¡¾·ì϶¹«¸æ¡¿Î¢Èí11Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2022-11-09


0x00 ·ì϶¸ÅÊö

2022Äê11ÔÂ8ÈÕ £¬Î¢Èí°ä²¼ÁË11Ô°²È«¸üР£¬±¾´Î¸üн¨¸´ÁËÔ̺¬6¸ö0 day·ì϶ÔÚÄÚµÄ68¸ö°²È«·ì϶ £¬ÆäÖÐÓÐ11¸ö·ì϶ÆÀ¼¶Îª¡°ÑϳÁ¡±¡£

 

0x01 ·ì϶ÏêÇé

±¾´Î°ä²¼µÄ°²È«¸üÐÂÉæ¼°.NET Framework¡¢Azure¡¢Linux Kernel¡¢Microsoft Exchange Server¡¢Microsoft Office¡¢Windows Hyper-V¡¢Visual Studio¡¢Windows ALPC¡¢Windows Kerberos¡¢Windows Mark of the Web (MOTW)¡¢Windows Network Address Translation (NAT)¡¢Windows ODBC Driver¡¢Windows Point-to-Point Tunneling Protocol¡¢Windows Print Spooler Components¡¢Windows ScriptingºÍWindows Win32KµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£

±¾´Î½¨¸´µÄ68¸ö·ì϶£¨²»Ô̺¬2¸öOpenSSL ·ì϶£©ÖÐ £¬27¸öΪÌáÈ¡·ì϶ £¬16¸öΪԶ³Ì´úÂëÖ´Ðзì϶ £¬11¸öΪÐÅϢй¶·ì϶ £¬6¸öΪ»Ø¾ø·þÎñ·ì϶ £¬4¸öΪ°²È«Ö°ÄÜÈÆ¹ý·ì϶ £¬ÒÔ¼°3¸öºýŪ·ì϶¡£

΢Èí±¾´Î¹²½¨¸´ÁË6¸ö±»»ý¼«ÀûÓõÄ0 day·ì϶ £¬ÆäÖÐCVE-2022-41091Òѱ»¹«¿ªÅû¶£º

CVE-2022-41128£ºWindows Scripting LanguagesÔ¶³Ì´úÂëÖ´Ðзì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8 £¬Ó°ÏìÁËJScript9 ¾ç±¾Ëµ»°ºÍ¶à¸öWindows °æ±¾ £¬ÀûÓø÷ì϶ÐèÓëÓû§½»»¥ £¬Ä¿Ç°ÒѼì²âµ½·ì϶ÀûÓá£

CVE-2022-41091£ºWindows Mark of the Web °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ5.4 £¬ÀûÓø÷ì϶ÐèÓëÓû§½»»¥¡£Äܹ»Ôì×÷¶ñÒâÎļþÀ´¶ã±ÜMark of the Web (MOTW)·ÀÓù £¬´Ó¶øµ¼Ö Microsoft Office ÖеÄÊܱ£»¤ÊÓͼµÈÒÀÀµ MOTW ÏóÕ÷µÄ°²È«Ö°ÄÜÊܵ½Ó°Ïì¡£¸Ã·ì϶ÒѾ­¹«¿ªÅû¶ £¬ÇÒÒѼì²âµ½·ì϶ÀûÓá£

CVE-2022-41073£ºWindows Print Spooler ÌØÈ¨ÌáÉý·ì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8 £¬Ó°ÏìÁËWindows ºó¶Ü´òÓ¡·¨Ê½ £¬³É¹¦ÀûÓø÷ì϶µÄ±¾µØ¶ñÒâÓû§Äܹ»»ñµÃSYSTEMȨÏÞ £¬Ä¿Ç°ÒѾ­¼ì²âµ½·ì϶ÀûÓá£

CVE-2022-41125£ºWindows CNG Key Isolation Service ÌØÈ¨ÌáÉý·ì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8 £¬Ó°ÏìÁËWindows CNG ÃÜÔ¿¸ôÀë·þÎñ £¬³É¹¦ÀûÓø÷ì϶µÄ±¾µØ¶ñÒâÓû§Äܹ»»ñµÃSYSTEMȨÏÞ £¬Ä¿Ç°ÒѾ­¼ì²âµ½·ì϶ÀûÓá£

