΢ÈíSMB3ЭÒéÔ¶³ÌʹÓÃ0dayÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-03-11

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-0796£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Windows 10 Version 1903 for 32-bit Systems

Windows 10 Version 1903 for x64-based Systems

Windows 10 Version 1903 for ARM64-based Systems

Windows Server, version 1903 (Server Core installation)

Windows 10 Version 1909 for 32-bit Systems

Windows 10 Version 1909 for x64-based Systems

Windows 10 Version 1909 for ARM64-based Systems

Windows Server, version 1909 (Server Core installation)


Îó²î¸ÅÊö


CVE-2020-0796 ÊDZ£´æÓÚ΢ÈíЧÀÍÆ÷SMBЭÒéÖеÄÒ»¸ö¡°È䳿»¯¡±Îó²î£¬£¬£¬ £¬£¬¸ÃÎó²îδ°üÀ¨ÔÚ΢Èí±¾ÔÂÐû²¼µÄ²¹¶¡ÖУ¬£¬£¬ £¬£¬ÊÇÔÚ²¹¶¡µÄÐòÑÔÖÐй¶µÄ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ΢ÈíÉÐδÐû²¼ÈκÎÊÖÒÕÏêÇ飬£¬£¬ £¬£¬Ë¼¿Æ Talos ÍÅ¶ÓºÍ Fortinet ¹«Ë¾ÌṩÁ˼ò¶Ì¸ÅÊö£¬£¬£¬ £¬£¬ÏÖÔÚÉв»ÇåÎú¸ÃÎó²îµÄ²¹¶¡ºÎʱÐû²¼¡£¡£¡£¡£¡£¡£¡£


Fortinet ¹«Ë¾Ö¸³ö£¬£¬£¬ £¬£¬¸ÃÎó²îÊÇ¡°Î¢Èí SMB ЧÀÍÆ÷ÖеÄÒ»¸ö»º³åÇøÒç³öÎó²î¡±£¬£¬£¬ £¬£¬ÑÏÖØÆ·¼¶Îª×î¸ßÆÀ·Ö£¬£¬£¬ £¬£¬¡°¸ÃÎó²îÓÉÒ×Êܹ¥»÷µÄÈí¼þ¹ýʧµØ´¦Öóͷ£¶ñÒâ½á¹¹µÄѹËõÊý¾Ý°ü¶ø´¥·¢¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¡¢Î´¾­ÈÏÖ¤µÄ¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚ¸ÃÓ¦ÓóÌÐòµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡±


˼¿Æ Talos ²©¿ÍÎÄÕÂÒ²¸ø³öÁËÀàËÆÐÎò£¬£¬£¬ £¬£¬²»¹ýËæºó½«Æäɾ³ý¡£¡£¡£¡£¡£¡£¡£Ë¼¿ÆÖ¸³ö£¬£¬£¬ £¬£¬¡°Ê¹ÓøÃÎó²î¿Éµ¼ÖÂϵͳÔâÈ䳿¹¥»÷£¬£¬£¬ £¬£¬Ò²¾ÍÊÇ˵Îó²î¿ÉÈÝÒ×µØÔÚÊܺ¦ÕßÖ®¼äÈö²¥¡£¡£¡£¡£¡£¡£¡£¡±


Îó²îÑéÖ¤


ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ΢ÈíûÓÐÐû²¼Îó²îÏêÇé¼°²¹¶¡¡£¡£¡£¡£¡£¡£¡£


»º½â²½·¥£º

1. ½ûÓÃSMbv3 compression¡£¡£¡£¡£¡£¡£¡£½ûÓÃSMbv3 compression ¿ÉÒÔÔÚSMBv3 ServerµÄPowershellÖÐÖ´ÐÐÈçÏ´úÂë

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 1 -Force

¾ÙÐиü¸Äºó£¬£¬£¬ £¬£¬ÎÞÐèÖØÐÂÆô¶¯¡£¡£¡£¡£¡£¡£¡£´Ë½â¾öÒªÁì²»¿É±ÜÃâʹÓÃSMB¿Í»§¶Ë¡£¡£¡£¡£¡£¡£¡££»£»£»£»£»

2. ÈôÎÞÓªÒµÐëÒª£¬£¬£¬ £¬£¬ÔÚÍøÂçÇå¾²Óò½çÏß·À»ðǽ·â¶ÂÎļþ´òÓ¡ºÍ¹²Ïí¶Ë¿Ú£¨tcp:135/139/445£©£»£»£»£»£»

3. ×°ÖÃɱ¶¾Èí¼þ£¬£¬£¬ £¬£¬²»ÎüÊպ͵ã»÷ȪԴ²»Ã÷µÄÎļþ¡¢Óʼþ¸½¼þ£¬£¬£¬ £¬£¬²¢×öºÃÊý¾Ý±¸·ÝÊÂÇ飬£¬£¬ £¬£¬±ÜÃâѬȾÀÕË÷²¡¶¾¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://fortiguard.com/encyclopedia/ips/48773