SMBv3¡°È䳿¼¶¡±Îó²îÀ´Ï® ¼øºÚµ£±£ÍøÌṩ½â¾ö¼Æ»®£¡
Ðû²¼Ê±¼ä 2020-03-123ÔÂ10ÈÕ£¬£¬£¬£¬Î¢ÈíÐû²¼Ç徲ͨ¸æ£¨ADV200005£©³ÆÔÚMicrosoft Server Message Block 3.1.1 £¨SMBv3£©ÐÒéÖб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2020-0796£¬£¬£¬£¬Óֳơ°CoronaBlue¡±»ò¡°SMB Ghost¡±)¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉSMBv3ÐÒé´¦Öóͷ£¶ñÒâѹËõÊý¾Ý°üʱ½øÈë¹ýʧÁ÷³ÌÔì³ÉµÄ£¬£¬£¬£¬Ô¶³Ìδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÔì³ÉÄ¿µÄÖ÷»úϵͳÍ߽⡢À¶ÆÁÉõÖÁÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
ÓÉÓÚ¸ÃÎó²î¿ÉÒÔÖ±½ÓÓÃÓÚÔ¶³Ì¹¥»÷£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔ¡°È䳿»¯¡±£¬£¬£¬£¬Òò´Ë£¬£¬£¬£¬ÆäΣº¦Ë®Æ½ÀàËÆÓÚ2017ÄêµÄ¡°ÓÀºãÖ®À¶¡±Îó²î¡£¡£¡£¡£¡£¡£µ«Ïà½ÏÓÚ¡°ÓÀºãÖ®À¶¡±£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìµÄ¹æÄ£Ïà¶Ô½ÏС£¬£¬£¬£¬Ö»ÏÞÓÚWindows10ÒÔ¼°Windows Server µÄ1903ºÍ1909°æ±¾£¬£¬£¬£¬ÏêϸӰÏìµÄ°æ±¾ºÅÈçÏ£º
Windows 10 Version 1903 for 32-bit Systems
Windows 10 Version 1903 for ARM64-based Systems
Windows 10 Version 1903 for x64-based Systems
Windows 10 Version 1909 for 32-bit Systems
Windows 10 Version 1909 for ARM64-based Systems
Windows 10 Version 1909 for x64-based Systems
Windows Server, version 1903 (Server Core installation)
Windows Server, version 1909 (Server Core installation)
¼øºÚµ£±£Íø½â¾ö¼Æ»®
Ò»¡¢ ½ûÓÃSMBv3ѹËõ
