¡¾Îó²îͨ¸æ¡¿Microsoft Windows DNS·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²îSigRed£¨CVE-2020-1350£© Ç徲ͨ¸æ
2020-07-15
×ÛÊö
ÍâµØÊ±¼ä7ÔÂ14ÈÕ£¬Î¢Èí×îеÄÔ¶Ȳ¹¶¡¸üÐÂÖÐÐÞ¸´ÁËһö±£´æÓÚWindows DNS ·þÎñÆ÷ÖеĿÉÈ䳿»¯Îó²îCVE-2020-1350£¨´úºÅ SigRed£©¡£ÕâÒâζ׏¥»÷ÕßʹÓøÃÎó²îÄܹ»ÔÚûÓÐÈκÎÓû§½»»¥µÄÇéÐÎÏ£¬ÔÚÒ×Êܹ¥»÷µÄ»úе¼äÈö²¥£¬´Ó¶øÓпÉÄÜѬȾÕû¸ö×éÖ¯µÄÍøÂç¡£
¾Ý±¨µÀ£¬¸ÃÎó²îÒѾ±£´æ17 ÄêÖ®¾Ã£¬Î¢Èí¹Ù·½¸ø³öµÄÆÀ·ÖΪ 10 ·Ö£¨CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C£©¡£
µ±DNS·þÎñÆ÷ÆÊÎö´«ÈëµÄÅÌÎÊ»ò¶Ôת·¢ÇëÇóÏìӦʱ£¬¿ÉÒÔʹÓøÃÎó²î¡£
Check PointµÄÑо¿Ö°Ô±·¢Ã÷£¬Í¨¹ý·¢ËͰüÀ¨SIG¼Í¼£¨´óÓÚ64KB£©µÄDNSÏìÓ¦¿ÉÒÔÔì³É»ùÓڶѵĻº³åÇøÒç³ö£¬½ø¶øÊ¹¹¥»÷ÕßÄܹ»¿ØÖÆ·þÎñÆ÷¡£
²Î¿¼Á´½Ó£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1350
ÊÜÓ°Ïì²úÆ·°æ±¾
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2012
Windows Server 2012 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 R2 (Server Core installation)
Windows Server 2016
Windows Server 2016 (Server Core installation)
Windows Server 2019
Windows Server 2019 (Server Core installation)
Windows Server, version 1909 (Server Core installation)
Windows Server, version 1903 (Server Core installation)
Windows Server, version 2004 (Server Core installation)
½â¾ö¼Æ»®
΢Èí¹Ù·½ÒÑÕë¶ÔÊÜÓ°ÏìϵͳÐû²¼Çå¾²²¹¶¡£¬Ç¿ÁÒ½¨ÒéÏà¹ØÓû§¾¡¿ì×°Öò¹¶¡¸üС£²¹¶¡Éý¼¶£¬²Î¿¼Á´½Ó:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1350
ÔÚÓ¦Óò¹¶¡Ö®Ç°£¬½¨Ò齫DNSÐÂÎÅ£¨Í¨¹ýTCP£©µÄ×î´ó³¤¶ÈÉèÖÃΪ0xFF00»º½âÎó²î¡£¿ÉÒÔͨ¹ýÖ´ÐÐÒÔÏÂÏÂÁîʵÏÖ£º
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters" /v "TcpReceivePacketSize" /t REG_DWORD /d 0xFF00 /f
net stop DNS && net start DNS
ͬʱ£¬½¨ÒéÉèÖÃDNS·þÎñÆ÷ΪÊÜÐÅÍеķþÎñÆ÷¡£
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







