¡¾·ì϶µý±¨¡¿Spectre CPU·ì϶£¨CVE-2017-5753£©
°ä²¼¹¦·ò 2021-03-020x00 ·ì϶¸ÅÊö
CVE ID | CVE-2017-5753 | ʱ ¼ä | 2021-03-02 |
Àà ÐÍ | Éè¼ÆÃýÎó | µÈ ¼¶ | |
Ô¶³ÌÀûÓà | Ó°ÏìÁìÓò |
0x01 ·ì϶ÏêÇé

2021Äê03ÔÂ01ÈÕ£¬°²È«×êÑÐÈËÔ±ÖìÀû°²¡¤ÎÖÒÁÉ£¨Julien Voisin£©ÔÚVirusTotal¶ñÒâÈí¼þ·ÖÎöƽ̨ÉÏ·¢ÏÖÁËSpectre CPU·ì϶£¨CVE-2017-5753£©µÄLinux°æºÍWindows°æµÄ·ì϶ÀûÓ÷¨Ê½£¬Õⰵʾ¿ÉÄܽøÐÐÏÖʵ·ÛËé²¢ÆëÈ«±øÆ÷»¯µÄÓÐЧÀûÓ÷¨Ê½ÒѾÔÚ¹«¹²ÁìÓòÖй«¿ª¡£
Spectre CPU·ì϶ÊÇ2018Äê1ÔÂGoogle Project ZeroÅû¶µÄIntel¡¢AMDºÍARM´¦ÖÃÆ÷¼Ü¹¹ÖеÄÓ²¼þÉè¼ÆÈ±µã£¨Meltdown£ºCVE-2017-5754¡¢Spectre£ºCVE-2017-5753ºÍCVE-2017-5715£©£¬¹¥»÷Õß¿ÉÄÜÀûÓ÷ì϶ÔËÐÐÀûÓ÷¨Ê½ÖеĴúÂëÀ´·ÛËé·ÖÆçÀûÓ÷¨Ê½Ö®¼äÔÚCPU²ãÃæµÄ¸ôÀ룬¶øºóÇÔȡͳһϵͳÉÏÔËÐÐµÄÆäËüÀûÓõÄÃô¸ÐÊý¾Ý¡£
Google°µÊ¾£¬Spectre CPU·ì϶»áÓ°ÏìÔ̺¬Windows¡¢Linux¡¢macOS¡¢AndroidºÍChromeOSµÈÔÚÄÚµÄÖ÷Á÷²Ù×÷ϵͳ¡£×Ô¾õÏָ÷ì϶ÒÔÀ´£¬ËùÓÐÖ÷Á÷CPUºÍOS¹©¸øÉ̾ù°ä²¼Á˹̼þ²¹¶¡ºÍÈí¼þ½¨¸´£¬µ«ÉÐδ¸üÐÂÆäϵͳµÄÓû§ÒÀÈ»ÈÝÒ×Êܵ½Spectre CPU·ì϶µÄ¹¥»÷£¬ÓÈÆäÊÇʹÓþɰæÐ¾Æ¬²¢ÔËÐоɰæ²Ù×÷ϵͳµÄÓû§£¨Èç2015Äê´úµÄPC£¬²¢Ê¹ÓÃHaswell»ò¾ÉµÄIntel´¦ÖÃÆ÷£©¡£
VirusTotalÉϵķì϶ÀûÓ÷¨Ê½ÊÇÉϸöÔÂÉÏ´«µÄ£¬¸ÃÈí¼þ°üÊǺÏÓÃÓÚWindowsºÍLinuxµÄImmunity Canvas 7.26×°Ö÷¨Ê½(Immunity CANVASΪȫÇòµÄÉøÈë²âÊÔÈËÔ±ºÍ°²È«×¨ÒµÈËÔ±ÌṩÁËÊý°ÙÖÖ·ì϶ÀûÓá¢×Ô¶¯»¯µÄ·ì϶ÀûÓÃϵͳÒÔ¼°È«Ãæ¡¢¿¿µÃסµÄ·ì϶ÀûÓÿª·¢¿ò¼Ü)¡£

