CVE-2020-1048 | PrintDemonÍâµØÌáȨÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-05-150x00 Îó²î¸ÅÊö
|
CVE ID |
CVE-2020-1048 |
ʱ ¼ä |
2020-05-15 |
|
Àà ÐÍ |
LPE |
µÈ ¼¶ |
¸ßΣ |
|
Ô¶³ÌʹÓà |
·ñ |
Ó°Ïì¹æÄ£ |
×Ô1996ÄêÒÔÀ´Ðû²¼(Windows NT 4)µÄËùÓÐWindows°æ±¾ |
0x01 Îó²îÏêÇé
2020Äê5ÔÂ12ÈÕÇå¾²Ñо¿Ö°Ô±Alex IonescuºÍYarden ShafirÐû²¼Îó²î±¨¸æ£¬£¬£¬£¬ÔÚWindows´òӡЧÀÍÖз¢Ã÷ÁËÒ»¸öÇå¾²Îó²î£¨CVE-2020-1048£©£¬£¬£¬£¬¿ÉÒÔÓÃÀ´Ð®ÖÆPrinter Spooler»úÖÆ£¬£¬£¬£¬¸ÃÎó²îÓ°Ïì×Ô1996ÄêÒÔÀ´Ðû²¼(Windows NT 4)µÄËùÓÐWindows°æ±¾¡£¡£¡£¡£
CVE-2020-1048ÊÇWindows ´òÓ¡ºǫ́´¦Öóͷ£³ÌÐòÌØÈ¨ÌáÉýÎó²î¡£¡£¡£¡£ÈôÊÇ Windows ´òÓ¡ºǫ́´¦Öóͷ£³ÌÐòЧÀÍÆ÷²»×¼È·µØÔÊÐíí§ÒâдÈëÎļþϵͳ£¬£¬£¬£¬Ôò»á±£´æÌØÈ¨ÌáÉýÎó²î¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÌáÉýµÄÏµÍ³ÌØÈ¨ÔËÐÐí§Òâ´úÂë¡£¡£¡£¡£¹¥»÷Õß¿ÉËæºó×°ÖóÌÐò£»£»£»£»Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»£»£»£»»òÕß½¨ÉèÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£¡£ÈôҪʹÓôËÎó²î£¬£¬£¬£¬¹¥»÷Õß±ØÐèµÇ¼µ½ÊÜÓ°ÏìµÄϵͳ²¢ÔËÐÐ¾ÌØÊâÉè¼ÆµÄ¾ç±¾»òÓ¦ÓóÌÐò¡£¡£¡£¡£
Ñо¿Ö°Ô±½«PrintDemon³ÆÎª¡°ÍâµØÌØÈ¨Éý¼¶¡±£¨LPE£©Îó²î£¬£¬£¬£¬×ÝÈ»¹¥»÷ÕßÖ»ÓÐͨË×Óû§È¨ÏÞ£¬£¬£¬£¬Ò²¿ÉÒÔͨ¹ýPowerShellÏÂÁîµÈ·½·¨ÈÝÒ×»ñȡϵͳµÄÖÎÀíԱȨÏÞ¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ³õʼ»¯Ò»¸ö´òÓ¡²Ù×÷£¬£¬£¬£¬¾ÓÐÄʹPrint SpoolerЧÀͱ¼À££¬£¬£¬£¬È»ºóÔÙ»Ö¸´´òӡʹÃü£¬£¬£¬£¬´Ëʱ´òÓ¡²Ù×÷¾ÍÒÔSYSTEMȨÏÞÔËÐÐÁË£¬£¬£¬£¬¿ÉÒÔÁýÕÖϵͳÖеÄí§ÒâÎļþ¡£¡£¡£¡£
¹¥»÷Õß¿ÉÒÔͨ¹ýÒ»¸öPowerShellÏÂÁîʹÓÃCVE-2020-1048£º
Add-PrinterPort -Name c:\windows\system32\ualapi.dll
ÔÚδװÖò¹¶¡µÄϵͳÖУ¬£¬£¬£¬ÔËÐÐÉÏÊöÏÂÁî»á×°ÖÃÒ»¸öÓÀÊÀºóÃÅ£¬£¬£¬£¬¸ÃºóÃÅ×ÝÈ»ÐÞ¸´ºóÒ²²»»áÏûÊÅ¡£¡£¡£¡£
POC: https://github.com/ionescu007/PrintDemon
0x02 ´¦Öóͷ£½¨Òé
΢ÈíÒѾÔÚ5ÔµÄ΢Èí²¹¶¡ÈÕÐû²¼Á˸ÃÎó²îµÄ²¹¶¡£¬£¬£¬£¬ÓÉÓÚ¸ÃÎó²îºÜÊÇÈÝÒ×±»Ê¹Ó㬣¬£¬£¬Ñо¿Ö°Ô±½¨ÒéÓû§¾¡¿ì×°Öò¹¶¡¡£¡£¡£¡£
ÔÝʱ²½·¥£ºÍ¨¹ýPowerShellµÄGet-PrinterPorts»òHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports À´É¨Ãè»ùÓÚÎļþµÄ¶Ë¿Ú£¬£¬£¬£¬ÓÈÆäÊÇÄÇЩ.DLL»ò.EXEÀ©Õ¹µÄÎļþ·¾¶¡£¡£¡£¡£
0x03 Ïà¹ØÐÂÎÅ
https://www.zdnet.com/article/printdemon-vulnerability-impacts-all-windows-versions/#ftag=RSSbaffb68
0x04 ²Î¿¼Á´½Ó
https://windows-internals.com/printdemon-cve-2020-1048/
0x05 ʱ¼äÏß
2020-05-15 VSRCÐû²¼Îó²îͨ¸æ


¾©¹«Íø°²±¸11010802024551ºÅ