¡¾Â©¶´Í¨¸æ¡¿Windows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2024-38077£©
Ðû²¼Ê±¼ä 2024-08-09Ò»¡¢Â©¶´¸ÅÊö
©¶´Ãû³Æ | Windows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ||
CVE ID | CVE-2024-38077 | ||
©¶´ÀàÐÍ | »º³åÇøÒç³ö | ·¢ÏÖʱ¼ä | 2024-07-10 |
©¶´ÆÀ·Ö | 9.8 | ©¶´Æ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Windows Remote Desktop Licensing Service£¨RDL£©ÊÇWindows ServerµÄÒ»¸ö×é¼þ£¬ÓÃÓÚ¿ØÖƺ͹ÜÀíÔ¶³Ì×ÀÃæ»á»°µÄÐí¿É£¬È·±£Ö»ÓÐÓµÓÐÓÐЧÐí¿ÉµÄÓû§²ÅÆøÍ¨¹ýÔ¶³Ì×ÀÃæÐÒ飨RDP£©Á¬½Óµ½·þÎñÆ÷¡£
2024Äê7ÔÂ10ÈÕ£¬¶¶È¦Îª¶Ä¶øÉú¼¯ÍÅVSRC¼à²âµ½Î¢Èí7ÔÂÄþ¾²¸üÐÂÐÞ¸´ÁËWindows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2024-38077£¬±»³ÆÎª¡°MadLicense¡±£©£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8¡£
Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖдæÔÚ¶Ñ»º³åÇøÒç³ö©¶´£¬ÓÉÓÚÔÚ½âÂëÓû§ÊäÈëµÄÐí¿ÉÃÜÔ¿°üʱȱ·¦ÕýÈ·µÄ»º³åÇø¾Þϸ¼ì²é£¬µ¼Ö½âÂëºó·ºÆð»º³åÇøÒç³ö£¬µ±Windows Server¿ªÆôÔ¶³Ì×ÀÃæÊÚȨ·þÎñ£¨·ÇĬÈÏÆôÓã©Ê±£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕ߿ɷ¢ËͶñÒâÏûÏ¢ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
¶þ¡¢Ó°Ï췶Χ
Windows Server 2012 R2 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server Core installation)
Windows Server 2012
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2016 (Server Core installation)
Windows Server 2016
Windows Server 2022, 23H2 Edition (Server Core installation)
Windows Server 2022 (Server Core installation)
Windows Server 2022
Windows Server 2019 (Server Core installation)
Windows Server 2019
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒÑÐû²¼Á˸é¶´µÄÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£
£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-38077
3.2 ÁÙʱ´ëÊ©
¸Ã©¶´»áÓ°ÏìÆôÓÃÁËWindows Remote Desktop Licensing ServiceµÄWindows Server£¬Windows PC²»ÊÜÓ°Ïì¡£
1.ĬÈÏÇé¿öÏ£¬Windows Server ²»»á°²×° Remote Desktop Licensing ·þÎñ£¬¿Éͨ¹ýÑéÖ¤Remote Desktop Licensing·þÎñÊÇ·ñÆô¶¯£¬Ïà¹Ø²¹¶¡ÊÇ·ñδ°²×°À´ÅжÏÊÇ·ñÒ×Êܸé¶´Ó°Ïì¡£
Èç·ÇÐëÒª£¬¿É½ûÓÃRemote Desktop Licensing·þÎñ×÷Ϊ»º½â´ëÊ©£¬µ«Õâ¿ÉÄÜ»áÓ°ÏìÔ¶³Ì×ÀÃæÄ³Ð©¹¦Ð§(¿ÉÄܲ»»áÖ±½Óµ¼ÖÂRDPÁ¬½Óʧ°Ü£¬µ«ÓÉÓÚÊÚȨÑéÖ¤µÄȱʧ£¬¿ÉÄÜ»áÒý·¢ÆäËûÓëÊÚȨÏà¹ØµÄ´íÎó»òÎÊÌâ)¡£´ËÍ⣬Microsoft½¨ÒéÊÜÓ°ÏìÓû§°²×°¸Ã©¶´µÄÄþ¾²¸üУ¬¼´Ê¹¼Æ»®½ûÓÃRemote Desktop Licensing·þÎñ¡£
2.´ËÍ⣬¿Éͨ¹ý¼ì²ìlserver.dll£¨Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÆ÷µÄÒ»¸öÒªº¦×é¼þ£¬Í¨³£Î»ÓÚC:\Windows\System32\lserver.dll£©Îļþ°æ±¾£¬²Î¿¼Ï±íÈ·¶¨ÊÇ·ñΪÒ×Êܹ¥»÷°æ±¾£¬¿ÉʹÓÃÒÔ϶àÖÖ·½Ê½¼ì²ì¸ÃÎļþ°æ±¾£º
