Éî¶È·Ö½â΢Èí×îзì϶£¬£¬£¬£¬£¬£¬£¬ÎªÄúÌṩ×îÓŽâ¾ö¹æ»®
°ä²¼¹¦·ò 2022-04-21½üÆÚ£¬£¬£¬£¬£¬£¬£¬Î¢Èí°ä²¼ÁË4Ô·ݵݲȫ¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËÔ̺¬2¸ö0day·ì϶ÔÚÄÚµÄ119¸ö°²È«·ì϶£¨²»Ô̺¬26¸öMicrosoftEdge·ì϶£©£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ10¸ö·ì϶±»ÆÀ¼¶ÎªÑϳÁ£¬£¬£¬£¬£¬£¬£¬Éæ¼°.NET Framework¡¢ActiveDirectoryDomainServicesµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£¡£¡£¡£¡££¨·ì϶ÏêÇéÔÚÎÄÄ©£©
8827Ì«Ñô¼¯Íű±Ú¤Êý¾Ý³¢ÊÔסլһ¹¦·ò¶Ô΢Èí4Ô°䲼µÄ°²È«²¼¸æ½øÐзÖÎöÑÐÅУ¬£¬£¬£¬£¬£¬£¬½áºÏÌ©ºÏÅÌ¹ÅÆ½Ì¨£¨THPangu-OS£©µÄµ××ùÄÜÁ¦£¬£¬£¬£¬£¬£¬£¬Îª¿í´óÓû§¸ø³öÓ¦¼±´ëÖÃÖ¸Òý¹æ»®¡£¡£¡£¡£¡£¡£¡£¡£
ÒòÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2022-26809Íþвˮƽ¸ß¡¢Ó°ÏìÁìÓò½Ï¹ã£¬£¬£¬£¬£¬£¬£¬ÀûÓõĸ´ÔӶȵͣ¬£¬£¬£¬£¬£¬£¬Ò×±»¹¥»÷Õß¿í·ºÀûÓýø¶ø¶Ô¿í´óÓû§Ôì³ÉÑϳÁ·çÏÕ£¬£¬£¬£¬£¬£¬£¬ËùÒÔÎÒÃÇÒÔ´Ë·ìÏ¶Éæ¼°µÄ·þÎñΪÀý£¬£¬£¬£¬£¬£¬£¬×ö³öÁ˽øÒ»²½µÄÏêϸ·ÖÎö¹ý³Ì£¬£¬£¬£¬£¬£¬£¬²¢¾ßÌå×¢Ã÷·ì϶½¨¸´Óë²¹¶¡ÏÂÔØ¡£¡£¡£¡£¡£¡£¡£¡£
·ì϶·ÖÎö
Óйطì϶λÓÚWindowsRPC·þÎñ£¬£¬£¬£¬£¬£¬£¬¸Ã·þÎñÓÉÃûΪrpcrt4.dllµÄ¿â¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÔËÐÐʱ¿â±»¼ÓÔØµ½Ê¹ÓÃRPCºÍ̸½øÐÐͨѶµÄ¿Í»§¶ËºÍ·þÎñÆ÷¹ý³ÌÖС£¡£¡£¡£¡£¡£¡£¡£
ͨ¹ý±ÈÁ¦ÁË10.0.22000.434£¨Î´´ò²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬´Ó2022Äê3ÔÂÆðÍ·£©ºÍ10.0.22000.613£¨ÒÑ´ò²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬´Ó2022Äê4ÔÂÆðÍ·£©°æ±¾£¬£¬£¬£¬£¬£¬£¬ÄÜ·¢ÏÖÒÔϸ÷ÀàÖ°ÄÜ»òº¯ÊýµÄ±ä¶¯Çåµ¥¡£¡£¡£¡£¡£¡£¡£¡£

