¡¾Îó²îͨ¸æ¡¿Î¢Èí3Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2024-03-13Ò»¡¢Îó²î¸ÅÊö
2024Äê3ÔÂ12ÈÕ£¬£¬£¬£¬Î¢ÈíÐû²¼ÁË3ÔÂÇå¾²¸üУ¬£¬£¬£¬±¾´Î¸üй²ÐÞ¸´ÁË60¸öÎó²î£¨²»°üÀ¨3ÔÂ7ÈÕÐÞ¸´µÄ4¸öMicrosoft EdgeÎó²î£©£¬£¬£¬£¬Îó²îÀàÐͰüÀ¨ÌØÈ¨ÌáÉýÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾øÐ§ÀÍÎó²îºÍÓÕÆÎó²îµÈ¡£¡£¡£¡£¡£
±¾´ÎÇå¾²¸üÐÂÖв»°üÀ¨±»Æð¾¢Ê¹ÓõÄ0 dayÎó²î£¬£¬£¬£¬ÆäÖÐÆÀ¼¶Îª¡°ÑÏÖØ¡±µÄ2¸öÎó²î°üÀ¨£º
CVE-2024-21407£ºWindows Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.1£¬£¬£¬£¬Ê¹ÓøÃÎó²îÐèÒªGuest VMÉϾÓÉÉí·ÝÑéÖ¤µÄÍþвÕßÏòÐéÄâ»úÉϵÄÓ²¼þ×ÊÔ´·¢ËÍÌØÖÆµÄÎļþ²Ù×÷ÇëÇ󣬣¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÔÚÖ÷»úЧÀÍÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£
CVE-2024-21408£ºWindows Hyper-V ¾Ü¾øÐ§ÀÍÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ5.5£¬£¬£¬£¬Ó°ÏìÁËWindows Server 2016/2019/2022¡¢Windows 10/11µÈ¶à¸ö°æ±¾£¬£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£
±¾´ÎÇå¾²¸üÐÂÖÐÆäËûÐèÒª¹Ø×¢µÄÎó²î»¹°üÀ¨µ«²»ÏÞÓÚ£º
CVE-2024-21400£ºMicrosoft Azure Kubernetes Service Confidential ContainerÌØÈ¨ÌáÉýÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.0£¬£¬£¬£¬ÍþвÕß¿ÉÒÔ»á¼û²»ÊÜÐÅÈ뵀 AKS Kubernetes ½ÚµãºÍ AKSÉñÃØÈÝÆ÷£¬£¬£¬£¬´Ó¶ø½ÓÊÜÆä¿ÉÄܰ󶨵ÄÍøÂç¿ÍÕ»Ö®ÍâµÄÉñÃØguestsºÍÈÝÆ÷¡£¡£¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕß¿ÉÒÔÇÔȡƾ֤²¢Ó°Ïì Azure Kubernetes ЧÀÍÉñÃØÈÝÆ÷ (AKSCC) ÖÎÀíµÄÇå¾²¹æÄ£Ö®ÍâµÄ×ÊÔ´¡£¡£¡£¡£¡£
CVE-2024-26199£ºMicrosoft OfficeÌØÈ¨ÌáÉýÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬¾ÓÉÉí·ÝÑéÖ¤µÄÓû§¿ÉʹÓøÃÎó²î»ñµÃSYSTEMȨÏÞ¡£¡£¡£¡£¡£
CVE-2024-20671£ºMicrosoft Defender Çå¾²¹¦Ð§ÈƹýÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ5.5£¬£¬£¬£¬¾ÓÉÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉʹÓøÃÎó²î×èÖ¹ Microsoft Defender Æô¶¯¡£¡£¡£¡£¡£¸ÃÎó²îÒÑÔÚWindows Defender°æ±¾4.18.24010.12ÖÐÐÞ¸´£¬£¬£¬£¬¿Éͨ¹ý Windows ×°±¸ÉÏ×Ô¶¯×°ÖÃµÄ Windows Defender ·´¶ñÒâÈí¼þƽ̨¸üоÙÐÐÐÞ¸´¡£¡£¡£¡£¡£
CVE-2024-21411£ºSkype for Consumer Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8£¬£¬£¬£¬ÍþвÕß¿ÉÒÔͨ¹ý¼´Ê±ÐÂÎÅÏòÓû§·¢ËͶñÒâÁ´½Ó»ò¶ñÒâͼÏñ£¬£¬£¬£¬È»ºóÓÕʹÓû§µ¥»÷¸ÃÁ´½Ó»òͼÏñÀ´Ê¹ÓøÃÎó²î£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕß¿ÉÒÔ»ñµÃ¶ÁÈ¡¡¢Ð´ÈëºÍɾ³ýµÈȨÏÞ¡£¡£¡£¡£¡£
CVE-2024-21334£ºOpen Management Infrastructure (OMI) Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÒÔ´Ó Internet »á¼û OMI ʵÀý²¢·¢ËÍÌØÖÆÇëÇóÒÔ´¥·¢ÊͷźóʹÓÃÎó²î£¬£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£ÔËÐÐÊÜÓ°ÏìµÄ SCOM (System Center Operations Manager) °æ±¾µÄ¿Í»§Ó¦¸üе½ OMI °æ±¾1.8.1-0¡£¡£¡£¡£¡£
CVE-2024-26198£ºMicrosoft Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔͨ¹ý½«ÌØÖÆÎļþ°²Åŵ½ÔÚÏßĿ¼»òÍâµØÍøÂçλÖ㬣¬£¬£¬È»ºóÓÕµ¼Óû§·¿ªÎļþÀ´Ê¹ÓøÃÎó²î£¬£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼Ö¼ÓÔØ¶ñÒâ DLL£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£
΢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀÖС°±»Ê¹ÓõĿÉÄÜÐԽϸߡ±µÄÎó²î°üÀ¨£º
CVE-2024-21433£ºWindows Print SpoolerÌØÈ¨ÌáÉýÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.0£¬£¬£¬£¬Ê¹ÓøÃÎó²îÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕ߿ɻñµÃSYSTEMȨÏÞ¡£¡£¡£¡£¡£
CVE-2024-21437£ºWindows Graphics ComponentÌØÈ¨ÌáÉýÎó²î
Windows ͼÐÎ×é¼þ±£´æÈ¨ÏÞÌáÉýÎó²î£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕ߿ɻñµÃSYSTEMȨÏÞ¡£¡£¡£¡£¡£
CVE-2024-26160£ºWindows Cloud Files Mini Filter DriverÐÅϢй¶Îó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ5.5£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕß¿ÉÒÔ´ÓÓû§Ä£Ê½Àú³Ì¶ÁÈ¡ÄÚºËÄÚ´æµÄÄÚÈÝ¡£¡£¡£¡£¡£
CVE-2024-26170£ºWindows Composite Image File System (CimFS) ÌØÈ¨ÌáÉýÎó²î
Windows ¸´ºÏÓ³ÏñÎļþϵͳ (CimFS)±£´æÈ¨ÏÞÌáÉýÎó²î£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕ߿ɻñµÃÊÜÏÞSYSTEMȨÏÞ¡£¡£¡£¡£¡£
CVE-2024-26182£ºWindows KernelÌØÈ¨ÌáÉýÎó²î
Windows Äں˱£´æÌØÈ¨ÌáÉýÎó²î£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕ߿ɻñµÃSYSTEMȨÏÞ¡£¡£¡£¡£¡£
