΢Èí | ¶à¸ö0day·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-05-21

0x00 ·ì϶¸ÅÊö



²úÆ·

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Ó°ÏìÁìÓò

Windows

CVE-2020-0915

EOA

¸ßΣ

Windows

CVE-2020-0986

EOA

¸ßΣ

CVE-2020-0916

EOA

¸ßΣ

CVE-2020-0915

II

µÍΣ

ÔÝÎÞ

AE

¸ßΣ


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



2020Äê5ÔÂ19ÈÕ£¬Ç÷Ïò¿Æ¼¼£¨ZDI£©µÄ°²È«×¨¼ÒÅû¶ÁËMicrosoft WindowsÖÐÎå¸ö0day·ì϶£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶À´Éý¼¶WindowsÍÆËã»úÉϵÄÌØÈ¨ ¡£

CVE-2020-0916/CVE-2020-0986/CVE-2020-0915 ÊÇMicrosoft Windows splwow64²»ÊÜÐÅÀµµÄÖ¸Õë½â³ýÒýÓÃÌØÈ¨Éý¼¶·ì϶£¬CVSSÆÀ·Ö7.0 ¡£¿Éµ¼Ö¹¥»÷ÕßÔÚÊÜÓ°ÏìϵͳÉÏÌáÉýȨÏÞ ¡£¸Ã·ì϶ӰÏìÓû§Ä£Ê½´òÓ¡»úÇý¶¯·¨Ê½Ö÷»ú¹ý³Ìsplwow64.exe£¬²¢ÇÒÊÇÓÉÓÚ¶Ìȱ¶ÔÓû§ÌṩµÄÊäÈëÑéÖ¤ËùÒýÆðµÄ ¡£¹¥»÷ÕßÊ×ÏȱØÒª»ñµÃ¶ÔϵͳµÄµÍ½Ó¼ûȨÏÞÄÜÁ¦ÀûÓÃÕâЩ·ì϶£¬ÈçÀûÓóɹ¦£¬¿Éµ¼Ö¹¥»÷ÕßÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÒÔÖÐµÈÆëÈ«ÐÔÖ´ÐдúÂë ¡£

Õâ¸öÓû§Ä£Ê½ÏµĴòÓ¡»úÇý¶¯Ö÷»ú¹ý³Ìsplwow64.exe »¹Ò×ÊÜÒ»¸öµÍΣµÄÐÅϢй©·ì϶ӰÏì ¡£¸Ã·ì϶µÄ±àºÅÊÇCVE-2020-0915£¬CVSSÆÀ·Ö2.5 ¡£¸ÃÎÊÌâÊÇÓÉÓÚÔÚ½«Óû§ÌṩµÄÖµ½âÒýÓÃΪָÕë֮ǰ£¬²»×ã¶ÔÓû§ÊäÈëÖµµÄÕýÈ·ÑéÖ¤ ¡£

Áí±íÒ»¸ö·ì϶ÊÇMicrosoft Windows WLANÏνÓÅäÖÃÎļþ¶ÌȱÉí·ÝÑéÖ¤ÌØÈ¨Éý¼¶·ì϶£¬ CVSSÆÀ·Ö7.0£¬Ä¿Ç°ÉÐδ·ÖÅäCVE±àºÅ ¡£ÓÉÓÚ²»ÕýÈ·µØ´¦ÖÃWLANÏνÓÅäÖÃÎļþ£¬¹¥»÷ÕßÄܹ»´´½¨¶ñÒâÅäÖÃÎļþÀ´Ð¹Â¶ÍÆËã»úÕÊ»§µÄÍ´´¦ ¡£


0x02 ´ëÖý¨Òé


Ŀǰ³§ÉÌ»¹Î´°ä²¼²¹¶¡ ¡£

һʱ´ëÊ©£º×î´óÏ޶ȵØÏ÷¼õÓë·þÎñµÄ½»»¥£¬½öÔÊÐíÓë¿ÉÐŵĿͻ§¶ËºÍ·þÎñÆ÷ÓëÆä½øÐÐͨѶ ¡£


0x03 ÓйØÐÂÎÅ


https://securityaffairs.co/wordpress/103507/hacking/microsoft-windows-zero-days.html


0x04 ²Î¿¼Á´½Ó


https://www.zerodayinitiative.com/advisories/published/


0x05 ¹¦·òÏß


2020-05-19 ZDI°ä²¼·ì϶

2020-05-21 VSRC°ä²¼·ì϶¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