¡¾·ì϶¹«¸æ¡¿Î¢Èí9Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2022-09-140x00 ·ì϶¸ÅÊö
2022Äê9ÔÂ13ÈÕ£¬Î¢Èí°ä²¼ÁË9Ô°²È«¸üУ¬±¾´Î¸üн¨¸´ÁËÔ̺¬2¸ö0 day·ì϶ÔÚÄÚµÄ63¸ö°²È«·ì϶£¨²»Ô̺¬Ö®Ç°½¨¸´µÄ16¸öMicrosoft Edge·ì϶£©£¬ÆäÖÐÓÐ5¸ö·ì϶ÆÀ¼¶Îª¡°ÑϳÁ¡±¡£
0x01 ·ì϶ÏêÇé
±¾´Î°ä²¼µÄ°²È«¸üÐÂÉæ¼°.NET Framework¡¢HTTP.sys¡¢Microsoft Office¡¢Microsoft Dynamics¡¢Windows Defender¡¢Windows Group Policy¡¢Windows IKE Extension¡¢Windows Kerberos¡¢Windows Kernel¡¢Windows LDAP¡¢Windows Print Spooler Components¡¢Windows Remote Access Connection Manager¡¢Windows Remote Procedure CallºÍWindows TCP/IPµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£
±¾´Î½¨¸´µÄ63¸ö·ì϶ÖУ¬18¸öΪÌáÈ¡·ì϶£¬30¸öΪԶ³Ì´úÂëÖ´Ðзì϶£¬7¸öΪÐÅϢй¶·ì϶£¬7¸öΪ»Ø¾ø·þÎñ·ì϶£¬1¸öΪ°²È«Ö°ÄÜÈÆ¹ý·ì϶¡£
΢Èí±¾´Î¹²½¨¸´ÁË2¸ö0 day·ì϶£¬ÆäÖÐCVE-2022-37969ÒÑ·¢ÏÖ±»»ý¼«ÀûÓãº
CVE-2022-37969 £ºWindows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶
Windows Common Log File System Driver´æÔÚ±¾µØÌáȨ·ì϶£¬´Ë·ì϶µÄCVSSÆÀ·ÖΪ7.8£¬¿ÉÔÚÓÐȨ½Ó¼ûÖ¸±êϵͳ²¢¿ÉÄÜÔÚÖ¸±êϵͳÉÏÔËÐдúÂëµÄÇé¿öÏÂÀûÓô˷ì϶»ñµÃϵͳȨÏÞ¡£´Ë·ì϶ÒѾ¹«¿ªÅû¶£¬ÇÒÒÑ·¢ÏÖ·ì϶ÀûÓá£
CVE-2022-23960£º»º´æ´§Ä¦ÏÞ¶È·ì϶£¨Arm£©
ijЩ Arm Cortex ºÍ Neoverse ´¦ÖÃÆ÷²»»áÕýÈ·ÏÞ¶È»º´æ´§Ä¦£¬¼´ Spectre-BHB£¬³É¹¦ÀûÓô˷ì϶¿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢй¶¡£´Ë·ì϶ӰÏìÁË»ùÓÚARM64ϵͳµÄWindows 11£¬Ä¿Ç°ÒѾ¹«¿ªÅû¶¡£
±¾´Î¸üÐÂÖÐÖµµÃ¹Ø×¢µÄ·ì϶Ô̺¬µ«²»ÏÞÓÚ£º
CVE-2022-34718 £ºWindows TCP/IP Ô¶³Ì´úÂëÖ´Ðзì϶
¿ÉÔÚδ¾Éí·ÝÑéÖ¤µÄÇé¿öϽ«ÌØÔìµÄIPv6Êý¾Ý°ü·¢Ë͵½ÆôÓÃÁË IPSec µÄ Windows ½Úµã£¬Õâ¿ÉÄÜ»áÔÚ¸ÃÍÆËã»úÉϵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Ö»ÓÐÔËÐÐ IPSec ·þÎñµÄϵͳ²ÅÈÝÒ×Êܵ½¹¥»÷£¬ÈôÊÇÔÚÖ¸±ê»úеÉϽûÓÃÁË IPv6£¬Ôòϵͳ²»»áÊܵ½Ó°Ïì¡£´Ë·ì϶µÄCVSSv3ÆÀ·ÖΪ9.8£¬¹¥»÷¸´ÔӶȵͣ¬ÎÞÐèÌØÊâȨÏÞºÍÓû§½»»¥¼´¿ÉÔ¶³ÌÀûÓô˷ì϶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°¿ÉÄܱ»ÀûÓᱡ£
CVE-2022-34721¡¢CVE-2022-34722 £ºWindows Internet Key Exchange (IKE) Protocol ExtensionsÔ¶³Ì´úÂëÖ´Ðзì϶
Õâ2¸ö·ì϶µÄCVSSv3ÆÀ·Ö¾ùΪ9.8£¬¿ÉÔÚδ¾Éí·ÝÑéÖ¤µÄÇé¿öϽ«ÌØÔìµÄIP Êý¾Ý°ü·¢Ë͵½ÔËÐÐ Windows ²¢ÆôÓÃÁË IPSec µÄÖ¸±êÍÆËã»ú£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£´Ë·ì϶½öÓ°Ïì IKEv1£¬IKEv2 ²»ÊÜÓ°Ï죬µ«´Ë·ì϶ӰÏìÁËËùÓÐWindows Server£¬ÓÉÓÚËüÃÇͬʱ½ÓÊÜ V1 ºÍ V2 Êý¾Ý°ü¡£
CVE-2022-35805¡¢CVE-2022-34700£ºMicrosoft Dynamics CRM (on-premises)Ô¶³Ì´úÂëÖ´Ðзì϶
¾¹ýÉí·ÝÑéÖ¤µÄÓû§Äܹ»ÔËÐÐÌØÔìµÄÊÜÐÅÀµ½â¾ö¹æ»®°üÀ´Ö´ÐÐËÁÒâ SQL ºÅÁÄܹ»ÊµÏÖÉý¼¶²¢ÔÚÆä Dynamics 365 Êý¾Ý¿âÖÐÒÔ db_owner Éí·ÝÖ´ÐкÅÁÕâ2¸ö·ì϶µÄCVSSv3ÆÀ·Ö¾ùΪ8.8¡£
CVE-2022-38009£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶
´Ë·ì϶µÄCVSSv3ÆÀ·ÖΪ8.8£¬¹¥»÷¸´ÔӶȺÍËùÐèȨÏ޵ͣ¬ÎÞÐèÓû§½»»¥¼´¿ÉÔ¶³ÌÀûÓ㬵«ÀûÓô˷ì϶±ØÐëͨ¹ýÖ¸±êÍøÕ¾µÄÉí·ÝÑéÖ¤£¬²¢ÓÐȨÔÚ SharePoint ÖÐʹÓÃÖÎÀíÁÐ±í£¬³É¹¦ÀûÓô˷ì϶Äܹ»ÔÚSharePoint Server ÉÏÔ¶³ÌÖ´ÐдúÂë¡£
CVE-2022-26929£º.NET Framework Ô¶³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8£¬ÀûÓô˷ì϶ÐèÓëÓû§½»»¥¡£
΢Èí9Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑϳÁÐÔ |
CVE-2022-35805 | Microsoft Dynamics CRM£¨±¾µØ£©Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-34700 | Microsoft Dynamics CRM£¨±¾µØ£©Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-34722 | Windows Internet ÃÜÔ¿»¥»» (IKE) ºÍ̸À©´óÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-34721 | Windows Internet ÃÜÔ¿»¥»» (IKE) ºÍ̸À©´óÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-34718 | Windows TCP/IP Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-38013 | .NET Core ºÍ Visual Studio »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-26929 | .NET Framework Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-38007 | Azure À´±öÅäÖÃºÍÆôÓà Azure Arc µÄ·þÎñÆ÷ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-23960 | Arm£ºCVE-2022-23960 »º´æ´§Ä¦ÏÞ¶È·ì϶ | ¸ßΣ |
