΢ÈíRDPÔ¶³Ì×ÀÃæÐ§ÀͶà¸öRCEÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-14

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1181£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1182£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1222£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬CVSS·ÖÖµ£º9.8
CVE±àºÅ£ºCVE-2019-1226£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Windows 7 SP1¡¢Windows Server 2008 R2 SP1¡¢ Windows Server 2012¡¢Windows 8.1¡¢Windows Server 2012 R2ºÍËùÓÐÊÜÖ§³ÖµÄ°üÀ¨Ð§ÀÍÆ÷°æ±¾ÔÚÄÚµÄWindows 10 °æ±¾


²»ÊÜÓ°ÏìµÄ°æ±¾


Windows XP¡¢Windows Server 2003ºÍ Windows Server 2008 ¾ù²»ÊÜÓ°Ï죬£¬£¬ÒÔ¼°Ô¶³Ì×ÀÃæÐ­Òé (RDP) ×Ô¼º²¢²»ÊÜÓ°Ïì


Îó²î¸ÅÊö


΢ÈíÐÇÆÚ¶þÐû²¼ÁËÀýÐв¹¶¡ÐÞ¸´¼Æ»®£¬£¬£¬ÆäÖаüÀ¨4¸öÑÏÖØµÄÔ¶³Ì×ÀÃæÐ§ÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâÌØÊâµÄRDPÇëÇó´¥·¢Îó²î£¬£¬£¬»ñÈ¡ÔÚÄ¿µÄϵͳÉϵÄÔ¶³Ì´úÂëÖ´ÐÐȨÏÞ¡£¡£¡£¡£¡£¡£´Ó΢Èíͨ¸æÖÐÀ´¿´£¬£¬£¬¸ÃÎó²îΪԤÉí·ÝÑéÖ¤£¬£¬£¬¼´ÎÞÐèÓû§½»»¥£¬£¬£¬ÕâÒâζןÃÎó²îÓпÉÄܱ»È䳿ËùʹÓᣡ£¡£¡£¡£¡£


ÏÖÔÚÍøÂçÉÏ¿ª·ÅRDPЧÀ͵ÄЧÀÍÆ÷ÊýÄ¿ÖØ´ó£¬£¬£¬Ó°ÏìÃæ¼«´ó¡£¡£¡£¡£¡£¡£


΢Èí»¹Ðû²¼ÁËÕë¶ÔCVE-2019-1181/CVE-2019-1182ÆôÓÃÁËÍøÂç¼¶±ðÈÏÖ¤ (NLA) ¹¦Ð§µÄÊÜÓ°ÏìϵͳµÄ»º½â²½·¥¡£¡£¡£¡£¡£¡£ÓÉÓÚÎó²î±»´¥·¢Ç°£¬£¬£¬NLA ÒªÇó¾ÙÐÐÈÏÖ¤£¬£¬£¬Òò´ËÊÜÓ°Ïìϵͳ»º½âÁËÄܹ»Ê¹ÓøÃÎó²îµÄ¡°È䳿¼¶¡±¶ñÒâÈí¼þ»ò¸ß½×µÄ¶ñÒâÈí¼þÍþв¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬ÈôÊǹ¥»÷Õß¾ßÓÐÄܹ»±»ÓÃÓÚ¾ÙÐÐÈÏÖ¤µÄÕýµ±Æ¾Ö¤£¬£¬£¬Òò´ËÊÜÓ°ÏìϵͳÈÔÈ»Ò×ÊÜÔ¶³Ì´úÂëÖ´ÐÐʹÓõĹ¥»÷¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ£¬£¬£¬Î¢Èí¹Ù·½ÒѾ­Ðû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬½¨ÒéÓû§¾¡¿ì½ÓÄÉÐÞ²¹²½·¥£¬£¬£¬ÒÔ×èֹDZÔÚµÄÇå¾²Íþв¡£¡£¡£¡£¡£¡£ÏëÒª¾ÙÐиüУ¬£¬£¬Ö»Ðèתµ½ÉèÖáú¸üкÍÇå¾²¡úWindows ¸üСú¼ì²é¸üУ¬£¬£¬»òÕßÒ²¿ÉÒÔͨ¹ýÊÖ¶¯¾ÙÐиüС£¡£¡£¡£¡£¡£


»º½â²½·¥£¬£¬£¬Õë¶ÔCVE-2019-1181/CVE-2019-1182£º


1. ÔÚϵͳÉÏÆôÓÃÍøÂç¼°Éí·ÝÈÏÖ¤£¨NLA£©ÒÔÔÝʱ¹æ±Ü¸ÃÎó²îÓ°Ïì


2. ÔÚÆóÒµÍâΧ·À»ðǽ×è¶ÏTCP¶Ë¿Ú3389µÄÁ´½Ó


3. ÈçÎÞÐèÇ󣬣¬£¬¿É½ûÓÃÏà¹ØÔ¶³Ì×ÀÃæÐ§ÀÍ


²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1181
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1182
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1222
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1226