¡¾Íþвͨ¸æ¡¿Windows CryptoAPI¸ßΣÎó²î£¨CVE-2020-0601£©
2020-01-15
×ÛÊö
ÍâµØÊ±¼ä1ÔÂ14ÈÕ£¬Î¢Èí×îеÄÔ¶Ȳ¹¶¡¸üÐÂÖУ¬ÓÐÒ»Ôò¸üÐÂÐÞ¸´ÁËÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©·¢Ã÷²¢±¨¸æ¸øÎ¢ÈíµÄ Windows CryptoAPI ÓÕÆÎó²î£¨CVE-2020-0601£©£¬¸ÃÎó²îÓ°Ïì Windows 10£¬Windows Server 2016 ºÍ Windows Server 2019¡£
ƾ֤MicrosoftÐû²¼µÄͨ¸æ£¬Õâ¸öÓÖ±»³ÆÎª“ NSACrypt ”µÄÇå¾²Îó²îפÁôÔÚ Crypt32.dll Ä£¿éÖУ¬ÊÇ Windows CryptoAPI ÑéÖ¤ÍÖÔ²ÇúÏßÃÜÂë(ECC)Ö¤ÊéµÄÀú³ÌÖб£´æµÄÓÕÆÎó²î¡£
¹¥»÷Õß¿ÉÄÜ»áͨ¹ýʹÓþßÓÐÓÕÆÐԵĴúÂëÊðÃûÖ¤Êé¶Ô¶ñÒâ¿ÉÖ´ÐÐÎļþ¾ÙÐÐÊðÃûÀ´Ê¹ÓôËÎó²î£¬Ê¹¶ñÒâÈí¼þ¿´ÆðÀ´ÏñÊÇÓÉÕýµ±Èí¼þ¹«Ë¾Éú²ú²¢ÊðÃûµÄÕý³£³ÌÐò¡£
ÁíÍ⣬¸ÃÎó²î»¹¿ÉÄܱ»ÓÃÓÚʵÑéÖÐÐÄÈ˹¥»÷£¬¹¥»÷Õß½«½âÃÜÓû§ºÍÊÜÓ°ÏìÈí¼þÅþÁ¬ÖеÄÉñÃØÐÅÏ¢¡£
´Ë´Î¸üÐÂͨ¹ýÈ·±£ Windows CryptoAPIÍêÈ«ÑéÖ¤ÁËECC Ö¤ÊéÀ´½â¾ö¸ÃÎÊÌâ¡£
ÊÜÓ°ÏìÇÒÔÚÖ§³Ö¹æÄ£ÄÚ²úÆ·
- Windows 10
- Windows Server 2016
- Windows Server 2019
¸üÏêϸ°æ±¾ÐÅÏ¢²Î¿¼¹Ù·½Í¨¸æ¡£
½â¾ö¼Æ»®
¹Ù·½ÒÑÕë¶ÔÊÜÖ§³Öϵͳ°æ±¾Ðû²¼ÐÞ¸´Á˸ÃÎó²îµÄÇå¾²²¹¶¡£¬Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì×°Öò¹¶¡¸üС£
¹Ù·½Í¨¸æÁ´½Ó£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601¡£
±¸×¢£ºÎ¢ÈíÐû²¼´Ó1ÔÂ14ÈÕÆð×èÖ¹¶ÔWindows7µÄά»¤£¬½¨ÒéÓû§Éý¼¶µ½×îа汾ϵͳ£¬¹Ø×¢Î¢Èí¹Ù·½Ç徲ͨ¸æ¡£

Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³Æ¾ÅÓÎÀÏ¸ç¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

¾ÅÓÎÀϸçÔÆ





