Win10´æÔÚ±¾µØÌáȨ0day·ì϶

°ä²¼¹¦·ò 2018-08-30
Ò»¡¢·ìϼûèÊö


        2018Äê8ÔÂ27ÈÕ£¬£¬ £¬£¬£¬°²È«×êÑÐÈËÔ±ÔÚTwitterÉÏÅû¶ÁËWindows 10ϵͳÖеÄÒ»¸ö0day·ì϶ ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÒ»¸ö±¾µØÌáȨ·ì϶£¬£¬ £¬£¬£¬´æÔÚÓÚWindowsµÄ¹¤×÷µ÷¶È·þÎñÖУ¬£¬ £¬£¬£¬ÔÊÐí¹¥»÷Õß´ÓUSERȨÏÞÌáȨµ½SYSTEMȨÏÞ ¡£¡£¡£¡£¡£¡£¡£Î¢Èí¹Ù·½Ä¿Ç°»¹Ã»ÓÐÌṩÏàÓ¦µÄ²¹¶¡ ¡£¡£¡£¡£¡£¡£¡£


¶þ¡¢·ì϶ӰÏìÁìÓò


        Windows 10


        Windows Server 2016


Èý¡¢·ì϶·ÖÎö


        Microsoft WindowsϵͳµÄ¹¤×÷µ÷¶È·þÎñÖи߼¶±¾µØ¹ý³ÌŲÓã¨ALPC£©½Ó¿Ú´æÔÚ±¾µØÌáȨ·ì϶£¬£¬ £¬£¬£¬¸Ã·ì϶´æÔÚÓÚschedsvc.dllÄ£¿£¿ £¿£¿£¿éÖеÄSchRpcSetSecurityº¯Êý£¬£¬ £¬£¬£¬SchRpcSetSecurityº¯Êý½ç˵ÈçÏ£¬£¬ £¬£¬£¬º¯ÊýÖ°ÄÜÊÇÉèÖð²È«ÃèÊö·û ¡£¡£¡£¡£¡£¡£¡£


 HRESULT SchRpcSetSecurity(


   [in, string] const wchar_t* path,


   [in, string] const wchar_t* sddl,


   [in] DWORD flags


 );


        SchRpcSetSecurityµÚÒ»¸ö²ÎÊýΪõè¾¶path£¬£¬ £¬£¬£¬µÚ¶þ¸ö²ÎÊýΪ°²È«ÃèÊö·û½ç˵˵»° (SDDL) ×Ö·û´®sddl£¬£¬ £¬£¬£¬¸Ãº¯ÊýÄÚ²¿Å²ÓÃÁËSetSecurity::RpcServerº¯Êý ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



        SetSecurity::RpcServerº¯ÊýÊ×ÏÈŲÓÃConvertStringSecurityDescriptorToSecurityDescriptor ½«SchRpcSetSecurityº¯Êý´«ÈëµÄsddl×Ö·û´®×ª»»Îª°²È«ÃèÊö·ûSecurityDescriptor ¡£¡£¡£¡£¡£¡£¡£²¢Å²ÓÃTaskPathCanonicalizeº¯Êý¶Ô´«Èëpath²ÎÊýõè¾¶¹æ·¶»¯ÎªDst ¡£¡£¡£¡£¡£¡£¡£



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


        ¶øºó»ñÈ¡Dstõè¾¶µÄJobSecurity°²È«ÃèÊö·ûpSecurityDescriptor£¬£¬ £¬£¬£¬¼Ì¶øÅ²ÓÃJobSecurity::Updateº¯Êý£¬£¬ £¬£¬£¬´«ÈëSecurityDescriptor²ÎÊý£¬£¬ £¬£¬£¬¸üÐÂpSecurityDescriptor ¡£¡£¡£¡£¡£¡£¡£



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


        ×îºó£¬£¬ £¬£¬£¬Å²ÓÃJobSecurity::AddRemovePrincipalAceº¯ÊýÉèÖÃDACL ¡£¡£¡£¡£¡£¡£¡£



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


        ÄÇôÈôºÎÅú¸ÄÖ¸¶¨Ö¸±êÎļþµÄDACLÊôÐÔÄØ£¿£¿ £¿£¿£¿Ê×ÏÈ£¬£¬ £¬£¬£¬Ê¹ÓÃZwSetInformationFileº¯ÊýΪָ±êÎļþ´´½¨Ó²Á´½Ó ¡£¡£¡£¡£¡£¡£¡£¶øºó£¬£¬ £¬£¬£¬Å²ÓÃ_SchRpcSetSecurityº¯ÊýÉèÖÃÓ²Á´½ÓÎļþµÄDACL£¬£¬ £¬£¬£¬µÈͬÓÚÅú¸ÄÖ¸±êÎļþµÄDACL ¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÉèÖÃSchRpcSetSecurityµÄµÚ3¸ö²ÎÊý£¬£¬ £¬£¬£¬¿ÉÒÔΪÓû§Administrators(BA)¡¢Authenticated Users£¨AU£©Ôö³¤¶ÔÓ²Á´½ÓÎļþµÄдÈëȨÏÞ ¡£¡£¡£¡£¡£¡£¡£


        ÒÔPrintConfig.dllÎļþΪÀý£¬£¬ £¬£¬£¬Å²ÓÃSchRpcSetSecurityº¯Êýǰ£¬£¬ £¬£¬£¬Îļþ½Ó¼ûȨÏÞÈçÏ£¬£¬ £¬£¬£¬´ËʱAdministrators²»ÓµÓжÔÎļþµÄдÈëȨÏÞ ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



        ŲÓÃSchRpcSetSecurityº¯Êýºó£¬£¬ £¬£¬£¬ÎļþµÄȨÏÞÈçÏ£¬£¬ £¬£¬£¬´ËʱAdministratorsºÍAuthenticated Users¶¼Õ¼ÓжÔÎļþдÈëȨÏÞ ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



        ÓÉÓÚSchRpcSetSecurityº¯Êý´æÔÚ°²È«Ñé֤ȱµã£¬£¬ £¬£¬£¬Ê¹Çе±Ç°Óû§¿ÉÅú¸ÄÖ»¶ÁÎļþµÄDACL£¬£¬ £¬£¬£¬Ôö³¤Ð´ÈëȨÏÞ ¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓø÷ì϶µÄÁ˾ÖÈçÏÂͼ ¡£¡£¡£¡£¡£¡£¡£



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ËÄ¡¢°²È«½¨Òé


        ²»ÒªÔËÐÐδ֪ÆðÔ´µÄ·¨Ê½ £»£»£»£»£»


?     ÔÚ΢Èí¸üв¹¶¡ºó£¬£¬ £¬£¬£¬ÊµÊ±×°Öò¹¶¡ ¡£¡£¡£¡£¡£¡£¡£


Îå¡¢²Î¿¼Á´½Ó


https://thehackernews.com/2018/08/windows-zero-day-exploit.html


https://www.kb.cert.org/vuls/id/906424