¡¾Â©¶´Í¨¸æ¡¿Î¢Èí10Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2022-10-120x00 ©¶´¸ÅÊö
2022Äê10ÔÂ11ÈÕ£¬Î¢ÈíÐû²¼ÁË10ÔÂÄþ¾²¸üУ¬±¾´Î¸üÐÂÐÞ¸´ÁË°üÂÞ2¸ö0 day©¶´ÔÚÄÚµÄ84¸öÄþ¾²Â©¶´£¨²»°üÂÞ10ÔÂ3ÈÕÐÞ¸´µÄ12¸öMicrosoft Edge©¶´£©£¬ÆäÖÐÓÐ13¸ö©¶´ÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£´ËÍ⣬Microsoft Exchange ProxyNotShell©¶´ÉÐδÐÞ¸´¡£
0x01 ©¶´ÏêÇé
±¾´ÎÐû²¼µÄÄþ¾²¸üÐÂÉæ¼°Active Directory Domain Services¡¢Azure¡¢Microsoft Office¡¢Microsoft Office SharePoint¡¢Windows Hyper-V¡¢Visual Studio Code¡¢Windows Active Directory Certificate Services¡¢Windows Defender¡¢Windows DHCP Client¡¢Windows Group Policy¡¢Windows Kernel¡¢Windows NTFS¡¢Windows NTLM¡¢Windows Point-to-Point Tunneling Protocol¡¢Windows TCP/IPºÍWindows Win32KµÈ¶à¸ö²úÎïºÍ×é¼þ¡£
±¾´ÎÐÞ¸´µÄ84¸ö©¶´ÖУ¬39¸öΪÌáȡ©¶´£¬20¸öΪԶ³Ì´úÂëÖ´ÐЩ¶´£¬11¸öΪÐÅϢ鶩¶´£¬8¸öΪ¾Ü¾ø·þÎñ©¶´£¬2¸öΪÄþ¾²¹¦Ð§Èƹý©¶´£¬ÒÔ¼°4¸öÆÛÆ©¶´¡£
΢Èí±¾´Î¹²ÐÞ¸´ÁË2¸ö0 day©¶´£¬ÆäÖÐCVE-2022-41033ÒÑ·¢ÏÖ±»»ý¼«ÀûÓã¬CVE-2022-41043ÒѾ¹ûÈ»Åû¶¡£
CVE-2022-41033£ºWindows COM+ Event System ServiceÌØȨÌáÉý©¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.8£¬ÀÖ³ÉÀûÓø鶴¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£Ä¿Ç°¸Ã©¶´ÔÝδ¹ûÈ»Åû¶£¬µ«ÒѾ¼ì²âµ½Â©¶´ÀûÓá£
CVE-2022-41043£ºMicrosoft Office ÐÅϢ鶩¶´
¸Ã©¶´Ó°ÏìÁËÊÊÓÃÓÚ Mac 2021 µÄ Microsoft Office LTSCºÍÊÊÓÃÓÚ Mac µÄ Microsoft Office 2019£¬ÆäCVSSv3ÆÀ·ÖΪ3.3£¬ÀÖ³ÉÀûÓø鶴¿ÉÄܻᵼÖÂÓû§ÁîÅÆ»òÆäËüÃô¸ÐÐÅÏ¢±»Ð¹Â¶¡£Ä¿Ç°¸Ã©¶´ÔÝδ¼ì²âµ½Â©¶´ÀûÓ㬵«ÒѾ±»¹ûÈ»Åû¶¡£
΢ÈíÉÐδÔÚ±¾´Î¸üÐÂÖÐÐÞ¸´Microsoft Exchange ProxyNotShell©¶´CVE-2022-41040£¨ÌØȨÌáÉý£©ºÍCVE-2022-41082£¨Ô¶³Ì´úÂëÖ´ÐУ©£¬µ«ÒѾÐû²¼ÁËÏà¹ØÄþ¾²Ö¸ÄÏ£¬Óû§¿ÉÓ¦ÓÃÖ¸ÄÏÖеĻº½â´ëÊ©²¢ÆÚ´ý¹Ù·½²¹¶¡Ðû²¼¡£
±¾´Î¸üÐÂÖÐÖµµÃ¹Ø×¢µÄ©¶´°üÂÞµ«²»ÏÞÓÚ£º
CVE-2022-37968£ºÆôÓà Azure Arc µÄ Kubernetes ¼¯ÈºÁ¬½ÓÌØȨÌáÉý©¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ10.0£¬Ó°ÏìÁËÆôÓà Azure Arc µÄ Kubernetes ¼¯ÈºµÄ¼¯ÈºÁ¬½Ó¹¦Ð§£¬¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÓû§ÌáÉýÆäȨÏÞ²¢¿ÉÄÜ»ñµÃ¶Ô Kubernetes ¼¯ÈºµÄ¹ÜÀí¿ØÖÆȨ¡£´ËÍ⣬ÓÉÓÚ Azure Stack Edge ÔÊÐí¿Í»§Í¨¹ý Azure Arc ÔÚÆäÉ豸Éϲ¿Êð Kubernetes ÊÂÇ鸺ÔØ£¬Òò´Ë Azure Stack Edge É豸ҲÈÝÒ×Êܵ½¸Ã©¶´µÄÓ°Ïì¡£
CVE-2022-37976£ºActive Directory Ö¤Êé·þÎñÌØȨÌáÉý©¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬Ö»Óе± Active Directory Ö¤Êé·þÎñÔÚÓòÉÏÔËÐÐʱ£¬ÏµÍ³²ÅÈÝÒ×Êܵ½¹¥»÷£¬ÀÖ³ÉÀûÓôË©¶´¿ÉÒÔ»ñµÃÓò¹ÜÀíԱȨÏÞ¡£¸Ã©¶´Ó°ÏìÁ˶à¸öWindows Server°æ±¾£¬ÊÜÓ°ÏìÓû§¿É¼°Ê±°²×°¸üС£
CVE-2022-41038£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬Í¨¹ýÄ¿±êÍøÕ¾µÄÉí·ÝÑéÖ¤²¢ÓÐȨÔÚ SharePoint ÖÐʹÓùÜÀíÁбíµÄÓû§¿ÉÒÔÔÚ SharePoint Server ÉÏÔ¶³ÌÖ´ÐдúÂë¡£
CVE-2022-38048£ºMicrosoft Office Ô¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.8£¬ÀûÓø鶴ÐèÓëÓû§½»»¥¡£¸Ã©¶´Ó°ÏìÁ˶à¸ö°æ±¾µÄMicrosoft Office 2013¡¢Microsoft Office 2016¡¢Microsoft Office 2019¡¢Microsoft Office LTSCºÍMicrosoft 365 ÆóÒµÓ¦Óá£
΢Èí10Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑÏÖØÐÔ |
CVE-2022-37968 | ÆôÓà Azure Arc µÄ Kubernetes ¼¯ÈºÁ¬½ÓÌØȨÌáÉý©¶´ | ÑÏÖØ |
CVE-2022-38048 | Microsoft Office Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2022-41038 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2022-37979 | Windows Hyper-V ÌØȨÌáÉý©¶´ | ÑÏÖØ |
CVE-2022-37976 | Active Directory Ö¤Êé·þÎñÌØȨÌáÉý©¶´ | ÑÏÖØ |
CVE-2022-34689 | Windows CryptoAPI ÆÛÆ©¶´ | ÑÏÖØ |
CVE-2022-33634 | Windows µã¶ÔµãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2022-22035 | Windows µã¶ÔµãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2022-24504 | Windows µã¶ÔµãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2022-38047 | Windows µã¶ÔµãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2022-41081 | Windows µã¶ÔµãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2022-30198 | Windows µã¶ÔµãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2022-38000 | Windows µã¶ÔµãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2022-38042 | Active Directory