¡¾Îó²îͨ¸æ¡¿CVE-2020-0601 | Windows CryptoAPIÓÕÆ­Îó²î

Ðû²¼Ê±¼ä 2020-01-16



¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


1.Åä¾°ÐÎò


1ÔÂ14ÈÕ΢ÈíÔÚÀýÐеÄÖܶþ²¹¶¡¸üÐÂÖÐÐÞ¸´ÁËÒ»¸öWindows CryptoAPIÓÕÆ­Îó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²î£¨CVE-2020-0601£©ÊÇWindows CryptoAPI£¨Crypt32.dll£©ÔÚÑéÖ¤ÍÖÔ²ÇúÏß¼ÓÃÜËã·¨£¨ECC£©Ö¤ÊéÀú³ÌÖеÄÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓøÃÎó²îαÔìÊý×ÖÖ¤Êé»òÌᳫÖÐÐÄÈ˹¥»÷¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉNSA·¢Ã÷ºÍ±¨¸æµÄ£¬£¬£¬£¬£¬£¬NSAÍøÂçÇå¾²×ܼàAnne NeubergerÌåÏÖ£¬£¬£¬£¬£¬£¬ÕâÊǸûú¹¹Ê״ξöÒéÏòÈí¼þ¹©Ó¦É̹ûÕæÅû¶Çå¾²Îó²î¡£¡£¡£¡£¡£¡£


2.Ó°Ïì¹æÄ£


Windows 10

Windows Server2016

Windows Server 2019


3.Îó²îÏêÇé


¸ÃÎó²î±»¸ú×ÙΪCVE-2020-0601£¬£¬£¬£¬£¬£¬Ó°ÏìÁËWindows CryptoAPI£¬£¬£¬£¬£¬£¬ºóÕßÊÇWindows²Ù×÷ϵͳ´¦Öóͷ£ÃÜÂë²Ù×÷µÄ½¹µã×é¼þ¡£¡£¡£¡£¡£¡£Æ¾Ö¤Î¢ÈíÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬ Windows CryptoAPI£¨Crypt32.dll£©ÑéÖ¤ÍÖÔ²ÇúÏß¼ÓÃÜËã·¨£¨ECC£©Ö¤ÊéµÄ·½·¨Öб£´æÒ»¸öÓÕÆ­Îó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î¶Ô¶ñÒâ¿ÉÖ´ÐÐÎļþ¾ÙÐÐÊðÃû£¬£¬£¬£¬£¬£¬Ê¹¸ÃÎļþ¿´ÆðÀ´ÏñÊÇÀ´×ÔÊÜÐÅÈεÄÕýµ±ÈªÔ´¡£¡£¡£¡£¡£¡£³ýÁËαÔìÎļþÊðÃûÖ®Í⣬£¬£¬£¬£¬£¬¸ÃÎó²î»¹¿ÉÒÔÓÃÓÚαÔìÓÃÓÚ¼ÓÃÜͨѶµÄÊý×ÖÖ¤Êé¡£¡£¡£¡£¡£¡£Î¢ÈíÌåÏÖ£¬£¬£¬£¬£¬£¬ÀֳɵÄʹÓû¹¿ÉÒÔʹ¹¥»÷Õß¾ÙÐÐÖÐÐÄÈ˹¥»÷£¬£¬£¬£¬£¬£¬²¢ÔÚÓëÊÜÓ°ÏìÈí¼þµÄÓû§ÅþÁ¬ÉϽâÃÜÉñÃØÐÅÏ¢¡£¡£¡£¡£¡£¡£¡±


ƾ֤NSAµÄ˵·¨£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²î½«ÔÊÐí¹¥»÷Õßת´ïÀ´×Ô¿ÉÐÅʵÌåµÄ¶ñÒâ´úÂ룬£¬£¬£¬£¬£¬²¢ÆÊÎöÖ¸³öÁËһЩÐÅÈÎÑéÖ¤»áÊܵ½Ó°ÏìµÄÀý×Ó£º


           HTTPsÅþÁ¬

           ÊðÃûÎļþºÍµç×ÓÓʼþ

           ×÷ΪÓû§Ä£Ê½Àú³ÌÆô¶¯µÄÊðÃû¿ÉÖ´ÐдúÂë


ÖµµÃ×¢ÖØµÄÊÇÖ¸¶¨²ÎÊýµÄ ECC ÃÜÔ¿Ö¤ÊéµÄ Windows °æ±¾»áÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬¶øÕâÒ»»úÖÆ£¬£¬£¬£¬£¬£¬×îÔçÓÉ WIN10 ÒýÈ룬£¬£¬£¬£¬£¬Ó°Ïì WIN10£¬£¬£¬£¬£¬£¬Windows Server 2016/2019 °æ±¾£¬£¬£¬£¬£¬£¬¶øÓÚ½ñÄê 1 Ô 14 ÈÕ×èÖ¹Ç徲ά»¤µÄ WIN7/Windows Server 2008 ÓÉÓÚ²»Ö§³Ö´ø²ÎÊýµÄ ECC ÃÜÔ¿£¬£¬£¬£¬£¬£¬Òò´Ë²»ÊÜÏà¹ØÓ°Ï죬£¬£¬£¬£¬£¬µ«ÈÔÈ»½¨ÒéÓû§½« WIN7/ Windows Server 2008 ϵͳ¸üÐÂÖÁ×îÐ嵀 WIN10 ϵͳ»ò Windows Server2016 Ö®ºóµÄ°æ±¾£¬£¬£¬£¬£¬£¬²¢¸üÐÂÏà¹ØÇå¾²²¹¶¡¡£¡£¡£¡£¡£¡£


΢ÈíºÍÃÀ¹úNSAÌåÏÖ£¬£¬£¬£¬£¬£¬ÔÚ²¹¶¡Ðû²¼Ö®Ç°»¹Ã»Óз¢Ã÷ÈκÎ×Ô¶¯Ê¹ÓôËÎó²îµÄ¹¥»÷¡£¡£¡£¡£¡£¡£NSAÔÚ14ÈÕÍíЩʱ¼äÐû²¼ÁË×Ô¼ºµÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨»º½âÐÅÏ¢ÒÔ¼°ÔõÑù¼ì²âÎó²îʹÓ㬣¬£¬£¬£¬£¬»¹±Þ²ßITÔ±¹¤¾¡¿ì×°ÖÃÖܶþÇå¾²¸üС£¡£¡£¡£¡£¡£ÁìÍÁÇå¾²²¿ÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨DHS CISA£©Ò²Ðû²¼Á˽ôÆÈÖ¸Á£¬£¬£¬£¬£¬ÌáÐÑÃÀ¹ú˽Ӫ²¿·ÖºÍÕþ¸®ÊµÌåÐèҪװÖÃ×îÐÂWindowsÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£¡£


4.ÐÞ¸´½¨Òé


½¨Òé¸üÐÂWindowsÇå¾²²¹¶¡


5.²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601

https://media.defense.gov/2020/Jan/14/2002234275/-1/-1/0/CSA-WINDOWS-10-CRYPT-LIB-20190114.PDF

https://cyber.dhs.gov/ed/20-02/