¡¾·ì϶¹«¸æ¡¿Î¢Èí10Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2022-10-120x00 ·ì϶¸ÅÊö
2022Äê10ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬Î¢Èí°ä²¼ÁË10Ô°²È«¸üУ¬£¬£¬£¬£¬£¬£¬±¾´Î¸üн¨¸´ÁËÔ̺¬2¸ö0 day·ì϶ÔÚÄÚµÄ84¸ö°²È«·ì϶£¨²»Ô̺¬10ÔÂ3ÈÕ½¨¸´µÄ12¸öMicrosoft Edge·ì϶£©£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ13¸ö·ì϶ÆÀ¼¶Îª¡°ÑϳÁ¡±¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬Microsoft Exchange ProxyNotShell·ì϶ÉÐ佨¸´¡£¡£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé
±¾´Î°ä²¼µÄ°²È«¸üÐÂÉæ¼°Active Directory Domain Services¡¢Azure¡¢Microsoft Office¡¢Microsoft Office SharePoint¡¢Windows Hyper-V¡¢Visual Studio Code¡¢Windows Active Directory Certificate Services¡¢Windows Defender¡¢Windows DHCP Client¡¢Windows Group Policy¡¢Windows Kernel¡¢Windows NTFS¡¢Windows NTLM¡¢Windows Point-to-Point Tunneling Protocol¡¢Windows TCP/IPºÍWindows Win32KµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£¡£¡£
±¾´Î½¨¸´µÄ84¸ö·ì϶ÖУ¬£¬£¬£¬£¬£¬£¬39¸öΪÌáÈ¡·ì϶£¬£¬£¬£¬£¬£¬£¬20¸öΪԶ³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬£¬11¸öΪÐÅϢй¶·ì϶£¬£¬£¬£¬£¬£¬£¬8¸öΪ»Ø¾ø·þÎñ·ì϶£¬£¬£¬£¬£¬£¬£¬2¸öΪ°²È«Ö°ÄÜÈÆ¹ý·ì϶£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°4¸öºýŪ·ì϶¡£¡£¡£¡£¡£¡£
΢Èí±¾´Î¹²½¨¸´ÁË2¸ö0 day·ì϶£¬£¬£¬£¬£¬£¬£¬ÆäÖÐCVE-2022-41033ÒÑ·¢ÏÖ±»»ý¼«ÀûÓ㬣¬£¬£¬£¬£¬£¬CVE-2022-41043ÒѾ¹«¿ªÅû¶¡£¡£¡£¡£¡£¡£
CVE-2022-41033£ºWindows COM+ Event System ServiceÌØÈ¨ÌáÉý·ì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓø÷ì϶Äܹ»»ñµÃSYSTEMȨÏÞ¡£¡£¡£¡£¡£¡£Ä¿Ç°¸Ã·ì϶ÔÝδ¹«¿ªÅû¶£¬£¬£¬£¬£¬£¬£¬µ«ÒѾ¼ì²âµ½·ì϶ÀûÓᣡ£¡£¡£¡£¡£
CVE-2022-41043£ºMicrosoft Office ÐÅϢй¶·ì϶
¸Ã·ì϶ӰÏìÁ˺ÏÓÃÓÚ Mac 2021 µÄ Microsoft Office LTSCºÍºÏÓÃÓÚ Mac µÄ Microsoft Office 2019£¬£¬£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ3.3£¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܻᵼÖÂÓû§ÁîÅÆ»òÆäËüÃô¸ÐÐÅÏ¢±»Ð¹Â¶¡£¡£¡£¡£¡£¡£Ä¿Ç°¸Ã·ì϶ÔÝδ¼ì²âµ½·ì϶ÀûÓ㬣¬£¬£¬£¬£¬£¬µ«ÒѾ±»¹«¿ªÅû¶¡£¡£¡£¡£¡£¡£
΢ÈíÉÐδÔÚ±¾´Î¸üÐÂÖн¨¸´Microsoft Exchange ProxyNotShell·ì϶CVE-2022-41040£¨ÌØÈ¨ÌáÉý£©ºÍCVE-2022-41082£¨Ô¶³Ì´úÂëÖ´ÐУ©£¬£¬£¬£¬£¬£¬£¬µ«ÒѾ°ä²¼ÁËÓйذ²È«Ö¸ÄÏ£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉÀûÓÃÖ¸ÄÏÖеĻº½â´ëÊ©²¢ÆÚ´ý¹Ù·½²¹¶¡°ä²¼¡£¡£¡£¡£¡£¡£
±¾´Î¸üÐÂÖÐÖµµÃ¹Ø×¢µÄ·ì϶Ô̺¬µ«²»ÏÞÓÚ£º
CVE-2022-37968£ºÆôÓà Azure Arc µÄ Kubernetes ¼¯ÈºÏνÓÌØÈ¨ÌáÉý·ì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ10.0£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËÆôÓà Azure Arc µÄ Kubernetes ¼¯ÈºµÄ¼¯ÈºÏνÓÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÓû§ÌáÉýÆäȨÏÞ²¢¿ÉÄÜ»ñµÃ¶Ô Kubernetes ¼¯ÈºµÄÖÎÀí½ÚÔìȨ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ Azure Stack Edge ÔÊÐí¿Í»§Í¨¹ý Azure Arc ÔÚÆäÉ豸Éϲ¿Êð Kubernetes ¹¤×÷¸ºÔØ£¬£¬£¬£¬£¬£¬£¬Òò¶ø Azure Stack Edge É豸ҲÈÝÒ×Êܵ½¸Ã·ì϶µÄÓ°Ïì¡£¡£¡£¡£¡£¡£
CVE-2022-37976£ºActive Directory Ö¤Êé·þÎñÌØÈ¨ÌáÉý·ì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.8£¬£¬£¬£¬£¬£¬£¬Ö»Óе± Active Directory Ö¤Êé·þÎñÔÚÓòÉÏÔËÐÐʱ£¬£¬£¬£¬£¬£¬£¬ÏµÍ³²ÅÈÝÒ×Êܵ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓô˷ì϶Äܹ»»ñµÃÓòÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁ˶à¸öWindows Server°æ±¾£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉʵʱװÖøüС£¡£¡£¡£¡£¡£
CVE-2022-41038£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.8£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÖ¸±êÍøÕ¾µÄÉí·ÝÑéÖ¤²¢ÓÐȨÔÚ SharePoint ÖÐʹÓÃÖÎÀíÁбíµÄÓû§Äܹ»ÔÚ SharePoint Server ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£