l ÎļþÊôÐÔ¼ì²ì£¬ÕÒµ½C:\Windows\System32\lserver.dll£¬ÓÒ¼üµã»÷ lserver.dll Îļþ£¬Ñ¡Ôñ¡°ÊôÐÔ¡±£¬ÔÚÊôÐÔ´°¿ÚÖУ¬µã»÷¡°ÏêϸÐÅÏ¢¡±Ñ¡Ï£¬ÔÚ¡°ÏêϸÐÅÏ¢¡±Ñ¡ÏÏ£¬¿É¿´µ½¡°Îļþ°æ±¾¡±ºÍ¡°²úÎï°æ±¾¡±ÐÅÏ¢¡£
l ʹÓÃPowershell¼ì²ìÎļþ°æ±¾£¬PowerShellÖÐÖ´ÐÐÒÔÏÂÃüÁ
(Get-Item "C:\Windows\System32\lserver.dll").VersionInfo
l ÔÚCMD Öе÷ÓÃPowerShell ÃüÁîÀ´»ñÈ¡Îļþ°æ±¾ÐÅÏ¢£º
powershell -command "(Get-Item 'C:\\Windows\\System32\\lserver.dll').VersionInfo.FileVersion"
ÊÜÓ°Ïìϵͳ | ƽ̨ | ÊÜÓ°Ïì°æ±¾ | ²»ÊÜÓ°Ïì°æ±¾ |
Windows Server 2019 | x64-based Systems | 10.0.0 - 10.0.17763.6054֮ǰ | 10.0.17763.6054 |
Windows Server 2019 (Server Core installation) | x64-based Systems | 10.0.0 -10.0.17763.6054֮ǰ | 10.0.17763.6054 |
Windows Server 2022 | x64-based Systems | 10.0.0 -10.0.20348.2582֮ǰ | 10.0.20348.2582 |
Windows Server 2022£¬23H2 Edition (Server Core installation) | x64-based Systems | 10.0.0 - 10.0.25398.1009֮ǰ | 10.0.25398.1009 |
Windows Server 2016 | x64-based Systems | 10.0.0 -10.0.14393.7159֮ǰ | 10.0.14393.7159 |
Windows Server 2016 (Server Core installation) | x64-based Systems | 10.0.0 -10.0.14393.7159֮ǰ | 10.0.14393.7159 |
Windows Server 2008 Service Pack 2 | 32-bit Systems | 6.0.0 - 6.0.6003.22769֮ǰ | 6.0.6003.22769 |
Windows Server 2008 Service Pack 2 (Server Core installation) | 32-bit Systems¡¢x64-based Systems | 6.0.0 - 6.0.6003.22769֮ǰ | 6.0.6003.22769 |
Windows Server 2008 Service Pack 2 | x64-based Systems | 6.0.0 - 6.0.6003.22769֮ǰ | 6.0.6003.22769 |
Windows Server 2008 R2 Service Pack 1 | x64-based Systems | 6.1.0 - 6.1.7601.27219֮ǰ | 6.1.7601.27219 |
Windows Server 2008 R2 Service Pack 1 (Server Core installation) | x64-based Systems | 6.0.0 - 6.1.7601.27219֮ǰ | 6.1.7601.27219 |
Windows Server 2012 | x64-based Systems | 6.2.0 - 6.2.9200.24975֮ǰ | 6.2.9200.24975 |
Windows Server 2012 (Server Core installation) | x64-based Systems | 6.2.0 - 6.2.9200.24975֮ǰ | 6.2.9200.24975 |
Windows Server 2012 R2 | x64-based Systems | 6.3.0 - 6.3.9600.22074֮ǰ | 6.3.9600.22074 |
Windows Server 2012 R2 (Server Core installation) | x64-based Systems | 6.3.0 - 6.3.9600.22074֮ǰ | 6.3.9600.22074 |
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Jul
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-38077
https://sites.google.com/site/zhiniangpeng/blogs/MadLicense
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-08-09 | Ê×´ÎÐû²¼ |
V1.1 | 2024-08-09 | ¸üÐÂPoC״̬¡¢»º½â´ëÊ©µÈ |
Îå¡¢¸½Â¼
5.1 ¶¶È¦Îª¶Ä¶øÉú¼ò½é
¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
5.2 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º