¡¾Â©¶´Í¨¸æ¡¿Î¢Èí7Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2024-07-10

 

Ò»¡¢Â©¶´¸ÅÊö

2024Äê7ÔÂ10ÈÕ£¬¶«É­Æ½Ì¨¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË7ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË142¸ö©¶´£¬Â©¶´ÀàÐÍ°üÂÞÌØȨÌáÉý©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢ鶩¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛƭ©¶´µÈ¡£

±¾´ÎÄþ¾²¸üÐÂÐÞ¸´ÁË4¸ö0 day©¶´£¬ÆäÖÐÁ½¸ö±»»ý¼«ÀûÓã¬ÁíÍâÁ½¸öÒѾ­¹ûÈ»Åû¶£º

CVE-2024-38080 £ºWindows Hyper-VÌØȨÌáÉý©¶´

Windows Hyper-V ÖдæÔÚÕûÊýÒç³ö»ò»·ÈÆ©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8£¬ÍþвÕß¿ÉÀûÓø鶴½«µ±µØȨÏÞÌáÉýΪSYSTEM ȨÏÞ£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-38112 £ºWindows MSHTML PlatformÆÛƭ©¶´

Windows MSHTML Platform´æÔÚÆÛƭ©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.5£¬ÀûÓÃÄѶȽϸߣ¬ÍþвÕß¿ÉÏòÊܺ¦Õß·¢ËͶñÒâÎļþ£¬²¢ÓÕµ¼Êܺ¦ÕßÖ´ÐиÃÎļþÀ´ÀûÓø鶴£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-35264 £º.NET ºÍ Visual StudioÔ¶³Ì´úÂëÖ´ÐЩ¶´

.NET ºÍ Visual StudioÖдæÔÚUse-After-Free©¶´£¬ÍþвÕß¿ÉÒÔͨ¹ýÔÚ´¦ÖÃÇëÇóÖ÷Ìåʱ¹Ø±Õ http/3 Á÷À´ÀûÓø鶴£¬´Ó¶øµ¼Ö¾ºÕùÌõ¼þ£¬ÀÖ³ÉÀûÓø鶴¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬µ«ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£

CVE-2024-37985 £ºArm -רÓÐԤȡÆ÷µÄϵͳʶ±ðºÍÌØÐÔ

΢ÈíÐÞ¸´ÁË֮ǰÅû¶µÄ¿ÉÓÃÓÚÇÔÈ¡ÃØÃÜÐÅÏ¢µÄFetchBench²àÐŵÀ¹¥»÷£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ5.9£¬ÀÖ³ÉÀûÓø鶴µÄÍþвÕß¿ÉÒÔ´Ó·þÎñÆ÷ÉÏÔËÐеÄÌØȨ½ø³Ì¼ì²ì¶ÑÄڴ棬µ¼ÖÂÐÅϢй¶¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£

±¾´ÎÄþ¾²¸üÐÂÖÐÐÞ¸´µÄ5¸öÑÏÖØ©¶´Îª£º

CVE-2024-38023£ºMicrosoft SharePoint ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft SharePoint ServerÖдæÔÚ·´ÐòÁл¯Â©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.2£¬¾ßÓÐÕ¾µãËùÓÐÕßȨÏ޵ľ­¹ýÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔ½«ÌØÖÆÎļþÉÏ´«µ½Ä¿±ê SharePoint Server£¬²¢Í¨¹ýÌØÖÆAPI ÇëÇóÒÔ´¥·¢Îļþ²ÎÊýµÄ·´ÐòÁл¯£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔÚ SharePoint Server ÉÏÏÂÎÄÖÐÔ¶³ÌÖ´ÐдúÂ롣΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£

CVE-2024-38060£ºWindows Imaging ComponentÔ¶³Ì´úÂëÖ´ÐЩ¶´

Windows ͼÏñ´¦ÖÃ×é¼þÖдæÔڶѻº³åÇøÒç³ö©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬¾­¹ýÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔͨ¹ý½«¶ñÒâTIFFÎļþÉÏ´«µ½·þÎñÆ÷À´ÀûÓø鶴£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£

CVE-2024-38076£ºWindows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐЩ¶´

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖдæÔڶѻº³åÇøÒç³ö©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬ÍþвÕß¿ÉÒÔÏòÉèÖÃΪԶ³Ì×ÀÃæÊÚȨ·þÎñÆ÷µÄ·þÎñÆ÷·¢ËÍÌØÖÆÊý¾Ý°ü£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Èç¹û²»ÐèÒª£¬¿É½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ×÷Ϊ»º½â´ëÊ©£¬Microsoft½¨ÒéÊÜÓ°ÏìÓû§°²×°¸Ã©¶´µÄÄþ¾²¸üУ¬¼´Ê¹¼Æ»®½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ¡£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£

