Õâ¸ö0day·ì϶Òѱ»ÔÚÒ°ÀûÓà OG¶«·½ÌüÌṩ¼ì²â¹æ»®
°ä²¼¹¦·ò 2023-07-24
²¶»ñµÄ´¹µöÎĵµ½çÃæ
¾ÝϤ£¬£¬¸Ã·ì϶Ϊ΢ÈíÓÚ7Ô°²È«¸üÐÂÖÐÅû¶µÄOfficeºÍWindows HTMLÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬´æÔÚÓÚ¶à¸öWindowsϵͳºÍOffice²úÆ·ÖС£ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©ÒѼà²âµ½·ì϶ÐÅÏ¢Åû¶ǰÒѲúÉúÔÚÒ°ÀûÓãºStorm-0978×éÖ¯£¨ÓÖ³ÆRomCom×éÖ¯£©ÔÚ¶Ô±±Ô¼·å»áµÄ¹¥»÷ÖУ¬£¬ÀûÓø÷ìÏ¶ÖÆ×÷ÁËÒÔÎÚ¿ËÀ¼ÊÀ½ç´ó»áΪÖ÷ÌâµÄµö¶üÎļþ£¬£¬ÌáÒé´¹µö¹¥»÷¡£
·ì϶¹¥»÷Á÷³Ì
CVE-2023-36884·ì϶Ö÷Ìâ˼·ÔÚÓÚÀûÓÃMicrosoft OfficeÎĵµOOXML¹æ·¶ÖпɴúÌæÌåʽ¿é£¨Alternative Format Chunk£©ÄÚǶ´øÓÐÆäËû¹¥»÷×é¼þµÄrtfÎĵµÊµÏÖOffice·ÀÓù»úÖÆÈÆ¹ý£¬£¬Äܹ»¹²Í¬ÆäËû·ì϶ʵÏÖÎÞ¸ÐÖª¡¢¡¢¡¢ÎÞ½»»¥µÄÔ¶³Ì´úÂëÖ´ÐС£
ÔçÆÚ´¹µö¹¥»÷Ñù±¾ÖØÒªÊ¹ÓÃCVE-2017-0199¡¢¡¢¡¢CVE-2021-40444¡¢¡¢¡¢CVE-2022-30190µÈÂß¼·ì϶£¬£¬ºóÐø¹¥»÷ÔØºÉÔ¶³Ì»ñÈ¡£¬£¬ÕûÌå¹¥»÷Á÷³Ì±ÈÁ¦¸´ÔÓ¡£
¶øÕâÁ½ÖÜÄÚÂ½Ðø²¶»ñµ½µÄÎÞÊý¹¥»÷Ñù±¾£¬£¬ÄÚǶµÄrtf¾ùѡȡģ°å»¯µÄCVE-2017-11882£¬£¬À´Ö´ÐÐrtfͬʱ¿ªÊ͵ÄPEÎļþ¡£

