ASUS ATK Package¿ÉÐÅ·¾¶´úÂëÖ´ÐÐÎó²î£¨CVE-2019-19235£©

Ðû²¼Ê±¼ä 2019-12-21


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


1.Åä¾°ÐÎò


SafeBreach LabsÔÚASUS ATKÈí¼þ°üÖз¢Ã÷ÁËÒ»¸öÎó²î£¨CVE-2019-19235£©£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚÌØÈ¨Àú³Ì£¨NT AUTHORITY\SYSTEM£©µÄÉÏÏÂÎÄÖÐÖ´ÐÐδÊðÃûµÄ¿ÉÖ´ÐÐÎļþ£¨exe£©£¬£¬£¬£¬ £¬£¬£¬´Ó¶øÈƹý¼ì²â²¢»ñµÃ³¤ÆÚÐÔ¡£ ¡£ ¡£¡£¡£


2.Îó²îÁбí


CVE ID  £º     CVE-2019-19235

CVSSÆÀ·Ö£º   ÔÝδÆÀ¶¨

Ó°Ïì¹æÄ££º     ATK Package 1.0.0060¼°Ö®Ç°µÄËùÓа汾


3.Îó²îÏêÇé


»ªË¶ATKÈí¼þ°üÊÇԤװÖÃÔÚ»ªË¶PCÉϵÄÊÊÓù¤¾ß£¬£¬£¬£¬ £¬£¬£¬ÆäASLDRЧÀÍ£¨AsLdrSrv.exe£©ÒÔNT AUTHORITY\SYSTEMÌØÈ¨ÕË»§ÔËÐУ¬£¬£¬£¬ £¬£¬£¬¸ÃЧÀ͵ĿÉÖ´ÐÐÎļþÓÉ¡° ASUSTek Computer Inc.¡±ÊðÃû¡£ ¡£ ¡£¡£¡£AsLdrSrv.exeÔÚÖ´ÐС°C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe¡±Îļþǰ£¬£¬£¬£¬ £¬£¬£¬»áÏȲéÕÒÒÔÏÂ3¸öɥʧµÄexeÎļþ¡£ ¡£ ¡£¡£¡£


C:\Program.exe

C:\Program Files(x86)\ASUS\ATK.exe

C:\Program Files(x86)\ASUS\ATK Package\ATK.exe


Òò´Ë£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÒÔ½«í§ÒâδÊðÃûµÄEXEÎļþ¼ÓÔØ½øÕýµ±Àú³Ì²¢ÒÔNT AUTHORITY\SYSTEMÖ´ÐУ¨ÎÞÐè¸ü¸ÄЧÀ͵Ä·¾¶»òÁýÕÖÈκÎÎļþ£©¡£ ¡£ ¡£¡£¡£

µ¼Ö¸ÃÎÊÌâµÄÔµ¹ÊÔ­ÓÉÊÇAsLdrSrv.exeÊÔͼ´Ó׼ȷµÄ·¾¶¼ÓÔØHControl.exeʱ£¬£¬£¬£¬ £¬£¬£¬´æ´¢¸Ã·¾¶µÄATK_path»º³åÇøÄÚµÄ×Ö·û´®Ã»ÓмÓÒýºÅ£¬£¬£¬£¬ £¬£¬£¬ÓÉÓڸ÷¾¶±£´æ¿Õ¸ñ£¬£¬£¬£¬ £¬£¬£¬Ê¹µÃCreateProcessAsUserWº¯ÊýʵÑé×ÔÐÐÆÊÎö·¾¶£¬£¬£¬£¬ £¬£¬£¬Òò´Ë³ÌÐò»á²éÕÒÕâ3¸ö²»±£´æµÄexeÎļþ¡£ ¡£ ¡£¡£¡£


4.ÐÞ¸´½¨Òé


½¨Òé¸üÐÂÖÁ×îа汾1.0.0061


5.²Î¿¼Á´½Ó


https://safebreach.com/Post/ASUS-ATK-Package-Unquoted-Search-Path-and-Potential-Abuses-CVE-2019-19235

https://nvd.nist.gov/vuln/detail/CVE-2019-19235

https://www.asus.com/Static_WebPage/ASUS-Product-Security-Advisory/