¡¾Îó²îͨ¸æ¡¿Î¢Èí8Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2022-08-100x00 Îó²î¸ÅÊö
2022Äê8ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬Î¢ÈíÐû²¼ÁË8ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÐÞ¸´Á˰üÀ¨2¸ö0 dayÎó²îÔÚÄÚµÄ121¸öÇå¾²Îó²î£¨²»°üÀ¨20¸öMicrosoft EdgeÎó²î£©£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ17¸öÎó²îÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé
±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÉæ¼°Active Directory Domain Services¡¢Azure ¡¢Microsoft Exchange Server¡¢Microsoft Office¡¢Microsoft MSDT¡¢Windows Kerberos¡¢Windows Kernel¡¢Windows Internet Information Services¡¢Windows Network File System¡¢Windows Secure Socket Tunneling Protocol (SSTP)ºÍWindows Win32KµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£¡£¡£
±¾´ÎÐÞ¸´µÄ121¸öÎó²îÖУ¬£¬£¬£¬£¬£¬64¸öΪÌáÈ¡Îó²î£¬£¬£¬£¬£¬£¬31¸öΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬12¸öΪÐÅϢй¶Îó²î£¬£¬£¬£¬£¬£¬7¸öΪ¾Ü¾øÐ§ÀÍÎó²î£¬£¬£¬£¬£¬£¬6¸öΪÇå¾²¹¦Ð§ÈƹýÎó²î£¬£¬£¬£¬£¬£¬ÒÔ¼°1¸öÓÕÆÎó²î¡£¡£¡£¡£¡£¡£
΢Èí±¾´Î¹²ÐÞ¸´ÁË2¸ö0 dayÎó²î£¬£¬£¬£¬£¬£¬ÆäÖÐCVE-2022-34713£¨DogWalkÎó²î£©ÒÑ·¢Ã÷±»Æð¾¢Ê¹Óãº
CVE-2022-34713£ºMicrosoft MSDTÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îλÓÚMicrosoft Windows Ö§³ÖÕï¶Ï¹¤¾ß (MSDT) ÖУ¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬¹¥»÷ÖØÆ¯ºóµÍÇÒÎÞÐèÌØÊâȨÏÞ£¬£¬£¬£¬£¬£¬µ«ÐèÓëÓû§½»»¥²Å»ªÍâµØÊ¹Óᣡ£¡£¡£¡£¡£¸ÃÎó²îÏÖÔÚÒѾ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬ÇÒÒѾ¼ì²âµ½Îó²îʹÓᣡ£¡£¡£¡£¡£
CVE-2022-30134 £ºMicrosoft Exchange ÐÅϢй¶Îó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.6£¬£¬£¬£¬£¬£¬¹¥»÷ÖØÆ¯ºóºÍËùÐèȨÏ޵ͣ¬£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥¼´¿ÉÔ¶³ÌʹÓ㬣¬£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÒÔ¶ÁȡĿµÄµç×ÓÓʼþ¡£¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃÎó²îÒѾ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬Î¢ÈíÒѾÐû²¼Á˸ÃÎó²îµÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬µ«ÊÜÓ°ÏìÓû§»¹ÐèÆôÓÃExchange ServerµÄWindows À©Õ¹±£»£»£»£»¤ÒÔ·À»¤´ËÎó²î¡£¡£¡£¡£¡£¡£
±¾´ÎÐÞ¸´µÄÎó²îÖУ¬£¬£¬£¬£¬£¬ÆÀ¼¶ÎªÑÏÖØµÄ17¸öÎó²î°üÀ¨£º
l CVE-2022-34691£ºActive Directory ÓòЧÀÍÌØÈ¨ÌáÉýÎó²î£º¾ÓÉÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔʹÓÃÆäÓµÓлòÖÎÀíµÄÅÌËã»úÕÊ»§µÄÊôÐÔ£¬£¬£¬£¬£¬£¬²¢´Ó Active Directory Ö¤ÊéЧÀÍ»ñȡ֤Ê飬£¬£¬£¬£¬£¬´Ó¶øÔÊÐíÌáÉýϵͳȨÏÞ¡£¡£¡£¡£¡£¡£Ö»Óе± Active Directory Ö¤ÊéЧÀÍÔÚÓòÉÏÔËÐÐʱ£¬£¬£¬£¬£¬£¬ÏµÍ³²ÅÈÝÒ×Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£
l CVE-2022-33646£ºAzure Batch ½ÚµãÊðÀíÌØÈ¨ÌáÉýÎó²î
l CVE-2022-21980£ºMicrosoft Exchange Server ÌØÈ¨ÌáÉýÎó²î
l CVE-2022-24516£ºMicrosoft Exchange Server ÌØÈ¨ÌáÉýÎó²î
l CVE-2022-24477£ºMicrosoft Exchange Server ÌØÈ¨ÌáÉýÎó²î
l CVE-2022-35752£ºWindows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î
l CVE-2022-35753£ºWindows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î
l CVE-2022-34696£ºWindows Hyper-V Ô¶³Ì´úÂëÖ´ÐÐÎó²î
l CVE-2022-35804£ºSMB ¿Í»§¶ËºÍЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î
l CVE-2022-30133£ºWindows µã¶ÔµãÐÒé (PPP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î
l CVE-2022-35744£ºWindows µã¶ÔµãÐÒé (PPP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î£ºÖ»ÄÜͨ¹ý¶Ë¿Ú 1723 ͨѶÀ´Ê¹ÓÃCVE-2022-30133ºÍCVE-2022-35744£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý½ûÓÃ¶Ë¿Ú 1723×÷ΪÔÝʱ»º½â²½·¥£¬£¬£¬£¬£¬£¬µ«Õâ¿ÉÄÜ»áÓ°ÏìÍøÂçÉϵÄͨѶ¡£¡£¡£¡£¡£¡£
l CVE-2022-35745£ºWindows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î
l CVE-2022-35766£ºWindows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î
l CVE-2022-35794£ºWindows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î£ºÀÖ³ÉʹÓôËÎó²îÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚδ¾Éí·ÝÑéÖ¤µÄÇéÐÎÏÂÏò RAS ЧÀÍÆ÷·¢ËÍÌØÖÆµÄÅþÁ¬ÇëÇ󣬣¬£¬£¬£¬£¬Õâ¿ÉÄܵ¼Ö RAS ЧÀÍÆ÷ÅÌËã»úÉϵÄÔ¶³Ì´úÂëÖ´ÐÐ (RCE)¡£¡£¡£¡£¡£¡£
l CVE-2022-34714£ºWindows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î
l CVE-2022-34702£ºWindows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î
l CVE-2022-35767£ºWindows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î
