¡¾Îó²îͨ¸æ¡¿Î¢Èí8Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2022-08-10


0x00 Îó²î¸ÅÊö

2022Äê8ÔÂ9ÈÕ£¬£¬£¬£¬ £¬£¬Î¢ÈíÐû²¼ÁË8ÔÂÇå¾²¸üУ¬£¬£¬£¬ £¬£¬±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÐÞ¸´Á˰üÀ¨2¸ö0 dayÎó²îÔÚÄÚµÄ121¸öÇå¾²Îó²î£¨²»°üÀ¨20¸öMicrosoft EdgeÎó²î£©£¬£¬£¬£¬ £¬£¬ÆäÖÐÓÐ17¸öÎó²îÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÉæ¼°Active Directory Domain Services¡¢Azure ¡¢Microsoft Exchange Server¡¢Microsoft Office¡¢Microsoft MSDT¡¢Windows Kerberos¡¢Windows Kernel¡¢Windows Internet Information Services¡¢Windows Network File System¡¢Windows Secure Socket Tunneling Protocol (SSTP)ºÍWindows Win32KµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£¡£¡£

±¾´ÎÐÞ¸´µÄ121¸öÎó²îÖУ¬£¬£¬£¬ £¬£¬64¸öΪÌáÈ¡Îó²î£¬£¬£¬£¬ £¬£¬31¸öΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬ £¬£¬12¸öΪÐÅϢй¶Îó²î£¬£¬£¬£¬ £¬£¬7¸öΪ¾Ü¾øÐ§ÀÍÎó²î£¬£¬£¬£¬ £¬£¬6¸öΪÇå¾²¹¦Ð§ÈƹýÎó²î£¬£¬£¬£¬ £¬£¬ÒÔ¼°1¸öÓÕÆ­Îó²î¡£¡£¡£¡£¡£¡£

΢Èí±¾´Î¹²ÐÞ¸´ÁË2¸ö0 dayÎó²î£¬£¬£¬£¬ £¬£¬ÆäÖÐCVE-2022-34713£¨DogWalkÎó²î£©ÒÑ·¢Ã÷±»Æð¾¢Ê¹Óãº

CVE-2022-34713£ºMicrosoft MSDTÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îλÓÚMicrosoft Windows Ö§³ÖÕï¶Ï¹¤¾ß (MSDT) ÖУ¬£¬£¬£¬ £¬£¬ÆäCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬ £¬£¬¹¥»÷ÖØÆ¯ºóµÍÇÒÎÞÐèÌØÊâȨÏÞ£¬£¬£¬£¬ £¬£¬µ«ÐèÓëÓû§½»»¥²Å»ªÍâµØÊ¹Óᣡ£¡£¡£¡£¡£¸ÃÎó²îÏÖÔÚÒѾ­¹ûÕæÅû¶£¬£¬£¬£¬ £¬£¬ÇÒÒѾ­¼ì²âµ½Îó²îʹÓᣡ£¡£¡£¡£¡£

CVE-2022-30134 £ºMicrosoft Exchange ÐÅϢй¶Îó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.6£¬£¬£¬£¬ £¬£¬¹¥»÷ÖØÆ¯ºóºÍËùÐèȨÏ޵ͣ¬£¬£¬£¬ £¬£¬ÎÞÐèÓû§½»»¥¼´¿ÉÔ¶³ÌʹÓ㬣¬£¬£¬ £¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÒÔ¶ÁȡĿµÄµç×ÓÓʼþ¡£¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃÎó²îÒѾ­¹ûÕæÅû¶£¬£¬£¬£¬ £¬£¬Î¢ÈíÒѾ­Ðû²¼Á˸ÃÎó²îµÄÇå¾²¸üУ¬£¬£¬£¬ £¬£¬µ«ÊÜÓ°ÏìÓû§»¹ÐèÆôÓÃExchange ServerµÄWindows À©Õ¹±£»£»£»£»¤ÒÔ·À»¤´ËÎó²î¡£¡£¡£¡£¡£¡£

