Hacker News

Kotsi ea Ts'ebetso ea Khoutu ea Remote ea Windows Notepad

Kotsi ea Ts'ebetso ea Khoutu ea Remote ea Windows Notepad Tlhahlobo ena e felletseng ea lifensetere e fana ka tlhahlobo e qaqileng ea likarolo tsa eona tsa mantlha le litlamorao tse pharalletseng. Libaka tsa Bohlokoa tsa Tsepamiso Lipuisano li shebane le: Mekhoa ea mantlha...

10 min read Via www.cve.org

Mewayz Team

Editorial Team

Hacker News

Ho se ho khethiloe ho ba kotsing ea ho ba kotsing ea Windows Notepad App Remote Code (RCE), e lumellang bahlaseli ho sebelisa likhoutu tse amehang ka ho qhekella basebelisi ho bula faele e entsoeng ka mokhoa o ikhethileng. Ho utloisisa hore na ts'oaetso ena e sebetsa joang - le mokhoa oa ho sireletsa lits'ebetso tsa khoebo ea hau - ho bohlokoa molemong oa mokhatlo ofe kapa ofe o sebetsang maemong a kajeno a kotsi.

Hantlentle Ke Eng Hantle-ntle Kotsi ea Windows Notepad ea Remote Code Eseng?

Windows Notepad, eo e leng khale e nkuoa e le mohlophisi oa mongolo o se nang kotsi, o se nang letho o kopantsoeng le mofuta o mong le o mong oa Microsoft Windows, esale e nkuoa e le bonolo haholo ho boloka liphoso tse tebileng tsa ts'ireletso. Khopolo eo e ipakile e fosahetse ka tsela e kotsi. Kotsi ea Ts'ebetso ea Khoutu ea Remote ea Windows ea Notepad e sebelisa bofokoli ba tsela eo Notepad e fetisang lifomate tse ling tsa lifaele le ho sebetsana le kabo ea memori nakong ea ho fana ka litaba tsa mongolo.

Motheong oa eona, sehlopha sena sa ts'okelo hangata se kenyelletsa buffer overflow or memory error e hlahisitsoeng ha Notepad e sebetsana le faele e hlophisitsoeng hampe. Ha mosebedisi a bula tokomane e entsoeng - hangata e ikgakanya e le .txt e se nang kotsi kapa faele ya log - shellcode ea mohlaseli e sebetsa ho latela moelelo oa nako ea mosebedisi. Hobane Notepad e sebetsa ka tumello ea mosebelisi ea keneng, mohlaseli a ka fumana taolo e felletseng ea litokelo tsa phihlello tsa ak'haonte eo, ho kenyelletsa phihlello ea ho bala / ho ngola lifaeleng tse hlokolosi le lisebelisoa tsa marang-rang.

Microsoft e buile ka likeletso tse ngata tse amanang le ts'ireletso tse amanang le Notepad lilemong tsa morao tjena ka potoloho ea eona ea Patch Labobeli, e nang le bofokoli bo thathamisitsoeng tlasa li-CVE tse amang Windows 10, Windows 11, le likhatiso tsa Windows Server. Mochini oa ts'ebetso o ts'oana: ho hloleha ha mohopolo ho baka maemo a ka sebetsoang a fetang ts'ireletso e tloaelehileng ea mohopolo.

Vector ea Tlhaselo e sebetsa Joang maemong a Sebele a Lefatše?

Ho utloisisa ketane ea tlhaselo ho thusa mekhatlo ho haha ​​ts'ireletso e sebetsang haholoanyane. Boemo bo tloaelehileng ba tšebeliso e mpe bo latela tatellano e ka lebelloang:

  • Delibari: Motho ea hlasetseng o etsa faele e lonya ebe o e phatlalatsa ka lengolo-tsoibila la bosholu, lihokelo tse kotsi tsa ho khoasolla, li-drive tsa marang-rang tse arolelanoang, kapa litšebeletso tsa polokelo ea leru tse senyehileng.
  • Sehlomathiso: Motho ea hlokofalitsoeng o tobetsa faele habeli, e buloang ho Notepad ka ho sa feleng ka lebaka la litlhophiso tsa Windows tsa ho kopanya lifaele tsa .txt, .log, le likeketso tse ling tse amanang le tsona.
  • ts'ebeliso ea memori: Enjene ea ho bala ea Notepad e kopana le data e sa sebetseng hantle, e bakang qubu kapa qubu e tlokomang e fetisang lintlha tsa bohlokoa tsa mohopolo tse nang le litekanyetso tse laoloang ke bahlaseli.
  • Kemiso ea Shellcode: Taolo ea phallo e lebisoa ho mojaro o kentsoeng, o ka khoasollang malware a mang, oa tiisa hore ha ho na malware, oa hlahisa lintlha tse itseng, kapa oa tsamaisa marang-rang ka thōko.
  • Keketseho ea litokelo (ka boikhethelo): Haeba e kopantsoe le ts'ebeliso e mpe ea sebaka sa lehae, mohlaseli a ka nyoloha ho tloha ho mokhoa o tloaelehileng oa mosebelisi ho ea ho phihlello ea boemo ba SYSTEM.

