¡¾Â©¶´Í¨¸æ¡¿Î¢Èí4Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2023-04-12


Ò»¡¢Â©¶´¸ÅÊö

2023Äê4ÔÂ11ÈÕ£¬Î¢ÈíÐû²¼ÁË4ÔÂÄþ¾²¸üУ¬±¾´Î¸üÐÂÐÞ¸´Á˰üÂÞ1¸ö0 day©¶´ÔÚÄÚµÄ97¸öÄþ¾²Â©¶´£¨²»°üÂÞMicrosoft Edge©¶´£©£¬ÆäÖÐÓÐ7¸ö©¶´ÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£

±¾´ÎÐÞ¸´µÄ©¶´ÖУ¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´ºÍÆÛƭ©¶´µÈ¡£

΢Èí±¾´Î¹²ÐÞ¸´ÁË1¸ö±»»ý¼«ÀûÓõÄ0 day©¶´£¬ÈçÏ£º

CVE-2023-28252 £ºWindows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

Windows CLFS Çý¶¯·¨Ê½ÖдæÔÚÔ½½çдÈë©¶´£¬µ±µØµÍȨÏÞÓû§¿ÉÒÔͨ¹ý»ù±¾ÈÕÖ¾Îļþ£¨.blf ÎļþÀ©Õ¹Ãû£©µÄ²Ù×÷´¥·¢¸Ã©¶´£¬ÀÖ³ÉÀûÓøÃ©¶´¿Éµ¼Öµ±µØÈ¨ÏÞÌáÉýΪSYSTEM¡£¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.8£¬Ä¿Ç°ÒÑ·¢ÏÖ±»Nokoyawa ÀÕË÷Èí¼þÀûÓá£

±¾´ÎÄþ¾²¸üÐÂÖÐÆÀ¼¶ÎªÑÏÖØµÄ7¸ö©¶´°üÂÞ£º

CVE-2023-21554£ºMicrosoft ÏûÏ¢ÐÐÁÐÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ9.8£¬¿ÉÒÔͨ¹ý·¢ËͶñÒâÖÆ×÷µÄMSMQ Êý¾Ý°üµ½MSMQ ·þÎñÆ÷À´ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼ÖÂÔÚ·þÎñÆ÷¶ËÔ¶³ÌÖ´ÐдúÂë¡£ÀûÓøÃ©¶´ÐèÒªÆôÓÃ×÷ΪWindows ×é¼þµÄWindows ÏûÏ¢ÐÐÁзþÎñ£¬¿ÉÒÔͨ¹ý¼ì²éÊÇ·ñÓÐÃûΪMessage QueuingµÄ·þÎñÔÚÔËÐУ¬ÒÔ¼°¼ÆËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£

CVE-2023-28231£ºDHCP Server Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬¾­¹ýÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔÀûÓÃÕë¶Ô DHCP ·þÎñµÄÌØÖÆ RPC µ÷ÓÃÀ´ÀûÓøÃ©¶´¡£

CVE-2023-28219/ CVE-2023-28220£º¶þ²ãËíµÀЭÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.1£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔÏò RAS ·þÎñÆ÷·¢ËͶñÒâÁ¬½ÓÇëÇó£¬Õâ¿ÉÄܵ¼Ö RAS ·þÎñÆ÷¼ÆËã»úÉϵÄÔ¶³Ì´úÂëÖ´ÐУ¬µ«ÀûÓøÃ©¶´ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ¡£

CVE-2023-28250£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ9.8£¬µ±ÆôÓÃWindowsÏûÏ¢ÐÐÁзþÎñʱ£¬ÀÖ³ÉÀûÓøÃ©¶´µÄÍþвÕß¿ÉÒÔͨ¹ýÍøÂç·¢ËÍÌØÖÆµÄÎļþ£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐУ¬²¢´¥·¢¶ñÒâ´úÂë¡£ÀûÓøÃ©¶´ÐèÒªÆôÓÃ×÷ΪWindows ×é¼þµÄWindows ÏûÏ¢ÐÐÁзþÎñ£¬¿ÉÒÔͨ¹ý¼ì²éÊÇ·ñÓÐÃûΪMessage QueuingµÄ·þÎñÔÚÔËÐУ¬ÒÔ¼°¼ÆËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£