±¾´ÎÐÞ¸´µÄÎó²îÖУ¬£¬£¬£¬ £¬£¬ÆÀ¼¶ÎªÑÏÖØµÄ17¸öÎó²î°üÀ¨£º

l  CVE-2022-34691£ºActive Directory ÓòЧÀÍÌØÈ¨ÌáÉýÎó²î£º¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔʹÓÃÆäÓµÓлòÖÎÀíµÄÅÌËã»úÕÊ»§µÄÊôÐÔ£¬£¬£¬£¬ £¬£¬²¢´Ó Active Directory Ö¤ÊéЧÀÍ»ñȡ֤Ê飬£¬£¬£¬ £¬£¬´Ó¶øÔÊÐíÌáÉýϵͳȨÏÞ¡£¡£¡£¡£¡£¡£Ö»Óе± Active Directory Ö¤ÊéЧÀÍÔÚÓòÉÏÔËÐÐʱ£¬£¬£¬£¬ £¬£¬ÏµÍ³²ÅÈÝÒ×Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£

l  CVE-2022-33646£ºAzure Batch ½ÚµãÊðÀíÌØÈ¨ÌáÉýÎó²î    

l  CVE-2022-21980£ºMicrosoft Exchange Server ÌØÈ¨ÌáÉýÎó²î     

l  CVE-2022-24516£ºMicrosoft Exchange Server ÌØÈ¨ÌáÉýÎó²î     

l  CVE-2022-24477£ºMicrosoft Exchange Server ÌØÈ¨ÌáÉýÎó²î     

l  CVE-2022-35752£ºWindows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î

l  CVE-2022-35753£ºWindows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î

l  CVE-2022-34696£ºWindows Hyper-V Ô¶³Ì´úÂëÖ´ÐÐÎó²î

l  CVE-2022-35804£ºSMB ¿Í»§¶ËºÍЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î

l  CVE-2022-30133£ºWindows µã¶ÔµãЭÒé (PPP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î     

l  CVE-2022-35744£ºWindows µã¶ÔµãЭÒé (PPP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î£ºÖ»ÄÜͨ¹ý¶Ë¿Ú 1723 ͨѶÀ´Ê¹ÓÃCVE-2022-30133ºÍCVE-2022-35744£¬£¬£¬£¬ £¬£¬¿ÉÒÔͨ¹ý½ûÓÃ¶Ë¿Ú 1723×÷ΪÔÝʱ»º½â²½·¥£¬£¬£¬£¬ £¬£¬µ«Õâ¿ÉÄÜ»áÓ°ÏìÍøÂçÉϵÄͨѶ¡£¡£¡£¡£¡£¡£

l  CVE-2022-35745£ºWindows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î

l  CVE-2022-35766£ºWindows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î

l  CVE-2022-35794£ºWindows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î£ºÀÖ³ÉʹÓôËÎó²îÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬£¬£¬£¬ £¬£¬¿ÉÒÔÔÚδ¾­Éí·ÝÑéÖ¤µÄÇéÐÎÏÂÏò RAS ЧÀÍÆ÷·¢ËÍÌØÖÆµÄÅþÁ¬ÇëÇ󣬣¬£¬£¬ £¬£¬Õâ¿ÉÄܵ¼Ö RAS ЧÀÍÆ÷ÅÌËã»úÉϵÄÔ¶³Ì´úÂëÖ´ÐÐ (RCE)¡£¡£¡£¡£¡£¡£

l  CVE-2022-34714£ºWindows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î

l  CVE-2022-34702£ºWindows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î

l  CVE-2022-35767£ºWindows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î

΢Èí8Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE ID

CVE ÎÊÌâ

ÑÏÖØÐÔ

CVE-2022-34716

.NET   ÓÕÆ­Îó²î

¸ßΣ

CVE-2022-34691

Active   Directory ÓòЧÀÍÌØÈ¨ÌáÉýÎó²î

ÑÏÖØ

CVE-2022-33646

Azure   Batch ½ÚµãÊðÀíÌØÈ¨ÌáÉýÎó²î

ÑÏÖØ

CVE-2022-34685

Azure   RTOS GUIX Studio ÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-34686

Azure   RTOS GUIX Studio ÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-35773

Azure   RTOS GUIX Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35779

Azure   RTOS GUIX Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35806

Azure   RTOS GUIX Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-34687

Azure   RTOS GUIX Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-30176

Azure   RTOS GUIX Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-30175

Azure   RTOS GUIX Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35791

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35818

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35809

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35789

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35815

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35817

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35816

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35814

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35785

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35812

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35811

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35784

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35810

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35813

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35788

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35783

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35786

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35787

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35819

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35781

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35775

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35790

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35780

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35799

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35772

Azure   Site Recovery Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35800

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35774

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35802

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35782

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35824

Azure   Site Recovery Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35801

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35808

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35776

Azure   Site Recovery ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-35807

