SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-03-29

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-0604£¬£¬£¬ £¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬ £¬ £¬£¬£¬£¬ CVSS·ÖÖµ£º7.8


Ó°Ïì°æ±¾£º


Microsoft SharePoint Server 2019
Microsoft SharePoint Enterprise Server 2016
Microsoft SharePoint Foundation 2013 Service Pack 1
Microsoft SharePoint Server 2010 Service Pack 2


·ì϶¸ÅÊö


SharePointÊÇ΢ÈíµÄÒ»¿îÍŶӺÏ×÷½â¾ö¹æ»®£¬£¬£¬ £¬ £¬£¬£¬£¬ÓÃÓÚÍŶӼ乲ÏíºÍÖÎÀíÄÚÈݺÍ֪ʶ ¡£ ¡£¡£ ¡£¡£ËüʹÓÃASP.NET¿ª·¢£¬£¬£¬ £¬ £¬£¬£¬£¬ºó¶ËÊý¾Ý¿âʹÓÃMicrosoft SQL Server ¡£ ¡£¡£ ¡£¡£
³É¹¦ÀûÓ÷ì϶£¬£¬£¬ £¬ £¬£¬£¬£¬¿Éµ¼ÖÂWindowsϵͳ·þÎñÆ÷Ô¶³ÌÖ´ÐкÅÁ£¬£¬ £¬ £¬£¬£¬£¬ÓпÉÄÜÆëÈ«½ÚÔì·þÎñÆ÷ ¡£ ¡£¡£ ¡£¡£
¹¥»÷Õ߿ɽ«¾«ÐÄ»ú¹ØµÄÒªÇóͨ¹ýItemPicker WebForm¿Ø¼þ´«Èëºó¶ËEntityInstanceIdEncoder.DecodeEntityInstanceId(encodedId)²½ÖèÖУ¬£¬£¬ £¬ £¬£¬£¬£¬ÓÉÓÚ²½ÖèûÓжԴ«ÈëµÄencodedId½øÐÐÈκδ¦Ö㬣¬£¬ £¬ £¬£¬£¬£¬Ò²Ã»ÓжÔXmlSerializer»ú¹Øº¯ÊýµÄÀàÐͲÎÊý½øÐÐÏÞ¶È£¬£¬£¬ £¬ £¬£¬£¬£¬¿ÉÖ±½Óͨ¹ýXmlSerializer·´ÐòÁл¯£¬£¬£¬ £¬ £¬£¬£¬£¬Ôì³ÉºÅÁîÖ´ÐÐ ¡£ ¡£¡£ ¡£¡£
ÒªÀûÓø÷ì϶£¬£¬£¬ £¬ £¬£¬£¬£¬±ØÒªÊÚȨ½Ó¼ûSharePointÌṩµÄÖÎÀíÍøÒ³£¬£¬£¬ £¬ £¬£¬£¬£¬ÊÚȨÕË»§¿ÉËùÒÔÒ»¸öÓòÕË»§ ¡£ ¡£¡£ ¡£¡£


·ì϶ϸ½Ú


ÀûÓÃǰÌ᣺


¿ÉÊÚȨ½Ó¼ûSharePointÌṩµÄÖÎÀíÍøÒ³£¬£¬£¬ £¬ £¬£¬£¬£¬ÊÚȨÕË»§¿ÉËùÒÔÒ»¸öÓòÕË»§ ¡£ ¡£¡£ ¡£¡£


»·¾³´î½¨£º


?    Windows server 2016
?    ASP.NETÓйØ×é¼þ
?    Microsoft SQL Server
?    SharePoint Server
×°ÖÃSharePointǰÄܹ»ÏÈÔËÐÐprerequisiteinstaller ×°ÖÃSharePoint±Ø±¸µÄ×é¼þ£¬£¬£¬ £¬ £¬£¬£¬£¬¶øºó×°ÖÃMicrosoft SQL Server£¬£¬£¬ £¬ £¬£¬£¬£¬ÅäÖúÃÕË»§ ¡£ ¡£¡£ ¡£¡£ÈôÊÇÔÚµ¥»úÉϴSharePoint±ØÒªÔÚ´Ëʱ½«·þÎñÆ÷Çл»ÎªÓò¿Ø·þÎñÆ÷£¬£¬£¬ £¬ £¬£¬£¬£¬¶øºóÔÙ³ÉÁ¢ÓòÕ˺Å×°ÖúͲ¿ÊðSharePoint ¡£ ¡£¡£ ¡£¡£±¾µØÕ˺Ų»ÇкÏSharePointµÄ²¿ÊðÒªÇó ¡£ ¡£¡£ ¡£¡£


