Ìá½»ÐèÇó
*
*

*
*
*
Á¢¼´Ìá½»
µã»÷¡±Á¢¼´Ìá½»¡±£¬±íÃ÷ÎÒÀí½â²¢Í¬Òâ ¡¶»Æ½ð³Ç¿Æ¼¼Òþ˽Ìõ¿î¡·

logo

    ²úÆ·Óë·þÎñ
    ½â¾ö·½°¸
    ¼¼ÊõÖ§³Ö
    ºÏ×÷·¢Õ¹
    ¹ØÓڻƽð³Ç

    ÉêÇëÊÔÓÃ
      ¡¾Â©¶´Í¨¸æ¡¿ Microsoft Exchange Server OWASSRF©¶´£¨CVE-2022-41080/41082£©
      ·¢²¼Ê±¼ä£º2022-12-28 ÔĶÁ´ÎÊý£º 917 ´Î
      ©¶´ÃèÊö

      »Æ½ð³Ç»Æ½ð³Ç¹ÙÍøÊµÑéÊÒ¼à²âµ½CrowdStrike·¢²¼Õë¶ÔMicrosoft Exchange ServerеÄÀûÓÃÁ´µÄ¼¼Êõϸ½Ú£¬½«ÆäÃüÃûΪ"OWASSRF"£¬Í¨¹ýMicrosoft Exchange ServerȨÏÞÌáÉý©¶´(CVE-2022-41080)ºÍMicrosoft Exchange ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´(CVE-2022-41082)×éºÏÀûÓÿÉͨ¹ýOutlook Web Application (OWA)¶Ëµã×îÖÕÖ´ÐÐÈÎÒâ´úÂ롣Ŀǰ£¬´Ë©¶´ÀûÓÃϸ½ÚÒѹ«¿ª£¬ÇÒ´æÔÚÔÚÒ°ÀûÓá£

      • CVE-2022-41080: Microsoft Exchange ServerȨÏÞÌáÉý©¶´

      ¼òÊö£º¸Ã©¶´´æÔÚÓÚMicrosoft Exchange ServerÖУ¬Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýOutlook Web Application (OWA)¶ËµãÔÚÊÜÓ°ÏìµÄϵͳÉÏ·¢ÆðSSRF¹¥»÷¡£¹¥»÷Õ߿ɽ«¸Ã©¶´ÓëCVE-2022-41082©¶´ÅäºÏʹÓã¬×îÖÕÔÚÄ¿±ê·þÎñÆ÷ÉÏÖ´ÐÐÈÎÒâ´úÂë¡£

      • CVE-2022-41082: Microsoft Exchange ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´

      ¼òÊö£º¸Ã©¶´´æÔÚÓÚMicrosoft Exchange ServerÖУ¬¾ßÓÐÖ´ÐÐPowerShellȨÏÞµÄÔ¶³Ì¹¥»÷Õß¿ÉÀûÓôË©¶´ÔÚÄ¿±êϵͳÉÏÖ´ÐÐÈÎÒâ´úÂë¡£

      Ó°Ï췶Χ
      ÊÜÓ°Ïì°æ±¾£º

      • Microsoft Exchange Server 2013 Cumulative £õ£ð£ä£á£ô£å 23
      • Microsoft Exchange Server 2016 Cumulative £õ£ð£ä£á£ô£å 22
      • Microsoft Exchange Server 2016 Cumulative £õ£ð£ä£á£ô£å 23
      • Microsoft Exchange Server 2019 Cumulative £õ£ð£ä£á£ô£å 11
      • Microsoft Exchange Server 2019 Cumulative £õ£ð£ä£á£ô£å 12

      ´¦Öý¨Òé

      Ŀǰ΢Èí¹Ù·½ÒÑÕë¶ÔÊÜÖ§³ÖµÄ²úÆ·°æ±¾·¢²¼ÁËÐÞ¸´¸Ã©¶´µÄ»Æ½ð³Ç¹ÙÍø²¹¶¡£¬½¨ÒéÊÜÓ°ÏìÓû§¿ªÆôϵͳ×Ô¶¯¸üа²×°²¹¶¡½øÐзÀ»¤¡£

      Windows server / Windows ¼ì²â²¢¿ªÆôWindows×Ô¶¯¸üÐÂÁ÷³ÌÈçÏ£º

      - µã»÷¿ªÊ¼²Ëµ¥£¬ÔÚµ¯³öµÄ²Ëµ¥ÖÐÑ¡Ôñ¡°¿ØÖÆÃæ°å¡±½øÐÐÏÂÒ»²½¡£

      - µã»÷¿ØÖÆÃæ°åÒ³ÃæÖеġ°ÏµÍ³ºÍ»Æ½ð³Ç¹ÙÍø¡±£¬½øÈëÉèÖá£

      - ÔÚµ¯³öµÄеĽçÃæÖÐÑ¡Ôñ¡°windows £õ£ð£ä£á£ô£å¡±Öеġ°ÆôÓûò½ûÓÃ×Ô¶¯¸üС±¡£

      - È»ºó½øÈëÉèÖô°¿Ú£¬Õ¹¿ªÏÂÀ­²Ëµ¥ÏѡÔñÆäÖеÄ×Ô¶¯°²×°¸üУ¨ÍƼö£©¡£


      Ãâ·ÑÊÔÓÃ
      ·þÎñÈÈÏß

      ÂíÉÏ×Éѯ

      400-811-3777

      »Øµ½¶¥²¿
      ¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