Õâ¸ö0day©¶´Òѱ»ÔÚÒ°ÀûÓà ¶«Éƽ̨Ìṩ¼ì²â·½°¸
Ðû²¼Ê±¼ä 2023-07-24²¶×½µÄµöÓãÎĵµ½çÃæ
¾ÝϤ£¬¸Ã©¶´ÎªÎ¢ÈíÓÚ7ÔÂÄþ¾²¸üÐÂÖÐÅû¶µÄOfficeºÍWindows HTMLÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬´æÔÚÓÚ¶à¸öWindowsϵͳºÍOffice²úÎïÖС£ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©ÒѼà²âµ½Â©¶´ÐÅÏ¢Åû¶ǰÒÑ·¢ÉúÔÚÒ°ÀûÓãºStorm-0978×éÖ¯£¨ÓÖ³ÆRomCom×éÖ¯£©ÔÚ¶Ô±±Ô¼·å»áµÄ¹¥»÷ÖУ¬ÀûÓø鶴ÖÆ×÷ÁËÒÔÎÚ¿ËÀ¼ÊÀ½ç´ó»áΪÖ÷ÌâµÄÓÕ¶üÎļþ£¬ÌᳫµöÓã¹¥»÷¡£
©¶´¹¥»÷Á÷³Ì
CVE-2023-36884©¶´ºËÐÄ˼·ÔÚÓÚÀûÓÃMicrosoft OfficeÎĵµOOXML¹æ·¶ÖпÉÌæ´ú¸ñʽ¿é£¨Alternative Format Chunk£©ÄÚǶ´øÓÐÆäËû¹¥»÷×é¼þµÄrtfÎĵµÍê³ÉOffice·ÀÓù»úÖÆÈƹý£¬¿ÉÒÔÅäºÏÆäËû©¶´ÊµÏÖÎÞ¸ÐÖª¡¢ÎÞ½»»¥µÄÔ¶³Ì´úÂëÖ´ÐС£
ÔçÆÚµöÓã¹¥»÷Ñù±¾Ö÷ҪʹÓÃCVE-2017-0199¡¢CVE-2021-40444¡¢CVE-2022-30190µÈÂ߼©¶´£¬ºóÐø¹¥»÷ÔغÉÔ¶³Ì»ñÈ¡£¬ÕûÌå¹¥»÷Á÷³Ì±ÈÁ¦ÅÓ´ó¡£
¶øÕâÁ½ÖÜÄÚ½Ðø²¶×½µ½µÄ¶àÊý¹¥»÷Ñù±¾£¬ÄÚǶµÄrtf¾ù½ÓÄÉÄ£°å»¯µÄCVE-2017-11882£¬À´Ö´ÐÐrtfͬʱÊͷŵÄPEÎļþ¡£
²¿ÃŲ¶×½Ñù±¾²»°üÂÞÓÕ¶üÐÅÏ¢£¬²¢´øÓÐеÄrtf»ìÏý¼¼ÇÉ£ºÀûÓÃrtfÎļþÖаüÂÞµÄole¹¤¾ß¹ý³Ì¶Ô16½øÖÆÊý¾ÝµÄ³¤¶ÈÏÞÖÆ£¬Ê¹¾²Ì¬½âÎö¹ý³ÌÊý¾Ý´í룬ÎÞ·¨¶ÔÆ뻹ÔÔÓÐole¹¤¾ß£¬¾ß±¸½ÏÇ¿µÄÃâɱÄÜÁ¦¡£
©¶´Î£º¦
ÔÚʵ¼ÊµöÓã¹¥»÷ÖУ¬¸Ã©¶´¿ÉÓÃÓÚÈƹýofficeÄþ¾²»úÖƼ°Ìṩһ²ãÃâɱ£¬ÎªÆäËûoffice³£ÓõöÓã¹¥»÷©¶´ÌṩÁ˱£»¤¿Ç£¬ÊµÏÖÁËÎÞ¸ÐÖª¡¢ÎÞ½»»¥µÄÔ¶³Ì´úÂëÖ´ÐУ¬´ó·ù½µµÍµöÓã¹¥»÷ÀûÓÃÃż÷£¬·Ç·¨Õ߿ɽÏΪÇáËɵؽ«ÔÓвâÊÔÓù¥»÷ÔغÉÌ滻ΪC2¹¤¾ß£¬ÐγɵöÓã¹¥»÷Èë¿Ú£¬Î£º¦¼«´ó£¬ÐèÒª×öºÃ·ÀÓù´ëÊ©¡£
¶«Éƽ̨¼ì²â·½°¸
1¡¢Îļþ»¹Ô¼ì²â
