¡¾Íþвͨ¸æ¡¿Î¢ÈíÔ¶³Ì×ÀÃæ·þÎñÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0708) ÔÙ´ÎÍþвԤ¾¯Í¨¸æ
2019-09-09
×ÛÊö
΢ÈíÔÚ5ÔÂÔ¶ȸüÐÂÖÐÔøÐÞ¸´Ò»¸ö±£´æÓÚÔ¶³Ì×ÀÃæ·þÎñÖеĸßΣԶ³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0708£©£¬¸ÃÎó²î¿ÉÒÔ±»È䳿À๥»÷ʹÓ᣼øÓÚ´ËÎó²îµÄÍþвˮƽ½Ï¸ß£¬Î¢ÈíÆäʱÕë¶ÔÒѾ×èֹά»¤µÄWindows°æ±¾Ò²Ðû²¼ÁËÇå¾²²¹¶¡¡£
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÑÓÚ5ÔÂ15ºÅÐû²¼Çå¾²Íþвͨ¸æ£¬5Ô 31ºÅÐû²¼Õë¶Ô´ËÎó²îµÄ¼ì²âºÍ·À»¤ÒªÁ죬Ïê¼û²Î¿¼ÅþÁ¬[2]»ò¼ûÏÂÎÄ¡°Îó²îÅŲ顱¼°¡°Îó²î·À»¤¡±¡£
ÔÚ¶Ô¸ÃÎó²îµÄÒ»Á¬¹Ø×¢Öз¢Ã÷£¬ÍâµØÊ±¼ä9ÔÂ6ÈÕ£¬ me
¿ÉÊÇÓÐÏֳɵÄʹÓù¤¾ß·ºÆðºó£¬ÕվɽµµÍÁ˹¥»÷ÕßʵÑé¹¥»÷µÄÃż÷£¬Òò´ËÔÙ´ÎÌáÐÑδ¾ÙÐв¹¶¡×°ÖõÄÓû§¾¡¿ì×°ÖÃÉý¼¶¾ÙÐзÀ»¤¡£
²Î¿¼Á´½Ó£º
[1]http://blog.nsfocus.net/cve-2019-0708/
[2]http://blog.nsfocus.net/nips-cve-2019-0708/
[3]https://www.zdnet.com/article/me
ÊÜÓ°Ïì°æ±¾
l Windows 7
l Windows Server 2008 R2
l Windows Server 2008
l Windows Server 2003£¨ÒÑ×èֹά»¤£©
l Windows XP£¨ÒÑ×èֹά»¤£©
²»ÊÜÓ°Ïì°æ±¾
l Windows 8
l Windows 10
Îó²îÅŲé
1¡¢ ¾ÅÓÎÀϸçÔÆ¼ì²â
¾ÅÓÎÀϸçÔÆÌṩÔÚÏߵļì²âÈë¿Ú£¬ÆóÒµÓû§¿É½øÈëÒ³Ãæ¼ì²â×ÔÓÐ×ʲúÊÇ·ñÊÜ´ËÎó²îÓ°Ïì¡£
ÊÖ»ú¶Ë»á¿´·¨Ö·£º
https://cloud.nsfocus.com/megi/holes/hole_WindowsRDP_2019_5_15.html
PC¶Ë»á¿´·¨Ö·£º
https://cloud.nsfocus.com/#/secwarning/secwarning_news
1¡¢ ²úÆ·¼ì²â
¹ØÓÚRSASµÄÉèÖÃÖ¸µ¼£¬Çë²Î¿¼ÈçÏÂÁ´½Ó£º
https://mp.weixin.qq.com/s/aLAWXs5DgRhNHf4WHHhQyg
Îó²î·À»¤
Õë¶Ô´ËÎó²î£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼·À»¤²úÆ·ÒÑÐû²¼¹æÔòÉý¼¶°ü£¬¿ÉÐγÉÕë¶Ô´ËÎó²îµÄ·À»¤ÄÜÁ¦¡£Ç¿ÁÒ½¨ÒéÏà¹ØÓû§Éý¼¶ÖÁ×îйæÔò¡£Çå¾²·À»¤²úÆ·¹æÔò°æ±¾ºÅÈçÏ£º
|
Çå¾²·À»¤²úÆ· |
¹æÔò°æ±¾ºÅ |
Éý¼¶°üÏÂÔØÁ´½Ó |
¹æÔò±àºÅ |
|
IPS |
5.6.10.20340 |
http://update.nsfocus.com/update/downloads/id/28804 |
¡¾24489¡¿ |
|
5.6.9.20340 |
http://update.nsfocus.com/update/downloads/id/28803 |
||
|
5.6.8.778 |
http://update.nsfocus.com/update/downloads/id/28794 |
||
|
NF |
6.0.1.778 |
http://update.nsfocus.com/update/downloads/id/28828 |
²úÆ·¹æÔòÉý¼¶µÄ²Ù×÷°ì·¨Ïê¼ûÈçÏÂÁ´½Ó£º
IPS£ºhttps://mp.weixin.qq.com/s/JsRktENQNj1TdZSU62N0Ww
NF£ºhttps://mp.weixin.qq.com/s/bggqcm9VqHiPnfV1XoNuDQ
2¡¢ ¹Ù·½²¹¶¡
