·À»¤¼Æ»®À´ÁË£¡Windows SMBv3Ô¶³Ì´úÂëÖ´ÐÐÎó²î (CVE-2020-0796)
2020-03-11
Ò»¡¢×ÛÊö
±±¾©Ê±¼ä3ÔÂ11ÈÕ£¬Î¢ÈíÐû²¼ÁË3ÔÂÇå¾²²¹¶¡¸üУ¬ÆäÖаüÀ¨Ò»ÌõÇ徲ͨ¸æ³ÆÆäÒѾÏàʶµ½ÔÚMicrosoft Server Message Block 3.1.1(SMBv3)Öб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄSMB·þÎñÆ÷»òSMB¿Í»§¶ËÉÏÖ´ÐдúÂë¡£¸ÃÎó²îÔ´ÓÚSMBv3ÐÒ鹨ÓÚÌØ¶¨ÇëÇóµÄ´¦Öóͷ£·½·¨±£´æ¹ýʧ£¬¹¥»÷Õß¿ÉÒÔÔÚδ¾Éí·ÝÑéÖ¤µÄÇéÐÎÏÂʹÓøÃÎó²î¡£
ÈôÒªÕë¶ÔSMBv3·þÎñÆ÷£¬¹¥»÷Õß¿ÉÒÔ½«ÌØÖƵÄÊý¾Ý°ü·¢Ë͵½SMB·þÎñÆ÷À´´¥·¢¡£ÈôÒªÕë¶ÔSMBv3¿Í»§¶Ë£¬¹¥»÷ÕßÐèÒªÉèÖúÃÒ»¸ö¶ñÒâµÄSMB·þÎñÆ÷£¬²¢ÓÕʹÓû§ÅþÁ¬¸Ã·þÎñÆ÷¡£
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÑÔÚµÚһʱ¼ä¸´ÏÖÁËʹÓøÃÎó²îµÄÀú³Ì£¬Ð§¹ûÈçÏÂËùʾ:

ÏÖÔÚ΢ÈíÒѾÐû²¼²¹¶¡¾ÙÐÐÁËÐÞ¸´¡£
¼øÓÚ¸ÃÎó²îDZÔÚÍþв´ó£¬Ç¿ÁÒ½¨ÒéÓû§¾¡¿ì½ÓÄÉÏà¹Ø·À»¤²½·¥¾ÙÐзÀ»¤¡£
²Î¿¼Á´½Ó£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796
¶þ¡¢Îó²îÓ°Ïì¹æÄ£
- Windows 10 Version 1903 for 32-bit Systems
- Windows 10 Version 1903 for ARM64-based Systems
- Windows 10 Version 1903 for x64-based Systems
- Windows 10 Version 1909 for 32-bit Systems
- Windows 10 Version 1909 for ARM64-based Systems
- Windows 10 Version 1909 for x64-based Systems
- Windows Server, version 1903 (Server Core installation)
- Windows Server, version 1909 (Server Core installation)
Èý¡¢·À»¤¼Æ»®
3.1 ¹Ù·½ÐÞ¸´¼Æ»®
3.1.1 Çå¾²²¹¶¡
΢Èí¹Ù·½ÒÑÕë¶ÔÊÜÓ°Ïì²úÆ·Ðû²¼ÁËÇå¾²²¹¶¡KB4551762£¬Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìÓû§¿ªÆôϵͳ×Ô¶¯¸üÐÂ×°Öò¹¶¡¾ÙÐзÀ»¤¡£
ÈçÐèµ¥¶À×°Ö㬹ٷ½ÌṩµÄ²¹¶¡ÏÂÔØµØµãÈçÏ¡£
https://www.catalog.update.microsoft.com/Search.aspx?q=KB4551762
3.1.2 ÔÝʱ·À»¤
ÎÞ·¨×°ÖøüеÄÓû§¿Éͨ¹ýÒÔÏÂPowershellÏÂÁîÀ´½ûÓÃSMBv3ÖеÄѹËõ¹¦Ð§£¬¶ÔSMBv3 Server¾ÙÐÐÔÝʱ·À»¤£º
|
1
2
|
Set-ItemProperty -Path
"HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 1 –Force
|
×¢ÖØ£º
1. ÒÔÉÏÏÂÁî²»ÐèÒªÖØÆô¼´¿ÉÉúЧ¡£
2. ÒÔÉÏÏÂÁî½ö¿ÉÒÔÓÃÀ´ÔÝʱ·À»¤Õë¶ÔSMB·þÎñÆ÷£¨SMB SERVER£©µÄ¹¥»÷£¬¹¥»÷ÕßÕվɿÉÒÔʹÓøÃÎó²îÀ´¹¥»÷SMB¿Í»§¶Ë£¨SMB Client£©¡£
3. Çë²ÎÔIJ¢×ñÕÕ΢ÈíµÄÖ¸µ¼À´±£»¤SMB client¡£
https://support.microsoft.com/en-us/help/3185535/preventing-smb-traffic-from-lateral-connections
4. ½ûÓÃSMBѹËõ²»»á¶ÔÐÔÄÜÔì³É¸ºÃæÓ°Ïì¡£
¸ü¶àÏêÇéÇë²Î¿¼Î¢Èí¹Ù·½Í¨¸æ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796
3.2 ¾ÅÓÎÀÏ¸ç¿Æ¼¼¼ì²â·À»¤½¨Òé
3.2.1 ¾ÅÓÎÀÏ¸ç¿Æ¼¼¼ì²âÀà²úÆ·Óë·þÎñ
ÄÚÍø×ʲú¿ÉÒÔʹÓþÅÓÎÀÏ¸ç¿Æ¼¼µÄÔ¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS V6£©¡¢ÈëÇÖ¼ì²âϵͳ(IDS)¡¢Í³Ò»Íþв̽Õ루UTS£©¾ÙÐмì²â¡£
- Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS V6£©
http://update.nsfocus.com/update/listRsas
- ÈëÇÖ¼ì²âϵͳ£¨IDS£©
http://update.nsfocus.com/update/listIds
- ͳһÍþв̽Õ루UTS£©
http://update.nsfocus.com/update/bsaUtsIndex
3.2.1.1 ¼ì²â²úÆ·Éý¼¶°ü/¹æÔò°æ±¾ºÅ

