BitdefenderÃâ·Ñ°æÉ±¶¾Èí¼þÖеÄÌáȨ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-08-23

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-15295£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.9£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Bitdefender Antivirus Free 2020


·ì϶¸ÅÊö


Bitdefender EnginesÊÇÂÞÂíÄáÑDZÈÌØèóµÂ£¨Bitdefender£©¹«Ë¾µÄÒ»¿îɱ¶¾Èí¼þÒýÇæ¡£


Bitdefender Antivirus Ãâ·Ñ°æ±¾Öб»ÆØÒ»¸öÌáȨ·ì϶£¬¿Éµ¼Ö¹¥»÷Õß»ñȡΪ Windows ×î¸ßȨÏÞÕË»§³ï±¸µÄϵͳ¼¶±ðȨÏÞ¡£


¸Ã·ì϶ԴÓÚ²»×ã¶ÔÒÑÊðÃûÇÒ¼ÓÔØ×Ô¿ÉÐŵØÎ»µÄ¶þ½øÔìµÄÑéÖ¤Ôì³ÉµÄ¡£Bitdefender µÄ°²È«·þÎñ (vsserv.exe) ºÍ¸üзþÎñ (updatesrv.exe) ×÷ΪÒÔϵͳȨÏÞÊðÃûµÄ¹ý³Ì¶øÆô¶¯¡£È»¶ø£¬ËûÃdz¢ÊÔÔÚ PATH »·¾³±äÁ¿ÖеĶà¸öµØÎ»¼ÓÔØÃÔʧµÄÒ»¸ö DLL Îļþ (¡®RestartWatchDog.dll¡¯)£¬ÈçͼËùʾ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÆäÖÐÒ»¸öµØÎ»ÊÇ¡®c:/python27¡¯£¬ËüÏòËùÓÐÈÏÖ¤Óû§Ê¢¿ªÁ˽Ӽû½ÚÔìÁбí (ACL)£¬Ê¹ÌáȨ²Ù×÷´¹Êֿɵã¬ÓÉÓÚÕý³£È¨ÏÞµÄÓû§¿ÉÄÜд×ÅÃÔʧµÄ DLL²¢Í¨¹ý Bitdefender µÄÊðÃû¹ý³Ì¼ÓÔØËü¡£ÎÊÌâµÄ¸ùÒòÔÚÓÚServiceInstance.dll ¿âÊÔͼ¼ÓÔØÃÔʧµÄ DLL¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ£¬¹Ù·½ÒѰ䲼Á˽¨¸´¸Ã·ì϶£¬ÏÂÔØÁ´½Ó£º


https://www.bitdefender.com/support/security-advisories/untrusted-search-path-vulnerability-serviceinstance-dll-bitdefender-antivirus-free-2020/¡£


²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/security/bitdefender-fixes-privilege-escalation-bug-in-free-antivirus-2020/