IE VML UAFÔ¶³Ì´úÂëÖ´ÐÐ0dayÎó²î (Alert2014-06)
2014-04-28
ÐÎò£º
Microsoft IEÊÇ΢Èí¹«Ë¾ÍÆ³öµÄÒ»¿îÍøÒ³ä¯ÀÀÆ÷¡£IE±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐ0dayÎó²î£¬Î¢ÈíÒѾ·¢Ã÷Óй¥»÷ÕßÔÚʹÓôËÎó²î¹¥»÷IE 9ºÍIE 11¡£ÊӲ췢Ã÷£¬´ËÎó²îÓ°Ïì´ÓIE 6µ½IE 11µÄËùÓа汾¡£ÏÖÔÚ΢Èí»¹Ã»ÓÐÌṩÕýʽ²¹¶¡£¬µ«ÌṩÁËÔÝʱ½â¾öÒªÁì¡£
Ç¿ÁÒ½¨ÒéIEÓû§²ÎÕÕ½â¾öÒªÁ첿·ÖµÄ²½·¥¾ÙÐÐÐëÒªµÄ·À»¤£¬²¢ÔÚ΢ÈíÕýʽ²¹¶¡Ðû²¼ºóʵʱÉý¼¶¡£
======
IEµÄVGX.DLL×é¼þ±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£Ê¹ÓôËÎó²î»á¼ûÒѾ±»É¾³ý»òδ׼ȷ·ÖÅɵÄÄڴ湤¾ß£¬µ¼ÖÂÄÚ´æÆÆË𣬴ӶøÒÔIEÄ¿½ñÓû§Éí·ÝÖ´ÐÐí§ÒâÖ¸Áî¡£
Ô¶³Ì¹¥»÷Õß¿ÉÄÜʹÓôËÎó²îͨ¹ýÓÕʹÓû§»á¼û¶ñÒâÍøÒ³Ö´ÐйÒÂí¹¥»÷£¬¿ØÖÆÓû§ÏµÍ³¡£
½â¾öÒªÁ죺
ÔÚ³§É̲¹¶¡Ðû²¼Ö®Ç°£¬ÎÒÃǽ¨ÒéÓû§ÔÝʱ¸ÄÓ÷ÇIEÄÚºËä¯ÀÀÆ÷£¬ÈçFirefoxChrome¡£¹ØÓÚIEä¯ÀÀÆ÷¿ÉÒÔ½ÓÄÉÈçÏ·À»¤²½·¥:
* ½ÓÄɳ§ÉÌÌṩµÄEnhanced Mitigation Experience Toolkit (EMET)¹¤¾ß¡£´ËÒªÁìÄÜÓÐÓÃÌá·À£¬ÇÒ²»Ó°ÏìÕý³£ÍøÕ¾µÄ»á¼û¡£
ÔöÇ¿»º½âÌåÑ鹤¾ß°ü£¨EMET£©ÊÇÒ»¸öÊÊÓù¤¾ß£¬ÓÃÓÚ±ÜÃâÈí¼þÖеÄÎó²î±»ÀÖ³ÉʹÓá£
´ÓÈçÏÂÍøÖ·ÏÂÔØÔöÇ¿»º½âÌåÑ鹤¾ß°ü£º
EMET 4.1:
http://www.microsoft.com/en-us/download/details.aspx?id=41138
×¢£ºEMET 3.0²»¿É»º½â´ËÎÊÌâ
×°ÖÃÒÔºóÔËÐУ¬ÔÚ½çÃæÖеã»÷¡°Configure Apps¡±£¬ÔÚ¶Ô»°¿òÖеã»÷¡°Add¡±£¬ä¯ÀÀµ½IEËùÔÚµÄ×°ÖÃĿ¼£¨Í¨³£ÊÇc:program filesInternet Explorer£©Ñ¡Ôñiexplore.exe£¬µã»÷¡°·¿ª¡±£¬ IE¾Í±»¼ÓÈëµ½Êܱ£»¤ÏîÄ¿ÁбíÖУ¬µã»÷¡°OK¡±£¬ÈôÊÇÓÐIEÕýÔÚÔËÐеϰÐèÒªÖØÆôÒ»ÏÂÓ¦Óá£