Se etsang hore sena se be kotsi haholo ke ts'epo e felletseng eo basebelisi ba e behang ho Notepad. Ho fapana le lifaele tse sebetsang, litokomane tse hlakileng ha li hlahlojoe hangata ke basebetsi ba amehileng ka ts'ireletso, e leng se etsang hore ho fana ka lifaele tse entsoeng ke sechaba ho atlehe haholo.

Key Insight: Likotsi tse kotsi ka ho fetisisa ha li fumanehe kamehla lits'ebetsong tse rarahaneng, tse shebaneng le marang-rang - hangata li lula lithulusing tse tšepahalang tsa letsatsi le letsatsi tseo mekhatlo e so kang ea li nka e le ts'okelo. Windows Notepad ke mohlala oa buka ea kamoo menahano ea lefa mabapi le software e "sireletsehileng" e hlahisang menyetla ea tlhaselo ea sejoale-joale.

Ke Likotsi life tse Bapisoang ho Feta Tikoloho e Fapanong ea Windows?

Bothata ba ts'oaetso ena bo fapana ho latela tikoloho ea Windows, tlhophiso ea litokelo tsa mosebelisi, le boemo ba taolo ea patch. Maemo a likhoebo a ntse a sebetsa Windows 11 ka liapdeite tsa morao-rao tse bokellaneng le Microsoft Defender e hlophisitsoeng ka har'a block mode sefahleho se fokotsehile haholo ha se bapisoa le mekhatlo e tsoetseng pele, e sa lokisoang Windows 10 kapa maemo a Windows Server.

💡 DID YOU KNOW?

Mewayz replaces 8+ business tools in one platform

CRM · Invoicing · HR · Projects · Booking · eCommerce · POS · Analytics. Free forever plan available.

Start Free →

On Windows 11, Microsoft e hahile Notepad bocha e nang le liphutheloana tsa sejoale-joale, ea e sebelisa joalo ka sesebelisoa sa Lebenkele la Microsoft se nang le sandbox se ikhethileng ka AppContainer litlhophisong tse itseng. Phetoho ena ea meralo e fana ka phokotso e utloahalang - leha RCE e ka finyelloa, sebaka sa mohlaseli se thibeloa ke moeli oa AppContainer. Leha ho le joalo, sandboxing ena ha e sebelisoe hohle hohle Windows 11 tlhophiso, le Windows 10 tikoloho ha e fumane tšireletso e joalo ka boiketsetso.

Mekhatlo e koaletseng Lintlafatso tsa Windows tse ikemetseng - e leng tlhophiso e tloaelehileng ka mokhoa o makatsang tikolohong e sebelisang software ea khale - e lula e pepesitsoe nako e telele kamora hore Microsoft e lokolle likotlo. Kotsi e ata libakeng tseo basebelisi ba sebetsang ka tloaelo ka litokelo tsa batsamaisi ba lehae, e leng tlhophiso e tlolang molao-motheo oa menyetla e fokolang empa e tsoela pele haholo likhoebong tse nyane le tse mahareng.

Ke Mehato Efe eo Likhoebo li Lokelang ho e Nka Hanghang ho Fokotsa Kotsi Bona?

Ho kokobetsa ka nepo ho hloka mokhoa o hlophisitsoeng o sebetsanang le bofokoli ba hona joale le likheo tsa boemo ba ts'ireletso tse etsang hore tšebeliso e be teng:

  1. Kenya lipeche hang-hang: Netefatsa hore lisistimi tsohle tsa Windows li na le liapdeite tsa morao-rao tse kenyelletsoeng. Bea pele lintlha tse sebelisoang ke basebetsi ba sebetsanang le likhokahano le lifaele tsa kantle.
  2. Hlahloba litlhophiso tsa mekhatlo ea lifaele: Hlahloba le ho thibela hore na ke lisebelisoa life tse behiloeng e le litšoari tsa kamehla bakeng sa lifaele tsa .txt le .log khoebong eohle, haholo-holo libakeng tsa boleng bo holimo.
  3. Eketsa litokelo tse fokolang: Tlosa litokelo tsa batsamaisi ba lehae ho tsoa ho li-account tse tloaelehileng tsa basebelisi. Leha RCE e ka finyelloa, litokelo tse fokolang tsa basebelisi li fokotsa haholo tšusumetso ea bahlaseli.
  4. Kenya mokhoa o tsoetseng pele oa ho lemoha: Lokisa litharollo tsa ho lemoha le ho arabela (EDR) ho beha leihlo tšebetso ea Notepad, ho tšoaea tšebetso e sa tloaelehang ea bana kapa likhokahano tsa marang-rang.
  5. Koetliso ea tlhokomeliso ea basebelisi: Ruta basebetsi hore esita le lifaele tse ngotsoeng ka mokhoa o hlakileng li ka sebelisoa, e leng ho matlafatsang lipelaelo tse nepahetseng mabapi le lifaele tse sa kōptjoang ho sa tsotellehe hore na li ka atolosoa joang.
.

