Intel Wi-FiÇý¶¯Â©¶´·ÖÎö

Ðû²¼Ê±¼ä 2021-04-27

Intel Wi-FiоƬ¹ã·ºÓ¦ÓÃÓÚ¸öÈËÌõ¼Ç±¾µçÄÔ²úÎÈçThinkPad¡¢DellÌõ¼Ç±¾µÈ ¡£2020Ä꣬ZDI×éÖ¯Åû¶ÁËIntelÎÞÏßÍø¿¨WindowsÇý¶¯·¨Ê½ÖдæÔÚCVE-2020-0557 ºÍ CVE-2020-0558©¶´ ¡£ÆäÖУ¬CVE-2020-0557µÄCVSS v3.0ÆÀ·ÖΪ 8.1 ·Ö£¬CVE-2020-0558µÄCVSS v3.0ÆÀ·ÖΪ 8.2 ·Ö ¡£Í¨¹ýÕâÁ½¸ö©¶´£¬¹¥»÷Õß¿ÉÒÔÔÚÊܺ¦ÕßµçÄÔÖÐÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë ¡£


©¶´±àºÅÓ°ÏìµÄÎÞÏßÍø¿¨Ó°ÏìÇý¶¯
CVE-2020-0557AC 7265 Rev D¡¢AC 3168¡¢AC 8265ºÍAC8260Intel PROSet/Wireless WiFi Software 21.70֮ǰ°æ±¾
CVE-2020-0558AC8265Intel PROSet/Wireless WiFi Software 21.70֮ǰ°æ±¾


CVE-2020-0558©¶´·ÖÎö


1¡¢Â©¶´Ô­Àí

µ±APÈȵ㴦ÖÃAssocReqʱ£¬»áµ÷ÓÃprvhPanClientSaveAssocRespº¯ÊýÉú´æAssocReqÖ¡ÖÐSSIDµÄÖµ£¬ÔÚ´¦ÖÃSSIDµÄ¹ý³ÌÖУ¬»áµ÷ÓÃparse_ieº¯Êý´ÓÊý¾ÝÖ¡ÖÐÈ¡³össidµÄTLV½á¹¹£¬²¢µ÷ÓÃmemcpy_sº¯Êý½«ssidµÄÄÚÈݸ´ÖƵ½Ä¿±ê»º³åÇø ¡£ÔÚµ÷ÓÃmemcpy_sº¯ÊýµÄʱºò£¬´íÎóµØʹÓÃssidµÄlength×÷ΪÊý¾Ý¸´ÖƳ¤¶È£¬µ±ssidµÄ³¤¶È´óÓÚÄ¿±ê»º³åÇøµÄ³¤¶Èʱ£¬»áµ¼Ö»º³åÇøÒç³ö ¡£º¯Êýµ÷ÓÃͼÈçÏÂËùʾ£º


1.jpg


2¡¢ÎÊÌâ´úÂë

µ÷ÓÃparse_ieº¯Êý´ÓÊý¾ÝÖ¡ÖÐÈ¡³össidµÄTLV½á¹¹£¬²¢µ÷ÓÃmemcpy_sº¯Êý½«ssidµÄÄÚÈݸ´ÖƵ½Ä¿±ê»º³åÇø ¡£ÔÚµ÷ÓÃmemcpy_sº¯ÊýµÄʱºò£¬´íÎóµØʹÓÃssidµÄlength×÷ΪÊý¾Ý¸´ÖƳ¤¶È£¬µ±ssidµÄ³¤¶È´óÓÚÄ¿±ê»º³åÇøµÄ³¤¶Èʱ£¬»áµ¼Ö»º³åÇøÒç³ö ¡£ÔÚÏÂͼÖУ¬¹¥»÷Õß¿ÉÒÔ¿ØÖÆ*(v8+1)µÄÖµ£¬¿ÉÒÔ¿½±´³¬³¤µÄÊý¾Ý¸´ÖƵ½Ä¿±êµØÖ·ÖУ¬´Ó¶øµ¼Ö»º³åÇøÒç³ö ¡£ÈçÏÂͼËùʾ£º


