¡¾Â©¶´Í¨¸æ¡¿Î¢Èí4Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2023-04-12Ò»¡¢Â©¶´¸ÅÊö
2023Äê4ÔÂ11ÈÕ£¬Î¢ÈíÐû²¼ÁË4ÔÂÄþ¾²¸üУ¬±¾´Î¸üÐÂÐÞ¸´Á˰üÂÞ1¸ö0 day©¶´ÔÚÄÚµÄ97¸öÄþ¾²Â©¶´£¨²»°üÂÞMicrosoft Edge©¶´£©£¬ÆäÖÐÓÐ7¸ö©¶´ÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£
±¾´ÎÐÞ¸´µÄ©¶´ÖУ¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´ºÍÆÛÆÂ©¶´µÈ¡£
΢Èí±¾´Î¹²ÐÞ¸´ÁË1¸ö±»»ý¼«ÀûÓõÄ0 day©¶´£¬ÈçÏ£º
CVE-2023-28252 £ºWindows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´
Windows CLFS Çý¶¯·¨Ê½ÖдæÔÚÔ½½çдÈë©¶´£¬µ±µØµÍȨÏÞÓû§¿ÉÒÔͨ¹ý»ù±¾ÈÕÖ¾Îļþ£¨.blf ÎļþÀ©Õ¹Ãû£©µÄ²Ù×÷´¥·¢¸Ã©¶´£¬ÀÖ³ÉÀûÓøÃ©¶´¿Éµ¼Öµ±µØÈ¨ÏÞÌáÉýΪSYSTEM¡£¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.8£¬Ä¿Ç°ÒÑ·¢ÏÖ±»Nokoyawa ÀÕË÷Èí¼þÀûÓá£
±¾´ÎÄþ¾²¸üÐÂÖÐÆÀ¼¶ÎªÑÏÖØµÄ7¸ö©¶´°üÂÞ£º
CVE-2023-21554£ºMicrosoft ÏûÏ¢ÐÐÁÐÔ¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ9.8£¬¿ÉÒÔͨ¹ý·¢ËͶñÒâÖÆ×÷µÄMSMQ Êý¾Ý°üµ½MSMQ ·þÎñÆ÷À´ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼ÖÂÔÚ·þÎñÆ÷¶ËÔ¶³ÌÖ´ÐдúÂë¡£ÀûÓøÃ©¶´ÐèÒªÆôÓÃ×÷ΪWindows ×é¼þµÄWindows ÏûÏ¢ÐÐÁзþÎñ£¬¿ÉÒÔͨ¹ý¼ì²éÊÇ·ñÓÐÃûΪMessage QueuingµÄ·þÎñÔÚÔËÐУ¬ÒÔ¼°¼ÆËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£
CVE-2023-28231£ºDHCP Server Service Ô¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬¾¹ýÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔÀûÓÃÕë¶Ô DHCP ·þÎñµÄÌØÖÆ RPC µ÷ÓÃÀ´ÀûÓøÃ©¶´¡£
CVE-2023-28219/ CVE-2023-28220£º¶þ²ãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.1£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔÏò RAS ·þÎñÆ÷·¢ËͶñÒâÁ¬½ÓÇëÇó£¬Õâ¿ÉÄܵ¼Ö RAS ·þÎñÆ÷¼ÆËã»úÉϵÄÔ¶³Ì´úÂëÖ´ÐУ¬µ«ÀûÓøÃ©¶´ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ¡£
CVE-2023-28250£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ9.8£¬µ±ÆôÓÃWindowsÏûÏ¢ÐÐÁзþÎñʱ£¬ÀÖ³ÉÀûÓøÃ©¶´µÄÍþвÕß¿ÉÒÔͨ¹ýÍøÂç·¢ËÍÌØÖÆµÄÎļþ£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐУ¬²¢´¥·¢¶ñÒâ´úÂë¡£ÀûÓøÃ©¶´ÐèÒªÆôÓÃ×÷ΪWindows ×é¼þµÄWindows ÏûÏ¢ÐÐÁзþÎñ£¬¿ÉÒÔͨ¹ý¼ì²éÊÇ·ñÓÐÃûΪMessage QueuingµÄ·þÎñÔÚÔËÐУ¬ÒÔ¼°¼ÆËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£
CVE-2023-28232£ºWindows µã¶ÔµãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.5£¬µ±Óû§½« Windows ¿Í»§¶ËÁ¬½Óµ½¶ñÒâ·þÎñÆ÷ʱ£¬¿ÉÄܻᴥ·¢´Ë©¶´£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
CVE-2023-28291£ºÔʼͼÏñÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.4£¬¿ÉÒÔͨ¹ýÓÕʹµ±µØÓû§´ò¿ª¶ñÒâÎļþ/Á´½ÓÀ´ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼ÖÂÈÎÒâ´úÂëÖ´ÐС£
´ËÍ⣬ֵµÃ¹Ø×¢µÄ©¶´»¹°üÂÞMicrosoft Office¡¢Word ºÍ Publisher Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2023-28285¡¢CVE-2023-28311¡¢CVE-2023-28295ºÍCVE-2023-28287£©µÈ£¬Ö»Ðè´ò¿ª¶ñÒâÎĵµ¼´¿ÉÀûÓÃÕâЩ©¶´£¬Ó¦×¢ÒâÐÞ¸´´ËÀà©¶´¡£
΢Èí4Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º
CVE | CVE ±êÌâ | ÑÏÖØË®Æ½ |
CVE-2023-21554 | Microsoft ÏûÏ¢ÐÐÁÐÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-28231 | DHCP Server Service Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-28219 | ¶þ²ãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-28220 | ¶þ²ãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-28250 | Windows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-28232 | Windows µã¶ÔµãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-28291 | ÔʼͼÏñÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-28260 | .NET DLL½Ù³ÖÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28312 | Azure »úÆ÷ѧϰÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-28300 | Azure ·þÎñÁ¬½ÓÆ÷Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-28227 | Windows À¶ÑÀÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-24860 | Microsoft Defender ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-28314 | Microsoft Dynamics 365 (on-premises) ¿çÕ¾½Å±¾Â©¶´ | ¸ßΣ |
CVE-2023-28309 | Microsoft Dynamics 365 (on-premises) ¿çÕ¾½Å±¾Â©¶´ | ¸ßΣ |
CVE-2023-28313 | Microsoft Dynamics 365 ¿Í»§ÓïÒô¿çÕ¾½Å±¾Â©¶´ | ¸ßΣ |
CVE-2023-24912 | Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21769 | Microsoft ÏûÏ¢ÐÐÁоܾø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-28285 | Microsoft Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28295 | Microsoft Publisher Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28287 | Microsoft Publisher Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28288 | Microsoft SharePoint Server ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-28311 | Microsoft Word Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28243 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-24883 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-24927 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-24925 