Éî¶ÈÆÊÎö΢Èí×îЩ¶´£¬ÎªÄúÌṩ×îÓŽâ¾ö·½°¸

Ðû²¼Ê±¼ä 2022-04-21
Ç°ÑÔ£º

½üÆÚ£¬Î¢ÈíÐû²¼ÁË4Ô·ݵÄÄþ¾²¸üУ¬ÐÞ¸´ÁË°üÂÞ2¸ö0day©¶´ÔÚÄÚµÄ119¸öÄþ¾²Â©¶´£¨²»°üÂÞ26¸öMicrosoftEdge©¶´£©£¬ÆäÖÐÓÐ10¸ö©¶´±»ÆÀ¼¶ÎªÑÏÖØ£¬Éæ¼°.NET Framework¡¢ActiveDirectoryDomainServicesµÈ¶à¸ö²úÎïºÍ×é¼þ¡££¨Â©¶´ÏêÇéÔÚÎÄÄ©£©


¶«É­Æ½Ì¨±±Ú¤Êý¾ÝʵÑéÊÒµÚһʱ¼ä¶Ô΢Èí4ÔÂÐû²¼µÄÄþ¾²Í¨¸æ½øÐзÖÎöÑÐÅУ¬½áºÏÌ©ºÏÅ̹Åƽ̨£¨THPangu-OS£©µÄµ××ùÄÜÁ¦£¬Îª¹ã´óÓû§¸ø³öÓ¦¼±´¦ÖÃÖ¸Òý·½°¸¡£


ÒòÔ¶³Ì´úÂëÖ´ÐЩ¶´CVE-2022-26809Íþвˮƽ¸ß¡¢Ó°Ï췶Χ½Ï¹ã£¬ÀûÓõÄÅÓ´ó¶ÈµÍ£¬Ò×±»¹¥»÷Õ߹㷺ÀûÓýø¶ø¶Ô¹ã´óÓû§Ôì³ÉÑÏÖØΣº¦£¬ËùÒÔÎÒÃÇÒÔ´Ë©¶´Éæ¼°µÄ·þÎñΪÀý£¬×ö³öÁ˽øÒ»²½µÄϸÖ·ÖÎö¹ý³Ì£¬²¢Ïêϸ˵Ã÷©¶´ÐÞ¸´Óë²¹¶¡ÏÂÔØ¡£


©¶´·ÖÎö


Ïà¹Ø©¶´Î»ÓÚWindowsRPC·þÎñ£¬¸Ã·þÎñÓÉÃûΪrpcrt4.dllµÄ¿â¡£¸ÃÔËÐÐʱ¿â±»¼ÓÔص½Ê¹ÓÃRPCЭÒé½øÐÐͨÐŵĿͻ§¶ËºÍ·þÎñÆ÷½ø³ÌÖС£


ͨ¹ý±ÈÁ¦ÁË10.0.22000.434£¨Î´´ò²¹¶¡£¬´Ó2022Äê3Ô¿ªÊ¼£©ºÍ10.0.22000.613£¨ÒÑ´ò²¹¶¡£¬´Ó2022Äê4Ô¿ªÊ¼£©°æ±¾£¬ÄÜ·¢ÏÖÒÔÏÂÖÖÖÖ¹¦Ð§»òº¯ÊýµÄ±ä»¯Çåµ¥¡£


1.jpg

º¯Êý±ä»¯Çåµ¥


º¯ÊýOSF_CCALL::ProcessResponseºÍOSF_SCALL::ProcessReceivedPDU¡£ÕâÁ½¸öº¯Êý±¾ÖÊÉÏÊÇÏàËƵÄ£»Á½Õ߶¼´¦ÖÃRPCÊý¾Ý°ü£¬µ«Ò»¸öÔÚ¿Í»§¶ËÔËÐУ¬ÁíÒ»¸öÔÚ·þÎñÆ÷¶ËÔËÐУ¨CCALLºÍSCALL·Ö±ð´ú±í¿Í»§¶Ëµ÷ÓúͷþÎñÆ÷µ÷Óã©¡£ÎÒÃǼÌÐø±ÈÁ¦OSF_SCALL::ProcessReceivedPDU£¬²¢×¢Ò⵽а汾ÖÐÌí¼ÓÁËÁ½¸ö´úÂë¿é¡£


