¡¾·ì϶¹«¸æ¡¿Kaseya VSA 7Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-07-120x00 ·ì϶¸ÅÊö
Kaseya VSAÊÇÍйܷþÎñÌṩÉÌ (MSP) ³£ÓÃÀ´ÖÎÀí¿Í»§ÍøÂçµÄ RMM£¨Ô¶³Ì¼à¿ØºÍÖÎÀí£©Èí¼þ¡£¡£¡£¡£¡£¡£¡£¡£
2021Äê7ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬Kaseya°ä²¼VSA 9.5.7a (9.5.7.2994)µÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËCVE-2021-30116¡¢CVE-2021-30119 ºÍ CVE-2021-30120·ì϶£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°»á»° cookie δʹÓð²È«±êÖ¾¡¢±©Á¦ÆÆ½âºÍÎļþÉÏ´«µÈÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé

½ñÄê4Ô£¬£¬£¬£¬£¬£¬£¬ºÉÀ¼·ì϶Åû¶×êÑÐËù (DIVD) Ïò Kaseya Åû¶ÁËÆß¸ö·ì϶£º
CVE-2021-30116£ºÐÅϢй¶·ì϶£¬£¬£¬£¬£¬£¬£¬Ó°Ïì9.5.7 ֮ǰµÄ°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2021-30117£ºSQL ×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬ÒÑÔÚ 5 Ô 8 ÈյIJ¹¶¡Öн¨¸´¡£¡£¡£¡£¡£¡£¡£¡££¨VSA 9.5.6£©
CVE-2021-30118£ºÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬£¬ÒÑÔÚ 4 Ô 10 ÈյIJ¹¶¡Öн¨¸´¡£¡£¡£¡£¡£¡£¡£¡£(v9.5.5)
CVE-2021-30119£ºXSS·ì϶£¬£¬£¬£¬£¬£¬£¬Ó°Ïì9.5.7 ֮ǰµÄ°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2021-30120 £º2FA ÈÆ¹ý·ì϶£¬£¬£¬£¬£¬£¬£¬Ó°Ïì9.5.7 ֮ǰµÄ°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2021-30121£º±¾µØÎļþÔ̺¬·ì϶£¬£¬£¬£¬£¬£¬£¬ÒÑÔÚ 5 Ô 8 ÈյIJ¹¶¡Öн¨¸´¡£¡£¡£¡£¡£¡£¡£¡££¨VSA 9.5.6£©
CVE-2021-30201£ºXML ±í²¿ÊµÌå·ì϶£¬£¬£¬£¬£¬£¬£¬ÒÑÔÚ 5 Ô 8 ÈյIJ¹¶¡Öн¨¸´¡£¡£¡£¡£¡£¡£¡£¡££¨VSA 9.5.6£©
ÊÂÎñÏêÇé
2021Äê7ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬£¬REvil ÍÅ»ïÀûÓà Kaseya VSA Èí¼þÖеݲȫ·ì϶Õë¶ÔÈ«Çò¶à¸öMSP¼°Æä¿Í»§ÌáÒ鹩¸øÁ´¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¾Ý°µÊ¾£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄܵ¥¶ÀÀûÓûò×éºÏÀûÓÃÁËCVE-2021-30116¡¢CVE-2021-30119 ºÍ CVE-2021-30120£¬£¬£¬£¬£¬£¬£¬ÒÔÈÆ¹ýÈÏÖ¤²¢ÔËÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£
×÷ΪÏìÓ¦£¬£¬£¬£¬£¬£¬£¬Kaseya½¨ÒéÁ¢¼´¹Ø¹ØVSA ·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬¿É´ÓInternet ½Ó¼ûµÄ Kaseya VSA Ê·ýÊýÁ¿ÒÑ´Ó2200 ¶à¸ö½µÂäµ½²»µ½ 140 ¸ö¡£¡£¡£¡£¡£¡£¡£¡£

