¡¾¹«¸æ¸üС¿Windows Print SpoolerÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-34527£©
°ä²¼¹¦·ò 2021-07-080x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-34527 | ʱ ¼ä | 2021-07-08 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
¹¥»÷¸´ÔÓ¶È | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | ÊÇ |
0x01 ·ì϶ÏêÇé

Windows Print SpoolerÊÇWindowsµÄ´òÓ¡»úºó¶Ü´¦Ö÷¨Ê½£¬£¬£¬£¬£¬£¬ÆäÖÎÀíËùÓб¾µØºÍÍøÂç´òÓ¡¶ÓÁв¢½ÚÔìËùÓдòÓ¡¹¤×÷£¬£¬£¬£¬£¬£¬±»¿í·ºÀûÓÃÓÚ±¾µØºÍÄÚÍøÖС£¡£¡£¡£¡£
2021Äê7ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬MicrosoftÕë¶ÔCVE-2021-34527°ä²¼ÁË´ø±í°²È«¸üÐÂKB5004945¡£¡£¡£¡£¡£µ«Êǽ¨Ò鲻ҪװÖÃMicrosoft 7 Ô 6 ÈÕ°ä²¼µÄ²¹¶¡£¬£¬£¬£¬£¬£¬ÓÉÓÚËü²»½ö²»ÄÜÔ¤·À·ì϶£¬£¬£¬£¬£¬£¬²¢ÇÒ»áÅú¸Ä¡°localspl.dll¡±Îļþ£¬£¬£¬£¬£¬£¬Ê¹µÃ0Patch µÄ²¹¶¡²»ÔÙÓÐЧ¡£¡£¡£¡£¡£
°²È«×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬Î¢ÈíÖ»½¨¸´Á˸÷ì϶µÄÔ¶³Ì´úÂëÖ´Ðв¿ÃÅ£¬£¬£¬£¬£¬£¬µ«ÔÚÆôÓÃ"Ö¸Ïò²¢´òÓ¡ÏÞ¶È"µÄWindowsÕ½ÊõµÄÇé¿öÏ£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þºÍ¹¥»÷ÕßÒÀÈ»Äܹ»Í¨¹ý±¾µØÈ¨ÏÞÌáÉý£¨LPE£©À´»ñµÃÒ×Êܹ¥»÷ϵͳµÄȨÏÞ£¬£¬£¬£¬£¬£¬²¢Äܹ»Èƹý²¹¶¡À´ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£
µ«ÒªÈƹý²¹¶¡²¢ÊµÏÖRCEºÍLPE£¬£¬£¬£¬£¬£¬±ØÐëÆôÓÃÃûΪ"Ö¸Ïò²¢´òÓ¡ÏÞ¶È"µÄWindowsÕ½Êõ£¬£¬£¬£¬£¬£¬²¢½« "×°ÖÃÐÂÏνӵÄÇý¶¯·¨Ê½Ê± "µÄÉèÖÃÅäÖÃΪ "²»ÏÔʾÖÒ¸æ»òÌáÉýÌáÐÑ"£¨ÅäÖÃõè¾¶£º×éÕ½Êõ>ÍÆËã»úÅäÖÃ>ÖÎÀíÄ£°å>´òÓ¡»ú>Ö¸Ïò²¢´òÓ¡ÏÞ¶È£©¡£¡£¡£¡£¡£

ÆôÓú󣬣¬£¬£¬£¬£¬ÔÚ×¢²á±íHKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint¼üÏ£¬£¬£¬£¬£¬£¬"NoWarningNoElevationOnInstall "Öµ½«±»ÉèÖÃΪ1¡£¡£¡£¡£¡£
¸Ã·ì϶£¨CVE-2021-34527£©ÊÇAddPrinterDriverEx£¨£©¡¢RpcAddPrinterDriver£¨£©ºÍRpcAsyncAddPrinterDriver£¨£©µÅ×ÃÓÚ×°Öñ¾µØ»òÔ¶³Ì´òÓ¡»úÇý¶¯·¨Ê½µÄWindows APIº¯ÊýÖжÌȱACL£¨½Ó¼û½ÚÔìÁÐ±í£©²é³Ôì³ÉµÄ¡£¡£¡£¡£¡£ÕâЩº¯Êý¶¼ÊÇͨ¹ý·ÖÆçµÄWindows APIʹÓ㬣¬£¬£¬£¬£¬ÈçÏ£º
AddPrinterDriverEx (SDK)
RpcAddPrinterDriver (MS-RPRN)
RpcAsyncAddPrinterDriver (MS-PAR)
ÀûÓø÷ì϶Äܹ»ÈƹýȨÏ޲鳣¬£¬£¬£¬£¬£¬½«¶ñÒâDLL×°Öõ½C:\Windows\System32\spool\driversÎļþ¼ÐÖУ¬£¬£¬£¬£¬£¬¶øºóͨ¹ý·ì϶¼ÓÔØÎª´òÓ¡Çý¶¯£¬£¬£¬£¬£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´Ðлò±¾µØÈ¨ÏÞÌáÉý¡£¡£¡£¡£¡£
