CVE-2020-17087 | Windows cng.sysȨÏÞÌáÉýÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-11-020x00 Îó²î¸ÅÊö
CNVD ID | CVE-2020-17087 | ʱ ¼ä | 2020-11-02 |
Àà ÐÍ | ȨÏÞÌáÉý | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ·ñ | Ó°Ïì¹æÄ£ | Windows7¡¢Windows10 |
cng.sysÊÇwindowsÖеÄÖ÷ÒªsysÎļþ¡£¡£¡£¡£ÈôÊǸÃÎļþË𻵣¬£¬£¬£¬£¬£¬Ôò»á·ºÆð·¿ªÓ¦ÓóÌÐòʱÌáÐÑȱÉÙsysÎļþ¡¢ÏµÍ³ÔËÐÐÖзºÆðÎļþȱʧµÄÌáÐѵ¯´°¡¢µçÄÔ·ºÆðÀ¶ÆÁµÈ״̬¡£¡£¡£¡£
0x01 Îó²îÏêÇé

2020Äê10ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬ÓÉÓÚWinodws cng.sysȨÏÞÌáÉýÎó²î£¨CVE-2020-17087£©Áè¼ÝÁËGoogleÒªÇó΢Èí7ÌìÄÚÐÞ¸´µÄÏÞÆÚ£¬£¬£¬£¬£¬£¬Google Progect ZeroÍŶÓÐû²¼Á˸ÃÎó²îµÄÊÖÒÕϸ½ÚºÍPOC¡£¡£¡£¡£
¸ÃÎó²îÊÇWindows cng.sysÇý¶¯ÖеĻº³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÓû§¶Ëͨ¹ýIOCTL 0x390400·¢ËͶÔÓ¦µÄ»ûÐÎÊý¾Ý£¬£¬£¬£¬£¬£¬´Ó¶øÔì³ÉÒç³ö¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔͨ¹ýÓÕʹÓû§·¿ª¶ñÒâµÄÎļþ»òÍøÂç×ÊÔ´£¬£¬£¬£¬£¬£¬ÔÙÁ¬ÏµÆäËüÎó²î£¨ÈçChrome 0dayÎó²î£©´ÓͨË×Óû§È¨ÏÞÌáÉýµ½ÖÎÀíԱȨÏÞ¡£¡£¡£¡£
ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬½üÆÚÅû¶µÄÒ»¸öChrome 0dayÎó²î£¨CVE-2020-15999£©¡£¡£¡£¡£¸ÃÎó²îÊÇChrome FreeType×ÖÌåäÖȾʱµÄÒ»´¦ÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§µã»÷£¬£¬£¬£¬£¬£¬×îÖÕ¿ÉÔì³É¾Ü¾øÐ§À͹¥»÷»òÔÚÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ÏÖÔÚ¸ÃÎó²îÒѾÔÚ86.0.4240.111°æ±¾ÖÐÐÞ¸´¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
΢ÈíÔ¤¼Æ½«ÔÚ2020Äê11ÔÂ10ÈÕÐû²¼¸ÃÎó²îµÄ²¹¶¡¡£¡£¡£¡£ÓÉÓÚ¸ÃÎó²îÏÖÔÚ´¦ÓÚ0day¿ÉʹÓÃ״̬£¬£¬£¬£¬£¬£¬ÇÒÒÑÈ·Èϱ£´æÏà¹ØµÄÔÚÒ°¹¥»÷°¸Àý¡£¡£¡£¡£Çå¾²Íþвˮƽ½Ï¸ß£¬£¬£¬£¬£¬£¬½¨ÒéÌá·ÀÏà¹ØÒÑÖªÎó²î£¬£¬£¬£¬£¬£¬²¢ÆÚ´ý¹Ù·½²¹¶¡¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://bugs.chromium.org/p/project-zero/issues/detail?id=2104
https://www.theregister.com/2020/10/30/windows_kernel_zeroday/
https://securityaffairs.co/wordpress/110193/hacking/google-discloses-windows-zero-day.html?
0x04 ʱ¼äÏß
2020-10-31 Google Project ZeroÐû²¼Í¨¸æ
2020-11-02 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