å瀟ã¯ã19ã®åºæã®è匱æ§ïŒã¯ãªãã£ã«ã«ã¹ããŒã¿ã¹ã®3ã€ã®ããããšéèŠãªã¹ããŒã¿ã¹ã®5ã€ã®ãããïŒãã«ããŒãã補åã®äžé£ã®ã¢ããããŒãããªãªãŒã¹ããŸããã ã¯ããŒãºãããè匱æ§ã補åã³ã³ããŒãã³ããããã³ãããã®ããŒãžã§ã³ã«é¢ãã詳现ãªã¬ããŒãã¯ã察å¿ãã
ã»ãã¥ãªãã£æ
å ±ããŒãžã«ãããŸãã ãã®ãããç«ææ¥ã®äžç°ãšããŠãMSã¯3ã€ã®éèŠãªæŽæ°ããã°ã©ã ãšããã©ãŠã¶ãŒãš
Internet Explorer 11ãWindows 8.1 / RT 8.1ã®ææ°ããŒãžã§ã³çšã®éèŠãªæŽæ°ããã°ã©ã ããªãªãŒã¹ããŸããã
MS13-090æŽæ°ããã°ã©ã ã¯ãicardie.dll ActiveXã³ã³ããŒãã³ãïŒWindows XP SP3ããWindows 8.1ã§çµããïŒã®ãã¹ãŠã®ããŒãžã§ã³ã®Windowsã®ã¯ãã¹ãã©ãããã©ãŒã
ãªã¢ãŒãã³ãŒãå®è¡ã®è匱æ§ã解決ããŸãã æ°æ¥åãFireEye
㯠ãæ»æè
ãæªæã®ããã³ãŒããã·ã¹ãã ã«ã€ã³ã¹ããŒã«ããInternet ExplorerããŒãžã§ã³7-8-9 [Windows XPããã³Windows 7]ã®DEPããã³ASLR [
msvcrt.dll ROP ]ãåé¿ãããšã¯ã¹ããã€ãã䜿çšããããšã
å ±åããŸããïŒCVE- 2013-3918ïŒå¥åãã©ã€ããã€ã ãã®è匱æ§ã¯OSã®ãã¹ãŠã®ããŒãžã§ã³ã«ååšãããšããäºå®ã«ãããããããWindows 8ããã³8.1ã§IE 10-11ãã©ãŠã¶ãŒã®ææ°ããŒãžã§ã³ã䜿çšããŠãããŠãŒã¶ãŒã¯ããããã®OSã§äœ¿çšããã軜æžã¡ã«ããºã ãå«ããæªçšã®åœ±é¿ãåããŸããã EMETãŠãŒã¶ãŒãããã®ãšã¯ã¹ããã€ãã®ç Žå£çãªã¢ã¯ã·ã§ã³ããä¿è·ãããŠããŸãã ååäžãMSã¯ãããã®ç«ææ¥ã®äžéšãšããŠãã®è匱æ§ã®è§£æ±ºã
確èªããŸãã ã ä¿®æ£ãé©çšããã«ã¯ãåèµ·åãå¿
èŠã§ãã

ãã€ã¯ããœãããèªç€Ÿã®è£œåã«äœ¿çšããŠããç·©åæè¡ã«ã€ããŠã¯ãã§ã«æžããŠããŸãã 64ãããWindowsã®ææ°ããŒãžã§ã³ã®1ã€ã䜿çšããããšèªäœãæ¢ã«ç·©åèŠå ã§ããDEPã¯ããµããŒãä»ãã§ã³ã³ãã€ã«ãããŠãããã©ããã«é¢ä¿ãªããããã©ã«ãã§ããã»ã¹ã«å«ãŸããŠããããã§ãïŒMSã«ããã°ã64ãããããã»ã¹ã§ã¯DEPã¯åžžã«ãªã³ã«ãªã£ãŠããŸãããå®éã«ã¯ãx64 OSã®ãªããã€ã³ã¢ãŒãã§ããå°ãªããšãWindows 8以éã§ã¯32ãããããã»ã¹ãä¿è·ããŸãã DEPãããã©ã«ãã§ãªããã€ã³ã¹ããŒã¿ã¹ã«ãªã£ãŠãã32ãããã·ã¹ãã ãšã¯å¯Ÿç
