¡¾Â©¶´Í¨¸æ¡¿Î¢Èí12Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2023-12-13Ò»¡¢Â©¶´¸ÅÊö
2023Äê12ÔÂ12ÈÕ£¬Î¢ÈíÐû²¼ÁË12ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË36¸ö©¶´£¨²»°üÂÞ12ÔÂ7ÈÕÐÞ¸´µÄ8¸öMicrosoft Edge©¶´£©£¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛÆÂ©¶´µÈ¡£
±¾´ÎÄþ¾²¸üÐÂÐÞ¸´ÁË1¸öÒÑÓÚ8ÔÂÅû¶µ«Ö®Ç°ÉÐδÐÞ¸´µÄAMD 0 day©¶´£º
CVE-2023-20588- AMD£ºAMDÍÆ²âÐÔй¶©¶´£¨ÖÐΣ£©
ijЩ AMD ´¦ÖÃÆ÷ÉÏ´æÔÚ³ýÁã´íÎ󣬿ÉÄܵ¼Ö·µ»ØÍƲâÊý¾Ý£¬Ôì³ÉÐÅϢй¶¡£
ÆÀ¼¶ÎªÑÏÖØµÄ4¸ö©¶´°üÂÞ£º
CVE-2023-36019£ºMicrosoft Power Platform ConnectorÆÛÆÂ©¶´£¨ÑÏÖØ£©
¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.6£¬¿Éͨ¹ýÓÕµ¼Óû§µ¥»÷ÌØÖÆµÄ URLÀ´ÀûÓøÃ©¶´£¬¿ÉÄܵ¼Ö¶ñÒâ½Å±¾ÔÚÊܺ¦Õß¼ÆËã»úÉϵÄä¯ÀÀÆ÷ÖÐÖ´ÐС£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£
CVE-2023-35630£ºInternet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨¸ßΣ£©
¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬ÀÖ³ÉÀûÓøÃ©¶´ÐèÒªÐÞ¸ÄDHCPv6 DHCPv6_MESSAGE_INFORMATION_REQUESTÊäÈëÏûÏ¢ÖеÄoption->length×ֶΡ£¸Ã©¶´²»ÄÜ¿ç¶à¸öÍøÂ磨ÈçWAN£©ÀûÓã¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£
CVE-2023-35641£ºInternet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨¸ßΣ£©
¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬¿Éͨ¹ýÏòÔËÐÐ Internet Á¬½Ó¹²Ïí·þÎñµÄ·þÎñÆ÷·¢ËͶñÒâÖÆ×÷µÄ DHCP ÏûÏ¢À´ÀûÓøÃ©¶´¡£¸Ã©¶´²»ÄÜ¿ç¶à¸öÍøÂ磨ÈçWAN£©ÀûÓã¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϴ󡱡£
CVE-2023-35628£ºWindows MSHTML PlatformÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨¸ßΣ£©
¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.1£¬¿ÉÒÔÔÚÎÞÐèÓû§½»»¥µÄÇé¿öÏÂÔ¶³ÌÀûÓ㬵«¹¥»÷ÅÓ´ó¶È½Ï¸ß¡£ÍþвÕß¿Éͨ¹ýµç×ÓÓʼþ»òÆäËû·½Ê½ÏòÊܺ¦Õß·¢ËͶñÒâÁ´½Ó²¢ÓÕµ¼Óû§µ¥»÷¶ñÒâÁ´½ÓÀ´ÀûÓøÃ©¶´£»»òÕß¿ÉÒÔͨ¹ý·¢ËÍÌØÖÆµç×ÓÓʼþÀ´ÀûÓøÃ©¶´£¬¸Ãµç×ÓÓʼþ¿ÉÄÜ»áÔÚOutlook ¿Í»§¶Ë¼ìË÷ºÍ´¦ÖÃʱ×Ô¶¯´¥·¢£¬¶øÎÞÐèÊܺ¦Õß´ò¿ª¡¢ÔĶÁ»òµ¥»÷Á´½Ó£¬Õâ¿ÉÄܻᵼÖÂÔÚÔ¤ÀÀ´°¸ñÖмì²ìµç×ÓÓʼþ֮ǰ±»ÀûÓá£ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼ÖÂÔÚÊܺ¦ÕߵļÆËã»úÉÏÔ¶³ÌÖ´ÐдúÂ롣΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϴ󡱡£
³ýÁËCVE-2023-35641ºÍCVE-2023-35628Í⣬΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖС°±»ÀûÓõĿÉÄÜÐԽϴ󡱵Ä©¶´»¹°üÂÞ£º
CVE-2023-35631£ºWin32k ÌØÈ¨ÌáÉý©¶´
CVE-2023-35632£ºWindows Ancillary Function Driver for WinSockÌØÈ¨ÌáÉý©¶´
CVE-2023-35633£ºWindows KernelÌØÈ¨ÌáÉý©¶´
CVE-2023-35644£ºWindows Sysmain ServiceÌØÈ¨ÌáÉý©¶´
CVE-2023-36005£ºWindows Telephony Server ÌØÈ¨ÌáÉý©¶´
CVE-2023-36010£ºMicrosoft Defender¾Ü¾ø·þÎñ©¶´
CVE-2023-36011£ºWin32k ÌØÈ¨ÌáÉý©¶´
CVE-2023-36391£ºLocal Security Authority Subsystem ServiceȨÌáÉý©¶´
CVE-2023-36696£ºWindows Cloud Files Mini Filter DriverÌØÈ¨ÌáÉý©¶´
΢Èí12Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑÏÖØÐÔ |
CVE-2023-36019 | Microsoft Power Platform Connector ÆÛÆÂ©¶´ | ÑÏÖØ |
CVE-2023-35630 | Internet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-35641 | Internet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-35628 | Windows MSHTML Platform Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-35624 | Azure Connected Machine Agent ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35625 | Azure Machine Learning Compute Instance for SDK Óû§ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-20588 | AMD£ºCVE-2023-20588 AMD ÍÆ²âÐÔй¶Äþ¾²Í¨Öª | ¸ßΣ |
CVE-2023-35634 | Windows Bluetooth Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-35621 | Microsoft Dynamics 365 Finance and Operations ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-36020 | Microsoft Dynamics 365 (on-premises) ¿çÕ¾µã½Å±¾Â©¶´ | ¸ßΣ |
