¡¾Â©¶´Í¨¸æ¡¿Î¢Èí2Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2024-02-19Ò»¡¢Â©¶´¸ÅÊö
2024Äê2ÔÂ13ÈÕ£¬Î¢ÈíÐû²¼ÁË2ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË73¸ö©¶´£¨²»°üÂÞ2ÔÂ8ÈÕÐÞ¸´µÄMicrosoft EdgeºÍÆäËü©¶´£©£¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛÆÂ©¶´µÈ¡£
±¾´ÎÄþ¾²¸üÐÂÖаüÂÞ2¸ö±»»ý¼«ÀûÓõÄ0 day©¶´£º
CVE-2024-21351£ºWindows SmartScreen Äþ¾²¹¦Ð§Èƹý©¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.6£¬ÍþвÕß¿ÉÏòÓû§·¢ËͶñÒâÎļþ²¢ÓÕµ¼Óû§´ò¿ªÎļþÀ´ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÈÆ¹ý SmartScreenÄþ¾²¹¦Ð§¡£¸Ã©¶´ÔÊÐíÍþвÕß½«´úÂë×¢Èë SmartScreen ²¢¿ÉÄÜ»ñµÃ´úÂëÖ´ÐÐȨÏÞ£¬´Ó¶ø¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢ÏµÍ³¿ÉÓÃÐÔÓ°Ï죬Ŀǰ¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£
CVE-2024-21412£ºInternet ¿ì½Ý·½Ê½ÎļþÄþ¾²¹¦Ð§Èƹý©¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.1£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔÏòÄ¿±êÓû§·¢ËÍÖ¼ÔÚÈÆ¹ýÏÔʾµÄÄþ¾²¼ì²éµÄÌØÖÆÎļþ²¢ÓÕµ¼Óû§´ò¿ª¸ÃÎļþ£¬µ¼ÖÂÄþ¾²¹¦Ð§Èƹý¡£ÒÑ·¢ÏÖAPT×éÖ¯Water Hydra£¨ÓÖÃû DarkCasino£©ÔÚÕë¶Ô½ðÈÚ½»Ò×ÕߵĻÖлý¼«ÀûÓøÃ©¶´¡£
±¾´ÎÄþ¾²¸üÐÂÖУ¬ÆÀ¼¶Îª¡°ÑÏÖØ¡±µÄ5¸ö©¶´°üÂÞ£º
CVE-2024-21380£ºMicrosoft Dynamics Business Central/NAV ÐÅϢй¶©¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.0£¬ÀÖ³ÉÀûÓøÃ©¶´ÐèÒª¾¹ýÉí·ÝÑéÖ¤¡¢Ó®µÃ¾ºÕùÌõ¼þ£¬²¢ÐèÒªÓû§½»»¥£¬ÀÖ³ÉÀûÓøÃ©¶´µÄÍþвÕß¿ÉÒÔ·ÃÎÊÓû§Êý¾Ý£¬µ¼ÖÂδÊÚȨ·ÃÎÊÊܺ¦ÕßµÄÕË»§»òй¶ÆäËü»úÃÜÐÅÏ¢¡£
CVE-2024-21410£ºMicrosoft Exchange Server ȨÏÞÌáÉý©¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬ÀÖ³ÉÀûÓøÃ©¶´µÄÍþвÕß¿ÉÒÔ½«Óû§Ð¹Â¶µÄNet-NTLMv2¹þÏ£Öм̵½Ò×Êܹ¥»÷µÄExchange Server£¬²¢ÒÔÓû§Éí·Ý½øÐÐÉí·ÝÑéÖ¤¡£ÊÜÓ°ÏìÓû§Ò²¿É²Î¿¼¹Ù·½ÌṩµÄÎĵµºÍ½Å±¾Îª Exchange ServerÆôÓÃÉí·ÝÑéÖ¤À©Õ¹±£»¤ (EPA)À´»º½â¸Ã©¶´£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£
CVE-2024-21413£ºMicrosoft OutlookÔ¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼ÖÂÈÆ¹ý Office Êܱ£»¤µÄÊÓͼ²¢ÒÔ±à¼Ä£Ê½¶ø²»ÊDZ£»¤Ä£Ê½´ò¿ª£¬Ô¤ÀÀ´°¸ñÊǸé¶´µÄÒ»¸ö¹¥»÷ý½é¡£ÍþвÕß¿ÉÒÔ´´½¨ÈƹýÊܱ£»¤ÊÓͼÐÒéµÄ¶ñÒâÁ´½Ó£¬´Ó¶øµ¼Öµ±µØNTLMƾ¾ÝÐÅϢй¶ºÍÔ¶³Ì´úÂëÖ´ÐС£
CVE-2024-20684£ºWindows Hyper-V ¾Ü¾ø·þÎñ©¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ6.5£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼Ö Hyper-V guestÓ°Ïì Hyper-V Ö÷»úµÄ¹¦Ð§¡£
CVE-2024-21357£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐЩ¶´
Windows Pragmatic General Multicast (PGM) ·¢ÉúµÄ×é²¥Á÷Á¿ÔÚµÚ4 ²ãÔËÐв¢¿É·ÓÉ£¬ÍþвÕß¿ÉÒÔͨ¹ýÏòÒ×Êܹ¥»÷µÄ·þÎñÆ÷·¢ËÍÌØÖÆµÄ¶ñÒâÁ÷Á¿À´ÀûÓøÃ©¶´¡£¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.1£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£
³ýCVE-2024-21410ºÍCVE-2024-21357ÒÔÍ⣬±¾´ÎÄþ¾²¸üÐÂÖУ¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖС°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ©¶´»¹°üÂÞ£º
CVE-2024-21338£ºWindows ÄÚºËÌØÈ¨ÌáÉý©¶´
CVE-2024-21345£ºWindows ÄÚºËÌØÈ¨ÌáÉý©¶´
CVE-2024-21346£ºWin32k ÌØÈ¨ÌáÉý©¶´
CVE-2024-21371£ºWindows ÄÚºËÌØÈ¨ÌáÉý©¶´
CVE-2024-21378£ºMicrosoft OutlookÔ¶³Ì´úÂëÖ´ÐЩ¶´
CVE-2024-21379£ºMicrosoft WordÔ¶³Ì´úÂëÖ´ÐЩ¶´
΢Èí2Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑÏÖØÐÔ |
CVE-2024-21380 | Microsoft Dynamics Business Central/NAV ÐÅϢй¶©¶´ | ÑÏÖØ |
CVE-2024-21410 | Microsoft Exchange Server ȨÏÞÌáÉý©¶´ | ÑÏÖØ |
CVE-2024-21413 | Microsoft Outlook Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2024-20684 | Windows Hyper-V ¾Ü¾ø·þÎñ©¶´ | ÑÏÖØ |
