¡¾Îó²îͨ¸æ¡¿Windows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-38077£©

Ðû²¼Ê±¼ä 2024-08-09

Ò»¡¢Îó²î¸ÅÊö

Îó²îÃû³Æ

Windows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐÐÎó²î

CVE   ID

CVE-2024-38077

Îó²îÀàÐÍ

»º³åÇøÒç³ö

·¢Ã÷ʱ¼ä

2024-07-10

Îó²îÆÀ·Ö

9.8

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷

 

Windows Remote Desktop Licensing Service£¨RDL£©ÊÇWindows ServerµÄÒ»¸ö×é¼þ£¬ÓÃÓÚ¿ØÖƺÍÖÎÀíÔ¶³Ì×ÀÃæ»á»°µÄÔÊÐí£¬È·±£Ö»ÓÐÓµÓÐÓÐÓÃÔÊÐíµÄÓû§²Å»ªÍ¨¹ýÔ¶³Ì×ÀÃæЭÒ飨RDP£©ÅþÁ¬µ½·þÎñÆ÷¡£

2024Äê7ÔÂ10ÈÕ£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼¯ÍÅVSRC¼à²âµ½Î¢Èí7ÔÂÇå¾²¸üÐÂÐÞ¸´ÁËWindows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-38077£¬±»³ÆΪ¡°MadLicense¡±£©£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8¡£

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖб£´æ¶Ñ»º³åÇøÒç³öÎó²î£¬ÓÉÓÚÔÚ½âÂëÓû§ÊäÈëµÄÔÊÐíÃÜÔ¿°üʱȱ·¦×¼È·µÄ»º³åÇø¾Þϸ¼ì²é£¬µ¼Ö½âÂëºó·ºÆ𻺳åÇøÒç³ö£¬µ±Windows Server¿ªÆôÔ¶³Ì×ÀÃæÊÚȨ·þÎñ£¨·ÇĬÈÏÆôÓã©Ê±£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿É·¢ËͶñÒâÐÂÎÅʹÓøÃÎó²î£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

 

¶þ¡¢Ó°Ïì¹æÄ£

Windows Server 2012 R2 (Server Core installation)

Windows Server 2012 R2

Windows Server 2012 (Server Core installation)

Windows Server 2012

Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server 2016 (Server Core installation)

Windows Server 2016

Windows Server 2022, 23H2 Edition (Server Core installation)

Windows Server 2022 (Server Core installation)

Windows Server 2022

Windows Server 2019 (Server Core installation)

Windows Server 2019


Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ΢ÈíÒÑÐû²¼Á˸ÃÎó²îµÄÇå¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔÏ°취ÊÖ¶¯¾ÙÐиüУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔز¢×°Öá£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-38077

3.2 ÔÝʱ²½·¥

¸ÃÎó²î»áÓ°ÏìÆôÓÃÁËWindows Remote Desktop Licensing ServiceµÄWindows Server£¬Windows PC²»ÊÜÓ°Ïì¡£

1.ĬÈÏÇéÐÎÏ£¬Windows Server ²»»á×°Öà Remote Desktop Licensing ·þÎñ£¬¿Éͨ¹ýÑéÖ¤Remote Desktop Licensing·þÎñÊÇ·ñÆô¶¯£¬Ïà¹Ø²¹¶¡ÊÇ·ñδװÖÃÀ´ÅжÏÊÇ·ñÒ×ÊܸÃÎó²îÓ°Ïì¡£

Èç·ÇÐëÒª£¬¿É½ûÓÃRemote Desktop Licensing·þÎñ×÷Ϊ»º½â²½·¥£¬µ«Õâ¿ÉÄÜ»áÓ°ÏìÔ¶³Ì×ÀÃæijЩ¹¦Ð§(¿ÉÄܲ»»áÖ±½Óµ¼ÖÂRDPÅþÁ¬Ê§°Ü£¬µ«ÓÉÓÚÊÚȨÑéÖ¤µÄȱʧ£¬¿ÉÄÜ»áÒý·¢ÆäËûÓëÊÚȨÏà¹ØµÄ¹ýʧ»òÎÊÌâ)¡£±ðµÄ£¬Microsoft½¨ÒéÊÜÓ°ÏìÓû§×°ÖøÃÎó²îµÄÇå¾²¸üУ¬×ÝÈ»ÍýÏë½ûÓÃRemote Desktop Licensing·þÎñ¡£

