tigerzyj 发表于 2024-11-13 09:32

CVE-2024-43639 RCE漏洞可能是下一个永恒之蓝吗

CVE-2024-43639 - Windows Kerberos Remote Code Execution Vulnerability

这个漏洞影响几乎所有的服务器,不需要登录就可以直接远程执行。那些已经过了服务期没有补丁可打的老系统要小心了。




I don’t often get excited about bugs (ok – that’s a lie – I totally do), but this CVSS 9.8 bug excites me. The vulnerability allows a remote, unauthenticated attacker to run code on an affected system by leveraging a bug in the cryptographic protocol. No user interaction is required. Since Kerberos runs with elevated privileges, that makes this a wormable bug between affected systems. What systems are impacted? Every supported version of Windows Server. I somehow doubt this will actually be seen in the wild, but I wouldn’t take that chance. Test and deploy this fix quickly.



wjqok 发表于 2024-11-13 12:14

我赶紧登陆我的支付宝!还好,里面的两百块钱还在

wjqok 发表于 2024-11-13 12:16

我艹!内容发出去以后不一样!!!

wjqok 发表于 2024-11-13 12:18

沙发我点编辑又是截图的内容...

Okorain 发表于 2024-11-18 15:23

楼上什么操作,没看懂。{:9_352:}
页: [1]
查看完整版本: CVE-2024-43639 RCE漏洞可能是下一个永恒之蓝吗