CVE-2023-35636 | Microsoft Outlook ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-35619 | Microsoft Outlook for Mac ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-36009 | Microsoft Word ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-36006 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-35622 | Windows DNS ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-36696 | Windows Cloud Files Mini Filter Driver ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36010 | Microsoft Defender ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-35643 | DHCP Server Service ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-35638 | DHCP Server Service ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-36012 | DHCP Server Service ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-36004 | Windows DPAPI£¨Êý¾Ý±£»¤Ó¦Ó÷¨Ê½±à³Ì½Ó¿Ú£©ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-35642 | Internet Connection Sharing (ICS) ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-35632 | Windows Ancillary Function Driver for WinSock ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35633 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35635 | Windows Äں˾ܾø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-35644 | Windows Sysmain Service ȨÏÞÌáÉý | ¸ßΣ |
CVE-2023-36391 | Local Security Authority Subsystem Service ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-21740 | Windows Media Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-35639 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-36005 | Windows Telephony Server ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35629 | Microsoft USBHUB 3.0 Device Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-36011 | Win32k ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35631 | Win32k ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36003 | XAML Diagnostics ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35618 | Microsoft Edge£¨»ùÓÚ Chromium£©È¨ÏÞÌáÉý©¶´ | ÖÐΣ |
CVE-2023-36880 | Microsoft Edge£¨»ùÓÚChromium£©ÐÅϢй¶©¶´ | µÍΣ |
CVE-2023-38174 | Microsoft Edge£¨»ùÓÚChromium£©ÐÅϢй¶©¶´ | µÍΣ |
CVE-2023-6509 | Chromium£ºCVE-2023-6509 ÔÚSide Panel SearchÖÐUse-after-free | δ֪ |
CVE-2023-6512 | Chromium£ºCVE-2023-6512 Web ä¯ÀÀÆ÷ UI ÖеÄʵʩ²»Í× | δ֪ |
CVE-2023-6508 | Chromium£ºCVE-2023-6508 ÔÚMedia StreamÖÐUse-after-free | δ֪ |
CVE-2023-6511 | Chromium£ºCVE-2023-6511 ×Ô¶¯Ìî³äÖеÄʵʩ²»Í× | δ֪ |
CVE-2023-6510 | Chromium£ºCVE-2023-6510 ÔÚMedia CaptureÖÐUse-after-free | δ֪ |
¶þ¡¢Ó°Ï췶Χ
ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º
Windows Media
Microsoft Edge (Chromium-based)
Microsoft Office Outlook
Microsoft Dynamics
Microsoft Windows DNS
Azure Connected Machine Agent
Azure Machine Learning
Windows MSHTML Platform
Windows USB Mass Storage Class Driver
Windows Internet Connection Sharing (ICS)
Windows Win32K
Windows Kernel
Microsoft Bluetooth Driver
Windows DHCP Server
Windows ODBC Driver
Windows Kernel-Mode Drivers
XAML Diagnostics
Windows DPAPI (Data Protection Application Programming Interface)
Windows Telephony Server
Microsoft WDAC OLE DB provider for SQL
Microsoft Office Word
Windows Defender
Microsoft Power Platform Connector
Windows Local Security Authority Subsystem Service (LSASS)
Windows Cloud Files Mini Filter Driver
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£
£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2023Äê12ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2023-Dec
²¹¶¡ÏÂÔØÊ¾Àý£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2022Äê2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£
Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£
3.2 ÁÙʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2023-Dec
https://www.bleepingcomputer.com/news/microsoft/microsoft-december-2023-patch-tuesday-fixes-34-flaws-1-zero-day/
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7007.html
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-12-13 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¶«Éƽ̨¼ò½é
¶«Éƽ̨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«Éƽ̨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶«Éƽ̨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
5.2 ¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º