Windows CVE-2019-0708 远程桌面代码执行漏洞复现
时间:2023年06月11日
/来源:网络
/编辑:佚名
一、漏洞说明
2019年5月15日微软发布安全补丁修复了CVE编号为CVE-2019-0708的Windows远程桌面服务(RDP)远程代码执行漏洞,该漏洞在不需身份认证的情况下即可远程触发,危害与影响面极大。
目前,9月7日EXP代码已被公开发布至metasploit-framework的Pull requests中,经测试已经可以远程代码执行。
二、漏洞影响版本
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for Itanium-Based Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows XP SP3 x86
Windows XP Professional x64 Edition SP2
Windows XP Embedded SP3 x86
Windows Server 2003 SP2 x86
Windows Server 2003 x64 Edition SP2
注:Windows 8和windows10以及之后的版本不受此漏洞影响
三、漏洞环境搭建
攻击机:kali 2018.2
靶机:win7 sp1 7061
data:image/s3,"s3://crabby-images/214e3/214e3f25a03c98fb89c4907c9e4993d0bc777f98" alt=""
四、漏洞复现
1、更新msf
apt-get update
apt-get install metasploit-framework
data:image/s3,"s3://crabby-images/67d2a/67d2ac9eb3de98531cba578a741e4639692c7176" alt=""
2、下载攻击套件
wget https://raw.githubusercontent.com/rapid7/metasploit-framework/edb7e20221e2088497d1f61132db3a56f81b8ce9/lib/msf/core/exploit/rdp.rb
wget https://github.com/rapid7/metasploit-framework/raw/edb7e20221e2088497d1f61132db3a56f81b8ce9/modules/auxiliary/scanner/rdp/rdp_scanner.rb
wget https://github.com/rapid7/metasploit-framework/raw/edb7e20221e2088497d1f61132db3a56f81b8ce9/modules/exploits/windows/rdp/cve_2019_0708_bluekeep_rce.rb
wget https://github.com/rapid7/metasploit-framework/raw/edb7e20221e2088497d1f61132db3a56f81b8ce9/modules/auxiliary/scanner/rdp/cve_2019_0708_bluekeep.rb
3、替换msf中相应的文件
复制代码
cve_2019_0708_bluekeep_rce.rb 添加 /usr/share/metasploit-framework/modules/exploits/windows/rdp/cve_2019_0708_bluekeep_rce.rb
rdp.rb 替换 /usr/share/metasploit-framework/lib/msf/core/exploit/rdp.rb
rdp_scanner.rb 替换 /usr/share//metasploit-framework/modules/auxiliary/scanner/rdp/rdp_scanner.rb
cve_2019_0708_bluekeep.rb 替换 /usr/share/metasploit-framework/modules/auxiliary/scanner/rdp/cve_2019_0708_bluekeep.rb
复制代码
4、启动msf,加载文件
data:image/s3,"s3://crabby-images/96271/962719fc1cd100fcb9f453e4e64f714578abe04f" alt=""
5、搜索0708,可以看到文件成功加载
data:image/s3,"s3://crabby-images/b55f7/b55f7e77b24666776716b38cd0ccc7e74ac838f9" alt=""
6、利用漏洞,设置rhosts、target、payload
data:image/s3,"s3://crabby-images/408fe/408fe1f8c65c4e3c068e78735c1268f435663a4d" alt=""
data:image/s3,"s3://crabby-images/8c602/8c6022d63e58a06d51872aed05d7b40f22fef3a3" alt=""
data:image/s3,"s3://crabby-images/903aa/903aa9f54918b0c90f43a9b86e76184590aac2b2" alt=""
data:image/s3,"s3://crabby-images/fd0da/fd0daeaf44559b10540d8a70aa7257650289f6a5" alt=""
7、开始执行exp,成功获得shell
data:image/s3,"s3://crabby-images/a01f2/a01f2c8882529af9ccb1e5eeea1d1d64004b2ad0" alt=""
data:image/s3,"s3://crabby-images/1a17d/1a17d0861d38e989a335a81ac5bd83fc38f72dc5" alt=""
五、漏洞防御
1、热补丁修复工具下载,下载地址: https://www.qianxin.com/other/CVE-2019-0708
