SMBv3¡°È䳿¼¶¡±·ì϶À´Ï® GA»Æ½ð¼×Ìṩ½â¾ö¹æ»®£¡

°ä²¼¹¦·ò 2020-03-12

3ÔÂ10ÈÕ £¬Î¢Èí°ä²¼°²È«²¼¸æ£¨ADV200005£©³ÆÔÚMicrosoft Server Message Block 3.1.1 £¨SMBv3£©ºÍ̸ÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2020-0796 £¬Óֳơ°CoronaBlue¡±»ò¡°SMB Ghost¡±)¡£¸Ã·ì϶ÊÇÓÉSMBv3ºÍ̸´¦ÖöñÒâѹËõÊý¾Ý°üʱ½øÈëÃýÎóÁ÷³ÌÔì³ÉµÄ £¬Ô¶³Ìδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶Ôì³ÉÖ¸±êÖ÷»úϵͳ±ÀÀ£¡¢À¶ÆÁÉõÖÁÖ´ÐÐËÁÒâ´úÂë¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÓÉÓڸ÷ì϶Äܹ»Ö±½ÓÓÃÓÚÔ¶³Ì¹¥»÷ £¬²¢ÇÒÄܹ»¡°È䳿»¯¡± £¬Òò¶ø £¬Æä·çÏÕˮƽÀàËÆÓÚ2017ÄêµÄ¡°ÓÀºãÖ®À¶¡±·ì϶¡£µ«Ïà½ÏÓÚ¡°ÓÀºãÖ®À¶¡± £¬¸Ã·ì϶ӰÏìµÄÁìÓòÏà¶Ô½ÏÓ× £¬Ö»ÏÞÓÚWindows10ÒÔ¼°Windows Server µÄ1903ºÍ1909°æ±¾ £¬¾ßÌåÓ°ÏìµÄ°æ±¾ºÅÈçÏ£º


Windows 10 Version 1903 for 32-bit Systems

Windows 10 Version 1903 for ARM64-based Systems

Windows 10 Version 1903 for x64-based Systems

Windows 10 Version 1909 for 32-bit Systems

Windows 10 Version 1909 for ARM64-based Systems

Windows 10 Version 1909 for x64-based Systems

Windows Server, version 1903 (Server Core installation)

Windows Server, version 1909 (Server Core installation)


GA»Æ½ð¼×½â¾ö¹æ»®



Ò»¡¢ ½ûÓÃSMBv3ѹËõ


¹ÌÈ»±¾·ì϶ӰÏìµÄÁìÓòÏà¶Ô½ÏÓ× £¬µ«ÊÇÓÉÓÚ·çÏÕ¼¶±ð½Ï¸ß £¬²¢ÇÒ΢ÈíûÓиø³öÏàÓ¦µÄ·ì϶²¹¶¡ £¬ËùÒÔ½¨Òé¶ÔÊÜÓ°ÏìµÄ²Ù×÷ϵͳʹÓÃÒÔÏ»º½â´ëÊ©½ûÓÃSMBv3µÄѹËõÖ°ÄÜÀ´½øÐзÀ»¤¡£


Ê×ÏȲ鿴×Ô¼ºÊ¹ÓõÄWindows°æ±¾ÊÇ·ñΪÊÜÓ°ÏìµÄ°æ±¾ £¬²½ÖèÈçÏ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ʹÓÃWin + RºóÊäÈë¡°WinVer¡±²é¿´µ±Ç°²Ù×÷ϵͳµÄ°æ±¾ºÅ¡£


ÈôÊÇÈ·ÈÏϵͳÊÜÓ°Ïì £¬Ôò½¨ÒéʹÓÃÒÔÏÂPowerShellºÅÁî½ûÓÃѹËõÖ°ÄÜ £¬ÒÔ×èֹδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÀûÓÃSMBv3·þÎñÆ÷µÄ·ì϶£¨ÎÞÐè³ÁÐÂÆô¶¯£©¡£


Set-ItemProperty-Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 1 -Force


¶þ¡¢ ²úÆ·½â¾ö¹æ»®


1¡¢ÒѲ¿ÊðGA»Æ½ð¼×IDS¡¢IPS¡¢WAF¡¢APT²úÆ·µÄ¿Í»§ÇëÈ·ÈÏÈçÏÂÊÂÎñ¹æ¶¨ÒѾ­Ï·¢²¢ÀûÓà £¬¼´¿ÉÓÐЧ¼ì²âÓйع¥»÷£º TCP_CVE-2020-0796·ì϶ÀûÓá£


£¨1£©ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ±¨¾¯½ØÍ¼£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


£¨2£©ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½ØÍ¼£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


£¨3£©ÌìÇåWebÀûÓð²È«Íø¹Ø±¨¾¯½ØÍ¼£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


£¨4£©Ììãٸ߼¶³ÖÐøÐÔÍþв¼ì²âÓëÖÎÀíϵͳ±¨¾¯½ØÍ¼£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2¡¢GA»Æ½ð¼×Ìì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0ÓÚ2020Äê3ÔÂ12ÈÕ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü £¬Ö§³Ö¶Ô¸Ã·ì϶½øÐмì²â £¬Óû§Éý¼¶Ì쾵©ɨ²úÆ··ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃè¡£6070°æ±¾Éý¼¶°üΪ607000278 £¬Éý¼¶°üÏÂÔØµØÖ·£º

