SolarWinds Orion¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-02-04

0x00 Îó²î¸ÅÊö

È¥Ä꣬£¬£¬£¬£¬£¬SolarWinds¹©Ó¦Á´¹¥»÷ÊÂÎñÒý·¢È«Çò¹Ø×¢¡£¡£¡£

2021Äê02ÔÂ03ÈÕ£¬£¬£¬£¬£¬£¬SolarWinds Orionƽ̨ºÍSolarWinds Serv-U FTPЧÀÍÆ÷±»Åû¶±£´æ¶à¸öÇå¾²Îó²î¡£¡£¡£SolarWinds Orionƽ̨¹©Ó¦Á´¹¥»÷ÊÂÎñÖÐûÓÐʹÓÃÕâЩÎó²î¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬Ïà¹ØÎó²îÒѾ­ËùÓÐÐÞ¸´£¬£¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬ÕâЩÎó²îµÄPoC½«ÓÚ02ÔÂ09ÈÕÐû²¼¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

 

±¾´ÎÅû¶µÄÎó²îÈçÏ£º

²úÆ·

CVE

ÀàÐÍ

ÆÀ¼¶

SolarWinds   Orionƽ̨

CVE-2021-25274

RCE

¸ßΣ

CVE-2021-25275

ÐÅϢй¶

ÖÐΣ

SolarWinds   Serv-U FTPЧÀÍÆ÷

CVE-2021-25276

»á¼û¿ØÖƲ»µ±

ÖÐΣ

 

SolarWinds OrionÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-25274£©

SolarWinds Collector Service ʹÓà MSMQ£¨MicrosoftÐÂÎÅÐÐÁУ©£¬£¬£¬£¬£¬£¬µ«²¢ÇÒδÔÚÆäרÓÃÐÐÁÐÉÏÉèÖÃȨÏÞ£¬£¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýTCP¶Ë¿Ú1801½«¶ñÒâÐÂÎÅ·¢Ë͵½ÐÐÁУ¬£¬£¬£¬£¬£¬ÔÚ´¦Öóͷ£´ËÀàÐÂÎÅʱ£¬£¬£¬£¬£¬£¬ÍøÂçÆ÷ЧÀͽ«ÒÔ²»Çå¾²µÄ·½·¨·´ÐòÁл¯ËüÃÇ£¬£¬£¬£¬£¬£¬´Ó¶øÔÊÐíÔ¶³Ì¹¥»÷ÕßÒÔLocalSystemµÄ·½·¨Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂЧÀÍÆ÷±»ÍêÈ«¿ØÖÆ¡£¡£¡£

image.png

SolarWindsͨ¹ýÔÚÐÂÐÂÎŵִïʱÌí¼ÓÊý×ÖÊðÃûÑéÖ¤À´ÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬£¬£¬ÔÚûÓÐÓÐÓõÄÊðÃûµÄÇéÐÎϽ«²»ÔÙ´¦Öóͷ£ÐÂÎÅ£¬£¬£¬£¬£¬£¬µ«MSMQÈÔÈ»ÊÇδ¾­Éí·ÝÑéÖ¤µÄ£¬£¬£¬£¬£¬£¬¿ÉÒÔÎüÊÕÀ´×ÔÈκÎÈ˵ÄÐÂÎÅ¡£¡£¡£

 

SolarWinds OrionÃô¸ÐÐÅϢй¶Îó²î£¨CVE-2021-25275£©

SolarWinds Orionºó¶ËÊý¾Ý¿âSOLARWINDS_ORIONÖеĴ洢ƾ֤±»·ÅÔÚÒ»¸ö·ÇÖÎÀíÔ±Óû§¿É¶ÁµÄÎļþÖУ¬£¬£¬£¬£¬£¬µ¼ÖÂÈκοÉÒÔ»á¼ûÎļþϵͳµÄÓû§¶¼¿ÉÒÔ´Ó¸ÃϵͳÖжÁÈ¡OrionÊý¾Ý¿âµÄµÇ¼ÐÅÏ¢£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉʹÓÃÆ¾Ö¤À´»ñµÃOrionÊý¾Ý¿âµÄËùÓÐÕßȨÏÞ¡£¡£¡£

image.png

 

SolarWinds Serv-U FTP £¨Windows£©»á¼û¿ØÖƲ»µ±Îó²î£¨CVE-2021-25276£©

¸ÃÎó²î±£´æÓÚWindowsµÄSolarWinds Serv-U FTPЧÀÍÆ÷ÖУ¬£¬£¬£¬£¬£¬ÈκοÉÒÔÍâµØµÇ¼»òͨ¹ýÔ¶³Ì×ÀÃæµÇ¼ϵͳµÄ¹¥»÷Õß¶¼¿ÉÒÔͨ¹ýʹÓôËÎó²îÀ´µÇ¼FTP£¬£¬£¬£¬£¬£¬×îÖÕ¶ÁÈ¡»òÌæ»»CÅÌÉϵÄÈκÎÎļþ¡£¡£¡£

 

Ó°Ïì¹æÄ£

SolarWinds Orion < 2020.2.4

SolarWinds ServU-FTP < 15.2.2 Hotfix 1

 

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÏà¹ØÎó²îÒѱ»ÐÞ¸´£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁ×îа汾¡£¡£¡£

SolarWinds Orion Platform 2020.2.4

SolarWinds ServU-FTP 15.2.2 Hotfix 1

ÏÂÔØÁ´½Ó£º

https://documentation.solarwinds.com/en/Success_Center/orionplatform/content/release_notes/orion_platform_2020-2-4_release_notes.htm

https://downloads.solarwinds.com/solarwinds/Release/HotFix/Serv-U-15.2.2-Hotfix-1.zip

 

0x03 ²Î¿¼Á´½Ó

https://www.bleepingcomputer.com/news/security/solarwinds-patches-critical-vulnerabilities-in-the-orion-platform/

https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=28389

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25274

 

0x04 ʱ¼äÏß

2021-02-03  Trustwave SpiderLabsÅû¶Îó²î

2021-02-04  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png