Windows COMÌØÈ¨ÌáÉý·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-11-21

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-8550£¬£¬ £¬£¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬ £¬£¬£¬£¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Windows 7£¬£¬ £¬£¬£¬£¬£¬ £¬Windows Server 2012 R2£¬£¬ £¬£¬£¬£¬£¬ £¬Windows RT 8.1£¬£¬ £¬£¬£¬£¬£¬ £¬Windows Server 2008£¬£¬ £¬£¬£¬£¬£¬ £¬Windows Server 2019£¬£¬ £¬£¬£¬£¬£¬ £¬Windows Server 2012£¬£¬ £¬£¬£¬£¬£¬ £¬Windows 8.1£¬£¬ £¬£¬£¬£¬£¬ £¬Windows Server 2016£¬£¬ £¬£¬£¬£¬£¬ £¬Windows Server 2008 R2£¬£¬ £¬£¬£¬£¬£¬ £¬Windows 10£¬£¬ £¬£¬£¬£¬£¬ £¬Windows 10 Server


·ì϶¸ÅÊö


Windows COM Aggregate Marshaler ÖдæÔÚȨÏÞÌáÉý·ì϶¡£¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ê¹ÓÃÌáÉýµÄÌØÈ¨ÔËÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£

ÈôÒªÀûÓô˷ì϶£¬£¬ £¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÄܹ»ÔËÐо­ÌØÊâÉè¼Æ²¢¿ÉÄÜÀûÓô˷ì϶µÄÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£´Ë·ì϶×ÔÉí²»ÔÊÐíÔËÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬ £¬£¬£¬£¬£¬ £¬´Ë·ì϶¿ÉÄÜÓëÒ»¸ö»ò¶à¸ö¿ÉÔÚÔËÐÐʱÀûÓÃÌáÉýÌØÈ¨µÄ·ì϶½áºÏʹÓᣡ£¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


POC/EXP£º

https://www.exploit-db.com/exploits/45893/


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


½¨¸´½¨Òé


΢Èí¹Ù·½ÒѾ­°ä²¼¸üв¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬ £¬£¬£¬£¬£¬ £¬Çëʵʱ½øÐв¹¶¡¸üС£¡£¡£¡£¡£¡£¡£¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8550


²Î¿¼Á´½Ó

https://bugs.chromium.org/p/project-zero/issues/detail?id=1644