Õâ¸ö0day©¶´Òѱ»ÔÚÒ°ÀûÓà ¶«É­Æ½Ì¨Ìṩ¼ì²â·½°¸

Ðû²¼Ê±¼ä 2023-07-24
½üÈÕ £¬Ä³Óû§´¦²¿ÊðµÄ¶«É­Æ½Ì¨ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©É豸²¶×½µ½ÀûÓñàºÅΪ CVE-2023-36884¸ßΣ0day©¶´µÄÑù±¾¡£½ØÖÁÄ¿Ç° £¬ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©ÒÑÏÖÍø¹²²¶×½9ÀýÔÚÒ°ÀûÓá£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

²¶×½µÄµöÓãÎĵµ½çÃæ


¾ÝϤ £¬¸Ã©¶´ÎªÎ¢ÈíÓÚ7ÔÂÄþ¾²¸üÐÂÖÐÅû¶µÄOfficeºÍWindows HTMLÔ¶³Ì´úÂëÖ´ÐЩ¶´ £¬´æÔÚÓÚ¶à¸öWindowsϵͳºÍOffice²úÎïÖС£ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©ÒѼà²âµ½Â©¶´ÐÅÏ¢Åû¶ǰÒÑ·¢ÉúÔÚÒ°ÀûÓãºStorm-0978×éÖ¯£¨ÓÖ³ÆRomCom×éÖ¯£©ÔÚ¶Ô±±Ô¼·å»áµÄ¹¥»÷ÖÐ £¬ÀûÓø鶴ÖÆ×÷ÁËÒÔÎÚ¿ËÀ¼ÊÀ½ç´ó»áΪÖ÷ÌâµÄÓÕ¶üÎļþ £¬ÌᳫµöÓã¹¥»÷¡£


 Â©¶´¹¥»÷Á÷³Ì 


CVE-2023-36884©¶´ºËÐÄ˼·ÔÚÓÚÀûÓÃMicrosoft OfficeÎĵµOOXML¹æ·¶ÖпÉÌæ´ú¸ñʽ¿é£¨Alternative Format Chunk£©ÄÚǶ´øÓÐÆäËû¹¥»÷×é¼þµÄrtfÎĵµÍê³ÉOffice·ÀÓù»úÖÆÈƹý £¬¿ÉÒÔÅäºÏÆäËû©¶´ÊµÏÖÎÞ¸ÐÖª¡¢ÎÞ½»»¥µÄÔ¶³Ì´úÂëÖ´ÐС£


ÔçÆÚµöÓã¹¥»÷Ñù±¾Ö÷ҪʹÓÃCVE-2017-0199¡¢CVE-2021-40444¡¢CVE-2022-30190µÈÂß¼­Â©¶´ £¬ºóÐø¹¥»÷ÔغÉÔ¶³Ì»ñÈ¡ £¬ÕûÌå¹¥»÷Á÷³Ì±ÈÁ¦ÅÓ´ó¡£


¶øÕâÁ½ÖÜÄÚ½Ðø²¶×½µ½µÄ¶àÊý¹¥»÷Ñù±¾ £¬ÄÚǶµÄrtf¾ù½ÓÄÉÄ£°å»¯µÄCVE-2017-11882 £¬À´Ö´ÐÐrtfͬʱÊͷŵÄPEÎļþ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


²¿ÃŲ¶×½Ñù±¾²»°üÂÞÓÕ¶üÐÅÏ¢ £¬²¢´øÓÐеÄrtf»ìÏý¼¼ÇÉ£ºÀûÓÃrtfÎļþÖаüÂÞµÄole¹¤¾ß¹ý³Ì¶Ô16½øÖÆÊý¾ÝµÄ³¤¶ÈÏÞÖÆ £¬Ê¹¾²Ì¬½âÎö¹ý³ÌÊý¾Ý´íλ £¬ÎÞ·¨¶ÔÆ뻹ԭԭÓÐole¹¤¾ß £¬¾ß±¸½ÏÇ¿µÄÃâɱÄÜÁ¦¡£


