Windows Print SpoolerÔ¶³Ì´úÂëÖ´ÐÐ0 dayÎó²î£¨CVE-2021-34527£©

Ðû²¼Ê±¼ä 2021-07-02

0x00 Îó²î¸ÅÊö

CVE     ID

CVE-2021-34527

ʱ      ¼ä

2021-07-02

Àà       ÐÍ

RCE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

  ËùÓÐWindows°æ±¾

¹¥»÷ÖØÆ¯ºó

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

ÊÇ

 

0x01 Îó²îÏêÇé

image.png

 

Windows Print SpoolerÊÇWindowsµÄ´òÓ¡»úºǫ́´¦Öóͷ£³ÌÐò£¬£¬£¬ £¬£¬£¬ÆäÖÎÀíËùÓÐÍâµØºÍÍøÂç´òÓ¡ÐÐÁв¢¿ØÖÆËùÓдòÓ¡ÊÂÇ飬£¬£¬ £¬£¬£¬±»ÆÕ±éÓ¦ÓÃÓÚÍâµØºÍÄÚÍøÖС£¡£¡£¡£¡£¡£ ¡£

2021Äê6ÔÂ29ÈÕ£¬£¬£¬ £¬£¬£¬Çå¾²Ñо¿Ö°Ô±ÔÚGitHubÉϹûÕæÁËÒ»¸öWindows Print SpoolerÔ¶³Ì´úÂëÖ´ÐÐ0dayÎó²î£¨CVE-2021-34527£©¡£¡£¡£¡£¡£¡£ ¡£

ÐèÒª×¢ÖØµÄÊÇ£¬£¬£¬ £¬£¬£¬¸ÃÎó²î£¨CVE-2021-34527£©ÓëMicrosoft 6ÔÂ8ÈÕÐÇÆÚ¶þ²¹¶¡ÈÕÖÐÐÞ¸´²¢ÓÚ6ÔÂ21ÈÕ¸üеÄÒ»¸öEoPÉý¼¶µ½RCEµÄÎó²î£¨CVE-2021-1675£©²»ÊÇͳһ¸öÎó²î¡£¡£¡£¡£¡£¡£ ¡£ÕâÁ½¸öÎó²îÏàËÆµ«²î±ð£¬£¬£¬ £¬£¬£¬¹¥»÷ÏòÁ¿Ò²²î±ð¡£¡£¡£¡£¡£¡£ ¡£

ÏÖÔÚ¸ÃÎó²îÒѾ­¹ûÕæÅû¶£¬£¬£¬ £¬£¬£¬²¢ÇÒÒÑ·ºÆðÔÚҰʹÓᣡ£¡£¡£¡£¡£ ¡£µ± Windows Print Spooler ЧÀͲ»×¼È·µØÖ´ÐÐÌØÈ¨Îļþ²Ù×÷ʱ£¬£¬£¬ £¬£¬£¬±£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¡£¡£¡£¡£¡£ ¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓà SYSTEM ȨÏÞÔËÐÐí§Òâ´úÂë¡¢×°ÖóÌÐò¡¢Éó²é²¢¸ü¸Ä»òɾ³ýÊý¾Ý¡¢»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§£¬£¬£¬ £¬£¬£¬µ«¹¥»÷±ØÐèÉæ¼°Å²Óà RpcAddPrinterDriverEx() µÄ¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§¡£¡£¡£¡£¡£¡£ ¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ¸ÃÎó²îÉÐδÐÞ¸´¡£¡£¡£¡£¡£¡£ ¡£

½¨Òé×èÖ¹²¢½ûÓÃWindows Print SpoolerЧÀÍ¡£¡£¡£¡£¡£¡£ ¡£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527

 

0x03 ²Î¿¼Á´½Ó

https://github.com/afwu/PrintNightmare

https://www.bleepingcomputer.com/news/security/public-windows-printnightmare-0-day-exploit-allows-domain-takeover/

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527

 

0x04 ʱ¼äÏß

2021-07-01  MicrosoftÐû²¼Ç徲ͨ¸æ

2021-07-02  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png