Ô¶³Ì×ÀÃæÐ§ÀÍ0dayÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-05

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-9510 £¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬£¬£¬£¬CVSS·ÖÖµ£º4.6


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Windows 10 1803»òServer 2019»ò¸üеÄϵͳ


Îó²î¸ÅÊö


Ñо¿Ö°Ô±·¢Ã÷Ò»¸öÐÂ0day £¬£¬£¬£¬¿Éµ¼Ö¹¥»÷ÕßÐ®ÖÆÏÖÓеÄÔ¶³Ì×ÀÃæÐ§ÀͻỰ £¬£¬£¬£¬»ñÈ¡¶ÔÅÌËã»úµÄ»á¼ûȨÏÞ¡£¡£¡£¡£¸Ã0day¿É±»ÓÃÓÚÈÆ¹ýWindows×°±¸µÄËøÆÁ £¬£¬£¬£¬×ÝȻ˫ÒòËØÈÏÖ¤ÈçDuo Security MFA¿ªÆôÒ²²»ÆÆÀý¡£¡£¡£¡£×éÖ¯»ú¹¹¿ÉÄÜÉèÖÃµÄÆäËüµÇ¼ÉèÖÃÒ²¿ÉÔâÈÆ¹ý¡£¡£¡£¡£


Microsoft WindowsÔ¶³Ì×ÀÃæÖ§³Ö³ÆÎªÍøÂç¼¶±ðÉí·ÝÑéÖ¤£¨NLA£©µÄ¹¦Ð§ £¬£¬£¬£¬¸Ã¹¦Ð§¿É½«Ô¶³Ì»á»°µÄÉí·ÝÑéÖ¤·½Ãæ´ÓRDP²ãÒÆÖÁÍøÂç²ã¡£¡£¡£¡£½¨ÒéʹÓÃNLAÀ´ïÔ̭ʹÓÃRDPЭÒé̻¶µÄϵͳµÄ¹¥»÷Ãæ¡£¡£¡£¡£ÔÚWindowsÖÐ £¬£¬£¬£¬¿ÉÒÔËø¶¨»á»° £¬£¬£¬£¬ÏòÓû§ÏÔʾÐèÒªÉí·ÝÑéÖ¤²Å»ª¼ÌÐøÊ¹ÓûỰµÄÆÁÄ»¡£¡£¡£¡£»£»£»á»°Ëø¶¨¿ÉÒÔͨ¹ýRDP±¬·¢ £¬£¬£¬£¬Æä·½·¨ÓëËø¶¨ÍâµØ»á»°µÄ·½·¨Ïàͬ¡£¡£¡£¡£


´ÓWindows 10 1803£¨2018Äê4ÔÂÐû²¼£©ºÍWindows Server 2019×îÏÈ £¬£¬£¬£¬»ùÓÚNLAµÄRDP»á»°µÄ´¦Öóͷ£·½·¨±¬·¢ÁËת±ä £¬£¬£¬£¬µ¼ÖÂ»á»°Ëø¶¨·½ÃæµÄÒâÍâÐÐΪ¡£¡£¡£¡£ÈôÊÇÍøÂçÒì³£´¥·¢ÔÝʱRDP¶Ï¿ªÅþÁ¬ £¬£¬£¬£¬ÔòÔÚ×Ô¶¯ÖØÐÂÅþÁ¬Ê± £¬£¬£¬£¬ÎÞÂÛÔ¶³ÌϵͳÔõÑùÍÑÀë £¬£¬£¬£¬RDP»á»°¶¼½«»Ö¸´µ½½âËø×´Ì¬¡£¡£¡£¡£ÀýÈç £¬£¬£¬£¬Çë˼Á¿ÒÔϰ취£º


Óû§Ê¹ÓÃRDPÅþÁ¬µ½Ô¶³ÌWindows 10 1803»òServer 2019»ò¸üеÄϵͳ¡£¡£¡£¡£


Óû§Ëø¶¨Ô¶³Ì×ÀÃæ»á»°¡£¡£¡£¡£


Óû§ÍÑÀë²¢ÁôÏÂRDP¿Í»§¶Ë


´Ëʱ £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÖÐÖ¹RDP¿Í»§¶ËϵͳµÄÍøÂçÅþÁ¬¡£¡£¡£¡£Ò»µ©»Ö¸´»¥ÁªÍøÅþÁ¬ £¬£¬£¬£¬RDP¿Í»§¶ËÈí¼þ½«×Ô¶¯ÖØÐÂÅþÁ¬µ½Ô¶³Ìϵͳ¡£¡£¡£¡£µ«ÓÉÓÚ´ËÎó²î £¬£¬£¬£¬ÖØÐÂÅþÁ¬µÄRDP»á»°½«»¹Ô­µ½µÇ¼×ÀÃæ¶ø²»ÊǵǼÆÁÄ»¡£¡£¡£¡£ÕâÒâζ×ÅÔ¶³Ìϵͳ½âËø¶øÎÞÐèÊÖ¶¯ÊäÈëÈÎºÎÆ¾Ö¤¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ΢Èí²¢Î´ÍýÏë½üÆÚÐÞ¸´ £¬£¬£¬£¬Óû§¿Éͨ¹ýËø¶¨ÍâµØÏµÍ³¶ø·ÇÔ¶³ÌϵͳµÄ·½·¨ £¬£¬£¬£¬»òͨ¹ý¶Ï¿ªÔ¶³Ì×ÀÃæ»á»°¶ø·Ç½öËø¶¨»á»°µÄ·½·¨×èÖ¹Ôâ¸ÃÎó²îÓ°Ïì¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://kb.cert.org/vuls/id/576688/
https://www.bleepingcomputer.com/news/security/remote-desktop-zero-day-bug-allows-attackers-to-hijack-sessions/