¡¾Îó²îͨ¸æ¡¿Windows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-38077£©
Ðû²¼Ê±¼ä 2024-08-09Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Windows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2024-38077 | ||
Îó²îÀàÐÍ | »º³åÇøÒç³ö | ·¢Ã÷ʱ¼ä | 2024-07-10 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Windows Remote Desktop Licensing Service£¨RDL£©ÊÇWindows ServerµÄÒ»¸ö×é¼þ£¬ÓÃÓÚ¿ØÖƺÍÖÎÀíÔ¶³Ì×ÀÃæ»á»°µÄÔÊÐí£¬È·±£Ö»ÓÐÓµÓÐÓÐÓÃÔÊÐíµÄÓû§²Å»ªÍ¨¹ýÔ¶³Ì×ÀÃæÐÒ飨RDP£©ÅþÁ¬µ½·þÎñÆ÷¡£
2024Äê7ÔÂ10ÈÕ£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼¯ÍÅVSRC¼à²âµ½Î¢Èí7ÔÂÇå¾²¸üÐÂÐÞ¸´ÁËWindows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-38077£¬±»³ÆΪ¡°MadLicense¡±£©£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8¡£
Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖб£´æ¶Ñ»º³åÇøÒç³öÎó²î£¬ÓÉÓÚÔÚ½âÂëÓû§ÊäÈëµÄÔÊÐíÃÜÔ¿°üʱȱ·¦×¼È·µÄ»º³åÇø¾Þϸ¼ì²é£¬µ¼Ö½âÂëºó·ºÆ𻺳åÇøÒç³ö£¬µ±Windows Server¿ªÆôÔ¶³Ì×ÀÃæÊÚȨ·þÎñ£¨·ÇĬÈÏÆôÓã©Ê±£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕß¿É·¢ËͶñÒâÐÂÎÅʹÓøÃÎó²î£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
¶þ¡¢Ó°Ïì¹æÄ£
Windows Server 2012 R2 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server Core installation)
Windows Server 2012
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2016 (Server Core installation)
Windows Server 2016
Windows Server 2022, 23H2 Edition (Server Core installation)
Windows Server 2022 (Server Core installation)
Windows Server 2022
Windows Server 2019 (Server Core installation)
Windows Server 2019
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ΢ÈíÒÑÐû²¼Á˸ÃÎó²îµÄÇå¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔÏ°취ÊÖ¶¯¾ÙÐиüУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔز¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£
ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-38077
3.2 ÔÝʱ²½·¥
¸ÃÎó²î»áÓ°ÏìÆôÓÃÁËWindows Remote Desktop Licensing ServiceµÄWindows Server£¬Windows PC²»ÊÜÓ°Ïì¡£
1.ĬÈÏÇéÐÎÏ£¬Windows Server ²»»á×°Öà Remote Desktop Licensing ·þÎñ£¬¿Éͨ¹ýÑéÖ¤Remote Desktop Licensing·þÎñÊÇ·ñÆô¶¯£¬Ïà¹Ø²¹¶¡ÊÇ·ñδװÖÃÀ´ÅжÏÊÇ·ñÒ×ÊܸÃÎó²îÓ°Ïì¡£
Èç·ÇÐëÒª£¬¿É½ûÓÃRemote Desktop Licensing·þÎñ×÷Ϊ»º½â²½·¥£¬µ«Õâ¿ÉÄÜ»áÓ°ÏìÔ¶³Ì×ÀÃæijЩ¹¦Ð§(¿ÉÄܲ»»áÖ±½Óµ¼ÖÂRDPÅþÁ¬Ê§°Ü£¬µ«ÓÉÓÚÊÚȨÑéÖ¤µÄȱʧ£¬¿ÉÄÜ»áÒý·¢ÆäËûÓëÊÚȨÏà¹ØµÄ¹ýʧ»òÎÊÌâ)¡£±ðµÄ£¬Microsoft½¨ÒéÊÜÓ°ÏìÓû§×°ÖøÃÎó²îµÄÇå¾²¸üУ¬×ÝÈ»ÍýÏë½ûÓÃRemote Desktop Licensing·þÎñ¡£
2.±ðµÄ£¬¿Éͨ¹ýÉó²élserver.dll£¨Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÆ÷µÄÒ»¸öÒªº¦×é¼þ£¬Í¨³£Î»ÓÚC:\Windows\System32\lserver.dll£©Îļþ°æ±¾£¬²Î¿¼Ï±íÈ·¶¨ÊÇ·ñΪÒ×Êܹ¥»÷°æ±¾£¬¿ÉʹÓÃÒÔ϶àÖÖ·½·¨Éó²é¸ÃÎļþ°æ±¾£º