΢Èí8Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º
CVE ID | CVE ÎÊÌâ | ÑÏÖØÐÔ |
CVE-2022-34716 | .NET ÓÕÆÎó²î | ¸ßΣ |
CVE-2022-34691 | Active Directory ÓòЧÀÍÌØÈ¨ÌáÉýÎó²î | ÑÏÖØ |
CVE-2022-33646 | Azure Batch ½ÚµãÊðÀíÌØÈ¨ÌáÉýÎó²î | ÑÏÖØ |
CVE-2022-34685 | Azure RTOS GUIX Studio ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-34686 | Azure RTOS GUIX Studio ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-35773 | Azure RTOS GUIX Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35779 | Azure RTOS GUIX Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35806 | Azure RTOS GUIX Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-34687 | Azure RTOS GUIX Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-30176 | Azure RTOS GUIX Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-30175 | Azure RTOS GUIX Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35791 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35818 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35809 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35789 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35815 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35817 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35816 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35814 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35785 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35812 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35811 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35784 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35810 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35813 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35788 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35783 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35786 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35787 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35819 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35781 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35775 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35790 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35780 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35799 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35772 | Azure Site Recovery Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35800 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35774 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35802 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35782 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35824 | Azure Site Recovery Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35801 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35808 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35776 | Azure Site Recovery ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2022-35807 | Azure Site Recovery ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35821 | Azure Sphere ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-35760 | Microsoft ATA ¶Ë¿ÚÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35820 | Windows À¶ÑÀÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-34692 | Microsoft Exchange ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-21980 | Microsoft Exchange Server ÌØÈ¨ÌáÉýÎó²î | ÑÏÖØ |
CVE-2022-21979 | Microsoft Exchange ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-24516 | Microsoft Exchange Server ÌØÈ¨ÌáÉýÎó²î | ÑÏÖØ |
CVE-2022-30134 | Microsoft Exchange ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-24477 | Microsoft Exchange Server ÌØÈ¨ÌáÉýÎó²î | ÑÏÖØ |
