ASUS ATK Package¿ÉÐÅ·¾¶´úÂëÖ´ÐÐÎó²î£¨CVE-2019-19235£©
Ðû²¼Ê±¼ä 2019-12-21

1.Åä¾°ÐÎò
SafeBreach LabsÔÚASUS ATKÈí¼þ°üÖз¢Ã÷ÁËÒ»¸öÎó²î£¨CVE-2019-19235£©£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚÌØÈ¨Àú³Ì£¨NT AUTHORITY\SYSTEM£©µÄÉÏÏÂÎÄÖÐÖ´ÐÐδÊðÃûµÄ¿ÉÖ´ÐÐÎļþ£¨exe£©£¬£¬£¬£¬´Ó¶øÈƹý¼ì²â²¢»ñµÃ³¤ÆÚÐÔ¡£¡£
2.Îó²îÁбí
CVE ID £º CVE-2019-19235
CVSSÆÀ·Ö£º ÔÝδÆÀ¶¨
Ó°Ïì¹æÄ££º ATK Package 1.0.0060¼°Ö®Ç°µÄËùÓа汾
3.Îó²îÏêÇé
»ªË¶ATKÈí¼þ°üÊÇԤװÖÃÔÚ»ªË¶PCÉϵÄÊÊÓù¤¾ß£¬£¬£¬£¬ÆäASLDRЧÀÍ£¨AsLdrSrv.exe£©ÒÔNT AUTHORITY\SYSTEMÌØÈ¨ÕË»§ÔËÐУ¬£¬£¬£¬¸ÃЧÀ͵ĿÉÖ´ÐÐÎļþÓÉ¡° ASUSTek Computer Inc.¡±ÊðÃû¡£¡£AsLdrSrv.exeÔÚÖ´ÐС°C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe¡±Îļþǰ£¬£¬£¬£¬»áÏȲéÕÒÒÔÏÂ3¸öɥʧµÄexeÎļþ¡£¡£
C:\Program.exe
C:\Program Files(x86)\ASUS\ATK.exe
C:\Program Files(x86)\ASUS\ATK Package\ATK.exe
Òò´Ë£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ½«í§ÒâδÊðÃûµÄEXEÎļþ¼ÓÔØ½øÕýµ±Àú³Ì²¢ÒÔNT AUTHORITY\SYSTEMÖ´ÐУ¨ÎÞÐè¸ü¸ÄЧÀ͵Ä·¾¶»òÁýÕÖÈκÎÎļþ£©¡£¡£
µ¼Ö¸ÃÎÊÌâµÄÔµ¹ÊÔÓÉÊÇAsLdrSrv.exeÊÔͼ´Ó׼ȷµÄ·¾¶¼ÓÔØHControl.exeʱ£¬£¬£¬£¬´æ´¢¸Ã·¾¶µÄATK_path»º³åÇøÄÚµÄ×Ö·û´®Ã»ÓмÓÒýºÅ£¬£¬£¬£¬ÓÉÓڸ÷¾¶±£´æ¿Õ¸ñ£¬£¬£¬£¬Ê¹µÃCreateProcessAsUserWº¯ÊýʵÑé×ÔÐÐÆÊÎö·¾¶£¬£¬£¬£¬Òò´Ë³ÌÐò»á²éÕÒÕâ3¸ö²»±£´æµÄexeÎļþ¡£¡£
4.ÐÞ¸´½¨Òé
½¨Òé¸üÐÂÖÁ×îа汾1.0.0061
5.²Î¿¼Á´½Ó
https://safebreach.com/Post/ASUS-ATK-Package-Unquoted-Search-Path-and-Potential-Abuses-CVE-2019-19235
https://nvd.nist.gov/vuln/detail/CVE-2019-19235
https://www.asus.com/Static_WebPage/ASUS-Product-Security-Advisory/


¾©¹«Íø°²±¸11010802024551ºÅ