Microsoft Windows DNS·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²îSigRed£¨CVE-2020-1350£© ·À»¤¼Æ»®
2020-07-16
Ò». ×ÛÊö
ÍâµØÊ±¼ä7ÔÂ14ÈÕ£¬Î¢Èí×îеÄÔ¶Ȳ¹¶¡¸üÐÂÖÐÐÞ¸´ÁËһö±£´æÓÚWindows DNS ·þÎñÆ÷ÖеĿÉÈ䳿»¯Îó²îCVE-2020-1350£¨´úºÅ SigRed£©¡£ÕâÒâζ׏¥»÷ÕßʹÓøÃÎó²îÄܹ»ÔÚûÓÐÈκÎÓû§½»»¥µÄÇéÐÎÏ£¬ÔÚÒ×Êܹ¥»÷µÄ»úе¼äÈö²¥£¬´Ó¶øÓпÉÄÜѬȾÕû¸ö×éÖ¯µÄÍøÂç¡£
¾Ý±¨µÀ£¬¸ÃÎó²îÒѾ±£´æ17 ÄêÖ®¾Ã£¬Î¢Èí¹Ù·½¸ø³öµÄÆÀ·ÖΪ 10 ·Ö£¨CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C£©¡£
δ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÏòWindows DNS·þÎñÆ÷·¢ËͶñÒâÇëÇóÀ´Ê¹ÓøÃÎó²î¡£Check PointµÄÑо¿Ö°Ô±·¢Ã÷£¬Í¨¹ý·¢ËͰüÀ¨SIG¼Í¼£¨´óÓÚ64KB£©µÄDNSÏìÓ¦¿ÉÒÔÔì³É»ùÓڶѵĻº³åÇøÒç³ö£¬½ø¶øÊ¹¹¥»÷ÕßÄܹ»¿ØÖÆ·þÎñÆ÷¡£
ÏÖÔÚÎó²îϸ½ÚÒѹûÕæ£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
²Î¿¼Á´½Ó£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1350
¶þ. Îó²îÓ°Ïì¹æÄ£
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2012
Windows Server 2012 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 R2 (Server Core installation)
Windows Server 2016
Windows Server 2016 (Server Core installation)
Windows Server 2019
Windows Server 2019 (Server Core installation)
Windows Server, version 1909 (Server Core installation)
Windows Server, version 1903 (Server Core installation)
Windows Server, version 2004 (Server Core installation)
Èý. ÊÖÒÕ·À»¤¼Æ»®
3.1 ¹Ù·½ÐÞ¸´¼Æ»®
΢Èí¹Ù·½ÒÑÕë¶ÔÊÜÓ°ÏìϵͳÐû²¼ÁËÇå¾²²¹¶¡£¬Ç¿ÁÒ½¨ÒéÏà¹ØÓû§¾¡¿ì×°ÖøüС£
²¹¶¡¸üÐ²ο¼¹Ù·½Í¨¸æ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1350
3.2 »º½â²½·¥
ÈôÊÇÎÞ·¨Á¬Ã¦×°ÖøüУ¬¹Ù·½ÌṩÁËÈçÏ»º½â²½·¥£º
½¨Òé¾ÙÐÐÒÔÏÂ×¢²á±í¸ü¸Ä£¬ÒÔÏÞÖÆÔÊÐíµÄ×î´óÈëÕ¾ TCP DNS ÏìÓ¦Êý¾Ý°üµÄ´óС£º
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters" /v "TcpReceivePacketSize" /t REG_DWORD /d 0xFF00 /f
net stop DNS && net start DNS
ÔÚ×°Öò¹¶¡³ÌÐòºó£¬½¨ÒéÔÚ×¢²á±íÖÐÒÆ³ý TcpReceivePacketSize ¼°ÆäÊý¾Ý£¬ÒÔʹע²á±íÏî HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters ϵÄËùÓÐÆäËûÄÚÈÝÓë֮ǰ¼á³ÖÒ»Ö¡£
https://support.microsoft.com/zh-cn/help/4569509/windows-dns-server-remote-code-execution-vulnerability
3.3 AG¹«Ë¾¿Æ¼¼¼ì²â·À»¤½¨Òé
3.3.1 AG¹«Ë¾¿Æ¼¼¼ì²âÀà²úÆ·Óë·þÎñ
ÄÚÍø×ʲú¿ÉÒÔʹÓÃAG¹«Ë¾¿Æ¼¼µÄÔ¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS V6£©¡¢ÈëÇÖ¼ì²âϵͳ(IDS)¡¢Í³Ò»Íþв̽Õ루UTS£©¾ÙÐмì²â¡£
Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS V6£©http://update.nsfocus.com/update/listRsas
ÈëÇÖ¼ì²âϵͳ£¨IDS£©
http://update.nsfocus.com/update/listIds
ͳһÍþв̽Õ루UTS£©
http://update.nsfocus.com/update/bsaUtsIndex
3.3.1.1 ¼ì²â²úÆ·Éý¼¶°ü/¹æÔò°æ±¾ºÅ
|
¼ì²â²úÆ· |
Éý¼¶°ü/¹æÔò°æ±¾ºÅ |
|
RSAS V6 ϵͳ²å¼þ |
6.0R02F01.1903 |
|
IDS |
5.6.10.23040 5.6.9.23040 |
|
UTS |
5.6.10.23040 |
RSAS V6 ϵͳ²å¼þ°üÏÂÔØÁ´½Ó£º
http://update.nsfocus.com/update/downloads/id/106565
IDS Éý¼¶°üÏÂÔØÁ´½Ó£º
5.6.10.23040
http://update.nsfocus.com/update/downloads/id/106570
5.6.9.23040
http://update.nsfocus.com/update/downloads/id/106569
UTSÉý¼¶°üÏÂÔØÁ´½Ó£º
http://update.nsfocus.com/update/downloads/id/106574
3.3.2 AG¹«Ë¾¿Æ¼¼·À»¤Àà²úÆ·
ʹÓÃAG¹«Ë¾¿Æ¼¼·À»¤Àà²úÆ·£¬ÈëÇÖ·À»¤ÏµÍ³£¨IPS£©¡¢ÏÂÒ»´ú·À»ðǽϵͳ£¨NF£©À´¾ÙÐзÀ»¤¡£
ÈëÇÖ·À»¤ÏµÍ³£¨IPS£©
http://update.nsfocus.com/update/listIps
ÏÂÒ»´ú·À»ðǽϵͳ£¨NF£©
http://update.nsfocus.com/update/listNf
3.3.2.1 ·À»¤²úÆ·Éý¼¶°ü/¹æÔò°æ±¾ºÅ
|
·À»¤²úÆ· |
Éý¼¶°ü/¹æÔò°æ±¾ºÅ |
¹æÔò±àºÅ |
|
IPS |
5.6.10.23040 5.6.9.23040 |
24962 |
|
NF |
6.0.2.819 6.0.1.819 |
24967 |
IPS Éý¼¶°üÏÂÔØÁ´½Ó£º
5.6.10.23040
http://update.nsfocus.com/update/downloads/id/106570
5.6.9.23040
http://update.nsfocus.com/update/downloads/id/106569
NF Éý¼¶°üÏÂÔØÁ´½Ó£º
6.0.2.819
http://update.nsfocus.com/update/downloads/id/106592
6.0.1.819
http://update.nsfocus.com/update/downloads/id/106591
¸½Â¼A ²úƷʹÓÃÖ¸ÄÏ
RSASɨÃèÉèÖÃ
ÔÚϵͳÉý¼¶ÖУ¬µã»÷ÏÂͼºì¿òλÖÃÑ¡ÔñÎļþ¡£