Óò·þÎñÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-38017 | StorSimple 8000 ϵÁÐÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37987 | Windows ¿Í»§¶Ë·þÎñÆ÷ÔËÐÐʱ×Óϵͳ (CSRSS) ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37989 | Windows ¿Í»§¶Ë·þÎñÆ÷ÔËÐÐʱ×Óϵͳ (CSRSS) ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37986 | Windows Win32k ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-38051 | Windows ͼÐÎ×é¼þÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37997 | Windows ͼÐÎ×é¼þÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37985 | Windows ͼÐÎ×é¼þÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2022-33635 | Windows GDI+ Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-38001 | Microsoft Office ÆÛÆ©¶´ | ¸ßΣ |
CVE-2022-41043 | Microsoft Office ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2022-38053 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-41036 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-41037 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-41031 | Microsoft Word Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-38049 | Microsoft Office Graphics Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-37982 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-38031 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-41032 | NuGet ¿Í»§¶ËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37965 | Windows µã¶ÔµãËíµÀÐÒé¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2022-35829 | Service Fabric Explorer ÆÛÆ©¶´ | ¸ßΣ |
CVE-2022-41042 | Visual Studio Code ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2022-41034 | Visual Studio Code Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-41083 | Visual Studio Code ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37978 | Windows Active Directory Ö¤Êé·þÎñÄþ¾²¹¦Ð§Èƹý | ¸ßΣ |
CVE-2022-38029 | Windows ALPC ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-38044 | Windows CD-ROM ÎļþϵͳÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-41033 | Windows COM+ ʼþϵͳ·þÎñÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-38021 | Connected User Experiences and TelemetryÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37971 | Microsoft Windows Defender ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-38026 | Windows DHCP ¿Í»§¶ËÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2022-37980 | Windows DHCP ¿Í»§¶ËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-38025 | Windows ÂþÑÜʽÎļþϵͳ (DFS) ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2022-37970 | Windows DWM ºËÐÄ¿âÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37983 | Microsoft DWM ºËÐÄ¿âÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37981 | Windows ʼþÈÕÖ¾¼Ç¼·þÎñ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2022-37975 | Windows ×é¼ÆıÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37994 | Windows ×é¼ÆıÊ×Ñ¡Ïî¿Í»§¶ËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37993 | Windows ×é¼ÆıÊ×Ñ¡Ïî¿Í»§¶ËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37999 | Windows ×é¼ÆıÊ×Ñ¡Ïî¿Í»§¶ËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-38036 | Internet ÃÜÔ¿½»»» (IKE) ÐÒé¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2022-37988 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-38037 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37990 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-38038 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-38039 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37995 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37991 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-38022 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-38016 | Windows µ±µØÄþ¾²»ú¹¹ (LSA) ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37977 | µ±µØÄþ¾²»ú¹¹×Óϵͳ·þÎñ (LSASS) ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2022-37973 | Windows µ±µØ»á»°¹ÜÀíÆ÷ (LSM) ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2022-37998 | Windows µ±µØ»á»°¹ÜÀíÆ÷ (LSM) ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2022-37996 | Windows ÄÚºËÄÚ´æÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2022-35770 | Windows NTLM ÆÛÆ©¶´ | ¸ßΣ |
