΢Èí | ¶à¸ö0day·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-05-21

0x00 ·ì϶¸ÅÊö



²úÆ·

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Ó°ÏìÁìÓò

Windows

CVE-2020-0915

EOA

¸ßΣ

Windows

CVE-2020-0986

EOA

¸ßΣ

CVE-2020-0916

EOA

¸ßΣ

CVE-2020-0915

II

µÍΣ

ÔÝÎÞ

AE

¸ßΣ


0x01 ·ì϶ÏêÇé


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



2020Äê5ÔÂ19ÈÕ£¬Ç÷Ïò¿Æ¼¼£¨ZDI£©µÄ°²È«×¨¼ÒÅû¶ÁËMicrosoft WindowsÖÐÎå¸ö0day·ì϶£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶À´Éý¼¶WindowsÍÆËã»úÉϵÄÌØÈ¨¡£

CVE-2020-0916/CVE-2020-0986/CVE-2020-0915 ÊÇMicrosoft Windows splwow64²»ÊÜÐÅÀµµÄÖ¸Õë½â³ýÒýÓÃÌØÈ¨Éý¼¶·ì϶£¬CVSSÆÀ·Ö7.0¡£¿Éµ¼Ö¹¥»÷ÕßÔÚÊÜÓ°ÏìϵͳÉÏÌáÉýȨÏÞ¡£¸Ã·ì϶ӰÏìÓû§Ä£Ê½´òÓ¡»úÇý¶¯·¨Ê½Ö÷»ú¹ý³Ìsplwow64.exe£¬²¢ÇÒÊÇÓÉÓÚ¶Ìȱ¶ÔÓû§ÌṩµÄÊäÈëÑéÖ¤ËùÒýÆðµÄ¡£¹¥»÷ÕßÊ×ÏȱØÒª»ñµÃ¶ÔϵͳµÄµÍ½Ó¼ûȨÏÞÄÜÁ¦ÀûÓÃÕâЩ·ì϶£¬ÈçÀûÓóɹ¦£¬¿Éµ¼Ö¹¥»÷ÕßÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÒÔÖÐµÈÆëÈ«ÐÔÖ´ÐдúÂë¡£

Õâ¸öÓû§Ä£Ê½ÏµĴòÓ¡»úÇý¶¯Ö÷»ú¹ý³Ìsplwow64.exe »¹Ò×ÊÜÒ»¸öµÍΣµÄÐÅϢй©·ì϶ӰÏì¡£¸Ã·ì϶µÄ±àºÅÊÇCVE-2020-0915£¬CVSSÆÀ·Ö2.5¡£¸ÃÎÊÌâÊÇÓÉÓÚÔÚ½«Óû§ÌṩµÄÖµ½âÒýÓÃΪָÕë֮ǰ£¬²»×ã¶ÔÓû§ÊäÈëÖµµÄÕýÈ·ÑéÖ¤¡£

Áí±íÒ»¸ö·ì϶ÊÇMicrosoft Windows WLANÏνÓÅäÖÃÎļþ¶ÌȱÉí·ÝÑéÖ¤ÌØÈ¨Éý¼¶·ì϶£¬ CVSSÆÀ·Ö7.0£¬Ä¿Ç°ÉÐδ·ÖÅäCVE±àºÅ¡£ÓÉÓÚ²»ÕýÈ·µØ´¦ÖÃWLANÏνÓÅäÖÃÎļþ£¬¹¥»÷ÕßÄܹ»´´½¨¶ñÒâÅäÖÃÎļþÀ´Ð¹Â¶ÍÆËã»úÕÊ»§µÄÍ´´¦¡£


0x02 ´ëÖý¨Òé


Ŀǰ³§ÉÌ»¹Î´°ä²¼²¹¶¡¡£

һʱ´ëÊ©£º×î´óÏ޶ȵØÏ÷¼õÓë·þÎñµÄ½»»¥£¬½öÔÊÐíÓë¿ÉÐŵĿͻ§¶ËºÍ·þÎñÆ÷ÓëÆä½øÐÐͨѶ¡£


0x03 ÓйØÐÂÎÅ


https://securityaffairs.co/wordpress/103507/hacking/microsoft-windows-zero-days.html


0x04 ²Î¿¼Á´½Ó


https://www.zerodayinitiative.com/advisories/published/


0x05 ¹¦·òÏß


2020-05-19 ZDI°ä²¼·ì϶

2020-05-21 VSRC°ä²¼·ì϶¹«¸æ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