¡¾Â©¶´Í¨¸æ¡¿Î¢Èí8Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2023-08-09

Ò»¡¢Â©¶´¸ÅÊö

2023Äê8ÔÂ8ÈÕ £¬Î¢ÈíÐû²¼ÁË8ÔÂÄþ¾²¸üР£¬±¾´Î¸üй²ÐÞ¸´ÁË87¸ö©¶´ £¬ÆäÖаüÂÞ2¸öÒѱ»ÀûÓõÄ©¶´¡¢23¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´ÒÔ¼°6¸öÆÀ¼¶ÎªÑÏÖØµÄ©¶´¡£

±¾´ÎÐÞ¸´µÄ©¶´ÖÐ £¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´ºÍÆÛƭ©¶´µÈ¡£

΢Èí±¾´Î¹²ÐÞ¸´ÁË2¸öÒѱ»ÀûÓõÄ©¶´£º

ADV230003£ºMicrosoft Office Éî¶È·ÀÓù¸üУ¨ÐÞ¸´CVE-2023-36884£©

Microsoft Ðû²¼ÁË Microsoft OfficeÉî¶È·ÀÓù¸üР£¬ÒÔÐÞ¸´ÏÈǰÒÑ»º½â²¢±»»ý¼«ÀûÓõÄCVE-2023-36884Ô¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Á´¡£CVE-2023-36884Ó°ÏìÁ˶à¸öWindowsºÍOffice²úÎï £¬ÍþвÕß¿ÉÒÔ´´½¨ÌØÖÆµÄ Microsoft OfficeÎĵµ²¢ÓÕµ¼Êܺ¦Õß´ò¿ª¶ñÒâÎļþ £¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔÚÊܺ¦ÕßµÄÉÏÏÂÎÄÖÐÔ¶³ÌÖ´ÐдúÂë¡£¸Ã©¶´ÒѾ­¹ûÈ»Åû¶ÇÒÒÑ·¢ÏÖ±»ÀûÓá£

CVE-2023-38180 £º.NET ºÍ Visual Studio ¾Ü¾ø·þÎñ©¶´

¸Ã©¶´µÄCVSSv3.1ÆÀ·ÖΪ7.5 £¬¿ÉÀûÓøÃ©¶´µ¼ÖÂ.NET Ó¦Ó÷¨Ê½ºÍ Visual Studio¾Ü¾ø·þÎñ £¬Ä¿Ç°¸Ã©¶´ÒÑ·¢ÏÖ±»ÀûÓá£

΢Èí±¾´Î¸üÐÂÖÐÐÞ¸´µÄ6¸öÆÀ¼¶Îª¡°ÑÏÖØ¡±µÄ©¶´ÈçÏ£º

CVE-2023-36895£ºMicrosoft OutlookÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸Ã©¶´µÄCVSSv3.1ÆÀ·ÖΪ7.8 £¬ÍþвÕß¿Éͨ¹ýÓÕµ¼Êܺ¦ÕßÏÂÔØ²¢´ò¿ªÌØÖÆÎļþ£¨ÐèÒªÓû§½»»¥£© £¬´Ó¶øµ¼Ö¶ÔÊܺ¦Õß¼ÆËã»úÖ´Ðе±µØ¹¥»÷ £¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼ÖÂÈÎÒâ´úÂëÖ´ÐС£

CVE-2023-29328/ CVE-2023-29330£ºMicrosoft TeamsÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸Ã©¶´µÄCVSSv3.1ÆÀ·ÖΪ8.8 £¬Ó°ÏìÁËMicrosoft Teams ×ÀÃæ°æ¡¢Android °æ¡¢ iOS°æºÍMac °æ¡£ÍþвÕß¿ÉÒÔͨ¹ýÓÕÆ­Êܺ¦Õß¼ÓÈëÆäÉèÖõĶñÒâTeams »áÒé £¬µ¼ÖÂÔÚÊܺ¦ÕßÓû§µÄÉÏÏÂÎÄÖÐÔ¶³ÌÖ´ÐдúÂë £¬´Ó¶øÄܹ»·ÃÎÊ»òÐÞ¸ÄÊܺ¦ÕßµÄÐÅÏ¢ £¬»ò¿ÉÄܵ¼Ö¿ͻ§¶Ë¼ÆËã»úÍ£»ú £¬ÀûÓøÃ©¶´ÎÞÐèÌØÈ¨¡£

