¡¾Îó²îͨ¸æ¡¿Î¢Èí3Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2024-03-13


Ò»¡¢Îó²î¸ÅÊö

2024Äê3ÔÂ12ÈÕ £¬£¬£¬£¬Î¢ÈíÐû²¼ÁË3ÔÂÇå¾²¸üР£¬£¬£¬£¬±¾´Î¸üй²ÐÞ¸´ÁË60¸öÎó²î£¨²»°üÀ¨3ÔÂ7ÈÕÐÞ¸´µÄ4¸öMicrosoft EdgeÎó²î£© £¬£¬£¬£¬Îó²îÀàÐͰüÀ¨ÌØÈ¨ÌáÉýÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾øÐ§ÀÍÎó²îºÍÓÕÆ­Îó²îµÈ¡£¡£¡£¡£¡£

±¾´ÎÇå¾²¸üÐÂÖв»°üÀ¨±»Æð¾¢Ê¹ÓõÄ0 dayÎó²î £¬£¬£¬£¬ÆäÖÐÆÀ¼¶Îª¡°ÑÏÖØ¡±µÄ2¸öÎó²î°üÀ¨£º

CVE-2024-21407£ºWindows Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.1 £¬£¬£¬£¬Ê¹ÓøÃÎó²îÐèÒªGuest VMÉϾ­ÓÉÉí·ÝÑéÖ¤µÄÍþвÕßÏòÐéÄâ»úÉϵÄÓ²¼þ×ÊÔ´·¢ËÍÌØÖÆµÄÎļþ²Ù×÷ÇëÇó £¬£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÔÚÖ÷»úЧÀÍÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£

CVE-2024-21408£ºWindows Hyper-V ¾Ü¾øÐ§ÀÍÎó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ5.5 £¬£¬£¬£¬Ó°ÏìÁËWindows Server 2016/2019/2022¡¢Windows 10/11µÈ¶à¸ö°æ±¾ £¬£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£

±¾´ÎÇå¾²¸üÐÂÖÐÆäËûÐèÒª¹Ø×¢µÄÎó²î»¹°üÀ¨µ«²»ÏÞÓÚ£º

CVE-2024-21400£ºMicrosoft Azure Kubernetes Service Confidential ContainerÌØÈ¨ÌáÉýÎó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.0 £¬£¬£¬£¬ÍþвÕß¿ÉÒÔ»á¼û²»ÊÜÐÅÈ뵀 AKS Kubernetes ½ÚµãºÍ AKSÉñÃØÈÝÆ÷ £¬£¬£¬£¬´Ó¶ø½ÓÊÜÆä¿ÉÄܰ󶨵ÄÍøÂç¿ÍÕ»Ö®ÍâµÄÉñÃØguestsºÍÈÝÆ÷¡£¡£¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕß¿ÉÒÔÇÔȡƾ֤²¢Ó°Ïì Azure Kubernetes ЧÀÍÉñÃØÈÝÆ÷ (AKSCC) ÖÎÀíµÄÇå¾²¹æÄ£Ö®ÍâµÄ×ÊÔ´¡£¡£¡£¡£¡£

CVE-2024-26199£ºMicrosoft OfficeÌØÈ¨ÌáÉýÎó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8 £¬£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§¿ÉʹÓøÃÎó²î»ñµÃSYSTEMȨÏÞ¡£¡£¡£¡£¡£

CVE-2024-20671£ºMicrosoft Defender Çå¾²¹¦Ð§ÈƹýÎó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ5.5 £¬£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉʹÓøÃÎó²î×èÖ¹ Microsoft Defender Æô¶¯¡£¡£¡£¡£¡£¸ÃÎó²îÒÑÔÚWindows Defender°æ±¾4.18.24010.12ÖÐÐÞ¸´ £¬£¬£¬£¬¿Éͨ¹ý Windows ×°±¸ÉÏ×Ô¶¯×°ÖÃµÄ Windows Defender ·´¶ñÒâÈí¼þƽ̨¸üоÙÐÐÐÞ¸´¡£¡£¡£¡£¡£

CVE-2024-21411£ºSkype for Consumer Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8 £¬£¬£¬£¬ÍþвÕß¿ÉÒÔͨ¹ý¼´Ê±ÐÂÎÅÏòÓû§·¢ËͶñÒâÁ´½Ó»ò¶ñÒâͼÏñ £¬£¬£¬£¬È»ºóÓÕʹÓû§µ¥»÷¸ÃÁ´½Ó»òͼÏñÀ´Ê¹ÓøÃÎó²î £¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕß¿ÉÒÔ»ñµÃ¶ÁÈ¡¡¢Ð´ÈëºÍɾ³ýµÈȨÏÞ¡£¡£¡£¡£¡£

