Éî¶È·Ö½â΢Èí×îзì϶£¬ÎªÄúÌṩ×îÓŽâ¾ö¹æ»®

°ä²¼¹¦·ò 2022-04-21
ý½é£º

½üÆÚ£¬Î¢Èí°ä²¼ÁË4Ô·ݵݲȫ¸üУ¬½¨¸´ÁËÔ̺¬2¸ö0day·ì϶ÔÚÄÚµÄ119¸ö°²È«·ì϶£¨²»Ô̺¬26¸öMicrosoftEdge·ì϶£©£¬ÆäÖÐÓÐ10¸ö·ì϶±»ÆÀ¼¶ÎªÑϳÁ£¬Éæ¼°.NET Framework¡¢ActiveDirectoryDomainServicesµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡££¨·ì϶ÏêÇéÔÚÎÄÄ©£©


GA»Æ½ð¼×±±Ú¤Êý¾Ý³¢ÊÔסլһ¹¦·ò¶Ô΢Èí4Ô°䲼µÄ°²È«²¼¸æ½øÐзÖÎöÑÐÅУ¬½áºÏÌ©ºÏÅÌ¹ÅÆ½Ì¨£¨THPangu-OS£©µÄµ××ùÄÜÁ¦£¬Îª¿í´óÓû§¸ø³öÓ¦¼±´ëÖÃÖ¸Òý¹æ»®¡£


ÒòÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2022-26809Íþвˮƽ¸ß¡¢Ó°ÏìÁìÓò½Ï¹ã£¬ÀûÓõĸ´ÔӶȵÍ£¬Ò×±»¹¥»÷Õß¿í·ºÀûÓýø¶ø¶Ô¿í´óÓû§Ôì³ÉÑϳÁ·çÏÕ£¬ËùÒÔÎÒÃÇÒÔ´Ë·ìÏ¶Éæ¼°µÄ·þÎñΪÀý£¬×ö³öÁ˽øÒ»²½µÄÏêϸ·ÖÎö¹ý³Ì£¬²¢¾ßÌå×¢Ã÷·ì϶½¨¸´Óë²¹¶¡ÏÂÔØ¡£


·ì϶·ÖÎö


Óйطì϶λÓÚWindowsRPC·þÎñ£¬¸Ã·þÎñÓÉÃûΪrpcrt4.dllµÄ¿â¡£¸ÃÔËÐÐʱ¿â±»¼ÓÔØµ½Ê¹ÓÃRPCºÍ̸½øÐÐͨѶµÄ¿Í»§¶ËºÍ·þÎñÆ÷¹ý³ÌÖС£


ͨ¹ý±ÈÁ¦ÁË10.0.22000.434£¨Î´´ò²¹¶¡£¬´Ó2022Äê3ÔÂÆðÍ·£©ºÍ10.0.22000.613£¨ÒÑ´ò²¹¶¡£¬´Ó2022Äê4ÔÂÆðÍ·£©°æ±¾£¬ÄÜ·¢ÏÖÒÔϸ÷ÀàÖ°ÄÜ»òº¯ÊýµÄ±ä¶¯Çåµ¥¡£


1.jpg

º¯Êý±ä¶¯Çåµ¥


º¯ÊýOSF_CCALL::ProcessResponseºÍOSF_SCALL::ProcessReceivedPDU¡£ÕâÁ½¸öº¯ÊýÐÔÖÊÉÏÊÇÀàËÆµÄ£»Á½Õß¶¼´¦ÖÃRPCÊý¾Ý°ü£¬µ«Ò»¸öÔÚ¿Í»§¶ËÔËÐУ¬ÁíÒ»¸öÔÚ·þÎñÆ÷¶ËÔËÐУ¨CCALLºÍSCALL±ðÀë´ú±í¿Í»§¶ËŲÓúͷþÎñÆ÷ŲÓã©¡£ÎÒÃdzÖÐø±ÈÁ¦OSF_SCALL::ProcessReceivedPDU£¬²¢°ÑÎȵ½Ð°汾ÖÐÔö³¤ÁËÁ½¸ö´úÂë¿é¡£


2.jpg

3.jpg

¶Ô±ÈÐÂÔö´úÂë¿é


²é¿´½¨¸´´úÂ룬ÎÒÃÇ¿´µ½ÔÚQUEUE::PutOnQueueÖ®ºóŲÓÃÁËÒ»¸öк¯Êý¡£½øÈëк¯Êý²¢²é³­Æä´úÂ룬ÎÒÃÇ·¢ÏÖËüÓÃÓڲ鳭ÕûÊýÒç³ö¡£¼´Ôö³¤ÁËк¯ÊýÒÔÑéÖ¤ÕûÊý±äÁ¿ÊÇ·ñά³ÖÔÚÔ¤ÆÚÖµÁìÓòÄÚ¡£


