¡¾Îó²îͨ¸æ¡¿Î¢Èí12Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2022-12-14


0x00 Îó²î¸ÅÊö

2022Äê12ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬Î¢ÈíÐû²¼ÁË12ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬£¬±¾´Î¸üÐÂÐÞ¸´Á˰üÀ¨2¸ö0 dayÎó²îÔÚÄÚµÄ49¸öÇå¾²Îó²î£¨²»°üÀ¨Ö®Ç°ÐÞ¸´µÄMicrosoft Edge Îó²î£©£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ6¸öÎó²îÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£¡£¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÉæ¼°.NET Framework¡¢Microsoft Dynamics¡¢Microsoft Bluetooth Driver¡¢Microsoft Office¡¢Microsoft Windows Codecs Library¡¢Windows Kernel¡¢Windows PowerShell¡¢Windows Secure Socket Tunneling Protocol (SSTP)¡¢Windows TerminalµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£¡£¡£¡£

±¾´ÎÐÞ¸´µÄÎó²î£¨²»°üÀ¨Microsoft Edge Îó²î£©ÖУ¬£¬£¬£¬£¬£¬19¸öΪÌáÈ¡Îó²î£¬£¬£¬£¬£¬£¬23¸öΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬3¸öΪÐÅϢй¶Îó²î£¬£¬£¬£¬£¬£¬3¸öΪ¾Ü¾øÐ§ÀÍÎó²î£¬£¬£¬£¬£¬£¬2¸öΪÇå¾²¹¦Ð§ÈƹýÎó²î£¬£¬£¬£¬£¬£¬ÒÔ¼°1¸öÓÕÆ­Îó²î¡£¡£¡£¡£¡£¡£¡£

΢Èí±¾´Î¹²ÐÞ¸´ÁË2¸ö0 dayÎó²î£¬£¬£¬£¬£¬£¬ÆäÖÐCVE-2022-44698Òѱ»Æð¾¢Ê¹Ó㬣¬£¬£¬£¬£¬CVE-2022-44710ÒѾ­¹ûÕæÅû¶£º

CVE-2022-44698£ºWindows SmartScreen Çå¾²¹¦Ð§ÈƹýÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ5.4£¬£¬£¬£¬£¬£¬Ê¹ÓøÃÎó²îÐèÓëÓû§½»»¥¡£¡£¡£¡£¡£¡£¡£¿ £¿£¿£¿£¿£¿ÉÒÔͨ¹ý¶ñÒâÎļþÀ´ÈƹýMark of the Web (MOTW)·ÀÓù£¬£¬£¬£¬£¬£¬²¢ÔÚijЩÇéÐÎϵ¼ÖÂSmartScreen¹ýʧ²¢ÇÒ²»ÏÔʾ Web Çå¾²ÖÒÑÔ±ê¼Ç£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö Microsoft Office ÖеÄÊܱ£» £»£»£»£»£»¤ÊÓͼµÈÒÀÀµ MOTW ±ê¼ÇµÄÇå¾²¹¦Ð§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼Ö¶ñÒâ¾ç±¾×Ô¶¯ÔËÐв¢×°ÖöñÒâÈí¼þ£¬£¬£¬£¬£¬£¬ÏÖÔÚ¸ÃÎó²îÒѼì²âµ½Îó²îʹÓᣡ£¡£¡£¡£¡£¡£

CVE-2022-44710£ºDirectX Graphics KernelÌØÈ¨ÌáÉýÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬Ê¹ÓøÃÎó²îÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÒÔ»ñµÃ SYSTEM ȨÏÞ£¬£¬£¬£¬£¬£¬ÏÖÔÚ¸ÃÎó²îÒѾ­¹ûÕæÅû¶¡£¡£¡£¡£¡£¡£¡£

±¾´Î¸üÐÂÖÐÆÀ¼¶ÎªÑÏÖØµÄ6¸öÎó²î°üÀ¨£º

CVE-2022-41127£ºMicrosoft Dynamics NAV ºÍ Microsoft Dynamics 365 Business Central£¨ÍâµØ£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.5£¬£¬£¬£¬£¬£¬Ê¹ÓøÃÎó²îÐè¾­ÓÉÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÃDynamics NAVÖеÄÎó²î¿ÉÒÔÔÚÒÑÉèÖÃʹÓà Dynamics ЧÀÍÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£

