¡¾Íþвͨ¸æ¡¿Î¢ÈíSQL Server Reporting ServicesÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2020-0618)
2020-02-14
×ÛÊö
ÔÚÉÏÖÜÐû²¼µÄ΢ÈíÔ¶ȸüÐÂÖУ¬°üÀ¨Ò»¸ö±£´æÓÚSQL Server Reporting Services£¨SSRS£©ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îCVE-2020-0618¡£ÏÖÔÚÒѱ£´æÕë¶Ô¸ÃÎó²îµÄ PoC£¬ÇëÏà¹ØÓû§¾¡¿ì×°Öò¹¶¡¾ÙÐзÀ»¤¡£
SQL Server Reporting Services (SSRS)ÊÇ΢Èí»ùÓÚ·þÎñÆ÷µÄ±¨±íÌìÉúÈí¼þ£¬ËüÊÇMicrosoft SQL Server·þÎñÌ×¼þµÄÒ»²¿·Ö£¬Í¨¹ýWeb½çÃæ¾ÙÐÐÖÎÀí£¬¿ÉÓÃÓÚ×¼±¸ºÍ½»¸¶ÖÖÖÖ½»»¥Ê½±¨¸æ¡£
SSRSÓ¦ÓÃÖеĹ¦Ð§ÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÏòÊÜÓ°ÏìµÄReporting ServicesʵÀýÌύȫÐĽṹµÄHTTPÇëÇó£¬Ê¹ÓÃÓ¦ÓÃÖеķ´ÐòÁл¯ÎÊÌâÔÚ·þÎñÆ÷ÉÏÖ´ÐдúÂë¡£
Ö»¹ÜÖ»ÓÐÊÚȨÓû§²Å»ª»á¼û¸ÃÓ¦ÓóÌÐò£¬¿ÉÊÇ×îµÍȨÏÞ£¨ä¯ÀÀÆ÷½ÇÉ«£©×ãÒÔʹÓôËÎó²î¡£
Ïà¹ØÁ´½Ó£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0618
ÊÜÓ°Ïì²úÆ·°æ±¾
- Microsoft SQL Server 2012 Service Pack 4£¨QFE£©
- Microsoft SQL Server 2014 Service Pack 3£¨CU£©
- Microsoft SQL Server 2014 Service Pack 3£¨GDR£©
- Microsoft SQL Server 2016 Service Pack 2 (CU)
- Microsoft SQL Server 2016 Service Pack 2 (GDR)
½â¾ö¼Æ»®
ÓÉÓÚ¹¥»÷Õß¿Éͨ¹ý¶ÔÇëÇóÊý¾Ý°ü±àÂëÈÆ¹ýWebÓ¦Ó÷À»ðǽµÄ·À»¤£¬Ç¿ÁÒ½¨ÒéÓû§×°Öò¹¶¡¾ÙÐÐÐÞ¸´¡£
΢Èí¹Ù·½ÒÑΪÊÜÖ§³Ö°æ±¾Ðû²¼ÁËÕë¶Ô¸ÃÎó²îµÄÇå¾²²¹¶¡£¬Çë²ÎÔÄ΢Èí¹Ù·½Í¨¸æÏÂÔØ×°Öá£
| ²úÆ· | °æ±¾ | ¸üбàºÅ |
| SQL Server 2016 Service Pack 2 (GDR) Çå¾²¸üР| 13.0.5026.0 – 13.0.5101.9 | KB4532097 |
| SQL Server 2016 Service Pack 2 CU11Çå¾²¸üР| 13.0.5149.0 – 13.0.5598.27 | KB4535706 |
| SQL Server 2014 Service Pack 3 (GDR) Çå¾²¸üР| 12.0.6024.0 – 12.0.6108.1 | KB4532095 |
| SQL Server 2014 Service Pack 2 CU4Çå¾²¸üР| 12.0.6205.1 – 12.0.6329.1 | KB4535288 |
| SQL Server 2012 Service Pack 4 (QFE) Çå¾²¸üР| 111.0.7001.0 – 11.0.7462.6 | KB4532098 |
ͬʱ£¬½¨ÒéեȡÄäÃû»á¼û£¬È·±£Ö»ÓоÓÉÉí·ÝÑéÖ¤µÄÓû§²Å»ª»á¼ûÏà¹ØÓ¦Óá£ÈôÊÇÏÓÒÉ·þÎñÆ÷ÒѾÊܵ½Íþв£¬³ý×°ÖÃÏìÓ¦²¹¶¡Í⣬Çëʵʱ¸ü¸Ä·þÎñÆ÷µÄÕË»§¿ÚÁ±ÜÃâ±»¹¥»÷ÕßʹÓá£
¹Ù·½Í¨¸æ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0618
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³Æ¾ÅÓÎÀÏ¸ç¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

¾ÅÓÎÀϸçÔÆ





