SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-03-29·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-0604£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ CVSS·ÖÖµ£º7.8
Ó°Ïì°æ±¾£º
Microsoft SharePoint Server 2019
Microsoft SharePoint Enterprise Server 2016
Microsoft SharePoint Foundation 2013 Service Pack 1
Microsoft SharePoint Server 2010 Service Pack 2
·ì϶¸ÅÊö
SharePointÊÇ΢ÈíµÄÒ»¿îÍŶӺÏ×÷½â¾ö¹æ»®£¬ÓÃÓÚÍŶӼ乲ÏíºÍÖÎÀíÄÚÈݺÍ֪ʶ¡£ËüʹÓÃASP.NET¿ª·¢£¬ºó¶ËÊý¾Ý¿âʹÓÃMicrosoft SQL Server¡£
³É¹¦ÀûÓ÷ì϶£¬¿Éµ¼ÖÂWindowsϵͳ·þÎñÆ÷Ô¶³ÌÖ´ÐкÅÁÓпÉÄÜÆëÈ«½ÚÔì·þÎñÆ÷¡£
¹¥»÷Õ߿ɽ«¾«ÐÄ»ú¹ØµÄÒªÇóͨ¹ýItemPicker WebForm¿Ø¼þ´«Èëºó¶ËEntityInstanceIdEncoder.DecodeEntityInstanceId(encodedId)²½ÖèÖУ¬ÓÉÓÚ²½ÖèûÓжԴ«ÈëµÄencodedId½øÐÐÈκδ¦Öã¬Ò²Ã»ÓжÔXmlSerializer»ú¹Øº¯ÊýµÄÀàÐͲÎÊý½øÐÐÏÞ¶È£¬¿ÉÖ±½Óͨ¹ýXmlSerializer·´ÐòÁл¯£¬Ôì³ÉºÅÁîÖ´ÐС£
ÒªÀûÓø÷ì϶£¬±ØÒªÊÚȨ½Ó¼ûSharePointÌṩµÄÖÎÀíÍøÒ³£¬ÊÚȨÕË»§¿ÉËùÒÔÒ»¸öÓòÕË»§¡£
·ì϶ϸ½Ú
ÀûÓÃǰÌ᣺
¿ÉÊÚȨ½Ó¼ûSharePointÌṩµÄÖÎÀíÍøÒ³£¬ÊÚȨÕË»§¿ÉËùÒÔÒ»¸öÓòÕË»§¡£
»·¾³´î½¨£º
? Windows server 2016
? ASP.NETÓйØ×é¼þ
? Microsoft SQL Server
? SharePoint Server
×°ÖÃSharePointǰÄܹ»ÏÈÔËÐÐprerequisiteinstaller ×°ÖÃSharePoint±Ø±¸µÄ×é¼þ£¬¶øºó×°ÖÃMicrosoft SQL Server£¬ÅäÖúÃÕË»§¡£ÈôÊÇÔÚµ¥»úÉϴSharePoint±ØÒªÔÚ´Ëʱ½«·þÎñÆ÷Çл»ÎªÓò¿Ø·þÎñÆ÷£¬¶øºóÔÙ³ÉÁ¢ÓòÕ˺Å×°ÖúͲ¿ÊðSharePoint¡£±¾µØÕ˺Ų»ÇкÏSharePointµÄ²¿ÊðÒªÇó¡£
·ì϶·ÖÎö£º
·ì϶Èë¿ÚÔÚhttp://
½øÈ븸ÀàPickerDialogÖУ¬¿´»ú¹Øº¯Êý£º
ÆäÖÐEntityEditorWithPickerÒ²ÊÇÒ»¸öWebForm¿Ø¼þ£¬×¢Ã÷ÔÚÕâÀï´«ÈëÁËÒ»¸öEntityEditorWithPickerµÄ×ÓÀàItemPicker£¬¸úÈëItemPicker¿É¿´µ½ItemPickerµÄÈ·¼Ì³Ð×ÔEntityEditorWithPicker£¬EntityEditorWithPickerÓּ̳Ð×ÔEntityEditor£º
EntityEditorʵÏÖÁ˽ӿڣºIPostBackDataHandlerºÍICallbackEventHandler£¬Æ¾¾ÝWebForm¿Ø¼þµÄÐÔÃüÖÜÆÚ£¬ÔÚÒ³ÃæÖÐÓÐÊÂÎñ´¥·¢__doPostBack()ºó£¬ÏÈŲÓÃͨ¹ýICallbackEventHandlerʵÏÖµÄRaiseCallbackEvent()²½ÖèºÍGetCallbackResult()²½ÖèµÃµ½±íµ¥ÄÚÈÝ£¬ÔÙŲÓÃͨ¹ýIPostBackDataHandlerʵÏÖµÄLoadPostData()²½Öè¡£
»Øµ½EntityEditorÖп´GetCallbackResult()²½ÖèÖÐŲÓÃÁËInvokeCallbackEvent()²½Ö裬InvokeCallbackEvent()²½ÖèŲÓÃÁËParseSpanData()²½Ö裺
À´µ½ParseSpanData()ÖÐÄܹ»¿´³öÕâÀï°Ñ±íµ¥Ìá½»µÄÊý¾Ý½øÐÐÁË´¦Öᣴ˴¦Âß¼¼«¶È¸´ÔÓ£¬ÎÒÃÇÖ»¸ú¶ÔHiddenSpanDataµÄ´¦Öãº
