¡¾Îó²îͨ¸æ¡¿Î¢Èí9Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2022-09-14


0x00 Îó²î¸ÅÊö

2022Äê9ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬Î¢ÈíÐû²¼ÁË9ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬£¬±¾´Î¸üÐÂÐÞ¸´Á˰üÀ¨2¸ö0 dayÎó²îÔÚÄÚµÄ63¸öÇå¾²Îó²î£¨²»°üÀ¨Ö®Ç°ÐÞ¸´µÄ16¸öMicrosoft  EdgeÎó²î£©£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ5¸öÎó²îÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÉæ¼°.NET Framework¡¢HTTP.sys¡¢Microsoft Office¡¢Microsoft Dynamics¡¢Windows Defender¡¢Windows Group Policy¡¢Windows IKE Extension¡¢Windows Kerberos¡¢Windows Kernel¡¢Windows LDAP¡¢Windows Print Spooler Components¡¢Windows Remote Access Connection Manager¡¢Windows Remote Procedure CallºÍWindows TCP/IPµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£

±¾´ÎÐÞ¸´µÄ63¸öÎó²îÖУ¬£¬£¬£¬£¬£¬18¸öΪÌáÈ¡Îó²î£¬£¬£¬£¬£¬£¬30¸öΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬7¸öΪÐÅϢй¶Îó²î£¬£¬£¬£¬£¬£¬7¸öΪ¾Ü¾øÐ§ÀÍÎó²î£¬£¬£¬£¬£¬£¬1¸öΪÇå¾²¹¦Ð§ÈƹýÎó²î¡£¡£¡£¡£

΢Èí±¾´Î¹²ÐÞ¸´ÁË2¸ö0 dayÎó²î£¬£¬£¬£¬£¬£¬ÆäÖÐCVE-2022-37969ÒÑ·¢Ã÷±»Æð¾¢Ê¹Óãº

CVE-2022-37969 £ºWindows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Windows Common Log File System Driver±£´æÍâµØÌáȨÎó²î£¬£¬£¬£¬£¬£¬´ËÎó²îµÄCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬¿ÉÔÚÓÐȨ»á¼ûÄ¿µÄϵͳ²¢Äܹ»ÔÚÄ¿µÄϵͳÉÏÔËÐдúÂëµÄÇéÐÎÏÂʹÓôËÎó²î»ñµÃϵͳȨÏÞ¡£¡£¡£¡£´ËÎó²îÒѾ­¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬ÇÒÒÑ·¢Ã÷Îó²îʹÓᣡ£¡£¡£

CVE-2022-23960£º»º´æÍƲâÏÞÖÆÎó²î£¨Arm£©

ijЩ Arm Cortex ºÍ Neoverse ´¦Öóͷ£Æ÷²»»á׼ȷÏÞÖÆ»º´æÍƲ⣬£¬£¬£¬£¬£¬¼´ Spectre-BHB£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¡£´ËÎó²îÓ°ÏìÁË»ùÓÚARM64ϵͳµÄWindows 11£¬£¬£¬£¬£¬£¬ÏÖÔÚÒѾ­¹ûÕæÅû¶¡£¡£¡£¡£

±¾´Î¸üÐÂÖÐÖµµÃ¹Ø×¢µÄÎó²î°üÀ¨µ«²»ÏÞÓÚ£º

CVE-2022-34718 £ºWindows TCP/IP Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¿ÉÔÚδ¾­Éí·ÝÑéÖ¤µÄÇéÐÎϽ«ÌØÖƵÄIPv6Êý¾Ý°ü·¢Ë͵½ÆôÓÃÁË IPSec µÄ Windows ½Úµã£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜ»áÔÚ¸ÃÅÌËã»úÉϵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£Ö»ÓÐÔËÐÐ IPSec ЧÀ͵Äϵͳ²ÅÈÝÒ×Êܵ½¹¥»÷£¬£¬£¬£¬£¬£¬ÈôÊÇÔÚÄ¿µÄ»úеÉϽûÓÃÁË IPv6£¬£¬£¬£¬£¬£¬Ôòϵͳ²»»áÊܵ½Ó°Ïì¡£¡£¡£¡£´ËÎó²îµÄCVSSv3ÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬¹¥»÷ÖØÆ¯ºóµÍ£¬£¬£¬£¬£¬£¬ÎÞÐèÌØÊâȨÏÞºÍÓû§½»»¥¼´¿ÉÔ¶³ÌʹÓôËÎó²î£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°¿ÉÄܱ»Ê¹Óᱡ£¡£¡£¡£