CVE-2023-35385/CVE-2023-36911/CVE-2023-36910£ºMicrosoftÏûÏ¢ÐÐÁÐÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÕâЩ©¶´µÄCVSSv3.1ÆÀ·Ö¾ùΪ9.8 £¬¿ÉÒÔͨ¹ý·¢ËͶñÒâÖÆ×÷µÄMSMQ Êý¾Ý°üµ½MSMQ ·þÎñÆ÷À´ÀûÓé¶´ £¬ÀÖ³ÉÀûÓÃÕâЩ©¶´¿ÉÄܵ¼ÖÂÔÚÄ¿±ê·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë¡£ÀûÓÃÕâЩ©¶´ÐèÒªÆôÓÃ×÷ΪWindows ×é¼þµÄWindows ÏûÏ¢ÐÐÁзþÎñ £¬¿ÉÒÔͨ¹ý¼ì²éÊÇ·ñÓÐÃûΪMessage QueuingµÄ·þÎñÔÚÔËÐÐ £¬ÒÔ¼°¼ÆËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£

ÆäËüÖµµÃ¹Ø×¢µÄ©¶´»¹°üÂÞµ«²»ÏÞÓÚ£º

CVE-2023-21709£ºMicrosoft Exchange Server ȨÏÞÌáÉý©¶´

¸Ã©¶´µÄCVSSv3.1ÆÀ·ÖΪ9.8 £¬ÔÚ»ùÓÚÍøÂçµÄ¹¥»÷ÖÐ £¬¿ÉÒÔͨ¹ý±©Á¦ÆÆ½âÓû§ÕÊ»§ÃÜÂëÒÔ¸ÃÓû§Éí·ÝµÇ¼¡£½¨ÒéʹÓÃÇ¿ÃÜÂëÀ´»º½â±©Á¦ÆÆ½â¹¥»÷¡£

CVE-2023-35388 /CVE-2023-38182£ºMicrosoft Exchange Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÕâЩ©¶´µÄCVSSv3.1ÆÀ·Ö¾ùΪ8.0 £¬Í¨¹ý LAN ·ÃÎÊÉí·ÝÑéÖ¤²¢ÓµÓÐÓÐЧ Exchange Óû§Æ¾¾ÝµÄÍþвÕß¿ÉÒÔͨ¹ý PowerShell Ô¶³Ì´¦ÖûỰԶ³ÌÖ´ÐдúÂë¡£

΢Èí8Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º

CVE ID

CVE ±êÌâ

ÑÏÖØÐÔ

CVE-2023-36895

Microsoft   Outlook Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-29328

Microsoft   Teams Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-29330

Microsoft   Teams Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-35385

Microsoft ÏûÏ¢ÐÐÁÐÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-36911

Microsoft ÏûÏ¢ÐÐÁÐÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-36910

Microsoft ÏûÏ¢ÐÐÁÐÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-38178

.NET Core ºÍ Visual Studio ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-35390

.NETºÍVisual StudioÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-36873

.NET   Framework ÆÛƭ©¶´

¸ßΣ

CVE-2023-38180

.NET ºÍ Visual Studio ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-36899

ASP.NET ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2023-35391

ASP.NET   Core SignalR ºÍ Visual Studio ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-38176

Azure   Arc-Enabled Servers ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-36869

Azure   DevOps Server ÆÛƭ©¶´

¸ßΣ

CVE-2023-38188

Azure   Apache Hadoop ÆÛƭ©¶´

¸ßΣ

CVE-2023-35393

Azure   Apache Hive ÆÛƭ©¶´

¸ßΣ

CVE-2023-35394

Azure HDInsight   Jupyter Notebook ÆÛƭ©¶´

¸ßΣ

CVE-2023-36881

Azure   Apache Ambari ÆÛƭ©¶´

¸ßΣ

CVE-2023-36877

Azure   Apache Oozie ÆÛƭ©¶´

¸ßΣ

CVE-2023-38167

Microsoft   Dynamics Business Central ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35389

