¡¾Ç徲ͨ¸æ¡¿Windows Print SpoolerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-1675/CVE-2021-34527£©´¦Öóͷ£ÊÖ²á
2021-07-08
Ò». Îó²î¸ÅÊö
±±¾©Ê±¼ä7ÔÂ7ÈÕ£¬Î¢ÈíÕë¶ÔCVE-2021-34527£¨PrintNightmare£©Ðû²¼ÁËÇå¾²¸üУ¬AG¹«Ë¾¿Æ¼¼CERT½¨Òé¿í´óÓû§¾¡¿ì×°Öò¹¶¡¾ÙÐзÀ»¤¡£
6ÔÂ29ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½ÓÐÇå¾²Ñо¿Ô±ÔÚGitHubÉÏÐû²¼ÁËWindows Print Spooler Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨PrintNightmare£©µÄEXP£¬Print SpoolerÊÇWindowsϵͳÖÐÖÎÀí´òÓ¡Ïà¹ØÊÂÎñµÄ·þÎñ£¬ÓÃÓÚÖÎÀíËùÓÐÍâµØºÍÍøÂç´òÓ¡ÐÐÁв¢¿ØÖÆËùÓдòÓ¡ÊÂÇé¡£WindowsϵͳĬÈÏ¿ªÆôPrint Spooler·þÎñ£¬Í¨Ë×Óû§¿ÉÒÔʹÓôËÎó²îÌáÉýÖÁSYSTEMÖÎÀíȨÏÞ¡£ÔÚÓòÇéÐÎÏ£¬ÓòÓû§¿ÉÔ¶³ÌʹÓøÃÎó²îÒÔSYSTEMȨÏÞÔÚÓò¿ØÖÆÆ÷ÉÏÖ´ÐÐí§Òâ´úÂ룬´Ó¶ø»ñµÃÕû¸öÓòµÄ¿ØÖÆÈ¨¡£AG¹«Ë¾¿Æ¼¼Ñо¿ÍŶÓÈ·ÈÏ£¬´ËEXPÔÚ×°ÖÃÁË΢Èí¹Ù·½6ÔÂÇå¾²²¹¶¡¸üÐÂÖÐÐû²¼µÄCVE-2021-1675ÐÞ¸´³ÌÐòµÄÇéÐÎÏÂÈԿɾÙÐÐʹÓá£
±±¾©Ê±¼ä7ÔÂ2ÈÕ£¬Î¢Èí¹ÙÄ¿µÄ¶Ô¹ûÕæµÄEXPÐû²¼ÁËCVE-2021-34527µÄÎó²îͨ¸æ£¬²¢ÌṩÁËÔÝʱ½â¾ö¼Æ»®¡£
´Ëǰmimikatz Òѽ«´ËEXPÎäÆ÷»¯£º
²Î¿¼Á´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-1675
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527
¶þ. ÊÂÎñʱ¼äÏß
2021-06-09 ΢ÈíÐû²¼Ô¶ÈÇå¾²¸üУºÍ¨¸æ½ç˵CVE-2021-1675ΪÍâµØÌáȨÎó²î
2021-06-09 AG¹«Ë¾¿Æ¼¼CERTÐû²¼Í¨¸æ£ºÖ¸³ö¸ÃÎó²î¿ÉʵÏÖÓòÇéÐÎRCE
Ïê¼û£ºhttps://mp.weixin.qq.com/s/0FzhRsbc17KHXL7z4CKinQ
2021-06-21 ΢Èí¸üÐÂͨ¸æ£º½«CVE-2021-1675¸ÄΪԶ³Ì´úÂëÖ´ÐÐÎó²î
2021-06-29 Îó²îPOC¹ûÕæ
2021-06-29 ÔÚWindows Server 2019ϵͳ²¹¶¡ÇéÐθ´ÏÖÊÓÆµ¹ûÕæ
2021-07-01 mimikatzʵÏÖÎäÆ÷»¯¼¯³É
2021-07-02 ΢Èí½ôÆÈÐû²¼CVE-2021-34527ͨ¸æ£¨Î´Ðû²¼²¹¶¡£©
2021-07-02 AG¹«Ë¾¿Æ¼¼CERT¸üÐÂͨ¸æ
2021-07-07 ΢ÈíÐû²¼CVE-2021-34527Îó²î²¹¶¡
2021-07-07 AG¹«Ë¾¿Æ¼¼CERTÐû²¼´¦Öóͷ£ÊÖ²á
Èý. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
Windows Server 2012 R2 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server Core installation)
Windows Server 2012
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows RT 8.1
Windows 8.1 for x64-based systems
Windows 8.1 for 32-bit systems
Windows 7 for x64-based Systems Service Pack 1
Windows 7 for 32-bit Systems Service Pack 1
