Win10ÍâµØÌáȨ0dayÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-08-29Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÎÞ£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ß£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Windows 10 32/64λ²Ù×÷ϵͳ
Îó²î¸ÅÊö
2018Äê8ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬Çå¾²Ñо¿Ö°Ô±ÔÚgithubÉÏÐû²¼ÁË×îеÄwin10x64°æµÄÍâµØÌáȨÎó²î£¬£¬£¬£¬£¬£¬²¢ÇÒÔÚÍÆÌØÉÏ¶ÔÆäÌáȨµÄdemo¾ÙÐÐÁËÑÝʾ¡£¡£¡£¡£¡£¡£¡£ÔÚgithubÉϵÄSandboxEscaperÉÏÓÐ×ÅÍêÕûµÄÎó²îʹÓóÌÐòÒÔ¼°demo£¬£¬£¬£¬£¬£¬²¢ÇÒ±»ÆäËûÇå¾²Ñо¿×¨¼Ò֤ʵ¸ÃÎó²î¿ÉÒÔÔÚ×î½üµÄwin10Éϸ´ÏÖ¡£¡£¡£¡£¡£¡£¡£
¸ÃÎó²îµÄÔµ¹ÊÔÓÉÔÚÓÚwin10ϵͳµÄʹÃüµ÷ÀíЧÀÍÖÐÓÐalpcµÄŲÓýӿڣ¬£¬£¬£¬£¬£¬¸Ã½Ó¿Úµ¼³öÁËSchRpcSetSecurityº¯Êý£¬£¬£¬£¬£¬£¬¸Ãº¯ÊýÕýÊDZ¾´ÎÎó²îʹÓõ½µÄº¯Êý¡£¡£¡£¡£¡£¡£¡£¸Ãº¯ÊýµÄÔÐÍÈçÏ£º
[in][string] wchar_t* arg_1, //Task name
[in][string] wchar_t* arg_2, //Security Descriptor string
[in]long arg_3);
µ±í§ÒâȨÏÞµÄÓû§Å²Óøú¯Êýʱ£¬£¬£¬£¬£¬£¬¸Ãº¯Êý»á¼ì²â c:\windows\tasksĿ¼ÏÂÊÇ·ñ±£´æÒ»¸öºó׺ΪjobµÄÎļþ£¬£¬£¬£¬£¬£¬ÈôÊǸÃÎļþ±£´æ»áÏò¸ÃÎļþдÈëÖ¸¶¨µÄDACLÊý¾Ý¡£¡£¡£¡£¡£¡£¡£±¾´ÎÎó²îʹÓõķ½·¨¼´Í¨¹ýÓ²Á´½ÓµÄ·½·¨½«¸ÃjobÎļþÖ¸¶¨Á´½Óµ½Ìض¨µÄdllÉÏ£¬£¬£¬£¬£¬£¬ÕâÑùµ±Óû§Å²Óøú¯Êýʱ»áÏòÌØ¶¨µÄdllдÈëÊý¾Ý£¬£¬£¬£¬£¬£¬¶øÌض¨µÄdllÍùÍùÊÇϵͳ¼¶±ðµÄdll¡£¡£¡£¡£¡£¡£¡£ÔÚgithubÉÏÐû²¼µÄÎó²îʹÓóÌÐòÔò»áÏòprintconfig.dllдÈëÌáȨ´úÂ룬£¬£¬£¬£¬£¬²¢Í¨¹ýÆô¶¯´òӡЧÀÍspoolsv.exeÀ´Ö´ÐÐÌáȨ´úÂ룬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖÄÚºËÌáȨ¡£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ËæºóʹÓÃieä¯ÀÀÆ÷¾ÙÐвâÊÔʱ·¢Ã÷ÎÞ·¨Ê¹ÓÃÀֳɣ¬£¬£¬£¬£¬£¬ËäÈ»Îó²îʹÓõÄdllÒѾ±»Ð´Èëµ½spoolsv.exeÖУ¬£¬£¬£¬£¬£¬µ«È´Ã»ÓÐʵÏÖÎó²îÕæÕýµÄЧ¹û¡£¡£¡£¡£¡£¡£¡£½ÓÏÂÀ´Æ¾Ö¤ÑÝʾdemoÖеIJÙ×÷£¬£¬£¬£¬£¬£¬·¿ªÒ»¸önotepad³ÌÐò£¬£¬£¬£¬£¬£¬²¢¶Ônotepad³ÌÐò¾ÙÐÐ×¢Èë¡£¡£¡£¡£¡£¡£¡£
ËæºóÉó²éspoolsv.exeϵÄËùÓÐ×ÓÀú³Ì£¬£¬£¬£¬£¬£¬·¢Ã÷¸Ãnotepad.exe³ÌÐò±»spoolsv.exe³ÌÐòÖØÐ·¿ª£¬£¬£¬£¬£¬£¬ºÍgithubÉϵÄÎó²îʹÓõÄdemoÖеÄЧ¹ûÒ»Ö£¬£¬£¬£¬£¬£¬¿ÉÒÔÈ·¶¨Îó²îʹÓÃÀֳɡ£¡£¡£¡£¡£¡£¡£
¶ø¸ÃdllµÄÐÞ¸Äʱ¼äÒ²ÏÔʾÊǸոÕÎó²îʹÓõÄʱ¼ä£¬£¬£¬£¬£¬£¬ÖÁ´ËÎó²î¸´ÏÖÀֳɡ£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
³§ÉÌÉÐδÐû²¼Ïà¹Ø²¹¶¡£¬£¬£¬£¬£¬£¬ÉóÉ÷Ö´ÐÐδ¾ÉóºËȪԴ¶ÔµÄ³ÌÐò¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://github.com/SandboxEscaper/randomrepo


¾©¹«Íø°²±¸11010802024551ºÅ