§çã«ãä¿è·ããããã®ã®ãªã¹ãã«ã¢ããªã±ãŒã·ã§ã³ãå«ããã«ã¯ããŠãŒã¶ãŒã«ããè¿œå ã®æ§æãå¿
èŠã§ãã ããã«ãx64 OSã§ã®64ãããå®è¡å¯èœãã¡ã€ã«ã®äœ¿çšã¯ãOSã64ãããããã»ã¹ãäœæã§ããããã«ãããããè¿œå ã®ä¿è·ã¬ãã«ã§ããããšãã°ãããŒãã¹ãã¬ãŒã®åœ±é¿ãåãã«ãããªããŸãã çŸåšãã·ã§ã«ã³ãŒãã®å®è¡æã«ASLRããã€ãã¹ããããã®äž»ãªææ³ã¯ã¹ãã¬ãŒã§ãã
管çè
æš©éã§cmdãå®è¡ããbcdeditã³ãã³ããå
¥åãããšãOSã®DEPããªã·ãŒã®ã¹ããŒã¿ã¹ã確èªã§ããŸãã

å³ ã·ã¹ãã ã®DEPèšå®ãNXãã©ã¡ãŒã¿ãŒã®ã¹ããŒã¿ã¹ã¯AlwaysOnã§ãïŒOSã§EMETãæå¹ã«ãªã£ãŠããŸãïŒã

å³ ã°ããŒãã«ãªDEPèšå®ã¯ãã¡ã€ã³ã®EMETãŠã£ã³ããŠã§èª¿æŽã§ããŸãã
ããšãã°ãæ¡åŒµä¿è·ã¢ãŒãã®Internet Explorer 10+ã§ã¯ã軜æžèŠçŽ ãšããŠWindows 7 x64ã®64ãããããã»ã¹ãšããŠã¿ãã®èµ·åã䜿çšããŸãã ããã«ãããã»ã¹ã¢ãã¬ã¹ç©ºéã«ããŒããããã©ã€ãã©ãªã®å ŽåãASLRïŒWindows 8+ããã³7ã®OSã§ã®ForceASLRæ§æïŒã¯ããµããŒããªãã§ã³ã³ãã€ã«ãããå Žåã§ãïŒ/ DYNAMICBASEïŒåŒ·å¶çã«æå¹ã«ãªããŸãã

å³ Windows 7 x64ã®EPMãæåã§æå¹ã«ãããšãã¿ãããã»ã¹ã64ãããããã»ã¹ãšããŠéå§ã§ããŸãïŒã¢ã³ãã¹ãã¬ãŒïŒã
IEã§EPMãæå¹ã«ããã«ã¯ãæé ã«åŸãå¿
èŠããããŸãã ããŒã«->ãã©ãŠã¶ã®ããããã£->詳现->詳现ä¿è·ã¢ãŒããæå¹ã«ããŸãã

å³ IE10 +ã®é«åºŠãªä¿è·ã¢ãŒãïŒãµã³ãããã¯ã¹åïŒãèšå®ããŸããããã¯ãWindows 7 x64ã§ã¯ããã©ã«ãã§ãªãã«ãªã£ãŠããŸãïŒWindows 7 x32ã§ã¯ç¡å¹ã§ãïŒã Windows 8以éã§ã¯ãããã©ã«ãã§æå¹ã«ãªã£ãŠãã
ãã¿ãã®å®å
šãªåé¢ã䜿çš
ããŸã ã
ã¢ãžã¥ãŒã«ã®ASLRã«é¢ããŠã¯ãããèªäœã«ã¯ã°ããŒãã«ãªå