CVE-2023-28232£ºWindows µã¶ÔµãËíµÀЭÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.5£¬µ±Óû§½« Windows ¿Í»§¶ËÁ¬½Óµ½¶ñÒâ·þÎñÆ÷ʱ£¬¿ÉÄܻᴥ·¢´Ë©¶´£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

CVE-2023-28291£ºÔ­Ê¼Í¼ÏñÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.4£¬¿ÉÒÔͨ¹ýÓÕʹµ±µØÓû§´ò¿ª¶ñÒâÎļþ/Á´½ÓÀ´ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼ÖÂÈÎÒâ´úÂëÖ´ÐС£

´ËÍ⣬ֵµÃ¹Ø×¢µÄ©¶´»¹°üÂÞMicrosoft Office¡¢Word ºÍ Publisher Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2023-28285¡¢CVE-2023-28311¡¢CVE-2023-28295ºÍCVE-2023-28287£©µÈ£¬Ö»Ðè´ò¿ª¶ñÒâÎĵµ¼´¿ÉÀûÓÃÕâЩ©¶´£¬Ó¦×¢ÒâÐÞ¸´´ËÀà©¶´¡£

΢Èí4Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º

CVE

CVE ±êÌâ

ÑÏÖØË®Æ½

CVE-2023-21554

Microsoft ÏûÏ¢ÐÐÁÐÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-28231

DHCP   Server Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-28219

¶þ²ãËíµÀЭÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-28220

¶þ²ãËíµÀЭÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-28250

Windows   Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-28232

Windows µã¶ÔµãËíµÀЭÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-28291

ԭʼͼÏñÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-28260

.NET DLL½Ù³ÖÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28312

Azure »úÆ÷ѧϰÐÅϢй¶©¶´

¸ßΣ

CVE-2023-28300

Azure ·þÎñÁ¬½ÓÆ÷Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-28227

Windows À¶ÑÀÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-24860

Microsoft   Defender ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-28314

Microsoft   Dynamics 365 (on-premises) ¿çÕ¾½Å±¾Â©¶´

¸ßΣ

CVE-2023-28309

Microsoft   Dynamics 365 (on-premises) ¿çÕ¾½Å±¾Â©¶´

¸ßΣ

CVE-2023-28313

Microsoft   Dynamics 365 ¿Í»§ÓïÒô¿çÕ¾½Å±¾Â©¶´

¸ßΣ

CVE-2023-24912

Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-21769

Microsoft ÏûÏ¢ÐÐÁоܾø·þÎñ©¶´

¸ßΣ

CVE-2023-28285

Microsoft   Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28295

Microsoft   Publisher Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28287

Microsoft   Publisher Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28288

Microsoft   SharePoint Server ÆÛƭ©¶´

¸ßΣ

CVE-2023-28311

Microsoft   Word Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28243

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-24883

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-24927

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-24925

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-24924

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-24885

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-24928

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-24884

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-24926

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-24929

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-24887

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-24886

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28275

Microsoft   WDAC OLE DB provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28256

Windows   DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28278

Windows   DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28307

Windows   DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28306

Windows   DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28223

WindowsÓòÃû·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28254

Windows   DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28305

Windows   DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28308

Windows   DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28255

Windows   DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28277

Windows   DNS ·þÎñÆ÷ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-23384

Microsoft   SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-23375

Microsoft   ODBC ºÍ OLE DB Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28304

Microsoft   ODBC ºÍ OLE DB Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28299

