Windows Print SpoolerÔ¶³Ì´úÂëÖ´ÐÐ0 day©¶´£¨CVE-2021-34527£©

Ðû²¼Ê±¼ä 2021-07-02

0x00 ©¶´¸ÅÊö

CVE     ID

CVE-2021-34527

ʱ      ¼ä

2021-07-02

Àà       ÐÍ

RCE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ

  ËùÓÐWindows°æ±¾

¹¥»÷ÅÓ´ó¶È

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP

ÒѹûÈ»

ÔÚÒ°ÀûÓÃ

ÊÇ

 

0x01 ©¶´ÏêÇé

image.png

 

Windows Print SpoolerÊÇWindowsµÄ´òÓ¡»úºǫ́´¦Ö÷¨Ê½£¬Æä¹ÜÀíËùÓе±µØºÍÍøÂç´òÓ¡ÐÐÁв¢¿ØÖÆËùÓдòÓ¡ÊÂÇ飬±»¹ã·ºÓ¦ÓÃÓÚµ±µØºÍÄÚÍøÖС£

2021Äê6ÔÂ29ÈÕ£¬Äþ¾²Ñо¿ÈËÔ±ÔÚGitHubÉϹûÈ»ÁËÒ»¸öWindows Print SpoolerÔ¶³Ì´úÂëÖ´ÐÐ0day©¶´£¨CVE-2021-34527£©¡£

ÐèҪעÒâµÄÊÇ£¬¸Ã©¶´£¨CVE-2021-34527£©ÓëMicrosoft 6ÔÂ8ÈÕÐÇÆÚ¶þ²¹¶¡ÈÕÖÐÐÞ¸´²¢ÓÚ6ÔÂ21ÈÕ¸üеÄÒ»¸öEoPÉý¼¶µ½RCEµÄ©¶´£¨CVE-2021-1675£©²»ÊÇͬһ¸ö©¶´¡£ÕâÁ½¸ö©¶´ÏàËƵ«²îÒ죬¹¥»÷ÏòÁ¿Ò²²îÒì¡£

Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬¶øÇÒÒÑ·ºÆðÔÚÒ°ÀûÓᣵ± Windows Print Spooler ·þÎñ²»ÕýÈ·µØÖ´ÐÐÌØȨÎļþ²Ù×÷ʱ£¬´æÔÚÔ¶³ÌÖ´ÐдúÂ멶´¡£ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷Õß¿ÉÒÔʹÓà SYSTEM ȨÏÞÔËÐÐÈÎÒâ´úÂë¡¢°²×°·¨Ê½¡¢¼ì²ì²¢¸ü¸Ä»òɾ³ýÊý¾Ý¡¢»ò´´½¨¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§£¬µ«¹¥»÷±ØÐëÉæ¼°µ÷Óà RpcAddPrinterDriverEx() µÄ¾­¹ýÉí·ÝÑéÖ¤µÄÓû§¡£

 

0x02 ´¦Öý¨Òé

Ä¿Ç°¸Ã©¶´ÉÐδÐÞ¸´¡£

½¨ÒéÍ£Ö¹²¢½ûÓÃWindows Print Spooler·þÎñ¡£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527

 

0x03 ²Î¿¼Á´½Ó

https://github.com/afwu/PrintNightmare

https://www.bleepingcomputer.com/news/security/public-windows-printnightmare-0-day-exploit-allows-domain-takeover/

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527

 

0x04 ʱ¼äÏß

2021-07-01  MicrosoftÐû²¼Äþ¾²Í¨¸æ

2021-07-02  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png