΢Èí¸ßΣÎó²îͨ¸æ £¨CVE-2020-0796/ CVE-2020-0684£©
Ðû²¼Ê±¼ä 2020-03-112020Äê3ÔÂ11ÈÕ£¬Î¢ÈíÐû²¼±¾ÔÂÇ徲ͨ¸æ£¬ÆäÖаüÀ¨¡°Èä³æÐÍ¡±Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-0796£©ºÍ¡°ÕðÍø¼¶¡±LNKÎó²î£¨CVE-2020-0684£©¡£ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¹«Ë¾ÌáÐÑ¿í´óÓû§¾¡¿ìÉý¼¶ÏµÍ³²¹¶¡»ò½ÓÄÉÏìÓ¦µÄ·À»¤²½·¥¡£
CVE-2020-0796
¡ñ Îó²îÐÎò
CVE-2020-0796ÊDZ£´æÓÚ΢Èí·þÎñÆ÷ÐÂÎÅ¿é3.0 (SMBv3)ÐÒéÖеÄÈä³æ¼¶Îó²î£¬ÏÖÔÚÉÐδ»ñµÃÐÞ¸´¡£
Çå¾²¹«Ë¾Cisco TalosºÍFortinetÔÚÆäÍøÕ¾ÉÏÐû²¼ÁË CVE-2020-0796Îó²îµÄÊÖÒÕϸ½Ú¡£¸ÃÎó²îÊÇÓÉSMBv3´¦Öóͷ£¶ñÒâѹËõÊý¾Ý°üʱ½øÈë¹ýʧÁ÷³ÌÔì³ÉµÄ£¬Ô¶³ÌµÄδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÔÚÓ¦ÓóÌÐòÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¸ÃÎó²îÓë¡°Eternal Blue¡±¶¼ÊDZ£´æÓÚsmbÐÒéµÄÎó²î£¬²¢ÇÒÊÇÔ¶³Ì¿ÉʹÓÃÎó²î£¬»ò½«³ÉΪÏÂÒ»´úÀÕË÷²¡¶¾¹¥»÷Ä¿µÄÊ×Ñ¡·½·¨¡£ÓÉÓÚ¸ÃÎó²îÓë¡°Eternal Blue ¡±ÏàËÆ£¬ÍÆÌØÒѾ×îÏÈʵÑ齫ÆäÃüÃûΪ¡°Corona Blue¡±¡£
¡ñ ·À»¤¼Æ»®
£¨1£©½ûÓÃSMBv3ѹËõ£¬Ê¹ÓÃÒÔÏÂPowerShellÏÂÁî¿É½ûÓÃSMBv3·þÎñµÄѹËõ£¨ÎÞÐèÖØÐÂÆô¶¯£©£º
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 1 -Force
£¨2£©¹Ø±Õ445¶Ë¿Ú£¬·ÀÓùʹÓøÃÎó²îµÄ¹¥»÷¡£
¡ñ Ó°Ïì°æ±¾
Windows 10 Version 1903 for 32-bit Systems
Windows 10 Version 1903 for ARM64-based Systems
Windows 10 Version 1903 for x64-based Systems
Windows 10 Version 1909 for 32-bit Systems
Windows 10 Version 1909 for ARM64-based Systems
Windows 10 Version 1909 for x64-based Systems
Windows Server, version 1903 (Server Core installation)
Windows Server, version 1909 (Server Core installation)
CVE-2020-0684
¡ñ Îó²îÐÎò
CVE-2020-0684±£´æÓÚLNKÎļþµÄ´¦Öóͷ£Àú³ÌÖУ¬ºÍ2010ÄêÕðÍø²¡¶¾ËùʹÓõÄÎó²îCVE-2010-2568ÒÔ¼°2017Äê΢ÈíÐÞ¸´µÄÎó²îCVE-2017-8464ÀàËÆ¡£¹¥»÷Õß¿ÉÒÔͨ¹ý¶ñÒâ½á¹¹µÄLNKÎļþÓÕʹÊܺ¦ÕßÒÔÆä×ÔÉíµÄÓû§È¨ÏÞÖ´ÐÐí§Òâ´úÂ룬΢Èí½«ÆäÑÏÖØÆ·¼¶½ç˵ΪCritical¡£
Ö»¹Ü΢ÈíÐû²¼²»ÔÙΪwin7ÌṩÇå¾²¸üУ¬win7Óû§ÈÔÈ»¿ÉÒÔÏÂÔØÕë¶Ô¸ÃÎó²îµÄ²¹¶¡¡£
¡ñ ·À»¤¼Æ»®
£¨1£©ÏµÍ³Éý¼¶ÖÁ×îв¹¶¡¡£
£¨2£©Î´ÏÂÔز¹¶¡µÄÓû§Ó¦Ö»¹Ü×èÖ¹ÎüÊÕËûÈË·¢Ë͹ýÀ´µÄLNKÎļþ»ò·¿ª´æÓÐLNKÎļþµÄ´æ´¢×°±¸£¬Èç·¿ªÉúÊèÈËÌṩµÄUÅÌ¡£
¡ñ Ó°Ïì°æ±¾
£¨ÒÔϽöÁгöÊÜÓ°ÏìϵͳµÄ´ó°æ±¾ºÅ£¬ÏêϸµÄÓ°Ïì°æ±¾ÐÅÏ¢°Ý¼û²Î¿¼Á´½Ó5¡££©
Windows 10
Windows 10 Version 1607
Windows 10 Version 1709
Windows 10 Version 1803
Windows 10 Version 1809
Windows 10 Version 1903
Windows 10 Version 1909
Windows 7 Service Pack 1
Windows 8.1
Windows RT 8.1
Windows Server 2008 Service Pack 2
Windows Server 2008 R2 Service Pack 1
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016
Windows Server 2019
Windows Server, version 1803
Windows Server, version 1903
Windows Server, version 1909
²Î¿¼Á´½Ó£º
1.https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200005
2.https://fortiguard.com/encyclopedia/ips/48773
3.https://twitter.com/search?q=CVE-2020-0796&src=typed_query
4.https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796
5.https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0684