Windows TCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐЩ¶´À´Ï®£¡¶«É­Æ½Ì¨Ìṩ½â¾ö·½°¸

Ðû²¼Ê±¼ä 2024-08-20

Windows ÊÇÓÉ΢Èí¹«Ë¾¿ª·¢µÄһϵÁÐͼÐÎÓû§½çÃæ²Ù×÷ϵͳ¡£×Ô 1985 ÄêÊ×´ÎÐû²¼ÒÔÀ´£¬Windows ÒѾ­¾­ÀúÁ˶à¸ö°æ±¾ºÍÖØ´ó¸üУ¬³ÉΪȫÇòʹÓÃ×î¹ã·ºµÄ²Ù×÷ϵͳ֮һ¡£


½üÈÕ£¬¶«É­Æ½Ì¨¼à²âµ½Î¢ÈíÔÚ°ËÔ·ÝÄþ¾²²¹¶¡ÖÐÐÞ¸´ÁËÒ»¸öÓ°ÏìWindows TCP/IPЭÒéÕ»µÄÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£¸Ã©¶´CVSSÆÀ·ÖΪ9.8£¬¶øÇÒ±»Î¢Èí¹Ù·½±ê־ΪExploitation More Likely(¸ß¿ÉÄÜÐÔÀûÓÃ)¡£


¾­¹ýÑо¿È·ÈÏ£¬¸Ã©¶´ÊÇÓÉÓÚWindowsµÄTCP/IP×é¼þ´íÎóµÄ´¦ÖÃÁËIPv6Êý¾Ý£¬´Ó¶øÔÚºóÐøµÄÁ÷³ÌÖе¼ÖÂÁËÕûÊýÒç³ö¡£¹¥»÷Õß¿ÉÒÔÔÚδ¾­Éí·ÝÑéÖ¤µÄÇé¿öÏ£¬Í¨¹ýÏòÊܺ¦ÕßÖظ´·¢ËÍÌض¨½á¹¹µÄIPv6Êý¾Ý°üÀ´´¥·¢Â©¶´£¬´Ó¶øÔì³ÉÀ¶ÆÁËÀ»ú(BSOD)ÉõÖÁ´úÂëÖ´ÐС£


¸Ã©¶´ÀûÓÃÎ޸У¬Ö»ÐèÄ¿µÄÖ÷»úÆôÓÃIPv6ЭÒé¼´¿É´¥·¢£¬¶øÇÒ¼¸ºõÓ°ÏìËùÓг£¼ûWindows°æ±¾¡£¿¼Âǵ½Windowsͨ³£Ä¬ÈÏÆôÓÃIPv6¹¦Ð§£¬½¨Òé¿Í»§»ý¼«×öºÃÅŲéºÍ·À»¤£¬¾¡¿ì°²×°¹Ù·½²¹¶¡£¬ÒÔ·À·¶Ç±ÔÚ·çÏÕ¡£


ͼƬ1.png


©¶´¸´ÏÖ


ͼƬ2.png

ͼƬ3.png


½â¾ö·½°¸


Ò»¡¢¹Ù·½ÐÞ¸´·½°¸


¹Ù·½ÒÑÐû²¼Äþ¾²¸üУ¬½¨Ò齫ÊÜÓ°ÏìµÄWindowsÉý¼¶ÖÁ×îа汾£º

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063


¶þ¡¢ÁÙʱÐÞ¸´·½°¸


ÔÚ²»Ó°ÏìÕý³£ÒµÎñµÄÇé¿öÏ£¬¿ÉÒÔÔÝʱ½«IPv6¹¦Ð§¹Ø±Õ¡£


Èý¡¢¶«É­Æ½Ì¨½â¾ö·½°¸


1¡¢¶«É­Æ½Ì¨¼ì²âÀà²úÎï·½°¸


£¨1£©¶«É­Æ½Ì¨¡°ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡±Éý¼¶µ½20240819°æ±¾¼´¿ÉÖ§³Ö¼ì²â¸Ã©¶´¡£


ͼƬ4.png


£¨2£©¶«É­Æ½Ì¨ ¡°ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡± Éý¼¶µ½20240819°æ±¾¼´¿ÉÖ§³Ö¼ì²â¸Ã©¶´¡£


ͼƬ5.jpg


2¡¢¶«É­Æ½Ì¨Â©É¨²úÎï·½°¸


£¨1£©¡°¶«É­Æ½Ì¨Ìì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳ¡±6075°æ±¾Òѽô¼±Ðû²¼Õë¶Ô¸Ã©¶´µÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸Ã©¶´½øÐÐɨÃ裬Óû§Éý¼¶³ß¶È©¶´¿âºó¼´¿É¶Ô¸Ã©¶´½øÐÐɨÃ裺