´Ë·ì϶ÀûÓ÷¨Ê½Äܹ»Ê¹Í¨³£Óû§Äܹ»´ÓÖ¸±êÉ豸µÄÄÚºËÄÚ´æÖÐת´¢WindowsϵͳºÍLinuxϵͳÖÐ/etc/shadowÎļþÖеÄLM/NT¹þÏ£¡£´Ë±í£¬¸ÃÀûÓ÷¨Ê½»¹¿ÉÄÜת´¢Kerberos tickets£¬¿ÉÓëPsExecһ·ÓÃÓÚWindowsϵͳµÄ±¾µØÈ¨ÏÞÉý¼¶ºÍºáÏòÒÆ¶¯¡£ÕâÒâζ×Å£¬ÈôÊǸ÷ì϶±»³É¹¦ÀûÓã¬Ôò¹¥»÷ÕßÄܹ»ÇÔÈ¡ÊÜÓ°ÏìϵͳµÄÃô¸ÐÊý¾Ý£¬Ô̺¬ÃÜÂë¡¢ÎĵµÒÔ¼°ÄÚ´æÖÐÈκοÉÓÃµÄÆäËüÊý¾Ý¡£


ÈçVoisinËù˵£¬´ò¹ý¸Ã·ì϶²¹¶¡µÄLinux»òWindowsϵͳÔò²»ÊÜÓ°Ïì¡£¶øÎ¢Èí°µÊ¾£¬ÓÉÓÚ×°Öò¹¶¡ºóϵͳ»úÄÜ»áÓÐÏÔÖøµÄ½µÂ䣬Òò¶øÓû§×îÈÝÒ×Ìø¹ýÀûÓûº½â´ëÊ©¡£
³ý´ËÖ®±í£¬¼´±ã¹¥»÷ÕßÄõ½ÁËÕâÁ½¸ö·ì϶ÀûÓ÷¨Ê½Èí¼þ°üÖеÄÈκÎÒ»¸ö£¬Ö»ÔËÐÐËüÃÇÒ²²»»á²úÉúÈκÎÁ˾֣¬ÓÉÓÚËüÃǶ¼Ö»ÄÜÔÚÕýÈ·µÄ²ÎÊýÏÂÖ´ÐУ¬³ý·Ç¹¥»÷Õß¿ÉÄÜÔËÐÐÕýÈ·µÄ²ÎÊý¡£
0x02 ´ëÖý¨Òé
Spectre CPU·ì϶ÒÑÓÚ2018Ä꽨¸´£¬½¨Òéδʵʱ¸üеÄÓû§²Î¿¼CPUºÍOS¹©¸øÉ̹ٷ½°ä²¼µÄ½¨¸´·¨Ê½»ò»º½â´ëÊ©¡£
Õë¶Ôwindowsϵͳ£¬Î¢Èíͨ¹ý¸ü¸ÄWindowsºÍоƬ΢´úÂëÀ´»º½â´Ë·ì϶£¬²¢½¨ÒéʹÓÃWindows UpdateºÍоƬ΢´úÂë¸üС£
ÏêÇéÁ´½Ó£º
https://www.microsoft.com/security/blog/2018/01/09/understanding-the-performance-impact-of-spectre-and-meltdown-mitigations-on-windows-systems/
0x03 ²Î¿¼Á´½Ó
https://www.virustotal.com/gui/file/6461d0988c835e91eb534757a9fa3ab35afe010bec7d5406d4dfb30ea767a62c/detection
https://www.bleepingcomputer.com/news/security/working-windows-and-linux-spectre-exploits-found-on-virustotal/?
https://dustri.org/b/spectre-exploits-in-the-wild.html
https://therecord.media/first-fully-weaponized-spectre-exploit-discovered-online/
0x04 ¹¦·òÏß
2021-03-01 Julien VoisinÅû¶ÀûÓ÷¨Ê½
2021-03-02 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