CVE-2022-44690/CVE-2022-44693£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÕâЩÎó²îµÄCVSSv3ÆÀ·Ö¾ùΪ8.8£¬£¬£¬£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤²¢¾ßÓÐÖÎÀíÁбíȨÏ޵ĶñÒâÓû§¿ÉÒÔÔÚ SharePoint Server ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£

CVE-2022-41076£ºPowerShell Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.5£¬£¬£¬£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔÌ PowerShell Ô¶³Ì»á»°ÉèÖò¢ÔÚÄ¿µÄϵͳÉÏÔËÐÐδ¾­ÊÚȨµÄÏÂÁî¡£¡£¡£¡£¡£¡£¡£

CVE-2022-44670/CVE-2022-44676£ºWindows Secure Socket Tunneling Protocol £¨SSTP£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÕâЩÎó²îµÄCVSSv3ÆÀ·Ö¾ùΪ8.1£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÃÎó²îÐèÒªÓ®µÃ¾ºÕùÌõ¼þ¡£¡£¡£¡£¡£¡£¡£¿ £¿£¿£¿£¿£¿ÉÒÔÔÚδ¾­Éí·ÝÑéÖ¤µÄÇéÐÎÏÂÏò RAS ЧÀÍÆ÷·¢ËÍÌØÖÆÅþÁ¬ÇëÇ󣬣¬£¬£¬£¬£¬Õâ¿ÉÄܵ¼Ö RAS ЧÀÍÆ÷ÅÌËã»úÉϵÄÔ¶³Ì´úÂëÖ´ÐÐ (RCE)¡£¡£¡£¡£¡£¡£¡£

΢Èí12Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE

CVE ÎÊÌâ

ÑÏÖØË®Æ½

CVE-2022-41127

Microsoft   Dynamics NAV ºÍ Microsoft Dynamics 365   

Business Central (On Premises)Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-44690

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-44693

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-41076

PowerShell Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-44670

Windows Çå¾²Ì×½Ó×ÖËíµÀЭÒé (SSTP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-44676

Windows Çå¾²Ì×½Ó×ÖËíµÀЭÒé (SSTP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2022-41089

.NET Framework Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-44699

Azure Network   Watcher ÊðÀíÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2022-44673

Windows ¿Í»§¶ËЧÀÍÆ÷ÔËÐÐʱ×Óϵͳ (CSRSS) ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44675

Windows À¶ÑÀÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44674

Windows À¶ÑÀÇý¶¯³ÌÐòÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-26805

Microsoft   Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-26804

Microsoft   Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-47213

Microsoft   Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-41121

Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44671

Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-47212

Microsoft   Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-26806

Microsoft   Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-47211

Microsoft   Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-41074

Windows ͼÐÎ×é¼þÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-44679

Windows ͼÐÎ×é¼þÐÅϢй¶Îó²î

¸ßΣ

CVE-2022-44680

Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44692

Microsoft   Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-44691

Microsoft Office   OneNote Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-24480

Outlook for   AndroidÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44713

Microsoft   Outlook for Mac ÓÕÆ­Îó²î

¸ßΣ

CVE-2022-44696

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-44695

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-44694

Microsoft Office   Visio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-44668

Windows Media Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-44667

Windows Media Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-44687

Raw Image   ExtensionÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-41094

Windows Hyper-V   ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44682

Windows Hyper-V   ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-44704

Microsoft   Windows Sysmon ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44666

Windows ÁªÏµÈËÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-44710

DirectX ͼÐÎÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44669

Windows ¹ýʧ±¨¸æÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-41077

Windows ´«Õæ×«Ð´±íµ¥ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44678

Windows ºǫ́´òÓ¡³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44707

Windows Äں˾ܾøÐ§ÀÍÎó²î

¸ßΣ

CVE-2022-44683

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44681

Windows ºǫ́´òÓ¡³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44677

Windows ͶӰÎļþÏµÍ³ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44689

ÊÊÓÃÓÚ Linux µÄ Windows ×Óϵͳ (WSL2) ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44702

Windows ÖÕ¶ËÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2022-41115

Microsoft Edge£¨»ùÓÚ Chromium£©¸üÐÂÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44708

Microsoft Edge£¨»ùÓÚ Chromium£©ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2022-44688

