Ó¦¶Ô΢ÈíÔ¶³Ì×ÀÃæ·þÎñ¸ßΣ·ì϶¡°BlueKeep¡±£¨CVE-2019-0708£©×îÈ«½â¾ö¹æ»®

°ä²¼¹¦·ò 2019-05-22
2019Äê5ÔÂ14ÈÕ £¬Î¢Èí°ä²¼²¹¶¡½¨¸´ÁËÒ»¸öÔ¶³Ì×ÀÃæ·þÎñ¸ßΣ·ì϶£¨CVE-2019-0708£©£¨±ðÃû£ºBlueKeep£©¡£¸Ã·ì϶ӰÏìÔ̺¬ Windows XP £¬Windows7 £¬Windows2003 £¬Windows2008 £¬Windows2008R2 µÈÔÚÄڵij£ÓÃWindows×ÀÃæÒÔ¼°·þÎñÆ÷²Ù×÷ϵͳ¡£µ±Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßʹÓÃÔ¶³Ì×ÀÃæÏνӵ½Ö¸±êϵͳ²¢·¢ËÍÌØÔìÒªÇóʱ £¬Äܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£´Ë·ì϶ÊÇÔ¤Éí·ÝÑéÖ¤ £¬ÎÞÐèÓû§½»»¥¡£
 
΢Èí½«´Ë·ì϶½ç˵ΪÑϳÁ¼¶±ð £¬Ç¿ÁÒ½¨Òé¿í´óÓû§ÊµÊ±¸üР£¬ÒÔÃâÔâ·ê¹¥»÷¡£Ä¿Ç° £¬»¥ÁªÍøÉÏÒѾ­³öÏÖÁËһЩƾ¾Ý·ì϶²¹¶¡ÐγɵÄÉв»³ÉÊìµÄPOC´úÂë¡£Ëæ×Å·ì϶µÄÉî¿Ì×êÑÐ £¬Ïà¶Ô³ÉÊì²¢ÇÒ¿ÉÀûÓõÄPOC»òºÜ¿ì³öÏÖ £¬Ò»µ©±»ºÚ¿Í´ó¹æÄ£ÀûÓà £¬½«»áÔì³ÉÀàËÆ2017Äê¡°WannaCry¡±ÀÕË÷È䳿µÄÑϳÁºó¹û¡£
 
±¦ÔËÀ³¹Ù·½ÍøÕ¾ÒѾ­°ä²¼½ØÖÁĿǰ×îÈ«µÄ²úµÈµÚÓ¦¶Ô¹æ»® £¬ÒÔÓ¦¶Ô¿ÉÄܵ½À´µÄ´ó¹æÄ£¹¥»÷¡£



01¡¢²úÆ·½â¾ö¹æ»®


1¡¢·ì϶ɨÃè

±¦ÔËÀ³¹Ù·½ÍøÕ¾Ìì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0ÓÚ2019Äê5ÔÂ14ÈÕ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü £¬Ö§³Ö¶Ô¸Ã·ì϶½øÐмì²â £¬Óû§Éý¼¶Ì쾵©ɨ²úÆ··ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃè¡£6070°æ±¾Éý¼¶°üΪ607000220 £¬Éý¼¶°üÏÂÔØµØÖ·£º
/article/type/1/146.html
 
ÇëʹÓÃÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾 £¬ÊµÊ±¶Ô¸Ã·ì϶½øÐмì²â £¬ÒԱ㾡¿ì²ÉÈ¡·À±¸´ëÊ©¡£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

 
2¡¢ÍøÂçÌìǵ¼ì²â

ÒѲ¿Êð±¦ÔËÀ³¹Ù·½ÍøÕ¾IDS¡¢IPS¡¢WAF¡¢APT²úÆ·µÄ¿Í»§ÇëÉý¼¶µ½×îÐÂÊÂÎñ¿â £¬²¢È·ÈÏÈçÏÂÊÂÎñ¹æ¶¨ÒѾ­Ï·¢²¢ÀûÓà £¬¼´¿ÉÓÐЧ¼ì²â»ò×è¶Ï¹¥»÷£º
TCP_΢ÈíÔ¶³Ì×ÀÃæ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶[CVE-2019-0708]


3¡¢Ó¦¼±´ëÖÃ
 
±¦ÔËÀ³¹Ù·½ÍøÕ¾¡°Ìì¾µÍøÂ簲ȫÊÂÎñÓ¦¼±´ëÖù¤¾ßÏ䡱²úÆ· £¬Õë¶Ô2019Äê5ÔÂ14ÈÕÅû¶µÄ΢ÈíÔ¶³Ì×ÀÃæ·þÎñÔ¶³ÌÖ´ÐдúÂë·ì϶CVE-2019-0708 £¬µÚÒ»¹¦·òÓ¦¼±ÏìÓ¦¸Ã·ì϶µÄ´ëÖÃÔ¤°¸ £¬²¢°ä²¼×îеIJúÆ·Éý¼¶°ü°æ±¾Îª600070080 £¬Îª¿Í»§´øÀ´µÚÒ»ÊÖµÄÓ¦¼±´ëÖù滮¡£

ÇëʹÓá°Ìì¾µÍøÂ簲ȫÊÂÎñÓ¦¼±´ëÖù¤¾ßÏ䡱²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾 £¬ÊµÊ±¶Ô¸Ã·ì϶½øÐÐÓ¦¼±´ëÖà £¬ÓÐЧ·À±¸¸Ã·ì϶´øÀ´µÄ°²È«·çÏպ;­¼ÃËðʧ¡£
 
±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 

02¡¢¹Ù·½½â¾ö¹æ»®


1¡¢Î¢ÈíÒѾ­°ä²¼Õë¶Ô¸Ã·ì϶µÄ²¹¶¡ £¬ÇëʹÓÃÉÏÊöÊÜÓ°ÏìµÄ²Ù×÷ϵͳÓû§ÊµÊ±¸üС£

¡ôÕë¶ÔWindows XP £¬Windows2003ϵͳµÄ²¹¶¡ÏÂÔØÒ³Ãæ£º
https://support.microsoft.com/en-us/help/4500705/customer-guidance-for-cve-2019-0708

¡ôÕë¶ÔWindows 7 £¬Windows Server 2008 R2 £¬Windows Server 2008ϵͳµÄ²¹¶¡ÏÂÔØÒ³Ãæ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708

2¡¢¶ÔÓÚÎÞ·¨ÊµÊ±¸üв¹¶¡µÄÓû§ £¬Ç뾡Á¿¹Ø¹ØÔ¶³Ì×ÀÃæ·þÎñ £¬Ô¤·ÀÖ÷»ú±»Ö±½Ó¶³öÔÚ»¥ÁªÍøÉÏ¡£

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