Dell SupportAssist 6Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-06-250x00 Îó²î¸ÅÊö
CVE ID | ʱ ¼ä | 2021-06-25 | |
Àà ÐÍ | µÈ ¼¶ | ¸ßΣ | |
Ô¶³ÌʹÓà | Ó°Ïì¹æÄ£ | ||
¹¥»÷ÖØÆ¯ºó | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ÎÞ | |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ·ñ |
0x01 Îó²îÏêÇé

2021Äê06ÔÂ24ÈÕ£¬£¬£¬£¬DellÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´ÁËDell SupportAssist µÄ BIOSConnect ¹¦Ð§ºÍHTTPSÖ¸µ¼¹¦Ð§ÖеÄ4¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²î»®·ÖΪ²»Çå¾²µÄTLSÅþÁ¬ÎÊÌ⣨CVE-2021-21571£©ºÍ3¸öÒç³öÎó²î£¨CVE-2021-21572¡¢CVE-2021-21573ºÍCVE-2021-21574£©£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄ×°±¸µÄBIOSÖÐÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬CVSSÆÀ·ÖΪ8.3¡£¡£¡£¡£¡£¡£¡£
ÕâЩÎó²îÓ°ÏìÁË129¿îDellÐͺŵÄÉÌÎñÌõ¼Ç±¾µçÄÔ¡¢Ì¨Ê½»úÇå¾²°åµçÄÔ£¬£¬£¬£¬°üÀ¨Ê¹ÓÃDellÇå¾²Æô¶¯ºÍÇå¾²ÄÚºËPC±£»£»£»£»¤µÄ×°±¸£¬£¬£¬£¬¾ÝÌåÏÖ£¬£¬£¬£¬Ô¼ÄªÓÐ3000Íǫ̀װ±¸Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£
Îó²îϸ½Ú
SupportAssist Èí¼þԤװÔÚ´ó´ó¶¼ÔËÐÐ Windows ϵͳµÄDell×°±¸ÉÏ£¬£¬£¬£¬¶ø BIOSConnect ÌṩԶ³Ì¹Ì¼þ¸üкͲÙ×÷ϵͳ»Ö¸´¹¦Ð§¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýһЩÎó²îʹÓÃÖ÷»úµÄUEFI¹Ì¼þ²¢»ñµÃ×°±¸ÉÏ´úÂëµÄ¿ØÖÆ£¬£¬£¬£¬ÏêÇéÈçÏ£º
UEFI BIOS https¿ÍÕ»Ö¤ÊéÑéÖ¤Îó²î£¨CVE-2021-21571£©
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ5.9¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚDell BIOSConnect¹¦Ð§ºÍDell HTTPSÖ¸µ¼¹¦Ð§Ê¹ÓõÄDell UEFI BIOS https¿ÍÕ»°üÀ¨Ò»¸öÖ¤ÊéÑéÖ¤Îó²î£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿Éͨ¹ýÖÐÐÄÈ˹¥»÷À´Ê¹ÓøÃÎó²î£¬£¬£¬£¬µ¼Ö¾ܾøÐ§ÀͺÍPayload¸Ä¶¯¡£¡£¡£¡£¡£¡£¡£
BIOSConnect»º³åÇøÒç³öÎó²î£¨CVE-2021-21572¡¢CVE-2021-21573ºÍCVE-2021-21574£©
ÕâЩÎó²îµÄCVSSv3ÆÀ·Ö¾ùΪ7.2¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚBIOSConnect¹¦Ð§°üÀ¨Ò»¸ö»º³åÇøÒç³öÎó²î£¬£¬£¬£¬¾ßÓÐϵͳÍâµØ»á¼ûȨÏ޵ľÓÉÈÏÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÔËÐÐí§Òâ´úÂë²¢ÈÆ¹ýUEFIÏÞÖÆ¡£¡£¡£¡£¡£¡£¡£
