Microsoft Exchange 3Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-03-03

0x00 ·ì϶¸ÅÊö

2021Äê03ÔÂ02ÈÕ£¬Microsoft°ä²¼¹ØÓÚExchangeµÄ°²È«¸üУ¬½¨¸´ÁËExchangeÖеĶà¸ö°²È«·ì϶ ¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÖ¸±êExchange Server·¢ËͶñÒâÊý¾Ý°üÀ´ÀûÓÃÕâЩ·ì϶£¬×îÖÕÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂ룬¶øÎÞÐèÓû§½»»¥ ¡£


0x01 ·ì϶ÏêÇé

image.png

 

±¾´Î½¨¸´µÄExchange·ì϶ÈçÏ£º

CVE ID

ÆÀ·Ö

Ó°Ïì

ÊÇ·ñÒѱ»ÀûÓÃ

CVE-2021-26855

9.1

¹¥»÷Õß¿ÉÄÜ·¢ËÍËÁÒâHTTPÒªÇó²¢Í¨¹ýExchange   Server½øÐÐÉí·ÝÑéÖ¤ ¡£

ÊÇ

CVE-2021-26857

7.8

¹¥»÷ÕßÄܹ»ÔÚExchange ServerÉÏÒÔSYSTEMȨÏÞÔËÐдúÂë ¡££¨ÐèÖÎÀíԱȨÏÞ£©

ÊÇ

CVE-2021-26858

7.8

ExchangeÖдæÔÚÑéÖ¤ºóµÄËÁÒâÎļþдÈë·ì϶ ¡£Í¨¹ýÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶½«ÎļþдÈë·þÎñÆ÷µÄÈκÎõè¾¶ÖÐ ¡£Í¬Ê±£¬Í¨¹ý¹²Í¬ÀûÓÃCVE-2021-26855 SSRF·ì϶Äܹ»·ÛËéÖÎÀíÔ±µÄÍ´´¦À´½øÐÐÉí·ÝÑéÖ¤ ¡£

ÊÇ

CVE-2021-27065

7.8

CVE-2021-26412

9.1

RCE

·ñ

CVE-2021-26854

6.6

RCE

·ñ

CVE-2021-27078

9.1

RCE

·ñ

 

ÆäÖУ¬CVE-2021-26855¡¢CVE-2021-26857¡¢CVE-2021-26858ºÍCVE-2021-27065·ì϶±»×÷Ϊ¹¥»÷Á´µÄÒ»²¿ÃÅ ¡£³õʼ¹¥»÷±ØÒªÓëExchange Server 443¶Ë¿Ú³ÉÁ¢ÏνÓ£¬Äܹ»Í¨¹ýÏÞ¶È·ÇÐÅÀµµÄÏνÓ£¬»òÉèÖÃVPN½«Exchange ServerÓë±í²¿½Ó¼û·Ö¸ôÀ´Ô¤·À³õʼ¹¥»÷£¬µ«ÈôÊǹ¥»÷ÕßÒѾ­ÓÐÁ˽ӼûȨÏÞ£¬»òÕßÄܹ»ÒÔÖÎÀíԱȨÏÞÔËÐжñÒâÎļþ£¬ÔòÄܹ»´¥·¢¹¥»÷Á´µÄÆäËü²¿ÃÅ ¡£

 

Ó°ÏìÁìÓò

Exchange Server 2010

Exchange Server 2013

Exchange Server 2016

Exchange Server 2019

 

0x02 ´ëÖý¨Òé

ĿǰMicrosoftÒѰ䲼Óйذ²È«¸üУ¬¼øÓÚ·ì϶µÄÑϳÁÐÔ£¬½¨Ò龡¿ìÉý¼¶½¨²¹£º

https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server/

 

һʱ´ëÊ©

CVE-2021-26855

Äܹ»Í¨¹ýÒÔÏÂExchange HttpProxyÈÕÖ¾½øÐмì²â£º

%PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging\HttpProxy

ͨ¹ýÒÔÏÂPowershell¿ÉÖ±½Ó½øÐÐÈÕÖ¾¼ì²â£¬²¢²é³­ÊÇ·ñÊܵ½¹¥»÷£º

Import-Csv -Path (Get-ChildItem -Recurse -Path ¡°$env:PROGRAMFILES\Microsoft\Exchange Server\V15\Logging\HttpProxy¡± -Filter ¡®*.log¡¯).FullName | Where-Object {  $_.AuthenticatedUser -eq ¡± -and $_.AnchorMailbox -like ¡®ServerInfo~*/*¡¯ } | select DateTime, AnchorMailbox

ÈôÊǼì²âµ½ÈëÇÖ£¬Äܹ»Í¨¹ýÒÔÏÂĿ¼»ñÈ¡¹¥»÷Õß²ÉÈ¡ÁËÄÄЩ»î¶¯£º

%PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging

 

CVE-2021-26857

¸Ã·ì϶µ¥¶ÀÀûÓÃÄѶȽϸߣ¬¿ÉÀûÓÃÒÔϺÅÁî¼ì²âÈÕÖ¾Ìõ¿î£¬²¢²é³­ÊÇ·ñÊܵ½¹¥»÷ ¡£

Get-EventLog -LogName Application -Source ¡°MSExchange Unified Messaging¡± -EntryType Error | Where-Object { $_.Message -like ¡°*System.InvalidCastException*¡± }

 

CVE-2021-26858

ÈÕ־Ŀ¼£º

C:\Program Files\Microsoft\Exchange Server\V15\Logging\OABGeneratorLog

¿Éͨ¹ýÒÔϺÅÁî½øÐм±¾çä¯ÀÀ£¬²¢²é³­ÊÇ·ñÊܵ½¹¥»÷£º

findstr /snip /c:¡±Download failed and temporary file¡± ¡°%PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging\OABGeneratorLog\*.log¡±

 

CVE-2021-27065

¿Éͨ¹ýÒÔÏÂpowershellºÅÁî½øÐÐÈÕÖ¾¼ì²â£¬²¢²é³­ÊÇ·ñÔâµ½¹¥»÷:

Select-String -Path ¡°$env:PROGRAMFILES\Microsoft\Exchange Server\V15\Logging\ECP\Server\*.log¡± -Pattern ¡®Set-.+VirtualDirectory¡¯

 

 

0x03 ²Î¿¼Á´½Ó

https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server/

https://techcommunity.microsoft.com/t5/exchange-team-blog/released-march-2021-exchange-server-security-updates/ba-p/2175901

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26855

https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/

 

0x04 ¹¦·òÏß

2021-03-02  MSRC°ä²¼°²È«²¼¸æ

2021-03-03  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png