¡¾·ì϶¹«¸æ¡¿Î¢Èí10Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2022-10-12

0x00 ·ì϶¸ÅÊö

2022Äê10ÔÂ11ÈÕ£¬Î¢Èí°ä²¼ÁË10Ô°²È«¸üУ¬±¾´Î¸üн¨¸´ÁËÔ̺¬2¸ö0 day·ì϶ÔÚÄÚµÄ84¸ö°²È«·ì϶£¨²»Ô̺¬10ÔÂ3ÈÕ½¨¸´µÄ12¸öMicrosoft  Edge·ì϶£©£¬ÆäÖÐÓÐ13¸ö·ì϶ÆÀ¼¶Îª¡°ÑϳÁ¡±¡£´Ë±í£¬Microsoft Exchange ProxyNotShell·ì϶ÉÐ佨¸´¡£

 

0x01 ·ì϶ÏêÇé

±¾´Î°ä²¼µÄ°²È«¸üÐÂÉæ¼°Active Directory Domain Services¡¢Azure¡¢Microsoft Office¡¢Microsoft Office SharePoint¡¢Windows Hyper-V¡¢Visual Studio Code¡¢Windows Active Directory Certificate Services¡¢Windows Defender¡¢Windows DHCP Client¡¢Windows Group Policy¡¢Windows Kernel¡¢Windows NTFS¡¢Windows NTLM¡¢Windows Point-to-Point Tunneling Protocol¡¢Windows TCP/IPºÍWindows Win32KµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£

±¾´Î½¨¸´µÄ84¸ö·ì϶ÖУ¬39¸öΪÌáÈ¡·ì϶£¬20¸öΪԶ³Ì´úÂëÖ´Ðзì϶£¬11¸öΪÐÅϢй¶·ì϶£¬8¸öΪ»Ø¾ø·þÎñ·ì϶£¬2¸öΪ°²È«Ö°ÄÜÈÆ¹ý·ì϶£¬ÒÔ¼°4¸öºýŪ·ì϶¡£

΢Èí±¾´Î¹²½¨¸´ÁË2¸ö0 day·ì϶£¬ÆäÖÐCVE-2022-41033ÒÑ·¢ÏÖ±»»ý¼«ÀûÓã¬CVE-2022-41043ÒѾ­¹«¿ªÅû¶¡£

CVE-2022-41033£ºWindows COM+ Event System ServiceÌØÈ¨ÌáÉý·ì϶

¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.8£¬³É¹¦ÀûÓø÷ì϶Äܹ»»ñµÃSYSTEMȨÏÞ¡£Ä¿Ç°¸Ã·ì϶ÔÝδ¹«¿ªÅû¶£¬µ«ÒѾ­¼ì²âµ½·ì϶ÀûÓá£

CVE-2022-41043£ºMicrosoft Office ÐÅϢй¶·ì϶

¸Ã·ì϶ӰÏìÁ˺ÏÓÃÓÚ Mac 2021 µÄ Microsoft Office LTSCºÍºÏÓÃÓÚ Mac µÄ Microsoft Office 2019£¬ÆäCVSSv3ÆÀ·ÖΪ3.3£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܻᵼÖÂÓû§ÁîÅÆ»òÆäËüÃô¸ÐÐÅÏ¢±»Ð¹Â¶¡£Ä¿Ç°¸Ã·ì϶ÔÝδ¼ì²âµ½·ì϶ÀûÓ㬵«ÒѾ­±»¹«¿ªÅû¶¡£

΢ÈíÉÐδÔÚ±¾´Î¸üÐÂÖн¨¸´Microsoft Exchange ProxyNotShell·ì϶CVE-2022-41040£¨ÌØÈ¨ÌáÉý£©ºÍCVE-2022-41082£¨Ô¶³Ì´úÂëÖ´ÐУ©£¬µ«ÒѾ­°ä²¼ÁËÓйذ²È«Ö¸ÄÏ£¬Óû§¿ÉÀûÓÃÖ¸ÄÏÖеĻº½â´ëÊ©²¢ÆÚ´ý¹Ù·½²¹¶¡°ä²¼¡£

±¾´Î¸üÐÂÖÐÖµµÃ¹Ø×¢µÄ·ì϶Ô̺¬µ«²»ÏÞÓÚ£º

CVE-2022-37968£ºÆôÓà Azure Arc µÄ Kubernetes ¼¯ÈºÏνÓÌØÈ¨ÌáÉý·ì϶

¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ10.0£¬Ó°ÏìÁËÆôÓà Azure Arc µÄ Kubernetes ¼¯ÈºµÄ¼¯ÈºÏνÓÖ°ÄÜ£¬¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÓû§ÌáÉýÆäȨÏÞ²¢¿ÉÄÜ»ñµÃ¶Ô Kubernetes ¼¯ÈºµÄÖÎÀí½ÚÔìȨ¡£´Ë±í£¬ÓÉÓÚ Azure Stack Edge ÔÊÐí¿Í»§Í¨¹ý Azure Arc ÔÚÆäÉ豸Éϲ¿Êð Kubernetes ¹¤×÷¸ºÔØ£¬Òò¶ø Azure Stack Edge É豸ҲÈÝÒ×Êܵ½¸Ã·ì϶µÄÓ°Ïì¡£

