BitdefenderÃâ·Ñ°æÉ±¶¾Èí¼þÖеÄÌáȨÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-23

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-15295£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.9£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Bitdefender Antivirus Free 2020


Îó²î¸ÅÊö


Bitdefender EnginesÊÇÂÞÂíÄáÑDZÈÌØèóµÂ£¨Bitdefender£©¹«Ë¾µÄÒ»¿îɱ¶¾Èí¼þÒýÇæ¡£


Bitdefender Antivirus Ãâ·Ñ°æ±¾Öб»ÆØÒ»¸öÌáȨÎó²î£¬¿Éµ¼Ö¹¥»÷Õß»ñȡΪ Windows ×î¸ßȨÏÞÕË»§×¼±¸µÄϵͳ¼¶±ðȨÏÞ¡£


¸ÃÎó²îÔ´ÓÚȱ·¦¶ÔÒÑÊðÃûÇÒ¼ÓÔØ×Ô¿ÉÐÅλÖõĶþ½øÖƵÄÑéÖ¤Ôì³ÉµÄ¡£Bitdefender µÄÇå¾²·þÎñ (vsserv.exe) ºÍ¸üзþÎñ (updatesrv.exe) ×÷ΪÒÔϵͳȨÏÞÊðÃûµÄÀú³Ì¶øÆô¶¯¡£È»¶ø£¬ËûÃÇʵÑéÔÚ PATH ÇéÐαäÁ¿ÖеĶà¸öλÖüÓÔØÉ¥Ê§µÄÒ»¸ö DLL Îļþ (¡®RestartWatchDog.dll¡¯)£¬ÈçͼËùʾ£º


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÆäÖÐÒ»¸öλÖÃÊÇ¡®c:/python27¡¯£¬ËüÏòËùÓÐÈÏÖ¤Óû§¿ª·ÅÁË»á¼û¿ØÖÆÁбí (ACL)£¬Ê¹ÌáȨ²Ù×÷ÍòÎÞһʧ£¬ÓÉÓÚÕý³£È¨ÏÞµÄÓû§Äܹ»Ð´ÈëɥʧµÄ DLL²¢Í¨¹ý Bitdefender µÄÊðÃûÀú³Ì¼ÓÔØËü¡£ÎÊÌâµÄ¸ùÒòÔÚÓÚServiceInstance.dll ¿âÊÔͼ¼ÓÔØÉ¥Ê§µÄ DLL¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ£¬¹Ù·½ÒÑÐû²¼ÁËÐÞ¸´¸ÃÎó²î£¬ÏÂÔØÁ´½Ó£º


https://www.bitdefender.com/support/security-advisories/untrusted-search-path-vulnerability-serviceinstance-dll-bitdefender-antivirus-free-2020/¡£


²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/security/bitdefender-fixes-privilege-escalation-bug-in-free-antivirus-2020/