¡¾Îó²îͨ¸æ¡¿Î¢Èí12Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2022-12-14


0x00 Îó²î¸ÅÊö

2022Äê12ÔÂ13ÈÕ£¬£¬£¬£¬£¬ £¬£¬Î¢ÈíÐû²¼ÁË12ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬ £¬£¬±¾´Î¸üÐÂÐÞ¸´Á˰üÀ¨2¸ö0 dayÎó²îÔÚÄÚµÄ49¸öÇå¾²Îó²î£¨²»°üÀ¨Ö®Ç°ÐÞ¸´µÄMicrosoft Edge Îó²î£©£¬£¬£¬£¬£¬ £¬£¬ÆäÖÐÓÐ6¸öÎó²îÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÉæ¼°.NET Framework¡¢Microsoft Dynamics¡¢Microsoft Bluetooth Driver¡¢Microsoft Office¡¢Microsoft Windows Codecs Library¡¢Windows Kernel¡¢Windows PowerShell¡¢Windows Secure Socket Tunneling Protocol (SSTP)¡¢Windows TerminalµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£¡£

±¾´ÎÐÞ¸´µÄÎó²î£¨²»°üÀ¨Microsoft Edge Îó²î£©ÖУ¬£¬£¬£¬£¬ £¬£¬19¸öΪÌáÈ¡Îó²î£¬£¬£¬£¬£¬ £¬£¬23¸öΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬ £¬£¬3¸öΪÐÅϢй¶Îó²î£¬£¬£¬£¬£¬ £¬£¬3¸öΪ¾Ü¾øÐ§ÀÍÎó²î£¬£¬£¬£¬£¬ £¬£¬2¸öΪÇå¾²¹¦Ð§ÈƹýÎó²î£¬£¬£¬£¬£¬ £¬£¬ÒÔ¼°1¸öÓÕÆ­Îó²î¡£¡£¡£¡£¡£

΢Èí±¾´Î¹²ÐÞ¸´ÁË2¸ö0 dayÎó²î£¬£¬£¬£¬£¬ £¬£¬ÆäÖÐCVE-2022-44698Òѱ»Æð¾¢Ê¹Ó㬣¬£¬£¬£¬ £¬£¬CVE-2022-44710ÒѾ­¹ûÕæÅû¶£º

CVE-2022-44698£ºWindows SmartScreen Çå¾²¹¦Ð§ÈƹýÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ5.4£¬£¬£¬£¬£¬ £¬£¬Ê¹ÓøÃÎó²îÐèÓëÓû§½»»¥¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔͨ¹ý¶ñÒâÎļþÀ´ÈƹýMark of the Web (MOTW)·ÀÓù£¬£¬£¬£¬£¬ £¬£¬²¢ÔÚijЩÇéÐÎϵ¼ÖÂSmartScreen¹ýʧ²¢ÇÒ²»ÏÔʾ Web Çå¾²ÖÒÑÔ±ê¼Ç£¬£¬£¬£¬£¬ £¬£¬´Ó¶øµ¼Ö Microsoft Office ÖеÄÊܱ £»£»£» £»£»£» £»¤ÊÓͼµÈÒÀÀµ MOTW ±ê¼ÇµÄÇå¾²¹¦Ð§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼Ö¶ñÒâ¾ç±¾×Ô¶¯ÔËÐв¢×°ÖöñÒâÈí¼þ£¬£¬£¬£¬£¬ £¬£¬ÏÖÔÚ¸ÃÎó²îÒѼì²âµ½Îó²îʹÓᣡ£¡£¡£¡£

CVE-2022-44710£ºDirectX Graphics KernelÌØÈ¨ÌáÉýÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬ £¬£¬Ê¹ÓøÃÎó²îÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬£¬£¬£¬£¬ £¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÒÔ»ñµÃ SYSTEM ȨÏÞ£¬£¬£¬£¬£¬ £¬£¬ÏÖÔÚ¸ÃÎó²îÒѾ­¹ûÕæÅû¶¡£¡£¡£¡£¡£

±¾´Î¸üÐÂÖÐÆÀ¼¶ÎªÑÏÖØµÄ6¸öÎó²î°üÀ¨£º

CVE-2022-41127£ºMicrosoft Dynamics NAV ºÍ Microsoft Dynamics 365 Business Central£¨ÍâµØ£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.5£¬£¬£¬£¬£¬ £¬£¬Ê¹ÓøÃÎó²îÐè¾­ÓÉÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬ £¬£¬ÀÖ³ÉʹÓÃDynamics NAVÖеÄÎó²î¿ÉÒÔÔÚÒÑÉèÖÃʹÓà Dynamics ЧÀÍÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£