CVE-2022-38040 | Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2022-37974 | Windows Mixed Reality ¿ª·¢Õß¹¤¾ßÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2022-38032 | Windows ±ãЯʽÉ豸ö¾ÙÆ÷·þÎñÄþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2022-38028 | Windows ºǫ́´òÓ¡·¨Ê½ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-38003 | Windows µ¯ÐÔÎļþϵͳÌØȨÌáÉý | ¸ßΣ |
CVE-2022-38041 | Windows Äþ¾²Í¨µÀ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2022-38043 | Windows Äþ¾²Ö§³ÖÌṩ·¨Ê½½Ó¿ÚÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2022-38033 | Windows Server ¿ÉÔ¶³Ì·ÃÎʵÄ×¢²á±íÏîÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2022-38045 | Server Service Remote ProtocolÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-38027 | Windows ´æ´¢ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-33645 | Windows TCP/IP Çý¶¯·¨Ê½¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2022-38030 | Windows USB ´®ÐÐÇý¶¯·¨Ê½ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2022-38046 | Web Account ManagerÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2022-38050 | Win32k ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-37984 | Windows WLAN Service ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-38034 | Windows Workstation ServiceÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2022-41035 | Microsoft Edge£¨»ùÓÚ Chromium£©ÆÛÆ©¶´ | ÖÐΣ |
CVE-2022-3311 | Chromium£ºCVE-2022-3311 ÔÚµ¼ÈëºóÃâ·ÑʹÓà | δ֪ |
CVE-2022-3313 | Chromium£ºCVE-2022-3313 È«ÆÁÏÔʾ²»ÕýÈ·µÄÄþ¾² UI | δ֪ |
CVE-2022-3315 | Chromium£ºCVE-2022-3315 Blink ÖеÄÀàÐÍ»ìÏý | δ֪ |
CVE-2022-3370 | Chromium£ºCVE-2022-3370 ÔÚ×Ô½ç˵ԪËØÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-3373 | Chromium£ºCVE-2022-3373 ÔÚV8ÖÐÔ½½çдÈë | δ֪ |
CVE-2022-3316 | Chromium£ºCVE-2022-3316 ¶ÔÄþ¾²ä¯ÀÀÖв»ÊÜÐÅÈεÄÊäÈëµÄÑéÖ¤²»×ã | δ֪ |
CVE-2022-3317 | Chromium£ºCVE-2022-3317 Intents Öв»ÊÜÐÅÈεÄÊäÈëÑéÖ¤²»×ã | δ֪ |
CVE-2022-3310 | Chromium£ºCVE-2022-3310 ×Ô½ç˵ѡÏÖеļÆıִÐв»×ã | δ֪ |
CVE-2022-3304 | Chromium£ºCVE-2022-3304 ÔÚ CSS ÖÐÃâ·ÑºóʹÓà | δ֪ |
CVE-2022-3308 | Chromium£ºCVE-2022-3308 ¿ª·¢ÈËÔ±¹¤¾ßÖеļÆıִÐв»×ã | δ֪ |
CVE-2022-3307 | Chromium£ºCVE-2022-3307 ÔÚýÌåÖÐÃâ·ÑºóʹÓà | δ֪ |
0x02 ´¦Öý¨Òé
Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows update¸üÐÂ
×Ô¶¯¸üУº
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£
ÊÖ¶¯¸üУº
1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔز¢°²×°¡£
£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
10ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2022-Oct
²¹¶¡ÏÂÔØʾÀý£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý
3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£
Àý3£º²¹¶¡ÏÂÔؽçÃæ
4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£
0x03 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2022-Oct
https://www.bleepingcomputer.com/news/microsoft/microsoft-october-2022-patch-tuesday-fixes-zero-day-used-in-attacks-84-flaws/
https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
0x04 °æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2022-10-12 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
¶«Éƽ̨¼ò½é
¶«Éƽ̨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«Éƽ̨´óÏ㬹«Ë¾Ô±¹¤½ü4000ÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶«Éƽ̨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦¡£
¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡È«Çò×îÐÂÄþ¾²×ÊѶ£º