CVE-2022-35838 | HTTP V3 »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-37954 | DirectX ͼÐÎÄÚºËÌáȨ·ì϶ | ¸ßΣ |
CVE-2022-38006 | Windows ͼÐÎ×é¼þÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-34729 | Windows GDI ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-34728 | Windows ͼÐÎ×é¼þÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-35837 | Windows ͼÐÎ×é¼þÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-37962 | Microsoft PowerPoint Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35823 | Microsoft SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-38009 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-38008 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-37961 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-37963 | Microsoft Office Visio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-38010 | Microsoft Office Visio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-34725 | Windows ALPC ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-38011 | Raw Image Extension Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-38019 | AV1 Video ExtensionÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-37959 | ÍøÂçÉ豸ע²á·þÎñ (NDES) °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2022-34724 | Windows DNS ·þÎñÆ÷»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-38004 | Windows ´«Õæ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-37958 | SPNEGO À©´óÐÉÌ (NEGOEX) °²È«»úÔìÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-38020 | Visual Studio Code ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35803 | Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37969 | Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-30170 | Windows Í´´¦ÖÜÓηþÎñÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35828 | Microsoft Defender for Endpoint for Mac ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-34719 | Windows É¢²¼Ê½Îļþϵͳ (DFS) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-34723 | Windows DPAPI£¨Êý¾Ý±£»¤ÀûÓ÷¨Ê½±à³Ì½Ó¿Ú£©ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-35841 | WindowsÆóÒµÀûÓÃÖÎÀí·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35832 | Windows ÊÂÎñ¸ú×ٻؾø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-37955 | Windows ×éÕ½ÊõÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-34720 | Windows Internet ÃÜÔ¿»¥»» (IKE) À©´ó»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-33647 | Windows Kerberos ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-33679 | Windows Kerberos ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37964 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37956 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37957 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-30200 | Windows ÇáÁ¿¼¶Ä¿Â¼½Ó¼ûºÍ̸ (LDAP) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-34726 | Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-34730 | Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-34727 | Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-34732 | Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-34734 | Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35834 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35835 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35836 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35840 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-34733 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-34731 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-26928 | Windows ÕÕÆ¬µ¼Èë API ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-38005 | Windows Print SpoolerÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-35831 | Windows Ô¶³Ì½Ó¼ûÁ¬ÊÕÊÜÀíÆ÷ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-35830 | Remote Procedure Call Runtime Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-35833 | Windows °²È«Í¨Â·»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-30196 | Windows °²È«Í¨Â·»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-3053 | Chromium£ºCVE-2022-3053 Ö¸ÕëËøÖеIJ»µ±ÊµÏÖ | δ֪ |
CVE-2022-3047 | Chromium£ºCVE-2022-3047 À©´ó API ÖеÄÕ½ÊõÖ´Ðв»¼° | δ֪ |
CVE-2022-3054 | Chromium£ºCVE-2022-3054 DevTools ÖеÄÕ½ÊõÖ´Ðв»¼° | δ֪ |
CVE-2022-3041 | Chromium£ºCVE-2022-3041 ÔÚ WebSQL ÖпªÊͺóʹÓà | δ֪ |
CVE-2022-3040 | Chromium£ºCVE-2022-3040 ÔÚ²¼¾ÖÖпªÊͺóʹÓà | δ֪ |
CVE-2022-3046 | Chromium£ºCVE-2022-3046 ÔÚä¯ÀÀÆ÷±êÇ©ÖпªÊͺóʹÓà | δ֪ |
CVE-2022-3039 | Chromium£ºCVE-2022-3039 ÔÚ WebSQL ÖпªÊͺóʹÓà | δ֪ |
CVE-2022-3045 | Chromium£ºCVE-2022-3045 V8 Öв»ÊÜÐÅÀµµÄÊäÈëÑéÖ¤²»¼° | δ֪ |
CVE-2022-3044 | Chromium£ºCVE-2022-3044 Õ¾µã¸ôÀëÖеIJ»µ±Ö´ÐÐ | δ֪ |
CVE-2022-3057 | Chromium£ºCVE-2022-3057 iframe ɳºÐÖеIJ»µ±Ö´ÐÐ | δ֪ |
CVE-2022-3075 | Chromium£ºCVE-2022-3075 Mojo ÖеÄÊý¾ÝÑéÖ¤²»¼° | δ֪ |
CVE-2022-3058 | Chromium£ºCVE-2022-3058 ÔڵǼÁ÷³ÌÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-3038 | Chromium£ºCVE-2022-3038 ÔÚÍøÂç·þÎñÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-3056 | Chromium£ºCVE-2022-3056 ÄÚÈݰ²È«Õ½ÊõÖеÄÕ½ÊõÖ´Ðв»¼° | δ֪ |
CVE-2022-3055 | Chromium£ºCVE-2022-3055 ÔÚÃÜÂëÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-38012 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´Ðзì϶ | µÍΣ |
0x02 ´ëÖý¨Òé
Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£
£¨Ò»£© Windows update¸üÐÂ
×Ô¶¯¸üУº
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£
ÊÖ¶¯¸üУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ½«×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
9Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2022-Sep
²¹¶¡ÏÂÔØÊ¾Àý£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2Ô£©
2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£
0x03 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2022-Sep
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2022-patch-tuesday-fixes-zero-day-used-in-attacks-63-flaws/
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2022-09-14 | ³õ´Î°ä²¼ |
0x05 ¸½Â¼
GA»Æ½ð¼×¼ò½é
GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤½ü4000ÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£
¹ØÓÚGA»Æ½ð¼×
GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÖØÒªÕë¶Ô³ÁÒª°²È«·ì϶µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвµý±¨ºÍ°²È«»ã±¨¡£
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñȡȫÇò×îа²È«×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