Windows Print SpoolerÔ¶³Ì´úÂëÖ´ÐÐ0 day·ì϶£¨CVE-2021-34527£©
°ä²¼¹¦·ò 2021-07-020x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-34527 | ʱ ¼ä | 2021-07-02 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | ËùÓÐWindows°æ±¾ |
¹¥»÷¸´ÔÓ¶È | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | ÊÇ |
0x01 ·ì϶ÏêÇé

Windows Print SpoolerÊÇWindowsµÄ´òÓ¡»úºó¶Ü´¦Ö÷¨Ê½£¬ÆäÖÎÀíËùÓб¾µØºÍÍøÂç´òÓ¡¶ÓÁв¢½ÚÔìËùÓдòÓ¡¹¤×÷£¬±»¿í·ºÀûÓÃÓÚ±¾µØºÍÄÚÍøÖС£
2021Äê6ÔÂ29ÈÕ£¬°²È«×êÑÐÈËÔ±ÔÚGitHubÉϹ«¿ªÁËÒ»¸öWindows Print SpoolerÔ¶³Ì´úÂëÖ´ÐÐ0day·ì϶£¨CVE-2021-34527£©¡£
±ØÒª°ÑÎȵÄÊÇ£¬¸Ã·ì϶£¨CVE-2021-34527£©ÓëMicrosoft 6ÔÂ8ÈÕÐÇÆÚ¶þ²¹¶¡ÈÕÖн¨¸´²¢ÓÚ6ÔÂ21ÈÕ¸üеÄÒ»¸öEoPÉý¼¶µ½RCEµÄ·ì϶£¨CVE-2021-1675£©²»ÊÇͳһ¸ö·ì϶¡£ÕâÁ½¸ö·ì϶ÀàËÆµ«·ÖÆç£¬¹¥»÷ÏòÁ¿Ò²·ÖÆç¡£
Ŀǰ¸Ã·ì϶ÒѾ¹«¿ªÅû¶£¬²¢ÇÒÒѳʴ˿ÌÒ°ÀûÓᣵ± Windows Print Spooler ·þÎñ²»ÕýÈ·µØÖ´ÐÐÌØÈ¨Îļþ²Ù×÷ʱ£¬´æÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ê¹Óà SYSTEM ȨÏÞÔËÐÐËÁÒâ´úÂë¡¢×°Ö÷¨Ê½¡¢²é¿´²¢¸ü¸Ä»òɾ³ýÊý¾Ý¡¢»ò´´½¨ÓµÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§£¬µ«¹¥»÷±ØÐëÉæ¼°Å²Óà RpcAddPrinterDriverEx() µÄ¾¹ýÉí·ÝÑéÖ¤µÄÓû§¡£
0x02 ´ëÖý¨Òé
Ŀǰ¸Ã·ì϶ÉÐ佨¸´¡£
½¨ÒéÖÕ³¡²¢½ûÓÃWindows Print Spooler·þÎñ¡£
ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527
0x03 ²Î¿¼Á´½Ó
https://github.com/afwu/PrintNightmare
https://www.bleepingcomputer.com/news/security/public-windows-printnightmare-0-day-exploit-allows-domain-takeover/
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527
0x04 ¹¦·òÏß
2021-07-01 Microsoft°ä²¼°²È«¹«¸æ
2021-07-02 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