¸Ã©¶´ÅäºÏÆäËûoffice©¶´Ê¹Óã¬ÓÃÓÚµöÓãÓʼþ¹¥»÷¡£ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©½ÓÄÉË«Ïò¼ì²âÒýÇ棬¿É¶Ô°ÙÓàÖÖÎļþ½øÐл¹Ô£¬ÄÚÖÃɳÏ䣬¿É¶Ô³£¼û°ÙÓàÖÖÓʼþ¸½¼þ¸ñʽ½øÐл¹ÔºÍɳÏä¼ì²â£¬Í¬Ê±¾ß±¸ÌáÈ¡ÕýÎÄÃÜÂëÆƽâÄÜÁ¦£¬¿É×Ô¶¯Ê¹ÓÃÓʼþÕýÎÄÃÜÂ뱬ÆÆѹËõ°ü¸½¼þ£¬±¬ÆÆÀֳɺó¶Ô¸½¼þ¼°¸½¼þ×ÓÎļþ½øÐмì²â¡£
2¡¢ÐÐΪ¼ì²â
ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©ÄÚÖÃɳÏ䣬³ý¾²Ì¬¼ì²âÍ⣬»¹¿É¶ÔofficeÎļþ½øÐÐÐÐΪ¼ì²âºÍ©¶´ÀûÓüì²â¡£É³Ïä½ÓÄɵÚÈý´úÓ²¼þ·ÂÕæ¼¼Êõ£¬¿É¶Ô¶ñÒâÑù±¾½øÐÐÆÛÆ£¬Í¨¹ýofficeÎļþÖ´ÐÐÐÐΪ£¬À´Åж¨¶ñÒâÐÐΪ¡£
ÐÐΪ¼ì²â¸æ¾¯½çÃæ
3¡¢»º½â´ëÊ©
ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©ÒÑÖ§³ÖCVE-2023-36884©¶´ÀûÓüì²â£¬ÇëÓû§²»Òª´ò¿ªÀ´Àú²»Ã÷µÄofficeÎĵµ£¬ÒѲ¿ÊðTARÓû§¿É½«¿ÉÒÉÎĵµÀëÏßÉÏ´«µ½TARÉ豸¼ì²â¡£
µ±µØ»º½â´ëÊ©£º
¿ÉÅäÖÃÏà¹Ø×¢²á±íÏîÀ´×èÖ¹Ïà¹Ø©¶´±»ÀûÓÃ,²½ÖèÈçÏÂ:
н¨Ò»¸öÎı¾Îĵµ,ÊäÈëÈçÏÂÄÚÈݲ¢Éú´æ¡£
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet
Explorer\Main\FeatureControl\FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION]
"Excel.exe"=dword:00000001
"Graph.exe"=dword:00000001
"MSAccess.exe"=dword:00000001
"MSPub.exe"=dword:00000001
"Powerpnt.exe"=dword:00000001
"Visio.exe"=dword:00000001
"WinProj.exe"=dword:00000001
"WinWord.exe"=dword:00000001
"Wordpad.exe"=dword:00000001
½«Éú´æµÄÎļþºó׺ÐÞ¸ÄΪ.reg¡£
Ë«»÷Ð޸ĺóµÄÎļþ,µ¼Èë×¢²á±í¼´¿É¡£
µ¼ÈëÍê³Éºó½¨ÒéÖØÆôËùÓдò¿ªµÄOffice·¨Ê½ÒÔÈ·±£ÉèÖÃÉúЧ¡£