CVE-2022-38048£ºMicrosoft Office Ô¶³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬£¬ÀûÓø÷ì϶ÐèÓëÓû§½»»¥¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁ˶à¸ö°æ±¾µÄMicrosoft Office 2013¡¢Microsoft Office 2016¡¢Microsoft Office 2019¡¢Microsoft Office LTSCºÍMicrosoft 365 ÆóÒµÀûÓᣡ£¡£¡£¡£¡£
΢Èí10Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑϳÁÐÔ |
CVE-2022-37968 | ÆôÓà Azure Arc µÄ Kubernetes ¼¯ÈºÏνÓÌØÈ¨ÌáÉý·ì϶ | ÑϳÁ |
CVE-2022-38048 | Microsoft Office Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-41038 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-37979 | Windows Hyper-V ÌØÈ¨ÌáÉý·ì϶ | ÑϳÁ |
CVE-2022-37976 | Active Directory Ö¤Êé·þÎñÌØÈ¨ÌáÉý·ì϶ | ÑϳÁ |
CVE-2022-34689 | Windows CryptoAPI ºýŪ·ì϶ | ÑϳÁ |
CVE-2022-33634 | Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-22035 | Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-24504 | Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-38047 | Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-41081 | Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-30198 | Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-38000 | Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2022-38042 | Active Directory Óò·þÎñÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-38017 | StorSimple 8000 ϵÁÐÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37987 | Windows ¿Í»§¶Ë·þÎñÆ÷ÔËÐÐʱ×Óϵͳ (CSRSS) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37989 | Windows ¿Í»§¶Ë·þÎñÆ÷ÔËÐÐʱ×Óϵͳ (CSRSS) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37986 | Windows Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-38051 | Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37997 | Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37985 | Windows ͼÐÎ×é¼þÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-33635 | Windows GDI+ Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-38001 | Microsoft Office ºýŪ·ì϶ | ¸ßΣ |
CVE-2022-41043 | Microsoft Office ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-38053 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-41036 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-41037 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-41031 | Microsoft Word Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-38049 | Microsoft Office Graphics Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-37982 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-38031 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-41032 | NuGet ¿Í»§¶ËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37965 | Windows µã¶ÔµãËí·ºÍ̸»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-35829 | Service Fabric Explorer ºýŪ·ì϶ | ¸ßΣ |
CVE-2022-41042 | Visual Studio Code ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-41034 | Visual Studio Code Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-41083 | Visual Studio Code ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37978 | Windows Active Directory Ö¤Êé·þÎñ°²È«Ö°ÄÜÈÆ¹ý | ¸ßΣ |
