Dell SupportAssist 6Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-06-250x00 ·ì϶¸ÅÊö
CVE ID | ʱ ¼ä | 2021-06-25 | |
Àà ÐÍ | µÈ ¼¶ | ¸ßΣ | |
Ô¶³ÌÀûÓà | Ó°ÏìÁìÓò | ||
¹¥»÷¸´ÔÓ¶È | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ÎÞ | |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ·ì϶ÏêÇé

2021Äê06ÔÂ24ÈÕ£¬Dell°ä²¼°²È«¸üУ¬½¨¸´ÁËDell SupportAssist µÄ BIOSConnect Ö°ÄܺÍHTTPSÊèµ¼Ö°ÄÜÖеÄ4¸ö°²È«·ì϶¡£ÕâЩ·ì϶±ðÀëΪ²»°²È«µÄTLSÏνÓÎÊÌ⣨CVE-2021-21571£©ºÍ3¸öÒç¶Âí½Å£¨CVE-2021-21572¡¢CVE-2021-21573ºÍCVE-2021-21574£©£¬ÔÊÐí¹¥»÷ÕßÔÚÖ¸±êÉ豸µÄBIOSÖÐÖ´ÐÐËÁÒâ´úÂ룬CVSSÆÀ·ÖΪ8.3¡£
ÕâЩ·ì϶ӰÏìÁË129¿îDellÐͺŵÄÉÌÎñ±Ê¼Ç±¾µçÄÔ¡¢Ì¨Ê½»úºÍƽ°åµçÄÔ£¬Ô̺¬Ê¹ÓÃDell°²È«Æô¶¯ºÍ°²È«ÄÚºËPC±£»¤µÄÉ豸£¬¾Ý°µÊ¾£¬Ô¼ÄªÓÐ3000Íǫ̀É豸Êܵ½Ó°Ïì¡£
·ì϶ϸ½Ú
SupportAssist Èí¼þԤװÔÚ´óÎÞÊýÔËÐÐ Windows ϵͳµÄDellÉ豸ÉÏ£¬¶ø BIOSConnect ÌṩԶ³Ì¹Ì¼þ¸üкͲÙ×÷ϵͳ¸´ÔÖ°ÄÜ¡£Ô¶³Ì¹¥»÷Õß¿ÉÄÜͨ¹ýһЩ·ì϶ÀûÓÃÖ÷»úµÄUEFI¹Ì¼þ²¢»ñµÃÉ豸ÉÏ´úÂëµÄ½ÚÔ죬ÏêÇéÈçÏ£º
UEFI BIOS https²Ö¿âÖ¤ÊéÑéÖ¤·ì϶£¨CVE-2021-21571£©
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ5.9¡£ÓÉÓÚDell BIOSConnectÖ°ÄܺÍDell HTTPSÊèµ¼Ö°ÄÜʹÓõÄDell UEFI BIOS https²Ö¿âÔ̺¬Ò»¸öÖ¤ÊéÑéÖ¤·ì϶£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿Éͨ¹ýÖÐÑëÈ˹¥»÷À´ÀûÓø÷ì϶£¬µ¼Ö»ؾø·þÎñºÍPayload´Û¸Ä¡£
BIOSConnect»º³åÇøÒç¶Âí½Å£¨CVE-2021-21572¡¢CVE-2021-21573ºÍCVE-2021-21574£©
ÕâЩ·ì϶µÄCVSSv3ÆÀ·Ö¾ùΪ7.2¡£ÓÉÓÚBIOSConnectÖ°ÄÜÔ̺¬Ò»¸ö»º³åÇøÒç¶Âí½Å£¬ÓµÓÐϵͳ±¾µØ½Ó¼ûȨÏ޵ľ¹ýÈÏÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ÔËÐÐËÁÒâ´úÂë²¢ÈÆ¹ýUEFIÏÞ¶È¡£
