메뉴
BL
Ars Technica 49일 전

MS, 보안 연구원과 갈등 끝 공개된 제로데이 취약점 패치

IMP
8/10
핵심 요약

마이크로소프트(MS)가 다크웹 연구원 '나이트메어 이클립스(Nightmare Eclipse)'와의 공개된 갈등 속에 제보된 다수의 고위험 제로데이 취약점을 수정했습니다. 이번 패치에는 공격자가 시스템 최고 권한을 획득할 수 있는 로컬 권한 상승 취약점과 과거 불완전하게 패치되어 재발생한 취약점이 포함되어 있습니다. 비트로커(BitLocker) 전체 디스크 암호화를 무력화하는 취약점 등 아직 완벽히 해결되지 않은 보안 구멍들도 남아있어 보안 담당자의 주의가 요구됩니다.

번역된 본문

마이크로소프트(Microsoft)는 화요일, 거대 소프트웨어 기업과 격렬한 갈등을 빚고 있는 한 보안 연구원에 의해 공개된 고위험도 제로데이(0-day) 취약점 2개에 대한 수정 패치를 릴리스했습니다.

가명인 '나이트메어 이클립스(Nightmare Eclipse)'로 활동하는 이 연구원은 최근 몇 달 동안 실제 악용될 가능성이 있는 제로데이 취약점 여러 개를 공개했습니다. 해당 연구원은 개념 증명(PoC) 코드가 포함된 이번 공개는 자신들이 논의했던 취약점과 관련하여 마이크로소프트가 체결한 합의를 파기했기 때문이라고 밝혔습니다.

공개 논란 "누군가 우리의 합의를 위반했고, 그 결과 나는 모든 것을 잃고 집 없는 신세가 되었습니다."라고 나이트메어 이클립스는 3월에 작성했습니다. "그들은 이런 일이 일어날 것을 알면서도 결국 내 등을 찔렀습니다. 이는 그들의 결정이지 내 결정이 아닙니다."

6월 취약점 패치 배치 릴리스의 일환으로, 마이크로소프트는 'CVE-2026-45586'에 대한 수정 패치를 배포했습니다. 나이트메어 이클립스는 이 취약점을 'GreenPlasma'라는 이름으로 5월에 공개하고 제한된 PoC 코드를 제공했습니다. 이 취약점은 로컬 권한 상승(Local Privilege Escalation) 취약점으로, 낮은 수준의 권한을 가진 사용자나 프로세스가 운영체제(OS) 보호 기능을 우회하여 악성코드를 설치하는 데 필요한 전체 'SYSTEM' 권한을 얻기 위해 다른 취약점과 연계(Chaining)될 수 있음을 의미합니다.

마이크로소프트는 CVE-2026-45586의 악용 난이도가 매우 낮고 사용자의 상호작용이 필요하지 않으며, 야생에서 실제 악용될 가능성이 높다고 밝혔습니다. 이 취약점은 Windows Collaborative Translation Framework 내의 "파일 액세스 전 부적절한 링크 해결('링크 따라가기')"로 인해 발생했다고 회사 측은 덧붙였습니다. 현재까지 해당 취약점이 실제로 악용되었다는 징후는 없습니다.

화요일의 패치 묶음에는 나이트메어 이클립스가 공개한 또 다른 취약점인 'MiniPlasma'도 수정되었습니다. 마이크로소프트는 이메일 성명을 통해 이 취약점이 'CVE-2020-17103'으로 추적된다고 밝혔는데, 이는 마이크로소프트가 6년 전 처음 수정했던 취약점입니다. 즉, MiniPlasma는 초기 형태의 회귀(Regression) 또는 불완전한 패치의 결과였습니다. 회사는 화요일 공지사항을 업데이트하여 해당 패치가 재배포되었음을 명시하는 중입니다.

마이크로소프트는 나이트메어 이클립스가 공개한 다른 취약점들에 대해서는 아직 패치를 릴리스하지 않았습니다. 회사는 공격자가 비트로커(BitLocker) 전체 디스크 암호화를 무력화할 수 있는 취약점인 'YellowKey'에 대한 수동 완화 지침을 제공했습니다. 이는 공격자가 기기에 물리적으로 액세스할 수 있는 상황(비트로커가 보호하기 위해 설계된 바로 그 시나리오)에서 큰 이점이 될 수 있습니다. 회사는 아직 이 취약점의 근본적인 원인을 수정하지 못했습니다.

