Windows TCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐÐÎó²îÀ´Ï®£¡918²©ÌìÌÃÌṩ½â¾ö¼Æ»®

Ðû²¼Ê±¼ä 2024-08-20

Windows ÊÇÓÉ΢Èí¹«Ë¾¿ª·¢µÄһϵÁÐͼÐÎÓû§½çÃæ²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£×Ô 1985 ÄêÊ×´ÎÐû²¼ÒÔÀ´£¬£¬ £¬£¬£¬£¬Windows ÒѾ­ÂÄÀúÁ˶à¸ö°æ±¾ºÍÖØ´ó¸üУ¬£¬ £¬£¬£¬£¬³ÉΪȫÇòʹÓÃ×îÆÕ±éµÄ²Ù×÷ϵͳ֮һ¡£¡£¡£¡£¡£¡£


¿ËÈÕ£¬£¬ £¬£¬£¬£¬918²©ÌìÌüà²âµ½Î¢ÈíÔÚ°ËÔ·ÝÇå¾²²¹¶¡ÖÐÐÞ¸´ÁËÒ»¸öÓ°ÏìWindows TCP/IPЭÒéÕ»µÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²îCVSSÆÀ·ÖΪ9.8£¬£¬ £¬£¬£¬£¬²¢ÇÒ±»Î¢Èí¹Ù·½±ê¼ÇΪExploitation More Likely(¸ß¿ÉÄÜÐÔʹÓÃ)¡£¡£¡£¡£¡£¡£


¾­ÓÉÑо¿È·ÈÏ£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÊÇÓÉÓÚWindowsµÄTCP/IP×é¼þ¹ýʧµÄ´¦Öóͷ£ÁËIPv6Êý¾Ý£¬£¬ £¬£¬£¬£¬´Ó¶øÔÚºóÐøµÄÁ÷³ÌÖе¼ÖÂÁËÕûÊýÒç³ö¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÔÚδ¾­Éí·ÝÑéÖ¤µÄÇéÐÎÏ£¬£¬ £¬£¬£¬£¬Í¨¹ýÏòÊܺ¦ÕßÖØ¸´·¢ËÍÌØ¶¨½á¹¹µÄIPv6Êý¾Ý°üÀ´´¥·¢Îó²î£¬£¬ £¬£¬£¬£¬´Ó¶øÔì³ÉÀ¶ÆÁËÀ»ú(BSOD)ÉõÖÁ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£


¸ÃÎó²îʹÓÃÎ޸У¬£¬ £¬£¬£¬£¬Ö»ÐèÄ¿µÄÖ÷»úÆôÓÃIPv6ЭÒé¼´¿É´¥·¢£¬£¬ £¬£¬£¬£¬²¢ÇÒÏÕЩӰÏìËùÓг£¼ûWindows°æ±¾¡£¡£¡£¡£¡£¡£¿£¿£¿ £Ë¼Á¿µ½Windowsͨ³£Ä¬ÈÏÆôÓÃIPv6¹¦Ð§£¬£¬ £¬£¬£¬£¬½¨Òé¿Í»§Æð¾¢×öºÃÅŲéºÍ·À»¤£¬£¬ £¬£¬£¬£¬¾¡¿ì×°Öùٷ½²¹¶¡£¬£¬ £¬£¬£¬£¬ÒÔÌá·ÀDZÔÚΣº¦¡£¡£¡£¡£¡£¡£


ͼƬ1.png


Îó²î¸´ÏÖ


ͼƬ2.png

ͼƬ3.png


½â¾ö¼Æ»®


Ò»¡¢¹Ù·½ÐÞ¸´¼Æ»®


¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬ £¬£¬£¬£¬½¨Ò齫ÊÜÓ°ÏìµÄWindowsÉý¼¶ÖÁ×îа汾£º

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063


¶þ¡¢ÔÝʱÐÞ¸´¼Æ»®


ÔÚ²»Ó°ÏìÕý³£ÓªÒµµÄÇéÐÎÏ£¬£¬ £¬£¬£¬£¬¿ÉÒÔÔÝʱ½«IPv6¹¦Ð§¹Ø±Õ¡£¡£¡£¡£¡£¡£


Èý¡¢918²©ÌìÌýâ¾ö¼Æ»®


1¡¢918²©ÌìÌüì²âÀà²úÆ·¼Æ»®


£¨1£©918²©ÌìÌá°ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©¡±Éý¼¶µ½20240819°æ±¾¼´¿ÉÖ§³Ö¼ì²â¸ÃÎó²î¡£¡£¡£¡£¡£¡£


ͼƬ4.png


£¨2£©918²©ÌìÌà ¡°ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡± Éý¼¶µ½20240819°æ±¾¼´¿ÉÖ§³Ö¼ì²â¸ÃÎó²î¡£¡£¡£¡£¡£¡£


ͼƬ5.jpg


2¡¢918²©ÌìÌéɨ²úÆ·¼Æ»®


£¨1£©¡°918²©ÌìÌÃÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳ¡±6075°æ±¾ÒѽôÆÈÐû²¼Õë¶Ô¸ÃÎó²îµÄÉý¼¶°ü£¬£¬ £¬£¬£¬£¬Ö§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃ裬£¬ £¬£¬£¬£¬Óû§Éý¼¶±ê×¼Îó²î¿âºó¼´¿É¶Ô¸ÃÎó²î¾ÙÐÐɨÃ裺