Microsoft   Dynamics 365 On-Premises Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-38185

Microsoft   Exchange Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35388

Microsoft   Exchange Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35368

Microsoft   Exchange Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-38181

Microsoft   Exchange Server ÆÛƭ©¶´

¸ßΣ

CVE-2023-38182

Microsoft   Exchange Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-21709

Microsoft   Exchange Server ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2023-36897

Visual   Studio Tools for Office Runtime ÆÛƭ©¶´

¸ßΣ

CVE-2023-36896

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35371

Microsoft   Office Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-36893

Microsoft   Outlook ÆÛƭ©¶´

¸ßΣ

CVE-2023-36891

Microsoft   SharePoint Server ÆÛƭ©¶´

¸ßΣ

CVE-2023-36894

Microsoft   SharePoint Server ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-36890

Microsoft   SharePoint Server ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-36892

Microsoft   SharePoint Server ÆÛƭ©¶´

¸ßΣ

CVE-2023-35372

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-36865

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-36866

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-36882

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-20569

AMD£ºCVE-2023-20569 ·µ»ØµØÖ·Ô¤²âÆ÷

¸ßΣ

CVE-2023-38170

HEVC Video   Extensions Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-36876

Reliability   Analysis Metrics Calculation (RacTask) ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2023-36908

Windows   Hyper-V ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-38169

Microsoft   OLE DB Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-36898

Tablet   Windows User Interface Application Core Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35387

Windows   Bluetooth A2DP driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-36904

Windows   Cloud Files Mini Filter Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-36900

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-36907

Windows ¼ÓÃÜ·þÎñÐÅϢй¶©¶´

¸ßΣ

CVE-2023-36906

Windows ¼ÓÃÜ·þÎñÐÅϢй¶©¶´

¸ßΣ

CVE-2023-38175

Microsoft   Windows Defender ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2023-35381

Windows ´«Õæ·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-36889

Windows ×鼯ıÄþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-35384

Windows   HTMLƽ̨Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-35359

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-38154

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35382

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35386

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35380

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-38184

Windows ÇáÁ¿¼¶Ä¿Â¼·ÃÎÊЭÒé (LDAP) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-36909

Microsoft ÏûÏ¢ÐÐÁоܾø·þÎñ©¶´

¸ßΣ

CVE-2023-35376

Microsoft ÏûÏ¢ÐÐÁоܾø·þÎñ©¶´

¸ßΣ

CVE-2023-38172

Microsoft ÏûÏ¢ÐÐÁоܾø·þÎñ©¶´

¸ßΣ

CVE-2023-35383

Microsoft ÏûÏ¢ÐÐÁÐÐÅϢй¶©¶´

¸ßΣ

CVE-2023-36913

Microsoft ÏûÏ¢ÐÐÁÐÐÅϢй¶©¶´

¸ßΣ

CVE-2023-35377

Microsoft ÏûÏ¢ÐÐÁоܾø·þÎñ©¶´

¸ßΣ

CVE-2023-38254

Microsoft ÏûÏ¢ÐÐÁоܾø·þÎñ©¶´

¸ßΣ

CVE-2023-36912

Microsoft ÏûÏ¢ÐÐÁоܾø·þÎñ©¶´

¸ßΣ

CVE-2023-38186

Windows   Mobile É豸¹ÜÀíȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2023-35378

Windows   Projected File System ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35379

Reliability   Analysis Metrics Calculation Engine (RACEng) ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-36914

Windows   Smart Card Resource Management Server Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-36903

Windows System   Assessment Tool ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-36905

