¡¾Â©¶´Í¨¸æ¡¿Î¢Èí4Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2024-04-10Ò»¡¢Â©¶´¸ÅÊö
2024Äê4ÔÂ9ÈÕ£¬Î¢ÈíÐû²¼ÁË4ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË150¸ö©¶´£¨²»°üÂÞ֮ǰÐÞ¸´µÄMicrosoft Edge ºÍMariner©¶´£©£¬Â©¶´ÀàÐÍ°üÂÞÌØȨÌáÉý©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢ鶩¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛÆ©¶´µÈ¡£
±¾´ÎÄþ¾²¸üÐÂÖаüÂÞ2¸ö±»»ý¼«ÀûÓõÄ0 day©¶´£º
CVE-2024-26234£ºProxy DriverÆÛÆ©¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ6.7£¬ÓëSophos X-Ops ·¢ÏÖµÄÓÐЧMicrosoftÓ²¼þ¿¯ÐÐÉÌÖ¤ÊéÇ©ÃûµÄ¶ñÒâÇý¶¯·¨Ê½»î¶¯Ïà¹Ø£¬¸ÃÇý¶¯·¨Ê½±»ÓÃÀ´²¿Êð¶ñÒâºóÃÅ£¬Ä¿Ç°¸Ã©¶´ÒÑ·¢ÏÖ±»ÀûÓò¢ÒѹûÈ»Åû¶¡£
CVE-2024-29988£ºSmartScreen PromptÄþ¾²¹¦Ð§Èƹý©¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬ÍþвÕß¿ÉÒÔÏòÄ¿±êÓû§·¢ËÍÌØÖÆÎļþ£¬²¢ÓÕµ¼Óû§Ê¹ÓÃÇëÇó²»ÏÔʾUI µÄÆô¶¯Æ÷Ó¦Ó÷¨Ê½À´Æô¶¯¶ñÒâÎļþ£¬¿ÉÄÜÔÚÎļþ´ò¿ªÊ±ÈƹýMicrosoft Defender Smartscreen Ìáʾ£¬ÔÚÄ¿±êϵͳÉÏÖ´ÐжñÒâ´úÂ롣Ŀǰ΢Èí¹Ù·½²¢Î´½«¸Ã©¶´±ê־ΪÒѱ»ÀûÓ㬵«¸Ã©¶´¿ÉÄÜ´æÔÚÔÚÒ°ÀûÓá£
±¾´ÎÄþ¾²¸üÐÂÖÐÆÀ¼¶ÎªÑÏÖصÄ3¸ö©¶´°üÂÞ£º
CVE-2024-29053£ºMicrosoft Defender for IoT Ô¶³Ì´úÂëÖ´ÐЩ¶´
Microsoft Defender for IoTÖдæÔÚ·¾¶±éÀú©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬ÓÐȨ·ÃÎÊÎļþÉÏ´«¹¦Ð§µÄ¾¹ýÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔͨ¹ý½«¶ñÒâÎļþÉÏ´«µ½·þÎñÆ÷ÉϵÄÃô¸ÐλÖÃÀ´ÀûÓø÷¾¶±éÀú©¶´£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
CVE-2024-21323£ºMicrosoft Defender for IoT Ô¶³Ì´úÂëÖ´ÐЩ¶´
Microsoft Defender for IoTÖдæÔÚ·¾¶±éÀú©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬¾¹ýÉí·ÝÑéÖ¤²¢»ñµÃÆô¶¯¸üйý³ÌËùÐèµÄȨÏÞµÄÍþвÕß¿ÉÏòDefender for IoT ´«¸ÐÆ÷·¢ËÍ tar ÎļþÀ´ÀûÓø鶴¡£ÌáÈ¡¹ý³ÌÍê³Éºó£¬ÍþвÕ߾ͿÉÒÔ·¢ËÍδǩÃûµÄ¸üаü£¬²¢ÁýÕÖËûÃÇÑ¡ÔñµÄÈκÎÎļþ¡£
CVE-2024-21322£ºMicrosoft Defender for IoT Ô¶³Ì´úÂëÖ´ÐЩ¶´
Microsoft Defender for IoTÖдæÔÚÃüÁî×¢È멶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.2£¬¾ßÓÐWeb Ó¦Ó÷¨Ê½µÄ¹ÜÀíȨÏÞµÄÍþвÕß¿ÉÀûÓø鶴µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
³ýCVE-2024-29988Í⣬΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ©¶´»¹°üÂÞ£º
l CVE-2024-26209£ºMicrosoft µ±µØÄþ¾²»ú¹¹×Óϵͳ·þÎñÖдæÔÚÐÅϢ鶩¶´£¬ÀÖ³ÉÀûÓø鶴¿ÉÄܵ¼ÖÂй¶δ³õʼ»¯µÄÄÚ´æ¡£
l CVE-2024-26218£ºWindows ÄÚºËÖдæÔÚÌáȨ©¶´£¬ÀÖ³ÉÀûÓø鶴¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£
l CVE-2024-26211£ºWindows Ô¶³Ì·ÃÎÊÁ¬½Ó¹ÜÀíÆ÷ÖдæÔÚÌØȨÌáÉý©¶´£¬ÀÖ³ÉÀûÓø鶴¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£
l CVE-2024-26230ºÍCVE-2024-26239£ºWindows Telephony Server ÖдæÔÚÌØȨÌáÉý©¶´£¬ÀÖ³ÉÀûÓø鶴¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£
l CVE-2024-29056£ºWindows Éí·ÝÑéÖ¤ÖдæÔÚÌØȨÌáÉý©¶´£¬ÀÖ³ÉÀûÓø鶴µÄÍþвÕß¿ÉÒÔ¼ì²ìijЩÃô¸ÐÐÅÏ¢¡£
l CVE-2024-26241£ºWin32kÖдæÔÚÌáȨ©¶´£¬ÀÖ³ÉÀûÓø鶴¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£
l CVE-2024-28921ºÍCVE-2024-28903£ºÄþ¾²Æô¶¯ÖдæÔÚÄþ¾²¹¦Ð§Èƹý©¶´£¬ÀÖ³ÉÀûÓÃÕâЩ©¶´¿ÉÄܵ¼ÖÂÍþвÕßÈƹýÄþ¾²Æô¶¯¡£
l CVE-2024-26158£ºMicrosoft Install ServiceÌØȨÌáÉý©¶´
l CVE-2024-26212£ºDHCP Server Service¾Ü¾ø·þÎñ©¶´
l CVE-2024-26256£ºlibarchive Ô¶³Ì´úÂëÖ´ÐЩ¶´
±¾´Î¸üÐÂÖÐÆäËûÖµµÃ¹Ø×¢µÄ©¶´»¹°üÂÞµ«²»ÏÞÓÚ£º
CVE-2024-26245£ºWindows SMB´æÔÚÌØȨÌáÉý©¶´£¬ÀÖ³ÉÀûÓø鶴¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£
CVE-2024-20670£ºOutlook for Windows´æÔÚÆÛÆ©¶´£¬ÍþвÕß¿ÉÏòÊܺ¦Õß·¢ËͶñÒâURL²¢ÓÕµ¼Êܺ¦ÕßÖ´ÐиÃURL£¬Èçͨ¹ý·¢ËÍÌØÖƵĵç×ÓÓʼþ£¬´Ó¶øµ¼ÖÂÊܺ¦ÕßÓëÍþвÕß¿ØÖƵIJ»ÊÜÐÅÈÎλÖý¨Á¢Á¬½Ó£¬´Ó¶ø½«Êܺ¦ÕßµÄ Net-NTLMv2 ¹þϣ鶵½²»ÊÜÐÅÈεÄÍøÂ磬ȻºóÍþвÕß¿ÉÒÔ½«ÆäÖм̵½ÁíÒ»¸ö·þÎñ²¢ÒÔÊܺ¦ÕßÉí·Ý½øÐÐÉí·ÝÑéÖ¤¡£
Microsoft SharePoint ÁãÈÕ©¶´£¨ÔÝÎÞCVE£©£ºÑо¿ÈËÔ±ÔÚSharePointÖз¢ÏÖÁËÁ½ÖÖÌÓ±ÜÉø͸¼ì²âµÄм¼Êõ£¬ÔÊÐíÓû§ÈƹýÉó¼ÆÈÕÖ¾£¬ÖÆÖ¹ÔÚÍâйÎļþʱ´¥·¢ÏÂÔØʼþ¡£
΢Èí4Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑÏÖØÐÔ |
CVE-2024-29053 | Microsoft Defender for IoT Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2024-21323 | Microsoft Defender for IoT Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2024-21322 | Microsoft Defender for IoT Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2024-21409 | .NET¡¢.NET Framework ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-29993 | Azure CycleCloud ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-29063 | Azure AIËÑË÷ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-28917 | Azure Arc-enabled Kubernetes Extension Cluster-Scope ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21424 | Azure Compute Gallery ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26193 | Azure Migrate Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-29989 | Azure Monitor Agent ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-2201 | Ó¢Ìضû£ºCVE-2024-2201 ·ÖÖ§ÀúÊ·×¢Èë | ¸ßΣ |
