¡¾·ì϶µý±¨¡¿Spectre CPU·ì϶£¨CVE-2017-5753£©

°ä²¼¹¦·ò 2021-03-02

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2017-5753

ʱ   ¼ä

2021-03-02

Àà   ÐÍ

Éè¼ÆÃýÎó  

µÈ   ¼¶


Ô¶³ÌÀûÓÃ


Ó°ÏìÁìÓò


 

0x01 ·ì϶ÏêÇé

image.png

2021Äê03ÔÂ01ÈÕ £¬°²È«×êÑÐÈËÔ±ÖìÀû°²¡¤ÎÖÒÁÉ­£¨Julien Voisin£©ÔÚVirusTotal¶ñÒâÈí¼þ·ÖÎöƽ̨ÉÏ·¢ÏÖÁËSpectre CPU·ì϶£¨CVE-2017-5753£©µÄLinux°æºÍWindows°æµÄ·ì϶ÀûÓ÷¨Ê½ £¬Õⰵʾ¿ÉÄܽøÐÐÏÖʵ·ÛËé²¢ÆëÈ«±øÆ÷»¯µÄÓÐЧÀûÓ÷¨Ê½ÒѾ­ÔÚ¹«¹²ÁìÓòÖй«¿ª¡£

Spectre CPU·ì϶ÊÇ2018Äê1ÔÂGoogle Project ZeroÅû¶µÄIntel¡¢AMDºÍARM´¦ÖÃÆ÷¼Ü¹¹ÖеÄÓ²¼þÉè¼ÆÈ±µã£¨Meltdown£ºCVE-2017-5754¡¢Spectre£ºCVE-2017-5753ºÍCVE-2017-5715£© £¬¹¥»÷Õß¿ÉÄÜÀûÓ÷ì϶ÔËÐÐÀûÓ÷¨Ê½ÖеĴúÂëÀ´·ÛËé·ÖÆçÀûÓ÷¨Ê½Ö®¼äÔÚCPU²ãÃæµÄ¸ôÀë £¬¶øºóÇÔȡͳһϵͳÉÏÔËÐÐµÄÆäËüÀûÓõÄÃô¸ÐÊý¾Ý¡£

Google°µÊ¾ £¬Spectre CPU·ì϶»áÓ°ÏìÔ̺¬Windows¡¢Linux¡¢macOS¡¢AndroidºÍChromeOSµÈÔÚÄÚµÄÖ÷Á÷²Ù×÷ϵͳ¡£×Ô¾õÏָ÷ì϶ÒÔÀ´ £¬ËùÓÐÖ÷Á÷CPUºÍOS¹©¸øÉ̾ù°ä²¼Á˹̼þ²¹¶¡ºÍÈí¼þ½¨¸´ £¬µ«ÉÐδ¸üÐÂÆäϵͳµÄÓû§ÒÀÈ»ÈÝÒ×Êܵ½Spectre CPU·ì϶µÄ¹¥»÷ £¬ÓÈÆäÊÇʹÓþɰæÐ¾Æ¬²¢ÔËÐоɰæ²Ù×÷ϵͳµÄÓû§£¨Èç2015Äê´úµÄPC £¬²¢Ê¹ÓÃHaswell»ò¾ÉµÄIntel´¦ÖÃÆ÷£©¡£

VirusTotalÉϵķì϶ÀûÓ÷¨Ê½ÊÇÉϸöÔÂÉÏ´«µÄ £¬¸ÃÈí¼þ°üÊǺÏÓÃÓÚWindowsºÍLinuxµÄImmunity Canvas 7.26×°Ö÷¨Ê½(Immunity CANVASΪȫÇòµÄÉøÈë²âÊÔÈËÔ±ºÍ°²È«×¨ÒµÈËÔ±ÌṩÁËÊý°ÙÖÖ·ì϶ÀûÓá¢×Ô¶¯»¯µÄ·ì϶ÀûÓÃϵͳÒÔ¼°È«Ãæ¡¢¿¿µÃסµÄ·ì϶ÀûÓÿª·¢¿ò¼Ü)¡£