Mefokolo joalo ka Windows Notepad RCE e totobatsa 'nete e tebileng: lisebelisoa tse arohaneng, tsa lefa li baka kotsi e arohaneng ea ts'ireletso. Kopo e 'ngoe le e' ngoe e eketsehileng ea komporo e sebetsang litsing tsa basebetsi ke vector e ka bang teng. Mekhatlo e kopanyang ts'ebetso ea khoebo ho li-platform tsa sejoale-joale, tse fumanehang marung, e fokotsa ts'epo ea eona ho lits'ebetso tsa Windows tse kentsoeng sebakeng sa heno - 'me ka mokhoa o hlakileng li fokotsa tlhaselo ea tsona.

Mehaho e kang Mewayz, tsamaiso ea khoebo ea 207-module e tšeptjoang ke basebelisi ba fetang 138,000, e thusa lihlopha ho laola CRM, mesebetsi ea morero, ts'ebetso ea khoebo ea e-commerce, liphaephe tsa litaba tsa marang-rang ka mokhoa o sireletsehileng oa ho buisana le bareki. Ha mesebetsi ea mantlha ea khoebo e phela ka har'a lits'ebetso tse thata tsa maru ho fapana le lits'ebetso tsa Windows tse kentsoeng sebakeng sa heno, kotsi e hlahisoang ke bofokoli joalo ka Notepad RCE e fokotsehile haholo bakeng sa ts'ebetso ea letsatsi le letsatsi.

Lipotso Tse Botsoang Hangata

Na Notepad ea Windows e ntse e le kotsing haeba ke na le Windows Defender e butsoitseng?

Windows Defender e fana ka tshireletso e matla kgahlanong le mesaeno e tsebahalang, empa ha se sebaka sa ho patch. Haeba ts'ireletso e le letsatsi la lefela kapa e sebelisa shellcode e sa bonahaleng ha e so fumanwe ke mesaeno ya Defender, tshireletso ya ntlha e le nngwe e ka se thibele tlhekefetso. Kamehla beha pele ho sebelisa likarolo tsa ts'ireletso tsa Microsoft joalo ka phokotso ea mantlha, 'me Defender e sebetsa e le karolo e tlatsetsang ea ts'ireletso.

Na ts'oaetso ee e ama mefuta eohle ea Windows?

Tlhahiso e itseng e fapana ho ya ka mofuta wa Windows le boemo ba patch. Windows 10 le tikoloho ea Windows Server ntle le lisebelisoa tsa morao-rao tse bokellaneng li kotsing e kholo. Windows 11 e nang le Notepad e ikhethileng ea AppContainer e na le likhaello tse ling tsa meralo, leha tsena li sa sebelisoe hohle. Lisebelisoa tsa Server Core tse sa kenyelletseng Notepad litlhophisong tsa tsona tsa kamehla li fokolitse ponahalo. Kamehla hlahloba Tataiso ea Ts'ireletso ea Microsoft bakeng sa ho sebetsa ka mofuta o itseng oa CVE.

Nka tseba jwang haeba sistimi ya ka e se e senyehile ka lebaka la tlokotsi ee?

Lipontšo tsa ho sekisetsa li kenyelletsa lits'ebetso tse sa lebelloang tsa bana tse hlahisitsoeng ke notepad.exe, likhokahano tse sa tloaelehang tsa marang-rang ho tsoa ts'ebetsong ea Notepad, mesebetsi e mecha e reriloeng kapa linotlolo tsa registry tse entsoeng nakong eo faele e belaetsang e buloa, le ts'ebetso e makatsang ea ak'haonte ea mosebelisi kamora ketsahalo ea ho bula tokomane. Hlahloba Litlaleho tsa Ketsahalo ea Windows, haholo-holo lintlha tsa Tšireletso le Tšebeliso, le litšupiso tse amanang le telemetry ea EDR haeba e le teng.

Ho lula ka pele ho bofokoli ho hloka ho falimeha le lisebelisoa tse nepahetseng tsa ts'ebetso. Mewayz e fa khoebo ea hau sebaka se sireletsehileng sa sejoale-joale sa ho kopanya tšebetso le ho fokotsa ho its'etleha ka lithulusi tsa khale tsa komporo — ho qala ka $19/khoeli feela. Fumana Mewayz ho app.mewayz.com 'me u bone hore na basebelisi ba 00,03 ba sebetsa hantle hakae, kajeno.

Try Mewayz Free

All-in-one platform for CRM, invoicing, projects, HR & more. No credit card required.

Start managing your business smarter today

Join 30,000+ businesses. Free forever plan · No credit card required.

Ready to put this into practice?

Join 30,000+ businesses using Mewayz. Free forever plan — no credit card required.

Start Free Trial →

Ready to take action?

Start your free Mewayz trial today

All-in-one business platform. No credit card required.

Start Free →

14-day free trial · No credit card · Cancel anytime