CVE-2024-29988 | SmartScreen Prompt Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-29990 | Microsoft Azure Kubernetes Service Confidential ContainerÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-28905 | Microsoft Brokering File System ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-28907 | Microsoft Brokering File System ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26213 | Microsoft Brokering File System ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-28904 | Microsoft Brokering File System ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-29055 | Microsoft Defender for IoT ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-29054 | Microsoft Defender for IoT ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21324 | Microsoft Defender for IoT ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26158 | Microsoft Install Service ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26257 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-20670 | Outlook for Windows ÆÛÆ©¶´ | ¸ßΣ |
CVE-2024-26251 | Microsoft SharePoint Server ÆÛÆ©¶´ | ¸ßΣ |
CVE-2024-26214 | Microsoft WDAC SQL Server ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26244 | Microsoft WDAC OLE DB Provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26210 | Microsoft WDAC OLE DB Provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26233 | Windows DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26231 | Windows DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26227 | Windows DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26223 | Windows DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26221 | Windows DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26224 | Windows DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26222 | Windows DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-29064 | Windows Hyper-V ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-28937 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28938 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-29044 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28935 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28940 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28943 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28941 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ | ¸ßΣ |
CVE-2024-28910 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28944 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28908 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28909 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-29985 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28906 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28926 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28933 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ | ¸ßΣ |
CVE-2024-28934 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ | ¸ßΣ |
CVE-2024-28927 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28930 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ | ¸ßΣ |
CVE-2024-29046 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28932 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ | ¸ßΣ |
CVE-2024-29047 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28931 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ | ¸ßΣ |
CVE-2024-29984 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28929 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ | ¸ßΣ |
CVE-2024-28939 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28942 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-29043 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ | ¸ßΣ |
CVE-2024-28936 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´µÄ | ¸ßΣ |
