SolarWinds Orion¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-02-04

0x00 Îó²î¸ÅÊö

È¥Ä꣬£¬£¬£¬ £¬SolarWinds¹©Ó¦Á´¹¥»÷ÊÂÎñÒý·¢È«Çò¹Ø×¢¡£¡£¡£¡£

2021Äê02ÔÂ03ÈÕ£¬£¬£¬£¬ £¬SolarWinds Orionƽ̨ºÍSolarWinds Serv-U FTPЧÀÍÆ÷±»Åû¶±£´æ¶à¸öÇå¾²Îó²î¡£¡£¡£¡£SolarWinds Orionƽ̨¹©Ó¦Á´¹¥»÷ÊÂÎñÖÐûÓÐʹÓÃÕâЩÎó²î¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬ £¬Ïà¹ØÎó²îÒѾ­ËùÓÐÐÞ¸´£¬£¬£¬£¬ £¬µ«Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬ £¬ÕâЩÎó²îµÄPoC½«ÓÚ02ÔÂ09ÈÕÐû²¼¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

 

±¾´ÎÅû¶µÄÎó²îÈçÏ£º

²úÆ·

CVE

ÀàÐÍ

ÆÀ¼¶

SolarWinds   Orionƽ̨

CVE-2021-25274

RCE

¸ßΣ

CVE-2021-25275

ÐÅϢй¶

ÖÐΣ

SolarWinds   Serv-U FTPЧÀÍÆ÷

CVE-2021-25276

»á¼û¿ØÖƲ»µ±

ÖÐΣ

 

SolarWinds OrionÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-25274£©

SolarWinds Collector Service ʹÓà MSMQ£¨MicrosoftÐÂÎÅÐÐÁУ©£¬£¬£¬£¬ £¬µ«²¢ÇÒδÔÚÆäרÓÃÐÐÁÐÉÏÉèÖÃȨÏÞ£¬£¬£¬£¬ £¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýTCP¶Ë¿Ú1801½«¶ñÒâÐÂÎÅ·¢Ë͵½ÐÐÁУ¬£¬£¬£¬ £¬ÔÚ´¦Öóͷ£´ËÀàÐÂÎÅʱ£¬£¬£¬£¬ £¬ÍøÂçÆ÷ЧÀͽ«ÒÔ²»Çå¾²µÄ·½·¨·´ÐòÁл¯ËüÃÇ£¬£¬£¬£¬ £¬´Ó¶øÔÊÐíÔ¶³Ì¹¥»÷ÕßÒÔLocalSystemµÄ·½·¨Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬ £¬×îÖÕµ¼ÖÂЧÀÍÆ÷±»ÍêÈ«¿ØÖÆ¡£¡£¡£¡£

image.png

SolarWindsͨ¹ýÔÚÐÂÐÂÎŵִïʱÌí¼ÓÊý×ÖÊðÃûÑéÖ¤À´ÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬ £¬ÔÚûÓÐÓÐÓõÄÊðÃûµÄÇéÐÎϽ«²»ÔÙ´¦Öóͷ£ÐÂÎÅ£¬£¬£¬£¬ £¬µ«MSMQÈÔÈ»ÊÇδ¾­Éí·ÝÑéÖ¤µÄ£¬£¬£¬£¬ £¬¿ÉÒÔÎüÊÕÀ´×ÔÈκÎÈ˵ÄÐÂÎÅ¡£¡£¡£¡£

 

SolarWinds OrionÃô¸ÐÐÅϢй¶Îó²î£¨CVE-2021-25275£©

SolarWinds Orionºó¶ËÊý¾Ý¿âSOLARWINDS_ORIONÖеĴ洢ƾ֤±»·ÅÔÚÒ»¸ö·ÇÖÎÀíÔ±Óû§¿É¶ÁµÄÎļþÖУ¬£¬£¬£¬ £¬µ¼ÖÂÈκοÉÒÔ»á¼ûÎļþϵͳµÄÓû§¶¼¿ÉÒÔ´Ó¸ÃϵͳÖжÁÈ¡OrionÊý¾Ý¿âµÄµÇ¼ÐÅÏ¢£¬£¬£¬£¬ £¬²¢ÇÒ¿ÉʹÓÃÆ¾Ö¤À´»ñµÃOrionÊý¾Ý¿âµÄËùÓÐÕßȨÏÞ¡£¡£¡£¡£

image.png

 

SolarWinds Serv-U FTP £¨Windows£©»á¼û¿ØÖƲ»µ±Îó²î£¨CVE-2021-25276£©

¸ÃÎó²î±£´æÓÚWindowsµÄSolarWinds Serv-U FTPЧÀÍÆ÷ÖУ¬£¬£¬£¬ £¬ÈκοÉÒÔÍâµØµÇ¼»òͨ¹ýÔ¶³Ì×ÀÃæµÇ¼ϵͳµÄ¹¥»÷Õß¶¼¿ÉÒÔͨ¹ýʹÓôËÎó²îÀ´µÇ¼FTP£¬£¬£¬£¬ £¬×îÖÕ¶ÁÈ¡»òÌæ»»CÅÌÉϵÄÈκÎÎļþ¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

SolarWinds Orion < 2020.2.4

SolarWinds ServU-FTP < 15.2.2 Hotfix 1

 

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÏà¹ØÎó²îÒѱ»ÐÞ¸´£¬£¬£¬£¬ £¬½¨ÒéÉý¼¶ÖÁ×îа汾¡£¡£¡£¡£

SolarWinds Orion Platform 2020.2.4

SolarWinds ServU-FTP 15.2.2 Hotfix 1

ÏÂÔØÁ´½Ó£º

https://documentation.solarwinds.com/en/Success_Center/orionplatform/content/release_notes/orion_platform_2020-2-4_release_notes.htm

https://downloads.solarwinds.com/solarwinds/Release/HotFix/Serv-U-15.2.2-Hotfix-1.zip

 

0x03 ²Î¿¼Á´½Ó

https://www.bleepingcomputer.com/news/security/solarwinds-patches-critical-vulnerabilities-in-the-orion-platform/

https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=28389

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25274

 

0x04 ʱ¼äÏß

2021-02-03  Trustwave SpiderLabsÅû¶Îó²î

2021-02-04  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png