PowerShell CoreµÄWDACÈÆ¹ý·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-07-18

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1167£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


PowerShell Core 6.0
PowerShell Core 6.1

PowerShell Core 6.2


·ì϶¸ÅÊö


PowerShell CoreÊÇÒ»Ì×ΪÒìÀà»·¾³ºÍ»ìºÏÔÆ¹¹½¨µÄ¿çƽ̨ºÅÁîÐо籾ִÐл·¾³¡£


MicrosoftÅû¶ÁËÒ»¸öWindows DefenderÀûÓ÷¨Ê½½ÚÔ죨WDAC£©°²È«Ö°ÄÜÈÆ¹ý·ì϶£¬WDACÊÇMicrosoftÌṩµÄÒ»ÖÖ°²È«²úÆ·£¬Ö»ÔÊÐíÔÚWindowsÖÐÔËÐÐÊÜÐÅÀµµÄÀûÓ÷¨Ê½ºÍÇý¶¯·¨Ê½¡£ÕâÖÖ°×Ãûµ¥·½Ãæ·¨ÌṩÁËÏÔÖøµÄ°²È«ÐԸĽø£¬ÓÉÓÚÖ»ÓÐÊÜÐÅÀµµÄÀûÓ÷¨Ê½ÄÜÁ¦ÔËÐУ¬¶ø¶ñÒâÈí¼þµÈδ֪ÀûÓ÷¨Ê½Ê¼ÖÕ²»»á±»ÔÊÐí¡£


´Ë·ì϶¿ÉÄÜÔÊÐí¹¥»÷ÕßÈÆ¹ýWDACÇ¿ÔìÖ´ÐС£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÈƹýÍÆËã»úÉϵÄPowerShellÖ÷ÌâÔ¼ÊøËµ»°Ä£Ê½¡£


ÒªÀûÓô˷ì϶£¬¹¥»÷ÕßÊ×ÏÅצӵÓжÔPowerShellÔÚÔ¼ÊøËµ»°Ä£Ê½ÏÂÔËÐеı¾µØÍÆËã»úµÄÖÎÀíÔ±½Ó¼ûȨÏÞ¡£ÕâÑù¹¥»÷ÕßÄܹ»ÒÔ·ÇÔ¤ÆÚµÄ·½Ê½½Ó¼û×ÊÔ´¡£


´Ë¸üÐÂͨ¹ý¸üÕýPowerShellÔÚÔ¼ÊøËµ»°Ä£Ê½ÏµÄÔËÐз½Ê½À´½â¾ö·ì϶¡£


Òª²é³­ÔÚÔËÐеÄPowerShell°æ±¾²¢È·¶¨ÄúÊÇ·ñÈÝÒ×Êܵ½¹¥»÷£¬Äܹ»´ÓºÅÁîÌáÐÑ·ûÖ´ÐÐpwsh -vºÅÁî¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 
ÈôÊÇÄú֪·װÖÃÁËPowerShell Core£¬µ«pwsh.exeºÅÁî²»Æð×÷Óã¬ÄÇôÄúʹÓõÄÊÇPowerShell Core 6.0£¬²¢ÇÒ±ØÒª¸üе½¸üеİ汾¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£ 


½¨¸´½¨Òé


Microsoft½¨²¹ÁË·ì϶£¬Çë¸üе½×îа汾¡£


²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1167