CVE-2022-37976£ºActive Directory Ö¤Êé·þÎñÌØÈ¨ÌáÉý·ì϶

¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.8£¬Ö»Óе± Active Directory Ö¤Êé·þÎñÔÚÓòÉÏÔËÐÐʱ£¬ÏµÍ³²ÅÈÝÒ×Êܵ½¹¥»÷£¬³É¹¦ÀûÓô˷ì϶Äܹ»»ñµÃÓòÖÎÀíԱȨÏÞ¡£¸Ã·ì϶ӰÏìÁ˶à¸öWindows Server°æ±¾£¬ÊÜÓ°ÏìÓû§¿ÉʵʱװÖøüС£

CVE-2022-41038£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.8£¬Í¨¹ýÖ¸±êÍøÕ¾µÄÉí·ÝÑéÖ¤²¢ÓÐȨÔÚ SharePoint ÖÐʹÓÃÖÎÀíÁбíµÄÓû§Äܹ»ÔÚ SharePoint Server ÉÏÔ¶³ÌÖ´ÐдúÂë¡£

CVE-2022-38048£ºMicrosoft Office Ô¶³Ì´úÂëÖ´Ðзì϶

¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.8£¬ÀûÓø÷ì϶ÐèÓëÓû§½»»¥¡£¸Ã·ì϶ӰÏìÁ˶à¸ö°æ±¾µÄMicrosoft Office 2013¡¢Microsoft Office 2016¡¢Microsoft Office 2019¡¢Microsoft Office LTSCºÍMicrosoft 365 ÆóÒµÀûÓá£

΢Èí10Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º

CVE ID

CVE ±êÌâ

ÑϳÁÐÔ

CVE-2022-37968

ÆôÓà Azure Arc µÄ Kubernetes ¼¯ÈºÏνÓÌØÈ¨ÌáÉý·ì϶

ÑϳÁ

CVE-2022-38048

Microsoft Office Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2022-41038

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2022-37979

Windows Hyper-V ÌØÈ¨ÌáÉý·ì϶

ÑϳÁ

CVE-2022-37976

Active Directory Ö¤Êé·þÎñÌØÈ¨ÌáÉý·ì϶

ÑϳÁ

CVE-2022-34689

Windows CryptoAPI ºýŪ·ì϶

ÑϳÁ

CVE-2022-33634

Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2022-22035

Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2022-24504

Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2022-38047

Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2022-41081

Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2022-30198

Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2022-38000

Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2022-38042

Active Directory Óò·þÎñÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-38017

StorSimple 8000 ϵÁÐÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37987

Windows ¿Í»§¶Ë·þÎñÆ÷ÔËÐÐʱ×Óϵͳ (CSRSS) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37989

Windows ¿Í»§¶Ë·þÎñÆ÷ÔËÐÐʱ×Óϵͳ (CSRSS) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37986

Windows Win32k ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-38051

Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37997

Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37985

Windows ͼÐÎ×é¼þÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-33635

Windows GDI+ Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-38001

Microsoft Office ºýŪ·ì϶

¸ßΣ

CVE-2022-41043

Microsoft Office ÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-38053

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-41036

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-41037

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-41031

Microsoft Word Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-38049

Microsoft Office Graphics Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-37982

Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-38031

Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-41032

NuGet ¿Í»§¶ËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37965

Windows µã¶ÔµãËí·ºÍ̸»Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2022-35829

Service Fabric Explorer ºýŪ·ì϶

¸ßΣ

CVE-2022-41042

Visual Studio Code ÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-41034

Visual Studio Code Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-41083

Visual Studio Code ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37978

Windows Active Directory Ö¤Êé·þÎñ°²È«Ö°ÄÜÈÆ¹ý

¸ßΣ

CVE-2022-38029

Windows ALPC ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-38044

Windows CD-ROM ÎļþϵͳÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-41033

Windows COM+ ÊÂÎñϵͳ·þÎñÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-38021

Connected User Experiences and TelemetryÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37971

Microsoft Windows Defender ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-38026

Windows DHCP ¿Í»§¶ËÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-37980

Windows DHCP ¿Í»§¶ËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-38025

Windows É¢²¼Ê½Îļþϵͳ (DFS) ÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-37970

Windows DWM Ö÷Ìâ¿âÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37983

Microsoft DWM Ö÷Ìâ¿âÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37981

Windows ÊÂÎñÈÕÖ¾¼Í¼·þÎñ»Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2022-37975

Windows ×éÕ½ÊõÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37994

Windows ×éÕ½ÊõÊ×Ñ¡Ïî¿Í»§¶ËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37993

