¡¾·ì϶¹«¸æ¡¿ Microsoft Windows PsExec 0day·ì϶

°ä²¼¹¦·ò 2021-01-08

0x00 ·ì϶¸ÅÊö

CVE  ID


ʱ  ¼ä

2021-01-08

Àà   ÐÍ

LPE

µÈ  ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

·ñ

Ó°ÏìÁìÓò

PsExec v1.72-v2.2

 

0x01 ·ì϶ÏêÇé

image.png

PsExecÊÇSysInternalsÌ×¼þµÄÒ»²¿ÃÅ£¬£¬£¬ £¬£¬£¬ËüÊÇϵͳÖÎÀíÔ±µÄÒ»ÖÖ¹¤¾ß£¬£¬£¬ £¬£¬£¬¿ÉÔÚÍÆËã»ú¿Í»§¶ËÔ¶³ÌÖ´ÐÐÀûÓ÷¨Ê½¡£ ¡£¡£¡£¡£¡£¡£¡£

2020Äê12ÔÂ09ÈÕ£¬£¬£¬ £¬£¬£¬PsExec±»Åû¶´æÔÚÒ»¸ö±¾µØÈ¨ÏÞÌáÉý0day·ì϶£¬£¬£¬ £¬£¬£¬¸Ã·ì϶±»¶¨ÃûΪ¹Ü·½Ù³Ö£¨»ò¶¨Ãû¹Ü·ռÓã©·ì϶£¬£¬£¬ £¬£¬£¬¸Ã·ì϶ÔÊÐí¹¥»÷ÕßÓÕʹPsExec³Áдò¿ª¶ñÒâ´´½¨µÄ¶¨Ãû¹Ü·²¢ÊÚÓèÆä±¾µØÏµÍ³È¨ÏÞ¡£ ¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶ºó£¬£¬£¬ £¬£¬£¬¹¥»÷Õß½«¿ÉÄÜÒÔ±¾µØÏµÍ³µÄÉí·ÝÖ´ÐÐËÁÒâ¹ý³Ì£¬£¬£¬ £¬£¬£¬´Ó¶ø½ÚÔìÕû¸öÍÆËã»ú¡£ ¡£¡£¡£¡£¡£¡£¡£

ÓйØ×êÑÐÈËÔ±°µÊ¾£¬£¬£¬ £¬£¬£¬¸Ã·ì϶ӰÏìPsExec°æ±¾´Ó1.72µ½×îа汾2.2£¬£¬£¬ £¬£¬£¬ÕâÒâζן÷ì϶ÒѾ­´æÔÚԼĪ14ÄêÁË¡£ ¡£¡£¡£¡£¡£¡£¡£

 

·ì϶ϸ½Ú

PsExecÔ̺¬Ò»¸öÃûΪ¡°PSEXESVC¡±µÄǶÈëʽ×ÊÔ´£¬£¬£¬ £¬£¬£¬ËüÊÇÒ»¸ö¿ÉÖ´ÐеķþÎñ¼¶±ð×é¼þ£¬£¬£¬ £¬£¬£¬Ã¿µ±PsExec¿Í»§»úÒÔÔ¶³Ì»úеΪָ±êÖ´ÐÐPsExecʱ£¬£¬£¬ £¬£¬£¬¸Ã×é¼þ¾Í»á×÷ΪSYSTEM±»ÌáÈ¡¡¢¸´Ôìµ½Ô¶³Ì»úеÉϲ¢Ö´ÐС£ ¡£¡£¡£¡£¡£¡£¡£PsExec¿Í»§¶ËºÍÔ¶³ÌPSEXESVC·þÎñÖ®¼äµÄͨѶͨ¹ý¶¨Ãû¹Ü·½øÐС£ ¡£¡£¡£¡£¡£¡£¡£¾ßÌåÀ´Ëµ£¬£¬£¬ £¬£¬£¬ÃûΪ¡°\PSEXESVC¡±µÄ¹ÜÂ·ÕÆ¹Ü½âÎöºÍÖ´ÐÐPsExec¿Í»§¶ËµÄºÅÁ£¬£¬ £¬£¬£¬ºÃ±È¡°ÒªÖ´ÐÐÄĸöÀûÓ÷¨Ê½¡±¡¢¡°ÓйغÅÁîÐÐÊý¾Ý¡±µÈ¡£ ¡£¡£¡£¡£¡£¡£¡£

µ±È»£¬£¬£¬ £¬£¬£¬³öÓÚ°²È«Ô­Òò£¬£¬£¬ £¬£¬£¬PSEXESVC·þÎñµÄ¡°\PSEXESVC¡±¹Ü·Êܵ½±£»£»£»£»£»£»¤£¬£¬£¬ £¬£¬£¬½öÔÊÐíÖÎÀíÔ±½øÐжÁ/д½Ó¼û¡£ ¡£¡£¡£¡£¡£¡£¡£

image.png

 

