CVE-2020-1048 | PrintDemonÍâµØÌáȨÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-05-15

0x00 Îó²î¸ÅÊö


CVE   ID

CVE-2020-1048

ʱ    ¼ä

2020-05-15

Àà    ÐÍ

LPE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

·ñ

Ó°Ïì¹æÄ£

×Ô1996ÄêÒÔÀ´Ðû²¼(Windows NT 4)µÄËùÓÐWindows°æ±¾


0x01 Îó²îÏêÇé


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


2020Äê5ÔÂ12ÈÕÇå¾²Ñо¿Ö°Ô±Alex IonescuºÍYarden ShafirÐû²¼Îó²î±¨¸æ£¬£¬ £¬£¬£¬£¬ £¬ÔÚWindows´òӡЧÀÍÖз¢Ã÷ÁËÒ»¸öÇå¾²Îó²î£¨CVE-2020-1048£©£¬£¬ £¬£¬£¬£¬ £¬¿ÉÒÔÓÃÀ´Ð®ÖÆPrinter Spooler»úÖÆ£¬£¬ £¬£¬£¬£¬ £¬¸ÃÎó²îÓ°Ïì×Ô1996ÄêÒÔÀ´Ðû²¼(Windows NT 4)µÄËùÓÐWindows°æ±¾¡£¡£¡£ ¡£¡£ ¡£

CVE-2020-1048ÊÇWindows ´òÓ¡ºǫ́´¦Öóͷ£³ÌÐòÌØÈ¨ÌáÉýÎó²î¡£¡£¡£ ¡£¡£ ¡£ÈôÊÇ Windows ´òÓ¡ºǫ́´¦Öóͷ£³ÌÐòЧÀÍÆ÷²»×¼È·µØÔÊÐíí§ÒâдÈëÎļþϵͳ£¬£¬ £¬£¬£¬£¬ £¬Ôò»á±£´æÌØÈ¨ÌáÉýÎó²î¡£¡£¡£ ¡£¡£ ¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÌáÉýµÄÏµÍ³ÌØÈ¨ÔËÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£ ¡£¹¥»÷Õß¿ÉËæºó×°ÖóÌÐò£»£»£»£»£»£»£»Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»£»£»£»£»£»£»»òÕß½¨ÉèÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£ ¡£¡£ ¡£ÈôҪʹÓôËÎó²î£¬£¬ £¬£¬£¬£¬ £¬¹¥»÷Õß±ØÐèµÇ¼µ½ÊÜÓ°ÏìµÄϵͳ²¢ÔËÐо­ÌØÊâÉè¼ÆµÄ¾ç±¾»òÓ¦ÓóÌÐò¡£¡£¡£ ¡£¡£ ¡£

Ñо¿Ö°Ô±½«PrintDemon³ÆÎª¡°ÍâµØÌØÈ¨Éý¼¶¡±£¨LPE£©Îó²î£¬£¬ £¬£¬£¬£¬ £¬×ÝÈ»¹¥»÷ÕßÖ»ÓÐͨË×Óû§È¨ÏÞ£¬£¬ £¬£¬£¬£¬ £¬Ò²¿ÉÒÔͨ¹ýPowerShellÏÂÁîµÈ·½·¨ÈÝÒ×»ñȡϵͳµÄÖÎÀíԱȨÏÞ¡£¡£¡£ ¡£¡£ ¡£¹¥»÷Õß¿ÉÒÔ³õʼ»¯Ò»¸ö´òÓ¡²Ù×÷£¬£¬ £¬£¬£¬£¬ £¬¾ÓÐÄʹPrint SpoolerЧÀͱ¼À££¬£¬ £¬£¬£¬£¬ £¬È»ºóÔÙ»Ö¸´´òӡʹÃü£¬£¬ £¬£¬£¬£¬ £¬´Ëʱ´òÓ¡²Ù×÷¾ÍÒÔSYSTEMȨÏÞÔËÐÐÁË£¬£¬ £¬£¬£¬£¬ £¬¿ÉÒÔÁýÕÖϵͳÖеÄí§ÒâÎļþ¡£¡£¡£ ¡£¡£ ¡£

¹¥»÷Õß¿ÉÒÔͨ¹ýÒ»¸öPowerShellÏÂÁîʹÓÃCVE-2020-1048£º

Add-PrinterPort -Name c:\windows\system32\ualapi.dll

ÔÚδװÖò¹¶¡µÄϵͳÖУ¬£¬ £¬£¬£¬£¬ £¬ÔËÐÐÉÏÊöÏÂÁî»á×°ÖÃÒ»¸öÓÀÊÀºóÃÅ£¬£¬ £¬£¬£¬£¬ £¬¸ÃºóÃÅ×ÝÈ»ÐÞ¸´ºóÒ²²»»áÏûÊÅ¡£¡£¡£ ¡£¡£ ¡£

POC: https://github.com/ionescu007/PrintDemon


0x02 ´¦Öóͷ£½¨Òé


΢ÈíÒѾ­ÔÚ5ÔµÄ΢Èí²¹¶¡ÈÕÐû²¼Á˸ÃÎó²îµÄ²¹¶¡£¬£¬ £¬£¬£¬£¬ £¬ÓÉÓÚ¸ÃÎó²îºÜÊÇÈÝÒ×±»Ê¹Ó㬣¬ £¬£¬£¬£¬ £¬Ñо¿Ö°Ô±½¨ÒéÓû§¾¡¿ì×°Öò¹¶¡¡£¡£¡£ ¡£¡£ ¡£

ÔÝʱ²½·¥£ºÍ¨¹ýPowerShellµÄGet-PrinterPorts»òHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports À´É¨Ãè»ùÓÚÎļþµÄ¶Ë¿Ú£¬£¬ £¬£¬£¬£¬ £¬ÓÈÆäÊÇÄÇЩ.DLL»ò.EXEÀ©Õ¹µÄÎļþ·¾¶¡£¡£¡£ ¡£¡£ ¡£


0x03 Ïà¹ØÐÂÎÅ


https://www.zdnet.com/article/printdemon-vulnerability-impacts-all-windows-versions/#ftag=RSSbaffb68


0x04 ²Î¿¼Á´½Ó


https://windows-internals.com/printdemon-cve-2020-1048/


0x05 ʱ¼äÏß


2020-05-15 VSRCÐû²¼Îó²îͨ¸æ

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