微軟證實目前Windows還有兩個未修補的遠 - 3C
By Skylar DavisLinda
at 2020-03-24T21:05
at 2020-03-24T21:05
Table of Contents
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/adv200006
微軟在今天證實目前Windows含有兩個未修補的遠端程式碼執行(RCE)漏洞。且已經有
實作攻擊的案例
這兩個漏洞都是利用Adobe Type Manager Library來觸發,Adobe Type Manager Library
起源是Adobe與微軟共同研發的OpenType字型,並使用上述工具讓Windows顯示該字型。
而在Windows Vista時期Adobe就已經將此工具交由微軟維護,所以跟Adobe基本上已經沒
甚麼關係了
該漏洞的觸發模式就是利用刻意改造過的字型來觸發錯誤,並進行遠端攻擊。估計從
Windows 7至Windows 10皆有此漏洞
微軟已經正在進行修補,但修補程式最快也會跟隨在4月份的Patch Tuesday釋出。微軟建
議在更新還沒釋出前關閉檔案總管的縮圖預覽功能,同時也關閉WebClient服務
https://i.imgur.com/P2j5LDV.png
另外一個方法是修改ATMFD.DLL的名稱。但這會造成部分使用OpenType字型的應用程式無
法運作,且在Win10 1709後就已經無此檔案。請斟酌使用
若需要修改,請在管理員權限下的cmd.exe輸入下列指令(以Win 10 64-bit版本為例)
cd "%windir%\system32"
takeown.exe /f atmfd.dll
icacls.exe atmfd.dll /save atmfd.dll.acl
icacls.exe atmfd.dll /grant Administrators:(F)
rename atmfd.dll x-atmfd.dll
cd "%windir%\syswow64"
takeown.exe /f atmfd.dll
icacls.exe atmfd.dll /save atmfd.dll.acl
icacls.exe atmfd.dll /grant Administrators:(F)
rename atmfd.dll x-atmfd.dll1
重開機後生效
若要回復的話請輸入下列指令
cd "%windir%\system32"
rename x-atmfd.dll atmfd.dll
icacls.exe atmfd.dll /setowner "NT SERVICE\TrustedInstaller"
icacls.exe . /restore atmfd.dll.acl
cd "%windir%\syswow64"
rename x-atmfd.dll atmfd.dll
icacls.exe atmfd.dll /setowner "NT SERVICE\TrustedInstaller"
icacls.exe . /restore atmfd.dll.acl
重開機後生效
--
作者 kech9111 (...) 看板 Gossiping
標題 [問卦] 有沒有亞洲只剩台灣沒有知名樂園的八卦?
時間 Wed Dec 24 19:18:26 2014
--
微軟在今天證實目前Windows含有兩個未修補的遠端程式碼執行(RCE)漏洞。且已經有
實作攻擊的案例
這兩個漏洞都是利用Adobe Type Manager Library來觸發,Adobe Type Manager Library
起源是Adobe與微軟共同研發的OpenType字型,並使用上述工具讓Windows顯示該字型。
而在Windows Vista時期Adobe就已經將此工具交由微軟維護,所以跟Adobe基本上已經沒
甚麼關係了
該漏洞的觸發模式就是利用刻意改造過的字型來觸發錯誤,並進行遠端攻擊。估計從
Windows 7至Windows 10皆有此漏洞
微軟已經正在進行修補,但修補程式最快也會跟隨在4月份的Patch Tuesday釋出。微軟建
議在更新還沒釋出前關閉檔案總管的縮圖預覽功能,同時也關閉WebClient服務
https://i.imgur.com/P2j5LDV.png
另外一個方法是修改ATMFD.DLL的名稱。但這會造成部分使用OpenType字型的應用程式無
法運作,且在Win10 1709後就已經無此檔案。請斟酌使用
若需要修改,請在管理員權限下的cmd.exe輸入下列指令(以Win 10 64-bit版本為例)
cd "%windir%\system32"
takeown.exe /f atmfd.dll
icacls.exe atmfd.dll /save atmfd.dll.acl
icacls.exe atmfd.dll /grant Administrators:(F)
rename atmfd.dll x-atmfd.dll
cd "%windir%\syswow64"
takeown.exe /f atmfd.dll
icacls.exe atmfd.dll /save atmfd.dll.acl
icacls.exe atmfd.dll /grant Administrators:(F)
rename atmfd.dll x-atmfd.dll1
重開機後生效
若要回復的話請輸入下列指令
cd "%windir%\system32"
rename x-atmfd.dll atmfd.dll
icacls.exe atmfd.dll /setowner "NT SERVICE\TrustedInstaller"
icacls.exe . /restore atmfd.dll.acl
cd "%windir%\syswow64"
rename x-atmfd.dll atmfd.dll
icacls.exe atmfd.dll /setowner "NT SERVICE\TrustedInstaller"
icacls.exe . /restore atmfd.dll.acl
重開機後生效
--
作者 kech9111 (...) 看板 Gossiping
標題 [問卦] 有沒有亞洲只剩台灣沒有知名樂園的八卦?
時間 Wed Dec 24 19:18:26 2014
噓 ineedadvice: 你把5566放在哪 12/24 19:19
→ ineedadvice: ......看錯12/24 19:19
推 KYALUCARD: ....要介紹眼鏡行嗎?12/24 19:19
--
Tags:
3C
All Comments
By Leila
at 2020-03-26T00:26
at 2020-03-26T00:26
By Tristan Cohan
at 2020-03-28T16:47
at 2020-03-28T16:47
By Leila
at 2020-03-29T04:22
at 2020-03-29T04:22
By Mason
at 2020-03-31T23:42
at 2020-03-31T23:42
By Agnes
at 2020-04-03T10:06
at 2020-04-03T10:06
By Mary
at 2020-04-04T13:28
at 2020-04-04T13:28
By Noah
at 2020-04-09T07:23
at 2020-04-09T07:23
By Liam
at 2020-04-12T15:49
at 2020-04-12T15:49
By Hedda
at 2020-04-12T19:37
at 2020-04-12T19:37
By Hedy
at 2020-04-17T12:39
at 2020-04-17T12:39
By Xanthe
at 2020-04-19T01:07
at 2020-04-19T01:07
By Candice
at 2020-04-22T10:42
at 2020-04-22T10:42
By Rae
at 2020-04-23T10:59
at 2020-04-23T10:59
By Lily
at 2020-04-26T15:34
at 2020-04-26T15:34
By Ivy
at 2020-04-30T14:53
at 2020-04-30T14:53
By Enid
at 2020-05-03T13:49
at 2020-05-03T13:49
By Freda
at 2020-05-08T04:27
at 2020-05-08T04:27
By Doris
at 2020-05-11T06:14
at 2020-05-11T06:14
Related Posts
40K長輩看盤機
By Quanna
at 2020-03-24T19:18
at 2020-03-24T19:18
在線式UPS
By Olivia
at 2020-03-24T19:15
at 2020-03-24T19:15
COMPUTEX 2020 延期至9月28-30日
By Olivia
at 2020-03-24T19:14
at 2020-03-24T19:14
為何有些產品明明維修客服等等問題一堆,
By Olive
at 2020-03-24T19:09
at 2020-03-24T19:09
70K含螢幕 電競爽機
By Ivy
at 2020-03-24T18:54
at 2020-03-24T18:54