Win10±¾µØÌáȨ0day·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-08-29

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÎÞ £¬Î£ÏÕ¼¶±ð£º¸ß £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Windows 10 32/64λ²Ù×÷ϵͳ


·ì϶¸ÅÊö


2018Äê8ÔÂ27ÈÕ £¬°²È«×êÑÐÈËÔ±ÔÚgithubÉϰ䲼ÁË×îеÄwin10x64°æµÄ±¾µØÌáȨ·ì϶ £¬²¢ÇÒÔÚÍÆÌØÉÏ¶ÔÆäÌáȨµÄdemo½øÐÐÁËÑÝʾ¡£ÔÚgithubÉϵÄSandboxEscaperÉÏÓÐ×ÅÆëÈ«µÄ·ì϶ÀûÓ÷¨Ê½ÒÔ¼°demo £¬²¢ÇÒ±»ÆäËû°²È«×êÑÐר¼Ò֤ʵ¸Ã·ì϶Äܹ»ÔÚ×î½üµÄwin10Éϸ´ÏÖ¡£


¸Ã·ì϶µÄÔ­ÒòÔÚÓÚwin10ϵͳµÄ¹¤×÷µ÷¶È·þÎñÖÐÓÐalpcµÄŲÓýӿÚ £¬¸Ã½Ó¿Úµ¼³öÁËSchRpcSetSecurityº¯Êý £¬¸Ãº¯ÊýÕýÊDZ¾´Î·ì϶ÀûÓõ½µÄº¯Êý¡£¸Ãº¯ÊýµÄÔ­ÐÍÈçÏ£º


long _SchRpcSetSecurity(
[in][string] wchar_t* arg_1, //Task name
[in][string] wchar_t* arg_2, //Security Descriptor string

[in]long arg_3);


µ±ËÁÒâȨÏÞµÄÓû§Å²Óøú¯Êýʱ £¬¸Ãº¯Êý»á¼ì²â c:\windows\tasksĿ¼ÏÂÊÇ·ñ´æÔÚÒ»¸öºó׺ΪjobµÄÎļþ £¬ÈôÊǸÃÎļþ´æÔÚ»áÏò¸ÃÎļþдÈëÖ¸¶¨µÄDACLÊý¾Ý¡£±¾´Î·ì϶ÀûÓõķ½Ê½¼´Í¨¹ýÓ²Á´½ÓµÄ·½Ê½½«¸ÃjobÎļþÖ¸¶¨Á´½Óµ½Ìض¨µÄdllÉÏ £¬ÕâÑùµ±Óû§Å²Óøú¯Êýʱ»áÏòÌØ¶¨µÄdllдÈëÊý¾Ý £¬¶øÌض¨µÄdllÍùÍùÊÇϵͳ¼¶´ËÍâdll¡£ÔÚgithubÉϰ䲼µÄ·ì϶ÀûÓ÷¨Ê½Ôò»áÏòprintconfig.dllдÈëÌáȨ´úÂë £¬²¢Í¨¹ýÆô¶¯´òÓ¡·þÎñspoolsv.exeÀ´Ö´ÐÐÌáȨ´úÂë £¬´Ó¶øÊµÏÖÄÚºËÌáȨ¡£


·ì϶ÑéÖ¤


±¾´Î¸´ÏÖʹÓÃÁËwin10x64°æ £¬Ê×ÏÈʹÓÃgithubÉÏÌṩµÄ·ì϶ÀûÓù¤¾ß £¬²é¿´Æä¾ßÌåÓ÷¨¡£¸Ã·ì϶ÀûÓù¤¾ßµÄÖØÒª·½Ê½ÊÇͨ¹ýdll×¢ÈëµÄ·½Ê½ÏòµÍȨÏ޵Ĺý³Ì×¢ÈëÄܹ»ÊµÏÖÕûÌ×ÌáȨ¹¥»÷µÄshellcode¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ËæºóÀûÓÃieä¯ÀÀÆ÷½øÐвâÊÔʱ·¢ÏÖÎÞ·¨ÀûÓóɹ¦ £¬¹ÌÈ»·ì϶ÀûÓõÄdllÒѾ­±»Ð´Èëµ½spoolsv.exeÖÐ £¬µ«È´Ã»ÓÐʵÏÖ·ìÏ¶ÕæÕýµÄ³ÉЧ¡£½ÓÏÂÀ´ÒÀÕÕÑÝʾdemoÖеIJÙ×÷ £¬´ò¿ªÒ»¸önotepad·¨Ê½ £¬²¢¶Ônotepad·¨Ê½½øÐÐ×¢Èë¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ëæºó²é¿´spoolsv.exeϵÄËùÓÐ×Ó¹ý³Ì £¬·¢ÏÖ¸Ãnotepad.exe·¨Ê½±»spoolsv.exe·¨Ê½³Áдò¿ª £¬ºÍgithubÉϵķì϶ÀûÓõÄdemoÖеijÉЧһÖ £¬Äܹ»È·¶¨·ì϶ÀûÓóɹ¦¡£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½ÓÏÂÀ´²é¿´spoolsv.exeÖеĵÚÈý·½¶¯Ì¬¿â £¬Äܹ»¿´µ½ÎÒÃÇÀûÓ÷ì϶ËùÅú¸ÄµÄdll

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶ø¸ÃdllµÄÅú¸Ä¹¦·òÒ²ÏÔʾÊǸոշì϶ÀûÓõŦ·ò £¬ÖÁ´Ë·ì϶¸´Ïֳɹ¦¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾ 

Poc£ºhttps://github.com/SandboxEscaper/randomrepo


½¨¸´½¨Òé


³§ÉÌÉÐδ°ä²¼Óйز¹¶¡ £¬ÉóÉ÷Ö´ÐÐδ¾­ÉóºËÆðÔ´¶ÔµÄ·¨Ê½¡£


²Î¿¼Á´½Ó


https://thehackernews.com/2018/08/windows-zero-day-exploit.html
https://github.com/SandboxEscaper/randomrepo