΢Èí2ÔÂÇå¾²¸üжà¸ö²úÆ·¸ßΣÎó²îͨ¸æ
2022-02-10
Ò». Îó²î¸ÅÊö
2ÔÂ9ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Î¢ÈíÐû²¼2ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË48¸öÇå¾²ÎÊÌâ£¬Éæ¼°Windows¡¢Microsoft Office¡¢Microsoft Dynamics¡¢AzureµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨È¨ÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐеȸßΣÎó²îÀàÐÍ¡£
±¾ÔÂ΢ÈíÔ¶ȸüÐÂÐÞ¸´µÄÎó²îÖУ¬²»±£´æÑÏÖØË®Æ½ÎªÒªº¦£¨Critical£©µÄÎó²î£¬Ö÷Òª£¨Important£©Îó²îÓÐ48¸ö£¬ÆäÖаüÀ¨1¸ö0dayÎó²î£º
Windows Kernel ȨÏÞÌáÉýÎó²î£¨CVE-2022-21989£©
ÇëÏà¹ØÓû§¾¡¿ì¸üв¹¶¡¾ÙÐзÀ»¤£¬ÍêÕûÎó²îÁбíÇë²Î¿¼¸½Â¼¡£
AG¹«Ë¾Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS£©ÒѾ߱¸Î¢Èí´Ë´Î²¹¶¡¸üÐÂÖд󲿷ÖÎó²îµÄ¼ì²âÄÜÁ¦£¨°üÀ¨CVE-2022-21984¡¢CVE-2022-22005¡¢CVE-2022-21999¡¢CVE-2022-21995µÈ¸ßΣÎó²î£©£¬ÇëÏà¹ØÓû§¹Ø×¢AG¹«Ë¾Ô¶³ÌÇå¾²ÆÀ¹Àϵͳϵͳ²å¼þÉý¼¶°üµÄ¸üУ¬ÊµÊ±Éý¼¶ÖÁ×îа汾£¬¹ÙÍøÁ´½Ó£ºhttp://update.nsfocus.com/update/listRsasDetail/v/vulsys
²Î¿¼Á´½Ó£º
https://msrc.microsoft.com/update-guide/en-us/releaseNote/2022-Feb
¶þ. ÖØµãÎó²î¼òÊö
ƾ֤²úÆ·Ê¢ÐжȺÍÎó²îÖ÷ÒªÐÔɸѡ³ö´Ë´Î¸üÐÂÖаüÀ¨Ó°Ïì½Ï´óµÄÎó²î£¬ÇëÏà¹ØÓû§Öصã¾ÙÐйØ×¢£º
Windows Kernel ȨÏÞÌáÉýÎó²î£¨CVE-2022-21989£©£º
Windows Kernel±£´æÈ¨ÏÞÌáÉýÎó²î£¬ÓÉÓÚWindows KernelÖб£´æ½çÏß¹ýʧ£¬¿Éµ¼Ö»º³åÇøÒç³ö¡£¾ßÓеÍȨÏ޵Ĺ¥»÷ÕßÔÚÌØ¶¨ÇéÐÎÏ¿ÉʹÓøÃÎó²îÔÚÄ¿µÄϵͳÉÏÌáÉýÖÁSYSTEMȨÏÞ²¢Ö´ÐÐí§Òâ´úÂë¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-21989
Windows DNS ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-21984£©£º
µ±DNS·þÎñÆ÷ÆôÓö¯Ì¬¸üеÄÇéÐÎÏ£¬¾ßÓеÍȨÏ޵Ĺ¥»÷Õß¿ÉʹÓøÃÎó²îʵÏÖ¶ÔDNS·þÎñÆ÷½ÓÊÜ£¬×îÖÕµ¼ÖÂÔÚÄ¿µÄϵͳÉÏÒÔÓû§È¨ÏÞÖ´ÐÐí§Òâ´úÂ룬ÇÒÎÞÐèÓû§½»»¥¡£CVSSÆÀ·ÖΪ8.8¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21984
Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-22005£©£º
ÓÉÓÚSharePoint ServerÖб£´æÎó²î£¬¸ÃÎó²îÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄÓû§ÔÚ SharePoint·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ.NET´úÂëÓëWebÓ¦ÓóÌÐò¡£µ±¹¥»÷ÕßÓµÓГÖÎÀíÁбí”ȨÏÞʱ£¬²Å»ªÀÖ³ÉʹÓøÃÎó²î¡£CVSSÆÀ·ÖΪ8.8¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22005
Windows Print SpoolerȨÏÞÌáÉýÎó²î£¨CVE-2022-21999£©£º
Windows´òÓ¡ºǫ́·þÎñÖб£´æÎó²î£¬¾ÓÉÉí·ÝÑéÖ¤µÄÍâµØ¹¥»÷ÕßʹÓøÃÎó²îÔÚÄ¿µÄϵͳÉÏÒÔSYSTEMȨÏÞÖ´ÐÐí§Òâ´úÂë¡£CVSSÆÀ·ÖΪ7.8¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21999
Windows Hyper-V Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-21995£©£º
Windows Hyper-VÊÇMicrosoftµÄÍâµØÐéÄâ»úÖÎÀí³ÌÐò£¬ÔÚÓû§½»»¥Ìõ¼þÏ£¬¹¥»÷ÕßÔÚÌØ¶¨ÇéÐοÉʹÓøÃÎó²îÈÆ¹ýÓû§ÐÅÍнçÏߣ¬×îÖÕµ¼ÖÂÔÚHyper-VÖ÷»úÉÏÒÔÓû§È¨ÏÞÖ´ÐÐí§Òâ´úÂë¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21995
