Microsoft ExchangeÄÚ´æÆÆËðÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-08-15Îó²î±àºÅºÍ¼¶±ð
CVE-2018-8302£¬£¬£¬ÑÏÖØ£¬£¬£¬CVSS·ÖÖµ¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 23
Microsoft Exchange Server 2013 Cumulative Update 20
Microsoft Exchange Server 2013 Cumulative Update 21
Microsoft Exchange Server 2016 Cumulative Update 10
Microsoft Exchange Server 2016 Cumulative Update 9
Îó²î¸ÅÊö
Îó²îµÄÔ´ÓÚÊÕ¼þÏäÎļþ¼ÐÊôÐÔ»á¼ûµÄTopNWords.Data¡£¡£¡£¡£ÕâЩÊý¾Ý´æ´¢ÔÚExchangeЧÀÍÆ÷ÉÏ£¬£¬£¬²¢ÇÒÊÇÒ»¸ö¹«¹²ÊôÐÔ£¬£¬£¬Óû§¿ÉÒÔͨ¹ýExchange Web Services (EWS)¸ü¸ÄËü¡£¡£¡£¡£Exchange Web Services ÊÇÒ»×é¿Í»§¶ËÓë Exchange ЧÀÍÆ÷ͨѶµÄ½Ó¿Ú¡£¡£¡£¡£
µ±ÊÕµ½ÓïÒôÓʼþʱ£¬£¬£¬Exchange»áÊÔͼ½«Æäת»»³ÉÎı¾£¬£¬£¬ÏÔʾÔÚÊÕ¼þÈ˵ÄÊÕ¼þÏäÖС£¡£¡£¡£ÔÚUnified Messaging(UM)ĬÈÏÆôÓõÄÇéÐÎÏ£¬£¬£¬×ªÂ¼»á×Ô¶¯¾ÙÐС£¡£¡£¡£Exchange»á¶ÁÈ¡TopNWords.DataµÄÊôÐÔÀ´ÉèÖÃÓû§µÄÊÕ¼þÏ䣬£¬£¬²¢Ê¹ÓÃ.NET BinaryFormatter¶ÔÆä¾ÙÐз´ÐòÁл¯£¬£¬£¬ÒÔ»ñµÃÎı¾µ½ÓïÒôµÄ×é¼þ¡£¡£¡£¡£
Îó²îÑéÖ¤
ʹÓôËÎó²îµÄÌõ¼þ£º
1.ExchangeЧÀÍÆ÷Ð轫Unified Messaging (UM)ÉèÖÃΪÆôÓÃ״̬£»£»£»£»£»
2.¹¥»÷ÕßÐèÒªÒ»¸öʹÓÃUMÓïÒôÓÊÏäÉèÖõÄÓÊÏäÕÊ»§¡£¡£¡£¡£
¹¥»÷ÕßʹÓÃExchangeЧÀͽ«.NETÐòÁл¯µÄpayloadÉÏ´«ÖÁЧÀÍÆ÷ÖÐ,ͬʱʹÓÃÍøÂç´¹ÂÚ·½·¨ÓÕʹÆäËûÕ˺ŵÄʹÓÃÕß·¿ªÓïÒôÓʼþ£¬£¬£¬×îÖÕÒÔϵͳ¼¶È¨ÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
º£ÄÚµÄÊÜÓ°Ïì×ʲúÂþÑÜÇéÐÎ
ÐÞ¸´½¨Òé
Microsoft ¹Ù·½ÒѾÔÚ8Ô·ݵÄÒªº¦Çå¾²²¹¶¡¸üÐÂÖÐÐÞ¸´Á˸ÃÎó²î£¬£¬£¬ÇëÊÜÓ°ÏìÓû§ÊµÊ±Ç°ÍùÏÂÔØ¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2018-8302
https://www.symantec.com/security-center/vulnerabilities/writeup/104973?om_rssid=sr-advisories


¾©¹«Íø°²±¸11010802024551ºÅ