Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Windows ·þÎñÆ÷¸üзþÎñ (WSUS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î |
CVE ID | CVE-2025-59287 |
Îó²îÀàÐÍ | RCE | ·¢Ã÷ʱ¼ä | 2025-10-23 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Microsoft Windows Server Update Services(WSUS)ÊÇÒ»¿îÓÉ΢Èí¿ª·¢µÄ·þÎñÆ÷ÖÎÀí¹¤¾ß£¬ÓÃÓÚ¼¯ÖÐÖÎÀíºÍ·Ö·¢Windows²Ù×÷ϵͳ¼°ÆäËû΢Èí²úÆ·µÄ¸üС£WSUSÔÊÐíITÖÎÀíÔ±ÔÚÆóÒµÍøÂçÖа²ÅŲ¹¶¡ºÍ¸üУ¬È·±£¸÷¸ö¿Í»§¶ËϵͳµÄÇå¾²ÐÔºÍÎȹÌÐÔ¡£Í¨¹ýWSUS£¬ÖÎÀíÔ±¿ÉÒÔÑ¡ÔñÌØ¶¨µÄ¸üУ¬¾ÙÐвâÊÔºÍÑéÖ¤£¬²¢½«ÆäÍÆË͵½×éÖ¯ÖеÄËùÓÐÅÌËã»ú¡£±ðµÄ£¬WSUS»¹ÌṩÁËÏêϸµÄ±¨¸æ¹¦Ð§£¬×ÊÖúÖÎÀíÔ±¼à¿Ø¸üеÄ״̬ºÍ°²ÅŽø¶È¡£
2025Äê10ÔÂ23ÈÕ£¬×ðÁú¿Ê±¼¯ÍÅVSRC¼à²âµ½Ò»¸öÓ°ÏìMicrosoft Windows Server Update Services(WSUS)µÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬Ô´ÓÚ²»Çå¾²µÄ·´ÐòÁл¯Àú³Ì¡£¸ÃÎó²î±¬·¢ÔÚWSUS´¦Öóͷ£AuthorizationCookieʱ£¬Ê¹ÓÃ.NETµÄBinaryFormatter¶Ô¼ÓÃܵÄCookieÊý¾Ý¾ÙÐз´ÐòÁл¯£¬µ«Î´¶ÔÀàÐ;ÙÐÐÑÏ¿áÑéÖ¤¡£¹¥»÷Õß¿ÉÒԽṹ¶ñÒâ¼ÓÃÜÊý¾Ý£¬Í¨¹ýGetCookie()½Ó¿Ú·¢ËÍ£¬µ¼ÖÂϵͳִÐÐí§Òâ´úÂ룬²¢ÒÔSYSTEMȨÏÞÔËÐУ¬Îó²îÆÀ·Ö9.8·Ö£¬Îó²î¼¶±ðÑÏÖØ¡£
¶þ¡¢Ó°Ïì¹æÄ£
Windows Server 2025 (Server Core installation)
Windows Server 2022 (Server Core installation)Windows Server 2019 (Server Core installation)Windows Server 2012 R2 (Server Core installation)Windows Server 2012 (Server Core installation)Windows Server 2016 (Server Core installation)Windows Server 2022, 23H2 Edition (Server Core installation)
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
Microsoft¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬ÒÔÐÞ¸´¸ÃÎó²î¡£
ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔ̽«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287/https://gist.github.com/hawktrace/880b54fb9c07ddb028baaae401bd3951https://hawktrace.com/blog/CVE-2025-59287