Éî¶ÈÆÊÎö΢Èí×îÐÂÎó²î£¬£¬£¬£¬£¬ÎªÄúÌṩ×îÓŽâ¾ö¼Æ»®
Ðû²¼Ê±¼ä 2022-04-21½üÆÚ£¬£¬£¬£¬£¬Î¢ÈíÐû²¼ÁË4Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´Á˰üÀ¨2¸ö0dayÎó²îÔÚÄÚµÄ119¸öÇå¾²Îó²î£¨²»°üÀ¨26¸öMicrosoftEdgeÎó²î£©£¬£¬£¬£¬£¬ÆäÖÐÓÐ10¸öÎó²î±»ÆÀ¼¶ÎªÑÏÖØ£¬£¬£¬£¬£¬Éæ¼°.NET Framework¡¢ActiveDirectoryDomainServicesµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£¡££¨Îó²îÏêÇéÔÚÎÄÄ©£©
¿Ðý¹ú¼ÊÓÎÏ·±±Ú¤Êý¾ÝʵÑéÊÒµÚһʱ¼ä¶Ô΢Èí4ÔÂÐû²¼µÄÇ徲ͨ¸æ¾ÙÐÐÆÊÎöÑÐÅУ¬£¬£¬£¬£¬Á¬ÏµÌ©ºÏÅÌ¹ÅÆ½Ì¨£¨THPangu-OS£©µÄµ××ùÄÜÁ¦£¬£¬£¬£¬£¬Îª¿í´óÓû§¸ø³öÓ¦¼±´¦Öóͷ£Ö¸Òý¼Æ»®¡£¡£¡£¡£¡£
ÒòÔ¶³Ì´úÂëÖ´ÐÐÎó²îCVE-2022-26809Íþвˮƽ¸ß¡¢Ó°Ïì¹æÄ£½Ï¹ã£¬£¬£¬£¬£¬Ê¹ÓõÄÖØÆ¯ºóµÍ£¬£¬£¬£¬£¬Ò×±»¹¥»÷Õ߯ձéʹÓýø¶ø¶Ô¿í´óÓû§Ôì³ÉÑÏÖØÎ£º¦£¬£¬£¬£¬£¬ÒÔÊÇÎÒÃÇÒÔ´ËÎó²îÉæ¼°µÄЧÀÍΪÀý£¬£¬£¬£¬£¬×ö³öÁ˽øÒ»²½µÄÏ꾡ÆÊÎöÀú³Ì£¬£¬£¬£¬£¬²¢Ïêϸ˵Ã÷Îó²îÐÞ¸´Óë²¹¶¡ÏÂÔØ¡£¡£¡£¡£¡£
Îó²îÆÊÎö
Ïà¹ØÎó²îλÓÚWindowsRPCЧÀÍ£¬£¬£¬£¬£¬¸ÃЧÀÍÓÉÃûΪrpcrt4.dllµÄ¿â¡£¡£¡£¡£¡£¸ÃÔËÐÐʱ¿â±»¼ÓÔØµ½Ê¹ÓÃRPCÐÒé¾ÙÐÐͨѶµÄ¿Í»§¶ËºÍЧÀÍÆ÷Àú³ÌÖС£¡£¡£¡£¡£
ͨ¹ý½ÏÁ¿ÁË10.0.22000.434£¨Î´´ò²¹¶¡£¬£¬£¬£¬£¬´Ó2022Äê3ÔÂ×îÏÈ£©ºÍ10.0.22000.613£¨ÒÑ´ò²¹¶¡£¬£¬£¬£¬£¬´Ó2022Äê4ÔÂ×îÏÈ£©°æ±¾£¬£¬£¬£¬£¬ÄÜ·¢Ã÷ÒÔÏÂÖÖÖÖ¹¦Ð§»òº¯ÊýµÄת±äÇåµ¥¡£¡£¡£¡£¡£
º¯Êýת±äÇåµ¥
º¯ÊýOSF_CCALL::ProcessResponseºÍOSF_SCALL::ProcessReceivedPDU¡£¡£¡£¡£¡£ÕâÁ½¸öº¯ÊýʵÖÊÉÏÊÇÏàËÆµÄ£»£»£»£»£»Á½Õß¶¼´¦Öóͷ£RPCÊý¾Ý°ü£¬£¬£¬£¬£¬µ«Ò»¸öÔÚ¿Í»§¶ËÔËÐУ¬£¬£¬£¬£¬ÁíÒ»¸öÔÚЧÀÍÆ÷¶ËÔËÐУ¨CCALLºÍSCALL»®·Ö´ú±í¿Í»§¶ËŲÓúÍЧÀÍÆ÷ŲÓã©¡£¡£¡£¡£¡£ÎÒÃǼÌÐø½ÏÁ¿OSF_SCALL::ProcessReceivedPDU£¬£¬£¬£¬£¬²¢×¢Öص½Ð°汾ÖÐÌí¼ÓÁËÁ½¸ö´úÂë¿é¡£¡£¡£¡£¡£
