΢ÈíWindows Certificate DialogȨÏÞÌáÉý·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-11-21

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1388£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º7.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Microsoft Windows Server 2019

Microsoft Windows Server 2016

Microsoft Windows Server 2012

Microsoft Windows Server 2008 R2

Microsoft Windows Server 2008

Microsoft Windows RT 8.1

Microsoft Windows 8.1

Microsoft Windows 7

Microsoft Windows 10



·ì϶¸ÅÊö


×êÑÐÈËÔ±Åû¶ÁË΢ÈíÉÏÖܶþ°ä²¼µÄ²¹¶¡ Windows ¸ßΣ·ì϶£¨CVE-2019-1388£©µÄÏêÇ飬Ëü¿Éµ¼Ö¹¥»÷ÕßȨÏÞÌáÉý£¬×îÖÕ×°Ö÷¨Ê½£¬²¢²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý ¡£


¸Ã·ì϶´æÔÚÓÚSecure Desktop ÖÐ Windows °²È«Ö°ÄÜ UAC£¨Óû§ÕË»§½ÚÔ죩ÖÐ ¡£¸ÃÖ°ÄÜÓÃÓÚ×èÖ¹¶Ô²Ù×÷ϵͳµÄԽȨ¸ü¸Ä ¡£Î¢ÈíÔÚ¶Ô¸ÃÖ°ÄܵĸÅÀÀÖÐÌáµ½£¬¡°ÆëÈ«ÆôÓøÃÖ°Äܺ󣬽»»¥ÐÔÖÎÀíÔ±ÔÚÕý³£Çé¿öÏÂÒÔ×îµÍÓû§È¨ÏÞÔËÐУ¬µ«ËûÃÇ¿Éͨ¹ý Consent UI ±í°×Ã÷È·Ô޳ɵķ½Ê½×ÔÐÐÌáÉýȨÏÞÀ´Ö´ÐÐÖÎÀí¹¤×÷ ¡£ÕâÖÖÖÎÀí¹¤×÷Ô̺¬×°ÖÃÈí¼þºÍÇý¶¯Æ÷¡¢¸ü¸ÄϵͳÉèÖᢲ鿴»ò¸ü¸ÄÆäËüÓû§µÄÕË»§²¢ÔËÐÐÖÎÀí¹¤¾ß ¡£¡±


ͨ¹ýºÍUACµÄÓû§½Ó¿Ú½»»¥£¬ÎÞȨÏ޵Ĺ¥»÷Õß¿ÉÄÜÀûÓøÃȱµãÔÚͨ³£×ÀÃæÉÏÆô¶¯¸ßȨÏÞµÄweb ä¯ÀÀÆ÷£¬´Ó¶ø¿ÉÄÜ×°ÖôúÂë²¢Ö´ÐÐÆäËü¶ñÒâ»î¶¯ ¡£


¸Ã·ì϶²úÉúµÄÔ­ÒòÔÚÓÚ£¬ÓÃÓÚÏêÊöÖ¤ÊÖÔýÏ¢ºÍ΢ÈíÌØ¶¨¶ÔÏó±êʶ·û (OID) µÄ UAC Windows Certificate Dialog δÕýÈ·µØÖ´ÐÐÓû§È¨ÏÞ ¡£ÒªÀûÓø÷ì϶£¬µÍȨÏÞ¹¥»÷ÕßÊ×ÏÈ´ÓÊܹ¥»÷Õß½ÚÔìµÄÍøÕ¾¸ßµÍÔØÓÉ΢ÈíÊðÃûµÄ¿ÉÖ´ÐÐÎļþ£¬Ö®ºó³¢ÊÔÒÔÖÎÀíÔ±Éí·ÝÔËÐиÿÉÖ´ÐÐÎļþ£¬Ò²¾ÍÊÇ˵ UAC ½«µ¯³ö²¢ÒªÇó¹¥»÷ÕßÊäÈëÖÎÀíÔ±ÃÜÂë ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



µã»÷ UAC ´°¿ÚÉϵġ°ÏÔʾÏêÇ顱°´Å¥ºó£¬¹¥»÷Õ߾ͿÉÄܲ鿴 Windows Certificate Dialog ÖÐµÄ OID£¬¶øÕâЩÐÅϢչʾÔÚÏêÇé±êÇ©¡°SpcSpAgencyInfo¡±ÉÏ£¬¶øÕâÒ²ÊÇÎÊÌâ´æÔڵĴ¦Ëù ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



¸ÃOID µÄÓïÒåÎļþºÜÉÙ£¬²»ÍâËÆºõ¸ÃÖ¤Êé¶Ô»°½âÎöµÄÊÇÕâ¸ö OID µÄÖµ£¬²¢ÇÒÈôÊÇÖµÊÇÓÐЧµÄÇÒÌåʽÕýÈ·£¬Ôò»áͨ¹ý¸ÃÊý¾Ý½«¡®Í¨Àý¡¯Ñ¡ÏÉϵġ®Issued by¡¯×ֶγöÏÖΪ³¬Á´½Ó ¡£µ«ÊÇÔÚ¸ÃÖ¤Êé¶Ô»°µÄ UAC °æ±¾£¬Î¢Èí½¡Íü½ûÓøó¬Á´½Ó ¡£


Ò²¾ÍÊÇ˵£¬¹¥»÷Õß¿ÉÄܵã»÷¸Ã³¬Á´½ÓÆô¶¯½«ÒÔ NT AUTHORITY\SYSTEM £¨ÓµÓÐÖÎÀíԱȨÏÞµÄä¯ÀÀÆ÷£©·½Ê½ÔËÐУ¬´Ó¶øµ¼ÖÂÒ×ÊÜ´úÂëÖ´ÐÓ×¢¶ñÒⷨʽװÖõȺó¹ûÓ°Ïì ¡£


·ì϶ÑéÖ¤


POC:https://www.zerodayinitiative.com/blog/2019/11/19/thanksgiving-treat-easy-as-pie-windows-7-secure-desktop-escalation-of-privilege ¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѾ­°ä²¼ÁËÉý¼¶²¹¶ ¡£º

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1388 ¡£


²Î¿¼Á´½Ó


https://www.zerodayinitiative.com/blog/2019/11/19/thanksgiving-treat-easy-as-pie-windows-7-secure-desktop-escalation-of-privilege