SMBv3¡°È䳿¼¶¡±·ì϶À´Ï® GA»Æ½ð¼×Ìṩ½â¾ö¹æ»®£¡
°ä²¼¹¦·ò 2020-03-123ÔÂ10ÈÕ£¬Î¢Èí°ä²¼°²È«²¼¸æ£¨ADV200005£©³ÆÔÚMicrosoft Server Message Block 3.1.1 £¨SMBv3£©ºÍ̸ÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2020-0796£¬Óֳơ°CoronaBlue¡±»ò¡°SMB Ghost¡±)¡£¸Ã·ì϶ÊÇÓÉSMBv3ºÍ̸´¦ÖöñÒâѹËõÊý¾Ý°üʱ½øÈëÃýÎóÁ÷³ÌÔì³ÉµÄ£¬Ô¶³Ìδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶Ôì³ÉÖ¸±êÖ÷»úϵͳ±ÀÀ£¡¢À¶ÆÁÉõÖÁÖ´ÐÐËÁÒâ´úÂë¡£
ÓÉÓڸ÷ì϶Äܹ»Ö±½ÓÓÃÓÚÔ¶³Ì¹¥»÷£¬²¢ÇÒÄܹ»¡°È䳿»¯¡±£¬Òò¶ø£¬Æä·çÏÕˮƽÀàËÆÓÚ2017ÄêµÄ¡°ÓÀºãÖ®À¶¡±·ì϶¡£µ«Ïà½ÏÓÚ¡°ÓÀºãÖ®À¶¡±£¬¸Ã·ì϶ӰÏìµÄÁìÓòÏà¶Ô½ÏÓ×£¬Ö»ÏÞÓÚWindows10ÒÔ¼°Windows Server µÄ1903ºÍ1909°æ±¾£¬¾ßÌåÓ°ÏìµÄ°æ±¾ºÅÈçÏ£º
Windows 10 Version 1903 for 32-bit Systems
Windows 10 Version 1903 for ARM64-based Systems
Windows 10 Version 1903 for x64-based Systems
Windows 10 Version 1909 for 32-bit Systems
Windows 10 Version 1909 for ARM64-based Systems
Windows 10 Version 1909 for x64-based Systems
Windows Server, version 1903 (Server Core installation)
Windows Server, version 1909 (Server Core installation)
GA»Æ½ð¼×½â¾ö¹æ»®
Ò»¡¢ ½ûÓÃSMBv3ѹËõ
¹ÌÈ»±¾·ì϶ӰÏìµÄÁìÓòÏà¶Ô½ÏÓ×£¬µ«ÊÇÓÉÓÚ·çÏÕ¼¶±ð½Ï¸ß£¬²¢ÇÒ΢ÈíûÓиø³öÏàÓ¦µÄ·ì϶²¹¶¡£¬ËùÒÔ½¨Òé¶ÔÊÜÓ°ÏìµÄ²Ù×÷ϵͳʹÓÃÒÔÏ»º½â´ëÊ©½ûÓÃSMBv3µÄѹËõÖ°ÄÜÀ´½øÐзÀ»¤¡£
Ê×ÏȲ鿴×Ô¼ºÊ¹ÓõÄWindows°æ±¾ÊÇ·ñΪÊÜÓ°ÏìµÄ°æ±¾£¬²½ÖèÈçÏ£º
ʹÓÃWin + RºóÊäÈë¡°WinVer¡±²é¿´µ±Ç°²Ù×÷ϵͳµÄ°æ±¾ºÅ¡£
ÈôÊÇÈ·ÈÏϵͳÊÜÓ°Ï죬Ôò½¨ÒéʹÓÃÒÔÏÂPowerShellºÅÁî½ûÓÃѹËõÖ°ÄÜ£¬ÒÔ×èֹδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÀûÓÃSMBv3·þÎñÆ÷µÄ·ì϶£¨ÎÞÐè³ÁÐÂÆô¶¯£©¡£
Set-ItemProperty-Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 1 -Force
¶þ¡¢ ²úÆ·½â¾ö¹æ»®
1¡¢ÒѲ¿ÊðGA»Æ½ð¼×IDS¡¢IPS¡¢WAF¡¢APT²úÆ·µÄ¿Í»§ÇëÈ·ÈÏÈçÏÂÊÂÎñ¹æ¶¨ÒѾÏ·¢²¢ÀûÓ㬼´¿ÉÓÐЧ¼ì²âÓйع¥»÷£º TCP_CVE-2020-0796·ì϶ÀûÓá£
£¨1£©ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ±¨¾¯½ØÍ¼£º
£¨2£©ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½ØÍ¼£º