å«ã€ã³ãžã±ãŒã¿ããããŸããã ASLRã¯ããã»ã¹çšã§ã¯ãªããã¢ãã¬ã¹ç©ºéã«ããŒããããç¹å®ã®ã¢ãžã¥ãŒã«çšã«å«ãŸããŠããŸãã å®è¡å¯èœã€ã¡ãŒãžãASLRãµããŒãä»ãã§ã³ã³ãã€ã«ãããŠããªãå ŽåãProcess Explorerã¯ããã®ããã»ã¹ã®ã³ã³ããã¹ãã§åäœããã·ã¹ãã ã©ã€ãã©ãªã«å«ãŸããŠããã«ãããããããã¹ããŒã¿ã¹ãASLRãæ¬ èœããŠããããã»ã¹ã«å²ãåœãŠãŸãã ããã«ãOSã«ã¯ãå²ãåœãŠãããã¡ã¢ãªã®ã¢ãã¬ã¹ãã©ã³ãã åããããªã·ãŒããããŸãïŒEMETã䜿çšããå ŽåãBottomUpASLRèšå®ã«ãã£ãŠèšå®ãããŸãïŒã
æŽæ°ããã°ã©ã
MS13-088 ïŒç·æ¥ïŒ/ãªã¢ãŒãã³ãŒãå®è¡ïŒãã¹ãŠã®ããŒãžã§ã³ã®Internet ExploerïŒ6-11ïŒã®ãã¹ãŠã®Windows XP SP3-7-8.1ã®10åã®è匱æ§ãä¿®æ£ããŸãã æ»æè
ã¯ãç¹å¥ã«åœ¢æãããWebããŒãžãä»ããŠã·ã¹ãã å
ã®ä»»æã®ã³ãŒããå®è¡ã§ããŸãã è匱æ§ã®ã¿ã€ãã¯ã¡ã¢ãªç Žå£ã§ããããã©ãŠã¶ã³ãŒãã®ã¡ã¢ãªãžã®èª€ã£ãã¢ã¯ã»ã¹ã«é¢é£ããŠããŸãã æ»æè
ã¯ãã®è匱æ§ã®æªçšãå©çšããŠãæªæã®ããã³ãŒãïŒãã©ã€ããã€ïŒãå¯ãã«ã€ã³ã¹ããŒã«ã§ããŸãã
ã³ãŒããæªçšããå¯èœæ§ããããŸãã
æŽæ°ããã°ã©ã
MS13-089 ïŒç·æ¥ïŒ/ãªã¢ãŒãã³ãŒãå®è¡ïŒWindows XP SP3ãã8.1ãŸã§ã®ãã¹ãŠã®OSããŒãžã§ã³ã®GDIã°ã©ãã£ãã¯ã³ã³ããŒãã³ãã®1ã€ã®è匱æ§ãä¿®æ£ããŸãã æ»æè
ã¯ãã¯ãŒããããçšã«ç¹å¥ã«æºåãããWindowsæžã蟌ã¿ãã¡ã€ã«ãä»ããŠãªã¢ãŒãã³ãŒããå®è¡ã§ããŸãã
ã³ãŒããæªçšããå¯èœæ§ããããŸãã
æŽæ°
MS13-091 ïŒéèŠïŒ/ãªã¢ãŒãã³ãŒãå®è¡ïŒMicrosoft Office 2003-2007-2010-2013-2013 RTã®ãµããŒããããŠãããã¹ãŠã®ããŒãžã§ã³ã®3ã€ã®è匱æ§ãä¿®æ£ããŸãã æ»æè
ã¯ãäºåã«æºåãããWordPerfectããã¥ã¡ã³ããä»ããŠãªã¢ãŒãã³ãŒããå®è¡ã§ããŸãã
ã³ãŒããæªçšããå¯èœæ§ããããŸãã
æŽæ°
MS13-092 ïŒéèŠïŒ/ç¹æš©ã®ææ ŒïŒ64ãããããŒãžã§ã³ã®Windows 8ããã³Windows Server 2012ã®1ã€ã®è匱æ§ãä¿®æ£ããŸã
ãHyper -V ïŒ
ãã€ããŒã³ãŒã«ïŒé¢æ°ãåŒã³åºããšãã«OSã³ãŒãããã©ã¡ãŒã¿ãŒãæ£ããåŠçããªããããæ»æè
ãã·ã¹ãã ã§ç¹æš©ãäžããããšãã§ããŸãã·ã¹ãã ã¬ãã«ã«ã