CVE-2022-44690/CVE-2022-44693£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÕâЩÎó²îµÄCVSSv3ÆÀ·Ö¾ùΪ8.8£¬£¬£¬£¬£¬ £¬£¬¾­ÓÉÉí·ÝÑéÖ¤²¢¾ßÓÐÖÎÀíÁбíȨÏ޵ĶñÒâÓû§¿ÉÒÔÔÚ SharePoint Server ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£

CVE-2022-41076£ºPowerShell Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.5£¬£¬£¬£¬£¬ £¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔÌ PowerShell Ô¶³Ì»á»°ÉèÖò¢ÔÚÄ¿µÄϵͳÉÏÔËÐÐδ¾­ÊÚȨµÄÏÂÁî¡£¡£¡£¡£¡£

CVE-2022-44670/CVE-2022-44676£ºWindows Secure Socket Tunneling Protocol £¨SSTP£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÕâЩÎó²îµÄCVSSv3ÆÀ·Ö¾ùΪ8.1£¬£¬£¬£¬£¬ £¬£¬ÀÖ³ÉʹÓÃÎó²îÐèÒªÓ®µÃ¾ºÕùÌõ¼þ¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔÔÚδ¾­Éí·ÝÑéÖ¤µÄÇéÐÎÏÂÏò RAS ЧÀÍÆ÷·¢ËÍÌØÖÆÅþÁ¬ÇëÇ󣬣¬£¬£¬£¬ £¬£¬Õâ¿ÉÄܵ¼Ö RAS ЧÀÍÆ÷ÅÌËã»úÉϵÄÔ¶³Ì´úÂëÖ´ÐÐ (RCE)¡£¡£¡£¡£¡£

΢Èí12Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE

CVE ÎÊÌâ

ÑÏÖØË®Æ½

CVE-2022-41127

Microsoft   Dynamics NAV ºÍ Microsoft Dynamics 365   

Business Central (On Premises)Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-44690

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-44693

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-41076

PowerShell Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-44670

Windows Çå¾²Ì×½Ó×ÖËíµÀЭÒé (SSTP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-44676

Windows Çå¾²Ì×½Ó×ÖËíµÀЭÒé (SSTP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-41089

.NET Framework Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-44699

Azure Network   Watcher ÊðÀíÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2022-44673

Windows ¿Í»§¶ËЧÀÍÆ÷ÔËÐÐʱ×Óϵͳ (CSRSS) ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44675

Windows À¶ÑÀÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44674

Windows À¶ÑÀÇý¶¯³ÌÐòÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-26805

Microsoft   Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-26804

Microsoft   Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-47213

Microsoft   Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-41121

Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44671

Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-47212

Microsoft   Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-26806

Microsoft   Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-47211

Microsoft   Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-41074

Windows ͼÐÎ×é¼þÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-44679

Windows ͼÐÎ×é¼þÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-44680

Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44692

Microsoft   Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-44691

Microsoft Office   OneNote Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-24480

Outlook for   AndroidÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44713

Microsoft   Outlook for Mac ÓÕÆ­Îó²î

¸ßΣ

CVE-2022-44696

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-44695

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-44694

Microsoft Office   Visio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-44668

Windows Media Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-44667

Windows Media Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-44687

Raw Image   ExtensionÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-41094

Windows Hyper-V   ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44682

Windows Hyper-V   ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-44704

Microsoft   Windows Sysmon ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44666

Windows ÁªÏµÈËÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-44710

DirectX ͼÐÎÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44669

Windows ¹ýʧ±¨¸æÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-41077

Windows ´«Õæ×«Ð´±íµ¥ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44678

Windows ºǫ́´òÓ¡³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44707

Windows Äں˾ܾøÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-44683

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44681

Windows ºǫ́´òÓ¡³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44677

Windows ͶӰÎļþÏµÍ³ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44689

ÊÊÓÃÓÚ Linux µÄ Windows ×Óϵͳ (WSL2) ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44702

Windows ÖÕ¶ËÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-41115

Microsoft Edge£¨»ùÓÚ Chromium£©¸üÐÂÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44708

Microsoft Edge£¨»ùÓÚ Chromium£©ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44688