2.jpg


3¡¢Â©¶´ÐÞ¸´

а汾µÄ´úÂëÖÐʹÓÃosalMemoryCopyº¯ÊýÌæ´úÁËÔ­À´µÄmemcpy_sº¯Êý£¬ÁíÍâ°ÑSSID¿½±´µÄ×î´ó³¤¶ÈÇ¿ÖÆÉèΪ32×Ö½Ú£¬ÕâÑù¾ÍÖÆÖ¹ÁË»º´æÇøÒç³öµÄÎÊÌâ ¡£ÈçÏÂͼËùʾ£º


3.jpg


CVE-2020-0557©¶´·ÖÎö


1¡¢Â©¶´Ô­Àí

µ±APÈȵ㴦ÖÃAssocReqʱ£¬»áµ÷ÓÃprvhPanClientSaveAssocRespº¯Êý´¦ÖÃAssocReqÖ¡ÖеÄÊý¾Ý£¬ÆäÖÐÔÚº¯ÊýÖлáµ÷ÓÃprvGoVifClientAssocStoreSupportedChannelsº¯ÊýÀ´´¦Öü°Éú´æÇëÇó¶ËͨµÀÐÅÏ¢£¬ÕâÆäÖÐprvGoVifClientAssocStoreSupportedChannelsº¯Êý»áÑ­»·µ÷ÓÃutilRegulatoryClassToChannelListÀ´´¦ÖÃRegulatoryClass£¨¹ÜÖÆÒªÇó£©ÐÅÏ¢ ¡£ÓÉÓÚÔÚÑ­»·´¦ÖÃûÓп¼ÂÇÄ¿±êµÄÆ«ÒÆÊÇ·ñÔ½½ç£¬µ±APÈȵã½ÓÊÕµ½AssocReqÊý¾ÝÖ¡ÖÐRegulatoryClassÐÅÏ¢µ¥ÔªÓжà¸öÐŵÀÊý¾Ýʱ»áµ¼ÖÂÔ½½çд ¡£º¯Êýµ÷ÓÃͼÈçÏÂͼËùʾ£º


4.jpg



2¡¢ÎÊÌâ´úÂë

prvGoVifClientAssocStoreSupportedChannelsº¯Êý£¬ÈçÏÂͼËùʾ£º

 

5.jpg

6.jpg


3¡¢Â©¶´ÐÞ¸´

ÔÚа汾 Ôö½øÁ˶Ե±Ç°indexµÄÅжÏ£¬Èç¹ûindex´óÓÚ255ÔòÍ˳öÑ­»· ¡£ÈçÏÂͼËùʾ£º


7.jpg


 4¡¢Â©¶´ÑéÖ¤



²Î¿¼Á´½Ó£º

¡¾1¡¿https://www.thezdi.com/blog/2020/5/4/analyzing-a-trio-of-remote-code-execution-bugs-in-intel-wireless-adapters


¶«É­Æ½Ì¨»ý¼«·ÀÓùʵÑéÊÒ£¨ADLab£©


ADLab½¨Á¢ÓÚ1999Ä꣬ÊÇÖйúÄþ¾²ÐÐÒµ×îÔ罨Á¢µÄ¹¥·À¼¼ÊõÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPP¼Æ»®ºËÐijÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß ¡£½ØֹĿǰ£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Äþ¾²Â©¶´½ü1100¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Äþ¾²Â©¶´1000Óà¸ö£¬Á¬Ðø±£³Ö¹ú¼ÊÍøÂçÄþ¾²ÁìÓòÒ»Á÷Ë®×¼ ¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÄþ¾²Ñо¿¡¢ÖÇÄÜÖÕ¶ËÄþ¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜÉ豸Äþ¾²Ñо¿¡¢WebÄþ¾²Ñо¿¡¢¹¤¿ØϵͳÄþ¾²Ñо¿¡¢ÔÆÄþ¾²Ñо¿ ¡£Ñо¿½á¹ûÓ¦ÓÃÓÚ²úÎïºËÐļ¼ÊõÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÄþ¾²·þÎñµÈ ¡£


adlab.jpg