CVE-2024-29045 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28915 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28913 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28945 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-29048 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28912 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28914 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-29983 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-28911 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-29982 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-29056 | Windows Authentication ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21447 | Windows Authentication ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-20665 | BitLocker Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-26256 | libarchive Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26228 | Windows Cryptographic Services Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-29050 | Windows Cryptographic Services Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26237 | Windows Defender Credential Guard ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26212 | DHCP Server Service ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-26215 | DHCP Server Service ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-26195 | DHCP Server Service Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26202 | DHCP Server Service Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-29066 | Windows ÂþÑÜʽÎļþϵͳ (DFS) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26226 | Windows ÂþÑÜʽÎļþϵͳ (DFS) ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-26172 | Windows DWM Core Library ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-26216 | Windows File Server Resource Management Service ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26219 | HTTP.sys ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-26253 | Windows rndismp6.sys Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26252 | Windows rndismp6.sys Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26183 | Windows Kerberos ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-26248 | Windows Kerberos ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-20693 | Windows Kernel ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26245 | Windows SMB ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26229 | Windows CSC Service ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26218 | Windows Kernel ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26209 | Microsoft Local Security Authority Subsystem Service ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-26232 | Microsoft Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26208 | Microsoft Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26220 | Windows Mobile Hotspot ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-26234 | Proxy Driver ÆÛÆ©¶´ | ¸ßΣ |
CVE-2024-28902 | Windows Remote Access Connection Manager ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-28900 | Windows Remote Access Connection Manager ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-28901 | Windows Remote Access Connection Manager ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-26255 | Windows Remote Access Connection Manager ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-26230 | Windows Telephony Server ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26239 | Windows Telephony Server ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26207 | Windows Remote Access Connection Manager ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-26217 | Windows Remote Access Connection Manager ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-26211 | Windows Remote Access Connection Manager ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-20678 | Remote Procedure Call Runtime Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26200 | Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26179 | Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26205 | Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-29061 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-28921 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-20689 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-26250 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-28922 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-29062 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-20669 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-28898 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-20688 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-23593 | Lenovo£ºCVE-2024-23593 Zero Out Boot Manager ²¢½µÖÁ UEFI Shell | ¸ßΣ |
CVE-2024-28896 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-28919 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-23594 | Lenovo£ºCVE-2024-23594 LenovoBT.efi ÖеĶÑÕ»»º³åÇøÒç³ö | ¸ßΣ |
