Windows PowerShellÔ¶³Ì´úÂëÖ´ÐЩ¶´

Ðû²¼Ê±¼ä 2021-07-04

0x00 ©¶´¸ÅÊö

CVE     ID


ʱ      ¼ä

2021-07-04

Àà      ÐÍ

RCE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


¹¥»÷ÅÓ´ó¶È


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP


ÔÚÒ°ÀûÓÃ


 

0x01 ©¶´ÏêÇé

image.png

 

PowerShellÌṩÁËÒ»¸öÃüÁîÐÐshell¡¢Ò»¸ö¿ò¼ÜºÍÒ»Öֽű¾ÓïÑÔ£¬×¨×¢ÓÚ´¦Öà PowerShell cmdlet µÄ×Ô¶¯»¯ ¡£Ëü¿ÉÒÔÔÚ Windows¡¢Linux ºÍ macOSµÈƽ̨ÉÏÔËÐУ¬¶øÇÒÔÊÐí´¦Öýṹ»¯Êý¾Ý£¬ÀýÈç JSON¡¢CSV ºÍ XML£¬ÒÔ¼° REST API ºÍ¹¤¾ßÄ£ÐÍ ¡£

½üÈÕ£¬Microsoft ¾¯¸æ PowerShell 7 ÖÐÑÏÖØµÄ .NET Core Ô¶³Ì´úÂëÖ´ÐЩ¶´£¬Ô­ÒòÔÚÓÚ.NET 5 ºÍ .NET Core ÖеÄÎı¾±àÂ뷽ʽ ¡£Microsoft¶Ø´Ù¿Í»§¾¡¿ì°²×°PowerShell 7.0.6 ºÍ 7.1.3  ¡£

MicrosoftÔÚ4 Ô·ÝʱÌåÏÖ£¬Ò×Êܹ¥»÷µÄ°üÊÇSystem.Text.Encodings.Web£¬ÈκÎʹÓÃÏÂÃæÁгöµÄ System.Text.Encodings.Web °ü°æ±¾µÄ»ùÓÚ .NET 5¡¢.NET Core »ò .NET Framework µÄÓ¦Ó÷¨Ê½¶¼ÈÝÒ×Êܵ½¹¥»÷£º

°üÃû³Æ

Ò×Êܹ¥»÷µÄ°æ±¾

ÐÞ¸´°æ±¾

System.Text.Encodings.Web

4.0.0 -   4.5.0

4.5.1

System.Text.Encodings.Web

4.6.0-4.7.1

4.7.2

System.Text.Encodings.Web

5.0.0

5.0.1

 

ƾ¾ÝMicrosoftµÄ×îÐÂÄþ¾²Í¨¸æ£¬ËäÈ» Visual Studio Ò²°üÂÞ .NET µÄ¶þ½øÖÆÎļþ£¬µ«Ëü²»Êܵ½´Ë©¶´µÄÓ°Ïì ¡£´ËÍ⣬MicrosoftÐû²¼£¬Ëü½«Í¨¹ý Microsoft Update ·þÎñÐû²¼Ö®ºóµÄ¸üУ¬ÒÔ±ã¸üÇáËɵظüÐÂWindows 10 ºÍ Windows Server ÉϵÄPowerShell ¡£

 

Ó°Ï췶Χ

PowerShell < 7.0.6

PowerShell < 7.1.3

PowerShell 5.1²»ÊÜ´Ë©¶´µÄÓ°Ïì ¡£

0x02 ´¦Öý¨Òé

MicrosoftÌåÏÖĿǰ´Ë©¶´Ã»ÓпÉÓõĻº½â´ëÊ©£¬½¨Ò龡¿ì°²×°¸üе½ PowerShell 7.0.6 ºÍ 7.1.3 °æ±¾ ¡£

Ҫͨ¹ý Microsoft Update ¸üРPowerShell£º

 ¡°¿ªÊ¼¡± > ¡°ÉèÖá± >¡°¸üкÍÄþ¾²¡±>¡°Windows ¸üС±£¬È»ºóµ¥»÷¡°¼ì²é¸üС± ¡£

ÏÂÔØÁ´½Ó£º

https://azure.microsoft.com/en-us/updates/update-powershell-versions-70-and-71-to-protect-against-a-vulnerability/

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26701

https://azure.microsoft.com/en-us/updates/update-powershell-versions-70-and-71-to-protect-against-a-vulnerability/

https://www.bleepingcomputer.com/news/security/microsoft-warns-of-critical-powershell-7-code-execution-vulnerability/?

 

0x04 ʱ¼äÏß

2021-07-01  MicrosoftÄþ¾²¸üÐÂ

2021-07-04  VSRCÄþ¾²Í¨¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png