Microsoft Edge£¨»ùÓÚ Chromium£©ÓÕÆ­Îó²î

ÖÐΣ

CVE-2022-44697

Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉýÎó²î

ÖÐΣ

CVE-2022-44698

Windows   SmartScreen Çå¾²¹¦Ð§ÈƹýÎó²î

ÖÐΣ

CVE-2022-4192

Chromium£ºCVE-2022-4192 ÔÚʵʱ×ÖÄ»ÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-4193

Chromium£ºCVE-2022-4193 Îļþϵͳ API ÖеÄÕ½ÂÔÖ´ÐÐȱ·¦

δ֪

CVE-2022-4190

Chromium£ºCVE-2022-4190 Ŀ¼ÖеÄÊý¾ÝÑé֤ȱ·¦

δ֪

CVE-2022-4191

Chromium£ºCVE-2022-4191 µÇ¼ºóÃâ·ÑʹÓÃ

δ֪

CVE-2022-4194

Chromium£ºCVE-2022-4194 ÔÚ Accessibility ÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-4195

Chromium£ºCVE-2022-4195 Çå¾²ä¯ÀÀÖеÄÕþ²ßÖ´ÐÐȱ·¦

δ֪

CVE-2022-4181

Chromium£ºCVE-2022-4181 ÔÚ Forms Ãâ·ÑºóʹÓÃ

δ֪

CVE-2022-4180

Chromium£ºCVE-2022-4180 ÔÚ Mojo ÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-4174

Chromium£ºV8 ÖÐµÄ   CVE-2022-4174 ÀàÐÍ»ìÏý

δ֪

CVE-2022-4182

Chromium£ºCVE-2022-4182 ÔÚ Fenced Frames ÖÐʵÑé²»µ±

δ֪

CVE-2022-4179

Chromium£ºCVE-2022-4179 ÔÚÒôƵÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-4178

Chromium£ºCVE-2022-4178 ÔÚ Mojo ÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-4175

Chromium£ºCVE-2022-4175 ÔÚ Camera Capture ÖÐÊͷźóʹÓÃ

δ֪

CVE-2022-4177

Chromium£ºCVE-2022-4177 ÔÚÀ©Õ¹ÖÐÃâ·ÑʹÓÃ

δ֪

CVE-2022-4187

Chromium£ºCVE-2022-4187 DevTools ÖеÄÕ½ÂÔÖ´ÐÐȱ·¦

δ֪

CVE-2022-4185

Chromium£ºCVE-2022-4185 ÔÚµ¼º½ÖÐʵÑé²»µ±

δ֪

CVE-2022-4188

Chromium£ºCVE-2022-4188 CORS Öв»¿ÉÐÅÊäÈëµÄÑé֤ȱ·¦

δ֪

CVE-2022-4189

Chromium£ºCVE-2022-4189 DevTools ÖеÄÕ½ÂÔÖ´ÐÐȱ·¦

δ֪

CVE-2022-4186

Chromium£ºCVE-2022-4186 ÏÂÔØÖв»ÊÜÐÅÈεÄÊäÈëÑéÖ¤²»³ä·Ö

δ֪

CVE-2022-4183

Chromium£ºCVE-2022-4183 µ¯³ö´°¿Ú×èÖ¹³ÌÐòÖеÄÕþ²ßÖ´ÐÐȱ·¦

δ֪

CVE-2022-4184

Chromium£ºCVE-2022-4184 ×Ô¶¯Ìî³äÖеÄÕþ²ßÖ´ÐÐȱ·¦

δ֪

ADV220005

ÓйضñÒâʹÓà Microsoft ÊðÃûÇý¶¯³ÌÐòµÄÖ¸ÄÏ

δ֪

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£¡£¡£¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£¡£¡£

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£¡£¡£

4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£¡£¡£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£¡£¡£

12ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2022-Dec

²¹¶¡ÏÂÔØÊ¾Àý£º

1.·­¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬£¬£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£¡£¡£¡£¡£¡£¡£

image.png

Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·­¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£¡£¡£¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Çå¾²¸üС¿£¬£¬£¬£¬£¬£¬·­¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬£¬£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öᣡ£¡£¡£¡£¡£¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£¡£¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2022-Dec

https://www.bleepingcomputer.com/news/apple/apple-fixes-new-webkit-zero-day-used-in-attacks-against-iphones/

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-12-14

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£¡£

 

¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png