ASUS ATK Package¿ÉÐÅõè¾¶´úÂëÖ´Ðзì϶£¨CVE-2019-19235£©

°ä²¼¹¦·ò 2019-12-21


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


1.²¼¾°ÃèÊö


SafeBreach LabsÔÚASUS ATKÈí¼þ°üÖз¢ÏÖÁËÒ»¸ö·ì϶£¨CVE-2019-19235£©£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚÌØÈ¨¹ý³Ì£¨NT AUTHORITY\SYSTEM£©µÄ¸ßµÍÎÄÖÐÖ´ÐÐδÊðÃûµÄ¿ÉÖ´ÐÐÎļþ£¨exe£©£¬£¬ £¬£¬£¬£¬£¬´Ó¶øÈƹý¼ì²â²¢»ñµÃÓÆ¾ÃÐÔ ¡£ ¡£¡£¡£¡£¡£¡£¡£


2.·ì϶Áбí


CVE ID  £º     CVE-2019-19235

CVSSÆÀ·Ö£º   ÔÝδÆÀ¶¨

Ó°ÏìÁìÓò£º     ATK Package 1.0.0060¼°Ö®Ç°µÄËùÓа汾


3.·ì϶ÏêÇé


»ªË¶ATKÈí¼þ°üÊÇԤװÖÃÔÚ»ªË¶PCÉϵÄʵÓù¤¾ß£¬£¬ £¬£¬£¬£¬£¬ÆäASLDR·þÎñ£¨AsLdrSrv.exe£©ÒÔNT AUTHORITY\SYSTEMÌØÈ¨ÕË»§ÔËÐУ¬£¬ £¬£¬£¬£¬£¬¸Ã·þÎñµÄ¿ÉÖ´ÐÐÎļþÓÉ¡° ASUSTek Computer Inc.¡±ÊðÃû ¡£ ¡£¡£¡£¡£¡£¡£¡£AsLdrSrv.exeÔÚÖ´ÐÓ×°C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe¡±Îļþǰ£¬£¬ £¬£¬£¬£¬£¬»áÏȲéÕÒÒÔÏÂ3¸öÃÔʧµÄexeÎļþ ¡£ ¡£¡£¡£¡£¡£¡£¡£


C:\Program.exe

C:\Program Files(x86)\ASUS\ATK.exe

C:\Program Files(x86)\ASUS\ATK Package\ATK.exe


Òò¶ø£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»½«ËÁÒâδÊðÃûµÄEXEÎļþ¼ÓÔØ½øºÏ·¨¹ý³Ì²¢ÒÔNT AUTHORITY\SYSTEMÖ´ÐУ¨ÎÞÐè¸ü¸Ä·þÎñµÄõè¾¶»ò¸²¸ÇÈκÎÎļþ£© ¡£ ¡£¡£¡£¡£¡£¡£¡£

µ¼Ö¸ÃÎÊÌâµÄÔ­ÒòÊÇAsLdrSrv.exeÊÔͼ´ÓÕýÈ·µÄõè¾¶¼ÓÔØHControl.exeʱ£¬£¬ £¬£¬£¬£¬£¬´æ´¢¸Ãõè¾¶µÄATK_path»º³åÇøÄÚµÄ×Ö·û´®Ã»ÓмÓÒýºÅ£¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚ¸Ãõè¾¶´æÔÚ¿Õ¸ñ£¬£¬ £¬£¬£¬£¬£¬Ê¹µÃCreateProcessAsUserWº¯Êý³¢ÊÔ×ÔÐнâÎöõè¾¶£¬£¬ £¬£¬£¬£¬£¬Òò¶ø·¨Ê½»á²éÕÒÕâ3¸ö²»´æÔÚµÄexeÎļþ ¡£ ¡£¡£¡£¡£¡£¡£¡£


4.½¨¸´½¨Òé


½¨Òé¸üÐÂÖÁ×îа汾1.0.0061


5.²Î¿¼Á´½Ó


https://safebreach.com/Post/ASUS-ATK-Package-Unquoted-Search-Path-and-Potential-Abuses-CVE-2019-19235

https://nvd.nist.gov/vuln/detail/CVE-2019-19235

https://www.asus.com/Static_WebPage/ASUS-Product-Security-Advisory/