4.jpg

½¨¸´´úÂë


Éî¿Ì½âÎö


OSF_SCALL:GetCoalescedBufferÖеÄÒ×Êܹ¥»÷´úÂ룬ÎÒÃǰÑÎȵ½ÕûÊýÒç³öÃýÎó¿ÉÄܵ¼Ö¶ѻº³åÇøÒç³ö£¬ÓÉÓÚÆäÖÐÊý¾Ý±»¸´Ô쵽̫Ó×¶øÎÞ·¨Ìî³ä¡£·´¹ýÀ´£¬ÕâÔÊÐí½«Êý¾ÝдÈë¶ÑÉϵĻº³åÇøÌìǵ֮±í¡£ÈôÊÇÀûÓÃÇе±£¬Õâ¸öÔ­Óï¿ÉÄܻᵼÖÂÔ¶³Ì´úÂëÖ´ÐС£


ÔÚÆäËûº¯ÊýÖÐÒ²Ôö³¤ÁËÀàËÆµÄ²é³­ÕûÊýÒç³öµÄŲÓãº


OSF_CCALL::ProcessResponse

OSF_SCALL::GetCoalescedBuffer

OSF_CCALL::GetCoalescedBuffer


²Î¿¼Á´½Ó£º

https://www.akamai.com/blog/security/critical-remote-code-execution-vulnerabilities-windows-rpc-runtime  



·ì϶¼ì²â


GA»Æ½ð¼×Ìì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳÒÑ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐÐÊÚȨɨÃ裬Óû§Éý¼¶³ß¶È·ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃ裺


6070°æ±¾Éý¼¶°üΪ607000428£¬Éý¼¶°üÏÂÔØµØÖ·£º

https://venustech.download.venuscloud.cn/


1.png

2.jpg

3.jpg

4.jpg

5.jpg

Éý¼¶ºóÒÑÖ§³Ö¸Ã·ì϶


ÇëʹÓÃÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬ÊµÊ±¶Ô¸Ã·ì϶½øÐмì²â£¬ÒԱ㾡¿ì²ÉÈ¡·À±¸´ëÊ©¡£


»ùÏߺ˲é


GA»Æ½ð¼×°²È«ÅäÖú˲éÖÎÀíϵͳÒÑ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄºË²é×ÊÔ´°ü£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐк˲飬Óû§Éý¼¶°²È«ÅäÖú˲éÖÎÀíϵͳ×ÊÔ´°üºó¼´¿É¶Ô¸Ã·ì϶½øÐк˲飺


6.jpg

»ùÏߺ˲é


½¨¸´½¨Òé


Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£


×Ô¶¯¸üÐÂ


MicrosoftUpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£


ÊÖ¶¯¸üÐÂ


µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖᱡ£


Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows8¡¢Windows8.1¡¢WindowsServer2012ÒÔ¼°WindowsServer2012R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©¡£


Ñ¡Ôñ¡°²é³­¸üС±£¬ÆÚ´ýϵͳ½«×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüС£


³ÁÆôÍÆËã»ú£¬×°ÖøüÐÂϵͳ³ÁÐÂÆô¶¯ºó£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£


Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2022-Apr


²¹¶¡ÏÂÔØÊ¾Àý


1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£


7.jpg

΢Èí·ì϶ÁаµÊ¾Àý


2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£


8.jpg

²¹¶¡ÏÂÔØÁ´½Ó


3.µã»÷¡¾SecurityUpdate¡¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡£¬ÏÂÔØÊµÏÖºóË«»÷×°Öá£