CVE-2022-34721¡¢CVE-2022-34722 £ºWindows Internet Key Exchange (IKE) Protocol ExtensionsÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Õâ2¸öÎó²îµÄCVSSv3ÆÀ·Ö¾ùΪ9.8£¬£¬£¬£¬£¬£¬¿ÉÔÚδ¾­Éí·ÝÑéÖ¤µÄÇéÐÎϽ«ÌØÖƵÄIP Êý¾Ý°ü·¢Ë͵½ÔËÐÐ Windows ²¢ÆôÓÃÁË IPSec µÄÄ¿µÄÅÌËã»ú£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£´ËÎó²î½öÓ°Ïì IKEv1£¬£¬£¬£¬£¬£¬IKEv2 ²»ÊÜÓ°Ï죬£¬£¬£¬£¬£¬µ«´ËÎó²îÓ°ÏìÁËËùÓÐWindows Server£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÃÇͬʱ½ÓÊÜ V1 ºÍ V2 Êý¾Ý°ü¡£¡£¡£¡£

CVE-2022-35805¡¢CVE-2022-34700£ºMicrosoft Dynamics CRM (on-premises)Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔÔËÐÐÌØÖÆµÄÊÜÐÅÈνâ¾ö¼Æ»®°üÀ´Ö´ÐÐí§Òâ SQL ÏÂÁ£¬£¬£¬£¬£¬¿ÉÒÔʵÏÖÉý¼¶²¢ÔÚÆä Dynamics 365 Êý¾Ý¿âÖÐÒÔ db_owner Éí·ÝÖ´ÐÐÏÂÁ£¬£¬£¬£¬£¬Õâ2¸öÎó²îµÄCVSSv3ÆÀ·Ö¾ùΪ8.8¡£¡£¡£¡£

CVE-2022-38009£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

´ËÎó²îµÄCVSSv3ÆÀ·ÖΪ8.8£¬£¬£¬£¬£¬£¬¹¥»÷ÖØÆ¯ºóºÍËùÐèȨÏ޵ͣ¬£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥¼´¿ÉÔ¶³ÌʹÓ㬣¬£¬£¬£¬£¬µ«Ê¹ÓôËÎó²î±ØÐèͨ¹ýÄ¿µÄÍøÕ¾µÄÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬²¢ÓÐȨÔÚ SharePoint ÖÐʹÓÃÖÎÀíÁбí£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÒÔÔÚSharePoint Server ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£

CVE-2022-26929£º.NET Framework Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬Ê¹ÓôËÎó²îÐèÓëÓû§½»»¥¡£¡£¡£¡£

΢Èí9Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE ID

CVE ÎÊÌâ

ÑÏÖØÐÔ

CVE-2022-35805

Microsoft Dynamics CRM£¨ÍâµØ£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-34700

Microsoft Dynamics CRM£¨ÍâµØ£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-34722

Windows Internet ÃÜÔ¿½»Á÷ (IKE) ЭÒéÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-34721

Windows Internet ÃÜÔ¿½»Á÷ (IKE) ЭÒéÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-34718

Windows TCP/IP Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-38013

.NET Core ºÍ Visual Studio ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-26929

.NET Framework Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-38007

Azure À´±öÉèÖÃºÍÆôÓà Azure Arc µÄЧÀÍÆ÷ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-23960

Arm£ºCVE-2022-23960 »º´æÍƲâÏÞÖÆÎó²î

¸ßΣ

CVE-2022-35838

HTTP V3 ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-37954

DirectX ͼÐÎÄÚºËÌáȨÎó²î

¸ßΣ

CVE-2022-38006

Windows ͼÐÎ×é¼þÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-34729

Windows GDI ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-34728

Windows ͼÐÎ×é¼þÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-35837

Windows ͼÐÎ×é¼þÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-37962

Microsoft PowerPoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35823

Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-38009

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-38008

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-37961

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-37963

Microsoft Office Visio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-38010

Microsoft Office Visio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-34725

Windows ALPC ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-38011

Raw Image Extension Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-38019

AV1 Video ExtensionÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-37959

ÍøÂç×°±¸×¢²áЧÀÍ (NDES) Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2022-34724

Windows DNS ЧÀÍÆ÷¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-38004

Windows ´«ÕæÐ§ÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-37958

SPNEGO À©Õ¹Ð­ÉÌ (NEGOEX) Çå¾²»úÖÆÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-38020

