Win10±¾µØÌáȨ0day·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-08-29·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÎÞ£¬Î£ÏÕ¼¶±ð£º¸ß£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Windows 10 32/64λ²Ù×÷ϵͳ
·ì϶¸ÅÊö
2018Äê8ÔÂ27ÈÕ£¬°²È«×êÑÐÈËÔ±ÔÚgithubÉϰ䲼ÁË×îеÄwin10x64°æµÄ±¾µØÌáȨ·ì϶£¬²¢ÇÒÔÚÍÆÌØÉÏ¶ÔÆäÌáȨµÄdemo½øÐÐÁËÑÝʾ¡£ÔÚgithubÉϵÄSandboxEscaperÉÏÓÐ×ÅÆëÈ«µÄ·ì϶ÀûÓ÷¨Ê½ÒÔ¼°demo£¬²¢ÇÒ±»ÆäËû°²È«×êÑÐר¼Ò֤ʵ¸Ã·ì϶Äܹ»ÔÚ×î½üµÄwin10Éϸ´ÏÖ¡£
¸Ã·ì϶µÄÔÒòÔÚÓÚwin10ϵͳµÄ¹¤×÷µ÷¶È·þÎñÖÐÓÐalpcµÄŲÓýӿڣ¬¸Ã½Ó¿Úµ¼³öÁËSchRpcSetSecurityº¯Êý£¬¸Ãº¯ÊýÕýÊDZ¾´Î·ì϶ÀûÓõ½µÄº¯Êý¡£¸Ãº¯ÊýµÄÔÐÍÈçÏ£º
[in][string] wchar_t* arg_1, //Task name
[in][string] wchar_t* arg_2, //Security Descriptor string
[in]long arg_3);
µ±ËÁÒâȨÏÞµÄÓû§Å²Óøú¯Êýʱ£¬¸Ãº¯Êý»á¼ì²â c:\windows\tasksĿ¼ÏÂÊÇ·ñ´æÔÚÒ»¸öºó׺ΪjobµÄÎļþ£¬ÈôÊǸÃÎļþ´æÔÚ»áÏò¸ÃÎļþдÈëÖ¸¶¨µÄDACLÊý¾Ý¡£±¾´Î·ì϶ÀûÓõķ½Ê½¼´Í¨¹ýÓ²Á´½ÓµÄ·½Ê½½«¸ÃjobÎļþÖ¸¶¨Á´½Óµ½Ìض¨µÄdllÉÏ£¬ÕâÑùµ±Óû§Å²Óøú¯Êýʱ»áÏòÌØ¶¨µÄdllдÈëÊý¾Ý£¬¶øÌض¨µÄdllÍùÍùÊÇϵͳ¼¶´ËÍâdll¡£ÔÚgithubÉϰ䲼µÄ·ì϶ÀûÓ÷¨Ê½Ôò»áÏòprintconfig.dllдÈëÌáȨ´úÂ룬²¢Í¨¹ýÆô¶¯´òÓ¡·þÎñspoolsv.exeÀ´Ö´ÐÐÌáȨ´úÂ룬´Ó¶øÊµÏÖÄÚºËÌáȨ¡£
·ì϶ÑéÖ¤
ËæºóÀûÓÃieä¯ÀÀÆ÷½øÐвâÊÔʱ·¢ÏÖÎÞ·¨ÀûÓóɹ¦£¬¹ÌÈ»·ì϶ÀûÓõÄdllÒѾ±»Ð´Èëµ½spoolsv.exeÖУ¬µ«È´Ã»ÓÐʵÏÖ·ìÏ¶ÕæÕýµÄ³ÉЧ¡£½ÓÏÂÀ´ÒÀÕÕÑÝʾdemoÖеIJÙ×÷£¬´ò¿ªÒ»¸önotepad·¨Ê½£¬²¢¶Ônotepad·¨Ê½½øÐÐ×¢Èë¡£
Ëæºó²é¿´spoolsv.exeϵÄËùÓÐ×Ó¹ý³Ì£¬·¢ÏÖ¸Ãnotepad.exe·¨Ê½±»spoolsv.exe·¨Ê½³Áдò¿ª£¬ºÍgithubÉϵķì϶ÀûÓõÄdemoÖеijÉЧһÖ£¬Äܹ»È·¶¨·ì϶ÀûÓóɹ¦¡£
¶ø¸ÃdllµÄÅú¸Ä¹¦·òÒ²ÏÔʾÊǸոշì϶ÀûÓõŦ·ò£¬ÖÁ´Ë·ì϶¸´Ïֳɹ¦¡£
½¨¸´½¨Òé
³§ÉÌÉÐδ°ä²¼Óйز¹¶¡£¬ÉóÉ÷Ö´ÐÐδ¾ÉóºËÆðÔ´¶ÔµÄ·¨Ê½¡£
²Î¿¼Á´½Ó
https://github.com/SandboxEscaper/randomrepo


¾©¹«Íø°²±¸11010802024551ºÅ