Dell SupportAssist 6Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2021-06-25

0x00 ©¶´¸ÅÊö

CVE     ID


ʱ      ¼ä

2021-06-25

Àà      ÐÍ


µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ


Ó°Ï췶Χ


¹¥»÷ÅÓ´ó¶È


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ

ÎÞ

PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ©¶´ÏêÇé

image.png

2021Äê06ÔÂ24ÈÕ £¬DellÐû²¼Äþ¾²¸üР£¬ÐÞ¸´ÁËDell SupportAssist µÄ BIOSConnect ¹¦Ð§ºÍHTTPSÒýµ¼¹¦Ð§ÖеÄ4¸öÄþ¾²Â©¶´¡£ÕâЩ©¶´·Ö±ðΪ²»Äþ¾²µÄTLSÁ¬½ÓÎÊÌ⣨CVE-2021-21571£©ºÍ3¸öÒç³ö©¶´£¨CVE-2021-21572¡¢CVE-2021-21573ºÍCVE-2021-21574£© £¬ÔÊÐí¹¥»÷ÕßÔÚÄ¿±êÉ豸µÄBIOSÖÐÖ´ÐÐÈÎÒâ´úÂë £¬CVSSÆÀ·ÖΪ8.3¡£

ÕâЩ©¶´Ó°ÏìÁË129¿îDellÐͺŵÄÉÌÎñÌõ¼Ç±¾µçÄÔ¡¢Ì¨Ê½»úºÍƽ°åµçÄÔ £¬°üÂÞʹÓÃDellÄþ¾²Æô¶¯ºÍÄþ¾²ÄÚºËPC±£»¤µÄÉ豸 £¬¾ÝÌåÏÖ £¬Ô¼ÄªÓÐ3000Íǫ̀É豸Êܵ½Ó°Ïì¡£

 

©¶´Ï¸½Ú

SupportAssist Èí¼þԤװÔÚ´ó¶àÊýÔËÐÐ Windows ϵͳµÄDellÉ豸ÉÏ £¬¶ø BIOSConnect ÌṩԶ³Ì¹Ì¼þ¸üкͲÙ×÷ϵͳ»Ö¸´¹¦Ð§¡£Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýһЩ©¶´ÀûÓÃÖ÷»úµÄUEFI¹Ì¼þ²¢»ñµÃÉ豸ÉÏ´úÂëµÄ¿ØÖÆ £¬ÏêÇéÈçÏ£º

UEFI BIOS https¶ÑÕ»Ö¤ÊéÑé֤©¶´£¨CVE-2021-21571£©

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ5.9¡£ÓÉÓÚDell BIOSConnect¹¦Ð§ºÍDell HTTPSÒýµ¼¹¦Ð§Ê¹ÓõÄDell UEFI BIOS https¶ÑÕ»°üÂÞÒ»¸öÖ¤ÊéÑé֤©¶´ £¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿Éͨ¹ýÖмäÈ˹¥»÷À´ÀûÓøÃ©¶´ £¬µ¼Ö¾ܾø·þÎñºÍPayload¸Ä¶¯¡£

 

BIOSConnect»º³åÇøÒç³ö©¶´£¨CVE-2021-21572¡¢CVE-2021-21573ºÍCVE-2021-21574£©

ÕâЩ©¶´µÄCVSSv3ÆÀ·Ö¾ùΪ7.2¡£ÓÉÓÚBIOSConnect¹¦Ð§°üÂÞÒ»¸ö»º³åÇøÒç³ö©¶´ £¬¾ßÓÐϵͳµ±µØ·ÃÎÊȨÏ޵ľ­¹ýÈÏÖ¤µÄ¹¥»÷Õß¿ÉÒÔÀûÓøÃ©¶´ÔËÐÐÈÎÒâ´úÂë²¢ÈÆ¹ýUEFIÏÞÖÆ¡£

