¡¾·ì϶¹«¸æ¡¿Progress Telerik Report ServerÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2024-4358£©

°ä²¼¹¦·ò 2024-06-05


Ò»¡¢·ì϶¸ÅÊö

·ìϼûû³Æ

  Progress   Telerik Report ServerÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶

CVE   ID

CVE-2024-4358

·ì϶ÀàÐÍ

Éí·ÝÑéÖ¤ÈÆ¹ý

·¢ÏÖ¹¦·ò

2024-06-05

·ì϶ÆÀ·Ö

9.8

·ì϶µÈ¼¶

ÑϳÁ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ

 

Progress SoftwareµÄTelerik Report ServerÊÇÒ»¿îÖ°ÄÜ׳´óµÄ±¨±í·þÎñÆ÷½â¾ö¹æ»®£¬£¬ £¬£¬£¬£¬£¬£¬¾ß±¸È«ÃæµÄ»ã±¨ÖÎÀíÖ°ÄÜ£¬£¬ £¬£¬£¬£¬£¬£¬¿ÉÔ®ÊÖ×éÖ¯´´½¨¡¢²¿Êð¡¢½»¸¶ºÍÖÎÀí»ã±¨¡£¡£¡£ ¡£¡£¡£¡£

2024Äê6ÔÂ5ÈÕ£¬£¬ £¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯Íż¯ÍÅVSRC¼à²âµ½Progress Telerik Report ServerÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2024-4358£©µÄ¼¼Êõϸ½Ú¼°PoCÔÚ»¥ÁªÍøÉϹ«¿ª£¬£¬ £¬£¬£¬£¬£¬£¬ÍþвÕß¿É×éºÏÀûÓÃCVE-2024-4358ºÍCVE-2024-1800ʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬£¬ £¬£¬£¬£¬£¬£¬ÏêÇéÈçÏ£º

CVE-2024-4358£ºProgress Telerik Report ServerÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶

IISÉϵÄProgress Telerik Report Server 2024 Q1 (10.0.24.305) ¼°Ö®Ç°°æ±¾ÔÚRegister²½ÖèµÄʵÏÖÖдæÔÚÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¬£¬ £¬£¬£¬£¬£¬£¬ÓÉÓÚ¶Ìȱ¶Ôµ±Ç°×°Öò½ÖèµÄÑéÖ¤£¬£¬ £¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÔ¶³ÌÍþвÕßÈÆ¹ýÉí·ÝÑéÖ¤½Ó¼ûTelerik Report Server ÊÜÏÞÖ°ÄÜ£¬£¬ £¬£¬£¬£¬£¬£¬Î´ÊÚȨ´´½¨ÖÎÀíÔ¹ØÊ»§¡£¡£¡£ ¡£¡£¡£¡£

CVE-2024-1800£ºProgress Telerik Report Server·´ÐòÁл¯·ì϶

Progress Telerik Report Server 2024 Q1 (10.0.24.130)¼°Ö®Ç°°æ±¾ÔÚObjectReader ÀàÖдæÔÚ·´ÐòÁл¯·ì϶£¬£¬ £¬£¬£¬£¬£¬£¬ÓÉÓÚ¶ÔÓû§ÌṩµÄÊý¾Ý²»×ãÕýÈ·ÑéÖ¤£¬£¬ £¬£¬£¬£¬£¬£¬¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÀûÓø÷ì϶ÔÚÊÜÓ°ÏìµÄ Progress Telerik Report Server ×°ÖÃÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£ ¡£¡£¡£¡£

 

¶þ¡¢Ó°ÏìÁìÓò

CVE-2024-4358

Progress Software Telerik Report Server <= 2024 Q1 (10.0.24.305)

CVE-2024-1800

Progress Software Telerik Report Server <= 2024 Q1 (10.0.24.130)

 

 

Èý¡¢°²È«´ëÊ©

3.1 Éý¼¶°æ±¾

ĿǰÕâЩ·ì϶ÒѾ­½¨¸´£¬£¬ £¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔϰ汾£º

CVE-2024-4358

Progress Software Telerik Report Server >= 2024 Q2 (10.1.24.514)

CVE-2024-1800

Progress Software Telerik Report Server >= 2024 Q1 (10.0.24.305)

