¾ÅÓÎÀϸç

¾ÅÓÎÀϸç

¾ÅÓÎÀÏ¸ç¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • AIÇå¾²

    AIÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

¡¾Îó²îͨ¸æ¡¿Netlogon?ÌØÈ¨ÌáÉýÎó²î£¨CVE-2020-1472£©´¦Öóͷ£ÊÖ²á

2020-09-17

Ò».  Îó²î¸ÅÊö

¿ËÈÕ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼¼à²âµ½ÍâÑóÇå¾²¹«Ë¾Secura¹ûÕæÁËNetLogonÌØÈ¨ÌáÉýÎó²î£¨CVE-2020-1472£©µÄÏêϸÐÅÏ¢ÓëÑéÖ¤¾ç±¾£¬µ¼ÖÂÎó²îΣº¦ÝëµØÌáÉý¡£¹¥»÷ÕßÐèÔÚÓëÄ¿µÄÏàͬµÄ¾ÖÓòÍø£¨LAN£©ÉϵÄÅÌËã»ú¾ÙÐÐʹÓã¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýNetLogonÔ¶³ÌЭÒ飨MS-NRPC£©½¨ÉèÓëÓò¿ØÖÆÆ÷ÅþÁ¬µÄ Ç徲ͨµÀʱ£¬¿ÉʹÓôËÎó²î»ñÈ¡ÓòÖÎÀíÔ±»á¼ûȨÏÞ¡£´ËÎó²îΪ΢ÈíÔÚ8Ô²¹¶¡¸üÐÂʱÅû¶£¬CVSSÆÀ·ÖΪ10£¬Ó°ÏìÆÕ±é£¬ÏÖÔÚÍøÉÏÒÑÓÐEXPÐû²¼£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£

NetlogonÊÇWindowsÖÐÓÃÓÚΪÓò¿ØÖÆÆ÷×¢²áËùÓÐSRV×ÊÔ´¼Í¼µÄ·þÎñ¡£ÌṩÓû§ºÍ»úеÔÚÓòÄÚÍøÂçÉϵÄÈÏÖ¤Óë¸´ÖÆÊý¾Ý¿â¾ÙÐÐÓò¿Ø±¸·Ý£¬»¹ÓÃÓÚά»¤Óò³ÉÔ±ÓëÓòÖ®¼ä¡¢ÓòÓëÓò¿ØÖ®¼ä¡¢ÓòDCÓë¿çÓòDCÖ®¼äµÄ¹ØÏµ¡£

¾ÅÓÎÀÏ¸ç¿Æ¼¼µÚһʱ¼ä¸´ÏÖÁË´ËÎó²î£º

¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

 

²Î¿¼Á´½Ó£º

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472

¶þ.  Ó°Ïì¹æÄ£

ÊÜÓ°Ïì°æ±¾

Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Windows Server 2012

Windows Server 2012 (Server Core installation)

Windows Server 2012 R2

Windows Server 2012 R2 (Server Core installation)

Windows Server 2016

Windows Server 2016  (Server Core installation)

Windows Server 2019

Windows Server 2019  (Server Core installation)

Windows Server, version 1903 (Server Core installation)

Windows Server, version 1909 (Server Core installation)

Windows Server, version 2004 (Server Core installation)

Èý.  Îó²î¼ì²â

3.1  ¹¤¾ßÑéÖ¤

Åû¶´ËÎó²îµÄSecuraÒÑÔÚGitHubÉÏ´«ÁËÑéÖ¤¾ç±¾£¬Ïà¹ØÓû§¿ÉʹÓô˹¤¾ß¾ÙÐмì²â£º

https://github.com/SecuraBV/CVE-2020-1472

ÊÜÓ°Ïìϵͳ£¨Windows Server 2012 R2£©µÄ¼ì²âЧ¹ûÈçÏ£º

 

¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

3.2  ²úÆ·¼ì²â

¾ÅÓÎÀÏ¸ç¿Æ¼¼Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS£©ÓëÍøÂçÈëÇÖ¼ì²âϵͳ£¨IDS£©¡¢×ÛºÏÍþв̽Õ루UTS£©ÒѾ߱¸¶Ô´ËÎó²îµÄɨÃèÓë¼ì²âÄÜÁ¦£¬ÇëÓа²ÅÅÒÔÉÏ×°±¸µÄÓû§Éý¼¶ÖÁ×îа汾¡£

Çå¾²²úÆ·°æ±¾

Éý¼¶°ü°æ±¾ºÅ

Éý¼¶°üÏÂÔØÁ´½Ó

RSAS  V6 ÏµÍ³²å¼þ°ü

V6.0R02F01.1917

http://update.nsfocus.com/update/downloads/id/108456

IDS

5.6.9.23542

http://update.nsfocus.com/update/downloads/id/108464

5.6.10.23542

http://update.nsfocus.com/update/downloads/id/108465

UTS

5.6.10.23542

http://update.nsfocus.com/update/downloads/id/108469

¹ØÓÚRSASµÄÉý¼¶ÉèÖÃÖ¸µ¼£¬Çë²Î¿¼ÈçÏÂÁ´½Ó£º

https://mp.weixin.qq.com/s/aLAWXs5DgRhNHf4WHHhQyg

ËÄ.  Îó²î·À»¤

4.1  ¹Ù·½Éý¼¶

ÏÖÔÚ΢Èí¹Ù·½ÒÑÕë¶ÔÊÜÖ§³ÖµÄϵͳ°æ±¾Ðû²¼ÁËÐÞ¸´´ËÎó²îµÄÇå¾²²¹¶¡£¬Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì×°Öò¹¶¡¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£º

