¡¾Â©¶´Í¨¸æ¡¿Î¢Èí9Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2022-09-140x00 ©¶´¸ÅÊö
2022Äê9ÔÂ13ÈÕ£¬Î¢ÈíÐû²¼ÁË9ÔÂÄþ¾²¸üУ¬±¾´Î¸üÐÂÐÞ¸´Á˰üÂÞ2¸ö0 day©¶´ÔÚÄÚµÄ63¸öÄþ¾²Â©¶´£¨²»°üÂÞ֮ǰÐÞ¸´µÄ16¸öMicrosoft Edge©¶´£©£¬ÆäÖÐÓÐ5¸ö©¶´ÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£
0x01 ©¶´ÏêÇé
±¾´ÎÐû²¼µÄÄþ¾²¸üÐÂÉæ¼°.NET Framework¡¢HTTP.sys¡¢Microsoft Office¡¢Microsoft Dynamics¡¢Windows Defender¡¢Windows Group Policy¡¢Windows IKE Extension¡¢Windows Kerberos¡¢Windows Kernel¡¢Windows LDAP¡¢Windows Print Spooler Components¡¢Windows Remote Access Connection Manager¡¢Windows Remote Procedure CallºÍWindows TCP/IPµÈ¶à¸ö²úÎïºÍ×é¼þ¡£
±¾´ÎÐÞ¸´µÄ63¸ö©¶´ÖУ¬18¸öΪÌáȡ©¶´£¬30¸öΪԶ³Ì´úÂëÖ´ÐЩ¶´£¬7¸öΪÐÅϢй¶©¶´£¬7¸öΪ¾Ü¾ø·þÎñ©¶´£¬1¸öΪÄþ¾²¹¦Ð§Èƹý©¶´¡£
΢Èí±¾´Î¹²ÐÞ¸´ÁË2¸ö0 day©¶´£¬ÆäÖÐCVE-2022-37969ÒÑ·¢ÏÖ±»»ý¼«ÀûÓãº
CVE-2022-37969 £ºWindows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´
Windows Common Log File System Driver´æÔÚµ±µØÌáȨ©¶´£¬´Ë©¶´µÄCVSSÆÀ·ÖΪ7.8£¬¿ÉÔÚÓÐȨ·ÃÎÊÄ¿±êϵͳ²¢Äܹ»ÔÚÄ¿±êϵͳÉÏÔËÐдúÂëµÄÇé¿öÏÂÀûÓôË©¶´»ñµÃϵͳȨÏÞ¡£´Ë©¶´ÒѾ¹ûÈ»Åû¶£¬ÇÒÒÑ·¢ÏÖ©¶´ÀûÓá£
CVE-2022-23960£º»º´æÍƲâÏÞÖÆÂ©¶´£¨Arm£©
ijЩ Arm Cortex ºÍ Neoverse ´¦ÖÃÆ÷²»»áÕýÈ·ÏÞÖÆ»º´æÍƲ⣬¼´ Spectre-BHB£¬ÀÖ³ÉÀûÓôË©¶´¿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢй¶¡£´Ë©¶´Ó°ÏìÁË»ùÓÚARM64ϵͳµÄWindows 11£¬Ä¿Ç°ÒѾ¹ûÈ»Åû¶¡£
±¾´Î¸üÐÂÖÐÖµµÃ¹Ø×¢µÄ©¶´°üÂÞµ«²»ÏÞÓÚ£º
CVE-2022-34718 £ºWindows TCP/IP Ô¶³Ì´úÂëÖ´ÐЩ¶´
¿ÉÔÚδ¾Éí·ÝÑéÖ¤µÄÇé¿öϽ«ÌØÖƵÄIPv6Êý¾Ý°ü·¢Ë͵½ÆôÓÃÁË IPSec µÄ Windows ½Úµã£¬Õâ¿ÉÄÜ»áÔڸüÆËã»úÉϵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Ö»ÓÐÔËÐÐ IPSec ·þÎñµÄϵͳ²ÅÈÝÒ×Êܵ½¹¥»÷£¬Èç¹ûÔÚÄ¿±ê»úÆ÷ÉϽûÓÃÁË IPv6£¬Ôòϵͳ²»»áÊܵ½Ó°Ïì¡£´Ë©¶´µÄCVSSv3ÆÀ·ÖΪ9.8£¬¹¥»÷ÅÓ´ó¶ÈµÍ£¬ÎÞÐèÌØÊâȨÏÞºÍÓû§½»»¥¼´¿ÉÔ¶³ÌÀûÓôË©¶´£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°¿ÉÄܱ»ÀûÓᱡ£
CVE-2022-34721¡¢CVE-2022-34722 £ºWindows Internet Key Exchange (IKE) Protocol ExtensionsÔ¶³Ì´úÂëÖ´ÐЩ¶´
Õâ2¸ö©¶´µÄCVSSv3ÆÀ·Ö¾ùΪ9.8£¬¿ÉÔÚδ¾Éí·ÝÑéÖ¤µÄÇé¿öϽ«ÌØÖƵÄIP Êý¾Ý°ü·¢Ë͵½ÔËÐÐ Windows ²¢ÆôÓÃÁË IPSec µÄÄ¿±ê¼ÆËã»ú£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£´Ë©¶´½öÓ°Ïì IKEv1£¬IKEv2 ²»ÊÜÓ°Ï죬µ«´Ë©¶´Ó°ÏìÁËËùÓÐWindows Server£¬ÒòΪËüÃÇͬʱ½ÓÊÜ V1 ºÍ V2 Êý¾Ý°ü¡£
CVE-2022-35805¡¢CVE-2022-34700£ºMicrosoft Dynamics CRM (on-premises)Ô¶³Ì´úÂëÖ´ÐЩ¶´
¾¹ýÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔÔËÐÐÌØÖÆµÄÊÜÐÅÈνâ¾ö·½°¸°üÀ´Ö´ÐÐÈÎÒâ SQL ÃüÁ¿ÉÒÔʵÏÖÉý¼¶²¢ÔÚÆä Dynamics 365 Êý¾Ý¿âÖÐÒÔ db_owner Éí·ÝÖ´ÐÐÃüÁÕâ2¸ö©¶´µÄCVSSv3ÆÀ·Ö¾ùΪ8.8¡£
CVE-2022-38009£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´
´Ë©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬¹¥»÷ÅÓ´ó¶ÈºÍËùÐèȨÏ޵ͣ¬ÎÞÐèÓû§½»»¥¼´¿ÉÔ¶³ÌÀûÓ㬵«ÀûÓôË©¶´±ØÐëͨ¹ýÄ¿±êÍøÕ¾µÄÉí·ÝÑéÖ¤£¬²¢ÓÐȨÔÚ SharePoint ÖÐʹÓùÜÀíÁÐ±í£¬ÀÖ³ÉÀûÓôË©¶´¿ÉÒÔÔÚSharePoint Server ÉÏÔ¶³ÌÖ´ÐдúÂë¡£
CVE-2022-26929£º.NET Framework Ô¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8£¬ÀûÓôË©¶´ÐèÓëÓû§½»»¥¡£
΢Èí9Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑÏÖØÐÔ |
CVE-2022-35805 | Microsoft Dynamics CRM£¨µ±µØ£©Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2022-34700 | Microsoft Dynamics CRM£¨µ±µØ£©Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2022-34722 | Windows Internet ÃÜÔ¿½»»» (IKE) ÐÒéÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2022-34721 | Windows Internet ÃÜÔ¿½»»» (IKE) ÐÒéÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2022-34718 | Windows TCP/IP Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2022-38013 | .NET Core ºÍ Visual Studio ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2022-26929 | .NET Framework Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-38007 | Azure À´±öÅäÖÃºÍÆôÓà Azure Arc µÄ·þÎñÆ÷ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2022-23960 | Arm£ºCVE-2022-23960 »º´æÍƲâÏÞÖÆÂ©¶´ | ¸ßΣ |
