Windows CryptoAPIÓÕÆ­Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-01-15

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-0601£¬£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.1£¬£¬ £¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Windows 10 Version 1607

Windows 10 Version 1709

Windows 10 Version 1803

Windows 10 Version 1809

Windows 10 Version 1903

Windows 10 Version 1909

Windows Server2016

Windows Server 2019


Îó²î¸ÅÊö


2020Äê1ÔÂ14ÈÕ΢ÈíÐû²¼ÁËCVE-2020-0601Îó²îͨ¸æ£¬£¬ £¬£¬£¬£¬´ËÎó²îΪWindows¼ÓÃÜ¿âÖеÄÒ»¸öÒªº¦µÄÎó²î£¬£¬ £¬£¬£¬£¬Windows CryptoAPI(Crypt32.dll) ÑéÖ¤ÍÖÔ²ÇúÏß¼ÓÃÜ (ECC)Ö¤ÊéµÄ·½·¨Öб£´æÓÕÆ­Îó²î¡£¡£¡£¡£¡£¡£


¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÓÕÆ­ÐԵĴúÂëÊðÃûÖ¤Êé¶Ô¶ñÒâ¿ÉÖ´ÐÐÎļþ¾ÙÐÐÊðÃûÀ´Ê¹ÓôËÎó²î£¬£¬ £¬£¬£¬£¬´Ó¶øÊ¹¸ÃÎļþËÆºõÀ´×Ô¿É¿¿µÄÕýµ±ÈªÔ´¡£¡£¡£¡£¡£¡£Óû§½«ÎÞ·¨ÖªµÀÎļþÊǶñÒâµÄ£¬£¬ £¬£¬£¬£¬ÓÉÓÚÊý×ÖÊðÃûËÆºõÀ´×ÔÊÜÐÅÈεÄÌṩ³ÌÐò¡£¡£¡£¡£¡£¡£ÀֳɵÄʹÓû¹¿ÉÒÔʹ¹¥»÷Õß¾ÙÐÐÖÐÐÄÈ˹¥»÷£¬£¬ £¬£¬£¬£¬²¢ÔÚÓëÊÜÓ°ÏìÈí¼þµÄÓû§ÅþÁ¬ÉϽâÃÜÉñÃØÐÅÏ¢¡£¡£¡£¡£¡£¡£


¸ÃÎó²îΪNSA×ÔÁ¦·¢Ã÷£¬£¬ £¬£¬£¬£¬²¢»ã±¨¸øÎ¢Èí¡£¡£¡£¡£¡£¡£Æ¾Ö¤NSAÀÖ³ÉʹÓôËÎó²î½«Ê¹¹¥»÷ÕßÄܹ»ÌṩÀ´×ÔÊÜÐÅÈÎʵÌåµÄ¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£ÆäÖаüÀ¨£ºÊðÃûµÄÎļþºÍµç×ÓÓʼþ¡¢ÊðÃû¿ÉÖ´ÐдúÂëµÈ¡¢HTTPsÅþÁ¬¡£¡£¡£¡£¡£¡£


ÖµµÃ×¢ÖØµÄÊÇÖ¸¶¨²ÎÊýµÄECCÃÜÔ¿Ö¤ÊéµÄWindows°æ±¾»áÊܵ½Ó°Ï죬£¬ £¬£¬£¬£¬¶øÕâÒ»»úÖÆ£¬£¬ £¬£¬£¬£¬×îÔçÓÉWIN10ÒýÈ룬£¬ £¬£¬£¬£¬Ó°ÏìWIN10£¬£¬ £¬£¬£¬£¬Windows Server 2016/2019°æ±¾£¬£¬ £¬£¬£¬£¬¶øÓÚ½ñÄê1ÔÂ14ÈÕ×èÖ¹Ç徲ά»¤µÄWIN7/Windows Server 2008ÓÉÓÚ²»Ö§³Ö´ø²ÎÊýµÄECCÃÜÔ¿£¬£¬ £¬£¬£¬£¬Òò´Ë²»ÊÜÏà¹ØÓ°Ï죬£¬ £¬£¬£¬£¬µ«ÈÔÈ»½¨ÒéÓû§½«WIN7/ Windows Server 2008ϵͳ¸üÐÂÖÁ×îеÄWIN10ϵͳ»òWindows Server2016Ö®ºóµÄ°æ±¾£¬£¬ £¬£¬£¬£¬²¢¸üÐÂÏà¹ØÇå¾²²¹¶¡¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ΢ÈíÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬ £¬£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601

https://media.defense.gov/2020/Jan/14/2002234275/-1/-1/0/CSA-WINDOWS-10-CRYPT-LIB-20190114.PDF