·ì϶·ÖÎö£º


·ì϶Èë¿ÚÔÚhttp:// SharePointDomin Or IP>:/_layouts/15/Picker.aspx?PickerDialogType=£¬£¬£¬ £¬ £¬£¬£¬£¬Í¨¹ýÅú¸ÄWebForm PostBackºóЯ´ø²ÎÊýctl00%24PlaceHolderDialogBodySection%24ctl05%24hiddenSpanDataµÄÖ·´¼ÓÔØPayload ¡£ ¡£¡£ ¡£¡£Ê¹Ó÷´±àÒ빤¾ßILSpy¼ÓÔØSharePoint.dllËÑË÷Èë¿ÚItemPickerDialog£¬£¬£¬ £¬ £¬£¬£¬£¬Í¨¹ý¶ÈÎöËüµÄ»ú¹Øº¯Êý£¬£¬£¬ £¬ £¬£¬£¬£¬·¢ÏÔìäŲÓÃÁ˸¸ÀàµÄ»ú¹Øº¯Êý£¬£¬£¬ £¬ £¬£¬£¬£¬´«²ÎÈçÏ£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


½øÈ븸ÀàPickerDialogÖУ¬£¬£¬ £¬ £¬£¬£¬£¬¿´»ú¹Øº¯Êý£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÆäÖÐEntityEditorWithPickerÒ²ÊÇÒ»¸öWebForm¿Ø¼þ£¬£¬£¬ £¬ £¬£¬£¬£¬×¢Ã÷ÔÚÕâÀï´«ÈëÁËÒ»¸öEntityEditorWithPickerµÄ×ÓÀàItemPicker£¬£¬£¬ £¬ £¬£¬£¬£¬¸úÈëItemPicker¿É¿´µ½ItemPickerµÄÈ·¼Ì³Ð×ÔEntityEditorWithPicker£¬£¬£¬ £¬ £¬£¬£¬£¬EntityEditorWithPickerÓּ̳Ð×ÔEntityEditor£º


 8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



EntityEditorʵÏÖÁ˽ӿڣºIPostBackDataHandlerºÍICallbackEventHandler£¬£¬£¬ £¬ £¬£¬£¬£¬Æ¾¾ÝWebForm¿Ø¼þµÄÐÔÃüÖÜÆÚ£¬£¬£¬ £¬ £¬£¬£¬£¬ÔÚÒ³ÃæÖÐÓÐÊÂÎñ´¥·¢__doPostBack()ºó£¬£¬£¬ £¬ £¬£¬£¬£¬ÏÈŲÓÃͨ¹ýICallbackEventHandlerʵÏÖµÄRaiseCallbackEvent()²½ÖèºÍGetCallbackResult()²½ÖèµÃµ½±íµ¥ÄÚÈÝ£¬£¬£¬ £¬ £¬£¬£¬£¬ÔÙŲÓÃͨ¹ýIPostBackDataHandlerʵÏÖµÄLoadPostData()²½Öè ¡£ ¡£¡£ ¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


»Øµ½EntityEditorÖп´GetCallbackResult()²½ÖèÖÐŲÓÃÁËInvokeCallbackEvent()²½Ö裬£¬£¬ £¬ £¬£¬£¬£¬InvokeCallbackEvent()²½ÖèŲÓÃÁËParseSpanData()²½Ö裺


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website




À´µ½ParseSpanData()ÖÐÄܹ»¿´³öÕâÀï°Ñ±íµ¥Ìá½»µÄÊý¾Ý½øÐÐÁË´¦Öà ¡£ ¡£¡£ ¡£¡£´Ë´¦Âß¼­¼«¶È¸´ÔÓ£¬£¬£¬ £¬ £¬£¬£¬£¬ÎÒÃÇÖ»¸ú¶ÔHiddenSpanDataµÄ´¦Öãº


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¿É·¢Ïִ˲½Ö轫HiddenSpanDataµÄÖµ·ÅÈëÁËPickerEntityµÄListÖУ¬£¬£¬ £¬ £¬£¬£¬£¬ÔÚ¾­¹ýһЩ´¦ÖúóÔ׸î³ÉÊý×飬£¬£¬ £¬ £¬£¬£¬£¬±éÀúÊý×飬£¬£¬ £¬ £¬£¬£¬£¬Ð½¨PickerEntity¶ÔÏópickerEntity2£¬£¬£¬ £¬ £¬£¬£¬£¬½«ÆäÖµ·ÅÈëpickerEntity2.KeyÖУ¬£¬£¬ £¬ £¬£¬£¬£¬×îÖÕ·ÅÈëarrayListÖв¢¸³Öµ¸øÀà³ÉÔ±±äÁ¿m_listOrderTemp:


