Éî¶È·Ö½â΢Èí×îзì϶£¬ÎªÄúÌṩ×îÓŽâ¾ö¹æ»®
°ä²¼¹¦·ò 2022-04-21½üÆÚ£¬Î¢Èí°ä²¼ÁË4Ô·ݵݲȫ¸üУ¬½¨¸´ÁËÔ̺¬2¸ö0day·ì϶ÔÚÄÚµÄ119¸ö°²È«·ì϶£¨²»Ô̺¬26¸öMicrosoftEdge·ì϶£©£¬ÆäÖÐÓÐ10¸ö·ì϶±»ÆÀ¼¶ÎªÑϳÁ£¬Éæ¼°.NET Framework¡¢ActiveDirectoryDomainServicesµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡££¨·ì϶ÏêÇéÔÚÎÄÄ©£©
GA»Æ½ð¼×±±Ú¤Êý¾Ý³¢ÊÔסլһ¹¦·ò¶Ô΢Èí4Ô°䲼µÄ°²È«²¼¸æ½øÐзÖÎöÑÐÅУ¬½áºÏÌ©ºÏÅÌ¹ÅÆ½Ì¨£¨THPangu-OS£©µÄµ××ùÄÜÁ¦£¬Îª¿í´óÓû§¸ø³öÓ¦¼±´ëÖÃÖ¸Òý¹æ»®¡£
ÒòÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2022-26809Íþвˮƽ¸ß¡¢Ó°ÏìÁìÓò½Ï¹ã£¬ÀûÓõĸ´ÔӶȵͣ¬Ò×±»¹¥»÷Õß¿í·ºÀûÓýø¶ø¶Ô¿í´óÓû§Ôì³ÉÑϳÁ·çÏÕ£¬ËùÒÔÎÒÃÇÒÔ´Ë·ìÏ¶Éæ¼°µÄ·þÎñΪÀý£¬×ö³öÁ˽øÒ»²½µÄÏêϸ·ÖÎö¹ý³Ì£¬²¢¾ßÌå×¢Ã÷·ì϶½¨¸´Óë²¹¶¡ÏÂÔØ¡£
·ì϶·ÖÎö
Óйطì϶λÓÚWindowsRPC·þÎñ£¬¸Ã·þÎñÓÉÃûΪrpcrt4.dllµÄ¿â¡£¸ÃÔËÐÐʱ¿â±»¼ÓÔØµ½Ê¹ÓÃRPCºÍ̸½øÐÐͨѶµÄ¿Í»§¶ËºÍ·þÎñÆ÷¹ý³ÌÖС£
ͨ¹ý±ÈÁ¦ÁË10.0.22000.434£¨Î´´ò²¹¶¡£¬´Ó2022Äê3ÔÂÆðÍ·£©ºÍ10.0.22000.613£¨ÒÑ´ò²¹¶¡£¬´Ó2022Äê4ÔÂÆðÍ·£©°æ±¾£¬ÄÜ·¢ÏÖÒÔϸ÷ÀàÖ°ÄÜ»òº¯ÊýµÄ±ä¶¯Çåµ¥¡£

º¯Êý±ä¶¯Çåµ¥
º¯ÊýOSF_CCALL::ProcessResponseºÍOSF_SCALL::ProcessReceivedPDU¡£ÕâÁ½¸öº¯ÊýÐÔÖÊÉÏÊÇÀàËÆµÄ£»Á½Õß¶¼´¦ÖÃRPCÊý¾Ý°ü£¬µ«Ò»¸öÔÚ¿Í»§¶ËÔËÐУ¬ÁíÒ»¸öÔÚ·þÎñÆ÷¶ËÔËÐУ¨CCALLºÍSCALL±ðÀë´ú±í¿Í»§¶ËŲÓúͷþÎñÆ÷ŲÓã©¡£ÎÒÃdzÖÐø±ÈÁ¦OSF_SCALL::ProcessReceivedPDU£¬²¢°ÑÎȵ½Ð°汾ÖÐÔö³¤ÁËÁ½¸ö´úÂë¿é¡£


¶Ô±ÈÐÂÔö´úÂë¿é
²é¿´½¨¸´´úÂ룬ÎÒÃÇ¿´µ½ÔÚQUEUE::PutOnQueueÖ®ºóŲÓÃÁËÒ»¸öк¯Êý¡£½øÈëк¯Êý²¢²é³Æä´úÂ룬ÎÒÃÇ·¢ÏÖËüÓÃÓÚ²é³ÕûÊýÒç³ö¡£¼´Ôö³¤ÁËк¯ÊýÒÔÑéÖ¤ÕûÊý±äÁ¿ÊÇ·ñά³ÖÔÚÔ¤ÆÚÖµÁìÓòÄÚ¡£

