´÷¶ûSupportAssist DLL½Ù³Ö©¶´

Ðû²¼Ê±¼ä 2019-06-22

Åä¾°ÃèÊö


6ÔÂ21ÈÕ´÷¶ûÐû²¼Äþ¾²Í¨±¨£¬¶Ø´ÙÓû§¸üд÷¶ûµçÄÔÉÏÔ¤°²×°µÄSupportAssistÈí¼þ£¬ÒÔÐÞ¸´DLL½Ù³Ö©¶´£¨CVE-2019-12280£© ¡£¸Ã©¶´¿É±»¾ßÓÐͨÀýÓû§È¨Ï޵Ĺ¥»÷ÕßÀûÓã¬Í¨¹ý¶ñÒâDLLÎļþ½øÐÐÌáȨºÍ»ñµÃ³Ö¾ÃÐÔ ¡£

©¶´Áбí


CVE ID  £º   CVE-2019-12280
´÷¶ûDSA±àºÅ£º   DSA-2019-084
©¶´Æ·¼¶£º   ¸ßΣ
CVSSÆÀ·Ö£º   ÔÝÎÞ
Ó°Ï췶Χ£º   Dell SupportAssist for Business PCs°æ±¾2.0£»Dell SupportAssist for Home PCs 3.2.1¼°Ö®Ç°µÄËùÓа汾

©¶´ÏêÇé


SupportAssistÊÇ´÷¶ûµçÄÔÉÏÔ¤°²×°µÄÒ»¸öÈí¼þ£¬ÓÃÓÚ¼ì²éϵͳӲ¼þºÍÈí¼þµÄÔËÐÐ×´¿ö£¬¸ÃÈí¼þÒÔSYSTEMȨÏÞÔËÐÐ ¡£SafeBreach LabsÑо¿ÈËÔ±·¢ÏÖ¸ÃÈí¼þ´æÔÚDLL½Ù³Ö©¶´£¨CVE-2019-12280£©£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß½«ÈÎÒâδǩÃûµÄDLL¼ÓÔص½ÒÔSYSTEMȨÏÞÔËÐеķþÎñÖУ¬´Ó¶øʵÏÖȨÏÞÌáÉýºÍ³Ö¾ÃÐÔ - °üÂÞ¶ÔÎïÀíÄڴ桢ϵͳ¹ÜÀíBIOSµÈµ×²ã×é¼þµÄ¶Á/д·ÃÎÊ ¡£¸Ã©¶´Ê¹¹¥»÷ÕßÄܹ»Í¨¹ýÒÑÇ©ÃûµÄ·þÎñ¼ÓÔغÍÖ´ÐжñÒâpayload£¬¹¥»÷Õ߿ɽ«´ËÄÜÁ¦ÓÃÓÚÖ´ÐлòÌӱܼì²âµÈ²îÒìÄ¿µÄ£¬ÀýÈ磺ӦÓ÷¨Ê½°×Ãûµ¥Èƹý¡¢Ç©ÃûÑéÖ¤Èƹý ¡£


ƾ¾ÝSafeBreachµÄ³ÂËߣ¬¸Ã©¶´µÄ»ù´¡Ô­ÒòÊÇ£º


1¡¢È±·¦Äþ¾²µÄDLL¼ÓÔØ ¡£´úÂëÖÐʹÓÃLoadLibraryWÒªÁ죬¶ø²»ÊÇLoadLibraryExW£»ÕâÔÊÐíδ¾­ÊÚȨµÄÓû§Í¨¹ýijЩ±êÖ¾À´½ç˵ËÑË÷˳Ðò£¬ÀýÈçLOAD_LIBRARY_SEARCH_DLL_LOAD_DIR ¡£·´¹ýÀ´£¬¸Ã±êÖ¾ÓÖÏÞ¶¨Ö»ÔÚ×Ô¼ºµÄÎļþ¼ÐÖÐËÑË÷DLL£¬ÖÆÖ¹ÁËÔÚPATH±äÁ¿ÖÐËÑË÷DLLµÄÇé¿ö ¡£


2¡¢Ã»ÓжԶþ½øÖÆÎļþ½øÐÐÇ©ÃûÑéÖ¤ ¡£¸Ã·¨Ê½Ã»ÓÐÑéÖ¤Ëü½«¼ÓÔصÄDLLÊÇ·ñÒÑÇ©Ãû£¬Òò´ËËü½«¼ÓÔØÈÎÒâδǩÃûµÄDLL ¡£


ÓÉÓÚ´÷¶ûSupportAssistʹÓõÄ×é¼þÊÇÓɵÚÈý·½PC-Doctor¿ª·¢ºÍά»¤µÄ£¬Òò´Ë¸Ã©¶´Ò²Ó°Ïìµ½ÒÀÀµPC-DoctorµÄÆäËüPCÖÆÔìÉÌ ¡£SafeBreach LabsÈ·ÈÏÊÜÓ°ÏìµÄ×é¼þÊÇPC-Doctor Toolbox for Windows£¬¸Ã×é¼þ±»ÒÔϹ¤¾ßËùʹÓãº


CORSAIR ONE Diagnostics
CORSAIR Diagnostics
Staples EasyTech Diagnostics
Tobii I-Series Diagnostic Tool
Tobii Dynavox Diagnostic Tool

©¶´Ê±¼äÏߣº


4ÔÂ29ÈÕ - ³ÂËß©¶´
5ÔÂ08ÈÕ - ´÷¶ûÈ·Èϸ鶴
5ÔÂ21ÈÕ - ´÷¶û½«Â©¶´·¢Ë͸øPC-Doctor
5ÔÂ22ÈÕ - »ñµÃ±àºÅCVE-2019-12280£¬assign¸øPC-Doctor
5ÔÂ28ÈÕ - ´÷¶ûÐû²¼SupportAssist¸üУ¬ÐÞ¸´¸Ã©¶´
6ÔÂ19ÈÕ - ©¶´Åû¶

ÐÞ¸´½¨Òé


½¨Òé´÷¶ûÓû§¸üÐÂÖÁÒÔÏ°汾£º


Dell SupportAssist for Business PCs °æ±¾2.0.1
Dell SupportAssist for Home PCs °æ±¾3.2.2

²Î¿¼Á´½Ó


https://www.dell.com/support/article/cn/zh/cndhs1/sln317291/dsa-2019-084-dell-supportassist-for-business-pcs-and-dell-supportassist-for-home-pcs-security-update-for-pc-doctor-vulnerability?lang=en
https://safebreach.com/Post/OEM-Software-Puts-Multiple-Laptops-At-Risk
https://thehackernews.com/2019/06/dells-supportassist-hacking.html