Microsoft IE CMarkup¹¤¾ßÊͷźóÖØÓÃ0dayÎó²î (Alert2014-02)
2014-02-17
ÐÎò£º
CVE ID£ºCVE-2014-0322ÊÜÓ°ÏìµÄÈí¼þ¼°ÏµÍ³£º
====================
Microsoft Internet Explorer 10
======
Microsoft IEÊÇ΢Èí¹«Ë¾ÍÆ³öµÄÒ»¿îÍøÒ³ä¯ÀÀÆ÷¡£
IE±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐ0dayÎó²î£¬Î¢ÈíÒѾ·¢Ã÷Óй¥»÷ÕßÔÚʹÓôËÎó²î¹¥»÷IE 10¡£ÊӲ췢Ã÷´ËÎó²îÖ»Ó°ÏìIE 10Ò»¸ö°æ±¾¡£ÏÖÔÚ΢Èí»¹Ã»ÓÐÌṩÕýʽ²¹¶¡¡£
Ç¿ÁÒ½¨ÒéIEÓû§²ÎÕÕ½â¾öÒªÁ첿·ÖµÄ²½·¥¾ÙÐÐÐëÒªµÄ·À»¤£¬²¢ÔÚ΢ÈíÕýʽ²¹¶¡Ðû²¼ºóʵʱÉý¼¶¡£
======
IEµÄMSHTML.DLL×é¼þ±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£Ê¹ÓôËÎó²î»á¼ûÒѾ±»É¾³ýµÄCMarkup¹¤¾ß£¬µ¼ÖÂÊͷźóÖØÓÃÎó²î£¬²¢Í¨¹ýºÍflashÍŽáÈÆ¹ýÏÖÓеÄÎó²îʹÓ÷À»¤ÊÖÒÕ£¬´Ó¶øÒÔIEÄ¿½ñÓû§Éí·ÝÖ´ÐÐí§ÒâÖ¸Áî¡£
Ô¶³Ì¹¥»÷Õß¿ÉÄÜʹÓôËÎó²îͨ¹ýÓÕʹÓû§»á¼û¶ñÒâÍøÒ³Ö´ÐйÒÂí¹¥»÷£¬¿ØÖÆÓû§ÏµÍ³¡£
½â¾öÒªÁ죺
ÔÚ³§É̲¹¶¡Ðû²¼Ö®Ç°£¬ÎÒÃǽ¨ÒéÓû§ÔÝʱ¸ÄÓ÷ÇIEÄÚºËä¯ÀÀÆ÷£¬ÈçFirefox,Chrome¡£¹ØÓÚIEä¯ÀÀÆ÷¿ÉÒÔ½ÓÄÉÈçÏ·À»¤²½·¥:
* ½ÓÄɳ§ÉÌÌṩµÄEnhanced Mitigation Experience Toolkit (EMET)¹¤¾ß¡£´ËÒªÁìÄÜÓÐÓÃÌá·À£¬ÇÒ²»Ó°ÏìÕý³£ÍøÕ¾µÄ»á¼û¡£
ÔöÇ¿»º½âÌåÑ鹤¾ß°ü£¨EMET£©ÊÇÒ»¸öÊÊÓù¤¾ß£¬ÓÃÓÚ±ÜÃâÈí¼þÖеÄÎó²î±»ÀÖ³ÉʹÓá£
´ÓÈçÏÂÍøÖ·ÏÂÔØÔöÇ¿»º½âÌåÑ鹤¾ß°ü£º
EMET 3.0:
http://www.microsoft.com/en-us/download/details.aspx?id=29851
EMET 4.0:
http://www.microsoft.com/en-us/download/details.aspx?id=39273
×°ÖÃÒÔºóÔËÐУ¬ÔÚ½çÃæÖеã»÷¡°Configure Apps¡±£¬ÔÚ¶Ô»°¿òÖеã»÷¡°Add¡±£¬ä¯ÀÀµ½IEËùÔÚµÄ×°ÖÃĿ¼£¨Í¨³£ÊÇc:program filesInternet Explorer£©Ñ¡Ôñiexplore.exe£¬µã»÷¡°·¿ª¡±£¬IE¾Í±»¼ÓÈëµ½Êܱ£»¤ÏîÄ¿ÁбíÖУ¬µã»÷¡°OK¡±£¬ÈôÊÇÓÐIEÕýÔÚÔËÐеϰÐèÒªÖØÆôÒ»ÏÂÓ¦Óá£
Ò²¿É½ÓÄÉÀàËÆµÄ²Ù×÷°ÑÆäËûµÄÓ¦ÓóÌÐò¼ÓÈë±£»¤¡£
* ÔÚ "IE Ñ¡Ïî"ÖÐÉèÖÃ"Internet"ºÍ"ÍâµØ Intranet"µÄÇøÓòÇå¾²ÐÔÉèÖÃΪ ¡°¸ß¡±ÒÔ×èÖ¹ActiveX¿Ø¼þºÍÔ˶¯¾ç±¾ÔÚÕâÁ½¸öÇøÓòÖÐÖ´ÐС£
ÕâÒªÁìËäÈ»ÄÜÓÐÓÃÌá·À£¬¿ÉÊÇ»áÓ°Ïìµ½Õý³£ÍøÕ¾¡£ÎªÁ˾¡¿ÉÄܵؽµµÍÓ°Ï죬Ӧ°ÑÐÅÍеÄÍøÕ¾Ìí¼Óµ½"ÊÜÐÅÍеÄÕ¾µã"¡£
* ÉèÖÃIEÔÚÔËÐÐÔ˶¯¾ç±¾Ìõ¼þʾ£¬»òÕßÔÚ"Internet"ºÍ"ÍâµØIntranet"ÓòÖнûÓÃÔ˶¯¾ç±¾¡£
ÕâÒªÁìËäÈ»ÄÜÓÐÓÃÌá·À£¬¿ÉÊÇ»áÓ°Ïìµ½Õý³£ÍøÕ¾¡£ÎªÁ˾¡¿ÉÄܵؽµµÍÓ°Ï죬Ӧ°ÑÐÅÍеÄÍøÕ¾Ìí¼Óµ½"ÊÜÐÅÍеÄÕ¾µã"¡£
==========
ÏÖÔÚ³§ÉÌ»¹Ã»ÓÐÌṩ²¹¶¡»òÕßÉý¼¶³ÌÐò£¬ÎÒÃǽ¨ÒéÓû§¿ªÆô×Ô¶¯¸üзþÎñÒÔʵʱװÖÃ×îв¹¶¡¡£
==========
1. http://www.fireeye.com/blog/technical/cyber-exploits/2014/02/new-ie-zero-day-found-in-watering-hole-attack-2.html
2. http://community.websense.com/blogs/securitylabs/archive/2014/02/13/msie-0-day-exploit-cve-2014-0322-possibly-targeting-french-aerospace-organization.aspx

¾ÅÓÎÀϸçÔÆ







