BitdefenderÃâ·Ñ°æÉ±¶¾Èí¼þÖеÄÌáȨÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-23

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-15295£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£ºÖÐΣ£¬£¬£¬ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º5.9£¬£¬£¬ £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Bitdefender Antivirus Free 2020


Îó²î¸ÅÊö


Bitdefender EnginesÊÇÂÞÂíÄáÑDZÈÌØèóµÂ£¨Bitdefender£©¹«Ë¾µÄÒ»¿îɱ¶¾Èí¼þÒýÇæ¡£¡£


Bitdefender Antivirus Ãâ·Ñ°æ±¾Öб»ÆØÒ»¸öÌáȨÎó²î£¬£¬£¬ £¬¿Éµ¼Ö¹¥»÷Õß»ñȡΪ Windows ×î¸ßȨÏÞÕË»§×¼±¸µÄϵͳ¼¶±ðȨÏÞ¡£¡£


¸ÃÎó²îÔ´ÓÚȱ·¦¶ÔÒÑÊðÃûÇÒ¼ÓÔØ×Ô¿ÉÐÅλÖõĶþ½øÖƵÄÑéÖ¤Ôì³ÉµÄ¡£¡£Bitdefender µÄÇ徲ЧÀÍ (vsserv.exe) ºÍ¸üÐÂЧÀÍ (updatesrv.exe) ×÷ΪÒÔϵͳȨÏÞÊðÃûµÄÀú³Ì¶øÆô¶¯¡£¡£È»¶ø£¬£¬£¬ £¬ËûÃÇʵÑéÔÚ PATH ÇéÐαäÁ¿ÖеĶà¸öλÖüÓÔØÉ¥Ê§µÄÒ»¸ö DLL Îļþ (¡®RestartWatchDog.dll¡¯)£¬£¬£¬ £¬ÈçͼËùʾ£º


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÆäÖÐÒ»¸öλÖÃÊÇ¡®c:/python27¡¯£¬£¬£¬ £¬ËüÏòËùÓÐÈÏÖ¤Óû§¿ª·ÅÁË»á¼û¿ØÖÆÁбí (ACL)£¬£¬£¬ £¬Ê¹ÌáȨ²Ù×÷ÍòÎÞһʧ£¬£¬£¬ £¬ÓÉÓÚÕý³£È¨ÏÞµÄÓû§Äܹ»Ð´ÈëɥʧµÄ DLL²¢Í¨¹ý Bitdefender µÄÊðÃûÀú³Ì¼ÓÔØËü¡£¡£ÎÊÌâµÄ¸ùÒòÔÚÓÚServiceInstance.dll ¿âÊÔͼ¼ÓÔØÉ¥Ê§µÄ DLL¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ£¬£¬£¬ £¬¹Ù·½ÒÑÐû²¼ÁËÐÞ¸´¸ÃÎó²î£¬£¬£¬ £¬ÏÂÔØÁ´½Ó£º


https://www.bitdefender.com/support/security-advisories/untrusted-search-path-vulnerability-serviceinstance-dll-bitdefender-antivirus-free-2020/¡£¡£


²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/security/bitdefender-fixes-privilege-escalation-bug-in-free-antivirus-2020/