CVE-2019-1458 | Win32kÌØÈ¨ÌáÉýÎó²î
Ðû²¼Ê±¼ä 2019-12-12

1.Åä¾°ÐÎò
¿ËÈÕMicrosoftÐû²¼ÁËÕë¶Ô36¸öCVEÎó²îµÄÁ½¸öͨ¸æºÍ¸üС£ÔÚÕâЩÎó²îÖУ¬ÓÐ7¸ö±»·ÖÀàΪÑÏÖØ£¬27¸ö±»·ÖÀàΪÖ÷Òª£¬1¸ö±»·ÖÀàΪÖУ¬1¸ö±»·ÖÀàΪµÍ¡£²¢ÇÒCVE-2019-1458Îó²îÒѱ»Ê¹Óá£
½üÆÚ¿¨°Í˹»ù¼ì²âµ½µÄ¹¥»÷ÊÂÎñ³ÆOperation WizardÔÚ¹¥»÷Àú³ÌÖÐʹÓÃÁËWindowsÎó²î£¨CVE-2019-1458£©ºÍGoogle ChromeÎó²î£¨CVE-2019-13720£©£¬½«¶ñÒâÈí¼þÏÂÔØ²¢×°Öõ½»á¼ûº«ÓïÐÂÎÅÃÅ»§µÄWindowsÅÌËã»úÉÏ¡£
2.Îó²îÏêÇé
CVE-2019-1458ÊÇWin32kÖеÄÌØÈ¨ÌáÉýÎó²î£¬Win32k×é¼þÎÞ·¨×¼È·´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ£¬µ¼ÖÂWindowsÖб£´æÒ»¸öÌØÈ¨ÌáÉýÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄÚºËģʽÏÂÔËÐÐí§Òâ´úÂ롣Ȼºó¹¥»÷Õß¿ÉÄÜ»á×°ÖóÌÐò¡¢Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£
ҪʹÓôËÎó²î£¬¹¥»÷ÕßÊ×ÏȱØÐèµÇ¼ϵͳ¡£¹¥»÷Õß¿ÉÄÜÔËÐпÉÒÔʹÓôËÎó²î²¢¿ØÖÆÊÜÓ°ÏìϵͳµÄÌØÖÆÓ¦ÓóÌÐò¡£
ÁíÍâGoogleÎó²îÖ®CVE-2019-13720ÒѾÔÚChrome 78.0.3904.87ÖÐÐÞ¸´£¬¿¨°Í˹»ù½«ChromeÎó²î¼ì²âΪExploit.Win32.Generic£¬½«MicrosoftÎó²î¼ì²âΪPDM£ºExploit.Win32.Generic¡£
3.ÐÞ¸´½¨Òé
ÏÖÔÚ΢Èí¹Ù·½ÒѾÐû²¼¸ÃÎó²îµÄ²¹¶¡£¬½¨ÒéÓû§¸üе½×îа汾£¬ÒÔïÔ̹¥»÷µÄ¿ÉÄÜÐÔ¡£
4.²Î¿¼Á´½Ó
https://securelist.com/windows-0-day-exploit-cve-2019-1458-used-in-operation-wizardopium/95432/
https://www.bleepingcomputer.com/news/security/windows-chrome-zero-days-chained-in-operation-wizardopium-attacks/
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1458


¾©¹«Íø°²±¸11010802024551ºÅ