CVE-2019-1458 | Win32kÌØÈ¨ÌáÉýÎó²î

Ðû²¼Ê±¼ä 2019-12-12


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


1.Åä¾°ÐÎò


¿ËÈÕMicrosoftÐû²¼ÁËÕë¶Ô36¸öCVEÎó²îµÄÁ½¸öͨ¸æºÍ¸üС£ÔÚÕâЩÎó²îÖУ¬ÓÐ7¸ö±»·ÖÀàΪÑÏÖØ£¬27¸ö±»·ÖÀàΪÖ÷Òª£¬1¸ö±»·ÖÀàΪÖУ¬1¸ö±»·ÖÀàΪµÍ¡£²¢ÇÒCVE-2019-1458Îó²îÒѱ»Ê¹Óá£

½üÆÚ¿¨°Í˹»ù¼ì²âµ½µÄ¹¥»÷ÊÂÎñ³ÆOperation WizardÔÚ¹¥»÷Àú³ÌÖÐʹÓÃÁËWindowsÎó²î£¨CVE-2019-1458£©ºÍGoogle ChromeÎó²î£¨CVE-2019-13720£©£¬½«¶ñÒâÈí¼þÏÂÔØ²¢×°Öõ½»á¼ûº«ÓïÐÂÎÅÃÅ»§µÄWindowsÅÌËã»úÉÏ¡£


2.Îó²îÏêÇé


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


CVE-2019-1458ÊÇWin32kÖеÄÌØÈ¨ÌáÉýÎó²î£¬Win32k×é¼þÎÞ·¨×¼È·´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ£¬µ¼ÖÂWindowsÖб£´æÒ»¸öÌØÈ¨ÌáÉýÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄÚºËģʽÏÂÔËÐÐí§Òâ´úÂ롣Ȼºó¹¥»÷Õß¿ÉÄÜ»á×°ÖóÌÐò¡¢Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£

ҪʹÓôËÎó²î£¬¹¥»÷ÕßÊ×ÏȱØÐèµÇ¼ϵͳ¡£¹¥»÷Õß¿ÉÄÜÔËÐпÉÒÔʹÓôËÎó²î²¢¿ØÖÆÊÜÓ°ÏìϵͳµÄÌØÖÆÓ¦ÓóÌÐò¡£

ÁíÍâGoogleÎó²îÖ®CVE-2019-13720ÒѾ­ÔÚChrome 78.0.3904.87ÖÐÐÞ¸´£¬¿¨°Í˹»ù½«ChromeÎó²î¼ì²âΪExploit.Win32.Generic£¬½«MicrosoftÎó²î¼ì²âΪPDM£ºExploit.Win32.Generic¡£


3.ÐÞ¸´½¨Òé


ÏÖÔÚ΢Èí¹Ù·½ÒѾ­Ðû²¼¸ÃÎó²îµÄ²¹¶¡£¬½¨ÒéÓû§¸üе½×îа汾£¬ÒÔïÔÌ­¹¥»÷µÄ¿ÉÄÜÐÔ¡£



4.²Î¿¼Á´½Ó


https://securelist.com/windows-0-day-exploit-cve-2019-1458-used-in-operation-wizardopium/95432/

https://www.bleepingcomputer.com/news/security/windows-chrome-zero-days-chained-in-operation-wizardopium-attacks/

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1458