¡¾Îó²îͨ¸æ¡¿Microsoft WordÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-21716£©

Ðû²¼Ê±¼ä 2023-03-07

 

Ò»¡¢Îó²î¸ÅÊö

CVE   ID

CVE-2023-21716

·¢Ã÷ʱ¼ä

2023-02-15

Àà    ÐÍ

RCE

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

ËùÐèȨÏÞ

ÎÞ

¹¥»÷ÖØÆ¯ºó

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

·ñ

 

¿ËÈÕ£¬£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨VSRC¼à²âµ½Microsoft WordÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-21716£©µÄPoCÔÚ»¥ÁªÍøÉϹûÕæ£¬£¬£¬£¬¸ÃÎó²îÒÑÔÚ΢Èí2023Äê2Ô²¹¶¡ÖÐÐÞ¸´£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£¡£

Microsoft Word ÖÐµÄ RTF ÆÊÎöÆ÷ÔÚ´¦Öóͷ£°üÀ¨¹ý¶à×ÖÌå (*\f###*) µÄ×ÖÌå±í (*\fonttbl *)ʱ±£´æ¶ÑËð»µÎó²î£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔ·¢ËͰüÀ¨ RTF PayloadµÄ¶ñÒâµç×ÓÓʼþ£¨»òÆäËü·½·¨£©£¬£¬£¬£¬ÒÔ·­¿ª¶ñÒâ RTF ÎĵµµÄÊܺ¦ÕßµÄȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

×¢ÖØ£¬£¬£¬£¬Ô¤ÀÀ´°¸ñÊǸÃÎó²îµÄ¹¥»÷ǰÑÔÖ®Ò»£¬£¬£¬£¬¼´Óû§²»±Ø·­¿ª¶ñÒâ RTF Îĵµ£¬£¬£¬£¬Ö»ÐèÔÚÔ¤ÀÀ´°¸ñÖмÓÔØÎļþ±ã¿É´¥·¢Ö´ÐС£¡£¡£¡£¡£¡£

  

¶þ¡¢Ó°Ïì¹æÄ£

Microsoft Office 2019 for 32-bit editions

Microsoft Office 2019 for 64-bit editions

Microsoft Word 2013 Service Pack 1 (64-bit editions)

Microsoft Word 2013 RT Service Pack 1

Microsoft Word 2013 Service Pack 1 (32-bit editions)

Microsoft SharePoint Foundation 2013 Service Pack 1

Microsoft Office Web Apps Server 2013 Service Pack 1

Microsoft Word 2016 (32-bit edition)

Microsoft Word 2016 (64-bit edition)

Microsoft SharePoint Server 2019

Microsoft SharePoint Enterprise Server 2013 Service Pack 1

Microsoft SharePoint Enterprise Server 2016

Microsoft 365 Apps for Enterprise for 64-bit Systems

Microsoft Office 2019 for Mac

Microsoft Office Online Server

SharePoint Server Subscription Edition Language Pack

Microsoft 365 Apps for Enterprise for 32-bit Systems

Microsoft Office LTSC 2021 for 64-bit editions

Microsoft SharePoint Server Subscription Edition

Microsoft Office LTSC 2021 for 32-bit editions

Microsoft Office LTSC for Mac 2021


Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ¸ÃÎó²îÒÑÔÚ΢Èí2023Äê2Ô²¹¶¡ÖÐÐÞ¸´£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿É¾¡¿ì×°ÖøüС£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21716

3.2 ÔÝʱ²½·¥

l  ʹÓà Microsoft Outlook ½µµÍÓû§·­¿ªÀ´×Ôδ֪»ò²»ÊÜÐÅÈÎȪԴµÄ RTF ÎļþµÄΣº¦¡£¡£¡£¡£¡£¡£ÈçÔĶÁ´¿Îı¾ÃûÌõĵç×ÓÓʼþ£¨ÒÔ´¿Îı¾ÃûÌÃÉó²éµÄµç×ÓÓʼþ½«²»°üÀ¨Í¼Æ¬¡¢×¨ÓÃ×ÖÌå¡¢¶¯»­»òÆäËû¸»ºñµÄÄÚÈÝ£¬£¬£¬£¬»ò½«Óöµ½ÆäËüÎÊÌ⣩£¬£¬£¬£¬ÓйØÔõÑùÉèÖà Microsoft Outlook ÒÔÔĶÁËùÓд¿Îı¾±ê×¼ÓʼþµÄÖ¸ÄÏ£¬£¬£¬£¬Çë²Î¿¼Î¢Èí¹Ù·½¹«¹²ÖеÄÏà¹ØÁ´½Ó¡£¡£¡£¡£¡£¡£

l  ʹÓà Microsoft Office Îļþ×èÖ¹Õ½ÂÔÀ´±ÜÃâ Office ·­¿ªÀ´×Ôδ֪»ò²»ÊÜÐÅÈÎȪԴµÄ RTF Îĵµ¡£¡£¡£¡£¡£¡£×¢ÖØ£¬£¬£¬£¬¸ÃÒªÁìÐèÒªÐÞ¸Ä×¢²á±í±à¼­Æ÷£¬£¬£¬£¬²»×¼È·Ð޸ĿÉÄܻᵼÖÂÑÏÖØÎÊÌ⣬£¬£¬£¬¿ÉÄÜÐèÒªÖØ×°ÏµÍ³¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ÒÑÉèÖÃÎļþ×èÖ¹Õ½ÂÔµ«Î´ÉèÖÃÌØÊâ¡°¿íÃâĿ¼¡±µÄÓû§½«ÎÞ·¨·­¿ªÒÔ RTF ÃûÌÃÉúÑĵÄÎĵµ£¬£¬£¬£¬¿É²Î¿¼£ºhttps://learn.microsoft.com/en-us/office/troubleshoot/settings/file-blocked-in-office

