Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-02-26

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-0688£¬£¬£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 30

Microsoft Exchange Server 2013 Cumulative Update 23

Microsoft Exchange Server 2016 Cumulative Update 14

Microsoft Exchange Server 2016 Cumulative Update 15

Microsoft Exchange Server 2019 Cumulative Update 3

Microsoft Exchange Server 2019 Cumulative Update 4


Îó²î¸ÅÊö


2020Äê2ÔÂ11ÈÕ£¬£¬£¬ £¬£¬£¬£¬MicrosoftÐû²¼ÁËÕë¶ÔMicrosoft Exchange ServerÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-0688£©µÄ²¹¶¡³ÌÐò¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃÕâ¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýExchangeЧÀÍÉϵÄͨË×Óû§È¨ÏÞ£¬£¬£¬ £¬£¬£¬£¬½ÓÊÜÕû¸öExchangeЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ´ËÎó²îµÄʹÓÃϸ½ÚÒѾ­ÔÚ»¥ÁªÍø¹ûÕæ¡£¡£¡£¡£¡£¡£¡£


Îó²î±¬·¢ÔÚ Exchange Control Panel £¨ECP£©×é¼þÖС£¡£¡£¡£¡£¡£¡£Óëÿ´ÎÈí¼þ×°Öö¼»á±¬·¢ËæÉñÃØÔ¿²î±ð£¬£¬£¬ £¬£¬£¬£¬ËùÓÐMicrosoft Exchange ServerÔÚ×°ÖúóµÄweb.configÎļþÖж¼ÓµÓÐÏàͬµÄvalidationKeyºÍdecryptionKey¡£¡£¡£¡£¡£¡£¡£ÕâЩÃÜÔ¿ÓÃÓÚ°ü¹ÜViewStateµÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£¡£¶øViewStateÊÇASP.NET WebÓ¦ÓÃÒÔÐòÁл¯ÃûÌô洢ÔÚ¿Í»§»úÉϵÄЧÀͶËÊý¾Ý¡£¡£¡£¡£¡£¡£¡ £¿£¿£¿£¿£¿Í»§¶Ëͨ¹ý__VIEWSTATEÇëÇó²ÎÊý½«ÕâЩÊý¾Ý·µ»Ø¸øÐ§ÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚʹÓÃÁ˾²Ì¬ÃÜÔ¿£¬£¬£¬ £¬£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÓÕÆ­Ä¿µÄЧÀÍÆ÷·´ÐòÁл¯¶ñÒ⽨ÉèµÄViewStateÊý¾Ý¡£¡£¡£¡£¡£¡£¡£µ±¹¥»÷Õß¿ÉÒԵǼExchangeÓÊÏäÕË»§Ê±£¬£¬£¬ £¬£¬£¬£¬ÔÚYSoSerial.netµÄ×ÊÖúÏ£¬£¬£¬ £¬£¬£¬£¬¿ÉÒÔÔÚExchange Control Panel webÓ¦ÓÃÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


PoC£ºhttps://www.zerodayinitiative.com/blog/2020/2/24/cve-2020-0688-remote-code-execution-on-microsoft-exchange-server-through-fixed-cryptographic-keys¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ£¬£¬£¬ £¬£¬£¬£¬Î¢Èí¹Ù·½ÒÑÐû²¼Õë¶ÔÊÜÓ°Ïì°æ±¾µÄ²¹¶¡³ÌÐò£¬£¬£¬ £¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì×°Öãºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0688¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.zerodayinitiative.com/blog/2020/2/24/cve-2020-0688-remote-code-execution-on-microsoft-exchange-server-through-fixed-cryptographic-keys