Windows TCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐЩ¶´À´Ï®£¡¶¶È¦Îª¶Ä¶øÉúÌṩ½â¾ö·½°¸
Ðû²¼Ê±¼ä 2024-08-20Windows ÊÇÓÉ΢Èí¹«Ë¾¿ª·¢µÄһϵÁÐͼÐÎÓû§½çÃæ²Ù×÷ϵͳ¡£×Ô 1985 ÄêÊ×´ÎÐû²¼ÒÔÀ´£¬Windows ÒѾ¾ÀúÁ˶à¸ö°æ±¾ºÍÖØ´ó¸üУ¬³ÉΪȫÇòʹÓÃ×î¹ã·ºµÄ²Ù×÷ϵͳ֮һ¡£
½üÈÕ£¬¶¶È¦Îª¶Ä¶øÉú¼à²âµ½Î¢ÈíÔÚ°ËÔ·ÝÄþ¾²²¹¶¡ÖÐÐÞ¸´ÁËÒ»¸öÓ°ÏìWindows TCP/IPÐÒéÕ»µÄÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£¸Ã©¶´CVSSÆÀ·ÖΪ9.8£¬¶øÇÒ±»Î¢Èí¹Ù·½±ê־ΪExploitation More Likely(¸ß¿ÉÄÜÐÔÀûÓÃ)¡£
¾¹ýÑо¿È·ÈÏ£¬¸Ã©¶´ÊÇÓÉÓÚWindowsµÄTCP/IP×é¼þ´íÎóµÄ´¦ÖÃÁËIPv6Êý¾Ý£¬´Ó¶øÔÚºóÐøµÄÁ÷³ÌÖе¼ÖÂÁËÕûÊýÒç³ö¡£¹¥»÷Õß¿ÉÒÔÔÚδ¾Éí·ÝÑéÖ¤µÄÇé¿öÏ£¬Í¨¹ýÏòÊܺ¦ÕßÖظ´·¢ËÍÌض¨½á¹¹µÄIPv6Êý¾Ý°üÀ´´¥·¢Â©¶´£¬´Ó¶øÔì³ÉÀ¶ÆÁËÀ»ú(BSOD)ÉõÖÁ´úÂëÖ´ÐС£
¸Ã©¶´ÀûÓÃÎ޸У¬Ö»ÐèÄ¿µÄÖ÷»úÆôÓÃIPv6ÐÒé¼´¿É´¥·¢£¬¶øÇÒ¼¸ºõÓ°ÏìËùÓг£¼ûWindows°æ±¾¡£¿¼Âǵ½Windowsͨ³£Ä¬ÈÏÆôÓÃIPv6¹¦Ð§£¬½¨Òé¿Í»§»ý¼«×öºÃÅŲéºÍ·À»¤£¬¾¡¿ì°²×°¹Ù·½²¹¶¡£¬ÒÔ·À·¶Ç±ÔÚ·çÏÕ¡£
©¶´¸´ÏÖ
½â¾ö·½°¸
Ò»¡¢¹Ù·½ÐÞ¸´·½°¸
¹Ù·½ÒÑÐû²¼Äþ¾²¸üУ¬½¨Ò齫ÊÜÓ°ÏìµÄWindowsÉý¼¶ÖÁ×îа汾£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063
¶þ¡¢ÁÙʱÐÞ¸´·½°¸
ÔÚ²»Ó°ÏìÕý³£ÒµÎñµÄÇé¿öÏ£¬¿ÉÒÔÔÝʱ½«IPv6¹¦Ð§¹Ø±Õ¡£
Èý¡¢¶¶È¦Îª¶Ä¶øÉú½â¾ö·½°¸
1¡¢¶¶È¦Îª¶Ä¶øÉú¼ì²âÀà²úÎï·½°¸
£¨1£©¶¶È¦Îª¶Ä¶øÉú¡°ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡±Éý¼¶µ½20240819°æ±¾¼´¿ÉÖ§³Ö¼ì²â¸Ã©¶´¡£
£¨2£©¶¶È¦Îª¶Ä¶øÉú ¡°ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡± Éý¼¶µ½20240819°æ±¾¼´¿ÉÖ§³Ö¼ì²â¸Ã©¶´¡£
2¡¢¶¶È¦Îª¶Ä¶øÉú©ɨ²úÎï·½°¸
£¨1£©¡°¶¶È¦Îª¶Ä¶øÉúÌì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳ¡±6075°æ±¾Òѽô¼±Ðû²¼Õë¶Ô¸Ã©¶´µÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸Ã©¶´½øÐÐɨÃ裬Óû§Éý¼¶³ß¶È©¶´¿âºó¼´¿É¶Ô¸Ã©¶´½øÐÐɨÃ裺
6070°æ±¾Éý¼¶°üΪ607000582-607000583.vup£¬Éý¼¶°üÏÂÔصØÖ·£º
https://venustech.download.venuscloud.cn/£¨2£©¶¶È¦Îª¶Ä¶øÉúÌì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳ608XϵÁа汾Òѽô¼±Ðû²¼Õë¶Ô¸Ã©¶´µÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸Ã©¶´½øÐÐɨÃ裬Óû§Éý¼¶³ß¶È©¶´¿âºó¼´¿É¶Ô¸Ã©¶´½øÐÐɨÃ裺
6080°æ±¾Éý¼¶°üΪÖ÷»ú²å¼þ°ü6080000133-S6080000134.svs©ɨ²å¼þ°üÏÂÔصØÖ·£º
