Win10´æÔÚµ±µØÌáȨ0day©¶´

Ðû²¼Ê±¼ä 2018-08-30
Ò»¡¢Â©¶´ÃèÊö


        2018Äê8ÔÂ27ÈÕ £¬Äþ¾²Ñо¿ÈËÔ±ÔÚTwitterÉÏÅû¶ÁËWindows 10ϵͳÖеÄÒ»¸ö0day©¶´¡£¸Ã©¶´ÊÇÒ»¸öµ±µØÌáȨ©¶´ £¬´æÔÚÓÚWindowsµÄÈÎÎñµ÷ÖηþÎñÖÐ £¬ÔÊÐí¹¥»÷Õß´ÓUSERȨÏÞÌáȨµ½SYSTEMȨÏÞ¡£Î¢Èí¹Ù·½Ä¿Ç°»¹Ã»ÓÐÌṩÏàÓ¦µÄ²¹¶¡¡£


¶þ¡¢Â©¶´Ó°Ï췶Χ


        Windows 10


        Windows Server 2016


Èý¡¢Â©¶´·ÖÎö


        Microsoft WindowsϵͳµÄÈÎÎñµ÷ÖηþÎñÖи߼¶µ±µØ¹ý³Ìµ÷Óã¨ALPC£©½Ó¿Ú´æÔÚµ±µØÌáȨ©¶´ £¬¸Ã©¶´´æÔÚÓÚschedsvc.dllÄ£¿éÖеÄSchRpcSetSecurityº¯Êý £¬SchRpcSetSecurityº¯Êý½ç˵ÈçÏ £¬º¯Êý¹¦Ð§ÊÇÉèÖÃÄþ¾²ÃèÊö·û¡£


 HRESULT SchRpcSetSecurity(


   [in, string] const wchar_t* path,


   [in, string] const wchar_t* sddl,


   [in] DWORD flags


 );


        SchRpcSetSecurityµÚÒ»¸ö²ÎÊýΪ·¾¶path £¬µÚ¶þ¸ö²ÎÊýΪÄþ¾²ÃèÊö·û½ç˵ÓïÑÔ (SDDL) ×Ö·û´®sddl £¬¸Ãº¯ÊýÄÚ²¿µ÷ÓÃÁËSetSecurity::RpcServerº¯Êý¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



        SetSecurity::RpcServerº¯ÊýÊ×Ïȵ÷ÓÃConvertStringSecurityDescriptorToSecurityDescriptor ½«SchRpcSetSecurityº¯Êý´«ÈëµÄsddl×Ö·û´®×ª»»ÎªÄþ¾²ÃèÊö·ûSecurityDescriptor¡£²¢µ÷ÓÃTaskPathCanonicalizeº¯Êý¶Ô´«Èëpath²ÎÊý·¾¶¹æ·¶»¯ÎªDst¡£



¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


        È»ºó»ñÈ¡Dst·¾¶µÄJobSecurityÄþ¾²ÃèÊö·ûpSecurityDescriptor £¬¼Ì¶øµ÷ÓÃJobSecurity::Updateº¯Êý £¬´«ÈëSecurityDescriptor²ÎÊý £¬¸üÐÂpSecurityDescriptor¡£



¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


        ×îºó £¬µ÷ÓÃJobSecurity::AddRemovePrincipalAceº¯ÊýÉèÖÃDACL¡£



¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


        ÄÇôÈçºÎÐÞ¸ÄÖ¸¶¨Ä¿±êÎļþµÄDACLÊôÐÔÄØ£¿Ê×ÏÈ £¬Ê¹ÓÃZwSetInformationFileº¯ÊýΪĿ±êÎļþ´´½¨Ó²Á´½Ó¡£È»ºó £¬µ÷ÓÃ_SchRpcSetSecurityº¯ÊýÉèÖÃÓ²Á´½ÓÎļþµÄDACL £¬µÈͬÓÚÐÞ¸ÄÄ¿±êÎļþµÄDACL¡£Í¨¹ýÉèÖÃSchRpcSetSecurityµÄµÚ3¸ö²ÎÊý £¬¿ÉÒÔΪÓû§Administrators(BA)¡¢Authenticated Users£¨AU£©Ìí¼Ó¶ÔÓ²Á´½ÓÎļþµÄдÈëȨÏÞ¡£


        ÒÔPrintConfig.dllÎļþΪÀý £¬µ÷ÓÃSchRpcSetSecurityº¯ÊýÇ° £¬Îļþ·ÃÎÊȨÏÞÈçÏ £¬´ËʱAdministrators²»¾ßÓжÔÎļþµÄдÈëȨÏÞ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



        µ÷ÓÃSchRpcSetSecurityº¯Êýºó £¬ÎļþµÄȨÏÞÈçÏ £¬´ËʱAdministratorsºÍAuthenticated Users¶¼ÓµÓжÔÎļþдÈëȨÏÞ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



        ÓÉÓÚSchRpcSetSecurityº¯Êý´æÔÚÄþ¾²Ñé֤ȱÏÝ £¬Ê¹Ç¡µ±Ç°Óû§¿ÉÐÞ¸ÄÖ»¶ÁÎļþµÄDACL £¬Ìí¼ÓдÈëȨÏÞ¡£ÀÖ³ÉÀûÓø鶴µÄ½á¹ûÈçÏÂͼ¡£



¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ËÄ¡¢Äþ¾²½¨Òé


        ²»ÒªÔËÐÐδ֪À´Ô´µÄ·¨Ê½£»


?     ÔÚ΢Èí¸üв¹¶¡ºó £¬¼°Ê±°²×°²¹¶¡¡£


Îå¡¢²Î¿¼Á´½Ó


https://thehackernews.com/2018/08/windows-zero-day-exploit.html


https://www.kb.cert.org/vuls/id/906424