Outlook¸ßΣԶ³Ì´úÂëÖ´ÐЩ¶´£¬¶«É­Æ½Ì¨Ìṩ½â¾ö·½°¸

Ðû²¼Ê±¼ä 2024-02-23
Microsoft Office OutlookÊÇ΢Èí¿ª·¢µÄ°ì¹«Èí¼þÌ××°ÖеÄÒ»¸ö×é¼þ£¬Ö÷Òª¹¦Ð§ÊÇÊÕ·¢µç×ÓÓʼþ£¬Í¬Ê±¾ßÓйÜÀíÁªÏµÈËÐÅÏ¢¡¢²¿ÊðÈճ̡¢·ÖÅäÈÎÎñµÈ¹¦Ð§¡£


©¶´ÏêÇé


½üÈÕ£¬¶«É­Æ½Ì¨½ð¾¦Äþ¾²Ñо¿ÍŶӼà²âµ½Î¢Èí¶þÔ·ÝÄþ¾²²¹¶¡ÖÐÒ»¸öCVSSÆÀ·ÖΪ9.8µÄ©¶´£¨Microsoft OutlookÔ¶³Ì´úÂëÖ´ÐЩ¶´CVE-2024-21413£©POC±»¹ûÈ»¡£
¾­¹ýÑо¿È·ÈÏ£¬¸Ã©¶´ÈƹýÁËOutlookÖеÄÄþ¾²ÏÞÖÆ£¬µ¼Ö¹¥»÷ÕßÖ»Ðè·¢ËÍÒ»¸öµöÓãÓʼþ£¬¼´¿ÉÔÚÊܺ¦ÕßÎÞÐèÈκν»»¥µÄÇé¿öÏÂй¶ÆäNTLMÉí·Ýƾ¾ÝÐÅÏ¢¡£Í¨¹ý½øÒ»²½µÄÆƽâ»òÕßNTLM relay¹¥»÷£¬¼´¿ÉαÔìÊܺ¦ÕßÉí·Ý½øÐÐÈÏÖ¤£¬´Ó¶ø»ñÈ¡¶ÔӦȨÏÞ¡£Í¬Ê±¸Ã©¶´ÔÚºÍÈÎÒâCOM©¶´½áºÏʹÓÃ(ÈçCVE-2022-30190)µÄʱºò£¬¹¥»÷ÕßÖ»ÐèÓÕµ¼Êܺ¦Õßµã»÷Á´½Ó£¬¼´¿ÉÔÚÓû§µçÄÔÉÏÖ´ÐÐÈÎÒâ´úÂë¡£
¸Ã©¶´ÀûÓÃÄѶȽϵÍ£¬ÓëÈ¥Äê±»APT28×é֯Ƶ·±ÀûÓõÄMicrosoft Outlook È¨ÏÞÌáÉý©¶´(CVE-2023-23397)µÄ¹¥»÷³¡¾°ÀàËÆ£¬ºóÐø±»ÀûÓõĿÉÄÜÐԽϸß¡£Ä¿Ç°¹Ù·½ÒÑÐû²¼Äþ¾²¸üУ¬½¨Òé¿Í»§»ý¼«×öºÃÅŲéºÍ·À»¤¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó°Ïì°æ±¾


Microsoft Office LTSC 2021 for 32-bit/64-bit editions

Microsoft Office 2019 for 32-bit/64-bit editions

Microsoft Office 2016 (32-bit/64-bit edition)

Microsoft 365 Apps for Enterprise for 32-bit/64-bit System


©¶´¸´ÏÖ


Ä¿Ç°ÒÑÀֳɸ´ÏÖÁ½ÖÖ¹¥»÷³¡¾°¡£


1¡¢NTLMй¶


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2¡¢½áºÏÆäËû©¶´´¥·¢RCE


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½â¾ö·½°¸


1¡¢¹Ù·½ÐÞ¸´·½°¸

¹Ù·½ÒÑÐû²¼Äþ¾²¸üУ¬½¨Ò齫ÊÜÓ°ÏìµÄofficeÉý¼¶ÖÁ×îа汾£ºhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21413£¬¶øÇÒÔÚÉý¼¶Ö®Ç°²»ÒªÇáÒ×µã»÷ÓʼþÖеÄÁ´½Ó»ò¸½¼þ¡£


2¡¢¶«É­Æ½Ì¨½â¾ö·½°¸


ÌìãÙÈëÇÖ¼ì²âÓë¹ÜÀíϵͳ¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©¿ÉÓÐЧ·À»¤CVE-2024-21413©¶´Ôì³ÉµÄ¹¥»÷·çÏÕ¡£´ËÍ⣬ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©ÄÚÖÃɳÏä¼ì²â¹¦Ð§£¬Éý¼¶µ½×îв¹¶¡¿ÉÓÐЧ¼ì²âÀûÓø鶴µÄ¶ñÒâÓʼþ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