Dell SupportAssist 6Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-06-250x00 Îó²î¸ÅÊö
CVE ID | ʱ ¼ä | 2021-06-25 | |
Àà ÐÍ | µÈ ¼¶ | ¸ßΣ | |
Ô¶³ÌʹÓà | Ó°Ïì¹æÄ£ | ||
¹¥»÷ÖØÆ¯ºó | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ÎÞ | |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ·ñ |
0x01 Îó²îÏêÇé
2021Äê06ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬DellÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËDell SupportAssist µÄ BIOSConnect ¹¦Ð§ºÍHTTPSÖ¸µ¼¹¦Ð§ÖеÄ4¸öÇå¾²Îó²î¡£¡£¡£¡£¡£ÕâЩÎó²î»®·ÖΪ²»Çå¾²µÄTLSÅþÁ¬ÎÊÌ⣨CVE-2021-21571£©ºÍ3¸öÒç³öÎó²î£¨CVE-2021-21572¡¢CVE-2021-21573ºÍCVE-2021-21574£©£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄ×°±¸µÄBIOSÖÐÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ8.3¡£¡£¡£¡£¡£
ÕâЩÎó²îÓ°ÏìÁË129¿îDellÐͺŵÄÉÌÎñÌõ¼Ç±¾µçÄÔ¡¢Ì¨Ê½»úÇå¾²°åµçÄÔ£¬£¬£¬£¬£¬£¬°üÀ¨Ê¹ÓÃDellÇå¾²Æô¶¯ºÍÇå¾²ÄÚºËPC±£»£»£»£»£»¤µÄ×°±¸£¬£¬£¬£¬£¬£¬¾ÝÌåÏÖ£¬£¬£¬£¬£¬£¬Ô¼ÄªÓÐ3000Íǫ̀װ±¸Êܵ½Ó°Ïì¡£¡£¡£¡£¡£
Îó²îϸ½Ú
SupportAssist Èí¼þԤװÔÚ´ó´ó¶¼ÔËÐÐ Windows ϵͳµÄDell×°±¸ÉÏ£¬£¬£¬£¬£¬£¬¶ø BIOSConnect ÌṩԶ³Ì¹Ì¼þ¸üкͲÙ×÷ϵͳ»Ö¸´¹¦Ð§¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýһЩÎó²îʹÓÃÖ÷»úµÄUEFI¹Ì¼þ²¢»ñµÃ×°±¸ÉÏ´úÂëµÄ¿ØÖÆ£¬£¬£¬£¬£¬£¬ÏêÇéÈçÏ£º
UEFI BIOS https¿ÍÕ»Ö¤ÊéÑéÖ¤Îó²î£¨CVE-2021-21571£©
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ5.9¡£¡£¡£¡£¡£ÓÉÓÚDell BIOSConnect¹¦Ð§ºÍDell HTTPSÖ¸µ¼¹¦Ð§Ê¹ÓõÄDell UEFI BIOS https¿ÍÕ»°üÀ¨Ò»¸öÖ¤ÊéÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿Éͨ¹ýÖÐÐÄÈ˹¥»÷À´Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬µ¼Ö¾ܾøÐ§ÀͺÍPayload¸Ä¶¯¡£¡£¡£¡£¡£
BIOSConnect»º³åÇøÒç³öÎó²î£¨CVE-2021-21572¡¢CVE-2021-21573ºÍCVE-2021-21574£©
ÕâЩÎó²îµÄCVSSv3ÆÀ·Ö¾ùΪ7.2¡£¡£¡£¡£¡£ÓÉÓÚBIOSConnect¹¦Ð§°üÀ¨Ò»¸ö»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬¾ßÓÐϵͳÍâµØ»á¼ûȨÏ޵ľÓÉÈÏÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÔËÐÐí§Òâ´úÂë²¢ÈÆ¹ýUEFIÏÞÖÆ¡£¡£¡£¡£¡£
