Windows COMÌØÈ¨ÌáÉý·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-11-21·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-8550£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Windows 7£¬£¬£¬£¬£¬£¬£¬£¬Windows Server 2012 R2£¬£¬£¬£¬£¬£¬£¬£¬Windows RT 8.1£¬£¬£¬£¬£¬£¬£¬£¬Windows Server 2008£¬£¬£¬£¬£¬£¬£¬£¬Windows Server 2019£¬£¬£¬£¬£¬£¬£¬£¬Windows Server 2012£¬£¬£¬£¬£¬£¬£¬£¬Windows 8.1£¬£¬£¬£¬£¬£¬£¬£¬Windows Server 2016£¬£¬£¬£¬£¬£¬£¬£¬Windows Server 2008 R2£¬£¬£¬£¬£¬£¬£¬£¬Windows 10£¬£¬£¬£¬£¬£¬£¬£¬Windows 10 Server
·ì϶¸ÅÊö
Windows COM Aggregate Marshaler ÖдæÔÚȨÏÞÌáÉý·ì϶¡£¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ê¹ÓÃÌáÉýµÄÌØÈ¨ÔËÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
ÈôÒªÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÔËÐÐ¾ÌØÊâÉè¼Æ²¢¿ÉÄÜÀûÓô˷ì϶µÄÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£´Ë·ì϶×ÔÉí²»ÔÊÐíÔËÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬£¬£¬£¬£¬£¬£¬´Ë·ì϶¿ÉÄÜÓëÒ»¸ö»ò¶à¸ö¿ÉÔÚÔËÐÐʱÀûÓÃÌáÉýÌØÈ¨µÄ·ì϶½áºÏʹÓᣡ£¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
POC/EXP£º
https://www.exploit-db.com/exploits/45893/
½¨¸´½¨Òé
΢Èí¹Ù·½ÒѾ°ä²¼¸üв¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬£¬Çëʵʱ½øÐв¹¶¡¸üС£¡£¡£¡£¡£¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8550
²Î¿¼Á´½Ó
https://bugs.chromium.org/p/project-zero/issues/detail?id=1644


¾©¹«Íø°²±¸11010802024551ºÅ