Azure Data ExplorerÓÕÆÎó²î£¨CVE-2022-23256£©£º
Azure Data Explorer±£´æÓÕÆÎó²î£¬¹¥»÷Õß¿Éͨ¹ýÖÆ×÷¶ñÒâµÄurl£¬µ±ÀÖ³ÉÓÕµ¼Óû§ÔÚÊÜÓ°ÏìµÄϵͳÉÏ·¿ª¶ñÒâurlºó£¬¿ÉÔÚÄ¿µÄϵͳÉÏÒÔ¸ÃÓû§È¨ÏÞÖ´ÐÐí§Òâ´úÂë¡£CVSSÆÀ·ÖΪ8.1¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23256
Microsoft Dynamics GPÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-23274£©£º
Microsoft Dynamics GP±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓøÃÎó²î½«ÌØÖƵÄSQLÇëÇó·¢ËÍÖÁ Dynamics GP Web ·þÎñÆ÷£¬×îÖÕÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23274
Èý. Ó°Ïì¹æÄ£
ÒÔÏÂÎªÖØµã¹Ø×¢Îó²îµÄÊÜÓ°Ïì²úÆ·°æ±¾£¬ÆäËûÎó²îÓ°Ïì²úÆ·¹æÄ£Çë²ÎÔĹٷ½Í¨¸æÁ´½Ó¡£
|
Îó²î±àºÅ |
ÊÜÓ°Ïì²úÆ·°æ±¾ |
|
CVE-2022-21989 CVE-2022-21999 |
Windows Server 2012 R2 (Server Core installation) Windows Server 2012 R2 Windows Server 2012 (Server Core installation) Windows Server 2012 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) Windows Server 2008 R2 for x64-based Systems Service Pack 1 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) Windows Server 2008 for x64-based Systems Service Pack 2 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) Windows Server 2008 for 32-bit Systems Service Pack 2 Windows RT 8.1 Windows 8.1 for x64-based systems Windows 8.1 for 32-bit systems Windows 7 for x64-based Systems Service Pack 1 Windows 7 for 32-bit Systems Service Pack 1 Windows Server 2016 Windows 10 Version 1607 for x64-based Systems Windows 10 Version 1607 for 32-bit Systems Windows 10 for x64-based Systems Windows 10 for 32-bit Systems Windows 10 Version 21H2 for x64-based Systems Windows 10 Version 21H2 for ARM64-based Systems Windows 10 Version 21H2 for 32-bit Systems Windows 11 for ARM64-based Systems Windows 11 for x64-based Systems Windows Server, version 20H2 (Server Core Installation) Windows 10 Version 20H2 for ARM64-based Systems Windows 10 Version 20H2 for 32-bit Systems Windows 10 Version 20H2 for x64-based Systems Windows Server 2022 Azure Edition Core Hotpatch Windows Server 2022 (Server Core installation) Windows Server 2022 Windows 10 Version 21H1 for 32-bit Systems Windows 10 Version 21H1 for ARM64-based Systems Windows 10 Version 21H1 for x64-based Systems Windows 10 Version 1909 for ARM64-based Systems Windows 10 Version 1909 for x64-based Systems Windows 10 Version 1909 for 32-bit Systems Windows Server 2019 (Server Core installation) Windows Server 2019 Windows 10 Version 1809 for ARM64-based Systems Windows 10 Version 1809 for x64-based Systems Windows 10 Version 1809 for 32-bit Systems |