CVE-2022-38029 | Windows ALPC ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-38044 | Windows CD-ROM ÎļþϵͳÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-41033 | Windows COM+ ÊÂÎñϵͳ·þÎñÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-38021 | Connected User Experiences and TelemetryÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37971 | Microsoft Windows Defender ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-38026 | Windows DHCP ¿Í»§¶ËÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-37980 | Windows DHCP ¿Í»§¶ËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-38025 | Windows É¢²¼Ê½Îļþϵͳ (DFS) ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-37970 | Windows DWM Ö÷Ìâ¿âÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37983 | Microsoft DWM Ö÷Ìâ¿âÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37981 | Windows ÊÂÎñÈÕÖ¾¼Í¼·þÎñ»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-37975 | Windows ×éÕ½ÊõÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37994 | Windows ×éÕ½ÊõÊ×Ñ¡Ïî¿Í»§¶ËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37993 | Windows ×éÕ½ÊõÊ×Ñ¡Ïî¿Í»§¶ËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37999 | Windows ×éÕ½ÊõÊ×Ñ¡Ïî¿Í»§¶ËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-38036 | Internet ÃÜÔ¿»¥»» (IKE) ºÍ̸»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-37988 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-38037 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37990 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-38038 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-38039 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37995 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37991 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-38022 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-38016 | Windows ±¾µØ°²È«»ú¹¹ (LSA) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37977 | ±¾µØ°²È«»ú¹¹×Óϵͳ·þÎñ (LSASS) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-37973 | Windows ±¾µØ»á»°ÖÎÀíÆ÷ (LSM) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-37998 | Windows ±¾µØ»á»°ÖÎÀíÆ÷ (LSM) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-37996 | Windows ÄÚºËÄÚ´æÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-35770 | Windows NTLM ºýŪ·ì϶ | ¸ßΣ |
CVE-2022-38040 | Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2022-37974 | Windows Mixed Reality ¿ª·¢Õß¹¤¾ßÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-38032 | Windows ±ãЯʽÉ豸ö¾ÙÆ÷·þÎñ°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2022-38028 | Windows ºó¶Ü´òÓ¡·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-38003 | Windows µ¯ÐÔÎļþÏµÍ³ÌØÈ¨ÌáÉý | ¸ßΣ |
CVE-2022-38041 | Windows °²È«Í¨Â·»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-38043 | Windows °²È«Ö§³ÖÌṩ·¨Ê½½Ó¿ÚÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-38033 | Windows Server ¿ÉÔ¶³Ì½Ó¼ûµÄ×¢²á±íÏîÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-38045 | Server Service Remote ProtocolÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-38027 | Windows ´æ´¢ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-33645 | Windows TCP/IP Çý¶¯·¨Ê½»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2022-38030 | Windows USB ´®ÐÐÇý¶¯·¨Ê½ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-38046 | Web Account ManagerÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2022-38050 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-37984 | Windows WLAN Service ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-38034 | Windows Workstation ServiceÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2022-41035 | Microsoft Edge£¨»ùÓÚ Chromium£©ºýŪ·ì϶ | ÖÐΣ |