CVE-2024-28923 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-28903 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-26189 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-26240 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-28924 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-28897 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-28925 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-26175 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-28920 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-26194 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-26180 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-26171 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-26168 | Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-29052 | Windows Storage ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26242 | Windows Telephony Server ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26236 | Windows Update Stack ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26235 | Windows Update Stack ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26243 | Windows USB Print Driver ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26254 | Microsoft Virtual Machine Bus(VMBus) ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-26241 | Win32k ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-20685 | Azure Private 5G Core ¾Ü¾ø·þÎñ©¶´ | ÖÐΣ |
CVE-2024-29992 | Azure Identity Library for .NET ÐÅϢ鶩¶´ | ÖÐΣ |
CVE-2024-29049 | Microsoft Edge£¨»ùÓÚ Chromium£©Webview2 ÆÛÆ©¶´ | ÖÐΣ |
CVE-2024-29981 | Microsoft Edge£¨»ùÓÚ Chromium£©ÆÛÆ©¶´ | µÍΣ |
CVE-2024-3156 | Chromium£ºCVE-2024-3156 V8 ÖеÄʵʩ²»Í× | δ֪ |
CVE-2024-3159 | Chromium£ºCVE-2024-3159 V8 ÖеÄÄÚ´æ·ÃÎÊÔ½½ç | δ֪ |
CVE-2024-3158 | Chromium£ºCVE-2024-3158 ÔÚÊéÇ©ÖÐ Use-after-free | δ֪ |
CVE-2019-3816 | δ֪ | δ֪ |
CVE-2019-3833 | δ֪ | δ֪ |
¶þ¡¢Ó°Ï췶Χ
ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º
Windows BitLocker
Windows Secure Boot
Microsoft Office Outlook
Windows Remote Procedure Call
Azure Private 5G Core
Windows Kernel
Microsoft Defender for IoT
.NET and Visual Studio
Azure Compute Gallery
Windows Authentication Methods
Microsoft Install Service
Windows DWM Core Library
Windows Routing and Remote Access Service (RRAS)
Windows Kerberos
Azure Migrate
Windows DHCP Server
Windows Remote Access Connection Manager
Windows Message Queuing
Windows Local Security Authority Subsystem Service (LSASS)
Microsoft WDAC OLE DB provider for SQL
Microsoft Brokering File System
Microsoft WDAC ODBC Driver
Windows File Server Resource Management Service
Windows HTTP.sys
Windows Mobile Hotspot
Role: DNS Server
Windows Distributed File System (DFS)
Windows Cryptographic Services
Windows Proxy Driver
Windows Update Stack
Windows Defender Credential Guard
Windows Win32K - ICOMP
Windows Telephony Server
Windows USB Print Driver
Microsoft Office SharePoint
Windows Internet Connection Sharing (ICS)
Windows Virtual Machine Bus
Windows Compressed Folder
Microsoft Office Excel
SQL Server
Azure Arc
Microsoft Edge (Chromium-based)
Windows Storage
Azure AI Search
Role: Windows Hyper-V
Internet Shortcut Files
Azure Monitor
Microsoft Azure Kubernetes Service
Azure SDK
Azure
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔز¢°²×°¡£
£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2024Äê4ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2024-Apr
²¹¶¡ÏÂÔØʾÀý£¨²Î¿¼£©£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢Èí©¶´ÁÐ±í£¨Ê¾Àý£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý
3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£
Àý3£º²¹¶¡ÏÂÔؽçÃæ
4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£
3.2 ÁÙʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼Æı£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏ޶ȡ£
l ÆôÓÃÇ¿ÃÜÂë¼Æı²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Apr
https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2024-patch-tuesday-fixes-150-security-flaws-67-rces/
https://news.sophos.com/en-us/2024/04/09/smoke-and-screen-mirrors-a-strange-signed-backdoor/
https://www.varonis.com/blog/sidestepping-detection-while-exfiltrating-sharepoint-data
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-04-10 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¶«Éƽ̨¼ò½é
¶«Éƽ̨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«Éƽ̨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶«Éƽ̨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦¡£
5.2 ¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º