¡¾Îó²îͨ¸æ¡¿Windows Active Directory ÓòЧÀÍȨÏÞÌáÉýÎó²î£¨CVE-2021-42278£©
Ðû²¼Ê±¼ä 2021-12-210x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-42278 | ʱ ¼ä | 2021-11-09 |
Àà ÐÍ | ȨÏÞÌáÉý | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | |
¹¥»÷ÖØÆ¯ºó | ¸ß | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | µÍ |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà |
0x01 Îó²îÏêÇé
2021Äê12ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬Î¢ÈíÅû¶ÁËWindows Active Directory ÓòЧÀÍȨÏÞÌáÉýÎó²î£¨CVE-2021-42287ºÍCVE-2021-42278£©µÄÎó²îϸ½Ú£¬£¬£¬£¬£¬£¬£¬²¢ÖÒÑÔ¿Í»§ÊµÊ±ÐÞ¸´Õâ2¸öÎó²î¡£¡£¡£¡£¡£¡£µ±Á¬ÏµÕâ2¸öÎó²îʱ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚûÓÐÓ¦Óò¹¶¡µÄ Active Directory ÇéÐÎÖн¨ÉèÒ»¸öÖ±½Ó»á¼ûÓòÖÎÀíÔ±Óû§µÄ·¾¶£¬£¬£¬£¬£¬£¬£¬ÔÚ¹¥»÷ÓòÖеÄͨË×Óû§ºóÇáËɽ«ÆäȨÏÞÌáÉýΪÓòÖÎÀíԱȨÏÞ£¬£¬£¬£¬£¬£¬£¬×îÖÕ½ÓÊÜWindowsÓò¡£¡£¡£¡£¡£¡£
Õâ2¸öÎó²î¶¼ÊÇ΢Èí11ÔÂ9ÈÕ²¹¶¡ÈÕÖÐÐÞ¸´µÄ£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö¾ùΪ7.5¡£¡£¡£¡£¡£¡£ÆäÖÐCVE-2021-42278ÊÇÒ»¸öÇå¾²ÈÆ¹ýÎó²î£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔÊÐí¹¥»÷ÕßʹÓÃÅÌËã»úÕÊ»§sAMAccountNameÓÕÆÀ´Ã°³äÓò¿ØÖÆÆ÷£¨SAMÃû³ÆÄ£Ä⣩¡£¡£¡£¡£¡£¡£CVE-2021-42287ÊÇÓ°ÏìKerberosÌØÈ¨ÊôÐÔÖ¤Ê飨PAC£©µÄÇå¾²ÈÆ¹ýÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷Õßð³äÓò¿ØÖÆÆ÷£¨KDCÓÕÆ£©¡£¡£¡£¡£¡£¡£
12 Ô 11 ÈÕ£¬£¬£¬£¬£¬£¬£¬Õâ2¸öÎó²îµÄϸ½ÚºÍPoC/EXPÒÑÔÚ»¥ÁªÍøÉϹûÕæ¡£¡£¡£¡£¡£¡£¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔÁ¬ÏµÕâ2¸öÎó²îÔÚĬÈÏÉèÖõÄÇéÐÎϽ«Í¨Ë×ȨÏÞÌáÉýµ½ÓòÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
CVE-2021-42287¡¢CVE-2021-42278£º
Windows Server, version 20H2 (Server Core Installation)
Windows Server, version 2004 (Server Core installation)
Windows Server 2022 (Server Core installation)
Windows Server 2022
Windows Server 2019 (Server Core installation)
Windows Server 2019
Windows Server 2016 (Server Core installation)
Windows Server 2016
Windows Server 2012 R2 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server Core installation)
Windows Server 2012
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÕâЩÎó²îÒÑÔÚ΢Èí11ÔÂ9ÈÕÐû²¼µÄÇå¾²¸üÐÂÖÐÐÞ¸´£¬£¬£¬£¬£¬£¬£¬½¨ÒéÆôÓÃWindows×Ô¶¯¸üлòÊÖ¶¯ÏÂÔØ×°Öò¹¶¡¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287
±ðµÄ£¬£¬£¬£¬£¬£¬£¬Î¢Èí»¹·ÖÏíÁËÕâ2¸öÎó²îµÄʹÓüì²â·Ö²½Ö¸ÄÏ£º