CVE-2024-21357 | Windows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2024-21386 | .NET ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-21404 | .NET ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-21401 | Microsoft Entra Jira Single-Sign-On Plugin ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21381 | Microsoft Azure Active Directory B2C ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2024-21329 | Azure Connected Machine Agent ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-20667 | Azure DevOps Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21397 | Microsoft Azure File SyncȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-20679 | Azure Stack Hub ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2024-21412 | Internet ¿ì½Ý·½Ê½ÎļþÄþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-21349 | Microsoft ActiveX Êý¾Ý¹¤¾ßÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21403 | Microsoft Azure Kubernetes Service Confidential Container ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21376 | Microsoft Azure Kubernetes Service Confidential Container Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21315 | Microsoft Defender for Endpoint Protection ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21393 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾½Å±¾Â©¶´ | ¸ßΣ |
CVE-2024-21389 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾½Å±¾Â©¶´ | ¸ßΣ |
CVE-2024-21395 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾½Å±¾Â©¶´ | ¸ßΣ |
CVE-2024-21328 | Dynamics 365 Sales ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2024-21394 | Dynamics 365 Field Service ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2024-21396 | Dynamics 365 Sales ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2024-21327 | Microsoft Dynamics 365 Customer Engagement ¿çÕ¾½Å±¾Â©¶´ | ¸ßΣ |
CVE-2024-20673 | Microsoft Office Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21384 | Microsoft Office OneNote Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21378 | Microsoft Outlook Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21402 | Microsoft Outlook ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21379 | Microsoft Word Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21374 | Microsoft Teams for Android ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2024-21353 | Microsoft WDAC ODBC Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21370 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21350 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21368 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21359 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21365 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21367 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21420 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21366 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21369 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21375 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21361 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21358 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21391 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21360 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21352 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21406 | Windows Printing Service ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2024-21377 | Windows DNS ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-50387 | MITRE£ºCVE-2023-50387 DNSSEC ÑéÖ¤ÅÓ´óÐԿɱ»ÀûÓÃÀ´ºÄ¾¡ CPU ×ÊÔ´²¢Í£Ö¹ DNS ½âÎöÆ÷ | ¸ßΣ |
CVE-2024-21342 | Windows DNS Client ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-20695 | Skype for Business ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2024-21347 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21304 | Trusted Compute Base ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21343 | Windows Network Address Translation (NAT) ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-21348 | Internet Connection Sharing (ICS) ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-21344 | Windows Network Address Translation (NAT) ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-21371 | Windows Kernel ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21338 | Windows Kernel ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21341 | Windows