Windows ×éÕ½ÊõÊ×Ñ¡Ïî¿Í»§¶ËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37999

Windows ×éÕ½ÊõÊ×Ñ¡Ïî¿Í»§¶ËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-38036

Internet ÃÜÔ¿»¥»» (IKE) ºÍ̸»Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2022-37988

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-38037

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37990

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-38038

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-38039

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37995

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37991

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-38022

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-38016

Windows ±¾µØ°²È«»ú¹¹ (LSA) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37977

±¾µØ°²È«»ú¹¹×Óϵͳ·þÎñ (LSASS) »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2022-37973

Windows ±¾µØ»á»°ÖÎÀíÆ÷ (LSM) »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2022-37998

Windows ±¾µØ»á»°ÖÎÀíÆ÷ (LSM) »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2022-37996

Windows ÄÚºËÄÚ´æÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-35770

Windows NTLM ºýŪ·ì϶

¸ßΣ

CVE-2022-38040

Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-37974

Windows Mixed Reality ¿ª·¢Õß¹¤¾ßÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-38032

Windows ±ãЯʽÉ豸ö¾ÙÆ÷·þÎñ°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2022-38028

Windows ºó¶Ü´òÓ¡·¨Ê½ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-38003

Windows µ¯ÐÔÎļþÏµÍ³ÌØÈ¨ÌáÉý

¸ßΣ

CVE-2022-38041

Windows °²È«Í¨Â·»Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2022-38043

Windows °²È«Ö§³ÖÌṩ·¨Ê½½Ó¿ÚÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-38033

Windows Server ¿ÉÔ¶³Ì½Ó¼ûµÄ×¢²á±íÏîÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-38045

Server Service Remote ProtocolÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-38027

Windows ´æ´¢ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-33645

Windows TCP/IP Çý¶¯·¨Ê½»Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2022-38030

Windows USB ´®ÐÐÇý¶¯·¨Ê½ÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-38046

Web Account ManagerÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-38050

Win32k ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37984

Windows WLAN Service ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-38034

Windows Workstation ServiceÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41035

Microsoft Edge£¨»ùÓÚ Chromium£©ºýŪ·ì϶

ÖÐΣ

CVE-2022-3311

Chromium£ºCVE-2022-3311 ÔÚµ¼ÈëºóÃâ·ÑʹÓÃ

δ֪

CVE-2022-3313

Chromium£ºCVE-2022-3313 È«ÆÁÏÔʾ²»ÕýÈ·µÄ°²È« UI

δ֪

CVE-2022-3315

Chromium£ºCVE-2022-3315 Blink ÖеÄÀàÐÍ»ìºÏ

δ֪

CVE-2022-3370

Chromium£ºCVE-2022-3370 ÔÚ×Ô½çËµÔªËØÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-3373

Chromium£ºCVE-2022-3373  ÔÚV8ÖÐÔ½½çдÈë

δ֪

CVE-2022-3316

Chromium£ºCVE-2022-3316 ¶Ô°²È«ä¯ÀÀÖв»ÊÜÐÅÀµµÄÊäÈëµÄÑéÖ¤²»¼°

δ֪

CVE-2022-3317

Chromium£ºCVE-2022-3317 Intents Öв»ÊÜÐÅÀµµÄÊäÈëÑéÖ¤²»¼°

δ֪

CVE-2022-3310

Chromium£ºCVE-2022-3310 ×Ô½ç˵ѡÏÖеÄÕ½ÊõÖ´Ðв»¼°

δ֪

CVE-2022-3304

Chromium£ºCVE-2022-3304 ÔÚ CSS ÖÐÃâ·ÑºóʹÓÃ

δ֪

CVE-2022-3308

Chromium£ºCVE-2022-3308 ¿ª·¢ÈËÔ±¹¤¾ßÖеÄÕ½ÊõÖ´Ðв»¼°

δ֪

CVE-2022-3307

Chromium£ºCVE-2022-3307 ÔÚýÌåÖÐÃâ·ÑºóʹÓÃ

δ֪

 

0x02 ´ëÖý¨Òé

Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС±£¬ÆÚ´ýϵͳ½«×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

10Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2022-Oct

²¹¶¡ÏÂÔØÊ¾Àý£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2Ô£©

2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2022-Oct

https://www.bleepingcomputer.com/news/microsoft/microsoft-october-2022-patch-tuesday-fixes-zero-day-used-in-attacks-84-flaws/

https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2022-10-12

³õ´Î°ä²¼

 

0x05 ¸½Â¼

GA»Æ½ð¼×¼ò½é

GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤½ü4000ÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£

 

¹ØÓÚGA»Æ½ð¼×

GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÖØÒªÕë¶Ô³ÁÒª°²È«·ì϶µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвµý±¨ºÍ°²È«»ã±¨¡£

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñȡȫÇò×îа²È«×ÊѶ£º

image.png