¡¾Â©¶´Í¨¸æ¡¿Î¢Èí4Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2024-04-10

Ò»¡¢Â©¶´¸ÅÊö

2024Äê4ÔÂ9ÈÕ£¬Î¢ÈíÐû²¼ÁË4ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË150¸ö©¶´£¨²»°üÂÞ֮ǰÐÞ¸´µÄMicrosoft Edge ºÍMariner©¶´£©£¬Â©¶´ÀàÐÍ°üÂÞÌØȨÌáÉý©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢ鶩¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛƭ©¶´µÈ¡£

±¾´ÎÄþ¾²¸üÐÂÖаüÂÞ2¸ö±»»ý¼«ÀûÓõÄ0 day©¶´£º

CVE-2024-26234£ºProxy DriverÆÛƭ©¶´

¸Ã©¶´µÄCVSSÆÀ·ÖΪ6.7£¬ÓëSophos X-Ops ·¢ÏÖµÄÓÐЧMicrosoftÓ²¼þ¿¯ÐÐÉÌÖ¤ÊéÇ©ÃûµÄ¶ñÒâÇý¶¯·¨Ê½»î¶¯Ïà¹Ø£¬¸ÃÇý¶¯·¨Ê½±»ÓÃÀ´²¿Êð¶ñÒâºóÃÅ£¬Ä¿Ç°¸Ã©¶´ÒÑ·¢ÏÖ±»ÀûÓò¢ÒѹûÈ»Åû¶¡£

CVE-2024-29988£ºSmartScreen PromptÄþ¾²¹¦Ð§Èƹý©¶´

¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬ÍþвÕß¿ÉÒÔÏòÄ¿±êÓû§·¢ËÍÌØÖÆÎļþ£¬²¢ÓÕµ¼Óû§Ê¹ÓÃÇëÇó²»ÏÔʾUI µÄÆô¶¯Æ÷Ó¦Ó÷¨Ê½À´Æô¶¯¶ñÒâÎļþ£¬¿ÉÄÜÔÚÎļþ´ò¿ªÊ±ÈƹýMicrosoft Defender Smartscreen Ìáʾ£¬ÔÚÄ¿±êϵͳÉÏÖ´ÐжñÒâ´úÂ롣Ŀǰ΢Èí¹Ù·½²¢Î´½«¸Ã©¶´±ê־ΪÒѱ»ÀûÓ㬵«¸Ã©¶´¿ÉÄÜ´æÔÚÔÚÒ°ÀûÓá£

±¾´ÎÄþ¾²¸üÐÂÖÐÆÀ¼¶ÎªÑÏÖصÄ3¸ö©¶´°üÂÞ£º

CVE-2024-29053£ºMicrosoft Defender for IoT Ô¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft Defender for IoTÖдæÔÚ·¾¶±éÀú©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬ÓÐȨ·ÃÎÊÎļþÉÏ´«¹¦Ð§µÄ¾­¹ýÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔͨ¹ý½«¶ñÒâÎļþÉÏ´«µ½·þÎñÆ÷ÉϵÄÃô¸ÐλÖÃÀ´ÀûÓø÷¾¶±éÀú©¶´£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

CVE-2024-21323£ºMicrosoft Defender for IoT Ô¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft Defender for IoTÖдæÔÚ·¾¶±éÀú©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬¾­¹ýÉí·ÝÑéÖ¤²¢»ñµÃÆô¶¯¸üйý³ÌËùÐèµÄȨÏÞµÄÍþвÕß¿ÉÏòDefender for IoT ´«¸ÐÆ÷·¢ËÍ tar ÎļþÀ´ÀûÓø鶴¡£ÌáÈ¡¹ý³ÌÍê³Éºó£¬ÍþвÕ߾ͿÉÒÔ·¢ËÍδǩÃûµÄ¸üаü£¬²¢ÁýÕÖËûÃÇÑ¡ÔñµÄÈκÎÎļþ¡£

CVE-2024-21322£ºMicrosoft Defender for IoT Ô¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft Defender for IoTÖдæÔÚÃüÁî×¢È멶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.2£¬¾ßÓÐWeb Ó¦Ó÷¨Ê½µÄ¹ÜÀíȨÏÞµÄÍþвÕß¿ÉÀûÓø鶴µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

