΢ÈíRDPÔ¶³Ì×ÀÃæ·þÎñ¶à¸öRCEÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-14

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1181£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1182£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1222£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1226£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Windows 7 SP1¡¢Windows Server 2008 R2 SP1¡¢ Windows Server 2012¡¢Windows 8.1¡¢Windows Server 2012 R2ºÍËùÓÐÊÜÖ§³ÖµÄ°üÀ¨·þÎñÆ÷°æ±¾ÔÚÄÚµÄWindows 10 °æ±¾


²»ÊÜÓ°ÏìµÄ°æ±¾


Windows XP¡¢Windows Server 2003ºÍ Windows Server 2008 ¾ù²»ÊÜÓ°Ï죬ÒÔ¼°Ô¶³Ì×ÀÃæÐ­Òé (RDP) ×Ô¼º²¢²»ÊÜÓ°Ïì


Îó²î¸ÅÊö


΢ÈíÐÇÆÚ¶þÐû²¼ÁËÀýÐв¹¶¡ÐÞ¸´¼Æ»®£¬ÆäÖаüÀ¨4¸öÑÏÖØµÄÔ¶³Ì×ÀÃæ·þÎñÔ¶³Ì´úÂëÖ´ÐÐÎó²î ¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâÌØÊâµÄRDPÇëÇó´¥·¢Îó²î£¬»ñÈ¡ÔÚÄ¿µÄϵͳÉϵÄÔ¶³Ì´úÂëÖ´ÐÐȨÏÞ ¡£´Ó΢Èíͨ¸æÖÐÀ´¿´£¬¸ÃÎó²îΪԤÉí·ÝÑéÖ¤£¬¼´ÎÞÐèÓû§½»»¥£¬ÕâÒâζןÃÎó²îÓпÉÄܱ»È䳿ËùʹÓà ¡£


ÏÖÔÚÍøÂçÉÏ¿ª·ÅRDP·þÎñµÄ·þÎñÆ÷ÊýÄ¿ÖØ´ó£¬Ó°ÏìÃæ¼«´ó ¡£


΢Èí»¹Ðû²¼ÁËÕë¶ÔCVE-2019-1181/CVE-2019-1182ÆôÓÃÁËÍøÂç¼¶±ðÈÏÖ¤ (NLA) ¹¦Ð§µÄÊÜÓ°ÏìϵͳµÄ»º½â²½·¥ ¡£ÓÉÓÚÎó²î±»´¥·¢Ç°£¬NLA ÒªÇó¾ÙÐÐÈÏÖ¤£¬Òò´ËÊÜÓ°Ïìϵͳ»º½âÁËÄܹ»Ê¹ÓøÃÎó²îµÄ¡°È䳿¼¶¡±¶ñÒâÈí¼þ»ò¸ß½×µÄ¶ñÒâÈí¼þÍþв ¡£È»¶ø£¬ÈôÊǹ¥»÷Õß¾ßÓÐÄܹ»±»ÓÃÓÚ¾ÙÐÐÈÏÖ¤µÄÕýµ±Æ¾Ö¤£¬Òò´ËÊÜÓ°ÏìϵͳÈÔÈ»Ò×ÊÜÔ¶³Ì´úÂëÖ´ÐÐʹÓõĹ¥»÷ ¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP ¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ£¬Î¢Èí¹Ù·½ÒѾ­Ðû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬½¨ÒéÓû§¾¡¿ì½ÓÄÉÐÞ²¹²½·¥£¬ÒÔ×èֹDZÔÚµÄÇå¾²Íþв ¡£ÏëÒª¾ÙÐиüУ¬Ö»Ðèתµ½ÉèÖáú¸üкÍÇå¾²¡úWindows ¸üСú¼ì²é¸üУ¬»òÕßÒ²¿ÉÒÔͨ¹ýÊÖ¶¯¾ÙÐиüР¡£


»º½â²½·¥£¬Õë¶ÔCVE-2019-1181/CVE-2019-1182£º


1. ÔÚϵͳÉÏÆôÓÃÍøÂç¼°Éí·ÝÈÏÖ¤£¨NLA£©ÒÔÔÝʱ¹æ±Ü¸ÃÎó²îÓ°Ïì


2. ÔÚÆóÒµÍâΧ·À»ðǽ×è¶ÏTCP¶Ë¿Ú3389µÄÁ´½Ó


3. ÈçÎÞÐèÇ󣬿ɽûÓÃÏà¹ØÔ¶³Ì×ÀÃæ·þÎñ


²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1181
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1182
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1222
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1226