ESET/ãã«ã¦ã§ã¢æ å ±å±
Windowsã®ã¼ããã¤èå¼±æ§ãä¿®æ£ããããããªãªã¼ã¹
ãæ¬è¨äºã¯ãã¤ãã³ãã¼ã±ãã£ã³ã°ã¸ã£ãã³ãæä¾ããããã«ã¦ã§ã¢æ å ±å±ãã«æ²è¼ããããæ¨çåæ»æã§æªç¨ãããWindowsã®ã¼ããã¤èå¼±æ§ãESETãè¦ã¤ããããåç·¨éãããã®ã§ãã
ã2019å¹´6æãESETã®ç ç©¶è ã¯ãæ±ã¨ã¼ãããã«ãããæ¨çåæ»æã§ä½¿ç¨ããã¦ããã¼ããã¤ã¨ã¯ã¹ããã¤ããæ¤åºãã¾ããã
ããã®ã¨ã¯ã¹ããã¤ãã¯ãMicrosoft Windowsã«åå¨ãããã¼ã«ã«æ¨©éææ ¼ã®èå¼±æ§ãå ·ä½çã«ã¯ãwin32k.sysã³ã³ãã¼ãã³ãã«ããNULLãã¤ã³ã¿ã®éåç §ãæªç¨ãã¾ãããã®ã¨ã¯ã¹ããã¤ãã¯æ¤åºããã³åæãããMicrosoftã®ã»ãã¥ãªãã£ã¬ã¹ãã³ã¹ã»ã³ã¿ã¼ã«å ±åããã¾ãããMicrosoftã»ãã¥ãªãã£ã¬ã¹ãã³ã¹ã»ã³ã¿ã¼ã¯éããã«ãã®èå¼±æ§ãä¿®æ£ãããããããªãªã¼ã¹ãã¾ããã
ããã®èå¼±æ§ã¯æ¬¡ã®ãã¼ã¸ã§ã³ã®Windowsã«å½±é¿ãã¾ãã
ãWindows 7 for 32-bit Systems Service Pack 1
ãWindows 7 for x64-based Systems Service Pack 1
ãWindows Server 2008 for 32-bit Systems Service Pack 2
ãWindows Server 2008 for Itanium-Based Systems Service Pack 2
ãWindows Server 2008 for x64-based Systems Service Pack 2
ãWindows Server 2008 R2 for Itanium-Based Systems Service Pack 1
ãWindows Server 2008 R2 for x64-based Systems Service Pack 1
ããã®ããã°ã§ã¯ããã®èå¼±æ§ã¨ã¨ã¯ã¹ããã¤ãã®æè¡çãªè©³ç´°ã«ã¤ãã¦ä¸»ã«èª¬æãã¾ããæ¬¡åã®ããã°ã§ã¯ããã®ãã«ã¦ã§ã¢ã®æ¤ä½ã¨ãã«ã¦ã§ã¢ã«ããåºç¯ãªå½±é¿ã«ã¤ãã¦è©³ãã説æãã¾ãã
æ»æææ³
ããã®æ°å¹´å ¬éãããä»ã®å¤ãã®Microsoft Windowsã®win32k.sysèå¼±æ§ã¨åæ§ã«ããã®ã¨ã¯ã¹ããã¤ãã¯ãããã¢ããã¡ãã¥ã¼ãªãã¸ã§ã¯ãã使ç¨ãã¾ãããã¨ãã°ã2017å¹´ã«ESETãåæããSednitã°ã«ã¼ãã®ãã¼ã«ã«æ¨©éææ ¼ã®ã¨ã¯ã¹ããã¤ãã§ã¯ãä»åã®ã¨ã¯ã¹ããã¤ãã¨é常ã«ããä¼¼ãã¡ãã¥ã¼ãªãã¸ã§ã¯ãã¨æ»æææ³ã使ç¨ããã¦ãã¾ãã