0x02 º¹Çà»ØÊ×
2021Äê6ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬°²È«×êÑÐÈËÔ±ÔÚGitHubÉϹ«¿ªÁËÒ»¸öWindows Print SpoolerÔ¶³Ì´úÂëÖ´ÐÐ0day·ì϶£¨CVE-2021-34527£©¡£¡£¡£¡£¡£
±ØÒª°ÑÎȵÄÊÇ£¬£¬£¬£¬£¬£¬¸Ã·ì϶£¨CVE-2021-34527£©ÓëMicrosoft 6ÔÂ8ÈÕÐÇÆÚ¶þ²¹¶¡ÈÕÖн¨¸´²¢ÓÚ6ÔÂ21ÈÕ¸üеÄÒ»¸öEoPÉý¼¶µ½RCEµÄ·ì϶£¨CVE-2021-1675£©²»ÊÇͳһ¸ö·ì϶¡£¡£¡£¡£¡£ÕâÁ½¸ö·ì϶ÀàËÆµ«·ÖÆç£¬£¬£¬£¬£¬£¬¹¥»÷ÏòÁ¿Ò²·ÖÆç¡£¡£¡£¡£¡£
Ŀǰ¸Ã·ì϶ÒѾ¹«¿ªÅû¶£¬£¬£¬£¬£¬£¬²¢ÇÒÒѳʴ˿ÌÒ°ÀûÓᣡ£¡£¡£¡£µ± Windows Print Spooler ·þÎñ²»ÕýÈ·µØÖ´ÐÐÌØÈ¨Îļþ²Ù×÷ʱ£¬£¬£¬£¬£¬£¬´æÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ê¹Óà SYSTEM ȨÏÞÔËÐÐËÁÒâ´úÂë¡¢×°Ö÷¨Ê½¡¢²é¿´²¢¸ü¸Ä»òɾ³ýÊý¾Ý¡¢»ò´´½¨ÓµÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§£¬£¬£¬£¬£¬£¬µ«¹¥»÷±ØÐëÉæ¼°Å²Óà RpcAddPrinterDriverEx() µÄ¾¹ýÉí·ÝÑéÖ¤µÄÓû§¡£¡£¡£¡£¡£
0x03 ´ëÖý¨Òé
µÚÈý·½²¹¶¡·þÎñÍŶÓ0patchΪ CVE-2021-34527°ä²¼ÁËÒ»¸öÃâ·ÑµÄ΢²¹¶¡£¬£¬£¬£¬£¬£¬¾Ý°µÊ¾¸Ã²¹¶¡¿ÉÄÜ×èÖ¹Õë¶Ô´Ë·ì϶ÀûÓᣡ£¡£¡£¡£ÔÚ΢Èí°ä²¼×îÖÕ¸üÐÂ֮ǰ£¬£¬£¬£¬£¬£¬½¨ÒéÓû§×°Öà 0Patch µÄ΢²¹¶¡»ò½ûÓà Print Spooler ·þÎñ¡£¡£¡£¡£¡£
1.½ûÓà Print Spooler ·þÎñ£¨¿ÉÑ¡ÆäÒ»£©¡£¡£¡£¡£¡£
ʹÓÃÒÔÏ PowerShell ºÅÁ
Stop-Service -Name Spooler -Force
Set-Service -Name Spooler -StartupType Disabled
2. ͨ¹ý×éÕ½Êõ½ûÓÃÈëÕ¾Ô¶³Ì´òÓ¡£¡£¡£¡£¡£¨¿ÉÑ¡ÆäÒ»£©
ÔËÐÐ×éÕ½Êõ±à×ëÆ÷£¨Win+R¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬ÊäÈëgpedit.msc£¬£¬£¬£¬£¬£¬´ò¿ª×éÕ½Êõ±à×ëÆ÷£©£¬£¬£¬£¬£¬£¬Ë³´Î½øÈë£ºÍÆËã»úÅäÖÃ>ÖÎÀíÄ£°å>´òÓ¡»ú£¬£¬£¬£¬£¬£¬½ûÓá°ÔÊÐí´òÓ¡ºó¶Ü´¦Ö÷¨Ê½½ÓÊܿͻ§¶ËÏνӡ±Õ½ÊõÒÔ×èÖ¹Ô¶³Ì¹¥»÷¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://blog.0patch.com/2021/07/free-micropatches-for-printnightmare.html
0x04 ²Î¿¼Á´½Ó
https://github.com/afwu/PrintNightmare
https://www.bleepingcomputer.com/news/microsoft/microsofts-incomplete-printnightmare-patch-fails-to-fix-vulnerability/
https://blog.0patch.com/2021/07/free-micropatches-for-printnightmare.html
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527
0x05 ¹¦·òÏß
2021-07-01 Microsoft°ä²¼°²È«¹«¸æ
2021-07-02 VSRC°ä²¼°²È«¹«¸æ
2021-07-06 Microsoft°ä²¼°²È«¸üÐÂ
2021-07-08 VSRC¸üа²È«¹«¸æ
0x06 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