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


»Øµ½LoadPostData()²½Öè¿´¶Ôm_listOrderTemp³ÉÔ±±äÁ¿µÄ´¦Ö㬣¬£¬ £¬ £¬£¬£¬£¬¿É¿´µ½ÔÚÕâÀï±éÀúÁËm_listOrderTemp³ÉÔ±±äÁ¿µÄÖµ²¢½«Æä¼Ó½øm_listRevalidation³ÉÔ±±äÁ¿ÖУ¬£¬£¬ £¬ £¬£¬£¬£¬¶øºóµü´ú½øÐÐValidate()²Ù×÷£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÔÚValidate()²½ÖèÖУ¬£¬£¬ £¬ £¬£¬£¬£¬½«m_listOrderTemp³ÉÔ±±äÁ¿¸³Öµ¸øm_listOrder³ÉÔ±±äÁ¿£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¶øºó±éÀúEntitiesµÄֵŲÓÃValidateEntity()²½Ö裺


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


EntitiesµÄÖ·´×ÔÓÚÉÏÃæµÄÒ»Ðкܲ»ÆðÑÛµÄLambda±í°×ʽ²½Ö裬£¬£¬ £¬ £¬£¬£¬£¬´Ë²½Ö轫·µ»Øm_listOrder³ÉÔ±±äÁ¿µÄÖµ£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¸úµ½ValidateEntity()²½Öè·¢ÏÖÊÇÐé²½Ö裬£¬£¬ £¬ £¬£¬£¬£¬Òò¶øÈ¥×ÓÀàÕÒ²½ÖèµÄ³Áд ¡£ ¡£¡£ ¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


À´µ½EntityEditorWithPickerÀàÖп´µ½ÁËValidateEntity() ²½ÖèµÄ³Áд£¬£¬£¬ £¬ £¬£¬£¬£¬·¢ÏÔì佫PickerEntityµÄkey£¨pe.Key£©´«ÈëÁËMicrosoft.SharePoint.BusinessData.Infrastructure.EntityInstanceIdEncoder.DecodeEntityInstanceId()ÖÐ ¡£ ¡£¡£ ¡£¡£
½øÈëDecodeEntityInstanceId() ²½Öè·¢ÏÖ·´ÐòÁл¯£¬£¬£¬ £¬ £¬£¬£¬£¬²¢ÇÒXmlSerializer»ú¹Øº¯ÊýµÄÀàÐͲÎÊý¿É¿Ø ¡£ ¡£¡£ ¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


²¹¶¡·ÖÎö£º


×°Öò¹¶¡KB4462211ºóÔٴη´±àÒ룬£¬£¬ £¬ £¬£¬£¬£¬¶Ô±ÈDecodeEntityInstanceId()²½ÖèµÄÔ´Â룬£¬£¬ £¬ £¬£¬£¬£¬·¢ÏÖÒѾ­²»ÔÙÖ§³Ö¶ÔÏóÀàÐ͵ķ´ÐòÁл¯ ¡£ ¡£¡£ ¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


·ì϶ÀûÓÃ


ÔÚ·ì϶·ÖÎöʱ£¬£¬£¬ £¬ £¬£¬£¬£¬ÎÒÃÇÔÚEntityInstanceIdEncoderÀàÖп´µ½ÁíÒ»¸ö²½ÖèEncodeEntityInstanceId(),Äܹ»Ö±½ÓʹÓÃËüÌìÉúPayload ¡£ ¡£¡£ ¡£¡£
»ú¹ØXML£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÌìÉúPayload£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÌìÉúPayloadʱ»áµ¯³öÒ»´ÎÍÆËãÆ÷£¬£¬£¬ £¬ £¬£¬£¬£¬¹Øµô¼´¿É ¡£ ¡£¡£ ¡£¡£
PoC£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


½¨¸´½¨Òé


Ŀǰ¹Ù·½ÒÑÍÆ³öÏàÓ¦²¹¶¡£¬£¬£¬ £¬ £¬£¬£¬£¬Ç뾡¿ìÉý¼¶½øÐн¨¸´ ¡£ ¡£¡£ ¡£¡£
Microsoft SharePoint Enterprise Server 2016
Security Update for Microsoft SharePoint Enterprise Server 2016(KB4462211)
https://www.microsoft.com/en-us/download/details.aspx?id=58072
Microsoft SharePoint Foundation 2013 Service Pack 1
Security Update for Microsoft SharePoint Enterprise Server 2013(KB4462202)
https://www.microsoft.com/en-us/download/details.aspx?id=58063
Microsoft SharePoint Server 2010 Service Pack 2
Security Update for 2010 Microsoft Business Productivity Servers(KB4462184)
https://www.microsoft.com/en-us/download/details.aspx?id=58066
Microsoft SharePoint Server 2019
Security Update for Microsoft SharePoint Server 2019 Core(KB4462199)
https://www.microsoft.com/en-us/download/details.aspx?id=58061


²Î¿¼Á´½Ó


https://www.thezdi.com/blog/2019/3/13/cve-2019-0604-details-of-a-microsoft-sharepoint-rce-vulnerability
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0604