¡¾Â©¶´Í¨¸æ¡¿Windows Active Directory Óò·þÎñȨÏÞÌáÉý©¶´£¨CVE-2021-42278£©
Ðû²¼Ê±¼ä 2021-12-210x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-42278 | ʱ ¼ä | 2021-11-09 |
Àà ÐÍ | ȨÏÞÌáÉý | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | |
¹¥»÷ÅÓ´ó¶È | ¸ß | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | µÍ |
PoC/EXP | ÒѹûÈ» | ÔÚÒ°ÀûÓà |
0x01 ©¶´ÏêÇé
2021Äê12ÔÂ20ÈÕ£¬Î¢ÈíÅû¶ÁËWindows Active Directory Óò·þÎñȨÏÞÌáÉý©¶´£¨CVE-2021-42287ºÍCVE-2021-42278£©µÄ©¶´Ï¸½Ú£¬²¢¾¯¸æ¿Í»§¼°Ê±ÐÞ¸´Õâ2¸ö©¶´¡£µ±½áºÏÕâ2¸ö©¶´Ê±£¬¹¥»÷Õß¿ÉÒÔÔÚûÓÐÓ¦Óò¹¶¡µÄ Active Directory »·¾³Öд´½¨Ò»¸öÖ±½Ó·ÃÎÊÓò¹ÜÀíÔ±Óû§µÄ·¾¶£¬ÔÚ¹¥»÷ÓòÖÐµÄÆÕͨÓû§ºóÇáËɽ«ÆäȨÏÞÌáÉýΪÓò¹ÜÀíԱȨÏÞ£¬×îÖÕ½Ó¹ÜWindowsÓò¡£
Õâ2¸ö©¶´¶¼ÊÇ΢Èí11ÔÂ9ÈÕ²¹¶¡ÈÕÖÐÐÞ¸´µÄ£¬CVSSÆÀ·Ö¾ùΪ7.5¡£ÆäÖÐCVE-2021-42278ÊÇÒ»¸öÄþ¾²Èƹý©¶´£¬¸Ã©¶´ÔÊÐí¹¥»÷ÕßʹÓüÆËã»úÕÊ»§sAMAccountNameÆÛÆÀ´Ã°³äÓò¿ØÖÆÆ÷£¨SAMÃû³ÆÄ£Ä⣩¡£CVE-2021-42287ÊÇÓ°ÏìKerberosÌØÈ¨ÊôÐÔÖ¤Ê飨PAC£©µÄÄþ¾²Èƹý©¶´£¬ÔÊÐí¹¥»÷Õßð³äÓò¿ØÖÆÆ÷£¨KDCÆÛÆ£©¡£
12 Ô 11 ÈÕ£¬Õâ2¸ö©¶´µÄϸ½ÚºÍPoC/EXPÒÑÔÚ»¥ÁªÍøÉϹûÈ»¡£¾¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔ½áºÏÕâ2¸ö©¶´ÔÚĬÈÏÅäÖõÄÇé¿öϽ«ÆÕͨȨÏÞÌáÉýµ½Óò¹ÜÀíԱȨÏÞ¡£
Ó°Ï췶Χ
CVE-2021-42287¡¢CVE-2021-42278£º
Windows Server, version 20H2 (Server Core Installation)
Windows Server, version 2004 (Server Core installation)
Windows Server 2022 (Server Core installation)
Windows Server 2022
Windows Server 2019 (Server Core installation)
Windows Server 2019
Windows Server 2016 (Server Core installation)
Windows Server 2016
Windows Server 2012 R2 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server Core installation)
Windows Server 2012
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
0x02 ´¦Öý¨Òé
ĿǰÕâЩ©¶´ÒÑÔÚ΢Èí11ÔÂ9ÈÕÐû²¼µÄÄþ¾²¸üÐÂÖÐÐÞ¸´£¬½¨ÒéÆôÓÃWindows×Ô¶¯¸üлòÊÖ¶¯ÏÂÔØ°²×°²¹¶¡¡£
ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287
´ËÍ⣬΢Èí»¹·ÖÏíÁËÕâ2¸ö©¶´µÄÀûÓüì²â·Ö²½Ö¸ÄÏ£º
1.sAMAccountName ¸ü¸Ä»ùÓÚʼþ 4662£¬ÇëÈ·±£ÔÚÓò¿ØÖÆÆ÷ÉÏÆôÓÃËüÒÔ²¶×½´ËÀà»î¶¯¡£
