Windows Installer×é¼þ0dayÎó²î
Ðû²¼Ê±¼ä 2021-02-010x00 Îó²î¸ÅÊö
CVE ID | ʱ ¼ä | 2021-02-01 | |
Àà ÐÍ | ȨÏÞÌáÉý | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ·ñ | Ó°Ïì¹æÄ£ | Windows 7- Windows 10 |
0x01 Îó²îÏêÇé
¼òÊö
Windows InstallerÊÇWindowsÖеÄÒ»¸ö×é¼þ£¬£¬£¬ËüÊÇרÃÅÓÃÀ´ÖÎÀíºÍÉèÖÃÈí¼þЧÀ͵Ť¾ß¡£¡£¡£¡£¡£¡£¡£
2020Äê10Ô£¬£¬£¬MicrosoftÐÞ¸´ÁËWindows Installer×é¼þÖеÄÒ»¸öÎó²î£¨CVE-2020-16902£¬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔø±»¶à´ÎÐÞ¸´¡¢Èƹý£¬£¬£¬ÀúÊ·×·×ÙΪCVE-2019-1415¡¢CVE-2020-1302ºÍCVE-2020-0814£©£¬£¬£¬µ«¸ÃÎó²îµÄÐÞ¸´³ÌÐòÈԿɱ»Èƹý¡£¡£¡£¡£¡£¡£¡£12ÔÂÏÂÑ®£¬£¬£¬¸ÃÎó²îµÄPoC±»¹ûÕæ¡£¡£¡£¡£¡£¡£¡£MicrosoftһֱûÓÐÍêÈ«ÐÞ¸´´ËÎó²î¡£¡£¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬Microsoft¶à´ÎʵÑéÐÞ¸´µÄWindows Installer×é¼þÎó²î£¨CVE-2020-16902²¹¶¡µÄÈÆ¹ý£© »ñµÃÁËÒ»¸öÔÝʱ²¹¶¡£¬£¬£¬¸Ã²¹¶¡Äܹ»×èÖ¹¹¥»÷ÕßʹÓÃÎó²î»ñȡĿµÄϵͳµÄ×î¸ßȨÏÞ¡£¡£¡£¡£¡£¡£¡£
Îó²îÆÊÎö
ÔÚ×°ÖÃMSIÈí¼þ°üµÄÀú³ÌÖУ¬£¬£¬Windows Installer»áͨ¹ý¡° msiexec.exe¡±½¨Éè»Ø¹ö¾ç±¾£¬£¬£¬ÒÔ±ãÔÚÀú³ÌÖзºÆð¹ýʧʱ»¹ÔËùÓиü¸Ä¡£¡£¡£¡£¡£¡£¡£
¾ßÓÐÍâµØÈ¨Ï޵Ĺ¥»÷ÕßÈôÊÇ¿ÉÒÔÓÃÒ»¸ö¸Ä±ä×¢²á±íÖµÀ´Ö¸ÏòËûÃǵÄPayloadµÄ½ÅÔÀ´Ìæ»»»Ø¹ö¾ç±¾£¬£¬£¬Ôò¿ÉÒÔÔËÐоßÓÐSYSTEMȨÏ޵ĿÉÖ´ÐÐÎļþ¡£¡£¡£¡£¡£¡£¡£
Îó²î¸´ÏÖ
¸ÃÎó²îµÄPoCÖÐʹÓõÄÊǻعö¾ç±¾£¬£¬£¬Ëü½«HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/services/Fax/ImagePathµÄÖµ¸ü¸ÄΪc:\Windows/tempasmae.exe£¬£¬£¬µ¼Ö´«ÕæÐ§ÀÍÆô¶¯Ê±Ê¹Óù¥»÷ÕßµÄasmae.exe¡£¡£¡£¡£¡£¡£¡£Ö®ÒÔÊÇʹÓøÃЧÀÍ£¬£¬£¬ÊÇÓÉÓÚÈκÎÓû§¶¼¿ÉÒÔÆô¶¯¸ÃЧÀÍ£¬£¬£¬²¢ÇÒ¸ÃЧÀÍÒÔÍâµØÏµÍ³µÄÉí·ÝÔËÐС£¡£¡£¡£¡£¡£¡£
¸ÃÎó²îµÄ΢²¹¶¡³ÌÐòͨ¹ý×èÖ¹ÍâµØ·ÇÖÎÀíÔ±Óû§ÐÞ¸ÄÖ¸Ïò´«ÕæÐ§ÀÍ¿ÉÖ´ÐÐÎļþµÄ×¢²á±íÖµÀ´±ÜÃâ¹¥»÷ÕßÔËÐдúÂë¡£¡£¡£¡£¡£¡£¡£PoC¸´ÏÖÈçÏ£º
0PatchµÄÔÝʱ²¹¶¡ÊÊÓÃÓÚÒÔÏÂϵͳ£º
Windows 10 v20H2 32/64룬£¬£¬ÒÑÓÚ2021Äê1Ô¸üÐÂ
Windows 10 v2004 32/64룬£¬£¬ÓÚ2021Äê1Ô¸üÐÂ
Windows 10 v1909 32/64룬£¬£¬ÒÑÓÚ2021Äê1Ô¸üÐÂ
Windows 7¡¢32/64λºÍESU£¬£¬£¬ÓÚ2021Äê1Ô¸üÐÂ
Windows 7¡¢32/64루²»´øESU£©£¬£¬£¬ÒÑÓÚ2020Äê1Ô¸üÐÂ
0x02 ´¦Öóͷ£½¨Òé
ÔÚMicrosoftÐû²¼ÓÀÊÀ²¹¶¡Ö®Ç°£¬£¬£¬¿ÉÒÔͨ¹ý0Patchƽ̨ÏÂÔØÔÝʱ²¹¶¡¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://blog.0patch.com/2021/01/windows-installer-local-privilege.html
0x03 ²Î¿¼Á´½Ó
https://blog.0patch.com/2021/01/windows-installer-local-privilege.html
https://www.bleepingcomputer.com/news/security/windows-installer-zero-day-vulnerability-gets-free-micropatch/
https://halove23.blogspot.com/2020/12/oh-so-you-have-antivirus-nameevery-bug.html
0x04 ʱ¼äÏß
2021-01-28 0PatchÐû²¼ÔÝʱ²¹¶¡
2021-02-01 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/