Õâ²¢²»ÊÇDellÅÌËã»úÓû§µÚÒ»´ÎÔâµ½ SupportAssist Èí¼þÖÐÇå¾²Îó²îµÄ¹¥»÷¡£¡£¡£¡£¡£2015Ä꣬£¬£¬£¬£¬£¬ÔÚDellϵͳ¼ì²âÈí¼þÖÐÒ²·¢Ã÷ÁËÒ»¸öRCE Îó²î¡£¡£¡£¡£¡£2019 Äê 5 Ô£¬£¬£¬£¬£¬£¬DellÐÞ¸´ÁËÒ»¸öÓÉÇå¾²Ñо¿Ô± Bill Demirkapi ÓÚ 2018Ä걨¸æµÄSupportAssist Ô¶³Ì´úÂëÖ´ÐÐ (RCE) Îó²î¡£¡£¡£¡£¡£ 2020 Äê 2 Ô£¬£¬£¬£¬£¬£¬SupportAssistÔٴα»ÐÞ¸´£¬£¬£¬£¬£¬£¬ÒÔ½â¾öÓÉÓÚ DLL ËÑË÷˳ÐòÐ®ÖÆÎó²î¶øµ¼ÖµÄÇå¾²Îó²î¡£¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬£¬ÉϸöÔÂDellÐÞ¸´ÁËÒ»¸ö¿ÉÒÔ½«·ÇÖÎÀíÔ±Óû§µÄȨÏÞÌáÉýµ½ÄÚºËȨÏÞµÄÎó²î£¬£¬£¬£¬£¬£¬ËüÊÇÔÚÊýÍòÍǫ̀´÷¶û×°±¸¸½´øµÄ DBUtil Çý¶¯³ÌÐòÖб»·¢Ã÷µÄ¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ£¬£¬£¬£¬£¬£¬CVE-2021-21573 ºÍ CVE-2021-21574ÒѾÔÚЧÀͶËÐÞ¸´£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÓû§²»ÐèÒªÌØÊâ²Ù×÷£»£»£»£»£»µ«CVE-2021-21571 ºÍ CVE-2021-21572 ÐèÒªDell¿Í»§¶Ë¾ÙÐÐ BIOS¸üÐÂÒÔÐÞ¸´Îó²î¡£¡£¡£¡£¡£ÏÖÔÚDellÕýÔÚΪÊÜÓ°ÏìµÄϵͳÌṩ BIOS/UEFI ¸üУ¬£¬£¬£¬£¬£¬²¢ÔÚ Dell.com É϶ÔÊÜÓ°ÏìµÄ¿ÉÖ´ÐгÌÐò¾ÙÐиüС£¡£¡£¡£¡£
Óû§±ØÐèΪËùÓÐÊÜÓ°ÏìµÄϵͳ¸üÐÂϵͳ BIOS/UEFI£¬£¬£¬£¬£¬£¬½¨ÒéʹÓà SupportAssist µÄ BIOSConnect¹¦Ð§ÒÔÍâµÄÒªÁì¾ÙÐÐBIOS¸üС£¡£¡£¡£¡£²»¿ÉÁ¬Ã¦¸üÐÂϵͳµÄÓû§¿ÉÒÔ´ÓBIOSÉèÖÃÒ³Ãæ»òʹÓÃDell Command | Configure£¨DCC£©µÄÔ¶³ÌϵͳÖÎÀí¹¤¾ß½ûÓÃBIOSConnect¡£¡£¡£¡£¡£
ÏêϸÊÜÓ°Ïì×°±¸ºÍÏà¹ØÐÞ¸´²½·¥Ïê¼ûDell¹Ù·½µÄÇ徲ͨ¸æ£º
https://www.dell.com/support/kbdoc/zh-cn/000188682/dsa-2021-106-dell-client-platform-security-update-for-multiple-vulnerabilities-in-the-supportassist-biosconnect-feature-and-https-boot-feature
0x03 ²Î¿¼Á´½Ó
https://www.dell.com/support/kbdoc/zh-cn/000188682/dsa-2021-106-dell-client-platform-security-update-for-multiple-vulnerabilities-in-the-supportassist-biosconnect-feature-and-https-boot-feature
https://www.bleepingcomputer.com/news/security/dell-supportassist-bugs-put-over-30-million-pcs-at-risk/
https://www.zdnet.com/article/biosconnect-code-execution-bugs-impact-millions-of-dell-devices/#ftag=RSSbaffb68
0x04 ʱ¼äÏß
2021-06-24 DellÐû²¼Ç徲ͨ¸æ
2021-06-25 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/