Dell SupportAssist 6Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-06-25

0x00 Îó²î¸ÅÊö

CVE     ID


ʱ      ¼ä

2021-06-25

Àà      ÐÍ


µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ


Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

·ñ

 

0x01 Îó²îÏêÇé

image.png

2021Äê06ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬DellÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËDell SupportAssist µÄ BIOSConnect ¹¦Ð§ºÍHTTPSÖ¸µ¼¹¦Ð§ÖеÄ4¸öÇå¾²Îó²î¡£¡£ ¡£¡£¡£ÕâЩÎó²î»®·ÖΪ²»Çå¾²µÄTLSÅþÁ¬ÎÊÌ⣨CVE-2021-21571£©ºÍ3¸öÒç³öÎó²î£¨CVE-2021-21572¡¢CVE-2021-21573ºÍCVE-2021-21574£©£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄ×°±¸µÄBIOSÖÐÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ8.3¡£¡£ ¡£¡£¡£

ÕâЩÎó²îÓ°ÏìÁË129¿îDellÐͺŵÄÉÌÎñÌõ¼Ç±¾µçÄÔ¡¢Ì¨Ê½»úÇå¾²°åµçÄÔ£¬£¬£¬£¬£¬£¬°üÀ¨Ê¹ÓÃDellÇå¾²Æô¶¯ºÍÇå¾²ÄÚºËPC±£»£»£»£»£»¤µÄ×°±¸£¬£¬£¬£¬£¬£¬¾ÝÌåÏÖ£¬£¬£¬£¬£¬£¬Ô¼ÄªÓÐ3000Íǫ̀װ±¸Êܵ½Ó°Ïì¡£¡£ ¡£¡£¡£

 

Îó²îϸ½Ú

SupportAssist Èí¼þԤװÔÚ´ó´ó¶¼ÔËÐÐ Windows ϵͳµÄDell×°±¸ÉÏ£¬£¬£¬£¬£¬£¬¶ø BIOSConnect ÌṩԶ³Ì¹Ì¼þ¸üкͲÙ×÷ϵͳ»Ö¸´¹¦Ð§¡£¡£ ¡£¡£¡£Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýһЩÎó²îʹÓÃÖ÷»úµÄUEFI¹Ì¼þ²¢»ñµÃ×°±¸ÉÏ´úÂëµÄ¿ØÖÆ£¬£¬£¬£¬£¬£¬ÏêÇéÈçÏ£º

UEFI BIOS https¿ÍÕ»Ö¤ÊéÑéÖ¤Îó²î£¨CVE-2021-21571£©

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ5.9¡£¡£ ¡£¡£¡£ÓÉÓÚDell BIOSConnect¹¦Ð§ºÍDell HTTPSÖ¸µ¼¹¦Ð§Ê¹ÓõÄDell UEFI BIOS https¿ÍÕ»°üÀ¨Ò»¸öÖ¤ÊéÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿Éͨ¹ýÖÐÐÄÈ˹¥»÷À´Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬µ¼Ö¾ܾøÐ§ÀͺÍPayload¸Ä¶¯¡£¡£ ¡£¡£¡£

 

BIOSConnect»º³åÇøÒç³öÎó²î£¨CVE-2021-21572¡¢CVE-2021-21573ºÍCVE-2021-21574£©

ÕâЩÎó²îµÄCVSSv3ÆÀ·Ö¾ùΪ7.2¡£¡£ ¡£¡£¡£ÓÉÓÚBIOSConnect¹¦Ð§°üÀ¨Ò»¸ö»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬¾ßÓÐϵͳÍâµØ»á¼ûȨÏ޵ľ­ÓÉÈÏÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÔËÐÐí§Òâ´úÂë²¢ÈÆ¹ýUEFIÏÞÖÆ¡£¡£ ¡£¡£¡£

