¡¾Îó²îÇ鱨¡¿Spectre CPUÎó²î£¨CVE-2017-5753£©
Ðû²¼Ê±¼ä 2021-03-020x00 Îó²î¸ÅÊö
CVE ID | CVE-2017-5753 | ʱ ¼ä | 2021-03-02 |
Àà ÐÍ | Éè¼Æ¹ýʧ | µÈ ¼¶ | |
Ô¶³ÌʹÓà | Ó°Ïì¹æÄ£ |
0x01 Îó²îÏêÇé

2021Äê03ÔÂ01ÈÕ£¬£¬£¬£¬£¬Çå¾²Ñо¿Ö°Ô±ÖìÀû°²¡¤ÎÖÒÁÉ£¨Julien Voisin£©ÔÚVirusTotal¶ñÒâÈí¼þÆÊÎöƽ̨ÉÏ·¢Ã÷ÁËSpectre CPUÎó²î£¨CVE-2017-5753£©µÄLinux°æºÍWindows°æµÄÎó²îʹÓóÌÐò£¬£¬£¬£¬£¬ÕâÌåÏÖÄܹ»¾ÙÐÐÏÖÊµÆÆËð²¢ÍêÈ«ÎäÆ÷»¯µÄÓÐÓÃʹÓóÌÐòÒѾÔÚ¹«¹²ÁìÓòÖйûÕæ¡£¡£¡£¡£¡£¡£
Spectre CPUÎó²îÊÇ2018Äê1ÔÂGoogle Project ZeroÅû¶µÄIntel¡¢AMDºÍARM´¦Öóͷ£Æ÷¼Ü¹¹ÖеÄÓ²¼þÉè¼ÆÈ±ÏÝ£¨Meltdown£ºCVE-2017-5754¡¢Spectre£ºCVE-2017-5753ºÍCVE-2017-5715£©£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃÎó²îÔËÐÐÓ¦ÓóÌÐòÖеĴúÂëÀ´ÆÆËð²î±ðÓ¦ÓóÌÐòÖ®¼äÔÚCPU²ãÃæµÄ¸ôÀ룬£¬£¬£¬£¬È»ºóÇÔȡͳһϵͳÉÏÔËÐÐµÄÆäËüÓ¦ÓõÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£
GoogleÌåÏÖ£¬£¬£¬£¬£¬Spectre CPUÎó²î»áÓ°Ïì°üÀ¨Windows¡¢Linux¡¢macOS¡¢AndroidºÍChromeOSµÈÔÚÄÚµÄÖ÷Á÷²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£×Ô¾õÏÖ¸ÃÎó²îÒÔÀ´£¬£¬£¬£¬£¬ËùÓÐÖ÷Á÷CPUºÍOS¹©Ó¦É̾ùÐû²¼Á˹̼þ²¹¶¡ºÍÈí¼þÐÞ¸´£¬£¬£¬£¬£¬µ«ÉÐδ¸üÐÂÆäϵͳµÄÓû§ÈÔÈ»ÈÝÒ×Êܵ½Spectre CPUÎó²îµÄ¹¥»÷£¬£¬£¬£¬£¬ÓÈÆäÊÇʹÓþɰæÐ¾Æ¬²¢ÔËÐоɰæ²Ù×÷ϵͳµÄÓû§£¨Èç2015ÄêÔµÄPC£¬£¬£¬£¬£¬²¢Ê¹ÓÃHaswell»ò¾ÉµÄIntel´¦Öóͷ£Æ÷£©¡£¡£¡£¡£¡£¡£
VirusTotalÉϵÄÎó²îʹÓóÌÐòÊÇÉϸöÔÂÉÏ´«µÄ£¬£¬£¬£¬£¬¸ÃÈí¼þ°üÊÇÊÊÓÃÓÚWindowsºÍLinuxµÄImmunity Canvas 7.26×°ÖóÌÐò(Immunity CANVASΪȫÇòµÄÉøÍ¸²âÊÔÖ°Ô±ºÍÇ徲רҵְԱÌṩÁËÊý°ÙÖÖÎó²îʹÓá¢×Ô¶¯»¯µÄÎó²îʹÓÃϵͳÒÔ¼°ÖÜÈ«¡¢¿É¿¿µÄÎó²îʹÓÿª·¢¿ò¼Ü)¡£¡£¡£¡£¡£¡£