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-24924 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-24885 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-24928 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-24884 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-24926 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-24929 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-24887 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-24886 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28275 | Microsoft WDAC OLE DB provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28256 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28278 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28307 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28306 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28223 | WindowsÓòÃû·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28254 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28305 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28308 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28255 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28277 | Windows DNS ·þÎñÆ÷ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-23384 | Microsoft SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-23375 | Microsoft ODBC ºÍ OLE DB Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28304 | Microsoft ODBC ºÍ OLE DB Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28299 | Visual Studio ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-28262 | Visual Studio ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-28263 | Visual Studio ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-28296 | Visual Studio Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-24893 | Visual Studio Code Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28302 | Microsoft ÏûÏ¢ÐÐÁоܾø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-28236 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-28216 | Windows ¸ß¼¶µ±µØ¹ý³Ìµ÷Óà (ALPC) ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-28218 | Windows Ancillary Function Driver for WinSock ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-28269 | Windows Æô¶¯¹ÜÀíÆ÷Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-28249 | Windows Æô¶¯¹ÜÀíÆ÷Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-28273 | Windows Clip ·þÎñÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-28229 | Windows CNG ÃÜÔ¿¸ôÀë·þÎñÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-28266 | Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-28252 | Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-28226 | Windows ×¢²áÒýÇæÄþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-28221 | Windows ´íÎó³ÂËß·þÎñÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-28276 | Windows ×鼯ıÄþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-28238 | Windows Internet ÃÜÔ¿½»»» (IKE) ÐÒéÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28244 | Windows Kerberos ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-28271 | Windows ÄÚºËÄÚ´æÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-28248 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-28222 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-28272 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-28293 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-28253 | Windows ÄÚºËÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-28237 | Windows ÄÚºËÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28298 | Windows Äں˾ܾø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-28270 | Windows ËøÆÁÄþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-28235 | Windows ËøÆÁÄþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-28268 | Netlogon RPC ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-28217 | Windows ÍøÂçµØÖ·×ª»» (NAT) ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-28247 | Windows ÍøÂçÎļþϵͳÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-28240 | Windows ÍøÂç¸ºÔØ¾ùºâÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28225 | Windows NTLM ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-28224 | Windows ÒÔÌ«Íøµã¶ÔµãÐÒé (PPPoE) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28292 | ÔʼͼÏñÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28228 | Windows ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-28267 | Ô¶³Ì×ÀÃæÐÒé¿Í»§¶ËÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-28246 | Windows ×¢²á±íÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21729 | Ô¶³Ì¹ý³Ìµ÷ÓÃÔËÐÐʱÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-21727 | Ô¶³Ì¹ý³Ìµ÷ÓÃÔËÐÐʱԶ³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-28297 | Windows Ô¶³Ì¹ý³Ìµ÷Ó÷þÎñ (RPCSS) ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-24931 | Windows Äþ¾²Í¨µÀ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-28233 | Windows Äþ¾²Í¨µÀ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-28241 | Windows Äþ¾²Ì×½Ó×ÖËíµÀÐÒé (SSTP) ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-28234 | Windows Äþ¾²Í¨µÀ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-28274 | Windows Win32k ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-24914 | Win32k ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-28284 | Microsoft Edge£¨»ùÓÚ Chromium£©Äþ¾²¹¦Ð§Èƹý©¶´ | ÖÐΣ |
CVE-2023-28301 | Microsoft Edge£¨»ùÓÚ Chromium£©¸Ä¶¯Â©¶´ | µÍΣ |
CVE-2023-24935 | Microsoft Edge£¨»ùÓÚ Chromium£©ÆÛÆÂ©¶´ | µÍΣ |
CVE-2023-1823 | Chromium£ºCVE-2023-1823 ÔÚ FedCM ÖÐʵʩ²»Í× | δ֪ |
CVE-2023-1810 | Chromium£ºCVE-2023-1810 VisualsÖеĶѻº³åÇøÒç³ö | δ֪ |
CVE-2023-1819 | Chromium£ºCVE-2023-1819 AccessibilityÖеÄÔ½½ç¶ÁÈ¡ | δ֪ |
CVE-2023-1818 | Chromium£ºCVE-2023-1818 Vulkan ÖеÄÊͷźóʹÓà | δ֪ |
CVE-2023-1814 | Chromium£ºCVE-2023-1814 Äþ¾²ä¯ÀÀÖв»ÊÜÐÅÈεÄÊäÈëÑéÖ¤²»³äʵ | δ֪ |
CVE-2023-1821 | Chromium£ºCVE-2023-1821 WebShare ÖеÄʵʩ²»Í× | δ֪ |
CVE-2023-1811 | Chromium£ºCVE-2023-1811 Frames ÖеÄÊͷźóʹÓà | δ֪ |
CVE-2023-1820 | Chromium£ºCVE-2023-1820 ä¯ÀÀÆ÷ÀúÊ·ÖеĶѻº³åÇøÒç³ö | δ֪ |
CVE-2023-1816 | Chromium£ºCVE-2023-1816 »ÖлÖеÄÄþ¾² UI ²»ÕýÈ· | δ֪ |
CVE-2023-1815 | Chromium£ºCVE-2023-1815 Networking APIsÖеÄÊͷźóʹÓà | δ֪ |
CVE-2023-1822 | Chromium£ºCVE-2023-1822 µ¼º½ÖеÄÄþ¾² UI ²»ÕýÈ· | δ֪ |
CVE-2023-1813 | Chromium£ºCVE-2023-1813 À©Õ¹ÖеÄʵʩ²»Í× | δ֪ |
CVE-2023-1812 | Chromium£ºCVE-2023-1812 DOM °ó¶¨ÖеÄÔ½½çÄÚ´æ·ÃÎÊ | δ֪ |
CVE-2023-1817 | Chromium£º CVE-2023-1817 IntentsÖеļÆÄ±Ö´Ðв»×ã | δ֪ |
¶þ¡¢Ó°Ï췶Χ
ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º
.NET Core
Azure Machine Learning
Azure Service Connector
Microsoft Bluetooth Driver
Microsoft Defender for Endpoint
Microsoft Dynamics
Microsoft Dynamics 365 Customer Voice
Microsoft Edge (Chromium-based)
Microsoft Graphics Component
Microsoft Message Queuing
Microsoft Office
Microsoft Office Publisher
Microsoft Office SharePoint
Microsoft Office Word
Microsoft PostScript Printer Driver
Microsoft Printer Drivers
Microsoft WDAC OLE DB provider for SQL
Microsoft Windows DNS
Visual Studio
Visual Studio Code
Windows Active Directory
Windows ALPC
Windows Ancillary Function Driver for WinSock
Windows Boot Manager
Windows Clip Service
Windows CNG Key Isolation Service
Windows Common Log File System Driver
Windows DHCP Server
Windows Enroll Engine
Windows Error Reporting
Windows Group Policy
Windows Internet Key Exchange (IKE) Protocol
Windows Kerberos
Windows Kernel
Windows Layer 2 Tunneling Protocol
Windows Lock Screen
Windows Netlogon
Windows Network Address Translation (NAT)
Windows Network File System
Windows Network Load Balancing
Windows NTLM
Windows PGM
Windows Point-to-Point Protocol over Ethernet (PPPoE)
Windows Point-to-Point Tunneling Protocol
Windows Raw Image Extension
Windows RDP Client
Windows Registry
Windows RPC API
Windows Secure Boot
Windows Secure Channel
Windows Secure Socket Tunneling Protocol (SSTP)
Windows Transport Security Layer (TLS)
Windows Win32K
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£
£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2023Äê4ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2023-Apr
²¹¶¡ÏÂÔØÊ¾Àý£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2022Äê2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£
Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£
3.2 ÁÙʱ´ëÊ©
Õë¶ÔCVE-2023-28252£¬¿É²Î¿¼ÒÔÏÂÁ´½Ó»ñ¸ü¶à©¶´ÐÅÏ¢¼°IoC£º
https://securelist.com/nokoyawa-ransomware-attacks-with-windows-zero-day/109483/
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2023-Apr
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28252
https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2023-patch-tuesday-fixes-1-zero-day-97-flaws/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-04-12 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¶«Éƽ̨¼ò½é
¶«Éƽ̨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«Éƽ̨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶«Éƽ̨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
5.2 ¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º