³ýCVE-2024-29988Í⣬΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ©¶´»¹°üÂÞ£º

l  CVE-2024-26209£ºMicrosoft µ±µØÄþ¾²»ú¹¹×Óϵͳ·þÎñÖдæÔÚÐÅϢ鶩¶´£¬ÀÖ³ÉÀûÓø鶴¿ÉÄܵ¼ÖÂй¶δ³õʼ»¯µÄÄÚ´æ¡£

l  CVE-2024-26218£ºWindows ÄÚºËÖдæÔÚÌáȨ©¶´£¬ÀÖ³ÉÀûÓø鶴¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£

l  CVE-2024-26211£ºWindows Ô¶³Ì·ÃÎÊÁ¬½Ó¹ÜÀíÆ÷ÖдæÔÚÌØȨÌáÉý©¶´£¬ÀÖ³ÉÀûÓø鶴¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£

l  CVE-2024-26230ºÍCVE-2024-26239£ºWindows Telephony Server ÖдæÔÚÌØȨÌáÉý©¶´£¬ÀÖ³ÉÀûÓø鶴¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£

l  CVE-2024-29056£ºWindows Éí·ÝÑéÖ¤ÖдæÔÚÌØȨÌáÉý©¶´£¬ÀÖ³ÉÀûÓø鶴µÄÍþвÕß¿ÉÒÔ¼ì²ìijЩÃô¸ÐÐÅÏ¢¡£

l  CVE-2024-26241£ºWin32kÖдæÔÚÌáȨ©¶´£¬ÀÖ³ÉÀûÓø鶴¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£

l  CVE-2024-28921ºÍCVE-2024-28903£ºÄþ¾²Æô¶¯ÖдæÔÚÄþ¾²¹¦Ð§Èƹý©¶´£¬ÀÖ³ÉÀûÓÃÕâЩ©¶´¿ÉÄܵ¼ÖÂÍþвÕßÈƹýÄþ¾²Æô¶¯¡£

l  CVE-2024-26158£ºMicrosoft Install ServiceÌØȨÌáÉý©¶´

l  CVE-2024-26212£ºDHCP Server Service¾Ü¾ø·þÎñ©¶´

l  CVE-2024-26256£ºlibarchive Ô¶³Ì´úÂëÖ´ÐЩ¶´

±¾´Î¸üÐÂÖÐÆäËûÖµµÃ¹Ø×¢µÄ©¶´»¹°üÂÞµ«²»ÏÞÓÚ£º

CVE-2024-26245£ºWindows SMB´æÔÚÌØȨÌáÉý©¶´£¬ÀÖ³ÉÀûÓø鶴¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£

CVE-2024-20670£ºOutlook for Windows´æÔÚÆÛƭ©¶´£¬ÍþвÕß¿ÉÏòÊܺ¦Õß·¢ËͶñÒâURL²¢ÓÕµ¼Êܺ¦ÕßÖ´ÐиÃURL£¬Èçͨ¹ý·¢ËÍÌØÖƵĵç×ÓÓʼþ£¬´Ó¶øµ¼ÖÂÊܺ¦ÕßÓëÍþвÕß¿ØÖƵIJ»ÊÜÐÅÈÎλÖý¨Á¢Á¬½Ó£¬´Ó¶ø½«Êܺ¦ÕßµÄ Net-NTLMv2 ¹þϣ鶵½²»ÊÜÐÅÈεÄÍøÂ磬ȻºóÍþвÕß¿ÉÒÔ½«ÆäÖм̵½ÁíÒ»¸ö·þÎñ²¢ÒÔÊܺ¦ÕßÉí·Ý½øÐÐÉí·ÝÑéÖ¤¡£

Microsoft SharePoint ÁãÈÕ©¶´£¨ÔÝÎÞCVE£©£ºÑо¿ÈËÔ±ÔÚSharePointÖз¢ÏÖÁËÁ½ÖÖÌÓ±ÜÉø͸¼ì²âµÄм¼Êõ£¬ÔÊÐíÓû§ÈƹýÉó¼ÆÈÕÖ¾£¬ÖÆÖ¹ÔÚÍâйÎļþʱ´¥·¢ÏÂÔØʼþ¡£

΢Èí4Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º

CVE ID

CVE ±êÌâ

ÑÏÖØÐÔ

CVE-2024-29053

Microsoft   Defender for IoT Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-21323

Microsoft   Defender for IoT Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-21322

Microsoft   Defender for IoT Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-21409