ËäÈ»±¾Îó²îÓ°ÏìµÄ¹æÄ£Ïà¶Ô½ÏС£¬£¬£¬£¬¿ÉÊÇÓÉÓÚΣº¦¼¶±ð½Ï¸ß£¬£¬£¬£¬²¢ÇÒ΢ÈíûÓиø³öÏìÓ¦µÄÎó²î²¹¶¡£¬£¬£¬£¬ÒÔÊǽ¨Òé¶ÔÊÜÓ°ÏìµÄ²Ù×÷ϵͳʹÓÃÒÔÏ»º½â²½·¥½ûÓÃSMBv3µÄѹËõ¹¦Ð§À´¾ÙÐзÀ»¤¡£¡£¡£¡£¡£¡£
Ê×ÏÈÉó²é×Ô¼ºÊ¹ÓõÄWindows°æ±¾ÊÇ·ñΪÊÜÓ°ÏìµÄ°æ±¾£¬£¬£¬£¬ÒªÁìÈçÏ£º
ʹÓÃWin + RºóÊäÈë¡°WinVer¡±Éó²éÄ¿½ñ²Ù×÷ϵͳµÄ°æ±¾ºÅ¡£¡£¡£¡£¡£¡£
ÈôÊÇÈ·ÈÏϵͳÊÜÓ°Ï죬£¬£¬£¬Ôò½¨ÒéʹÓÃÒÔÏÂPowerShellÏÂÁî½ûÓÃѹËõ¹¦Ð§£¬£¬£¬£¬ÒÔ×èֹδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßʹÓÃSMBv3ЧÀÍÆ÷µÄÎó²î£¨ÎÞÐèÖØÐÂÆô¶¯£©¡£¡£¡£¡£¡£¡£
Set-ItemProperty-Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 1 -Force
¶þ¡¢ ²úÆ·½â¾ö¼Æ»®
1¡¢ÒѰ²ÅżøºÚµ£±£ÍøIDS¡¢IPS¡¢WAF¡¢APT²úÆ·µÄ¿Í»§ÇëÈ·ÈÏÈçÏÂÊÂÎñ¹æÔòÒѾÏ·¢²¢Ó¦Ó㬣¬£¬£¬¼´¿ÉÓÐÓüì²âÏà¹Ø¹¥»÷£º TCP_CVE-2020-0796Îó²îʹÓᣡ£¡£¡£¡£¡£
£¨1£©ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ±¨¾¯½ØÍ¼£º
£¨2£©ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½ØÍ¼£º
£¨3£©ÌìÇåWebÓ¦ÓÃÇå¾²Íø¹Ø±¨¾¯½ØÍ¼£º
£¨4£©Ììãٸ߼¶Ò»Á¬ÐÔÍþв¼ì²âÓëÖÎÀíϵͳ±¨¾¯½ØÍ¼£º
2¡¢¼øºÚµ£±£ÍøÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0ÓÚ2020Äê3ÔÂ12ÈÕ½ôÆÈÐû²¼Õë¶Ô¸ÃÎó²îµÄÉý¼¶°ü£¬£¬£¬£¬Ö§³Ö¶Ô¸ÃÎó²î¾ÙÐмì²â£¬£¬£¬£¬Óû§Éý¼¶Ì쾵©ɨ²úÆ·Îó²î¿âºó¼´¿É¶Ô¸ÃÎó²î¾ÙÐÐɨÃè¡£¡£¡£¡£¡£¡£6070°æ±¾Éý¼¶°üΪ607000278£¬£¬£¬£¬Éý¼¶°üÏÂÔØµØµã£º
/article/type/1/146.html
ÇëÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬£¬£¬£¬ÊµÊ±¶Ô¸ÃÎó²î¾ÙÐмì²â£¬£¬£¬£¬ÒԱ㾡¿ì½ÓÄÉÌá·À²½·¥¡£¡£¡£¡£¡£¡£
3¡¢ÒѰ²ÅÅÌ©ºÏTSOCϵÁвúÆ·µÄÆóÊÂÒµµ¥Î»£¬£¬£¬£¬½¨ÒéÌí¼ÓÏìÓ¦µÄ¹æÔòÒ»Á¬¶Ô¸ÃÐÐΪ¾ÙÐÐ¼à¿Ø¡£¡£¡£¡£¡£¡£
