¡¾Îó²îͨ¸æ¡¿Microsoft WordÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-21716£©

Ðû²¼Ê±¼ä 2023-03-07

 

Ò»¡¢Îó²î¸ÅÊö

CVE   ID

CVE-2023-21716

·¢Ã÷ʱ¼ä

2023-02-15

Àà    ÐÍ

RCE

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

ËùÐèȨÏÞ

ÎÞ

¹¥»÷ÖØÆ¯ºó

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

·ñ

 

¿ËÈÕ£¬£¬ £¬ÈËÉú¾ÍÊDz©VSRC¼à²âµ½Microsoft WordÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-21716£©µÄPoCÔÚ»¥ÁªÍøÉϹûÕæ£¬£¬ £¬¸ÃÎó²îÒÑÔÚ΢Èí2023Äê2Ô²¹¶¡ÖÐÐÞ¸´£¬£¬ £¬ÆäCVSSv3ÆÀ·ÖΪ9.8 ¡£¡£¡£¡£¡£

Microsoft Word ÖÐµÄ RTF ÆÊÎöÆ÷ÔÚ´¦Öóͷ£°üÀ¨¹ý¶à×ÖÌå (*\f###*) µÄ×ÖÌå±í (*\fonttbl *)ʱ±£´æ¶ÑËð»µÎó²î£¬£¬ £¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔ·¢ËͰüÀ¨ RTF PayloadµÄ¶ñÒâµç×ÓÓʼþ£¨»òÆäËü·½·¨£©£¬£¬ £¬ÒÔ·­¿ª¶ñÒâ RTF ÎĵµµÄÊܺ¦ÕßµÄȨÏÞÖ´ÐÐí§Òâ´úÂë ¡£¡£¡£¡£¡£

×¢ÖØ£¬£¬ £¬Ô¤ÀÀ´°¸ñÊǸÃÎó²îµÄ¹¥»÷ǰÑÔÖ®Ò»£¬£¬ £¬¼´Óû§²»±Ø·­¿ª¶ñÒâ RTF Îĵµ£¬£¬ £¬Ö»ÐèÔÚÔ¤ÀÀ´°¸ñÖмÓÔØÎļþ±ã¿É´¥·¢Ö´ÐÐ ¡£¡£¡£¡£¡£

  

¶þ¡¢Ó°Ïì¹æÄ£

Microsoft Office 2019 for 32-bit editions

Microsoft Office 2019 for 64-bit editions

Microsoft Word 2013 Service Pack 1 (64-bit editions)

Microsoft Word 2013 RT Service Pack 1

Microsoft Word 2013 Service Pack 1 (32-bit editions)

Microsoft SharePoint Foundation 2013 Service Pack 1

Microsoft Office Web Apps Server 2013 Service Pack 1

Microsoft Word 2016 (32-bit edition)

Microsoft Word 2016 (64-bit edition)

Microsoft SharePoint Server 2019

Microsoft SharePoint Enterprise Server 2013 Service Pack 1

Microsoft SharePoint Enterprise Server 2016

Microsoft 365 Apps for Enterprise for 64-bit Systems

Microsoft Office 2019 for Mac

Microsoft Office Online Server

SharePoint Server Subscription Edition Language Pack

Microsoft 365 Apps for Enterprise for 32-bit Systems

Microsoft Office LTSC 2021 for 64-bit editions

Microsoft SharePoint Server Subscription Edition

Microsoft Office LTSC 2021 for 32-bit editions

Microsoft Office LTSC for Mac 2021


Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ¸ÃÎó²îÒÑÔÚ΢Èí2023Äê2Ô²¹¶¡ÖÐÐÞ¸´£¬£¬ £¬ÊÜÓ°ÏìÓû§¿É¾¡¿ì×°ÖøüР¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21716

