ʱ¼ä£º2021-10-28 ×÷ÕߣºÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐÄ
Åä¾°
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐĺìÓêµÎÍŶÓÍŽáºìÓêµÎÔÆÉ³Ïä²ú³öµÄÏà¹ØIOCÇ鱨£¬£¬£¬£¬£¬£¬£¬²¢ÅäºÏÄÚ²¿ÃÛ¹Þϵͳ£¬£¬£¬£¬£¬£¬£¬ÔÚÈ«Çò¹æÄ£ÄÚÊ׸ö¼à²âµ½¶àÀý×éºÏʹÓÃChromeä¯ÀÀÆ÷¸ßΣÎó²îºÍWindowsÄÚºËȨÏÞÌáÉýÎó²îÓÃÓÚ´©Í¸Chromeä¯ÀÀÆ÷ɳºÐʵÏÖÔ¶³Ì´úÂëÖ´Ðе͍Ïò¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÊµÏÖÁË»ùÓÚÍþвÇ鱨ºÍÁ÷Á¿ÆÊÎöµÄÔÚÒ°Chromeä¯ÀÀÆ÷Îó²î¹¥»÷¼ì²âµÄÍ»ÆÆ¡£¡£¡£¡£¡£¡£¡£¡£
¹ØÓÚPuzzleMaker
̫ͨ¹ýÎöÑÐÅУ¬£¬£¬£¬£¬£¬£¬ºìÓêµÎÍŶӲ¶»ñµ½µÄChromeä¯ÀÀÆ÷ÍêÕûÎó²îʹÓù¥»÷Á´ÒÉËÆ½ñÄê6ÔÂ8ÈÕÓÉ¿¨°Í˹»ùÅû¶µÄPuzzleMaker×éÖ¯Õë¶Ô¶à¼Ò¹«Ë¾µÄ¸ß¶ÈÕë¶ÔÐÔ¹¥»÷Ô˶¯ÖÐËùʹÓõÄÎó²î¹¥»÷Á´£¬£¬£¬£¬£¬£¬£¬PuzzleMakerÔÚ¹¥»÷Öд®ÁªÊ¹ÓÃÁËChromeºÍWindows10µÄ0dayÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Ò»¸öChrome0dayºÍÁ½¸öWindows100day¡£¡£¡£¡£¡£¡£¡£¡£¶øÆäʱµÄÏà¹ØÑо¿Ö°Ô±²¢Î´»¹ÔÍêÕûµÄ¹¥»÷Á´£¬£¬£¬£¬£¬£¬£¬Ò²ÔÝδ²¶»ñ´øÓÐÍêÕûÎó²îʹÓõÄJavaScript´úÂë¡£¡£¡£¡£¡£¡£¡£¡£¹Ê±¾´ÎÊÇÊ״β¶»ñµ½ÔÚÒ°µÄÍêÕûÎó²îʹÓù¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
ÓÉÓÚ¸ÃÎó²îÒѾÓÃÓÚÕæÊµµÄAPT¹¥»÷£¬£¬£¬£¬£¬£¬£¬ºìÓêµÎÍŶӵÚһʱ¼ä¸´ÏÖ²¢È·Èϲ¶»ñµ½µÄÑù±¾¿ÉÓ㬣¬£¬£¬£¬£¬£¬²¢¶Ô¸ÃÎó²îʹÓõÄÏà¹ØÊÖÒÕϸ½Ú¾ÙÐÐÁËÆÊÎö£¬£¬£¬£¬£¬£¬£¬ÒÔ±ãÇå¾²³§ÉÌ¿ÉÒÔÔöÌíÏìÓ¦µÄ·À»¤²½·¥¡£¡£¡£¡£¡£¡£¡£¡£

https://twitter.com/RedDrip7/status/1453291780078714880
´©Í¸ChromeɳºÐµÄÎó²îʹÓÃÑÝʾÊÓÆµ
ºìÓêµÎÍŶӸ´ÏÖµÄÔÚÒ°Chrome´©Í¸É³ºÐÎó²îʹÓÃÊÓÆµÈçÏ£º
Îó²îʹÓÃÆÊÎö
¸ÃÔÚÒ°Îó²îʹÓÃÁ´Í¨¹ýChromeÎó²îCVE-2021-21224ºÍWindowsÄÚºËÌáȨÎó²îCVE-2021-31956¾ÙÐÐ×éºÏ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Õû¸öʹÓûùÓÚ4ÔµÄй¶EXP£¬£¬£¬£¬£¬£¬£¬¿ÉÊDz¿·Ö×Ö¶Î×öÁËÏìÓ¦µÄ»ìÏý¡£¡£¡£¡£¡£¡£¡£¡£
ÔÚËæºóÆÊÎö¸ÃEXPʹÓôúÂëµÄʱ¼ä·¢Ã÷£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÖлñÈ¡µ½í§ÒâµØµã¶ÁдÔ×Ӻ󣬣¬£¬£¬£¬£¬£¬Ð´ÈëÖ´ÐеÄShellCodeÓÐÁ½¶Î£¬£¬£¬£¬£¬£¬£¬ÕâÀïÒýÆðÁËÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!×¢ÖØ£¬£¬£¬£¬£¬£¬£¬Ò»Ñùƽ³£À´ËµChromeÎó²îÊÇÎÞ·¨×ÔÁ¦Ö´Ðе쬣¬£¬£¬£¬£¬£¬ÐèÒªÒ»¸öÌáȨµÄÎó²îÓÃÓÚɳÏäÈÆ¹ý¡£¡£¡£¡£¡£¡£¡£¡£
¾ÓɲâÊÔ·¢Ã÷Õû¸öÎó²îCVE-2021-21224²¿·ÖÄÜÕý³£Ö´ÐУ¬£¬£¬£¬£¬£¬£¬ÈçÏÂËùʾµÚÒ»¶ÎShellCodeдÈëµ½ÁËWASM¹¤¾ßµÄ¿É¶Á¿Éд¿ÉÖ´ÐÐÄÚ´æÒ³ÃæÖС£¡£¡£¡£¡£¡£¡£¡£