½¨¸´´úÂë
Éî¿Ì½âÎö
OSF_SCALL:GetCoalescedBufferÖеÄÒ×Êܹ¥»÷´úÂ룬ÎÒÃǰÑÎȵ½ÕûÊýÒç³öÃýÎó¿ÉÄܵ¼Ö¶ѻº³åÇøÒç³ö£¬ÓÉÓÚÆäÖÐÊý¾Ý±»¸´Ô쵽̫Ó×¶øÎÞ·¨Ìî³ä¡£·´¹ýÀ´£¬ÕâÔÊÐí½«Êý¾ÝдÈë¶ÑÉϵĻº³åÇøÌìǵ֮±í¡£ÈôÊÇÀûÓÃÇе±£¬Õâ¸öÔÓï¿ÉÄܻᵼÖÂÔ¶³Ì´úÂëÖ´ÐС£
ÔÚÆäËûº¯ÊýÖÐÒ²Ôö³¤ÁËÀàËÆµÄ²é³ÕûÊýÒç³öµÄŲÓãº
OSF_CCALL::ProcessResponse
OSF_SCALL::GetCoalescedBuffer
OSF_CCALL::GetCoalescedBuffer
²Î¿¼Á´½Ó£º
https://www.akamai.com/blog/security/critical-remote-code-execution-vulnerabilities-windows-rpc-runtime
·ì϶¼ì²â
GA»Æ½ð¼×Ìì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳÒÑ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐÐÊÚȨɨÃ裬Óû§Éý¼¶³ß¶È·ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃ裺
6070°æ±¾Éý¼¶°üΪ607000428£¬Éý¼¶°üÏÂÔØµØÖ·£º
https://venustech.download.venuscloud.cn/





Éý¼¶ºóÒÑÖ§³Ö¸Ã·ì϶
ÇëʹÓÃÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬ÊµÊ±¶Ô¸Ã·ì϶½øÐмì²â£¬ÒԱ㾡¿ì²ÉÈ¡·À±¸´ëÊ©¡£
»ùÏߺ˲é
GA»Æ½ð¼×°²È«ÅäÖú˲éÖÎÀíϵͳÒÑ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄºË²é×ÊÔ´°ü£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐк˲飬Óû§Éý¼¶°²È«ÅäÖú˲éÖÎÀíϵͳ×ÊÔ´°üºó¼´¿É¶Ô¸Ã·ì϶½øÐк˲飺

»ùÏߺ˲é
½¨¸´½¨Òé
Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£
×Ô¶¯¸üÐÂ
MicrosoftUpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£
ÊÖ¶¯¸üÐÂ
µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖᱡ£
Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows8¡¢Windows8.1¡¢WindowsServer2012ÒÔ¼°WindowsServer2012R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©¡£
Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ½«×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
³ÁÆôÍÆËã»ú£¬×°ÖøüÐÂϵͳ³ÁÐÂÆô¶¯ºó£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2022-Apr
²¹¶¡ÏÂÔØÊ¾Àý
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

΢Èí·ì϶ÁаµÊ¾Àý
2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

²¹¶¡ÏÂÔØÁ´½Ó
3.µã»÷¡¾SecurityUpdate¡¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡£¬ÏÂÔØÊµÏÖºóË«»÷×°Öá£

²¹¶¡ÏÂÔØ
Ó×ÌùÊ¿£º
·ì϶ÏêÇé
±±Ú¤Êý¾Ý³¢ÊÔÊÒ
±±Ú¤Êý¾Ý³¢ÊÔÊÒ³ÉÁ¢ÓÚ2022Äê3Ô£¬ÖÂÁ¦ÓÚÍøÂç¿Õ¼ä°²È«ÖªÊ¶¹¤³Ì×êÑкÍϵͳ»¯½¨ÉèµÄרҵÍŶӣ¬ÓÉGA»Æ½ð¼×¼¯ÍÅÌì¾µ·ì϶×êÑÐÍŶӡ¢Ì©ºÏ֪ʶ¹¤³ÌÍŶӡ¢´óÊý¾Ý³¢ÊÔÊÒ£¨BDlab£©³¡¾°»¯·ÖÎöÍŶӽáºÏ×é³É¡£
±±Ú¤Êý¾Ý³¢ÊÔÊÒʼÖÕ±ü³ÖÒÔÐèҪΪµ¼Ïò¡¢ÖªÊ¶¸³ÄܲúÆ·µÄÖ÷ÌâÀíÏ룬רһÓÚÌá¹©ÍøÂç¿Õ¼ä°²È«µÄ»ù´¡ÖªÊ¶×êÑкͿª·¢£¬Ôì¶©½áºÏÍþвºÍ·ì϶µý±¨¡¢ÍøÂç¿Õ¼ä×ʲúºÍÔÆ°²È«¼à²âÊý¾ÝµÈ×ۺϵý±¨ÒÔ¼°Óû§ÏÖʵ³¡¾°µÄ°²È«·ÖÎö·À»¤Õ½Êõ£¬¹¹½¨×Ô¶¯»¯µ÷²éºÍ´ëÖÃÏìÓ¦´ëÊ©£¬Ðγɳ¡¾°»¯¡¢½á¹¹»¯µÄ֪ʶ¹¤³Ìϵͳ£¬¶Ô¸÷Àలȫ²úÆ·¡¢Æ½Ì¨ºÍ°²È«ÔËÓªÌṩ֪ʶ¸³ÄÜ¡£


¾©¹«Íø°²±¸11010802024551ºÅ