΢Èí¹Ù·½ÒѾÐû²¼¸üв¹¶¡£¨°üÀ¨¹Ù·½×èֹά»¤°æ±¾£©£¬ÇëÓû§ÊµÊ±¾ÙÐв¹¶¡¸üС£»ñµÃ²¢×°Öò¹¶¡µÄ·½·¨ÓÐÈýÖÖ£ºÄÚÍøWSUS·þÎñ¡¢Î¢Èí¹ÙÍøMicrosoft Update·þÎñ¡¢ÀëÏß×°Öò¹¶¡¡£
×¢£ºÈôÊÇÐèÒªÁ¬Ã¦Æô¶¯Windows Update¸üУ¬¿ÉÒÔÔÚÏÂÁîÌáÐÑ·ûϼüÈëwuauclt.exe /detectnow¡£
·½·¨Ò»£ºÄÚÍøWSUS·þÎñ
ÊÊÓù¤¾ß£ºÒѼÓÈë´î½¨ÓÐWSUS·þÎñÆ÷ÄÚÍøÔ˶¯Ä¿Â¼ÓòµÄÅÌËã»ú£¬»òÊÖ¹¤ÉèÖÃÁË»á¼ûÄÚÍøWSUS·þÎñ¡£
ϵͳ»á׼ʱ×Ô¶¯ÏÂÔØËùÐèµÄÇå¾²²¹¶¡²¢ÌáÐÑ×°Öã¬Çë°´ÌáÐѾÙÐÐ×°ÖúÍÖØÆôϵͳ¡£
ÈôÊÇÏ£Íû¾¡¿ì×°Öò¹¶¡£¬ÇëÖØÐÂÆô¶¯Ò»´ÎÅÌËã»ú¼´¿É¡£
·½·¨¶þ£º ΢Èí¹ÙÍøMicrosoft Update·þÎñ
ÊÊÓù¤¾ß£ºËùÓпÉÒÔÁªÍø£¬²»¿ÉʹÓÃÄÚÍøWSUS·þÎñµÄÅÌËã»ú£¬°üÀ¨Î´ÆôÓÃÄÚÍøWSUS·þÎñµÄÅÌËã»ú¡¢ÆôÓÃÁËÄÚÍøWSUS·þÎñµ«Î´ÓëÄÚÍøÅþÁ¬µÄÅÌËã»ú¡£
δÆôÓÃÄÚÍøWSUS·þÎñµÄÅÌËã»ú£¬ÇëÈ·±£Windows×Ô¶¯¸üÐÂÆôÓã¬Æ¾Ö¤ÌáÐÑ×°Öò¹¶¡²¢ÖØÆôÅÌËã»ú¡£
ÆôÓÃÄÚÍøWSUS·þÎñµÄÅÌËã»úµ«Ã»ÓÐÓëÄÚÍøÅþÁ¬µÄÅÌËã»ú£¬Çëµã»÷×îÏȲ˵¥-ËùÓгÌÐò-Windows Update£¬µã»÷¡°ÔÚÏß¼ì²éÀ´×ÔWindows UpdateµÄ¸üС±£¬°´ÌáÐѾÙÐвÙ×÷¡£
·½·¨Èý£º ÀëÏß×°Öò¹¶¡
ÏÂÔØ¶ÔÓ¦µÄ²¹¶¡×°Öðü£¬Ë«»÷ÔËÐм´¿É¾ÙÐÐÐÞ¸´£¬ÏÂÔØÁ´½Ó¿É²Î¿¼±¾ÎÄ¡°¸½Â¼A ¹Ù·½²¹¶¡ÏÂÔØÁ´½Ó¡±¡£
ÔÝʱ½â¾ö½¨Òé
ÈôÓû§Ôݲ»Àû±ã×°Öò¹¶¡¸üУ¬¿É½ÓÄÉÏÂÁÐÔÝʱ·À»¤²½·¥£¬¶Ô´ËÎó²î¾ÙÐзÀ»¤¡£
1¡¢ ÈôÓû§²»ÐèÒªÓõ½Ô¶³Ì×ÀÃæ·þÎñ£¬½¨Òé½ûÓø÷þÎñ¡£
2¡¢ ÔÚ·À»ðǽÖжÔTCP 3389¶Ë¿Ú¾ÙÐÐ×è¶Ï¡£
3¡¢ ÆôÓÃÍøÂç¼¶ÈÏÖ¤£¨NLA£©£¬´Ë¼Æ»®ÊÊÓÃÓÚWindows 7 Windows Server 2008 and Windows Server 2008 R2¡£
¸½Â¼ ¹Ù·½²¹¶¡ÏÂÔØÁ´½Ó
|
²Ù×÷ϵͳ°æ±¾ |
²¹¶¡ÏÂÔØÁ´½Ó |
|
Windows 7 x86 |
http://download.windowsupdate.com/d/msdownload/update/software/secu/2019/05/windows6.1-kb4499175-x86_6f1319c32d5bc4caf2058ae8ff40789ab10bf41b.msu |
|
Windows 7 x64 |
http://download.windowsupdate.com/d/msdownload/update/software/secu/2019/05/windows6.1-kb4499175-x64_3704acfff45ddf163d8049683d5a3b75e49b58cb.msu |
|
Windows Embedded Standard 7 for x64 |
http://download.windowsupdate.com/d/msdownload/update/software/secu/2019/05/windows6.1-kb4499175-x64_3704acfff45ddf163d8049683d5a3b75e49b58cb.msu |
|
Windows Embedded Standard 7 for x86 |
http://download.windowsupdate.com/d/msdownload/update/software/secu/2019/05/windows6.1-kb4499175-x86_6f1319c32d5bc4caf2058ae8ff40789ab10bf41b.msu |
|
Windows Server 2008 x64 |
