Microsoft | Windows Codecs & Visual Studio JSONÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ
°ä²¼¹¦·ò 2020-10-190x00 ·ì϶¸ÅÊö
²úÆ·Ãû³Æ | CVE ID | Àà ÐÍ | ·ì϶µÈ¼¶ | Ô¶³ÌÀûÓà | Ó°ÏìÁìÓò |
Windows Codecs | CVE-2020-17022 | RCE | ¸ßΣ | ÊÇ | |
Visual Studio Code | CVE-2020-17023 | RCE | ¸ßΣ | ÊÇ |
΢ÈíÓÚ2020Äê10ÔÂ15ÈÕ°ä²¼ÁËÁ½¸ö´ø±í°²È«¸üУ¬ÒÔ½¨¸´Microsoft Windows CodecsºÍVisual Studio CodeÖеÄÁ½¸öÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶¡£·ì϶¸ú×ÙΪCVE-2020-17022ºÍCVE-2020-17023£¬ÆäCVSSÆÀ·Ö¾ùΪ7.8¡£
0x01 ·ì϶ÏêÇé

Microsoft Windows CodecsÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-17022£©
Microsoft Windows CodecsÊÇMicrosoftµÄ±à½âÂëÆ÷¿â£¬ÆäÖеıà½âÂëÆ÷Ä£¿éÌṩÁËÓÃÓÚ¶ÔWindows·¨Ê½ÖеÄÊý¾Ý½øÐдúÂëת»»µÄÁ÷ºÍÎļþ½Ó¿Ú¡£¸Ã·ì϶ÊÇÓÉÓÚMicrosoft Windows Codecs¿âÔÚ´¦ÖÃÄÚ´æ¶ÔÏóµÄ·½Ê½ÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷ÕßÄܹ»Ê¹ÓöñÒâ»ú¹ØµÄµÄͼÏñÎļþÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£
Ó°ÏìÁìÓò£º
Windows 10 Version 1709 for 32-bit Systems
Windows 10 Version 1709 for ARM64-based Systems
Windows 10 Version 1709 for x64-based Systems
Windows 10 Version 1803 for 32-bit Systems
Windows 10 Version 1803 for ARM64-based Systems
Windows 10 Version 1803 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems
Windows 10 Version 1809 for ARM64-based Systems
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 1903 for 32-bit Systems
Windows 10 Version 1903 for ARM64-based Systems
Windows 10 Version 1903 for x64-based Systems
Windows 10 Version 1909 for ARM64-based Systems
Windows 10 Version 1909 for x64-based Systems
Windows 10 Version 2004 for 32-bit Systems
Windows 10 Version 2004 for ARM64-based Systems
Windows 10 Version 2004 for x64-based Systems
Visual Studio JSONÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-17023£©
MicrosoftµÄVisual Studio CodeÊÇMicrosoftÕë¶ÔWindows¡¢LinuxºÍmacOS¿ª·¢µÄÒ»ÖÖÃâ·ÑµÄÔ´´úÂë±à×ëÆ÷¡£
¹¥»÷ÕßÄܹ»Í¨¹ýÓÕʹÓû§´ò¿ª¶ñÒâµÄ¡° package.json¡±ÎļþÀ´ÀûÓô˷ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂë¡£
ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬Ôò¹¥»÷ÕßÄܹ»½ÚÔìÕû¸öϵͳ£¬ÀýÈç×°Ö÷¨Ê½¡¢²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý¡¢´´½¨ÓµÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§µÈ¡£
Ŀǰ£¬MicrosoftµÄ¸üÐÂÊÇͨ¹ýÅú¸ÄVisual Studio Code´¦ÖÃJSONÎļþµÄ·½Ê½À´½â¾öÁË´Ë·ì϶¡£
Ó°ÏìÁìÓò£º
Visual Studio Code 1.50.1֮ǰµÄ°æ±¾¡£
0x02 ´ëÖý¨Òé
ĿǰMicrosoftÒѰ䲼°²È«¸üУ¬½¨ÒéʵʱװÖÃÓйز¹¶¡¡£
£¨Ò»£© Windows update¸üÐÂ
×Ô¶¯¸üУº
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£
ÊÖ¶¯¸üУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ½«×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
4¡¢³ÁÆôÍÆËã»ú£¬×°ÖøüÐÂϵͳ³ÁÐÂÆô¶¯ºó£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
΢Èí¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
CVE-2020-17022Á´½ÓµØÖ·£º
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17022
CVE-2020-17023Á´½ÓµØÖ·£º
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17023
0x03 ²Î¿¼Á´½Ó
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17022
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17023
https://securityaffairs.co/wordpress/109665/security/microsoft-windows-rce.html?
https://threatpost.com/microsoft-rce-flaws-windows-update/160244/
0x04 ¹¦·òÏß
2020-10-15 Microsoft°ä²¼°²È«¸üÐÂ
2020-10-19 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