ืคื’ื™ืขื•ืช ื‘-7-Zip ื”ืžืืคืฉืจืช ืœืš ืœืงื‘ืœ ื”ืจืฉืื•ืช SYSTEM ื‘-Windows

ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช (CVE-7-2022) ื‘ืืจื›ื™ื•ืŸ ื”ื—ื™ื ืžื™ 29072-Zip, ื”ืžืืคืฉืจ ืœื‘ืฆืข ืคืงื•ื“ื•ืช ืฉืจื™ืจื•ืชื™ื•ืช ืขื ื”ืจืฉืื•ืช SYSTEM ืขืœ ื™ื“ื™ ื”ืขื‘ืจืช ืงื•ื‘ืฅ ืฉืชื•ื›ื ืŸ ื‘ืžื™ื•ื—ื“ ืขื ืกื™ื•ืžืช .7z ืœืื–ื•ืจ ืขื ืจืžื– ื”ืžื•ืฆื’ ื‘ืขืช ื”ืคืชื™ื—ื” ืชืคืจื™ื˜ "ืขื–ืจื”>ืชื•ื›ืŸ". ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ืจืง ื‘ืคืœื˜ืคื•ืจืžืช Windows ื•ื”ื™ื ื ื’ืจืžืช ืขืœ ื™ื“ื™ ืฉื™ืœื•ื‘ ืฉืœ ืชืฆื•ืจื” ืฉื’ื•ื™ื” ืฉืœ 7z.dll ื•ื”ืฆืคืช ืžืื’ืจ.

ืจืื•ื™ ืœืฆื™ื™ืŸ ื›ื™ ืœืื—ืจ ื”ื•ื“ืขื” ืขืœ ื”ื‘ืขื™ื”, ืžืคืชื—ื™ 7-Zip ืœื ื”ื›ื™ืจื• ื‘ืคื’ื™ืขื•ืช ื•ื”ืฆื”ื™ืจื• ื›ื™ ืžืงื•ืจ ื”ืคื’ื™ืขื•ืช ื”ื•ื ืชื”ืœื™ืš Microsoft HTML Helper (hh.exe), ื”ืžืจื™ืฅ ืงื•ื“ ื‘ืขืช ื”ืขื‘ืจืช ื”ืงื•ื‘ืฅ. ื”ื—ื•ืงืจ ืฉื–ื™ื”ื” ืืช ื”ืคื’ื™ืขื•ืช ืกื‘ื•ืจ ื›ื™ hh.exe ืžืขื•ืจื‘ ืจืง ื‘ืขืงื™ืคื™ืŸ ื‘ื ื™ืฆื•ืœ ื”ืคื’ื™ืขื•ืช, ื•ื”ืคืงื•ื“ื” ืฉืฆื•ื™ื ื” ื‘-exploit ืžื•ืคืขืœืช ื‘-7zFM.exe ื›ืชื”ืœื™ืš ื™ืœื“. ื”ืกื™ื‘ื•ืช ืœืืคืฉืจื•ืช ืฉืœ ื‘ื™ืฆื•ืข ื”ืชืงืคื” ื‘ืืžืฆืขื•ืช ื”ื–ืจืงืช ืคืงื•ื“ื” ื”ืŸ ื”ืฆืคืช ื—ื™ืฅ ื‘ืชื”ืœื™ืš 7zFM.exe ื•ื”ื’ื“ืจื•ืช ืฉื’ื•ื™ื•ืช ืฉืœ ื–ื›ื•ื™ื•ืช ืขื‘ื•ืจ ืกืคืจื™ื™ืช 7z.dll.

ื›ื“ื•ื’ืžื”, ืžื•ืฆื’ ืงื•ื‘ืฅ ืขื–ืจื” ืœื“ื•ื’ืžื” ื”ืžืจื™ืฅ ืืช "cmd.exe". ื›ืžื• ื›ืŸ, ื”ื•ื›ืจื– ื›ื™ ื™ื•ื›ืŸ ื ื™ืฆื•ืœ ืฉื™ืืคืฉืจ ืœื–ื›ื•ืช ื‘ื”ืจืฉืื•ืช SYSTEM ื‘-Windows, ืืš ื”ืงื•ื“ ืฉืœื• ืžืชื•ื›ื ืŸ ืœื”ืชืคืจืกื ืœืื—ืจ ืฉื—ืจื•ืจื• ืฉืœ ืขื“ื›ื•ืŸ 7-Zip ืฉืžื‘ื˜ืœ ืืช ื”ืคื’ื™ืขื•ืช. ืžื›ื™ื•ื•ืŸ ืฉื”ืชื™ืงื•ื ื™ื ืขื“ื™ื™ืŸ ืœื ืคื•ืจืกืžื•, ื›ื“ืจืš ืขื•ืงืคืช ืœื”ื’ื ื”, ืžื•ืฆืข ืœื”ื’ื‘ื™ืœ ืืช ื”ื’ื™ืฉื” ืฉืœ ืชื•ื›ื ื™ืช 7-zip ืœืงืจื™ืื” ื•ื”ืคืขืœื” ื‘ืœื‘ื“.



ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”