¡¾·ì϶¹«¸æ¡¿Î¢Èí8Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2022-08-100x00 ·ì϶¸ÅÊö
2022Äê8ÔÂ9ÈÕ£¬Î¢Èí°ä²¼ÁË8Ô°²È«¸üУ¬±¾´Î°ä²¼µÄ°²È«¸üн¨¸´ÁËÔ̺¬2¸ö0 day·ì϶ÔÚÄÚµÄ121¸ö°²È«·ì϶£¨²»Ô̺¬20¸öMicrosoft Edge·ì϶£©£¬ÆäÖÐÓÐ17¸ö·ì϶ÆÀ¼¶Îª¡°ÑϳÁ¡±¡£
0x01 ·ì϶ÏêÇé
±¾´Î°ä²¼µÄ°²È«¸üÐÂÉæ¼°Active Directory Domain Services¡¢Azure ¡¢Microsoft Exchange Server¡¢Microsoft Office¡¢Microsoft MSDT¡¢Windows Kerberos¡¢Windows Kernel¡¢Windows Internet Information Services¡¢Windows Network File System¡¢Windows Secure Socket Tunneling Protocol (SSTP)ºÍWindows Win32KµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£
±¾´Î½¨¸´µÄ121¸ö·ì϶ÖУ¬64¸öΪÌáÈ¡·ì϶£¬31¸öΪԶ³Ì´úÂëÖ´Ðзì϶£¬12¸öΪÐÅϢй¶·ì϶£¬7¸öΪ»Ø¾ø·þÎñ·ì϶£¬6¸öΪ°²È«Ö°ÄÜÈÆ¹ý·ì϶£¬ÒÔ¼°1¸öºýŪ·ì϶¡£
΢Èí±¾´Î¹²½¨¸´ÁË2¸ö0 day·ì϶£¬ÆäÖÐCVE-2022-34713£¨DogWalk·ì϶£©ÒÑ·¢ÏÖ±»»ý¼«ÀûÓãº
CVE-2022-34713£ºMicrosoft MSDTÔ¶³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶λÓÚMicrosoft Windows Ö§³ÖÕï¶Ï¹¤¾ß (MSDT) ÖУ¬ÆäCVSSÆÀ·ÖΪ7.8£¬¹¥»÷¸´ÔӶȵÍÇÒÎÞÐèÌØÊâȨÏÞ£¬µ«ÐèÓëÓû§½»»¥ÄÜÁ¦±¾µØÀûÓ᣸÷ì϶ĿǰÒѾ¹«¿ªÅû¶£¬ÇÒÒѾ¼ì²âµ½·ì϶ÀûÓá£
CVE-2022-30134 £ºMicrosoft Exchange ÐÅϢй¶·ì϶
¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.6£¬¹¥»÷¸´ÔӶȺÍËùÐèȨÏ޵ͣ¬ÎÞÐèÓû§½»»¥¼´¿ÉÔ¶³ÌÀûÓ㬳ɹ¦ÀûÓø÷ì϶Äܹ»¶Áȡָ±êµç×ÓÓʼþ¡£Ä¿Ç°¸Ã·ì϶ÒѾ¹«¿ªÅû¶£¬Î¢ÈíÒѾ°ä²¼Á˸÷ì϶µÄ°²È«¸üУ¬µ«ÊÜÓ°ÏìÓû§»¹ÐèÆôÓÃExchange ServerµÄWindows À©´ó±£»¤ÒÔ·À»¤´Ë·ì϶¡£
±¾´Î½¨¸´µÄ·ì϶ÖУ¬ÆÀ¼¶ÎªÑϳÁµÄ17¸ö·ì϶Ô̺¬£º
l CVE-2022-34691£ºActive Directory Óò·þÎñÌØÈ¨ÌáÉý·ì϶£º¾¹ýÉí·ÝÑéÖ¤µÄÓû§Äܹ»°Ñ³ÖÆäÕ¼ÓлòÖÎÀíµÄÍÆËã»úÕÊ»§µÄÊôÐÔ£¬²¢´Ó Active Directory Ö¤Êé·þÎñ»ñȡ֤Ê飬´Ó¶øÔÊÐíÌáÉýϵͳȨÏÞ¡£Ö»Óе± Active Directory Ö¤Êé·þÎñÔÚÓòÉÏÔËÐÐʱ£¬ÏµÍ³²ÅÈÝÒ×Êܵ½¹¥»÷¡£
l CVE-2022-33646£ºAzure Batch ½Úµã´úÀíÌØÈ¨ÌáÉý·ì϶
l CVE-2022-21980£ºMicrosoft Exchange Server ÌØÈ¨ÌáÉý·ì϶
l CVE-2022-24516£ºMicrosoft Exchange Server ÌØÈ¨ÌáÉý·ì϶
l CVE-2022-24477£ºMicrosoft Exchange Server ÌØÈ¨ÌáÉý·ì϶
l CVE-2022-35752£ºWindows SSTPÔ¶³Ì´úÂëÖ´Ðзì϶
l CVE-2022-35753£ºWindows SSTPÔ¶³Ì´úÂëÖ´Ðзì϶
l CVE-2022-34696£ºWindows Hyper-V Ô¶³Ì´úÂëÖ´Ðзì϶
l CVE-2022-35804£ºSMB ¿Í»§¶ËºÍ·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶
l CVE-2022-30133£ºWindows µã¶ÔµãºÍ̸ (PPP) Ô¶³Ì´úÂëÖ´Ðзì϶
l CVE-2022-35744£ºWindows µã¶ÔµãºÍ̸ (PPP) Ô¶³Ì´úÂëÖ´Ðзì϶£ºÖ»ÄÜͨ¹ý¶Ë¿Ú 1723 ͨѶÀ´ÀûÓÃCVE-2022-30133ºÍCVE-2022-35744£¬Äܹ»Í¨¹ý½ûÓÃ¶Ë¿Ú 1723×÷Ϊһʱ»º½â´ëÊ©£¬µ«Õâ¿ÉÄÜ»áÓ°ÏìÍøÂçÉϵÄͨѶ¡£
l CVE-2022-35745£ºWindows SSTPÔ¶³Ì´úÂëÖ´Ðзì϶
l CVE-2022-35766£ºWindows SSTPÔ¶³Ì´úÂëÖ´Ðзì϶
l CVE-2022-35794£ºWindows SSTPÔ¶³Ì´úÂëÖ´Ðзì϶£º³É¹¦ÀûÓô˷ì϶±ØÒªÓ®µÃ¾ºÕùǰÌᣬÄܹ»ÔÚδ¾Éí·ÝÑéÖ¤µÄÇé¿öÏÂÏò RAS ·þÎñÆ÷·¢ËÍÌØÔìµÄÏνÓÒªÇó£¬Õâ¿ÉÄܵ¼Ö RAS ·þÎñÆ÷ÍÆËã»úÉϵÄÔ¶³Ì´úÂëÖ´ÐÐ (RCE)¡£
l CVE-2022-34714£ºWindows SSTPÔ¶³Ì´úÂëÖ´Ðзì϶
l CVE-2022-34702£ºWindows SSTPÔ¶³Ì´úÂëÖ´Ðзì϶
l CVE-2022-35767£ºWindows SSTPÔ¶³Ì´úÂëÖ´Ðзì϶
΢Èí8Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑϳÁÐÔ |
CVE-2022-34716 | .NET ºýŪ·ì϶ | ¸ßΣ |
CVE-2022-34691 | Active Directory Óò·þÎñÌØÈ¨ÌáÉý·ì϶ | ÑϳÁ |
CVE-2022-33646 | Azure Batch ½Úµã´úÀíÌØÈ¨ÌáÉý·ì϶ | ÑϳÁ |
CVE-2022-34685 | Azure RTOS GUIX Studio ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-34686 | Azure RTOS GUIX Studio ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-35773 | Azure RTOS GUIX Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35779 | Azure RTOS GUIX Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35806 | Azure RTOS GUIX Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-34687 | Azure RTOS GUIX Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-30176 | Azure RTOS GUIX Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-30175 | Azure RTOS GUIX Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35791 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35818 