Microsoft Edge£¨»ùÓÚ Chromium£©ÓÕÆ­Îó²î

ÖÐΣ

CVE-2022-44697

Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉýÎó²î

ÖÐΣ

CVE-2022-44698

Windows   SmartScreen Çå¾²¹¦Ð§ÈƹýÎó²î

ÖÐΣ

CVE-2022-4192

Chromium£ºCVE-2022-4192 ÔÚʵʱ×ÖÄ»ÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-4193

Chromium£ºCVE-2022-4193 Îļþϵͳ API ÖеÄÕ½ÂÔÖ´ÐÐȱ·¦

δ֪

CVE-2022-4190

Chromium£ºCVE-2022-4190 Ŀ¼ÖеÄÊý¾ÝÑé֤ȱ·¦

δ֪

CVE-2022-4191

Chromium£ºCVE-2022-4191 µÇ¼ºóÃâ·ÑʹÓÃ

δ֪

CVE-2022-4194

Chromium£ºCVE-2022-4194 ÔÚ Accessibility ÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-4195

Chromium£ºCVE-2022-4195 Çå¾²ä¯ÀÀÖеÄÕþ²ßÖ´ÐÐȱ·¦

δ֪

CVE-2022-4181

Chromium£ºCVE-2022-4181 ÔÚ Forms Ãâ·ÑºóʹÓÃ

δ֪

CVE-2022-4180

Chromium£ºCVE-2022-4180 ÔÚ Mojo ÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-4174

Chromium£ºV8 ÖÐµÄ   CVE-2022-4174 ÀàÐÍ»ìÏý

δ֪

CVE-2022-4182

Chromium£ºCVE-2022-4182 ÔÚ Fenced Frames ÖÐʵÑé²»µ±

δ֪

CVE-2022-4179

Chromium£ºCVE-2022-4179 ÔÚÒôƵÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-4178

Chromium£ºCVE-2022-4178 ÔÚ Mojo ÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-4175

Chromium£ºCVE-2022-4175 ÔÚ Camera Capture ÖÐÊͷźóʹÓÃ

δ֪

CVE-2022-4177

Chromium£ºCVE-2022-4177 ÔÚÀ©Õ¹ÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-4187

Chromium£ºCVE-2022-4187 DevTools ÖеÄÕ½ÂÔÖ´ÐÐȱ·¦

δ֪

CVE-2022-4185

Chromium£ºCVE-2022-4185 ÔÚµ¼º½ÖÐʵÑé²»µ±

δ֪

CVE-2022-4188

Chromium£ºCVE-2022-4188 CORS Öв»¿ÉÐÅÊäÈëµÄÑé֤ȱ·¦

δ֪

CVE-2022-4189

Chromium£ºCVE-2022-4189 DevTools ÖеÄÕ½ÂÔÖ´ÐÐȱ·¦

δ֪

CVE-2022-4186

Chromium£ºCVE-2022-4186 ÏÂÔØÖв»ÊÜÐÅÈεÄÊäÈëÑéÖ¤²»³ä·Ö

δ֪

CVE-2022-4183

Chromium£ºCVE-2022-4183 µ¯³ö´°¿Ú×èÖ¹³ÌÐòÖеÄÕþ²ßÖ´ÐÐȱ·¦

δ֪

CVE-2022-4184

Chromium£ºCVE-2022-4184 ×Ô¶¯Ìî³äÖеÄÕþ²ßÖ´ÐÐȱ·¦

δ֪

ADV220005

ÓйضñÒâʹÓà Microsoft ÊðÃûÇý¶¯³ÌÐòµÄÖ¸ÄÏ

δ֪

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬ £¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬ £¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬ £¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬ £¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬ £¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬ £¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬ £¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£

4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬ £¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬ £¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬ £¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬ £¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£

12ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2022-Dec

²¹¶¡ÏÂÔØÊ¾Àý£º

1.·­¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬£¬ £¬£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£¡£¡£¡£¡£

image.png

Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬£¬ £¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·­¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Çå¾²¸üС¿£¬£¬£¬£¬£¬ £¬£¬·­¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬£¬ £¬£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öᣡ£¡£¡£¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2022-Dec

https://www.bleepingcomputer.com/news/apple/apple-fixes-new-webkit-zero-day-used-in-attacks-against-iphones/

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-12-14

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬ £¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬£¬ £¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬ £¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬ £¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬£¬£¬£¬ £¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬ £¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬ £¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£

 

¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬ £¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png