Windows NTLM改动误差清静通告

宣布时间 2019-06-12

误差编号和级别


CVE编号:CVE-2019-1040 ,危险级别:中危 ,CVSS分值:厂商自评:5.3 ,官方未评定


影响版本


受影响的版本


Windows 10 for 32-bit Systems
Windows 10 for x64-based Systems
Windows 10 Version 1607 for 32-bit Systems
Windows 10 Version 1607 for x64-based Systems
Windows 10 Version 1703 for 32-bit Systems
Windows 10 Version 1703 for x64-based Systems
Windows 10 Version 1709 for 32-bit Systems
Windows 10 Version 1709 for ARM64-based Systems
Windows 10 Version 1709 for x64-based Systems
Windows 10 Version 1803 for 32-bit Systems
Windows 10 Version 1803 for ARM64-based Systems
Windows 10 Version 1803 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems
Windows 10 Version 1809 for ARM64-based Systems
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 1903 for 32-bit Systems
Windows 10 Version 1903 for ARM64-based Systems
Windows 10 Version 1903 for x64-based Systems
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems Service Pack 1
Windows 8.1 for 32-bit systems
Windows 8.1 for x64-based systems
Windows RT 8.1
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for Itanium-Based Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2012
Windows Server 2012 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 R2 (Server Core installation)
Windows Server 2016
Windows Server 2016 (Server Core installation)
Windows Server 2019
Windows Server 2019 (Server Core installation)
Windows Server, version 1803 (Server Core Installation)

Windows Server, version 1903 (Server Core installation)


误差概述


6月11日 ,微软官方宣布误差CVE-2019-1040的通告。


该误差保存于Windows认证机制中。当中心人攻击者能够乐成绕过NTLM MIC(新闻完整性检查)�;な� ,Microsoft Windows中保存改动误差。乐成使用此误差的攻击者可以获得降级NTLM清静功效的能力。要使用此误差 ,攻击者需要改动NTLM交流。然后 ,攻击者可以修改NTLM数据包的标记 ,而不会使署名无效。


攻击者通过使用该误差可造成多种差别的危害。其中 ,最严重危害为:通过使用该误差 ,攻击者在仅有一个通俗域账号的情形下可远程控制 Windows 域内的任何机械 ,包括域控服务器。


误差验证


暂无POC/EXP。


修复建议


微软官方已推出更新补丁 ,请在所有受影响的 Windows 客户端、服务器下载安


装更新:https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1040。装置完毕后需重启服务器。


其他加固步伐:


强烈建议通过装置官方补丁的方法对误差举行修复。关于无法装置补丁的服务器 ,可通过以下加固步伐对此误差的某些使用方法举行适当缓解。(注重 ,这些加固步伐并没有修复误差 ,只是针对该误差可能保存的一些使用方法举行缓解。这些缓解步伐有可能被高级别的攻击者绕过。)


开启所有主要服务器的强制 SMB 署名功效

(在 Windows 域情形下 ,默认只有域控服务器开启了强制 SMB 署名)


启用所有域控服务器的强制 LDAPS Channel Binding 功效

(此功效默认不启用。启用后有可能造成兼容性问题。)


启用所有域控服务器的强制 LDAP Signing 功效

(此功效默认不启用。启用后有可能造成兼容性问题。)


开启所有主要服务器(好比所有 Exchange 服务器)上相关应用的Channel Binding 功效(如 IIS 的 Channel Binding 功效)


参考链接


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1040