¡¾Â©¶´Í¨¸æ¡¿.NET Core & Visual Studio ÐÅϢ鶩¶´ (CVE-2021-41355)

Ðû²¼Ê±¼ä 2021-10-19


0x00 ©¶´¸ÅÊö

CVE     ID

CVE-2021-41355

ʱ      ¼ä

2021-10-12

Àà      ÐÍ

ÐÅϢй¶

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ


Ó°Ï췶Χ


¹¥»÷ÅÓ´ó¶È

µÍ

¿ÉÓÃÐÔ

ÎÞ

Óû§½»»¥

 ÊÇ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP


ÔÚÒ°ÀûÓÃ


 

0x01 ©¶´ÏêÇé

image.png

2021Äê10ÔÂ12ÈÕ£¬Î¢ÈíÐÞ¸´ÁË .NET Core ºÍ Visual Studio ÖеÄÒ»¸öÐÅϢ鶩¶´£¨CVE-2021-41355£©£¬¸Ã©¶´¿ÉÄܻᵼÖÂƾ֤ÒÔÃ÷ÎÄÐÎʽй¶£¬ÆäCVSSÆÀ·ÖΪ5.7£¬Ó°ÏìÁË.NET 5.0¡¢Microsoft Visual Studio 2019 ºÍPowerShell 7.1¡£

½üÈÕ£¬Î¢ÈíÐû²¼Windows Defender Ó¦Ó÷¨Ê½¿ØÖÆÄþ¾²¹¦Ð§Èƹý©¶´£¨CVE-2020-0951£¬ÓÚ2020Äê9ÔÂ8ÈÕÊ×´ÎÐû²¼£©Äþ¾²Í¨¸æ£¬¸Ã©¶´¿ÉÄÜʹ¹¥»÷ÕßÈƹý WDAC ¡£ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷Õß¿ÉÒÔÖ´Ðб» WDAC ×èÖ¹µÄ PowerShell ÃüÁî¡£µ«ÒªÀûÓø鶴£¬¹¥»÷ÕßÐèÒªÔÚÔËÐÐPowerShellµÄµ±µØ»úÆ÷ÉÏÓйÜÀíԱȨÏÞ¡£È»ºó£¬¹¥»÷Õß¿ÉÒÔÁ¬½Óµ½PowerShell»á»°£¬²¢·¢ËÍÃüÁîÀ´Ö´ÐÐÈÎÒâ´úÂë¡£¸Ã©¶´Ó°ÏìÁËPowerShell 7.0ºÍ7.1°æ±¾¡£

PowerShell ÊÇÒ»¸ö¿çƽ̨µÄÈÎÎñ×Ô¶¯»¯½â¾ö·½°¸£¬ÓÉÃüÁîÐÐ shell¡¢½Å±¾ÓïÑÔºÍÅäÖùÜÀí¿ò¼Ü×é³É¡£PowerShell ¿ÉÒÔÔÚ Windows¡¢Linux ºÍ macOS ÉÏÔËÐС£Windows Defender Ó¦Ó÷¨Ê½¿ØÖÆ£¨WDAC£©Ö¼ÔÚ±£»¤WindowsÉ豸ÃâÊÜDZÔڵĶñÒâÈí¼þÈëÇÖ£¬È·±£Ö»ÓÐÊÜÐÅÈεÄÓ¦Ó÷¨Ê½ºÍÇý¶¯·¨Ê½¿ÉÒÔÔËÐУ¬´Ó¶ø×èÖ¹¶ñÒâÈí¼þºÍ²»ÐèÒªµÄÈí¼þÆô¶¯¡£

Ä¿Ç°£¬Redmond ÒѾ­Ðû²¼ÁË PowerShell 7.0.8 ºÍ PowerShell 7.1.5£¬ÒÔÐÞ¸´ PowerShell 7 ºÍ PowerShell 7.1 ·ÖÖ§ÖеÄÄþ¾²Â©¶´CVE-2020-0951ºÍCVE-2021-41355¡£ÓÉÓÚ¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ©¶´ÈƹýWDACÇ¿ÖÆÖ´Ðв¢»ñµÃ¶Ô´¿Îı¾Æ¾¾ÝµÄ·ÃÎÊȨÏÞ£¬Î¢ÈíÒªÇóϵͳ¹ÜÀíԱΪPowerShell 7¸üв¹¶¡¡£

 

Ó°Ï췶Χ

Õâ2¸ö©¶´Ó°ÏìÁËPowerShell 7µÄÒÔÏ°汾£º

CVE-2021-41355£ºPowerShell 7.1

CVE-2020-0951£ºPowerShell 7.0 ¡¢PowerShell7.1

 

0x02 ´¦Öý¨Òé

Ä¿Ç°ÕâЩ©¶´ÒѾ­ÐÞ¸´¡£Õë¶ÔPowerShell £¬½¨ÒéÊÜÓ°ÏìµÄÓû§¼°Ê±Éý¼¶¸üе½PowerShell 7.0.8 »ò PowerShell 7.1.5¡£Òª¼ì²âPowerShell 7 °æ±¾ÊÇ·ñÊܵ½Ó°Ï죬ÇëÔÚPowershell´°¿ÚÖÐÊäÈëÃüÁ$PSVersionTable¡£

ÏÂÔØÁ´½Ó£º

https://github.com/PowerShell/PowerShell#get-powershell

 

0x03 ²Î¿¼Á´½Ó

https://github.com/PowerShell/Announcements/issues/27

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41355

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-0951

https://www.bleepingcomputer.com/news/microsoft/microsoft-asks-admins-to-patch-powershell-to-fix-wdac-bypass/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-10-19

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

CVSS£ºwww.first.org

NVD£ºnvd.nist.gov

 

0x06 ¹ØÓÚ¶«É­Æ½Ì¨

¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png