ASUS ATK Package¿ÉÐÅ·¾¶´úÂëÖ´ÐÐÎó²î£¨CVE-2019-19235£©
Ðû²¼Ê±¼ä 2019-12-21
1.Åä¾°ÐÎò
SafeBreach LabsÔÚASUS ATKÈí¼þ°üÖз¢Ã÷ÁËÒ»¸öÎó²î£¨CVE-2019-19235£©£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚÌØÈ¨Àú³Ì£¨NT AUTHORITY\SYSTEM£©µÄÉÏÏÂÎÄÖÐÖ´ÐÐδÊðÃûµÄ¿ÉÖ´ÐÐÎļþ£¨exe£©£¬£¬£¬£¬£¬£¬£¬´Ó¶øÈƹý¼ì²â²¢»ñµÃ³¤ÆÚÐÔ¡£¡£¡£¡£¡£
2.Îó²îÁбí
CVE ID £º CVE-2019-19235
CVSSÆÀ·Ö£º ÔÝδÆÀ¶¨
Ó°Ïì¹æÄ££º ATK Package 1.0.0060¼°Ö®Ç°µÄËùÓа汾
3.Îó²îÏêÇé
»ªË¶ATKÈí¼þ°üÊÇԤװÖÃÔÚ»ªË¶PCÉϵÄÊÊÓù¤¾ß£¬£¬£¬£¬£¬£¬£¬ÆäASLDRЧÀÍ£¨AsLdrSrv.exe£©ÒÔNT AUTHORITY\SYSTEMÌØÈ¨ÕË»§ÔËÐУ¬£¬£¬£¬£¬£¬£¬¸ÃЧÀ͵ĿÉÖ´ÐÐÎļþÓÉ¡° ASUSTek Computer Inc.¡±ÊðÃû¡£¡£¡£¡£¡£AsLdrSrv.exeÔÚÖ´ÐС°C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe¡±Îļþǰ£¬£¬£¬£¬£¬£¬£¬»áÏȲéÕÒÒÔÏÂ3¸öɥʧµÄexeÎļþ¡£¡£¡£¡£¡£
C:\Program.exe
C:\Program Files(x86)\ASUS\ATK.exe
C:\Program Files(x86)\ASUS\ATK Package\ATK.exe
Òò´Ë£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ½«í§ÒâδÊðÃûµÄEXEÎļþ¼ÓÔØ½øÕýµ±Àú³Ì²¢ÒÔNT AUTHORITY\SYSTEMÖ´ÐУ¨ÎÞÐè¸ü¸ÄЧÀ͵Ä·¾¶»òÁýÕÖÈκÎÎļþ£©¡£¡£¡£¡£¡£
µ¼Ö¸ÃÎÊÌâµÄÔµ¹ÊÔÓÉÊÇAsLdrSrv.exeÊÔͼ´Ó׼ȷµÄ·¾¶¼ÓÔØHControl.exeʱ£¬£¬£¬£¬£¬£¬£¬´æ´¢¸Ã·¾¶µÄATK_path»º³åÇøÄÚµÄ×Ö·û´®Ã»ÓмÓÒýºÅ£¬£¬£¬£¬£¬£¬£¬ÓÉÓڸ÷¾¶±£´æ¿Õ¸ñ£¬£¬£¬£¬£¬£¬£¬Ê¹µÃCreateProcessAsUserWº¯ÊýʵÑé×ÔÐÐÆÊÎö·¾¶£¬£¬£¬£¬£¬£¬£¬Òò´Ë³ÌÐò»á²éÕÒÕâ3¸ö²»±£´æµÄexeÎļþ¡£¡£¡£¡£¡£
4.ÐÞ¸´½¨Òé
½¨Òé¸üÐÂÖÁ×îа汾1.0.0061
5.²Î¿¼Á´½Ó
https://safebreach.com/Post/ASUS-ATK-Package-Unquoted-Search-Path-and-Potential-Abuses-CVE-2019-19235
https://nvd.nist.gov/vuln/detail/CVE-2019-19235
https://www.asus.com/Static_WebPage/ASUS-Product-Security-Advisory/