Microsoft ExchangeÄÚ´æÆÆËðÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-08-15

Îó²î±àºÅºÍ¼¶±ð


CVE-2018-8302£¬£¬£¬£¬ÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 23
Microsoft Exchange Server 2013 Cumulative Update 20
Microsoft Exchange Server 2013 Cumulative Update 21
Microsoft Exchange Server 2016 Cumulative Update 10
Microsoft Exchange Server 2016 Cumulative Update 9


Îó²î¸ÅÊö


Îó²îµÄÔ´ÓÚÊÕ¼þÏäÎļþ¼ÐÊôÐÔ»á¼ûµÄTopNWords.Data¡£¡£¡£¡£¡£¡£¡£ÕâЩÊý¾Ý´æ´¢ÔÚExchangeЧÀÍÆ÷ÉÏ£¬£¬£¬£¬²¢ÇÒÊÇÒ»¸ö¹«¹²ÊôÐÔ£¬£¬£¬£¬Óû§¿ÉÒÔͨ¹ýExchange Web Services (EWS)¸ü¸ÄËü¡£¡£¡£¡£¡£¡£¡£Exchange Web Services ÊÇÒ»×é¿Í»§¶ËÓë Exchange ЧÀÍÆ÷ͨѶµÄ½Ó¿Ú¡£¡£¡£¡£¡£¡£¡£ 
µ±ÊÕµ½ÓïÒôÓʼþʱ£¬£¬£¬£¬Exchange»áÊÔͼ½«Æäת»»³ÉÎı¾£¬£¬£¬£¬ÏÔʾÔÚÊÕ¼þÈ˵ÄÊÕ¼þÏäÖС£¡£¡£¡£¡£¡£¡£ÔÚUnified Messaging(UM)ĬÈÏÆôÓõÄÇéÐÎÏ£¬£¬£¬£¬×ªÂ¼»á×Ô¶¯¾ÙÐС£¡£¡£¡£¡£¡£¡£Exchange»á¶ÁÈ¡TopNWords.DataµÄÊôÐÔÀ´ÉèÖÃÓû§µÄÊÕ¼þÏ䣬£¬£¬£¬²¢Ê¹ÓÃ.NET BinaryFormatter¶ÔÆä¾ÙÐз´ÐòÁл¯£¬£¬£¬£¬ÒÔ»ñµÃÎı¾µ½ÓïÒôµÄ×é¼þ¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


 Ê¹ÓôËÎó²îµÄÌõ¼þ£º


1.ExchangeЧÀÍÆ÷Ð轫Unified Messaging (UM)ÉèÖÃΪÆôÓÃ״̬£»£»£»


2.¹¥»÷ÕßÐèÒªÒ»¸öʹÓÃUMÓïÒôÓÊÏäÉèÖõÄÓÊÏäÕÊ»§¡£¡£¡£¡£¡£¡£¡£
 ¹¥»÷ÕßʹÓÃExchangeЧÀͽ«.NETÐòÁл¯µÄpayloadÉÏ´«ÖÁЧÀÍÆ÷ÖÐ,ͬʱʹÓÃÍøÂç´¹ÂÚ·½·¨ÓÕʹÆäËûÕ˺ŵÄʹÓÃÕß·­¿ªÓïÒôÓʼþ£¬£¬£¬£¬×îÖÕÒÔϵͳ¼¶È¨ÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£


º£ÄÚµÄÊÜÓ°Ïì×ʲúÂþÑÜÇéÐÎ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÐÞ¸´½¨Òé


Microsoft ¹Ù·½ÒѾ­ÔÚ8Ô·ݵÄÒªº¦Çå¾²²¹¶¡¸üÐÂÖÐÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬ÇëÊÜÓ°ÏìÓû§ÊµÊ±Ç°ÍùÏÂÔØ¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2018-8302
https://www.symantec.com/security-center/vulnerabilities/writeup/104973?om_rssid=sr-advisories