
Windows OS ã«åå¨ãã RCE èå¼±æ§(CVE-2021-31166) ã«ã¤ãã¦ã®æ¤è¨¼ã¬ãã¼ã
2021å¹´5æ11æ¥ã«Microsoftãå ¬è¡¨ããhttp.sys ã«åå¨ãããªã¢ã¼ãã³ã¼ãå®è¡ã®èå¼±æ§ï¼CVE-2021-31166ï¼[1]ã«ã¤ãã¦ã®æ¤è¨¼ãå®æ½ããèå¼±æ§ã®æªç¨ãå¯è½ã§ãããã¨ã確èªãã¾ããã
1. æ¬èå¼±æ§ã®æ¦è¦
http.sys ã¯ãHTTP ãããã³ã«ã¹ã¿ãã¯ãå¦çããã«ã¼ãã«ã¢ã¼ããã©ã¤ãã§ãWindows ãã·ã³ã® Web ãµã¼ãã¹ã§ãã Internet Information Services(IIS)ãªã©ã§å©ç¨ããã¦ãã¾ããæ¬èå¼±æ§ã¯ãhttp.sys ã«åå¨ãã Use-After-Free(解æ¾æ¸ã¿ã¡ã¢ãªä½¿ç¨)ã®åé¡ã«èµ·å ãã¾ãããã®èå¼±æ§ãæªç¨ãããå ´åãæ»æè
ããªã¢ã¼ãããä»»æã®ã³ã¼ããå®è¡ã§ããå¯è½æ§ãããã¾ãã
æ¬èå¼±æ§ã¯ CVSSv3 ã¹ã³ã¢ã 9.8 ã¨è©ä¾¡ããã¦ãã¾ããã¾ã Blue Screen of Death(BSoD)ãå¼ãèµ·ããæ¦å¿µå®è¨¼(PoC)ã³ã¼ãã確èªããã¦ãããããæ¬èå¼±æ§ãåå¨ããç°å¢ã§ã¯ DoS æ»æãåããå¯è½æ§ãããã¾ãã
å³1. æ¬èå¼±æ§ãæªç¨ããæ»æã®ä¾
å³1ã¯ãæ¬èå¼±æ§ã«å¯¾ããæ»æã®ä¸ä¾ã¨ãã¦ãèå¼±æ§ãå«ã IIS ã稼åãã Windows ãã·ã³ã«å¯¾ããæ»æè ãç´°å·¥ããä¸æ£ãªãªã¯ã¨ã¹ããéä¿¡ãã¦ãWindows ãã·ã³ä¸ã§ä»»æã®ã³ã¼ããå®è¡ããä¾ã示ãã¦ãã¾ãã
2. æ¬èå¼±æ§ã®å½±é¿ãåããç°å¢
æ¬èå¼±æ§ã®å½±é¿ãåããå¯è½æ§ããããã¼ã¸ã§ã³ã¯ä»¥ä¸ã®éãã§ãã[1]
- Windows 10 Version 2004 for 32-bit/x64-based/ARM64-based Systems
- Windows 10 Version 20H2 for 32-bit/x64-based/ARM64-based Systems
- Windows Server, version 2004/20H2 (Server Core installation)
3. æ¬èå¼±æ§ãå©ç¨ããæ»æã®æ¤è¨¼
PoC ã³ã¼ããç¨ãã¦æ¬èå¼±æ§ã«å¯¾ããæ»æã試è¡ããèå¼±æ§ã®æªç¨ãå¯è½ã§ãããã¨ã確èªãã¾ããã
3.1. æ¤è¨¼ç°å¢
表1. æ¤è¨¼ã«ä½¿ç¨ããç°å¢
çä¼¼æ»æè | ç似被害è | |
---|---|---|
OS | Kali Linux 64bit | Windows 10 Pro 64bit Version 20H2 |
ã¢ããªã±ã¼ã·ã§ã³/ãã¼ã« | PoC ã³ã¼ã | Microsoft IIS |
3.2. æ»æææ³
æ¬èå¼±æ§ãåå¨ããç似被害è ã«å¯¾ãã¦ãçä¼¼æ»æè ããä¸æ£ãªãªã¯ã¨ã¹ããéä¿¡ãã¾ãããªã¯ã¨ã¹ããããã«ã¯ãå©ç¨å¯è½ãªå§ç¸®ã¢ã«ã´ãªãºã ãä¼ãã Accept-Encoding ã®å¤ã«ãåå¨ããªãã¢ã«ã´ãªãºã åãè¤æ°æå®ãã¾ãããã®ãªã¯ã¨ã¹ããç似被害è ãåä¿¡ããéã«ãé©åã«å¦çãè¡ããã¨ã«å¤±æãããã¨ã§ BSoD ãçºçãã¾ããæ¬æ¤è¨¼ã§ã¯ PoC ã³ã¼ããå©ç¨ãã¦ä¸æ£ãªãªã¯ã¨ã¹ããéä¿¡ãããã¨ã«ãããæ¬èå¼±æ§ã®æªç¨ã試ã¿ã¾ããã
3.3. æ¤è¨¼çµæ
å³2ã«ç¤ºãçµæã®éããç似被害è ã«å¯¾ãã¦çä¼¼æ»æè ããä¸æ£ãªãªã¯ã¨ã¹ããéä¿¡ãããã¨ã§ãBSoD ãçºçããããã¨ãã§ãã¾ããã
å³2. PoC ã³ã¼ãã®å®è¡ã¨ BSoD ã®çºç
4. æ¬èå¼±æ§ã«å¯¾ãã対ç
4.1. ç¾å¨æ¨å¥¨ããã¦ãã対ç
2021å¹´5æ31æ¥ç¾å¨ãMicrosoft ããæ¬èå¼±æ§ã®ä¿®æ£ããããæä¾ããã¦ãã¾ãã[2]
4.2. ä¸æ£ã¢ã¯ã»ã¹ç£è¦æ©å¨ã«ãã対ç
å½ç¤¾ã確èªãã¦ããä¸æ£ã¢ã¯ã»ã¹ç£è¦æ©å¨ã®å¯¾å¿ç¶æ³
