΢Èí³¬¸ßΣ·ì϶¡°¿ñÔêÐí¿É¡±À´Ï®£¡OG¶«·½ÌüÌṩ½â¾ö¹æ»®

°ä²¼¹¦·ò 2024-08-11

½üÈÕ£¬£¬£¬OG¶«·½Ìü¼à²âµ½WindowsÔ¶³Ì×ÀÃæÐí¿É·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-38077£©ÓйØÐÅÏ¢¡£¸Ã·ì϶ӰÏìËùÓÐÆôÓà RDL ·þÎñµÄ Windows Server·þÎñÆ÷£¬£¬£¬Î´¾­Éí·ÝÈÏÖ¤µÄ¹¥»÷Õß¿ÉÀûÓø÷ì϶Զ³ÌÖ´ÐдúÂ룬£¬£¬»ñÈ¡·þÎñÆ÷½ÚÖÆÈ¨ÏÞ¡£Ä¿Ç°£¬£¬£¬¸Ã·ì϶µÄ¼¼ÊõµÀÀíºÍPOCα´úÂëÒѹ«¿ª¡£¼øÓÚ´Ë·ì϶ӰÏìÁìÓò½Ï´ó£¬£¬£¬½¨Ò龡¿ì×öºÃ×Բ鼰·À»¤¡£


·ì϶ÏêÇé


2024Äê07ÔÂ09ÈÕ£¬£¬£¬Î¢Èí¹Ù·½ÐÞ²¹ÁËÒ»¸ö´æÔÚÓÚWindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-38077£©¡£Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñ£¨RDL£©ÊÇÓÃÓÚÖÎÀíÔ¶³Ì×ÀÃæ(RDP)µÄÖØÒª×é¼þ£¬£¬£¬Æäͨ¹ýÖÎÀíºÍ·ÖÅäÐí¿ÉÖ¤À´½ÚÖÆºÍ¼à¿ØÔ¶³ÌÏνӵĺϷ¨ÐÔ¡£


¾­¹ý×êÑÐÈ·ÈÏ£¬£¬£¬¸Ã·ì϶ÊÇÓÉÓÚRDL·þÎñδÕýȷУÑéÓû§ÊäÈëÊý¾Ý£¬£¬£¬µ¼ÖÂÔÚ½âÎöʱ²úÉúÒç³ö£¬£¬£¬¹¥»÷ÕßÄܹ»ÔÚδ¾­¹ýÉí·ÝÑéÖ¤µÄÇé¿öÏ£¬£¬£¬Í¨¹ýÏò¿ªÆôRDL·þÎñµÄÖ÷»ú·¢ËÍÓйØÔ¶³ÌŲÓÃÀ´ÊµÏÖ·ì϶ÀûÓᣳɹ¦ÀûÓø÷ì϶¼´¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬´Ó¶øµ¼ÖÂÃô¸ÐÊý¾ÝµÄй¶£¬£¬£¬ÒÔ¼°¿ÉÄܵĶñÒâÈí¼þ´«²¼¡£¸Ã·ì϶ÏÕЩӰÏìËùÓÐWindows Server°æ±¾¡£


ͼƬ1.png


·ì϶¸´ÏÖ


ͼƬ2.png


½â¾ö¹æ»®


Ò»¡¢¹Ù·½ÐÞ¸´¹æ»®


¹Ù·½ÒѰ䲼°²È«¸üУ¬£¬£¬½¨Ò齫ÊÜÓ°ÏìµÄWindowsÉý¼¶ÖÁ×îа汾£º£º£º 

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38077


¶þ¡¢Ò»Ê±ÐÞ¸´¹æ»®


¸Ã·þÎñĬÈÏδװÖ㬣¬£¬ÈçûÓÐÓйØÒµÎñÐèÒª£¬£¬£¬Äܹ»¹Ø±ÕRemote Desktop Licensing·þÎñ¡£


Èý¡¢OG¶«·½Ìü½â¾ö¹æ»®


1¡¢OG¶«·½Ìü¼ì²âÓë·À»¤Àà²úÆ·¹æ»®


£¨1£©OG¶«·½Ìü¡°ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡±Éý¼¶µ½20240810°æ±¾¼´¿ÉÖ§³Ö¼ì²â¸Ã·ì϶¡£


ͼƬ3.png


£¨2£©OG¶«·½Ìü ¡°ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡± Éý¼¶µ½20240810°æ±¾¼´¿ÉÖ§³Ö¼ì²â¸Ã·ì϶¡£


ͼƬ4.png


£¨3£©OG¶«·½Ìü¡°ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©¡±Éý¼¶µ½20240810°æ±¾¼´¿ÉÖ§³Ö·À»¤¸Ã·ì϶¡£


ͼƬ5.png


2¡¢OG¶«·½Ìü©ɨ²úÆ·¹æ»®


£¨1£©¡°OG¶«·½ÌüÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ¡±6075°æ±¾ÒÑ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü£¬£¬£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃ裬£¬£¬Óû§Éý¼¶³ß¶È·ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃ裺£º£º


6070°æ±¾Éý¼¶°üΪ607000581-607000582.vup£¬£¬£¬Éý¼¶°üÏÂÔØµØÖ·£º£º£ºhttps://venustech.download.venuscloud.cn/


