Windows Installer×é¼þ0dayÎó²î

Ðû²¼Ê±¼ä 2021-02-01

0x00 Îó²î¸ÅÊö

CVE  ID


ʱ   ¼ä

2021-02-01

Àà  ÐÍ

ȨÏÞÌáÉý

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

·ñ

Ó°Ïì¹æÄ£

Windows 7- Windows 10

 

0x01 Îó²îÏêÇé

image.png

¼òÊö

Windows InstallerÊÇWindowsÖеÄÒ»¸ö×é¼þ£¬£¬£¬£¬ËüÊÇרÃÅÓÃÀ´ÖÎÀíºÍÉèÖÃÈí¼þЧÀ͵Ť¾ß¡£¡£¡£¡£¡£¡£¡£¡£

2020Äê10Ô£¬£¬£¬£¬MicrosoftÐÞ¸´ÁËWindows Installer×é¼þÖеÄÒ»¸öÎó²î£¨CVE-2020-16902£¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔø±»¶à´ÎÐÞ¸´¡¢Èƹý£¬£¬£¬£¬ÀúÊ·×·×ÙΪCVE-2019-1415¡¢CVE-2020-1302ºÍCVE-2020-0814£©£¬£¬£¬£¬µ«¸ÃÎó²îµÄÐÞ¸´³ÌÐòÈԿɱ»Èƹý¡£¡£¡£¡£¡£¡£¡£¡£12ÔÂÏÂÑ®£¬£¬£¬£¬¸ÃÎó²îµÄPoC±»¹ûÕæ¡£¡£¡£¡£¡£¡£¡£¡£MicrosoftһֱûÓÐÍêÈ«ÐÞ¸´´ËÎó²î¡£¡£¡£¡£¡£¡£¡£¡£

¿ËÈÕ£¬£¬£¬£¬Microsoft¶à´ÎʵÑéÐÞ¸´µÄWindows Installer×é¼þÎó²î£¨CVE-2020-16902²¹¶¡µÄÈÆ¹ý£© »ñµÃÁËÒ»¸öÔÝʱ²¹¶¡£¬£¬£¬£¬¸Ã²¹¶¡Äܹ»×èÖ¹¹¥»÷ÕßʹÓÃÎó²î»ñȡĿµÄϵͳµÄ×î¸ßȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£


Îó²îÆÊÎö

ÔÚ×°ÖÃMSIÈí¼þ°üµÄÀú³ÌÖУ¬£¬£¬£¬Windows Installer»áͨ¹ý¡° msiexec.exe¡±½¨Éè»Ø¹ö¾ç±¾£¬£¬£¬£¬ÒÔ±ãÔÚÀú³ÌÖзºÆð¹ýʧʱ»¹Ô­ËùÓиü¸Ä¡£¡£¡£¡£¡£¡£¡£¡£

¾ßÓÐÍâµØÈ¨Ï޵Ĺ¥»÷ÕßÈôÊÇ¿ÉÒÔÓÃÒ»¸ö¸Ä±ä×¢²á±íÖµÀ´Ö¸ÏòËûÃǵÄPayloadµÄ½ÅÔ­À´Ìæ»»»Ø¹ö¾ç±¾£¬£¬£¬£¬Ôò¿ÉÒÔÔËÐоßÓÐSYSTEMȨÏ޵ĿÉÖ´ÐÐÎļþ¡£¡£¡£¡£¡£¡£¡£¡£

 

Îó²î¸´ÏÖ

¸ÃÎó²îµÄPoCÖÐʹÓõÄÊǻعö¾ç±¾£¬£¬£¬£¬Ëü½«HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/services/Fax/ImagePathµÄÖµ¸ü¸ÄΪc:\Windows/tempasmae.exe£¬£¬£¬£¬µ¼Ö´«ÕæÐ§ÀÍÆô¶¯Ê±Ê¹Óù¥»÷ÕßµÄasmae.exe¡£¡£¡£¡£¡£¡£¡£¡£Ö®ÒÔÊÇʹÓøÃЧÀÍ£¬£¬£¬£¬ÊÇÓÉÓÚÈκÎÓû§¶¼¿ÉÒÔÆô¶¯¸ÃЧÀÍ£¬£¬£¬£¬²¢ÇÒ¸ÃЧÀÍÒÔÍâµØÏµÍ³µÄÉí·ÝÔËÐС£¡£¡£¡£¡£¡£¡£¡£

¸ÃÎó²îµÄ΢²¹¶¡³ÌÐòͨ¹ý×èÖ¹ÍâµØ·ÇÖÎÀíÔ±Óû§ÐÞ¸ÄÖ¸Ïò´«ÕæÐ§ÀÍ¿ÉÖ´ÐÐÎļþµÄ×¢²á±íÖµÀ´±ÜÃâ¹¥»÷ÕßÔËÐдúÂë¡£¡£¡£¡£¡£¡£¡£¡£PoC¸´ÏÖÈçÏ£º

image.png

 

0PatchµÄÔÝʱ²¹¶¡ÊÊÓÃÓÚÒÔÏÂϵͳ£º

Windows 10 v20H2 32/64룬£¬£¬£¬ÒÑÓÚ2021Äê1Ô¸üÐÂ

Windows 10 v2004 32/64룬£¬£¬£¬ÓÚ2021Äê1Ô¸üÐÂ

Windows 10 v1909 32/64룬£¬£¬£¬ÒÑÓÚ2021Äê1Ô¸üÐÂ

Windows 7¡¢32/64λºÍESU£¬£¬£¬£¬ÓÚ2021Äê1Ô¸üÐÂ

Windows 7¡¢32/64루²»´øESU£©£¬£¬£¬£¬ÒÑÓÚ2020Äê1Ô¸üÐÂ

 

 

0x02 ´¦Öóͷ£½¨Òé

ÔÚMicrosoftÐû²¼ÓÀÊÀ²¹¶¡Ö®Ç°£¬£¬£¬£¬¿ÉÒÔͨ¹ý0Patchƽ̨ÏÂÔØÔÝʱ²¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://blog.0patch.com/2021/01/windows-installer-local-privilege.html

 

0x03 ²Î¿¼Á´½Ó

https://blog.0patch.com/2021/01/windows-installer-local-privilege.html

https://www.bleepingcomputer.com/news/security/windows-installer-zero-day-vulnerability-gets-free-micropatch/

https://halove23.blogspot.com/2020/12/oh-so-you-have-antivirus-nameevery-bug.html

 

0x04 ʱ¼äÏß

2021-01-28  0PatchÐû²¼ÔÝʱ²¹¶¡

2021-02-01  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png