CVE-2020-17087 | Windows cng.sysȨÏÞÌáÉý·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-11-02

0x00 ·ì϶¸ÅÊö

CNVD   ID

CVE-2020-17087

ʱ      ¼ä

2020-11-02

Àà    ÐÍ

ȨÏÞÌáÉý

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

·ñ

Ó°ÏìÁìÓò

Windows7¡¢Windows10

 

cng.sysÊÇwindowsÖеijÁÒªsysÎļþ ¡£ÈôÊǸÃÎļþ°Ü»µ£¬Ôò»á³öÏÖ´ò¿ªÀûÓ÷¨Ê½Ê±ÌáÐѶÌȱsysÎļþ¡¢ÏµÍ³ÔËÐÐÖгöÏÖÎļþȱʧµÄÌáÐѵ¯´°¡¢µçÄÔ³öÏÖÀ¶ÆÁµÈÇé¿ö ¡£

0x01 ·ì϶ÏêÇé

 

image.png


2020Äê10ÔÂ31ÈÕ£¬ÓÉÓÚWinodws cng.sysȨÏÞÌáÉý·ì϶£¨CVE-2020-17087£©³¬¹ýÁËGoogleÒªÇó΢Èí7ÌìÄÚ½¨¸´µÄÆÚÏÞ£¬Google Progect ZeroÍŶӰ䲼Á˸÷ì϶µÄ¼¼Êõϸ½ÚºÍPOC ¡£

¸Ã·ì϶ÊÇWindows cng.sysÇý¶¯ÖеĻº³åÇøÒç¶Âí½Å£¬¹¥»÷ÕßÄܹ»ÔÚÓû§¶Ëͨ¹ýIOCTL 0x390400·¢ËͶÔÓ¦µÄ»ûÐÎÊý¾Ý£¬´Ó¶øÔì³ÉÒç³ö ¡£¹¥»÷Õß»¹Äܹ»Í¨¹ýÓÕʹÓû§´ò¿ª¶ñÒâµÄÎļþ»òÍøÂç×ÊÔ´£¬ÔÙ½áºÏÆäËü·ì϶£¨ÈçChrome 0day·ì϶£©´Óͨ³£Óû§È¨ÏÞÌáÉýµ½ÖÎÀíԱȨÏÞ ¡£

ÖµÍ×ÌùÐĵÄÊÇ£¬½üÆÚÅû¶µÄÒ»¸öChrome 0day·ì϶£¨CVE-2020-15999£© ¡£¸Ã·ì϶ÊÇChrome FreeType×ÖÌåäÖȾʱµÄÒ»´¦ÄÚ´æ·ÛËé·ì϶£¬Ô¶³Ì¹¥»÷Õß¿ÉÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó£¬ÓÕʹÓû§µã»÷£¬×îÖÕ¿ÉÔì³É»Ø¾ø·þÎñ¹¥»÷»òÔÚÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£Ä¿Ç°¸Ã·ì϶ÒѾ­ÔÚ86.0.4240.111°æ±¾Öн¨¸´ ¡£

 

0x02 ´ëÖý¨Òé

΢ÈíÔ¤¼Æ½«ÔÚ2020Äê11ÔÂ10ÈÕ°ä²¼¸Ã·ì϶µÄ²¹¶¡ ¡£ÓÉÓڸ÷ì϶Ŀǰ´¦ÓÚ0day¿ÉÀûÓÃ״̬£¬ÇÒÒÑÈ·ÈÏ´æÔÚÓйصÄÔÚÒ°¹¥»÷°¸Àý ¡£°²È«Íþвˮƽ½Ï¸ß£¬½¨Òé·À±¸ÓйØÒÑÖª·ì϶£¬²¢ÆÚ´ý¹Ù·½²¹¶¡ ¡£

 

0x03 ²Î¿¼Á´½Ó

https://bugs.chromium.org/p/project-zero/issues/detail?id=2104

https://www.theregister.com/2020/10/30/windows_kernel_zeroday/

https://securityaffairs.co/wordpress/110193/hacking/google-discloses-windows-zero-day.html?

 

0x04 ¹¦·òÏß

2020-10-31  Google Project Zero°ä²¼²¼¸æ

2020-11-02  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

 



image.png