΢ÈíSQL Server Reporting ServicesÔ¶³Ì´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-02-17

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-0618£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Microsoft SQL Server 2012 for 32-bit Systems Service Pack 4 (QFE)

Microsoft SQL Server 2012 for x64-based Systems Service Pack 4 (QFE)

Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU)

Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)

Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU)

Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)

Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (CU)

Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)


·ì϶¸ÅÊö


½üÈÕ£¬±¾ÔÂ΢Èí²¹¶¡¸üеķì϶£¬Î¢ÈíSQL Server Reporting ServicesÔ¶³Ì´úÂëÖ´Ðзì϶µÄPoC±»¹«¿ª£¬SQL Server Reporting ServicesÌṩһ×é±¾µØ¹¤¾ßºÍ·þÎñ£¬ÓÃÓÚ´´½¨¡¢²¿ÊðºÍÖÎÀí±¨±í¡£SQL Server Reporting ServicesÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¬½öÐè»ñµÃµÍȨÏ޵Ĺ¥»÷ÕßÄܹ»ÏòÊÜÓ°Ïì°æ±¾µÄReporting ServicesÊ·ýÌá½»¾«ÐÄ»ú¹ØµÄÒªÇóÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÔÚReport Server·þÎñÕÊ»§¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£


´Ë·ì϶λÓÚReportingServicesWebServer.dllÎļþÖеÄBrowserNavigationCorrectorÀ࣬ÈçÏÂͼËùʾ:


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´ÓÉÏͼ¿É¼û£¬ BrowserNavigationCorrectorÀàÖеÄOnLoad²½ÖèʹÓÃLosFormatterÀà½øÐз´ÐòÁл¯²Ù×÷¡£


LosFormatterͨ³£ÓÃÓÚÐòÁл¯ºÍ·´ÐòÁл¯Web´°ÌåÒ³µÄÊÓͼ״̬(ViewState) £¬µ±Î´¾­¹ýÂ˵ÄÓû§ÊäÈë±»LosFormatterÀà½øÐз´ÐòÁл¯²Ù×÷ʱ£¬¾Í»á²úÉú·´ÐòÁл¯·ì϶¡£


BrowserNavigationCorrectorÀà±»Microsoft.ReportingServices.WebServer.ReportViewerPageÀàŲÓã¬ÈçÏÂͼ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ReportViewerPageÀàÄܹ»ÓÉ/ReportServer/pages/ReportViewer.aspxÒ³Ãæ½øÐд«²ÎŲÓ㬵±¹¥»÷ÕßŲÓøÃÒ³Ãæ²¢´«Èë¶ñÒâ»ú¹ØµÄÐòÁл¯payload£¬¼´¿É´¥·¢·ì϶¡£


·ì϶ÑéÖ¤


PoC£ºhttps://www.mdsec.co.uk/2020/02/cve-2020-0618-rce-in-sql-server-reporting-services-ssrs/¡£


½¨¸´½¨Òé


Ŀǰ΢ÈíÒѰ䲼²¹¶¡½¨¸´·ì϶£¬²Î¿¼Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0618¡£


ÈôÊÇÄúµÄSQL Server°æ±¾ºÅδÔÚÉÏÎÄÖУ¬ÄÇôÄúµÄSQL Server°æ±¾½«²»ÔÙÊܵ½Î¢Èí¹Ù·½Ö§³Ö¡£Í¬ÑùÓб»´Ë·ì϶ӰÏìµÄ·çÏÕ¡£ÇëÉý¼¶µ½×îеÄSQL Server£¬ÒÔÃâÔâ·ê·ì϶¹¥»÷¡£


²Î¿¼Á´½Ó


https://www.mdsec.co.uk/2020/02/cve-2020-0618-rce-in-sql-server-reporting-services-ssrs/