¡¾Â©¶´Í¨¸æ¡¿Î¢Èí10Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2022-10-12

0x00 ©¶´¸ÅÊö

2022Äê10ÔÂ11ÈÕ£¬Î¢ÈíÐû²¼ÁË10ÔÂÄþ¾²¸üУ¬±¾´Î¸üÐÂÐÞ¸´ÁË°üÂÞ2¸ö0 day©¶´ÔÚÄÚµÄ84¸öÄþ¾²Â©¶´£¨²»°üÂÞ10ÔÂ3ÈÕÐÞ¸´µÄ12¸öMicrosoft  Edge©¶´£©£¬ÆäÖÐÓÐ13¸ö©¶´ÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£´ËÍ⣬Microsoft Exchange ProxyNotShell©¶´ÉÐδÐÞ¸´¡£

 

0x01 ©¶´ÏêÇé

±¾´ÎÐû²¼µÄÄþ¾²¸üÐÂÉæ¼°Active Directory Domain Services¡¢Azure¡¢Microsoft Office¡¢Microsoft Office SharePoint¡¢Windows Hyper-V¡¢Visual Studio Code¡¢Windows Active Directory Certificate Services¡¢Windows Defender¡¢Windows DHCP Client¡¢Windows Group Policy¡¢Windows Kernel¡¢Windows NTFS¡¢Windows NTLM¡¢Windows Point-to-Point Tunneling Protocol¡¢Windows TCP/IPºÍWindows Win32KµÈ¶à¸ö²úÎïºÍ×é¼þ¡£

±¾´ÎÐÞ¸´µÄ84¸ö©¶´ÖУ¬39¸öΪÌáȡ©¶´£¬20¸öΪԶ³Ì´úÂëÖ´ÐЩ¶´£¬11¸öΪÐÅϢ鶩¶´£¬8¸öΪ¾Ü¾ø·þÎñ©¶´£¬2¸öΪÄþ¾²¹¦Ð§Èƹý©¶´£¬ÒÔ¼°4¸öÆÛƭ©¶´¡£

΢Èí±¾´Î¹²ÐÞ¸´ÁË2¸ö0 day©¶´£¬ÆäÖÐCVE-2022-41033ÒÑ·¢ÏÖ±»»ý¼«ÀûÓã¬CVE-2022-41043ÒѾ­¹ûÈ»Åû¶¡£

CVE-2022-41033£ºWindows COM+ Event System ServiceÌØȨÌáÉý©¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.8£¬ÀÖ³ÉÀûÓø鶴¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£Ä¿Ç°¸Ã©¶´ÔÝδ¹ûÈ»Åû¶£¬µ«ÒѾ­¼ì²âµ½Â©¶´ÀûÓá£

CVE-2022-41043£ºMicrosoft Office ÐÅϢ鶩¶´

¸Ã©¶´Ó°ÏìÁËÊÊÓÃÓÚ Mac 2021 µÄ Microsoft Office LTSCºÍÊÊÓÃÓÚ Mac µÄ Microsoft Office 2019£¬ÆäCVSSv3ÆÀ·ÖΪ3.3£¬ÀÖ³ÉÀûÓø鶴¿ÉÄܻᵼÖÂÓû§ÁîÅÆ»òÆäËüÃô¸ÐÐÅÏ¢±»Ð¹Â¶¡£Ä¿Ç°¸Ã©¶´ÔÝδ¼ì²âµ½Â©¶´ÀûÓ㬵«ÒѾ­±»¹ûÈ»Åû¶¡£

΢ÈíÉÐδÔÚ±¾´Î¸üÐÂÖÐÐÞ¸´Microsoft Exchange ProxyNotShell©¶´CVE-2022-41040£¨ÌØȨÌáÉý£©ºÍCVE-2022-41082£¨Ô¶³Ì´úÂëÖ´ÐУ©£¬µ«ÒѾ­Ðû²¼ÁËÏà¹ØÄþ¾²Ö¸ÄÏ£¬Óû§¿ÉÓ¦ÓÃÖ¸ÄÏÖеĻº½â´ëÊ©²¢ÆÚ´ý¹Ù·½²¹¶¡Ðû²¼¡£