ããã®ã¨ã¯ã¹ããã¤ãã¯2ã¤ã®ã¦ã£ã³ãã¦ã使ãã¾ããæ»æã®æåã®æ®µéã¨2çªç®ã®æ®µéã§1ã¤ãã¤ã¦ã£ã³ãã¦ã使ãã¾ããæåã®ã¦ã£ã³ãã¦ã§ã¯ãCreatePopupMenu颿°ã¨AppendMenu颿°ã使ç¨ãã¦ãããã¢ããã¡ãã¥ã¼ãªãã¸ã§ã¯ãã使ããã¡ãã¥ã¼é ç®ã追å ãã¾ããããã«ããã®ã¨ã¯ã¹ããã¤ãã¯ãWH_CALLWNDPROCã¨EVENT_SYSTEM_MENUPOPUPSTARTããã¯ãè¨å®ãã¾ãã
ãæ¬¡ã«ããã®ã¨ã¯ã¹ããã¤ãã¯TrackPopupMenu颿°ã使ã£ã¦ã¡ãã¥ã¼ã表示ãã¾ãããã®æç¹ã§ãEVENT_SYSTEM_MENUPOPUPSTARTã«ããã¯ãããã³ã¼ããå®è¡ããã¾ãããã®ã³ã¼ãã¯ãMN_SELECTITEMãMN_SELECTFIRSTVALIDITEMãããã³MN_OPENHIERARCHYã®ä¸é£ã®ã¡ãã»ã¼ã¸ãã¡ãã¥ã¼ã«éä¿¡ããã¡ãã¥ã¼ã§æåã®å©ç¨å¯è½ãªã¢ã¤ãã ãéãã¾ãã
ãæ¬¡ã®ã¹ãããã¯ããã®èå¼±æ§ãããªã¬ã¼ããããã«é常ã«éè¦ã§ããæåã®ã¡ãã¥ã¼ã使ãããå¾ã«ããµãã¡ãã¥ã¼ã使ããããã¨ãã¦ããç¬éããã®ã¨ã¯ã¹ããã¤ãã¯æããå¿ è¦ãããã¾ãããã®ããã«ããã®ã¨ã¯ã¹ããã¤ãã«ã¯ãWH_CALLWNDPROCããã¯ã§WM_NCCREATEã¡ãã»ã¼ã¸ãå¦çããã³ã¼ããåå¨ãã¾ããã¨ã¯ã¹ããã¤ãã®ã³ã¼ãã«ãã£ã¦ãã·ã¹ãã ããã®ãããªç¶æ ã«ãããã¨ãæ¤åºãããã¨ãæåã®ã¡ãã¥ã¼ã«MN_CANCELMENUSï¼0x1E6ï¼ã¡ãã»ã¼ã¸ãéä¿¡ãããæåã¡ãã¥ã¼ã¯ãã£ã³ã»ã«ããã¾ããããã®ãµãã¡ãã¥ã¼ã¯ã¾ã 使ããããã¨ãã¦ãã¾ãã
ããã®ãµãã¡ãã¥ã¼ãªãã¸ã§ã¯ããã«ã¼ãã«ã¢ã¼ãã§ç¢ºèªããã¨ã tagPOPUPMENU >ppopupmenuRootã¯0ã«ãªã£ã¦ãããã¨ããããã¾ãããã®ç¶æ ã§ã¯ãæ»æè ã¯ãã®ã«ã¼ãã«æ§é ã«ãããã®è¦ç´ ãNULLãã¤ã³ã¿ã®éåç §ã¨ãã¦ä½¿ç¨ã§ãã¾ãããã®ã¨ã¯ã¹ããã¤ãã¯ã¢ãã¬ã¹0x0ã«æ°ãããã¼ã¸ãå²ãå½ã¦ã¾ãããã®ã¢ãã¬ã¹ã¯ã«ã¼ãã«ã«ãã£ã¦tagPOPUPMENUãªãã¸ã§ã¯ãï¼å³1åç §ï¼ã¨ãã¦æ±ããã¾ãã
ããã®æç¹ã§ãæ»æè ã¯2çªç®ã®ã¦ã£ã³ãã¦ã使ç¨ãã¾ãããã®ã¨ã¯ã¹ããã¤ãã®ä¸»ãªç®çã¯ã2çªç®ã®ã¦ã£ã³ãã¦ã®tagWNDæ§é ã®bServerSideWindowProcããããå転ããããã¨ã§ããããã«ãããã«ã¼ãã«ã¢ã¼ãã§WndProcããã·ã¼ã¸ã£ãå®è¡ã§ããããã«ãªãã¾ãã
ãWndProcããã·ã¼ã¸ã£ãå®è¡ããããã«ãæ»æè ã¯user32.dllã©ã¤ãã©ãªã§ã¨ã¯ã¹ãã¼ãããã¦ããªãHMValidateHandle颿°ãå¼ã³åºãã¦ã2çªç®ã®ã¦ã£ã³ãã¦ã®tagWNDæ§é ã®ã«ã¼ãã«ã¡ã¢ãªã¢ãã¬ã¹ããªã¼ã¯ãã¾ããæ¬¡ã«ããã®ã¨ã¯ã¹ããã¤ãã¯NULLãã¼ã¸ã§å½ã®tagPOPUPMENUãªãã¸ã§ã¯ãã使ãããµãã¡ãã¥ã¼ã«MN_BUTTONDOWNã¡ãã»ã¼ã¸ãéä¿¡ãã¾ãã
