Win10±¾µØÌáȨ0day·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-08-29

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÎÞ£¬Î£ÏÕ¼¶±ð£º¸ß£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Windows 10 32/64λ²Ù×÷ϵͳ


·ì϶¸ÅÊö


2018Äê8ÔÂ27ÈÕ£¬°²È«×êÑÐÈËÔ±ÔÚgithubÉϰ䲼ÁË×îеÄwin10x64°æµÄ±¾µØÌáȨ·ì϶£¬²¢ÇÒÔÚÍÆÌØÉÏ¶ÔÆäÌáȨµÄdemo½øÐÐÁËÑÝʾ¡£ÔÚgithubÉϵÄSandboxEscaperÉÏÓÐ×ÅÆëÈ«µÄ·ì϶ÀûÓ÷¨Ê½ÒÔ¼°demo£¬²¢ÇÒ±»ÆäËû°²È«×êÑÐר¼Ò֤ʵ¸Ã·ì϶Äܹ»ÔÚ×î½üµÄwin10Éϸ´ÏÖ¡£


¸Ã·ì϶µÄÔ­ÒòÔÚÓÚwin10ϵͳµÄ¹¤×÷µ÷¶È·þÎñÖÐÓÐalpcµÄŲÓýӿÚ£¬¸Ã½Ó¿Úµ¼³öÁËSchRpcSetSecurityº¯Êý£¬¸Ãº¯ÊýÕýÊDZ¾´Î·ì϶ÀûÓõ½µÄº¯Êý¡£¸Ãº¯ÊýµÄÔ­ÐÍÈçÏ£º


long _SchRpcSetSecurity(
[in][string] wchar_t* arg_1, //Task name
[in][string] wchar_t* arg_2, //Security Descriptor string

[in]long arg_3);


µ±ËÁÒâȨÏÞµÄÓû§Å²Óøú¯Êýʱ£¬¸Ãº¯Êý»á¼ì²â c:\windows\tasksĿ¼ÏÂÊÇ·ñ´æÔÚÒ»¸öºó׺ΪjobµÄÎļþ£¬ÈôÊǸÃÎļþ´æÔÚ»áÏò¸ÃÎļþдÈëÖ¸¶¨µÄDACLÊý¾Ý¡£±¾´Î·ì϶ÀûÓõķ½Ê½¼´Í¨¹ýÓ²Á´½ÓµÄ·½Ê½½«¸ÃjobÎļþÖ¸¶¨Á´½Óµ½Ìض¨µÄdllÉÏ£¬ÕâÑùµ±Óû§Å²Óøú¯Êýʱ»áÏòÌØ¶¨µÄdllдÈëÊý¾Ý£¬¶øÌض¨µÄdllÍùÍùÊÇϵͳ¼¶´ËÍâdll¡£ÔÚgithubÉϰ䲼µÄ·ì϶ÀûÓ÷¨Ê½Ôò»áÏòprintconfig.dllдÈëÌáȨ´úÂ룬²¢Í¨¹ýÆô¶¯´òÓ¡·þÎñspoolsv.exeÀ´Ö´ÐÐÌáȨ´úÂ룬´Ó¶øÊµÏÖÄÚºËÌáȨ¡£


·ì϶ÑéÖ¤


±¾´Î¸´ÏÖʹÓÃÁËwin10x64°æ£¬Ê×ÏÈʹÓÃgithubÉÏÌṩµÄ·ì϶ÀûÓù¤¾ß£¬²é¿´Æä¾ßÌåÓ÷¨¡£¸Ã·ì϶ÀûÓù¤¾ßµÄÖØÒª·½Ê½ÊÇͨ¹ýdll×¢ÈëµÄ·½Ê½ÏòµÍȨÏ޵Ĺý³Ì×¢ÈëÄܹ»ÊµÏÖÕûÌ×ÌáȨ¹¥»÷µÄshellcode¡£

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

ËæºóÀûÓÃieä¯ÀÀÆ÷½øÐвâÊÔʱ·¢ÏÖÎÞ·¨ÀûÓóɹ¦£¬¹ÌÈ»·ì϶ÀûÓõÄdllÒѾ­±»Ð´Èëµ½spoolsv.exeÖУ¬µ«È´Ã»ÓÐʵÏÖ·ìÏ¶ÕæÕýµÄ³ÉЧ¡£½ÓÏÂÀ´ÒÀÕÕÑÝʾdemoÖеIJÙ×÷£¬´ò¿ªÒ»¸önotepad·¨Ê½£¬²¢¶Ônotepad·¨Ê½½øÐÐ×¢Èë¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ëæºó²é¿´spoolsv.exeϵÄËùÓÐ×Ó¹ý³Ì£¬·¢ÏÖ¸Ãnotepad.exe·¨Ê½±»spoolsv.exe·¨Ê½³Áдò¿ª£¬ºÍgithubÉϵķì϶ÀûÓõÄdemoÖеijÉЧһÖ£¬Äܹ»È·¶¨·ì϶ÀûÓóɹ¦¡£

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


½ÓÏÂÀ´²é¿´spoolsv.exeÖеĵÚÈý·½¶¯Ì¬¿â£¬Äܹ»¿´µ½ÎÒÃÇÀûÓ÷ì϶ËùÅú¸ÄµÄdll

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¶ø¸ÃdllµÄÅú¸Ä¹¦·òÒ²ÏÔʾÊǸոշì϶ÀûÓõŦ·ò£¬ÖÁ´Ë·ì϶¸´Ïֳɹ¦¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾ 

Poc£ºhttps://github.com/SandboxEscaper/randomrepo


½¨¸´½¨Òé


³§ÉÌÉÐδ°ä²¼Óйز¹¶¡£¬ÉóÉ÷Ö´ÐÐδ¾­ÉóºËÆðÔ´¶ÔµÄ·¨Ê½¡£


²Î¿¼Á´½Ó


https://thehackernews.com/2018/08/windows-zero-day-exploit.html
https://github.com/SandboxEscaper/randomrepo