¡¾Â©¶´Í¨¸æ¡¿Î¢Èí12Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2023-12-13
 

Ò»¡¢Â©¶´¸ÅÊö

2023Äê12ÔÂ12ÈÕ £¬Î¢ÈíÐû²¼ÁË12ÔÂÄþ¾²¸üР£¬±¾´Î¸üй²ÐÞ¸´ÁË36¸ö©¶´£¨²»°üÂÞ12ÔÂ7ÈÕÐÞ¸´µÄ8¸öMicrosoft Edge©¶´£© £¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛƭ©¶´µÈ¡£

±¾´ÎÄþ¾²¸üÐÂÐÞ¸´ÁË1¸öÒÑÓÚ8ÔÂÅû¶µ«Ö®Ç°ÉÐδÐÞ¸´µÄAMD 0 day©¶´£º

CVE-2023-20588- AMD£ºAMDÍÆ²âÐÔй¶©¶´£¨ÖÐΣ£©

ijЩ AMD ´¦ÖÃÆ÷ÉÏ´æÔÚ³ýÁã´íÎó £¬¿ÉÄܵ¼Ö·µ»ØÍƲâÊý¾Ý £¬Ôì³ÉÐÅϢй¶¡£

ÆÀ¼¶ÎªÑÏÖØµÄ4¸ö©¶´°üÂÞ£º

CVE-2023-36019£ºMicrosoft Power Platform ConnectorÆÛƭ©¶´£¨ÑÏÖØ£©

¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.6 £¬¿Éͨ¹ýÓÕµ¼Óû§µ¥»÷ÌØÖÆµÄ URLÀ´ÀûÓøÃ©¶´ £¬¿ÉÄܵ¼Ö¶ñÒâ½Å±¾ÔÚÊܺ¦Õß¼ÆËã»úÉϵÄä¯ÀÀÆ÷ÖÐÖ´ÐС£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£

CVE-2023-35630£ºInternet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨¸ßΣ£©

¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8 £¬ÀÖ³ÉÀûÓøÃ©¶´ÐèÒªÐÞ¸ÄDHCPv6 DHCPv6_MESSAGE_INFORMATION_REQUESTÊäÈëÏûÏ¢ÖеÄoption->length×ֶΡ£¸Ã©¶´²»ÄÜ¿ç¶à¸öÍøÂ磨ÈçWAN£©ÀûÓà £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£

CVE-2023-35641£ºInternet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨¸ßΣ£©

¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8 £¬¿Éͨ¹ýÏòÔËÐÐ Internet Á¬½Ó¹²Ïí·þÎñµÄ·þÎñÆ÷·¢ËͶñÒâÖÆ×÷µÄ DHCP ÏûÏ¢À´ÀûÓøÃ©¶´¡£¸Ã©¶´²»ÄÜ¿ç¶à¸öÍøÂ磨ÈçWAN£©ÀûÓà £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϴ󡱡£

CVE-2023-35628£ºWindows MSHTML PlatformÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨¸ßΣ£©

¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.1 £¬¿ÉÒÔÔÚÎÞÐèÓû§½»»¥µÄÇé¿öÏÂÔ¶³ÌÀûÓà £¬µ«¹¥»÷ÅÓ´ó¶È½Ï¸ß¡£ÍþвÕß¿Éͨ¹ýµç×ÓÓʼþ»òÆäËû·½Ê½ÏòÊܺ¦Õß·¢ËͶñÒâÁ´½Ó²¢ÓÕµ¼Óû§µ¥»÷¶ñÒâÁ´½ÓÀ´ÀûÓøÃ©¶´£»»òÕß¿ÉÒÔͨ¹ý·¢ËÍÌØÖÆµç×ÓÓʼþÀ´ÀûÓøÃ©¶´ £¬¸Ãµç×ÓÓʼþ¿ÉÄÜ»áÔÚOutlook ¿Í»§¶Ë¼ìË÷ºÍ´¦ÖÃʱ×Ô¶¯´¥·¢ £¬¶øÎÞÐèÊܺ¦Õß´ò¿ª¡¢ÔĶÁ»òµ¥»÷Á´½Ó £¬Õâ¿ÉÄܻᵼÖÂÔÚÔ¤ÀÀ´°¸ñÖмì²ìµç×ÓÓʼþ֮ǰ±»ÀûÓá£ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼ÖÂÔÚÊܺ¦ÕߵļÆËã»úÉÏÔ¶³ÌÖ´ÐдúÂ롣΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϴ󡱡£

³ýÁËCVE-2023-35641ºÍCVE-2023-35628Íâ £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖС°±»ÀûÓõĿÉÄÜÐԽϴ󡱵Ä©¶´»¹°üÂÞ£º

CVE-2023-35631£ºWin32k ÌØÈ¨ÌáÉý©¶´

CVE-2023-35632£ºWindows Ancillary Function Driver for WinSockÌØÈ¨ÌáÉý©¶´

CVE-2023-35633£ºWindows KernelÌØÈ¨ÌáÉý©¶´

CVE-2023-35644£ºWindows Sysmain ServiceÌØÈ¨ÌáÉý©¶´

CVE-2023-36005£ºWindows Telephony Server ÌØÈ¨ÌáÉý©¶´

CVE-2023-36010£ºMicrosoft Defender¾Ü¾ø·þÎñ©¶´

CVE-2023-36011£ºWin32k ÌØÈ¨ÌáÉý©¶´

CVE-2023-36391£ºLocal Security Authority Subsystem ServiceȨÌáÉý©¶´

CVE-2023-36696£ºWindows Cloud Files Mini Filter DriverÌØÈ¨ÌáÉý©¶´

΢Èí12Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º

CVE ID

CVE ±êÌâ

ÑÏÖØÐÔ

CVE-2023-36019

Microsoft Power Platform Connector ÆÛƭ©¶´

ÑÏÖØ

CVE-2023-35630

Internet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-35641

Internet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-35628

Windows MSHTML Platform Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-35624

