¡¾Îó²îͨ¸æ¡¿Windows Active Directory ÓòЧÀÍȨÏÞÌáÉýÎó²î£¨CVE-2021-42278£©

Ðû²¼Ê±¼ä 2021-12-21


0x00 Îó²î¸ÅÊö

CVE     ID

CVE-2021-42278

ʱ      ¼ä

2021-11-09

Àà      ÐÍ

ȨÏÞÌáÉý

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó

¸ß

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

 ÎÞ

ËùÐèȨÏÞ

µÍ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

image.png

2021Äê12ÔÂ20ÈÕ £¬ £¬£¬£¬£¬£¬£¬Î¢ÈíÅû¶ÁËWindows Active Directory ÓòЧÀÍȨÏÞÌáÉýÎó²î£¨CVE-2021-42287ºÍCVE-2021-42278£©µÄÎó²îϸ½Ú £¬ £¬£¬£¬£¬£¬£¬²¢ÖÒÑÔ¿Í»§ÊµÊ±ÐÞ¸´Õâ2¸öÎó²î¡£ ¡£¡£¡£¡£¡£µ±Á¬ÏµÕâ2¸öÎó²îʱ £¬ £¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚûÓÐÓ¦Óò¹¶¡µÄ Active Directory ÇéÐÎÖн¨ÉèÒ»¸öÖ±½Ó»á¼ûÓòÖÎÀíÔ±Óû§µÄ·¾¶ £¬ £¬£¬£¬£¬£¬£¬ÔÚ¹¥»÷ÓòÖеÄͨË×Óû§ºóÇáËɽ«ÆäȨÏÞÌáÉýΪÓòÖÎÀíԱȨÏÞ £¬ £¬£¬£¬£¬£¬£¬×îÖÕ½ÓÊÜWindowsÓò¡£ ¡£¡£¡£¡£¡£

Õâ2¸öÎó²î¶¼ÊÇ΢Èí11ÔÂ9ÈÕ²¹¶¡ÈÕÖÐÐÞ¸´µÄ £¬ £¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö¾ùΪ7.5¡£ ¡£¡£¡£¡£¡£ÆäÖÐCVE-2021-42278ÊÇÒ»¸öÇå¾²ÈÆ¹ýÎó²î £¬ £¬£¬£¬£¬£¬£¬¸ÃÎó²îÔÊÐí¹¥»÷ÕßʹÓÃÅÌËã»úÕÊ»§sAMAccountNameÓÕÆ­À´Ã°³äÓò¿ØÖÆÆ÷£¨SAMÃû³ÆÄ£Ä⣩¡£ ¡£¡£¡£¡£¡£CVE-2021-42287ÊÇÓ°ÏìKerberosÌØÈ¨ÊôÐÔÖ¤Ê飨PAC£©µÄÇå¾²ÈÆ¹ýÎó²î £¬ £¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷Õßð³äÓò¿ØÖÆÆ÷£¨KDCÓÕÆ­£©¡£ ¡£¡£¡£¡£¡£

12 Ô 11 ÈÕ £¬ £¬£¬£¬£¬£¬£¬Õâ2¸öÎó²îµÄϸ½ÚºÍPoC/EXPÒÑÔÚ»¥ÁªÍøÉϹûÕæ¡£ ¡£¡£¡£¡£¡£¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔÁ¬ÏµÕâ2¸öÎó²îÔÚĬÈÏÉèÖõÄÇéÐÎϽ«Í¨Ë×ȨÏÞÌáÉýµ½ÓòÖÎÀíԱȨÏÞ¡£ ¡£¡£¡£¡£¡£

image.png

 

Ó°Ïì¹æÄ£

CVE-2021-42287¡¢CVE-2021-42278£º

Windows Server, version 20H2 (Server Core Installation)

Windows Server, version 2004 (Server Core installation)

Windows Server 2022 (Server Core installation)

Windows Server 2022

Windows Server 2019 (Server Core installation)

Windows Server 2019

Windows Server 2016 (Server Core installation)

Windows Server 2016

Windows Server 2012 R2 (Server Core installation)

Windows Server 2012 R2

Windows Server 2012 (Server Core installation)

Windows Server 2012

Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Windows Server 2008 R2 for x64-based Systems Service Pack 1

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÕâЩÎó²îÒÑÔÚ΢Èí11ÔÂ9ÈÕÐû²¼µÄÇå¾²¸üÐÂÖÐÐÞ¸´ £¬ £¬£¬£¬£¬£¬£¬½¨ÒéÆôÓÃWindows×Ô¶¯¸üлòÊÖ¶¯ÏÂÔØ×°Öò¹¶¡¡£ ¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287

