¾ÅÓÎÀϸç

¾ÅÓÎÀϸç

¾ÅÓÎÀÏ¸ç¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

Microsoft Windows DNS·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²îSigRed£¨CVE-2020-1350£© ·À»¤¼Æ»®

2020-07-16

Ò».  ×ÛÊö

ÍâµØÊ±¼ä7ÔÂ14ÈÕ £¬Î¢Èí×îеÄÔ¶Ȳ¹¶¡¸üÐÂÖÐÐÞ¸´ÁËһö±£´æÓÚWindows DNS ·þÎñÆ÷ÖеĿÉÈ䳿»¯Îó²îCVE-2020-1350£¨´úºÅ SigRed£©  ¡£ÕâÒâζ׏¥»÷ÕßʹÓøÃÎó²îÄܹ»ÔÚûÓÐÈκÎÓû§½»»¥µÄÇéÐÎÏ £¬ÔÚÒ×Êܹ¥»÷µÄ»úе¼äÈö²¥ £¬´Ó¶øÓпÉÄÜѬȾÕû¸ö×éÖ¯µÄÍøÂç  ¡£

¾Ý±¨µÀ £¬¸ÃÎó²îÒѾ­±£´æ17 ÄêÖ®¾Ã £¬Î¢Èí¹Ù·½¸ø³öµÄÆÀ·ÖΪ 10 ·Ö£¨CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C£©  ¡£

δ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòWindows DNS·þÎñÆ÷·¢ËͶñÒâÇëÇóÀ´Ê¹ÓøÃÎó²î  ¡£Check PointµÄÑо¿Ö°Ô±·¢Ã÷ £¬Í¨¹ý·¢ËͰüÀ¨SIG¼Í¼£¨´óÓÚ64KB£©µÄDNSÏìÓ¦¿ÉÒÔÔì³É»ùÓڶѵĻº³åÇøÒç³ö £¬½ø¶øÊ¹¹¥»÷ÕßÄܹ»¿ØÖÆ·þÎñÆ÷  ¡£

ÏÖÔÚÎó²îϸ½ÚÒѹûÕæ £¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤  ¡£

²Î¿¼Á´½Ó£º

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1350

¶þ.  Îó²îÓ°Ïì¹æÄ£

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Windows Server 2012

Windows Server 2012 (Server Core installation)

Windows Server 2012 R2

Windows Server 2012 R2 (Server Core installation)

Windows Server 2016

Windows Server 2016 (Server Core installation)

Windows Server 2019

Windows Server 2019 (Server Core installation)

Windows Server, version 1909 (Server Core installation)

Windows Server, version 1903 (Server Core installation)

Windows Server, version 2004 (Server Core installation)

 

Èý.  ÊÖÒÕ·À»¤¼Æ»®

3.1  ¹Ù·½ÐÞ¸´¼Æ»®

΢Èí¹Ù·½ÒÑÕë¶ÔÊÜÓ°ÏìϵͳÐû²¼ÁËÇå¾²²¹¶¡ £¬Ç¿ÁÒ½¨ÒéÏà¹ØÓû§¾¡¿ì×°ÖøüР ¡£

    ²¹¶¡¸üÐ²ο¼¹Ù·½Í¨¸æ£º

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1350

3.2  »º½â²½·¥

ÈôÊÇÎÞ·¨Á¬Ã¦×°ÖøüР£¬¹Ù·½ÌṩÁËÈçÏ»º½â²½·¥£º

½¨Òé¾ÙÐÐÒÔÏÂ×¢²á±í¸ü¸Ä £¬ÒÔÏÞÖÆÔÊÐíµÄ×î´óÈëÕ¾ TCP DNS ÏìÓ¦Êý¾Ý°üµÄ´óÐ  ¡£º

reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters" /v "TcpReceivePacketSize" /t REG_DWORD /d 0xFF00 /f

net stop DNS && net start DNS

 

ÔÚ×°Öò¹¶¡³ÌÐòºó £¬½¨ÒéÔÚ×¢²á±íÖÐÒÆ³ý TcpReceivePacketSize ¼°ÆäÊý¾Ý £¬ÒÔʹע²á±íÏî HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters ϵÄËùÓÐÆäËûÄÚÈÝÓë֮ǰ¼á³ÖÒ»Ö  ¡£

https://support.microsoft.com/zh-cn/help/4569509/windows-dns-server-remote-code-execution-vulnerability

3.3  ¾ÅÓÎÀÏ¸ç¿Æ¼¼¼ì²â·À»¤½¨Òé

3.3.1  ¾ÅÓÎÀÏ¸ç¿Æ¼¼¼ì²âÀà²úÆ·Óë·þÎñ

ÄÚÍø×ʲú¿ÉÒÔʹÓþÅÓÎÀÏ¸ç¿Æ¼¼µÄÔ¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS V6£©¡¢ÈëÇÖ¼ì²âϵͳ(IDS)¡¢Í³Ò»Íþв̽Õ루UTS£©¾ÙÐмì²â  ¡£

Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS V6£©http://update.nsfocus.com/update/listRsas

ÈëÇÖ¼ì²âϵͳ£¨IDS£©

http://update.nsfocus.com/update/listIds

ͳһÍþв̽Õ루UTS£©

http://update.nsfocus.com/update/bsaUtsIndex

3.3.1.1  ¼ì²â²úÆ·Éý¼¶°ü/¹æÔò°æ±¾ºÅ

¼ì²â²úÆ·

Éý¼¶°ü/¹æÔò°æ±¾ºÅ

RSAS V6 ϵͳ²å¼þ

6.0R02F01.1903

IDS

5.6.10.23040

5.6.9.23040

UTS

5.6.10.23040

RSAS V6 ϵͳ²å¼þ°üÏÂÔØÁ´½Ó£º

http://update.nsfocus.com/update/downloads/id/106565

IDS Éý¼¶°üÏÂÔØÁ´½Ó£º

5.6.10.23040

http://update.nsfocus.com/update/downloads/id/106570

5.6.9.23040

http://update.nsfocus.com/update/downloads/id/106569

UTSÉý¼¶°üÏÂÔØÁ´½Ó£º

http://update.nsfocus.com/update/downloads/id/106574

 

