΢Èí¸ßΣ©¶´Í¨¸æ £¨CVE-2020-0796/ CVE-2020-0684£©

Ðû²¼Ê±¼ä 2020-03-11

2020Äê3ÔÂ11ÈÕ£¬Î¢ÈíÐû²¼±¾ÔÂÄþ¾²Í¨¸æ£¬ÆäÖаüÂÞ¡°Èä³æÐÍ¡±Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2020-0796£©ºÍ¡°ÕðÍø¼¶¡±LNK©¶´£¨CVE-2020-0684£©¡£¶«É­Æ½Ì¨¹«Ë¾ÌáÐѹã´óÓû§¾¡¿ìÉý¼¶ÏµÍ³²¹¶¡»ò½ÓÄÉÏàÓ¦µÄ·À»¤´ëÊ©¡£


CVE-2020-0796


¡ñ ©¶´ÃèÊö


CVE-2020-0796ÊÇ´æÔÚÓÚ΢Èí·þÎñÆ÷ÏûÏ¢¿é3.0 (SMBv3)ЭÒéÖеÄÈä³æ¼¶Â©¶´£¬Ä¿Ç°ÉÐδµÃµ½ÐÞ¸´¡£

Äþ¾²¹«Ë¾Cisco TalosºÍFortinetÔÚÆäÍøÕ¾ÉÏÐû²¼ÁË CVE-2020-0796©¶´µÄ¼¼Êõϸ½Ú¡£¸Ã©¶´ÊÇÓÉSMBv3´¦ÖöñÒâѹËõÊý¾Ý°üʱ½øÈë´íÎóÁ÷³ÌÔì³ÉµÄ£¬Ô¶³ÌµÄδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÀûÓø鶴ÔÚÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖÐÖ´ÐÐÈÎÒâ´úÂë¡£¸Ã©¶´Óë¡°Eternal Blue¡±¶¼ÊÇ´æÔÚÓÚsmbЭÒéµÄ©¶´£¬¶øÇÒÊÇÔ¶³Ì¿ÉÀûÓ鶴£¬»ò½«³ÉΪÏÂÒ»´úÀÕË÷²¡¶¾¹¥»÷Ä¿±êÊ×Ñ¡·½Ê½¡£ÓÉÓڸ鶴Óë¡°Eternal Blue ¡±ÏàËÆ£¬ÍÆÌØÒѾ­¿ªÊ¼ÊµÑ齫ÆäÃüÃûΪ¡°Corona Blue¡±¡£


¡ñ ·À»¤·½°¸


£¨1£©½ûÓÃSMBv3ѹËõ£¬Ê¹ÓÃÒÔÏÂPowerShellÃüÁî¿É½ûÓÃSMBv3·þÎñµÄѹËõ£¨ÎÞÐèÖØÐÂÆô¶¯£©£º

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 1 -Force

£¨2£©¹Ø±Õ445¶Ë¿Ú£¬·ÀÓùÀûÓø鶴µÄ¹¥»÷¡£


¡ñ Ó°Ïì°æ±¾


Windows 10 Version 1903 for 32-bit Systems    

Windows 10 Version 1903 for ARM64-based Systems      

Windows 10 Version 1903 for x64-based Systems      

Windows 10 Version 1909 for 32-bit Systems    

Windows 10 Version 1909 for ARM64-based Systems      

Windows 10 Version 1909 for x64-based Systems      

Windows Server, version 1903 (Server Core installation)    

Windows Server, version 1909 (Server Core installation)


CVE-2020-0684


¡ñ Â©¶´ÃèÊö


CVE-2020-0684´æÔÚÓÚLNKÎļþµÄ´¦Öùý³ÌÖУ¬ºÍ2010ÄêÕðÍø²¡¶¾ËùʹÓõÄ©¶´CVE-2010-2568ÒÔ¼°2017Äê΢ÈíÐÞ¸´µÄ©¶´CVE-2017-8464ÀàËÆ¡£¹¥»÷Õß¿ÉÒÔͨ¹ý¶ñÒâ½á¹¹µÄLNKÎļþÓÕʹÊܺ¦ÕßÒÔÆä×ÔÉíµÄÓû§È¨ÏÞÖ´ÐÐÈÎÒâ´úÂ룬΢Èí½«ÆäÑÏÖØÆ·¼¶½ç˵ΪCritical¡£


¾¡¹Ü΢ÈíÐû²¼²»ÔÙΪwin7ÌṩÄþ¾²¸üУ¬win7Óû§ÈԾɿÉÒÔÏÂÔØÕë¶Ô¸Ã©¶´µÄ²¹¶¡¡£


¡ñ ·À»¤·½°¸


£¨1£©ÏµÍ³Éý¼¶ÖÁ×îв¹¶¡¡£

£¨2£©Î´ÏÂÔز¹¶¡µÄÓû§Ó¦¾¡Á¿ÖÆÖ¹½ÓÊÕËûÈË·¢Ë͹ýÀ´µÄLNKÎļþ»ò´ò¿ª´æÓÐLNKÎļþµÄ´æ´¢É豸£¬Èç´ò¿ªÄ°ÉúÈËÌṩµÄUÅÌ¡£


¡ñ Ó°Ïì°æ±¾


£¨ÒÔϽöÁгöÊÜÓ°ÏìϵͳµÄ´ó°æ±¾ºÅ£¬ÏêϸµÄÓ°Ïì°æ±¾ÐÅÏ¢²Î¼û²Î¿¼Á´½Ó5¡££©

Windows 10

Windows 10 Version 1607

Windows 10 Version 1709

Windows 10 Version 1803

Windows 10 Version 1809

Windows 10 Version 1903

Windows 10 Version 1909

Windows 7 Service Pack 1

Windows 8.1

Windows RT 8.1

Windows Server 2008 Service Pack 2

Windows Server 2008 R2 Service Pack 1

Windows Server 2012

Windows Server 2012 R2

Windows Server 2016

Windows Server 2019

Windows Server, version 1803

Windows Server, version 1903

Windows Server, version 1909


²Î¿¼Á´½Ó£º


1.https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200005

2.https://fortiguard.com/encyclopedia/ips/48773

3.https://twitter.com/search?q=CVE-2020-0796&src=typed_query

4.https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796

5.https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0684