΢ÈíSMB3ÐÒéÔ¶³ÌʹÓÃ0dayÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-03-11Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-0796£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Windows 10 Version 1903 for 32-bit Systems
Windows 10 Version 1903 for x64-based Systems
Windows 10 Version 1903 for ARM64-based Systems
Windows Server, version 1903 (Server Core installation)
Windows 10 Version 1909 for 32-bit Systems
Windows 10 Version 1909 for x64-based Systems
Windows 10 Version 1909 for ARM64-based Systems
Windows Server, version 1909 (Server Core installation)
Îó²î¸ÅÊö
CVE-2020-0796 ÊDZ£´æÓÚ΢ÈíЧÀÍÆ÷SMBÐÒéÖеÄÒ»¸ö¡°È䳿»¯¡±Îó²î£¬£¬£¬£¬¸ÃÎó²îδ°üÀ¨ÔÚ΢Èí±¾ÔÂÐû²¼µÄ²¹¶¡ÖУ¬£¬£¬£¬ÊÇÔÚ²¹¶¡µÄÐòÑÔÖÐй¶µÄ¡£¡£¡£ÏÖÔÚ΢ÈíÉÐδÐû²¼ÈκÎÊÖÒÕÏêÇ飬£¬£¬£¬Ë¼¿Æ Talos ÍÅ¶ÓºÍ Fortinet ¹«Ë¾ÌṩÁ˼ò¶Ì¸ÅÊö£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎú¸ÃÎó²îµÄ²¹¶¡ºÎʱÐû²¼¡£¡£¡£
Fortinet ¹«Ë¾Ö¸³ö£¬£¬£¬£¬¸ÃÎó²îÊÇ¡°Î¢Èí SMB ЧÀÍÆ÷ÖеÄÒ»¸ö»º³åÇøÒç³öÎó²î¡±£¬£¬£¬£¬ÑÏÖØÆ·¼¶Îª×î¸ßÆÀ·Ö£¬£¬£¬£¬¡°¸ÃÎó²îÓÉÒ×Êܹ¥»÷µÄÈí¼þ¹ýʧµØ´¦Öóͷ£¶ñÒâ½á¹¹µÄѹËõÊý¾Ý°ü¶ø´¥·¢¡£¡£¡£Ô¶³Ì¡¢Î´¾ÈÏÖ¤µÄ¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚ¸ÃÓ¦ÓóÌÐòµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡±
˼¿Æ Talos ²©¿ÍÎÄÕÂÒ²¸ø³öÁËÀàËÆÐÎò£¬£¬£¬£¬²»¹ýËæºó½«Æäɾ³ý¡£¡£¡£Ë¼¿ÆÖ¸³ö£¬£¬£¬£¬¡°Ê¹ÓøÃÎó²î¿Éµ¼ÖÂϵͳÔâÈ䳿¹¥»÷£¬£¬£¬£¬Ò²¾ÍÊÇ˵Îó²î¿ÉÈÝÒ×µØÔÚÊܺ¦ÕßÖ®¼äÈö²¥¡£¡£¡£¡±
Îó²îÑéÖ¤
ÔÝÎÞPoC/EXP¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ΢ÈíûÓÐÐû²¼Îó²îÏêÇé¼°²¹¶¡¡£¡£¡£
»º½â²½·¥£º
1. ½ûÓÃSMbv3 compression¡£¡£¡£½ûÓÃSMbv3 compression ¿ÉÒÔÔÚSMBv3 ServerµÄPowershellÖÐÖ´ÐÐÈçÏ´úÂë
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 1 -Force
¾ÙÐиü¸Äºó£¬£¬£¬£¬ÎÞÐèÖØÐÂÆô¶¯¡£¡£¡£´Ë½â¾öÒªÁì²»¿É±ÜÃâʹÓÃSMB¿Í»§¶Ë¡£¡£¡££»£»£»£»£»£»£»
2. ÈôÎÞÓªÒµÐëÒª£¬£¬£¬£¬ÔÚÍøÂçÇå¾²Óò½çÏß·À»ðǽ·â¶ÂÎļþ´òÓ¡ºÍ¹²Ïí¶Ë¿Ú£¨tcp:135/139/445£©£»£»£»£»£»£»£»
3. ×°ÖÃɱ¶¾Èí¼þ£¬£¬£¬£¬²»ÎüÊպ͵ã»÷ȪԴ²»Ã÷µÄÎļþ¡¢Óʼþ¸½¼þ£¬£¬£¬£¬²¢×öºÃÊý¾Ý±¸·ÝÊÂÇ飬£¬£¬£¬±ÜÃâѬȾÀÕË÷²¡¶¾¡£¡£¡£
²Î¿¼Á´½Ó
https://fortiguard.com/encyclopedia/ips/48773