http://download.windowsupdate.com/d/msdownload/update/software/secu/2019/05/windows6.0-kb4499149-x64_9236b098f7cea864f7638e7d4b77aa8f81f70fd6.msu |
|
Windows Server 2008 Itanium |
http://download.windowsupdate.com/d/msdownload/update/software/secu/2019/05/windows6.0-kb4499180-ia64_805e448d48ab8b1401377ab9845f39e1cae836d4.msu |
|
Windows Server 2008 x86 |
http://download.windowsupdate.com/d/msdownload/update/software/secu/2019/05/windows6.0-kb4499149-x86_832cf179b302b861c83f2a92acc5e2a152405377.msu |
|
Windows Server 2008 R2 Itanium |
http://download.windowsupdate.com/c/msdownload/update/software/secu/2019/05/windows6.1-kb4499175-ia64_fabc8e54caa0d31a5abe8a0b347ab4a77aa98c36.msu |
|
Windows Server 2008 R2 x64 |
http://download.windowsupdate.com/d/msdownload/update/software/secu/2019/05/windows6.1-kb4499175-x64_3704acfff45ddf163d8049683d5a3b75e49b58cb.msu |
|
Windows Server 2003 x86 |
http://download.windowsupdate.com/d/csa/csa/secu/2019/04/windowsserver2003-kb4500331-x86-custom-chs_4892823f525d9d532ed3ae36fc440338d2b46a72.exe |
|
Windows Server 2003 x64 |
http://download.windowsupdate.com/d/csa/csa/secu/2019/04/windowsserver2003-kb4500331-x64-custom-chs_f2f949a9a764ff93ea13095a0aca1fc507320d3c.exe |
|
Windows XP SP3 |
http://download.windowsupdate.com/c/csa/csa/secu/2019/04/windowsxp-kb4500331-x86-custom-chs_718543e86e06b08b568826ac13c05f967392238c.exe |
|
Windows XP SP2 for x64 |
http://download.windowsupdate.com/d/csa/csa/secu/2019/04/windowsserver2003-kb4500331-x64-custom-enu_e2fd240c402134839cfa22227b11a5ec80ddafcf.exe |
|
Windows XP SP3 for XPe |
http://download.windowsupdate.com/d/csa/csa/secu/2019/04/windowsxp-kb4500331-x86-embedded-custom-chs_96da48aaa9d9bcfe6cd820f239db2fe96500bfae.exe |
|
|
http://download.windowsupdate.com/d/msdownload/update/software/secu/2019/04/windowsxp-kb4500331-x86-embedded-chs_e3fceca22313ca5cdda811f49a606a6632b51c1c.exe |
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³Æ¾ÅÓÎÀÏ¸ç¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

¾ÅÓÎÀϸçÔÆ