µ«ÊÇ£¬£¬£¬ £¬£¬£¬Í¨¹ý¹Ü·ÇÀ×¢£¨¼´Æð³õ´´½¨¹Ü·µÄ²½Ö裩£¬£¬£¬ £¬£¬£¬µÍȨÏÞÀûÓ÷¨Ê½Äܹ»½Ó¼û¸Ã¹Ü·¡£ ¡£¡£¡£¡£¡£¡£¡£Ò²¾ÍÊÇ˵£¬£¬£¬ £¬£¬£¬ÈôÊDZ¾µØµÍȨÏÞÀûÓ÷¨Ê½ÔÚÖ´ÐÐPSEXESVC֮ǰ´´½¨ÁË¡°\PSEXESVC¡±¶¨Ãû¹Ü·£¬£¬£¬ £¬£¬£¬ÔòPSEXESVC½«»ñÈ¡ÏÖÓÐÊ·ýµÄ¾ä±ú£¬£¬£¬ £¬£¬£¬¶ø²»ÊÇ´´½¨¶¨Ãû¹Ü·£¬£¬£¬ £¬£¬£¬Õ⽫²úÉúһЩÒâÁÏÖ®±íµÄºó¹û£¬£¬£¬ £¬£¬£¬ÉԺ󽫿´µ½¡£ ¡£¡£¡£¡£¡£¡£¡£ÏÂÃæÕ¹Ê¾ÁËPSEXESVCÈôºÎ´´½¨¡°\PSEXESVC¡±¹Ü·µÄ·´»ã±à£º

image.png

 

ÔÚÕâÀ£¬£¬ £¬£¬£¬´ÓnMaxInstances²ÎÊýÄܹ»¿´µ½£¬£¬£¬ £¬£¬£¬ËüÔÊÐí´æÔÚÎÞÏ޵ġ°\PSEXESVC¡±¹Ü·Ê·ý¡£ ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬Ëü²¢²»ÄÜÈ·±£ËüÊǵÚÒ»¸ö´´½¨¡°\PSEXESVC¡±¹Ü·µÄÀûÓ÷¨Ê½£¬£¬£¬ £¬£¬£¬²¢ÇÒͨ³£Ê¹ÓÃFILE_FLAG_FIRST_PIPE_INSTANCE±êÖ¾À´ÊµÏÖ¡£ ¡£¡£¡£¡£¡£¡£¡£ÔÚÕâÖÖÇé¿öÏ£¬£¬£¬ £¬£¬£¬Ëü½«³¢ÊÔ´´½¨¶¨Ãû¹Ü·£¬£¬£¬ £¬£¬£¬ÈôÊǶ¨Ãû¹Ü·ÒѾ­´æÔÚ£¬£¬£¬ £¬£¬£¬ÔòÖ»ÐèÔÚŲÓúó»ñÈ¡ÏÖÓÓ×°\PSEXESVC¡±¹Ü·µÄ¾ä±ú¼´¿É£¬£¬£¬ £¬£¬£¬Õ⽫¼Ì³ÐÏÖÓйÜ·µÄACL¡£ ¡£¡£¡£¡£¡£¡£¡£

 

ÒÔÏ£¬£¬£¬ £¬£¬£¬Í¨¹ýÔì×÷ÁËÒ»¸öµ¥Ò»µÄ¡° PipeHijack.exe¡±·¨Ê½£¬£¬£¬ £¬£¬£¬¸Ã·¨Ê½´´½¨ÁË¡°\PSEXESVC¡±¹Ü·£¬£¬£¬ £¬£¬£¬¸Ã¹Ü·ӵÓжԡ° David Wells¡±Óû§µÄ¶Á/д½Ó¼ûȨÏÞ¡£ ¡£¡£¡£¡£¡£¡£¡£

image.png

 

ÔËÐк󣬣¬£¬ £¬£¬£¬ÈôÊǽ«À´ÔÚ±¾»úÉϱ¾µØ»òÔ¶³ÌÖ´ÐÐPsExec£¬£¬£¬ £¬£¬£¬PSEXESVCÊ·ý½«»ñµÃ¹Ü·µÄ¾ä±ú£¬£¬£¬ £¬£¬£¬²¢Äܹ»¶ÁÈ¡/дÈë¸Ã¾ä±ú£¬£¬£¬ £¬£¬£¬´Ó¶øÔÊÐíµÍȨÏÞÀûÓ÷¨Ê½Óë´ËPSEXESVCϵͳ·þÎñͨѶ¡£ ¡£¡£¡£¡£¡£¡£¡£

image.png

 

PoCÁ´½Ó£º

https://github.com/tenable/poc/blob/master/Microsoft/Sysinternals/PsExecEscalate.cpp

 

0x02 ´ëÖý¨Òé

Ŀǰ£¬£¬£¬ £¬£¬£¬MicrosoftÔÝδ°ä²¼´Ë·ì϶µÄ°²È«¸üУ¬£¬£¬ £¬£¬£¬µ« 0patchÍŶÓÒѾ­°ä²¼ÁË´Ë·ì϶µÄ΢²¹¶¡¡£ ¡£¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://blog.0patch.com/2021/01/local-privilege-escalation-0day-in.html

 

0x03 ²Î¿¼Á´½Ó

https://www.bleepingcomputer.com/news/security/windows-psexec-zero-day-vulnerability-gets-a-free-micropatch/

https://medium.com/tenable-techblog/psexec-local-privilege-escalation-2e8069adc9c8

 

0x04 ¹¦·òÏß

2020-12-09  David WellsÅû¶·ì϶

2021-01-07  0patchÍŶӰ䲼΢²¹¶¡

2021-01-08  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png