CVE-2022-3311 | Chromium£ºCVE-2022-3311 ÔÚµ¼ÈëºóÃâ·ÑʹÓà | δ֪ |
CVE-2022-3313 | Chromium£ºCVE-2022-3313 È«ÆÁÏÔʾ²»ÕýÈ·µÄ°²È« UI | δ֪ |
CVE-2022-3315 | Chromium£ºCVE-2022-3315 Blink ÖеÄÀàÐÍ»ìºÏ | δ֪ |
CVE-2022-3370 | Chromium£ºCVE-2022-3370 ÔÚ×Ô½çËµÔªËØÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2022-3373 | Chromium£ºCVE-2022-3373 ÔÚV8ÖÐÔ½½çдÈë | δ֪ |
CVE-2022-3316 | Chromium£ºCVE-2022-3316 ¶Ô°²È«ä¯ÀÀÖв»ÊÜÐÅÀµµÄÊäÈëµÄÑéÖ¤²»¼° | δ֪ |
CVE-2022-3317 | Chromium£ºCVE-2022-3317 Intents Öв»ÊÜÐÅÀµµÄÊäÈëÑéÖ¤²»¼° | δ֪ |
CVE-2022-3310 | Chromium£ºCVE-2022-3310 ×Ô½ç˵ѡÏÖеÄÕ½ÊõÖ´Ðв»¼° | δ֪ |
CVE-2022-3304 | Chromium£ºCVE-2022-3304 ÔÚ CSS ÖÐÃâ·ÑºóʹÓà | δ֪ |
CVE-2022-3308 | Chromium£ºCVE-2022-3308 ¿ª·¢ÈËÔ±¹¤¾ßÖеÄÕ½ÊõÖ´Ðв»¼° | δ֪ |
CVE-2022-3307 | Chromium£ºCVE-2022-3307 ÔÚýÌåÖÐÃâ·ÑºóʹÓà | δ֪ |
0x02 ´ëÖý¨Òé
Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£¡£¡£¡£¡£¡£
£¨Ò»£© Windows update¸üÐÂ
×Ô¶¯¸üУº
Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£¡£
ÊÖ¶¯¸üУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬£¬£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬£¬£¬£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£¡£
4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¡£¡£¡£¡£¡£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬£¬£¬£¬£¬£¬£¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬£¬£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£¡£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£¡£¡£¡£¡£¡£
10Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2022-Oct
²¹¶¡ÏÂÔØÊ¾Àý£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬£¬£¬£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£¡£¡£¡£¡£¡£

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2Ô£©
2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£¡£¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾°²È«¸üС¿£¬£¬£¬£¬£¬£¬£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öᣡ£¡£¡£¡£¡£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£¡£¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2022-Oct
https://www.bleepingcomputer.com/news/microsoft/microsoft-october-2022-patch-tuesday-fixes-zero-day-used-in-attacks-84-flaws/
https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
0x04 °æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2022-10-12 | ³õ´Î°ä²¼ |
0x05 ¸½Â¼
8827Ì«Ñô¼¯Íżò½é
8827Ì«Ñô¼¯ÍųÉÁ¢ÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°8827Ì«Ñô¼¯ÍÅ´óÏ㬣¬£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤½ü4000ÈË£¬£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÀö½ÖÐÓ×°å¹ÒÅÆÉÏÊÓ×£¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬£¬£¬£¬£¬£¬£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£¡£¡£¡£¡£¡£
¹ØÓÚ8827Ì«Ñô¼¯ÍÅ
8827Ì«Ñô¼¯ÍŰ²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÖØÒªÕë¶Ô³ÁÒª°²È«·ì϶µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвµý±¨ºÍ°²È«»ã±¨¡£¡£¡£¡£¡£¡£
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬£¬£¬£¬»ñȡȫÇò×îа²È«×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