Azure   Site Recovery ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35821

Azure   Sphere ÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-35760

Microsoft   ATA ¶Ë¿ÚÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35820

Windows   À¶ÑÀÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-34692

Microsoft   Exchange ÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-21980

Microsoft   Exchange Server ÌØÈ¨ÌáÉýÎó²î

ÑÏÖØ

CVE-2022-21979

Microsoft   Exchange ÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-24516

Microsoft   Exchange Server ÌØÈ¨ÌáÉýÎó²î

ÑÏÖØ

CVE-2022-30134

Microsoft   Exchange ÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-24477

Microsoft   Exchange Server ÌØÈ¨ÌáÉýÎó²î

ÑÏÖØ

CVE-2022-34717

Microsoft   Office Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-33648

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-33631

Microsoft   Excel Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2022-35742

Microsoft   Outlook ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-34713

Microsoft   Windows Ö§³ÖÕï¶Ï¹¤¾ß (MSDT) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35743

Microsoft   Windows Ö§³ÖÕï¶Ï¹¤¾ß (MSDT) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35752

Windows   SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-35753

Windows   SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-35769

Windows   µã¶ÔµãЭÒé (PPP) ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-34690

Windows   ´«ÕæÐ§ÀÍÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-34696

Windows   Hyper-V Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-35751

Windows   Hyper-V ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-33640

System   Center Operations Manager£º¿ª·ÅʽÖÎÀí»ù´¡¼Ü¹¹ (OMI) ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35827

Visual   Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35777

Visual   Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35825

Visual   Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35826

Visual   Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-30144

WindowsÀ¶ÑÀЧÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35750

Win32k   ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35757

Windows   Cloud Files Mini Filter Çý¶¯³ÌÐòÌáȨÎó²î

¸ßΣ

CVE-2022-35771

Windows   Defender Credential Guard ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-34705

Windows   Defender Credential Guard ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-34710

Windows   Defender Credential Guard ÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-34709

Windows   Defender Credential Guard Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2022-34704

Windows   Defender Credential Guard ÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-34712

Windows   Defender Credential Guard ÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-35746

Windows   Êý×ÖýÌåÎüÊÕÆ÷ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35749

Windows   Êý×ÖýÌåÎüÊÕÆ÷ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35795

Windows   ¹ýʧ±¨¸æÐ§ÀÍÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35797

Windows   Hello Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2022-35748

HTTP.sys   ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-35756

Windows   Kerberos ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35761

Windows   ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35768

Windows   ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-34708

Windows   ÄÚºËÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-34707

Windows   ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35804

SMB   ¿Í»§¶ËºÍЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-30197

Windows   ÄÚºËÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-35758

Windows   ÄÚºËÄÚ´æÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-34706

Windows   ÍâµØÇå¾²»ú¹¹ (LSA) ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35759

Windows   ÍâµØÇå¾²»ú¹¹ (LSA) ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-34715

Windows   ÍøÂçÎļþϵͳԶ³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-33670

Windows   ·ÖÇøÖÎÀíÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-34703

Windows   ·ÖÇøÖÎÀíÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-30133

Windows   µã¶ÔµãЭÒé (PPP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-35747

Windows   µã¶ÔµãЭÒé (PPP) ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-35744

Windows   µã¶ÔµãЭÒé (PPP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-35793

Windows   ºǫ́´òÓ¡³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35755

Windows   ºǫ́´òÓ¡³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-34301

CERT/CC£ºCVE-2022-34301 Eurosoft Ö¸µ¼¼ÓÔØ³ÌÐòÈÆ¹ý

¸ßΣ

CVE-2022-34302

CERT/CC£ºCVE-2022-34302 New Horizon   Data Systems Inc Ö¸µ¼¼ÓÔØ³ÌÐòÈÆ¹ý

¸ßΣ

CVE-2022-34303

CERT/CC£ºCVE-20220-34303 Crypto Pro Ö¸µ¼¼ÓÔØ³ÌÐòÈÆ¹ý

¸ßΣ

CVE-2022-35745

Windows   SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-35766

Windows   SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-35794

Windows   SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-34701

Windows   SSTP¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-34714

Windows   SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-34702

Windows   SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-35767

Windows   SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-35762

´æ´¢¿Õ¼äÖ±½ÓÌáÉýÌØÈ¨Îó²î

¸ßΣ

CVE-2022-35765

´æ´¢¿Õ¼äÖ±½ÓÌáÉýÌØÈ¨Îó²î

¸ßΣ

CVE-2022-35792

´æ´¢¿Õ¼äÖ±½ÓÌáÉýÌØÈ¨Îó²î

¸ßΣ

CVE-2022-35763

´æ´¢¿Õ¼äÖ±½ÓÌáÉýÌØÈ¨Îó²î

¸ßΣ

CVE-2022-35764

´æ´¢¿Õ¼äÖ±½ÓÌáÉýÌØÈ¨Îó²î

¸ßΣ

CVE-2022-35754

ͳһдÈë¹ýÂËÆ÷ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-30194

Windows   WebBrowser ¿ØÖÆÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-34699

