Ç÷ÊÆ¿Æ¼¼·ÀÍþв¹¤¾ß°üÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-10-23

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-9491£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨£¬£¬£¬£¬£¬£¬³§ÉÌ×ÔÆÀ7.5


Ó°Ïì°æ±¾


ATTK 1.62.0.1218 ¼°ÒÔϰ汾¡£¡£¡£ ¡£¡£


µ¥»ú°æÓ°Ïì ATTK×é¼þ¼°ÆäËü²¿·Ö£¨Èç WCRY²¹¶¡¹¤¾ß¡¢OfficeScanToolbox µÈ£©


Îó²î¸ÅÊö


Ç÷ÊÆ¿Æ¼¼·ÀÍþв¹¤¾ß¼¯£¨Anti-Threat Toolkit£¬£¬£¬£¬£¬£¬¼ò³Æ ATTK£©Öб»ÆØ±£´æÒ»¸öȱÏÝ£¬£¬£¬£¬£¬£¬¿É±»ºÚ¿ÍÓÃÓÚÔÚÊܺ¦Õß Windows ÅÌËã»úÉÏÔËÐжñÒâÈí¼þ¡£¡£¡£ ¡£¡£


CVE-2019-9491ÓÉHyp3rlinx·¢Ã÷¡£¡£¡£ ¡£¡£ATTK¿É±»ÓÕÆ­Ö´ÐÐí§ÒâÈí¼þ£¬£¬£¬£¬£¬£¬°üÀ¨¶ñÒâÈí¼þÔÚÄÚ¡£¡£¡£ ¡£¡£µ±¶ñÒâÈí¼þ±»É¨Ãèʱ£¬£¬£¬£¬£¬£¬ÈôÊÇÎļþÃûÊÇ cmd.exe »ò regedit.exe£¬£¬£¬£¬£¬£¬ÄÇô¶ñÒâÈí¼þ¾Í»á±»Ö´ÐС£¡£¡£ ¡£¡£


ÈôÊǶñÒâÈí¼þ×÷ÕßÇ¡ÇÉʹÓÃÁËÒ×Êܹ¥»÷µÄÃüÃûÔ¼¶¨¡®cmd.exe¡¯»ò¡®regedit.exe¡¯£¬£¬£¬£¬£¬£¬ATTK ½«»á¼ÓÔØ²¢Ö´ÐÐí§Òâ .EXE Îļþ¡£¡£¡£ ¡£¡£µ±ÖÕ¶ËÓû§Æô¶¯É¨Ãèʱ£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ¾Í¿É·ÅÔÚ ATTKÖÜΧ¡£¡£¡£ ¡£¡£


ATTK ¿É±»ÓÕÆ­ÔËÐв¡¶¾¡£¡£¡£ ¡£¡£ÈôÊÇÄãÄܹ»Í¨¹ýÏÂÔØÆ÷»òÓʼþµÈ·½·¨ÔÚ±ðÈ˵ĵçÄÔÉϽ«ÎļþÉúÑÄΪcmd.exe »ò regedit.exe£¬£¬£¬£¬£¬£¬ÄÇô¹¥»÷Õ߾ͿÉÒÔͨ¹ýÔËÐÐ ATTKÖ´ÐжñÒâ´úÂë¡£¡£¡£ ¡£¡£


ÓÉÓÚATTK ÊÇÓÉÂÄÀúÖ¤µÄÐû²¼·½ÊðÃûµÄ£¬£¬£¬£¬£¬£¬Òò´ËÈôÊǶñÒâÈí¼þÊÇ´Ó»¥ÁªÍøÉÏÏÂÔØµÄ£¬£¬£¬£¬£¬£¬ÄÇôËü»áÈÆ¹ýÈκοÉÐŵÄMOTWÇå¾²ÖÒÑÔ£¬£¬£¬£¬£¬£¬Í¬Ê±ÓÉÓÚÿ´ÎÔËÐÐ ATTK ʱҲ»áÔËÐжñÒâÈí¼þ£¬£¬£¬£¬£¬£¬Òò´ËËüÒ²³ÉΪһÖÖ³¤ÆÚÐÔ»úÖÆ¡£¡£¡£ ¡£¡£


Îó²îÑéÖ¤


EXP£º

ͨ¹ýÈçÏ C ´úÂë±àÒëÒ»¸ö .EXE£¬£¬£¬£¬£¬£¬²¢Ê¹Óá°cmd.exe¡±»ò¡°regedit.exe¡±×÷ΪÃüÃûÔ¼¶¨¡£¡£¡£ ¡£¡£ÔËÐÐ ATTK¹¤¾ß²¢ÊÓ²ì ATTKÃæ°åÒÔÉó²éľÂíÎļþ±»¼ÓÔØÇÒÖ´ÐеÄÀú³Ì¡£¡£¡£ ¡£¡£


#include <windows.h>

void main(void){

  puts("Trend Micro Anti-Threat Toolkit PWNED!");

  puts("Discovery: hyp3rlinx");

  puts("CVE-2019-9491\n");

  WinExec("powershell", 0);

}


PoC ÊÓÆµURL£º


https://www.youtube.com/watch?v=HBrRVe8WCHs


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



ÐÞ¸´½¨Òé


Ç÷ÊÆ¿Æ¼¼ÏÖÒѽ«ËùÓÐ ATTK¸üÐÂÖÁ 1.62.0.1223°æ±¾¡£¡£¡£ ¡£¡£µ«ÉÐδÐû²¼Ï¸½Ú¡£¡£¡£ ¡£¡£

https://success.trendmicro.com/solution/000149878


²Î¿¼Á´½Ó


http://hyp3rlinx.altervista.org/advisories/TREND-MICRO-ANTI-THREAT-TOOLKIT-(ATTK)-REMOTE-CODE-EXECUTION.txt