ÏÂÔØÁ´½Ó£º

https://www.telerik.com/report-server

3.2 һʱ´ëÊ©

Äܹ»Í¨¹ýÒÔÏ·½Ê½²é¿´ËùÔËÐеİ汾ÊÇ·ñÊÜÓ°Ï죺

1.½Ó¼ûReport Server web UI½çÃæ²¢Ê¹Æ÷ÓµÓÐÖÎÀíԱȨÏÞµÄÕË»§µÇ¼¡£¡£¡£ ¡£¡£¡£¡£

2.´ò¿ªÅäÖÃÒ³Ãæ£¨root-uri/Configuration/Index£©¡£¡£¡£ ¡£¡£¡£¡£

3.Ñ¡Ôñ ¡°About¡±Ñ¡Ï£¬£¬ £¬£¬£¬£¬£¬£¬°æ±¾ºÅ½«ÏÔʾÔÚÓҲര¸ñÖÓ×£¡£¡£ ¡£¡£¡£¡£

Õë¶ÔCVE-2024-4358£¬£¬ £¬£¬£¬£¬£¬£¬ÈçÎÞ·¨Á¢¼´Éý¼¶£¬£¬ £¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐURL RewriteÒÔ½â³ý IIS ÖеĹ¥»÷ÃæÀ´Ò»Ê±»º½â¸Ã·ì϶£º

1.´Ë»º½â´ëÊ©±ØÒªURL Rewrite IIS Ä£¿ £¿£¿£¿£¿é¡£¡£¡£ ¡£¡£¡£¡£ÈôÊÇÉÐδװÖÿÉÏÂÔØ×°Öã¨×°Öúó³ÁÐÂÆô¶¯ IIS ÖÎÀíÆ÷£©£¬£¬ £¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º

https://www.iis.net/downloads/microsoft/url-rewrite

2. ´ò¿ª IIS ÖÎÀíÆ÷²¢Ñ¡ÔñTelerik Report ServerÕ¾µã¡£¡£¡£ ¡£¡£¡£¡£

3.Ñ¡Ôñ URL Rewrite Ä£¿ £¿£¿£¿£¿é²¢Ö´ÐÐÒÔϲ½Ö裺

a)     µã»÷¡°Add Rules¡±

b)     Ñ¡Ôñ¡°Request Blocking¡±¹æ¶¨¡£¡£¡£ ¡£¡£¡£¡£

c)     ¶ÔÓÚ¡°Block Access Based On¡±, Ñ¡Ôñ¡°URL Path¡±¡£¡£¡£ ¡£¡£¡£¡£

d)     ¶ÔÓÚ¡°Pattern¡±£¬£¬ £¬£¬£¬£¬£¬£¬ÊäÈëÖµ: startup/register

e)     µ¥»÷¡° OK¡±±£Áô²¢¼¤»î¹æ¶¨¡£¡£¡£ ¡£¡£¡£¡£

ÈçÏÂͼËùʾ£º

image.png

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬ £¬£¬£¬£¬£¬£¬Ï÷¼õϵͳ·ì϶£¬£¬ £¬£¬£¬£¬£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¡£¡£ ¡£¡£¡£¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬£¬ £¬£¬£¬£¬£¬£¬Åú¸Ä·À»ðǽսÊõ£¬£¬ £¬£¬£¬£¬£¬£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬ £¬£¬£¬£¬£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬ £¬£¬£¬£¬£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£¡£¡£ ¡£¡£¡£¡£

l  ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬ £¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¡£¡£ ¡£¡£¡£¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬ £¬£¬£¬£¬£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬£¬ £¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£ ¡£¡£¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£¡£ ¡£¡£¡£¡£

3.4 ²Î¿¼Á´½Ó

https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358

https://docs.telerik.com/report-server/knowledge-base/deserialization-vulnerability-cve-2024-1800

https://summoning.team/blog/progress-report-server-rce-cve-2024-4358-cve-2024-1800/

 

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-06-05

³õ´Î°ä²¼

 

 

Îå¡¢¸½Â¼

5.1 8827Ì«Ñô¼¯Íżò½é

8827Ì«Ñô¼¯ÍųÉÁ¢ÓÚ1996Ä꣬£¬ £¬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£ ¡£¡£¡£¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£ ¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°8827Ì«Ñô¼¯ÍÅ´óÏ㬣¬ £¬£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬ £¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£¡£¡£ ¡£¡£¡£¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬ £¬£¬£¬£¬£¬£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¡£¡£ ¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÀö½­ÖÐÓ×°å¹ÒÅÆÉÏÊÓ×£¡£¡£ ¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬ £¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬£¬ £¬£¬£¬£¬£¬£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬£¬ £¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£¡£¡£ ¡£¡£¡£¡£

5.2 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ

8827Ì«Ñô¼¯ÍŰ²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬£¬ £¬£¬£¬£¬£¬£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬£¬ £¬£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£¡£¡£ ¡£¡£¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png