ã³ãŒããæªçšããå¯èœæ§ããããŸããæŽæ°
MS13-093 ïŒéèŠïŒ/æ
å ±é瀺ïŒ8.1ïŒXP SP2-8-Server 2012ïŒãé€ããã¹ãŠã®64ããããšãã£ã·ã§ã³ã®Windowsäžã®afd.sysã«ãŒãã«ã¢ãŒããã©ã€ããŒïŒAncillary Functionãã©ã€ããŒïŒã®1ã€ã®è匱æ§ãä¿®æ£ããŸãã ãã®è匱æ§ã¯ããã©ãŠã¶ã³ãŒãããŠãŒã¶ãŒã¢ãŒããšã«ãŒãã«ã¢ãŒãã®ã¡ã¢ãªãããã¯éã§ããŒã¿ã誀ã£ãŠè»¢éããå Žåã«çºçããŸãã
æªçšãããå¯èœæ§ã¯ã»ãšãã©ãããŸãããæŽæ°
MS13-094 ïŒéèŠïŒ/æ
å ±é瀺ïŒMicrosoft Outlookã¡ãŒã«ã¯ã©ã€ã¢ã³ãã®ãã¹ãŠã®ãµããŒããããŠããããŒãžã§ã³ã®1ã€ã®è匱æ§ãä¿®æ£ããŸãã æ»æè
ã¯ãç¹å¥ã«æºåãããã¡ãã»ãŒãžïŒS / MIME蚌ææžä»ãïŒã䜿çšããŠãè匱ãªã·ã¹ãã ãšåããããã¯ãŒã¯äžã«ããã³ã³ãã¥ãŒã¿ãŒã®éããŠããããŒããšIPã¢ãã¬ã¹ã«é¢ããæ
å ±ã«ã¢ã¯ã»ã¹ã§ããŸãã
æªçšãããå¯èœæ§ã¯ã»ãšãã©ãããŸãããæŽæ°
MS13-095 ïŒéèŠïŒ/ãµãŒãã¹æåŠïŒãµããŒããããŠãããã¹ãŠã®OSããŒãžã§ã³ã®1ã€ã®è匱æ§ãä¿®æ£ããŸãã X.509ããžã¿ã«èšŒææžåŠçã³ã³ããŒãã³ãã«è匱æ§ãååšããŸãã æ»æè
ã¯ãç¹å¥ã«æºåããããã¡ã€ã«ãä»ããŠWebãµãŒãã¹ãããªãŒãºãããå¯èœæ§ããããŸãã
æªçšãããå¯èœæ§ã¯ã»ãšãã©ãããŸããã1-æªçšãããå¯èœæ§ã®ããã³ãŒããã®è匱æ§ãæªçšãããå¯èœæ§ã¯éåžžã«é«ããæ»æè
ã¯ãã®æªçšã䜿çšããŠãããšãã°ãªã¢ãŒãã§ã³ãŒããå®è¡ã§ããŸãã
2-æªçšã³ãŒãã®æ§ç¯ã¯é£ããè匱æ§ã®æè¡çç¹åŸŽãšãšã¯ã¹ããã€ãéçºã®è€éãã ãã§ãªããæ»æè
ãæç¶å¯èœãªãšã¯ã¹ããã€ãç¶æ³ãéæããå¯èœæ§ã¯äœãããããšã¯ã¹ããã€ãã®å¯èœæ§ã¯å¹³åã§ãã
3-æªçšãããå¯èœæ§ã®äœãã³ãŒãæªçšãããå¯èœæ§ã¯æå°éã§ãããæ»æè
ã¯æ£åžžã«æ©èœããã³ãŒããéçºãããã®è匱æ§ã䜿çšããŠæ»æãè¡ãããšã¯ã§ããŸããã
ã§ããã ãæ©ãæŽæ°ããã°ã©ã ãã€ã³ã¹ããŒã«ããããšããå§ãããŸãããŸã ã€ã³ã¹ããŒã«ããŠããªãå Žåã¯ãWindows Updateã䜿çšããŠæŽæ°ããã°ã©ã ã®èªåé
ä¿¡ãæå¹ã«ããŸãïŒãã®ãªãã·ã§ã³ã¯æ¢å®ã§æå¹ã«ãªã£ãŠããŸãïŒã


å®å
šã§ããã