¡¾Â©¶´Í¨¸æ¡¿Windows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2024-38077£©

Ðû²¼Ê±¼ä 2024-08-09

Ò»¡¢Â©¶´¸ÅÊö

©¶´Ãû³Æ

Windows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐЩ¶´

CVE   ID

CVE-2024-38077

©¶´ÀàÐÍ

»º³åÇøÒç³ö

·¢ÏÖʱ¼ä

2024-07-10

©¶´ÆÀ·Ö

9.8

©¶´Æ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ

 

Windows Remote Desktop Licensing Service£¨RDL£©ÊÇWindows ServerµÄÒ»¸ö×é¼þ £¬ÓÃÓÚ¿ØÖƺ͹ÜÀíÔ¶³Ì×ÀÃæ»á»°µÄÐí¿É £¬È·±£Ö»ÓÐÓµÓÐÓÐЧÐí¿ÉµÄÓû§²ÅÆøÍ¨¹ýÔ¶³Ì×ÀÃæÐ­Ò飨RDP£©Á¬½Óµ½·þÎñÆ÷¡£

2024Äê7ÔÂ10ÈÕ £¬¶¶È¦Îª¶Ä¶øÉú¼¯ÍÅVSRC¼à²âµ½Î¢Èí7ÔÂÄþ¾²¸üÐÂÐÞ¸´ÁËWindows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2024-38077 £¬±»³ÆÎª¡°MadLicense¡±£© £¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8¡£

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖдæÔÚ¶Ñ»º³åÇøÒç³ö©¶´ £¬ÓÉÓÚÔÚ½âÂëÓû§ÊäÈëµÄÐí¿ÉÃÜÔ¿°üʱȱ·¦ÕýÈ·µÄ»º³åÇø¾Þϸ¼ì²é £¬µ¼Ö½âÂëºó·ºÆð»º³åÇøÒç³ö £¬µ±Windows Server¿ªÆôÔ¶³Ì×ÀÃæÊÚȨ·þÎñ£¨·ÇĬÈÏÆôÓã©Ê± £¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕ߿ɷ¢ËͶñÒâÏûÏ¢ÀûÓøÃ©¶´ £¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

 

¶þ¡¢Ó°Ï췶Χ

Windows Server 2012 R2 (Server Core installation)

Windows Server 2012 R2

Windows Server 2012 (Server Core installation)

Windows Server 2012

Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server 2016 (Server Core installation)

Windows Server 2016

Windows Server 2022, 23H2 Edition (Server Core installation)

Windows Server 2022 (Server Core installation)

Windows Server 2022

Windows Server 2019 (Server Core installation)

Windows Server 2019


Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Á˸é¶´µÄÄþ¾²¸üР£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓà £¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ £¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü £¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡± £¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС± £¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС± £¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú £¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üР£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó £¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡± £¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-38077

3.2 ÁÙʱ´ëÊ©

¸Ã©¶´»áÓ°ÏìÆôÓÃÁËWindows Remote Desktop Licensing ServiceµÄWindows Server £¬Windows PC²»ÊÜÓ°Ïì¡£

1.ĬÈÏÇé¿öÏ £¬Windows Server ²»»á°²×° Remote Desktop Licensing ·þÎñ £¬¿Éͨ¹ýÑéÖ¤Remote Desktop Licensing·þÎñÊÇ·ñÆô¶¯ £¬Ïà¹Ø²¹¶¡ÊÇ·ñδ°²×°À´ÅжÏÊÇ·ñÒ×Êܸé¶´Ó°Ïì¡£

Èç·ÇÐëÒª £¬¿É½ûÓÃRemote Desktop Licensing·þÎñ×÷Ϊ»º½â´ëÊ© £¬µ«Õâ¿ÉÄÜ»áÓ°ÏìÔ¶³Ì×ÀÃæÄ³Ð©¹¦Ð§(¿ÉÄܲ»»áÖ±½Óµ¼ÖÂRDPÁ¬½Óʧ°Ü £¬µ«ÓÉÓÚÊÚȨÑéÖ¤µÄȱʧ £¬¿ÉÄÜ»áÒý·¢ÆäËûÓëÊÚȨÏà¹ØµÄ´íÎó»òÎÊÌâ)¡£´ËÍâ £¬Microsoft½¨ÒéÊÜÓ°ÏìÓû§°²×°¸Ã©¶´µÄÄþ¾²¸üР£¬¼´Ê¹¼Æ»®½ûÓÃRemote Desktop Licensing·þÎñ¡£

