Windows JScript ×é¼þ0day Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-06-01Îó²î±àºÅ
CVEÔÝÎÞ
Îó²î¼¶±ð
ÖÐ
³§ÉÌ×ÔÆÀ£º6.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Îó²îÐÎò
¿ËÈÕ£¬windowsϵͳÓÖ·¢Ã÷Ò»Æð0dayÎó²î£¬¸ÃÎó²îÊÇÓÉϵͳÖеÄJScript×é¼þÔì³ÉµÄ£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÓû§µÄPCÉÏÖ´ÐжñÒâ´úÂ룬 ËäȻ΢Èí²¢Î´ÌṩÍýÏëÍÆ³ö²¹¶¡¼òÖ±ÇÐʱ¼ä±í£¬µ«Ò»Î»½²»°ÈËÅú×¢ËûÃÇÕýÔÚ¾ÙÐÐÐÞ¸´¡£
5ÔÂ29ÈÕ£¬ZDIÐû²¼ÁËÒ»·Ý±¨¸æ£¬ÆäÖаüÀ¨ÓйظùýʧµÄÏêϸÊÖÒÕϸ½Ú£º
ÓÉÓÚ¸ÃÎó²îÓ°Ïì JScript ×é¼þ£¨Î¢Èí×Ô½ç˵µÄ JavaScript Ö´ÐУ©£¬Î¨Ò»µÄÌõ¼þ¾ÍÊǹ¥»÷Õß±ØÐèÓÕÆÓû§»á¼ûÒ»¸ö¶ñÒâÍøÒ³»òÕßÔÚϵͳÉÏÏÂÔØ²¢·¿ª¶ñÒâ JS Îļþ£¨Ò»Ñùƽ³£¾ÓÉ Windows Script Host-wscript.exe Ö´ÐУ©¡£
Õâ¸öȱÏݱ£´æÓÚ JScript ¶Ô Error ¹¤¾ßµÄ´¦Öóͷ£Àú³ÌÖС£¹¥»÷Õßͨ¹ýÔÚJScript ÖÐÖ´ÐÐÐж¯£¬Äܹ»µ¼ÖÂij¸öÖ¸ÕëÔÚÊͷźóÔâÖØÓ᣹¥»÷ÕßÄÜʹÓøÃÎó²îÔÚÄ¿½ñÀú³ÌÏÂÖ´ÐдúÂë¡£
¸ÃÎó²îµÄΣÏÕϵÊý²¢Ã»ÓÐÌýÉÏÈ¥µÄÄÇô¸ß£¬ÓÉÓÚËüÎÞ·¨µ¼ÖÂϵͳÔâÍêÈ«¹¥ÏÝ¡£Õâ¸öȱÏݽöÔÊÐíɳÏäÇéÐÎÖеĴúÂëÖ´ÐÐÎÊÌâ¡£¹¥»÷ÕßÐèÒªÆäËüʹÓòŻªÌÓÀëɳÏä²¢ÔÚÄ¿µÄϵͳÉÏÖ´ÐдúÂë¡£
΢ÈíÕýÔÚÍÆ³ö²¹¶¡£¬²»¹ýÒѾÁè¼ÝÁËÅû¶սÂÔÉèÖõÄʱ¼äÖá¡£
ͨ³£ÔÚÅû¶ȱÏݺó¸øÓè³§ÉÌ120ÌìµÄʱ¼äÐû²¼²¹¶¡¡£´Ó΢Èí»Ö¸´µÄʱ¼äÖáÀ´¿´£¬Î¢ÈíÄÑÒÔ¸´ÏÖ´¥·¢¸ÃÎó²îµÄ PoC ´úÂ룬´Ó¶øÆÆ·ÑÁË75%µÄÅû¶ʱ¼äÖᣬµ¼Ö¹¤³ÌʦÎÞ·¨ÊµÊ±¸ÏÔÚ5ÔµIJ¹¶¡ÐÇÆÚ¶þ²âÊÔ²¢Ðû²¼²¹¶¡¡£
ËäȻ΢Èí²¢Î´Ìá¹©ÍÆ³ö²¹¶¡µÄÏêϸʱ¼äÖᣬµ«Î¢ÈíµÄÒ»Ãû½²»°ÈË֤ʵ³ÆÕýÔÚÍÆ³öÐÞ¸´¼Æ»®¡£
ÔÚÅû¶Îó²î֮ʱ²¢Î´·¢Ã÷Îó²îÔâʹÓõÄÇéÐΡ£ÓÉÓÚÍøÉÏÏÕЩ²»±£´æÊÖÒÕÏêÇ飬Òò´ËÔÚ΢ÈíÐû²¼ÐÞ¸´¼Æ»®Ç°ºÜ¿ÉÄÜÕÕ¾ÉδÔâʹÓõÄÇéÐΡ£
½â¾ö²½·¥
½¨ÒéÓû§²»ÒªÊ¹ÓÃÒÀÀµ JScript ×é¼þµÄÓ¦ÓÃÈç IE ä¯ÀÀÆ÷¡¢wscript.exe µÈÀ´´¦Öóͷ£²»ÊÜÐÅÍÐµÄ JS ´úÂë»òÎļþ¡£
²Î¿¼×ÊÁÏ
https://www.zerodayinitiative.com/advisories/ZDI-18-534/
https://www.bleepingcomputer.com/news/security/remote-code-execution-vulnerability-disclosed-in-windows-jscript-component/


¾©¹«Íø°²±¸11010802024551ºÅ