Windows Server 2016 (Server Core installation)
Windows Server 2016
Windows 10 Version 1607 for x64-based Systems
Windows 10 Version 1607 for 32-bit Systems
Windows 10 for x64-based Systems
Windows 10 for 32-bit Systems
Windows Server, version 20H2 (Server Core Installation)
Windows 10 Version 20H2 for ARM64-based Systems
Windows 10 Version 20H2 for 32-bit Systems
Windows 10 Version 20H2 for x64-based Systems
Windows Server, version 2004 (Server Core installation)
Windows 10 Version 2004 for x64-based Systems
Windows 10 Version 2004 for ARM64-based Systems
Windows 10 Version 2004 for 32-bit Systems
Windows 10 Version 21H1 for 32-bit Systems
Windows 10 Version 21H1 for ARM64-based Systems
Windows 10 Version 21H1 for x64-based Systems
Windows Server, version 1909 (Server Core installation)
Windows 10 Version 1909 for ARM64-based Systems
Windows 10 Version 1909 for x64-based Systems
Windows 10 Version 1909 for 32-bit Systems
Windows Server 2019 (Server Core installation)
Windows Server 2019
Windows 10 Version 1809 for ARM64-based Systems
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems
ËÄ. Îó²î¼ì²â
4.1 ²úÆ·¼ì²â
AG¹«Ë¾¿Æ¼¼Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS£©¡¢ÍøÂçÈëÇÖ¼ì²âϵͳ£¨IDS£©Óë×ÛºÏÍþв̽Õ루UTS£©ÒѾ߱¸¶Ô´ËÎó²îµÄɨÃèÓë¼ì²âÄÜÁ¦£¬ÇëÓа²ÅÅÒÔÉÏ×°±¸µÄÓû§Éý¼¶ÖÁ×îа汾¡£
|
Çå¾²²úÆ·°æ±¾ |
Éý¼¶°ü°æ±¾ºÅ |
Éý¼¶°üÏÂÔØÁ´½Ó |
|
RSAS V6 ϵͳ²å¼þ°ü |
V6.0R02F01.2400 |
http://update.nsfocus.com/update/listRsasDetail/v/vulsys |
|
IDS |
5.6.9.25788 |
http://update.nsfocus.com/update/listNewidsDetail/v/rule5.6.9 |
|
5.6.10.25788 |
http://update.nsfocus.com/update/listNewidsDetail/v/rule5.6.10 |
|
|
5.6.11.25788 |
http://update.nsfocus.com/update/listNewidsDetail/v/rule5.6.11 |
|
|
UTS |
5.6.10.25788 |
http://update.nsfocus.com/update/listBsaUtsDetail/v/rule2.0.0 |
¹ØÓÚRSASµÄÉý¼¶ÉèÖÃÖ¸µ¼£¬Çë²Î¿¼ÈçÏÂÁ´½Ó£º
https://mp.weixin.qq.com/s/aLAWXs5DgRhNHf4WHHhQyg
Îå. Îó²î·À»¤
5.1 ²¹¶¡¸üÐÂ
ÏÖÔÚ΢Èí¹Ù·½ÒÑÕë¶ÔÖ§³ÖµÄϵͳ°æ±¾Ðû²¼ÁËÐÞ¸´ÒÔÉÏÎó²îµÄÇå¾²²¹¶¡£¬Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì×°Öò¹¶¡¾ÙÐзÀ»¤£¬ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-1675