1.sAMAccountName ¸ü¸Ä»ùÓÚÊÂÎñ 4662£¬£¬£¬£¬£¬£¬£¬ÇëÈ·±£ÔÚÓò¿ØÖÆÆ÷ÉÏÆôÓÃËüÒÔ²¶»ñ´ËÀà»î¶¯¡£¡£¡£¡£¡£¡£
2. ·¿ª Microsoft 365 Defender ²¢µ¼º½µ½Advanced Hunting¡£¡£¡£¡£¡£¡£
3.¸´ÖÆÒÔÏÂÅÌÎÊ£¨Ò²¿ÉÔÚ Microsoft 365 Defender GitHub¸ß¼¶á÷ÁÔÅÌÎÊÖÐÕÒµ½£©£¬£¬£¬£¬£¬£¬£¬²éÕÒÒì³£×°±¸Ãû³Æ¸ü¸Ä£º
IdentityDirectoryEvents
| where Timestamp > ago(1d)
| where ActionType == "SAM Account Name changed"
| extend FROMSAM = parse_json(AdditionalFields)['FROM SAM Account Name']
| extend TOSAM = parse_json(AdditionalFields)['TO SAM Account Name']
| where (FROMSAM has "$" and TOSAM !has "$")
or TOSAM in ("DC1", "DC2", "DC3", "DC4") // DC Names in the org
| project Timestamp, Application, ActionType, TargetDeviceName, FROMSAM, TOSAM, ReportId, AdditionalFields
4.ÓÃÓò¿ØÖÆÆ÷µÄÃüÃûÔ¼¶¨Ìæ»»±ê¼ÇÇøÓò
5.ÔËÐÐÅÌÎʲ¢ÆÊÎö°üÀ¨ÊÜÓ°Ïì×°±¸µÄЧ¹û¡£¡£¡£¡£¡£¡£¿£¿£¿ÉÒÔʹÓÃWindows ÊÂÎñ 4741²éÕÒÕâЩÅÌËã»úµÄ½¨ÉèÕߣ¨ÈôÊÇËüÃÇÊÇн¨ÉèµÄ£©¡£¡£¡£¡£¡£¡£
6.½¨ÒéÊÓ²ìÕâЩ±»Ñ¬È¾µÄÅÌËã»ú²¢È·¶¨ËüÃÇûÓб»ÎäÆ÷»¯¡£¡£¡£¡£¡£¡£
7.È·±£Ê¹ÓÃÒÔÏÂ֪ʶ¿âÎÄÕÂÖÐÏêÊöµÄ°ì·¨ºÍÐÅÏ¢¸üÐÂÔâÊܹ¥»÷µÄ×°±¸£ºKB5008102¡¢KB5008380¡¢KB5008602¡£¡£¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://techcommunity.microsoft.com/t5/security-compliance-and-identity/sam-name-impersonation/ba-p/3042699
https://twitter.com/safe_buffer/status/1469742616505954323
https://support.microsoft.com/en-us/topic/kb5008102-active-directory-security-accounts-manager-hardening-changes-cve-2021-42278-5975b463-4c95-45e1-831a-d120004e258e
https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-easy-windows-domain-takeover-via-active-directory-bugs/
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-12-21 | Ê×´ÎÐû²¼ |
0x05 ¹ØÓÚ¼øºÚµ£±£Íø
¼øºÚµ£±£Íø¼ò½é
¼øºÚµ£±£Íø¹«Ë¾½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬£¬£¬£¬£¬£¬£¬ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·ºÍÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬£¬£¬£¬£¬£¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ£»£»£»£»£»£»£»²¢ÔÚ»ª±±¡¢»ª¶«¡¢Î÷ÄϺͻªÄϽṹËÄ´óÑз¢ÖÐÐÄ£¬£¬£¬£¬£¬£¬£¬»®·ÖΪ±±¾©Ñз¢×ܲ¿¡¢ÉϺ£Ñз¢ÖÐÐÄ¡¢³É¶¼Ñз¢ÖÐÐĺ͹ãÖÝÑз¢ÖÐÐÄ¡£¡£¡£¡£¡£¡£
¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£
¹ØÓÚ¼øºÚµ£±£Íø
¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£¡£
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º