ͼƬ6.jpg


£¨2£©OG¶«·½ÌüÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ608XϵÁа汾ÒÑ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü£¬£¬£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃ裬£¬£¬Óû§Éý¼¶³ß¶È·ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃ裺£º£º


6080°æ±¾Éý¼¶°üΪÖ÷»ú²å¼þ°ü6080000130-S6080000131.svs©ɨ²å¼þ°üÏÂÔØµØÖ·£º£º£º

https://venustech.download.venuscloud.cn/

ͼƬ7.jpg


£¨3£©Í¨¹ýOG¶«·½ÌüÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳµÄÅäÖú˲éÄ£¿£¿é¶Ô¸Ã·ì϶ӰÏìµÄWindows°æ±¾½øÐлñÈ¡£¬£¬£¬Ê¹ÓÃÖÇÄÜ»¯·ÖÎöÑÐÅлúÖÆÑéÖ¤¸Ã·ì϶ÊÇ·ñ´æÔÚ£¬£¬£¬ÈôÊÇ´æÔڸ÷ì϶½¨Òé¸üе½°²È«°æ±¾¡£


ÇëʹÓÃOG¶«·½ÌüÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬£¬£¬ÊµÊ±¶Ô¸Ã·ì϶½øÐмì²â£¬£¬£¬ÒԱ㾡¿ì²ÉÈ¡·À±¸´ëÊ©¡£


3¡¢OG¶«·½Ìü×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¹æ»®


OG¶«·½Ìü×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±²É¼¯²¢¸üеý±¨ÐÅÏ¢£¬£¬£¬¶ÔÈë¿â×ʲú·ì϶WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-38077£©½øÐÐÖÎÀí¡£ 


ͼƬ8.jpg


4¡¢OG¶«·½Ìü°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¹æ»®


Óû§Äܹ»Í¨¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬£¬£¬½øÐйØÁªÕ½ÊõÅäÖ㬣¬£¬½áºÏÏÖʵ»·¾³ÖÐϵͳÈÕÖ¾ºÍ°²È«É豸µÄ¸æ¾¯ÐÅÏ¢½øÐгÖÐø¼à¿Ø£¬£¬£¬´Ó¶ø·¢ÏÖ¡°WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´ÐС±µÄ·ì϶ÀûÓù¥»÷ÐÐΪ¡£


£¨1£©Í¨¹ý´àÈõÐÔ·¢ÏÖÖ°ÄÜÕë¶Ô¡°WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-38077£©¡±·ì϶ɨÃ蹤×÷£¬£¬£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´Ë·ì϶ӰÏìµÄÖØÒª×ʲú¡£


ͼƬ9.png


£¨2£©Æ½Ì¨¡°¹ØÁª·ÖÎö¡±Ä£¿£¿éÖУ¬£¬£¬Ôö³¤¡°L2_WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶¡±£¬£¬£¬Í¨¹ýOG¶«·½Ìü¼ì²âÉ豸¡¢Ö¸±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬£¬£¬·¢ÏÖÍⲿ¹¥»÷ÐÐΪ£º£º£º


ͼƬ10.png


ͨ¹ý¶ÈÎö¹æ¶¨×Ô¶¯½«L2_WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ôö³¤µ½¹Û²ìÁÐ±í¡°¸ß·çÏÕÏνӡ±ÖУ¬£¬£¬×÷ΪÄÚ²¿µý±¨Êý¾ÝʹÓã» £»


£¨3£©Ôö³¤¡°L3_WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶ÀûÓóɹ¦¡±£¬£¬£¬Ç°ÌáÈÕÖ¾Ãû³ÆµÈÓÚ»òÔ̺¬¡°L2_WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶ÀûÓá±£¬£¬£¬¹¥»÷Á˾ֵÈÓÚ¡°¹¥»÷³É¹¦¡±£¬£¬£¬Ö÷ÕŵØÖ·ÒýÓÃ×ʲú·ì϶»òÔ´µØÖ·Æ¥ÅäÍþвµý±¨£¬£¬£¬´Ó¶øÌáÉý¹ØÁª¹æ¶¨µÄÏàÐŶÈ¡£


ͼƬ11.png


£¨4£©Æ¾¾Ý¶ÔCVE-2024-38077·ì϶µÄ¹¥»÷ÀûÓùý³Ì½øÐзÖÎö£¬£¬£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍ¼¼Êõ½×¶Î£¬£¬£¬¸²¸ÇµÄTTPÔ̺¬£º£º£º


TA0001³õʼ½Ó¼û£º£º£ºT1190ÀûÓÃÃæÏò¹«¼ÒµÄÀûÓ÷¨Ê½

TA0002Ö´ÐУº£º£ºT1059ºÅÁîºÍ¾ç±¾Ú¹ÊÍÆ÷

TA0004ȨÏÞÌáÉý£º£º£ºT1548ÀÄÓÃÌáȨ½ÚÖÆ»úÖÆ

TA0010Êý¾ÝÍâй£º£º£ºT1041Êý¾Ýͨ¹ýC2ͨµÀÍâй


ͼƬ12.png


ͨ¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´ëÖÃÄÜÁ¦£¬£¬£¬Õë¶Ô¸Ã·ì϶ÀûÓõĸ澯ÊÂÎñ±àÅž籾£¬£¬£¬½øÐÐ×Ô¶¯»¯´ëÖá£