CVE-2022-41040£ºMicrosoft Exchange Server ÌØÈ¨ÌáÉý·ì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8 £¬Î¢ÈíÓÚ2022Äê9ÔÂ30ÈÕ³õ´ÎÅû¶¸Ã·ì϶£¨Microsoft Exchange ProxyNotShell·ì϶£© £¬³É¹¦ÀûÓø÷ì϶Äܹ»ÌáÉýȨÏÞ £¬²¢ÔÚÖ¸±êϵͳÖÐÔËÐÐPowerShell £¬µ«±ØÐë¾­¹ýÉí·ÝÑéÖ¤ £¬¸Ã·ì϶ÒѾ­¼ì²âµ½·ì϶ÀûÓá£

CVE-2022-41082£ºMicrosoft Exchange Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8 £¬Î¢ÈíÓÚ2022Äê9ÔÂ30ÈÕ³õ´ÎÅû¶¸Ã·ì϶£¨Microsoft Exchange ProxyNotShell·ì϶£© £¬¾­¹ýÉí·ÝÑéÖ¤µÄ¶ñÒâÓû§Äܹ»Í¨¹ýÍøÂçŲÓÃÔÚ·þÎñÆ÷ÕÊ»§µÄ¸ßµÍÎÄÖд¥·¢¶ñÒâ´úÂë £¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ £¬¸Ã·ì϶ÒѾ­¼ì²âµ½·ì϶ÀûÓá£

΢Èí11Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º

CVE ID

CVE ±êÌâ

ÑϳÁÐÔ

CVE-2022-39327

GitHub£ºCVE-2022-39327 Azure CLI´úÂë×¢Èë·ì϶

ÑϳÁ

CVE-2022-41040

Microsoft Exchange ÐÅϢй¶·ì϶

ÑϳÁ

CVE-2022-41080

Microsoft Exchange Server ÌØÈ¨ÌáÉý·ì϶

ÑϳÁ

CVE-2022-38015

Windows Hyper-V »Ø¾ø·þÎñ·ì϶

ÑϳÁ

CVE-2022-37967

Windows Kerberos ÌØÈ¨ÌáÉý·ì϶

ÑϳÁ

CVE-2022-37966

Windows Kerberos RC4-HMAC ÌØÈ¨ÌáÉý·ì϶

ÑϳÁ

CVE-2022-41044

Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2022-41039

Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2022-41088

Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2022-41118

Windows ¾ç±¾Ëµ»°Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2022-41128

Windows ¾ç±¾Ëµ»°Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2022-41064

.NET Framework ÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-23824

AMD£ºCVE-2022-23824 IBPBºÍ·µ»ØµØÖ·Ô¤²âÆ÷½»»¥

¸ßΣ

CVE-2022-41085

Azure CycleCloud ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41051

Azure RTOS GUIX Studio Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-38014

Windows Subsystem for Linux (WSL2) ÄÚºËȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2022-41066

Microsoft ÒµÎñÖÐÐÄÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-41082

Microsoft Exchange Server ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41078

Microsoft Exchange Server ºýŪ·ì϶

¸ßΣ

CVE-2022-41079

Microsoft Exchange Server ºýŪ·ì϶

¸ßΣ

CVE-2022-41123

Microsoft Exchange Server ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41113

Windows Win32 Kernel Subsystem ÌáȨ·ì϶

¸ßΣ

CVE-2022-41052

Windows Graphics Component Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

ADV220003

Microsoft DefenseÉî¶È¸üÐÂ

¸ßΣ

CVE-2022-41105

Microsoft Excel ÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-41107

Microsoft Office Graphics Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-41104

Microsoft Excel °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2022-41063

Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-41106

Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-41122

Microsoft SharePoint Server ºýŪ·ì϶

¸ßΣ

CVE-2022-41062

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-41103

Microsoft Word ÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-41061

Microsoft Word Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-41060

Microsoft Word ÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-41056

ÍøÂçÕ½Êõ·þÎñÆ÷ (NPS) RADIUS ºÍ̸»Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2022-41097