.NET¡¢.NET Framework ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29993

Azure   CycleCloud ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-29063

Azure AIËÑË÷ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-28917

Azure   Arc-enabled Kubernetes Extension Cluster-Scope ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-21424

Azure   Compute Gallery ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-26193

Azure   Migrate Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29989

Azure   Monitor Agent ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-2201

Ó¢Ìضû£ºCVE-2024-2201 ·ÖÖ§ÀúÊ·×¢Èë

¸ßΣ

CVE-2024-29988

SmartScreen   Prompt Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-29990

Microsoft   Azure Kubernetes Service Confidential ContainerÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-28905

Microsoft   Brokering File System ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-28907

Microsoft   Brokering File System ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-26213

Microsoft   Brokering File System ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-28904

Microsoft   Brokering File System ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-29055

Microsoft   Defender for IoT ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-29054

Microsoft   Defender for IoT ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-21324

Microsoft   Defender for IoT ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-26158

Microsoft   Install Service ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-26257

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-20670

Outlook   for Windows ÆÛƭ©¶´

¸ßΣ

CVE-2024-26251

Microsoft   SharePoint Server ÆÛƭ©¶´

¸ßΣ

CVE-2024-26214

Microsoft   WDAC SQL Server ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26244

Microsoft   WDAC OLE DB Provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26210

Microsoft   WDAC OLE DB Provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26233

Windows   DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26231

Windows   DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26227

Windows   DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26223

Windows   DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26221

Windows   DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26224

Windows   DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26222

Windows   DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29064

Windows   Hyper-V ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-28937

Microsoft   ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28938

Microsoft   ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29044

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28935

Microsoft   ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28940

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28943

Microsoft   ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28941

Microsoft   ODBC Driver for SQL Server  Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ

¸ßΣ

CVE-2024-28910

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28944

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28908

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28909

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29985

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28906

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28926

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28933

Microsoft   ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ

¸ßΣ

CVE-2024-28934

Microsoft   ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ

¸ßΣ

CVE-2024-28927

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28930

Microsoft   ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ

¸ßΣ

CVE-2024-29046

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28932

Microsoft   ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ

¸ßΣ

CVE-2024-29047

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28931

Microsoft   ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ

¸ßΣ

CVE-2024-29984

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28929

Microsoft   ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ

¸ßΣ

CVE-2024-28939

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28942

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29043

Microsoft   ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ

¸ßΣ

CVE-2024-28936

Microsoft   ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ

¸ßΣ

CVE-2024-29045

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28915

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28913

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28945

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29048

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28912

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28914

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29983

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-28911

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29982

Microsoft   OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29056

Windows   Authentication ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-21447

Windows   Authentication ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-20665

BitLocker Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-26256

libarchive   Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26228

Windows Cryptographic   Services Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-29050

Windows   Cryptographic Services Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26237

Windows   Defender Credential Guard ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-26212

DHCP   Server Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-26215

DHCP   Server Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-26195

DHCP   Server Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26202

DHCP   Server Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29066

Windows ÂþÑÜʽÎļþϵͳ (DFS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26226

Windows ÂþÑÜʽÎļþϵͳ (DFS) ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-26172

Windows   DWM Core Library ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-26216

Windows   File Server Resource Management Service ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-26219

HTTP.sys ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-26253

Windows   rndismp6.sys Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26252

Windows   rndismp6.sys Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26183

Windows   Kerberos ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-26248

Windows   Kerberos ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-20693

Windows   Kernel ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-26245

Windows   SMB ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-26229

Windows   CSC Service ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-26218

Windows   Kernel ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-26209

Microsoft   Local Security Authority Subsystem Service ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-26232

Microsoft   Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26208

Microsoft   Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26220

Windows   Mobile Hotspot ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-26234

Proxy   Driver ÆÛƭ©¶´

¸ßΣ

CVE-2024-28902

Windows   Remote Access Connection Manager ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-28900

Windows   Remote Access Connection Manager ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-28901

Windows   Remote Access Connection Manager ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-26255

Windows   Remote Access Connection Manager ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-26230

Windows   Telephony Server ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-26239

Windows   Telephony Server ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-26207

Windows   Remote Access Connection Manager ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-26217

Windows   Remote Access Connection Manager ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-26211

Windows   Remote Access Connection Manager ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-20678

Remote   Procedure Call Runtime Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26200

