PowerShell CoreµÄWDACÈÆ¹ýÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-18

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1167£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


PowerShell Core 6.0
PowerShell Core 6.1

PowerShell Core 6.2


Îó²î¸ÅÊö


PowerShell CoreÊÇÒ»Ì×ΪÒìÀàÇéÐκͻìÏýÔÆ¹¹½¨µÄ¿çƽ̨ÏÂÁîÐо籾ִÐÐÇéÐΡ£¡£¡£¡£¡£


MicrosoftÅû¶ÁËÒ»¸öWindows DefenderÓ¦ÓóÌÐò¿ØÖÆ£¨WDAC£©Çå¾²¹¦Ð§ÈƹýÎó²î£¬£¬£¬£¬£¬£¬£¬WDACÊÇMicrosoftÌṩµÄÒ»ÖÖÇå¾²²úÆ·£¬£¬£¬£¬£¬£¬£¬Ö»ÔÊÐíÔÚWindowsÖÐÔËÐÐÊÜÐÅÈεÄÓ¦ÓóÌÐòºÍÇý¶¯³ÌÐò¡£¡£¡£¡£¡£ÕâÖÖ°×Ãûµ¥ÒªÁìÌṩÁËÏÔÖøµÄÇå¾²ÐÔˢУ¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÖ»ÓÐÊÜÐÅÈεÄÓ¦ÓóÌÐò²Å»ªÔËÐУ¬£¬£¬£¬£¬£¬£¬¶ø¶ñÒâÈí¼þµÈδ֪ӦÓóÌÐòÓÀÔ¶²»»á±»ÔÊÐí¡£¡£¡£¡£¡£


´ËÎó²î¿ÉÄÜÔÊÐí¹¥»÷ÕßÈÆ¹ýWDACÇ¿ÖÆÖ´ÐС£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÈÆ¹ýÅÌËã»úÉϵÄPowerShell½¹µãÔ¼ÊøÓïÑÔģʽ¡£¡£¡£¡£¡£


ҪʹÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÊ×ÏÈÓ¦¾ßÓжÔPowerShellÔÚÔ¼ÊøÓïÑÔģʽÏÂÔËÐеÄÍâµØÅÌËã»úµÄÖÎÀíÔ±»á¼ûȨÏÞ¡£¡£¡£¡£¡£ÕâÑù¹¥»÷Õß¿ÉÒÔÒÔ·ÇÔ¤ÆÚµÄ·½·¨»á¼û×ÊÔ´¡£¡£¡£¡£¡£


´Ë¸üÐÂͨ¹ý¸üÕýPowerShellÔÚÔ¼ÊøÓïÑÔģʽϵÄÔËÐз½·¨À´½â¾öÎó²î¡£¡£¡£¡£¡£


Òª¼ì²éÕýÔÚÔËÐеÄPowerShell°æ±¾²¢È·¶¨ÄúÊÇ·ñÈÝÒ×Êܵ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ´ÓÏÂÁîÌáÐÑ·ûÖ´ÐÐpwsh -vÏÂÁî¡£¡£¡£¡£¡£


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

 
ÈôÊÇÄúÖªµÀ×°ÖÃÁËPowerShell Core£¬£¬£¬£¬£¬£¬£¬µ«pwsh.exeÏÂÁî²»Æð×÷Ó㬣¬£¬£¬£¬£¬£¬ÄÇôÄúʹÓõÄÊÇPowerShell Core 6.0£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÐèÒª¸üе½¸üеİ汾¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£ 


ÐÞ¸´½¨Òé


MicrosoftÐÞ²¹ÁËÎó²î£¬£¬£¬£¬£¬£¬£¬Çë¸üе½×îа汾¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1167