¡¾·ì϶¹«¸æ¡¿CVE-2020-17008 Windows Kernel 0day·ì϶

°ä²¼¹¦·ò 2020-12-24

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2020-17008

ʱ  ¼ä

2020-12-24

Àà   ÐÍ


µÈ  ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

·ñ

Ó°ÏìÁìÓò


 

0x01 ·ì϶ÏêÇé

image.png

½ñÄê6Ô £¬£¬£¬£¬£¬Microsoft°ä²¼°²È«²¼¸æ £¬£¬£¬£¬£¬Windows kernelÖдæÔÚÒ»¸öȨÏÞÌáÉý·ì϶£¨CVE-2020-0986£©¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÓÉÓÚWindows kernelÎÞ·¨ÕýÈ·´¦ÖÃÄÚ´æÖеĶÔÏó £¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.8¡£¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚkernelģʽÏÂÔËÐÐËÁÒâ´úÂë £¬£¬£¬£¬£¬×îÖÕµ¼Ö¹¥»÷ÕßÔÚϵͳÉÏ×°ÖöñÒⷨʽ¡¢¸ü¸Ä»òɾ³ýÊý¾Ý¡¢´´½¨ÕÊ»§µÈ¡£¡£¡£¡£¡£¡£¡£¡£µ«ÒªÀûÓô˷ì϶ £¬£¬£¬£¬£¬¹¥»÷Õß±ØÐëÏȵǼ²¢½ÚÔìϵͳ¡£¡£¡£¡£¡£¡£¡£¡£MicrosoftÔÚ6Ô°䲼µÄ°²È«¸üÐÂÖÐͨ¹ý¸ü¸ÄWindows kernel´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£¡£¡£¡£¡£¡£¡£¡£

µ«ÓÉÓÚMicrosoft°ä²¼µÄ²¹¶¡·¨Ê½ÎÞ·¨½¨¸´CVE-2020-0986 £¬£¬£¬£¬£¬¹¥»÷ÕßÒÀÈ»Äܹ»Í¨¹ý·¢ËÍÆ«ÒÆÁ¿À´´¥·¢´Ë·ì϶ £¬£¬£¬£¬£¬ÒÔÌá¸ßÆä¶ÔkernelµÄȨÏÞ £¬£¬£¬£¬£¬´Ë·ì϶±»·ÖÅäµÄCVE IDΪCVE-2020-17008¡£¡£¡£¡£¡£¡£¡£¡£

CVE-2020-0986ÊÇÓÉÓÚËÁÒâÖ¸ÕëÒýÓà £¬£¬£¬£¬£¬ÔÊÐí¹¥»÷Õß½ÚÔìÖ¸Ïòmemcpyº¯ÊýµÄ¡°src¡±ºÍ¡°dest¡±Ö¸Õë¡£¡£¡£¡£¡£¡£¡£¡£MicrosoftµÄ²¹¶¡·¨Ê½ÊDz»ÕýÈ·µÄ £¬£¬£¬£¬£¬ÓÉÓÚËü¸ü¸ÄÁËÖ¸ÏòÆ«ÒÆÁ¿µÄÖ¸Õë £¬£¬£¬£¬£¬Òò¶ø¹¥»÷ÕßÈÔÄܹ»½ÚÔì¸Ãº¯ÊýµÄ²ÎÊý¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÅû¶ÆÚÏÞ³¬ÆÚ £¬£¬£¬£¬£¬Ä¿Ç°¸Ã·ì϶µÄPoCÒѾ­°ä²¼¡£¡£¡£¡£¡£¡£¡£¡£

Ó°ÏìÁìÓò£º

Windows Server 2012

Windows RT 8.1

Windows 8.1 for x64-based systems

Windows 8.1 for 32-bit systems

Windows Server 2016 (Server Core installation)

Windows Server 2016

Windows 10 for x64-based Systems

Windows 10 Version 1709 for x64-based Systems

Windows 10 Version 1709 for 32-bit Systems

Windows Server, version 1909 (Server Core installation)

Windows 10 Version 1909 for ARM64-based Systems

Windows Server, version 2004 (Server Core installation)

Windows 10 Version 2004 for 32-bit Systems

Windows 10 for 32-bit Systems

Windows Server, version 1903 (Server Core installation)

Windows 10 Version 1903 for ARM64-based Systems

Windows 10 Version 1903 for x64-based Systems

Windows 10 Version 2004 for x64-based Systems

Windows 10 Version 2004 for ARM64-based Systems

Windows 10 Version 1903 for 32-bit Systems

Windows 10 Version 1709 for ARM64-based Systems

Windows 10 Version 1607 for x64-based Systems

Windows 10 Version 1607 for 32-bit Systems

Windows 10 Version 1909 for x64-based Systems

Windows 10 Version 1909 for 32-bit Systems

Windows Server 2019 (Server Core installation)

Windows Server 2019

Windows 10 Version 1809 for ARM64-based Systems

Windows 10 Version 1809 for x64-based Systems

Windows 10 Version 1809 for 32-bit Systems

Windows 10 Version 1803 for ARM64-based Systems

Windows Server, version 1803 (Server Core Installation)

Windows 10 Version 1803 for x64-based Systems

Windows 10 Version 1803 for 32-bit Systems

Windows Server 2012 R2 (Server Core installation)

Windows Server 2012 R2

Windows Server 2012 (Server Core installation)

 

0x02 ´ëÖý¨Òé

Microsoft´òËãÔÚ2020Äê11Ô°䲼¸Ã·ì϶µÄ²¹¶¡ £¬£¬£¬£¬£¬µ«ÓÉÓÚÔÚ²âÊԽ׶η¢ÏÖÎÊÌâ £¬£¬£¬£¬£¬Òò¶øÍƳٵ½2021Äê1ÔÂ12ÈÕÐÇÆÚ¶þ°ä²¼ £¬£¬£¬£¬£¬½¨ÒéÆÚ´ý¹Ù·½°ä²¼²¹¶¡²¢×öºÃÓйطÀ»¤´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-0986

https://www.bleepingcomputer.com/news/security/windows-zero-day-with-bad-patch-gets-new-public-exploit-code/

https://bugs.chromium.org/p/project-zero/issues/detail?id=2096

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17008

 

0x04 ¹¦·òÏß

2020-12-23  StoneÅû¶·ì϶

2020-12-24  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png