Windows JScript ×é¼þ0day Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-06-01

Îó²î±àºÅ


CVEÔÝÎÞ


Îó²î¼¶±ð


ÖÐ


³§ÉÌ×ÔÆÀ£º6.8   CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Îó²îÐÎò


¿ËÈÕ £¬ £¬ £¬£¬windowsϵͳÓÖ·¢Ã÷Ò»Æð0dayÎó²î £¬ £¬ £¬£¬¸ÃÎó²îÊÇÓÉϵͳÖеÄJScript×é¼þÔì³ÉµÄ £¬ £¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÓû§µÄPCÉÏÖ´ÐжñÒâ´úÂë £¬ £¬ £¬£¬ ËäȻ΢Èí²¢Î´ÌṩÍýÏëÍÆ³ö²¹¶¡¼òÖ±ÇÐʱ¼ä±í £¬ £¬ £¬£¬µ«Ò»Î»½²»°ÈËÅú×¢ËûÃÇÕýÔÚ¾ÙÐÐÐÞ¸´¡£¡£¡£ ¡£¡£


5ÔÂ29ÈÕ £¬ £¬ £¬£¬ZDIÐû²¼ÁËÒ»·Ý±¨¸æ £¬ £¬ £¬£¬ÆäÖаüÀ¨ÓйظùýʧµÄÏêϸÊÖÒÕϸ½Ú£º


ÓÉÓÚ¸ÃÎó²îÓ°Ïì JScript ×é¼þ£¨Î¢Èí×Ô½ç˵µÄ JavaScript Ö´ÐУ© £¬ £¬ £¬£¬Î¨Ò»µÄÌõ¼þ¾ÍÊǹ¥»÷Õß±ØÐèÓÕÆ­Óû§»á¼ûÒ»¸ö¶ñÒâÍøÒ³»òÕßÔÚϵͳÉÏÏÂÔØ²¢·­¿ª¶ñÒâ JS Îļþ£¨Ò»Ñùƽ³£¾­ÓÉ Windows Script Host-wscript.exe Ö´ÐУ©¡£¡£¡£ ¡£¡£


Õâ¸öȱÏݱ£´æÓÚ JScript ¶Ô Error ¹¤¾ßµÄ´¦Öóͷ£Àú³ÌÖС£¡£¡£ ¡£¡£¹¥»÷Õßͨ¹ýÔÚJScript ÖÐÖ´ÐÐÐж¯ £¬ £¬ £¬£¬Äܹ»µ¼ÖÂij¸öÖ¸ÕëÔÚÊͷźóÔâÖØÓᣡ£¡£ ¡£¡£¹¥»÷ÕßÄÜʹÓøÃÎó²îÔÚÄ¿½ñÀú³ÌÏÂÖ´ÐдúÂë¡£¡£¡£ ¡£¡£


¸ÃÎó²îµÄΣÏÕϵÊý²¢Ã»ÓÐÌýÉÏÈ¥µÄÄÇô¸ß £¬ £¬ £¬£¬ÓÉÓÚËüÎÞ·¨µ¼ÖÂϵͳÔâÍêÈ«¹¥ÏÝ¡£¡£¡£ ¡£¡£Õâ¸öȱÏݽöÔÊÐíɳÏäÇéÐÎÖеĴúÂëÖ´ÐÐÎÊÌâ¡£¡£¡£ ¡£¡£¹¥»÷ÕßÐèÒªÆäËüʹÓòŻªÌÓÀëɳÏä²¢ÔÚÄ¿µÄϵͳÉÏÖ´ÐдúÂë¡£¡£¡£ ¡£¡£


΢ÈíÕýÔÚÍÆ³ö²¹¶¡ £¬ £¬ £¬£¬²»¹ýÒѾ­Áè¼ÝÁËÅû¶սÂÔÉèÖõÄʱ¼äÖá¡£¡£¡£ ¡£¡£


ͨ³£ÔÚÅû¶ȱÏݺó¸øÓè³§ÉÌ120ÌìµÄʱ¼äÐû²¼²¹¶¡¡£¡£¡£ ¡£¡£´Ó΢Èí»Ö¸´µÄʱ¼äÖáÀ´¿´ £¬ £¬ £¬£¬Î¢ÈíÄÑÒÔ¸´ÏÖ´¥·¢¸ÃÎó²îµÄ PoC ´úÂë £¬ £¬ £¬£¬´Ó¶øÆÆ·ÑÁË75%µÄÅû¶ʱ¼äÖá £¬ £¬ £¬£¬µ¼Ö¹¤³ÌʦÎÞ·¨ÊµÊ±¸ÏÔÚ5ÔµIJ¹¶¡ÐÇÆÚ¶þ²âÊÔ²¢Ðû²¼²¹¶¡¡£¡£¡£ ¡£¡£


ËäȻ΢Èí²¢Î´Ìá¹©ÍÆ³ö²¹¶¡µÄÏêϸʱ¼äÖá £¬ £¬ £¬£¬µ«Î¢ÈíµÄÒ»Ãû½²»°ÈË֤ʵ³ÆÕýÔÚÍÆ³öÐÞ¸´¼Æ»®¡£¡£¡£ ¡£¡£


ÔÚÅû¶Îó²î֮ʱ²¢Î´·¢Ã÷Îó²îÔâʹÓõÄÇéÐΡ£¡£¡£ ¡£¡£ÓÉÓÚÍøÉÏÏÕЩ²»±£´æÊÖÒÕÏêÇé £¬ £¬ £¬£¬Òò´ËÔÚ΢ÈíÐû²¼ÐÞ¸´¼Æ»®Ç°ºÜ¿ÉÄÜÕÕ¾ÉδÔâʹÓõÄÇéÐΡ£¡£¡£ ¡£¡£


½â¾ö²½·¥


½¨ÒéÓû§²»ÒªÊ¹ÓÃÒÀÀµ JScript ×é¼þµÄÓ¦ÓÃÈç IE ä¯ÀÀÆ÷¡¢wscript.exe µÈÀ´´¦Öóͷ£²»ÊÜÐÅÈεĠJS ´úÂë»òÎļþ¡£¡£¡£ ¡£¡£


²Î¿¼×ÊÁÏ


https://www.zerodayinitiative.com/advisories/ZDI-18-534/


https://www.bleepingcomputer.com/news/security/remote-code-execution-vulnerability-disclosed-in-windows-jscript-component/