Windows BlueKeep·ì϶£¨CVE-2019-0708£©
°ä²¼¹¦·ò 2019-09-07

2019Äê5ÔÂ14ÈÕ΢Èí°ä²¼Ô¶³Ì×ÀÃæ·þÎñ£¨ÒÔǰ³ÆÎªÖÕ¶Ë·þÎñ£©µÄÔ¶³ÌÖ´ÐдúÂë·ì϶BlueKeep£¨CVE-2019-0708£©µÄ½¨¸´·¨Ê½¡£¡£¡£¡£¡£¡£¡£´Ë·ì϶ÊÇÔ¤Éí·ÝÑéÖ¤£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥²¢ÓпÉÄÜÒÔÀàËÆÈ䳿µÄ·½Ê½´«²¼¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
9ÔÂ6ÈÕMetasploitÒѾ½«BlueKeep·ì϶EXP°ä²¼µ½metasploit-frameworkµÄPull requestsÖУ¬£¬£¬£¬£¬Ä¿Ç°ÖØÒªÕë¶Ô64λ°æ±¾µÄWindows 7ºÍWindows Server 2008 R2¡£¡£¡£¡£¡£¡£¡£¶ÔÓÚWindows Server 2008 R2£¬£¬£¬£¬£¬±ØÒªÅú¸Ä×¢²á±í£¬£¬£¬£¬£¬µ«ÈÔÓÐÆäËû¿ÉÄÜÐÔʹÓÃÔÚËùÓÐWindows²Ù×÷ϵͳÉÏ¡£¡£¡£¡£¡£¡£¡£
¹ØÓÚBlueKeep·ì϶µÄÔ¤¾¯ÏêÇé¿É²Î¿¼Î¬ËûÃüµÄº¹Çà·ì϶Ԥ¾¯£º
¡¾·ì϶Ԥ¾¯¡¿Windows RDPÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2019-0708£©
¹ÌÈ»Õë¶Ô´Ë·ì϶ÀûÓõÄÌØ¶¨·ÀÓùºÍ¼ì²âºÜÓÐЧ£¬£¬£¬£¬£¬µ«¡°DejaBlue¡±ÏµÁÐÖнÏеÄRDP·ì϶ͨ³£¶¼Ç¿µ÷Á˴˺Í̸µÄ·çÏÕ¡£¡£¡£¡£¡£¡£¡£¸ÃºÍ̸¹ÌÓеĸ´ÔÓÐÔÅú×¢£¬£¬£¬£¬£¬½ñÌìÒÑÖªµÄÃýÎó²»»áÊÇ×îºóÒ»¸ö£¬£¬£¬£¬£¬³ö¸ñÊÇÓÉÓÚ·ì϶ÀûÓÿª·¢ÈËÔ±ºÍ×êÑÐÈËÔ±´Ë¿Ì¶ÔRDP¼°ÆäÈõµãÓÐÁ˸üÇá΢µÄÀí½â¡£¡£¡£¡£¡£¡£¡£Ëæ×Å·ì϶ÀûÓÃˮƽµÄÌá¸ß£¬£¬£¬£¬£¬¿ÉÄÜ»á³ÖÐø¿ª·¢¡£¡£¡£¡£¡£¡£¡£
½¨¸´CVE-2019-0708·ì϶ӵÓгÁÒªÐԺͽôÆÈÐÔ£¬£¬£¬£¬£¬½¨ÒéÓû§²»ÒªÐÄ´æÐÒÔË¡£¡£¡£¡£¡£¡£¡£Rapid7 LabsÖ®Ç°ÔøÐ´¹ý×ÔBlueKeep·ì϶°ä²¼ÒÔÀ´ËûÃǹ۲쵽µÄ¶ñÒâRDP»î¶¯ÔÚ³ÖÐøÉÏÉý¡£¡£¡£¡£¡£¡£¡£
Ŀǰ¼ì²âµ½È«Çò³¬¹ý100Íò¸öϵͳ¿ªÆôRDP·þÎñ¡£¡£¡£¡£¡£¡£¡£×Ըò¹¶¡ÓÚ5Ô°䲼ÒÔÀ´£¬£¬£¬£¬£¬¸Ã·ì϶Êܵ½Á˰²È«ÐÐÒµµÄ¿í·º¹Ø×¢£¬£¬£¬£¬£¬½¨ÒéÓû§ºâÁ¿Î´½¨²¹·ì϶ËùÔì³ÉµÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