¡¾·ì϶¹«¸æ¡¿Windows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-38077£©
°ä²¼¹¦·ò 2024-08-09Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Windows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´Ðзì϶ | ||
CVE ID | CVE-2024-38077 | ||
·ì϶ÀàÐÍ | »º³åÇøÒç³ö | ·¢ÏÖ¹¦·ò | 2024-07-10 |
·ì϶ÆÀ·Ö | 9.8 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Windows Remote Desktop Licensing Service£¨RDL£©ÊÇWindows ServerµÄÒ»¸ö×é¼þ£¬ÓÃÓÚ½ÚÔìºÍÖÎÀíÔ¶³Ì×ÀÃæ»á»°µÄÐí¿É£¬È·±£Ö»ÓÐÕ¼ÓÐÓÐЧÐí¿ÉµÄÓû§ÄÜÁ¦Í¨¹ýÔ¶³Ì×ÀÃæºÍ̸£¨RDP£©Ïνӵ½·þÎñÆ÷¡£
2024Äê7ÔÂ10ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Î¢Èí7Ô°²È«¸üн¨¸´ÁËWindows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-38077£¬±»³ÆÎª¡°MadLicense¡±£©£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8¡£
Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖдæÔÚ¶Ñ»º³åÇøÒç¶Âí½Å£¬ÓÉÓÚÔÚ½âÂëÓû§ÊäÈëµÄÐí¿ÉÃÜÔ¿°üʱ²»×ãÕýÈ·µÄ»º³åÇø´óÓײ鳣¬µ¼Ö½âÂëºó³öÏÖ»º³åÇøÒç³ö£¬µ±Windows Server¿ªÆôÔ¶³Ì×ÀÃæÊÚȨ·þÎñ£¨·ÇĬÈÏÆôÓã©Ê±£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕ߿ɷ¢ËͶñÒâÐÂÎÅÀûÓø÷ì϶£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
¶þ¡¢Ó°ÏìÁìÓò
Windows Server 2012 R2 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server Core installation)
Windows Server 2012
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2016 (Server Core installation)
Windows Server 2016
Windows Server 2022, 23H2 Edition (Server Core installation)
Windows Server 2022 (Server Core installation)
Windows Server 2022
Windows Server 2019 (Server Core installation)
Windows Server 2019
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒѰ䲼Á˸÷ì϶µÄ°²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-38077
3.2 һʱ´ëÊ©
¸Ã·ì϶»áÓ°ÏìÆôÓÃÁËWindows Remote Desktop Licensing ServiceµÄWindows Server£¬Windows PC²»ÊÜÓ°Ïì¡£
1.ĬÈÏÇé¿öÏ£¬Windows Server ²»»á×°Öà Remote Desktop Licensing ·þÎñ£¬¿Éͨ¹ýÑéÖ¤Remote Desktop Licensing·þÎñÊÇ·ñÆô¶¯£¬Óйز¹¶¡ÊÇ·ñδװÖÃÀ´ÅжÏÊÇ·ñÒ×Êܸ÷ì϶ӰÏì¡£
Èç·Ç±ØÒª£¬¿É½ûÓÃRemote Desktop Licensing·þÎñ×÷Ϊ»º½â´ëÊ©£¬µ«Õâ¿ÉÄÜ»áÓ°ÏìÔ¶³Ì×ÀÃæÄ³Ð©Ö°ÄÜ(¿ÉÄܲ»»áÖ±½Óµ¼ÖÂRDPÏνÓʧ°Ü£¬µ«ÓÉÓÚÊÚȨÑéÖ¤µÄȱʧ£¬¿ÉÄÜ»áÒý·¢ÆäËûÓëÊÚȨÓйصÄÃýÎó»òÎÊÌâ)¡£´Ë±í£¬Microsoft½¨ÒéÊÜÓ°ÏìÓû§×°Öø÷ì϶µÄ°²È«¸üУ¬¼´±ã´òËã½ûÓÃRemote Desktop Licensing·þÎñ¡£
2.´Ë±í£¬¿Éͨ¹ý²é¿´lserver.dll£¨Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÆ÷µÄÒ»¸ö¹Ø¼ü×é¼þ£¬Í¨³£Î»ÓÚC:\Windows\System32\lserver.dll£©Îļþ°æ±¾£¬²Î¿¼Ï±íÈ·¶¨ÊÇ·ñΪÒ×Êܹ¥»÷°æ±¾£¬¿ÉʹÓÃÒÔ϶àÖÖ·½Ê½²é¿´¸ÃÎļþ°æ±¾£º