6070°æ±¾Éý¼¶°üΪ607000582-607000583.vup£¬£¬ £¬£¬£¬£¬Éý¼¶°üÏÂÔØµØµã£º

https://venustech.download.venuscloud.cn/


ͼƬ6.png


£¨2£©918²©ÌìÌÃÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳ608XϵÁа汾ÒѽôÆÈÐû²¼Õë¶Ô¸ÃÎó²îµÄÉý¼¶°ü£¬£¬ £¬£¬£¬£¬Ö§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃ裬£¬ £¬£¬£¬£¬Óû§Éý¼¶±ê×¼Îó²î¿âºó¼´¿É¶Ô¸ÃÎó²î¾ÙÐÐɨÃ裺


6080°æ±¾Éý¼¶°üΪÖ÷»ú²å¼þ°ü6080000133-S6080000134.svs©ɨ²å¼þ°üÏÂÔØµØµã£º

https://venustech.download.venuscloud.cn/


ͼƬ7.jpg


3¡¢918²©ÌìÌÃ×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¼Æ»®


918²©ÌìÌÃ×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±ÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢£¬£¬ £¬£¬£¬£¬¶ÔÈë¿â×ʲúÎó²îWindows TCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-38063£©¾ÙÐÐÖÎÀí¡£¡£¡£¡£¡£¡£


ͼƬ8.png


4¡¢918²©ÌìÌÃÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¼Æ»®


Óû§¿ÉÒÔͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬£¬ £¬£¬£¬£¬¾ÙÐйØÁªÕ½ÂÔÉèÖ㬣¬ £¬£¬£¬£¬Á¬ÏµÏÖÕæÏàÐÎÖÐϵͳÈÕÖ¾ºÍÇå¾²×°±¸µÄ¸æ¾¯ÐÅÏ¢¾ÙÐÐÒ»Á¬¼à¿Ø£¬£¬ £¬£¬£¬£¬´Ó¶ø·¢Ã÷¡°Windows TCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-38063£©¡±µÄÎó²îʹÓù¥»÷ÐÐΪ¡£¡£¡£¡£¡£¡£


£¨1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬£¬ £¬£¬£¬£¬Í¨¹ýųÈõÐÔ·¢Ã÷¹¦Ð§Õë¶Ô¡°Windows TCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-38063£©¡±Îó²îɨÃèʹÃü£¬£¬ £¬£¬£¬£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´ËÎó²îÓ°ÏìµÄÖ÷Òª×ʲú¡£¡£¡£¡£¡£¡£


ͼƬ9.png


£¨2£©Æ½Ì¨¡°¹ØÁªÆÊÎö¡±Ä£¿£¿£¿ £¿éÖУ¬£¬ £¬£¬£¬£¬Ìí¼Ó¡°L2_WindowsTCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐÐÎó²î¡±£¬£¬ £¬£¬£¬£¬Í¨¹ý918²©ÌìÌüì²â×°±¸¡¢Ä¿µÄÖ÷»úϵͳµÈ×°±¸µÄ¸æ¾¯ÈÕÖ¾£¬£¬ £¬£¬£¬£¬·¢Ã÷Íⲿ¹¥»÷ÐÐΪ£º


ͼƬ10.png


̫ͨ¹ýÎö¹æÔò×Ô¶¯½«"L2_WindowsTCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐÐÎó²î"Îó²îʹÓõĿÉÒÉÐÐΪԴµØµãÌí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ßΣº¦ÅþÁ¬¡±ÖУ¬£¬ £¬£¬£¬£¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓᣡ£¡£¡£¡£¡£


£¨3£©Ìí¼Ó¡°L3_WindowsTCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐÐÎó²îʹÓÃÀֳɡ±£¬£¬ £¬£¬£¬£¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ»ò°üÀ¨¡°L2_WindowsTCP/IP¸ßΣԶ³Ì´úÂëÖ´ÐÐÎó²î¡±£¬£¬ £¬£¬£¬£¬¹¥»÷Ч¹û¼´ÊÇ¡°¹¥»÷Àֳɡ±£¬£¬ £¬£¬£¬£¬Ä¿µÄµØµãÒýÓÃ×ʲúÎó²î»òÔ´µØµãÆ¥ÅäÍþвÇ鱨£¬£¬ £¬£¬£¬£¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶÈ¡£¡£¡£¡£¡£¡£


ͼƬ11.png


£¨4£©ATT&CK¹¥»÷Á´ÌõÆÊÎöÓëSOAR´¦Öóͷ£½¨Òé


ƾ֤¶ÔCVE-2024-38063Îó²îµÄ¹¥»÷ʹÓÃÀú³Ì¾ÙÐÐÆÊÎö£¬£¬ £¬£¬£¬£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍÊÖÒս׶Σ¬£¬ £¬£¬£¬£¬ÁýÕÖµÄTTP°üÀ¨£º


TA0001³õʼ»á¼û£ºT1190ʹÓÃÃæÏò¹«ÖÚµÄÓ¦ÓóÌÐò

TA0002Ö´ÐУºT1059ÏÂÁîºÍ¾ç±¾Ú¹ÊÍÆ÷


ͼƬ12.png


ͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´¦Öóͷ£ÄÜÁ¦£¬£¬ £¬£¬£¬£¬Õë¶Ô¸ÃÎó²îʹÓõĸ澯ÊÂÎñ±àÅž籾£¬£¬ £¬£¬£¬£¬¾ÙÐÐ×Ô¶¯»¯´¦Öóͷ£¡£¡£¡£¡£¡£¡£