¡¾Îó²îͨ¸æ¡¿Î¢Èí9Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2022-09-140x00 Îó²î¸ÅÊö
2022Äê9ÔÂ13ÈÕ£¬£¬£¬£¬Î¢ÈíÐû²¼ÁË9ÔÂÇå¾²¸üУ¬£¬£¬£¬±¾´Î¸üÐÂÐÞ¸´Á˰üÀ¨2¸ö0 dayÎó²îÔÚÄÚµÄ63¸öÇå¾²Îó²î£¨²»°üÀ¨Ö®Ç°ÐÞ¸´µÄ16¸öMicrosoft EdgeÎó²î£©£¬£¬£¬£¬ÆäÖÐÓÐ5¸öÎó²îÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé
±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÉæ¼°.NET Framework¡¢HTTP.sys¡¢Microsoft Office¡¢Microsoft Dynamics¡¢Windows Defender¡¢Windows Group Policy¡¢Windows IKE Extension¡¢Windows Kerberos¡¢Windows Kernel¡¢Windows LDAP¡¢Windows Print Spooler Components¡¢Windows Remote Access Connection Manager¡¢Windows Remote Procedure CallºÍWindows TCP/IPµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£¡£
±¾´ÎÐÞ¸´µÄ63¸öÎó²îÖУ¬£¬£¬£¬18¸öΪÌáÈ¡Îó²î£¬£¬£¬£¬30¸öΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬7¸öΪÐÅϢй¶Îó²î£¬£¬£¬£¬7¸öΪ¾Ü¾øÐ§ÀÍÎó²î£¬£¬£¬£¬1¸öΪÇå¾²¹¦Ð§ÈƹýÎó²î¡£¡£¡£¡£¡£
΢Èí±¾´Î¹²ÐÞ¸´ÁË2¸ö0 dayÎó²î£¬£¬£¬£¬ÆäÖÐCVE-2022-37969ÒÑ·¢Ã÷±»Æð¾¢Ê¹Óãº
CVE-2022-37969 £ºWindows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î
Windows Common Log File System Driver±£´æÍâµØÌáȨÎó²î£¬£¬£¬£¬´ËÎó²îµÄCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬¿ÉÔÚÓÐȨ»á¼ûÄ¿µÄϵͳ²¢Äܹ»ÔÚÄ¿µÄϵͳÉÏÔËÐдúÂëµÄÇéÐÎÏÂʹÓôËÎó²î»ñµÃϵͳȨÏÞ¡£¡£¡£¡£¡£´ËÎó²îÒѾ¹ûÕæÅû¶£¬£¬£¬£¬ÇÒÒÑ·¢Ã÷Îó²îʹÓᣡ£¡£¡£¡£
CVE-2022-23960£º»º´æÍƲâÏÞÖÆÎó²î£¨Arm£©
ijЩ Arm Cortex ºÍ Neoverse ´¦Öóͷ£Æ÷²»»á׼ȷÏÞÖÆ»º´æÍƲ⣬£¬£¬£¬¼´ Spectre-BHB£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£´ËÎó²îÓ°ÏìÁË»ùÓÚARM64ϵͳµÄWindows 11£¬£¬£¬£¬ÏÖÔÚÒѾ¹ûÕæÅû¶¡£¡£¡£¡£¡£
±¾´Î¸üÐÂÖÐÖµµÃ¹Ø×¢µÄÎó²î°üÀ¨µ«²»ÏÞÓÚ£º
CVE-2022-34718 £ºWindows TCP/IP Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¿ÉÔÚδ¾Éí·ÝÑéÖ¤µÄÇéÐÎϽ«ÌØÖƵÄIPv6Êý¾Ý°ü·¢Ë͵½ÆôÓÃÁË IPSec µÄ Windows ½Úµã£¬£¬£¬£¬Õâ¿ÉÄÜ»áÔÚ¸ÃÅÌËã»úÉϵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£Ö»ÓÐÔËÐÐ IPSec ЧÀ͵Äϵͳ²ÅÈÝÒ×Êܵ½¹¥»÷£¬£¬£¬£¬ÈôÊÇÔÚÄ¿µÄ»úеÉϽûÓÃÁË IPv6£¬£¬£¬£¬Ôòϵͳ²»»áÊܵ½Ó°Ïì¡£¡£¡£¡£¡£´ËÎó²îµÄCVSSv3ÆÀ·ÖΪ9.8£¬£¬£¬£¬¹¥»÷ÖØÆ¯ºóµÍ£¬£¬£¬£¬ÎÞÐèÌØÊâȨÏÞºÍÓû§½»»¥¼´¿ÉÔ¶³ÌʹÓôËÎó²î£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°¿ÉÄܱ»Ê¹Óᱡ£¡£¡£¡£¡£
CVE-2022-34721¡¢CVE-2022-34722 £ºWindows Internet Key Exchange (IKE) Protocol ExtensionsÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Õâ2¸öÎó²îµÄCVSSv3ÆÀ·Ö¾ùΪ9.8£¬£¬£¬£¬¿ÉÔÚδ¾Éí·ÝÑéÖ¤µÄÇéÐÎϽ«ÌØÖƵÄIP Êý¾Ý°ü·¢Ë͵½ÔËÐÐ Windows ²¢ÆôÓÃÁË IPSec µÄÄ¿µÄÅÌËã»ú£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£´ËÎó²î½öÓ°Ïì IKEv1£¬£¬£¬£¬IKEv2 ²»ÊÜÓ°Ï죬£¬£¬£¬µ«´ËÎó²îÓ°ÏìÁËËùÓÐWindows Server£¬£¬£¬£¬ÓÉÓÚËüÃÇͬʱ½ÓÊÜ V1 ºÍ V2 Êý¾Ý°ü¡£¡£¡£¡£¡£
CVE-2022-35805¡¢CVE-2022-34700£ºMicrosoft Dynamics CRM (on-premises)Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¾ÓÉÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔÔËÐÐÌØÖÆµÄÊÜÐÅÈνâ¾ö¼Æ»®°üÀ´Ö´ÐÐí§Òâ SQL ÏÂÁ£¬£¬£¬¿ÉÒÔʵÏÖÉý¼¶²¢ÔÚÆä Dynamics 365 Êý¾Ý¿âÖÐÒÔ db_owner Éí·ÝÖ´ÐÐÏÂÁ£¬£¬£¬Õâ2¸öÎó²îµÄCVSSv3ÆÀ·Ö¾ùΪ8.8¡£¡£¡£¡£¡£
CVE-2022-38009£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î
´ËÎó²îµÄCVSSv3ÆÀ·ÖΪ8.8£¬£¬£¬£¬¹¥»÷ÖØÆ¯ºóºÍËùÐèȨÏ޵ͣ¬£¬£¬£¬ÎÞÐèÓû§½»»¥¼´¿ÉÔ¶³ÌʹÓ㬣¬£¬£¬µ«Ê¹ÓôËÎó²î±ØÐèͨ¹ýÄ¿µÄÍøÕ¾µÄÉí·ÝÑéÖ¤£¬£¬£¬£¬²¢ÓÐȨÔÚ SharePoint ÖÐʹÓÃÖÎÀíÁÐ±í£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÒÔÔÚSharePoint Server ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£
CVE-2022-26929£º.NET Framework Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬Ê¹ÓôËÎó²îÐèÓëÓû§½»»¥¡£¡£¡£¡£¡£
΢Èí9Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º
CVE ID | CVE ÎÊÌâ | ÑÏÖØÐÔ |
