµÄRDPÒªÇó´¥·¢·ì϶ £¬»ñÈ¡ÔÚÖ¸±êϵͳÉϵÄÔ¶³Ì´úÂëÖ´ÐÐȨÏÞ¡£´Ó΢Èí²¼¸æÖÐÀ´¿´ £¬¸Ã·ì϶ΪԤÉí·ÝÑéÖ¤ £¬¼´ÎÞÐèÓû§½»»¥ £¬ÕâÒâζן÷ì϶ÓпÉÄܱ»È䳿ËùÀûÓá£


Ä¿Ç°ÍøÂçÉÏÊ¢¿ªRDP·þÎñµÄ·þÎñÆ÷ÊýÁ¿¾Þ´ó £¬Ó°ÏìÃæ¼«´ó¡£


΢Èí»¹°ä²¼ÁËÕë¶ÔCVE-2019-1181/CVE-2019-1182ÆôÓÃÁËÍøÂç¼¶±ðÈÏÖ¤ (NLA) Ö°ÄܵÄÊÜÓ°ÏìϵͳµÄ»º½â´ëÊ©¡£ÓÉÓÚ·ì϶±»´¥·¢Ç° £¬NLA ÒªÇó½øÐÐÈÏÖ¤ £¬Òò¶øÊÜÓ°Ïìϵͳ»º½âÁË¿ÉÄÜÀûÓø÷ì϶µÄ¡°È䳿¼¶¡±¶ñÒâÈí¼þ»ò¸ß½×µÄ¶ñÒâÈí¼þÍþв¡£È»¶ø £¬ÈôÊǹ¥»÷ÕßÓµÓпÉÄܱ»ÓÃÓÚ½øÐÐÈÏÖ¤µÄºÏ·¨Æ¾Ö¤ £¬Òò¶øÊÜÓ°ÏìϵͳÒÀÈ»Ò×ÊÜÔ¶³Ì´úÂëÖ´ÐÐÀûÓõĹ¥»÷¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ £¬Î¢Èí¹Ù·½ÒѾ­°ä²¼²¹¶¡½¨¸´ÁËÉÏÊö·ì϶ £¬½¨ÒéÓû§¾¡¿ì²ÉÈ¡½¨²¹´ëÊ© £¬ÒÔÔ¤·ÀDZÔڵݲȫÍþв¡£ÏëÒª½øÐиüР£¬Ö»Ðèתµ½ÉèÖáú¸üкͰ²È«¡úWindows ¸üСú²é³­¸üР£¬»òÕßÒ²Äܹ»Í¨¹ýÊÖ¶¯½øÐиüС£


»º½â´ëÊ© £¬Õë¶ÔCVE-2019-1181/CVE-2019-1182£º


1. ÔÚϵͳÉÏÆôÓÃÍøÂç¼°Éí·ÝÈÏÖ¤£¨NLA£©ÒÔÁÙʱ¶ã±Ü¸Ã·ì϶ӰÏì


2. ÔÚÆóÒµ±íΧ·À»ðǽ×è¶ÏTCP¶Ë¿Ú3389µÄÁ´½Ó


3. ÈçÎÞÐèÒª £¬¿É½ûÓÃÓйØÔ¶³Ì×ÀÃæ·þÎñ


²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1181
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1182
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1222
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1226