|
Á¦¸ñ |
 |
[º¸¾È °æº¸] 2012³â 6¿ù 4ÀÏ Microsoft [º¸¾È ±Ç°í 2718704 ¹ÌÀÎÁõ µðÁöÅÐ ÀÎÁõ¼·Î ÀÎÇÑ ½ºÇªÇÎ ¹®Á¦Á¡] ¹ßÇ¥ |
|
Microsoft´Â ÃÖ±Ù¿¡ ¸Å¿ì Á¤±³ÇÑ ¹æ¹ýÀ¸·Î Á¤ÇØÁø ¸ñÇ¥¸¦ °ø°ÝÇÏ´Â ¡°Flame¡± À̶ó´Â º¹ÀâÇÑ ¾Ç¼ºÄڵ带 º¸°í ¹Þ¾Ò½À´Ï´Ù.
Flame ¾Ç¼ºÄÚµåÀÇ ÀϺΠ±¸¼º¿ä¼Ò°¡ Microsoft¿¡¼ Á¦ÀÛµÈ °Íó·³ Ç¥½ÃµÇ´Â ÀÎÁõ¼¸¦ ÀÌ¿ëÇÑ´Ù´Â °ÍÀ» ¹ß°ßÇÏ¿´°í, °ü·Ã ÀÎÁõ¼¸¦ ÇØÁ¦½ÃÄ×½À´Ï´Ù.
º¸´Ù ÀÚ¼¼ÇÑ Á¤º¸´Â ¾Æ·¡ Ãß°¡ Á¤º¸ÀÇ ºí·Î±×¸¦ Âü°íÇØ ÁֽʽÿÀ.
ÀÌ·¯ÇÑ °ø°Ý À¯ÇüÀº MicrosoftÀÇ ´ë´Ù¼ö °í°´²²´Â À§ÇèÀÌ ¾ø´Â °ÍÀ¸·Î º¸À̳ª, »ç¿ëÀÚ¸¦ º¸È£Çϱâ À§ÇØ ¸î °¡Áö Á¶Ä¡ ¹æ¹ýÀ» ¾È³»ÇÕ´Ï´Ù.
ù°, 2012³â 6¿ù 4ÀÏ(Çѱ¹ ½Ã°¢) ¿¡ Microsoft´Â Çã°¡µÇÁö ¾ÊÀº ÀÎÁõ¼¸¦ ÇØÁ¦ÇÏ´Â º¸¾È±Ç°í 2718704¸¦ ¹ßÇ¥ÇÏ¿´½À´Ï´Ù. Áï½Ã ¼³Ä¡ÇϽñ⸦ ±Ç°íÇÕ´Ï´Ù.
µÑ°, º¸¾È ±Ç°í2718704´Â ÀÚµ¿ ¾÷µ¥ÀÌÆ® µË´Ï´Ù.
¼Â°, Å͹̳Π¼¹ö ¶óÀ̼¾½Ì ¼ºñ½º(Terminal Server Licensing Service) ´Â ´õ ÀÌ»ó ÄÚµå ¼¸íµÈ ÀÎÁõ¼¸¦ ¹ß±ÞÇÏÁö ¾Ê½À´Ï´Ù.
º¸´Ù ÀÚ¼¼ÇÑ ³»¿ëÀº ¾Æ·¡ Á¤º¸¸¦ È®ÀÎÇØ ÁֽʽÿÀ.
Microsoft´Â ÀÌ ¹®Á¦¸¦ °è¼Ó ¿¬±¸Çϰí ÀÖÀ¸¸ç Ãß°¡ Á¤º¸¸¦ Á¦°øÇÒ ¿¹Á¤ÀÔ´Ï´Ù.
Microsoft ´Â 2012³â 6¿ù 4ÀÏ(Çѱ¹ ½Ã°¢)¿¡ [º¸¾È ±Ç°í 2718704 - ¹ÌÀÎÁõ µðÁöÅÐ ÀÎÁõ¼·Î ÀÎÇÑ ½ºÇªÇÎ ¹®Á¦Á¡] ¸¦ ¹ßÇ¥ÇÏ¿´½À´Ï´Ù.
¿ä¾à
Microsoft´Â ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® ÀÎÁõ ±â°ü(Microsoft Certificate Authority)À¸·ÎºÎÅÍ Çã°¡µÇÁö ¾ÊÀº µðÁöÅÐ ÀÎÁõ¼ ¸¦ ÀÌ¿ëÇÑ ½ÇÁ¦ °ø°Ý¿¡ ´ëÇÑ º¸°í¸¦ ¹Þ¾Ò½À´Ï´Ù.
Çã°¡µÇÁö ¾ÊÀº ÀÎÁõ¼´Â ÄÜÅÙÃ÷ ½ºÇªÇÎÀ̳ª ÇÇ½Ì °ø°Ý, MITM(Man-in-the-Middle)°ø°Ý¿¡ »ç¿ëµÉ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ¹®Á¦´Â ¸ðµç Áö¿ø ´ë»óÀÎ Windows ¸±¸®½º¿¡ ¿µÇâÀ» ¹ÌĨ´Ï´Ù.
Microsoft´Â ¸ðµç Áö¿ø ´ë»óÀÎ Windows ¸±¸®½º¿¡ ´ëÇÑ º¸¾È ¾÷µ¥ÀÌÆ®¸¦ Á¦°øÇÕ´Ï´Ù.
ÀÌ ¾÷µ¥ÀÌÆ®´Â ¾Æ·¡ÀÇ Intermediate CA ÀÎÁõ¼ ¿¡ ´ëÇÑ ½Å·Ú¸¦ ÇØÁ¦ÇÕ´Ï´Ù.
• Microsoft Enforced Licensing Intermediate PCA (2 °³ ÀÎÁõ¼)
• Microsoft Enforced Licensing Registration Authority CA (SHA1)
±Ç°í. Microsoft´Â ¸ðµç Áö¿ø ´ë»óÀÎ Windows ¸±¸®½º¿¡ ´ëÇÏ¿© ¾÷µ¥ÀÌÆ® °ü¸® ¼ÒÇÁÆ®¿þ¾î ¶Ç´Â Microsoft Update¼ºñ½º¸¦ ÀÌ¿ëÇÏ¿© Áï½Ã º¸¾È ±Ç°í 2718704¸¦ ¼³Ä¡ÇÒ °ÍÀ» ±Ç°íÇÕ´Ï´Ù.
Ãß°¡ Á¤º¸
• Microsoft Security Advisory 2718704 -Unauthorized Digital Certificates Could Allow Spoofing - http://technet.microsoft.com/security/advisory/2718704
• Microsoft Security Response Center (MSRC) Blog: http://blogs.technet.com/msrc
• Microsoft Malware Protection Center (MMPC) Blog: http://blogs.technet.com/mmpc
• Security Vulnerability Research & Defense (SRD) Blog: http://blogs.technet.com/srd
• Remote Desktop Services (Terminal Services) Team Blog: http://blogs.msdn.com/b/rds |
|
[2012-06-08] |
|