Intel Wi-FiÇý¶¯·ì϶·ÖÎö

°ä²¼¹¦·ò 2021-04-27

Intel Wi-FiоƬ¿í·ºÀûÓÃÓÚÓ×ÎұʼDZ¾µçÄÔ²úÆ·£¬ÈçThinkPad¡¢Dell±Ê¼Ç±¾µÈ ¡£2020Ä꣬ZDI×éÖ¯Åû¶ÁËIntelÎÞÏßÍø¿¨WindowsÇý¶¯·¨Ê½ÖдæÔÚCVE-2020-0557 ºÍ CVE-2020-0558·ì϶ ¡£ÆäÖУ¬CVE-2020-0557µÄCVSS v3.0ÆÀ·ÖΪ 8.1 ·Ö£¬CVE-2020-0558µÄCVSS v3.0ÆÀ·ÖΪ 8.2 ·Ö ¡£Í¨¹ýÕâÁ½¸ö·ì϶£¬¹¥»÷ÕßÄܹ»ÔÚÊܺ¦ÕßµçÄÔÖÐÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë ¡£


·ì϶±àºÅÓ°ÏìµÄÎÞÏßÍø¿¨Ó°ÏìÇý¶¯
CVE-2020-0557AC 7265 Rev D¡¢AC 3168¡¢AC 8265ºÍAC8260Intel PROSet/Wireless WiFi Software 21.70֮ǰ°æ±¾
CVE-2020-0558AC8265Intel PROSet/Wireless WiFi Software 21.70֮ǰ°æ±¾


CVE-2020-0558·ì϶·ÖÎö


1¡¢·ì϶µÀÀí

µ±APÈȵ㴦ÖÃAssocReqʱ£¬»áŲÓÃprvhPanClientSaveAssocRespº¯Êý±£ÁôAssocReqÖ¡ÖÐSSIDµÄÖµ£¬ÔÚ´¦ÖÃSSIDµÄ¹ý³ÌÖУ¬»áŲÓÃparse_ieº¯Êý´ÓÊý¾ÝÖ¡ÖÐÈ¡³össidµÄTLV½á¹¹£¬²¢Å²ÓÃmemcpy_sº¯Êý½«ssidµÄÄÚÈݸ´Ôìµ½Ö¸±ê»º³åÇø ¡£ÔÚŲÓÃmemcpy_sº¯ÊýµÄʱ³½£¬ÃýÎóµØÊ¹ÓÃssidµÄlength×÷ΪÊý¾Ý¸´Ô쳤¶È£¬µ±ssidµÄ³¤¶È´óÓÚÖ¸±ê»º³åÇøµÄ³¤¶Èʱ£¬»áµ¼Ö»º³åÇøÒç³ö ¡£º¯ÊýŲÓÃͼÈçÏÂËùʾ£º


1.jpg


2¡¢ÎÊÌâ´úÂë

ŲÓÃparse_ieº¯Êý´ÓÊý¾ÝÖ¡ÖÐÈ¡³össidµÄTLV½á¹¹£¬²¢Å²ÓÃmemcpy_sº¯Êý½«ssidµÄÄÚÈݸ´Ôìµ½Ö¸±ê»º³åÇø ¡£ÔÚŲÓÃmemcpy_sº¯ÊýµÄʱ³½£¬ÃýÎóµØÊ¹ÓÃssidµÄlength×÷ΪÊý¾Ý¸´Ô쳤¶È£¬µ±ssidµÄ³¤¶È´óÓÚÖ¸±ê»º³åÇøµÄ³¤¶Èʱ£¬»áµ¼Ö»º³åÇøÒç³ö ¡£±ÉÈËͼÖУ¬¹¥»÷ÕßÄܹ»½ÚÔì*(v8+1)µÄÖµ£¬Äܹ»¿½±´³¬³¤µÄÊý¾Ý¸´Ôìµ½Ö¸±êµØÖ·ÖУ¬´Ó¶øµ¼Ö»º³åÇøÒç³ö ¡£ÈçÏÂͼËùʾ£º


