CVE-2018-8090
Quick Heal Total Security/Internet Security/AntiVirus Pro(安装程序)中的 DLL 劫持
受影响产品:
- Quick Heal Total Security - 17.00
- Quick Heal Internet Security - 17.00
- Quick Heal AntiVirus Pro - 17.00
受影响的安装程序:
- Quick Heal Total Security 64 位 17.00 (QHTS64.exe), (QHTSFT64.exe) - 版本 10.0.1.38
- Quick Heal Total Security 32 位 17.00 (QHTS32.exe), (QHTSFT32.exe) - 版本 10.0.1.38
- Quick Heal Internet Security 64 位 17.00 (QHIS64.exe), (QHISFT64.exe) - 版本 10.0.0.37
- Quick Heal Internet Security 32 位 17.00 (QHIS32.exe), (QHISFT32.exe) - 版本 10.0.0.37
- Quick Heal AntiVirus Pro 64 位 17.00 (QHAV64.exe), (QHAVFT64.exe) - 版本 10.0.0.37
- Quick Heal AntiVirus Pro 32 位 17.00 (QHAV32.exe), (QHAVFT32.exe) - 版本 10.0.0.37
上述所有安装程序因不安全的库加载而导致 DLL 劫持。由于这些安装程序都需要管理员权限,因此可能以管理员权限加载并执行代码。
32 位版本可加载的 DLL:
- cryptsp.dll
- cryptnet.dll
- cryptbase.dll
- gpapi.dll
- ncrypt.dll
- profapi.dll
- sensapi.dll
- userenv.dll
64 位版本可加载的 DLL:
- cryptsp.dll
- cryptbase.dll
- iphlpapi.dll
时间线:
- 04/12月/2017 - 向 Quick Heal 报告漏洞
- 25/12月/2017 - Quick Heal 确认漏洞
- 27/4月/2018 - 漏洞已修复(Total Security 版本 - 10.0.1.46)
- 23/7月/2018 - 收到赏金(30,000 卢比)
附加链接
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8090
https://nvd.nist.gov/vuln/detail/CVE-2018-8090