¡¾Â©¶´Í¨¸æ¡¿SolarWinds Serv-U Ô¶³Ì´úÂëÖ´ÐÐ0 day©¶´£¨CVE-2021-35211£©

Ðû²¼Ê±¼ä 2021-07-13

0x00 ©¶´¸ÅÊö

CVE     ID

CVE-2021-35211

ʱ      ¼ä

2021-07-13

Àà     ÐÍ

RCE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ

 < 15.2.3 HF2

¹¥»÷ÅÓ´ó¶È


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP


ÔÚÒ°ÀûÓÃ

ÊÇ

 

0x01 ©¶´ÏêÇé

image.png

2021Äê7ÔÂ9ÈÕ£¬SolarWindsÐû²¼Äþ¾²Í¨¸æ£¬MicrosoftÔÚÆäServ-U²úÎïÖз¢ÏÖÁËÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐ0 day©¶´£¨CVE-2021-35211£©£¬ÀÖ³ÉÀûÓôË©¶´µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÒÔÌØÊâȨÏÞÖ´ÐÐÈÎÒâ´úÂ룬ȻºóÔÚÊÜÓ°ÏìµÄϵͳÉϰ²×°²¢ÔËÐз¨Ê½¡¢¼ì²ì¡¢¸ü¸Ä»òɾ³ýÊý¾ÝµÈ¡£Ä¿Ç°¸Ã©¶´ÒѾ­·ºÆðÔÚÒ°ÀûÓá£

¸Ã©¶´½ö´æÔÚÓÚSolarWinds Serv-U Managed File TransferºÍServ-U Secure FTPÖУ¬ÆäËü SolarWinds ²úÎï²»ÊÜÓ°Ï죬²»Ê¹Óà Serv-U µÄ N-able ¿Í»§Ò²²»ÊÜ´Ë©¶´µÄÓ°Ïì¡£µ«ÐèҪעÒâµÄÊÇ£¬Serv-U GatewayÊÇÕâÁ½¸ö²úÎïµÄÒ»¸ö×é¼þ£¬¶ø²»ÊÇÒ»¸öµ¥¶ÀµÄ²úÎï¡£

´ËÍ⣬¾ÝSolarWindsÌåÏÖ£¬Èç¹ûServ-U »·¾³ÖÐδÆôÓà SSH£¬Ôò¸Ã©¶´²»´æÔÚ¡£

 

Ó°Ï췶Χ

Serv-U °æ±¾ < 15.2.3 HF2

 

0x02 ´¦Öý¨Òé

Ŀǰ´Ë©¶´ÒÑÔÚ2021 Äê 7 Ô 9 ÈÕÐû²¼µÄServ-U 15.2.3 HF2ÖÐÐÞ¸´£¬½¨ÒéËùÓÐÊÜÓ°ÏìµÄServ-U ¿Í»§²Î¿¼ÒÔÏ·½Ê½¼°Ê±Éý¼¶¸üУº

Serv-U 15.2.3 HF1°æ±¾£ºÖ±½ÓÉý¼¶¸üÐÂÖÁServ-U 15.2.3 HF2 £»

Serv-U 15.2.3°æ±¾£ºÏÈÉý¼¶¸üÐÂÖÁServ-U 15.2.3 HF1 £¬È»ºóÔÙÉý¼¶¸üÐÂÖÁServ-U 15.2.3 HF2 £»

15.2.3 ֮ǰµÄËùÓÐServ-U °æ±¾£ºÏÈÉý¼¶¸üÐÂÖÁServ-U 15.2.3 £¬ÔÙÉý¼¶¸üÐÂÖÁServ-U 15.2.3 HF1 £¬È»ºóÔÙÉý¼¶¸üÐÂÖÁ Serv-U 15.2.3 HF2 ¡£

 

ÏÂÔØÁ´½Ó£º

https://www.serv-u.com/

 

0x03 ²Î¿¼Á´½Ó

https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35211

https://www.bleepingcomputer.com/news/security/solarwinds-patches-critical-serv-u-vulnerability-exploited-in-the-wild/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-35211

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-07-13

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD¹ÙÍø£ºwww.cnvd.org.cn

CNNVD¹ÙÍø£ºwww.cnnvd.org.cn

CVE¹ÙÍø£ºcve.mitre.org

NVD¹ÙÍø£ºnvd.nist.gov

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºwww.first.org

 

 

0x06 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png         image.png