¡¾·ì϶¹«¸æ¡¿CVE-2020-17008 Windows Kernel 0day·ì϶
°ä²¼¹¦·ò 2020-12-240x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-17008 | ʱ ¼ä | 2020-12-24 |
Àà ÐÍ | µÈ ¼¶ | ¸ßΣ | |
Ô¶³ÌÀûÓà | ·ñ | Ó°ÏìÁìÓò |
0x01 ·ì϶ÏêÇé

½ñÄê6Ô£¬Microsoft°ä²¼°²È«²¼¸æ£¬Windows kernelÖдæÔÚÒ»¸öȨÏÞÌáÉý·ì϶£¨CVE-2020-0986£©¡£¸Ã·ì϶ÊÇÓÉÓÚWindows kernelÎÞ·¨ÕýÈ·´¦ÖÃÄÚ´æÖеĶÔÏ󣬯äCVSSÆÀ·ÖΪ7.8¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚkernelģʽÏÂÔËÐÐËÁÒâ´úÂ룬×îÖÕµ¼Ö¹¥»÷ÕßÔÚϵͳÉÏ×°ÖöñÒⷨʽ¡¢¸ü¸Ä»òɾ³ýÊý¾Ý¡¢´´½¨ÕÊ»§µÈ¡£µ«ÒªÀûÓô˷ì϶£¬¹¥»÷Õß±ØÐëÏȵǼ²¢½ÚÔìϵͳ¡£MicrosoftÔÚ6Ô°䲼µÄ°²È«¸üÐÂÖÐͨ¹ý¸ü¸ÄWindows kernel´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£
µ«ÓÉÓÚMicrosoft°ä²¼µÄ²¹¶¡·¨Ê½ÎÞ·¨½¨¸´CVE-2020-0986£¬¹¥»÷ÕßÒÀÈ»Äܹ»Í¨¹ý·¢ËÍÆ«ÒÆÁ¿À´´¥·¢´Ë·ì϶£¬ÒÔÌá¸ßÆä¶ÔkernelµÄȨÏÞ£¬´Ë·ì϶±»·ÖÅäµÄCVE IDΪCVE-2020-17008¡£
CVE-2020-0986ÊÇÓÉÓÚËÁÒâÖ¸ÕëÒýÓã¬ÔÊÐí¹¥»÷Õß½ÚÔìÖ¸Ïòmemcpyº¯ÊýµÄ¡°src¡±ºÍ¡°dest¡±Ö¸Õë¡£MicrosoftµÄ²¹¶¡·¨Ê½ÊDz»ÕýÈ·µÄ£¬ÓÉÓÚËü¸ü¸ÄÁËÖ¸ÏòÆ«ÒÆÁ¿µÄÖ¸Õ룬Òò¶ø¹¥»÷ÕßÈÔÄܹ»½ÚÔì¸Ãº¯ÊýµÄ²ÎÊý¡£ÓÉÓÚÅû¶ÆÚÏÞ³¬ÆÚ£¬Ä¿Ç°¸Ã·ì϶µÄPoCÒѾ°ä²¼¡£
Ó°ÏìÁìÓò£º
Windows Server 2012
Windows RT 8.1
Windows 8.1 for x64-based systems
Windows 8.1 for 32-bit systems
Windows Server 2016 (Server Core installation)
Windows Server 2016
Windows 10 for x64-based Systems
Windows 10 Version 1709 for x64-based Systems
Windows 10 Version 1709 for 32-bit Systems
Windows Server, version 1909 (Server Core installation)
Windows 10 Version 1909 for ARM64-based Systems
Windows Server, version 2004 (Server Core installation)
Windows 10 Version 2004 for 32-bit Systems
Windows 10 for 32-bit Systems
Windows Server, version 1903 (Server Core installation)
Windows 10 Version 1903 for ARM64-based Systems
Windows 10 Version 1903 for x64-based Systems
Windows 10 Version 2004 for x64-based Systems
Windows 10 Version 2004 for ARM64-based Systems
Windows 10 Version 1903 for 32-bit Systems
Windows 10 Version 1709 for ARM64-based Systems
Windows 10 Version 1607 for x64-based Systems
Windows 10 Version 1607 for 32-bit Systems
Windows 10 Version 1909 for x64-based Systems
Windows 10 Version 1909 for 32-bit Systems
Windows Server 2019 (Server Core installation)
Windows Server 2019
Windows 10 Version 1809 for ARM64-based Systems
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems
Windows 10 Version 1803 for ARM64-based Systems
Windows Server, version 1803 (Server Core Installation)
Windows 10 Version 1803 for x64-based Systems
Windows 10 Version 1803 for 32-bit Systems
Windows Server 2012 R2 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server Core installation)
0x02 ´ëÖý¨Òé
Microsoft´òËãÔÚ2020Äê11Ô°䲼¸Ã·ì϶µÄ²¹¶¡£¬µ«ÓÉÓÚÔÚ²âÊԽ׶η¢ÏÖÎÊÌ⣬Òò¶øÍƳٵ½2021Äê1ÔÂ12ÈÕÐÇÆÚ¶þ°ä²¼£¬½¨ÒéÆÚ´ý¹Ù·½°ä²¼²¹¶¡²¢×öºÃÓйطÀ»¤´ëÊ©¡£
0x03 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-0986
https://www.bleepingcomputer.com/news/security/windows-zero-day-with-bad-patch-gets-new-public-exploit-code/
https://bugs.chromium.org/p/project-zero/issues/detail?id=2096
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17008
0x04 ¹¦·òÏß
2020-12-23 StoneÅû¶·ì϶
2020-12-24 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