/article/type/1/146.html


ÇëÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾 £¬ÊµÊ±¶Ô¸Ã·ì϶½øÐмì²â £¬ÒԱ㾡¿ì²ÉÈ¡·À±¸´ëÊ©¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3¡¢ÒѲ¿ÊðÌ©ºÏTSOCϵÁвúÆ·µÄÆóÊÂÒµµ¥Ôª £¬½¨ÒéÔö³¤ÏàÓ¦µÄ¹æ¶¨³ÖÐø¶Ô¸ÃÐÐΪ½øÐÐ¼à¿Ø¡£


¹ØÁª¹æ¶¨£ºL3_MC_SMBv3Èä³æÔ¶³ÌÖ´Ðзì϶ÀûÓÃ-CVE-2020-0796

×¢Ã÷£º


¡°L3_MC_SMBv3Èä³æÔ¶³ÌÖ´Ðзì϶ÀûÓÃ-CVE-2020-0796¡±¹ØÁª¹æ¶¨Êǹ涨ǶÌ׵Ĺ涨 £¬ÓÃÓÚ¼à²âSMBv3·ì϶¡¾CVE-2020-0706¡¿ÀûÓÃÐÐΪ £¬Í¬Ê±Ò²¼à²âÅúÁ¿445¶Ë¿Ú½Ó¼ûµÄÐÐΪ¡£


Èô½ÓÈëTSOCƽ̨µÄ°²È«¼ì²âÉ豸սÊõÎÞÉý¼¶¡¢¸üР£¬Äܹ»µ¥¶ÀʹÓá°L2_ADS_ÅúÁ¿445¶Ë¿Ú½Ó¼û¡±¹æ¶¨¶Ô445¶Ë¿Ú½Ó¼ûÇé¿ö½øÐÐ¼à¿Ø¡£


×¢£º¡°L3_MC_SMBv3Èä³æÔ¶³ÌÖ´Ðзì϶ÀûÓÃ-CVE-2020-0796¡±¹æ¶¨ÒÑÔ̺¬¡°L2_ADS_ÅúÁ¿445¶Ë¿Ú½Ó¼û¡± £¬Ö±½Óµ¼Èë¡°L3_MC_SMBv3Èä³æÔ¶³ÌÖ´Ðзì϶ÀûÓÃ-CVE-2020-0796¡±¹æ¶¨°ü £¬ÎÞÐèµ¥¶ÀÅäÖá°L2_ADS_ÅúÁ¿445¶Ë¿Ú½Ó¼û¡±¡£


¡°L3_MC_SMBv3Èä³æÔ¶³ÌÖ´Ðзì϶ÀûÓÃ-CVE-2020-0796¡±¹æ¶¨Ç°Ì᣺


ÊÂÎñ=£¨ÈÕÖ¾ÀàÐÍ£¡=¡°¹ØÁªÊÂÎñ¡±£©&£¨£¨É豸ÀàÐÍÊôÓÚ£¨°²È«É豸/°²È«·À»¤Íø¹Ø¡¢°²È«É豸/webÀûÓÃÍø¹Ø¡¢°²È«É豸/ÈëÇÖ¼ì²â¡¢°²È«É豸/°²È«·ÀÓù¡¢°²È«É豸/·À²¡¶¾ÏµÍ³¡¢°²È«É豸/¶ñÒâ´úÂë¼ì²â¡¢°²È«É豸/Öն˰²È«ÖÎÀí£©£©&£¨Ö÷ÕŶ˿Ú=¡°445¡±£©&£¨ÒýÓùýÂËÆ÷=¡°CVE20200796_°²È«É豸¡±£©£©|£¨ÒýÓù涨=¡°L2_ADS_ÅúÁ¿445¶Ë¿Ú½Ó¼û¡±£©


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¡°CVE20200796_°²È«É豸¡±¹ýÂËÆ÷ǰÌ᣺


ÊÂÎñ=£¨ÈÕÖ¾ÀàÐÍ£¡=¡°¹ØÁªÊÂÎñ¡±£©&£¨£¨ÊÂÎñÃû³Æ Ô̺¬ ¡°Corona¡± £©&£¨ÊÂÎñÃû³Æ Ô̺¬ ¡°Blue¡±£©&£¨ÊÂÎñÃû³Æ Ô̺¬ ¡°·ì϶¡±£©£©|(£¨ÊÂÎñÃû³Æ Ô̺¬ ¡°CVE-2020-0796¡± £©)|(£¨ÊÂÎñÃû³Æ Ô̺¬ ¡°SMBv3¡± £©&£¨£¨£¨ÊÂÎñÃû³Æ Ô̺¬ ¡°·ì϶¡± £©|£¨ÊÂÎñÃû³Æ Ô̺¬ ¡°Ïνӡ± £©£©£©)


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¡°L2_ADS_ÅúÁ¿445¶Ë¿Ú½Ó¼û¡±¹æ¶¨Ç°Ì᣺


ÊÂÎñ=£¨ÈÕÖ¾ÀàÐÍ£¡=¡°¹ØÁªÊÂÎñ¡±£©&£¨Ö÷ÕŶ˿Ú=¡°445¡±£©


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¡°L2_ADS_ÅúÁ¿445¶Ë¿Ú½Ó¼û¡±´ÎÊýÉèÖãº


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