¡¾·ì϶¹«¸æ¡¿.NET Core & Visual Studio ÐÅϢй¶·ì϶ (CVE-2021-41355)

°ä²¼¹¦·ò 2021-10-19


0x00 ·ì϶¸ÅÊö

CVE     ID

CVE-2021-41355

ʱ      ¼ä

2021-10-12

Àà      ÐÍ

ÐÅϢй¶

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ


Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È

µÍ

¿ÉÓÃÐÔ

ÎÞ

Óû§½»»¥

 ÊÇ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP


ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

2021Äê10ÔÂ12ÈÕ£¬£¬£¬£¬£¬ £¬£¬Î¢Èí½¨¸´ÁË .NET Core ºÍ Visual Studio ÖеÄÒ»¸öÐÅϢй¶·ì϶£¨CVE-2021-41355£©£¬£¬£¬£¬£¬ £¬£¬¸Ã·ì϶¿ÉÄܻᵼÖÂÆ¾Ö¤ÒÔÃ÷ÎÄ´ó¾Öй¶£¬£¬£¬£¬£¬ £¬£¬ÆäCVSSÆÀ·ÖΪ5.7£¬£¬£¬£¬£¬ £¬£¬Ó°ÏìÁË.NET 5.0¡¢Microsoft Visual Studio 2019 ºÍPowerShell 7.1¡£¡£¡£¡£¡£

½üÈÕ£¬£¬£¬£¬£¬ £¬£¬Î¢Èí°ä²¼Windows Defender ÀûÓ÷¨Ê½½ÚÔ찲ȫְÄÜÈÆ¹ý·ì϶£¨CVE-2020-0951£¬£¬£¬£¬£¬ £¬£¬ÓÚ2020Äê9ÔÂ8ÈÕ³õ´Î°ä²¼£©°²È«²¼¸æ£¬£¬£¬£¬£¬ £¬£¬¸Ã·ì϶¿ÉÄÜʹ¹¥»÷ÕßÈÆ¹ý WDAC ¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ö´Ðб» WDAC ×èÖ¹µÄ PowerShell ºÅÁî¡£¡£¡£¡£¡£µ«ÒªÀûÓø÷ì϶£¬£¬£¬£¬£¬ £¬£¬¹¥»÷Õß±ØÒªÔÚÔËÐÐPowerShellµÄ±¾µØ»úеÉÏÓÐÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£¶øºó£¬£¬£¬£¬£¬ £¬£¬¹¥»÷ÕßÄܹ»Ïνӵ½PowerShell»á»°£¬£¬£¬£¬£¬ £¬£¬²¢·¢ËͺÅÁîÀ´Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁËPowerShell 7.0ºÍ7.1°æ±¾¡£¡£¡£¡£¡£

PowerShell ÊÇÒ»¸ö¿çƽ̨µÄ¹¤×÷×Ô¶¯»¯½â¾ö¹æ»®£¬£¬£¬£¬£¬ £¬£¬ÓɺÅÁîÐÐ shell¡¢¾ç±¾Ëµ»°ºÍÅäÖÃÖÎÀí¿ò¼Ü×é³É¡£¡£¡£¡£¡£PowerShell Äܹ»ÔÚ Windows¡¢Linux ºÍ macOS ÉÏÔËÐÓ×£¡£¡£¡£¡£Windows Defender ÀûÓ÷¨Ê½½ÚÔ죨WDAC£©Ö¼ÔÚ±£» £»£»£» £»£»£»£»¤WindowsÉ豸ÃâÊÜDZÔڵĶñÒâÈí¼þÈëÇÖ£¬£¬£¬£¬£¬ £¬£¬È·±£Ö»ÓÐÊÜÐÅÀµµÄÀûÓ÷¨Ê½ºÍÇý¶¯·¨Ê½Äܹ»ÔËÐУ¬£¬£¬£¬£¬ £¬£¬´Ó¶ø×èÖ¹¶ñÒâÈí¼þºÍ²»±ØÒªµÄÈí¼þÆô¶¯¡£¡£¡£¡£¡£

Ŀǰ£¬£¬£¬£¬£¬ £¬£¬Redmond ÒѾ­°ä²¼ÁË PowerShell 7.0.8 ºÍ PowerShell 7.1.5£¬£¬£¬£¬£¬ £¬£¬ÒÔ½¨¸´ PowerShell 7 ºÍ PowerShell 7.1 ·ÖÖ§Öеݲȫ·ì϶CVE-2020-0951ºÍCVE-2021-41355¡£¡£¡£¡£¡£ÓÉÓÚ¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ìÏ¶ÈÆ¹ýWDACÇ¿ÔìÖ´Ðв¢»ñµÃ¶Ô´¿Îı¾Í´´¦µÄ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬ £¬£¬Î¢ÈíÒªÇóϵͳÖÎÀíԱΪPowerShell 7¸üв¹¶¡¡£¡£¡£¡£¡£

 

Ó°ÏìÁìÓò

Õâ2¸ö·ì϶ӰÏìÁËPowerShell 7µÄÒÔϰ汾£º

CVE-2021-41355£ºPowerShell 7.1

CVE-2020-0951£ºPowerShell 7.0 ¡¢PowerShell7.1

 

0x02 ´ëÖý¨Òé

ĿǰÕâЩ·ì϶ÒѾ­½¨¸´¡£¡£¡£¡£¡£Õë¶ÔPowerShell £¬£¬£¬£¬£¬ £¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§ÊµÊ±Éý¼¶¸üе½PowerShell 7.0.8 »ò PowerShell 7.1.5¡£¡£¡£¡£¡£Òª¼ì²âPowerShell 7 °æ±¾ÊÇ·ñÊܵ½Ó°Ï죬£¬£¬£¬£¬ £¬£¬ÇëÔÚPowershell´°¿ÚÖÐÊäÈëºÅÁ$PSVersionTable¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://github.com/PowerShell/PowerShell#get-powershell

 

0x03 ²Î¿¼Á´½Ó

https://github.com/PowerShell/Announcements/issues/27

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41355

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-0951

https://www.bleepingcomputer.com/news/microsoft/microsoft-asks-admins-to-patch-powershell-to-fix-wdac-bypass/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-10-19

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

CVSS£ºwww.first.org

NVD£ºnvd.nist.gov

 

0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬£¬ £¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png