k8凯发(中国)

      当前位置:首页  网络安全

      【安全更新】Microsoft发布2022年1月安全更新 ​

      时间:2022-01-17   浏览:1126 

      安全公告编号:CNTA-2022-0001

      1月11日,微软发布了2022年1月份的月度例行安全公告,修复了多款产品存在的127个安全漏洞。受影响的产品包括:Windows 11(66个)、Windows Server 2022(81个)、Windows 10 21H1 & 21H2(79个)、Windows 10 20H2 & Windows Server v20H2(81个)、Windows 10 1909(77个)、Windows 8.1 & Server 2012 R2(52个)、Windows Server 2012(49个)、Windows RT 8.1(48个)和Microsoft Office-related software(4个)。

      利用上述漏洞,攻击者可进行欺骗,绕过安全功能限制,获取敏感信息,提升权限,执行远程代码,或发起拒绝服务攻击等。CNVD提醒广大Microsoft用户尽快下载补丁更新,避免引发漏洞相关的网络安全事件。

      CVE编号

      公告标题

      最高严重等级和漏洞影响

      受影响的软件

      CVE-2022-21907

      HTTP Protocol栈远程代码执行漏洞

      严重

      远程代码执行

      Windows 11

      Server 2022

      Server, version 20H2

      Server 2019

      Windows 10

      CVE-2022-21893

      Remote Desktop Protocol远程代码执行漏洞

      重要

      远程代码执行

      Windows 11

      Server 2022

      Server, version 20H2

      Server 2019

      Windows 10

      Server 2016

      Server 2012 R2

      Server 2012

      Windows 8.1

      CVE-2022-21849

      Windows IKE Extension远程代码执行漏洞

      重要

      远程代码执行

      Windows 11

      Server 2022

      Server, version 20H2

      Server 2019

      Windows 10

      Server 2016

      CVE-2022-21922

      Remote Procedure Call Runtime远程代码执行漏洞

      重要

      远程代码执行

      Windows 11

      Server 2022

      Server, version 20H2

      Server 2019

      Windows 10

      Server 2016

      Server 2012 R2

      Server 2012

      Windows 8.1

      CVE-2022-21901

      Windows Hyper-V权限提升漏洞

      重要

      特权提升

      Windows 11

      Server 2022

      Server, version 20H2

      Server 2019

      Windows 10

      Server 2016

      Server 2012 R2

      Windows 8.1

      CVE-2022-21850

      Remote Desktop Client远程代码执行漏洞

      重要

      远程代码执行

      Windows 11

      Server 2022

      Server, version 20H2

      Server 2019

      Windows 10

      Server 2016

      Server 2012 R2

      Server 2012

      Windows 8.1

      Remote Desktop client

      Windows Desktop

      CVE-2022-21920

      Windows Kerberos权限提升漏洞

      重要

      特权提升

      Windows 11

      Server 2022

      Server, version 20H2

      Server 2019

      Windows 10

      Server 2016

      Server 2012 R2

      Server 2012

      Windows 8.1

      CVE-2022-21874

      Windows Installer权限提升漏洞

      重要

      特权提升

      Windows 11

      Server 2022

      Server, version 20H2

      Server, version 2004

      Server 2019

      Windows 10

      Server 2016

      Server 2012 R2

      Server 2012

      Windows 8.1

      CVE-2022-21874

      Windows Security Center API远程代码执行漏洞

      重要

      远程代码执行

      Windows 11

      Server 2022

      Server, version 20H2

      Server 2019

      Windows 10

      Server 2016

      CVE-2022-21857

      Active Directory Domain Services权限提升漏洞

      严重

      远程代码执行

      Windows 11

      Server 2022

      Server, version 20H2

      Server 2019

      Windows 10

      Server 2016

      Server 2012 R2

      Server 2012

      Windows 8.1

      CVE-2022-21836

      Windows Certificate欺骗漏洞

      重要

      欺骗

      Windows 11

      Server 2022

      Server, version 20H2

      Server 2019

      Windows 10

      Server 2016

      Server 2012 R2

      Server 2012

      Windows 8.1

      CVE-2022-21919

      Windows User Profile Service权限提升漏洞

      重要

      特权提升

      Windows 11

      Server 2022

      Server, version 20H2

      Server 2019

      Windows 10

      Server 2016

      Server 2012 R2

      Server 2012

      Windows 8.1

      CVE-2022-21840

      Microsoft Office远程代码执行漏洞

      严重

      远程代码执行

      Excel 2013/2016

      Office 2013/2016/2019

      Office LTSC 2021

      SharePoint Server —

      Subscription Edition

      SharePoint Server —

      Sub Edition Language Pack

      Office Web Apps Server 201

      SharePoint Foundation 2013

      SharePoint Server 2019

      SharePoint Ent. Server 2016

      SharePoint Ent. Server 2013

      365 Apps Enterprise

      Office LTSC for Mac 2021

      Office 2019 for Mac

      Office Online Server

      CVE-2022-21837

      Microsoft SharePoint Server远程代码执行漏洞

      重要

      远程代码执行

      SharePoint Server

      Subscription Edition

      SharePoint Foundation 2013

      SharePoint Enterprise Server 2016

      SharePoint Server 2019

      文章来源:国家信息安全漏洞共享平台