l ÎļþÊôÐÔÉó²é£¬ÕÒµ½C:\Windows\System32\lserver.dll£¬ÓÒ¼üµã»÷ lserver.dll Îļþ£¬Ñ¡Ôñ¡°ÊôÐÔ¡±£¬ÔÚÊôÐÔ´°¿ÚÖУ¬µã»÷¡°ÏêϸÐÅÏ¢¡±Ñ¡Ï£¬ÔÚ¡°ÏêϸÐÅÏ¢¡±Ñ¡ÏÏ£¬¿É¿´µ½¡°Îļþ°æ±¾¡±ºÍ¡°²úÆ·°æ±¾¡±ÐÅÏ¢¡£
l ʹÓÃPowershellÉó²éÎļþ°æ±¾£¬PowerShellÖÐÖ´ÐÐÒÔÏÂÏÂÁ
(Get-Item "C:\Windows\System32\lserver.dll").VersionInfo
l ÔÚCMD ÖÐŲÓÃPowerShell ÏÂÁîÀ´»ñÈ¡Îļþ°æ±¾ÐÅÏ¢£º
powershell -command "(Get-Item 'C:\\Windows\\System32\\lserver.dll').VersionInfo.FileVersion"
ÊÜÓ°Ïìϵͳ | ƽ̨ | ÊÜÓ°Ïì°æ±¾ | ²»ÊÜÓ°Ïì°æ±¾ |
Windows Server 2019 | x64-based Systems | 10.0.0 - 10.0.17763.6054֮ǰ | 10.0.17763.6054 |
Windows Server 2019 (Server Core installation) | x64-based Systems | 10.0.0 -10.0.17763.6054֮ǰ | 10.0.17763.6054 |
Windows Server 2022 | x64-based Systems | 10.0.0 -10.0.20348.2582֮ǰ | 10.0.20348.2582 |
Windows Server 2022£¬23H2 Edition (Server Core installation) | x64-based Systems | 10.0.0 - 10.0.25398.1009֮ǰ | 10.0.25398.1009 |
Windows Server 2016 | x64-based Systems | 10.0.0 -10.0.14393.7159֮ǰ | 10.0.14393.7159 |
Windows Server 2016 (Server Core installation) | x64-based Systems | 10.0.0 -10.0.14393.7159֮ǰ | 10.0.14393.7159 |
Windows Server 2008 Service Pack 2 | 32-bit Systems | 6.0.0 - 6.0.6003.22769֮ǰ | 6.0.6003.22769 |
Windows Server 2008 Service Pack 2 (Server Core installation) | 32-bit Systems¡¢x64-based Systems | 6.0.0 - 6.0.6003.22769֮ǰ | 6.0.6003.22769 |
Windows Server 2008 Service Pack 2 | x64-based Systems | 6.0.0 - 6.0.6003.22769֮ǰ | 6.0.6003.22769 |
Windows Server 2008 R2 Service Pack 1 | x64-based Systems | 6.1.0 - 6.1.7601.27219֮ǰ | 6.1.7601.27219 |
Windows Server 2008 R2 Service Pack 1 (Server Core installation) | x64-based Systems | 6.0.0 - 6.1.7601.27219֮ǰ | 6.1.7601.27219 |
Windows Server 2012 | x64-based Systems | 6.2.0 - 6.2.9200.24975֮ǰ | 6.2.9200.24975 |
Windows Server 2012 (Server Core installation) | x64-based Systems | 6.2.0 - 6.2.9200.24975֮ǰ | 6.2.9200.24975 |
Windows Server 2012 R2 | x64-based Systems | 6.3.0 - 6.3.9600.22074֮ǰ | 6.3.9600.22074 |
Windows Server 2012 R2 (Server Core installation) | x64-based Systems | 6.3.0 - 6.3.9600.22074֮ǰ | 6.3.9600.22074 |
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔ̽«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Jul
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-38077
https://sites.google.com/site/zhiniangpeng/blogs/MadLicense
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-08-09 | Ê×´ÎÐû²¼ |
V1.1 | 2024-08-09 | ¸üÐÂPoC״̬¡¢»º½â²½·¥µÈ |
Îå¡¢¸½Â¼
5.1 ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ò½é
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½¨ÉèÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Çå¾²·þÎñ½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Æ𾢡£
5.2 ¹ØÓÚÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º