Visual Studio Code ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35803

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-37969

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-30170

Windows ƾ֤ÖÜÓÎЧÀÍÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35828

Microsoft Defender for Endpoint for Mac ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-34719

Windows ÂþÑÜʽÎļþϵͳ (DFS) ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-34723

Windows DPAPI£¨Êý¾Ý±£»£»£»£»£»¤Ó¦ÓóÌÐò±à³Ì½Ó¿Ú£©ÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-35841

WindowsÆóÒµÓ¦ÓÃÖÎÀíЧÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35832

Windows ÊÂÎñ¸ú×پܾøÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-37955

Windows ×éÕ½ÂÔÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-34720

Windows Internet ÃÜÔ¿½»Á÷ (IKE) À©Õ¹¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-33647

Windows Kerberos ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-33679

Windows Kerberos ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-37964

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-37956

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-37957

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-30200

Windows ÇáÁ¿¼¶Ä¿Â¼»á¼ûЭÒé (LDAP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-34726

Microsoft ODBC Çý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-34730

Microsoft ODBC Çý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-34727

Microsoft ODBC Çý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-34732

Microsoft ODBC Çý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-34734

Microsoft ODBC Çý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35834

Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35835

Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35836

Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35840

Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-34733

Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-34731

Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-26928

Windows ÕÕÆ¬µ¼Èë API ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-38005

Windows Print SpoolerÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-35831

Windows Ô¶³Ì»á¼ûÅþÁ¬ÖÎÀíÆ÷ÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-35830

Remote Procedure Call Runtime Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-35833

Windows Ç徲ͨµÀ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-30196

Windows Ç徲ͨµÀ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-3053

Chromium£ºCVE-2022-3053 Ö¸ÕëËøÖеIJ»µ±ÊµÏÖ

δ֪

CVE-2022-3047

Chromium£ºCVE-2022-3047 À©Õ¹ API ÖеÄÕ½ÂÔÖ´ÐÐȱ·¦

δ֪

CVE-2022-3054

Chromium£ºCVE-2022-3054 DevTools ÖеÄÕ½ÂÔÖ´ÐÐȱ·¦

δ֪

CVE-2022-3041

Chromium£ºCVE-2022-3041 ÔÚ WebSQL ÖÐÊͷźóʹÓÃ

δ֪

CVE-2022-3040

Chromium£ºCVE-2022-3040 ÔڽṹÖÐÊͷźóʹÓÃ

δ֪

CVE-2022-3046

Chromium£ºCVE-2022-3046 ÔÚä¯ÀÀÆ÷±êÇ©ÖÐÊͷźóʹÓÃ

δ֪

CVE-2022-3039

Chromium£ºCVE-2022-3039 ÔÚ WebSQL ÖÐÊͷźóʹÓÃ

δ֪

CVE-2022-3045

Chromium£ºCVE-2022-3045 V8 Öв»ÊÜÐÅÈεÄÊäÈëÑé֤ȱ·¦

δ֪

CVE-2022-3044

Chromium£ºCVE-2022-3044 Õ¾µã¸ôÀëÖеIJ»µ±ÊµÑé

δ֪

CVE-2022-3057

Chromium£ºCVE-2022-3057 iframe ɳºÐÖеIJ»µ±ÊµÑé

δ֪

CVE-2022-3075

Chromium£ºCVE-2022-3075 Mojo ÖеÄÊý¾ÝÑé֤ȱ·¦

δ֪

CVE-2022-3058

Chromium£ºCVE-2022-3058 ÔڵǼÁ÷³ÌÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-3038

Chromium£ºCVE-2022-3038 ÔÚÍøÂçЧÀÍÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-3056

Chromium£ºCVE-2022-3056 ÄÚÈÝÇå¾²Õ½ÂÔÖеÄÕ½ÂÔÖ´ÐÐȱ·¦

δ֪

CVE-2022-3055

Chromium£ºCVE-2022-3055 ÔÚÃÜÂëÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-38012

Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î

µÍΣ

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£

4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£

9ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2022-Sep

²¹¶¡ÏÂÔØÊ¾Àý£º

1.·­¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬£¬£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£¡£¡£¡£

image.png

Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·­¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Çå¾²¸üС¿£¬£¬£¬£¬£¬£¬·­¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬£¬£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öᣡ£¡£¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2022-Sep

https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2022-patch-tuesday-fixes-zero-day-used-in-attacks-63-flaws/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-09-14

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤½ü4000ÈË£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£

 

¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png