Windows 10¤ä11¤Î¡ÖSmart App Control¡×¤È¡ÖSmartScreen¡×¤ò¤¹¤êÈ´¤±¤Æ·Ù¹ð¤Ê¤·¤Ç¥×¥í¥°¥é¥à¤¬µ¯Æ°¤Ç¤¤ëÉÔ¶ñ¹ç¤Î¸ºß¤¬È½ÌÀ
Windows¤ËÅëºÜ¤µ¤ì¤Æ¤¤¤ë¥»¥¥å¥ê¥Æ¥£µ¡Ç½¤Ç¤¢¤ë¡ÖSmart App Control¡×¤È¡ÖSmartScreen¡×¤Ë¡¢¥»¥¥å¥ê¥Æ¥£·Ù¹ð¤ä¥Ý¥Ã¥×¥¢¥Ã¥×ɽ¼¨¤Ê¤·¤Ç¥×¥í¥°¥é¥à¤òµ¯Æ°¤Ç¤¤ëÀß·×¾å¤Î·ç´Ù¤¬¤¢¤ë¤³¤È¤¬¡¢¥»¥¥å¥ê¥Æ¥£´ë¶È¤ÎElastic Security Labs¤Ë¤è¤Ã¤Æȯ¸«¤µ¤ì¤Þ¤·¤¿¡£
Dismantling Smart App Control - Elastic Security Labs
Researchers Uncover Flaws in Windows Smart App Control and SmartScreen
https://thehackernews.com/2024/08/researchers-uncover-flaws-in-windows.html
Windows Smart App Control, SmartScreen bypass exploited since 2018
https://www.bleepingcomputer.com/news/microsoft/windows-smart-app-control-smartscreen-bypass-exploited-since-2018/
Smart App Control¤ÏWindows 11¤«¤éƳÆþ¤µ¤ì¤Æ¤¤¤ë¥¯¥é¥¦¥É¥Ù¡¼¥¹¤Î¥»¥¥å¥ê¥Æ¥£µ¡Ç½¤Ç¡¢°°Õ¤¢¤ë¥¢¥×¥ê¤ä¿®Íê¤Ç¤¤Ê¤¤¥¢¥×¥ê¡¢½ð̾¤µ¤ì¤Æ¤¤¤Ê¤¤¥¢¥×¥ê¤¬¼Â¹Ô¤µ¤ì¤ë¤Î¤ò¥Ö¥í¥Ã¥¯¤¹¤ë¤È¤¤¤¦¤â¤Î¤Ç¤¹¡£
¤Þ¤¿¡¢SmartScreen¤ÏWindows 8¤«¤éƳÆþ¤µ¤ì¤¿Æ±Íͤε¡Ç½¤Ç¡¢Smart App Control¤¬Í¸ú¤Ç¤Ê¤¤¾ì¹ç¤ÏSmartScreen¤¬Âå¤ï¤ê¤ËÀøºßŪ¤Ê°°Õ¤Î¤¢¤ë¥³¥ó¥Æ¥ó¥Ä¤«¤éWindows¤òÊݸ¤Þ¤¹¡£