A£®¹ØÓÚ Office 2013

1.ÒÔÖÎÀíÔ±Éí·ÝÔËÐÐ regedit.exe ²¢µ¼º½µ½ÒÔÏÂ×ÓÏ

 `[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Security\FileBlock]`

2.½« RtfFiles DWORD ÖµÉèÖÃΪ 2¡£¡£¡£¡£¡£¡£

3.½« OpenInProtectedView DWORD ÖµÉèÖÃΪ 0¡£¡£¡£¡£¡£¡£

¹ØÓÚ Office 2013£¬£¬£¬£¬×÷·ÏÉÏÊö²Ù×÷£º

1.ÒÔÖÎÀíÔ±Éí·ÝÔËÐÐ regedit.exe ²¢µ¼º½µ½ÒÔÏÂ×ÓÏ              

 `[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Security\FileBlock]`

2.½« RtfFiles DWORD ÖµÉèÖÃΪ 0¡£¡£¡£¡£¡£¡£

3.½« OpenInProtectedView DWORD ÖµÉèÖÃΪ 0¡£¡£¡£¡£¡£¡£

 

B£®¹ØÓÚ Office 2016

1.ÒÔÖÎÀíÔ±Éí·ÝÔËÐÐ regedit.exe ²¢µ¼º½µ½ÒÔÏÂ×ÓÏ    

`[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Security\FileBlock]`

2.½«RtfFiles DWORD ÖµÉèÖÃΪ2¡£¡£¡£¡£¡£¡£

3.½« OpenInProtectedView DWORD ÖµÉèÖÃΪ0¡£¡£¡£¡£¡£¡£

¹ØÓÚ Office 2016£¬£¬£¬£¬×÷·ÏÉÏÊö²Ù×÷£º

1.ÒÔÖÎÀíÔ±Éí·ÝÔËÐÐ regedit.exe ²¢µ¼º½µ½ÒÔÏÂ×ÓÏ

`[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Security\FileBlock]`

2.½«RtfFiles DWORD ÖµÉèÖÃΪ0¡£¡£¡£¡£¡£¡£

3.½« OpenInProtectedView DWORD ÖµÉèÖÃΪ0¡£¡£¡£¡£¡£¡£

 

C¡¢¹ØÓÚ Office 2019

1.ÒÔÖÎÀíÔ±Éí·ÝÔËÐÐ regedit.exe ²¢µ¼º½µ½ÒÔÏÂ×ÓÏ

`[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Security\FileBlock]`

2.½«RtfFiles DWORD ÖµÉèÖÃΪ2¡£¡£¡£¡£¡£¡£

3.½« OpenInProtectedView DWORD ÖµÉèÖÃΪ0¡£¡£¡£¡£¡£¡£

¹ØÓÚ Office 2019£¬£¬£¬£¬×÷·ÏÉÏÊö²Ù×÷£º

1.ÒÔÖÎÀíÔ±Éí·ÝÔËÐÐ regedit.exe ²¢µ¼º½µ½ÒÔÏÂ×ÓÏ

`[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Security\FileBlock]`

2.½«RtfFiles DWORD ÖµÉèÖÃΪ0¡£¡£¡£¡£¡£¡£

3.½« OpenInProtectedView DWORD ÖµÉèÖÃΪ0¡£¡£¡£¡£¡£¡£

 

D¡¢¹ØÓÚ Office 2021

1.ÒÔÖÎÀíÔ±Éí·ÝÔËÐÐ regedit.exe ²¢µ¼º½µ½ÒÔÏÂ×ÓÏ

`[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Security\FileBlock]`

2.½«RtfFiles DWORD ÖµÉèÖÃΪ2¡£¡£¡£¡£¡£¡£

3.½« OpenInProtectedView DWORD ÖµÉèÖÃΪ0¡£¡£¡£¡£¡£¡£

¹ØÓÚ Office 2021£¬£¬£¬£¬×÷·ÏÉÏÊö²Ù×÷£º

1.ÒÔÖÎÀíÔ±Éí·ÝÔËÐÐ regedit.exe ²¢µ¼º½µ½ÒÔÏÂ×ÓÏ

`[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Security\FileBlock]`

2£®½«RtfFiles DWORD ÖµÉèÖÃΪ0¡£¡£¡£¡£¡£¡£

3.½« OpenInProtectedView DWORD ÖµÉèÖÃΪ0¡£¡£¡£¡£¡£¡£

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21716

https://qoop.org/publications/cve-2023-21716-rtf-fonttbl.md

https://www.bleepingcomputer.com/news/security/proof-of-concept-released-for-critical-microsoft-word-rce-bug/

https://twitter.com/jduck

  

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-03-07

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼

5.1 c7c7ÓéÀÖÆ½Ì¨¼ò½é

c7c7ÓéÀÖÆ½Ì¨½¨ÉèÓÚ1996Ä꣬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°c7c7ÓéÀÖÆ½Ì¨´óÏ㬣¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£

5.2 ¹ØÓÚc7c7ÓéÀÖÆ½Ì¨

c7c7ÓéÀÖÆ½Ì¨Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png