å製åãã³ãã¼ã®æ¬èå¼±æ§ã¸ã®å¯¾å¿ç¶æ³ã«é¢ããæ å ±ãããã³æ¬æ¤è¨¼ã«ããå製åã§ã®æ¤ç¥çµæã¯ä»¥ä¸ã®éãã§ãã表2ã«å ¬å¼ã·ã°ããã£ã®æä¾ç¶æ³ãè¨è¼ãã¾ãã
表2. 製åãã³ãã¼ã«ããã·ã°ããã£æä¾ç¶æ³ï¼2021å¹´5æ31æ¥æç¹ï¼
ç¨®å¥ | 製åãã³ãã¼/製å | 製åãã³ãã¼æä¾ã®ã·ã°ãã㣠| æ¤ç¥çµæ |
---|---|---|---|
IDS/IPS | IBM QRader Network Security GX/XGS Series |
ã¡ã¼ã«ã¼ããã®ã·ã°ããã£ã¯ç¾å¨æªæä¾ã§ãã æ¢åã®ã·ã°ããã£ã§æ¤åºã§ãããã©ãããç¾å¨ç¢ºèªä¸ã§ãã |
æ¤è¨¼ä¸ |
McAfee Network Security Platform NS/M Series |
Signature Set 10.8.21.5: Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability (CVE-2021-31166) [0x4528f000] |
ã | |
WAF | Imperva SecureSphere |
ã¡ã¼ã«ã¼ããã®ã·ã°ããã£ã¯ç¾å¨æªæä¾ã§ãã æ¢åã®ã·ã°ããã£ã§æ¤åºã§ãããã©ãããç¾å¨ç¢ºèªä¸ã§ãã |
æ¤è¨¼ä¸ |
F5 Networks BIG-IP |
対å¿ããã·ã°ããã£ããããã©ãããç¾å¨ç¢ºèªä¸ã§ãã | - | |
NGFW | Palo Alto PA Series |
Threat ID 91104, 91126, 91146, 91166 Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability |
ã |
Check Point NGFW Series |
CPAI-2021-0292 Microsoft HTTP Protocol Stack Remote Code Execution (CVE-2021-31166) |
æ¤è¨¼ä¸ | |
ç·åãµã¼ãã»ãã¥ãªãã£å¯¾ç | Trend Micro Deep Security |
DPI 1010949 Microsoft Windows HTTP Protocol Stack Remote Code Execution Vulnerability (CVE-2021-31166) |
æ¤è¨¼ä¸ |
åèæç®
-
[1]
HTTP ãããã³ã« ã¹ã¿ãã¯ã®ãªã¢ã¼ãã§ã³ã¼ããå®è¡ãããèå¼±æ§
https://msrc.microsoft.com/update-guide/ja-JP/vulnerability/CVE-2021-31166 -
[2]
Microsoft Update ã«ã¿ãã°
https://www.catalog.update.microsoft.com/Search.aspx?q=KB5003173
æ©å¨å¥å½ç¤¾å¯¾å¿ãµã¼ãã¹
IDS/IPS
-
INTELLILINK IDS/IPSã»ãã¥ãªãã£ç£è¦ã»éç¨ãµã¼ãã¹
https://www.intellilink.co.jp/business/security/scrutiny_01.aspx
WAF
-
INTELLILINK WAFã»ãã¥ãªãã£ç£è¦ã»éç¨ãµã¼ãã¹
https://www.intellilink.co.jp/business/security/scrutiny_05.aspx
NGFW
-
INTELLILINK UTMã»ãã¥ãªãã£ç£è¦ã»éç¨ãµã¼ãã¹
https://www.intellilink.co.jp/business/security/scrutiny_06.aspx
ç·åãµã¼ãã»ãã¥ãªãã£å¯¾ç
-
INTELLILINK ã¯ã©ã¦ãã»ãã¥ãªãã£ç£è¦ã»éç¨ãµã¼ãã¹
https://www.intellilink.co.jp/business/security/deepsecurity.aspx
æ´æ°å±¥æ´
2021/5/31 åçä½æ
â» åè¦æ ¼åãä¼ç¤¾åãå£ä½åã製ååã¯ãä¸è¬ã«å社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ãã
æ¬ä»¶ã«é¢ãããåãåããå
NTTãã¼ã¿å
端æè¡æ ªå¼ä¼ç¤¾
ãåãåãããã©ã¼ã