SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-03-29·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-0604£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º7.8
Ó°Ïì°æ±¾£º
Microsoft SharePoint Server 2019
Microsoft SharePoint Enterprise Server 2016
Microsoft SharePoint Foundation 2013 Service Pack 1
Microsoft SharePoint Server 2010 Service Pack 2
·ì϶¸ÅÊö
SharePointÊÇ΢ÈíµÄÒ»¿îÍŶӺÏ×÷½â¾ö¹æ»®£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÍŶӼ乲ÏíºÍÖÎÀíÄÚÈݺÍ֪ʶ¡£¡£¡£¡£¡£ËüʹÓÃASP.NET¿ª·¢£¬£¬£¬£¬£¬£¬£¬£¬ºó¶ËÊý¾Ý¿âʹÓÃMicrosoft SQL Server¡£¡£¡£¡£¡£
³É¹¦ÀûÓ÷ì϶£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂWindowsϵͳ·þÎñÆ÷Ô¶³ÌÖ´ÐкÅÁ£¬£¬£¬£¬£¬£¬£¬ÓпÉÄÜÆëÈ«½ÚÔì·þÎñÆ÷¡£¡£¡£¡£¡£
¹¥»÷Õ߿ɽ«¾«ÐÄ»ú¹ØµÄÒªÇóͨ¹ýItemPicker WebForm¿Ø¼þ´«Èëºó¶ËEntityInstanceIdEncoder.DecodeEntityInstanceId(encodedId)²½ÖèÖУ¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ²½ÖèûÓжԴ«ÈëµÄencodedId½øÐÐÈκδ¦Ö㬣¬£¬£¬£¬£¬£¬£¬Ò²Ã»ÓжÔXmlSerializer»ú¹Øº¯ÊýµÄÀàÐͲÎÊý½øÐÐÏÞ¶È£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÖ±½Óͨ¹ýXmlSerializer·´ÐòÁл¯£¬£¬£¬£¬£¬£¬£¬£¬Ôì³ÉºÅÁîÖ´ÐС£¡£¡£¡£¡£
ÒªÀûÓø÷ì϶£¬£¬£¬£¬£¬£¬£¬£¬±ØÒªÊÚȨ½Ó¼ûSharePointÌṩµÄÖÎÀíÍøÒ³£¬£¬£¬£¬£¬£¬£¬£¬ÊÚȨÕË»§¿ÉËùÒÔÒ»¸öÓòÕË»§¡£¡£¡£¡£¡£
·ì϶ϸ½Ú
ÀûÓÃǰÌ᣺
¿ÉÊÚȨ½Ó¼ûSharePointÌṩµÄÖÎÀíÍøÒ³£¬£¬£¬£¬£¬£¬£¬£¬ÊÚȨÕË»§¿ÉËùÒÔÒ»¸öÓòÕË»§¡£¡£¡£¡£¡£
»·¾³´î½¨£º
? Windows server 2016
? ASP.NETÓйØ×é¼þ
? Microsoft SQL Server
? SharePoint Server
×°ÖÃSharePointǰÄܹ»ÏÈÔËÐÐprerequisiteinstaller ×°ÖÃSharePoint±Ø±¸µÄ×é¼þ£¬£¬£¬£¬£¬£¬£¬£¬¶øºó×°ÖÃMicrosoft SQL Server£¬£¬£¬£¬£¬£¬£¬£¬ÅäÖúÃÕË»§¡£¡£¡£¡£¡£ÈôÊÇÔÚµ¥»úÉϴSharePoint±ØÒªÔÚ´Ëʱ½«·þÎñÆ÷Çл»ÎªÓò¿Ø·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬¶øºóÔÙ³ÉÁ¢ÓòÕ˺Å×°ÖúͲ¿ÊðSharePoint¡£¡£¡£¡£¡£±¾µØÕ˺Ų»ÇкÏSharePointµÄ²¿ÊðÒªÇ󡣡£¡£¡£¡£
·ì϶·ÖÎö£º
·ì϶Èë¿ÚÔÚhttp://
½øÈ븸ÀàPickerDialogÖУ¬£¬£¬£¬£¬£¬£¬£¬¿´»ú¹Øº¯Êý£º
