Windows Print SpoolerÔ¶³Ì´úÂëÖ´ÐÐ0 day·ì϶£¨CVE-2021-34527£©

°ä²¼¹¦·ò 2021-07-02

0x00 ·ì϶¸ÅÊö

CVE     ID

CVE-2021-34527

ʱ      ¼ä

2021-07-02

Àà       ÐÍ

RCE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

  ËùÓÐWindows°æ±¾

¹¥»÷¸´ÔÓ¶È

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

ÊÇ

 

0x01 ·ì϶ÏêÇé

image.png

 

Windows Print SpoolerÊÇWindowsµÄ´òÓ¡»úºó¶Ü´¦Ö÷¨Ê½ £¬ÆäÖÎÀíËùÓб¾µØºÍÍøÂç´òÓ¡¶ÓÁв¢½ÚÔìËùÓдòÓ¡¹¤×÷ £¬±»¿í·ºÀûÓÃÓÚ±¾µØºÍÄÚÍøÖÐ ¡£

2021Äê6ÔÂ29ÈÕ £¬°²È«×êÑÐÈËÔ±ÔÚGitHubÉϹ«¿ªÁËÒ»¸öWindows Print SpoolerÔ¶³Ì´úÂëÖ´ÐÐ0day·ì϶£¨CVE-2021-34527£© ¡£

±ØÒª°ÑÎȵÄÊÇ £¬¸Ã·ì϶£¨CVE-2021-34527£©ÓëMicrosoft 6ÔÂ8ÈÕÐÇÆÚ¶þ²¹¶¡ÈÕÖн¨¸´²¢ÓÚ6ÔÂ21ÈÕ¸üеÄÒ»¸öEoPÉý¼¶µ½RCEµÄ·ì϶£¨CVE-2021-1675£©²»ÊÇͳһ¸ö·ì϶ ¡£ÕâÁ½¸ö·ì϶ÀàËÆµ«·ÖÆç £¬¹¥»÷ÏòÁ¿Ò²·ÖÆç ¡£

Ŀǰ¸Ã·ì϶ÒѾ­¹«¿ªÅû¶ £¬²¢ÇÒÒѳʴ˿ÌÒ°ÀûÓà ¡£µ± Windows Print Spooler ·þÎñ²»ÕýÈ·µØÖ´ÐÐÌØÈ¨Îļþ²Ù×÷ʱ £¬´æÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶ ¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ê¹Óà SYSTEM ȨÏÞÔËÐÐËÁÒâ´úÂë¡¢×°Ö÷¨Ê½¡¢²é¿´²¢¸ü¸Ä»òɾ³ýÊý¾Ý¡¢»ò´´½¨ÓµÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§ £¬µ«¹¥»÷±ØÐëÉæ¼°Å²Óà RpcAddPrinterDriverEx() µÄ¾­¹ýÉí·ÝÑéÖ¤µÄÓû§ ¡£

 

0x02 ´ëÖý¨Òé

Ŀǰ¸Ã·ì϶ÉÐ佨¸´ ¡£

½¨ÒéÖÕ³¡²¢½ûÓÃWindows Print Spooler·þÎñ ¡£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527

 

0x03 ²Î¿¼Á´½Ó

https://github.com/afwu/PrintNightmare

https://www.bleepingcomputer.com/news/security/public-windows-printnightmare-0-day-exploit-allows-domain-takeover/

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527

 

0x04 ¹¦·òÏß

2021-07-01  Microsoft°ä²¼°²È«¹«¸æ

2021-07-02  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png