Ç÷ÊÆ¿Æ¼¼·ÀÍþв¹¤¾ß°üÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-10-23Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-9491£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨£¬£¬£¬£¬£¬³§ÉÌ×ÔÆÀ7.5
Ó°Ïì°æ±¾
ATTK 1.62.0.1218 ¼°ÒÔϰ汾¡£¡£¡£¡£¡£¡£
µ¥»ú°æÓ°Ïì ATTK×é¼þ¼°ÆäËü²¿·Ö£¨Èç WCRY²¹¶¡¹¤¾ß¡¢OfficeScanToolbox µÈ£©
Îó²î¸ÅÊö
Ç÷ÊÆ¿Æ¼¼·ÀÍþв¹¤¾ß¼¯£¨Anti-Threat Toolkit£¬£¬£¬£¬£¬¼ò³Æ ATTK£©Öб»ÆØ±£´æÒ»¸öȱÏÝ£¬£¬£¬£¬£¬¿É±»ºÚ¿ÍÓÃÓÚÔÚÊܺ¦Õß Windows ÅÌËã»úÉÏÔËÐжñÒâÈí¼þ¡£¡£¡£¡£¡£¡£
CVE-2019-9491ÓÉHyp3rlinx·¢Ã÷¡£¡£¡£¡£¡£¡£ATTK¿É±»ÓÕÆÖ´ÐÐí§ÒâÈí¼þ£¬£¬£¬£¬£¬°üÀ¨¶ñÒâÈí¼þÔÚÄÚ¡£¡£¡£¡£¡£¡£µ±¶ñÒâÈí¼þ±»É¨Ãèʱ£¬£¬£¬£¬£¬ÈôÊÇÎļþÃûÊÇ cmd.exe »ò regedit.exe£¬£¬£¬£¬£¬ÄÇô¶ñÒâÈí¼þ¾Í»á±»Ö´ÐС£¡£¡£¡£¡£¡£
ÈôÊǶñÒâÈí¼þ×÷ÕßÇ¡ÇÉʹÓÃÁËÒ×Êܹ¥»÷µÄÃüÃûÔ¼¶¨¡®cmd.exe¡¯»ò¡®regedit.exe¡¯£¬£¬£¬£¬£¬ATTK ½«»á¼ÓÔØ²¢Ö´ÐÐí§Òâ .EXE Îļþ¡£¡£¡£¡£¡£¡£µ±ÖÕ¶ËÓû§Æô¶¯É¨Ãèʱ£¬£¬£¬£¬£¬¶ñÒâÈí¼þ¾Í¿É·ÅÔÚ ATTKÖÜΧ¡£¡£¡£¡£¡£¡£
ATTK ¿É±»ÓÕÆÔËÐв¡¶¾¡£¡£¡£¡£¡£¡£ÈôÊÇÄãÄܹ»Í¨¹ýÏÂÔØÆ÷»òÓʼþµÈ·½·¨ÔÚ±ðÈ˵ĵçÄÔÉϽ«ÎļþÉúÑÄΪcmd.exe »ò regedit.exe£¬£¬£¬£¬£¬ÄÇô¹¥»÷Õ߾ͿÉÒÔͨ¹ýÔËÐÐ ATTKÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£
ÓÉÓÚATTK ÊÇÓÉÂÄÀúÖ¤µÄÐû²¼·½ÊðÃûµÄ£¬£¬£¬£¬£¬Òò´ËÈôÊǶñÒâÈí¼þÊÇ´Ó»¥ÁªÍøÉÏÏÂÔØµÄ£¬£¬£¬£¬£¬ÄÇôËü»áÈÆ¹ýÈκοÉÐŵÄMOTWÇå¾²ÖÒÑÔ£¬£¬£¬£¬£¬Í¬Ê±ÓÉÓÚÿ´ÎÔËÐÐ ATTK ʱҲ»áÔËÐжñÒâÈí¼þ£¬£¬£¬£¬£¬Òò´ËËüÒ²³ÉΪһÖÖ³¤ÆÚÐÔ»úÖÆ¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
EXP£º
ͨ¹ýÈçÏ C ´úÂë±àÒëÒ»¸ö .EXE£¬£¬£¬£¬£¬²¢Ê¹Óá°cmd.exe¡±»ò¡°regedit.exe¡±×÷ΪÃüÃûÔ¼¶¨¡£¡£¡£¡£¡£¡£ÔËÐÐ ATTK¹¤¾ß²¢ÊÓ²ì ATTKÃæ°åÒÔÉó²éľÂíÎļþ±»¼ÓÔØÇÒÖ´ÐеÄÀú³Ì¡£¡£¡£¡£¡£¡£
#include <windows.h>
void main(void){
puts("Trend Micro Anti-Threat Toolkit PWNED!");
puts("Discovery: hyp3rlinx");
puts("CVE-2019-9491\n");
WinExec("powershell", 0);
}
PoC ÊÓÆµURL£º
https://www.youtube.com/watch?v=HBrRVe8WCHs
ÐÞ¸´½¨Òé
Ç÷ÊÆ¿Æ¼¼ÏÖÒѽ«ËùÓÐ ATTK¸üÐÂÖÁ 1.62.0.1223°æ±¾¡£¡£¡£¡£¡£¡£µ«ÉÐδÐû²¼Ï¸½Ú¡£¡£¡£¡£¡£¡£
https://success.trendmicro.com/solution/000149878
²Î¿¼Á´½Ó
http://hyp3rlinx.altervista.org/advisories/TREND-MICRO-ANTI-THREAT-TOOLKIT-(ATTK)-REMOTE-CODE-EXECUTION.txt