´ËÎó²îʹÓóÌÐò¿ÉÒÔʹͨË×Óû§¿ÉÒÔ´ÓÄ¿µÄ×°±¸µÄÄÚºËÄÚ´æÖÐת´¢WindowsϵͳºÍLinuxϵͳÖÐ/etc/shadowÎļþÖеÄLM/NT¹þÏ£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¸ÃʹÓóÌÐò»¹Äܹ»×ª´¢Kerberos tickets£¬£¬£¬£¬£¬¿ÉÓëPsExecÒ»ÆðÓÃÓÚWindowsϵͳµÄÍâµØÈ¨ÏÞÉý¼¶ºÍºáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£ÕâÒâζ×Å£¬£¬£¬£¬£¬ÈôÊǸÃÎó²î±»ÀÖ³ÉʹÓ㬣¬£¬£¬£¬Ôò¹¥»÷Õß¿ÉÒÔÇÔÈ¡ÊÜÓ°ÏìϵͳµÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬°üÀ¨ÃÜÂë¡¢ÎĵµÒÔ¼°ÄÚ´æÖÐÈκοÉÓÃµÄÆäËüÊý¾Ý¡£¡£¡£¡£¡£¡£


ÈçVoisinËù˵£¬£¬£¬£¬£¬´ò¹ý¸ÃÎó²î²¹¶¡µÄLinux»òWindowsϵͳÔò²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¶øÎ¢ÈíÌåÏÖ£¬£¬£¬£¬£¬ÓÉÓÚ×°Öò¹¶¡ºóϵͳÐÔÄÜ»áÓÐÏÔ×ŵÄϽµ£¬£¬£¬£¬£¬Òò´ËÓû§×îÈÝÒ×Ìø¹ýÓ¦Óûº½â²½·¥¡£¡£¡£¡£¡£¡£
³ý´ËÖ®Í⣬£¬£¬£¬£¬×ÝÈ»¹¥»÷ÕßÄõ½ÁËÕâÁ½¸öÎó²îʹÓóÌÐòÈí¼þ°üÖеÄÈκÎÒ»¸ö£¬£¬£¬£¬£¬Ö»ÔËÐÐËüÃÇÒ²²»»á±¬·¢ÈκÎЧ¹û£¬£¬£¬£¬£¬ÓÉÓÚËüÃǶ¼Ö»ÄÜÔÚ׼ȷµÄ²ÎÊýÏÂÖ´ÐУ¬£¬£¬£¬£¬³ý·Ç¹¥»÷ÕßÄܹ»ÔËÐÐ׼ȷµÄ²ÎÊý¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
Spectre CPUÎó²îÒÑÓÚ2018ÄêÐÞ¸´£¬£¬£¬£¬£¬½¨Òéδʵʱ¸üеÄÓû§²Î¿¼CPUºÍOS¹©Ó¦É̹ٷ½Ðû²¼µÄÐÞ¸´³ÌÐò»ò»º½â²½·¥¡£¡£¡£¡£¡£¡£
Õë¶Ôwindowsϵͳ£¬£¬£¬£¬£¬Î¢Èíͨ¹ý¸ü¸ÄWindowsºÍоƬ΢´úÂëÀ´»º½â´ËÎó²î£¬£¬£¬£¬£¬²¢½¨ÒéʹÓÃWindows UpdateºÍоƬ΢´úÂë¸üС£¡£¡£¡£¡£¡£
ÏêÇéÁ´½Ó£º
https://www.microsoft.com/security/blog/2018/01/09/understanding-the-performance-impact-of-spectre-and-meltdown-mitigations-on-windows-systems/
0x03 ²Î¿¼Á´½Ó
https://www.virustotal.com/gui/file/6461d0988c835e91eb534757a9fa3ab35afe010bec7d5406d4dfb30ea767a62c/detection
https://www.bleepingcomputer.com/news/security/working-windows-and-linux-spectre-exploits-found-on-virustotal/?
https://dustri.org/b/spectre-exploits-in-the-wild.html
https://therecord.media/first-fully-weaponized-spectre-exploit-discovered-online/
0x04 ʱ¼äÏß
2021-03-01 Julien VoisinÅû¶ʹÓóÌÐò
2021-03-02 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