Dell SupportAssist 6Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-06-250x00 ·ì϶¸ÅÊö
CVE ID | ʱ ¼ä | 2021-06-25 | |
Àà ÐÍ | µÈ ¼¶ | ¸ßΣ | |
Ô¶³ÌÀûÓà | Ó°ÏìÁìÓò | ||
¹¥»÷¸´ÔÓ¶È | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ÎÞ | |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ·ì϶ÏêÇé

2021Äê06ÔÂ24ÈÕ£¬£¬£¬£¬£¬Dell°ä²¼°²È«¸üУ¬£¬£¬£¬£¬½¨¸´ÁËDell SupportAssist µÄ BIOSConnect Ö°ÄܺÍHTTPSÊèµ¼Ö°ÄÜÖеÄ4¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶±ðÀëΪ²»°²È«µÄTLSÏνÓÎÊÌ⣨CVE-2021-21571£©ºÍ3¸öÒç¶Âí½Å£¨CVE-2021-21572¡¢CVE-2021-21573ºÍCVE-2021-21574£©£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÔÚÖ¸±êÉ豸µÄBIOSÖÐÖ´ÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬CVSSÆÀ·ÖΪ8.3¡£¡£¡£¡£¡£¡£
ÕâЩ·ì϶ӰÏìÁË129¿îDellÐͺŵÄÉÌÎñ±Ê¼Ç±¾µçÄÔ¡¢Ì¨Ê½»úºÍƽ°åµçÄÔ£¬£¬£¬£¬£¬Ô̺¬Ê¹ÓÃDell°²È«Æô¶¯ºÍ°²È«ÄÚºËPC±£»£»£»£»£»¤µÄÉ豸£¬£¬£¬£¬£¬¾Ý°µÊ¾£¬£¬£¬£¬£¬Ô¼ÄªÓÐ3000Íǫ̀É豸Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£
·ì϶ϸ½Ú
SupportAssist Èí¼þԤװÔÚ´óÎÞÊýÔËÐÐ Windows ϵͳµÄDellÉ豸ÉÏ£¬£¬£¬£¬£¬¶ø BIOSConnect ÌṩԶ³Ì¹Ì¼þ¸üкͲÙ×÷ϵͳ¸´ÔÖ°ÄÜ¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÄÜͨ¹ýһЩ·ì϶ÀûÓÃÖ÷»úµÄUEFI¹Ì¼þ²¢»ñµÃÉ豸ÉÏ´úÂëµÄ½ÚÔ죬£¬£¬£¬£¬ÏêÇéÈçÏ£º
UEFI BIOS https²Ö¿âÖ¤ÊéÑéÖ¤·ì϶£¨CVE-2021-21571£©
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ5.9¡£¡£¡£¡£¡£¡£ÓÉÓÚDell BIOSConnectÖ°ÄܺÍDell HTTPSÊèµ¼Ö°ÄÜʹÓõÄDell UEFI BIOS https²Ö¿âÔ̺¬Ò»¸öÖ¤ÊéÑéÖ¤·ì϶£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿Éͨ¹ýÖÐÑëÈ˹¥»÷À´ÀûÓø÷ì϶£¬£¬£¬£¬£¬µ¼Ö»ؾø·þÎñºÍPayload´Û¸Ä¡£¡£¡£¡£¡£¡£
BIOSConnect»º³åÇøÒç¶Âí½Å£¨CVE-2021-21572¡¢CVE-2021-21573ºÍCVE-2021-21574£©
ÕâЩ·ì϶µÄCVSSv3ÆÀ·Ö¾ùΪ7.2¡£¡£¡£¡£¡£¡£ÓÉÓÚBIOSConnectÖ°ÄÜÔ̺¬Ò»¸ö»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬ÓµÓÐϵͳ±¾µØ½Ó¼ûȨÏ޵ľ¹ýÈÏÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ÔËÐÐËÁÒâ´úÂë²¢ÈÆ¹ýUEFIÏÞ¶È¡£¡£¡£¡£¡£¡£
