Ô¶³Ì×ÀÃæ·þÎñ0day·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-06-05·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-9510£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º4.6
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
Windows 10 1803»òServer 2019»ò¸üеÄϵͳ
·ì϶¸ÅÊö
×êÑÐÈËÔ±·¢ÏÖÒ»¸öÐÂ0day£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼Ö¹¥»÷Õß½Ù³ÖÏÖÓеÄÔ¶³Ì×ÀÃæ·þÎñ»á»°£¬£¬£¬£¬£¬£¬£¬£¬»ñÈ¡¶ÔÍÆËã»úµÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¸Ã0day¿É±»ÓÃÓÚÈÆ¹ýWindowsÉ豸µÄËøÆÁ£¬£¬£¬£¬£¬£¬£¬£¬¼´±ãË«³É·ÖÈÏÖ¤ÈçDuo Security MFA¿ªÆôÒ²²»Àý±í¡£¡£¡£¡£¡£¡£¡£×éÖ¯»ú¹¹¿ÉÄÜÉèÖÃµÄÆäËüµÇ¼ÅäÖÃÒ²¿ÉÔâÈÆ¹ý¡£¡£¡£¡£¡£¡£¡£
Microsoft WindowsÔ¶³Ì×ÀÃæÖ§³Ö³ÆÎªÍøÂç¼¶±ðÉí·ÝÑéÖ¤£¨NLA£©µÄÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÖ°Äܿɽ«Ô¶³Ì»á»°µÄÉí·ÝÑéÖ¤·½Ãæ´ÓRDP²ãÒÆÖÁÍøÂç²ã¡£¡£¡£¡£¡£¡£¡£½¨ÒéʹÓÃNLAÀ´Ï÷¼õʹÓÃRDPºÍ̸¶³öµÄϵͳµÄ¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£ÔÚWindowsÖУ¬£¬£¬£¬£¬£¬£¬£¬Äܹ»Ëø¶¨»á»°£¬£¬£¬£¬£¬£¬£¬£¬ÏòÓû§ÏÔʾ±ØÒªÉí·ÝÑéÖ¤ÄÜÁ¦³ÖÐøÊ¹ÓûỰµÄÆÁÄ»¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»á»°Ëø¶¨Äܹ»Í¨¹ýRDP²úÉú£¬£¬£¬£¬£¬£¬£¬£¬Æä·½Ê½ÓëËø¶¨±¾µØ»á»°µÄ·½Ê½Ò»Ñù¡£¡£¡£¡£¡£¡£¡£
´ÓWindows 10 1803£¨2018Äê4Ô°䲼£©ºÍWindows Server 2019ÆðÍ·£¬£¬£¬£¬£¬£¬£¬£¬»ùÓÚNLAµÄRDP»á»°µÄ´¦Ö÷½Ê½²úÉúÁ˱䶯£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂ»á»°Ëø¶¨·½ÃæµÄÒâ±íÐÐΪ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÍøÂçÒì³£´¥·¢Ò»Ê±RDP¶Ï¿ªÏνӣ¬£¬£¬£¬£¬£¬£¬£¬ÔòÔÚ×Ô¶¯³ÁÐÂÏνÓʱ£¬£¬£¬£¬£¬£¬£¬£¬ÎÞÂÛÔ¶³ÌϵͳÈôºÎÍÑÀ룬£¬£¬£¬£¬£¬£¬£¬RDP»á»°¶¼½«¸´Ôµ½½âËø×´Ì¬¡£¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬£¬£¬Çë˼¿¼ÒÔϲ½Ö裺
Óû§Ê¹ÓÃRDPÏνӵ½Ô¶³ÌWindows 10 1803»òServer 2019»ò¸üеÄϵͳ¡£¡£¡£¡£¡£¡£¡£
Óû§Ëø¶¨Ô¶³Ì×ÀÃæ»á»°¡£¡£¡£¡£¡£¡£¡£
Óû§ÍÑÀë²¢ÁôÏÂRDP¿Í»§¶Ë
´Ëʱ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÖжÏRDP¿Í»§¶ËϵͳµÄÍøÂçÏνӡ£¡£¡£¡£¡£¡£¡£Ò»µ©¸´Ô»¥ÁªÍøÏνӣ¬£¬£¬£¬£¬£¬£¬£¬RDP¿Í»§¶ËÈí¼þ½«×Ô¶¯³ÁÐÂÏνӵ½Ô¶³Ìϵͳ¡£¡£¡£¡£¡£¡£¡£µ«ÓÉÓÚ´Ë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬³ÁÐÂÏνӵÄRDP»á»°½«»¹Ôµ½µÇ¼×ÀÃæ¶ø²»ÊǵǼÆÁÄ»¡£¡£¡£¡£¡£¡£¡£ÕâÒâζ×ÅÔ¶³Ìϵͳ½âËø¶øÎÞÐèÊÖ¶¯ÊäÈëÈκÎÍ´´¦¡£¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
Ŀǰ΢Èí²¢Î´³ïËã½üÆÚ½¨¸´£¬£¬£¬£¬£¬£¬£¬£¬Óû§¿Éͨ¹ýËø¶¨±¾µØÏµÍ³¶ø·ÇÔ¶³ÌϵͳµÄ·½Ê½£¬£¬£¬£¬£¬£¬£¬£¬»òͨ¹ý¶Ï¿ªÔ¶³Ì×ÀÃæ»á»°¶ø·Ç½öËø¶¨»á»°µÄ·½Ê½Ô¤·ÀÔâ¸Ã·ì϶ӰÏì¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/remote-desktop-zero-day-bug-allows-attackers-to-hijack-sessions/


¾©¹«Íø°²±¸11010802024551ºÅ