Win10±¾µØÌáȨ0day·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-08-29·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÎÞ£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ß£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Windows 10 32/64λ²Ù×÷ϵͳ
·ì϶¸ÅÊö
2018Äê8ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬°²È«×êÑÐÈËÔ±ÔÚgithubÉϰ䲼ÁË×îеÄwin10x64°æµÄ±¾µØÌáȨ·ì϶£¬£¬£¬£¬£¬£¬²¢ÇÒÔÚÍÆÌØÉÏ¶ÔÆäÌáȨµÄdemo½øÐÐÁËÑÝʾ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚgithubÉϵÄSandboxEscaperÉÏÓÐ×ÅÆëÈ«µÄ·ì϶ÀûÓ÷¨Ê½ÒÔ¼°demo£¬£¬£¬£¬£¬£¬²¢ÇÒ±»ÆäËû°²È«×êÑÐר¼Ò֤ʵ¸Ã·ì϶Äܹ»ÔÚ×î½üµÄwin10Éϸ´ÏÖ¡£¡£¡£¡£¡£¡£¡£¡£
¸Ã·ì϶µÄÔÒòÔÚÓÚwin10ϵͳµÄ¹¤×÷µ÷¶È·þÎñÖÐÓÐalpcµÄŲÓýӿڣ¬£¬£¬£¬£¬£¬¸Ã½Ó¿Úµ¼³öÁËSchRpcSetSecurityº¯Êý£¬£¬£¬£¬£¬£¬¸Ãº¯ÊýÕýÊDZ¾´Î·ì϶ÀûÓõ½µÄº¯Êý¡£¡£¡£¡£¡£¡£¡£¡£¸Ãº¯ÊýµÄÔÐÍÈçÏ£º
[in][string] wchar_t* arg_1, //Task name
[in][string] wchar_t* arg_2, //Security Descriptor string
[in]long arg_3);
µ±ËÁÒâȨÏÞµÄÓû§Å²Óøú¯Êýʱ£¬£¬£¬£¬£¬£¬¸Ãº¯Êý»á¼ì²â c:\windows\tasksĿ¼ÏÂÊÇ·ñ´æÔÚÒ»¸öºó׺ΪjobµÄÎļþ£¬£¬£¬£¬£¬£¬ÈôÊǸÃÎļþ´æÔÚ»áÏò¸ÃÎļþдÈëÖ¸¶¨µÄDACLÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£±¾´Î·ì϶ÀûÓõķ½Ê½¼´Í¨¹ýÓ²Á´½ÓµÄ·½Ê½½«¸ÃjobÎļþÖ¸¶¨Á´½Óµ½Ìض¨µÄdllÉÏ£¬£¬£¬£¬£¬£¬ÕâÑùµ±Óû§Å²Óøú¯Êýʱ»áÏòÌØ¶¨µÄdllдÈëÊý¾Ý£¬£¬£¬£¬£¬£¬¶øÌض¨µÄdllÍùÍùÊÇϵͳ¼¶´ËÍâdll¡£¡£¡£¡£¡£¡£¡£¡£ÔÚgithubÉϰ䲼µÄ·ì϶ÀûÓ÷¨Ê½Ôò»áÏòprintconfig.dllдÈëÌáȨ´úÂ룬£¬£¬£¬£¬£¬²¢Í¨¹ýÆô¶¯´òÓ¡·þÎñspoolsv.exeÀ´Ö´ÐÐÌáȨ´úÂ룬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖÄÚºËÌáȨ¡£¡£¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
ËæºóÀûÓÃieä¯ÀÀÆ÷½øÐвâÊÔʱ·¢ÏÖÎÞ·¨ÀûÓóɹ¦£¬£¬£¬£¬£¬£¬¹ÌÈ»·ì϶ÀûÓõÄdllÒѾ±»Ð´Èëµ½spoolsv.exeÖУ¬£¬£¬£¬£¬£¬µ«È´Ã»ÓÐʵÏÖ·ìÏ¶ÕæÕýµÄ³ÉЧ¡£¡£¡£¡£¡£¡£¡£¡£½ÓÏÂÀ´ÒÀÕÕÑÝʾdemoÖеIJÙ×÷£¬£¬£¬£¬£¬£¬´ò¿ªÒ»¸önotepad·¨Ê½£¬£¬£¬£¬£¬£¬²¢¶Ônotepad·¨Ê½½øÐÐ×¢Èë¡£¡£¡£¡£¡£¡£¡£¡£
Ëæºó²é¿´spoolsv.exeϵÄËùÓÐ×Ó¹ý³Ì£¬£¬£¬£¬£¬£¬·¢ÏÖ¸Ãnotepad.exe·¨Ê½±»spoolsv.exe·¨Ê½³Áдò¿ª£¬£¬£¬£¬£¬£¬ºÍgithubÉϵķì϶ÀûÓõÄdemoÖеijÉЧһÖ£¬£¬£¬£¬£¬£¬Äܹ»È·¶¨·ì϶ÀûÓóɹ¦¡£¡£¡£¡£¡£¡£¡£¡£
¶ø¸ÃdllµÄÅú¸Ä¹¦·òÒ²ÏÔʾÊǸոշì϶ÀûÓõŦ·ò£¬£¬£¬£¬£¬£¬ÖÁ´Ë·ì϶¸´Ïֳɹ¦¡£¡£¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
³§ÉÌÉÐδ°ä²¼Óйز¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬ÉóÉ÷Ö´ÐÐδ¾ÉóºËÆðÔ´¶ÔµÄ·¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://github.com/SandboxEscaper/randomrepo


¾©¹«Íø°²±¸11010802024551ºÅ