현재 나이트메어 이클립스가 공개한 다른 취약점들의 상태도 불분명합니다. 연구원은 Windows Defender에 존재하는 취약점 하나에 'RedSun'이라는 이름을 붙였습니다. 'BlueHammer'라는 이름의 또 다른 취약점 역시 SYSTEM 권한을 제공하는 로컬 권한 상승 결함입니다.

지난 몇 달 동안 나이트메어 이클립스는 마이크로소프트를 향해 여러 차례 비난을 가했습니다. 구체적인 비판 내용은 명확하지 않지만, 회사의 취약점 공개 프로그램에 대한 불만을 암시하는 내용이 많습니다. 이에 대해 마이크로소프트는 연구원이 "책임감 있게" 취약점을 공개하지 않았다며 공개적으로 비난하고 법적 조치를 취할 가능성을 은연중에 내비쳤습니다. 그러나 대중의 거센 역풍이 일자, 마이크로소프트는 나중에 태도를 누그러뜨리며 그러한 법적 조치를 취하지 않겠다고 약속했습니다.

화요일, 나이트메어 이클립스는 새로운 Windows 취약점에 대한 익스플로잇 코드를 게시했습니다. 이는 Defender를 표적으로 삼는 경쟁 상태(Race Condition) 취약점입니다.

화요일 패치 배치에는 약 200개의 취약점 수정이 포함되었습니다. MiniPlasma가 이미 수정된 것으로 보이지만, 이 중 2개 역시 제로데이로 확인되었습니다.

게시물은 최초 발행 후 마이크로소프트가 제공한 정보를 포함하도록 업데이트되었습니다.

댄 구딘(Dan Goodin), 수석 보안 에디터

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Microsoft on Tuesday released fixes for two high-severity zero-days that were disclosed by a researcher who has been locked in a testy beef with the software giant. Nightmare Eclipse, the pseudonym the researcher goes by, released a handful of high-severity vulnerabilities in recent months, making them zero-days that had the potential to be exploited in the wild. The researcher has said the disclosures, which included proof-of-concept code, came after Microsoft reneged on an arrangement the two made regarding vulnerabilities they had discussed. Disclosure drama “But someone violated our agreement and left me homeless with nothing,” Nightmare Eclipse wrote in March. “They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.” As part of June’s vulnerability patch batch release, Microsoft issued a fix for CVE-2026-45586 . Nightmare Eclipse disclosed the vulnerability and limited PoC code in May under the name GreenPlasma . The vulnerability is a local privilege escalation, meaning it can be chained to a separate vulnerability to give users or processes with low-level privileges the ability to defeat OS protections and gain full SYSTEM rights needed to install malware. Microsoft said CVE-2026-45586 required minimal complexity to exploit, required no user interaction, and that chances of active exploitation in the wild were likely. The vulnerability, the company added, was the result of “improper link resolution before file access (‘link following’) in [the] Windows Collaborative Translation Framework.” There are no indications that the vulnerability has been actively exploited so far. Tuesday’s patch bundle also fixed MiniPlasma , a separate vulnerability disclosed by Nightmare Eclipse. Microsoft said in an email that the vulnerability is tracked as CVE-2020-17103, a vulnerability Microsoft first fixed six years ago. That means MiniPlasma was the result of a regression or an incomplete patch in its initial form. The company is in the process of updating Tuesday’s bulletin to note the republication. Microsoft has yet to release patches for other vulnerabilities disclosed by Nightmare Eclipse. The company did provide manual instructions for mitigating YellowKey, a vulnerability that allows attackers to defeat Bitlocker full-disk encryption. That could be a boon when attackers have physical access to a device (the precise scenario Bitlocker is designed to protect against). The company has yet to fix the underlying cause of the vulnerability. The status of other vulnerabilities disclosed by Nightmare Eclipse are also unclear at the moment. The researcher named one vulnerability, present in Windows Defender RedSun . Another, named BlueHammer, is also a local privilege escalation flaw that provides SYSTEM rights. Over the past few months, Nightmare Eclipse has taken multiple potshots at Microsoft. The specific criticisms remain unclear, but many make references to complaints about the company’s vulnerability disclosure program. Microsoft, in turn, has publicly railed against the researcher for “not responsibly” disclosing the vulnerabilities and made a vailed reference to the possibility of pursuing legal action. After a public backlash, Microsoft later relented and vowed no such legal action would occur. On Tuesday, Nightmare Eclipse published exploit code for a new Windows vulnerability. It’s a race condition that targets Defender. Tuesday’s patch batch included fixes for roughly 200 vulnerabilities. Notwithstanding the appearance that MiniPlasma was fixed, two of them were also confirmed as zero-days. Post updated to include information Microsoft provided after initial publication of this post. Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 24 Comments