Ò²¿É½ÓÄÉÀàËÆµÄ²Ù×÷°ÑÆäËûµÄÓ¦ÓóÌÐò¼ÓÈë±£»¤¡£
* ÔÚ "IE Ñ¡Ïî"ÖÐÉèÖÃ"Internet"ºÍ"ÍâµØ Intranet"µÄÇøÓòÇå¾²ÐÔÉèÖÃΪ ¡°¸ß¡±ÒÔ×èÖ¹ActiveX¿Ø¼þºÍÔ˶¯¾ç±¾ÔÚÕâÁ½¸öÇøÓòÖÐÖ´ÐС£
ÕâÒªÁìËäÈ»ÄÜÓÐÓÃÌá·À£¬¿ÉÊÇ»áÓ°Ïìµ½Õý³£ÍøÕ¾¡£ÎªÁ˾¡¿ÉÄܵؽµµÍÓ°Ï죬Ӧ°ÑÐÅÍеÄÍøÕ¾Ìí¼Óµ½"ÊÜÐÅÍеÄÕ¾µã"¡£
* ÉèÖÃIEÔÚÔËÐÐÔ˶¯¾ç±¾Ìõ¼þʾ£¬»òÕßÔÚ"Internet"ºÍ"ÍâµØIntranet"ÓòÖнûÓÃÔ˶¯¾ç±¾¡£
ÕâÒªÁìËäÈ»ÄÜÓÐÓÃÌá·À£¬¿ÉÊÇ»áÓ°Ïìµ½Õý³£ÍøÕ¾¡£ÎªÁ˾¡¿ÉÄܵؽµµÍÓ°Ï죬Ӧ°ÑÐÅÍеÄÍøÕ¾Ìí¼Óµ½"ÊÜÐÅÍеÄÕ¾µã"¡£
* ×¢ÏúVGX.DLL¡£
µ¥»÷×îÏÈ£¬µ¥»÷ÔËÐУ¬¼üÈë"%SystemRoot%System32regsvr32.exe" -u "%CommonProgramFiles%Microsoft SharedVGXvgx.dll"£¬È»ºóµ¥»÷OK(È·¶¨)¡£
´ËÒªÁìËäÈ»ÄÜÓÐÓÃÌá·À£¬¿ÉÊÇ·ºÆðVMLµÄÓ¦Óý«²»ÔÙÏÔʾ¡£
µ±Çå¾²ÎÊÌâ½â¾öºó£¬¿ÉÒÔÔÚ×°ÖÃÇå¾²¸üкóÖØÐÂ×¢²áVGX.DLL¡£Æ¾Ö¤Èçϰ취¡£
1.µ¥»÷×îÏÈ£¬µ¥»÷ÔËÐУ¬¼üÈë"%SystemRoot%System32regsvr32.exe" "%CommonProgramFiles%Microsoft SharedVGXvgx.dll"£¬È»ºóµ¥»÷OK(È·¶¨)¡£
2.»á·ºÆðÒ»¸ö¶Ô»°¿ò£¬È·ÈÏ×¢²áÀú³ÌÒѾÀÖ³ÉÍê³É¡£µ¥»÷OK(È·¶¨)ÒԹرնԻ°¿ò¡£
³§ÉÌ״̬£º
==========
³§ÉÌÒÑÐû²¼Ç徲ͨ¸æºÍÔÝʱ½â¾ö¼Æ»®£¬ÏÖÔÚ»¹Ã»ÓÐÐû²¼²¹¶¡¡£ÎÒÃǽ¨ÒéÓû§¿ªÆô×Ô¶¯¸üзþÎñÒÔʵʱװÖÃв¹¶¡¡£
³§ÉÌÇ徲ͨ¸æ£º
http://technet.microsoft.com/en-us/security/advisory/2963983
¸½¼ÓÐÅÏ¢£º
==========
1. http://technet.microsoft.com/en-us/security/advisory/2963983
2. http://www.nsfocus.net/index.php?act=alert&do=view&aid=148

AG¹«Ë¾ÔÆ







