Windows CryptoAPIÓÕÆ­Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-01-15

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-0601£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.1£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Windows 10 Version 1607

Windows 10 Version 1709

Windows 10 Version 1803

Windows 10 Version 1809

Windows 10 Version 1903

Windows 10 Version 1909

Windows Server2016

Windows Server 2019


Îó²î¸ÅÊö


2020Äê1ÔÂ14ÈÕ΢ÈíÐû²¼ÁËCVE-2020-0601Îó²îͨ¸æ£¬£¬£¬£¬£¬´ËÎó²îΪWindows¼ÓÃÜ¿âÖеÄÒ»¸öÒªº¦µÄÎó²î£¬£¬£¬£¬£¬Windows CryptoAPI(Crypt32.dll) ÑéÖ¤ÍÖÔ²ÇúÏß¼ÓÃÜ (ECC)Ö¤ÊéµÄ·½·¨Öб£´æÓÕÆ­Îó²î¡£¡£


¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÓÕÆ­ÐԵĴúÂëÊðÃûÖ¤Êé¶Ô¶ñÒâ¿ÉÖ´ÐÐÎļþ¾ÙÐÐÊðÃûÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬´Ó¶øÊ¹¸ÃÎļþËÆºõÀ´×Ô¿É¿¿µÄÕýµ±ÈªÔ´¡£¡£Óû§½«ÎÞ·¨ÖªµÀÎļþÊǶñÒâµÄ£¬£¬£¬£¬£¬ÓÉÓÚÊý×ÖÊðÃûËÆºõÀ´×ÔÊÜÐÅÈεÄÌṩ³ÌÐò¡£¡£ÀֳɵÄʹÓû¹¿ÉÒÔʹ¹¥»÷Õß¾ÙÐÐÖÐÐÄÈ˹¥»÷£¬£¬£¬£¬£¬²¢ÔÚÓëÊÜÓ°ÏìÈí¼þµÄÓû§ÅþÁ¬ÉϽâÃÜÉñÃØÐÅÏ¢¡£¡£


¸ÃÎó²îΪNSA×ÔÁ¦·¢Ã÷£¬£¬£¬£¬£¬²¢»ã±¨¸øÎ¢Èí¡£¡£Æ¾Ö¤NSAÀÖ³ÉʹÓôËÎó²î½«Ê¹¹¥»÷ÕßÄܹ»ÌṩÀ´×ÔÊÜÐÅÈÎʵÌåµÄ¶ñÒâ´úÂë¡£¡£ÆäÖаüÀ¨£ºÊðÃûµÄÎļþºÍµç×ÓÓʼþ¡¢ÊðÃû¿ÉÖ´ÐдúÂëµÈ¡¢HTTPsÅþÁ¬¡£¡£


ÖµµÃ×¢ÖØµÄÊÇÖ¸¶¨²ÎÊýµÄECCÃÜÔ¿Ö¤ÊéµÄWindows°æ±¾»áÊܵ½Ó°Ï죬£¬£¬£¬£¬¶øÕâÒ»»úÖÆ£¬£¬£¬£¬£¬×îÔçÓÉWIN10ÒýÈ룬£¬£¬£¬£¬Ó°ÏìWIN10£¬£¬£¬£¬£¬Windows Server 2016/2019°æ±¾£¬£¬£¬£¬£¬¶øÓÚ½ñÄê1ÔÂ14ÈÕ×èÖ¹Ç徲ά»¤µÄWIN7/Windows Server 2008ÓÉÓÚ²»Ö§³Ö´ø²ÎÊýµÄECCÃÜÔ¿£¬£¬£¬£¬£¬Òò´Ë²»ÊÜÏà¹ØÓ°Ï죬£¬£¬£¬£¬µ«ÈÔÈ»½¨ÒéÓû§½«WIN7/ Windows Server 2008ϵͳ¸üÐÂÖÁ×îеÄWIN10ϵͳ»òWindows Server2016Ö®ºóµÄ°æ±¾£¬£¬£¬£¬£¬²¢¸üÐÂÏà¹ØÇå¾²²¹¶¡¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ΢ÈíÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601¡£¡£


²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601

https://media.defense.gov/2020/Jan/14/2002234275/-1/-1/0/CSA-WINDOWS-10-CRYPT-LIB-20190114.PDF