- RSAS V6Éý¼¶°üÏÂÔØÁ´½Ó£º
http://update.nsfocus.com/update/downloads/id/103169
×¢£º“Microsoft SMBv3Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2020-0796)¡¾ÔÀíɨÃè¡¿” ´Ë²å¼þΪΣÏÕ²å¼þ£¬¿ÉÄÜÔì³ÉÊÜ´ËÎó²îÓ°ÏìµÄÖ÷»úÀ¶ÆÁ¡¢ÖØÆô¡¢¹Ø±ÕµÈÒì³£¡£Ä¬Èϲ»¿ªÆô£¬ÈçÐèÒª£¬Ç뿪ÆôΣÏÕ²å¼þºó¾ÙÐÐɨÃè ¡£
- IDS Éý¼¶°üÏÂÔØÁ´½Ó£º
5.6.10.22154
http://update.nsfocus.com/update/downloads/id/103168
5.6.9.22154
http://update.nsfocus.com/update/downloads/id/103167
- UTS Éý¼¶°üÏÂÔØÁ´½Ó£º
http://update.nsfocus.com/update/downloads/id/103172
3.2.2 ¾ÅÓÎÀÏ¸ç¿Æ¼¼·À»¤Àà²úÆ·
ʹÓþÅÓÎÀÏ¸ç¿Æ¼¼·À»¤Àà²úÆ·£¬ÈëÇÖ·À»¤ÏµÍ³£¨IPS£©À´¾ÙÐзÀ»¤¡£
- ÈëÇÖ·À»¤ÏµÍ³£¨IPS£©
http://update.nsfocus.com/update/listIps
3.2.2.1 ·À»¤²úÆ·Éý¼¶°ü/¹æÔò°æ±¾ºÅ

- IPS ¹æÔòÉý¼¶°üÏÂÔØÁ´½Ó£º
5.6.10.22154
http://update.nsfocus.com/update/downloads/id/103168
5.6.9.22154
http://update.nsfocus.com/update/downloads/id/103167
3.2.3 Ç徲ƽ̨