Windows   Win32k ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35796

Microsoft   Edge£¨»ùÓÚ Chromium£©ÌØÈ¨ÌáÉýÎó²î

µÍΣ

CVE-2022-33649

Microsoft   Edge£¨»ùÓÚ Chromium£©Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2022-33636

Microsoft   Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÖÐΣ

CVE-2022-2618

Chromium£ºCVE-2022-2618 ÄÚ²¿½á¹¹Öв»ÊÜÐÅÈεÄÊäÈëÑé֤ȱ·¦

δ֪

CVE-2022-2616

Chromium£ºCVE-2022-2616 Extensions API ÖеIJ»µ±ÊµÏÖ

δ֪

CVE-2022-2617

Chromium£ºCVE-2022-2617 ÔÚ Extensions API ÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-2619

Chromium£ºCVE-2022-2619 ÉèÖÃÖв»ÊÜÐÅÈεÄÊäÈëÑé֤ȱ·¦

δ֪

CVE-2022-2622

Chromium£ºCVE-2022-2622 ¶ÔÇå¾²ä¯ÀÀÖв»ÊÜÐÅÈεÄÊäÈëµÄÑé֤ȱ·¦

δ֪

CVE-2022-2623

Chromium£ºCVE-2022-2623 ÔÚÀëÏߺóÃâ·ÑʹÓÃ

δ֪

CVE-2022-2621

Chromium£ºCVE-2022-2621 ÔÚÀ©Õ¹ÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-2615

Chromium£ºCVE-2022-2615 Cookie ÖеÄÕ½ÂÔÖ´ÐÐȱ·¦

δ֪

CVE-2022-2604

Chromium£ºCVE-2022-2604 ÔÚÇå¾²ä¯ÀÀÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-2605

Chromium£ºCVE-2022-2605 ÔÚ Dawn ÖжÁȡԽ½ç

δ֪

CVE-2022-2624

Chromium£ºCVE-2022-2624 PDF ÖеĶѻº³åÇøÒç³ö

δ֪

CVE-2022-2603

Chromium£ºCVE-2022-2603 Ôڶ๦Ч¿òÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-2606

Chromium£ºCVE-2022-2606 ÔÚÍйÜ×°±¸ API ÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-2612

Chromium£ºCVE-2022-2612 ¼üÅÌÊäÈëÖеIJàͨµÀÐÅÏ¢×ß©

δ֪

CVE-2022-2614

Chromium£ºCVE-2022-2614 ÔڵǼÁ÷³ÌÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-2610

Chromium£ºCVE-2022-2610 ºǫ́ÌáÈ¡ÖеÄÕ½ÂÔÖ´ÐÐȱ·¦

δ֪

CVE-2022-2611

Chromium£ºCVE-2022-2611 È«ÆÁ API ÖеIJ»Êʵ±ÊµÏÖ

δ֪


0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬ £¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£¡£¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬ £¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬ £¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£¡£

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬ £¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬ £¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬ £¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬ £¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£¡£

4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬£¬£¬£¬ £¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬ £¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬ £¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬ £¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£¡£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£¡£

8ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2022-Aug

²¹¶¡ÏÂÔØÊ¾Àý£º

1.·­¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬ £¬£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£¡£¡£¡£¡£¡£

image.png

Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬ £¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·­¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£¡£¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Çå¾²¸üС¿£¬£¬£¬£¬ £¬£¬·­¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬ £¬£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öᣡ£¡£¡£¡£¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2022-Aug

https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2022-patch-tuesday-fixes-exploited-zero-day-121-flaws/

https://blog.qualys.com/vulnerabilities-threat-research/2022/08/09/august-2022-patch-tuesday

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-08-10

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬ £¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬ £¬£¬¹«Ë¾Ô±¹¤½ü4000ÈË£¬£¬£¬£¬ £¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬ £¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬£¬£¬ £¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬ £¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬ £¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£

 

¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬ £¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png