¿É·¢Ïִ˲½Ö轫HiddenSpanDataµÄÖµ·ÅÈëÁËPickerEntityµÄListÖУ¬ÔÚ¾¹ýһЩ´¦ÖúóÔ׸î³ÉÊý×飬±éÀúÊý×飬н¨PickerEntity¶ÔÏópickerEntity2£¬½«ÆäÖµ·ÅÈëpickerEntity2.KeyÖУ¬×îÖÕ·ÅÈëarrayListÖв¢¸³Öµ¸øÀà³ÉÔ±±äÁ¿m_listOrderTemp:
»Øµ½LoadPostData()²½Öè¿´¶Ôm_listOrderTemp³ÉÔ±±äÁ¿µÄ´¦Ö㬿ɿ´µ½ÔÚÕâÀï±éÀúÁËm_listOrderTemp³ÉÔ±±äÁ¿µÄÖµ²¢½«Æä¼Ó½øm_listRevalidation³ÉÔ±±äÁ¿ÖУ¬¶øºóµü´ú½øÐÐValidate()²Ù×÷£º
ÔÚValidate()²½ÖèÖУ¬½«m_listOrderTemp³ÉÔ±±äÁ¿¸³Öµ¸øm_listOrder³ÉÔ±±äÁ¿£º
¶øºó±éÀúEntitiesµÄֵŲÓÃValidateEntity()²½Ö裺
EntitiesµÄÖ·´×ÔÓÚÉÏÃæµÄÒ»Ðкܲ»ÆðÑÛµÄLambda±í°×ʽ²½Ö裬´Ë²½Ö轫·µ»Øm_listOrder³ÉÔ±±äÁ¿µÄÖµ£º
¸úµ½ValidateEntity()²½Öè·¢ÏÖÊÇÐé²½Ö裬Òò¶øÈ¥×ÓÀàÕÒ²½ÖèµÄ³Áд¡£
À´µ½EntityEditorWithPickerÀàÖп´µ½ÁËValidateEntity() ²½ÖèµÄ³Áд£¬·¢ÏÔì佫PickerEntityµÄkey£¨pe.Key£©´«ÈëÁËMicrosoft.SharePoint.BusinessData.Infrastructure.EntityInstanceIdEncoder.DecodeEntityInstanceId()ÖС£
½øÈëDecodeEntityInstanceId() ²½Öè·¢ÏÖ·´ÐòÁл¯£¬²¢ÇÒXmlSerializer»ú¹Øº¯ÊýµÄÀàÐͲÎÊý¿É¿Ø¡£
²¹¶¡·ÖÎö£º
×°Öò¹¶¡KB4462211ºóÔٴη´±àÒ룬¶Ô±ÈDecodeEntityInstanceId()²½ÖèµÄÔ´Â룬·¢ÏÖÒѾ²»ÔÙÖ§³Ö¶ÔÏóÀàÐ͵ķ´ÐòÁл¯¡£
·ì϶ÀûÓÃ
ÔÚ·ì϶·ÖÎöʱ£¬ÎÒÃÇÔÚEntityInstanceIdEncoderÀàÖп´µ½ÁíÒ»¸ö²½ÖèEncodeEntityInstanceId(),Äܹ»Ö±½ÓʹÓÃËüÌìÉúPayload¡£
»ú¹ØXML£º
ÌìÉúPayload£º
ÌìÉúPayloadʱ»áµ¯³öÒ»´ÎÍÆËãÆ÷£¬¹Øµô¼´¿É¡£
PoC£º
½¨¸´½¨Òé
Ŀǰ¹Ù·½ÒÑÍÆ³öÏàÓ¦²¹¶¡£¬Ç뾡¿ìÉý¼¶½øÐн¨¸´¡£
Microsoft SharePoint Enterprise Server 2016
Security Update for Microsoft SharePoint Enterprise Server 2016(KB4462211)
https://www.microsoft.com/en-us/download/details.aspx?id=58072
Microsoft SharePoint Foundation 2013 Service Pack 1
Security Update for Microsoft SharePoint Enterprise Server 2013(KB4462202)
https://www.microsoft.com/en-us/download/details.aspx?id=58063
Microsoft SharePoint Server 2010 Service Pack 2
Security Update for 2010 Microsoft Business Productivity Servers(KB4462184)
https://www.microsoft.com/en-us/download/details.aspx?id=58066
Microsoft SharePoint Server 2019
Security Update for Microsoft SharePoint Server 2019 Core(KB4462199)
https://www.microsoft.com/en-us/download/details.aspx?id=58061
²Î¿¼Á´½Ó
https://www.thezdi.com/blog/2019/3/13/cve-2019-0604-details-of-a-microsoft-sharepoint-rce-vulnerability
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0604


¾©¹«Íø°²±¸11010802024551ºÅ