CVE-2024-26185£ºWindows ѹËõÎļþ¼Ð¸Ä¶¯Îó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ6.5£¬£¬£¬£¬Ó°ÏìÁËWindows 11¶à¸ö°æ±¾¡£¡£¡£¡£¡£ÍþвÕß¿Éͨ¹ýÔÚµç×ÓÓʼþÖÐÏòÓû§·¢ËÍÌØÖÆÎļþ²¢ÓÕµ¼Óû§·¿ª¸ÃÎļþ£¬£¬£¬£¬»òÓÕµ¼Óû§µ¥»÷¶ñÒâÍøÕ¾»òwebÁ´½Ó²¢·¿ªÌØÖÆÎļþÀ´Ê¹ÓøÃÎó²î£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÆÆËðϵͳÍêÕûÐÔ¡£¡£¡£¡£¡£
΢Èí3Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º
CVE ID | CVE ÎÊÌâ | ÑÏÖØÐÔ |
CVE-2024-21407 | Windows Hyper-V Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2024-21408 | Windows Hyper-V ¾Ü¾øÐ§ÀÍÎó²î | ÑÏÖØ |
CVE-2024-21392 | .NET ºÍ Visual Studio ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2024-26203 | Azure Data Studio ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21421 | Azure SDK ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-28746 | Intel£ºCVE-2023-28746 ¼Ä´æÆ÷ÎļþÊý¾Ý²ÉÑù (RFDS) | ¸ßΣ |
CVE-2024-21390 | Microsoft Authenticator ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21400 | Microsoft Azure Kubernetes Service Confidential Container ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-26164 | Microsoft Django Backend for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21419 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2024-26198 | Microsoft Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21437 | Windows Graphics Component ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-26201 | Microsoft Intune Linux Agent ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-26199 | Microsoft Office ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21426 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-26190 | Microsoft QUIC ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2024-21448 | Microsoft Teams for Android ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-21451 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21441 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-26161 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-26166 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21444 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21450 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21434 | Microsoft Windows SCSI Class System File ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21330 | Open Management Infrastructure (OMI) ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21334 | Open Management Infrastructure (OMI) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-26204 | Outlook for Android ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-21411 | Skype for Consumer Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21418 | Software for Open Networking in the Cloud (SONiC) ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-26165 | Visual Studio Code ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21438 | Microsoft AllJoyn API ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2024-26160 | Windows Cloud Files Mini Filter Driver ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-26170 | Windows Composite Image File System (CimFS) ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-26185 | Windows ѹËõÎļþ¼Ð¸Ä¶¯Îó²î | ¸ßΣ |
CVE-2024-20671 | Microsoft Defender Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2024-26169 | Windows Error Reporting Service ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21431 | Hypervisor-Protected Code Integrity (HVCI) Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2024-21436 | Windows Installer ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21427 | Windows Kerberos Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2024-26177 | Windows ÄÚºËÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-26176 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-26174 | Windows ÄÚºËÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-26182 