搜尋

情資內容

更新時間:2022/09/16 18:40:07
發佈時間:2022/09/16 18:26:21
TLP: (White)
得對外公開散布,但不得違反著作權法等相關規定

更新說明:

一、漏洞說明[1] Microsoft 通用記錄檔系統驅動程式(Common Log File System,CLFS)存在高風險提權漏洞,並影響多數 Windows 版本,未經身份認證的攻擊者可輕易利用此漏洞取得系統權限。 二、已揭露攻擊程式碼說明[1][2] 相關資安新聞說明觀察到此漏洞遭利用,官方亦已證實。 三、CVSS向量: CVE-2022-37969 [1] 使用版本:CVSS 3.1 分析分數:7.8 參考來源: Microsoft 建議措施: 1.CVE-2022-37969 [1] Microsoft 已於2022年9月例行安全性更新中發布更新,建議會員依照單位內既有漏洞管理機制,評估後執行相關作業。 參考資料: 1. Microsoft https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-37969 2. Bleeping Computer https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2022-patch-tuesday-fixes-zero-day-used-in-attacks-63-flaws/ 影響平台: Windows 10 for 32-bit Systems、x64-based Systems Windows 10 Version 1607 for 32-bit Systems、x64-based Systems Windows 10 Version 1809 for 32-bit Systems、ARM64-based Systems、x64-based Systems Windows 10 Version 20H2 for 32-bit Systems、ARM64-based Systems、x64-based Systems Windows 10 Version 21H1 for 32-bit Systems、ARM64-based Systems、x64-based Systems Windows 10 Version 21H2 for 32-bit Systems、ARM64-based Systems、x64-based Systems Windows 11 for ARM64-based Systems、x64-based Systems Windows 7 for 32-bit Systems Service Pack 1、x64-based Systems Service Pack 1 Windows 8.1 for 32-bit systems、x64-based systems Windows RT 8.1 Windows Server 2008 for 32-bit Systems Service Pack 2 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) Windows Server 2008 for x64-based Systems Service Pack 2 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) Windows Server 2008 R2 for x64-based Systems Service Pack 1 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) Windows Server 2012 Windows Server 2012 (Server Core installation) Windows Server 2012 R2 Windows Server 2012 R2 (Server Core installation) Windows Server 2016 Windows Server 2016 (Server Core installation) Windows Server 2019 Windows Server 2019 (Server Core installation) Windows Server 2022 Windows Server 2022 (Server Core installation) Windows Server 2022 Azure Edition Core Hotpatch
情資編號:
FISAC-ANA-202209-0021
系統目錄:
資安漏洞
資安類別:
資安訊息情資 / 漏洞訊息
影響等級:
3
關鍵字:
弱點漏洞