¡¾Â©¶´Í¨¸æ¡¿Î¢Èí7Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2023-07-12

Ò»¡¢Â©¶´¸ÅÊö

2023Äê7ÔÂ11ÈÕ£¬Î¢ÈíÐû²¼ÁË7ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË132¸ö©¶´£¬ÆäÖаüÂÞ6¸öÒѱ»ÀûÓõÄ©¶´¡¢37¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬ÒÔ¼°9¸öÆÀ¼¶ÎªÑÏÖØµÄ©¶´¡£

±¾´ÎÐÞ¸´µÄ©¶´ÖУ¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´ºÍÆÛƭ©¶´µÈ¡£

΢Èí±¾´Î¹²ÐÞ¸´ÁË6¸öÒѱ»ÀûÓõÄ©¶´£¬ÆäÖÐCVE-2023-36884Òѱ»¹ûÈ»Åû¶£¬ÏêÇéÈçÏ£º

CVE-2023-32046£ºWindows MSHTML PlatformȨÏÞÌáÉý©¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.8£¬ÀûÓøÃ©¶´ÐèÒªÓû§½»»¥£¬¿ÉÒÔͨ¹ýµç×ÓÓʼþ»ò¶ñÒâÍøÕ¾´ò¿ªÌØÖÆÎļþÀ´ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓÿɻñµÃÔËÐÐÊÜÓ°ÏìÓ¦Ó÷¨Ê½µÄÓû§µÄȨÏÞ¡£Ä¿Ç°¸Ã©¶´ÒÑ·¢ÏÖ±»ÀûÓá£

CVE-2023-32049£ºWindows SmartScreenÄþ¾²¹¦Ð§Èƹý©¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬ÀûÓøÃ©¶´ÐèÒªÓû§½»»¥£¬¿ÉÒÔͨ¹ýÓÕµ¼Óû§µ¥»÷ÌØÖÆURLÀ´Ö´Ðй¥»÷£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÈÆ¹ý¡°´ò¿ªÎļþ-Äþ¾²¾¯¸æ¡±Ìáʾ¡£Ä¿Ç°¸Ã©¶´ÒÑ·¢ÏÖ±»ÀûÓá£

CVE-2023-36874£ºWindows Error Reporting ServiceÌØÈ¨ÌáÉý©¶´

¸Ã©¶´´æÔÚÓÚWindows ´íÎó³ÂËß·þÎñÖУ¬ÆäCVSSv3ÆÀ·ÖΪ7.8£¬¶ÔÄ¿±ê¼ÆËã»ú¾ßÓе±µØ·ÃÎÊȨÏÞÇÒÄܹ»ÔÚ¼ÆËã»úÉÏ´´½¨Îļþ¼ÐºÍÐÔÄܸú×Ù£¬²¢¾ßÓÐÆÕͨÓû§Ä¬ÈÏȨÏÞµÄÍþвÕß¿ÉÀûÓøÃ©¶´»ñµÃ¹ÜÀíԱȨÏÞ¡£Ä¿Ç°¸Ã©¶´ÒÑ·¢ÏÖ±»ÀûÓá£

CVE-2023-36884 £ºOffice ºÍ Windows HTML Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸Ã©¶´Ó°ÏìÁ˶à¸öWindowsºÍOffice²úÎÆäCVSSv3ÆÀ·ÖΪ8.3£¬ÍþвÕß¿ÉÒÔ´´½¨ÌØÖÆµÄ Microsoft OfficeÎĵµ²¢ÓÕµ¼Êܺ¦Õß´ò¿ª¶ñÒâÎļþ£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔÚÊܺ¦ÕßµÄÉÏÏÂÎÄÖÐÔ¶³ÌÖ´ÐдúÂë¡£¸Ã©¶´ÒѾ­¹ûÈ»Åû¶ÇÒÒÑ·¢ÏÖ±»ÀûÓã¬Ä¿Ç°Î¢ÈíÔÝδÐû²¼¸Ã©¶´µÄÄþ¾²¸üУ¬µ«ÒÑÐû²¼Á˸é¶´µÄ»º½â´ëÊ©¡£