CVE-2022-35805 | Microsoft Dynamics CRM£¨ÍâµØ£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2022-34700 | Microsoft Dynamics CRM£¨ÍâµØ£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2022-34722 | Windows Internet ÃÜÔ¿½»Á÷ (IKE) ÐÒéÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2022-34721 | Windows Internet ÃÜÔ¿½»Á÷ (IKE) ÐÒéÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2022-34718 | Windows TCP/IP Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2022-38013 | .NET Core ºÍ Visual Studio ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2022-26929 | .NET Framework Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-38007 | Azure À´±öÉèÖÃºÍÆôÓà Azure Arc µÄЧÀÍÆ÷ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-23960 | Arm£ºCVE-2022-23960 »º´æÍƲâÏÞÖÆÎó²î | ¸ßΣ |
CVE-2022-35838 | HTTP V3 ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2022-37954 | DirectX ͼÐÎÄÚºËÌáȨÎó²î | ¸ßΣ |
CVE-2022-38006 | Windows ͼÐÎ×é¼þÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-34729 | Windows GDI ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-34728 | Windows ͼÐÎ×é¼þÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-35837 | Windows ͼÐÎ×é¼þÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-37962 | Microsoft PowerPoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35823 | Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-38009 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-38008 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-37961 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-37963 | Microsoft Office Visio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-38010 | Microsoft Office Visio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-34725 | Windows ALPC ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-38011 | Raw Image Extension Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-38019 | AV1 Video ExtensionÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-37959 | ÍøÂç×°±¸×¢²áЧÀÍ (NDES) Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2022-34724 | Windows DNS ЧÀÍÆ÷¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2022-38004 | Windows ´«ÕæÐ§ÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-37958 | SPNEGO À©Õ¹ÐÉÌ (NEGOEX) Çå¾²»úÖÆÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-38020 | Visual Studio Code ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35803 | Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-37969 | Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-30170 | Windows ƾ֤ÖÜÓÎЧÀÍÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35828 | Microsoft Defender for Endpoint for Mac ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-34719 | Windows ÂþÑÜʽÎļþϵͳ (DFS) ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-34723 | Windows DPAPI£¨Êý¾Ý±£»£»£»£»¤Ó¦ÓóÌÐò±à³Ì½Ó¿Ú£©ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-35841 | WindowsÆóÒµÓ¦ÓÃÖÎÀíЧÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35832 | Windows ÊÂÎñ¸ú×پܾøÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2022-37955 | Windows ×éÕ½ÂÔÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-34720 | Windows Internet ÃÜÔ¿½»Á÷ (IKE) À©Õ¹¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2022-33647 | Windows Kerberos ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-33679 | Windows Kerberos ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-37964 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-37956 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-37957 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-30200 | Windows ÇáÁ¿¼¶Ä¿Â¼»á¼ûÐÒé (LDAP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-34726 | Microsoft