CVE-2019-1458 | Win32kÌØÈ¨ÌáÉýÎó²î
Ðû²¼Ê±¼ä 2019-12-12

1.Åä¾°ÐÎò
¿ËÈÕMicrosoftÐû²¼ÁËÕë¶Ô36¸öCVEÎó²îµÄÁ½¸öͨ¸æºÍ¸üС£¡£¡£ÔÚÕâЩÎó²îÖУ¬£¬ÓÐ7¸ö±»·ÖÀàΪÑÏÖØ£¬£¬27¸ö±»·ÖÀàΪÖ÷Òª£¬£¬1¸ö±»·ÖÀàΪÖУ¬£¬1¸ö±»·ÖÀàΪµÍ¡£¡£¡£²¢ÇÒCVE-2019-1458Îó²îÒѱ»Ê¹Óᣡ£¡£
½üÆÚ¿¨°Í˹»ù¼ì²âµ½µÄ¹¥»÷ÊÂÎñ³ÆOperation WizardÔÚ¹¥»÷Àú³ÌÖÐʹÓÃÁËWindowsÎó²î£¨CVE-2019-1458£©ºÍGoogle ChromeÎó²î£¨CVE-2019-13720£©£¬£¬½«¶ñÒâÈí¼þÏÂÔØ²¢×°Öõ½»á¼ûº«ÓïÐÂÎÅÃÅ»§µÄWindowsÅÌËã»úÉÏ¡£¡£¡£
2.Îó²îÏêÇé
CVE-2019-1458ÊÇWin32kÖеÄÌØÈ¨ÌáÉýÎó²î£¬£¬Win32k×é¼þÎÞ·¨×¼È·´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ£¬£¬µ¼ÖÂWindowsÖб£´æÒ»¸öÌØÈ¨ÌáÉýÎó²î¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄÚºËģʽÏÂÔËÐÐí§Òâ´úÂë¡£¡£¡£È»ºó¹¥»÷Õß¿ÉÄÜ»á×°ÖóÌÐò¡¢Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£
ҪʹÓôËÎó²î£¬£¬¹¥»÷ÕßÊ×ÏȱØÐèµÇ¼ϵͳ¡£¡£¡£¹¥»÷Õß¿ÉÄÜÔËÐпÉÒÔʹÓôËÎó²î²¢¿ØÖÆÊÜÓ°ÏìϵͳµÄÌØÖÆÓ¦ÓóÌÐò¡£¡£¡£
ÁíÍâGoogleÎó²îÖ®CVE-2019-13720ÒѾÔÚChrome 78.0.3904.87ÖÐÐÞ¸´£¬£¬¿¨°Í˹»ù½«ChromeÎó²î¼ì²âΪExploit.Win32.Generic£¬£¬½«MicrosoftÎó²î¼ì²âΪPDM£ºExploit.Win32.Generic¡£¡£¡£
3.ÐÞ¸´½¨Òé
ÏÖÔÚ΢Èí¹Ù·½ÒѾÐû²¼¸ÃÎó²îµÄ²¹¶¡£¬£¬½¨ÒéÓû§¸üе½×îа汾£¬£¬ÒÔïÔ̹¥»÷µÄ¿ÉÄÜÐÔ¡£¡£¡£
4.²Î¿¼Á´½Ó
https://securelist.com/windows-0-day-exploit-cve-2019-1458-used-in-operation-wizardopium/95432/
https://www.bleepingcomputer.com/news/security/windows-chrome-zero-days-chained-in-operation-wizardopium-attacks/
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1458


¾©¹«Íø°²±¸11010802024551ºÅ