Windows PowerShellÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Ðû²¼Ê±¼ä 2021-07-04

0x00 Îó²î¸ÅÊö

CVE     ID


ʱ      ¼ä

2021-07-04

Àà      ÐÍ

RCE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP


ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

image.png

 

PowerShellÌṩÁËÒ»¸öÏÂÁîÐÐshell¡¢Ò»¸ö¿ò¼ÜºÍÒ»Ö־籾ÓïÑÔ£¬£¬ £¬×¨×¢ÓÚ´¦Öóͷ£ PowerShell cmdlet µÄ×Ô¶¯»¯¡£¡£¡£¡£Ëü¿ÉÒÔÔÚ Windows¡¢Linux ºÍ macOSµÈƽ̨ÉÏÔËÐУ¬£¬ £¬²¢ÇÒÔÊÐí´¦Öóͷ£½á¹¹»¯Êý¾Ý£¬£¬ £¬ÀýÈç JSON¡¢CSV ºÍ XML£¬£¬ £¬ÒÔ¼° REST API ºÍ¹¤¾ßÄ£×Ó¡£¡£¡£¡£

¿ËÈÕ£¬£¬ £¬Microsoft ÖÒÑÔ PowerShell 7 ÖÐÑÏÖØµÄ .NET Core Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬ £¬Ôµ¹ÊÔ­ÓÉÔÚÓÚ.NET 5 ºÍ .NET Core ÖеÄÎı¾±àÂë·½·¨¡£¡£¡£¡£Microsoft±Þ²ß¿Í»§¾¡¿ì×°ÖÃPowerShell 7.0.6 ºÍ 7.1.3 ¡£¡£¡£¡£

MicrosoftÔÚ4 Ô·ÝʱÌåÏÖ£¬£¬ £¬Ò×Êܹ¥»÷µÄ°üÊÇSystem.Text.Encodings.Web£¬£¬ £¬ÈκÎʹÓÃÏÂÃæÁгöµÄ System.Text.Encodings.Web °ü°æ±¾µÄ»ùÓÚ .NET 5¡¢.NET Core »ò .NET Framework µÄÓ¦ÓóÌÐò¶¼ÈÝÒ×Êܵ½¹¥»÷£º

°üÃû³Æ

Ò×Êܹ¥»÷µÄ°æ±¾

ÐÞ¸´°æ±¾

System.Text.Encodings.Web

4.0.0 -   4.5.0

4.5.1

System.Text.Encodings.Web

4.6.0-4.7.1

4.7.2

System.Text.Encodings.Web

5.0.0

5.0.1

 

ƾ֤MicrosoftµÄ×îÐÂÇ徲ͨ¸æ£¬£¬ £¬ËäÈ» Visual Studio Ò²°üÀ¨ .NET µÄ¶þ½øÖÆÎļþ£¬£¬ £¬µ«Ëü²»Êܵ½´ËÎó²îµÄÓ°Ïì¡£¡£¡£¡£±ðµÄ£¬£¬ £¬MicrosoftÐû²¼£¬£¬ £¬Ëü½«Í¨¹ý Microsoft Update ЧÀÍÐû²¼Ö®ºóµÄ¸üУ¬£¬ £¬ÒÔ±ã¸üÇáËɵظüÐÂWindows 10 ºÍ Windows Server ÉϵÄPowerShell¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

PowerShell < 7.0.6

PowerShell < 7.1.3

PowerShell 5.1²»ÊÜ´ËÎó²îµÄÓ°Ïì¡£¡£¡£¡£

0x02 ´¦Öóͷ£½¨Òé

MicrosoftÌåÏÖÏÖÔÚ´ËÎó²îûÓпÉÓõĻº½â²½·¥£¬£¬ £¬½¨Ò龡¿ì×°Öøüе½ PowerShell 7.0.6 ºÍ 7.1.3 °æ±¾¡£¡£¡£¡£

Ҫͨ¹ý Microsoft Update ¸üРPowerShell£º

 ¡°×îÏÈ¡± > ¡°ÉèÖá± >¡°¸üкÍÇå¾²¡±>¡°Windows ¸üС±£¬£¬ £¬È»ºóµ¥»÷¡°¼ì²é¸üС±¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://azure.microsoft.com/en-us/updates/update-powershell-versions-70-and-71-to-protect-against-a-vulnerability/

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26701

https://azure.microsoft.com/en-us/updates/update-powershell-versions-70-and-71-to-protect-against-a-vulnerability/

https://www.bleepingcomputer.com/news/security/microsoft-warns-of-critical-powershell-7-code-execution-vulnerability/?

 

0x04 ʱ¼äÏß

2021-07-01  MicrosoftÇå¾²¸üÐÂ

2021-07-04  VSRCÇ徲ͨ¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png