ASUS ATK Package¿ÉÐÅõè¾¶´úÂëÖ´Ðзì϶£¨CVE-2019-19235£©
°ä²¼¹¦·ò 2019-12-21

1.²¼¾°ÃèÊö
SafeBreach LabsÔÚASUS ATKÈí¼þ°üÖз¢ÏÖÁËÒ»¸ö·ì϶£¨CVE-2019-19235£©£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚÌØÈ¨¹ý³Ì£¨NT AUTHORITY\SYSTEM£©µÄ¸ßµÍÎÄÖÐÖ´ÐÐδÊðÃûµÄ¿ÉÖ´ÐÐÎļþ£¨exe£©£¬´Ó¶øÈƹý¼ì²â²¢»ñµÃÓÆ¾ÃÐÔ¡£
2.·ì϶Áбí
CVE ID £º CVE-2019-19235
CVSSÆÀ·Ö£º ÔÝδÆÀ¶¨
Ó°ÏìÁìÓò£º ATK Package 1.0.0060¼°Ö®Ç°µÄËùÓа汾
3.·ì϶ÏêÇé
»ªË¶ATKÈí¼þ°üÊÇԤװÖÃÔÚ»ªË¶PCÉϵÄʵÓù¤¾ß£¬ÆäASLDR·þÎñ£¨AsLdrSrv.exe£©ÒÔNT AUTHORITY\SYSTEMÌØÈ¨ÕË»§ÔËÐУ¬¸Ã·þÎñµÄ¿ÉÖ´ÐÐÎļþÓÉ¡° ASUSTek Computer Inc.¡±ÊðÃû¡£AsLdrSrv.exeÔÚÖ´ÐÓ×°C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe¡±Îļþǰ£¬»áÏȲéÕÒÒÔÏÂ3¸öÃÔʧµÄexeÎļþ¡£
C:\Program.exe
C:\Program Files(x86)\ASUS\ATK.exe
C:\Program Files(x86)\ASUS\ATK Package\ATK.exe
Òò¶ø£¬¹¥»÷ÕßÄܹ»½«ËÁÒâδÊðÃûµÄEXEÎļþ¼ÓÔØ½øºÏ·¨¹ý³Ì²¢ÒÔNT AUTHORITY\SYSTEMÖ´ÐУ¨ÎÞÐè¸ü¸Ä·þÎñµÄõè¾¶»ò¸²¸ÇÈκÎÎļþ£©¡£
µ¼Ö¸ÃÎÊÌâµÄÔÒòÊÇAsLdrSrv.exeÊÔͼ´ÓÕýÈ·µÄõè¾¶¼ÓÔØHControl.exeʱ£¬´æ´¢¸Ãõè¾¶µÄATK_path»º³åÇøÄÚµÄ×Ö·û´®Ã»ÓмÓÒýºÅ£¬ÓÉÓÚ¸Ãõè¾¶´æÔÚ¿Õ¸ñ£¬Ê¹µÃCreateProcessAsUserWº¯Êý³¢ÊÔ×ÔÐнâÎöõè¾¶£¬Òò¶ø·¨Ê½»á²éÕÒÕâ3¸ö²»´æÔÚµÄexeÎļþ¡£
4.½¨¸´½¨Òé
½¨Òé¸üÐÂÖÁ×îа汾1.0.0061
5.²Î¿¼Á´½Ó
https://safebreach.com/Post/ASUS-ATK-Package-Unquoted-Search-Path-and-Potential-Abuses-CVE-2019-19235
https://nvd.nist.gov/vuln/detail/CVE-2019-19235
https://www.asus.com/Static_WebPage/ASUS-Product-Security-Advisory/


¾©¹«Íø°²±¸11010802024551ºÅ