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35809 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35789 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35815 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35817 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35816 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35814 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35785 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35812 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35811 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35784 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35810 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35813 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35788 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35783 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35786 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35787 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35819 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35781 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35775 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35790 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35780 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35799 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35772 | Azure Site Recovery Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35800 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35774 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35802 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35782 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35824 | Azure Site Recovery Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35801 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35808 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35776 | Azure Site Recovery »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-35807 | Azure Site Recovery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35821 | Azure Sphere ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-35760 | Microsoft ATA ¶Ë¿ÚÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35820 | Windows À¶ÑÀÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-34692 | Microsoft Exchange ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-21980 | Microsoft Exchange Server ÌØÈ¨ÌáÉý·ì϶ | ÑϳÁ |
CVE-2022-21979 | Microsoft Exchange ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-24516 | Microsoft Exchange Server ÌØÈ¨ÌáÉý·ì϶ | ÑϳÁ |
CVE-2022-30134 | Microsoft Exchange ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-24477 | Microsoft Exchange Server ÌØÈ¨ÌáÉý·ì϶ | ÑϳÁ |
CVE-2022-34717 | Microsoft Office Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-33648 | Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-33631 | Microsoft Excel °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2022-35742 | Microsoft Outlook »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-34713 | Microsoft Windows Ö§³ÖÕï¶Ï¹¤¾ß (MSDT) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35743 | Microsoft Windows Ö§³ÖÕï¶Ï¹¤¾ß (MSDT) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35752 | Windows SSTPÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-35753 | Windows SSTPÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-35769 | Windows µã¶ÔµãºÍ̸ (PPP) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-34690 | Windows ´«Õæ·þÎñÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-34696 | Windows