BitdefenderÃâ·Ñ°æÉ±¶¾Èí¼þÖеÄÌáȨÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-23

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-15295£¬£¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.9£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Bitdefender Antivirus Free 2020


Îó²î¸ÅÊö


Bitdefender EnginesÊÇÂÞÂíÄáÑDZÈÌØèóµÂ£¨Bitdefender£©¹«Ë¾µÄÒ»¿îɱ¶¾Èí¼þÒýÇæ¡£¡£¡£¡£¡£


Bitdefender Antivirus Ãâ·Ñ°æ±¾Öб»ÆØÒ»¸öÌáȨÎó²î£¬£¬¿Éµ¼Ö¹¥»÷Õß»ñȡΪ Windows ×î¸ßȨÏÞÕË»§×¼±¸µÄϵͳ¼¶±ðȨÏÞ¡£¡£¡£¡£¡£


¸ÃÎó²îÔ´ÓÚȱ·¦¶ÔÒÑÊðÃûÇÒ¼ÓÔØ×Ô¿ÉÐÅλÖõĶþ½øÖƵÄÑéÖ¤Ôì³ÉµÄ¡£¡£¡£¡£¡£Bitdefender µÄÇ徲ЧÀÍ (vsserv.exe) ºÍ¸üÐÂЧÀÍ (updatesrv.exe) ×÷ΪÒÔϵͳȨÏÞÊðÃûµÄÀú³Ì¶øÆô¶¯¡£¡£¡£¡£¡£È»¶ø£¬£¬ËûÃÇʵÑéÔÚ PATH ÇéÐαäÁ¿ÖеĶà¸öλÖüÓÔØÉ¥Ê§µÄÒ»¸ö DLL Îļþ (¡®RestartWatchDog.dll¡¯)£¬£¬ÈçͼËùʾ£º


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÆäÖÐÒ»¸öλÖÃÊÇ¡®c:/python27¡¯£¬£¬ËüÏòËùÓÐÈÏÖ¤Óû§¿ª·ÅÁË»á¼û¿ØÖÆÁбí (ACL)£¬£¬Ê¹ÌáȨ²Ù×÷ÍòÎÞһʧ£¬£¬ÓÉÓÚÕý³£È¨ÏÞµÄÓû§Äܹ»Ð´ÈëɥʧµÄ DLL²¢Í¨¹ý Bitdefender µÄÊðÃûÀú³Ì¼ÓÔØËü¡£¡£¡£¡£¡£ÎÊÌâµÄ¸ùÒòÔÚÓÚServiceInstance.dll ¿âÊÔͼ¼ÓÔØÉ¥Ê§µÄ DLL¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ£¬£¬¹Ù·½ÒÑÐû²¼ÁËÐÞ¸´¸ÃÎó²î£¬£¬ÏÂÔØÁ´½Ó£º


https://www.bitdefender.com/support/security-advisories/untrusted-search-path-vulnerability-serviceinstance-dll-bitdefender-antivirus-free-2020/¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/security/bitdefender-fixes-privilege-escalation-bug-in-free-antivirus-2020/