¡¸Îó²îͨ¸æ¡¹Î¢ÈíSMBv3Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2020-0796)
2020-03-11
×ÛÊö
±±¾©Ê±¼ä3ÔÂ11ÈÕ£¬Î¢ÈíÐû²¼ÁË3ÔÂÇå¾²²¹¶¡¸üУ¬ÆäÖаüÀ¨Ò»ÌõÇ徲ͨ¸æ³ÆÆäÒѾÏàʶµ½ÔÚMicrosoft Server Message Block 3.1.1(SMBv3)Öб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄSMB·þÎñÆ÷»òSMB¿Í»§¶ËÉÏÖ´ÐдúÂë¡£ÏÖÔÚ΢Èí¹Ù·½Ã»ÓÐÌṩÇå¾²²¹¶¡£¬¿ÉÊÇÌṩÁË»º½â²½·¥¡£
²Î¿¼Á´½Ó£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/adv200005
Îó²î¸ÅÊö
¸ÃÎó²îÔ´ÓÚSMBv3ÐÒ鹨ÓÚÌØ¶¨ÇëÇóµÄ´¦Öóͷ£·½·¨±£´æ¹ýʧ£¬¹¥»÷Õß¿ÉÒÔÔÚδ¾Éí·ÝÑéÖ¤µÄÇéÐÎÏÂʹÓøÃÎó²î¡£
ÈôÒªÕë¶ÔSMBv3·þÎñÆ÷£¬¹¥»÷Õß¿ÉÒÔ½«ÌØÖƵÄÊý¾Ý°ü·¢Ë͵½SMB·þÎñÆ÷À´´¥·¢¡£ÈôÒªÕë¶ÔSMBv3¿Í»§¶Ë£¬¹¥»÷ÕßÐèÒªÉèÖúÃÒ»¸ö¶ñÒâµÄSMB·þÎñÆ÷£¬²¢ÓÕʹÓû§ÅþÁ¬¸Ã·þÎñÆ÷¡£
Áí¾Ý¶à·½Ñо¿Ö°Ô±³Æ£¬¸ÃÎó²î£¨CVE-2020-0796£©¾ßÓÐÈä³æÌØÕ÷¡£
ÊÜÓ°Ïì°æ±¾
- Windows 10 Version 1903 for 32-bit Systems
- Windows 10 Version 1903 for ARM64-based Systems
- Windows 10 Version 1903 for x64-based Systems
- Windows 10 Version 1909 for 32-bit Systems
- Windows 10 Version 1909 for ARM64-based Systems
- Windows 10 Version 1909 for x64-based Systems
- Windows Server, version 1903 (Server Core installation)
- Windows Server, version 1909 (Server Core installation)
»º½â¼Æ»®
΢ÈíËäÈ»´Ë´ÎûÓÐÐû²¼¸ÃÎó²îµÄÇå¾²²¹¶¡£¬¿ÉÊÇÌṩÁË»º½â²½·¥£¬½¨ÒéÓû§¾¡¿ì½ÓÄÉÏà¹ØÔÝʱ·À»¤²½·¥¡£
Óû§¿ÉÒÔͨ¹ýÒÔÏÂPowershellÏÂÁîÀ´½ûÓÃSMBv3 ServerµÄcompressionÀ´ÔÝʱ·À»¤£º
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 1 –Force
×¢£ºÒÔÉÏÏÂÁî²»ÐèÒªÖØÆô¼´¿ÉÉúЧ¡£ÒÔÉÏÏÂÁî½ö¿ÉÒÔÓÃÀ´ÔÝʱ·À»¤Õë¶ÔSMB·þÎñÆ÷£¨SMB SERVER£©µÄ¹¥»÷£¬¹¥»÷ÕßÕվɿÉÒÔʹÓøÃÎó²îÀ´¹¥»÷SMB¿Í»§¶Ë£¨SMB Client£©¡£
³ý´ËÖ®Í⣬Óû§»¹¿ÉÒÔÔÚ·À»ðǽ×öºÃÇå¾²Õ½ÂÔ×èÖ¹SMBͨѶÁ÷³öÆóÒµÄÚ²¿£¬ÏêÇéÇë²Î¿¼Î¢Èí¹Ù·½Í¨¸æÖ¸ÄÏ£º
https://support.microsoft.com/zh-cn/help/3185535/preventing-smb-traffic-from-lateral-connections

¾ÅÓÎÀϸçÔÆ