ODBC Çý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-34730 | Microsoft ODBC Çý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-34727 | Microsoft ODBC Çý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-34732 | Microsoft ODBC Çý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-34734 | Microsoft ODBC Çý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35834 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35835 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35836 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35840 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-34733 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-34731 | Microsoft OLE DB Provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-26928 | Windows ÕÕÆ¬µ¼Èë API ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-38005 | Windows Print SpoolerÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2022-35831 | Windows Ô¶³Ì»á¼ûÅþÁ¬ÖÎÀíÆ÷ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2022-35830 | Remote Procedure Call Runtime Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2022-35833 | Windows Ç徲ͨµÀ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2022-30196 | Windows Ç徲ͨµÀ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2022-3053 | Chromium£ºCVE-2022-3053 Ö¸ÕëËøÖеIJ»µ±ÊµÏÖ | δ֪ |
CVE-2022-3047 | Chromium£ºCVE-2022-3047 À©Õ¹ API ÖеÄÕ½ÂÔÖ´ÐÐȱ·¦ | δ֪ |
CVE-2022-3054 | Chromium£ºCVE-2022-3054 DevTools ÖеÄÕ½ÂÔÖ´ÐÐȱ·¦ | δ֪ |
CVE-2022-3041 | Chromium£ºCVE-2022-3041 ÔÚ WebSQL ÖÐÊͷźóʹÓà | δ֪ |
CVE-2022-3040 | Chromium£ºCVE-2022-3040 ÔڽṹÖÐÊͷźóʹÓà | δ֪ |
CVE-2022-3046 | Chromium£ºCVE-2022-3046 ÔÚä¯ÀÀÆ÷±êÇ©ÖÐÊͷźóʹÓà | δ֪ |
CVE-2022-3039 | Chromium£ºCVE-2022-3039 ÔÚ WebSQL ÖÐÊͷźóʹÓà | δ֪ |
CVE-2022-3045 | Chromium£ºCVE-2022-3045 V8 Öв»ÊÜÐÅÈεÄÊäÈëÑé֤ȱ·¦ | δ֪ |
CVE-2022-3044 | Chromium£ºCVE-2022-3044 Õ¾µã¸ôÀëÖеIJ»µ±ÊµÑé | δ֪ |
CVE-2022-3057 | Chromium£ºCVE-2022-3057 iframe ɳºÐÖеIJ»µ±ÊµÑé | δ֪ |
CVE-2022-3075 | Chromium£ºCVE-2022-3075 Mojo ÖеÄÊý¾ÝÑé֤ȱ·¦ | δ֪ |
CVE-2022-3058 | Chromium£ºCVE-2022-3058 ÔڵǼÁ÷³ÌÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-3038 | Chromium£ºCVE-2022-3038 ÔÚÍøÂçЧÀÍÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-3056 | Chromium£ºCVE-2022-3056 ÄÚÈÝÇå¾²Õ½ÂÔÖеÄÕ½ÂÔÖ´ÐÐȱ·¦ | δ֪ |
CVE-2022-3055 | Chromium£ºCVE-2022-3055 ÔÚÃÜÂëÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-38012 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î | µÍΣ |
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£¡£
£¨Ò»£© Windows update¸üÐÂ
×Ô¶¯¸üУº
Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£
ÊÖ¶¯¸üУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£
4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£
9ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2022-Sep
²¹¶¡ÏÂÔØÊ¾Àý£º
1.·¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£¡£¡£¡£¡£

Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾Çå¾²¸üС¿£¬£¬£¬£¬·¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öᣡ£¡£¡£¡£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2022-Sep
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2022-patch-tuesday-fixes-zero-day-used-in-attacks-63-flaws/
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2022-09-14 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
c7c7ÓéÀÖÆ½Ì¨¼ò½é
c7c7ÓéÀÖÆ½Ì¨½¨ÉèÓÚ1996Ä꣬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°c7c7ÓéÀÖÆ½Ì¨´óÏ㬣¬£¬£¬¹«Ë¾Ô±¹¤½ü4000ÈË£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£
¹ØÓÚc7c7ÓéÀÖÆ½Ì¨
c7c7ÓéÀÖÆ½Ì¨Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