Remote Desktop ClientÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-09-11¡ñ·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-0787£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º7.5
CVE±àºÅ£ºCVE-2019-0788£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º7.5
CVE±àºÅ£ºCVE-2019-1290£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º7.5
CVE±àºÅ£ºCVE-2019-1291£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º7.5
¡ñÓ°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
ÆÕ±éÓ°ÏìÒÔϰ汾µÄWindows£º
Microsoft Windows 10 for 32λ¡¢64λ¼°ARM64λϵͳ
Microsoft Windows 7 for 32λ¡¢64λSP1
Microsoft Windows 8.1 for 32λ¡¢64λ
Microsoft Windows RT 8.1
CVE-2019-1290/1291¶î±íÓ°ÏìÒÔϰ汾µÄWindows Serverϵͳ£º
Microsoft Windows Server 2008 R2 for Itanium-based Systems SP1
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft Windows Server 1803/1903
¡ñ·ì϶¸ÅÊö
Remote Desktop ClientÊÇ΢ÈíRDPºÍ̸µÄ¿Í»§¶Ë´úÀíÈí¼þ£¬ÄÚÖÃÔÚ΢ÈíµÄ²Ù×÷ϵͳÖС£Óû§Äܹ»Í¨¹ýRemote Desktop Client´ÓÏÕЩÈκδ¦ËùÏνӵ½Ô¶³ÌPC£¬²¢Äܹ»½Ó¼ûËùÓÐÀûÓ÷¨Ê½£¬ÎļþºÍÍøÂç×ÊÔ´¡£
ÔÚ9ÔÂ10ºÅ΢Èí°ä²¼µÄÔ¶Ȳ¹¶¡ÖУ¬°ä²¼ÁË4¸ö·çÏյȼ¶ÎªCriticalµÄRDP ¿Í»§¶Ë·ì϶µÄ°²È«²¹¶¡¡£Õâ´Î°ä²¼µÄ¼¸¸ö·ì϶·ÖÆçÓÚ2019Äê5Ô·ݵÄRDPºÍ̸×ÔÉíµÄ·ì϶CVE-2019-0708£¬¶øÊÇRDP¿Í»§¶Ë´úÂëµÄ·ì϶£¬ÀûÓöÔÏóºÍ·½Ê½¶¼ÓÐןܴóµÄ·ÖÆç¡£
·ì϶λÓÚRDP¿Í»§¶Ë´¦ÖÃͼÏñÊÓÆµÁ÷µÄ¹ý³ÌÖУ¬·ì϶²úÉúµÄÔÓÉÓÚ·¨Ê½Ô±ÔÚÍÆËãÒ»¶ÎÊý¾Ý°üµÄ³¤¶Èʱ·¸ÁËÒ»¸öÃýÎó×îÖÕµ¼ÖÂÔ½½ç¶ÁдµÄ¿ÉÔ¶³ÌÖ´Ðеķì϶£¬¸Ã·ì϶Äܹ»Ôì³É¿Í»§¶Ë±»Ô¶³ÌÖ÷»ú½ÚÔì¡£
ÒªÀûÓô˷ì϶£¬¹¥»÷Õß±ØÒª½ÚÔì·þÎñÆ÷£¬¶øºóʹÓû§Ïνӵ½¸Ã·þÎñÆ÷¡£µ«ÓÉÓÚ¹¥»÷ÕßÎÞ·¨Ç¿ÆÅ×û§Ïνӵ½¶ñÒâ·þÎñÆ÷£¬ËùÒÔ¿ÉÄܱØÒªÍ¨¹ý¶àÖÖ·½Ê½ºýŪÓû§Ïνӣ¬ÈçÀûÓÃÉç»á¹¤³Ìѧ¡¢DNSÖж¾»òʹÓÃÖÐÑëÈ˹¥»÷£¨MITM£©¡£¹¥»÷Õß»¹Äܹ»·ÛËéºÏ·¨·þÎñÆ÷£¬ÔÚÆäÉÏÍйܶñÒâ´úÂ룬²¢ÆÚ´ýÓû§Ïνӡ£ÕâÖÖ¹¥»÷·½Ê½µÄÓ°ÏìÁ¦¾Þ´ó£¬ÇÒÒ»µ©±»Ï°È¾£¬ºÜÓпÉÄÜÔì³É´óÁìÓòµÄÖ÷»úÂÙÏÝ¡£¸ÃÖÖ¹¥»÷·½Ê½¿É±»¹¥»÷ÕßÓÃÀ´¹¹½¨½©Ê¬ÍøÂç¡£
¡ñ·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
¡ñ½¨¸´½¨Òé
΢Èí¹Ù·½½¨ÒéÓû§¾¡¿ì×°ÖòÙ×÷ϵͳ²¹¶¡¡£
ÉèÖáú¸üкͰ²È«¡úWindows Update¡ú²é³×°ÖÃÍÆËã»úÉϵĸüС£
»òÕßÏÂÔØµØÖ·¼û²Î¿¼Á´½Ó£¬ÇëÏÂÔØ¶ÔÓ¦²¹¶¡×°Öðü£¬Ë«»÷ÔËÐм´¿É½øÐн¨¸´¡£
¡ñ²Î¿¼Á´½Ó
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2019-0787
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2019-0788
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2019-1290
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2019-1291


¾©¹«Íø°²±¸11010802024551ºÅ