目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2021-24105— Microsoft 程序包管理器服务安全漏洞

一分钟漏洞结论

影响对象
Microsoft Package Manager Configurations
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Microsoft Windows Package Manager(程序包管理器)是美国微软(Microsoft)公司的一个综合的程序包管理器解决方案。用于自动安装、升级、配置和使用软件的系统或工具集。 大多数程序包管理器都是设计用于发现和安装开发人员工具。 Microsoft 程序包管理器服务中存在安全漏洞。以下产品和版本受到影响:Package Manager Configurations。

CVSS 8.4 · High EPSS 2.37% · P83
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2021-24105 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Package Managers Configurations Remote Code Execution Vulnerability
来源: CVE Program / CVE List V5
Vulnerability Description
<p>Depending on configuration of various package managers it is possible for an attacker to insert a malicious package into a package manager's repository which can be retrieved and used during development, build, and release processes. This insertion could lead to remote code execution. We believe this vulnerability affects multiple package managers across multiple languages, including but not limited to: Python/pip, .NET/NuGet, Java/Maven, JavaScript/npm.</p> <p><strong>Attack scenarios</strong></p> <p>An attacker could take advantage of this ecosystem-wide issue to cause harm in a variety of ways. The original attack scenarios were discovered by Alex Birsan and are detailed in their whitepaper, <a href="https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610">Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies</a>.</p> <ul> <li><p>With basic knowledge of the target ecosystems, an attacker could create an empty shell for a package and insert malicious code in the install scripts, give it a high version, and publish it to the public repository. Vulnerable victim machines will download the higher version of the package between the public and private repositories and attempt to install it. Due to code incompatibility it will probably error out upon import or upon compilation, making it easier to detect; however the attacker would have gained code execution by that point.</p> </li> <li><p>An advanced attacker with some inside knowledge of the target could take a copy of a working package, insert the malicious code (in the package itself or in the install), and then publish it to a public repository. The package will likely install and import correctly, granting the attacker an initial foothold and persistence.</p> </li> </ul> <p>These two methods could affect target organizations at any of these various levels:</p> <ul> <li>Developer machines</li> <li>An entire team if the configuration to import the malicious package is uploaded to a code repository</li> <li>Continuous integration pipelines if they pull the malicious packages during the build, test, and/or deploy stages</li> <li>Customers, download servers, production services if the malicious code has not been detected</li> </ul> <p>This remote code execution vulnerability can only be addressed by reconfiguring installation tools and workflows, and not by correcting anything in the package repositories themselves. See the <strong>FAQ</strong> section of this CVE for configuration guidance.</p>
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Microsoft 程序包管理器服务安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Microsoft Windows Package Manager(程序包管理器)是美国微软(Microsoft)公司的一个综合的程序包管理器解决方案。用于自动安装、升级、配置和使用软件的系统或工具集。 大多数程序包管理器都是设计用于发现和安装开发人员工具。 Microsoft 程序包管理器服务中存在安全漏洞。以下产品和版本受到影响:Package Manager Configurations。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Microsoft Package Manager Configurations N/A -

二、漏洞 CVE-2021-24105 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2021-24105 的情报信息

请登录查看更多情报信息。

CVE-2021-24105 厂商安全公告 (1)

同批安全公告 · Microsoft · 2021-02-25 · 共 58 条

CVE-2021-24074 9.8 CRITICAL Microsoft Windows TCP/IP 安全漏洞
CVE-2021-24077 9.8 CRITICAL Microsoft Windows 传真服务安全漏洞
CVE-2021-24078 9.8 CRITICAL Microsoft Windows DNS 服务器安全漏洞
CVE-2021-24094 9.8 CRITICAL Microsoft Windows tcp/ip 安全漏洞
CVE-2021-24072 8.8 HIGH Microsoft SharePoint 安全漏洞
CVE-2021-24066 8.8 HIGH Microsoft SharePoint 代码问题漏洞
CVE-2021-24093 8.8 HIGH Microsoft Graphics Components 安全漏洞
CVE-2020-17162 8.8 HIGH Microsoft Windows 安全特征漏洞
CVE-2021-24088 8.8 HIGH Microsoft Windows 本地后台处理程序安全漏洞
CVE-2021-1728 8.8 HIGH Microsoft System Center Operations Manager 安全特征问题漏洞
CVE-2021-24112 8.1 HIGH Microsoft .NET Core 安全漏洞
CVE-2021-26701 8.1 HIGH Microsoft .NET Core 安全漏洞
CVE-2021-1722 8.1 HIGH Microsoft Windows 传真服务安全漏洞
CVE-2021-1726 8.0 HIGH Microsoft SharePoint 安全漏洞
CVE-2021-24102 7.8 HIGH 多款 Microsoft 产品安全特征问题漏洞
CVE-2021-24069 7.8 HIGH Microsoft Excel 安全漏洞
CVE-2021-24091 7.8 HIGH Microsoft Windows 缓冲区错误漏洞
CVE-2021-24081 7.8 HIGH Microsoft Windows Codecs 库 缓冲区错误漏洞
CVE-2021-24092 7.8 HIGH Microsoft Defender 安全特征问题漏洞
CVE-2021-24096 7.8 HIGH Microsoft Windows 安全漏洞

显示前 20 条,共 58 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2021-24105

暂无评论


发表评论