Elastic Security Labs¤Ï2024ǯ8·î6Æü¤Ë¡¢Smart App Control¤ÈSmartScreen¤Ë¹¶·â¼Ô¤¬¥»¥¥å¥ê¥Æ¥£·Ù¹ð¤ä¥Ý¥Ã¥×¥¢¥Ã¥×¤Ê¤·¤Ç½é´ü¥¢¥¯¥»¥¹¤ò¼èÆÀ¤Ç¤¤ëÀß·×¾å¤Î·ç´Ù¤¬¤¤¤¯¤Ä¤«¤¢¤ë¤ÈÊó¹ð¤·¤Þ¤·¤¿¡£¤Ê¤ª¡¢½é´ü¥¢¥¯¥»¥¹¤È¤Ï¥µ¥¤¥Ð¡¼¹¶·â¤Î¥¿¡¼¥²¥Ã¥È¤ËÂФ¹¤ëÉÔÀµ¥¢¥¯¥»¥¹¤Î½é´üÃʳ¬¤Î¤³¤È¤Ç¤¹¡£
¥ì¥Ý¡¼¥È¤Ë¤è¤ë¤È¡¢¹¶·â¼Ô¤Ï´ë¶È¤Ë¤Ê¤ê¤¹¤Þ¤·¤ÆExtended Validation(EV)¾ÚÌÀ½ñ¤ò¼èÆÀ¤·¡¢¤³¤ì¤Ç¥Þ¥ë¥¦¥§¥¢¤Ë½ð̾¤·¤ÆSmart App Control¤ò²óÈò¤·¤Æ¤¤¤ë¤È¤Î¤³¤È¡£
¤Þ¤¿¡¢É¾È½¤Î¤¤¤¤¥¢¥×¥ê¤ò¾è¤Ã¼è¤ë¡Ö¥ì¥Ô¥å¥Æ¡¼¥·¥ç¥ó¡¦¥Ï¥¤¥¸¥ã¥Ã¥¯¡×¤ä¡¢¡ÖLNK¥¹¥È¥ó¥Ô¥ó¥°¡×¤È¸Æ¤Ð¤ì¤ëLNK¥Õ¥¡¥¤¥ë¤Î½èÍý¤ÎÉÔ¶ñ¹ç¤Ë¤è¤Ã¤Æ¤â¡¢Smart App Control¤äSmartScreen¤ò¤¯¤°¤êÈ´¤±¤ë¤³¤È¤¬²Äǽ¤À¤ÈElastic Security Labs¤Ï»ØŦ¤·¤Æ¤¤¤Þ¤¹¡£
Elastic Security Labs¤¬¡¢¥Þ¥ë¥¦¥§¥¢¸¡ºº¥µ¥¤¥È¤ÎVirusTotal¤Ç¤³¤ì¤é¤ÎÉÔ¶ñ¹ç¤¬°ÍѤµ¤ì¤¿º¯ÀפòÄ´¤Ù¤¿¤È¤³¤í¡¢ºÇ¤â¸Å¤¤Êó¹ð¤Ï2018ǯ¤Î¤â¤Î¤Ç¤·¤¿¡£¤Ä¤Þ¤ê¡¢¤³¤ì¤é¤Î¥»¥¥å¥ê¥Æ¥£¾å¤Î·ç´Ù¤Ïº£²ó¤ÎÊó¹ð¤Þ¤Ç6ǯ´Ö¤Ë¤ï¤¿¤Ã¤Æ°ÍѤµ¤ì¤Æ¤¤¤ë¤³¤È¤Ë¤Ê¤ê¤Þ¤¹¡£
Elastic Security Labs¤Ï¡Ö¥ì¥Ô¥å¥Æ¡¼¥·¥ç¥ó¥Ù¡¼¥¹¤ÎÊݸ¥¹¥Æ¥à¤Ï¡¢°ìÈÌŪ¤Ê¥Þ¥ë¥¦¥§¥¢¤ò¥Ö¥í¥Ã¥¯¤¹¤ë¤¿¤á¤Î¶¯ÎϤʥ쥤¥ä¡¼¤Ç¤¹¤¬¡¢¤É¤Î¤è¤¦¤Ê¥»¥¥å¥ê¥Æ¥£µ»½Ñ¤Ë¤â·çÅÀ¤¬¤¢¤ê¡¢Ãí°Õ¿¼¤¯¤½¤Î·çÅÀ¤òõ¤»¤Ð¥Ö¥í¥Ã¥¯¤ò²óÈò¤¹¤ë¤³¤È¤¬²Äǽ¤Ç¤¹¡£¥»¥¥å¥ê¥Æ¥£¥Á¡¼¥à¤Ï¡¢¸¡½Ð¥¹¥¿¥Ã¥¯¤Ë¤ª¤±¤ë¥À¥¦¥ó¥í¡¼¥É¤òÃí°Õ¿¼¤¯Àººº¤·¡¢¤³¤ÎÎΰè¤Ç¤ÎÊݸî¤òOS¥Í¥¤¥Æ¥£¥Ö¤Î¥»¥¥å¥ê¥Æ¥£µ¡Ç½¤À¤±¤ËÍê¤ë¤Ù¤¤Ç¤Ï¤¢¤ê¤Þ¤»¤ó¡×¤È½Ò¤Ù¤Þ¤·¤¿¡£