Windows BlueKeepÎó²î£¨CVE-2019-0708£©
Ðû²¼Ê±¼ä 2019-09-07

2019Äê5ÔÂ14ÈÕ΢ÈíÐû²¼Ô¶³Ì×ÀÃæ·þÎñ£¨ÒÔǰ³ÆÎªÖÕ¶Ë·þÎñ£©µÄÔ¶³ÌÖ´ÐдúÂëÎó²îBlueKeep£¨CVE-2019-0708£©µÄÐÞ¸´³ÌÐò¡£´ËÎó²îÊÇÔ¤Éí·ÝÑéÖ¤£¬ÎÞÐèÓû§½»»¥²¢ÓпÉÄÜÒÔÀàËÆÈ䳿µÄ·½·¨Èö²¥¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£
9ÔÂ6ÈÕMetasploitÒѾ½«BlueKeepÎó²îEXPÐû²¼µ½metasploit-frameworkµÄPull requestsÖУ¬ÏÖÔÚÖ÷ÒªÕë¶Ô64λ°æ±¾µÄWindows 7ºÍWindows Server 2008 R2¡£¹ØÓÚWindows Server 2008 R2£¬ÐèÒªÐÞ¸Ä×¢²á±í£¬µ«ÈÔÓÐÆäËû¿ÉÄÜÐÔʹÓÃÔÚËùÓÐWindows²Ù×÷ϵͳÉÏ¡£
¹ØÓÚBlueKeepÎó²îµÄÔ¤¾¯ÏêÇé¿É²Î¿¼Î¬ËûÃüµÄÀúÊ·Îó²îÔ¤¾¯£º
¡¾Îó²îÔ¤¾¯¡¿Windows RDPÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2019-0708£©
ËäÈ»Õë¶Ô´ËÎó²îʹÓõÄÌØ¶¨·ÀÓùºÍ¼ì²âºÜÓÐÓ㬵«¡°DejaBlue¡±ÏµÁÐÖнÏеÄRDPÎó²îÒ»Ñùƽ³£¶¼Ç¿µ÷ÁË´ËÐÒéµÄΣº¦¡£¸ÃÐÒé¹ÌÓеÄÖØ´óÐÔÅú×¢£¬½ñÌìÒÑÖªµÄ¹ýʧ²»»áÊÇ×îºóÒ»¸ö£¬ÌØÊâÊÇÓÉÓÚÎó²îʹÓÿª·¢Ö°Ô±ºÍÑо¿Ö°Ô±ÏÖÔÚ¶ÔRDP¼°ÆäÈõµãÓÐÁ˸üϸ΢µÄÃ÷È·¡£Ëæ×ÅÎó²îʹÓÃˮƽµÄÌá¸ß£¬¿ÉÄÜ»áÒ»Á¬¿ª·¢¡£
ÐÞ¸´CVE-2019-0708Îó²î¾ßÓÐÖ÷ÒªÐԺͽôÆÈÐÔ£¬½¨ÒéÓû§²»ÒªÐÄ´æÐÒÔË¡£Rapid7 LabsÖ®Ç°ÔøÐ´¹ý×ÔBlueKeepÎó²îÐû²¼ÒÔÀ´ËûÃÇÊӲ쵽µÄ¶ñÒâRDPÔ˶¯ÔÚÒ»Á¬ÉÏÉý¡£
ÏÖÔÚ¼ì²âµ½È«ÇòÁè¼Ý100Íò¸öϵͳ¿ªÆôRDP·þÎñ¡£×Ըò¹¶¡ÓÚ5ÔÂÐû²¼ÒÔÀ´£¬¸ÃÎó²îÊܵ½ÁËÇå¾²ÐÐÒµµÄÆÕ±é¹Ø×¢£¬½¨ÒéÓû§È¨ºâδÐÞ²¹Îó²îËùÔì³ÉµÄÓ°Ïì¡£


¾©¹«Íø°²±¸11010802024551ºÅ