注: CVE-2019-0708热补丁工具”是针对“Windows远程桌面服务的远程代码执行漏洞CVE-2019-0708”推出的热补丁修复工具,可以针对不能直接打补丁环境,提供的临时解决漏洞问题的方案。
1、 下载文件进行解压。
2、 使用win+R快捷键或开始菜单选择“运行”,输入cmd。调起命令行工具。
3、 在命令行工具,执行命令到工具所在文件夹
4、 输入命令对应功能,启用热补丁命令:QKShield.exe /enable ;禁用热补丁命令:QKShield.exe/disable 。
5、 重启系统后,需要重新运行命令行来启用热补丁
2、启用热补丁
data:image/s3,"s3://crabby-images/3ad5c/3ad5c63ba11fa5c2928303941d6fd97a5dabe182" alt=""
3、再次检测是否存在漏洞,可以看到打完热补丁之后,不存在漏洞了
data:image/s3,"s3://crabby-images/03cff/03cff4b2b7999c86dea9c776bef862c081d7955d" alt=""
4、打补丁,漏洞修复工具下载,下载地址: https://www.qianxin.com/other/CVE-2019-0708
data:image/s3,"s3://crabby-images/5e130/5e1300b85600958945f79bc05334f2c610089dca" alt=""
5、点击”立即修复”,完成安装之后,重启电脑
data:image/s3,"s3://crabby-images/364d2/364d212b787fc152fdf496fed9a8f62a3d820c9b" alt=""
data:image/s3,"s3://crabby-images/90eea/90eeae18a671161ac965046d73a0e6b472f0d041" alt=""
6、使用漏洞扫描工具检测是否存在漏洞,扫描工具下载地址: https://www.qianxin.com/other/CVE-2019-0708
data:image/s3,"s3://crabby-images/03dd4/03dd4aec674c62ee73922de1e3c6cdec5865182f" alt=""
7、 官方补丁:https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
8、临时措施
1、若用户不需要用到远程桌面服务,建议禁用该服务。
2、开启网络级别身份验证(NLA),此方案适用于Windows 7, Windows Server 2008, Windows Server 2008 R2。
data:image/s3,"s3://crabby-images/3544d/3544daf61337191c732d696b4499a24507d810c3" alt=""
9、开启"网络级别身份验证"之后,再次漏洞扫描,发现不存在漏洞
data:image/s3,"s3://crabby-images/4a383/4a383457c0ba7e2b3f03a8c74519969abec536b8" alt=""
官方补丁:https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
2019年5月15日微软发布安全补丁修复了CVE编号为CVE-2019-0708的Windows远程桌面服务(RDP)远程代码执行漏洞,该漏洞在不需身份认证的情况下即可远程触发,危害与影响面极大。
目前,9月7日EXP代码已被公开发布至metasploit-framework的Pull requests中,经测试已经可以远程代码执行。
二、漏洞影响版本
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for Itanium-Based Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows XP SP3 x86
Windows XP Professional x64 Edition SP2
Windows XP Embedded SP3 x86
Windows Server 2003 SP2 x86
Windows Server 2003 x64 Edition SP2
注:Windows 8和windows10以及之后的版本不受此漏洞影响
三、漏洞环境搭建
攻击机:kali 2018.2
靶机:win7 sp1 7061
data:image/s3,"s3://crabby-images/214e3/214e3f25a03c98fb89c4907c9e4993d0bc777f98" alt=""
四、漏洞复现
1、更新msf
apt-get update
apt-get install metasploit-framework
data:image/s3,"s3://crabby-images/67d2a/67d2ac9eb3de98531cba578a741e4639692c7176" alt=""
2、下载攻击套件
wget https://raw.githubusercontent.com/rapid7/metasploit-framework/edb7e20221e2088497d1f61132db3a56f81b8ce9/lib/msf/core/exploit/rdp.rb
wget https://github.com/rapid7/metasploit-framework/raw/edb7e20221e2088497d1f61132db3a56f81b8ce9/modules/auxiliary/scanner/rdp/rdp_scanner.rb
wget https://github.com/rapid7/metasploit-framework/raw/edb7e20221e2088497d1f61132db3a56f81b8ce9/modules/exploits/windows/rdp/cve_2019_0708_bluekeep_rce.rb
wget https://github.com/rapid7/metasploit-framework/raw/edb7e20221e2088497d1f61132db3a56f81b8ce9/modules/auxiliary/scanner/rdp/cve_2019_0708_bluekeep.rb