ããã®å¾ãã«ã¼ãã«ã¯æçµçã«win32k!xxxMNOpenHierarchy颿°ãå®è¡ãã¾ãã
ããã®é¢æ°ã¯NULLãã¼ã¸ã§ç´°å·¥ããããªãã¸ã§ã¯ããwin32k!HMAssignmentLockã«æ¸¡ãã¾ããbServerSideWindowProcããããwin32k!HMAssignmentLock颿°ã§è¨å®ããã¦ãã¾ãããã®é¢æ°ã¯ãwin32k!HMDestroyUnlockedObjectã®æ·±å±¤ã«ããããã¤ãã®å¼ã³åºãã«åå¨ãã¾ãã
ãããã§ãã¹ã¦å®äºã§ãããã®ã¨ã¯ã¹ããã¤ãã¯ã2çªç®ã®ã¦ã£ã³ãã¦ã«ç¹æ®ãªã¡ãã»ã¼ã¸ãéä¿¡ãã¦ãWndProcãã«ã¼ãã«ã¢ã¼ãã§å®è¡ã§ããããã«ãªãã¾ããã
ããã®ã¨ã¯ã¹ããã¤ãã¯ãæå¾ã®ã¹ãããã¨ãã¦ãç¾å¨ã®ããã»ã¹ãã¼ã¯ã³ãã·ã¹ãã ãã¼ã¯ã³ã«ç½®ãæãã¾ãã
çµè«
ãWindows 8以éã§ã¯ã¦ã¼ã¶ã¼ããã»ã¹ãNULLãã¼ã¸ã«ãããã³ã°ãããã¨ã許å¯ãããªãããããã®æ»æã¯å¤ããã¼ã¸ã§ã³ã®Windowsã«å¯¾ãã¦ã®ã¿æ©è½ãã¾ããMicrosoftã¯ããã®å¯¾çãWindows 7 for x64-based systemsã«ããã¯ãã¼ããã¦ãã¾ãã
ãWindows 7 for 32-bit systems Service Pack 1ãã¾ã 使ç¨ãã¦ããã¦ã¼ã¶ã¼ã¯ã2020å¹´1æ14æ¥ã«Windows 7 Service Pack 1ã®å»¶é·ãµãã¼ããçµäºãããããæ°ãããªãã¬ã¼ãã£ã³ã°ã·ã¹ãã ã«ã¢ãããã¼ããããã¨ãæ¤è¨ãã¦ãã ãããWindows 7ã®å»¶é·ãµãã¼ããçµäºããã¨ãWindows 7ã®ã¦ã¼ã¶ã¼ã«ç·æ¥ã®ã»ãã¥ãªãã£ã¢ãããã¼ãã¯æä¾ãããªããªãããã®ãããªèå¼±æ§ã®ä¿®æ£ãããã¯æ°¸ä¹ ã«é©ç¨ããã¾ããã
| IoCï¼ã»ãã¥ãªãã£ä¾µå®³ã®çè·¡æ å ±ï¼ | |
|---|---|
| SHA-1 | ãã¡ã¤ã«å |
| CBC93A9DD769DEE98FFE1F43A4F5CADAF568E321 | Win32/Exploit.CVE-2019-1132.A |
ãã®è¨äºã®ç·¨éè ã¯ä»¥ä¸ã®è¨äºããªã¹ã¹ã¡ãã¦ãã¾ã
-
ãã¸ã¿ã«
PCã使ããªãä¸ä»£ã«ã©ããªã»ãã¥ãªãã£ã¼å¯¾çæè²ãããã¹ããï¼ -
ãã¸ã¿ã«
ãã£ã¼ãªã³ã¯ã®ã«ã¡ã©ã«èå¼±æ§ããããªçã¿è¦ã«ãã¡ã¼ã ã¦ã§ã¢æä½ã -
ãã¸ã¿ã«
ã¨ã¯ã¹ããã¤ãã使ã£ãæ»æãæ¯æ¥æ°10ä¸ä»¶ãèµ·ãã¦ãã -
ãã¸ã¿ã«
macOSãçã£ããã«ã¦ã§ã¢ãã¢ãããã¼ãã§æ©è½è¿½å -
ãã¸ã¿ã«
SSDãHDDããã«ãã£ã¹ã¯æå·åã§ãããESET Endpoint Encryptionã
