¡¾Ç徲ͨ¸æ¡¿Windows TCP/IPÔ¶³Ì´úÂëÖ´ÐÐÎó²î (CVE-2020-16898)
2020-10-14
×ÛÊö
ÍâµØÊ±¼ä10ÔÂ13ÈÕ£¬Î¢Èí×îеÄÔ¶Ȳ¹¶¡¸üÐÂÖÐÐÞ¸´ÁËһö±£´æÓÚWindows TCP/IP¿ÍÕ»ÖеÄCritical¼¶±ðÎó²î£¨CVE-2020-16898£¬´úºÅ“Bad Neighbor”£©¡£¹¥»÷Õßͨ¹ý·¢ËͶñÒâÖÆ×÷µÄICMPv6 Router AdvertisementÊý¾Ý°ü£¬ÓпÉÄÜÔÚÔ¶³ÌϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£
McAfee ÌåÏÖ£¬MAPP£¨Microsoft Active Protection£©ÍýÏë³ÉÔ±¹²ÏíµÄ¿´·¨ÑéÖ¤´úÂë¼È¼òÆÓÓÖ¿É¿¿£¬¿Éµ¼ÖÂÀ¶ÆÁËÀ»ú¡£
΢Èí¹Ù·½¸ø³öµÄÆÀ·ÖΪ 9.8 £ºCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16898
Îó²î¸ÅÊö
µ±Windows TCP/IP¿Íջδ׼ȷ´¦Öóͷ£Ê¹ÓÃOptionÀàÐÍΪ 25£¨µÝ¹éDNS·þÎñÆ÷£©ÇÒLength×Ö¶ÎֵΪżÊýµÄ?ICMPv6 Router AdvertisementÊý¾Ý°üʱ£¬±£´æÎó²î¡£
µ±LengthֵΪżÊýʱ£¬Windows TCP/IPÐÒéÕ»¹ýʧµØ½«ÍøÂ绺³åÇøÌáǰÁË8¸ö×Ö½Ú¡£ÕâÊÇÓÉÓÚ¿ÍÕ»ÄÚ²¿ÒÔ16×Ö½ÚΪÔöÁ¿¾ÙÐмÆÊý£¬Ã»ÓÐ˼Á¿µ½Ê¹Ó÷ÇRFC¼æÈݳ¤¶ÈÖµµÄÇéÐΡ£ÕâÖÖ²»Æ¥Åäµ¼Ö¿ÍÕ»½«Ä¿½ñoptionµÄ×îºó8¸ö×Ö½ÚÚ¹ÊÍΪµÚ¶þ¸öoptionµÄ×îÏÈ£¬×îÖÕµ¼Ö»º³åÇøÒç³öºÍDZÔÚµÄRCE¡£
²Î¿¼Á´½Ó£º
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/cve-2020-16898-bad-neighbor/
ÊÜÓ°Ïì²úÆ·°æ±¾
Windows 10 Version 1709 for 32-bit Systems
Windows 10 Version 1709 for ARM64-based Systems
Windows 10 Version 1709 for x64-based Systems
Windows 10 Version 1803 for 32-bit Systems
Windows 10 Version 1803 for ARM64-based Systems
Windows 10 Version 1803 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems
Windows 10 Version 1809 for ARM64-based Systems
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 1903 for 32-bit Systems
Windows 10 Version 1903 for ARM64-based Systems
Windows 10 Version 1903 for x64-based Systems
Windows 10 Version 1909 for 32-bit Systems
Windows 10 Version 1909 for ARM64-based Systems
Windows 10 Version 1909 for x64-based Systems
Windows 10 Version 2004 for 32-bit Systems
Windows 10 Version 2004 for ARM64-based Systems
Windows 10 Version 2004 for x64-based Systems
Windows Server 2019
Windows Server 2019 (Server Core installation)
Windows Server, version 1903 (Server Core installation)
Windows Server, version 1909 (Server Core installation)
Windows Server, version 2004 (Server Core installation)
½â¾ö¼Æ»®
΢Èí¹Ù·½ÒÑÕë¶ÔÊÜÓ°ÏìϵͳÐû²¼Çå¾²²¹¶¡£¬Ç¿ÁÒ½¨ÒéÏà¹ØÓû§¾¡¿ì¸üС£²¹¶¡Éý¼¶£¬²Î¿¼Á´½Ó:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16898
ÁíÍ⣬»¹ÌṩÁËÒÔÏ»º½â²½·¥£º
½ûÓÃICMPv6 RDNSS
ʹÓÃÏÂÃæµÄPowerShellÏÂÁî¿É½ûÓÃICMPv6 RDNSS£¬ÒÔ±ÜÃâ¹¥»÷ÕßʹÓôËÎó²î¡£´Ë½â¾öÒªÁì½öÊÊÓÃÓÚWindows 1709¼°¸ü¸ß°æ±¾¡£
|
netsh int ipv6 set int *INTERFACENUMBER* rabaseddnsconfig=disable |
±¸×¢£º ¾ÙÐиü¸Äºó£¬ÎÞÐèÖØÐÂÆô¶¯¡£
ÈçÐè½ûÓÃÒÔÉÏ»º½â²½·¥£¬Ö´ÐÐÈçÏÂÏÂÁ
|
netsh int ipv6 set int *INTERFACENUMBER* rabaseddnsconfig=enable |
±¸×¢£ºÖ´ÐкóÒ²ÎÞÐèÖØÐÂÆô¶¯¡£
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
AG¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
AG¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