 

±ðµÄ £¬ £¬£¬£¬£¬£¬£¬Î¢Èí»¹·ÖÏíÁËÕâ2¸öÎó²îµÄʹÓüì²â·Ö²½Ö¸ÄÏ£º

1.sAMAccountName ¸ü¸Ä»ùÓÚÊÂÎñ 4662 £¬ £¬£¬£¬£¬£¬£¬ÇëÈ·±£ÔÚÓò¿ØÖÆÆ÷ÉÏÆôÓÃËüÒÔ²¶»ñ´ËÀà»î¶¯¡£ ¡£¡£¡£¡£¡£

2. ·­¿ª Microsoft 365 Defender ²¢µ¼º½µ½Advanced Hunting¡£ ¡£¡£¡£¡£¡£

3.¸´ÖÆÒÔÏÂÅÌÎÊ£¨Ò²¿ÉÔÚ Microsoft 365 Defender GitHub¸ß¼¶á÷ÁÔÅÌÎÊÖÐÕÒµ½£© £¬ £¬£¬£¬£¬£¬£¬²éÕÒÒì³£×°±¸Ãû³Æ¸ü¸Ä£º

IdentityDirectoryEvents

| where Timestamp > ago(1d)

| where ActionType == "SAM Account Name changed"

| extend FROMSAM = parse_json(AdditionalFields)['FROM SAM Account Name']

| extend TOSAM = parse_json(AdditionalFields)['TO SAM Account Name']

| where (FROMSAM has "$" and TOSAM !has "$")

        or TOSAM in ("DC1", "DC2", "DC3", "DC4") // DC Names in the org

| project Timestamp, Application, ActionType, TargetDeviceName, FROMSAM, TOSAM, ReportId, AdditionalFields

4.ÓÃÓò¿ØÖÆÆ÷µÄÃüÃûÔ¼¶¨Ìæ»»±ê¼ÇÇøÓò

5.ÔËÐÐÅÌÎʲ¢ÆÊÎö°üÀ¨ÊÜÓ°Ïì×°±¸µÄЧ¹û¡£ ¡£¡£¡£¡£¡£¿£¿£¿ÉÒÔʹÓÃWindows ÊÂÎñ 4741²éÕÒÕâЩÅÌËã»úµÄ½¨ÉèÕߣ¨ÈôÊÇËüÃÇÊÇн¨ÉèµÄ£©¡£ ¡£¡£¡£¡£¡£

6.½¨ÒéÊÓ²ìÕâЩ±»Ñ¬È¾µÄÅÌËã»ú²¢È·¶¨ËüÃÇûÓб»ÎäÆ÷»¯¡£ ¡£¡£¡£¡£¡£

7.È·±£Ê¹ÓÃÒÔÏÂ֪ʶ¿âÎÄÕÂÖÐÏêÊöµÄ°ì·¨ºÍÐÅÏ¢¸üÐÂÔâÊܹ¥»÷µÄ×°±¸£ºKB5008102¡¢KB5008380¡¢KB5008602¡£ ¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://techcommunity.microsoft.com/t5/security-compliance-and-identity/sam-name-impersonation/ba-p/3042699

https://twitter.com/safe_buffer/status/1469742616505954323

https://support.microsoft.com/en-us/topic/kb5008102-active-directory-security-accounts-manager-hardening-changes-cve-2021-42278-5975b463-4c95-45e1-831a-d120004e258e

https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-easy-windows-domain-takeover-via-active-directory-bugs/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-12-21

Ê×´ÎÐû²¼

 

0x05 ¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø¹«Ë¾½¨ÉèÓÚ1996Äê £¬ £¬£¬£¬£¬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊÐ £¬ £¬£¬£¬£¬£¬£¬ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·ºÍÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£ ¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ° £¬ £¬£¬£¬£¬£¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬ £¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ£»£»£» £»£»£»£»²¢ÔÚ»ª±±¡¢»ª¶«¡¢Î÷ÄϺͻªÄϽṹËÄ´óÑз¢ÖÐÐÄ £¬ £¬£¬£¬£¬£¬£¬»®·ÖΪ±±¾©Ñз¢×ܲ¿¡¢ÉϺ£Ñз¢ÖÐÐÄ¡¢³É¶¼Ñз¢ÖÐÐĺ͹ãÖÝÑз¢ÖÐÐÄ¡£ ¡£¡£¡£¡£¡£

¶àÄêÀ´ £¬ £¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ £¬ £¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ £¬ £¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£ ¡£¡£¡£¡£¡£


¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£ ¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«ÖںŠ£¬ £¬£¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png