Win10±¾µØÌáȨ0day·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-08-29

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÎÞ£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ß£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Windows 10 32/64λ²Ù×÷ϵͳ


·ì϶¸ÅÊö


2018Äê8ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬°²È«×êÑÐÈËÔ±ÔÚgithubÉϰ䲼ÁË×îеÄwin10x64°æµÄ±¾µØÌáȨ·ì϶£¬£¬£¬£¬£¬£¬²¢ÇÒÔÚÍÆÌØÉÏ¶ÔÆäÌáȨµÄdemo½øÐÐÁËÑÝʾ¡£¡£¡£ ¡£¡£¡£¡£¡£ÔÚgithubÉϵÄSandboxEscaperÉÏÓÐ×ÅÆëÈ«µÄ·ì϶ÀûÓ÷¨Ê½ÒÔ¼°demo£¬£¬£¬£¬£¬£¬²¢ÇÒ±»ÆäËû°²È«×êÑÐר¼Ò֤ʵ¸Ã·ì϶Äܹ»ÔÚ×î½üµÄwin10Éϸ´ÏÖ¡£¡£¡£ ¡£¡£¡£¡£¡£


¸Ã·ì϶µÄÔ­ÒòÔÚÓÚwin10ϵͳµÄ¹¤×÷µ÷¶È·þÎñÖÐÓÐalpcµÄŲÓýӿڣ¬£¬£¬£¬£¬£¬¸Ã½Ó¿Úµ¼³öÁËSchRpcSetSecurityº¯Êý£¬£¬£¬£¬£¬£¬¸Ãº¯ÊýÕýÊDZ¾´Î·ì϶ÀûÓõ½µÄº¯Êý¡£¡£¡£ ¡£¡£¡£¡£¡£¸Ãº¯ÊýµÄÔ­ÐÍÈçÏ£º


long _SchRpcSetSecurity(
[in][string] wchar_t* arg_1, //Task name
[in][string] wchar_t* arg_2, //Security Descriptor string

[in]long arg_3);


µ±ËÁÒâȨÏÞµÄÓû§Å²Óøú¯Êýʱ£¬£¬£¬£¬£¬£¬¸Ãº¯Êý»á¼ì²â c:\windows\tasksĿ¼ÏÂÊÇ·ñ´æÔÚÒ»¸öºó׺ΪjobµÄÎļþ£¬£¬£¬£¬£¬£¬ÈôÊǸÃÎļþ´æÔÚ»áÏò¸ÃÎļþдÈëÖ¸¶¨µÄDACLÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£¡£±¾´Î·ì϶ÀûÓõķ½Ê½¼´Í¨¹ýÓ²Á´½ÓµÄ·½Ê½½«¸ÃjobÎļþÖ¸¶¨Á´½Óµ½Ìض¨µÄdllÉÏ£¬£¬£¬£¬£¬£¬ÕâÑùµ±Óû§Å²Óøú¯Êýʱ»áÏòÌØ¶¨µÄdllдÈëÊý¾Ý£¬£¬£¬£¬£¬£¬¶øÌض¨µÄdllÍùÍùÊÇϵͳ¼¶´ËÍâdll¡£¡£¡£ ¡£¡£¡£¡£¡£ÔÚgithubÉϰ䲼µÄ·ì϶ÀûÓ÷¨Ê½Ôò»áÏòprintconfig.dllдÈëÌáȨ´úÂ룬£¬£¬£¬£¬£¬²¢Í¨¹ýÆô¶¯´òÓ¡·þÎñspoolsv.exeÀ´Ö´ÐÐÌáȨ´úÂ룬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖÄÚºËÌáȨ¡£¡£¡£ ¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


±¾´Î¸´ÏÖʹÓÃÁËwin10x64°æ£¬£¬£¬£¬£¬£¬Ê×ÏÈʹÓÃgithubÉÏÌṩµÄ·ì϶ÀûÓù¤¾ß£¬£¬£¬£¬£¬£¬²é¿´Æä¾ßÌåÓ÷¨¡£¡£¡£ ¡£¡£¡£¡£¡£¸Ã·ì϶ÀûÓù¤¾ßµÄÖØÒª·½Ê½ÊÇͨ¹ýdll×¢ÈëµÄ·½Ê½ÏòµÍȨÏ޵Ĺý³Ì×¢ÈëÄܹ»ÊµÏÖÕûÌ×ÌáȨ¹¥»÷µÄshellcode¡£¡£¡£ ¡£¡£¡£¡£¡£

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ËæºóÀûÓÃieä¯ÀÀÆ÷½øÐвâÊÔʱ·¢ÏÖÎÞ·¨ÀûÓóɹ¦£¬£¬£¬£¬£¬£¬¹ÌÈ»·ì϶ÀûÓõÄdllÒѾ­±»Ð´Èëµ½spoolsv.exeÖУ¬£¬£¬£¬£¬£¬µ«È´Ã»ÓÐʵÏÖ·ìÏ¶ÕæÕýµÄ³ÉЧ¡£¡£¡£ ¡£¡£¡£¡£¡£½ÓÏÂÀ´ÒÀÕÕÑÝʾdemoÖеIJÙ×÷£¬£¬£¬£¬£¬£¬´ò¿ªÒ»¸önotepad·¨Ê½£¬£¬£¬£¬£¬£¬²¢¶Ônotepad·¨Ê½½øÐÐ×¢Èë¡£¡£¡£ ¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ëæºó²é¿´spoolsv.exeϵÄËùÓÐ×Ó¹ý³Ì£¬£¬£¬£¬£¬£¬·¢ÏÖ¸Ãnotepad.exe·¨Ê½±»spoolsv.exe·¨Ê½³Áдò¿ª£¬£¬£¬£¬£¬£¬ºÍgithubÉϵķì϶ÀûÓõÄdemoÖеijÉЧһÖ£¬£¬£¬£¬£¬£¬Äܹ»È·¶¨·ì϶ÀûÓóɹ¦¡£¡£¡£ ¡£¡£¡£¡£¡£

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


½ÓÏÂÀ´²é¿´spoolsv.exeÖеĵÚÈý·½¶¯Ì¬¿â£¬£¬£¬£¬£¬£¬Äܹ»¿´µ½ÎÒÃÇÀûÓ÷ì϶ËùÅú¸ÄµÄdll

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¶ø¸ÃdllµÄÅú¸Ä¹¦·òÒ²ÏÔʾÊǸոշì϶ÀûÓõŦ·ò£¬£¬£¬£¬£¬£¬ÖÁ´Ë·ì϶¸´Ïֳɹ¦¡£¡£¡£ ¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website 

Poc£ºhttps://github.com/SandboxEscaper/randomrepo


½¨¸´½¨Òé


³§ÉÌÉÐδ°ä²¼Óйز¹¶¡£¡£¡£ ¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬ÉóÉ÷Ö´ÐÐδ¾­ÉóºËÆðÔ´¶ÔµÄ·¨Ê½¡£¡£¡£ ¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://thehackernews.com/2018/08/windows-zero-day-exploit.html
https://github.com/SandboxEscaper/randomrepo