Windows CryptoAPIºýŪ·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-01-15

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-0601 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.1 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Windows 10 Version 1607

Windows 10 Version 1709

Windows 10 Version 1803

Windows 10 Version 1809

Windows 10 Version 1903

Windows 10 Version 1909

Windows Server2016

Windows Server 2019


·ì϶¸ÅÊö


2020Äê1ÔÂ14ÈÕ΢Èí°ä²¼ÁËCVE-2020-0601·ì϶²¼¸æ £¬´Ë·ì϶ΪWindows¼ÓÃÜ¿âÖеÄÒ»¸ö¹Ø¼üµÄ·ì϶ £¬Windows CryptoAPI(Crypt32.dll) ÑéÖ¤ÍÖÔ²ÇúÏß¼ÓÃÜ (ECC)Ö¤ÊéµÄ·½Ê½ÖдæÔÚºýŪ·ì϶¡£


¹¥»÷ÕßÄܹ»Í¨¹ýʹÓúýŪÐԵĴúÂëÊðÃûÖ¤Êé¶Ô¶ñÒâ¿ÉÖ´ÐÐÎļþ½øÐÐÊðÃûÀ´ÀûÓô˷ì϶ £¬´Ó¶øÊ¹¸ÃÎļþËÆºõÀ´×Ô¿¿µÃסµÄºÏ·¨ÆðÔ´¡£Óû§½«ÎÞ·¨ÖªÂ·ÎļþÊǶñÒâµÄ £¬ÓÉÓÚÊý×ÖÊðÃûËÆºõÀ´×ÔÊÜÐÅÀµµÄÌṩ·¨Ê½¡£³É¹¦µÄÀûÓû¹Äܹ»Ê¹¹¥»÷Õß½øÐÐÖÐÑëÈ˹¥»÷ £¬²¢ÔÚÓëÊÜÓ°ÏìÈí¼þµÄÓû§ÏνÓÉϽâÃÜ»úÃÜÐÅÏ¢¡£


¸Ã·ì϶ΪNSA¶ÀÁ¢·¢ÏÖ £¬²¢»ã±¨¸øÎ¢Èí¡£Æ¾¾ÝNSA³É¹¦ÀûÓô˷ì϶½«Ê¹¹¥»÷Õß¿ÉÄÜÌṩÀ´×ÔÊÜÐÅÀµÊµÌåµÄ¶ñÒâ´úÂë¡£ÆäÖÐÔ̺¬£ºÊðÃûµÄÎļþºÍµç×ÓÓʼþ¡¢ÊðÃû¿ÉÖ´ÐдúÂëµÈ¡¢HTTPsÏνÓ¡£


ÖµÍ×ÌùÐĵÄÊÇÖ¸¶¨²ÎÊýµÄECCÃÜÔ¿Ö¤ÊéµÄWindows°æ±¾»áÊܵ½Ó°Ïì £¬¶øÕâÒ»»úÔì £¬×îÔçÓÉWIN10ÒýÈë £¬Ó°ÏìWIN10 £¬Windows Server 2016/2019°æ±¾ £¬¶øÓÚ½ñÄê1ÔÂ14ÈÕÖÕ³¡°²È«ÊØ»¤µÄWIN7/Windows Server 2008ÓÉÓÚ²»Ö§³Ö´ø²ÎÊýµÄECCÃÜÔ¿ £¬Òò¶ø²»ÊÜÓйØÓ°Ïì £¬µ«ÒÀÈ»½¨ÒéÓû§½«WIN7/ Windows Server 2008ϵͳ¸üÐÂÖÁ×îеÄWIN10ϵͳ»òWindows Server2016Ö®ºóµÄ°æ±¾ £¬²¢¸üÐÂÓйذ²È«²¹¶¡¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ΢ÈíÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶ £¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601¡£


²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601

https://media.defense.gov/2020/Jan/14/2002234275/-1/-1/0/CSA-WINDOWS-10-CRYPT-LIB-20190114.PDF