3.2 ÔÝʱ²½·¥

l  ʹÓà Microsoft Outlook ½µµÍÓû§·­¿ªÀ´×Ôδ֪»ò²»ÊÜÐÅÈÎȪԴµÄ RTF ÎļþµÄΣº¦ ¡£¡£¡£¡£¡£ÈçÔĶÁ´¿Îı¾ÃûÌõĵç×ÓÓʼþ£¨ÒÔ´¿Îı¾ÃûÌÃÉó²éµÄµç×ÓÓʼþ½«²»°üÀ¨Í¼Æ¬¡¢×¨ÓÃ×ÖÌå¡¢¶¯»­»òÆäËû¸»ºñµÄÄÚÈÝ£¬£¬ £¬»ò½«Óöµ½ÆäËüÎÊÌ⣩£¬£¬ £¬ÓйØÔõÑùÉèÖà Microsoft Outlook ÒÔÔĶÁËùÓд¿Îı¾±ê×¼ÓʼþµÄÖ¸ÄÏ£¬£¬ £¬Çë²Î¿¼Î¢Èí¹Ù·½¹«¹²ÖеÄÏà¹ØÁ´½Ó ¡£¡£¡£¡£¡£

l  ʹÓà Microsoft Office Îļþ×èÖ¹Õ½ÂÔÀ´±ÜÃâ Office ·­¿ªÀ´×Ôδ֪»ò²»ÊÜÐÅÈÎȪԴµÄ RTF Îĵµ ¡£¡£¡£¡£¡£×¢ÖØ£¬£¬ £¬¸ÃÒªÁìÐèÒªÐÞ¸Ä×¢²á±í±à¼­Æ÷£¬£¬ £¬²»×¼È·Ð޸ĿÉÄܻᵼÖÂÑÏÖØÎÊÌ⣬£¬ £¬¿ÉÄÜÐèÒªÖØ×°ÏµÍ³ ¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬ÒÑÉèÖÃÎļþ×èÖ¹Õ½ÂÔµ«Î´ÉèÖÃÌØÊâ¡°¿íÃâĿ¼¡±µÄÓû§½«ÎÞ·¨·­¿ªÒÔ RTF ÃûÌÃÉúÑĵÄÎĵµ£¬£¬ £¬¿É²Î¿¼£ºhttps://learn.microsoft.com/en-us/office/troubleshoot/settings/file-blocked-in-office

A£®¹ØÓÚ Office 2013

1.ÒÔÖÎÀíÔ±Éí·ÝÔËÐÐ regedit.exe ²¢µ¼º½µ½ÒÔÏÂ×ÓÏ

 `[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Security\FileBlock]`

2.½« RtfFiles DWORD ÖµÉèÖÃΪ 2 ¡£¡£¡£¡£¡£

3.½« OpenInProtectedView DWORD ÖµÉèÖÃΪ 0 ¡£¡£¡£¡£¡£

¹ØÓÚ Office 2013£¬£¬ £¬×÷·ÏÉÏÊö²Ù×÷£º

1.ÒÔÖÎÀíÔ±Éí·ÝÔËÐÐ regedit.exe ²¢µ¼º½µ½ÒÔÏÂ×ÓÏ              

 `[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Security\FileBlock]`

2.½« RtfFiles DWORD ÖµÉèÖÃΪ 0 ¡£¡£¡£¡£¡£

3.½« OpenInProtectedView DWORD ÖµÉèÖÃΪ 0 ¡£¡£¡£¡£¡£

 

B£®¹ØÓÚ Office 2016

1.ÒÔÖÎÀíÔ±Éí·ÝÔËÐÐ regedit.exe ²¢µ¼º½µ½ÒÔÏÂ×ÓÏ    

`[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Security\FileBlock]`

2.½«RtfFiles DWORD ÖµÉèÖÃΪ2 ¡£¡£¡£¡£¡£

3.½« OpenInProtectedView DWORD ÖµÉèÖÃΪ0 ¡£¡£¡£¡£¡£

¹ØÓÚ Office 2016£¬£¬ £¬×÷·ÏÉÏÊö²Ù×÷£º

1.ÒÔÖÎÀíÔ±Éí·ÝÔËÐÐ regedit.exe ²¢µ¼º½µ½ÒÔÏÂ×ÓÏ

`[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Security\FileBlock]`

2.½«RtfFiles DWORD ÖµÉèÖÃΪ0 ¡£¡£¡£¡£¡£

3.½« OpenInProtectedView DWORD ÖµÉèÖÃΪ0 ¡£¡£¡£¡£¡£

 

