΢ÈíSQL Server Reporting ServicesÔ¶³Ì´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-02-17

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-0618£¬£¬£¬ £¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Microsoft SQL Server 2012 for 32-bit Systems Service Pack 4 (QFE)

Microsoft SQL Server 2012 for x64-based Systems Service Pack 4 (QFE)

Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU)

Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)

Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU)

Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)

Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (CU)

Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)


·ì϶¸ÅÊö


½üÈÕ£¬£¬£¬ £¬ £¬±¾ÔÂ΢Èí²¹¶¡¸üеķì϶£¬£¬£¬ £¬ £¬Î¢ÈíSQL Server Reporting ServicesÔ¶³Ì´úÂëÖ´Ðзì϶µÄPoC±»¹«¿ª£¬£¬£¬ £¬ £¬SQL Server Reporting ServicesÌṩһ×é±¾µØ¹¤¾ßºÍ·þÎñ£¬£¬£¬ £¬ £¬ÓÃÓÚ´´½¨¡¢²¿ÊðºÍÖÎÀí±¨±í¡£¡£¡£¡£¡£ ¡£¡£SQL Server Reporting ServicesÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬ £¬ £¬½öÐè»ñµÃµÍȨÏ޵Ĺ¥»÷ÕßÄܹ»ÏòÊÜÓ°Ïì°æ±¾µÄReporting ServicesÊ·ýÌá½»¾«ÐÄ»ú¹ØµÄÒªÇóÀ´ÀûÓô˷ì϶¡£¡£¡£¡£¡£ ¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÔÚReport Server·þÎñÕÊ»§¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£


´Ë·ì϶λÓÚReportingServicesWebServer.dllÎļþÖеÄBrowserNavigationCorrectorÀ࣬£¬£¬ £¬ £¬ÈçÏÂͼËùʾ:


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


´ÓÉÏͼ¿É¼û£¬£¬£¬ £¬ £¬ BrowserNavigationCorrectorÀàÖеÄOnLoad²½ÖèʹÓÃLosFormatterÀà½øÐз´ÐòÁл¯²Ù×÷¡£¡£¡£¡£¡£ ¡£¡£


LosFormatterͨ³£ÓÃÓÚÐòÁл¯ºÍ·´ÐòÁл¯Web´°ÌåÒ³µÄÊÓͼ״̬(ViewState) £¬£¬£¬ £¬ £¬µ±Î´¾­¹ýÂ˵ÄÓû§ÊäÈë±»LosFormatterÀà½øÐз´ÐòÁл¯²Ù×÷ʱ£¬£¬£¬ £¬ £¬¾Í»á²úÉú·´ÐòÁл¯·ì϶¡£¡£¡£¡£¡£ ¡£¡£


BrowserNavigationCorrectorÀà±»Microsoft.ReportingServices.WebServer.ReportViewerPageÀàŲÓ㬣¬£¬ £¬ £¬ÈçÏÂͼ£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ReportViewerPageÀàÄܹ»ÓÉ/ReportServer/pages/ReportViewer.aspxÒ³Ãæ½øÐд«²ÎŲÓ㬣¬£¬ £¬ £¬µ±¹¥»÷ÕßŲÓøÃÒ³Ãæ²¢´«Èë¶ñÒâ»ú¹ØµÄÐòÁл¯payload£¬£¬£¬ £¬ £¬¼´¿É´¥·¢·ì϶¡£¡£¡£¡£¡£ ¡£¡£


·ì϶ÑéÖ¤


PoC£ºhttps://www.mdsec.co.uk/2020/02/cve-2020-0618-rce-in-sql-server-reporting-services-ssrs/¡£¡£¡£¡£¡£ ¡£¡£


½¨¸´½¨Òé


Ŀǰ΢ÈíÒѰ䲼²¹¶¡½¨¸´·ì϶£¬£¬£¬ £¬ £¬²Î¿¼Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0618¡£¡£¡£¡£¡£ ¡£¡£


ÈôÊÇÄúµÄSQL Server°æ±¾ºÅδÔÚÉÏÎÄÖУ¬£¬£¬ £¬ £¬ÄÇôÄúµÄSQL Server°æ±¾½«²»ÔÙÊܵ½Î¢Èí¹Ù·½Ö§³Ö¡£¡£¡£¡£¡£ ¡£¡£Í¬ÑùÓб»´Ë·ì϶ӰÏìµÄ·çÏÕ¡£¡£¡£¡£¡£ ¡£¡£ÇëÉý¼¶µ½×îеÄSQL Server£¬£¬£¬ £¬ £¬ÒÔÃâÔâ·ê·ì϶¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£


²Î¿¼Á´½Ó


https://www.mdsec.co.uk/2020/02/cve-2020-0618-rce-in-sql-server-reporting-services-ssrs/