image.png


´Ë·ì϶ÀûÓ÷¨Ê½Äܹ»Ê¹Í¨³£Óû§Äܹ»´ÓÖ¸±êÉ豸µÄÄÚºËÄÚ´æÖÐת´¢WindowsϵͳºÍLinuxϵͳÖÐ/etc/shadowÎļþÖеÄLM/NT¹þÏ£¡£´Ë±í £¬¸ÃÀûÓ÷¨Ê½»¹¿ÉÄÜת´¢Kerberos tickets £¬¿ÉÓëPsExecһ·ÓÃÓÚWindowsϵͳµÄ±¾µØÈ¨ÏÞÉý¼¶ºÍºáÏòÒÆ¶¯¡£ÕâÒâζ×Å £¬ÈôÊǸ÷ì϶±»³É¹¦ÀûÓà £¬Ôò¹¥»÷ÕßÄܹ»ÇÔÈ¡ÊÜÓ°ÏìϵͳµÄÃô¸ÐÊý¾Ý £¬Ô̺¬ÃÜÂë¡¢ÎĵµÒÔ¼°ÄÚ´æÖÐÈκοÉÓÃµÄÆäËüÊý¾Ý¡£

image.png

image.png

 

ÈçVoisinËù˵ £¬´ò¹ý¸Ã·ì϶²¹¶¡µÄLinux»òWindowsϵͳÔò²»ÊÜÓ°Ïì¡£¶øÎ¢Èí°µÊ¾ £¬ÓÉÓÚ×°Öò¹¶¡ºóϵͳ»úÄÜ»áÓÐÏÔÖøµÄ½µÂä £¬Òò¶øÓû§×îÈÝÒ×Ìø¹ýÀûÓûº½â´ëÊ©¡£

³ý´ËÖ®±í £¬¼´±ã¹¥»÷ÕßÄõ½ÁËÕâÁ½¸ö·ì϶ÀûÓ÷¨Ê½Èí¼þ°üÖеÄÈκÎÒ»¸ö £¬Ö»ÔËÐÐËüÃÇÒ²²»»á²úÉúÈκÎÁ˾Ö £¬ÓÉÓÚËüÃǶ¼Ö»ÄÜÔÚÕýÈ·µÄ²ÎÊýÏÂÖ´ÐÐ £¬³ý·Ç¹¥»÷Õß¿ÉÄÜÔËÐÐÕýÈ·µÄ²ÎÊý¡£

 

0x02 ´ëÖý¨Òé

Spectre CPU·ì϶ÒÑÓÚ2018Ä꽨¸´ £¬½¨Òéδʵʱ¸üеÄÓû§²Î¿¼CPUºÍOS¹©¸øÉ̹ٷ½°ä²¼µÄ½¨¸´·¨Ê½»ò»º½â´ëÊ©¡£

Õë¶Ôwindowsϵͳ £¬Î¢Èíͨ¹ý¸ü¸ÄWindowsºÍоƬ΢´úÂëÀ´»º½â´Ë·ì϶ £¬²¢½¨ÒéʹÓÃWindows UpdateºÍоƬ΢´úÂë¸üС£

ÏêÇéÁ´½Ó£º

https://www.microsoft.com/security/blog/2018/01/09/understanding-the-performance-impact-of-spectre-and-meltdown-mitigations-on-windows-systems/

 

0x03 ²Î¿¼Á´½Ó

https://www.virustotal.com/gui/file/6461d0988c835e91eb534757a9fa3ab35afe010bec7d5406d4dfb30ea767a62c/detection

https://www.bleepingcomputer.com/news/security/working-windows-and-linux-spectre-exploits-found-on-virustotal/?

https://dustri.org/b/spectre-exploits-in-the-wild.html

https://therecord.media/first-fully-weaponized-spectre-exploit-discovered-online/

 

0x04 ¹¦·òÏß

2021-03-01  Julien VoisinÅû¶ÀûÓ÷¨Ê½

2021-03-02  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png