6070°æ±¾Éý¼¶°üΪ607000582-607000583.vup£¬Éý¼¶°üÏÂÔصØÖ·£º

https://venustech.download.venuscloud.cn/


ͼƬ6.png


£¨2£©¶«É­Æ½Ì¨Ìì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳ608XϵÁа汾Òѽô¼±Ðû²¼Õë¶Ô¸Ã©¶´µÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸Ã©¶´½øÐÐɨÃ裬Óû§Éý¼¶³ß¶È©¶´¿âºó¼´¿É¶Ô¸Ã©¶´½øÐÐɨÃ裺


6080°æ±¾Éý¼¶°üΪÖ÷»ú²å¼þ°ü6080000133-S6080000134.svs©ɨ²å¼þ°üÏÂÔصØÖ·£º

https://venustech.download.venuscloud.cn/


ͼƬ7.jpg


3¡¢¶«É­Æ½Ì¨×ʲúÓë´àÈõÐÔ¹ÜÀíƽ̨²úÎï·½°¸


¶«É­Æ½Ì¨×ʲúÓë´àÈõÐÔ¹ÜÀíƽ̨ʵʱÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢£¬¶ÔÈë¿â×ʲú©¶´Windows TCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2024-38063£©½øÐйÜÀí¡£


ͼƬ8.png


4¡¢¶«É­Æ½Ì¨Äþ¾²¹ÜÀíºÍ̬ÊƸÐ֪ƽ̨²úÎï·½°¸


Óû§¿ÉÒÔͨ¹ýÌ©ºÏÄþ¾²¹ÜÀíºÍ̬ÊƸÐ֪ƽ̨£¬½øÐйØÁª¼ÆıÅäÖ㬽áºÏʵ¼Ê»·¾³ÖÐϵͳÈÕÖ¾ºÍÄþ¾²É豸µÄ¸æ¾¯ÐÅÏ¢½øÐÐÁ¬Ðø¼à¿Ø£¬´Ó¶ø·¢ÏÖ¡°Windows TCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2024-38063£©¡±µÄ©¶´ÀûÓù¥»÷ÐÐΪ¡£


£¨1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬Í¨¹ý´àÈõÐÔ·¢ÏÖ¹¦Ð§Õë¶Ô¡°Windows TCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2024-38063£©¡±Â©¶´É¨ÃèÈÎÎñ£¬ÅŲé¹ÜÀíÍøÂçÖÐÊÜ´Ë©¶´Ó°ÏìµÄÖØÒª×ʲú¡£


ͼƬ9.png


£¨2£©Æ½Ì¨¡°¹ØÁª·ÖÎö¡±Ä£¿éÖУ¬Ìí¼Ó¡°L2_WindowsTCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐЩ¶´¡±£¬Í¨¹ý¶«É­Æ½Ì¨¼ì²âÉ豸¡¢Ä¿±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬·¢ÏÖÍⲿ¹¥»÷ÐÐΪ£º


ͼƬ10.png


ͨ¹ý·ÖÎö¹æÔò×Ô¶¯½«"L2_WindowsTCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐЩ¶´"©¶´ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ìí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ß·çÏÕÁ¬½Ó¡±ÖУ¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓá£


£¨3£©Ìí¼Ó¡°L3_WindowsTCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐЩ¶´ÀûÓÃÀֳɡ±£¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ»ò°üÂÞ¡°L2_WindowsTCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐЩ¶´¡±£¬¹¥»÷½á¹û¼´ÊÇ¡°¹¥»÷Àֳɡ±£¬Ä¿µÄµØÖ·ÒýÓÃ×ʲú©¶´»òÔ´µØÖ·Æ¥ÅäÍþвÇ鱨£¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶÈ¡£


ͼƬ11.png


£¨4£©ATT&CK¹¥»÷Á´Ìõ·ÖÎöÓëSOAR´¦Öý¨Òé


ƾ¾Ý¶ÔCVE-2024-38063©¶´µÄ¹¥»÷ÀûÓùý³Ì½øÐзÖÎö£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍ¼¼Êõ½×¶Î£¬ÁýÕÖµÄTTP°üÂÞ£º


TA0001³õʼ·ÃÎÊ£ºT1190ÀûÓÃÃæÏò¹«ÖÚµÄÓ¦Ó÷¨Ê½

TA0002Ö´ÐУºT1059ÃüÁîºÍ½Å±¾½âÊÍÆ÷


ͼƬ12.png


ͨ¹ýÌ©ºÏÄþ¾²¹ÜÀíºÍ̬ÊƸÐ֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´¦ÖÃÄÜÁ¦£¬Õë¶Ô¸Ã©¶´ÀûÓõĸ澯ʼþ±àÅž籾£¬½øÐÐ×Ô¶¯»¯´¦Öá£