CVE-2024-21334£ºOpen Management Infrastructure (OMI) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8 £¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÒÔ´Ó Internet »á¼û OMI ʵÀý²¢·¢ËÍÌØÖÆÇëÇóÒÔ´¥·¢ÊͷźóʹÓÃÎó²î £¬£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£ÔËÐÐÊÜÓ°ÏìµÄ SCOM (System Center Operations Manager) °æ±¾µÄ¿Í»§Ó¦¸üе½ OMI °æ±¾1.8.1-0¡£¡£¡£¡£¡£

CVE-2024-26198£ºMicrosoft Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8 £¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔͨ¹ý½«ÌØÖÆÎļþ°²Åŵ½ÔÚÏßĿ¼»òÍâµØÍøÂçλÖà £¬£¬£¬£¬È»ºóÓÕµ¼Óû§·­¿ªÎļþÀ´Ê¹ÓøÃÎó²î £¬£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼Ö¼ÓÔØ¶ñÒâ DLL £¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£

΢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀÖС°±»Ê¹ÓõĿÉÄÜÐԽϸߡ±µÄÎó²î°üÀ¨£º

CVE-2024-21433£ºWindows Print SpoolerÌØÈ¨ÌáÉýÎó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.0 £¬£¬£¬£¬Ê¹ÓøÃÎó²îÐèÒªÓ®µÃ¾ºÕùÌõ¼þ £¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕ߿ɻñµÃSYSTEMȨÏÞ¡£¡£¡£¡£¡£

CVE-2024-21437£ºWindows Graphics ComponentÌØÈ¨ÌáÉýÎó²î

Windows ͼÐÎ×é¼þ±£´æÈ¨ÏÞÌáÉýÎó²î £¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8 £¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕ߿ɻñµÃSYSTEMȨÏÞ¡£¡£¡£¡£¡£

CVE-2024-26160£ºWindows Cloud Files Mini Filter DriverÐÅϢй¶Îó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ5.5 £¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕß¿ÉÒÔ´ÓÓû§Ä£Ê½Àú³Ì¶ÁÈ¡ÄÚºËÄÚ´æµÄÄÚÈÝ¡£¡£¡£¡£¡£

CVE-2024-26170£ºWindows Composite Image File System (CimFS) ÌØÈ¨ÌáÉýÎó²î

Windows ¸´ºÏÓ³ÏñÎļþϵͳ (CimFS)±£´æÈ¨ÏÞÌáÉýÎó²î £¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8 £¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕ߿ɻñµÃÊÜÏÞSYSTEMȨÏÞ¡£¡£¡£¡£¡£

CVE-2024-26182£ºWindows KernelÌØÈ¨ÌáÉýÎó²î

Windows Äں˱£´æÌØÈ¨ÌáÉýÎó²î £¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8 £¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕ߿ɻñµÃSYSTEMȨÏÞ¡£¡£¡£¡£¡£

CVE-2024-26185£ºWindows ѹËõÎļþ¼Ð¸Ä¶¯Îó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ6.5 £¬£¬£¬£¬Ó°ÏìÁËWindows 11¶à¸ö°æ±¾¡£¡£¡£¡£¡£ÍþвÕß¿Éͨ¹ýÔÚµç×ÓÓʼþÖÐÏòÓû§·¢ËÍÌØÖÆÎļþ²¢ÓÕµ¼Óû§·­¿ª¸ÃÎļþ £¬£¬£¬£¬»òÓÕµ¼Óû§µ¥»÷¶ñÒâÍøÕ¾»òwebÁ´½Ó²¢·­¿ªÌØÖÆÎļþÀ´Ê¹ÓøÃÎó²î £¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÆÆËðϵͳÍêÕûÐÔ¡£¡£¡£¡£¡£

΢Èí3Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE ID

CVE ÎÊÌâ

ÑÏÖØÐÔ

CVE-2024-21407

Windows   Hyper-V Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2024-21408

Windows   Hyper-V ¾Ü¾øÐ§ÀÍÎó²î

ÑÏÖØ

CVE-2024-21392

.NET ºÍ Visual Studio ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2024-26203

Azure Data   Studio ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2024-21421

Azure SDK ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-28746

Intel£ºCVE-2023-28746 ¼Ä´æÆ÷ÎļþÊý¾Ý²ÉÑù (RFDS)

¸ßΣ

CVE-2024-21390

Microsoft   Authenticator ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2024-21400

Microsoft   Azure Kubernetes Service Confidential Container ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2024-26164

Microsoft   Django Backend for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21419

Microsoft   Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾Îó²î

¸ßΣ

CVE-2024-26198

Microsoft   Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21437

Windows   Graphics Component ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2024-26201

Microsoft   Intune Linux Agent ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2024-26199

Microsoft   Office ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2024-21426

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-26190

Microsoft   QUIC ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2024-21448

Microsoft   Teams for Android ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-21451

Microsoft   ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21441

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-26161

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-26166

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21444

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21450

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21434

Microsoft   Windows SCSI Class System File ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2024-21330

