Windows COM特权提升误差清静通告

宣布时间 2018-11-21

误差编号和级别


CVE编号:CVE-2018-8550 ,危险级别:高危 ,CVSS分值:官方未评定


影响版本


Windows 7 ,Windows Server 2012 R2 ,Windows RT 8.1 ,Windows Server 2008 ,Windows Server 2019 ,Windows Server 2012 ,Windows 8.1 ,Windows Server 2016 ,Windows Server 2008 R2 ,Windows 10 ,Windows 10 Server


误差概述


Windows COM Aggregate Marshaler 中保存权限提升误差。乐成使用此误差的攻击者可以使用提升的特权运行恣意代码。

若要使用此误差 ,攻击者可以运行经特殊设计并能够使用此误差的应用程序。此误差自己不允许运行恣意代码。可是 ,此误差可能与一个或多个可在运行时使用提升特权的误差团结使用。


误差验证


POC/EXP:

https://www.exploit-db.com/exploits/45893/


尊龙凯时 - 人生就是搏!


修复建议


微软官方已经宣布更新补丁 ,请实时举行补丁更新。

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8550


参考链接

https://bugs.chromium.org/p/project-zero/issues/detail?id=1644