CVE-2022-34717 | Microsoft Office Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-33648 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-33631 | Microsoft Excel Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2022-35742 | Microsoft Outlook ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2022-34713 | Microsoft Windows Ö§³ÖÕï¶Ï¹¤¾ß (MSDT) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35743 | Microsoft Windows Ö§³ÖÕï¶Ï¹¤¾ß (MSDT) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35752 | Windows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2022-35753 | Windows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2022-35769 | Windows µã¶ÔµãÐÒé (PPP) ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2022-34690 | Windows ´«ÕæÐ§ÀÍÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-34696 | Windows Hyper-V Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2022-35751 | Windows Hyper-V ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-33640 | System Center Operations Manager£º¿ª·ÅʽÖÎÀí»ù´¡¼Ü¹¹ (OMI) ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35827 | Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35777 | Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35825 | Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35826 | Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-30144 | WindowsÀ¶ÑÀЧÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35750 | Win32k ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35757 | Windows Cloud Files Mini Filter Çý¶¯³ÌÐòÌáȨÎó²î | ¸ßΣ |
CVE-2022-35771 | Windows Defender Credential Guard ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-34705 | Windows Defender Credential Guard ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-34710 | Windows Defender Credential Guard ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-34709 | Windows Defender Credential Guard Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2022-34704 | Windows Defender Credential Guard ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-34712 | Windows Defender Credential Guard ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-35746 | Windows Êý×ÖýÌåÎüÊÕÆ÷ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35749 | Windows Êý×ÖýÌåÎüÊÕÆ÷ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35795 | Windows ¹ýʧ±¨¸æÐ§ÀÍÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35797 | Windows Hello Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2022-35748 | HTTP.sys ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2022-35756 | Windows Kerberos ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35761 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35768 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-34708 | Windows ÄÚºËÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-34707 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35804 | SMB ¿Í»§¶ËºÍЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2022-30197 | Windows ÄÚºËÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-35758 | Windows ÄÚºËÄÚ´æÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-34706 | Windows ÍâµØÇå¾²»ú¹¹ (LSA) ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35759 | Windows ÍâµØÇå¾²»ú¹¹ (LSA) ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2022-34715 | Windows ÍøÂçÎļþϵͳԶ³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-33670 | Windows ·ÖÇøÖÎÀíÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-34703 | Windows ·ÖÇøÖÎÀíÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-30133 | Windows µã¶ÔµãÐÒé (PPP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2022-35747 | Windows µã¶ÔµãÐÒé (PPP) ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2022-35744 | Windows µã¶ÔµãÐÒé (PPP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2022-35793 | Windows ºǫ́´òÓ¡³ÌÐòÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35755 | Windows ºǫ́´òÓ¡³ÌÐòÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-34301 | CERT/CC£ºCVE-2022-34301 Eurosoft Ö¸µ¼¼ÓÔØ³ÌÐòÈÆ¹ý | ¸ßΣ |
CVE-2022-34302 | CERT/CC£ºCVE-2022-34302 New Horizon Data Systems Inc Ö¸µ¼¼ÓÔØ³ÌÐòÈÆ¹ý | ¸ßΣ |
CVE-2022-34303 | CERT/CC£ºCVE-20220-34303 Crypto Pro Ö¸µ¼¼ÓÔØ³ÌÐòÈÆ¹ý | ¸ßΣ |