¹ýºó£¬£¬£¬£¬£¬£¬£¬Kaseya°µÊ¾£¬£¬£¬£¬£¬£¬£¬REvil¹©¸øÁ´ÀÕË÷Èí¼þ¹¥»÷ÈëÇÖÁËÔ¼60¸öʹÓøù«Ë¾VSAÄÚ²¿²úÆ·µÄ¿Í»§µÄϵͳ£¬£¬£¬£¬£¬£¬£¬Êܺ¦Õß½ü1500Ãû£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËûÃǵÄÍøÂçÊÇÓÉMSPʹÓÃKaseyaÔ¶³ÌÖÎÀí¹¤¾ßÖÎÀíµÄ¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬RevilµÄ¹¥»÷ÕßÊÇͨ¹ýVSA ²úÆ·Ö°Äܲ¿ÊðÀÕË÷Èí¼þµÄ£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°Ã»ÓÐÖ¤¾ÝÅú×¢ Kaseya µÄ VSA ´úÂë¿âÒѱ»´Û¸Ä¡£¡£¡£¡£¡£¡£¡£¡£
REvilÐû³ÆÒѾ¼ÓÃÜÁ˳¬¹ý 1,000,000 ¸öϵͳ£¬£¬£¬£¬£¬£¬£¬×î³õÆäÒªÇó 7000 ÍòÃÀÔªµÄÊê½ð£¬£¬£¬£¬£¬£¬£¬´Ë¿ÌÒªÇó 5000 ÍòÃÀÔª²É°ìͨÓýâÃÜÆ÷¡£¡£¡£¡£¡£¡£¡£¡£
Ó°ÏìÁìÓò
Kaseya VSA < 9.5.7a
0x02 ´ëÖý¨Òé
ĿǰÕâЩ·ì϶ÒѾ½¨¸´£¬£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁVSA 9.5.7a (9.5.7.2994) °æ±¾¡£¡£¡£¡£¡£¡£¡£¡£
ÆäËü´ëÊ©
1.Kaseya ¶½´Ù¿Í»§ÔÚ×°ÖøüÐÂ֮ǰ×ñÑ¡°±¾µØ VSA Æô¶¯³ï±¸Ö¸ÄÏ¡±²½Ö裬£¬£¬£¬£¬£¬£¬ÒÔÔ¤·À¹¥»÷ÐÐΪ¡£¡£¡£¡£¡£¡£¡£¡£ÒÔÏÂÊÇÖÎÀíÔ±ÔÚÔÙ´ÎÆô¶¯ VSA ·þÎñÆ÷²¢½«ËüÃÇÏνӵ½ Internet ֮ǰӦ¸ÃÖ´Ðеĸù»ù²½Ö裺£¨³Áµã£º²»ÄÜ´Ó Internet ¹«¿ª½Ó¼û±¾µØ VSA ·þÎñÆ÷£©
l È·±£ÄúµÄ VSA ·þÎñÆ÷ÊǸôÀëµÄ £»£»£»£»£»
l ²é³ÏµÍ³µÄÍ×ÐÖ¸±ê (IOC) £»£»£»£»£»
l ×°ÖÃVSA·þÎñÆ÷²Ù×÷ϵͳ²¹¶¡ £»£»£»£»£»
l ʹÓà URL Rewrite ½ÚÔìͨ¹ý IIS ¶Ô VSA µÄ½Ó¼û £»£»£»£»£»
l ×°Öà FireEye ´úÀí £»£»£»£»£»
l ɾ³ý¹ÒÆðµÄ¾ç±¾/×÷Òµ¡£¡£¡£¡£¡£¡£¡£¡£
2.´Ë±í£¬£¬£¬£¬£¬£¬£¬Kaseya »¹¶½´Ù¿Í»§Ê¹ÓÃËûÃǵÄPowerShell ¾ç±¾µÄ¡°ÈëÇÖ¼ì²â¹¤¾ß¡±À´¼ì²â VSA ·þÎñÆ÷»ò¶ËµãÊÇ·ñÒѱ»ÈëÇÖ£º¾ç±¾½«²é³ VSA ·þÎñÆ÷ÊÇ·ñ´æÔÚ¡°Kaseya\webpages\managedfiles\vsaticketfiles\agent.crt¡±ºÍ¡°Kaseya\webpages\managedfiles\vsaticketfiles\agent.exe¡±ÒÔ¼°¡°agent.crt¡±ºÍ¡°agent.exe¡±Ôڶ˵ãÉÏ¡£¡£¡£¡£¡£¡£¡£¡££¨×¢£ºREvil ÍÅ»ïʹÓà agent.crt ºÍ agent.exe ÎļþÀ´²¿Êð REvil ÀÕË÷Èí¼þ¿ÉÖ´ÐÐÎļþ£©¡£¡£¡£¡£¡£¡£¡£¡£
3. ΪÁËÌá¸ß°²È«ÐÔ£¬£¬£¬£¬£¬£¬£¬Kaseya »¹½¨ÒéÄÚ²¿²¿ÊðµÄ VSA ÖÎÀíÔ±½«¶Ô Web GUI µÄ½Ó¼ûȨÏÞÏÞ¶ÈΪ±¾µØ IP µØÖ·ºÍÒÑÖª°²È«²úƷʹÓÃµÄ IP µØÖ·¡£¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://helpdesk.kaseya.com/hc/en-gb/articles/4403785889041
https://kaseya.app.box.com/s/0ysvgss7w48nxh8k1xt7fqhbcjxhas40
0x03 ²Î¿¼Á´½Ó
https://helpdesk.kaseya.com/hc/en-gb/articles/4403785889041
https://mp.weixin.qq.com/s/aoSf0HFH7lOz6bGXGKboNg
https://www.bleepingcomputer.com/news/security/kaseya-patches-vsa-vulnerabilities-used-in-revil-ransomware-attack/
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2021-07-12 | ³õ´Î°ä²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
NVD£ºnvd.nist.gov
CVSS£ºwww.first.org
0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