3、替换msf中相应的文件
复制代码
cve_2019_0708_bluekeep_rce.rb 添加 /usr/share/metasploit-framework/modules/exploits/windows/rdp/cve_2019_0708_bluekeep_rce.rb
rdp.rb 替换 /usr/share/metasploit-framework/lib/msf/core/exploit/rdp.rb
rdp_scanner.rb 替换 /usr/share//metasploit-framework/modules/auxiliary/scanner/rdp/rdp_scanner.rb
cve_2019_0708_bluekeep.rb 替换 /usr/share/metasploit-framework/modules/auxiliary/scanner/rdp/cve_2019_0708_bluekeep.rb
复制代码
4、启动msf,加载文件
data:image/s3,"s3://crabby-images/96271/962719fc1cd100fcb9f453e4e64f714578abe04f" alt=""
5、搜索0708,可以看到文件成功加载
data:image/s3,"s3://crabby-images/b55f7/b55f7e77b24666776716b38cd0ccc7e74ac838f9" alt=""
6、利用漏洞,设置rhosts、target、payload
data:image/s3,"s3://crabby-images/408fe/408fe1f8c65c4e3c068e78735c1268f435663a4d" alt=""
data:image/s3,"s3://crabby-images/8c602/8c6022d63e58a06d51872aed05d7b40f22fef3a3" alt=""
data:image/s3,"s3://crabby-images/903aa/903aa9f54918b0c90f43a9b86e76184590aac2b2" alt=""
data:image/s3,"s3://crabby-images/fd0da/fd0daeaf44559b10540d8a70aa7257650289f6a5" alt=""
7、开始执行exp,成功获得shell
data:image/s3,"s3://crabby-images/a01f2/a01f2c8882529af9ccb1e5eeea1d1d64004b2ad0" alt=""
data:image/s3,"s3://crabby-images/1a17d/1a17d0861d38e989a335a81ac5bd83fc38f72dc5" alt=""
五、漏洞防御
1、热补丁修复工具下载,下载地址: https://www.qianxin.com/other/CVE-2019-0708
注: CVE-2019-0708热补丁工具”是针对“Windows远程桌面服务的远程代码执行漏洞CVE-2019-0708”推出的热补丁修复工具,可以针对不能直接打补丁环境,提供的临时解决漏洞问题的方案。
1、 下载文件进行解压。
2、 使用win+R快捷键或开始菜单选择“运行”,输入cmd。调起命令行工具。
3、 在命令行工具,执行命令到工具所在文件夹
4、 输入命令对应功能,启用热补丁命令:QKShield.exe /enable ;禁用热补丁命令:QKShield.exe/disable 。
5、 重启系统后,需要重新运行命令行来启用热补丁
2、启用热补丁
data:image/s3,"s3://crabby-images/3ad5c/3ad5c63ba11fa5c2928303941d6fd97a5dabe182" alt=""
3、再次检测是否存在漏洞,可以看到打完热补丁之后,不存在漏洞了
data:image/s3,"s3://crabby-images/03cff/03cff4b2b7999c86dea9c776bef862c081d7955d" alt=""
4、打补丁,漏洞修复工具下载,下载地址: https://www.qianxin.com/other/CVE-2019-0708
data:image/s3,"s3://crabby-images/5e130/5e1300b85600958945f79bc05334f2c610089dca" alt=""
5、点击”立即修复”,完成安装之后,重启电脑
data:image/s3,"s3://crabby-images/364d2/364d212b787fc152fdf496fed9a8f62a3d820c9b" alt=""
data:image/s3,"s3://crabby-images/90eea/90eeae18a671161ac965046d73a0e6b472f0d041" alt=""
6、使用漏洞扫描工具检测是否存在漏洞,扫描工具下载地址: https://www.qianxin.com/other/CVE-2019-0708
data:image/s3,"s3://crabby-images/03dd4/03dd4aec674c62ee73922de1e3c6cdec5865182f" alt=""
7、 官方补丁:https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
8、临时措施
1、若用户不需要用到远程桌面服务,建议禁用该服务。
2、开启网络级别身份验证(NLA),此方案适用于Windows 7, Windows Server 2008, Windows Server 2008 R2。
data:image/s3,"s3://crabby-images/3544d/3544daf61337191c732d696b4499a24507d810c3" alt=""
9、开启"网络级别身份验证"之后,再次漏洞扫描,发现不存在漏洞
data:image/s3,"s3://crabby-images/4a383/4a383457c0ba7e2b3f03a8c74519969abec536b8" alt=""
官方补丁:https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
新闻资讯 更多