Azure Connected Machine Agent ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2023-35625

Azure Machine Learning Compute   Instance for SDK Óû§ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-20588

AMD£ºCVE-2023-20588 AMD ÍÆ²âÐÔй¶Äþ¾²Í¨Öª

¸ßΣ

CVE-2023-35634

Windows Bluetooth Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35621

Microsoft Dynamics 365 Finance and   Operations ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-36020

Microsoft Dynamics 365 (on-premises) ¿çÕ¾µã½Å±¾Â©¶´

¸ßΣ

CVE-2023-35636

Microsoft Outlook ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-35619

Microsoft Outlook for Mac ÆÛƭ©¶´

¸ßΣ

CVE-2023-36009

Microsoft Word ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-36006

Microsoft WDAC OLE DB provider for   SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35622

Windows DNS ÆÛƭ©¶´

¸ßΣ

CVE-2023-36696

Windows Cloud Files Mini Filter   Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-36010

Microsoft Defender ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-35643

DHCP Server Service ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-35638

DHCP Server Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-36012

DHCP Server Service ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-36004

Windows DPAPI£¨Êý¾Ý±£»¤Ó¦Ó÷¨Ê½±à³Ì½Ó¿Ú£©ÆÛƭ©¶´

¸ßΣ

CVE-2023-35642

Internet Connection Sharing (ICS) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-35632

Windows Ancillary Function Driver for   WinSock ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35633

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35635

Windows Äں˾ܾø·þÎñ©¶´

¸ßΣ

CVE-2023-35644

Windows Sysmain Service ȨÏÞÌáÉý

¸ßΣ

CVE-2023-36391

Local Security Authority Subsystem   Service ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-21740

Windows Media Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-35639

Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-36005

Windows Telephony Server ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2023-35629

Microsoft USBHUB 3.0 Device Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-36011

Win32k ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35631

Win32k ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-36003

XAML Diagnostics ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-35618

Microsoft Edge£¨»ùÓÚ Chromium£©È¨ÏÞÌáÉý©¶´

ÖÐΣ

CVE-2023-36880

Microsoft Edge£¨»ùÓÚChromium£©ÐÅϢй¶©¶´

µÍΣ

CVE-2023-38174

Microsoft Edge£¨»ùÓÚChromium£©ÐÅϢй¶©¶´

µÍΣ

CVE-2023-6509

Chromium£ºCVE-2023-6509 ÔÚSide Panel SearchÖÐUse-after-free

δ֪

CVE-2023-6512

Chromium£ºCVE-2023-6512 Web ä¯ÀÀÆ÷ UI ÖеÄʵʩ²»Í×

δ֪

CVE-2023-6508

Chromium£ºCVE-2023-6508 ÔÚMedia StreamÖÐUse-after-free

δ֪

CVE-2023-6511

Chromium£ºCVE-2023-6511 ×Ô¶¯Ìî³äÖеÄʵʩ²»Í×

δ֪

CVE-2023-6510

Chromium£ºCVE-2023-6510 ÔÚMedia CaptureÖÐUse-after-free

δ֪

 


¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

Windows Media

Microsoft Edge (Chromium-based)

Microsoft Office Outlook

Microsoft Dynamics

Microsoft Windows DNS

Azure Connected Machine Agent

Azure Machine Learning

Windows MSHTML Platform

Windows USB Mass Storage Class Driver

Windows Internet Connection Sharing (ICS)

Windows Win32K

Windows Kernel

Microsoft Bluetooth Driver

Windows DHCP Server

Windows ODBC Driver

Windows Kernel-Mode Drivers

XAML Diagnostics

Windows DPAPI (Data Protection Application Programming Interface)

Windows Telephony Server

Microsoft WDAC OLE DB provider for SQL

Microsoft Office Word

Windows Defender

Microsoft Power Platform Connector

Windows Local Security Authority Subsystem Service (LSASS)

Windows Cloud Files Mini Filter Driver

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üР£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓà £¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ £¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü £¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡± £¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС± £¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС± £¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú £¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üР£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó £¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡± £¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2023Äê12ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2023-Dec

²¹¶¡ÏÂÔØÊ¾Àý£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó £¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2022Äê2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ £¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Äþ¾²¸üС¿ £¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ £¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£

3.2 ÁÙʱ´ëÊ©

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡ £¬¼õÉÙϵͳ©¶´ £¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ £¬Ð޸ķÀ»ðǽ¼ÆÄ± £¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ £¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎï £¬ÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí £¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2023-Dec

https://www.bleepingcomputer.com/news/microsoft/microsoft-december-2023-patch-tuesday-fixes-34-flaws-1-zero-day/

https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7007.html

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-12-13

Ê×´ÎÐû²¼

 

 

Îå¡¢¸½Â¼

5.1 ¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Äê £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏà £¬¹«Ë¾Ô±¹¤6000ÓàÈË £¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ £¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯ £¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´ £¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png