ÍøÂçÕ½Êõ·þÎñÆ÷ (NPS) RADIUS ºÍ̸ÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-41120

Microsoft Windows Sysmon ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-39253

GitHub£ºCVE-2022-39253 ±¾µØ¿Ë¡ÓÅ»¯Ä¬ÈÏÈ¡µÞÒýÓ÷ûºÅÁ´½Ó

¸ßΣ

CVE-2022-41119

Visual Studio Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-41093

Windows ¸ß¼¶±¾µØ¹ý³ÌŲÓà (ALPC) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41045

Windows ¸ß¼¶±¾µØ¹ý³ÌŲÓà (ALPC) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41100

Windows ¸ß¼¶±¾µØ¹ý³ÌŲÓà (ALPC) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41114

Windows Bind Filter DriverÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41099

BitLocker °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2022-41125

Windows CNG ÃÜÔ¿¸ôÀë·þÎñÌáȨ·ì϶

¸ßΣ

CVE-2022-41055

Windows ÈË»ú½çÃæÉ豸ÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-41095

Windows Êý×ÖýÌå½Ó¹ÜÆ÷ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41096

Microsoft DWM Ö÷Ìâ¿âÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41050

Windows ¿ÉÀ©´óÎļþ·ÖÅä±íÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-37992

Windows ×éÕ½ÊõÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41086

Windows ×éÕ½ÊõÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41057

Windows HTTP.sys ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41053

Windows Kerberos »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2022-41049

Windows Mark of the Web°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2022-41091

Windows Mark of the Web°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2022-38023

Netlogon RPC ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41058

Windows ÍøÂçµØÖ·×ª»» (NAT) »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2022-41047

Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-41048

Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2022-41101

Windows ¸²¸Ç²ã¹ýÂËÆ÷ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41102

Windows ¸²¸Ç²ã¹ýÂËÆ÷ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41116

Windows µã¶ÔµãËí·ºÍ̸»Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2022-41090

Windows µã¶ÔµãËí·ºÍ̸»Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2022-41073

Windows ºó¶Ü´òÓ¡·¨Ê½ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41054

Windows µ¯ÐÔÎļþϵͳ (ReFS) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41092

Windows Win32k ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41109

Windows Win32k ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2022-41098

Windows GDI+ ÐÅϢй¶·ì϶

¸ßΣ

CVE-2022-3786

OpenSSL£ºCVE-2022-3786 X.509 Ö¤ÊéÑéÖ¤»º³åÇøÒç³ö

δ֪

CVE-2022-3602

OpenSSL£ºCVE-2022-3602 X.509 Ö¤ÊéÑéÖ¤»º³åÇøÒç³ö

δ֪

 

0x02 ´ëÖý¨Òé

Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üР£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓà £¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ £¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü £¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡± £¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС± £¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС± £¬ÆÚ´ýϵͳ½«×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú £¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüР£¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó £¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡± £¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

11Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2022-Nov

²¹¶¡ÏÂÔØÊ¾Àý£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó £¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2Ô£©

2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ £¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾°²È«¸üС¿ £¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ £¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£


0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2022-Nov

https://www.bleepingcomputer.com/news/microsoft/microsoft-november-2022-patch-tuesday-fixes-6-exploited-zero-days-68-flaws/

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2022-11-09

³õ´Î°ä²¼

 

0x05 ¸½Â¼

GA»Æ½ð¼×¼ò½é

GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Äê £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏà £¬¹«Ë¾Ô±¹¤6000ÓàÈË £¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ £¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£

 

¹ØÓÚGA»Æ½ð¼×

GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÖØÒªÕë¶Ô³ÁÒª°²È«·ì϶µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвµý±¨ºÍ°²È«»ã±¨¡£

¹Ø×¢ÒÔϹ«¼ÒºÅ £¬»ñȡȫÇò×îа²È«×ÊѶ£º

image.png