CVE-2022-35838 | HTTP V3 ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2022-37954 | DirectX ͼÐÎÄÚºËÌáȨ©¶´ | ¸ßΣ |
CVE-2022-38006 | Windows ͼÐÎ×é¼þÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2022-34729 | Windows GDI ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2022-34728 | Windows ͼÐÎ×é¼þÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2022-35837 | Windows ͼÐÎ×é¼þÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2022-37962 | Microsoft PowerPoint Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-35823 | Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-38009 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-38008 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-37961 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-37963 | Microsoft Office Visio Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-38010 | Microsoft Office Visio Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-34725 | Windows ALPC ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2022-38011 | Raw Image Extension Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-38019 | AV1 Video ExtensionÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-37959 | ÍøÂçÉ豸ע²á·þÎñ (NDES) Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2022-34724 | Windows DNS ·þÎñÆ÷¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2022-38004 | Windows ´«Õæ·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-37958 | SPNEGO À©Õ¹ÐÉÌ (NEGOEX) Äþ¾²»úÖÆÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2022-38020 | Visual Studio Code ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2022-35803 | Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37969 | Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2022-30170 | Windows ƾ¾ÝÂþÓηþÎñÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2022-35828 | Microsoft Defender for Endpoint for Mac ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2022-34719 | Windows ÂþÑÜʽÎļþϵͳ (DFS) ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2022-34723 | Windows DPAPI£¨Êý¾Ý±£»¤Ó¦Ó÷¨Ê½±à³Ì½Ó¿Ú£©ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2022-35841 | WindowsÆóÒµÓ¦ÓùÜÀí·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-35832 | Windows ʼþ¸ú×پܾø·þÎñ©¶´ | ¸ßΣ |
CVE-2022-37955 | Windows ×é¼ÆÄ±ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2022-34720 | Windows Internet ÃÜÔ¿½»»» (IKE) À©Õ¹¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2022-33647 | Windows Kerberos ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2022-33679 | Windows Kerberos ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37964 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37956 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37957 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2022-30200 | Windows ÇáÁ¿¼¶Ä¿Â¼·ÃÎÊÐÒé (LDAP) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-34726 | Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-34730 | Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-34727 | Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-34732 | Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-34734 | Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-35834 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-35835 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-35836 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-35840 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-34733 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-34731 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-26928 | Windows ÕÕÆ¬µ¼Èë API ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2022-38005 | Windows Print SpoolerÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2022-35831 | Windows Ô¶³Ì·ÃÎÊÁ¬½Ó¹ÜÀíÆ÷ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2022-35830 | Remote Procedure Call Runtime Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-35833 | Windows Äþ¾²Í¨µÀ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2022-30196 | Windows Äþ¾²Í¨µÀ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2022-3053 | Chromium£ºCVE-2022-3053 Ö¸ÕëËøÖеIJ»Í×ʵÏÖ | δ֪ |
CVE-2022-3047 | Chromium£ºCVE-2022-3047 À©Õ¹ API ÖеļÆÄ±Ö´Ðв»×ã | δ֪ |
CVE-2022-3054 | Chromium£ºCVE-2022-3054 DevTools ÖеļÆÄ±Ö´Ðв»×ã | δ֪ |
CVE-2022-3041 | Chromium£ºCVE-2022-3041 ÔÚ WebSQL ÖÐÊͷźóʹÓà | δ֪ |
CVE-2022-3040 | Chromium£ºCVE-2022-3040 ÔڽṹÖÐÊͷźóʹÓà | δ֪ |
CVE-2022-3046 | Chromium£ºCVE-2022-3046 ÔÚä¯ÀÀÆ÷±êÇ©ÖÐÊͷźóʹÓà | δ֪ |
CVE-2022-3039 | Chromium£ºCVE-2022-3039 ÔÚ WebSQL ÖÐÊͷźóʹÓà | δ֪ |
CVE-2022-3045 | Chromium£ºCVE-2022-3045 V8 Öв»ÊÜÐÅÈεÄÊäÈëÑéÖ¤²»×ã | δ֪ |
CVE-2022-3044 | Chromium£ºCVE-2022-3044 Õ¾µã¸ôÀëÖеIJ»Í×ʵʩ | δ֪ |
CVE-2022-3057 | Chromium£ºCVE-2022-3057 iframe ɳºÐÖеIJ»Í×ʵʩ | δ֪ |
CVE-2022-3075 | Chromium£ºCVE-2022-3075 Mojo ÖеÄÊý¾ÝÑéÖ¤²»×ã | δ֪ |
CVE-2022-3058 | Chromium£ºCVE-2022-3058 ÔڵǼÁ÷³ÌÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-3038 | Chromium£ºCVE-2022-3038 ÔÚÍøÂç·þÎñÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-3056 | Chromium£ºCVE-2022-3056 ÄÚÈÝÄþ¾²¼ÆÄ±ÖеļÆÄ±Ö´Ðв»×ã | δ֪ |
CVE-2022-3055 | Chromium£ºCVE-2022-3055 ÔÚÃÜÂëÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-38012 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐЩ¶´ | µÍΣ |
0x02 ´¦Öý¨Òé
Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows update¸üÐÂ
×Ô¶¯¸üУº
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£
ÊÖ¶¯¸üУº
1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£
£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
9ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2022-Sep
²¹¶¡ÏÂÔØÊ¾Àý£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£
Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£
0x03 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2022-Sep
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2022-patch-tuesday-fixes-zero-day-used-in-attacks-63-flaws/
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2022-09-14 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
¶«Éƽ̨¼ò½é
¶«Éƽ̨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«Éƽ̨´óÏ㬹«Ë¾Ô±¹¤½ü4000ÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶«Éƽ̨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£
¹Ø×¢ÒÔϹ«Öںţ¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º