2. ´ò¿ª Microsoft 365 Defender ²¢µ¼º½µ½Advanced Hunting¡£
3.¸´ÖÆÒÔϲéѯ£¨Ò²¿ÉÔÚ Microsoft 365 Defender GitHub¸ß¼¶á÷ÁÔ²éѯÖÐÕÒµ½£©£¬²éÕÒÒì³£É豸Ãû³Æ¸ü¸Ä£º
IdentityDirectoryEvents
| where Timestamp > ago(1d)
| where ActionType == "SAM Account Name changed"
| extend FROMSAM = parse_json(AdditionalFields)['FROM SAM Account Name']
| extend TOSAM = parse_json(AdditionalFields)['TO SAM Account Name']
| where (FROMSAM has "$" and TOSAM !has "$")
or TOSAM in ("DC1", "DC2", "DC3", "DC4") // DC Names in the org
| project Timestamp, Application, ActionType, TargetDeviceName, FROMSAM, TOSAM, ReportId, AdditionalFields
4.ÓÃÓò¿ØÖÆÆ÷µÄÃüÃûÔ¼¶¨Ìæ»»±êÖ¾ÇøÓò
5.ÔËÐвéѯ²¢·ÖÎö°üÂÞÊÜÓ°ÏìÉ豸µÄ½á¹û¡£¿ÉÒÔʹÓÃWindows ʼþ 4741²éÕÒÕâЩ¼ÆËã»úµÄ´´½¨Õߣ¨Èç¹ûËüÃÇÊÇд´½¨µÄ£©¡£
6.½¨ÒéÊÓ²ìÕâЩ±»Ñ¬È¾µÄ¼ÆËã»ú²¢È·¶¨ËüÃÇûÓб»ÎäÆ÷»¯¡£
7.È·±£Ê¹ÓÃÒÔÏÂ֪ʶ¿âÎÄÕÂÖÐÏêÊöµÄ²½ÖèºÍÐÅÏ¢¸üÐÂÔâÊܹ¥»÷µÄÉ豸£ºKB5008102¡¢KB5008380¡¢KB5008602¡£
0x03 ²Î¿¼Á´½Ó
https://techcommunity.microsoft.com/t5/security-compliance-and-identity/sam-name-impersonation/ba-p/3042699
https://twitter.com/safe_buffer/status/1469742616505954323
https://support.microsoft.com/en-us/topic/kb5008102-active-directory-security-accounts-manager-hardening-changes-cve-2021-42278-5975b463-4c95-45e1-831a-d120004e258e
https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-easy-windows-domain-takeover-via-active-directory-bugs/
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-12-21 | Ê×´ÎÐû²¼ |
0x05 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¶¶È¦Îª¶Ä¶øÉú¼ò½é
¶¶È¦Îª¶Ä¶øÉú¹«Ë¾½¨Á¢ÓÚ1996Ä꣬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎïºÍÄþ¾²¹ÜÀíÆ½Ì¨¡¢Äþ¾²·þÎñÓë½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ£»²¢ÔÚ»ª±±¡¢»ª¶«¡¢Î÷ÄϺͻªÄϽṹËÄ´óÑз¢ÖÐÐÄ£¬·Ö±ðΪ±±¾©Ñз¢×ܲ¿¡¢ÉϺ£Ñз¢ÖÐÐÄ¡¢³É¶¼Ñз¢ÖÐÐĺ͹ãÖÝÑз¢ÖÐÐÄ¡£
¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£
¹Ø×¢ÒÔϹ«Öںţ¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º