2.jpg

3.jpg

¶Ô±ÈÐÂÔö´úÂë¿é


¼ì²ìÐÞ¸´´úÂ룬ÎÒÃÇ¿´µ½ÔÚQUEUE::PutOnQueueÖ®ºóµ÷ÓÃÁËÒ»¸öк¯Êý¡£½øÈëк¯Êý²¢¼ì²éÆä´úÂ룬ÎÒÃÇ·¢ÏÖËüÓÃÓÚ¼ì²éÕûÊýÒç³ö¡£¼´Ìí¼ÓÁËк¯ÊýÒÔÑéÖ¤ÕûÊý±äÁ¿ÊÇ·ñ±£³ÖÔÚÔ¤ÆÚÖµ·¶Î§ÄÚ¡£


4.jpg

ÐÞ¸´´úÂë


ÉîÈë½âÎö


OSF_SCALL:GetCoalescedBufferÖеÄÒ×Êܹ¥»÷´úÂ룬ÎÒÃÇ×¢Òâµ½ÕûÊýÒç¶éÂäÎó¿ÉÄܵ¼Ö¶ѻº³åÇøÒç³ö£¬ÒòΪÆäÖÐÊý¾Ý±»¸´ÖƵ½Ì«Ð¡¶øÎÞ·¨Ìî³ä¡£·´¹ýÀ´£¬ÕâÔÊÐí½«Êý¾ÝдÈë¶ÑÉϵĻº³åÇø½çÏÞÖ®Íâ¡£Èç¹ûÀûÓÃÇ¡µ±£¬Õâ¸öÔ­Óï¿ÉÄܻᵼÖÂÔ¶³Ì´úÂëÖ´ÐС£


ÔÚÆäËûº¯ÊýÖÐÒ²Ìí¼ÓÁËÀàËƵļì²éÕûÊýÒç³öµÄµ÷Óãº


OSF_CCALL::ProcessResponse

OSF_SCALL::GetCoalescedBuffer

OSF_CCALL::GetCoalescedBuffer


²Î¿¼Á´½Ó£º

https://www.akamai.com/blog/security/critical-remote-code-execution-vulnerabilities-windows-rpc-runtime  



©¶´¼ì²â


¶«É­Æ½Ì¨Ìì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳÒѽô¼±Ðû²¼Õë¶Ô¸Ã©¶´µÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸Ã©¶´½øÐÐÊÚȨɨÃ裬Óû§Éý¼¶³ß¶È©¶´¿âºó¼´¿É¶Ô¸Ã©¶´½øÐÐɨÃ裺


6070°æ±¾Éý¼¶°üΪ607000428£¬Éý¼¶°üÏÂÔصØÖ·£º

https://venustech.download.venuscloud.cn/


1.png

2.jpg

3.jpg

4.jpg

5.jpg

Éý¼¶ºóÒÑÖ§³Ö¸Ã©¶´


ÇëʹÓÃÌì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳ²úÎïµÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬¼°Ê±¶Ô¸Ã©¶´½øÐмì²â£¬ÒԱ㾡¿ì½ÓÄÉ·À·¶´ëÊ©¡£


»ùÏߺ˲é


¶«É­Æ½Ì¨Äþ¾²ÅäÖú˲é¹ÜÀíϵͳÒѽô¼±Ðû²¼Õë¶Ô¸Ã©¶´µÄºË²é×ÊÔ´°ü£¬Ö§³Ö¶Ô¸Ã©¶´½øÐк˲飬Óû§Éý¼¶Äþ¾²ÅäÖú˲é¹ÜÀíϵͳ×ÊÔ´°üºó¼´¿É¶Ô¸Ã©¶´½øÐк˲飺


