Windows Installer×é¼þ0day·ì϶
°ä²¼¹¦·ò 2021-02-010x00 ·ì϶¸ÅÊö
CVE ID | ʱ ¼ä | 2021-02-01 | |
Àà ÐÍ | ȨÏÞÌáÉý | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ·ñ | Ó°ÏìÁìÓò | Windows 7- Windows 10 |
0x01 ·ì϶ÏêÇé

¼òÊö
Windows InstallerÊÇWindowsÖеÄÒ»¸ö×é¼þ£¬£¬£¬£¬£¬ËüÊÇרÃÅÓÃÀ´ÖÎÀíºÍÅäÖÃÈí¼þ·þÎñµÄ¹¤¾ß¡£¡£¡£¡£¡£
2020Äê10Ô£¬£¬£¬£¬£¬Microsoft½¨¸´ÁËWindows Installer×é¼þÖеÄÒ»¸ö·ì϶£¨CVE-2020-16902£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¡£¸Ã·ìÏ¶Ôø±»ÂŴν¨¸´¡¢Èƹý£¬£¬£¬£¬£¬º¹Çà×·×ÙΪCVE-2019-1415¡¢CVE-2020-1302ºÍCVE-2020-0814£©£¬£¬£¬£¬£¬µ«¸Ã·ì϶µÄ½¨¸´·¨Ê½ÈԿɱ»Èƹý¡£¡£¡£¡£¡£12ÔÂÏÂÑ®£¬£¬£¬£¬£¬¸Ã·ì϶µÄPoC±»¹«¿ª¡£¡£¡£¡£¡£MicrosoftÒ»ÏòûÓÐÆëÈ«½¨¸´´Ë·ì϶¡£¡£¡£¡£¡£
½üÈÕ£¬£¬£¬£¬£¬MicrosoftÂŴγ¢ÊÔ½¨¸´µÄWindows Installer×é¼þ·ì϶£¨CVE-2020-16902²¹¶¡µÄÈÆ¹ý£© »ñµÃÁËÒ»¸öһʱ²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬¸Ã²¹¶¡¿ÉÄÜÔ¤·À¹¥»÷ÕßÀûÓ÷ì϶»ñȡָ±êϵͳµÄ×î¸ßȨÏÞ¡£¡£¡£¡£¡£
·ì϶·ÖÎö
ÔÚ×°ÖÃMSIÈí¼þ°üµÄ¹ý³ÌÖУ¬£¬£¬£¬£¬Windows Installer»áͨ¹ý¡° msiexec.exe¡±´´½¨»Ø¹ö¾ç±¾£¬£¬£¬£¬£¬ÒÔ±ãÔÚ¹ý³ÌÖгöÏÖÃýÎóʱ»¹ÔËùÓиü¸Ä¡£¡£¡£¡£¡£
ÓµÓб¾µØÈ¨Ï޵Ĺ¥»÷ÕßÈôÊÇÄܹ»ÓÃÒ»¸öŤתע²á±íÖ·´Ö¸ÏòËûÃǵÄPayloadµÄ½ÅÕý±¾´úÌæ»Ø¹ö¾ç±¾£¬£¬£¬£¬£¬ÔòÄܹ»ÔËÐÐÓµÓÐSYSTEMȨÏ޵ĿÉÖ´ÐÐÎļþ¡£¡£¡£¡£¡£
·ì϶¸´ÏÖ
¸Ã·ì϶µÄPoCÖÐʹÓõÄÊǻعö¾ç±¾£¬£¬£¬£¬£¬Ëü½«HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/services/Fax/ImagePathµÄÖµ¸ü¸ÄΪc:\Windows/tempasmae.exe£¬£¬£¬£¬£¬µ¼Ö´«Õæ·þÎñÆô¶¯Ê±Ê¹Óù¥»÷ÕßµÄasmae.exe¡£¡£¡£¡£¡£Ö®ËùÒÔʹÓø÷þÎñ£¬£¬£¬£¬£¬ÊÇÓÉÓÚÈκÎÓû§¶¼Äܹ»Æô¶¯¸Ã·þÎñ£¬£¬£¬£¬£¬²¢ÇҸ÷þÎñÒÔ±¾µØÏµÍ³µÄÉí·ÝÔËÐС£¡£¡£¡£¡£
¸Ã·ì϶µÄ΢²¹¶¡·¨Ê½Í¨¹ý×èÖ¹±¾µØ·ÇÖÎÀíÔ±Óû§Åú¸ÄÖ¸Ïò´«Õæ·þÎñ¿ÉÖ´ÐÐÎļþµÄ×¢²á±íÖ·´Ô¤·À¹¥»÷ÕßÔËÐдúÂë¡£¡£¡£¡£¡£PoC¸´ÏÖÈçÏ£º

0PatchµÄһʱ²¹¶¡ºÏÓÃÓÚÒÔÏÂϵͳ£º
Windows 10 v20H2 32/64룬£¬£¬£¬£¬ÒÑÓÚ2021Äê1Ô¸üÐÂ
Windows 10 v2004 32/64룬£¬£¬£¬£¬ÓÚ2021Äê1Ô¸üÐÂ
Windows 10 v1909 32/64룬£¬£¬£¬£¬ÒÑÓÚ2021Äê1Ô¸üÐÂ
Windows 7¡¢32/64λºÍESU£¬£¬£¬£¬£¬ÓÚ2021Äê1Ô¸üÐÂ
Windows 7¡¢32/64루²»´øESU£©£¬£¬£¬£¬£¬ÒÑÓÚ2020Äê1Ô¸üÐÂ
0x02 ´ëÖý¨Òé
ÔÚMicrosoft°ä²¼ÓÀÔ¶²¹¶¡Ö®Ç°£¬£¬£¬£¬£¬Äܹ»Í¨¹ý0Patchƽ̨ÏÂÔØÒ»Ê±²¹¶¡¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://blog.0patch.com/2021/01/windows-installer-local-privilege.html
0x03 ²Î¿¼Á´½Ó
https://blog.0patch.com/2021/01/windows-installer-local-privilege.html
https://www.bleepingcomputer.com/news/security/windows-installer-zero-day-vulnerability-gets-free-micropatch/
https://halove23.blogspot.com/2020/12/oh-so-you-have-antivirus-nameevery-bug.html
0x04 ¹¦·òÏß
2021-01-28 0Patch°ä²¼Ò»Ê±²¹¶¡
2021-02-01 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