ÆäÖÐEntityEditorWithPickerÒ²ÊÇÒ»¸öWebForm¿Ø¼þ£¬£¬£¬£¬£¬£¬£¬£¬×¢Ã÷ÔÚÕâÀï´«ÈëÁËÒ»¸öEntityEditorWithPickerµÄ×ÓÀàItemPicker£¬£¬£¬£¬£¬£¬£¬£¬¸úÈëItemPicker¿É¿´µ½ItemPickerµÄÈ·¼Ì³Ð×ÔEntityEditorWithPicker£¬£¬£¬£¬£¬£¬£¬£¬EntityEditorWithPickerÓּ̳Ð×ÔEntityEditor£º
EntityEditorʵÏÖÁ˽ӿڣºIPostBackDataHandlerºÍICallbackEventHandler£¬£¬£¬£¬£¬£¬£¬£¬Æ¾¾ÝWebForm¿Ø¼þµÄÐÔÃüÖÜÆÚ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÒ³ÃæÖÐÓÐÊÂÎñ´¥·¢__doPostBack()ºó£¬£¬£¬£¬£¬£¬£¬£¬ÏÈŲÓÃͨ¹ýICallbackEventHandlerʵÏÖµÄRaiseCallbackEvent()²½ÖèºÍGetCallbackResult()²½ÖèµÃµ½±íµ¥ÄÚÈÝ£¬£¬£¬£¬£¬£¬£¬£¬ÔÙŲÓÃͨ¹ýIPostBackDataHandlerʵÏÖµÄLoadPostData()²½Öè¡£¡£¡£¡£¡£
»Øµ½EntityEditorÖп´GetCallbackResult()²½ÖèÖÐŲÓÃÁËInvokeCallbackEvent()²½Ö裬£¬£¬£¬£¬£¬£¬£¬InvokeCallbackEvent()²½ÖèŲÓÃÁËParseSpanData()²½Ö裺
À´µ½ParseSpanData()ÖÐÄܹ»¿´³öÕâÀï°Ñ±íµ¥Ìá½»µÄÊý¾Ý½øÐÐÁË´¦Öᣡ£¡£¡£¡£´Ë´¦Âß¼¼«¶È¸´ÔÓ£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÖ»¸ú¶ÔHiddenSpanDataµÄ´¦Öãº
¿É·¢Ïִ˲½Ö轫HiddenSpanDataµÄÖµ·ÅÈëÁËPickerEntityµÄListÖУ¬£¬£¬£¬£¬£¬£¬£¬ÔÚ¾¹ýһЩ´¦ÖúóÔ׸î³ÉÊý×飬£¬£¬£¬£¬£¬£¬£¬±éÀúÊý×飬£¬£¬£¬£¬£¬£¬£¬Ð½¨PickerEntity¶ÔÏópickerEntity2£¬£¬£¬£¬£¬£¬£¬£¬½«ÆäÖµ·ÅÈëpickerEntity2.KeyÖУ¬£¬£¬£¬£¬£¬£¬£¬×îÖÕ·ÅÈëarrayListÖв¢¸³Öµ¸øÀà³ÉÔ±±äÁ¿m_listOrderTemp:
»Øµ½LoadPostData()²½Öè¿´¶Ôm_listOrderTemp³ÉÔ±±äÁ¿µÄ´¦Ö㬣¬£¬£¬£¬£¬£¬£¬¿É¿´µ½ÔÚÕâÀï±éÀúÁËm_listOrderTemp³ÉÔ±±äÁ¿µÄÖµ²¢½«Æä¼Ó½øm_listRevalidation³ÉÔ±±äÁ¿ÖУ¬£¬£¬£¬£¬£¬£¬£¬¶øºóµü´ú½øÐÐValidate()²Ù×÷£º
ÔÚValidate()²½ÖèÖУ¬£¬£¬£¬£¬£¬£¬£¬½«m_listOrderTemp³ÉÔ±±äÁ¿¸³Öµ¸øm_listOrder³ÉÔ±±äÁ¿£º
¶øºó±éÀúEntitiesµÄֵŲÓÃValidateEntity()²½Ö裺
EntitiesµÄÖ·´×ÔÓÚÉÏÃæµÄÒ»Ðкܲ»ÆðÑÛµÄLambda±í°×ʽ²½Ö裬£¬£¬£¬£¬£¬£¬£¬´Ë²½Ö轫·µ»Øm_listOrder³ÉÔ±±äÁ¿µÄÖµ£º
¸úµ½ValidateEntity()²½Öè·¢ÏÖÊÇÐé²½Ö裬£¬£¬£¬£¬£¬£¬£¬Òò¶øÈ¥×ÓÀàÕÒ²½ÖèµÄ³Áд¡£¡£¡£¡£¡£