2.´ËÍâ £¬¿Éͨ¹ý¼ì²ìlserver.dll£¨Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÆ÷µÄÒ»¸öÒªº¦×é¼þ £¬Í¨³£Î»ÓÚC:\Windows\System32\lserver.dll£©Îļþ°æ±¾ £¬²Î¿¼Ï±íÈ·¶¨ÊÇ·ñΪÒ×Êܹ¥»÷°æ±¾ £¬¿ÉʹÓÃÒÔ϶àÖÖ·½Ê½¼ì²ì¸ÃÎļþ°æ±¾£º

l  ÎļþÊôÐÔ¼ì²ì £¬ÕÒµ½C:\Windows\System32\lserver.dll £¬ÓÒ¼üµã»÷ lserver.dll Îļþ £¬Ñ¡Ôñ¡°ÊôÐÔ¡± £¬ÔÚÊôÐÔ´°¿ÚÖÐ £¬µã»÷¡°ÏêϸÐÅÏ¢¡±Ñ¡Ï £¬ÔÚ¡°ÏêϸÐÅÏ¢¡±Ñ¡ÏÏ £¬¿É¿´µ½¡°Îļþ°æ±¾¡±ºÍ¡°²úÎï°æ±¾¡±ÐÅÏ¢¡£

l  ʹÓÃPowershell¼ì²ìÎļþ°æ±¾ £¬PowerShellÖÐÖ´ÐÐÒÔÏÂÃüÁ

(Get-Item "C:\Windows\System32\lserver.dll").VersionInfo

l  ÔÚCMD Öе÷ÓÃPowerShell ÃüÁîÀ´»ñÈ¡Îļþ°æ±¾ÐÅÏ¢£º

powershell -command "(Get-Item 'C:\\Windows\\System32\\lserver.dll').VersionInfo.FileVersion"

ÊÜÓ°Ïìϵͳ

ƽ̨

ÊÜÓ°Ïì°æ±¾

²»ÊÜÓ°Ïì°æ±¾

Windows Server 2019

x64-based Systems

10.0.0 - 10.0.17763.6054֮ǰ

10.0.17763.6054

Windows Server 2019 (Server Core installation)

x64-based Systems

10.0.0 -10.0.17763.6054֮ǰ

10.0.17763.6054

Windows Server 2022

x64-based Systems

10.0.0 -10.0.20348.2582֮ǰ

10.0.20348.2582

Windows Server 2022 £¬23H2 Edition (Server Core   installation)

x64-based Systems

10.0.0 - 10.0.25398.1009֮ǰ

10.0.25398.1009

Windows Server 2016

x64-based Systems

10.0.0 -10.0.14393.7159֮ǰ

10.0.14393.7159

Windows Server 2016 (Server Core installation)

x64-based Systems

10.0.0 -10.0.14393.7159֮ǰ

10.0.14393.7159

Windows Server 2008 Service Pack 2

32-bit Systems

6.0.0 - 6.0.6003.22769֮ǰ

6.0.6003.22769

Windows Server 2008 Service Pack 2 (Server Core   installation)

32-bit Systems¡¢x64-based Systems

6.0.0 - 6.0.6003.22769֮ǰ

6.0.6003.22769

Windows Server 2008 Service Pack 2

x64-based Systems

6.0.0 - 6.0.6003.22769֮ǰ

6.0.6003.22769

Windows Server 2008 R2 Service Pack 1

x64-based Systems

6.1.0 - 6.1.7601.27219֮ǰ

6.1.7601.27219

Windows Server 2008 R2 Service Pack 1 (Server   Core installation)

x64-based Systems

6.0.0 - 6.1.7601.27219֮ǰ

6.1.7601.27219

Windows Server 2012

x64-based Systems

6.2.0 - 6.2.9200.24975֮ǰ

6.2.9200.24975

Windows Server 2012 (Server Core installation)

x64-based Systems

6.2.0 - 6.2.9200.24975֮ǰ

6.2.9200.24975

Windows Server 2012 R2

x64-based Systems

6.3.0 - 6.3.9600.22074֮ǰ

6.3.9600.22074

Windows Server 2012 R2 (Server Core installation)

x64-based Systems

6.3.0 - 6.3.9600.22074֮ǰ

6.3.9600.22074

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡ £¬¼õÉÙϵͳ©¶´ £¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ £¬Ð޸ķÀ»ðǽ¼ÆÄ± £¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ £¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎï £¬ÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí £¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Jul

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-38077

https://sites.google.com/site/zhiniangpeng/blogs/MadLicense


 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-08-09

Ê×´ÎÐû²¼

V1.1

2024-08-09

¸üÐÂPoC״̬¡¢»º½â´ëÊ©µÈ

 


Îå¡¢¸½Â¼

5.1 ¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Äê £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏà £¬¹«Ë¾Ô±¹¤6000ÓàÈË £¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ £¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯ £¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´ £¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png