Windows Installer×é¼þ0day·ì϶

°ä²¼¹¦·ò 2021-02-01

0x00 ·ì϶¸ÅÊö

CVE  ID


ʱ   ¼ä

2021-02-01

Àà  ÐÍ

ȨÏÞÌáÉý

µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

·ñ

Ó°ÏìÁìÓò

Windows 7- Windows 10

 

0x01 ·ì϶ÏêÇé

image.png

¼òÊö

Windows InstallerÊÇWindowsÖеÄÒ»¸ö×é¼þ£¬ËüÊÇרÃÅÓÃÀ´ÖÎÀíºÍÅäÖÃÈí¼þ·þÎñµÄ¹¤¾ß ¡£

2020Äê10Ô£¬Microsoft½¨¸´ÁËWindows Installer×é¼þÖеÄÒ»¸ö·ì϶£¨CVE-2020-16902£¬ÆäCVSSÆÀ·Ö7.8 ¡£¸Ã·ìÏ¶Ôø±»ÂŴν¨¸´¡¢Èƹý£¬º¹Çà×·×ÙΪCVE-2019-1415¡¢CVE-2020-1302ºÍCVE-2020-0814£©£¬µ«¸Ã·ì϶µÄ½¨¸´·¨Ê½ÈԿɱ»Èƹý ¡£12ÔÂÏÂÑ®£¬¸Ã·ì϶µÄPoC±»¹«¿ª ¡£MicrosoftÒ»ÏòûÓÐÆëÈ«½¨¸´´Ë·ì϶ ¡£

½üÈÕ£¬MicrosoftÂŴγ¢ÊÔ½¨¸´µÄWindows Installer×é¼þ·ì϶£¨CVE-2020-16902²¹¶¡µÄÈÆ¹ý£© »ñµÃÁËÒ»¸öһʱ²¹¶¡£¬¸Ã²¹¶¡¿ÉÄÜÔ¤·À¹¥»÷ÕßÀûÓ÷ì϶»ñȡָ±êϵͳµÄ×î¸ßȨÏÞ ¡£


·ì϶·ÖÎö

ÔÚ×°ÖÃMSIÈí¼þ°üµÄ¹ý³ÌÖУ¬Windows Installer»áͨ¹ý¡° msiexec.exe¡±´´½¨»Ø¹ö¾ç±¾£¬ÒÔ±ãÔÚ¹ý³ÌÖгöÏÖÃýÎóʱ»¹Ô­ËùÓиü¸Ä ¡£

ÓµÓб¾µØÈ¨Ï޵Ĺ¥»÷ÕßÈôÊÇÄܹ»ÓÃÒ»¸öŤתע²á±íÖ·´Ö¸ÏòËûÃǵÄPayloadµÄ½ÅÕý±¾´úÌæ»Ø¹ö¾ç±¾£¬ÔòÄܹ»ÔËÐÐÓµÓÐSYSTEMȨÏ޵ĿÉÖ´ÐÐÎļþ ¡£

 

·ì϶¸´ÏÖ

¸Ã·ì϶µÄPoCÖÐʹÓõÄÊǻعö¾ç±¾£¬Ëü½«HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/services/Fax/ImagePathµÄÖµ¸ü¸ÄΪc:\Windows/tempasmae.exe£¬µ¼Ö´«Õæ·þÎñÆô¶¯Ê±Ê¹Óù¥»÷ÕßµÄasmae.exe ¡£Ö®ËùÒÔʹÓø÷þÎñ£¬ÊÇÓÉÓÚÈκÎÓû§¶¼Äܹ»Æô¶¯¸Ã·þÎñ£¬²¢ÇҸ÷þÎñÒÔ±¾µØÏµÍ³µÄÉí·ÝÔËÐÐ ¡£

¸Ã·ì϶µÄ΢²¹¶¡·¨Ê½Í¨¹ý×èÖ¹±¾µØ·ÇÖÎÀíÔ±Óû§Åú¸ÄÖ¸Ïò´«Õæ·þÎñ¿ÉÖ´ÐÐÎļþµÄ×¢²á±íÖ·´Ô¤·À¹¥»÷ÕßÔËÐдúÂë ¡£PoC¸´ÏÖÈçÏ£º

image.png

 

0PatchµÄһʱ²¹¶¡ºÏÓÃÓÚÒÔÏÂϵͳ£º

Windows 10 v20H2 32/64룬ÒÑÓÚ2021Äê1Ô¸üÐÂ

Windows 10 v2004 32/64룬ÓÚ2021Äê1Ô¸üÐÂ

Windows 10 v1909 32/64룬ÒÑÓÚ2021Äê1Ô¸üÐÂ

Windows 7¡¢32/64λºÍESU£¬ÓÚ2021Äê1Ô¸üÐÂ

Windows 7¡¢32/64루²»´øESU£©£¬ÒÑÓÚ2020Äê1Ô¸üÐÂ

 

 

0x02 ´ëÖý¨Òé

ÔÚMicrosoft°ä²¼ÓÀÔ¶²¹¶¡Ö®Ç°£¬Äܹ»Í¨¹ý0Patchƽ̨ÏÂÔØÒ»Ê±²¹¶¡ ¡£

ÏÂÔØÁ´½Ó£º

https://blog.0patch.com/2021/01/windows-installer-local-privilege.html

 

0x03 ²Î¿¼Á´½Ó

https://blog.0patch.com/2021/01/windows-installer-local-privilege.html

https://www.bleepingcomputer.com/news/security/windows-installer-zero-day-vulnerability-gets-free-micropatch/

https://halove23.blogspot.com/2020/12/oh-so-you-have-antivirus-nameevery-bug.html

 

0x04 ¹¦·òÏß

2021-01-28  0Patch°ä²¼Ò»Ê±²¹¶¡

2021-02-01  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png