±¾´Î¸üÐÂÖÐÖµµÃ¹Ø×¢µÄ©¶´°üÂÞµ«²»ÏÞÓÚ£º

CVE-2022-37968£ºÆôÓà Azure Arc µÄ Kubernetes ¼¯ÈºÁ¬½ÓÌØȨÌáÉý©¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ10.0£¬Ó°ÏìÁËÆôÓà Azure Arc µÄ Kubernetes ¼¯ÈºµÄ¼¯ÈºÁ¬½Ó¹¦Ð§£¬¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÓû§ÌáÉýÆäȨÏÞ²¢¿ÉÄÜ»ñµÃ¶Ô Kubernetes ¼¯ÈºµÄ¹ÜÀí¿ØÖÆȨ¡£´ËÍ⣬ÓÉÓÚ Azure Stack Edge ÔÊÐí¿Í»§Í¨¹ý Azure Arc ÔÚÆäÉ豸Éϲ¿Êð Kubernetes ÊÂÇ鸺ÔØ£¬Òò´Ë Azure Stack Edge É豸ҲÈÝÒ×Êܵ½¸Ã©¶´µÄÓ°Ïì¡£

CVE-2022-37976£ºActive Directory Ö¤Êé·þÎñÌØȨÌáÉý©¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬Ö»Óе± Active Directory Ö¤Êé·þÎñÔÚÓòÉÏÔËÐÐʱ£¬ÏµÍ³²ÅÈÝÒ×Êܵ½¹¥»÷£¬ÀÖ³ÉÀûÓôË©¶´¿ÉÒÔ»ñµÃÓò¹ÜÀíԱȨÏÞ¡£¸Ã©¶´Ó°ÏìÁ˶à¸öWindows Server°æ±¾£¬ÊÜÓ°ÏìÓû§¿É¼°Ê±°²×°¸üС£

CVE-2022-41038£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬Í¨¹ýÄ¿±êÍøÕ¾µÄÉí·ÝÑéÖ¤²¢ÓÐȨÔÚ SharePoint ÖÐʹÓùÜÀíÁбíµÄÓû§¿ÉÒÔÔÚ SharePoint Server ÉÏÔ¶³ÌÖ´ÐдúÂë¡£

CVE-2022-38048£ºMicrosoft Office Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.8£¬ÀûÓø鶴ÐèÓëÓû§½»»¥¡£¸Ã©¶´Ó°ÏìÁ˶à¸ö°æ±¾µÄMicrosoft Office 2013¡¢Microsoft Office 2016¡¢Microsoft Office 2019¡¢Microsoft Office LTSCºÍMicrosoft 365 ÆóÒµÓ¦Óá£

΢Èí10Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º

CVE ID

CVE ±êÌâ

ÑÏÖØÐÔ

CVE-2022-37968

ÆôÓà Azure Arc µÄ Kubernetes ¼¯ÈºÁ¬½ÓÌØȨÌáÉý©¶´

ÑÏÖØ

CVE-2022-38048

Microsoft Office Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2022-41038

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2022-37979

Windows Hyper-V ÌØȨÌáÉý©¶´

ÑÏÖØ

CVE-2022-37976

Active Directory Ö¤Êé·þÎñÌØȨÌáÉý©¶´

ÑÏÖØ

CVE-2022-34689

Windows CryptoAPI ÆÛƭ©¶´

ÑÏÖØ

CVE-2022-33634

Windows µã¶ÔµãËíµÀЭÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2022-22035

Windows µã¶ÔµãËíµÀЭÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2022-24504

Windows µã¶ÔµãËíµÀЭÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2022-38047

Windows µã¶ÔµãËíµÀЭÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2022-41081

Windows µã¶ÔµãËíµÀЭÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2022-30198

Windows µã¶ÔµãËíµÀЭÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2022-38000

Windows µã¶ÔµãËíµÀЭÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2022-38042

Active Directory Óò·þÎñÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-38017

StorSimple 8000 ϵÁÐÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37987

Windows ¿Í»§¶Ë·þÎñÆ÷ÔËÐÐʱ×Óϵͳ (CSRSS) ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37989

Windows ¿Í»§¶Ë·þÎñÆ÷ÔËÐÐʱ×Óϵͳ (CSRSS) ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37986

Windows Win32k ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-38051

Windows ͼÐÎ×é¼þÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37997

Windows ͼÐÎ×é¼þÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37985

Windows ͼÐÎ×é¼þÐÅϢ鶩¶´

¸ßΣ

CVE-2022-33635

Windows GDI+ Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2022-38001

Microsoft Office ÆÛƭ©¶´

¸ßΣ

CVE-2022-41043

Microsoft Office ÐÅϢ鶩¶´

¸ßΣ

CVE-2022-38053

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2022-41036

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2022-41037

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2022-41031

Microsoft Word Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2022-38049

Microsoft Office Graphics Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2022-37982

Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2022-38031

Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2022-41032

NuGet ¿Í»§¶ËÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37965

Windows µã¶ÔµãËíµÀЭÒé¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2022-35829

Service Fabric Explorer ÆÛƭ©¶´

¸ßΣ

CVE-2022-41042

Visual Studio Code ÐÅϢ鶩¶´

¸ßΣ

CVE-2022-41034

Visual Studio Code Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2022-41083

Visual Studio Code ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37978

Windows Active Directory Ö¤Êé·þÎñÄþ¾²¹¦Ð§Èƹý

¸ßΣ

CVE-2022-38029

Windows ALPC ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-38044

Windows CD-ROM ÎļþϵͳÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2022-41033

Windows COM+ ʼþϵͳ·þÎñÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-38021

Connected User Experiences and TelemetryÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37971

Microsoft Windows Defender ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-38026

Windows DHCP ¿Í»§¶ËÐÅϢ鶩¶´

¸ßΣ

CVE-2022-37980

Windows DHCP ¿Í»§¶ËÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-38025

Windows ÂþÑÜʽÎļþϵͳ (DFS) ÐÅϢ鶩¶´

¸ßΣ

CVE-2022-37970

Windows DWM ºËÐÄ¿âÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37983

Microsoft DWM ºËÐÄ¿âÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37981

Windows ʼþÈÕÖ¾¼Ç¼·þÎñ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2022-37975

Windows ×é¼ÆıÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37994

Windows ×é¼ÆıÊ×Ñ¡Ïî¿Í»§¶ËÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37993

Windows ×é¼ÆıÊ×Ñ¡Ïî¿Í»§¶ËÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37999

Windows ×é¼ÆıÊ×Ñ¡Ïî¿Í»§¶ËÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-38036

Internet ÃÜÔ¿½»»» (IKE) ЭÒé¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2022-37988

Windows ÄÚºËÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-38037

Windows ÄÚºËÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37990

Windows ÄÚºËÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-38038

Windows ÄÚºËÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-38039

Windows ÄÚºËÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37995

Windows ÄÚºËÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37991

Windows ÄÚºËÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-38022

Windows ÄÚºËÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-38016

Windows µ±µØÄþ¾²»ú¹¹ (LSA) ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37977

µ±µØÄþ¾²»ú¹¹×Óϵͳ·þÎñ (LSASS) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2022-37973

Windows µ±µØ»á»°¹ÜÀíÆ÷ (LSM) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2022-37998

Windows µ±µØ»á»°¹ÜÀíÆ÷ (LSM) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2022-37996

Windows ÄÚºËÄÚ´æÐÅϢ鶩¶´

¸ßΣ

CVE-2022-35770

Windows NTLM ÆÛƭ©¶´

¸ßΣ

CVE-2022-38040

Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2022-37974

Windows Mixed Reality ¿ª·¢Õß¹¤¾ßÐÅϢ鶩¶´

¸ßΣ

CVE-2022-38032

Windows ±ãЯʽÉ豸ö¾ÙÆ÷·þÎñÄþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2022-38028

