΢Èí¸ßΣÎó²îͨ¸æ £¨CVE-2020-0796/ CVE-2020-0684£©

Ðû²¼Ê±¼ä 2020-03-11

2020Äê3ÔÂ11ÈÕ£¬£¬£¬£¬£¬Î¢ÈíÐû²¼±¾ÔÂÇ徲ͨ¸æ£¬£¬£¬£¬£¬ÆäÖаüÀ¨¡°È䳿ÐÍ¡±Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-0796£©ºÍ¡°ÕðÍø¼¶¡±LNKÎó²î£¨CVE-2020-0684£©¡£¡£¡£¡£¡£ ¡£ ¡£¼øºÚµ£±£Íø¹«Ë¾ÌáÐÑ¿í´óÓû§¾¡¿ìÉý¼¶ÏµÍ³²¹¶¡»ò½ÓÄÉÏìÓ¦µÄ·À»¤²½·¥¡£¡£¡£¡£¡£ ¡£ ¡£


CVE-2020-0796


¡ñ Îó²îÐÎò


CVE-2020-0796ÊDZ£´æÓÚ΢ÈíЧÀÍÆ÷ÐÂÎÅ¿é3.0 (SMBv3)ЭÒéÖеÄÈ䳿¼¶Îó²î£¬£¬£¬£¬£¬ÏÖÔÚÉÐδ»ñµÃÐÞ¸´¡£¡£¡£¡£¡£ ¡£ ¡£

Çå¾²¹«Ë¾Cisco TalosºÍFortinetÔÚÆäÍøÕ¾ÉÏÐû²¼ÁË CVE-2020-0796Îó²îµÄÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£ ¡£ ¡£¸ÃÎó²îÊÇÓÉSMBv3´¦Öóͷ£¶ñÒâѹËõÊý¾Ý°üʱ½øÈë¹ýʧÁ÷³ÌÔì³ÉµÄ£¬£¬£¬£¬£¬Ô¶³ÌµÄδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÔÚÓ¦ÓóÌÐòÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ ¡£ ¡£¸ÃÎó²îÓë¡°Eternal Blue¡±¶¼ÊDZ£´æÓÚsmbЭÒéµÄÎó²î£¬£¬£¬£¬£¬²¢ÇÒÊÇÔ¶³Ì¿ÉʹÓÃÎó²î£¬£¬£¬£¬£¬»ò½«³ÉΪÏÂÒ»´úÀÕË÷²¡¶¾¹¥»÷Ä¿µÄÊ×Ñ¡·½·¨¡£¡£¡£¡£¡£ ¡£ ¡£ÓÉÓÚ¸ÃÎó²îÓë¡°Eternal Blue ¡±ÏàËÆ£¬£¬£¬£¬£¬ÍÆÌØÒѾ­×îÏÈʵÑ齫ÆäÃüÃûΪ¡°Corona Blue¡±¡£¡£¡£¡£¡£ ¡£ ¡£


¡ñ ·À»¤¼Æ»®


£¨1£©½ûÓÃSMBv3ѹËõ£¬£¬£¬£¬£¬Ê¹ÓÃÒÔÏÂPowerShellÏÂÁî¿É½ûÓÃSMBv3ЧÀ͵ÄѹËõ£¨ÎÞÐèÖØÐÂÆô¶¯£©£º

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 1 -Force

£¨2£©¹Ø±Õ445¶Ë¿Ú£¬£¬£¬£¬£¬·ÀÓùʹÓøÃÎó²îµÄ¹¥»÷¡£¡£¡£¡£¡£ ¡£ ¡£


¡ñ Ó°Ïì°æ±¾


Windows 10 Version 1903 for 32-bit Systems    

Windows 10 Version 1903 for ARM64-based Systems      

Windows 10 Version 1903 for x64-based Systems      

Windows 10 Version 1909 for 32-bit Systems    

Windows 10 Version 1909 for ARM64-based Systems      

Windows 10 Version 1909 for x64-based Systems      

Windows Server, version 1903 (Server Core installation)    

Windows Server, version 1909 (Server Core installation)


CVE-2020-0684


¡ñ Îó²îÐÎò


CVE-2020-0684±£´æÓÚLNKÎļþµÄ´¦Öóͷ£Àú³ÌÖУ¬£¬£¬£¬£¬ºÍ2010ÄêÕðÍø²¡¶¾ËùʹÓõÄÎó²îCVE-2010-2568ÒÔ¼°2017Äê΢ÈíÐÞ¸´µÄÎó²îCVE-2017-8464ÀàËÆ¡£¡£¡£¡£¡£ ¡£ ¡£¹¥»÷Õß¿ÉÒÔͨ¹ý¶ñÒâ½á¹¹µÄLNKÎļþÓÕʹÊܺ¦ÕßÒÔÆä×ÔÉíµÄÓû§È¨ÏÞÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬Î¢Èí½«ÆäÑÏÖØÆ·¼¶½ç˵ΪCritical¡£¡£¡£¡£¡£ ¡£ ¡£


Ö»¹Ü΢ÈíÐû²¼²»ÔÙΪwin7ÌṩÇå¾²¸üУ¬£¬£¬£¬£¬win7Óû§ÈÔÈ»¿ÉÒÔÏÂÔØÕë¶Ô¸ÃÎó²îµÄ²¹¶¡¡£¡£¡£¡£¡£ ¡£ ¡£


¡ñ ·À»¤¼Æ»®


£¨1£©ÏµÍ³Éý¼¶ÖÁ×îв¹¶¡¡£¡£¡£¡£¡£ ¡£ ¡£

£¨2£©Î´ÏÂÔØ²¹¶¡µÄÓû§Ó¦Ö»¹Ü×èÖ¹ÎüÊÕËûÈË·¢Ë͹ýÀ´µÄLNKÎļþ»ò·­¿ª´æÓÐLNKÎļþµÄ´æ´¢×°±¸£¬£¬£¬£¬£¬Èç·­¿ªÉúÊèÈËÌṩµÄUÅÌ¡£¡£¡£¡£¡£ ¡£ ¡£


¡ñ Ó°Ïì°æ±¾


£¨ÒÔϽöÁгöÊÜÓ°ÏìϵͳµÄ´ó°æ±¾ºÅ£¬£¬£¬£¬£¬ÏêϸµÄÓ°Ïì°æ±¾ÐÅÏ¢°Ý¼û²Î¿¼Á´½Ó5¡£¡£¡£¡£¡£ ¡£ ¡££©

Windows 10

Windows 10 Version 1607

Windows 10 Version 1709

Windows 10 Version 1803

Windows 10 Version 1809

Windows 10 Version 1903

Windows 10 Version 1909

Windows 7 Service Pack 1

Windows 8.1

Windows RT 8.1

Windows Server 2008 Service Pack 2

Windows Server 2008 R2 Service Pack 1

Windows Server 2012

Windows Server 2012 R2

Windows Server 2016

Windows Server 2019

Windows Server, version 1803

Windows Server, version 1903

Windows Server, version 1909


²Î¿¼Á´½Ó£º


1.https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200005

2.https://fortiguard.com/encyclopedia/ips/48773

3.https://twitter.com/search?q=CVE-2020-0796&src=typed_query

4.https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796

5.https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0684