Ñ¡ÔñÏÂÔØºÃµÄÏìÓ¦Éý¼¶°ü£¬µã»÷Éý¼¶°´Å¥¾ÙÐÐÊÖ¶¯Éý¼¶¡£ÆÚ´ýÉý¼¶Íê³Éºó£¬¿Éͨ¹ý¶¨ÖÆÉ¨ÃèÄ£°å£¬Õë¶Ô´Ë´ÎÎó²î¾ÙÐÐɨÃè¡£
UTS¼ì²âÉèÖÃ
ÔÚϵͳÉý¼¶Öеã»÷ÀëÏßÉý¼¶£¬Ñ¡Ôñ¹æÔòÉý¼¶Îļþ£¬Ñ¡Ôñ¶ÔÓ¦µÄÉý¼¶°üÎļþ£¬µã»÷ÉÏ´«£¬ÆÚ´ýÉý¼¶Àֳɼ´¿É¡£

IPS·À»¤ÉèÖÃ
ÔÚϵͳÉý¼¶Öеã»÷ÀëÏßÉý¼¶£¬Ñ¡Ôñϵͳ¹æÔò¿â£¬Ñ¡Ôñ¶ÔÓ¦µÄÎļþ£¬µã»÷ÉÏ´«¡£

¸üÐÂÀֳɺó£¬ÔÚϵͳĬÈϹæÔò¿âÖвéÕÒ¹æÔò±àºÅ£¬¼´¿ÉÅÌÎʵ½¶ÔÓ¦µÄ¹æÔòÏêÇé¡£

×¢ÖØ£º¸ÃÉý¼¶°üÉý¼¶ºóÒýÇæ×Ô¶¯ÖØÆôÉúЧ£¬²»»áÔì³É»á»°ÖÐÖ¹£¬µ«ping°ü»á¶ª3~5¸ö£¬ÇëÑ¡ÔñºÏÊʵÄʱ¼äÉý¼¶¡£
NF·À»¤ÉèÖÃ
ÔÚ NF µÄ¹æÔòÉý¼¶½çÃæ¾ÙÐÐÉý¼¶£º

ÊÖ¶¯Ñ¡Ôñ¹æÔò°ü£¬Ìá½»¼´¿ÉÍê³É¸üС£
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