Õâ²¢²»ÊÇDellÅÌËã»úÓû§µÚÒ»´ÎÔâµ½ SupportAssist Èí¼þÖÐÇå¾²Îó²îµÄ¹¥»÷¡£¡£ ¡£¡£¡£2015Ä꣬£¬£¬£¬£¬£¬ÔÚDellϵͳ¼ì²âÈí¼þÖÐÒ²·¢Ã÷ÁËÒ»¸öRCE Îó²î¡£¡£ ¡£¡£¡£2019 Äê 5 Ô£¬£¬£¬£¬£¬£¬DellÐÞ¸´ÁËÒ»¸öÓÉÇå¾²Ñо¿Ô± Bill Demirkapi ÓÚ 2018Ä걨¸æµÄSupportAssist Ô¶³Ì´úÂëÖ´ÐÐ (RCE) Îó²î¡£¡£ ¡£¡£¡£ 2020 Äê 2 Ô£¬£¬£¬£¬£¬£¬SupportAssistÔٴα»ÐÞ¸´£¬£¬£¬£¬£¬£¬ÒÔ½â¾öÓÉÓÚ DLL ËÑË÷˳ÐòÐ®ÖÆÎó²î¶øµ¼ÖµÄÇå¾²Îó²î¡£¡£ ¡£¡£¡£×îºó£¬£¬£¬£¬£¬£¬ÉϸöÔÂDellÐÞ¸´ÁËÒ»¸ö¿ÉÒÔ½«·ÇÖÎÀíÔ±Óû§µÄȨÏÞÌáÉýµ½ÄÚºËȨÏÞµÄÎó²î£¬£¬£¬£¬£¬£¬ËüÊÇÔÚÊýÍòÍǫ̀´÷¶û×°±¸¸½´øµÄ DBUtil Çý¶¯³ÌÐòÖб»·¢Ã÷µÄ¡£¡£ ¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ£¬£¬£¬£¬£¬£¬CVE-2021-21573 ºÍ CVE-2021-21574ÒѾ­ÔÚЧÀͶËÐÞ¸´£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÓû§²»ÐèÒªÌØÊâ²Ù×÷£»£»£»£»£»µ«CVE-2021-21571 ºÍ CVE-2021-21572 ÐèÒªDell¿Í»§¶Ë¾ÙÐÐ BIOS¸üÐÂÒÔÐÞ¸´Îó²î¡£¡£ ¡£¡£¡£ÏÖÔÚDellÕýÔÚΪÊÜÓ°ÏìµÄϵͳÌṩ BIOS/UEFI ¸üУ¬£¬£¬£¬£¬£¬²¢ÔÚ Dell.com É϶ÔÊÜÓ°ÏìµÄ¿ÉÖ´ÐгÌÐò¾ÙÐиüС£¡£ ¡£¡£¡£

Óû§±ØÐèΪËùÓÐÊÜÓ°ÏìµÄϵͳ¸üÐÂϵͳ BIOS/UEFI£¬£¬£¬£¬£¬£¬½¨ÒéʹÓà SupportAssist µÄ BIOSConnect¹¦Ð§ÒÔÍâµÄÒªÁì¾ÙÐÐBIOS¸üС£¡£ ¡£¡£¡£²»¿ÉÁ¬Ã¦¸üÐÂϵͳµÄÓû§¿ÉÒÔ´ÓBIOSÉèÖÃÒ³Ãæ»òʹÓÃDell Command | Configure£¨DCC£©µÄÔ¶³ÌϵͳÖÎÀí¹¤¾ß½ûÓÃBIOSConnect¡£¡£ ¡£¡£¡£

ÏêϸÊÜÓ°Ïì×°±¸ºÍÏà¹ØÐÞ¸´²½·¥Ïê¼ûDell¹Ù·½µÄÇ徲ͨ¸æ£º

https://www.dell.com/support/kbdoc/zh-cn/000188682/dsa-2021-106-dell-client-platform-security-update-for-multiple-vulnerabilities-in-the-supportassist-biosconnect-feature-and-https-boot-feature

 

0x03 ²Î¿¼Á´½Ó

https://www.dell.com/support/kbdoc/zh-cn/000188682/dsa-2021-106-dell-client-platform-security-update-for-multiple-vulnerabilities-in-the-supportassist-biosconnect-feature-and-https-boot-feature

https://www.bleepingcomputer.com/news/security/dell-supportassist-bugs-put-over-30-million-pcs-at-risk/

https://www.zdnet.com/article/biosconnect-code-execution-bugs-impact-millions-of-dell-devices/#ftag=RSSbaffb68

 

0x04 ʱ¼äÏß

2021-06-24  DellÐû²¼Ç徲ͨ¸æ

2021-06-25  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png