Á½¶ÎShellCodeÖдó×ÚµÄAPIŲÓÃͨ¹ýsyscallµÄ·½·¨Íê³É¡£¡£¡£¡£¡£¡£¡£¡£

ͨ¹ýµ÷ÊÔ·¢Ã÷£¬£¬£¬£¬£¬£¬£¬µÚÒ»¶ÎдÈëµÄShellCodeÏÖʵÉÏÊÇCVE-2021-31956µÄʹÓôúÂ룬£¬£¬£¬£¬£¬£¬¸Ã0dayÎó²îÓÚ½ñÄêÁùÔ±»¿¨°Í˹»ùÅû¶ÔÚPuzzleMakerÍÅ»ïµÄ¹¥»÷Öб»Ê¹Ó㬣¬£¬£¬£¬£¬£¬ÇɺϵÄÊǸÃÎó²îÔÚ¿¨°Í˹»ùµÄ±¨¸æÖлùÓÚʱ¼äÍÆ²âÊÇ×÷ΪCVE-2021-21224Õâ¸öChrome0dayÎó²î¾ÙÐй¥»÷ʱµÄÌáȨģ¿£¿£¿£¿£¿£¿£¿£¿é(ÓÉÓÚÔÚÏÖʵµÄ¹¥»÷Öв¢Ã»Óв¶»ñµ½ChromeÎó²îµÄ¹¥»÷´úÂë)£¬£¬£¬£¬£¬£¬£¬Òò´ËÕâÀïÓÐÀíÓÉÏÓÒɸôι¥»÷¿ÉÄܺÍPuzzleMakerÓйأ¬£¬£¬£¬£¬£¬£¬±ðµÄÖ»¹Ü4¸öÔÂÒÑÍùÁË£¬£¬£¬£¬£¬£¬£¬CVE-2021-31956Õâ¸öÎó²î×Ô¼ºµÄʹÓôúÂëûÓб»¹ûÕæ¡£¡£¡£¡£¡£¡£¡£¡£
¸ÃÎó²î±¬·¢ÔÚÄÚºËÄ£¿£¿£¿£¿£¿£¿£¿£¿éntfs.sysµÄº¯ÊýNtfsQueryEaUserEaListÖУ¬£¬£¬£¬£¬£¬£¬ÈκÎÔÚNTFS·ÖÇøÉÏÓÐдÈëȨÏÞµÄÎļþ¾ä±úµÄÀú³Ì¶¼¿ÉÒÔ»á¼ûËü£¬£¬£¬£¬£¬£¬£¬ÕâÀï¾Í°üÀ¨ÁËChromeµÄäÖȾÀú³Ì£¬£¬£¬£¬£¬£¬£¬Òò´Ë¸ÃÎó²îºÜÊÇÊÊÓÃÓÚÍ»ÆÆÉ³Ï䣬£¬£¬£¬£¬£¬£¬µ±NtfsQueryEaUserEaList´¦Öóͷ£ÎļþµÄÍØÕ¹ÊôÐÔÁÐ±í£¬£¬£¬£¬£¬£¬£¬²¢½«Öµ·µ»Øµ½´æ´¢µÄ»º´æÇøÊ±£¬£¬£¬£¬£¬£¬£¬±£´æÒ»´¦ÕûÊýÏÂÒ磬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÖ®ºóµÄÒç³ö¡£¡£¡£¡£¡£¡£¡£¡£
ÕâÀï½¹µãµÄÒç³öÂß¼ÔÚea_block_size

out_buf_length/paddingÖµ°´ÈçÏ·½·¨ÌìÉú£¬£¬£¬£¬£¬£¬£¬paddingµÄȡֵΪ0£¬£¬£¬£¬£¬£¬£¬1£¬£¬£¬£¬£¬£¬£¬2£¬£¬£¬£¬£¬£¬£¬3£¬£¬£¬£¬£¬£¬£¬Òò´ËÕâÀï¹¥»÷Õßͨ¹ýÊʵ±µÄ½á¹¹£¬£¬£¬£¬£¬£¬£¬µ±Ñ»·ÖÐÌìÉúout_buf_lengthΪ0ʱ£¬£¬£¬£¬£¬£¬£¬out_buf_length–padding½«·ºÆðÏÂÒç¡£¡£¡£¡£¡£¡£¡£¡£