9.jpg

²¹¶¡ÏÂÔØ



Ó×ÌùÊ¿£º


·ì϶ÏêÇé


±¾´Î½¨¸´µÄ119¸ö·ì϶ÖУ¬47¸öΪȨÏÞÌáÉý·ì϶£¬47¸öΪԶ³Ì´úÂëÖ´Ðзì϶£¬13¸öΪÐÅϢй¶·ì϶£¬9¸öΪ»Ø¾ø·þÎñ·ì϶£¬ÒÔ¼°3¸öºýŪ·ì϶¡£1£©Î¢Èí±¾´Î¹²½¨¸´ÁË2¸ö0day·ì϶£¬ÆäÖÐCVE-2022-24521ÔÚ±»»ý¼«ÀûÓã¬CVE-2022-26904ÒѾ­¹«¿ªÅû¶¡£?CVE-2022-26904£ºWindowsÓû§ÅäÖÃÎļþ·þÎñȨÏÞÌáÉý·ì϶¸Ã·ì϶ÊÇWindowsUserProfileServiceÖеı¾µØÈ¨ÏÞÌáÉý·ì϶£¬CVSSÆÀ·ÖΪ7.0£¬ËùÐèȨÏÞµÍÇÒÎÞÐèÓû§½»»¥£¬µ«¹¥»÷¸´ÔӶȸߣ¨±ØÒªÓ®µÃ¾ºÕùǰÌᣩ£¬Ä¿Ç°´Ë·ì϶ÒѾ­¹«¿ªÅû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔ½«ÆäÆÀ¹ÀΪ¿ÉÄܱ»ÀûÓá£?CVE-2022-24521£ºWindowsͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½È¨ÏÞÌáÉý·ì϶¸Ã·ì϶µÄ¹¥»÷¸´ÔӶȺÍËùÐèȨÏ޵ͣ¬ÎÞÐèÓû§½»»¥¼´¿É±»±¾µØÀûÓá£Î¢Èí°µÊ¾ÒѼì²âµ½Õë¶Ô´Ë·ì϶µÄ·ì϶ÀûÓá£2£©±¾´Î½¨¸´µÄ10¸öÑϳÁ·ì϶Ô̺¬£º?CVE-2022-26919£ºWindowsLDAPÔ¶³Ì´úÂëÖ´Ðзì϶ÔÚÓòÖÐͨ¹ýÉí·ÝÑéÖ¤µÄ³ß¶ÈÓû§¿ÉÄÜÀûÓô˷ì϶ÔÚLDAP·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£µ«ÒªÀûÓô˷ì϶£¬±ØÒªÅú¸ÄĬÈϵÄMaxReceiveBufferLDAPÉèÖá£?CVE-2022-23259£ºMicrosoftDynamics365(on-premises)Ô¶³Ì´úÂëÖ´Ðзì϶¾­¹ýÉí·ÝÑéÖ¤µÄÓû§Äܹ»ÔËÐÐÌØÔìµÄÊÜÐÅÀµ½â¾ö¹æ»®°üÀ´Ö´ÐÐËÁÒâSQLºÅÁî¡£¹¥»÷ÕßÄܹ»´ÓÄÇÀïÉý¼¶²¢ÔÚÆäDynamics356Êý¾Ý¿âÖÐÒÔdb_ownerÉí·ÝÖ´ÐкÅÁî¡£?CVE-2022-22008/CVE-2022-24537/CVE-2022-2325£ºWindowsHyper-VÔ¶³ÌÖ´ÐдúÂë·ì϶Äܹ»ÔÚHyper-VguestÉÏÔËÐÐÌØÔìµÄÀûÓ÷¨Ê½£¬Õâ¿ÉÄܵ¼ÖÂÔÚHyper-VÖ÷»úϵͳִÐÐËÁÒâ´úÂë¡£?CVE-2022-24491/CVE-2022-24497£ºWindowsNetworkFileSystemÔ¶³Ì´úÂëÖ´Ðзì϶¹¥»÷ÕßÄܹ»½«ÌØÔìµÄNFSºÍÌ¸ÍøÂçÐÂÎÅ·¢Ë͵½Ò×Êܹ¥»÷µÄWindows»úе£¬´Ó¶øÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£°ÑÎÈ£º´Ë·ì϶½öÓ°ÏìÆôÓÃNFS½ÇÉ«µÄϵͳ¡£?CVE-2022-26809£ºRemoteProcedureCallRuntimeÔ¶³Ì´úÂëÖ´Ðзì϶´Ë·ì϶µÄCVSSv3ÆÀ·ÖΪ9.8¡£Äܹ»Í¨¹ýÏòRPCÖ÷»ú·¢ËÍÒ»¸öÌØÔìµÄRPCŲÓã¬Õâ¿ÉÄܵ¼ÖÂÔÚ·þÎñÆ÷¶ËÒÔÓëRPC·þÎñÒ»ÑùµÄȨÏÞÔ¶³ÌÖ´ÐдúÂë¡£Äܹ»Í¨¹ýÔÚÆóÒµ±íΧ·À»ðǽÖÐ×èÖ¹TCP¶Ë¿Ú445ºÍ×ñÑ­MicrosoftÖ¸ÄÏÒÔ±£»¤SMBÁ÷Á¿À´»º½â´Ë·ì϶¡£ÊÜÓ°ÏìµÄ²úÆ·¼°°æ±¾£ºWindows 7 for 32¡¢Windows Server 2016  (Server Core installation)¡¢Windows 11 for ARM64¡¢Windows Server, version20H2 (Server Core Installation)¡¢Windows 10 Version 20H2for ARM64¡¢Windows 10 Version 1909 for ARM64¡¢Windows 10 Version 1809 for x64¡¢Windows 10for 32¡¢Windows 10 Version 21H2 for x64¡¢Windows 10 Version 21H2 for ARM64¡¢Windows 10Version 21H2 for 32¡¢Windows 10 Version 1809 for 32¡¢Windows Server 2022 (Server Core installation)¡¢Windows Server 2022¡¢Windows 10 Version 21H1for 32¡¢Windows 10 Version 21H1 for ARM64¡¢Windows 10 Version 21H1 for x64¡¢WindowsServer 2012 R2 (Server Core installation)¡¢WindowsServer 2012 R2¡¢Windows Server 2012 (Server Coreinstallation)¡¢Windows Server 2012¡¢Windows Server 2008 R2 for x64¡¢WindowsServer 2008 R2 for x64¡¢Windows 10 Version 20H2 for 32¡¢Windows 10 Version 20H2 for x64¡¢WindowsServer 2008 for x64¡¢Windows Server 2016¡¢Windows 10 Version 1607 for x64¡¢Windows 10Version 1607 for 32¡¢Windows 10 for x64¡¢Windows 10 Version 1909 for x64¡¢Windows 10Version 1909 for 32¡¢Windows 10 Version 1809 for ARM64¡¢Windows Server 2008 for x64¡¢Windows Server2008 for 32¡¢Windows 8.1 for 32¡¢Windows7 for x64¡¢Windows Server 2008 for 32¡¢Windows RT 8.1¡¢Windows 8.1 for x64¡¢Windows 11 for x64¡¢Windows Server 2019 (Server Core installation)¡¢Windows Server 2019µÈ¡£?CVE-2022-24541£ºWindowsServer·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶´Ë·ì϶ҪÇóʹÓÃÊÜÓ°ÏìµÄWindows°æ±¾µÄÓû§½Ó¼û¶ñÒâ·þÎñÆ÷¡£Äܹ»Í¨¹ýÔÚÆóÒµ±íΧ·À»ðǽÖÐ×èÖ¹TCP¶Ë¿Ú445ºÍ×ñÑ­MicrosoftÖ¸ÄÏÒÔ±£»¤SMBÁ÷Á¿À´»º½â´Ë·ì϶¡£?CVE-2022-24500£ºWindowsSMBÔ¶³Ì´úÂëÖ´Ðзì϶´Ë·ì϶ҪÇóʹÓÃÊÜÓ°ÏìµÄWindows°æ±¾µÄÓû§½Ó¼û¶ñÒâ·þÎñÆ÷¡£Äܹ»Í¨¹ýÔÚÆóÒµ±íΧ·À»ðǽÖÐ×èÖ¹TCP¶Ë¿Ú445ºÍ×ñÑ­MicrosoftÖ¸ÄÏÒÔ±£»¤SMBÁ÷Á¿À´»º½â´Ë·ì϶¡£


