Windows BlueKeep·ì϶£¨CVE-2019-0708£©

°ä²¼¹¦·ò 2019-09-07

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


2019Äê5ÔÂ14ÈÕ΢Èí°ä²¼Ô¶³Ì×ÀÃæ·þÎñ£¨ÒÔǰ³ÆÎªÖÕ¶Ë·þÎñ£©µÄÔ¶³ÌÖ´ÐдúÂë·ì϶BlueKeep£¨CVE-2019-0708£©µÄ½¨¸´·¨Ê½¡£´Ë·ì϶ÊÇÔ¤Éí·ÝÑéÖ¤ £¬ÎÞÐèÓû§½»»¥²¢ÓпÉÄÜÒÔÀàËÆÈ䳿µÄ·½Ê½´«²¼¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£


9ÔÂ6ÈÕMetasploitÒѾ­½«BlueKeep·ì϶EXP°ä²¼µ½metasploit-frameworkµÄPull requestsÖÐ £¬Ä¿Ç°ÖØÒªÕë¶Ô64λ°æ±¾µÄWindows 7ºÍWindows Server 2008 R2¡£¶ÔÓÚWindows Server 2008 R2 £¬±ØÒªÅú¸Ä×¢²á±í £¬µ«ÈÔÓÐÆäËû¿ÉÄÜÐÔʹÓÃÔÚËùÓÐWindows²Ù×÷ϵͳÉÏ¡£


¹ØÓÚBlueKeep·ì϶µÄÔ¤¾¯ÏêÇé¿É²Î¿¼Î¬ËûÃüµÄº¹Çà·ì϶Ԥ¾¯£º



¡¾·ì϶Ԥ¾¯¡¿Windows RDPÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2019-0708£©



¹ÌÈ»Õë¶Ô´Ë·ì϶ÀûÓõÄÌØ¶¨·ÀÓùºÍ¼ì²âºÜÓÐЧ £¬µ«¡°DejaBlue¡±ÏµÁÐÖнÏеÄRDP·ì϶ͨ³£¶¼Ç¿µ÷Á˴˺Í̸µÄ·çÏÕ¡£¸ÃºÍ̸¹ÌÓеĸ´ÔÓÐÔÅú×¢ £¬½ñÌìÒÑÖªµÄÃýÎó²»»áÊÇ×îºóÒ»¸ö £¬³ö¸ñÊÇÓÉÓÚ·ì϶ÀûÓÿª·¢ÈËÔ±ºÍ×êÑÐÈËÔ±´Ë¿Ì¶ÔRDP¼°ÆäÈõµãÓÐÁ˸üÇá΢µÄÀí½â¡£Ëæ×Å·ì϶ÀûÓÃˮƽµÄÌá¸ß £¬¿ÉÄÜ»á³ÖÐø¿ª·¢¡£

½¨¸´CVE-2019-0708·ì϶ӵÓгÁÒªÐԺͽôÆÈÐÔ £¬½¨ÒéÓû§²»ÒªÐÄ´æÐÒÔË¡£Rapid7 LabsÖ®Ç°ÔøÐ´¹ý×ÔBlueKeep·ì϶°ä²¼ÒÔÀ´ËûÃǹ۲쵽µÄ¶ñÒâRDP»î¶¯ÔÚ³ÖÐøÉÏÉý¡£



±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ŀǰ¼ì²âµ½È«Çò³¬¹ý100Íò¸öϵͳ¿ªÆôRDP·þÎñ¡£×Ըò¹¶¡ÓÚ5Ô°䲼ÒÔÀ´ £¬¸Ã·ì϶Êܵ½Á˰²È«ÐÐÒµµÄ¿í·º¹Ø×¢ £¬½¨ÒéÓû§ºâÁ¿Î´½¨²¹·ì϶ËùÔì³ÉµÄÓ°Ïì¡£


²Î¿¼Á´½Ó£ºhttps://github.com/rapid7/metasploit-framework/pull/12283?from=timeline&isappinstalled=0https://blog.rapid7.com/2019/09/06/initial-metasploit-exploit-module-for-bluekeep-cve-2019-0708/