²¿ÃŲ¶»ñÑù±¾²»Ô̺¬µö¶üÐÅÏ¢£¬£¬²¢´øÓÐеÄrtf»ìºÏ¼¼ÇÉ£ºÀûÓÃrtfÎļþÖÐÔ̺¬µÄole¶ÔÏó¹ý³Ì¶Ô16½øÖÆÊý¾ÝµÄ³¤¶ÈÏÞ¶È£¬£¬Ê¹¾²Ì¬½âÎö¹ý³ÌÊý¾Ý´í룬£¬ÎÞ·¨¶ÔÆë»¹ÔÔÓÐole¶ÔÏ󣬣¬¾ß±¸½ÏÇ¿µÄÃâɱÄÜÁ¦¡£
·ì϶·çÏÕ
ÔÚÏÖʵ´¹µö¹¥»÷ÖУ¬£¬¸Ã·ì϶¿ÉÓÃÓÚÈÆ¹ýoffice°²È«»úÖÆ¼°Ìṩһ²ãÃâɱ£¬£¬ÎªÆäËûoffice³£Óô¹µö¹¥»÷·ì϶ÌṩÁ˱£»£»£»¤¿Ç£¬£¬ÊµÏÖÁËÎÞ¸ÐÖª¡¢¡¢¡¢ÎÞ½»»¥µÄÔ¶³Ì´úÂëÖ´ÐУ¬£¬´ó·ù½µµÍ´¹µö¹¥»÷ÀûÓÃÃż÷£¬£¬·¸·¨Õ߿ɽÏΪÇáËɵؽ«ÔÓвâÊÔÓù¥»÷ÔØºÉ´úÌæÎªC2¹¤¾ß£¬£¬Ðγɴ¹µö¹¥»÷Èë¿Ú£¬£¬·çÏÕ¼«´ó£¬£¬±ØÒª×öºÃ·ÀÓù´ëÊ©¡£
OG¶«·½Ìü¼ì²â¹æ»®
1¡¢¡¢¡¢Îļþ»¹Ô¼ì²â
¸Ã·ì϶¹²Í¬ÆäËûoffice·ì϶ʹÓ㬣¬ÓÃÓÚ´¹µöÓʼþ¹¥»÷¡£ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©Ñ¡È¡Ë«Ïò¼ì²âÒýÇæ£¬£¬¿É¶Ô°ÙÓàÖÖÎļþ½øÐл¹Ô£¬£¬ÄÚÖÃɳÏ䣬£¬¿É¶Ô³£¼û°ÙÓàÖÖÓʼþ¸½¼þÌåʽ½øÐл¹ÔºÍɳÏä¼ì²â£¬£¬Í¬Ê±¾ß±¸ÌáÈ¡ÕýÎÄÃÜÂëÆÆ½âÄÜÁ¦£¬£¬¿É×Ô¶¯Ê¹ÓÃÓʼþÕýÎÄÃÜÂë±¬ÆÆÑ¹Ëõ°ü¸½¼þ£¬£¬±¬ÆÆ³É¹¦ºó¶Ô¸½¼þ¼°¸½¼þ×ÓÎļþ½øÐмì²â¡£
2¡¢¡¢¡¢ÐÐΪ¼ì²â
ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©ÄÚÖÃɳÏ䣬£¬³ý¾²Ì¬¼ì²âÍ⣬£¬»¹¿É¶ÔofficeÎļþ½øÐÐÐÐΪ¼ì²âºÍ·ì϶ÀûÓüì²â¡£É³ÏäѡȡµÚÈý´úÓ²¼þ·ÂÕæ¼¼Êõ£¬£¬¿É¶Ô¶ñÒâÑù±¾½øÐкýŪ£¬£¬Í¨¹ýofficeÎļþÖ´ÐÐÐÐΪ£¬£¬À´Åж¨¶ñÒâÐÐΪ¡£

ÐÐΪ¼ì²â¸æ¾¯½çÃæ
3¡¢¡¢¡¢»º½â´ëÊ©
ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©ÒÑÖ§³ÖCVE-2023-36884·ì϶ÀûÓüì²â£¬£¬ÇëÓû§²»Òª´ò¿ªÀ´Àú²»Ã÷µÄofficeÎĵµ£¬£¬ÒѲ¿ÊðTARÓû§¿É½«¿ÉÒÉÎĵµÀëÏßÉÏ´«µ½TARÉ豸¼ì²â¡£
±¾µØ»º½â´ëÊ©£º
¿ÉÅäÖÃÓйØ×¢²á±íÏîÀ´×èÖ¹Óйطì϶±»ÀûÓÃ,²½ÖèÈçÏÂ:
н¨Ò»¸öÎı¾Îĵµ,ÊäÈëÈçÏÂÄÚÈݲ¢±£Áô¡£
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet
Explorer\Main\FeatureControl\FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION]
"Excel.exe"=dword:00000001
"Graph.exe"=dword:00000001
"MSAccess.exe"=dword:00000001
"MSPub.exe"=dword:00000001
"Powerpnt.exe"=dword:00000001
"Visio.exe"=dword:00000001
"WinProj.exe"=dword:00000001
"WinWord.exe"=dword:00000001
"Wordpad.exe"=dword:00000001
½«±£ÁôµÄÎļþºó׺Åú¸ÄΪ.reg¡£
Ë«»÷Åú¸ÄºóµÄÎļþ,µ¼Èë×¢²á±í¼´¿É¡£
µ¼ÈëʵÏÖºó½¨ÒéÖØÆôËùÓдò¿ªµÄOffice·¨Ê½ÒÔÈ·±£ÉèÖÃÉúЧ¡£


¾©¹«Íø°²±¸11010802024551ºÅ