3.3.2  ¾ÅÓÎÀÏ¸ç¿Æ¼¼·À»¤Àà²úÆ·

ʹÓþÅÓÎÀÏ¸ç¿Æ¼¼·À»¤Àà²úÆ· £¬ÈëÇÖ·À»¤ÏµÍ³£¨IPS£©¡¢ÏÂÒ»´ú·À»ðǽϵͳ£¨NF£©À´¾ÙÐзÀ»¤  ¡£

ÈëÇÖ·À»¤ÏµÍ³£¨IPS£©

http://update.nsfocus.com/update/listIps

ÏÂÒ»´ú·À»ðǽϵͳ£¨NF£©

http://update.nsfocus.com/update/listNf

3.3.2.1  ·À»¤²úÆ·Éý¼¶°ü/¹æÔò°æ±¾ºÅ

·À»¤²úÆ·

Éý¼¶°ü/¹æÔò°æ±¾ºÅ

¹æÔò±àºÅ

IPS

5.6.10.23040

5.6.9.23040

24962

NF

6.0.2.819

6.0.1.819

24967

IPS Éý¼¶°üÏÂÔØÁ´½Ó£º

5.6.10.23040

http://update.nsfocus.com/update/downloads/id/106570

5.6.9.23040

http://update.nsfocus.com/update/downloads/id/106569

NF Éý¼¶°üÏÂÔØÁ´½Ó£º

6.0.2.819

http://update.nsfocus.com/update/downloads/id/106592

6.0.1.819

http://update.nsfocus.com/update/downloads/id/106591

 

¸½Â¼A ²úƷʹÓÃÖ¸ÄÏ

 RSASɨÃèÉèÖÃ

ÔÚϵͳÉý¼¶ÖÐ £¬µã»÷ÏÂͼºì¿òλÖÃÑ¡ÔñÎļþ  ¡£

¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

Ñ¡ÔñÏÂÔØºÃµÄÏìÓ¦Éý¼¶°ü £¬µã»÷Éý¼¶°´Å¥¾ÙÐÐÊÖ¶¯Éý¼¶  ¡£ÆÚ´ýÉý¼¶Íê³Éºó £¬¿Éͨ¹ý¶¨ÖÆÉ¨ÃèÄ£°å £¬Õë¶Ô´Ë´ÎÎó²î¾ÙÐÐɨÃè  ¡£

 UTS¼ì²âÉèÖÃ

ÔÚϵͳÉý¼¶Öеã»÷ÀëÏßÉý¼¶ £¬Ñ¡Ôñ¹æÔòÉý¼¶Îļþ £¬Ñ¡Ôñ¶ÔÓ¦µÄÉý¼¶°üÎļþ £¬µã»÷ÉÏ´« £¬ÆÚ´ýÉý¼¶Àֳɼ´¿É  ¡£

¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

 

 IPS·À»¤ÉèÖÃ

ÔÚϵͳÉý¼¶Öеã»÷ÀëÏßÉý¼¶ £¬Ñ¡Ôñϵͳ¹æÔò¿â £¬Ñ¡Ôñ¶ÔÓ¦µÄÎļþ £¬µã»÷ÉÏ´«  ¡£

¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

¸üÐÂÀֳɺó £¬ÔÚϵͳĬÈϹæÔò¿âÖвéÕÒ¹æÔò±àºÅ £¬¼´¿ÉÅÌÎʵ½¶ÔÓ¦µÄ¹æÔòÏêÇé  ¡£

¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

×¢ÖØ£º¸ÃÉý¼¶°üÉý¼¶ºóÒýÇæ×Ô¶¯ÖØÆôÉúЧ £¬²»»áÔì³É»á»°ÖÐÖ¹ £¬µ«ping°ü»á¶ª3~5¸ö £¬ÇëÑ¡ÔñºÏÊʵÄʱ¼äÉý¼¶  ¡£

 NF·À»¤ÉèÖÃ

ÔÚ NF µÄ¹æÔòÉý¼¶½çÃæ¾ÙÐÐÉý¼¶£º

¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

 

ÊÖ¶¯Ñ¡Ôñ¹æÔò°ü £¬Ìá½»¼´¿ÉÍê³É¸üР ¡£

 

Éù Ã÷

±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌâ £¬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí  ¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ £¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ £¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈÎ  ¡£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ  ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ £¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ £¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ  ¡£Î´¾­¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí £¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ £¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ  ¡£

 

¹ØÓÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼

¾ÅÓÎÀϸ磨¼ò³Æ¾ÅÓÎÀÏ¸ç¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô £¬×ܲ¿Î»ÓÚ±±¾©  ¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹ £¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§ £¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»® £¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐÐ  ¡£

»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿ £¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò £¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ  ¡£

¾ÅÓÎÀϸçÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊÐ £¬¹ÉƱ¼ò³Æ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼ £¬¹ÉƱ´úÂ룺300369  ¡£

?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈë¾ÅÓÎÀÏ¸ç¿Æ¼¼ £¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
  • Ìá½»µ½ÓÊÏä
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷

? 2025 NSFOCUS ¾ÅÓÎÀÏ¸ç¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