CVE-2023-35311 £ºMicrosoft Outlook Äþ¾²¹¦Ð§Èƹý©¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬ÀûÓøÃ©¶´ÐèÒªÓû§½»»¥£¬¿ÉÒÔͨ¹ýÓÕµ¼Óû§µ¥»÷ÌØÖÆURLÀ´Ö´Ðй¥»÷£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÒÔÈÆ¹ý Microsoft Outlook Äþ¾²Í¨ÖªÌáʾ¡£Ä¿Ç°¸Ã©¶´ÒÑ·¢ÏÖ±»ÀûÓá£

ADV230001£º¹ØÓÚ¶ñÒâʹÓà Microsoft Ç©ÃûÇý¶¯·¨Ê½µÄÖ¸ÄÏ

΢Èí×î½ü»ñϤ£¬¾­Î¢ÈíWindows Ó²¼þ¿ª·¢ÈËÔ±¼Æ»®£¨MWHDP£©ÈÏÖ¤µÄÇý¶¯·¨Ê½ÔÚºóÀûÓûÖб»¶ñÒâʹÓá£ÔÚÕâЩ¹¥»÷ÖУ¬¹¥»÷ÕßÔÚʹÓÃÇý¶¯·¨Ê½Ö®Ç°¾ÍÒѾ­»ñµÃÁËÊÜѬȾϵͳµÄ¹ÜÀíȨÏÞ£¬ÊÓ²ìÏÔʾ£¬Î¢ÈíºÏ×÷»ï°éÖÐÐÄ (MPC) µÄ¶à¸ö¿ª·¢ÕßÕÊ»§ÕýÔÚÌá½»¶ñÒâÇý¶¯·¨Ê½ÒÔ»ñȡ΢ÈíÇ©Ãû£¬Ä¿Ç°Î¢ÈíÒѾ­µõÏú/½ûÓÃÁËÀÄÓà Windows ¼ÆÄ±Â©¶´°²×°¶ñÒâÄÚºËģʽÇý¶¯·¨Ê½µÄ´úÂëÇ©ÃûÖ¤ÊéºÍ¿ª·¢ÈËÔ±ÕÊ»§¡£

΢Èí7Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º

CVE-ID

CVE±êÌâ

ÑÏÖØÐÔ

CVE-2023-33160

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-33157

Microsoft   SharePointÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-35315

Windows   Layer-2 Bridge Network Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-32057

Microsoft ÏûÏ¢ÐÐÁÐÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-35297

Windows   Pragmatic ͨÓÃ×é²¥ (PGM) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-35352

Windows Ô¶³Ì×ÀÃæÄþ¾²¹¦Ð§Èƹý©¶´

ÑÏÖØ

CVE-2023-35367

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-35366

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-35365

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-33127

.NET ºÍ Visual Studio ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-33170

ASP.NET ºÍ Visual Studio Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-36871

Azure   Active Directory Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-35348

Active   Directory ÁªºÏÉí·ÝÑéÖ¤·þÎñÄþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-33171

Microsoft   Dynamics 365£¨on-premises£©¿çÕ¾½Å±¾Â©¶´

¸ßΣ

CVE-2023-35335

Microsoft   Dynamics 365£¨on-premises£©¿çÕ¾½Å±¾Â©¶´

¸ßΣ

CVE-2023-33149

Microsoft   Office Graphics Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-21756

Windows   Win32k ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35333

MediaWiki   PandocUpload À©Õ¹Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-33148

Microsoft   Office ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2023-36884

Office ºÍ Windows HTML Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-33150

Microsoft   Office Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-33152

Microsoft   ActiveX Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-33158

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-33161

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-33162

Microsoft   Excel ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-33151

Microsoft   Outlook ÆÛƭ©¶´

¸ßΣ

CVE-2023-33153

Microsoft   Outlook Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35311

Microsoft   Outlook Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-33134

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-33165

Microsoft   SharePoint Server Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-33159

Microsoft   SharePoint Server ÆÛƭ©¶´

¸ßΣ

CVE-2023-32052

Microsoft   Power Apps ÆÛƭ©¶´

¸ßΣ

CVE-2023-32085

Microsoft   PostScript and PCL6 Class Printer Driver ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-35302

Microsoft   PostScript and PCL6 Class Printer Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35296

Microsoft   PostScript and PCL6 Class Printer Driver ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-35324

Microsoft   PostScript and PCL6 Class Printer Driver ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-32040

Microsoft   PostScript and PCL6 Class Printer Driver ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-35306

Microsoft   PostScript and PCL6 Class Printer Driver ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-32039

