Microsoft ExchangeÔ¶³Ì´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-02-26

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-0688£¬£¬£¬£¬ £¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ £¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 30

Microsoft Exchange Server 2013 Cumulative Update 23

Microsoft Exchange Server 2016 Cumulative Update 14

Microsoft Exchange Server 2016 Cumulative Update 15

Microsoft Exchange Server 2019 Cumulative Update 3

Microsoft Exchange Server 2019 Cumulative Update 4


·ì϶¸ÅÊö


2020Äê2ÔÂ11ÈÕ£¬£¬£¬£¬ £¬£¬ £¬£¬Microsoft°ä²¼ÁËÕë¶ÔMicrosoft Exchange ServerÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-0688£©µÄ²¹¶¡·¨Ê½ ¡£¡£¡£¡£¡£¡£¡£¡£ÀûÓÃÕâ¸ö·ì϶£¬£¬£¬£¬ £¬£¬ £¬£¬¹¥»÷Õß¿Éͨ¹ýExchange·þÎñÉϵÄͨ³£Óû§È¨ÏÞ£¬£¬£¬£¬ £¬£¬ £¬£¬ÊÕÊÜÕû¸öExchange·þÎñÆ÷ ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°´Ë·ì϶µÄÀûÓÃϸ½ÚÒѾ­ÔÚ»¥ÁªÍø¹«¿ª ¡£¡£¡£¡£¡£¡£¡£¡£


·ì϶²úÉúÔÚ Exchange Control Panel £¨ECP£©×é¼þÖÐ ¡£¡£¡£¡£¡£¡£¡£¡£Óëÿ´ÎÈí¼þ×°ÖóÇÊвúÉúËæ»úÃÜÔ¿·ÖÆç£¬£¬£¬£¬ £¬£¬ £¬£¬ËùÓÐMicrosoft Exchange ServerÔÚ×°ÖúóµÄweb.configÎļþÖж¼Õ¼ÓÐÒ»ÑùµÄvalidationKeyºÍdecryptionKey ¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÃÜÔ¿ÓÃÓÚ±£ÕÏViewStateµÄ°²È«ÐÔ ¡£¡£¡£¡£¡£¡£¡£¡£¶øViewStateÊÇASP.NET WebÀûÓÃÒÔÐòÁл¯Ìåʽ´æ´¢ÔÚ¿Í»§»úÉϵķþÎñ¶ËÊý¾Ý ¡£¡£¡£¡£¡£¡£¡£¡£¿£¿ £¿£¿£¿£¿Í»§¶Ëͨ¹ý__VIEWSTATEÒªÇó²ÎÊý½«ÕâЩÊý¾Ý·µ»Ø¸ø·þÎñÆ÷ ¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚʹÓÃÁ˾²Ì¬ÃÜÔ¿£¬£¬£¬£¬ £¬£¬ £¬£¬¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ºýŪָ±ê·þÎñÆ÷·´ÐòÁл¯¶ñÒâ´´½¨µÄViewStateÊý¾Ý ¡£¡£¡£¡£¡£¡£¡£¡£µ±¹¥»÷ÕßÄܹ»µÇ¼ExchangeÓÊÏäÕË»§Ê±£¬£¬£¬£¬ £¬£¬ £¬£¬ÔÚYSoSerial.netµÄÔ®ÊÖÏ£¬£¬£¬£¬ £¬£¬ £¬£¬Äܹ»ÔÚExchange Control Panel webÀûÓÃÉÏÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


PoC£ºhttps://www.zerodayinitiative.com/blog/2020/2/24/cve-2020-0688-remote-code-execution-on-microsoft-exchange-server-through-fixed-cryptographic-keys ¡£¡£¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ£¬£¬£¬£¬ £¬£¬ £¬£¬Î¢Èí¹Ù·½ÒѰ䲼Õë¶ÔÊÜÓ°Ïì°æ±¾µÄ²¹¶¡·¨Ê½£¬£¬£¬£¬ £¬£¬ £¬£¬½¨ÒéÓû§¾¡¿ì×°Öãºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0688 ¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.zerodayinitiative.com/blog/2020/2/24/cve-2020-0688-remote-code-execution-on-microsoft-exchange-server-through-fixed-cryptographic-keys