À´µ½EntityEditorWithPickerÀàÖп´µ½ÁËValidateEntity() ²½ÖèµÄ³Áд£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÔì佫PickerEntityµÄkey£¨pe.Key£©´«ÈëÁËMicrosoft.SharePoint.BusinessData.Infrastructure.EntityInstanceIdEncoder.DecodeEntityInstanceId()ÖС£¡£¡£¡£¡£
½øÈëDecodeEntityInstanceId() ²½Öè·¢ÏÖ·´ÐòÁл¯£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒXmlSerializer»ú¹Øº¯ÊýµÄÀàÐͲÎÊý¿É¿Ø¡£¡£¡£¡£¡£
²¹¶¡·ÖÎö£º
×°Öò¹¶¡KB4462211ºóÔٴη´±àÒ룬£¬£¬£¬£¬£¬£¬£¬¶Ô±ÈDecodeEntityInstanceId()²½ÖèµÄÔ´Â룬£¬£¬£¬£¬£¬£¬£¬·¢ÏÖÒѾ²»ÔÙÖ§³Ö¶ÔÏóÀàÐ͵ķ´ÐòÁл¯¡£¡£¡£¡£¡£
·ì϶ÀûÓÃ
ÔÚ·ì϶·ÖÎöʱ£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÔÚEntityInstanceIdEncoderÀàÖп´µ½ÁíÒ»¸ö²½ÖèEncodeEntityInstanceId(),Äܹ»Ö±½ÓʹÓÃËüÌìÉúPayload¡£¡£¡£¡£¡£
»ú¹ØXML£º
ÌìÉúPayload£º
ÌìÉúPayloadʱ»áµ¯³öÒ»´ÎÍÆËãÆ÷£¬£¬£¬£¬£¬£¬£¬£¬¹Øµô¼´¿É¡£¡£¡£¡£¡£
PoC£º
½¨¸´½¨Òé
Ŀǰ¹Ù·½ÒÑÍÆ³öÏàÓ¦²¹¶¡£¬£¬£¬£¬£¬£¬£¬£¬Ç뾡¿ìÉý¼¶½øÐн¨¸´¡£¡£¡£¡£¡£
Microsoft SharePoint Enterprise Server 2016
Security Update for Microsoft SharePoint Enterprise Server 2016(KB4462211)
https://www.microsoft.com/en-us/download/details.aspx?id=58072
Microsoft SharePoint Foundation 2013 Service Pack 1
Security Update for Microsoft SharePoint Enterprise Server 2013(KB4462202)
https://www.microsoft.com/en-us/download/details.aspx?id=58063
Microsoft SharePoint Server 2010 Service Pack 2
Security Update for 2010 Microsoft Business Productivity Servers(KB4462184)
https://www.microsoft.com/en-us/download/details.aspx?id=58066
Microsoft SharePoint Server 2019
Security Update for Microsoft SharePoint Server 2019 Core(KB4462199)
https://www.microsoft.com/en-us/download/details.aspx?id=58061
²Î¿¼Á´½Ó
https://www.thezdi.com/blog/2019/3/13/cve-2019-0604-details-of-a-microsoft-sharepoint-rce-vulnerability
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0604


¾©¹«Íø°²±¸11010802024551ºÅ