Windows ºǫ́´òÓ¡·¨Ê½ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-38003

Windows µ¯ÐÔÎļþϵͳÌØȨÌáÉý

¸ßΣ

CVE-2022-38041

Windows Äþ¾²Í¨µÀ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2022-38043

Windows Äþ¾²Ö§³ÖÌṩ·¨Ê½½Ó¿ÚÐÅϢ鶩¶´

¸ßΣ

CVE-2022-38033

Windows Server ¿ÉÔ¶³Ì·ÃÎʵÄ×¢²á±íÏîÐÅϢ鶩¶´

¸ßΣ

CVE-2022-38045

Server Service Remote ProtocolÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-38027

Windows ´æ´¢ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-33645

Windows TCP/IP Çý¶¯·¨Ê½¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2022-38030

Windows USB ´®ÐÐÇý¶¯·¨Ê½ÐÅϢ鶩¶´

¸ßΣ

CVE-2022-38046

Web Account ManagerÐÅϢ鶩¶´

¸ßΣ

CVE-2022-38050

Win32k ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-37984

Windows WLAN Service ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-38034

Windows Workstation ServiceÌØȨÌáÉý©¶´

¸ßΣ

CVE-2022-41035

Microsoft Edge£¨»ùÓÚ Chromium£©ÆÛƭ©¶´

ÖÐΣ

CVE-2022-3311

Chromium£ºCVE-2022-3311 ÔÚµ¼ÈëºóÃâ·ÑʹÓÃ

δ֪

CVE-2022-3313

Chromium£ºCVE-2022-3313 È«ÆÁÏÔʾ²»ÕýÈ·µÄÄþ¾² UI

δ֪

CVE-2022-3315

Chromium£ºCVE-2022-3315 Blink ÖеÄÀàÐÍ»ìÏý

δ֪

CVE-2022-3370

Chromium£ºCVE-2022-3370 ÔÚ×Ô½ç˵ԪËØÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-3373

Chromium£ºCVE-2022-3373  ÔÚV8ÖÐÔ½½çдÈë

δ֪

CVE-2022-3316

Chromium£ºCVE-2022-3316 ¶ÔÄþ¾²ä¯ÀÀÖв»ÊÜÐÅÈεÄÊäÈëµÄÑéÖ¤²»×ã

δ֪

CVE-2022-3317

Chromium£ºCVE-2022-3317 Intents Öв»ÊÜÐÅÈεÄÊäÈëÑéÖ¤²»×ã

δ֪

CVE-2022-3310

Chromium£ºCVE-2022-3310 ×Ô½ç˵ѡÏÖеļÆıִÐв»×ã

δ֪

CVE-2022-3304

Chromium£ºCVE-2022-3304 ÔÚ CSS ÖÐÃâ·ÑºóʹÓÃ

δ֪

CVE-2022-3308

Chromium£ºCVE-2022-3308 ¿ª·¢ÈËÔ±¹¤¾ßÖеļÆıִÐв»×ã

δ֪

CVE-2022-3307

Chromium£ºCVE-2022-3307 ÔÚýÌåÖÐÃâ·ÑºóʹÓÃ

δ֪

 

0x02 ´¦Öý¨Òé

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔز¢°²×°¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

10ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2022-Oct

²¹¶¡ÏÂÔØʾÀý£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý

3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£

image.png

Àý3£º²¹¶¡ÏÂÔؽçÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2022-Oct

https://www.bleepingcomputer.com/news/microsoft/microsoft-october-2022-patch-tuesday-fixes-zero-day-used-in-attacks-84-flaws/

https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-10-12

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏ㬹«Ë¾Ô±¹¤½ü4000ÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦¡£

 

¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£

¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡È«Çò×îÐÂÄþ¾²×ÊѶ£º

image.png