¹ØÁª¹æÔò£ºL3_MC_SMBv3Èä³æÔ¶³ÌÖ´ÐÐÎó²îʹÓÃ-CVE-2020-0796
˵Ã÷£º
¡°L3_MC_SMBv3Èä³æÔ¶³ÌÖ´ÐÐÎó²îʹÓÃ-CVE-2020-0796¡±¹ØÁª¹æÔòÊǹæÔòǶÌ׵ĹæÔò£¬£¬£¬£¬ÓÃÓÚ¼à²âSMBv3Îó²î¡¾CVE-2020-0706¡¿Ê¹ÓÃÐÐΪ£¬£¬£¬£¬Í¬Ê±Ò²¼à²âÅúÁ¿445¶Ë¿Ú»á¼ûµÄÐÐΪ¡£¡£¡£¡£¡£¡£
Èô½ÓÈëTSOCƽ̨µÄÇå¾²¼ì²â×°±¸Õ½ÂÔÎÞÉý¼¶¡¢¸üУ¬£¬£¬£¬¿ÉÒÔµ¥¶ÀʹÓá°L2_ADS_ÅúÁ¿445¶Ë¿Ú»á¼û¡±¹æÔò¶Ô445¶Ë¿Ú»á¼ûÇéÐξÙÐÐ¼à¿Ø¡£¡£¡£¡£¡£¡£
×¢£º¡°L3_MC_SMBv3Èä³æÔ¶³ÌÖ´ÐÐÎó²îʹÓÃ-CVE-2020-0796¡±¹æÔòÒѰüÀ¨¡°L2_ADS_ÅúÁ¿445¶Ë¿Ú»á¼û¡±£¬£¬£¬£¬Ö±½Óµ¼Èë¡°L3_MC_SMBv3Èä³æÔ¶³ÌÖ´ÐÐÎó²îʹÓÃ-CVE-2020-0796¡±¹æÔò°ü£¬£¬£¬£¬ÎÞÐèµ¥¶ÀÉèÖá°L2_ADS_ÅúÁ¿445¶Ë¿Ú»á¼û¡±¡£¡£¡£¡£¡£¡£
¡°L3_MC_SMBv3Èä³æÔ¶³ÌÖ´ÐÐÎó²îʹÓÃ-CVE-2020-0796¡±¹æÔòÌõ¼þ£º
ÊÂÎñ=£¨ÈÕÖ¾ÀàÐÍ£¡=¡°¹ØÁªÊÂÎñ¡±£©&£¨£¨×°±¸ÀàÐÍÊôÓÚ£¨Çå¾²×°±¸/Çå¾²·À»¤Íø¹Ø¡¢Çå¾²×°±¸/webÓ¦ÓÃÍø¹Ø¡¢Çå¾²×°±¸/ÈëÇÖ¼ì²â¡¢Çå¾²×°±¸/Çå¾²·ÀÓù¡¢Çå¾²×°±¸/·À²¡¶¾ÏµÍ³¡¢Çå¾²×°±¸/¶ñÒâ´úÂë¼ì²â¡¢Çå¾²×°±¸/ÖÕ¶ËÇå¾²ÖÎÀí£©£©&£¨Ä¿µÄ¶Ë¿Ú=¡°445¡±£©&£¨ÒýÓùýÂËÆ÷=¡°CVE20200796_Çå¾²×°±¸¡±£©£©|£¨ÒýÓùæÔò=¡°L2_ADS_ÅúÁ¿445¶Ë¿Ú»á¼û¡±£©
¡°CVE20200796_Çå¾²×°±¸¡±¹ýÂËÆ÷Ìõ¼þ£º
ÊÂÎñ=£¨ÈÕÖ¾ÀàÐÍ£¡=¡°¹ØÁªÊÂÎñ¡±£©&£¨£¨ÊÂÎñÃû³Æ °üÀ¨ ¡°Corona¡± £©&£¨ÊÂÎñÃû³Æ °üÀ¨ ¡°Blue¡±£©&£¨ÊÂÎñÃû³Æ °üÀ¨ ¡°Îó²î¡±£©£©|(£¨ÊÂÎñÃû³Æ °üÀ¨ ¡°CVE-2020-0796¡± £©)|(£¨ÊÂÎñÃû³Æ °üÀ¨ ¡°SMBv3¡± £©&£¨£¨£¨ÊÂÎñÃû³Æ °üÀ¨ ¡°Îó²î¡± £©|£¨ÊÂÎñÃû³Æ °üÀ¨ ¡°ÅþÁ¬¡± £©£©£©)
¡°L2_ADS_ÅúÁ¿445¶Ë¿Ú»á¼û¡±¹æÔòÌõ¼þ£º
ÊÂÎñ=£¨ÈÕÖ¾ÀàÐÍ£¡=¡°¹ØÁªÊÂÎñ¡±£©&£¨Ä¿µÄ¶Ë¿Ú=¡°445¡±£©
¡°L2_ADS_ÅúÁ¿445¶Ë¿Ú»á¼û¡±´ÎÊýÉèÖãº