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-26181 | Windows Äں˾ܾøÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2024-26178 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-26173 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21443 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21446 | NTFS ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21440 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-26162 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-26159 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21435 | Windows OLE Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21433 | Windows Print Spooler ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-26197 | Windows Standards-Based Storage Management Service ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2024-21439 | Windows Telephony Server ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21432 | Windows Update Stack ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21429 | Windows USB Hub Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21442 | Windows USB Print Driver ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21445 | Windows USB Print Driver ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21430 | Windows USB Attached SCSI (UAS) Protocol Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-2174 | Chromium£ºCVE-2024-2174 V8 ÖеÄʵÑé²»µ± | δ֪ |
CVE-2024-2173 | Chromium£ºCVE-2024-2173 V8 ÖеÄÄÚ´æ»á¼ûÔ½½ç | δ֪ |
CVE-2024-2176 | Chromium£ºCVE-2024-2176 ÔÚ FedCM ÖÐÊͷźóʹÓà | δ֪ |
CVE-2024-26167 | Microsoft Edge for Android ÓÕÆÎó²î | δ֪ |
¶þ¡¢Ó°Ïì¹æÄ£
ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/ЧÀÍ/×é¼þ°üÀ¨£º
Windows Defender
Open Management Infrastructure
Microsoft Authenticator
.NET
Microsoft Azure Kubernetes Service
Role: Windows Hyper-V
Skype for Consumer
Software for Open Networking in the Cloud (SONiC)
Microsoft Dynamics
Azure SDK
Microsoft Office SharePoint
Windows Kerberos
Windows USB Hub Driver
Windows USB Serial Driver
Windows Hypervisor-Protected Code Integrity
Windows Update Stack
Windows Print Spooler Components
Microsoft Windows SCSI Class System File
Windows OLE
Windows Installer
Microsoft Graphics Component
Windows AllJoyn API
Windows Telephony Server
Windows ODBC Driver
Microsoft WDAC OLE DB provider for SQL
Windows USB Print Driver
Windows Kernel
Windows NTFS
Microsoft Teams for Android
Microsoft WDAC ODBC Driver
Windows Cloud Files Mini Filter Driver
SQL Server
Visual Studio Code
Microsoft Edge for Android
Windows Error Reporting
Windows Composite Image File System
Windows Compressed Folder
Microsoft QUIC
Windows Standards-Based Storage Management Service
Microsoft Exchange Server
Microsoft Office
Microsoft Intune
Azure Data Studio
Outlook for Android
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϰ취ÊÖ¶¯¾ÙÐиüУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£
4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£
2024Äê3ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2024-Mar
²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º
1.·¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£¡£¡£¡£¡£
Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2022Äê2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾Çå¾²¸üС¿£¬£¬£¬£¬·¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öᣡ£¡£¡£¡£
Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£¡£¡£¡£¡£
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Mar
https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2024-patch-tuesday-fixes-60-flaws-18-rce-bugs/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-03-13 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¼øºÚµ£±£Íø¼ò½é
¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£
5.2 ¹ØÓÚ¼øºÚµ£±£Íø
¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£
¹Ø×¢ÎÒÃÇ£º