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26179

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26205

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29061

Secure Boot   Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-28921

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-20689

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-26250

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-28922

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-29062

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-20669

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-28898

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-20688

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-23593

Lenovo£ºCVE-2024-23593 Zero Out Boot Manager ²¢½µÖÁ   UEFI Shell

¸ßΣ

CVE-2024-28896

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-28919

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-23594

Lenovo£ºCVE-2024-23594 LenovoBT.efi ÖеĶÑÕ»»º³åÇøÒç³ö

¸ßΣ

CVE-2024-28923

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-28903

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-26189

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-26240

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-28924

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-28897

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-28925

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-26175

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-28920

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-26194

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-26180

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-26171

Secure Boot   Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-26168

Secure   Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-29052

Windows   Storage ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-26242

Windows   Telephony Server ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-26236

Windows   Update Stack ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-26235

Windows   Update Stack ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-26243

Windows   USB Print Driver ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-26254

Microsoft   Virtual Machine Bus(VMBus) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-26241

Win32k ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-20685

Azure   Private 5G Core ¾Ü¾ø·þÎñ©¶´

ÖÐΣ

CVE-2024-29992

Azure   Identity Library for .NET ÐÅϢ鶩¶´

ÖÐΣ

CVE-2024-29049

Microsoft   Edge£¨»ùÓÚ Chromium£©Webview2 ÆÛƭ©¶´

ÖÐΣ

CVE-2024-29981

Microsoft   Edge£¨»ùÓÚ Chromium£©ÆÛƭ©¶´

µÍΣ

CVE-2024-3156

Chromium£ºCVE-2024-3156 V8 ÖеÄʵʩ²»Í×

δ֪

CVE-2024-3159

Chromium£ºCVE-2024-3159 V8 ÖеÄÄÚ´æ·ÃÎÊÔ½½ç

δ֪

CVE-2024-3158

Chromium£ºCVE-2024-3158 ÔÚÊéÇ©ÖÐ Use-after-free

δ֪

CVE-2019-3816

δ֪

δ֪

CVE-2019-3833

δ֪

δ֪

 

 

¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

Windows BitLocker

Windows Secure Boot

Microsoft Office Outlook

Windows Remote Procedure Call

Azure Private 5G Core

Windows Kernel

Microsoft Defender for IoT

.NET and Visual Studio

Azure Compute Gallery

Windows Authentication Methods

Microsoft Install Service

Windows DWM Core Library

Windows Routing and Remote Access Service (RRAS)

Windows Kerberos

Azure Migrate

Windows DHCP Server

Windows Remote Access Connection Manager

Windows Message Queuing

Windows Local Security Authority Subsystem Service (LSASS)

Microsoft WDAC OLE DB provider for SQL

Microsoft Brokering File System

Microsoft WDAC ODBC Driver

Windows File Server Resource Management Service

Windows HTTP.sys

Windows Mobile Hotspot

Role: DNS Server

Windows Distributed File System (DFS)

Windows Cryptographic Services

Windows Proxy Driver

Windows Update Stack

Windows Defender Credential Guard

Windows Win32K - ICOMP

Windows Telephony Server

Windows USB Print Driver

Microsoft Office SharePoint

Windows Internet Connection Sharing (ICS)

Windows Virtual Machine Bus

Windows Compressed Folder

Microsoft Office Excel

SQL Server

Azure Arc

Microsoft Edge (Chromium-based)

Windows Storage

Azure AI Search

Role: Windows Hyper-V

Internet Shortcut Files

Azure Monitor

Microsoft Azure Kubernetes Service

Azure SDK

Azure

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔز¢°²×°¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2024Äê4ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Apr

²¹¶¡ÏÂÔØʾÀý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí©¶´ÁÐ±í£¨Ê¾Àý£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý

3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£

image.png

Àý3£º²¹¶¡ÏÂÔؽçÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£

3.2 ÁÙʱ´ëÊ©

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼Æı£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏ޶ȡ£

l  ÆôÓÃÇ¿ÃÜÂë¼Æı²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Apr

https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2024-patch-tuesday-fixes-150-security-flaws-67-rces/

https://news.sophos.com/en-us/2024/04/09/smoke-and-screen-mirrors-a-strange-signed-backdoor/

https://www.varonis.com/blog/sidestepping-detection-while-exfiltrating-sharepoint-data

 


ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-04-10

Ê×´ÎÐû²¼

 

 

 

Îå¡¢¸½Â¼

5.1 ¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png