PixieFAIL - ืคื’ื™ืขื•ื™ื•ืช ื‘ืขืจื™ืžืช ืจืฉืช ื”ืงื•ืฉื—ื” ืฉืœ UEFI ื”ืžืฉืžืฉืช ืœืืชื—ื•ืœ PXE

ืชืฉืข ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื–ื•ื”ื• ื‘ืงื•ืฉื—ื” ืฉืœ UEFI ื”ืžื‘ื•ืกืกืช ืขืœ ื”ืคืœื˜ืคื•ืจืžื” ื”ืคืชื•ื—ื” TianoCore EDK2, ื”ื ืคื•ืฆื” ื‘ืฉื™ืžื•ืฉ ื‘ืžืขืจื›ื•ืช ืฉืจืชื™ื, ื‘ืฉื ื”ืงื•ื“ ื”ืžืฉื•ืชืฃ PixieFAIL. ืคื’ื™ืขื•ื™ื•ืช ืงื™ื™ืžื•ืช ื‘ืขืจื™ืžืช ืงื•ืฉื—ืช ื”ืจืฉืช ื”ืžืฉืžืฉืช ืœืืจื’ื•ืŸ ืืชื—ื•ืœ ื”ืจืฉืช (PXE). ื”ืคื’ื™ืขื•ื™ื•ืช ื”ืžืกื•ื›ื ื•ืช ื‘ื™ื•ืชืจ ืžืืคืฉืจื•ืช ืœืชื•ืงืฃ ืœื ืžืื•ืžืช ืœื‘ืฆืข ืงื•ื“ ืžืจื—ื•ืง ื‘ืจืžืช ื”ืงื•ืฉื—ื” ื‘ืžืขืจื›ื•ืช ื”ืžืืคืฉืจื•ืช ืืชื—ื•ืœ PXE ื‘ืจืฉืช IPv9.

ื‘ืขื™ื•ืช ืคื—ื•ืช ื—ืžื•ืจื•ืช ื’ื•ืจืžื•ืช ืœืžื ื™ืขืช ืฉื™ืจื•ืช (ื—ืกื™ืžืช ืืชื—ื•ืœ), ื“ืœื™ืคืช ืžื™ื“ืข, ื”ืจืขืœืช ืžื˜ืžื•ืŸ DNS ื•ื—ื˜ื™ืคืช ื”ืคืขืœืช TCP. ื ื™ืชืŸ ืœื ืฆืœ ืืช ืจื•ื‘ ื”ืคื’ื™ืขื•ื™ื•ืช ืžื”ืจืฉืช ื”ืžืงื•ืžื™ืช, ืืš ื ื™ืชืŸ ืœืชืงื•ืฃ ื—ืœืง ืžื”ื—ื•ืœื™ื•ืช ื’ื ืžืจืฉืช ื—ื™ืฆื•ื ื™ืช. ืชืจื—ื™ืฉ ื”ืชืงืคื” ื˜ื™ืคื•ืกื™ ืžืกืชื›ื ื‘ื ื™ื˜ื•ืจ ืชืขื‘ื•ืจื” ื‘ืจืฉืช ืžืงื•ืžื™ืช ื•ืฉืœื™ื—ืช ืžื ื•ืช ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“ ื›ืืฉืจ ืžื–ื•ื”ื” ืคืขื™ืœื•ืช ื”ืงืฉื•ืจื” ืœืืชื—ื•ืœ ื”ืžืขืจื›ืช ื‘ืืžืฆืขื•ืช PXE. ืื™ืŸ ืฆื•ืจืš ื‘ื’ื™ืฉื” ืœืฉืจืช ื”ื”ื•ืจื“ื•ืช ืื• ืœืฉืจืช DHCP. ื›ื“ื™ ืœื”ื“ื’ื™ื ืืช ื˜ื›ื ื™ืงืช ื”ื”ืชืงืคื”, ืคื•ืจืกืžื• ื ื™ืฆื•ืœ ืื‘ ื˜ื™ืคื•ืก.