Visual   Studio ÆÛƭ©¶´

¸ßΣ

CVE-2023-28262

Visual   Studio ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-28263

Visual   Studio ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-28296

Visual   Studio Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-24893

Visual   Studio Code Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28302

Microsoft ÏûÏ¢ÐÐÁоܾø·þÎñ©¶´

¸ßΣ

CVE-2023-28236

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-28216

Windows ¸ß¼¶µ±µØ¹ý³Ìµ÷Óà (ALPC) ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-28218

Windows   Ancillary Function Driver for WinSock ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-28269

Windows Æô¶¯¹ÜÀíÆ÷Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-28249

Windows Æô¶¯¹ÜÀíÆ÷Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-28273

Windows   Clip ·þÎñÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-28229

Windows   CNG ÃÜÔ¿¸ôÀë·þÎñÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-28266

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-28252

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-28226

Windows ×¢²áÒýÇæÄþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-28221

Windows ´íÎó³ÂËß·þÎñÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-28276

Windows ×鼯ıÄþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-28238

Windows   Internet ÃÜÔ¿½»»» (IKE) ЭÒéÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28244

Windows   Kerberos ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-28271

Windows ÄÚºËÄÚ´æÐÅϢй¶©¶´

¸ßΣ

CVE-2023-28248

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-28222

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-28272

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-28293

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-28253

Windows ÄÚºËÐÅϢй¶©¶´

¸ßΣ

CVE-2023-28237

Windows ÄÚºËÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28298

Windows Äں˾ܾø·þÎñ©¶´

¸ßΣ

CVE-2023-28270

Windows ËøÆÁÄþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-28235

Windows ËøÆÁÄþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-28268

Netlogon   RPC ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-28217

Windows ÍøÂçµØÖ·×ª»» (NAT) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-28247

Windows ÍøÂçÎļþϵͳÐÅϢй¶©¶´

¸ßΣ

CVE-2023-28240

Windows ÍøÂç¸ºÔØ¾ùºâÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28225

Windows   NTLM ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-28224

Windows ÒÔÌ«Íøµã¶ÔµãЭÒé (PPPoE) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28292

ԭʼͼÏñÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28228

Windows ÆÛƭ©¶´

¸ßΣ

CVE-2023-28267

Ô¶³Ì×ÀÃæÐ­Òé¿Í»§¶ËÐÅϢй¶©¶´

¸ßΣ

CVE-2023-28246

Windows ×¢²á±íÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-21729

Ô¶³Ì¹ý³Ìµ÷ÓÃÔËÐÐʱÐÅϢй¶©¶´

¸ßΣ

CVE-2023-21727

Ô¶³Ì¹ý³Ìµ÷ÓÃÔËÐÐʱԶ³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28297

Windows Ô¶³Ì¹ý³Ìµ÷Ó÷þÎñ (RPCSS) ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-24931

Windows Äþ¾²Í¨µÀ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-28233

Windows Äþ¾²Í¨µÀ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-28241

Windows Äþ¾²Ì×½Ó×ÖËíµÀЭÒé (SSTP) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-28234