6.jpg

»ùÏߺ˲é


ÐÞ¸´½¨Òé


Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£


×Ô¶¯¸üÐÂ


MicrosoftUpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£


ÊÖ¶¯¸üÐÂ


µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖᱡ£


Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows8¡¢Windows8.1¡¢WindowsServer2012ÒÔ¼°WindowsServer2012R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©¡£


Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£


ÖØÆô¼ÆËã»ú£¬°²×°¸üÐÂϵͳÖØÐÂÆô¶¯ºó£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔز¢°²×°¡£


Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2022-Apr


²¹¶¡ÏÂÔØʾÀý


1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£


7.jpg

΢Èí©¶´ÁÐÌåÏÖÀý


2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£


8.jpg

²¹¶¡ÏÂÔØÁ´½Ó


3.µã»÷¡¾SecurityUpdate¡¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏàÓ¦²¹¶¡£¬ÏÂÔØÍê³ÉºóË«»÷°²×°¡£


9.jpg

²¹¶¡ÏÂÔØ



СÌùÊ¿£º


©¶´ÏêÇé


±¾´ÎÐÞ¸´µÄ119¸ö©¶´ÖУ¬47¸öΪȨÏÞÌáÉý©¶´£¬47¸öΪԶ³Ì´úÂëÖ´ÐЩ¶´£¬13¸öΪÐÅϢ鶩¶´£¬9¸öΪ¾Ü¾ø·þÎñ©¶´£¬ÒÔ¼°3¸öÆÛƭ©¶´¡£1£©Î¢Èí±¾´Î¹²ÐÞ¸´ÁË2¸ö0day©¶´£¬ÆäÖÐCVE-2022-24521ÕýÔÚ±»»ý¼«ÀûÓã¬CVE-2022-26904ÒѾ­¹ûÈ»Åû¶¡£?CVE-2022-26904£ºWindowsÓû§ÅäÖÃÎļþ·þÎñȨÏÞÌáÉý©¶´¸Ã©¶´ÊÇWindowsUserProfileServiceÖеĵ±µØȨÏÞÌáÉý©¶´£¬CVSSÆÀ·ÖΪ7.0£¬ËùÐèȨÏÞµÍÇÒÎÞÐèÓû§½»»¥£¬µ«¹¥»÷ÅÓ´ó¶È¸ß£¨ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£©£¬Ä¿Ç°´Ë©¶´ÒѾ­¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔ½«ÆäÆÀ¹ÀΪ¿ÉÄܱ»ÀûÓá£?CVE-2022-24521£ºWindowsͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½È¨ÏÞÌáÉý©¶´¸Ã©¶´µÄ¹¥»÷ÅÓ´ó¶ÈºÍËùÐèȨÏ޵ͣ¬ÎÞÐèÓû§½»»¥¼´¿É±»µ±µØÀûÓá£Î¢ÈíÌåÏÖÒѼì²âµ½Õë¶Ô´Ë©¶´µÄ©¶´ÀûÓá£2£©±¾´ÎÐÞ¸´µÄ10¸öÑÏÖØ©¶´°üÂÞ£º?CVE-2022-26919£ºWindowsLDAPÔ¶³Ì´úÂëÖ´ÐЩ¶´ÔÚÓòÖÐͨ¹ýÉí·ÝÑéÖ¤µÄ³ß¶ÈÓû§Äܹ»ÀûÓôË©¶´ÔÚLDAP·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£µ«ÒªÀûÓôË©¶´£¬ÐèÒªÐÞ¸ÄĬÈϵÄMaxReceiveBufferLDAPÉèÖá£?CVE-2022-23259£ºMicrosoftDynamics365(on-premises)Ô¶³Ì´úÂëÖ´ÐЩ¶´¾­¹ýÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔÔËÐÐÌØÖƵÄÊÜÐÅÈνâ¾ö·½°¸°üÀ´Ö´ÐÐÈÎÒâSQLÃüÁî¡£¹¥»÷Õß¿ÉÒÔ´ÓÄÇÀïÉý¼¶²¢ÔÚÆäDynamics356Êý¾Ý¿âÖÐÒÔdb_ownerÉí·ÝÖ´ÐÐÃüÁî¡£?CVE-2022-22008/CVE-2022-24537/CVE-2022-2325£ºWindowsHyper-VÔ¶³ÌÖ´ÐдúÂ멶´¿ÉÒÔÔÚHyper-VguestÉÏÔËÐÐÌØÖƵÄÓ¦Ó÷¨Ê½£¬Õâ¿ÉÄܵ¼ÖÂÔÚHyper-VÖ÷»úϵͳִÐÐÈÎÒâ´úÂë¡£?CVE-2022-24491/CVE-2022-24497£ºWindowsNetworkFileSystemÔ¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Õß¿ÉÒÔ½«ÌØÖƵÄNFSЭÒéÍøÂçÏûÏ¢·¢Ë͵½Ò×Êܹ¥»÷µÄWindows»úÆ÷£¬´Ó¶øʵÏÖÔ¶³Ì´úÂëÖ´ÐС£×¢Ò⣺´Ë©¶´½öÓ°ÏìÆôÓÃNFS½ÇÉ«µÄϵͳ¡£?CVE-2022-26809£ºRemoteProcedureCallRuntimeÔ¶³Ì´úÂëÖ´ÐЩ¶´´Ë©¶´µÄCVSSv3ÆÀ·ÖΪ9.8¡£¿ÉÒÔͨ¹ýÏòRPCÖ÷»ú·¢ËÍÒ»¸öÌØÖƵÄRPCµ÷Óã¬Õâ¿ÉÄܵ¼ÖÂÔÚ·þÎñÆ÷¶ËÒÔÓëRPC·þÎñÏàͬµÄȨÏÞÔ¶³ÌÖ´ÐдúÂë¡£¿ÉÒÔͨ¹ýÔÚÆóÒµÍâΧ·À»ðǽÖÐ×èÖ¹TCP¶Ë¿Ú445ºÍ×ñÑ­MicrosoftÖ¸ÄÏÒÔ±£»¤SMBÁ÷Á¿À´»º½â´Ë©¶´¡£ÊÜÓ°ÏìµÄ²úÎï¼°°æ±¾£ºWindows 7 for 32¡¢Windows Server 2016  (Server Core installation)¡¢Windows 11 for ARM64¡¢Windows Server, version20H2 (Server Core Installation)¡¢Windows 10 Version 20H2for ARM64¡¢Windows 10 Version 1909 for ARM64¡¢Windows 10 Version 1809 for x64¡¢Windows 10for 32¡¢Windows 10 Version 21H2 for x64¡¢Windows 10 Version 21H2 for ARM64¡¢Windows 10Version 21H2 for 32¡¢Windows 10 Version 1809 for 32¡¢Windows Server 2022 (Server Core installation)¡¢Windows Server 2022¡¢Windows 10 Version 21H1for 32¡¢Windows 10 Version 21H1 for ARM64¡¢Windows 10 Version 21H1 for x64¡¢WindowsServer 2012 R2 (Server Core installation)¡¢WindowsServer 2012 R2¡¢Windows Server 2012 (Server Coreinstallation)¡¢Windows Server 2012¡¢Windows Server 2008 R2 for x64¡¢WindowsServer 2008 R2 for x64¡¢Windows 10 Version 20H2 for 32¡¢Windows 10 Version 20H2 for x64¡¢WindowsServer 2008 for x64¡¢Windows Server 2016¡¢Windows 10 Version 1607 for x64¡¢Windows 10Version 1607 for 32¡¢Windows 10 for x64¡¢Windows 10 Version 1909 for x64¡¢Windows 10Version 1909 for 32¡¢Windows 10 Version 1809 for ARM64¡¢Windows Server 2008 for x64¡¢Windows Server2008 for 32¡¢Windows 8.1 for 32¡¢Windows7 for x64¡¢Windows Server 2008 for 32¡¢Windows RT 8.1¡¢Windows 8.1 for x64¡¢Windows 11 for x64¡¢Windows Server 2019 (Server Core installation)¡¢Windows Server 2019µÈ¡£?CVE-2022-24541£ºWindowsServer·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´´Ë©¶´ÒªÇóʹÓÃÊÜÓ°ÏìµÄWindows°æ±¾µÄÓû§·ÃÎʶñÒâ·þÎñÆ÷¡£¿ÉÒÔͨ¹ýÔÚÆóÒµÍâΧ·À»ðǽÖÐ×èÖ¹TCP¶Ë¿Ú445ºÍ×ñÑ­MicrosoftÖ¸ÄÏÒÔ±£»¤SMBÁ÷Á¿À´»º½â´Ë©¶´¡£?CVE-2022-24500£ºWindowsSMBÔ¶³Ì´úÂëÖ´ÐЩ¶´´Ë©¶´ÒªÇóʹÓÃÊÜÓ°ÏìµÄWindows°æ±¾µÄÓû§·ÃÎʶñÒâ·þÎñÆ÷¡£¿ÉÒÔͨ¹ýÔÚÆóÒµÍâΧ·À»ðǽÖÐ×èÖ¹TCP¶Ë¿Ú445ºÍ×ñÑ­MicrosoftÖ¸ÄÏÒÔ±£»¤SMBÁ÷Á¿À´»º½â´Ë©¶´¡£


