CVE-2020-17087 | Windows cng.sysȨÏÞÌáÉýÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-11-020x00 Îó²î¸ÅÊö
CNVD ID | CVE-2020-17087 | ʱ ¼ä | 2020-11-02 |
Àà ÐÍ | ȨÏÞÌáÉý | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ·ñ | Ó°Ïì¹æÄ£ | Windows7¡¢Windows10 |
cng.sysÊÇwindowsÖеÄÖ÷ÒªsysÎļþ¡£¡£¡£¡£¡£¡£ÈôÊǸÃÎļþË𻵣¬£¬£¬Ôò»á·ºÆð·¿ªÓ¦ÓóÌÐòʱÌáÐÑȱÉÙsysÎļþ¡¢ÏµÍ³ÔËÐÐÖзºÆðÎļþȱʧµÄÌáÐѵ¯´°¡¢µçÄÔ·ºÆðÀ¶ÆÁµÈ״̬¡£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé

2020Äê10ÔÂ31ÈÕ£¬£¬£¬ÓÉÓÚWinodws cng.sysȨÏÞÌáÉýÎó²î£¨CVE-2020-17087£©Áè¼ÝÁËGoogleÒªÇó΢Èí7ÌìÄÚÐÞ¸´µÄÏÞÆÚ£¬£¬£¬Google Progect ZeroÍŶÓÐû²¼Á˸ÃÎó²îµÄÊÖÒÕϸ½ÚºÍPOC¡£¡£¡£¡£¡£¡£
¸ÃÎó²îÊÇWindows cng.sysÇý¶¯ÖеĻº³åÇøÒç³öÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÓû§¶Ëͨ¹ýIOCTL 0x390400·¢ËͶÔÓ¦µÄ»ûÐÎÊý¾Ý£¬£¬£¬´Ó¶øÔì³ÉÒç³ö¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔͨ¹ýÓÕʹÓû§·¿ª¶ñÒâµÄÎļþ»òÍøÂç×ÊÔ´£¬£¬£¬ÔÙÁ¬ÏµÆäËüÎó²î£¨ÈçChrome 0dayÎó²î£©´ÓͨË×Óû§È¨ÏÞÌáÉýµ½ÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£¡£
ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬½üÆÚÅû¶µÄÒ»¸öChrome 0dayÎó²î£¨CVE-2020-15999£©¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇChrome FreeType×ÖÌåäÖȾʱµÄÒ»´¦ÄÚ´æÆÆËðÎó²î£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬£¬ÓÕʹÓû§µã»÷£¬£¬£¬×îÖÕ¿ÉÔì³É¾Ü¾øÐ§À͹¥»÷»òÔÚÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃÎó²îÒѾÔÚ86.0.4240.111°æ±¾ÖÐÐÞ¸´¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
΢ÈíÔ¤¼Æ½«ÔÚ2020Äê11ÔÂ10ÈÕÐû²¼¸ÃÎó²îµÄ²¹¶¡¡£¡£¡£¡£¡£¡£ÓÉÓÚ¸ÃÎó²îÏÖÔÚ´¦ÓÚ0day¿ÉʹÓÃ״̬£¬£¬£¬ÇÒÒÑÈ·Èϱ£´æÏà¹ØµÄÔÚÒ°¹¥»÷°¸Àý¡£¡£¡£¡£¡£¡£Çå¾²Íþвˮƽ½Ï¸ß£¬£¬£¬½¨ÒéÌá·ÀÏà¹ØÒÑÖªÎó²î£¬£¬£¬²¢ÆÚ´ý¹Ù·½²¹¶¡¡£¡£¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://bugs.chromium.org/p/project-zero/issues/detail?id=2104
https://www.theregister.com/2020/10/30/windows_kernel_zeroday/
https://securityaffairs.co/wordpress/110193/hacking/google-discloses-windows-zero-day.html?
0x04 ʱ¼äÏß
2020-10-31 Google Project ZeroÐû²¼Í¨¸æ
2020-11-02 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