Check Point Endpoint Security ClientÌáȨ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-08-30

?·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-8461 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


?Ó°Ïì°æ±¾


Check Point Endpoint Security Initial Client for Windows - Below Version E81.30


?·ì϶¸ÅÊö


Check Point Endpoint Security ClientÊÇÒÔÉ«ÁÐCheck Point¹«Ë¾µÄÒ»¿îÖն˰²È«·À»¤Èí¼þ £¬ËüÊÇÒ»¿î´øÓжà¸öÄ£¿éµÄÈí¼þ £¬Ô̺¬Êý¾ÝºÍÍøÂ簲ȫ £¬¸ß¼¶Íþв·ÀÓùºÍȡ֤ £¬ÒÔ¼°Ô¶³Ì½Ó¼ûVPNÈí¼þ½â¾ö¹æ»® £¬ÆäÖв¿ÃÅÄÚÈÝ×÷ΪWindows·þÎñÖ´ÐÐ £¬ÓµÓж¥¼¶NT AUTHORITY \SYSTEMȨÏÞ¡£


»ùÓÚWindowsƽ̨µÄCheck Point Endpoint Security Client´æÔÚÌáȨ·ì϶ £¬ÔÊÐíDZÔڵĹ¥»÷ÕßÉý¼¶È¨ÏÞ²¢Ê¹ÓÃSYSTEMȨÏÞÖ´ÐдúÂë¡£¹¥»÷ÕßÄܹ»Ê¹ÓÃϵͳ¼¶È¨ÏÞÔËÐжñÒâ¸ºÔØ £¬²¢Í¨¹ýÈÆ¹ýÀûÓ÷¨Ê½°×Ãûµ¥À´Ìӱܷ´¶ñÒâÈí¼þ¼ì²â¡£


°²È«×êÑÐÔ±·¢ÏÖ ¡°¿Éͨ¹ý½«ËÁÒâδÊðÃûµÄDLL¼ÓÔØµ½Check Point Endpoint SecurityÈí¼þʹÓõÄWindows·þÎñÖ®Ò»À´ÊµÏÖȨÏÞÌáÉýºÍÓÆ¾ÃÐÔ¡±¡£¸Ã·ì϶ÊÇÓÉÓÚʹÓò»ÊܽÚÔìµÄËÑË÷õè¾¶µ¼Öµİ²È«DLL¼ÓÔØ²»¼°ÒÔ¼°Î´ÑéÖ¤Æä¼ÓÔØµÄDLLÊÇ·ñʹÓÃÊý×ÖÖ¤Êé×÷ΪHadar¾ßÌåÐÅÏ¢½øÐÐÊðÃû¶øÒýÆðµÄ¡£


?·ì϶ÑéÖ¤


POC£ºhttps://safebreach.com/Post/Check-Point-Endpoint-Security-Initial-Client-for-Windows-Privilege-Escalation-to-SYSTEM¡£


?½¨¸´½¨Òé


Check Point°ä²¼°æ±¾¸üн¨¸´ÁË´Ë·ì϶£ºhttps://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk160812#Endpoint%20Security%20Server%20Downloads¡£


?²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/security/check-point-patches-privilege-escalation-flaw-in-endpoint-client/