ืงื•ืฉื—ืช UEFI ื”ืžื‘ื•ืกืกืช ืขืœ ืคืœื˜ืคื•ืจืžืช TianoCore EDK2 ื ืžืฆืืช ื‘ืฉื™ืžื•ืฉ ื‘ื—ื‘ืจื•ืช ื’ื“ื•ืœื•ืช ืจื‘ื•ืช, ืกืคืงื™ ืขื ืŸ, ืžืจื›ื–ื™ ื ืชื•ื ื™ื ื•ืืฉื›ื•ืœื•ืช ืžื—ืฉื•ื‘. ื‘ืคืจื˜, ืžื•ื“ื•ืœ NetworkPkg ื”ืคื’ื™ืข ืขื ืžื™ืžื•ืฉ ืืชื—ื•ืœ PXE ืžืฉืžืฉ ื‘ืงื•ืฉื—ื” ืฉืคื•ืชื—ื” ืขืœ ื™ื“ื™ ARM, Insyde Software (Insyde H20 UEFI BIOS), American Megatrends (AMI Aptio OpenEdition), Phoenix Technologies (SecureCore), Intel, Dell ื•-Microsoft (Project Mu) ). ื”ื”ืขืจื›ื” ื”ื™ื ืฉื”ืคืจืฆื•ืช ืžืฉืคื™ืขื•ืช ื’ื ืขืœ ืคืœื˜ืคื•ืจืžืช ChromeOS, ืฉื™ืฉ ืœื” ื—ื‘ื™ืœืช EDK2 ื‘ืžืื’ืจ, ืืš ื’ื•ื’ืœ ืžืกืจื” ื›ื™ ื”ื—ื‘ื™ืœื” ื”ื–ื• ืื™ื ื” ื‘ืฉื™ืžื•ืฉ ื‘ืงื•ืฉื—ื” ืขื‘ื•ืจ Chromebooks ื•ืคืœื˜ืคื•ืจืžืช ChromeOS ืื™ื ื” ืžื•ืฉืคืขืช ืžื”ื‘ืขื™ื”.

ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉื–ื•ื”ื•:

  • CVE-2023-45230 - ื”ืฆืคืช ืžืื’ืจ ื‘ืงื•ื“ ื”ืœืงื•ื— DHCPv6, ืžื ื•ืฆืœ ืขืœ ื™ื“ื™ ื”ืขื‘ืจืช ืžื–ื”ื” ืฉืจืช ืืจื•ืš ืžื“ื™ (ืืคืฉืจื•ืช ืžื–ื”ื” ืฉืจืช).
  • CVE-2023-45234 - ื”ืฆืคืช ืžืื’ืจ ืžืชืจื—ืฉืช ื‘ืขืช ืขื™ื‘ื•ื“ ืืคืฉืจื•ืช ืขื ืคืจืžื˜ืจื™ื ืฉืœ ืฉืจืช DNS ื”ืžื•ืขื‘ืจื™ื ื‘ื”ื•ื“ืขื” ื”ืžื›ืจื™ื–ื” ืขืœ ื ื•ื›ื—ื•ืช ืฉืœ ืฉืจืช DHCPv6.
  • CVE-2023-45235 - ื”ืฆืคืช ืžืื’ืจ ื‘ืขืช ืขื™ื‘ื•ื“ ืืคืฉืจื•ืช ื”-Server ID ื‘ื”ื•ื“ืขื•ืช ื”ื•ื“ืขื•ืช ืคืจื•ืงืกื™ DHCPv6.
  • CVE-2023-45229 ื”ื•ื ื–ืจื™ืžืช ืชืช ืžืกืคืจ ืฉืœืžื™ื ื”ืžืชืจื—ืฉืช ื‘ืžื”ืœืš ืขื™ื‘ื•ื“ ืืคืฉืจื•ื™ื•ืช IA_NA/IA_TA ื‘ื”ื•ื“ืขื•ืช DHCPv6 ื”ืžืคืจืกืžื•ืช ืฉืจืช DHCP.
  • CVE-2023-45231 ื“ืœื™ืคืช ื ืชื•ื ื™ื ืžื—ื•ืฅ ืœืžืื’ืจ ืžืชืจื—ืฉืช ื‘ืขืช ืขื™ื‘ื•ื“ ื”ื•ื“ืขื•ืช ND Redirect (ื’ื™ืœื•ื™ ืฉื›ืŸ) ืขื ืขืจื›ื™ ืื•ืคืฆื™ื•ืช ืงื˜ื•ืขื™ื.
  • CVE-2023-45232 ืœื•ืœืื” ืื™ื ืกื•ืคื™ืช ืžืชืจื—ืฉืช ื‘ืขืช ื ื™ืชื•ื— ืืคืฉืจื•ื™ื•ืช ืœื ื™ื“ื•ืขื•ืช ื‘ื›ื•ืชืจืช Destination Options.
  • CVE-2023-45233 ืœื•ืœืื” ืื™ื ืกื•ืคื™ืช ืžืชืจื—ืฉืช ื‘ืขืช ื ื™ืชื•ื— ื”ืืคืฉืจื•ืช PadN ื‘ื›ื•ืชืจืช ื”ื—ื‘ื™ืœื”.
  • CVE-2023-45236 - ืฉื™ืžื•ืฉ ื‘ื–ืจืขื™ ืจืฆืฃ TCP ื”ื ื™ืชื ื™ื ืœื—ื™ื–ื•ื™ ื›ื“ื™ ืœืืคืฉืจ ื˜ืจื™ื– ืฉืœ ื—ื™ื‘ื•ืจ TCP.
  • CVE-2023-45237 โ€“ ืฉื™ืžื•ืฉ ื‘ืžื—ื•ืœืœ ืžืกืคืจื™ื ืคืกืื•ื“ื•-ืืงืจืื™ื™ื ืœื ืืžื™ืŸ ื”ืžื™ื™ืฆืจ ืขืจื›ื™ื ื”ื ื™ืชื ื™ื ืœื—ื™ื–ื•ื™.

ื”ืคื’ื™ืขื•ื™ื•ืช ื”ื•ื’ืฉื• ืœ-CERT/CC ื‘-3 ื‘ืื•ื’ื•ืกื˜ 2023, ื•ืชืืจื™ืš ื”ื—ืฉื™ืคื” ื ืงื‘ืข ืœ-2 ื‘ื ื•ื‘ืžื‘ืจ. ืขื ื–ืืช, ื‘ืฉืœ ื”ืฆื•ืจืš ื‘ื”ืคืฆืช ืชื™ืงื•ืŸ ืžืชื•ืืžืช ื‘ื™ืŸ ืกืคืงื™ื ืžืจื•ื‘ื™ื, ืชืืจื™ืš ื”ืฉื—ืจื•ืจ ื ื“ื—ืง ื‘ืชื—ื™ืœื” ืœ-1 ื‘ื“ืฆืžื‘ืจ, ื•ืœืื—ืจ ืžื›ืŸ ื ื“ื—ืง ืœ-12 ื‘ื“ืฆืžื‘ืจ ื•ืœ-19 ื‘ื“ืฆืžื‘ืจ 2023, ืืš ื‘ืกื•ืคื• ืฉืœ ื“ื‘ืจ ื ื—ืฉืฃ ื‘-16 ื‘ื™ื ื•ืืจ 2024. ื‘ืžืงื‘ื™ืœ, ื‘ื™ืงืฉื” ืžื™ืงืจื•ืกื•ืคื˜ ืœื“ื—ื•ืช ืืช ืคืจืกื•ื ื”ืžื™ื“ืข ืœื—ื•ื“ืฉ ืžืื™.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”