Ô¶³Ì×ÀÃæ·þÎñ0day·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-06-05

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-9510£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º4.6


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Windows 10 1803»òServer 2019»ò¸üеÄϵͳ


·ì϶¸ÅÊö


×êÑÐÈËÔ±·¢ÏÖÒ»¸öÐÂ0day£¬¿Éµ¼Ö¹¥»÷Õß½Ù³ÖÏÖÓеÄÔ¶³Ì×ÀÃæ·þÎñ»á»°£¬»ñÈ¡¶ÔÍÆËã»úµÄ½Ó¼ûȨÏÞ¡£¸Ã0day¿É±»ÓÃÓÚÈÆ¹ýWindowsÉ豸µÄËøÆÁ£¬¼´±ãË«³É·ÖÈÏÖ¤ÈçDuo Security MFA¿ªÆôÒ²²»Àý±í¡£×éÖ¯»ú¹¹¿ÉÄÜÉèÖÃµÄÆäËüµÇ¼ÅäÖÃÒ²¿ÉÔâÈÆ¹ý¡£


Microsoft WindowsÔ¶³Ì×ÀÃæÖ§³Ö³ÆÎªÍøÂç¼¶±ðÉí·ÝÑéÖ¤£¨NLA£©µÄÖ°ÄÜ£¬¸ÃÖ°Äܿɽ«Ô¶³Ì»á»°µÄÉí·ÝÑéÖ¤·½Ãæ´ÓRDP²ãÒÆÖÁÍøÂç²ã¡£½¨ÒéʹÓÃNLAÀ´Ï÷¼õʹÓÃRDPºÍ̸¶³öµÄϵͳµÄ¹¥»÷Ãæ¡£ÔÚWindowsÖУ¬Äܹ»Ëø¶¨»á»°£¬ÏòÓû§ÏÔʾ±ØÒªÉí·ÝÑéÖ¤ÄÜÁ¦³ÖÐøÊ¹ÓûỰµÄÆÁÄ»¡£»á»°Ëø¶¨Äܹ»Í¨¹ýRDP²úÉú£¬Æä·½Ê½ÓëËø¶¨±¾µØ»á»°µÄ·½Ê½Ò»Ñù¡£


´ÓWindows 10 1803£¨2018Äê4Ô°䲼£©ºÍWindows Server 2019ÆðÍ·£¬»ùÓÚNLAµÄRDP»á»°µÄ´¦Ö÷½Ê½²úÉúÁ˱䶯£¬µ¼ÖÂ»á»°Ëø¶¨·½ÃæµÄÒâ±íÐÐΪ¡£ÈôÊÇÍøÂçÒì³£´¥·¢Ò»Ê±RDP¶Ï¿ªÏνÓ£¬ÔòÔÚ×Ô¶¯³ÁÐÂÏνÓʱ£¬ÎÞÂÛÔ¶³ÌϵͳÈôºÎÍÑÀ룬RDP»á»°¶¼½«¸´Ô­µ½½âËø×´Ì¬¡£ÀýÈ磬Çë˼¿¼ÒÔϲ½Ö裺


Óû§Ê¹ÓÃRDPÏνӵ½Ô¶³ÌWindows 10 1803»òServer 2019»ò¸üеÄϵͳ¡£


Óû§Ëø¶¨Ô¶³Ì×ÀÃæ»á»°¡£


Óû§ÍÑÀë²¢ÁôÏÂRDP¿Í»§¶Ë


´Ëʱ£¬¹¥»÷ÕßÄܹ»ÖжÏRDP¿Í»§¶ËϵͳµÄÍøÂçÏνÓ¡£Ò»µ©¸´Ô­»¥ÁªÍøÏνÓ£¬RDP¿Í»§¶ËÈí¼þ½«×Ô¶¯³ÁÐÂÏνӵ½Ô¶³Ìϵͳ¡£µ«ÓÉÓÚ´Ë·ì϶£¬³ÁÐÂÏνӵÄRDP»á»°½«»¹Ô­µ½µÇ¼×ÀÃæ¶ø²»ÊǵǼÆÁÄ»¡£ÕâÒâζ×ÅÔ¶³Ìϵͳ½âËø¶øÎÞÐèÊÖ¶¯ÊäÈëÈκÎÍ´´¦¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ΢Èí²¢Î´³ïËã½üÆÚ½¨¸´£¬Óû§¿Éͨ¹ýËø¶¨±¾µØÏµÍ³¶ø·ÇÔ¶³ÌϵͳµÄ·½Ê½£¬»òͨ¹ý¶Ï¿ªÔ¶³Ì×ÀÃæ»á»°¶ø·Ç½öËø¶¨»á»°µÄ·½Ê½Ô¤·ÀÔâ¸Ã·ì϶ӰÏì¡£


²Î¿¼Á´½Ó


https://kb.cert.org/vuls/id/576688/
https://www.bleepingcomputer.com/news/security/remote-desktop-zero-day-bug-allows-attackers-to-hijack-sessions/