±±Ú¤Êý¾ÝʵÑéÊÒ


±±Ú¤Êý¾ÝʵÑéÊÒ½¨Á¢ÓÚ2022Äê3Ô£¬ÖÂÁ¦ÓÚÍøÂç¿Õ¼äÄþ¾²ÖªÊ¶¹¤³ÌÑо¿ºÍÌåϵ»¯½¨ÉèµÄרҵÍŶÓ£¬Óɶ«É­Æ½Ì¨¼¯ÍÅÌ쾵©¶´Ñо¿ÍŶӡ¢Ì©ºÏ֪ʶ¹¤³ÌÍŶӡ¢´óÊý¾ÝʵÑéÊÒ£¨BDlab£©³¡¾°»¯·ÖÎöÍŶÓÁªºÏ×é³É¡£


±±Ú¤Êý¾ÝʵÑéÊÒʼÖÕ±ü³ÖÒÔÐèÇóΪµ¼Ïò¡¢ÖªÊ¶¸³ÄܲúÎïµÄºËÐÄÀíÄרעÓÚÌṩÍøÂç¿Õ¼äÄþ¾²µÄ»ù´¡ÖªÊ¶Ñо¿ºÍ¿ª·¢£¬Öƶ¨½áºÏÍþвºÍ©¶´Ç鱨¡¢ÍøÂç¿Õ¼ä×ʲúºÍÔÆÄþ¾²¼à²âÊý¾ÝµÈ×ÛºÏÇ鱨ÒÔ¼°Óû§Êµ¼Ê³¡¾°µÄÄþ¾²·ÖÎö·À»¤¼Æı£¬¹¹½¨×Ô¶¯»¯ÊÓ²ìºÍ´¦ÖÃÏìÓ¦´ëÊ©£¬Ðγɳ¡¾°»¯¡¢½á¹¹»¯µÄ֪ʶ¹¤³ÌÌåϵ£¬¶ÔÖÖÖÖÄþ¾²²úÎƽ̨ºÍÄþ¾²ÔËÓªÌṩ֪ʶ¸³ÄÜ¡£