|
CVE-2022-21984 |
Windows 10 Version 21H2 for x64-based Systems Windows 10 Version 21H2 for ARM64-based Systems Windows 10 Version 21H2 for 32-bit Systems Windows 11 for ARM64-based Systems Windows 11 for x64-based Systems Windows Server, version 20H2 (Server Core Installation) Windows 10 Version 20H2 for ARM64-based Systems Windows 10 Version 20H2 for 32-bit Systems Windows 10 Version 20H2 for x64-based Systems Windows Server 2022 Azure Edition Core Hotpatch Windows Server 2022 (Server Core installation) Windows Server 2022 Windows 10 Version 21H1 for 32-bit Systems Windows 10 Version 21H1 for ARM64-based Systems Windows 10 Version 21H1 for x64-based Systems Windows 10 Version 1909 for ARM64-based Systems Windows 10 Version 1909 for x64-based Systems Windows 10 Version 1909 for 32-bit Systems |
|
CVE-2022-22005 |
Microsoft SharePoint Server Subscription Edition Microsoft SharePoint Server 2019 Microsoft SharePoint Enterprise Server 2013 Service Pack 1 Microsoft SharePoint Enterprise Server 2016 |
|
CVE-2022-21995 |
Windows Server 2016 (Server Core installation) Windows Server 2016 Windows 10 Version 1607 for x64-based Systems Windows 10 for x64-based Systems Windows 10 Version 21H2 for x64-based Systems Windows 11 for x64-based Systems Windows Server, version 20H2 (Server Core Installation) Windows 10 Version 20H2 for x64-based Systems Windows Server 2022 Azure Edition Core Hotpatch Windows Server 2022 (Server Core installation) Windows Server 2022 Windows 10 Version 21H1 for x64-based Systems Windows 10 Version 1909 for x64-based Systems Windows Server 2019 (Server Core installation) Windows Server 2019 Windows 10 Version 1809 for x64-based Systems |
|
CVE-2022-23256 |
Azure Data Explorer |
|
CVE-2022-23274 |
Microsoft Dynamics GP |
ËÄ. Îó²î·À»¤
4.1 ²¹¶¡¸üÐÂ
ÏÖÔÚ΢Èí¹Ù·½ÒÑÕë¶ÔÊÜÖ§³ÖµÄ²úÆ·°æ±¾Ðû²¼ÁËÐÞ¸´ÒÔÉÏÎó²îµÄÇå¾²²¹¶¡£¬Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì×°Öò¹¶¡¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-us/releaseNote/2022-Feb
×¢£ºÓÉÓÚÍøÂçÎÊÌâ¡¢ÅÌËã»úÇéÐÎÎÊÌâµÈÔµ¹ÊÔÓÉ£¬Windows UpdateµÄ²¹¶¡¸üпÉÄÜ·ºÆðʧ°Ü¡£Óû§ÔÚ×°Öò¹¶¡ºó£¬Ó¦ÊµÊ±¼ì²é²¹¶¡ÊÇ·ñÀֳɸüС£
ÓÒ¼üµã»÷Windowsͼ±ê£¬Ñ¡Ôñ“ÉèÖÃ(N)”£¬Ñ¡Ôñ“¸üкÍÇå¾²”-“Windows¸üД£¬Éó²é¸ÃÒ³ÃæÉϵÄÌáÐÑÐÅÏ¢£¬Ò²¿Éµã»÷“Éó²é¸üÐÂÀúÊ·¼Í¼”Éó²éÀúÊ·¸üÐÂÇéÐΡ£
Õë¶ÔδÀÖ³É×°ÖõĸüУ¬¿Éµã»÷¸üÐÂÃû³ÆÌø×ªµ½Î¢Èí¹Ù·½ÏÂÔØÒ³Ãæ£¬½¨ÒéÓû§µã»÷¸ÃÒ³ÃæÉϵÄÁ´½Ó£¬×ªµ½“Microsoft¸üÐÂĿ¼”ÍøÕ¾ÏÂÔØ×ÔÁ¦³ÌÐò°ü²¢×°Öá£

AG¹«Ë¾ÔÆ







