Windows CryptoAPIÓÕÆ­Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-01-15

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-0601£¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.1£¬£¬£¬£¬ £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Windows 10 Version 1607

Windows 10 Version 1709

Windows 10 Version 1803

Windows 10 Version 1809

Windows 10 Version 1903

Windows 10 Version 1909

Windows Server2016

Windows Server 2019


Îó²î¸ÅÊö


2020Äê1ÔÂ14ÈÕ΢ÈíÐû²¼ÁËCVE-2020-0601Îó²îͨ¸æ£¬£¬£¬£¬ £¬´ËÎó²îΪWindows¼ÓÃÜ¿âÖеÄÒ»¸öÒªº¦µÄÎó²î£¬£¬£¬£¬ £¬Windows CryptoAPI(Crypt32.dll) ÑéÖ¤ÍÖÔ²ÇúÏß¼ÓÃÜ (ECC)Ö¤ÊéµÄ·½·¨Öб£´æÓÕÆ­Îó²î¡£¡£¡£


¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÓÕÆ­ÐԵĴúÂëÊðÃûÖ¤Êé¶Ô¶ñÒâ¿ÉÖ´ÐÐÎļþ¾ÙÐÐÊðÃûÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬ £¬´Ó¶øÊ¹¸ÃÎļþËÆºõÀ´×Ô¿É¿¿µÄÕýµ±ÈªÔ´¡£¡£¡£Óû§½«ÎÞ·¨ÖªµÀÎļþÊǶñÒâµÄ£¬£¬£¬£¬ £¬ÓÉÓÚÊý×ÖÊðÃûËÆºõÀ´×ÔÊÜÐÅÈεÄÌṩ³ÌÐò¡£¡£¡£ÀֳɵÄʹÓû¹¿ÉÒÔʹ¹¥»÷Õß¾ÙÐÐÖÐÐÄÈ˹¥»÷£¬£¬£¬£¬ £¬²¢ÔÚÓëÊÜÓ°ÏìÈí¼þµÄÓû§ÅþÁ¬ÉϽâÃÜÉñÃØÐÅÏ¢¡£¡£¡£


¸ÃÎó²îΪNSA×ÔÁ¦·¢Ã÷£¬£¬£¬£¬ £¬²¢»ã±¨¸øÎ¢Èí¡£¡£¡£Æ¾Ö¤NSAÀÖ³ÉʹÓôËÎó²î½«Ê¹¹¥»÷ÕßÄܹ»ÌṩÀ´×ÔÊÜÐÅÈÎʵÌåµÄ¶ñÒâ´úÂë¡£¡£¡£ÆäÖаüÀ¨£ºÊðÃûµÄÎļþºÍµç×ÓÓʼþ¡¢ÊðÃû¿ÉÖ´ÐдúÂëµÈ¡¢HTTPsÅþÁ¬¡£¡£¡£


ÖµµÃ×¢ÖØµÄÊÇÖ¸¶¨²ÎÊýµÄECCÃÜÔ¿Ö¤ÊéµÄWindows°æ±¾»áÊܵ½Ó°Ï죬£¬£¬£¬ £¬¶øÕâÒ»»úÖÆ£¬£¬£¬£¬ £¬×îÔçÓÉWIN10ÒýÈ룬£¬£¬£¬ £¬Ó°ÏìWIN10£¬£¬£¬£¬ £¬Windows Server 2016/2019°æ±¾£¬£¬£¬£¬ £¬¶øÓÚ½ñÄê1ÔÂ14ÈÕ×èÖ¹Ç徲ά»¤µÄWIN7/Windows Server 2008ÓÉÓÚ²»Ö§³Ö´ø²ÎÊýµÄECCÃÜÔ¿£¬£¬£¬£¬ £¬Òò´Ë²»ÊÜÏà¹ØÓ°Ï죬£¬£¬£¬ £¬µ«ÈÔÈ»½¨ÒéÓû§½«WIN7/ Windows Server 2008ϵͳ¸üÐÂÖÁ×îеÄWIN10ϵͳ»òWindows Server2016Ö®ºóµÄ°æ±¾£¬£¬£¬£¬ £¬²¢¸üÐÂÏà¹ØÇå¾²²¹¶¡¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ΢ÈíÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬ £¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601¡£¡£¡£


²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601

https://media.defense.gov/2020/Jan/14/2002234275/-1/-1/0/CSA-WINDOWS-10-CRYPT-LIB-20190114.PDF