Windows JScript ×é¼þ0day Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-06-01

·ì϶±àºÅ


CVEÔÝÎÞ


·ì϶¼¶±ð


ÖÐ


³§ÉÌ×ÔÆÀ£º6.8   CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


·ìϼûèÊö


½üÈÕ £¬windowsϵͳÓÖ·¢ÏÖһ·0day·ì϶ £¬¸Ã·ì϶ÊÇÓÉϵͳÖеÄJScript×é¼þÔì³ÉµÄ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÓû§µÄPCÉÏÖ´ÐжñÒâ´úÂë £¬ ¹ÌȻ΢Èí²¢Î´Ìṩ´òËãÍÆ³ö²¹¶¡¼òÖ±Çй¦·ò±í £¬µ«Ò»Î»½²»°ÈËÅú×¢ËûÃÇÔÚ½øÐн¨¸´¡£


5ÔÂ29ÈÕ £¬ZDI°ä²¼ÁËÒ»·Ý»ã±¨ £¬ÆäÖÐÔ̺¬ÓйظÃÃýÎóµÄ¾ßÌå¼¼Êõϸ½Ú£º


ÓÉÓڸ÷ì϶ӰÏì JScript ×é¼þ£¨Î¢Èí×Ô½ç˵µÄ JavaScript Ö´ÐУ© £¬Î¨Ò»µÄǰÌá¾ÍÊǹ¥»÷Õß±ØÐëÓÕÆ­Óû§½Ó¼ûÒ»¸ö¶ñÒâÍøÒ³»òÕßÔÚϵͳ¸ßµÍÔØ²¢´ò¿ª¶ñÒâ JS Îļþ£¨Í¨³£¾­ÓÉ Windows Script Host-wscript.exe Ö´ÐУ©¡£


Õâ¸öȱµã´æÔÚÓÚ JScript ¶Ô Error ¶ÔÏóµÄ´¦Öùý³ÌÖС£¹¥»÷Õßͨ¹ýÔÚJScript ÖÐÖ´ÐÐ×÷Ϊ £¬¿ÉÄܵ¼ÖÂij¸öÖ¸ÕëÔÚ¿ªÊͺóÔâ³ÁÓ᣹¥»÷ÕßÄÜÀûÓø÷ì϶ÔÚµ±Ç°¹ý³ÌÏÂÖ´ÐдúÂë¡£


¸Ã·ì϶µÄΣÏÕϵÊý²¢Ã»ÓÐÌýÉÏÈ¥µÄÄÇô¸ß £¬ÓÉÓÚËüÎÞ·¨µ¼ÖÂϵͳÔâÆëÈ«¹¥Ï¡£Õâ¸öȱµã½öÔÊÐíɳÏä»·¾³ÖеĴúÂëÖ´ÐÐÎÊÌâ¡£¹¥»÷Õß±ØÒªÆäËüÀûÓÃÄÜÁ¦ÌÓÀëɳÏä²¢ÔÚÖ¸±êϵͳÉÏÖ´ÐдúÂë¡£


΢ÈíÔÚÍÆ³ö²¹¶¡ £¬²»ÍâÒѾ­³¬³öÁËÅû¶սÊõÉèÖõŦ·òÖá¡£


ͨ³£ÔÚÅû¶ȱµãºó´ÍÓë³§ÉÌ120ÌìµÄ¹¦·ò°ä²¼²¹¶¡¡£´Ó΢Èí¸´Ô­µÄ¹¦·òÖáÀ´¿´ £¬Î¢ÈíÄÑÒÔ¸´ÏÖ´¥·¢¸Ã·ì϶µÄ PoC ´úÂë £¬´Ó¶øÆÆ·ÑÁË75%µÄÅû¶¹¦·òÖá £¬µ¼Ö¹¤³ÌʦÎÞ·¨ÊµÊ±¸ÏÔÚ5ÔµIJ¹¶¡ÐÇÆÚ¶þ²âÊÔ²¢°ä²¼²¹¶¡¡£


¹ÌȻ΢Èí²¢Î´Ìá¹©ÍÆ³ö²¹¶¡µÄ¾ßÌ幦·òÖá £¬µ«Î¢ÈíµÄÒ»Ãû½²»°ÈË֤ʵ³ÆÔÚÍÆ³ö½¨¸´¹æ»®¡£


ÔÚÅû¶·ì϶֮ʱ²¢Î´·¢ÏÖ·ì϶ÔâÀûÓõÄÇé¿ö¡£ÓÉÓÚÍøÉÏÏÕЩ²»´æÔÚ¼¼ÊõÏêÇé £¬Òò¶øÔÚ΢Èí°ä²¼½¨¸´¹æ»®Ç°ºÜ¿ÉÄÜ»¹ÊÇδÔâÀûÓõÄÇé¿ö¡£


½â¾ö´ëÊ©


½¨ÒéÓû§²»ÒªÊ¹ÓÃÒÀ¸½ JScript ×é¼þµÄÀûÓÃÈç IE ä¯ÀÀÆ÷¡¢wscript.exe µÈÀ´´¦Öò»ÊÜÐÅÀµµÄ JS ´úÂë»òÎļþ¡£


²Î¿¼×ÊÁÏ


https://www.zerodayinitiative.com/advisories/ZDI-18-534/


https://www.bleepingcomputer.com/news/security/remote-code-execution-vulnerability-disclosed-in-windows-jscript-component/