΢Èí¸ßΣ·ì϶¹«¸æ £¨CVE-2020-0796/ CVE-2020-0684£©
°ä²¼¹¦·ò 2020-03-112020Äê3ÔÂ11ÈÕ£¬£¬£¬Î¢Èí°ä²¼±¾Ô°²È«²¼¸æ£¬£¬£¬ÆäÖÐÔ̺¬¡°È䳿ÐÍ¡±Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-0796£©ºÍ¡°ÕðÍø¼¶¡±LNK·ì϶£¨CVE-2020-0684£©¡£¡£OG¶«·½Ìü¹«Ë¾ÌáÐÑ¿í´óÓû§¾¡¿ìÉý¼¶ÏµÍ³²¹¶¡»òѡȡÏàÓ¦µÄ·À»¤´ëÊ©¡£¡£
CVE-2020-0796
¡ñ ·ì϶ÃèÊö
CVE-2020-0796ÊÇ´æÔÚÓÚ΢Èí·þÎñÆ÷ÐÂÎÅ¿é3.0 (SMBv3)ºÍ̸ÖеÄÈ䳿¼¶·ì϶£¬£¬£¬Ä¿Ç°ÉÐδµÃµ½ÐÞ¸´¡£¡£
°²È«¹«Ë¾Cisco TalosºÍFortinetÔÚÆäÍøÕ¾Éϰ䲼ÁË CVE-2020-0796·ì϶µÄ¼¼Êõϸ½Ú¡£¡£¸Ã·ì϶ÊÇÓÉSMBv3´¦ÖöñÒâѹËõÊý¾Ý°üʱ½øÈëÃýÎóÁ÷³ÌÔì³ÉµÄ£¬£¬£¬Ô¶³ÌµÄδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ÔÚÀûÓ÷¨Ê½¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡£¸Ã·ì϶Óë¡°Eternal Blue¡±¶¼ÊÇ´æÔÚÓÚsmbºÍ̸µÄ·ì϶£¬£¬£¬²¢ÇÒÊÇÔ¶³Ì¿ÉÀûÓ÷ì϶£¬£¬£¬»ò½«³ÉΪÏÂÒ»´úÀÕË÷²¡¶¾¹¥»÷Ö¸±êÊ×Ñ¡·½Ê½¡£¡£ÓÉÓڸ÷ì϶Óë¡°Eternal Blue ¡±ÀàËÆ£¬£¬£¬ÍÆÌØÒѾÆðÍ·³¢ÊÔ½«Æä¶¨ÃûΪ¡°Corona Blue¡±¡£¡£
¡ñ ·À»¤¹æ»®
£¨1£©½ûÓÃSMBv3ѹËõ£¬£¬£¬Ê¹ÓÃÒÔÏÂPowerShellºÅÁî¿É½ûÓÃSMBv3·þÎñµÄѹËõ£¨ÎÞÐèÖØÐÂÆô¶¯£©£º
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 1 -Force
£¨2£©¹Ø±Õ445¶Ë¿Ú£¬£¬£¬·ÀÓùÀûÓø÷ì϶µÄ¹¥»÷¡£¡£
¡ñ Ó°Ïì°æ±¾
Windows 10 Version 1903 for 32-bit Systems
Windows 10 Version 1903 for ARM64-based Systems
Windows 10 Version 1903 for x64-based Systems
Windows 10 Version 1909 for 32-bit Systems
Windows 10 Version 1909 for ARM64-based Systems
Windows 10 Version 1909 for x64-based Systems
Windows Server, version 1903 (Server Core installation)
Windows Server, version 1909 (Server Core installation)
CVE-2020-0684
¡ñ ·ì϶ÃèÊö
CVE-2020-0684´æÔÚÓÚLNKÎļþµÄ´¦Öùý³ÌÖУ¬£¬£¬ºÍ2010ÄêÕðÍø²¡¶¾ËùʹÓõķì϶CVE-2010-2568ÒÔ¼°2017Äê΢ÈíÐÞ¸´µÄ·ì϶CVE-2017-8464ÀàËÆ¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ý¶ñÒâ»ú¹ØµÄLNKÎļþÓÕʹÊܺ¦ÕßÒÔÆä×ÔÉíµÄÓû§È¨ÏÞÖ´ÐÐËÁÒâ´úÂ룬£¬£¬Î¢Èí½«ÆäÑÏÖØµÈ¼¶½ç˵ΪCritical¡£¡£
Ö»¹Ü΢Èí°ä·¢²»ÔÙΪwin7Ìṩ°²È«¸üУ¬£¬£¬win7Óû§ÈÔ¾ÉÄܹ»ÏÂÔØÕë¶Ô¸Ã·ì϶µÄ²¹¶¡¡£¡£
¡ñ ·À»¤¹æ»®
£¨1£©ÏµÍ³Éý¼¶ÖÁ×îв¹¶¡¡£¡£
£¨2£©Î´ÏÂÔØ²¹¶¡µÄÓû§Ó¦¾¡Á¿Ô¤·À½Ó¹ÜËûÈË·¢Ë͹ýÀ´µÄLNKÎļþ»ò´ò¿ª´æÓÐLNKÎļþµÄ´æ´¢É豸£¬£¬£¬Èç´ò¿ªÄ°ÉúÈËÌṩµÄUÅÌ¡£¡£
¡ñ Ó°Ïì°æ±¾
£¨ÒÔϽöÁгöÊÜÓ°ÏìϵͳµÄ´ó°æ±¾ºÅ£¬£¬£¬¾ßÌåµÄÓ°Ïì°æ±¾ÐÅÏ¢°Ý¼û²Î¿¼Á´½Ó5¡£¡££©
Windows 10
Windows 10 Version 1607
Windows 10 Version 1709
Windows 10 Version 1803
Windows 10 Version 1809
Windows 10 Version 1903
Windows 10 Version 1909
Windows 7 Service Pack 1
Windows 8.1
Windows RT 8.1
Windows Server 2008 Service Pack 2
Windows Server 2008 R2 Service Pack 1
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016
Windows Server 2019
Windows Server, version 1803
Windows Server, version 1903
Windows Server, version 1909
²Î¿¼Á´½Ó£º
1.https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200005
2.https://fortiguard.com/encyclopedia/ips/48773
3.https://twitter.com/search?q=CVE-2020-0796&src=typed_query
4.https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796
5.https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0684


¾©¹«Íø°²±¸11010802024551ºÅ