΢ÈíSMB3ºÍ̸Զ³ÌÀûÓÃ0day·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-03-11

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-0796£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Windows 10 Version 1903 for 32-bit Systems

Windows 10 Version 1903 for x64-based Systems

Windows 10 Version 1903 for ARM64-based Systems

Windows Server, version 1903 (Server Core installation)

Windows 10 Version 1909 for 32-bit Systems

Windows 10 Version 1909 for x64-based Systems

Windows 10 Version 1909 for ARM64-based Systems

Windows Server, version 1909 (Server Core installation)


·ì϶¸ÅÊö


CVE-2020-0796 ÊÇ´æÔÚÓÚ΢Èí·þÎñÆ÷SMBºÍ̸ÖеÄÒ»¸ö¡°È䳿»¯¡±·ì϶£¬£¬£¬£¬£¬£¬¸Ã·ì϶δÔ̺¬ÔÚ΢Èí±¾Ô°䲼µÄ²¹¶¡ÖУ¬£¬£¬£¬£¬£¬ÊÇÔÚ²¹¶¡µÄÐòÑÔÖÐй¶µÄ¡£¡£ ¡£¡£¡£¡£Ä¿Ç°Î¢ÈíÉÐδ°ä²¼Èκμ¼ÊõÏêÇ飬£¬£¬£¬£¬£¬Ë¼¿Æ Talos ÍÅ¶ÓºÍ Fortinet ¹«Ë¾ÌṩÁ˼ò¶Ì¸ÅÊö£¬£¬£¬£¬£¬£¬Ä¿Ç°Éв»Ã÷ÏԸ÷ì϶µÄ²¹¶¡ºÎʱ°ä²¼¡£¡£ ¡£¡£¡£¡£


Fortinet ¹«Ë¾Ö¸³ö£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÊÇ¡°Î¢Èí SMB ·þÎñÆ÷ÖеÄÒ»¸ö»º³åÇøÒç¶Âí½Å¡±£¬£¬£¬£¬£¬£¬ÑϳÁµÈ¼¶Îª×î¸ßÆÀ·Ö£¬£¬£¬£¬£¬£¬¡°¸Ã·ì϶ÓÉÒ×Êܹ¥»÷µÄÈí¼þÃýÎ󵨴¦ÖöñÒâ»ú¹ØµÄѹËõÊý¾Ý°ü¶ø´¥·¢¡£¡£ ¡£¡£¡£¡£Ô¶³Ì¡¢Î´¾­ÈÏÖ¤µÄ¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚ¸ÃÀûÓ÷¨Ê½µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡£ ¡£¡£¡£¡£¡±


˼¿Æ Talos ²©¿ÍÎÄÕÂÒ²¸ø³öÁËÀàËÆÃèÊö£¬£¬£¬£¬£¬£¬²»ÍâËæºó½«Æäɾ³ý¡£¡£ ¡£¡£¡£¡£Ë¼¿ÆÖ¸³ö£¬£¬£¬£¬£¬£¬¡°ÀûÓø÷ì϶¿Éµ¼ÖÂϵͳÔâÈ䳿¹¥»÷£¬£¬£¬£¬£¬£¬Ò²¾ÍÊÇ˵·ì϶¿ÉµÈÏеØÔÚÊܺ¦ÕßÖ®¼ä´«²¼¡£¡£ ¡£¡£¡£¡£¡±


·ì϶ÑéÖ¤


ÔÝÎÞPoC/EXP¡£¡£ ¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ΢ÈíûÓа䲼·ì϶ÏêÇé¼°²¹¶¡¡£¡£ ¡£¡£¡£¡£


»º½â´ëÊ©£º

1. ½ûÓÃSMbv3 compression¡£¡£ ¡£¡£¡£¡£½ûÓÃSMbv3 compression Äܹ»ÔÚSMBv3 ServerµÄPowershellÖÐÖ´ÐÐÈçÏ´úÂë

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 1 -Force

½øÐиü¸Äºó£¬£¬£¬£¬£¬£¬ÎÞÐè³ÁÐÂÆô¶¯¡£¡£ ¡£¡£¡£¡£´Ë½â¾ö²½Öè²»ÄÜÔ¤·ÀÀûÓÃSMB¿Í»§¶Ë¡£¡£ ¡£¡£¡£¡££»£»£» £»£»

2. ÈôÎÞÒµÎñ±ØÒª£¬£¬£¬£¬£¬£¬ÔÚÍøÂ簲ȫÓòÌìǵ·À»ðǽ·â¶ÂÎļþ´òÓ¡ºÍ¹²Ïí¶Ë¿Ú£¨tcp:135/139/445£©£»£»£» £»£»

3. ×°ÖÃɱ¶¾Èí¼þ£¬£¬£¬£¬£¬£¬²»½Ó¹ÜºÍµã»÷À´Àú²»Ã÷µÄÎļþ¡¢Óʼþ¸½¼þ£¬£¬£¬£¬£¬£¬²¢×öºÃÊý¾Ý±¸·Ý¹¤×÷£¬£¬£¬£¬£¬£¬Ô¤·ÀϰȾÀÕË÷²¡¶¾¡£¡£ ¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://fortiguard.com/encyclopedia/ips/48773