¡¾Îó²îͨ¸æ¡¿Netlogon?ÌØÈ¨ÌáÉýÎó²î£¨CVE-2020-1472£©´¦Öóͷ£ÊÖ²á
2020-09-17
Ò». Îó²î¸ÅÊö
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½ÍâÑóÇå¾²¹«Ë¾Secura¹ûÕæÁËNetLogonÌØÈ¨ÌáÉýÎó²î£¨CVE-2020-1472£©µÄÏêϸÐÅÏ¢ÓëÑéÖ¤¾ç±¾£¬µ¼ÖÂÎó²îΣº¦ÝëµØÌáÉý¡£¹¥»÷ÕßÐèÔÚÓëÄ¿µÄÏàͬµÄ¾ÖÓòÍø£¨LAN£©ÉϵÄÅÌËã»ú¾ÙÐÐʹÓã¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýNetLogonÔ¶³ÌÐÒ飨MS-NRPC£©½¨ÉèÓëÓò¿ØÖÆÆ÷ÅþÁ¬µÄ Ç徲ͨµÀʱ£¬¿ÉʹÓôËÎó²î»ñÈ¡ÓòÖÎÀíÔ±»á¼ûȨÏÞ¡£´ËÎó²îΪ΢ÈíÔÚ8Ô²¹¶¡¸üÐÂʱÅû¶£¬CVSSÆÀ·ÖΪ10£¬Ó°ÏìÆÕ±é£¬ÏÖÔÚÍøÉÏÒÑÓÐEXPÐû²¼£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
NetlogonÊÇWindowsÖÐÓÃÓÚΪÓò¿ØÖÆÆ÷×¢²áËùÓÐSRV×ÊÔ´¼Í¼µÄ·þÎñ¡£ÌṩÓû§ºÍ»úеÔÚÓòÄÚÍøÂçÉϵÄÈÏÖ¤Óë¸´ÖÆÊý¾Ý¿â¾ÙÐÐÓò¿Ø±¸·Ý£¬»¹ÓÃÓÚά»¤Óò³ÉÔ±ÓëÓòÖ®¼ä¡¢ÓòÓëÓò¿ØÖ®¼ä¡¢ÓòDCÓë¿çÓòDCÖ®¼äµÄ¹ØÏµ¡£
AG¹«Ë¾¿Æ¼¼µÚһʱ¼ä¸´ÏÖÁË´ËÎó²î£º

²Î¿¼Á´½Ó£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2012
Windows Server 2012 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 R2 (Server Core installation)
Windows Server 2016
Windows Server 2016 (Server Core installation)
Windows Server 2019
Windows Server 2019 (Server Core installation)
Windows Server, version 1903 (Server Core installation)
Windows Server, version 1909 (Server Core installation)
Windows Server, version 2004 (Server Core installation)
Èý. Îó²î¼ì²â
3.1 ¹¤¾ßÑéÖ¤
Åû¶´ËÎó²îµÄSecuraÒÑÔÚGitHubÉÏ´«ÁËÑéÖ¤¾ç±¾£¬Ïà¹ØÓû§¿ÉʹÓô˹¤¾ß¾ÙÐмì²â£º
https://github.com/SecuraBV/CVE-2020-1472
ÊÜÓ°Ïìϵͳ£¨Windows Server 2012 R2£©µÄ¼ì²âЧ¹ûÈçÏ£º

3.2 ²úÆ·¼ì²â
AG¹«Ë¾¿Æ¼¼Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS£©ÓëÍøÂçÈëÇÖ¼ì²âϵͳ£¨IDS£©¡¢×ÛºÏÍþв̽Õ루UTS£©ÒѾ߱¸¶Ô´ËÎó²îµÄɨÃèÓë¼ì²âÄÜÁ¦£¬ÇëÓа²ÅÅÒÔÉÏ×°±¸µÄÓû§Éý¼¶ÖÁ×îа汾¡£
|
Çå¾²²úÆ·°æ±¾ |
Éý¼¶°ü°æ±¾ºÅ |
Éý¼¶°üÏÂÔØÁ´½Ó |
|
RSAS V6 ϵͳ²å¼þ°ü |
V6.0R02F01.1917 |
http://update.nsfocus.com/update/downloads/id/108456 |
|
IDS |
5.6.9.23542 |
http://update.nsfocus.com/update/downloads/id/108464 |
|
5.6.10.23542 |