2.jpg


3¡¢·ì϶½¨¸´

а汾µÄ´úÂëÖÐʹÓÃosalMemoryCopyº¯Êý´úÌæÁËÔ­À´µÄmemcpy_sº¯Êý£¬Áí±í°ÑSSID¿½±´µÄ×î´ó³¤¶ÈÇ¿ÔìÉèΪ32×Ö½Ú£¬ÕâÑù¾ÍÔ¤·ÀÁË»º´æÇøÒç³öµÄÎÊÌâ ¡£ÈçÏÂͼËùʾ£º


3.jpg


CVE-2020-0557·ì϶·ÖÎö


1¡¢·ì϶µÀÀí

µ±APÈȵ㴦ÖÃAssocReqʱ£¬»áŲÓÃprvhPanClientSaveAssocRespº¯Êý´¦ÖÃAssocReqÖ¡ÖеÄÊý¾Ý£¬ÆäÖÐÔÚº¯ÊýÖлáŲÓÃprvGoVifClientAssocStoreSupportedChannelsº¯ÊýÀ´´¦Öü°±£ÁôÒªÇó¶Ëͨ·ÐÅÏ¢£¬ÕâÆäÖÐprvGoVifClientAssocStoreSupportedChannelsº¯Êý»áÑ­»·Å²ÓÃutilRegulatoryClassToChannelListÀ´´¦ÖÃRegulatoryClass£¨¹ÜÔìÒªÇó£©ÐÅÏ¢ ¡£ÓÉÓÚÔÚÑ­»·´¦ÖÃûÓÐ˼¿¼Ö¸±êµÄÆ«ÒÆÊÇ·ñÔ½½ç£¬µ±APÈȵã½Ó¹Üµ½AssocReqÊý¾ÝÖ¡ÖÐRegulatoryClassÐÅÏ¢µ¥ÔªÓжà¸öÐÅ·Êý¾Ýʱ»áµ¼ÖÂÔ½½çд ¡£º¯ÊýŲÓÃͼÈçÏÂͼËùʾ£º


4.jpg



2¡¢ÎÊÌâ´úÂë

prvGoVifClientAssocStoreSupportedChannelsº¯Êý£¬ÈçÏÂͼËùʾ£º

 

5.jpg

6.jpg


3¡¢·ì϶½¨¸´

ÔÚа汾 ÍƽøÁ˶Ե±Ç°indexµÄÅжÏ£¬ÈôÊÇindex´óÓÚ255ÔòÍ˳öÑ­»· ¡£ÈçÏÂͼËùʾ£º


7.jpg


 4¡¢·ì϶ÑéÖ¤



²Î¿¼Á´½Ó£º

¡¾1¡¿https://www.thezdi.com/blog/2020/5/4/analyzing-a-trio-of-remote-code-execution-bugs-in-intel-wireless-adapters


GA»Æ½ð¼×»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


ADLab³ÉÁ¢ÓÚ1999Ä꣬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¸ÅÏëÊ×ÍÆÕß ¡£½ØÖ¹Ä¿Ç°£¬ADLabÒÑͨ¹ýCVEÀۼư䲼°²È«·ì϶½ü1100¸ö£¬Í¨¹ý CNVD/CNNVDÀۼư䲼°²È«·ì϶1000Óà¸ö£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼ ¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç²Ù×÷ϵͳÓëÀûÓÃϵͳ°²È«×êÑÓ×¢ÖÇÄÜÖն˰²È«×êÑÓ×¢ÎïÁªÍøÖÇÄÜÉ豸°²È«×êÑÓ×¢Web°²È«×êÑÓ×¢¹¤¿ØÏµÍ³°²È«×êÑÓ×¢ÔÆ°²È«×êÑÐ ¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑÓ×¢¹ú¶È³Áµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ ¡£


adlab.jpg