Õâ²¢²»ÊÇDellÍÆËã»úÓû§µÚÒ»´ÎÔâµ½ SupportAssist Èí¼þÖа²È«·ì϶µÄ¹¥»÷¡£¡£¡£¡£¡£¡£2015Ä꣬£¬£¬£¬£¬ÔÚDellϵͳ¼ì²âÈí¼þÖÐÒ²·¢ÏÖÁËÒ»¸öRCE ·ì϶¡£¡£¡£¡£¡£¡£2019 Äê 5 Ô£¬£¬£¬£¬£¬Dell½¨¸´ÁËÒ»¸öÓɰ²È«×êÑÐÔ± Bill Demirkapi ÓÚ 2018Äê»ã±¨µÄSupportAssist Ô¶³Ì´úÂëÖ´ÐÐ (RCE) ·ì϶¡£¡£¡£¡£¡£¡£ 2020 Äê 2 Ô£¬£¬£¬£¬£¬SupportAssistÔٴα»½¨¸´£¬£¬£¬£¬£¬ÒÔ½â¾öÓÉÓÚ DLL ËÑË÷°¤´Î½Ù³Ö·ì϶¶øµ¼Öµİ²È«·ì϶¡£¡£¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬ÉϸöÔÂDell½¨¸´ÁËÒ»¸öÄܹ»½«·ÇÖÎÀíÔ±Óû§µÄȨÏÞÌáÉýµ½ÄÚºËȨÏ޵ķì϶£¬£¬£¬£¬£¬ËüÊÇÔÚÊýǧÍǫ̀´÷¶ûÉ豸¸½´øµÄ DBUtil Çý¶¯·¨Ê½Öб»·¢Ïֵġ£¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
Ŀǰ£¬£¬£¬£¬£¬CVE-2021-21573 ºÍ CVE-2021-21574ÒѾÔÚ·þÎñ¶Ë½¨¸´£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÓû§²»±ØÒª¶î±í²Ù×÷£»£»£»£»£»µ«CVE-2021-21571 ºÍ CVE-2021-21572 ±ØÒªDell¿Í»§¶Ë½øÐÐ BIOS¸üÐÂÒÔ½¨¸´·ì϶¡£¡£¡£¡£¡£¡£Ä¿Ç°DellÔÚΪÊÜÓ°ÏìµÄϵͳÌṩ BIOS/UEFI ¸üУ¬£¬£¬£¬£¬²¢ÔÚ Dell.com É϶ÔÊÜÓ°ÏìµÄ¿ÉÖ´Ðз¨Ê½½øÐиüС£¡£¡£¡£¡£¡£
Óû§±ØÐëΪËùÓÐÊÜÓ°ÏìµÄϵͳ¸üÐÂϵͳ BIOS/UEFI£¬£¬£¬£¬£¬½¨ÒéʹÓà SupportAssist µÄ BIOSConnectÖ°ÄÜÒÔ±íµÄ²½Öè½øÐÐBIOS¸üС£¡£¡£¡£¡£¡£²»ÄÜÁ¢¼´¸üÐÂϵͳµÄÓû§Äܹ»´ÓBIOSÉèÖÃÒ³Ãæ»òʹÓÃDell Command | Configure£¨DCC£©µÄÔ¶³ÌϵͳÖÎÀí¹¤¾ß½ûÓÃBIOSConnect¡£¡£¡£¡£¡£¡£
¾ßÌåÊÜÓ°ÏìÉ豸ºÍÓйؽ¨¸´´ëÊ©Ïê¼ûDell¹Ù·½µÄ°²È«²¼¸æ£º
https://www.dell.com/support/kbdoc/zh-cn/000188682/dsa-2021-106-dell-client-platform-security-update-for-multiple-vulnerabilities-in-the-supportassist-biosconnect-feature-and-https-boot-feature
0x03 ²Î¿¼Á´½Ó
https://www.dell.com/support/kbdoc/zh-cn/000188682/dsa-2021-106-dell-client-platform-security-update-for-multiple-vulnerabilities-in-the-supportassist-biosconnect-feature-and-https-boot-feature
https://www.bleepingcomputer.com/news/security/dell-supportassist-bugs-put-over-30-million-pcs-at-risk/
https://www.zdnet.com/article/biosconnect-code-execution-bugs-impact-millions-of-dell-devices/#ftag=RSSbaffb68
0x04 ¹¦·òÏß
2021-06-24 Dell°ä²¼°²È«¹«¸æ
2021-06-25 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