CVE-2020-17087 | Windows cng.sysȨÏÞÌáÉýÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-11-020x00 Îó²î¸ÅÊö
CNVD ID | CVE-2020-17087 | ʱ ¼ä | 2020-11-02 |
Àà ÐÍ | ȨÏÞÌáÉý | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ·ñ | Ó°Ïì¹æÄ£ | Windows7¡¢Windows10 |
cng.sysÊÇwindowsÖеÄÖ÷ÒªsysÎļþ¡£¡£¡£ÈôÊǸÃÎļþË𻵣¬£¬£¬Ôò»á·ºÆð·¿ªÓ¦ÓóÌÐòʱÌáÐÑȱÉÙsysÎļþ¡¢ÏµÍ³ÔËÐÐÖзºÆðÎļþȱʧµÄÌáÐѵ¯´°¡¢µçÄÔ·ºÆðÀ¶ÆÁµÈ״̬¡£¡£¡£
0x01 Îó²îÏêÇé
2020Äê10ÔÂ31ÈÕ£¬£¬£¬ÓÉÓÚWinodws cng.sysȨÏÞÌáÉýÎó²î£¨CVE-2020-17087£©Áè¼ÝÁËGoogleÒªÇó΢Èí7ÌìÄÚÐÞ¸´µÄÏÞÆÚ£¬£¬£¬Google Progect ZeroÍŶÓÐû²¼Á˸ÃÎó²îµÄÊÖÒÕϸ½ÚºÍPOC¡£¡£¡£
¸ÃÎó²îÊÇWindows cng.sysÇý¶¯ÖеĻº³åÇøÒç³öÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÓû§¶Ëͨ¹ýIOCTL 0x390400·¢ËͶÔÓ¦µÄ»ûÐÎÊý¾Ý£¬£¬£¬´Ó¶øÔì³ÉÒç³ö¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔͨ¹ýÓÕʹÓû§·¿ª¶ñÒâµÄÎļþ»òÍøÂç×ÊÔ´£¬£¬£¬ÔÙÁ¬ÏµÆäËüÎó²î£¨ÈçChrome 0dayÎó²î£©´ÓͨË×Óû§È¨ÏÞÌáÉýµ½ÖÎÀíԱȨÏÞ¡£¡£¡£
ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬½üÆÚÅû¶µÄÒ»¸öChrome 0dayÎó²î£¨CVE-2020-15999£©¡£¡£¡£¸ÃÎó²îÊÇChrome FreeType×ÖÌåäÖȾʱµÄÒ»´¦ÄÚ´æÆÆËðÎó²î£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬£¬ÓÕʹÓû§µã»÷£¬£¬£¬×îÖÕ¿ÉÔì³É¾Ü¾øÐ§À͹¥»÷»òÔÚÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ÏÖÔÚ¸ÃÎó²îÒѾÔÚ86.0.4240.111°æ±¾ÖÐÐÞ¸´¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
΢ÈíÔ¤¼Æ½«ÔÚ2020Äê11ÔÂ10ÈÕÐû²¼¸ÃÎó²îµÄ²¹¶¡¡£¡£¡£ÓÉÓÚ¸ÃÎó²îÏÖÔÚ´¦ÓÚ0day¿ÉʹÓÃ״̬£¬£¬£¬ÇÒÒÑÈ·Èϱ£´æÏà¹ØµÄÔÚÒ°¹¥»÷°¸Àý¡£¡£¡£Çå¾²Íþвˮƽ½Ï¸ß£¬£¬£¬½¨ÒéÌá·ÀÏà¹ØÒÑÖªÎó²î£¬£¬£¬²¢ÆÚ´ý¹Ù·½²¹¶¡¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://bugs.chromium.org/p/project-zero/issues/detail?id=2104
https://www.theregister.com/2020/10/30/windows_kernel_zeroday/
https://securityaffairs.co/wordpress/110193/hacking/google-discloses-windows-zero-day.html?
0x04 ʱ¼äÏß
2020-10-31 Google Project ZeroÐû²¼Í¨¸æ
2020-11-02 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/