´÷¶ûSupportAssist DLLÐ®ÖÆÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-25

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12280£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Dell SupportAssist for Business PCs°æ±¾2.0 £»

Dell SupportAssist for Home PCs 3.2.1¼°Ö®Ç°µÄËùÓа汾


Îó²î¸ÅÊö


6ÔÂ21ÈÕ´÷¶ûÐû²¼Ç徲ת´ï£¬±Þ²ßÓû§¸üд÷¶ûµçÄÔÉÏԤװÖõÄSupportAssistÈí¼þ£¬ÒÔÐÞ¸´DLLÐ®ÖÆÎó²î£¨CVE-2019-12280£© ¡£¸ÃÎó²î¿É±»¾ßÓÐͨÀýÓû§È¨Ï޵Ĺ¥»÷ÕßʹÓã¬Í¨¹ý¶ñÒâDLLÎļþ¾ÙÐÐÌáȨºÍ»ñµÃ³¤ÆÚÐÔ ¡£


SupportAssistÊÇ´÷¶ûµçÄÔÉÏԤװÖõÄÒ»¸öÈí¼þ£¬ÓÃÓÚ¼ì²éϵͳӲ¼þºÍÈí¼þµÄÔËÐÐ״̬£¬¸ÃÈí¼þÒÔSYSTEMȨÏÞÔËÐÐ ¡£Ñо¿Ö°Ô±·¢Ã÷¸ÃÈí¼þ±£´æDLLÐ®ÖÆÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß½«í§ÒâδÊðÃûµÄDLL¼ÓÔØµ½ÒÔSYSTEMȨÏÞÔËÐеķþÎñÖУ¬´Ó¶øÊµÏÖȨÏÞÌáÉýºÍ³¤ÆÚÐÔ - °üÀ¨¶ÔÎïÀíÄڴ桢ϵͳÖÎÀíBIOSµÈµ×²ã×é¼þµÄ¶Á/д»á¼û ¡£¸ÃÎó²îʹ¹¥»÷ÕßÄܹ»Í¨¹ýÒÑÊðÃûµÄ·þÎñ¼ÓÔØºÍÖ´ÐжñÒâpayload£¬¹¥»÷Õ߿ɽ«´ËÄÜÁ¦ÓÃÓÚÖ´ÐлòÌӱܼì²âµÈ²î±ðÄ¿µÄ£¬ÀýÈ磺ӦÓóÌÐò°×Ãûµ¥Èƹý¡¢ÊðÃûÑéÖ¤ÈÆ¹ý ¡£


¸ÃÎó²îµÄ»ù´¡Ôµ¹ÊÔ­ÓÉÊÇ£º


1¡¢È±·¦Çå¾²µÄDLL¼ÓÔØ ¡£´úÂëÖÐʹÓÃLoadLibraryWÒªÁ죬¶ø²»ÊÇLoadLibraryExW £»ÕâÔÊÐíδ¾­ÊÚȨµÄÓû§Í¨¹ýijЩ±ê¼ÇÀ´½ç˵ËÑË÷˳Ðò£¬ÀýÈçLOAD_LIBRARY_SEARCH_DLL_LOAD_DIR ¡£·´¹ýÀ´£¬¸Ã±ê¼ÇÓÖÏÞÖÆÖ»ÔÚ×Ô¼ºµÄÎļþ¼ÐÖÐËÑË÷DLL£¬×èÖ¹ÁËÔÚPATH±äÁ¿ÖÐËÑË÷DLLµÄÇéÐÎ ¡£


2¡¢Ã»ÓжԶþ½øÖÆÎļþ¾ÙÐÐÊðÃûÑéÖ¤ ¡£¸Ã³ÌÐòûÓÐÑéÖ¤Ëü½«¼ÓÔØµÄDLLÊÇ·ñÒÑÊðÃû£¬Òò´ËËü½«¼ÓÔØí§ÒâδÊðÃûµÄDLL ¡£


ÓÉÓÚ´÷¶ûSupportAssistʹÓõÄ×é¼þÊÇÓɵÚÈý·½PC-Doctor¿ª·¢ºÍά»¤µÄ£¬Òò´Ë¸ÃÎó²îÒ²Ó°Ïìµ½ÒÀÀµPC-DoctorµÄÆäËüPCÖÆÔìÉÌ ¡£È·ÈÏÊÜÓ°ÏìµÄ×é¼þÊÇPC-Doctor Toolbox for Windows£¬¸Ã×é¼þ±»ÒÔϹ¤¾ßËùʹÓãº


CORSAIR ONE Diagnostics
CORSAIR Diagnostics
Staples EasyTech Diagnostics
Tobii I-Series Diagnostic Tool
Tobii Dynavox Diagnostic Tool

Îó²îÑéÖ¤


POC£ºhttps://safebreach.com/Post/OEM-Software-Puts-Multiple-Laptops-At-Risk ¡£


ÐÞ¸´½¨Òé


½¨Òé´÷¶ûÓû§¸üÐÂÖÁÒÔϰ汾£º


Dell SupportAssist for Business PCs °æ±¾2.0.1

Dell SupportAssist for Home PCs °æ±¾3.2.2


²Î¿¼Á´½Ó


https://www.dell.com/support/article/cn/zh/cndhs1/sln317291/dsa-2019-084-dell-supportassist-for-business-pcs-and-dell-supportassist-for-home-pcs-security-update-for-pc-doctor-vulnerability?lang=en