Hyper-V Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-35751 | Windows Hyper-V ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-33640 | System Center Operations Manager£ºÊ¢¿ªÊ½ÖÎÀí»ù´¡¼Ü¹¹ (OMI) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35827 | Visual Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35777 | Visual Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35825 | Visual Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35826 | Visual Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-30144 | WindowsÀ¶ÑÀ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35750 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35757 | Windows Cloud Files Mini Filter Çý¶¯·¨Ê½ÌáȨ·ì϶ | ¸ßΣ |
CVE-2022-35771 | Windows Defender Credential Guard ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-34705 | Windows Defender Credential Guard ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-34710 | Windows Defender Credential Guard ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-34709 | Windows Defender Credential Guard °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2022-34704 | Windows Defender Credential Guard ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-34712 | Windows Defender Credential Guard ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-35746 | Windows Êý×ÖýÌå½Ó¹ÜÆ÷ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35749 | Windows Êý×ÖýÌå½Ó¹ÜÆ÷ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35795 | Windows ÃýÎó»ã±¨·þÎñÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35797 | Windows Hello °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2022-35748 | HTTP.sys »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-35756 | Windows Kerberos ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35761 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35768 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-34708 | Windows ÄÚºËÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-34707 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35804 | SMB ¿Í»§¶ËºÍ·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-30197 | Windows ÄÚºËÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-35758 | Windows ÄÚºËÄÚ´æÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-34706 | Windows ±¾µØ°²È«»ú¹¹ (LSA) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35759 | Windows ±¾µØ°²È«»ú¹¹ (LSA) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-34715 | Windows ÍøÂçÎļþϵͳԶ³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-33670 | Windows ·ÖÇøÖÎÀíÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-34703 | Windows ·ÖÇøÖÎÀíÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-30133 | Windows µã¶ÔµãºÍ̸ (PPP) Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-35747 | Windows µã¶ÔµãºÍ̸ (PPP) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-35744 | Windows µã¶ÔµãºÍ̸ (PPP) Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-35793 | Windows ºó¶Ü´òÓ¡·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35755 | Windows ºó¶Ü´òÓ¡·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-34301 | CERT/CC£ºCVE-2022-34301 Eurosoft Êèµ¼¼ÓÔØ·¨Ê½Èƹý | ¸ßΣ |
CVE-2022-34302 | CERT/CC£ºCVE-2022-34302 New Horizon Data Systems Inc Êèµ¼¼ÓÔØ·¨Ê½Èƹý | ¸ßΣ |
CVE-2022-34303 | CERT/CC£ºCVE-20220-34303 Crypto Pro Êèµ¼¼ÓÔØ·¨Ê½Èƹý | ¸ßΣ |