http://update.nsfocus.com/update/downloads/id/108465 |
|
|
UTS |
5.6.10.23542 |
http://update.nsfocus.com/update/downloads/id/108469 |
¹ØÓÚRSASµÄÉý¼¶ÉèÖÃÖ¸µ¼£¬Çë²Î¿¼ÈçÏÂÁ´½Ó£º
https://mp.weixin.qq.com/s/aLAWXs5DgRhNHf4WHHhQyg
ËÄ. Îó²î·À»¤
4.1 ¹Ù·½Éý¼¶
ÏÖÔÚ΢Èí¹Ù·½ÒÑÕë¶ÔÊÜÖ§³ÖµÄϵͳ°æ±¾Ðû²¼ÁËÐÞ¸´´ËÎó²îµÄÇå¾²²¹¶¡£¬Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì×°Öò¹¶¡¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472
×¢£ºÓÉÓÚÍøÂçÎÊÌâ¡¢ÅÌËã»úÇéÐÎÎÊÌâµÈÔµ¹ÊÔÓÉ£¬Windows UpdateµÄ²¹¶¡¸üпÉÄÜ·ºÆðʧ°Ü¡£Óû§ÔÚ×°Öò¹¶¡ºó£¬Ó¦ÊµÊ±¼ì²é²¹¶¡ÊÇ·ñÀֳɸüС£
ÓÒ¼üµã»÷Windowsͼ±ê£¬Ñ¡Ôñ“ÉèÖÃ(N)”£¬Ñ¡Ôñ“¸üкÍÇå¾²”-“Windows¸üД£¬Éó²é¸ÃÒ³ÃæÉϵÄÌáÐÑÐÅÏ¢£¬Ò²¿Éµã»÷“Éó²é¸üÐÂÀúÊ·¼Í¼”Éó²éÀúÊ·¸üÐÂÇéÐΡ£
Õë¶ÔδÀÖ³É×°ÖõĸüУ¬¿Éµã»÷¸üÐÂÃû³ÆÌø×ªµ½Î¢Èí¹Ù·½ÏÂÔØÒ³Ãæ£¬½¨ÒéÓû§µã»÷¸ÃÒ³ÃæÉϵÄÁ´½Ó£¬×ªµ½“Microsoft¸üÐÂĿ¼”ÍøÕ¾ÏÂÔØ×ÔÁ¦³ÌÐò°ü²¢×°Öá£
4.2 ÆäËû·À»¤²½·¥
ÔÚ×°Öøüв¹¶¡ºó£¬»¹¿Éͨ¹ý°²ÅÅÓò¿ØÖÆÆ÷ (DC) Ç¿ÖÆÄ£Ê½ÒÔÃâÊܵ½¸ÃÎó²îÓ°Ï죺
Çë²Î¿¼¹Ù·½Îĵµ¾ÙÐÐÉèÖá¶ÔõÑùÖÎÀíÓë CVE-2020-1472 Ïà¹ØµÄ Netlogon Ç徲ͨµÀÅþÁ¬µÄ¸ü¸Ä¡·£º
https://support.microsoft.com/zh-cn/help/4557222/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc
4.3 ²úÆ··À»¤
Õë¶Ô´ËÎó²î£¬AG¹«Ë¾¿Æ¼¼ÍøÂçÈëÇÖ·À»¤ÏµÍ³(IPS) ÒÑÐû²¼¹æÔòÉý¼¶°ü£¬ÇëÏà¹ØÓû§Éý¼¶ÖÁ×îа汾¹æÔò£¬ÒÔÐγÉÇå¾²²úÆ··À»¤ÄÜÁ¦¡£Çå¾²·À»¤²úÆ·¹æÔò°æ±¾ºÅÈçÏ£º
|
Çå¾²·À»¤²úÆ· |
¹æÔò°æ±¾ºÅ |
Éý¼¶°üÏÂÔØÁ´½Ó |
|
IPS |
5.6.9.23542 |
http://update.nsfocus.com/update/downloads/id/108464 |
|
5.6.10.23542 |
http://update.nsfocus.com/update/downloads/id/108465 |
²úÆ·¹æÔòÉý¼¶µÄ²Ù×÷°ì·¨Ïê¼ûÈçÏÂÁ´½Ó£º
IPS£ºhttps://mp.weixin.qq.com/s/JsRktENQNj1TdZSU62N0Ww
4.4 ƽ̨¼à²â
AG¹«Ë¾ÆóÒµÇ徲ƽ̨£¨ESP-H£©ÒѾ¾ß±¸Õë¶Ô´ËÎó²îµÄ¼à²âÄÜÁ¦£¬°²ÅÅÓÐAG¹«Ë¾¿Æ¼¼Æ½Ì¨Àà²úÆ·µÄÓû§£¬¿ÉʵÏÖ¶ÔÎó²îµÄƽ̨¼à²âÄÜÁ¦¡£
|
Ç徲ƽ̨ |
Éý¼¶°ü/¹æÔò°æ±¾ºÅ |
|
ESP-H£¨AG¹«Ë¾ÆóÒµÇ徲ƽ̨£© |
ʹÓÃ×îйæÔòÉý¼¶°ü ESP-EVENTRULE-013-20200915 |
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ40¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