£¨3£©ÌìÇåWebÀûÓð²È«Íø¹Ø±¨¾¯½ØÍ¼£º
£¨4£©Ììãٸ߼¶³ÖÐøÐÔÍþв¼ì²âÓëÖÎÀíϵͳ±¨¾¯½ØÍ¼£º
2¡¢GA»Æ½ð¼×Ìì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0ÓÚ2020Äê3ÔÂ12ÈÕ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐмì²â£¬Óû§Éý¼¶Ì쾵©ɨ²úÆ··ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃè¡£6070°æ±¾Éý¼¶°üΪ607000278£¬Éý¼¶°üÏÂÔØµØÖ·£º
/article/type/1/146.html
ÇëÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬ÊµÊ±¶Ô¸Ã·ì϶½øÐмì²â£¬ÒԱ㾡¿ì²ÉÈ¡·À±¸´ëÊ©¡£
3¡¢ÒѲ¿ÊðÌ©ºÏTSOCϵÁвúÆ·µÄÆóÊÂÒµµ¥Ôª£¬½¨ÒéÔö³¤ÏàÓ¦µÄ¹æ¶¨³ÖÐø¶Ô¸ÃÐÐΪ½øÐÐ¼à¿Ø¡£
¹ØÁª¹æ¶¨£ºL3_MC_SMBv3Èä³æÔ¶³ÌÖ´Ðзì϶ÀûÓÃ-CVE-2020-0796
×¢Ã÷£º
¡°L3_MC_SMBv3Èä³æÔ¶³ÌÖ´Ðзì϶ÀûÓÃ-CVE-2020-0796¡±¹ØÁª¹æ¶¨Êǹ涨ǶÌ׵Ĺ涨£¬ÓÃÓÚ¼à²âSMBv3·ì϶¡¾CVE-2020-0706¡¿ÀûÓÃÐÐΪ£¬Í¬Ê±Ò²¼à²âÅúÁ¿445¶Ë¿Ú½Ó¼ûµÄÐÐΪ¡£
Èô½ÓÈëTSOCƽ̨µÄ°²È«¼ì²âÉ豸սÊõÎÞÉý¼¶¡¢¸üУ¬Äܹ»µ¥¶ÀʹÓá°L2_ADS_ÅúÁ¿445¶Ë¿Ú½Ó¼û¡±¹æ¶¨¶Ô445¶Ë¿Ú½Ó¼ûÇé¿ö½øÐÐ¼à¿Ø¡£
×¢£º¡°L3_MC_SMBv3Èä³æÔ¶³ÌÖ´Ðзì϶ÀûÓÃ-CVE-2020-0796¡±¹æ¶¨ÒÑÔ̺¬¡°L2_ADS_ÅúÁ¿445¶Ë¿Ú½Ó¼û¡±£¬Ö±½Óµ¼Èë¡°L3_MC_SMBv3Èä³æÔ¶³ÌÖ´Ðзì϶ÀûÓÃ-CVE-2020-0796¡±¹æ¶¨°ü£¬ÎÞÐèµ¥¶ÀÅäÖá°L2_ADS_ÅúÁ¿445¶Ë¿Ú½Ó¼û¡±¡£
¡°L3_MC_SMBv3Èä³æÔ¶³ÌÖ´Ðзì϶ÀûÓÃ-CVE-2020-0796¡±¹æ¶¨Ç°Ì᣺
ÊÂÎñ=£¨ÈÕÖ¾ÀàÐÍ£¡=¡°¹ØÁªÊÂÎñ¡±£©&£¨£¨É豸ÀàÐÍÊôÓÚ£¨°²È«É豸/°²È«·À»¤Íø¹Ø¡¢°²È«É豸/webÀûÓÃÍø¹Ø¡¢°²È«É豸/ÈëÇÖ¼ì²â¡¢°²È«É豸/°²È«·ÀÓù¡¢°²È«É豸/·À²¡¶¾ÏµÍ³¡¢°²È«É豸/¶ñÒâ´úÂë¼ì²â¡¢°²È«É豸/Öն˰²È«ÖÎÀí£©£©&£¨Ö÷ÕŶ˿Ú=¡°445¡±£©&£¨ÒýÓùýÂËÆ÷=¡°CVE20200796_°²È«É豸¡±£©£©|£¨ÒýÓù涨=¡°L2_ADS_ÅúÁ¿445¶Ë¿Ú½Ó¼û¡±£©
¡°CVE20200796_°²È«É豸¡±¹ýÂËÆ÷ǰÌ᣺
ÊÂÎñ=£¨ÈÕÖ¾ÀàÐÍ£¡=¡°¹ØÁªÊÂÎñ¡±£©&£¨£¨ÊÂÎñÃû³Æ Ô̺¬ ¡°Corona¡± £©&£¨ÊÂÎñÃû³Æ Ô̺¬ ¡°Blue¡±£©&£¨ÊÂÎñÃû³Æ Ô̺¬ ¡°·ì϶¡±£©£©|(£¨ÊÂÎñÃû³Æ Ô̺¬ ¡°CVE-2020-0796¡± £©)|(£¨ÊÂÎñÃû³Æ Ô̺¬ ¡°SMBv3¡± £©&£¨£¨£¨ÊÂÎñÃû³Æ Ô̺¬ ¡°·ì϶¡± £©|£¨ÊÂÎñÃû³Æ Ô̺¬ ¡°Ïνӡ± £©£©£©)
¡°L2_ADS_ÅúÁ¿445¶Ë¿Ú½Ó¼û¡±¹æ¶¨Ç°Ì᣺
ÊÂÎñ=£¨ÈÕÖ¾ÀàÐÍ£¡=¡°¹ØÁªÊÂÎñ¡±£©&£¨Ö÷ÕŶ˿Ú=¡°445¡±£©
¡°L2_ADS_ÅúÁ¿445¶Ë¿Ú½Ó¼û¡±´ÎÊýÉèÖãº


¾©¹«Íø°²±¸11010802024551ºÅ