Win10ÍâµØÌáȨ0dayÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-08-29

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÎÞ£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ß£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Windows 10 32/64λ²Ù×÷ϵͳ


Îó²î¸ÅÊö


2018Äê8ÔÂ27ÈÕ£¬£¬£¬£¬£¬Çå¾²Ñо¿Ö°Ô±ÔÚgithubÉÏÐû²¼ÁË×îеÄwin10x64°æµÄÍâµØÌáȨÎó²î£¬£¬£¬£¬£¬²¢ÇÒÔÚÍÆÌØÉÏ¶ÔÆäÌáȨµÄdemo¾ÙÐÐÁËÑÝʾ¡£¡£¡£¡£¡£¡£ÔÚgithubÉϵÄSandboxEscaperÉÏÓÐ×ÅÍêÕûµÄÎó²îʹÓóÌÐòÒÔ¼°demo£¬£¬£¬£¬£¬²¢ÇÒ±»ÆäËûÇå¾²Ñо¿×¨¼Ò֤ʵ¸ÃÎó²î¿ÉÒÔÔÚ×î½üµÄwin10Éϸ´ÏÖ¡£¡£¡£¡£¡£¡£


¸ÃÎó²îµÄÔµ¹ÊÔ­ÓÉÔÚÓÚwin10ϵͳµÄʹÃüµ÷ÀíЧÀÍÖÐÓÐalpcµÄŲÓýӿÚ£¬£¬£¬£¬£¬¸Ã½Ó¿Úµ¼³öÁËSchRpcSetSecurityº¯Êý£¬£¬£¬£¬£¬¸Ãº¯ÊýÕýÊDZ¾´ÎÎó²îʹÓõ½µÄº¯Êý¡£¡£¡£¡£¡£¡£¸Ãº¯ÊýµÄÔ­ÐÍÈçÏ£º


long _SchRpcSetSecurity(
[in][string] wchar_t* arg_1, //Task name
[in][string] wchar_t* arg_2, //Security Descriptor string

[in]long arg_3);


µ±í§ÒâȨÏÞµÄÓû§Å²Óøú¯Êýʱ£¬£¬£¬£¬£¬¸Ãº¯Êý»á¼ì²â c:\windows\tasksĿ¼ÏÂÊÇ·ñ±£´æÒ»¸öºó׺ΪjobµÄÎļþ£¬£¬£¬£¬£¬ÈôÊǸÃÎļþ±£´æ»áÏò¸ÃÎļþдÈëÖ¸¶¨µÄDACLÊý¾Ý¡£¡£¡£¡£¡£¡£±¾´ÎÎó²îʹÓõķ½·¨¼´Í¨¹ýÓ²Á´½ÓµÄ·½·¨½«¸ÃjobÎļþÖ¸¶¨Á´½Óµ½Ìض¨µÄdllÉÏ£¬£¬£¬£¬£¬ÕâÑùµ±Óû§Å²Óøú¯Êýʱ»áÏòÌØ¶¨µÄdllдÈëÊý¾Ý£¬£¬£¬£¬£¬¶øÌض¨µÄdllÍùÍùÊÇϵͳ¼¶±ðµÄdll¡£¡£¡£¡£¡£¡£ÔÚgithubÉÏÐû²¼µÄÎó²îʹÓóÌÐòÔò»áÏòprintconfig.dllдÈëÌáȨ´úÂ룬£¬£¬£¬£¬²¢Í¨¹ýÆô¶¯´òӡЧÀÍspoolsv.exeÀ´Ö´ÐÐÌáȨ´úÂ룬£¬£¬£¬£¬´Ó¶øÊµÏÖÄÚºËÌáȨ¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


±¾´Î¸´ÏÖʹÓÃÁËwin10x64°æ£¬£¬£¬£¬£¬Ê×ÏÈʹÓÃgithubÉÏÌṩµÄÎó²îʹÓù¤¾ß£¬£¬£¬£¬£¬Éó²éÆäÏêϸÓ÷¨¡£¡£¡£¡£¡£¡£¸ÃÎó²îʹÓù¤¾ßµÄÖ÷Òª·½·¨ÊÇͨ¹ýdll×¢ÈëµÄ·½·¨ÏòµÍȨÏÞµÄÀú³Ì×¢Èë¿ÉÒÔʵÏÖÕûÌ×ÌáȨ¹¥»÷µÄshellcode¡£¡£¡£¡£¡£¡£

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ËæºóʹÓÃieä¯ÀÀÆ÷¾ÙÐвâÊÔʱ·¢Ã÷ÎÞ·¨Ê¹ÓÃÀֳɣ¬£¬£¬£¬£¬ËäÈ»Îó²îʹÓõÄdllÒѾ­±»Ð´Èëµ½spoolsv.exeÖУ¬£¬£¬£¬£¬µ«È´Ã»ÓÐʵÏÖÎó²îÕæÕýµÄЧ¹û¡£¡£¡£¡£¡£¡£½ÓÏÂÀ´Æ¾Ö¤ÑÝʾdemoÖеIJÙ×÷£¬£¬£¬£¬£¬·­¿ªÒ»¸önotepad³ÌÐò£¬£¬£¬£¬£¬²¢¶Ônotepad³ÌÐò¾ÙÐÐ×¢Èë¡£¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ËæºóÉó²éspoolsv.exeϵÄËùÓÐ×ÓÀú³Ì£¬£¬£¬£¬£¬·¢Ã÷¸Ãnotepad.exe³ÌÐò±»spoolsv.exe³ÌÐòÖØÐ·­¿ª£¬£¬£¬£¬£¬ºÍgithubÉϵÄÎó²îʹÓõÄdemoÖеÄЧ¹ûÒ»Ö£¬£¬£¬£¬£¬¿ÉÒÔÈ·¶¨Îó²îʹÓÃÀֳɡ£¡£¡£¡£¡£¡£

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


½ÓÏÂÀ´Éó²éspoolsv.exeÖеĵÚÈý·½¶¯Ì¬¿â£¬£¬£¬£¬£¬¿ÉÒÔ¿´µ½ÎÒÃÇʹÓÃÎó²îËùÐ޸ĵÄdll

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¶ø¸ÃdllµÄÐÞ¸Äʱ¼äÒ²ÏÔʾÊǸոÕÎó²îʹÓõÄʱ¼ä£¬£¬£¬£¬£¬ÖÁ´ËÎó²î¸´ÏÖÀֳɡ£¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨ 

Poc£ºhttps://github.com/SandboxEscaper/randomrepo


ÐÞ¸´½¨Òé


³§ÉÌÉÐδÐû²¼Ïà¹Ø²¹¶¡£¬£¬£¬£¬£¬ÉóÉ÷Ö´ÐÐδ¾­ÉóºËȪԴ¶ÔµÄ³ÌÐò¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://thehackernews.com/2018/08/windows-zero-day-exploit.html
https://github.com/SandboxEscaper/randomrepo