CVE-2019-1458 | Win32kÌØÈ¨ÌáÉý·ì϶

°ä²¼¹¦·ò 2019-12-12


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


1.²¼¾°ÃèÊö


½üÈÕMicrosoft°ä²¼ÁËÕë¶Ô36¸öCVE·ì϶µÄÁ½¸ö²¼¸æºÍ¸üС£ÔÚÕâЩ·ì϶ÖУ¬ÓÐ7¸ö±»·ÖÀàΪÑϳÁ£¬27¸ö±»·ÖÀàΪ³ÁÒª£¬1¸ö±»·ÖÀàΪÖУ¬1¸ö±»·ÖÀàΪµÍ¡£²¢ÇÒCVE-2019-1458·ì϶Òѱ»ÀûÓá£

½üÆÚ¿¨°Í˹»ù¼ì²âµ½µÄ¹¥»÷ÊÂÎñ³ÆOperation WizardÔÚ¹¥»÷¹ý³ÌÖÐʹÓÃÁËWindows·ì϶£¨CVE-2019-1458£©ºÍGoogle Chrome·ì϶£¨CVE-2019-13720£©£¬½«¶ñÒâÈí¼þÏÂÔØ²¢×°Öõ½½Ó¼ûº«ÓïÐÂÎÅÃÅ»§µÄWindowsÍÆËã»úÉÏ¡£


2.·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


CVE-2019-1458ÊÇWin32kÖеÄÌØÈ¨ÌáÉý·ì϶£¬Win32k×é¼þÎÞ·¨ÕýÈ·´¦ÖÃÄÚ´æÖеĶÔÏóʱ£¬µ¼ÖÂWindowsÖдæÔÚÒ»¸öÌØÈ¨ÌáÉý·ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÄÚºËģʽÏÂÔËÐÐËÁÒâ´úÂë¡£¶øºó¹¥»÷Õß¿ÉÄÜ»á×°Ö÷¨Ê½¡¢²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»ò´´½¨ÓµÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£

ÒªÀûÓô˷ì϶£¬¹¥»÷ÕßÊ×ÏȱØÐëµÇ¼ϵͳ¡£¹¥»÷Õß¿ÉÄÜÔËÐÐÄܹ»ÀûÓô˷ì϶²¢½ÚÔìÊÜÓ°ÏìϵͳµÄÌØÔìÀûÓ÷¨Ê½¡£

Áí±íGoogle·ì϶֮CVE-2019-13720ÒѾ­ÔÚChrome 78.0.3904.87Öн¨¸´£¬¿¨°Í˹»ù½«Chrome·ì϶¼ì²âΪExploit.Win32.Generic£¬½«Microsoft·ì϶¼ì²âΪPDM£ºExploit.Win32.Generic¡£


3.½¨¸´½¨Òé


Ŀǰ΢Èí¹Ù·½ÒѾ­°ä²¼¸Ã·ì϶µÄ²¹¶¡£¬½¨ÒéÓû§¸üе½×îа汾£¬ÒÔÏ÷¼õ¹¥»÷µÄ¿ÉÄÜÐÔ¡£



4.²Î¿¼Á´½Ó


https://securelist.com/windows-0-day-exploit-cve-2019-1458-used-in-operation-wizardopium/95432/

https://www.bleepingcomputer.com/news/security/windows-chrome-zero-days-chained-in-operation-wizardopium-attacks/

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1458