WindowsÔ¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-10-10Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-1333£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Windows 10£»£»£»
Windows 7£»£»£»
Windows 8.1£»£»£»
Windows Server 2008 SP2,SP1£»£»£»
Windows Server 2012£»£»£»
Windows Server 2012 R2£»£»£»
Windows Server 2016£»£»£»
Windows Server 2019£»£»£»
Windows Server, version 1803
Windows Server, version 1903
Îó²î¸ÅÊö
Remote Desktop Protocol(Ô¶³Ì×ÀÃæÐÒ飬£¬£¬£¬£¬RDP)ÊÇ΢Èí¹«Ë¾½¨ÉèµÄרÓÐÐÒé¡£¡£¡£ËüÔÊÐíϵͳÓû§Í¨¹ýͼÐÎÓû§½çÃæÅþÁ¬µ½Ô¶³Ìϵͳ¡£¡£¡£ÔÚĬÈÏÇéÐÎÏ£¬£¬£¬£¬£¬¸ÃÐÒéµÄ¿Í»§¶ËÊðÀíÄÚÖÃÔÚ΢ÈíµÄ²Ù×÷ϵͳÖУ¬£¬£¬£¬£¬Ò²¿ÉÒÔ×°ÖÃÔÚ·Ç΢Èí²Ù×÷ϵͳÖС£¡£¡£RDPµÄЧÀÍÆ÷¶Ë×°ÖÃÔÚ΢Èí²Ù×÷ϵͳÖУ¬£¬£¬£¬£¬´Ó¿Í»§¶ËÊðÀíÎüÊÕÇëÇ󣬣¬£¬£¬£¬ÏÔʾÐû²¼Ó¦ÓóÌÐòµÄͼÐνçÃæ»òÕßÔ¶³Ì»á¼ûϵͳ×Ô¼º¡£¡£¡£Ä¬ÈÏÇéÐÎÏ£¬£¬£¬£¬£¬ÏµÍ³ÔÚ3389¶Ë¿ÚÀ´¼àÌýÀ´×Ô¿Í»§¶ËµÄͨ¹ýRDPµÄÅþÁ¬ÇëÇ󡣡£¡£
Remote Desktop ClientÊÇ΢Èí¿ª·¢µÄÓÃÓÚʵÏÖÔ¶³Ì×ÀÃæÐÒéµÄÒ»¸ö¿Í»§¶Ë²Ù×÷Èí¼þ¡£¡£¡£Óû§¿ÉÒÔʹÓÃMicrosoftÔ¶³Ì×ÀÃæ¿Í»§¶Ë´Óí§ÒâµØ·½ÅþÁ¬µ½Ô¶³ÌPCÖ÷»úºÍÊÂÇé×ÊÔ´£¬£¬£¬£¬£¬²¢¿ÉÒÔ»á¼ûËùÓÐÓ¦ÓóÌÐò£¬£¬£¬£¬£¬ÎļþºÍÍøÂç×ÊÔ´¡£¡£¡£
2019Äê10ÔÂ08ÈÕ£¬£¬£¬£¬£¬Î¢ÈíÀýÐÐÐû²¼ÁË10Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬£¬ÆäÖÐÐÞ¸´ÁËWindowsÔ¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-1333£©£¬£¬£¬£¬£¬µ±Óû§ÅþÁ¬µ½¶ñÒâЧÀÍÆ÷ʱ£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÅþÁ¬¿Í»§¶ËµÄÅÌËã»úÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¹¥»÷Õß¿ÉÄÜ»á×°ÖóÌÐò£¬£¬£¬£¬£¬Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£¬£¬£¬£¬£¬»òÕß½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕË»§¡£¡£¡£
ҪʹÓôËÎó²î£¬£¬£¬£¬£¬¹¥»÷ÕßÐèÒª¿ØÖÆÐ§ÀÍÆ÷£¬£¬£¬£¬£¬È»ºóÓÕʹÓû§ÅþÁ¬µ½¸ÃЧÀÍÆ÷¡£¡£¡£¹¥»÷ÕßÎÞ·¨Ç¿ÆÈÓû§ÅþÁ¬µ½¶ñÒâЧÀÍÆ÷£¬£¬£¬£¬£¬ËûÃÇÐèҪͨ¹ýÉç½»¹¤³Ì£¬£¬£¬£¬£¬DNSÖж¾»òʹÓÃÖÐÐÄÈËÊÖÒÕÓÕʹÓû§¾ÙÐÐÅþÁ¬¡£¡£¡£¹¥»÷Õß»¹¿ÉÄÜÆÆËðÕýµ±Ð§ÀÍÆ÷£¬£¬£¬£¬£¬ÔÚÆäÉÏÍйܶñÒâ´úÂ룬£¬£¬£¬£¬È»ºóÆÚ´ýÓû§ÅþÁ¬¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£
ÐÞ¸´½¨Òé
΢Èí¹Ù·½ÒÑ¾ÍÆ³öÇå¾²¸üУ¬£¬£¬£¬£¬Çë²Î¿¼ÒÔϹٷ½Ç徲ͨ¸æÏÂÔØ²¢×°ÖÃ×îв¹¶¡£¡£¡£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1333
²Î¿¼Á´½Ó
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1333