CVE-2019-1458 | Win32kÌØÈ¨ÌáÉýÎó²î

Ðû²¼Ê±¼ä 2019-12-12


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


1.Åä¾°ÐÎò


¿ËÈÕMicrosoftÐû²¼ÁËÕë¶Ô36¸öCVEÎó²îµÄÁ½¸öͨ¸æºÍ¸üС£¡£¡£¡£ÔÚÕâЩÎó²îÖУ¬£¬£¬£¬£¬ÓÐ7¸ö±»·ÖÀàΪÑÏÖØ£¬£¬£¬£¬£¬27¸ö±»·ÖÀàΪÖ÷Òª£¬£¬£¬£¬£¬1¸ö±»·ÖÀàΪÖУ¬£¬£¬£¬£¬1¸ö±»·ÖÀàΪµÍ¡£¡£¡£¡£²¢ÇÒCVE-2019-1458Îó²îÒѱ»Ê¹Óᣡ£¡£¡£

½üÆÚ¿¨°Í˹»ù¼ì²âµ½µÄ¹¥»÷ÊÂÎñ³ÆOperation WizardÔÚ¹¥»÷Àú³ÌÖÐʹÓÃÁËWindowsÎó²î£¨CVE-2019-1458£©ºÍGoogle ChromeÎó²î£¨CVE-2019-13720£©£¬£¬£¬£¬£¬½«¶ñÒâÈí¼þÏÂÔØ²¢×°Öõ½»á¼ûº«ÓïÐÂÎÅÃÅ»§µÄWindowsÅÌËã»úÉÏ¡£¡£¡£¡£


2.Îó²îÏêÇé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


CVE-2019-1458ÊÇWin32kÖеÄÌØÈ¨ÌáÉýÎó²î£¬£¬£¬£¬£¬Win32k×é¼þÎÞ·¨×¼È·´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ£¬£¬£¬£¬£¬µ¼ÖÂWindowsÖб£´æÒ»¸öÌØÈ¨ÌáÉýÎó²î¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄÚºËģʽÏÂÔËÐÐí§Òâ´úÂë¡£¡£¡£¡£È»ºó¹¥»÷Õß¿ÉÄÜ»á×°ÖóÌÐò¡¢Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£» £»£»£»£»£»£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£¡£

ҪʹÓôËÎó²î£¬£¬£¬£¬£¬¹¥»÷ÕßÊ×ÏȱØÐèµÇ¼ϵͳ¡£¡£¡£¡£¹¥»÷Õß¿ÉÄÜÔËÐпÉÒÔʹÓôËÎó²î²¢¿ØÖÆÊÜÓ°ÏìϵͳµÄÌØÖÆÓ¦ÓóÌÐò¡£¡£¡£¡£

ÁíÍâGoogleÎó²îÖ®CVE-2019-13720ÒѾ­ÔÚChrome 78.0.3904.87ÖÐÐÞ¸´£¬£¬£¬£¬£¬¿¨°Í˹»ù½«ChromeÎó²î¼ì²âΪExploit.Win32.Generic£¬£¬£¬£¬£¬½«MicrosoftÎó²î¼ì²âΪPDM£ºExploit.Win32.Generic¡£¡£¡£¡£


3.ÐÞ¸´½¨Òé


ÏÖÔÚ΢Èí¹Ù·½ÒѾ­Ðû²¼¸ÃÎó²îµÄ²¹¶¡£¡£¡£¡£¬£¬£¬£¬£¬½¨ÒéÓû§¸üе½×îа汾£¬£¬£¬£¬£¬ÒÔïÔÌ­¹¥»÷µÄ¿ÉÄÜÐÔ¡£¡£¡£¡£



4.²Î¿¼Á´½Ó


https://securelist.com/windows-0-day-exploit-cve-2019-1458-used-in-operation-wizardopium/95432/

https://www.bleepingcomputer.com/news/security/windows-chrome-zero-days-chained-in-operation-wizardopium-attacks/

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1458