l ÎļþÊôÐԲ鿴£¬ÕÒµ½C:\Windows\System32\lserver.dll£¬ÓÒ¼üµã»÷ lserver.dll Îļþ£¬Ñ¡Ôñ¡°ÊôÐÔ¡±£¬ÔÚÊôÐÔ´°¿ÚÖУ¬µã»÷¡°¾ßÌåÐÅÏ¢¡±Ñ¡Ï£¬ÔÚ¡°¾ßÌåÐÅÏ¢¡±Ñ¡ÏÏ£¬¿É¿´µ½¡°Îļþ°æ±¾¡±ºÍ¡°²úÆ·°æ±¾¡±ÐÅÏ¢¡£
l ʹÓÃPowershell²é¿´Îļþ°æ±¾£¬PowerShellÖÐÖ´ÐÐÒÔϺÅÁ
(Get-Item "C:\Windows\System32\lserver.dll").VersionInfo
l ÔÚCMD ÖÐŲÓÃPowerShell ºÅÁîÀ´»ñÈ¡Îļþ°æ±¾ÐÅÏ¢£º
powershell -command "(Get-Item 'C:\\Windows\\System32\\lserver.dll').VersionInfo.FileVersion"
ÊÜÓ°Ïìϵͳ | ƽ̨ | ÊÜÓ°Ïì°æ±¾ | ²»ÊÜÓ°Ïì°æ±¾ |
Windows Server 2019 | x64-based Systems | 10.0.0 - 10.0.17763.6054֮ǰ | 10.0.17763.6054 |
Windows Server 2019 (Server Core installation) | x64-based Systems | 10.0.0 -10.0.17763.6054֮ǰ | 10.0.17763.6054 |
Windows Server 2022 | x64-based Systems | 10.0.0 -10.0.20348.2582֮ǰ | 10.0.20348.2582 |
Windows Server 2022£¬23H2 Edition (Server Core installation) | x64-based Systems | 10.0.0 - 10.0.25398.1009֮ǰ | 10.0.25398.1009 |
Windows Server 2016 | x64-based Systems | 10.0.0 -10.0.14393.7159֮ǰ | 10.0.14393.7159 |
Windows Server 2016 (Server Core installation) | x64-based Systems | 10.0.0 -10.0.14393.7159֮ǰ | 10.0.14393.7159 |
Windows Server 2008 Service Pack 2 | 32-bit Systems | 6.0.0 - 6.0.6003.22769֮ǰ | 6.0.6003.22769 |
Windows Server 2008 Service Pack 2 (Server Core installation) | 32-bit Systems¡¢x64-based Systems | 6.0.0 - 6.0.6003.22769֮ǰ | 6.0.6003.22769 |
Windows Server 2008 Service Pack 2 | x64-based Systems | 6.0.0 - 6.0.6003.22769֮ǰ | 6.0.6003.22769 |
Windows Server 2008 R2 Service Pack 1 | x64-based Systems | 6.1.0 - 6.1.7601.27219֮ǰ | 6.1.7601.27219 |
Windows Server 2008 R2 Service Pack 1 (Server Core installation) | x64-based Systems | 6.0.0 - 6.1.7601.27219֮ǰ | 6.1.7601.27219 |
Windows Server 2012 | x64-based Systems | 6.2.0 - 6.2.9200.24975֮ǰ | 6.2.9200.24975 |
Windows Server 2012 (Server Core installation) | x64-based Systems | 6.2.0 - 6.2.9200.24975֮ǰ | 6.2.9200.24975 |
Windows Server 2012 R2 | x64-based Systems | 6.3.0 - 6.3.9600.22074֮ǰ | 6.3.9600.22074 |
Windows Server 2012 R2 (Server Core installation) | x64-based Systems | 6.3.0 - 6.3.9600.22074֮ǰ | 6.3.9600.22074 |
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Jul
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-38077
https://sites.google.com/site/zhiniangpeng/blogs/MadLicense
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-08-09 | ³õ´Î°ä²¼ |
V1.1 | 2024-08-09 | ¸üÐÂPoC״̬¡¢»º½â´ëÊ©µÈ |
Îå¡¢¸½Â¼
5.1 GA»Æ½ð¼×¼ò½é
GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£
5.2 ¹ØÓÚGA»Æ½ð¼×
GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