服務(wù)公告
Microsoft Windows 支持診斷工具 (MSDT) 遠程代碼執(zhí)行漏洞(CVE-2022-30190)
2022-06-02
一、概要
近日,華為云關(guān)注到業(yè)界有安全研究人員披露漏洞代號為“Follina”,利用Windows 支持診斷工具 (MSDT)實現(xiàn)遠程代碼執(zhí)行的技術(shù)細節(jié)。根據(jù)微軟官方描述,從 Word 等調(diào)用應(yīng)用程序使用 URL 協(xié)議調(diào)用 MSDT 時存在遠程執(zhí)行代碼漏洞(CVE-2022-30190),成功利用此漏洞的攻擊者可以使用調(diào)用應(yīng)用程序的權(quán)限運行任意代碼。目前EXP/POC已公開,已出現(xiàn)在野利用,風(fēng)險較高。
華為云提醒用戶盡快安排自檢并做好安全加固。
參考鏈接:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30190
二、漏洞級別
漏洞級別:【嚴(yán)重】
(說明:漏洞級別共四級:一般、重要、嚴(yán)重、緊急)
三、影響范圍
影響版本:
Windows Server 2012 R2 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server Core installation)
Windows Server 2012
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows RT 8.1
Windows 8.1 for x64-based systems
Windows 8.1 for 32-bit systems
Windows 7 for x64-based Systems Service Pack 1
Windows 7 for 32-bit Systems Service Pack 1
Windows Server 2016 (Server Core installation)
Windows Server 2016
Windows 10 Version 1607 for x64-based Systems
Windows 10 Version 1607 for 32-bit Systems
Windows 10 for x64-based Systems
Windows 10 for 32-bit Systems
Windows 10 Version 21H2 for x64-based Systems
Windows 10 Version 21H2 for ARM64-based Systems
Windows 10 Version 21H2 for 32-bit Systems
Windows 11 for ARM64-based Systems
Windows 11 for x64-based Systems
Windows Server, version 20H2 (Server Core Installation)
Windows 10 Version 20H2 for ARM64-based Systems
Windows 10 Version 20H2 for 32-bit Systems
Windows 10 Version 20H2 for x64-based Systems
Windows Server 2022 Azure Edition Core Hotpatch
Windows Server 2022 (Server Core installation)
Windows Server 2022
Windows 10 Version 21H1 for 32-bit Systems
Windows 10 Version 21H1 for ARM64-based Systems
Windows 10 Version 21H1 for x64-based Systems
Windows Server 2019 (Server Core installation)
Windows Server 2019
Windows 10 Version 1809 for ARM64-based Systems
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems
安全版本:暫無
五、安全建議
截止到目前微軟官方還未發(fā)布安全補丁,請受影響用戶關(guān)注微軟官方發(fā)布補丁進展,及時升級修復(fù)。
緩解措施:
1、警惕點擊來源不明的郵件附件文檔;
2、禁用 MSDT URL 協(xié)議:參考官方提供的緩解措施,禁用 MSDT URL 協(xié)議或通過 Microsoft Defender 檢測和保護系統(tǒng)進行臨時緩解,詳情請查看:guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability
注:修復(fù)漏洞前請將資料備份,并進行充分測試。