ËÄ¡¢ÊÖÒÕÆÊÎö
Îó²îÔÀí
¸ÃÎó²îCVE-2020-0796(ÓÖÃûSMBGhost)Ô´ÓÚSMB v3µÄÊý¾ÝѹËõ¹¦Ð§¡£ÔÚSMB v3ÖÐ΢ÈíÒýÈëÁËÊý¾ÝѹËõµÄ¹¦Ð§£¬Í¨¹ýÓë·þÎñÆ÷µÄǰÆÚ½»»¥£¬¿ÉÒÔÉ趨´«Êä¾ÓÉѹËõµÄÊý¾Ý£¬´Ó¶øÔöÌíЧÂÊ¡£È»¶øÔÚ°üÀ¨Ñ¹ËõÊý¾ÝµÄSMB°üÖУ¬¹¥»÷Õß¿ÉÒÔͨ¹ý¿ØÖÆÏà¹Ø×ֶΣ¬Ê¹µÃ³ÌÐòÔÚÉêÇë´æ´¢Êý¾ÝµÄ»º³åÇøÊ±±¬·¢Òç³ö£¬´Ó¶øÊ¹µÃÄ¿µÄϵͳÀ¶ÆÁ¾Ü¾ø·þÎñ¡£
Îå¡¢¸½Â¼ ²úÆ·/ƽ̨ʹÓÃÖ¸ÄÏ
5.1 RSASɨÃèÉèÖÃ
ÔÚϵͳÉý¼¶ÖУ¬µã»÷ÏÂͼºì¿òλÖÃÑ¡ÔñÎļþ¡£

Ñ¡ÔñÏÂÔØºÃµÄÏìÓ¦Éý¼¶°ü£¬µã»÷Éý¼¶°´Å¥¾ÙÐÐÊÖ¶¯Éý¼¶¡£ÆÚ´ýÉý¼¶Íê³Éºó£¬¿Éͨ¹ý¶¨ÖÆÉ¨ÃèÄ£°å£¬Õë¶Ô´ËÎó²î¾ÙÐÐɨÃè¡£
5.2 UTS¼ì²âÉèÖÃ
ÔÚϵͳÉý¼¶Öеã»÷ÀëÏßÉý¼¶£¬Ñ¡Ôñ¹æÔòÉý¼¶Îļþ£¬Ñ¡Ôñ¶ÔÓ¦µÄÉý¼¶°üÎļþ£¬µã»÷ÉÏ´«£¬²¢ÆÚ´ýÉý¼¶Àֳɼ´¿É¡£

5.3 IPS·À»¤ÉèÖÃ
5.3.1 ÔÚϵͳÉý¼¶Öеã»÷ÀëÏßÉý¼¶£¬Ñ¡Ôñϵͳ¹æÔò¿â£¬Ñ¡Ôñ¶ÔÓ¦µÄÎļþ£¬µã»÷ÉÏ´«¡£

5.3.2 ¸üÐÂÀֳɺó£¬ÔÚϵͳĬÈϹæÔò¿âÖвéÕÒ¹æÔò±àºÅ£¬¼´¿ÉÅÌÎʵ½¶ÔÓ¦µÄ¹æÔòÏêÇé¡£

×¢ÖØÊÂÏ¸ÃÉý¼¶°üÉý¼¶ºóÒýÇæ×Ô¶¯ÖØÆôÉúЧ£¬²»»áÔì³É»á»°ÖÐÖ¹£¬µ«ping°ü»á¶ª3~5¸ö£¬ÇëÑ¡ÔñºÏÊʵÄʱ¼äÉý¼¶¡£
5.4 ISOP ¾ÅÓÎÀϸçÖÇÄÜÇå¾²ÔËӪƽ̨
µÚÒ»²½£ºµÇ¼ISOPƽ̨£¬µã»÷ϵͳÉý¼¶£¬ÈçÏÂͼËùʾ£º

µÚ¶þ²½£ºÔړͳһ¹æÔò¿âÉý¼¶”ÖÐÑ¡Ôñ“¹¥»÷ʶ±ð¹æÔò°ü”£¬½«ÏÂÔØµÄ×îа汾¹æÔò°üµ¼ÈëÉÏ´«£¬²¢µã»÷Éý¼¶¼´¿É¡£


¾ÅÓÎÀϸçÔÆ







