΢ÈíSQL Server Reporting ServicesÔ¶³Ì´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-02-17·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-0618£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Microsoft SQL Server 2012 for 32-bit Systems Service Pack 4 (QFE)
Microsoft SQL Server 2012 for x64-based Systems Service Pack 4 (QFE)
Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU)
Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)
Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU)
Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)
Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (CU)
Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)
·ì϶¸ÅÊö
½üÈÕ£¬±¾ÔÂ΢Èí²¹¶¡¸üеķì϶£¬Î¢ÈíSQL Server Reporting ServicesÔ¶³Ì´úÂëÖ´Ðзì϶µÄPoC±»¹«¿ª£¬SQL Server Reporting ServicesÌṩһ×é±¾µØ¹¤¾ßºÍ·þÎñ£¬ÓÃÓÚ´´½¨¡¢²¿ÊðºÍÖÎÀí±¨±í¡£SQL Server Reporting ServicesÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¬½öÐè»ñµÃµÍȨÏ޵Ĺ¥»÷ÕßÄܹ»ÏòÊÜÓ°Ïì°æ±¾µÄReporting ServicesÊ·ýÌá½»¾«ÐÄ»ú¹ØµÄÒªÇóÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÔÚReport Server·þÎñÕÊ»§¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£
´Ë·ì϶λÓÚReportingServicesWebServer.dllÎļþÖеÄBrowserNavigationCorrectorÀ࣬ÈçÏÂͼËùʾ:
´ÓÉÏͼ¿É¼û£¬ BrowserNavigationCorrectorÀàÖеÄOnLoad²½ÖèʹÓÃLosFormatterÀà½øÐз´ÐòÁл¯²Ù×÷¡£
LosFormatterͨ³£ÓÃÓÚÐòÁл¯ºÍ·´ÐòÁл¯Web´°ÌåÒ³µÄÊÓͼ״̬(ViewState) £¬µ±Î´¾¹ýÂ˵ÄÓû§ÊäÈë±»LosFormatterÀà½øÐз´ÐòÁл¯²Ù×÷ʱ£¬¾Í»á²úÉú·´ÐòÁл¯·ì϶¡£
BrowserNavigationCorrectorÀà±»Microsoft.ReportingServices.WebServer.ReportViewerPageÀàŲÓã¬ÈçÏÂͼ£º
ReportViewerPageÀàÄܹ»ÓÉ/ReportServer/pages/ReportViewer.aspxÒ³Ãæ½øÐд«²ÎŲÓ㬵±¹¥»÷ÕßŲÓøÃÒ³Ãæ²¢´«Èë¶ñÒâ»ú¹ØµÄÐòÁл¯payload£¬¼´¿É´¥·¢·ì϶¡£
·ì϶ÑéÖ¤
PoC£ºhttps://www.mdsec.co.uk/2020/02/cve-2020-0618-rce-in-sql-server-reporting-services-ssrs/¡£
½¨¸´½¨Òé
Ŀǰ΢ÈíÒѰ䲼²¹¶¡½¨¸´·ì϶£¬²Î¿¼Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0618¡£
ÈôÊÇÄúµÄSQL Server°æ±¾ºÅδÔÚÉÏÎÄÖУ¬ÄÇôÄúµÄSQL Server°æ±¾½«²»ÔÙÊܵ½Î¢Èí¹Ù·½Ö§³Ö¡£Í¬ÑùÓб»´Ë·ì϶ӰÏìµÄ·çÏÕ¡£ÇëÉý¼¶µ½×îеÄSQL Server£¬ÒÔÃâÔâ·ê·ì϶¹¥»÷¡£
²Î¿¼Á´½Ó
https://www.mdsec.co.uk/2020/02/cve-2020-0618-rce-in-sql-server-reporting-services-ssrs/


¾©¹«Íø°²±¸11010802024551ºÅ