Windows JScript ×é¼þ0day Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-06-01·ì϶±àºÅ
CVEÔÝÎÞ
·ì϶¼¶±ð
ÖÐ
³§ÉÌ×ÔÆÀ£º6.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
·ìϼûèÊö
½üÈÕ£¬windowsϵͳÓÖ·¢ÏÖһ·0day·ì϶£¬¸Ã·ì϶ÊÇÓÉϵͳÖеÄJScript×é¼þÔì³ÉµÄ£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÓû§µÄPCÉÏÖ´ÐжñÒâ´úÂ룬 ¹ÌȻ΢Èí²¢Î´Ìṩ´òËãÍÆ³ö²¹¶¡¼òÖ±Çй¦·ò±í£¬µ«Ò»Î»½²»°ÈËÅú×¢ËûÃÇÔÚ½øÐн¨¸´¡£
5ÔÂ29ÈÕ£¬ZDI°ä²¼ÁËÒ»·Ý»ã±¨£¬ÆäÖÐÔ̺¬ÓйظÃÃýÎóµÄ¾ßÌå¼¼Êõϸ½Ú£º
ÓÉÓڸ÷ì϶ӰÏì JScript ×é¼þ£¨Î¢Èí×Ô½ç˵µÄ JavaScript Ö´ÐУ©£¬Î¨Ò»µÄǰÌá¾ÍÊǹ¥»÷Õß±ØÐëÓÕÆÓû§½Ó¼ûÒ»¸ö¶ñÒâÍøÒ³»òÕßÔÚϵͳ¸ßµÍÔØ²¢´ò¿ª¶ñÒâ JS Îļþ£¨Í¨³£¾ÓÉ Windows Script Host-wscript.exe Ö´ÐУ©¡£
Õâ¸öȱµã´æÔÚÓÚ JScript ¶Ô Error ¶ÔÏóµÄ´¦Öùý³ÌÖС£¹¥»÷Õßͨ¹ýÔÚJScript ÖÐÖ´ÐÐ×÷Ϊ£¬¿ÉÄܵ¼ÖÂij¸öÖ¸ÕëÔÚ¿ªÊͺóÔâ³ÁÓ᣹¥»÷ÕßÄÜÀûÓø÷ì϶ÔÚµ±Ç°¹ý³ÌÏÂÖ´ÐдúÂë¡£
¸Ã·ì϶µÄΣÏÕϵÊý²¢Ã»ÓÐÌýÉÏÈ¥µÄÄÇô¸ß£¬ÓÉÓÚËüÎÞ·¨µ¼ÖÂϵͳÔâÆëÈ«¹¥Ï¡£Õâ¸öȱµã½öÔÊÐíɳÏä»·¾³ÖеĴúÂëÖ´ÐÐÎÊÌâ¡£¹¥»÷Õß±ØÒªÆäËüÀûÓÃÄÜÁ¦ÌÓÀëɳÏä²¢ÔÚÖ¸±êϵͳÉÏÖ´ÐдúÂë¡£
΢ÈíÔÚÍÆ³ö²¹¶¡£¬²»ÍâÒѾ³¬³öÁËÅû¶սÊõÉèÖõŦ·òÖá¡£
ͨ³£ÔÚÅû¶ȱµãºó´ÍÓë³§ÉÌ120ÌìµÄ¹¦·ò°ä²¼²¹¶¡¡£´Ó΢Èí¸´ÔµÄ¹¦·òÖáÀ´¿´£¬Î¢ÈíÄÑÒÔ¸´ÏÖ´¥·¢¸Ã·ì϶µÄ PoC ´úÂ룬´Ó¶øÆÆ·ÑÁË75%µÄÅû¶¹¦·òÖᣬµ¼Ö¹¤³ÌʦÎÞ·¨ÊµÊ±¸ÏÔÚ5ÔµIJ¹¶¡ÐÇÆÚ¶þ²âÊÔ²¢°ä²¼²¹¶¡¡£
¹ÌȻ΢Èí²¢Î´Ìá¹©ÍÆ³ö²¹¶¡µÄ¾ßÌ幦·òÖᣬµ«Î¢ÈíµÄÒ»Ãû½²»°ÈË֤ʵ³ÆÔÚÍÆ³ö½¨¸´¹æ»®¡£
ÔÚÅû¶·ì϶֮ʱ²¢Î´·¢ÏÖ·ì϶ÔâÀûÓõÄÇé¿ö¡£ÓÉÓÚÍøÉÏÏÕЩ²»´æÔÚ¼¼ÊõÏêÇ飬Òò¶øÔÚ΢Èí°ä²¼½¨¸´¹æ»®Ç°ºÜ¿ÉÄÜ»¹ÊÇδÔâÀûÓõÄÇé¿ö¡£
½â¾ö´ëÊ©
½¨ÒéÓû§²»ÒªÊ¹ÓÃÒÀ¸½ JScript ×é¼þµÄÀûÓÃÈç IE ä¯ÀÀÆ÷¡¢wscript.exe µÈÀ´´¦Öò»ÊÜÐÅÀµµÄ JS ´úÂë»òÎļþ¡£
²Î¿¼×ÊÁÏ
https://www.zerodayinitiative.com/advisories/ZDI-18-534/
https://www.bleepingcomputer.com/news/security/remote-code-execution-vulnerability-disclosed-in-windows-jscript-component/


¾©¹«Íø°²±¸11010802024551ºÅ