´÷¶ûSupportAssist DLL½Ù³Ö·ì϶
°ä²¼¹¦·ò 2019-06-22²¼¾°ÃèÊö
·ì϶Áбí
´÷¶ûDSA±àºÅ£º DSA-2019-084
·ì϶µÈ¼¶£º ¸ßΣ
CVSSÆÀ·Ö£º ÔÝÎÞ
Ó°ÏìÁìÓò£º Dell SupportAssist for Business PCs°æ±¾2.0£»£»£»Dell SupportAssist for Home PCs 3.2.1¼°Ö®Ç°µÄËùÓа汾
·ì϶ÏêÇé
SupportAssistÊÇ´÷¶ûµçÄÔÉÏԤװÖõÄÒ»¸öÈí¼þ£¬£¬ÓÃÓÚ²é³ÏµÍ³Ó²¼þºÍÈí¼þµÄÔËÐÐÇé¿ö£¬£¬¸ÃÈí¼þÒÔSYSTEMȨÏÞÔËÐС£¡£SafeBreach Labs×êÑÐÈËÔ±·¢ÏÖ¸ÃÈí¼þ´æÔÚDLL½Ù³Ö·ì϶£¨CVE-2019-12280£©£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß½«ËÁÒâδÊðÃûµÄDLL¼ÓÔØµ½ÒÔSYSTEMȨÏÞÔËÐеķþÎñÖУ¬£¬´Ó¶øÊµÏÖȨÏÞÌáÉýºÍÓÆ¾ÃÐÔ - Ô̺¬¶ÔÎïÀíÄÚ´æ¡¢¡¢ÏµÍ³ÖÎÀíBIOSµÈµ×²ã×é¼þµÄ¶Á/д½Ó¼û¡£¡£¸Ã·ì϶ʹ¹¥»÷Õß¿ÉÄÜͨ¹ýÒÑÊðÃûµÄ·þÎñ¼ÓÔØºÍÖ´ÐжñÒâpayload£¬£¬¹¥»÷Õ߿ɽ«´ËÄÜÁ¦ÓÃÓÚÖ´ÐлòÌӱܼì²âµÈ·ÖÆçÖ÷ÕÅ£¬£¬ÀýÈ磺ÀûÓ÷¨Ê½°×Ãûµ¥Èƹý¡¢¡¢ÊðÃûÑéÖ¤ÈÆ¹ý¡£¡£
ƾ¾ÝSafeBreachµÄ»ã±¨£¬£¬¸Ã·ì϶µÄµ××ÓÔÒòÊÇ£º
1¡¢¡¢²»×㰲ȫµÄDLL¼ÓÔØ¡£¡£´úÂëÖÐʹÓÃLoadLibraryW²½Ö裬£¬¶ø²»ÊÇLoadLibraryExW£»£»£»ÕâÔÊÐíδ¾ÊÚȨµÄÓû§Í¨¹ýijЩÏóÕ÷À´½ç˵ËÑË÷°¤´Î£¬£¬ÀýÈçLOAD_LIBRARY_SEARCH_DLL_LOAD_DIR¡£¡£·´¹ýÀ´£¬£¬¸ÃÏóÕ÷ÓÖÏÞ¶¨Ö»ÔÚ×Ô¼ºµÄÎļþ¼ÐÖÐËÑË÷DLL£¬£¬Ô¤·ÀÁËÔÚPATH±äÁ¿ÖÐËÑË÷DLLµÄÇé¿ö¡£¡£
2¡¢¡¢Ã»ÓжԶþ½øÖÆÎļþ½øÐÐÊðÃûÑéÖ¤¡£¡£¸Ã·¨Ê½Ã»ÓÐÑéÖ¤Ëü½«¼ÓÔØµÄDLLÊÇ·ñÒÑÊðÃû£¬£¬Òò¶øËü½«¼ÓÔØËÁÒâδÊðÃûµÄDLL¡£¡£
ÓÉÓÚ´÷¶ûSupportAssistʹÓõÄ×é¼þÊÇÓɵÚÈý·½PC-Doctor¿ª·¢ºÍÊØ»¤µÄ£¬£¬Òò¶ø¸Ã·ì϶ҲӰÏìµ½ÒÀÀµPC-DoctorµÄÆäËüPCÖÆ×÷ÉÌ¡£¡£SafeBreach LabsÈ·ÈÏÊÜÓ°ÏìµÄ×é¼þÊÇPC-Doctor Toolbox for Windows£¬£¬¸Ã×é¼þ±»ÒÔϹ¤¾ßËùʹÓãº
CORSAIR Diagnostics
Staples EasyTech Diagnostics
Tobii I-Series Diagnostic Tool
Tobii Dynavox Diagnostic Tool
·ì϶¹¦·òÏߣº
5ÔÂ08ÈÕ - ´÷¶ûÈ·Èϸ÷ì϶
5ÔÂ21ÈÕ - ´÷¶û½«·ì϶·¢Ë͸øPC-Doctor
5ÔÂ22ÈÕ - »ñµÃ±àºÅCVE-2019-12280£¬£¬assign¸øPC-Doctor
5ÔÂ28ÈÕ - ´÷¶û°ä²¼SupportAssist¸üУ¬£¬ÐÞ¸´¸Ã·ì϶
6ÔÂ19ÈÕ - ·ì϶Åû¶
ÐÞ¸´½¨Òé
½¨Òé´÷¶ûÓû§¸üÐÂÖÁÒÔϰ汾£º
Dell SupportAssist for Home PCs °æ±¾3.2.2
²Î¿¼Á´½Ó
https://safebreach.com/Post/OEM-Software-Puts-Multiple-Laptops-At-Risk
https://thehackernews.com/2019/06/dells-supportassist-hacking.html


¾©¹«Íø°²±¸11010802024551ºÅ