Microsoft | Windows Codecs & Visual Studio JSONÔ¶³Ì´úÂëÖ´Ðзì϶¹«¸æ
°ä²¼¹¦·ò 2020-10-190x00 ·ì϶¸ÅÊö
²úÆ·Ãû³Æ | CVE ID | Àà ÐÍ | ·ì϶µÈ¼¶ | Ô¶³ÌÀûÓà | Ó°ÏìÁìÓò |
Windows Codecs | CVE-2020-17022 | RCE | ¸ßΣ | ÊÇ | |
Visual Studio Code | CVE-2020-17023 | RCE | ¸ßΣ | ÊÇ |
΢ÈíÓÚ2020Äê10ÔÂ15ÈÕ°ä²¼ÁËÁ½¸ö´ø±í°²È«¸üУ¬£¬£¬£¬£¬£¬ÒÔ½¨¸´Microsoft Windows CodecsºÍVisual Studio CodeÖеÄÁ½¸öÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶¡£¡£¡£¡£¡£¡£¡£·ì϶¸ú×ÙΪCVE-2020-17022ºÍCVE-2020-17023£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö¾ùΪ7.8¡£¡£¡£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé

Microsoft Windows CodecsÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-17022£©
Microsoft Windows CodecsÊÇMicrosoftµÄ±à½âÂëÆ÷¿â£¬£¬£¬£¬£¬£¬ÆäÖеıà½âÂëÆ÷Ä£¿£¿£¿£¿£¿£¿éÌṩÁËÓÃÓÚ¶ÔWindows·¨Ê½ÖеÄÊý¾Ý½øÐдúÂëת»»µÄÁ÷ºÍÎļþ½Ó¿Ú¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÓÉÓÚMicrosoft Windows Codecs¿âÔÚ´¦ÖÃÄÚ´æ¶ÔÏóµÄ·½Ê½ÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Ê¹ÓöñÒâ»ú¹ØµÄµÄͼÏñÎļþÀ´ÀûÓô˷ì϶¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
Ó°ÏìÁìÓò£º
Windows 10 Version 1709 for 32-bit Systems
Windows 10 Version 1709 for ARM64-based Systems
Windows 10 Version 1709 for x64-based Systems
Windows 10 Version 1803 for 32-bit Systems
Windows 10 Version 1803 for ARM64-based Systems
Windows 10 Version 1803 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems
Windows 10 Version 1809 for ARM64-based Systems
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 1903 for 32-bit Systems
Windows 10 Version 1903 for ARM64-based Systems
Windows 10 Version 1903 for x64-based Systems
Windows 10 Version 1909 for ARM64-based Systems
Windows 10 Version 1909 for x64-based Systems
Windows 10 Version 2004 for 32-bit Systems
Windows 10 Version 2004 for ARM64-based Systems
Windows 10 Version 2004 for x64-based Systems
Visual Studio JSONÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-17023£©
MicrosoftµÄVisual Studio CodeÊÇMicrosoftÕë¶ÔWindows¡¢LinuxºÍmacOS¿ª·¢µÄÒ»ÖÖÃâ·ÑµÄÔ´´úÂë±à×ëÆ÷¡£¡£¡£¡£¡£¡£¡£
¹¥»÷ÕßÄܹ»Í¨¹ýÓÕʹÓû§´ò¿ª¶ñÒâµÄ¡° package.json¡±ÎļþÀ´ÀûÓô˷ì϶¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬£¬£¬£¬£¬£¬Ôò¹¥»÷ÕßÄܹ»½ÚÔìÕû¸öϵͳ£¬£¬£¬£¬£¬£¬ÀýÈç×°Ö÷¨Ê½¡¢²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý¡¢´´½¨ÓµÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§µÈ¡£¡£¡£¡£¡£¡£¡£
Ŀǰ£¬£¬£¬£¬£¬£¬MicrosoftµÄ¸üÐÂÊÇͨ¹ýÅú¸ÄVisual Studio Code´¦ÖÃJSONÎļþµÄ·½Ê½À´½â¾öÁË´Ë·ì϶¡£¡£¡£¡£¡£¡£¡£
Ó°ÏìÁìÓò£º
Visual Studio Code 1.50.1֮ǰµÄ°æ±¾¡£¡£¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
ĿǰMicrosoftÒѰ䲼°²È«¸üУ¬£¬£¬£¬£¬£¬½¨ÒéʵʱװÖÃÓйز¹¶¡¡£¡£¡£¡£¡£¡£¡£
£¨Ò»£© Windows update¸üÐÂ
×Ô¶¯¸üУº
Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£¡£¡£
ÊÖ¶¯¸üУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬£¬£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£¡£¡£
4¡¢³ÁÆôÍÆËã»ú£¬£¬£¬£¬£¬£¬×°ÖøüÐÂϵͳ³ÁÐÂÆô¶¯ºó£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¡£¡£¡£¡£¡£¡£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬£¬£¬£¬£¬£¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£¡£¡£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
΢Èí¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£¡£¡£¡£¡£¡£¡£
CVE-2020-17022Á´½ÓµØÖ·£º
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17022
CVE-2020-17023Á´½ÓµØÖ·£º
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17023
0x03 ²Î¿¼Á´½Ó
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17022
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17023
https://securityaffairs.co/wordpress/109665/security/microsoft-windows-rce.html?
https://threatpost.com/microsoft-rce-flaws-windows-update/160244/
0x04 ¹¦·òÏß
2020-10-15 Microsoft°ä²¼°²È«¸üÐÂ
2020-10-19 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