Windows PowerShellÔ¶³Ì´úÂëÖ´Ðзì϶

°ä²¼¹¦·ò 2021-07-04

0x00 ·ì϶¸ÅÊö

CVE     ID


ʱ      ¼ä

2021-07-04

Àà      ÐÍ

RCE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP


ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

 

PowerShellÌṩÁËÒ»¸öºÅÁîÐÐshell¡¢Ò»¸ö¿ò¼ÜºÍÒ»Ö־籾˵»°£¬×¨Ò»ÓÚ´¦Öà PowerShell cmdlet µÄ×Ô¶¯»¯¡£ËüÄܹ»ÔÚ Windows¡¢Linux ºÍ macOSµÈƽ̨ÉÏÔËÐУ¬²¢ÇÒÔÊÐí´¦Öýṹ»¯Êý¾Ý£¬ÀýÈç JSON¡¢CSV ºÍ XML£¬ÒÔ¼° REST API ºÍ¶ÔÏóÄ£ÐÍ¡£

½üÈÕ£¬Microsoft ÖÒ¸æ PowerShell 7 ÖÐÑϳÁµÄ .NET Core Ô¶³Ì´úÂëÖ´Ðзì϶£¬Ô­ÒòÔÚÓÚ.NET 5 ºÍ .NET Core ÖеÄÎı¾±àÂ뷽ʽ¡£Microsoft¶½´Ù¿Í»§¾¡¿ì×°ÖÃPowerShell 7.0.6 ºÍ 7.1.3 ¡£

MicrosoftÔÚ4 Ô·Ýʱ°µÊ¾£¬Ò×Êܹ¥»÷µÄ°üÊÇSystem.Text.Encodings.Web£¬ÈκÎʹÓÃÏÂÃæÁгöµÄ System.Text.Encodings.Web °ü°æ±¾µÄ»ùÓÚ .NET 5¡¢.NET Core »ò .NET Framework µÄÀûÓ÷¨Ê½¶¼ÈÝÒ×Êܵ½¹¥»÷£º

°üÃû³Æ

Ò×Êܹ¥»÷µÄ°æ±¾

½¨¸´°æ±¾

System.Text.Encodings.Web

4.0.0 -   4.5.0

4.5.1

System.Text.Encodings.Web

4.6.0-4.7.1

4.7.2

System.Text.Encodings.Web

5.0.0

5.0.1

 

ƾ¾ÝMicrosoftµÄ×îа²È«²¼¸æ£¬¹ÌÈ» Visual Studio Ò²Ô̺¬ .NET µÄ¶þ½øÔìÎļþ£¬µ«Ëü²»Êܵ½´Ë·ì϶µÄÓ°Ïì¡£´Ë±í£¬Microsoft°ä·¢£¬Ëü½«Í¨¹ý Microsoft Update ·þÎñ°ä²¼Ö®ºóµÄ¸üУ¬ÒÔ±ã¸üÇáËɵظüÐÂWindows 10 ºÍ Windows Server ÉϵÄPowerShell¡£

 

Ó°ÏìÁìÓò

PowerShell < 7.0.6

PowerShell < 7.1.3

PowerShell 5.1²»ÊÜ´Ë·ì϶µÄÓ°Ïì¡£

0x02 ´ëÖý¨Òé

Microsoft°µÊ¾Ä¿Ç°´Ë·ìϼû»ÓпÉÓõĻº½â´ëÊ©£¬½¨Ò龡¿ì×°Öøüе½ PowerShell 7.0.6 ºÍ 7.1.3 °æ±¾¡£

Ҫͨ¹ý Microsoft Update ¸üРPowerShell£º

 ¡°ÆðÍ·¡± > ¡°ÉèÖá± >¡°¸üкͰ²È«¡±>¡°Windows ¸üС±£¬¶øºóµ¥»÷¡°²é³­¸üС±¡£

ÏÂÔØÁ´½Ó£º

https://azure.microsoft.com/en-us/updates/update-powershell-versions-70-and-71-to-protect-against-a-vulnerability/

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26701

https://azure.microsoft.com/en-us/updates/update-powershell-versions-70-and-71-to-protect-against-a-vulnerability/

https://www.bleepingcomputer.com/news/security/microsoft-warns-of-critical-powershell-7-code-execution-vulnerability/?

 

0x04 ¹¦·òÏß

2021-07-01  Microsoft°²È«¸üÐÂ

2021-07-04  VSRC°²È«¹«¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png