C¡¢¹ØÓÚ Office 2019

1.ÒÔÖÎÀíÔ±Éí·ÝÔËÐÐ regedit.exe ²¢µ¼º½µ½ÒÔÏÂ×ÓÏ

`[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Security\FileBlock]`

2.½«RtfFiles DWORD ÖµÉèÖÃΪ2 ¡£¡£¡£¡£¡£

3.½« OpenInProtectedView DWORD ÖµÉèÖÃΪ0 ¡£¡£¡£¡£¡£

¹ØÓÚ Office 2019£¬£¬ £¬×÷·ÏÉÏÊö²Ù×÷£º

1.ÒÔÖÎÀíÔ±Éí·ÝÔËÐÐ regedit.exe ²¢µ¼º½µ½ÒÔÏÂ×ÓÏ

`[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Security\FileBlock]`

2.½«RtfFiles DWORD ÖµÉèÖÃΪ0 ¡£¡£¡£¡£¡£

3.½« OpenInProtectedView DWORD ÖµÉèÖÃΪ0 ¡£¡£¡£¡£¡£

 

D¡¢¹ØÓÚ Office 2021

1.ÒÔÖÎÀíÔ±Éí·ÝÔËÐÐ regedit.exe ²¢µ¼º½µ½ÒÔÏÂ×ÓÏ

`[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Security\FileBlock]`

2.½«RtfFiles DWORD ÖµÉèÖÃΪ2 ¡£¡£¡£¡£¡£

3.½« OpenInProtectedView DWORD ÖµÉèÖÃΪ0 ¡£¡£¡£¡£¡£

¹ØÓÚ Office 2021£¬£¬ £¬×÷·ÏÉÏÊö²Ù×÷£º

1.ÒÔÖÎÀíÔ±Éí·ÝÔËÐÐ regedit.exe ²¢µ¼º½µ½ÒÔÏÂ×ÓÏ

`[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Security\FileBlock]`

2£®½«RtfFiles DWORD ÖµÉèÖÃΪ0 ¡£¡£¡£¡£¡£

3.½« OpenInProtectedView DWORD ÖµÉèÖÃΪ0 ¡£¡£¡£¡£¡£

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬ £¬ïÔ̭ϵͳÎó²î£¬£¬ £¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ ¡£¡£¡£¡£¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬ £¬Ð޸ķÀ»ðǽսÂÔ£¬£¬ £¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬ £¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬ £¬ïÔÌ­¹¥»÷Ãæ ¡£¡£¡£¡£¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬ £¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ ¡£¡£¡£¡£¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬ £¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬ £¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È ¡£¡£¡£¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐÞ¸Ä ¡£¡£¡£¡£¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21716

https://qoop.org/publications/cve-2023-21716-rtf-fonttbl.md

https://www.bleepingcomputer.com/news/security/proof-of-concept-released-for-critical-microsoft-word-rce-bug/

https://twitter.com/jduck

  

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-03-07

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼

5.1 ÈËÉú¾ÍÊDz©¼ò½é

ÈËÉú¾ÍÊDz©½¨ÉèÓÚ1996Ä꣬£¬ £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò» ¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÈËÉú¾ÍÊDz©´óÏ㬣¬ £¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬ £¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË ¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬ £¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊÐ ¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬ £¬ÈËÉú¾ÍÊDz©ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬ £¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢ ¡£¡£¡£¡£¡£

5.2 ¹ØÓÚÈËÉú¾ÍÊDz©

ÈËÉú¾ÍÊDz©Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬ £¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬ £¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½ ¡£¡£¡£¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png