Kernel Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21345 | Windows Kernel ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21362 | Windows Kernel Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-21340 | Windows Kernel ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2024-21356 | Windows Lightweight Directory Access Protocol (LDAP) ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-21363 | Microsoft Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21355 | Microsoft Message Queuing (MSMQ) ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21405 | Microsoft Message Queuing (MSMQ) ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21354 | Microsoft Message Queuing (MSMQ) ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21372 | Windows OLE Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21339 | Windows USB Generic Parent Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21346 | Win32k ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21364 | Microsoft Azure Site RecoveryÌØÈ¨ÌáÉý©¶´ | ÖÐΣ |
CVE-2024-21399 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÖÐΣ |
CVE-2024-21351 | Windows SmartScreen Äþ¾²¹¦Ð§Èƹý©¶´ | ÖÐΣ |
CVE-2024-21626 | runc ÎļþÃèÊö·ûй© | δ֪ |
CVE-2024-1284 | Chromium£ºCVE-2024-1284 ÔÚ Mojo ÖÐÊͷźóʹÓà | δ֪ |
CVE-2024-1060 | Chromium£ºCVE-2024-1060 ÔÚ Canvas ÖÐÊͷźóʹÓà | δ֪ |
CVE-2024-1077 | Chromium£ºCVE-2024-1077 ÔÚ Network ÖÐÊͷźóʹÓà | δ֪ |
CVE-2024-1283 | Chromium£ºCVE-2024-1283 Skia ÖеĶѻº³åÇøÒç³ö | δ֪ |
CVE-2024-1059 | Chromium£ºCVE-2024-1059 ÔÚ WebRTC ÖÐÊͷźóʹÓà | δ֪ |
¶þ¡¢Ó°Ï췶Χ
ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º
Azure DevOps
Microsoft Office
Azure Stack
Windows Hyper-V
Skype for Business
Trusted Compute Base
Microsoft Defender for Endpoint
Microsoft Dynamics
Azure Connected Machine Agent
Windows Kernel
Windows USB Serial Driver
Role: DNS Server
Windows Internet Connection Sharing (ICS)
Windows Win32K - ICOMP
SQL Server
Microsoft ActiveX
Microsoft WDAC OLE DB provider for SQL
Windows SmartScreen
Microsoft WDAC ODBC Driver
Windows Message Queuing
Windows LDAP - Lightweight Directory Access Protocol
Azure Site Recovery
Windows OLE
Microsoft Teams for Android
Microsoft Azure Kubernetes Service
Microsoft Windows DNS
Microsoft Office Outlook
Microsoft Office Word
Azure Active Directory
Microsoft Office OneNote
.NET
Azure File Sync
Microsoft Edge (Chromium-based)
Microsoft Windows
Microsoft Exchange Server
Internet Shortcut Files
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£
£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2024Äê2ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2024-Feb
²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2022Äê2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£
Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£
3.2 ÁÙʱ´ëÊ©
Õë¶ÔCVE-2024-21410£¬ÔÚ Exchange Server 2019 ÀÛ»ý¸üÐÂ14 (CU14) ¸üÐÂ֮ǰ£¬Exchange Server ĬÈÏÇé¿öϲ»ÆôÓà NTLM ƾ¾ÝÖм̱£»¤£¨³ÆÎªÉí·ÝÑéÖ¤À©Õ¹±£»¤»ò EPA£©£¬Exchange Server 2019 CU14 ĬÈÏÔÚ Exchange ServerÉÏÆôÓà EPA£¬Microsoft ½¨ÒéÔÚ Exchange Server 2019 Éϰ²×° CU14 £¬»ò²ÎÔÄExchange À©Õ¹±£»¤Îĵµ²¢Ê¹ÓÃExchangeExtendedProtectionManagement.ps1½Å±¾Îª Exchange ServerÆôÓÃÉí·ÝÑéÖ¤À©Õ¹±£»¤ (EPA)À´»º½â¸Ã©¶´¡£
¸ü¶à©¶´ÏêÇé¼°»º½â´ëÊ©¿É²Î¿¼¹Ù·½Í¨¸æ£º
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-21410
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Feb
https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2024-patch-tuesday-fixes-2-zero-days-73-flaws/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-02-19 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¶«Éƽ̨¼ò½é
¶«Éƽ̨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«Éƽ̨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶«Éƽ̨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
5.2 ¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º