±±Ú¤Êý¾Ý³¢ÊÔÊÒ


±±Ú¤Êý¾Ý³¢ÊÔÊÒ³ÉÁ¢ÓÚ2022Äê3Ô£¬ÖÂÁ¦ÓÚÍøÂç¿Õ¼ä°²È«ÖªÊ¶¹¤³Ì×êÑкÍϵͳ»¯½¨ÉèµÄרҵÍŶÓ£¬ÓÉGA»Æ½ð¼×¼¯ÍÅÌì¾µ·ì϶×êÑÐÍŶӡ¢Ì©ºÏ֪ʶ¹¤³ÌÍŶӡ¢´óÊý¾Ý³¢ÊÔÊÒ£¨BDlab£©³¡¾°»¯·ÖÎöÍŶӽáºÏ×é³É¡£


±±Ú¤Êý¾Ý³¢ÊÔÊÒʼÖÕ±ü³ÖÒÔÐèҪΪµ¼Ïò¡¢ÖªÊ¶¸³ÄܲúÆ·µÄÖ÷ÌâÀíÏ룬רһÓÚÌá¹©ÍøÂç¿Õ¼ä°²È«µÄ»ù´¡ÖªÊ¶×êÑкͿª·¢£¬Ôì¶©½áºÏÍþвºÍ·ì϶µý±¨¡¢ÍøÂç¿Õ¼ä×ʲúºÍÔÆ°²È«¼à²âÊý¾ÝµÈ×ۺϵý±¨ÒÔ¼°Óû§ÏÖʵ³¡¾°µÄ°²È«·ÖÎö·À»¤Õ½Êõ£¬¹¹½¨×Ô¶¯»¯µ÷²éºÍ´ëÖÃÏìÓ¦´ëÊ©£¬Ðγɳ¡¾°»¯¡¢½á¹¹»¯µÄ֪ʶ¹¤³Ìϵͳ£¬¶Ô¸÷Àలȫ²úÆ·¡¢Æ½Ì¨ºÍ°²È«ÔËÓªÌṩ֪ʶ¸³ÄÜ¡£