WindowsÔ¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-10-10

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1333£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Windows 10 £»

Windows 7 £»

Windows 8.1 £»

Windows Server 2008 SP2,SP1 £»

Windows Server 2012 £»

Windows Server 2012 R2 £»

Windows Server 2016 £»

Windows Server 2019 £»

Windows Server, version 1803

Windows Server, version 1903


·ì϶¸ÅÊö


Remote Desktop Protocol(Ô¶³Ì×ÀÃæºÍ̸£¬RDP)ÊÇ΢Èí¹«Ë¾´´½¨µÄרÓкÍ̸¡£ËüÔÊÐíϵͳÓû§Í¨¹ýͼÐÎÓû§½çÃæÏνӵ½Ô¶³Ìϵͳ¡£ÔÚĬÈÏÇé¿öÏ£¬¸ÃºÍ̸µÄ¿Í»§¶Ë´úÀíÄÚÖÃÔÚ΢ÈíµÄ²Ù×÷ϵͳÖУ¬Ò²Äܹ»×°ÖÃÔÚ·Ç΢Èí²Ù×÷ϵͳÖС£RDPµÄ·þÎñÆ÷¶Ë×°ÖÃÔÚ΢Èí²Ù×÷ϵͳÖУ¬´Ó¿Í»§¶Ë´úÀí½Ó¹ÜÒªÇó£¬ÏÔʾ°ä²¼ÀûÓ÷¨Ê½µÄͼÐνçÃæ»òÕßÔ¶³Ì½Ó¼ûϵͳ×ÔÉí¡£Ä¬ÈÏÇé¿öÏ£¬ÏµÍ³ÔÚ3389¶Ë¿ÚÀ´¼àÌýÀ´×Ô¿Í»§¶ËµÄͨ¹ýRDPµÄÏνÓÒªÇó¡£


Remote Desktop ClientÊÇ΢Èí¿ª·¢µÄÓÃÓÚʵÏÖÔ¶³Ì×ÀÃæºÍ̸µÄÒ»¸ö¿Í»§¶Ë²Ù×÷Èí¼þ¡£Óû§Äܹ»Ê¹ÓÃMicrosoftÔ¶³Ì×ÀÃæ¿Í»§¶Ë´ÓËÁÒâ´¦ËùÏνӵ½Ô¶³ÌPCÖ÷»úºÍ¹¤×÷×ÊÔ´£¬²¢Äܹ»½Ó¼ûËùÓÐÀûÓ÷¨Ê½£¬ÎļþºÍÍøÂç×ÊÔ´¡£


2019Äê10ÔÂ08ÈÕ£¬Î¢ÈíÀýÐа䲼ÁË10Ô·ݵݲȫ¸üУ¬ÆäÖн¨¸´ÁËWindowsÔ¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-1333£©£¬µ±Óû§Ïνӵ½¶ñÒâ·þÎñÆ÷ʱ£¬¹¥»÷ÕßÄܹ»ÔÚÏνӿͻ§¶ËµÄÍÆËã»úÉÏÖ´ÐÐËÁÒâ´úÂë¡£¹¥»÷Õß¿ÉÄÜ»á×°Ö÷¨Ê½£¬²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£¬»òÕß´´½¨ÓµÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕË»§¡£


ÒªÀûÓô˷ì϶£¬¹¥»÷Õß±ØÒª½ÚÔì·þÎñÆ÷£¬¶øºóÓÕʹÓû§Ïνӵ½¸Ã·þÎñÆ÷¡£¹¥»÷ÕßÎÞ·¨Ç¿ÆÅ×û§Ïνӵ½¶ñÒâ·þÎñÆ÷£¬ËûÃDZØÒªÍ¨¹ýÉç½»¹¤³Ì£¬DNSÖж¾»òʹÓÃÖÐÑëÈ˼¼ÊõÓÕʹÓû§½øÐÐÏνÓ¡£¹¥»÷Õß»¹¿ÉÄÜ·ÛËéºÏ·¨·þÎñÆ÷£¬ÔÚÆäÉÏÍйܶñÒâ´úÂ룬¶øºóÆÚ´ýÓû§ÏνÓ¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


΢Èí¹Ù·½ÒѾ­ÍƳö°²È«¸üУ¬Çë²Î¿¼ÒÔϹٷ½°²È«¹«¸æÏÂÔØ²¢×°ÖÃ×îв¹¶¡£º

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1333


²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1333