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-34527
ÏÖÔÚÉÐÓÐÉÙ²¿·ÖWindows °æ±¾ÔÝδÐû²¼CVE-2021-34527µÄÇå¾²²¹¶¡£¬Î¢Èí³ÆºÜ¿ì½«»áÐû²¼¸üУ¬ÇëÏà¹ØÓû§Ò»Á¬¾ÙÐйØ×¢¡£
±¾´Î²¹¶¡×°ÖÃÐèÒªÒ»¶¨Ç°ÖøüУ¬ÏêÇéÇë²Î¿¼£ºhttps://support.microsoft.com/zh-cn/topic/july-6-2021-kb5004945-os-builds-19041-1083-19042-1083-and-19043-1083-out-of-band-44b34928-0a71-4473-aa22-ecf3b83eed0e
×¢£ºÓÉÓÚÍøÂçÎÊÌâ¡¢ÅÌËã»úÇéÐÎÎÊÌâµÈÔµ¹ÊÔÓÉ£¬Windows UpdateµÄ²¹¶¡¸üпÉÄÜ·ºÆðʧ°Ü¡£Óû§ÔÚ×°Öò¹¶¡ºó£¬Ó¦ÊµÊ±¼ì²é²¹¶¡ÊÇ·ñÀֳɸüС£
ÓÒ¼üµã»÷Windowsͼ±ê£¬Ñ¡Ôñ“ÉèÖÃ(N)”£¬Ñ¡Ôñ“¸üкÍÇå¾²”-“Windows¸üД£¬Éó²é¸ÃÒ³ÃæÉϵÄÌáÐÑÐÅÏ¢£¬Ò²¿Éµã»÷“Éó²é¸üÐÂÀúÊ·¼Í¼”Éó²éÀúÊ·¸üÐÂÇéÐΡ£
Õë¶ÔδÀÖ³É×°ÖõĸüУ¬¿Éµã»÷¸üÐÂÃû³ÆÌø×ªµ½Î¢Èí¹Ù·½ÏÂÔØÒ³Ãæ£¬½¨ÒéÓû§µã»÷¸ÃÒ³ÃæÉϵÄÁ´½Ó£¬×ªµ½“Microsoft¸üÐÂĿ¼”ÍøÕ¾ÏÂÔØ×ÔÁ¦³ÌÐò°ü²¢×°Öá£
5.2 ÔÝʱ·À»¤²½·¥
Ò»¡¢Óû§¿Éͨ¹ý×èÖ¹²¢½ûÓÃPrint Spooler·þÎñ¶ÔÒÔÉÏÎó²î¾ÙÐлº½â£º
½øÈëʹÃüÖÎÀíÆ÷£¬Ñ¡Ôñ“·þÎñ”->”·¿ª·þÎñ”->”Ñ¡ÔñPrint Spooler”->”ÓÒ¼üÊôÐÔ”£¬
Æô¶¯ÀàÐ͔ѡÔñ”½ûÓÔ£¬²¢µã»÷”×èÖ¹”£¬¹Ø±Õ·þÎñ£¬µã»÷”Ó¦ÓԺ͔ȷ¶¨”£¬Ê¹ÉèÖÃÉúЧ¡£
×¢£ºÍ£Óô˷þÎñ½«µ¼Ö´òÓ¡¹¦Ð§Ê§Ð§¡£
¶þ¡¢Í¨¹ý×éÕ½ÂÔ½ûÓÃÈëÕ¾Ô¶³Ì´òÓ¡£º
ÔËÐÐ×éÕ½ÂÔ±à¼Æ÷£¨Win+R£¬ÊäÈëgpedit.msc£¬·¿ª×éÕ½ÂÔ±à¼Æ÷£©£¬ÒÀ´Îä¯ÀÀµ½£ºÅÌËã»úÉèÖÃ/ÖÎÀíÄ£°å/´òÓ¡»ú£º½ûÓÓÔÊÐí´òÓ¡ºǫ́´¦Öóͷ£³ÌÐò½ÓÊܿͻ§¶ËÅþÁ¬£º”Õ½ÂÔÒÔ×èÖ¹Ô¶³Ì¹¥»÷¡£
×¢£º´ËÕ½ÂÔ½«Í¨¹ý×èÖ¹ÈëÕ¾Ô¶³Ì´òÓ¡²Ù×÷À´×èÖ¹Ô¶³Ì¹¥»÷¡£¸Ãϵͳ½«²»ÔÙÓÃ×÷´òÓ¡·þÎñÆ÷£¬µ«ÈÔÈ»¿ÉÒÔÍâµØ´òÓ¡µ½Ö±½ÓÅþÁ¬µÄ×°±¸¡£
5.3 ²úÆ··À»¤
Õë¶ÔÉÏÊöÎó²î£¬AG¹«Ë¾¿Æ¼¼ÍøÂçÈëÇÖ·À»¤ÏµÍ³(IPS) ÒÑÐû²¼¹æÔòÉý¼¶°ü£¬ÇëÏà¹ØÓû§Éý¼¶ÖÁ×îа汾¹æÔò£¬ÒÔÐγÉÇå¾²²úÆ··À»¤ÄÜÁ¦¡£Çå¾²·À»¤²úÆ·¹æÔò°æ±¾ºÅÈçÏ£º
|
Çå¾²·À»¤²úÆ· |
¹æÔò°æ±¾ºÅ |
Éý¼¶°üÏÂÔØÁ´½Ó |
|
IPS |
5.6.9.25788 |
http://update.nsfocus.com/update/listNewipsDetail/v/rule5.6.9 |
|
5.6.10.25788 |
http://update.nsfocus.com/update/listNewipsDetail/v/rule5.6.10 |
|
|
5.6.11.25788 |
http://update.nsfocus.com/update/listNewipsDetail/v/rule5.6.11 |
²úÆ·¹æÔòÉý¼¶µÄ²Ù×÷°ì·¨Ïê¼ûÈçÏÂÁ´½Ó£º
IPS£ºhttps://mp.weixin.qq.com/s/JsRktENQNj1TdZSU62N0Ww
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







