¡¾Îó²îͨ¸æ¡¿Microsoft Remote Registry ServiceÌØÈ¨ÌáÉýÎó²î£¨CVE-2024-43532£©

Ðû²¼Ê±¼ä 2024-10-23


Ò»¡¢Îó²î¸ÅÊö

Îó²îÃû³Æ

Microsoft Remote Registry ServiceÌØÈ¨ÌáÉýÎó²î

CVE   ID

CVE-2024-43532

Îó²îÀàÐÍ

ȨÏÞÌáÉý

·¢Ã÷ʱ¼ä

2024-10-09

Îó²îÆÀ·Ö

8.8

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

µÍ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷

 

Microsoft Remote Registry Service£¨Ô¶³Ì×¢²á±íЧÀÍ£©ÊÇWindows ²Ù×÷ϵͳÖеÄÒ»¸öЧÀÍ£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³ÌÓû§Í¨¹ýÍøÂç»á¼ûºÍÐÞ¸ÄÅÌËã»úÉϵÄ×¢²á±í¡£¡£ ¡£¡£¡£¡£

2024Äê10ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬MG±ùÇòÍ»ÆÆÊÔÍæ¼¯ÍÅVSRC¼à²âµ½Microsoft Remote Registry ServiceÌØÈ¨ÌáÉýÎó²î£¨CVE-2024-43532£©µÄÊÖÒÕϸ½Ú¼°PoCÔÚ»¥ÁªÍøÉϹûÕæ£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8¡£¡£ ¡£¡£¡£¡£

¸ÃÎó²îÔ´ÓÚMicrosoft Remote Registry¿Í»§¶ËÔÚSMB´«Êä²»¿ÉÓõÄÇéÐÎÏ»ØÍ˵½ RPC£¨Ô¶³ÌÀú³ÌŲÓã©ÈÏ֤ʱ£¬£¬£¬£¬£¬£¬Çл»µ½½Ï¾ÉµÄЭÒ飨ÈçTCP/IP£©²¢½ÓÄÉÈõÈÏÖ¤¼¶±ð£¨RPC_C_AUTHN_LEVEL_CONNECT£©£¬£¬£¬£¬£¬£¬¸Ã¼¶±ðÎÞ·¨Ñé֤ͨѶµÄÍêÕûÐÔ»òȪԴ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃȱÏÝ£¬£¬£¬£¬£¬£¬Í¨¹ý×èµ²NTLM Éí·ÝÑéÖ¤ÎÕÊÖ²¢½«ÆäÖм̵½ÆäËûЧÀÍ£¨ÈçADCS£©£¬£¬£¬£¬£¬£¬ÊµÏÖ NTLM Öм̹¥»÷£¬£¬£¬£¬£¬£¬½ø¶ø¿ÉÄܽ¨ÉèÓòÖÎÀíÔ±ÕË»§»ò½ÓÊÜÕû¸öÓò¡£¡£ ¡£¡£¡£¡£

 

¶þ¡¢Ó°Ïì¹æÄ£

Windows Server 2012 R2 (Server Core installation)

Windows Server 2012 R2

Windows Server 2012 (Server Core installation)

Windows Server 2012

Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server 2016 (Server Core installation)

Windows Server 2016

Windows 10 Version 1607 for x64-based Systems

Windows 10 Version 1607 for 32-bit Systems

Windows 10 for x64-based Systems

Windows 10 for 32-bit Systems

Windows 11 Version 24H2 for x64-based Systems

Windows 11 Version 24H2 for ARM64-based Systems

Windows Server 2022, 23H2 Edition (Server Core installation)

Windows 11 Version 23H2 for x64-based Systems

Windows 11 Version 23H2 for ARM64-based Systems

Windows 10 Version 22H2 for 32-bit Systems

Windows 10 Version 22H2 for ARM64-based Systems

Windows 10 Version 22H2 for x64-based Systems

Windows 11 Version 22H2 for x64-based Systems

Windows 11 Version 22H2 for ARM64-based Systems

Windows 10 Version 21H2 for x64-based Systems

Windows 10 Version 21H2 for ARM64-based Systems

Windows 10 Version 21H2 for 32-bit Systems

Windows 11 version 21H2 for ARM64-based Systems

Windows 11 version 21H2 for x64-based Systems

Windows Server 2022 (Server Core installation)

Windows Server 2022

Windows Server 2019 (Server Core installation)

Windows Server 2019

Windows 10 Version 1809 for x64-based Systems

Windows 10 Version 1809 for 32-bit Systems

 

Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ¸ÃÎó²îÒÑÔÚ΢Èí10ÔÂÐû²¼µÄÇå¾²¸üÐÂÖÐÐÞ¸´£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉʵʱÐÞ¸´¡£¡£ ¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43532

WindowsÖпÉͨ¹ý¿ØÖÆÃæ°å-³ÌÐòºÍ¹¦Ð§-Éó²éÒÑ×°ÖõĸüÐÂÅÌÎÊÄ¿½ñϵͳÒÑ×°ÖõĸüУ¬£¬£¬£¬£¬£¬ÈôÊÇϵͳÉÐδװÖÃÏìÓ¦²¹¶¡£¡£ ¡£¡£¡£¡£¬£¬£¬£¬£¬£¬¿ÉÊÖ¶¯ÏÂÔØ×°Öᣡ£ ¡£¡£¡£¡£

3.2 ÔÝʱ²½·¥

ÔÝÎÞ¡£¡£ ¡£¡£¡£¡£

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£ ¡£¡£¡£¡£¬£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£ ¡£¡£¡£¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£ ¡£¡£¡£¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£ ¡£¡£¡£¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£ ¡£¡£¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£ ¡£¡£¡£¡£

3.4 ²Î¿¼Á´½Ó

https://www.akamai.com/blog/security-research/winreg-relay-vulnerability

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43532

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-10-23

Ê×´ÎÐû²¼

 

 

Îå¡¢¸½Â¼

5.1 MG±ùÇòÍ»ÆÆÊÔÍæ¼ò½é

MG±ùÇòÍ»ÆÆÊÔÍæ½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£ ¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£ ¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°MG±ùÇòÍ»ÆÆÊÔÍæ´óÏ㬣¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£ ¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£ ¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£ ¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬£¬£¬£¬£¬MG±ùÇòÍ»ÆÆÊÔÍæÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£ ¡£¡£¡£¡£

5.2 ¹ØÓÚMG±ùÇòÍ»ÆÆÊÔÍæ

MG±ùÇòÍ»ÆÆÊÔÍæÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£ ¡£¡£¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png