Õâ²¢²»ÊÇDell¼ÆËã»úÓû§µÚÒ»´ÎÔâµ½ SupportAssist Èí¼þÖÐÄþ¾²Â©¶´µÄ¹¥»÷¡£2015Äê £¬ÔÚDellϵͳ¼ì²âÈí¼þÖÐÒ²·¢ÏÖÁËÒ»¸öRCE ©¶´¡£2019 Äê 5 Ô £¬DellÐÞ¸´ÁËÒ»¸öÓÉÄþ¾²Ñо¿Ô± Bill Demirkapi ÓÚ 2018Äê³ÂËßµÄSupportAssist Ô¶³Ì´úÂëÖ´ÐÐ (RCE) ©¶´¡£ 2020 Äê 2 Ô £¬SupportAssistÔٴα»ÐÞ¸´ £¬ÒÔ½â¾öÓÉÓÚ DLL ËÑË÷˳Ðò½Ù³Ö©¶´¶øµ¼ÖµÄÄþ¾²Â©¶´¡£×îºó £¬ÉϸöÔÂDellÐÞ¸´ÁËÒ»¸ö¿ÉÒÔ½«·Ç¹ÜÀíÔ±Óû§µÄȨÏÞÌáÉýµ½ÄÚºËȨÏ޵ĩ¶´ £¬ËüÊÇÔÚÊýǧÍǫ̀´÷¶ûÉ豸¸½´øµÄ DBUtil Çý¶¯·¨Ê½Öб»·¢Ïֵġ£

 

0x02 ´¦Öý¨Òé

Ŀǰ £¬CVE-2021-21573 ºÍ CVE-2021-21574ÒѾ­ÔÚ·þÎñ¶ËÐÞ¸´ £¬ÊÜÓ°ÏìµÄÓû§²»ÐèÒªÌØ±ð²Ù×÷£»µ«CVE-2021-21571 ºÍ CVE-2021-21572 ÐèÒªDell¿Í»§¶Ë½øÐÐ BIOS¸üÐÂÒÔÐÞ¸´Â©¶´¡£Ä¿Ç°DellÕýÔÚΪÊÜÓ°ÏìµÄϵͳÌṩ BIOS/UEFI ¸üР£¬²¢ÔÚ Dell.com É϶ÔÊÜÓ°ÏìµÄ¿ÉÖ´Ðз¨Ê½½øÐиüС£

Óû§±ØÐëΪËùÓÐÊÜÓ°ÏìµÄϵͳ¸üÐÂϵͳ BIOS/UEFI £¬½¨ÒéʹÓà SupportAssist µÄ BIOSConnect¹¦Ð§ÒÔÍâµÄÒªÁì½øÐÐBIOS¸üС£²»ÄÜÁ¢¼´¸üÐÂϵͳµÄÓû§¿ÉÒÔ´ÓBIOSÉèÖÃÒ³Ãæ»òʹÓÃDell Command | Configure£¨DCC£©µÄÔ¶³Ìϵͳ¹ÜÀí¹¤¾ß½ûÓÃBIOSConnect¡£

¾ßÌåÊÜÓ°ÏìÉ豸ºÍÏà¹ØÐÞ¸´´ëÊ©Ïê¼ûDell¹Ù·½µÄÄþ¾²Í¨¸æ£º

https://www.dell.com/support/kbdoc/zh-cn/000188682/dsa-2021-106-dell-client-platform-security-update-for-multiple-vulnerabilities-in-the-supportassist-biosconnect-feature-and-https-boot-feature

 

0x03 ²Î¿¼Á´½Ó

https://www.dell.com/support/kbdoc/zh-cn/000188682/dsa-2021-106-dell-client-platform-security-update-for-multiple-vulnerabilities-in-the-supportassist-biosconnect-feature-and-https-boot-feature

https://www.bleepingcomputer.com/news/security/dell-supportassist-bugs-put-over-30-million-pcs-at-risk/

https://www.zdnet.com/article/biosconnect-code-execution-bugs-impact-millions-of-dell-devices/#ftag=RSSbaffb68

 

0x04 ʱ¼äÏß

2021-06-24  DellÐû²¼Äþ¾²Í¨¸æ

2021-06-25  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png