Microsoft Exchange 3Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-03-030x00 ·ì϶¸ÅÊö
2021Äê03ÔÂ02ÈÕ£¬£¬£¬£¬£¬Microsoft°ä²¼¹ØÓÚExchangeµÄ°²È«¸üУ¬£¬£¬£¬£¬½¨¸´ÁËExchangeÖеĶà¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ýÏòÖ¸±êExchange Server·¢ËͶñÒâÊý¾Ý°üÀ´ÀûÓÃÕâЩ·ì϶£¬£¬£¬£¬£¬×îÖÕÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬¶øÎÞÐèÓû§½»»¥¡£¡£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé

±¾´Î½¨¸´µÄExchange·ì϶ÈçÏ£º
CVE ID | ÆÀ·Ö | Ó°Ïì | ÊÇ·ñÒѱ»ÀûÓà |
CVE-2021-26855 | 9.1 | ¹¥»÷Õß¿ÉÄÜ·¢ËÍËÁÒâHTTPÒªÇó²¢Í¨¹ýExchange Server½øÐÐÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£ | ÊÇ |
CVE-2021-26857 | 7.8 | ¹¥»÷ÕßÄܹ»ÔÚExchange ServerÉÏÒÔSYSTEMȨÏÞÔËÐдúÂë¡£¡£¡£¡£¡£¡££¨ÐèÖÎÀíԱȨÏÞ£© | ÊÇ |
CVE-2021-26858 | 7.8 | ExchangeÖдæÔÚÑéÖ¤ºóµÄËÁÒâÎļþдÈë·ì϶¡£¡£¡£¡£¡£¡£Í¨¹ýÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶½«ÎļþдÈë·þÎñÆ÷µÄÈκÎõè¾¶ÖС£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬Í¨¹ý¹²Í¬ÀûÓÃCVE-2021-26855 SSRF·ì϶Äܹ»·ÛËéÖÎÀíÔ±µÄÍ´´¦À´½øÐÐÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£ | ÊÇ |
CVE-2021-27065 | 7.8 | ||
CVE-2021-26412 | 9.1 | RCE | ·ñ |
CVE-2021-26854 | 6.6 | RCE | ·ñ |
CVE-2021-27078 | 9.1 | RCE | ·ñ |
ÆäÖУ¬£¬£¬£¬£¬CVE-2021-26855¡¢CVE-2021-26857¡¢CVE-2021-26858ºÍCVE-2021-27065·ì϶±»×÷Ϊ¹¥»÷Á´µÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£³õʼ¹¥»÷±ØÒªÓëExchange Server 443¶Ë¿Ú³ÉÁ¢Ïνӣ¬£¬£¬£¬£¬Äܹ»Í¨¹ýÏÞ¶È·ÇÐÅÀµµÄÏνӣ¬£¬£¬£¬£¬»òÉèÖÃVPN½«Exchange ServerÓë±í²¿½Ó¼û·Ö¸ôÀ´Ô¤·À³õʼ¹¥»÷£¬£¬£¬£¬£¬µ«ÈôÊǹ¥»÷ÕßÒѾÓÐÁ˽ӼûȨÏÞ£¬£¬£¬£¬£¬»òÕßÄܹ»ÒÔÖÎÀíԱȨÏÞÔËÐжñÒâÎļþ£¬£¬£¬£¬£¬ÔòÄܹ»´¥·¢¹¥»÷Á´µÄÆäËü²¿ÃÅ¡£¡£¡£¡£¡£¡£
Ó°ÏìÁìÓò
Exchange Server 2010
Exchange Server 2013
Exchange Server 2016
Exchange Server 2019
0x02 ´ëÖý¨Òé
ĿǰMicrosoftÒѰ䲼Óйذ²È«¸üУ¬£¬£¬£¬£¬¼øÓÚ·ì϶µÄÑϳÁÐÔ£¬£¬£¬£¬£¬½¨Ò龡¿ìÉý¼¶½¨²¹£º
https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server/
һʱ´ëÊ©
CVE-2021-26855
Äܹ»Í¨¹ýÒÔÏÂExchange HttpProxyÈÕÖ¾½øÐмì²â£º
%PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging\HttpProxy
ͨ¹ýÒÔÏÂPowershell¿ÉÖ±½Ó½øÐÐÈÕÖ¾¼ì²â£¬£¬£¬£¬£¬²¢²é³ÊÇ·ñÊܵ½¹¥»÷£º
Import-Csv -Path (Get-ChildItem -Recurse -Path ¡°$env:PROGRAMFILES\Microsoft\Exchange Server\V15\Logging\HttpProxy¡± -Filter ¡®*.log¡¯).FullName | Where-Object { $_.AuthenticatedUser -eq ¡± -and $_.AnchorMailbox -like ¡®ServerInfo~*/*¡¯ } | select DateTime, AnchorMailbox
ÈôÊǼì²âµ½ÈëÇÖ£¬£¬£¬£¬£¬Äܹ»Í¨¹ýÒÔÏÂĿ¼»ñÈ¡¹¥»÷Õß²ÉÈ¡ÁËÄÄЩ»î¶¯£º
%PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging
CVE-2021-26857
¸Ã·ì϶µ¥¶ÀÀûÓÃÄѶȽϸߣ¬£¬£¬£¬£¬¿ÉÀûÓÃÒÔϺÅÁî¼ì²âÈÕÖ¾Ìõ¿î£¬£¬£¬£¬£¬²¢²é³ÊÇ·ñÊܵ½¹¥»÷¡£¡£¡£¡£¡£¡£
Get-EventLog -LogName Application -Source ¡°MSExchange Unified Messaging¡± -EntryType Error | Where-Object { $_.Message -like ¡°*System.InvalidCastException*¡± }
CVE-2021-26858
ÈÕ־Ŀ¼£º
C:\Program Files\Microsoft\Exchange Server\V15\Logging\OABGeneratorLog
¿Éͨ¹ýÒÔϺÅÁî½øÐм±¾çä¯ÀÀ£¬£¬£¬£¬£¬²¢²é³ÊÇ·ñÊܵ½¹¥»÷£º
findstr /snip /c:¡±Download failed and temporary file¡± ¡°%PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging\OABGeneratorLog\*.log¡±
CVE-2021-27065
¿Éͨ¹ýÒÔÏÂpowershellºÅÁî½øÐÐÈÕÖ¾¼ì²â£¬£¬£¬£¬£¬²¢²é³ÊÇ·ñÔâµ½¹¥»÷:
Select-String -Path ¡°$env:PROGRAMFILES\Microsoft\Exchange Server\V15\Logging\ECP\Server\*.log¡± -Pattern ¡®Set-.+VirtualDirectory¡¯
0x03 ²Î¿¼Á´½Ó
https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server/
https://techcommunity.microsoft.com/t5/exchange-team-blog/released-march-2021-exchange-server-security-updates/ba-p/2175901
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26855
https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
0x04 ¹¦·òÏß
2021-03-02 MSRC°ä²¼°²È«²¼¸æ
2021-03-03 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