Ç÷Ïò¿Æ¼¼·ÀÍþв¹¤¾ß°üÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-10-23·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-9491£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨£¬£¬£¬£¬£¬£¬£¬³§ÉÌ×ÔÆÀ7.5
Ó°Ïì°æ±¾
ATTK 1.62.0.1218 ¼°ÒÔϰ汾¡£¡£¡£¡£¡£
µ¥»ú°æÓ°Ïì ATTK×é¼þ¼°ÆäËü²¿ÃÅ£¨Èç WCRY²¹¶¡¹¤¾ß¡¢OfficeScanToolbox µÈ£©
·ì϶¸ÅÊö
Ç÷Ïò¿Æ¼¼·ÀÍþв¹¤¾ß¼¯£¨Anti-Threat Toolkit£¬£¬£¬£¬£¬£¬£¬¼ò³Æ ATTK£©Öб»ÆØ´æÔÚÒ»¸öȱµã£¬£¬£¬£¬£¬£¬£¬¿É±»ºÚ¿ÍÓÃÓÚÔÚÊܺ¦Õß Windows ÍÆËã»úÉÏÔËÐжñÒâÈí¼þ¡£¡£¡£¡£¡£
CVE-2019-9491ÓÉHyp3rlinx·¢ÏÖ¡£¡£¡£¡£¡£ATTK¿É±»ÓÕÆÖ´ÐÐËÁÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬Ô̺¬¶ñÒâÈí¼þÔÚÄÚ¡£¡£¡£¡£¡£µ±¶ñÒâÈí¼þ±»É¨Ãèʱ£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÎļþÃûÊÇ cmd.exe »ò regedit.exe£¬£¬£¬£¬£¬£¬£¬ÄÇô¶ñÒâÈí¼þ¾Í»á±»Ö´ÐС£¡£¡£¡£¡£
ÈôÊǶñÒâÈí¼þ×÷ÕßÇ¡ÇÉʹÓÃÁËÒ×Êܹ¥»÷µÄ¶¨ÃûÔ¼¶¨¡®cmd.exe¡¯»ò¡®regedit.exe¡¯£¬£¬£¬£¬£¬£¬£¬ATTK ½«»á¼ÓÔØ²¢Ö´ÐÐËÁÒâ .EXE Îļþ¡£¡£¡£¡£¡£µ±ÖÕ¶ËÓû§Æô¶¯É¨Ãèʱ£¬£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ¾Í¿É·ÅÔÚ ATTK×ó½ü¡£¡£¡£¡£¡£
ATTK ¿É±»ÓÕÆÔËÐв¡¶¾¡£¡£¡£¡£¡£ÈôÊÇÄã¿ÉÄÜͨ¹ýÏÂÔØÆ÷»òÓʼþµÈ·½Ê½ÔÚ±ðÈ˵ĵçÄÔ´ó½«Îļþ±£ÁôΪcmd.exe »ò regedit.exe£¬£¬£¬£¬£¬£¬£¬ÄÇô¹¥»÷Õß¾ÍÄܹ»Í¨¹ýÔËÐÐ ATTKÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£
ÓÉÓÚATTK ÊÇÓɾÑéÖ¤µÄ°ä²¼·½ÊðÃûµÄ£¬£¬£¬£¬£¬£¬£¬Òò¶øÈôÊǶñÒâÈí¼þÊÇ´Ó»¥ÁªÍø¸ßµÍÔØµÄ£¬£¬£¬£¬£¬£¬£¬ÄÇôËü»áÈÆ¹ýÈκοÉÐŵÄMOTW°²È«ÖҸ棬£¬£¬£¬£¬£¬£¬Í¬Ê±ÓÉÓÚÿ´ÎÔËÐÐ ATTK ʱҲ»áÔËÐжñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬Òò¶øËüÒ²³ÉΪһÖÖÓÆ¾ÃÐÔ»úÔì¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
EXP£º
ͨ¹ýÈçÏ C ´úÂë±àÒëÒ»¸ö .EXE£¬£¬£¬£¬£¬£¬£¬²¢Ê¹Óá°cmd.exe¡±»ò¡°regedit.exe¡±×÷Ϊ¶¨ÃûÔ¼¶¨¡£¡£¡£¡£¡£ÔËÐÐ ATTK¹¤¾ß²¢¹Û²ì ATTKÃæ°åÒԲ鿴ľÂíÎļþ±»¼ÓÔØÇÒÖ´ÐеĹý³Ì¡£¡£¡£¡£¡£
#include <windows.h>
void main(void){
puts("Trend Micro Anti-Threat Toolkit PWNED!");
puts("Discovery: hyp3rlinx");
puts("CVE-2019-9491\n");
WinExec("powershell", 0);
}
PoC ÊÓÆµURL£º
https://www.youtube.com/watch?v=HBrRVe8WCHs
½¨¸´½¨Òé
Ç÷Ïò¿Æ¼¼ÏÖÒѽ«ËùÓÐ ATTK¸üÐÂÖÁ 1.62.0.1223°æ±¾¡£¡£¡£¡£¡£µ«ÉÐδ°ä²¼Ï¸½Ú¡£¡£¡£¡£¡£
https://success.trendmicro.com/solution/000149878
²Î¿¼Á´½Ó
http://hyp3rlinx.altervista.org/advisories/TREND-MICRO-ANTI-THREAT-TOOLKIT-(ATTK)-REMOTE-CODE-EXECUTION.txt


¾©¹«Íø°²±¸11010802024551ºÅ