¡¾Â©¶´Í¨¸æ¡¿Î¢Èí1Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2023-01-110x00 ©¶´¸ÅÊö
2023Äê1ÔÂ10ÈÕ£¬Î¢ÈíÐû²¼ÁË1ÔÂÄþ¾²¸üУ¬±¾´Î¸üÐÂÐÞ¸´ÁË°üÂÞ1¸ö0 day©¶´ÔÚÄÚµÄ98¸öÄþ¾²Â©¶´£¬ÆäÖÐÓÐ11¸ö©¶´ÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£
0x01 ©¶´ÏêÇé
±¾´ÎÐû²¼µÄÄþ¾²¸üÐÂÉæ¼°.NET Core¡¢3D Builder¡¢Microsoft Exchange Server¡¢Microsoft Office¡¢Microsoft Office SharePoint¡¢Windows Cryptographic Services¡¢Windows Kernel¡¢Windows Layer 2 Tunneling Protocol¡¢Windows NTLM¡¢Windows RPC API¡¢Windows Secure Socket Tunneling Protocol (SSTP)¡¢Windows Virtual Registry ProviderµÈ¶à¸ö²úÎïºÍ×é¼þ¡£
±¾´ÎÐÞ¸´µÄ©¶´ÖУ¬39¸öΪÌáȡ©¶´£¬33¸öΪԶ³Ì´úÂëÖ´ÐЩ¶´£¬10¸öΪÐÅϢ鶩¶´£¬10¸öΪ¾Ü¾ø·þÎñ©¶´£¬4¸öΪÄþ¾²¹¦Ð§Èƹý©¶´£¬ÒÔ¼°2¸öÆÛÆ©¶´¡£
΢Èí±¾´Î¹²ÐÞ¸´ÁË1¸ö±»ÀûÓõÄ0 day©¶´£¬ÆäÖÐCVE-2023-21674Òѱ»»ý¼«ÀûÓã¬CVE-2023-21549ÒѾ¹ûÈ»Åû¶£º
l CVE-2023-21674£ºWindows Advanced Local Procedure Call (ALPC)ÌØȨÌáÉý©¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬¿ÉÄܵ¼ÖÂä¯ÀÀÆ÷ɳÏäÌÓÒݲ¢ÌáÉýȨÏÞ£¬ÀÖ³ÉÀûÓø鶴¿ÉÒÔ»ñµÃSYSTEM ȨÏÞ£¬Ä¿Ç°¸Ã©¶´ÒѾ¼ì²âµ½Â©¶´ÀûÓá£
l CVE-2023-21549£ºWindows SMB Witness ServiceÌØȨÌáÉý©¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬¿ÉÒÔͨ¹ýÖÆ×÷¶ñÒâ½Å±¾Ö´ÐÐ¶Ô RPC Ö÷»úµÄ RPC µ÷Ó㬵¼ÖÂÔÚ·þÎñÆ÷¶ËÌáÉýȨÏÞ£¬ÀÖ³ÉÀûÓø鶴¿ÉÒÔÖ´ÐнöÏÞÓÚÌØȨÕÊ»§µÄ RPC¹¦Ð§£¬Ä¿Ç°¸Ã©¶´ÒѾ¹ûÈ»Åû¶¡£
±¾´ÎÄþ¾²¸üÐÂÖÐÆÀ¼¶ÎªÑÏÖصÄ11¸ö©¶´°üÂÞ£º
l CVE-2023-21743£ºMicrosoft SharePoint Server Äþ¾²¹¦Ð§Èƹý©¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ5.3£¬Î´¾Éí·ÝÑéÖ¤µÄÓû§¿ÉÒÔÓëÄ¿±ê SharePoint ·þÎñÆ÷½¨Á¢ÄäÃûÁ¬½ÓÀ´ÀûÓø鶴¡£
l CVE-2023-21551/ CVE-2023-21730£ºMicrosoft Cryptographic ServicesÌØȨÌáÉý©¶´
Microsoft¼ÓÃÜ·þÎñ´æÔÚ¶à¸öÄþ¾²Â©¶´£¬ÕâЩ©¶´µÄCVSSv3ÆÀ·ÖΪ7.8£¬ÀÖ³ÉÀûÓÿÉÒÔ»ñµÃSYSTEM ȨÏÞ¡£
l CVE-2023-21561£ºMicrosoft Cryptographic ServicesÌØȨÌáÉý©¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬¾¹ýµ±µØÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔ½«¶ñÒâÊý¾Ý·¢Ë͵½µ±µØ CSRSS ·þÎñ£¬ÒÔ½«ÆäÌØȨ´Ó AppContainer ÌáÉýµ½ SYSTEM¡£
l CVE-2023-21556/CVE-2023-21555/CVE-2023-21543/CVE-2023-21546/CVE-2023-21679£ºWindows Layer 2 Tunneling Protocol (L2TP) Ô¶³Ì´úÂëÖ´ÐЩ¶´
Windows 2²ãËíµÀÐÒé (L2TP)´æÔÚ¶à¸öÄþ¾²Â©¶´£¬ÕâЩ©¶´µÄCVSSv3ÆÀ·Ö¾ùΪ8.1£¬ÀÖ³ÉÀûÓÃÕâЩ©¶´ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ»òÌáÇ°×¼±¸Ä¿±ê»·¾³£¬Î´¾Éí·ÝÑéÖ¤µÄÖ÷»ú¿ÉÒÔÏò RAS ·þÎñÆ÷·¢ËͶñÒâÁ¬½ÓÇëÇ󣬵¼ÖÂÔÚRAS ·þÎñÆ÷¼ÆËã»úÉÏÔ¶³ÌÖ´ÐдúÂë¡£
l CVE-2023-21548£ºWindows Äþ¾²Ì×½Ó×ÖËíµÀÐÒé (SSTP) Ô¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.1£¬ÀÖ³ÉÀûÓø鶴ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬¿ÉÒÔͨ¹ýÏò SSTP ·þÎñÆ÷·¢ËͶñÒâPPTPÊý¾Ý°üÀ´ÀûÓø鶴£¬ÀÖ³ÉÀûÓÿÉÔÚ·þÎñÆ÷¶ËÔ¶³ÌÖ´ÐдúÂë¡£
l CVE-2023-21535£ºWindows Äþ¾²Ì×½Ó×ÖËíµÀÐÒé (SSTP) Ô¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.1£¬ÀÖ³ÉÀûÓø鶴ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬Î´¾Éí·ÝÑéÖ¤µÄÖ÷»ú¿ÉÒÔÏò RAS ·þÎñÆ÷·¢ËͶñÒâÁ¬½ÓÇëÇ󣬵¼ÖÂÔÚRAS ·þÎñÆ÷¼ÆËã»úÉÏÔ¶³ÌÖ´ÐдúÂë¡£
΢Èí1Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º
CVE-ID | CVE ±êÌâ | ÑÏÖØÐÔ |
CVE-2023-21743 | Microsoft SharePoint Server Äþ¾²¹¦Ð§Èƹý©¶´ | ÑÏÖØ |
CVE-2023-21551 | Microsoft ¼ÓÃÜ·þÎñÌØȨÌáÉý©¶´ | ÑÏÖØ |
CVE-2023-21561 | Microsoft ¼ÓÃÜ·þÎñÌØȨÌáÉý©¶´ | ÑÏÖØ |
CVE-2023-21730 | Microsoft ¼ÓÃÜ·þÎñÌØȨÌáÉý©¶´ | ÑÏÖØ |
CVE-2023-21556 | Windows µÚ 2 ²ãËíµÀÐÒé (L2TP) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-21555 | Windows µÚ 2 ²ãËíµÀÐÒé (L2TP) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-21543 | Windows µÚ 2 ²ãËíµÀÐÒé (L2TP) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-21546 | Windows µÚ 2 ²ãËíµÀÐÒé (L2TP) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-21679 | Windows µÚ 2 ²ãËíµÀÐÒé (L2TP) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-21548 | Windows Äþ¾²Ì×½Ó×ÖËíµÀÐÒé (SSTP) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-21535 | Windows Äþ¾²Ì×½Ó×ÖËíµÀÐÒé (SSTP) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-21538 | .NET ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-21782 | 3D Builder Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21781 | 3D Builder Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21783 | 3D Builder Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21784 | 3D Builder Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21791 | 3D Builder Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21793 | 3D Builder Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21786 | 3D Builder Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21790 | 3D Builder Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21780 | 3D Builder Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21792 | 3D Builder Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21789 | 3D Builder Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21785 | 3D Builder Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21787 | 3D Builder Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21788 | 3D Builder Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21531 | Azure Service Fabric ÈÝÆ÷ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21739 | Windows Bluetooth Driver ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21764 | Microsoft Exchange Server ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21763 | Microsoft Exchange Server ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21762 | Microsoft Exchange Server ÆÛÆ©¶´ | ¸ßΣ |
CVE-2023-21761 | Microsoft Exchange Server ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2023-21745 | Microsoft Exchange Server ÆÛÆ©¶´ | ¸ßΣ |
CVE-2023-21680 | Windows Win32k ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21532 | Windows GDI ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21552 | Windows GDI ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21728 | Windows Netlogon ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-21537 | Microsoft Message Queuing(MSMQ) ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21734 | Microsoft Office Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21735 | Microsoft Office Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21742 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21744 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21741 | Microsoft Office Visio ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2023-21736 | Microsoft Office Visio Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21737 | Microsoft Office Visio Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21738 | Microsoft Office Visio Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21681 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21779 | Visual Studio Code Ô¶³Ì´úÂëÖ´ÐÐ | ¸ßΣ |
CVE-2023-21674 | Windows ¸ß¼¶µ±µØ¹ý³Ìµ÷Óà (ALPC) ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21768 | Windows Ancillary Function Driver for WinSock ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21539 | Windows Éí·ÝÑéÖ¤Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21752 | Windows ±¸·Ý·þÎñÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21733 | Windows °ó¶¨É¸Ñ¡Æ÷Çý¶¯·¨Ê½ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21563 | BitLocker Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-21560 | Windows Æô¶¯¹ÜÀíÆ÷Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-21726 | Windows ƾ¾Ý¹ÜÀíÆ÷Óû§½çÃæÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21559 | Windows ÃÜÂëÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2023-21540 | Windows ÃÜÂëÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2023-21550 | Windows ÃÜÂëÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2023-21724 | Microsoft DWM ºËÐÄ¿âÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21558 | Windows ´íÎó³ÂËß·þÎñÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21536 | Event Tracing for WindowsÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2023-21758 | Windows Internet ÃÜÔ¿½»»» (IKE) À©Õ¹¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-21683 | Windows Internet ÃÜÔ¿½»»» (IKE) À©Õ¹¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-21677 | Windows Internet ÃÜÔ¿½»»» (IKE) À©Õ¹¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-21542 | Windows Installer ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21547 | »¥ÁªÍøÃÜÔ¿½»»» (IKE) ÐÒé¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-21527 | Windows iSCSI ·þÎñ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-21755 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21753 | Event Tracing for WindowsÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2023-21676 | Windows ÇáÐÍĿ¼·ÃÎÊÐÒé (LDAP) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21557 | Windows ÇáÐÍĿ¼·ÃÎÊÐÒé (LDAP) ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-21524 | Windows Local Security Authority (LSA) ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21771 | Windows µ±µØ»á»°¹ÜÀíÆ÷ (LSM) ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21725 | Windows ¶ñÒâÈí¼þɾ³ý¹¤¾ßÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21754 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21746 | Windows NTLM ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21732 | Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21766 | WindowsÁýÕÖ¹ýÂËÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2023-21767 | Windows ÁýÕÖ¹ýÂËÆ÷ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21682 | Windows µã¶ÔµãÐÒé (PPP) ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2023-21760 | Windows ºǫ́´òÓ¡·¨Ê½ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21765 | Windows ºǫ́´òÓ¡·¨Ê½ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21678 | Windows ºǫ́´òÓ¡·¨Ê½ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21757 | Windows µÚ 2 ²ãËíµÀÐÒé (L2TP) ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-21525 | Remote Procedure Call Runtime¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-21759 | WindowsÖÇÄÜ¿¨×ÊÔ´¹ÜÀí·þÎñÆ÷Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-21541 | Windows ÈÎÎñ¼Æ»®·¨Ê½ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21772 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21748 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21773 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21747 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21776 | Windows ÄÚºËÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2023-21774 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21750 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21675 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21749 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21549 | Windows SMB Witness ServiceÌØȨÌáÉý©¶´ | ¸ßΣ |
0x02 ´¦Öý¨Òé
Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔز¢°²×°¡£
£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2023Äê1ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2023-Jan
²¹¶¡ÏÂÔØʾÀý£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2022Äê2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý
3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£
Àý3£º²¹¶¡ÏÂÔؽçÃæ
4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£
0x03 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2023-Jan
https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2023-patch-tuesday-fixes-98-flaws-1-zero-day/
0x04 °æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2023-01-11 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
¶«Éƽ̨¼ò½é
¶«Éƽ̨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«Éƽ̨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶«Éƽ̨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦¡£
¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡È«Çò×îÐÂÄþ¾²×ÊѶ£º