Windows CryptoAPIÓÕÆÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-01-15Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-0601£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.1£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Windows 10 Version 1607
Windows 10 Version 1709
Windows 10 Version 1803
Windows 10 Version 1809
Windows 10 Version 1903
Windows 10 Version 1909
Windows Server2016
Windows Server 2019
Îó²î¸ÅÊö
2020Äê1ÔÂ14ÈÕ΢ÈíÐû²¼ÁËCVE-2020-0601Îó²îͨ¸æ£¬´ËÎó²îΪWindows¼ÓÃÜ¿âÖеÄÒ»¸öÒªº¦µÄÎó²î£¬Windows CryptoAPI(Crypt32.dll) ÑéÖ¤ÍÖÔ²ÇúÏß¼ÓÃÜ (ECC)Ö¤ÊéµÄ·½·¨Öб£´æÓÕÆÎó²î¡£
¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÓÕÆÐԵĴúÂëÊðÃûÖ¤Êé¶Ô¶ñÒâ¿ÉÖ´ÐÐÎļþ¾ÙÐÐÊðÃûÀ´Ê¹ÓôËÎó²î£¬´Ó¶øÊ¹¸ÃÎļþËÆºõÀ´×Ô¿É¿¿µÄÕýµ±ÈªÔ´¡£Óû§½«ÎÞ·¨ÖªµÀÎļþÊǶñÒâµÄ£¬ÓÉÓÚÊý×ÖÊðÃûËÆºõÀ´×ÔÊÜÐÅÍеÄÌṩ³ÌÐò¡£ÀֳɵÄʹÓû¹¿ÉÒÔʹ¹¥»÷Õß¾ÙÐÐÖÐÐÄÈ˹¥»÷£¬²¢ÔÚÓëÊÜÓ°ÏìÈí¼þµÄÓû§ÅþÁ¬ÉϽâÃÜÉñÃØÐÅÏ¢¡£
¸ÃÎó²îΪNSA×ÔÁ¦·¢Ã÷£¬²¢»ã±¨¸øÎ¢Èí¡£Æ¾Ö¤NSAÀÖ³ÉʹÓôËÎó²î½«Ê¹¹¥»÷ÕßÄܹ»ÌṩÀ´×ÔÊÜÐÅÍÐʵÌåµÄ¶ñÒâ´úÂë¡£ÆäÖаüÀ¨£ºÊðÃûµÄÎļþºÍµç×ÓÓʼþ¡¢ÊðÃû¿ÉÖ´ÐдúÂëµÈ¡¢HTTPsÅþÁ¬¡£
ÖµµÃ×¢ÖØµÄÊÇÖ¸¶¨²ÎÊýµÄECCÃÜÔ¿Ö¤ÊéµÄWindows°æ±¾»áÊܵ½Ó°Ï죬¶øÕâÒ»»úÖÆ£¬×îÔçÓÉWIN10ÒýÈ룬ӰÏìWIN10£¬Windows Server 2016/2019°æ±¾£¬¶øÓÚ½ñÄê1ÔÂ14ÈÕ×èÖ¹Ç徲ά»¤µÄWIN7/Windows Server 2008ÓÉÓÚ²»Ö§³Ö´ø²ÎÊýµÄECCÃÜÔ¿£¬Òò´Ë²»ÊÜÏà¹ØÓ°Ï죬µ«ÈÔÈ»½¨ÒéÓû§½«WIN7/ Windows Server 2008ϵͳ¸üÐÂÖÁ×îеÄWIN10ϵͳ»òWindows Server2016Ö®ºóµÄ°æ±¾£¬²¢¸üÐÂÏà¹ØÇå¾²²¹¶¡¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ΢ÈíÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601¡£
²Î¿¼Á´½Ó
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601
https://media.defense.gov/2020/Jan/14/2002234275/-1/-1/0/CSA-WINDOWS-10-CRYPT-LIB-20190114.PDF


¾©¹«Íø°²±¸11010802024551ºÅ