¡¾·ì϶¹«¸æ¡¿ Microsoft Windows PsExec 0day·ì϶
°ä²¼¹¦·ò 2021-01-080x00 ·ì϶¸ÅÊö
CVE ID | ʱ ¼ä | 2021-01-08 | |
Àà ÐÍ | LPE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ·ñ | Ó°ÏìÁìÓò | PsExec v1.72-v2.2 |
0x01 ·ì϶ÏêÇé

PsExecÊÇSysInternalsÌ×¼þµÄÒ»²¿ÃÅ£¬£¬£¬£¬£¬£¬ËüÊÇϵͳÖÎÀíÔ±µÄÒ»ÖÖ¹¤¾ß£¬£¬£¬£¬£¬£¬¿ÉÔÚÍÆËã»ú¿Í»§¶ËÔ¶³ÌÖ´ÐÐÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£
2020Äê12ÔÂ09ÈÕ£¬£¬£¬£¬£¬£¬PsExec±»Åû¶´æÔÚÒ»¸ö±¾µØÈ¨ÏÞÌáÉý0day·ì϶£¬£¬£¬£¬£¬£¬¸Ã·ì϶±»¶¨ÃûΪ¹Ü·½Ù³Ö£¨»ò¶¨Ãû¹Ü·ռÓã©·ì϶£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÔÊÐí¹¥»÷ÕßÓÕʹPsExec³Áдò¿ª¶ñÒâ´´½¨µÄ¶¨Ãû¹Ü·²¢ÊÚÓèÆä±¾µØÏµÍ³È¨ÏÞ¡£¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶ºó£¬£¬£¬£¬£¬£¬¹¥»÷Õß½«¿ÉÄÜÒÔ±¾µØÏµÍ³µÄÉí·ÝÖ´ÐÐËÁÒâ¹ý³Ì£¬£¬£¬£¬£¬£¬´Ó¶ø½ÚÔìÕû¸öÍÆËã»ú¡£¡£¡£¡£¡£¡£¡£¡£
ÓйØ×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìPsExec°æ±¾´Ó1.72µ½×îа汾2.2£¬£¬£¬£¬£¬£¬ÕâÒâζן÷ì϶ÒѾ´æÔÚԼĪ14ÄêÁË¡£¡£¡£¡£¡£¡£¡£¡£
·ì϶ϸ½Ú
PsExecÔ̺¬Ò»¸öÃûΪ¡°PSEXESVC¡±µÄǶÈëʽ×ÊÔ´£¬£¬£¬£¬£¬£¬ËüÊÇÒ»¸ö¿ÉÖ´ÐеķþÎñ¼¶±ð×é¼þ£¬£¬£¬£¬£¬£¬Ã¿µ±PsExec¿Í»§»úÒÔÔ¶³Ì»úеΪָ±êÖ´ÐÐPsExecʱ£¬£¬£¬£¬£¬£¬¸Ã×é¼þ¾Í»á×÷ΪSYSTEM±»ÌáÈ¡¡¢¸´Ôìµ½Ô¶³Ì»úеÉϲ¢Ö´ÐС£¡£¡£¡£¡£¡£¡£¡£PsExec¿Í»§¶ËºÍÔ¶³ÌPSEXESVC·þÎñÖ®¼äµÄͨѶͨ¹ý¶¨Ãû¹Ü·½øÐС£¡£¡£¡£¡£¡£¡£¡£¾ßÌåÀ´Ëµ£¬£¬£¬£¬£¬£¬ÃûΪ¡°\PSEXESVC¡±µÄ¹ÜÂ·ÕÆ¹Ü½âÎöºÍÖ´ÐÐPsExec¿Í»§¶ËµÄºÅÁ£¬£¬£¬£¬£¬ºÃ±È¡°ÒªÖ´ÐÐÄĸöÀûÓ÷¨Ê½¡±¡¢¡°ÓйغÅÁîÐÐÊý¾Ý¡±µÈ¡£¡£¡£¡£¡£¡£¡£¡£
µ±È»£¬£¬£¬£¬£¬£¬³öÓÚ°²È«ÔÒò£¬£¬£¬£¬£¬£¬PSEXESVC·þÎñµÄ¡°\PSEXESVC¡±¹Ü·Êܵ½±£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬½öÔÊÐíÖÎÀíÔ±½øÐжÁ/д½Ó¼û¡£¡£¡£¡£¡£¡£¡£¡£

