** 描述
- CVE-2022-21907 的 POC:HTTP 协议栈远程代码执行漏洞。
- 由 antx 于 2022-01-17 创建。
** CVE 严重性
- attackComplexity: LOW
- attackVector: NETWORK
- availabilityImpact: HIGH
- confidentialityImpact: HIGH
- integrityImpact: HIGH
- privilegesRequired: NONE
- scope: UNCHANGED
- userInteraction: NONE
- version: 3.1
- baseScore: 9.8
- baseSeverity: CRITICAL
** 影响
- Windows
- 10 Version 1809 for 32-bit Systems
- 10 Version 1809 for x64-based Systems
- 10 Version 1809 for ARM64-based Systems
- 10 Version 21H1 for 32-bit Systems
- 10 Version 21H1 for x64-based System
- 10 Version 21H1 for ARM64-based Systems
- 10 Version 20H2 for 32-bit Systems
- 10 Version 20H2 for x64-based Systems
- 10 Version 20H2 for ARM64-based Systems
- 10 Version 21H2 for 32-bit Systems
- 10 Version 21H2 for x64-based Systems
- 10 Version 21H2 for ARM64-based Systems
- 11 for x64-based Systems
- 11 for ARM64-based Systems
- Windows Server
- 2019
- 2019 (Core installation)
- 2022
- 2022 (Server Core installation)
- version 20H2 (Server Core Installation)
** POC
- [[./CVE-2022-21907.py][POC]]
** 缓解措施
- Windows Server 2019 和 Windows 10 version 1809 默认不受影响。除非您通过 EnableTrailerSupport 注册表值启用了 HTTP Trailer Support,否则系统不受影响。
- 如果存在,请删除 DWORD 注册表值 "EnableTrailerSupport":
#+begin_src bash
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTTP\Parameters
#+end_src
- 此缓解措施仅适用于 Windows Server 2019 和 Windows 10 version 1809,不适用于 Windows 20H2 及更新版本。
** 常见问题
- 攻击者如何利用此漏洞?
- 在多数情况下,未认证的攻击者可以通过向使用 HTTP 协议栈 (http.sys) 处理数据包的目标服务器发送特制数据包来利用此漏洞。
- 该漏洞是否可蠕虫传播?
- 是的。微软建议优先修补受影响的服务器。
- Windows 10 Version 1909 不在安全更新表中。它受此漏洞影响吗?
- 不,易受攻击的代码不存在于 Windows 10 version 1909 中。它不受此漏洞影响。
- EnableTrailerSupport 注册表键是否存在于除 Windows Server 2019 和 Windows 10 version 1809 之外的其他平台?
- 不,该注册表键仅存在于 Windows Server 2019 和 Windows 10 version 1809 中。
** 参考
- 参考来源
- [[https://github.com/mauricelambert/CVE-2022-21907]]
- [[https://github.com/nu11secur1ty/Windows10Exploits/tree/master/2022/CVE-2022-21907]]
- 参考风险
- [[https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-21907][HTTP 协议栈远程代码执行漏洞]]
- [[https://nvd.nist.gov/vuln/detail/CVE-2022-21907][NVD]]
- CVE
- [[https://github.com/CVEProject/cvelist/blob/master/2022/21xxx/CVE-2022-21907.json][CVE-2022-21907]]
- [[https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21907][CVE-2022-21907]]
- 相关参考
- [[https://github.com/antx-code/CVE-2021-31166][CVE-2021-31166]]