CVE-2022-35745 | Windows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2022-35766 | Windows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2022-35794 | Windows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2022-34701 | Windows SSTP¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2022-34714 | Windows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2022-34702 | Windows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2022-35767 | Windows SSTPÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2022-35762 | ´æ´¢¿Õ¼äÖ±½ÓÌáÉýÌØÈ¨Îó²î | ¸ßΣ |
CVE-2022-35765 | ´æ´¢¿Õ¼äÖ±½ÓÌáÉýÌØÈ¨Îó²î | ¸ßΣ |
CVE-2022-35792 | ´æ´¢¿Õ¼äÖ±½ÓÌáÉýÌØÈ¨Îó²î | ¸ßΣ |
CVE-2022-35763 | ´æ´¢¿Õ¼äÖ±½ÓÌáÉýÌØÈ¨Îó²î | ¸ßΣ |
CVE-2022-35764 | ´æ´¢¿Õ¼äÖ±½ÓÌáÉýÌØÈ¨Îó²î | ¸ßΣ |
CVE-2022-35754 | ͳһдÈë¹ýÂËÆ÷ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-30194 | Windows WebBrowser ¿ØÖÆÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-34699 | Windows Win32k ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35796 | Microsoft Edge£¨»ùÓÚ Chromium£©ÌØÈ¨ÌáÉýÎó²î | µÍΣ |
CVE-2022-33649 | Microsoft Edge£¨»ùÓÚ Chromium£©Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2022-33636 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÖÐΣ |
CVE-2022-2618 | Chromium£ºCVE-2022-2618 ÄÚ²¿½á¹¹Öв»ÊÜÐÅÈεÄÊäÈëÑé֤ȱ·¦ | δ֪ |
CVE-2022-2616 | Chromium£ºCVE-2022-2616 Extensions API ÖеIJ»µ±ÊµÏÖ | δ֪ |
CVE-2022-2617 | Chromium£ºCVE-2022-2617 ÔÚ Extensions API ÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-2619 | Chromium£ºCVE-2022-2619 ÉèÖÃÖв»ÊÜÐÅÈεÄÊäÈëÑé֤ȱ·¦ | δ֪ |
CVE-2022-2622 | Chromium£ºCVE-2022-2622 ¶ÔÇå¾²ä¯ÀÀÖв»ÊÜÐÅÈεÄÊäÈëµÄÑé֤ȱ·¦ | δ֪ |
CVE-2022-2623 | Chromium£ºCVE-2022-2623 ÔÚÀëÏߺóÃâ·ÑʹÓà | δ֪ |
CVE-2022-2621 | Chromium£ºCVE-2022-2621 ÔÚÀ©Õ¹ÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-2615 | Chromium£ºCVE-2022-2615 Cookie ÖеÄÕ½ÂÔÖ´ÐÐȱ·¦ | δ֪ |
CVE-2022-2604 | Chromium£ºCVE-2022-2604 ÔÚÇå¾²ä¯ÀÀÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-2605 | Chromium£ºCVE-2022-2605 ÔÚ Dawn ÖжÁȡԽ½ç | δ֪ |
CVE-2022-2624 | Chromium£ºCVE-2022-2624 PDF ÖеĶѻº³åÇøÒç³ö | δ֪ |
CVE-2022-2603 | Chromium£ºCVE-2022-2603 Ôڶ๦Ч¿òÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-2606 | Chromium£ºCVE-2022-2606 ÔÚÍйÜ×°±¸ API ÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-2612 | Chromium£ºCVE-2022-2612 ¼üÅÌÊäÈëÖеIJàͨµÀÐÅÏ¢×ß© | δ֪ |
CVE-2022-2614 | Chromium£ºCVE-2022-2614 ÔڵǼÁ÷³ÌÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-2610 | Chromium£ºCVE-2022-2610 ºǫ́ÌáÈ¡ÖеÄÕ½ÂÔÖ´ÐÐȱ·¦ | δ֪ |
CVE-2022-2611 | Chromium£ºCVE-2022-2611 È«ÆÁ API ÖеIJ»Êʵ±ÊµÏÖ | δ֪ |
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£¡£¡£
£¨Ò»£© Windows update¸üÐÂ
×Ô¶¯¸üУº
Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£¡£
ÊÖ¶¯¸üУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£¡£
4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£¡£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£¡£
8ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2022-Aug
²¹¶¡ÏÂÔØÊ¾Àý£º
1.·¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬£¬£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£¡£¡£¡£¡£¡£
Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£¡£¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾Çå¾²¸üС¿£¬£¬£¬£¬£¬£¬·¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬£¬£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öᣡ£¡£¡£¡£¡£
Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£¡£¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2022-Aug
https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2022-patch-tuesday-fixes-exploited-zero-day-121-flaws/
https://blog.qualys.com/vulnerabilities-threat-research/2022/08/09/august-2022-patch-tuesday
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2022-08-10 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
¼øºÚµ£±£Íø¼ò½é
¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤½ü4000ÈË£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£
¹ØÓÚ¼øºÚµ£±£Íø
¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£¡£
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º