Microsoft   PostScript and PCL6 Class Printer Driver ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-35303

USB Audio   Class System Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-36872

VP9 Video   Extensions ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-32051

Raw Image   Extension Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35373

Mono   Authenticode ÑéÖ¤ÆÛƭ©¶´

¸ßΣ

CVE-2023-35374

Paint 3D Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-32047

Paint 3D Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35310

Windows   DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35346

Windows   DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35345

Windows   DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35344

Windows   DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-36868

Azure   Service Fabric on Windows ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-36867

Visual   Studio Code GitHub Pull Requests and Issues Extension Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35351

Windows   Active Directory Ö¤Êé·þÎñ (AD CS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35350

Windows   Active Directory Ö¤Êé·þÎñ (AD CS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-32055

Active   Template Library ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2023-29347

Windows   Admin Center ÆÛƭ©¶´

¸ßΣ

CVE-2023-35347

Microsoft °²×°·þÎñȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2023-35329

Windows Éí·ÝÑéÖ¤¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-35326

Windows   CDPÓû§×é¼þÐÅϢй¶©¶´

¸ßΣ

CVE-2023-35362

Windows   Clip ·þÎñÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-33155

Windows   Cloud Files Mini Filter Driver ÐòÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-32033

Microsoft   Failover Cluster Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35340

Windows   CNG ÃÜÔ¿¸ôÀë·þÎñÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35299

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35320

Connected   User Experiences and Telemetry ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35353

Connected   User Experiences and Telemetry ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35339

Windows   CryptoAPI ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-33174

Windows ¼ÓÃÜÐÅϢй¶©¶´

¸ßΣ

CVE-2023-33156

Microsoft   Defender ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2023-35322

Windows ²¿Êð·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35321

Windows ²¿Êð·þÎñ¾Ü¾ø·þÎñ©¶´

¸ßΣ

ADV230002

Microsoft ½â¾öÇ÷ÊÆ¿Æ¼¼ EFI Ä£¿éÖеÄÄþ¾²¹¦Ð§ÈƹýÎÊÌâµÄÖ¸ÄÏ

¸ßΣ

CVE-2023-36874

Windows ´íÎó³ÂËß·þÎñÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-32083

Microsoft   Failover Cluster ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-35343

Windows µØÀí¶¨Î»·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-32084

HTTP.sys ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-35298

HTTP.sys ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-35342

Windows   Image Acquisition ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2023-32053

Windows   Installer ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2023-32050

Windows   Installer ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2023-35304

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35363

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35305

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35356

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35357

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35358

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-32037

Windows   Layer-2 Bridge Network Driver ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-35331

Windows   Local Security Authority (LSA) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-35341

Microsoft   DirectMusic ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-35309

Microsoft ÏûÏ¢ÐÐÁÐÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-32045

Microsoft ÏûÏ¢ÐÐÁоܾø·þÎñ©¶´

¸ßΣ

CVE-2023-32044

Microsoft ÏûÏ¢ÐÐÁоܾø·þÎñ©¶´

¸ßΣ

CVE-2023-32046

Windows   MSHTML ƽ̨ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2023-35336

Windows   MSHTML ƽ̨Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-35308

Windows   MSHTML ƽ̨Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-21526

Windows   Netlogon ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-33163

Windows ÍøÂç¸ºÔØÆ½ºâÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35361

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35364

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35360

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-32038

Microsoft   ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-32042

OLE×Ô¶¯»¯ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-35323

Windows OLEÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35313

Windows ÔÚÏßÖ¤Êé״̬ЭÒé (OCSP) SnapIn Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-33154

Windows ·ÖÇø¹ÜÀíÇý¶¯·¨Ê½È¨ÏÞÌáÉý©¶´

¸ßΣ

CVE-2023-35338

Windows ¶ÔµÈÃû³Æ½âÎöЭÒé¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-35325

Windows ´òÓ¡ºǫ́´¦Ö÷¨Ê½ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-32043

Windows Ô¶³Ì×ÀÃæÄþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-35332

Windows Ô¶³Ì×ÀÃæÐ­ÒéÄþ¾²¹¦Ð§Èƹý

¸ßΣ

CVE-2023-35300

Remote   Procedure Call Runtime Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-33168