Windows Äþ¾²Í¨µÀ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-28274

Windows   Win32k ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-24914

Win32k ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-28284

Microsoft   Edge£¨»ùÓÚ Chromium£©Äþ¾²¹¦Ð§Èƹý©¶´

ÖÐΣ

CVE-2023-28301

Microsoft   Edge£¨»ùÓÚ Chromium£©¸Ä¶¯Â©¶´

µÍΣ

CVE-2023-24935

Microsoft   Edge£¨»ùÓÚ Chromium£©ÆÛƭ©¶´

µÍΣ

CVE-2023-1823

Chromium£ºCVE-2023-1823 ÔÚ FedCM ÖÐʵʩ²»Í×

δ֪

CVE-2023-1810

Chromium£ºCVE-2023-1810 VisualsÖеĶѻº³åÇøÒç³ö

δ֪

CVE-2023-1819

Chromium£ºCVE-2023-1819 AccessibilityÖеÄÔ½½ç¶ÁÈ¡

δ֪

CVE-2023-1818

Chromium£ºCVE-2023-1818 Vulkan ÖеÄÊͷźóʹÓÃ

δ֪

CVE-2023-1814

Chromium£ºCVE-2023-1814 Äþ¾²ä¯ÀÀÖв»ÊÜÐÅÈεÄÊäÈëÑéÖ¤²»³äʵ

δ֪

CVE-2023-1821

Chromium£ºCVE-2023-1821 WebShare ÖеÄʵʩ²»Í×

δ֪

CVE-2023-1811

Chromium£ºCVE-2023-1811 Frames ÖеÄÊͷźóʹÓÃ

δ֪

CVE-2023-1820

Chromium£ºCVE-2023-1820 ä¯ÀÀÆ÷ÀúÊ·ÖеĶѻº³åÇøÒç³ö

δ֪

CVE-2023-1816

Chromium£ºCVE-2023-1816 »­Öл­ÖеÄÄþ¾² UI ²»ÕýÈ·

δ֪

CVE-2023-1815

Chromium£ºCVE-2023-1815 Networking APIsÖеÄÊͷźóʹÓÃ

δ֪

CVE-2023-1822

Chromium£ºCVE-2023-1822 µ¼º½ÖеÄÄþ¾² UI ²»ÕýÈ·

δ֪

CVE-2023-1813

Chromium£ºCVE-2023-1813 À©Õ¹ÖеÄʵʩ²»Í×

δ֪

CVE-2023-1812

Chromium£ºCVE-2023-1812 DOM °ó¶¨ÖеÄÔ½½çÄÚ´æ·ÃÎÊ

δ֪

CVE-2023-1817

Chromium£º CVE-2023-1817 IntentsÖеļÆÄ±Ö´Ðв»×ã

δ֪

 

¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

.NET Core

Azure Machine Learning

Azure Service Connector

Microsoft Bluetooth Driver

Microsoft Defender for Endpoint

Microsoft Dynamics

Microsoft Dynamics 365 Customer Voice

Microsoft Edge (Chromium-based)

Microsoft Graphics Component

Microsoft Message Queuing

Microsoft Office

Microsoft Office Publisher

Microsoft Office SharePoint

Microsoft Office Word

Microsoft PostScript Printer Driver

Microsoft Printer Drivers

Microsoft WDAC OLE DB provider for SQL

Microsoft Windows DNS

Visual Studio

Visual Studio Code

Windows Active Directory

Windows ALPC

Windows Ancillary Function Driver for WinSock

Windows Boot Manager

Windows Clip Service

Windows CNG Key Isolation Service

Windows Common Log File System Driver

Windows DHCP Server

Windows Enroll Engine

Windows Error Reporting

Windows Group Policy

Windows Internet Key Exchange (IKE) Protocol

Windows Kerberos

Windows Kernel

Windows Layer 2 Tunneling Protocol

Windows Lock Screen

Windows Netlogon

Windows Network Address Translation (NAT)

Windows Network File System

Windows Network Load Balancing

Windows NTLM

Windows PGM

Windows Point-to-Point Protocol over Ethernet (PPPoE)

Windows Point-to-Point Tunneling Protocol

Windows Raw Image Extension

Windows RDP Client

Windows Registry

Windows RPC API

Windows Secure Boot

Windows Secure Channel

Windows Secure Socket Tunneling Protocol (SSTP)

Windows Transport Security Layer (TLS)

Windows Win32K

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2023Äê4ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2023-Apr

²¹¶¡ÏÂÔØÊ¾Àý£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2022Äê2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£

 

3.2 ÁÙʱ´ëÊ©

Õë¶ÔCVE-2023-28252£¬¿É²Î¿¼ÒÔÏÂÁ´½Ó»ñ¸ü¶à©¶´ÐÅÏ¢¼°IoC£º

https://securelist.com/nokoyawa-ransomware-attacks-with-windows-zero-day/109483/

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2023-Apr

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28252

https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2023-patch-tuesday-fixes-1-zero-day-97-flaws/

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-04-12

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼

5.1 ¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png