CVE-2020-17087 | Windows cng.sysȨÏÞÌáÉýÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-11-02

0x00 Îó²î¸ÅÊö

CNVD   ID

CVE-2020-17087

ʱ      ¼ä

2020-11-02

Àà    ÐÍ

ȨÏÞÌáÉý

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

·ñ

Ó°Ïì¹æÄ£

Windows7¡¢Windows10

 

cng.sysÊÇwindowsÖеÄÖ÷ÒªsysÎļþ ¡£ÈôÊǸÃÎļþË𻵣¬Ôò»á·ºÆð·­¿ªÓ¦ÓóÌÐòʱÌáÐÑȱÉÙsysÎļþ¡¢ÏµÍ³ÔËÐÐÖзºÆðÎļþȱʧµÄÌáÐѵ¯´°¡¢µçÄÔ·ºÆðÀ¶ÆÁµÈ״̬ ¡£

0x01 Îó²îÏêÇé

 

image.png


2020Äê10ÔÂ31ÈÕ£¬ÓÉÓÚWinodws cng.sysȨÏÞÌáÉýÎó²î£¨CVE-2020-17087£©Áè¼ÝÁËGoogleÒªÇó΢Èí7ÌìÄÚÐÞ¸´µÄÏÞÆÚ£¬Google Progect ZeroÍŶÓÐû²¼Á˸ÃÎó²îµÄÊÖÒÕϸ½ÚºÍPOC ¡£

¸ÃÎó²îÊÇWindows cng.sysÇý¶¯ÖеĻº³åÇøÒç³öÎó²î£¬¹¥»÷Õß¿ÉÒÔÔÚÓû§¶Ëͨ¹ýIOCTL 0x390400·¢ËͶÔÓ¦µÄ»ûÐÎÊý¾Ý£¬´Ó¶øÔì³ÉÒç³ö ¡£¹¥»÷Õß»¹¿ÉÒÔͨ¹ýÓÕʹÓû§·­¿ª¶ñÒâµÄÎļþ»òÍøÂç×ÊÔ´£¬ÔÙÍŽáÆäËüÎó²î£¨ÈçChrome 0dayÎó²î£©´ÓͨË×Óû§È¨ÏÞÌáÉýµ½ÖÎÀíԱȨÏÞ ¡£

ÖµµÃ×¢ÖØµÄÊÇ£¬½üÆÚÅû¶µÄÒ»¸öChrome 0dayÎó²î£¨CVE-2020-15999£© ¡£¸ÃÎó²îÊÇChrome FreeType×ÖÌåäÖȾʱµÄÒ»´¦ÄÚ´æÆÆËðÎó²î£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§µã»÷£¬×îÖÕ¿ÉÔì³É¾Ü¾ø·þÎñ¹¥»÷»òÔÚÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë ¡£ÏÖÔÚ¸ÃÎó²îÒѾ­ÔÚ86.0.4240.111°æ±¾ÖÐÐÞ¸´ ¡£

 

0x02 ´¦Öóͷ£½¨Òé

΢ÈíÔ¤¼Æ½«ÔÚ2020Äê11ÔÂ10ÈÕÐû²¼¸ÃÎó²îµÄ²¹¶¡ ¡£ÓÉÓÚ¸ÃÎó²îÏÖÔÚ´¦ÓÚ0day¿ÉʹÓÃ״̬£¬ÇÒÒÑÈ·Èϱ£´æÏà¹ØµÄÔÚÒ°¹¥»÷°¸Àý ¡£Çå¾²Íþвˮƽ½Ï¸ß£¬½¨ÒéÌá·ÀÏà¹ØÒÑÖªÎó²î£¬²¢ÆÚ´ý¹Ù·½²¹¶¡ ¡£

 

0x03 ²Î¿¼Á´½Ó

https://bugs.chromium.org/p/project-zero/issues/detail?id=2104

https://www.theregister.com/2020/10/30/windows_kernel_zeroday/

https://securityaffairs.co/wordpress/110193/hacking/google-discloses-windows-zero-day.html?

 

0x04 ʱ¼äÏß

2020-10-31  Google Project ZeroÐû²¼Í¨¸æ

2020-11-02  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

 



image.png