¡¾Îó²îͨ¸æ¡¿SolarWinds Serv-U Ô¶³Ì´úÂëÖ´ÐÐ0 dayÎó²î£¨CVE-2021-35211£©
Ðû²¼Ê±¼ä 2021-07-130x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-35211 | ʱ ¼ä | 2021-07-13 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | < 15.2.3 HF2 |
¹¥»÷ÖØÆ¯ºó | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | ÔÚҰʹÓà | ÊÇ |
0x01 Îó²îÏêÇé
2021Äê7ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬£¬SolarWindsÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬MicrosoftÔÚÆäServ-U²úÆ·Öз¢Ã÷ÁËÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐ0 dayÎó²î£¨CVE-2021-35211£©£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÒÔÌØÊâȨÏÞÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬£¬È»ºóÔÚÊÜÓ°ÏìµÄϵͳÉÏ×°Öò¢ÔËÐгÌÐò¡¢Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾ÝµÈ¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃÎó²îÒѾ·ºÆðÔÚҰʹÓᣡ£¡£¡£¡£
¸ÃÎó²î½ö±£´æÓÚSolarWinds Serv-U Managed File TransferºÍServ-U Secure FTPÖУ¬£¬£¬£¬£¬£¬£¬ÆäËü SolarWinds ²úÆ·²»ÊÜÓ°Ï죬£¬£¬£¬£¬£¬£¬²»Ê¹Óà Serv-U µÄ N-able ¿Í»§Ò²²»ÊÜ´ËÎó²îµÄÓ°Ïì¡£¡£¡£¡£¡£µ«ÐèÒª×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬£¬Serv-U GatewayÊÇÕâÁ½¸ö²úÆ·µÄÒ»¸ö×é¼þ£¬£¬£¬£¬£¬£¬£¬¶ø²»ÊÇÒ»¸öµ¥¶ÀµÄ²úÆ·¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬£¬¾ÝSolarWindsÌåÏÖ£¬£¬£¬£¬£¬£¬£¬ÈôÊÇServ-U ÇéÐÎÖÐδÆôÓà SSH£¬£¬£¬£¬£¬£¬£¬Ôò¸ÃÎó²î²»±£´æ¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
Serv-U °æ±¾ < 15.2.3 HF2
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ´ËÎó²îÒÑÔÚ2021 Äê 7 Ô 9 ÈÕÐû²¼µÄServ-U 15.2.3 HF2ÖÐÐÞ¸´£¬£¬£¬£¬£¬£¬£¬½¨ÒéËùÓÐÊÜÓ°ÏìµÄServ-U ¿Í»§²Î¿¼ÒÔÏ·½·¨ÊµÊ±Éý¼¶¸üУº
Serv-U 15.2.3 HF1°æ±¾£ºÖ±½ÓÉý¼¶¸üÐÂÖÁServ-U 15.2.3 HF2 £»£»£»£»£»
Serv-U 15.2.3°æ±¾£ºÏÈÉý¼¶¸üÐÂÖÁServ-U 15.2.3 HF1 £¬£¬£¬£¬£¬£¬£¬È»ºóÔÙÉý¼¶¸üÐÂÖÁServ-U 15.2.3 HF2 £»£»£»£»£»
15.2.3 ֮ǰµÄËùÓÐServ-U °æ±¾£ºÏÈÉý¼¶¸üÐÂÖÁServ-U 15.2.3 £¬£¬£¬£¬£¬£¬£¬ÔÙÉý¼¶¸üÐÂÖÁServ-U 15.2.3 HF1 £¬£¬£¬£¬£¬£¬£¬È»ºóÔÙÉý¼¶¸üÐÂÖÁ Serv-U 15.2.3 HF2 ¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://www.serv-u.com/
0x03 ²Î¿¼Á´½Ó
https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35211
https://www.bleepingcomputer.com/news/security/solarwinds-patches-critical-serv-u-vulnerability-exploited-in-the-wild/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35211
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-07-13 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD¹ÙÍø£ºwww.cnvd.org.cn
CNNVD¹ÙÍø£ºwww.cnnvd.org.cn
CVE¹ÙÍø£ºcve.mitre.org
NVD¹ÙÍø£ºnvd.nist.gov
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºwww.first.org
0x06 ¹ØÓÚ¼øºÚµ£±£Íø
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º