CVE-2018-8090
Quickheal Total Security/Internet Security/Antivirus Pro (설치 프로그램)의 DLL 하이재킹
영향을 받는 제품:
- Quick Heal Total Security - 17.00
- Quick Heal Internet Security - 17.00
- Quick Heal AntiVirus Pro - 17.00
영향을 받는 설치 프로그램:
- Quick Heal Total Security 64비트 17.00 (QHTS64.exe), (QHTSFT64.exe) - 버전 10.0.1.38
- Quick Heal Total Security 32비트 17.00 (QHTS32.exe), (QHTSFT32.exe) - 버전 10.0.1.38
- Quick Heal Internet Security 64비트 17.00 (QHIS64.exe), (QHISFT64.exe) - 버전 10.0.0.37
- Quick Heal Internet Security 32비트 17.00 (QHIS32.exe), (QHISFT32.exe) - 버전 10.0.0.37
- Quick Heal AntiVirus Pro 64비트 17.00 (QHAV64.exe), (QHAVFT64.exe) - 버전 10.0.0.37
- Quick Heal AntiVirus Pro 32비트 17.00 (QHAV32.exe), (QHAVFT32.exe) - 버전 10.0.0.37
위의 모든 설치 프로그램은 안전하지 않은 라이브러리 로딩으로 인해 DLL 하이재킹이 가능합니다. 이러한 설치 프로그램은 모두 관리자 권한이 필요하므로 관리자 권한으로 코드를 로드하고 실행할 수 있습니다.
32비트 버전에서 로드 가능한 DLL:
- cryptsp.dll
- cryptnet.dll
- cryptbase.dll
- gpapi.dll
- ncrypt.dll
- profapi.dll
- sensapi.dll
- userenv.dll
64비트 버전에서 로드 가능한 DLL:
- cryptsp.dll
- cryptbase.dll
- iphlpapi.dll
타임라인:
- 2017년 12월 4일 - Quickheal에 취약점 제보
- 2017년 12월 25일 - Quickheal이 취약점 확인
- 2018년 4월 27일 - 취약점 수정 (Total Security 버전 - 10.0.1.46)
- 2018년 7월 23일 - 현상금 수령 (30,000루피)
추가 링크
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8090
https://nvd.nist.gov/vuln/detail/CVE-2018-8090