µ«ÊÇ£¬£¬£¬£¬£¬£¬Í¨¹ý¹Ü·ÇÀ×¢£¨¼´Æð³õ´´½¨¹Ü·µÄ²½Ö裩£¬£¬£¬£¬£¬£¬µÍȨÏÞÀûÓ÷¨Ê½Äܹ»½Ó¼û¸Ã¹Ü·¡£¡£¡£¡£¡£¡£¡£¡£Ò²¾ÍÊÇ˵£¬£¬£¬£¬£¬£¬ÈôÊDZ¾µØµÍȨÏÞÀûÓ÷¨Ê½ÔÚÖ´ÐÐPSEXESVC֮ǰ´´½¨ÁË¡°\PSEXESVC¡±¶¨Ãû¹Ü·£¬£¬£¬£¬£¬£¬ÔòPSEXESVC½«»ñÈ¡ÏÖÓÐÊ·ýµÄ¾ä±ú£¬£¬£¬£¬£¬£¬¶ø²»ÊÇ´´½¨¶¨Ãû¹Ü·£¬£¬£¬£¬£¬£¬Õ⽫²úÉúһЩÒâÁÏÖ®±íµÄºó¹û£¬£¬£¬£¬£¬£¬ÉԺ󽫿´µ½¡£¡£¡£¡£¡£¡£¡£¡£ÏÂÃæÕ¹Ê¾ÁËPSEXESVCÈôºÎ´´½¨¡°\PSEXESVC¡±¹Ü·µÄ·´»ã±à£º

ÔÚÕâÀ£¬£¬£¬£¬£¬´ÓnMaxInstances²ÎÊýÄܹ»¿´µ½£¬£¬£¬£¬£¬£¬ËüÔÊÐí´æÔÚÎÞÏ޵ġ°\PSEXESVC¡±¹Ü·Ê·ý¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬Ëü²¢²»ÄÜÈ·±£ËüÊǵÚÒ»¸ö´´½¨¡°\PSEXESVC¡±¹Ü·µÄÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬²¢ÇÒͨ³£Ê¹ÓÃFILE_FLAG_FIRST_PIPE_INSTANCE±êÖ¾À´ÊµÏÖ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÕâÖÖÇé¿öÏ£¬£¬£¬£¬£¬£¬Ëü½«³¢ÊÔ´´½¨¶¨Ãû¹Ü·£¬£¬£¬£¬£¬£¬ÈôÊǶ¨Ãû¹Ü·ÒѾ´æÔÚ£¬£¬£¬£¬£¬£¬ÔòÖ»ÐèÔÚŲÓúó»ñÈ¡ÏÖÓÓ×°\PSEXESVC¡±¹Ü·µÄ¾ä±ú¼´¿É£¬£¬£¬£¬£¬£¬Õ⽫¼Ì³ÐÏÖÓйÜ·µÄACL¡£¡£¡£¡£¡£¡£¡£¡£
ÒÔÏ£¬£¬£¬£¬£¬£¬Í¨¹ýÔì×÷ÁËÒ»¸öµ¥Ò»µÄ¡° PipeHijack.exe¡±·¨Ê½£¬£¬£¬£¬£¬£¬¸Ã·¨Ê½´´½¨ÁË¡°\PSEXESVC¡±¹Ü·£¬£¬£¬£¬£¬£¬¸Ã¹Ü·ӵÓжԡ° David Wells¡±Óû§µÄ¶Á/д½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£

ÔËÐк󣬣¬£¬£¬£¬£¬ÈôÊǽ«À´ÔÚ±¾»úÉϱ¾µØ»òÔ¶³ÌÖ´ÐÐPsExec£¬£¬£¬£¬£¬£¬PSEXESVCÊ·ý½«»ñµÃ¹Ü·µÄ¾ä±ú£¬£¬£¬£¬£¬£¬²¢Äܹ»¶ÁÈ¡/дÈë¸Ã¾ä±ú£¬£¬£¬£¬£¬£¬´Ó¶øÔÊÐíµÍȨÏÞÀûÓ÷¨Ê½Óë´ËPSEXESVCϵͳ·þÎñͨѶ¡£¡£¡£¡£¡£¡£¡£¡£

PoCÁ´½Ó£º
https://github.com/tenable/poc/blob/master/Microsoft/Sysinternals/PsExecEscalate.cpp
0x02 ´ëÖý¨Òé
Ŀǰ£¬£¬£¬£¬£¬£¬MicrosoftÔÝδ°ä²¼´Ë·ì϶µÄ°²È«¸üУ¬£¬£¬£¬£¬£¬µ« 0patchÍŶÓÒѾ°ä²¼ÁË´Ë·ì϶µÄ΢²¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://blog.0patch.com/2021/01/local-privilege-escalation-0day-in.html
0x03 ²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/windows-psexec-zero-day-vulnerability-gets-a-free-micropatch/
https://medium.com/tenable-techblog/psexec-local-privilege-escalation-2e8069adc9c8
0x04 ¹¦·òÏß
2020-12-09 David WellsÅû¶·ì϶
2021-01-07 0patchÍŶӰ䲼΢²¹¶¡
2021-01-08 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