º¯Êý±ä¶¯Çåµ¥
º¯ÊýOSF_CCALL::ProcessResponseºÍOSF_SCALL::ProcessReceivedPDU¡£¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸öº¯ÊýÐÔÖÊÉÏÊÇÀàËÆµÄ£»£»£»£»£»£»£»Á½Õß¶¼´¦ÖÃRPCÊý¾Ý°ü£¬£¬£¬£¬£¬£¬£¬µ«Ò»¸öÔÚ¿Í»§¶ËÔËÐУ¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸öÔÚ·þÎñÆ÷¶ËÔËÐУ¨CCALLºÍSCALL±ðÀë´ú±í¿Í»§¶ËŲÓúͷþÎñÆ÷ŲÓã©¡£¡£¡£¡£¡£¡£¡£¡£ÎÒÃdzÖÐø±ÈÁ¦OSF_SCALL::ProcessReceivedPDU£¬£¬£¬£¬£¬£¬£¬²¢°ÑÎȵ½Ð°汾ÖÐÔö³¤ÁËÁ½¸ö´úÂë¿é¡£¡£¡£¡£¡£¡£¡£¡£


¶Ô±ÈÐÂÔö´úÂë¿é
²é¿´½¨¸´´úÂ룬£¬£¬£¬£¬£¬£¬ÎÒÃÇ¿´µ½ÔÚQUEUE::PutOnQueueÖ®ºóŲÓÃÁËÒ»¸öк¯Êý¡£¡£¡£¡£¡£¡£¡£¡£½øÈëк¯Êý²¢²é³Æä´úÂ룬£¬£¬£¬£¬£¬£¬ÎÒÃÇ·¢ÏÖËüÓÃÓÚ²é³ÕûÊýÒç³ö¡£¡£¡£¡£¡£¡£¡£¡£¼´Ôö³¤ÁËк¯ÊýÒÔÑéÖ¤ÕûÊý±äÁ¿ÊÇ·ñά³ÖÔÚÔ¤ÆÚÖµÁìÓòÄÚ¡£¡£¡£¡£¡£¡£¡£¡£

½¨¸´´úÂë
Éî¿Ì½âÎö
OSF_SCALL:GetCoalescedBufferÖеÄÒ×Êܹ¥»÷´úÂ룬£¬£¬£¬£¬£¬£¬ÎÒÃǰÑÎȵ½ÕûÊýÒç³öÃýÎó¿ÉÄܵ¼Ö¶ѻº³åÇøÒç³ö£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÆäÖÐÊý¾Ý±»¸´Ô쵽̫Ó×¶øÎÞ·¨Ìî³ä¡£¡£¡£¡£¡£¡£¡£¡£·´¹ýÀ´£¬£¬£¬£¬£¬£¬£¬ÕâÔÊÐí½«Êý¾ÝдÈë¶ÑÉϵĻº³åÇøÌìǵ֮±í¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÀûÓÃÇе±£¬£¬£¬£¬£¬£¬£¬Õâ¸öÔÓï¿ÉÄܻᵼÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£
ÔÚÆäËûº¯ÊýÖÐÒ²Ôö³¤ÁËÀàËÆµÄ²é³ÕûÊýÒç³öµÄŲÓãº
OSF_CCALL::ProcessResponse
OSF_SCALL::GetCoalescedBuffer
OSF_CCALL::GetCoalescedBuffer
²Î¿¼Á´½Ó£º
https://www.akamai.com/blog/security/critical-remote-code-execution-vulnerabilities-windows-rpc-runtime
·ì϶¼ì²â
8827Ì«Ñô¼¯ÍÅÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳÒÑ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü£¬£¬£¬£¬£¬£¬£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐÐÊÚȨɨÃ裬£¬£¬£¬£¬£¬£¬Óû§Éý¼¶³ß¶È·ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃ裺
6070°æ±¾Éý¼¶°üΪ607000428£¬£¬£¬£¬£¬£¬£¬Éý¼¶°üÏÂÔØµØÖ·£º
https://venustech.download.venuscloud.cn/





Éý¼¶ºóÒÑÖ§³Ö¸Ã·ì϶
ÇëʹÓÃÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬£¬£¬£¬£¬£¬£¬ÊµÊ±¶Ô¸Ã·ì϶½øÐмì²â£¬£¬£¬£¬£¬£¬£¬ÒԱ㾡¿ì²ÉÈ¡·À±¸´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£
»ùÏߺ˲é
8827Ì«Ñô¼¯ÍŰ²È«ÅäÖú˲éÖÎÀíϵͳÒÑ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄºË²é×ÊÔ´°ü£¬£¬£¬£¬£¬£¬£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐк˲飬£¬£¬£¬£¬£¬£¬Óû§Éý¼¶°²È«ÅäÖú˲éÖÎÀíϵͳ×ÊÔ´°üºó¼´¿É¶Ô¸Ã·ì϶½øÐк˲飺