Remote   Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-33173

Remote   Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-33172

Remote   Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-32035

Remote   Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-33166

Remote   Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-32034

Remote   Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-33167

Remote   Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-33169

Remote   Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-35318

Remote   Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-33164

Remote   Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-35319

Remote   Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-35316

Remote   Procedure Call Runtime ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-35314

Remote   Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-35317

Windows   Server Update Service (WSUS) ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-32056

Windows   Server Update Service (WSUS) ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-32049

Windows   SmartScreenÄþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-35330

Windows À©Õ¹Ð­Éܾ̾ø·þÎñ©¶´

¸ßΣ

CVE-2023-35328

Windows ÊÂÎñ¹ÜÀíÆ÷ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-32041

Windows   Update Orchestrator·þÎñÐÅϢй¶©¶´

¸ßΣ

CVE-2023-35312

Microsoft   VOLSNAP.SYS ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-32054

Volume   Shadow Copy ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35337

Win32k ÌØÈ¨ÌáÉý©¶´

¸ßΣ

ADV230001

¹ØÓÚ¶ñÒâʹÓà Microsoft Ç©ÃûÇý¶¯·¨Ê½µÄÖ¸ÄÏ

ÎÞ

  

¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

Windows Certificates

Windows EFI Partition

Windows Netlogon

Microsoft Graphics Component

Windows Admin Center

Windows Cluster Server

Windows Remote Procedure Call

Windows Layer 2 Tunneling Protocol

Windows ODBC Driver

Microsoft Printer Drivers

Windows Update Orchestrator Service

Windows OLE

Windows Remote Desktop

Windows Message Queuing

Windows MSHTML Platform

Paint 3D

Windows SmartScreen

Windows Installer

Microsoft Windows Codecs Library

Microsoft Power Apps

Windows Volume Shadow Copy

Windows Active Template Library

Windows Server Update Service

Windows Failover Cluster

Windows HTTP.sys

.NET and Visual Studio

Microsoft Office SharePoint

Microsoft Office

Microsoft Office Outlook

Microsoft Office Access

Windows Partition Management Driver

Windows Cloud Files Mini Filter Driver

Windows Defender

Microsoft Office Excel

Windows Network Load Balancing

ASP.NET and .NET

Microsoft Dynamics

Windows Cryptographic Services

Windows PGM

Windows Common Log File System Driver

Windows Kernel

Role: DNS Server

Windows VOLSNAP.SYS

Windows Online Certificate Status Protocol (OCSP) SnapIn

Windows Layer-2 Bridge Network Driver

Windows Connected User Experiences and Telemetry

Windows Deployment Services

Windows Print Spooler Components

Windows CDP User Components

Windows Transaction Manager

Windows Authentication Methods

Windows SPNEGO Extended Negotiation

Windows Local Security Authority (LSA)

Microsoft Media-Wiki Extensions

Windows Win32K

Windows Peer Name Resolution Protocol

Windows CryptoAPI

Windows CNG Key Isolation Service

Windows Media

Windows Image Acquisition

Windows Geolocation Service

Windows App Store

Azure Active Directory

Windows Active Directory Certificate Services

Windows NT OS Kernel

Windows Clip Service

Windows Routing and Remote Access Service (RRAS)

Mono Authenticode

Visual Studio Code

Service Fabric

Windows Error Reporting


Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2023Äê7ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2023-Jul

²¹¶¡ÏÂÔØÊ¾Àý£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2022Äê2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£

 

3.2 ÁÙʱ´ëÊ©

Õë¶ÔCVE-2023-36884£¬Î¢ÈíÒѾ­Ðû²¼ÁËÏà¹Ø»º½â´ëÊ©£¬¿É²Î¿¼£º

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884

https://www.microsoft.com/en-us/security/blog/2023/07/11/storm-0978-attacks-reveal-financial-and-espionage-motives/

¹ØÓÚ¶ñÒâʹÓà Microsoft Ç©ÃûÇý¶¯·¨Ê½µÄÖ¸ÄÏ£¬¸ü¶àÐÅÏ¢¿É²Î¿¼£º

https://msrc.microsoft.com/update-guide/en-US/vulnerability/ADV230001

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2023-Jul

https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2023-patch-tuesday-warns-of-6-zero-days-132-flaws/

https://www.bleepingcomputer.com/news/security/microsoft-unpatched-office-zero-day-exploited-in-nato-summit-attacks/

  

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-07-12

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼

5.1 ¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png