Windows ÎÞÏß¹ãÓòÍø·þÎñ (WwanSvc) ÐÅϢй¶©¶´

¸ßΣ

ADV230004

ÄÚ´æÍêÕûÐÔϵͳ¾ÍÐ÷ɨÃ蹤¾ßÉî¶È·ÀÓù¸üÐÂ

ÖÐΣ

CVE-2023-38157

Microsoft   Edge£¨»ùÓÚ Chromium£©Äþ¾²¹¦Ð§Èƹý©¶´

ÖÐΣ

ADV230003

Microsoft   Office Éî¶È·ÀÓù¸üÐÂ

ÖÐΣ

CVE-2023-35945

Envoy ¾Ü¾ø·þÎñ©¶´

δ֪

CVE-2023-4068

Chromium£ºCVE-2023-4068 V8 ÖеÄÀàÐÍ»ìÏý

δ֪

CVE-2023-4072

Chromium£ºCVE-2023-4072 WebGL ÖеĶÁдԽ½ç

δ֪

CVE-2023-4071

Chromium£ºCVE-2023-4071 Visuals ÖеĶѻº³åÇøÒç³ö

δ֪

CVE-2023-4073

Chromium£ºCVE-2023-4073 ANGLE ÖеÄÄÚ´æ·ÃÎÊÔ½½ç

δ֪

CVE-2023-4075

Chromium£ºCVE-2023-4075 ÔÚ Cast ÖÐÊͷźóʹÓÃ

δ֪

CVE-2023-4074

Chromium£ºCVE-2023-4074 ÔÚ Blink ÈÎÎñµ÷ÖÎÖÐÊͷźóʹÓÃ

δ֪

CVE-2023-4076

Chromium£ºCVE-2023-4076 ÔÚ WebRTC ÖÐÊͷźóʹÓÃ

δ֪

CVE-2023-4077

Chromium£ºCVE-2023-4077 À©Õ¹ÖеÄÊý¾ÝÑéÖ¤²»×ã

δ֪

CVE-2023-4078

Chromium£ºCVE-2023-4078 À©Õ¹ÖеÄʵʩ²»Í×

δ֪

CVE-2023-4070

Chromium£ºCVE-2023-4070 V8 ÖеÄÀàÐÍ»ìÏý

δ֪

CVE-2023-4069

Chromium£ºCVE-2023-4069 V8 ÖеÄÀàÐÍ»ìÏý

δ֪

 

¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

Microsoft Office

Memory Integrity System Readiness Scan Tool

Microsoft Exchange Server

Microsoft Teams

Windows Kernel

Microsoft Office Excel

Microsoft Office Visio

Windows Message Queuing

Windows Projected File System

Windows Reliability Analysis Metrics Calculation Engine

Windows Fax and Scan Service

Windows HTML Platform

Windows Bluetooth A2DP driver

Microsoft Dynamics

.NET Core

ASP.NET and Visual Studio

Azure HDInsights

Azure DevOps

.NET Framework

Reliability Analysis Metrics Calculation Engine

Microsoft WDAC OLE DB provider for SQL

Windows Group Policy

Microsoft Office SharePoint

Microsoft Office Outlook

Tablet Windows User Interface

ASP.NET

Windows Common Log File System Driver

Windows System Assessment Tool

Windows Cloud Files Mini Filter Driver

Windows Wireless Wide Area Network Service

Windows Cryptographic Services

Role: Windows Hyper-V

Windows Smart Card

Microsoft Edge (Chromium-based)

Dynamics Business Central Control

SQL Server

Microsoft Windows Codecs Library

Windows Defender

Azure Arc

ASP .NET

Windows LDAP - Lightweight Directory Access Protocol

Windows Mobile Device Management

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üР£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓà £¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ £¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü £¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡± £¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС± £¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС± £¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú £¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üР£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó £¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡± £¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2023Äê8ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2023-Aug

²¹¶¡ÏÂÔØÊ¾Àý£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó £¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2022Äê2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ £¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Äþ¾²¸üС¿ £¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ £¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£

 

3.2 ÁÙʱ´ëÊ©

Õë¶ÔCVE-2023-21709 £¬¿É²Î¿¼£º

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21709

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡ £¬¼õÉÙϵͳ©¶´ £¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ £¬Ð޸ķÀ»ðǽ¼ÆÄ± £¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ £¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎï £¬ÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí £¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2023-Aug

https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2023-patch-tuesday-warns-of-2-zero-days-87-flaws/

  

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-08-09

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼

5.1 ¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Äê £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏà £¬¹«Ë¾Ô±¹¤6000ÓàÈË £¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ £¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯ £¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´ £¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png