Acer Quick Access DLLÐ®ÖÆÎó²î£¨CVE-2019-18670£©

Ðû²¼Ê±¼ä 2019-12-21


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


1.Åä¾°ÐÎò


¿ËÈÕ£¬£¬£¬SafeBreach LabsÔÚAcer PCµÄԤװÖÃÈí¼þQuick AccessÖз¢Ã÷Ò»¸öDLLÐ®ÖÆÎó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î½«í§ÒâδÊðÃûµÄDLL¼ÓÔØµ½ÒÔSYSTEMȨÏÞÔËÐеÄÀú³ÌÖУ¬£¬£¬´Ó¶øÊµÏÖ³¤ÆÚÐÔ¡¢Èƹý¼ì²âÒÔ¼°Ä³Ð©ÇéÐÎϵÄÌØÈ¨ÌáÉý¡£¡£¡£¡£¡£¡£


2.Îó²îÁбí


CVE ID  £º     CVE-2019-18670

CVSSÆÀ·Ö£º   ÔÝδÆÀ¶¨

Ó°Ïì¹æÄ££ºAcer Quick Access v2.01.3000 - v.201.3027£»£»£»£»£»£»Acer Quick Access v3.00.3000 - v3.00.3008


3.Îó²îÏêÇé


Acer Quick AccessÔÚÆô¶¯ºóÒÔNT AUTHORITY\SYSTEMȨÏÞÔËÐÐQAAdminAgent.exe£¬£¬£¬²¢ÊÔͼ´ÓÇéÐαäÁ¿PATHµÄ·¾¶ÖмÓÔØÈý¸öDLLÎļþ£¨atiadlxx.dll¡¢atiadlxy.dllºÍnvapi.dll£©¡£¡£¡£¡£¡£¡£ÓÉÓÚ¸ÃÀú³ÌûÓжÔDLLÎļþ¾ÙÐÐÊðÃûÑéÖ¤£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÀú³Ì¼ÓÔØí§Òâ¶ñÒâDLL£¨Î´ÊðÃû£©£¬£¬£¬´Ó¶øÊµÏÖÌØÈ¨ÌáÉýºÍÒÔNT AUTHORITY\SYSTEMȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£


ÓÉÓÚAcer Quick AccessÊÇ´ó´ó¶¼Acer PCÉÏԤװÖõĸ¨ÖúÈí¼þ£¬£¬£¬Òò´Ë¸ÃÎó²îµÄDZÔÚÓ°Ïì¹æÄ£½Ï´ó¡£¡£¡£¡£¡£¡£


4.ÐÞ¸´½¨Òé


½¨Òé¸üÐÂÖÁ°æ±¾Acer Quick Access v2.01.3028»òv3.00.3009


5.²Î¿¼Á´½Ó


https://safebreach.com/Post/Acer-Quick-Access-DLL-Search-Order-Hijacking-and-Potential-Abuses-CVE-2019-18670

https://nvd.nist.gov/vuln/detail/CVE-2019-18670