2.±ðµÄ£¬¿Éͨ¹ýÉó²élserver.dll£¨Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÆ÷µÄÒ»¸öÒªº¦×é¼þ£¬Í¨³£Î»ÓÚC:\Windows\System32\lserver.dll£©Îļþ°æ±¾£¬²Î¿¼Ï±íÈ·¶¨ÊÇ·ñΪÒ×Êܹ¥»÷°æ±¾£¬¿ÉʹÓÃÒÔ϶àÖÖ·½·¨Éó²é¸ÃÎļþ°æ±¾£º

l  ÎļþÊôÐÔÉó²é£¬ÕÒµ½C:\Windows\System32\lserver.dll£¬ÓÒ¼üµã»÷ lserver.dll Îļþ£¬Ñ¡Ôñ¡°ÊôÐÔ¡±£¬ÔÚÊôÐÔ´°¿ÚÖУ¬µã»÷¡°ÏêϸÐÅÏ¢¡±Ñ¡Ï£¬ÔÚ¡°ÏêϸÐÅÏ¢¡±Ñ¡ÏÏ£¬¿É¿´µ½¡°Îļþ°æ±¾¡±ºÍ¡°²úÆ·°æ±¾¡±ÐÅÏ¢¡£

l  ʹÓÃPowershellÉó²éÎļþ°æ±¾£¬PowerShellÖÐÖ´ÐÐÒÔÏÂÏÂÁ

(Get-Item "C:\Windows\System32\lserver.dll").VersionInfo

l  ÔÚCMD ÖÐŲÓÃPowerShell ÏÂÁîÀ´»ñÈ¡Îļþ°æ±¾ÐÅÏ¢£º

powershell -command "(Get-Item 'C:\\Windows\\System32\\lserver.dll').VersionInfo.FileVersion"

ÊÜÓ°Ïìϵͳ

ƽ̨

ÊÜÓ°Ïì°æ±¾

²»ÊÜÓ°Ïì°æ±¾

Windows Server 2019

x64-based Systems

10.0.0 - 10.0.17763.6054֮ǰ

10.0.17763.6054

Windows Server 2019 (Server Core installation)

x64-based Systems

10.0.0 -10.0.17763.6054֮ǰ

10.0.17763.6054

Windows Server 2022

x64-based Systems

10.0.0 -10.0.20348.2582֮ǰ

10.0.20348.2582

Windows Server 2022£¬23H2 Edition (Server Core   installation)

x64-based Systems

10.0.0 - 10.0.25398.1009֮ǰ

10.0.25398.1009

Windows Server 2016

x64-based Systems

10.0.0 -10.0.14393.7159֮ǰ

10.0.14393.7159

Windows Server 2016 (Server Core installation)

x64-based Systems

10.0.0 -10.0.14393.7159֮ǰ

10.0.14393.7159

Windows Server 2008 Service Pack 2

32-bit Systems

6.0.0 - 6.0.6003.22769֮ǰ

6.0.6003.22769

Windows Server 2008 Service Pack 2 (Server Core   installation)

32-bit Systems¡¢x64-based Systems

6.0.0 - 6.0.6003.22769֮ǰ

6.0.6003.22769

Windows Server 2008 Service Pack 2

x64-based Systems

6.0.0 - 6.0.6003.22769֮ǰ

6.0.6003.22769

Windows Server 2008 R2 Service Pack 1

x64-based Systems

6.1.0 - 6.1.7601.27219֮ǰ

6.1.7601.27219

Windows Server 2008 R2 Service Pack 1 (Server   Core installation)

x64-based Systems

6.0.0 - 6.1.7601.27219֮ǰ

6.1.7601.27219

Windows Server 2012

x64-based Systems

6.2.0 - 6.2.9200.24975֮ǰ

6.2.9200.24975

Windows Server 2012 (Server Core installation)

x64-based Systems

6.2.0 - 6.2.9200.24975֮ǰ

6.2.9200.24975

Windows Server 2012 R2

x64-based Systems

6.3.0 - 6.3.9600.22074֮ǰ

6.3.9600.22074

Windows Server 2012 R2 (Server Core installation)

x64-based Systems

6.3.0 - 6.3.9600.22074֮ǰ

6.3.9600.22074

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔ̭ϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔÌ­½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔÌ­¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Jul

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-38077

https://sites.google.com/site/zhiniangpeng/blogs/MadLicense


 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-08-09

Ê×´ÎÐû²¼

V1.1

2024-08-09

¸üÐÂPoC״̬¡¢»º½â²½·¥µÈ

 


Îå¡¢¸½Â¼

5.1 ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ò½é

ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½¨ÉèÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Çå¾²·þÎñ½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Æ𾢡£

5.2 ¹ØÓÚÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø

ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png