»ùÏߺ˲é
½¨¸´½¨Òé
Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£¡£¡£¡£¡£¡£¡£¡£
×Ô¶¯¸üÐÂ
MicrosoftUpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£¡£¡£¡£
ÊÖ¶¯¸üÐÂ
µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖᱡ£¡£¡£¡£¡£¡£¡£¡£
Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬£¬£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows8¡¢Windows8.1¡¢WindowsServer2012ÒÔ¼°WindowsServer2012R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©¡£¡£¡£¡£¡£¡£¡£¡£
Ñ¡Ôñ¡°²é³¸üС±£¬£¬£¬£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£¡£¡£¡£
³ÁÆôÍÆËã»ú£¬£¬£¬£¬£¬£¬£¬×°ÖøüÐÂϵͳ³ÁÐÂÆô¶¯ºó£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¡£¡£¡£¡£¡£¡£¡£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬£¬£¬£¬£¬£¬£¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬£¬£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£¡£¡£¡£
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2022-Apr
²¹¶¡ÏÂÔØÊ¾Àý
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬£¬£¬£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£¡£¡£¡£¡£¡£¡£¡£

΢Èí·ì϶ÁаµÊ¾Àý
2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£¡£¡£¡£¡£

²¹¶¡ÏÂÔØÁ´½Ó
3.µã»÷¡¾SecurityUpdate¡¿£¬£¬£¬£¬£¬£¬£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÏàÓ¦²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÊµÏÖºóË«»÷×°Öᣡ£¡£¡£¡£¡£¡£¡£

²¹¶¡ÏÂÔØ
Ó×ÌùÊ¿£º
·ì϶ÏêÇé
±±Ú¤Êý¾Ý³¢ÊÔÊÒ
±±Ú¤Êý¾Ý³¢ÊÔÊÒ³ÉÁ¢ÓÚ2022Äê3Ô£¬£¬£¬£¬£¬£¬£¬ÖÂÁ¦ÓÚÍøÂç¿Õ¼ä°²È«ÖªÊ¶¹¤³Ì×êÑкÍϵͳ»¯½¨ÉèµÄרҵÍŶӣ¬£¬£¬£¬£¬£¬£¬ÓÉ8827Ì«Ñô¼¯Íż¯ÍÅÌì¾µ·ì϶×êÑÐÍŶӡ¢Ì©ºÏ֪ʶ¹¤³ÌÍŶӡ¢´óÊý¾Ý³¢ÊÔÊÒ£¨BDlab£©³¡¾°»¯·ÖÎöÍŶӽáºÏ×é³É¡£¡£¡£¡£¡£¡£¡£¡£
±±Ú¤Êý¾Ý³¢ÊÔÊÒʼÖÕ±ü³ÖÒÔÐèҪΪµ¼Ïò¡¢ÖªÊ¶¸³ÄܲúÆ·µÄÖ÷ÌâÀíÏ룬£¬£¬£¬£¬£¬£¬×¨Ò»ÓÚÌá¹©ÍøÂç¿Õ¼ä°²È«µÄ»ù´¡ÖªÊ¶×êÑкͿª·¢£¬£¬£¬£¬£¬£¬£¬Ôì¶©½áºÏÍþвºÍ·ì϶µý±¨¡¢ÍøÂç¿Õ¼ä×ʲúºÍÔÆ°²È«¼à²âÊý¾ÝµÈ×ۺϵý±¨ÒÔ¼°Óû§ÏÖʵ³¡¾°µÄ°²È«·ÖÎö·À»¤Õ½Êõ£¬£¬£¬£¬£¬£¬£¬¹¹½¨×Ô¶¯»¯µ÷²éºÍ´ëÖÃÏìÓ¦´ëÊ©£¬£¬£¬£¬£¬£¬£¬Ðγɳ¡¾°»¯¡¢½á¹¹»¯µÄ֪ʶ¹¤³Ìϵͳ£¬£¬£¬£¬£¬£¬£¬¶Ô¸÷Àలȫ²úÆ·¡¢Æ½Ì¨ºÍ°²È«ÔËÓªÌṩ֪ʶ¸³ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