±ÈÕÕÐÂÔö´úÂë¿é
Éó²éÐÞ¸´´úÂ룬£¬£¬£¬£¬ÎÒÃÇ¿´µ½ÔÚQUEUE::PutOnQueueÖ®ºóŲÓÃÁËÒ»¸öк¯Êý¡£¡£¡£¡£¡£½øÈëк¯Êý²¢¼ì²éÆä´úÂ룬£¬£¬£¬£¬ÎÒÃÇ·¢Ã÷ËüÓÃÓÚ¼ì²éÕûÊýÒç³ö¡£¡£¡£¡£¡£¼´Ìí¼ÓÁËк¯ÊýÒÔÑéÖ¤ÕûÊý±äÁ¿ÊÇ·ñ¼á³ÖÔÚÔ¤ÆÚÖµ¹æÄ£ÄÚ¡£¡£¡£¡£¡£
ÐÞ¸´´úÂë
ÉîÈëÆÊÎö
OSF_SCALL:GetCoalescedBufferÖеÄÒ×Êܹ¥»÷´úÂ룬£¬£¬£¬£¬ÎÒÃÇ×¢ÖØµ½ÕûÊýÒçÍÉ»¯Îó¿ÉÄܵ¼Ö¶ѻº³åÇøÒç³ö£¬£¬£¬£¬£¬ÓÉÓÚÆäÖÐÊý¾Ý±»¸´ÖƵ½Ì«Ð¡¶øÎÞ·¨Ìî³ä¡£¡£¡£¡£¡£·´¹ýÀ´£¬£¬£¬£¬£¬ÕâÔÊÐí½«Êý¾ÝдÈë¶ÑÉϵĻº³åÇø½çÏßÖ®Íâ¡£¡£¡£¡£¡£ÈôÊÇʹÓÃÊʵ±£¬£¬£¬£¬£¬Õâ¸öÔÓï¿ÉÄܻᵼÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£
ÔÚÆäËûº¯ÊýÖÐÒ²Ìí¼ÓÁËÀàËÆµÄ¼ì²éÕûÊýÒç³öµÄŲÓãº
OSF_CCALL::ProcessResponse
OSF_SCALL::GetCoalescedBuffer
OSF_CCALL::GetCoalescedBuffer
²Î¿¼Á´½Ó£º
https://www.akamai.com/blog/security/critical-remote-code-execution-vulnerabilities-windows-rpc-runtime
Îó²î¼ì²â
¿Ðý¹ú¼ÊÓÎÏ·Ì쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳÒѽôÆÈÐû²¼Õë¶Ô¸ÃÎó²îµÄÉý¼¶°ü£¬£¬£¬£¬£¬Ö§³Ö¶Ô¸ÃÎó²î¾ÙÐÐÊÚȨɨÃ裬£¬£¬£¬£¬Óû§Éý¼¶±ê×¼Îó²î¿âºó¼´¿É¶Ô¸ÃÎó²î¾ÙÐÐɨÃ裺
6070°æ±¾Éý¼¶°üΪ607000428£¬£¬£¬£¬£¬Éý¼¶°üÏÂÔØµØµã£º
https://venustech.download.venuscloud.cn/
Éý¼¶ºóÒÑÖ§³Ö¸ÃÎó²î
ÇëʹÓÃÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳ²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬£¬£¬£¬£¬ÊµÊ±¶Ô¸ÃÎó²î¾ÙÐмì²â£¬£¬£¬£¬£¬ÒԱ㾡¿ì½ÓÄÉÌá·À²½·¥¡£¡£¡£¡£¡£
»ùÏߺ˲é
¿Ðý¹ú¼ÊÓÎÏ·Çå¾²ÉèÖú˲éÖÎÀíϵͳÒѽôÆÈÐû²¼Õë¶Ô¸ÃÎó²îµÄºË²é×ÊÔ´°ü£¬£¬£¬£¬£¬Ö§³Ö¶Ô¸ÃÎó²î¾ÙÐк˲飬£¬£¬£¬£¬Óû§Éý¼¶Çå¾²ÉèÖú˲éÖÎÀíϵͳ×ÊÔ´°üºó¼´¿É¶Ô¸ÃÎó²î¾ÙÐк˲飺
»ùÏߺ˲é
ÐÞ¸´½¨Òé
ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£¡£
×Ô¶¯¸üÐÂ
MicrosoftUpdateĬÈÏÆôÓ㬣¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£
ÊÖ¶¯¸üÐÂ
µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖᱡ£¡£¡£¡£¡£
Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows8¡¢Windows8.1¡¢WindowsServer2012ÒÔ¼°WindowsServer2012R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©¡£¡£¡£¡£¡£
Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£
ÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬×°ÖøüÐÂÏµÍ³ÖØÐÂÆô¶¯ºó£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2022-Apr
²¹¶¡ÏÂÔØÊ¾Àý
1.·¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£¡£¡£¡£¡£
΢ÈíÎó²îÁÐÌåÏÖÀý
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£¡£
²¹¶¡ÏÂÔØÁ´½Ó
3.µã»÷¡¾SecurityUpdate¡¿£¬£¬£¬£¬£¬·¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬£¬ÏÂÔØÏìÓ¦²¹¶¡£¬£¬£¬£¬£¬ÏÂÔØÍê³ÉºóË«»÷×°Öᣡ£¡£¡£¡£
²¹¶¡ÏÂÔØ
СÌùÊ¿£º
Îó²îÏêÇé
±±Ú¤Êý¾ÝʵÑéÊÒ
±±Ú¤Êý¾ÝʵÑéÊÒ½¨ÉèÓÚ2022Äê3Ô£¬£¬£¬£¬£¬ÖÂÁ¦ÓÚÍøÂç¿Õ¼äÇ徲֪ʶ¹¤³ÌÑо¿ºÍϵͳ»¯½¨ÉèµÄרҵÍŶӣ¬£¬£¬£¬£¬ÓÉ¿Ðý¹ú¼ÊÓÎÏ·¼¯ÍÅÌì¾µÎó²îÑо¿ÍŶӡ¢Ì©ºÏ֪ʶ¹¤³ÌÍŶӡ¢´óÊý¾ÝʵÑéÊÒ£¨BDlab£©³¡¾°»¯ÆÊÎöÍŶÓÁªºÏ×é³É¡£¡£¡£¡£¡£
±±Ú¤Êý¾ÝʵÑéÊÒʼÖÕ±ü³ÖÒÔÐèÇóΪµ¼Ïò¡¢ÖªÊ¶¸³ÄܲúÆ·µÄ½¹µãÀíÄ£¬£¬£¬£¬×¨×¢ÓÚÌá¹©ÍøÂç¿Õ¼äÇå¾²µÄ»ù´¡ÖªÊ¶Ñо¿ºÍ¿ª·¢£¬£¬£¬£¬£¬Öƶ©Á¬ÏµÍþвºÍÎó²îÇ鱨¡¢ÍøÂç¿Õ¼ä×ʲúºÍÔÆÇå¾²¼à²âÊý¾ÝµÈ×ÛºÏÇ鱨ÒÔ¼°Óû§ÏÖʵ³¡¾°µÄÇå¾²ÆÊÎö·À»¤Õ½ÂÔ£¬£¬£¬£¬£¬¹¹½¨×Ô¶¯»¯ÊÓ²ìºÍ´¦Öóͷ£ÏìÓ¦²½·¥£¬£¬£¬£¬£¬Ðγɳ¡¾°»¯¡¢½á¹¹»¯µÄ֪ʶ¹¤³Ìϵͳ£¬£¬£¬£¬£¬¶ÔÖÖÖÖÇå¾²²úÆ·¡¢Æ½Ì¨ºÍÇå¾²ÔËÓªÌṩ֪ʶ¸³ÄÜ¡£¡£¡£¡£¡£