CVE-2020-17087 | Windows cng.sysȨÏÞÌáÉýÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-11-02

0x00 Îó²î¸ÅÊö

CNVD   ID

CVE-2020-17087

ʱ      ¼ä

2020-11-02

Àà    ÐÍ

ȨÏÞÌáÉý

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

·ñ

Ó°Ïì¹æÄ£

Windows7¡¢Windows10

 

cng.sysÊÇwindowsÖеÄÖ÷ÒªsysÎļþ¡£¡£¡£ÈôÊǸÃÎļþË𻵣¬£¬£¬Ôò»á·ºÆð·­¿ªÓ¦ÓóÌÐòʱÌáÐÑȱÉÙsysÎļþ¡¢ÏµÍ³ÔËÐÐÖзºÆðÎļþȱʧµÄÌáÐѵ¯´°¡¢µçÄÔ·ºÆðÀ¶ÆÁµÈ״̬¡£¡£¡£

0x01 Îó²îÏêÇé

 

image.png


2020Äê10ÔÂ31ÈÕ£¬£¬£¬ÓÉÓÚWinodws cng.sysȨÏÞÌáÉýÎó²î£¨CVE-2020-17087£©Áè¼ÝÁËGoogleÒªÇó΢Èí7ÌìÄÚÐÞ¸´µÄÏÞÆÚ£¬£¬£¬Google Progect ZeroÍŶÓÐû²¼Á˸ÃÎó²îµÄÊÖÒÕϸ½ÚºÍPOC¡£¡£¡£

¸ÃÎó²îÊÇWindows cng.sysÇý¶¯ÖеĻº³åÇøÒç³öÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÓû§¶Ëͨ¹ýIOCTL 0x390400·¢ËͶÔÓ¦µÄ»ûÐÎÊý¾Ý£¬£¬£¬´Ó¶øÔì³ÉÒç³ö¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔͨ¹ýÓÕʹÓû§·­¿ª¶ñÒâµÄÎļþ»òÍøÂç×ÊÔ´£¬£¬£¬ÔÙÁ¬ÏµÆäËüÎó²î£¨ÈçChrome 0dayÎó²î£©´ÓͨË×Óû§È¨ÏÞÌáÉýµ½ÖÎÀíԱȨÏÞ¡£¡£¡£

ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬½üÆÚÅû¶µÄÒ»¸öChrome 0dayÎó²î£¨CVE-2020-15999£©¡£¡£¡£¸ÃÎó²îÊÇChrome FreeType×ÖÌåäÖȾʱµÄÒ»´¦ÄÚ´æÆÆËðÎó²î£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬£¬ÓÕʹÓû§µã»÷£¬£¬£¬×îÖÕ¿ÉÔì³É¾Ü¾øÐ§À͹¥»÷»òÔÚÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ÏÖÔÚ¸ÃÎó²îÒѾ­ÔÚ86.0.4240.111°æ±¾ÖÐÐÞ¸´¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

΢ÈíÔ¤¼Æ½«ÔÚ2020Äê11ÔÂ10ÈÕÐû²¼¸ÃÎó²îµÄ²¹¶¡¡£¡£¡£ÓÉÓÚ¸ÃÎó²îÏÖÔÚ´¦ÓÚ0day¿ÉʹÓÃ״̬£¬£¬£¬ÇÒÒÑÈ·Èϱ£´æÏà¹ØµÄÔÚÒ°¹¥»÷°¸Àý¡£¡£¡£Çå¾²Íþвˮƽ½Ï¸ß£¬£¬£¬½¨ÒéÌá·ÀÏà¹ØÒÑÖªÎó²î£¬£¬£¬²¢ÆÚ´ý¹Ù·½²¹¶¡¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://bugs.chromium.org/p/project-zero/issues/detail?id=2104

https://www.theregister.com/2020/10/30/windows_kernel_zeroday/

https://securityaffairs.co/wordpress/110193/hacking/google-discloses-windows-zero-day.html?

 

0x04 ʱ¼äÏß

2020-10-31  Google Project ZeroÐû²¼Í¨¸æ

2020-11-02  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

 



image.png