CVE-2022-35745 | Windows SSTPÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-35766 | Windows SSTPÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-35794 | Windows SSTPÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-34701 | Windows SSTP»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-34714 | Windows SSTPÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-34702 | Windows SSTPÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-35767 | Windows SSTPÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-35762 | ´æ´¢¿Õ¼äÖ±½ÓÌáÉýÌØÈ¨·ì϶ | ¸ßΣ |
CVE-2022-35765 | ´æ´¢¿Õ¼äÖ±½ÓÌáÉýÌØÈ¨·ì϶ | ¸ßΣ |
CVE-2022-35792 | ´æ´¢¿Õ¼äÖ±½ÓÌáÉýÌØÈ¨·ì϶ | ¸ßΣ |
CVE-2022-35763 | ´æ´¢¿Õ¼äÖ±½ÓÌáÉýÌØÈ¨·ì϶ | ¸ßΣ |
CVE-2022-35764 | ´æ´¢¿Õ¼äÖ±½ÓÌáÉýÌØÈ¨·ì϶ | ¸ßΣ |
CVE-2022-35754 | ͳһдÈë¹ýÂËÆ÷ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-30194 | Windows WebBrowser ½ÚÔìÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-34699 | Windows Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35796 | Microsoft Edge£¨»ùÓÚ Chromium£©ÌØÈ¨ÌáÉý·ì϶ | µÍΣ |
CVE-2022-33649 | Microsoft Edge£¨»ùÓÚ Chromium£©°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2022-33636 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´Ðзì϶ | ÖÐΣ |
CVE-2022-2618 | Chromium£ºCVE-2022-2618 ÄÚ²¿½á¹¹Öв»ÊÜÐÅÀµµÄÊäÈëÑéÖ¤²»¼° | δ֪ |
CVE-2022-2616 | Chromium£ºCVE-2022-2616 Extensions API ÖеIJ»µ±ÊµÏÖ | δ֪ |
CVE-2022-2617 | Chromium£ºCVE-2022-2617 ÔÚ Extensions API ÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-2619 | Chromium£ºCVE-2022-2619 ÉèÖÃÖв»ÊÜÐÅÀµµÄÊäÈëÑéÖ¤²»¼° | δ֪ |
CVE-2022-2622 | Chromium£ºCVE-2022-2622 ¶Ô°²È«ä¯ÀÀÖв»ÊÜÐÅÀµµÄÊäÈëµÄÑéÖ¤²»¼° | δ֪ |
CVE-2022-2623 | Chromium£ºCVE-2022-2623 ÔÚÀëÏߺóÃâ·ÑʹÓà | δ֪ |
CVE-2022-2621 | Chromium£ºCVE-2022-2621 ÔÚÀ©´óÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-2615 | Chromium£ºCVE-2022-2615 Cookie ÖеÄÕ½ÊõÖ´Ðв»¼° | δ֪ |
CVE-2022-2604 | Chromium£ºCVE-2022-2604 ÔÚ°²È«ä¯ÀÀÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-2605 | Chromium£ºCVE-2022-2605 ÔÚ Dawn ÖжÁȡԽ½ç | δ֪ |
CVE-2022-2624 | Chromium£ºCVE-2022-2624 PDF ÖеĶѻº³åÇøÒç³ö | δ֪ |
CVE-2022-2603 | Chromium£ºCVE-2022-2603 ÔÚ¶àÖ°ÄÜ¿òÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-2606 | Chromium£ºCVE-2022-2606 ÔÚÍйÜÉ豸 API ÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-2612 | Chromium£ºCVE-2022-2612 ¼üÅÌÊäÈëÖеIJàͨ·ÐÅϢй© | δ֪ |
CVE-2022-2614 | Chromium£ºCVE-2022-2614 ÔڵǼÁ÷³ÌÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-2610 | Chromium£ºCVE-2022-2610 ºó¶ÜÌáÈ¡ÖеÄÕ½ÊõÖ´Ðв»¼° | δ֪ |
CVE-2022-2611 | Chromium£ºCVE-2022-2611 È«ÆÁ API ÖеIJ»Êʵ±ÊµÏÖ | δ֪ |
0x02 ´ëÖý¨Òé
Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£
£¨Ò»£© Windows update¸üÐÂ
×Ô¶¯¸üУº
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£
ÊÖ¶¯¸üУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ½«×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
8Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2022-Aug
²¹¶¡ÏÂÔØÊ¾Àý£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2Ô£©
2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£
0x03 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2022-Aug
https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2022-patch-tuesday-fixes-exploited-zero-day-121-flaws/
https://blog.qualys.com/vulnerabilities-threat-research/2022/08/09/august-2022-patch-tuesday
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2022-08-10 | ³õ´Î°ä²¼ |
0x05 ¸½Â¼
GA»Æ½ð¼×¼ò½é
GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤½ü4000ÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£
¹ØÓÚGA»Æ½ð¼×
GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÖØÒªÕë¶Ô³ÁÒª°²È«·ì϶µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвµý±¨ºÍ°²È«»ã±¨¡£
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñȡȫÇò×îа²È«×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