ÕâÀïÒç³öдÈëµÄµØµãΪÎó²îº¯Êý¸¸º¯ÊýNtfsCommonQueryEaÖзÖÅɵÄÄں˷ÖÒ³³ØÖС£¡£¡£¡£¡£¡£¡£¡£

Îó²îʹÓÃÁËWNFÄ£¿£¿£¿£¿£¿£¿£¿£¿éÀ´Íê³Éí§ÒâµØµã¶ÁдÒÔ¼°Ô½½ç¶Áд²Ù×÷£¬£¬£¬£¬£¬£¬£¬Ê×ÏÈNtUpdateWnfStateData/NtDeleteWnfStateData¾ÙÐжÔÓ¦µÄÄÚ´æ½á¹¹¡£¡£¡£¡£¡£¡£¡£¡£

ŲÓú¯ÊýNtQueryEaFile´¥·¢ÏÂÒç¡£¡£¡£¡£¡£¡£¡£¡£

×îÖÕͨ¹ýÐÞˢгÌtokenÌáÉýȨÏÞ£¬£¬£¬£¬£¬£¬£¬ÕâÀïÏêϸµÄʹÓÃÆÊÎö²»ÔÙ׸Êö£¬£¬£¬£¬£¬£¬£¬nccgroupµÄÎÄÕ“CVE-2021-31956exploitingthewindowskernelntfswithwnf”ÒѾÆÊÎöµÃºÜÇåÎú£¬£¬£¬£¬£¬£¬£¬¸ÐÐËȤµÄ¶ÁÕß¿ÉÒԴӲο¼Á´½ÓÕÒµ½¶ÔÓ¦ÎÄÕ¡£¡£¡£¡£¡£¡£¡£¡£

ÈçÏÂËùʾ£¬£¬£¬£¬£¬£¬£¬µÚÒ»¶Î°üÀ¨CVE-2021-31956ʹÓôúÂëµÄShellCodeÖ´ÐÐÍê±Ïºó£¬£¬£¬£¬£¬£¬£¬¶ÔÓ¦expÒ³ÃæµÄäÖȾÀú³ÌÒѾÊÇsystemȨÏÞ£¬£¬£¬£¬£¬£¬£¬ºóÐøÖ´Ðеĵڶþ¶ÎShellCode½«ÒÔsystemµÄȨÏÞÔÚÊܺ¦Õß»úеÉÏÔËÐÐÈκζñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£

ͨ¹ýµÚÒ»¶ÎShellCodeÌáȨ´©¹ýɳÏäºó£¬£¬£¬£¬£¬£¬£¬Ö´Ðеڶþ¶ÎShellCode£¬£¬£¬£¬£¬£¬£¬×îÖÕ¿ªÆôÒ»¸öÏ̺߳ÍccµÄͨѶ¡£¡£¡£¡£¡£¡£¡£¡£

ÈçÏÂËùʾ»ñÈ¡wininetÏà¹ØµÄÁªÍøº¯ÊýºóʵÑé»á¼ûºóÐøµÄ¹¥»÷´úÂë¡£¡£¡£¡£¡£¡£¡£¡£

×ܽá
ÏÖÔÚ°üÀ¨ÌìÑ۸߼¶Íþв¼ì²â²úÆ·ÔÚÄÚµÄÌìÇæÖÕ¶ËÇå¾²ÖÎÀíϵͳ¡¢NGSOC¡¢TIPÍþвÇ鱨ƽ̨¡¢Öǻ۷À»ðǽµÈÈ«ÏßÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!¹¥»÷¼ì²âÀà²úÆ·¶¼ÒѾ֧³Ö¶Ô´ËÍþвµÄ¼ì²â£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔÉý¼¶Ïà¹ØµÄ×°±¸µ½×îеİ汾ºÍ¹æÔò¿â¡£¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://securelist.com/puzzlemaker-chrome-zero-day-exploit-chain/102771/
https://research.nccgroup.com/2021/07/15/cve-2021-31956-exploiting-the-windows-kernel-ntfs-with-wnf-part-1/
ʱ¼ä£º2026-04-22
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-18
Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ
ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
¿ì½Ý´°¿Ú
ÆìÏÂÍøÕ¾
¹ØÓÚÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!
95015ЧÀÍÈÈÏß
΢ÐŹ«ÖÚºÅ
Á¬Ã¦²¦´ò