Õâ²¢²»ÊÇDellÍÆËã»úÓû§µÚÒ»´ÎÔâµ½ SupportAssist Èí¼þÖа²È«·ì϶µÄ¹¥»÷¡£2015Ä꣬ÔÚDellϵͳ¼ì²âÈí¼þÖÐÒ²·¢ÏÖÁËÒ»¸öRCE ·ì϶¡£2019 Äê 5 Ô£¬Dell½¨¸´ÁËÒ»¸öÓɰ²È«×êÑÐÔ± Bill Demirkapi ÓÚ 2018Äê»ã±¨µÄSupportAssist Ô¶³Ì´úÂëÖ´ÐÐ (RCE) ·ì϶¡£ 2020 Äê 2 Ô£¬SupportAssistÔٴα»½¨¸´£¬ÒÔ½â¾öÓÉÓÚ DLL ËÑË÷°¤´Î½Ù³Ö·ì϶¶øµ¼Öµİ²È«·ì϶¡£×îºó£¬ÉϸöÔÂDell½¨¸´ÁËÒ»¸öÄܹ»½«·ÇÖÎÀíÔ±Óû§µÄȨÏÞÌáÉýµ½ÄÚºËȨÏ޵ķì϶£¬ËüÊÇÔÚÊýǧÍǫ̀´÷¶ûÉ豸¸½´øµÄ DBUtil Çý¶¯·¨Ê½Öб»·¢Ïֵġ£
0x02 ´ëÖý¨Òé
Ŀǰ£¬CVE-2021-21573 ºÍ CVE-2021-21574ÒѾÔÚ·þÎñ¶Ë½¨¸´£¬ÊÜÓ°ÏìµÄÓû§²»±ØÒª¶î±í²Ù×÷£»µ«CVE-2021-21571 ºÍ CVE-2021-21572 ±ØÒªDell¿Í»§¶Ë½øÐÐ BIOS¸üÐÂÒÔ½¨¸´·ì϶¡£Ä¿Ç°DellÔÚΪÊÜÓ°ÏìµÄϵͳÌṩ BIOS/UEFI ¸üУ¬²¢ÔÚ Dell.com É϶ÔÊÜÓ°ÏìµÄ¿ÉÖ´Ðз¨Ê½½øÐиüС£
Óû§±ØÐëΪËùÓÐÊÜÓ°ÏìµÄϵͳ¸üÐÂϵͳ BIOS/UEFI£¬½¨ÒéʹÓà SupportAssist µÄ BIOSConnectÖ°ÄÜÒÔ±íµÄ²½Öè½øÐÐBIOS¸üС£²»Äܵ±¼´¸üÐÂϵͳµÄÓû§Äܹ»´ÓBIOSÉèÖÃÒ³Ãæ»òʹÓÃDell Command | Configure£¨DCC£©µÄÔ¶³ÌϵͳÖÎÀí¹¤¾ß½ûÓÃBIOSConnect¡£
¾ßÌåÊÜÓ°ÏìÉ豸ºÍÓйؽ¨¸´´ëÊ©Ïê¼ûDell¹Ù·½µÄ°²È«²¼¸æ£º
https://www.dell.com/support/kbdoc/zh-cn/000188682/dsa-2021-106-dell-client-platform-security-update-for-multiple-vulnerabilities-in-the-supportassist-biosconnect-feature-and-https-boot-feature
0x03 ²Î¿¼Á´½Ó
https://www.dell.com/support/kbdoc/zh-cn/000188682/dsa-2021-106-dell-client-platform-security-update-for-multiple-vulnerabilities-in-the-supportassist-biosconnect-feature-and-https-boot-feature
https://www.bleepingcomputer.com/news/security/dell-supportassist-bugs-put-over-30-million-pcs-at-risk/
https://www.zdnet.com/article/biosconnect-code-execution-bugs-impact-millions-of-dell-devices/#ftag=RSSbaffb68
0x04 ¹¦·òÏß
2021-06-24 Dell°ä²¼°²È«¹«¸æ
2021-06-25 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