Open   Management Infrastructure (OMI) ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2024-21334

Open   Management Infrastructure (OMI) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-26204

Outlook   for Android ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-21411

Skype for   Consumer Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21418

Software   for Open Networking in the Cloud (SONiC) ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2024-26165

Visual   Studio Code ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2024-21438

Microsoft   AllJoyn API ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2024-26160

Windows   Cloud Files Mini Filter Driver ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-26170

Windows   Composite Image File System (CimFS) ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2024-26185

Windows ѹËõÎļþ¼Ð¸Ä¶¯Îó²î

¸ßΣ

CVE-2024-20671

Microsoft   Defender Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-26169

Windows   Error Reporting Service ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2024-21431

Hypervisor-Protected   Code Integrity (HVCI) Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-21436

Windows   Installer ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2024-21427

Windows   Kerberos Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-26177

Windows ÄÚºËÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-26176

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2024-26174

Windows ÄÚºËÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-26182

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2024-26181

Windows Äں˾ܾøÐ§ÀÍÎó²î

¸ßΣ

CVE-2024-26178

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2024-26173

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2024-21443

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2024-21446

NTFS ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2024-21440

Microsoft   ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-26162

Microsoft   ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-26159

Microsoft   ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21435

Windows   OLE Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21433

Windows   Print Spooler ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2024-26197

Windows   Standards-Based Storage Management Service ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2024-21439

Windows   Telephony Server ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2024-21432

Windows   Update Stack ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2024-21429

Windows   USB Hub Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21442

Windows   USB Print Driver ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2024-21445

Windows   USB Print Driver ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2024-21430

Windows   USB Attached SCSI (UAS) Protocol Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-2174

Chromium£ºCVE-2024-2174 V8 ÖеÄʵÑé²»µ±

δ֪

CVE-2024-2173

Chromium£ºCVE-2024-2173 V8 ÖеÄÄÚ´æ»á¼ûÔ½½ç

δ֪

CVE-2024-2176

Chromium£ºCVE-2024-2176 ÔÚ FedCM ÖÐÊͷźóʹÓÃ

δ֪

CVE-2024-26167

Microsoft   Edge for Android ÓÕÆ­Îó²î

δ֪

 

 

¶þ¡¢Ó°Ïì¹æÄ£

ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/ЧÀÍ/×é¼þ°üÀ¨£º

Windows Defender

Open Management Infrastructure

Microsoft Authenticator

.NET

Microsoft Azure Kubernetes Service

Role: Windows Hyper-V

Skype for Consumer

Software for Open Networking in the Cloud (SONiC)

Microsoft Dynamics

Azure SDK

Microsoft Office SharePoint

Windows Kerberos

Windows USB Hub Driver

Windows USB Serial Driver

Windows Hypervisor-Protected Code Integrity

Windows Update Stack

Windows Print Spooler Components

Microsoft Windows SCSI Class System File

Windows OLE

Windows Installer

Microsoft Graphics Component

Windows AllJoyn API

Windows Telephony Server

Windows ODBC Driver

Microsoft WDAC OLE DB provider for SQL

Windows USB Print Driver

Windows Kernel

Windows NTFS

Microsoft Teams for Android

Microsoft WDAC ODBC Driver

Windows Cloud Files Mini Filter Driver

SQL Server

Visual Studio Code

Microsoft Edge for Android

Windows Error Reporting

Windows Composite Image File System

Windows Compressed Folder

Microsoft QUIC

Windows Standards-Based Storage Management Service

Microsoft Exchange Server

Microsoft Office

Microsoft Intune

Azure Data Studio

Outlook for Android

 


Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üР£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓà £¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ £¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϰ취ÊÖ¶¯¾ÙÐиüУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü £¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡± £¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС± £¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС± £¬£¬£¬£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£

4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú £¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüР£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó £¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡± £¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£

2024Äê3ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Mar

²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º

1.·­¿ªÉÏÊöÏÂÔØÁ´½Ó £¬£¬£¬£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£¡£¡£¡£¡£

image.png

Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2022Äê2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ £¬£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·­¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Çå¾²¸üС¿ £¬£¬£¬£¬·­¿ª²¹¶¡ÏÂÔØÒ³Ãæ £¬£¬£¬£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öᣡ£¡£¡£¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£¡£¡£¡£¡£

3.2 ÔÝʱ²½·¥

ÔÝÎÞ¡£¡£¡£¡£¡£

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡ £¬£¬£¬£¬ïÔ̭ϵͳÎó²î £¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ £¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ £¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ £¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ· £¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí £¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Mar

https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2024-patch-tuesday-fixes-60-flaws-18-rce-bugs/

  

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-03-13

Ê×´ÎÐû²¼

 


Îå¡¢¸½Â¼

5.1 ¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø½¨ÉèÓÚ1996Äê £¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏà £¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË £¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ £¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ £¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£

5.2 ¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯ £¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î £¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png