Windows CryptoAPIÓÕÆÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-01-15Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-0601£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.1£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Windows 10 Version 1607
Windows 10 Version 1709
Windows 10 Version 1803
Windows 10 Version 1809
Windows 10 Version 1903
Windows 10 Version 1909
Windows Server2016
Windows Server 2019
Îó²î¸ÅÊö
2020Äê1ÔÂ14ÈÕ΢ÈíÐû²¼ÁËCVE-2020-0601Îó²îͨ¸æ£¬£¬£¬£¬´ËÎó²îΪWindows¼ÓÃÜ¿âÖеÄÒ»¸öÒªº¦µÄÎó²î£¬£¬£¬£¬Windows CryptoAPI(Crypt32.dll) ÑéÖ¤ÍÖÔ²ÇúÏß¼ÓÃÜ (ECC)Ö¤ÊéµÄ·½·¨Öб£´æÓÕÆÎó²î¡£¡£¡£¡£¡£
¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÓÕÆÐԵĴúÂëÊðÃûÖ¤Êé¶Ô¶ñÒâ¿ÉÖ´ÐÐÎļþ¾ÙÐÐÊðÃûÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬´Ó¶øÊ¹¸ÃÎļþËÆºõÀ´×Ô¿É¿¿µÄÕýµ±ÈªÔ´¡£¡£¡£¡£¡£Óû§½«ÎÞ·¨ÖªµÀÎļþÊǶñÒâµÄ£¬£¬£¬£¬ÓÉÓÚÊý×ÖÊðÃûËÆºõÀ´×ÔÊÜÐÅÈεÄÌṩ³ÌÐò¡£¡£¡£¡£¡£ÀֳɵÄʹÓû¹¿ÉÒÔʹ¹¥»÷Õß¾ÙÐÐÖÐÐÄÈ˹¥»÷£¬£¬£¬£¬²¢ÔÚÓëÊÜÓ°ÏìÈí¼þµÄÓû§ÅþÁ¬ÉϽâÃÜÉñÃØÐÅÏ¢¡£¡£¡£¡£¡£
¸ÃÎó²îΪNSA×ÔÁ¦·¢Ã÷£¬£¬£¬£¬²¢»ã±¨¸øÎ¢Èí¡£¡£¡£¡£¡£Æ¾Ö¤NSAÀÖ³ÉʹÓôËÎó²î½«Ê¹¹¥»÷ÕßÄܹ»ÌṩÀ´×ÔÊÜÐÅÈÎʵÌåµÄ¶ñÒâ´úÂë¡£¡£¡£¡£¡£ÆäÖаüÀ¨£ºÊðÃûµÄÎļþºÍµç×ÓÓʼþ¡¢ÊðÃû¿ÉÖ´ÐдúÂëµÈ¡¢HTTPsÅþÁ¬¡£¡£¡£¡£¡£
ÖµµÃ×¢ÖØµÄÊÇÖ¸¶¨²ÎÊýµÄECCÃÜÔ¿Ö¤ÊéµÄWindows°æ±¾»áÊܵ½Ó°Ï죬£¬£¬£¬¶øÕâÒ»»úÖÆ£¬£¬£¬£¬×îÔçÓÉWIN10ÒýÈ룬£¬£¬£¬Ó°ÏìWIN10£¬£¬£¬£¬Windows Server 2016/2019°æ±¾£¬£¬£¬£¬¶øÓÚ½ñÄê1ÔÂ14ÈÕ×èÖ¹Ç徲ά»¤µÄWIN7/Windows Server 2008ÓÉÓÚ²»Ö§³Ö´ø²ÎÊýµÄECCÃÜÔ¿£¬£¬£¬£¬Òò´Ë²»ÊÜÏà¹ØÓ°Ï죬£¬£¬£¬µ«ÈÔÈ»½¨ÒéÓû§½«WIN7/ Windows Server 2008ϵͳ¸üÐÂÖÁ×îеÄWIN10ϵͳ»òWindows Server2016Ö®ºóµÄ°æ±¾£¬£¬£¬£¬²¢¸üÐÂÏà¹ØÇå¾²²¹¶¡¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ΢ÈíÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601
https://media.defense.gov/2020/Jan/14/2002234275/-1/-1/0/CSA-WINDOWS-10-CRYPT-LIB-20190114.PDF


¾©¹«Íø°²±¸11010802024551ºÅ