Windows JScript ×é¼þ0day Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-06-01·ì϶±àºÅ
CVEÔÝÎÞ
·ì϶¼¶±ð
ÖÐ
³§ÉÌ×ÔÆÀ£º6.8 CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
·ìϼûèÊö
½üÈÕ£¬£¬£¬£¬£¬£¬windowsϵͳÓÖ·¢ÏÖһ·0day·ì϶£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÊÇÓÉϵͳÖеÄJScript×é¼þÔì³ÉµÄ£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÓû§µÄPCÉÏÖ´ÐжñÒâ´úÂ룬£¬£¬£¬£¬£¬ ¹ÌȻ΢Èí²¢Î´Ìṩ´òËãÍÆ³ö²¹¶¡¼òÖ±Çй¦·ò±í£¬£¬£¬£¬£¬£¬µ«Ò»Î»½²»°ÈËÅú×¢ËûÃÇÔÚ½øÐн¨¸´¡£¡£¡£¡£¡£¡£¡£¡£
5ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬ZDI°ä²¼ÁËÒ»·Ý»ã±¨£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÓйظÃÃýÎóµÄ¾ßÌå¼¼Êõϸ½Ú£º
ÓÉÓڸ÷ì϶ӰÏì JScript ×é¼þ£¨Î¢Èí×Ô½ç˵µÄ JavaScript Ö´ÐУ©£¬£¬£¬£¬£¬£¬Î¨Ò»µÄǰÌá¾ÍÊǹ¥»÷Õß±ØÐëÓÕÆÓû§½Ó¼ûÒ»¸ö¶ñÒâÍøÒ³»òÕßÔÚϵͳ¸ßµÍÔØ²¢´ò¿ª¶ñÒâ JS Îļþ£¨Í¨³£¾ÓÉ Windows Script Host-wscript.exe Ö´ÐУ©¡£¡£¡£¡£¡£¡£¡£¡£
Õâ¸öȱµã´æÔÚÓÚ JScript ¶Ô Error ¶ÔÏóµÄ´¦Öùý³ÌÖÓ×£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÔÚJScript ÖÐÖ´ÐÐ×÷Ϊ£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂij¸öÖ¸ÕëÔÚ¿ªÊͺóÔâ³ÁÓᣡ£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄÜÀûÓø÷ì϶ÔÚµ±Ç°¹ý³ÌÏÂÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¡£
¸Ã·ì϶µÄΣÏÕϵÊý²¢Ã»ÓÐÌýÉÏÈ¥µÄÄÇô¸ß£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÎÞ·¨µ¼ÖÂϵͳÔâÆëÈ«¹¥Ï¡£¡£¡£¡£¡£¡£¡£¡£Õâ¸öȱµã½öÔÊÐíɳÏä»·¾³ÖеĴúÂëÖ´ÐÐÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß±ØÒªÆäËüÀûÓÃÄÜÁ¦ÌÓÀëɳÏä²¢ÔÚÖ¸±êϵͳÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¡£
΢ÈíÔÚÍÆ³ö²¹¶¡£¬£¬£¬£¬£¬£¬²»ÍâÒѾ³¬³öÁËÅû¶սÊõÉèÖõŦ·òÖá¡£¡£¡£¡£¡£¡£¡£¡£
ͨ³£ÔÚÅû¶ȱµãºó´ÍÓë³§ÉÌ120ÌìµÄ¹¦·ò°ä²¼²¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£´Ó΢Èí¸´ÔµÄ¹¦·òÖáÀ´¿´£¬£¬£¬£¬£¬£¬Î¢ÈíÄÑÒÔ¸´ÏÖ´¥·¢¸Ã·ì϶µÄ PoC ´úÂ룬£¬£¬£¬£¬£¬´Ó¶øÆÆ·ÑÁË75%µÄÅû¶¹¦·òÖᣬ£¬£¬£¬£¬£¬µ¼Ö¹¤³ÌʦÎÞ·¨ÊµÊ±¸ÏÔÚ5ÔµIJ¹¶¡ÐÇÆÚ¶þ²âÊÔ²¢°ä²¼²¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£
¹ÌȻ΢Èí²¢Î´Ìá¹©ÍÆ³ö²¹¶¡µÄ¾ßÌ幦·òÖᣬ£¬£¬£¬£¬£¬µ«Î¢ÈíµÄÒ»Ãû½²»°ÈË֤ʵ³ÆÔÚÍÆ³ö½¨¸´¹æ»®¡£¡£¡£¡£¡£¡£¡£¡£
ÔÚÅû¶·ì϶֮ʱ²¢Î´·¢ÏÖ·ì϶ÔâÀûÓõÄÇé¿ö¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÍøÉÏÏÕЩ²»´æÔÚ¼¼ÊõÏêÇ飬£¬£¬£¬£¬£¬Òò¶øÔÚ΢Èí°ä²¼½¨¸´¹æ»®Ç°ºÜ¿ÉÄÜ»¹ÊÇδÔâÀûÓõÄÇé¿ö¡£¡£¡£¡£¡£¡£¡£¡£
½â¾ö´ëÊ©
½¨ÒéÓû§²»ÒªÊ¹ÓÃÒÀ¸½ JScript ×é¼þµÄÀûÓÃÈç IE ä¯ÀÀÆ÷¡¢wscript.exe µÈÀ´´¦Öò»ÊÜÐÅÀµµÄ JS ´úÂë»òÎļþ¡£¡£¡£¡£¡£¡£¡£¡£
²Î¿¼×ÊÁÏ
https://www.zerodayinitiative.com/advisories/ZDI-18-534/
https://www.bleepingcomputer.com/news/security/remote-code-execution-vulnerability-disclosed-in-windows-jscript-component/


¾©¹«Íø°²±¸11010802024551ºÅ