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472

×¢£ºÓÉÓÚÍøÂçÎÊÌâ¡¢ÅÌËã»úÇéÐÎÎÊÌâµÈÔµ¹ÊÔ­ÓÉ£¬Windows UpdateµÄ²¹¶¡¸üпÉÄÜ·ºÆðʧ°Ü¡£Óû§ÔÚ×°Öò¹¶¡ºó£¬Ó¦ÊµÊ±¼ì²é²¹¶¡ÊÇ·ñÀֳɸüС£

ÓÒ¼üµã»÷Windowsͼ±ê£¬Ñ¡Ôñ“ÉèÖÃ(N)”£¬Ñ¡Ôñ“¸üкÍÇå¾²”-“Windows¸üД£¬Éó²é¸ÃÒ³ÃæÉϵÄÌáÐÑÐÅÏ¢£¬Ò²¿Éµã»÷“Éó²é¸üÐÂÀúÊ·¼Í¼”Éó²éÀúÊ·¸üÐÂÇéÐΡ£

Õë¶ÔδÀÖ³É×°ÖõĸüУ¬¿Éµã»÷¸üÐÂÃû³ÆÌø×ªµ½Î¢Èí¹Ù·½ÏÂÔØÒ³Ãæ£¬½¨ÒéÓû§µã»÷¸ÃÒ³ÃæÉϵÄÁ´½Ó£¬×ªµ½“Microsoft¸üÐÂĿ¼”ÍøÕ¾ÏÂÔØ×ÔÁ¦³ÌÐò°ü²¢×°Öá£

4.2  ÆäËû·À»¤²½·¥

ÔÚ×°Öøüв¹¶¡ºó£¬»¹¿Éͨ¹ý°²ÅÅÓò¿ØÖÆÆ÷ (DC) Ç¿ÖÆÄ£Ê½ÒÔÃâÊܵ½¸ÃÎó²îÓ°Ï죺

Çë²Î¿¼¹Ù·½Îĵµ¾ÙÐÐÉèÖá¶ÔõÑùÖÎÀíÓë CVE-2020-1472 Ïà¹ØµÄ Netlogon Ç徲ͨµÀÅþÁ¬µÄ¸ü¸Ä¡·£º

https://support.microsoft.com/zh-cn/help/4557222/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc

4.3  ²úÆ··À»¤

Õë¶Ô´ËÎó²î£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍøÂçÈëÇÖ·À»¤ÏµÍ³(IPS) ÒÑÐû²¼¹æÔòÉý¼¶°ü£¬ÇëÏà¹ØÓû§Éý¼¶ÖÁ×îа汾¹æÔò£¬ÒÔÐγÉÇå¾²²úÆ··À»¤ÄÜÁ¦¡£Çå¾²·À»¤²úÆ·¹æÔò°æ±¾ºÅÈçÏ£º

Çå¾²·À»¤²úÆ·

¹æÔò°æ±¾ºÅ

Éý¼¶°üÏÂÔØÁ´½Ó

IPS

5.6.9.23542

http://update.nsfocus.com/update/downloads/id/108464

5.6.10.23542

http://update.nsfocus.com/update/downloads/id/108465

²úÆ·¹æÔòÉý¼¶µÄ²Ù×÷°ì·¨Ïê¼ûÈçÏÂÁ´½Ó£º

IPS£ºhttps://mp.weixin.qq.com/s/JsRktENQNj1TdZSU62N0Ww

 

4.4  Æ½Ì¨¼à²â

¾ÅÓÎÀϸçÆóÒµÇ徲ƽ̨£¨ESP-H£©ÒѾ­¾ß±¸Õë¶Ô´ËÎó²îµÄ¼à²âÄÜÁ¦£¬°²ÅÅÓоÅÓÎÀÏ¸ç¿Æ¼¼Æ½Ì¨Àà²úÆ·µÄÓû§£¬¿ÉʵÏÖ¶ÔÎó²îµÄƽ̨¼à²âÄÜÁ¦¡£

Ç徲ƽ̨

Éý¼¶°ü/¹æÔò°æ±¾ºÅ

ESP-H£¨¾ÅÓÎÀϸçÆóÒµÇ徲ƽ̨£©

ʹÓÃ×îйæÔòÉý¼¶°ü

ESP-EVENTRULE-013-20200915

 

ÉùÃ÷

±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£

¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾­¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¹ØÓÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼

¾ÅÓÎÀϸ磨¼ò³Æ¾ÅÓÎÀÏ¸ç¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ40¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£

»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£

¾ÅÓÎÀϸçÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈë¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
  • Ìá½»µ½ÓÊÏä
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷
΢²©
΢²©

΢²©

΢ÐÅ
΢ÐÅ

΢ÐÅ

BÕ¾
BÕ¾

BÕ¾

¶¶Òô
¶¶Òô

¶¶Òô

ÊÓÆµºÅ
ÊÓÆµºÅ

ÊÓÆµºÅ

·þÎñÈÈÏß

400-818-6868

·þÎñʱ¼ä

7*24Сʱ

? 2026 NSFOCUS ¾ÅÓÎÀÏ¸ç¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