https://venustech.download.venuscloud.cn/3¡¢¶¶È¦Îª¶Ä¶øÉú×ʲúÓë´àÈõÐÔ¹ÜÀíƽ̨²úÎï·½°¸
¶¶È¦Îª¶Ä¶øÉú×ʲúÓë´àÈõÐÔ¹ÜÀíƽ̨ʵʱÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢£¬¶ÔÈë¿â×ʲú©¶´Windows TCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2024-38063£©½øÐйÜÀí¡£
4¡¢¶¶È¦Îª¶Ä¶øÉúÄþ¾²¹ÜÀíºÍ̬ÊƸÐ֪ƽ̨²úÎï·½°¸
Óû§¿ÉÒÔͨ¹ýÌ©ºÏÄþ¾²¹ÜÀíºÍ̬ÊƸÐ֪ƽ̨£¬½øÐйØÁª¼ÆıÅäÖ㬽áºÏʵ¼Ê»·¾³ÖÐϵͳÈÕÖ¾ºÍÄþ¾²É豸µÄ¸æ¾¯ÐÅÏ¢½øÐÐÁ¬Ðø¼à¿Ø£¬´Ó¶ø·¢ÏÖ¡°Windows TCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2024-38063£©¡±µÄ©¶´ÀûÓù¥»÷ÐÐΪ¡£
£¨1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬Í¨¹ý´àÈõÐÔ·¢ÏÖ¹¦Ð§Õë¶Ô¡°Windows TCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2024-38063£©¡±Â©¶´É¨ÃèÈÎÎñ£¬ÅŲé¹ÜÀíÍøÂçÖÐÊÜ´Ë©¶´Ó°ÏìµÄÖØÒª×ʲú¡£
£¨2£©Æ½Ì¨¡°¹ØÁª·ÖÎö¡±Ä£¿éÖУ¬Ìí¼Ó¡°L2_WindowsTCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐЩ¶´¡±£¬Í¨¹ý¶¶È¦Îª¶Ä¶øÉú¼ì²âÉ豸¡¢Ä¿±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬·¢ÏÖÍⲿ¹¥»÷ÐÐΪ£º
ͨ¹ý·ÖÎö¹æÔò×Ô¶¯½«"L2_WindowsTCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐЩ¶´"©¶´ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ìí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ß·çÏÕÁ¬½Ó¡±ÖУ¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓá£
£¨3£©Ìí¼Ó¡°L3_WindowsTCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐЩ¶´ÀûÓÃÀֳɡ±£¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ»ò°üÂÞ¡°L2_WindowsTCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐЩ¶´¡±£¬¹¥»÷½á¹û¼´ÊÇ¡°¹¥»÷Àֳɡ±£¬Ä¿µÄµØÖ·ÒýÓÃ×ʲú©¶´»òÔ´µØÖ·Æ¥ÅäÍþвÇ鱨£¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶȡ£
£¨4£©ATT&CK¹¥»÷Á´Ìõ·ÖÎöÓëSOAR´¦Öý¨Òé
ƾ¾Ý¶ÔCVE-2024-38063©¶´µÄ¹¥»÷ÀûÓùý³Ì½øÐзÖÎö£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍ¼¼Êõ½×¶Î£¬ÁýÕÖµÄTTP°üÂÞ£º
TA0001³õʼ·ÃÎÊ£ºT1190ÀûÓÃÃæÏò¹«ÖÚµÄÓ¦Ó÷¨Ê½
TA0002Ö´ÐУºT1059ÃüÁîºÍ½Å±¾½âÊÍÆ÷
ͨ¹ýÌ©ºÏÄþ¾²¹ÜÀíºÍ̬ÊƸÐ֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´¦ÖÃÄÜÁ¦£¬Õë¶Ô¸Ã©¶´ÀûÓõĸ澯ʼþ±àÅž籾£¬½øÐÐ×Ô¶¯»¯´¦Öá£