Õâ²¢²»ÊÇDellÅÌËã»úÓû§µÚÒ»´ÎÔâµ½ SupportAssist Èí¼þÖÐÇå¾²Îó²îµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£2015Ä꣬£¬£¬£¬ÔÚDellϵͳ¼ì²âÈí¼þÖÐÒ²·¢Ã÷ÁËÒ»¸öRCE Îó²î¡£¡£¡£¡£¡£¡£¡£2019 Äê 5 Ô£¬£¬£¬£¬DellÐÞ¸´ÁËÒ»¸öÓÉÇå¾²Ñо¿Ô± Bill Demirkapi ÓÚ 2018Ä걨¸æµÄSupportAssist Ô¶³Ì´úÂëÖ´ÐÐ (RCE) Îó²î¡£¡£¡£¡£¡£¡£¡£ 2020 Äê 2 Ô£¬£¬£¬£¬SupportAssistÔٴα»ÐÞ¸´£¬£¬£¬£¬ÒÔ½â¾öÓÉÓÚ DLL ËÑË÷˳ÐòÐ®ÖÆÎó²î¶øµ¼ÖµÄÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£×îºó£¬£¬£¬£¬ÉϸöÔÂDellÐÞ¸´ÁËÒ»¸ö¿ÉÒÔ½«·ÇÖÎÀíÔ±Óû§µÄȨÏÞÌáÉýµ½ÄÚºËȨÏÞµÄÎó²î£¬£¬£¬£¬ËüÊÇÔÚÊýÍòÍǫ̀´÷¶û×°±¸¸½´øµÄ DBUtil Çý¶¯³ÌÐòÖб»·¢Ã÷µÄ¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ£¬£¬£¬£¬CVE-2021-21573 ºÍ CVE-2021-21574ÒѾÔÚЧÀͶËÐÞ¸´£¬£¬£¬£¬ÊÜÓ°ÏìµÄÓû§²»ÐèÒªÌØÊâ²Ù×÷£»£»£»£»µ«CVE-2021-21571 ºÍ CVE-2021-21572 ÐèÒªDell¿Í»§¶Ë¾ÙÐÐ BIOS¸üÐÂÒÔÐÞ¸´Îó²î¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚDellÕýÔÚΪÊÜÓ°ÏìµÄϵͳÌṩ BIOS/UEFI ¸üУ¬£¬£¬£¬²¢ÔÚ Dell.com É϶ÔÊÜÓ°ÏìµÄ¿ÉÖ´ÐгÌÐò¾ÙÐиüС£¡£¡£¡£¡£¡£¡£
Óû§±ØÐèΪËùÓÐÊÜÓ°ÏìµÄϵͳ¸üÐÂϵͳ BIOS/UEFI£¬£¬£¬£¬½¨ÒéʹÓà SupportAssist µÄ BIOSConnect¹¦Ð§ÒÔÍâµÄÒªÁì¾ÙÐÐBIOS¸üС£¡£¡£¡£¡£¡£¡£²»¿ÉÁ¬Ã¦¸üÐÂϵͳµÄÓû§¿ÉÒÔ´ÓBIOSÉèÖÃÒ³Ãæ»òʹÓÃDell Command | Configure£¨DCC£©µÄÔ¶³ÌϵͳÖÎÀí¹¤¾ß½ûÓÃBIOSConnect¡£¡£¡£¡£¡£¡£¡£
ÏêϸÊÜÓ°Ïì×°±¸ºÍÏà¹ØÐÞ¸´²½·¥Ïê¼ûDell¹Ù·½µÄÇ徲ͨ¸æ£º
https://www.dell.com/support/kbdoc/zh-cn/000188682/dsa-2021-106-dell-client-platform-security-update-for-multiple-vulnerabilities-in-the-supportassist-biosconnect-feature-and-https-boot-feature
0x03 ²Î¿¼Á´½Ó
https://www.dell.com/support/kbdoc/zh-cn/000188682/dsa-2021-106-dell-client-platform-security-update-for-multiple-vulnerabilities-in-the-supportassist-biosconnect-feature-and-https-boot-feature
https://www.bleepingcomputer.com/news/security/dell-supportassist-bugs-put-over-30-million-pcs-at-risk/
https://www.zdnet.com/article/biosconnect-code-execution-bugs-impact-millions-of-dell-devices/#ftag=RSSbaffb68
0x04 ʱ¼äÏß
2021-06-24 DellÐû²¼Ç徲ͨ¸æ
2021-06-25 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