©¶´Î£º¦ 


ÔÚʵ¼ÊµöÓã¹¥»÷ÖÐ £¬¸Ã©¶´¿ÉÓÃÓÚÈƹýofficeÄþ¾²»úÖƼ°Ìṩһ²ãÃâɱ £¬ÎªÆäËûoffice³£ÓõöÓã¹¥»÷©¶´ÌṩÁ˱£»¤¿Ç £¬ÊµÏÖÁËÎÞ¸ÐÖª¡¢ÎÞ½»»¥µÄÔ¶³Ì´úÂëÖ´ÐÐ £¬´ó·ù½µµÍµöÓã¹¥»÷ÀûÓÃÃż÷ £¬·Ç·¨Õ߿ɽÏΪÇáËɵؽ«Ô­ÓвâÊÔÓù¥»÷ÔغÉÌ滻ΪC2¹¤¾ß £¬ÐγɵöÓã¹¥»÷Èë¿Ú £¬Î£º¦¼«´ó £¬ÐèÒª×öºÃ·ÀÓù´ëÊ©¡£


 ¶«É­Æ½Ì¨¼ì²â·½°¸ 


1¡¢Îļþ»¹Ô­¼ì²â


¸Ã©¶´ÅäºÏÆäËûoffice©¶´Ê¹Óà £¬ÓÃÓÚµöÓãÓʼþ¹¥»÷¡£ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©½ÓÄÉË«Ïò¼ì²âÒýÇæ £¬¿É¶Ô°ÙÓàÖÖÎļþ½øÐл¹Ô­ £¬ÄÚÖÃɳÏä £¬¿É¶Ô³£¼û°ÙÓàÖÖÓʼþ¸½¼þ¸ñʽ½øÐл¹Ô­ºÍɳÏä¼ì²â £¬Í¬Ê±¾ß±¸ÌáÈ¡ÕýÎÄÃÜÂëÆƽâÄÜÁ¦ £¬¿É×Ô¶¯Ê¹ÓÃÓʼþÕýÎÄÃÜÂ뱬ÆÆѹËõ°ü¸½¼þ £¬±¬ÆÆÀֳɺó¶Ô¸½¼þ¼°¸½¼þ×ÓÎļþ½øÐмì²â¡£


2¡¢ÐÐΪ¼ì²â


ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©ÄÚÖÃɳÏä £¬³ý¾²Ì¬¼ì²âÍâ £¬»¹¿É¶ÔofficeÎļþ½øÐÐÐÐΪ¼ì²âºÍ©¶´ÀûÓüì²â¡£É³Ïä½ÓÄɵÚÈý´úÓ²¼þ·ÂÕæ¼¼Êõ £¬¿É¶Ô¶ñÒâÑù±¾½øÐÐÆÛÆ­ £¬Í¨¹ýofficeÎļþÖ´ÐÐÐÐΪ £¬À´Åж¨¶ñÒâÐÐΪ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÐÐΪ¼ì²â¸æ¾¯½çÃæ


3¡¢»º½â´ëÊ©


ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©ÒÑÖ§³ÖCVE-2023-36884©¶´ÀûÓüì²â £¬ÇëÓû§²»Òª´ò¿ªÀ´Àú²»Ã÷µÄofficeÎĵµ £¬ÒѲ¿ÊðTARÓû§¿É½«¿ÉÒÉÎĵµÀëÏßÉÏ´«µ½TARÉ豸¼ì²â¡£


µ±µØ»º½â´ëÊ©£º


¿ÉÅäÖÃÏà¹Ø×¢²á±íÏîÀ´×èÖ¹Ïà¹Ø©¶´±»ÀûÓÃ,²½ÖèÈçÏÂ:


н¨Ò»¸öÎı¾Îĵµ,ÊäÈëÈçÏÂÄÚÈݲ¢Éú´æ¡£


Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet

Explorer\Main\FeatureControl\FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION]

"Excel.exe"=dword:00000001

"Graph.exe"=dword:00000001

"MSAccess.exe"=dword:00000001

"MSPub.exe"=dword:00000001

"Powerpnt.exe"=dword:00000001

"Visio.exe"=dword:00000001

"WinProj.exe"=dword:00000001

"WinWord.exe"=dword:00000001

"Wordpad.exe"=dword:00000001


½«Éú´æµÄÎļþºó׺ÐÞ¸ÄΪ.reg¡£


Ë«»÷Ð޸ĺóµÄÎļþ,µ¼Èë×¢²á±í¼´¿É¡£


µ¼ÈëÍê³Éºó½¨ÒéÖØÆôËùÓдò¿ªµÄOffice·¨Ê½ÒÔÈ·±£ÉèÖÃÉúЧ¡£