CVE-2024-38074£ºWindows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐЩ¶´

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖдæÔÚÕûÊýÏÂÒ究´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬ÍþвÕß¿ÉÒÔÏòÉèÖÃΪԶ³Ì×ÀÃæÊÚȨ·þÎñÆ÷µÄ·þÎñÆ÷·¢ËÍÌØÖÆÊý¾Ý°ü£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Èç¹û²»ÐèÒª£¬¿É½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ×÷Ϊ»º½â´ëÊ©£¬Microsoft½¨ÒéÊÜÓ°ÏìÓû§°²×°¸Ã©¶´µÄÄþ¾²¸üУ¬¼´Ê¹¼Æ»®½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ¡£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£

CVE-2024-38077£ºWindows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐЩ¶´

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖдæÔڶѻº³åÇøÒç³ö©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔÁ¬½Óµ½Ô¶³Ì×ÀÃæÊÚȨ·þÎñ²¢·¢ËͶñÒâÏûÏ¢£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Èç¹û²»ÐèÒª£¬¿É½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ×÷Ϊ»º½â´ëÊ©£¬Microsoft½¨ÒéÊÜÓ°ÏìÓû§°²×°¸Ã©¶´µÄÄþ¾²¸üУ¬¼´Ê¹¼Æ»®½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ¡£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£

³ýCVE-2024-38023ºÍCVE-2024-38060Í⣬΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ©¶´»¹°üÂÞ£º

CVE-2024-38021£ºMicrosoft Office Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÍþвÕß¿ÉÒÔÖÆ×÷Ò»¸öÈƹýÊܱ £»¤ÊÓͼЭÒéµÄ¶ñÒâÁ´½ÓÀ´ÀûÓø鶴£¬´Ó¶øÔÚÓû§½»»¥µÄÇé¿öϵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

CVE-2024-38024/ CVE-2024-38094£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft SharePoint ServerÖдæÔÚ¶à¸ö·´ÐòÁл¯Â©¶´£¬¾ßÓÐÕ¾µãËùÓÐÕßȨÏ޵ľ­¹ýÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔÀûÓø鶴עÈëÈÎÒâ´úÂë²¢ÔÚ SharePoint Server ÉÏÏÂÎÄÖÐÖ´ÐС£

CVE-2024-38052£ºKernel Streaming WOW Thunk Service DriverÌØȨÌáÉý©¶´

Kernel Streaming WOW Thunk Service DriverÖдæÔÚÊäÈëÑéÖ¤²»Íש¶´£¬ÀÖ³ÉÀûÓø鶴¿É»ñµÃSYSTEM ȨÏÞ¡£

CVE-2024-38054£ºKernel Streaming WOW Thunk Service DriverÌØȨÌáÉý©¶´

Kernel Streaming WOW Thunk Service DriverÖдæÔڶѻº³åÇøÒç³ö©¶´£¬ÀÖ³ÉÀûÓø鶴¿É»ñµÃSYSTEM ȨÏÞ¡£

CVE-2024-38059£ºWin32k ÌØȨÌáÉý©¶´

Win32kÖдæÔÚUse-After-Free©¶´£¬ÀÖ³ÉÀûÓø鶴¿É»ñµÃSYSTEM ȨÏÞ¡£

CVE-2024-38066£ºWindows Win32k ÌØȨÌáÉý©¶´

Windows Win32kÖдæÔÚUse-After-Free©¶´£¬ÀÖ³ÉÀûÓø鶴¿É»ñµÃSYSTEM ȨÏÞ¡£

CVE-2024-38079£ºWindows Graphics ComponentÌØȨÌáÉý©¶´

Windows ͼÐÎ×é¼þÖдæÔڶѻº³åÇøÒç³ö©¶´£¬µ±µØÍþвÕß¿ÉÒÔÔËÐпÉÀûÓø鶴µÄÌØÖÆÓ¦Ó÷¨Ê½£¬ÀÖ³ÉÀûÓÿÉÒÔ»ñµÃSYSTEM ȨÏÞ¡£

CVE-2024-38085£ºWindows Graphics ComponentÌØȨÌáÉý©¶´

Windows ͼÐÎ×é¼þÖдæÔÚUse-After-Free©¶´£¬ÀÖ³ÉÀûÓø鶴¿É»ñµÃSYSTEM ȨÏÞ¡£

CVE-2024-38099£ºWindows Remote Desktop Licensing Service¾Ü¾ø·þÎñ©¶´

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖдæÔÚÉí·ÝÑéÖ¤²»Íש¶´£¬ÀÖ³ÉÀûÓø鶴ÐèÒªÍþвÕßÓµÓи߼¶ÄæÏò¹¤³Ì¼¼ÄÜÀ´Ê¶±ð²¢»ñµÃ¶ÔÌض¨Ô¶³Ì¹ý³Ìµ÷Óà (RPC) ¶ËµãµÄδ¾­ÊÚȨµÄ·ÃÎÊ£¬ÀÖ³ÉÀûÓÿÉÄܵ¼Ö¾ܾø·þÎñ¡£

CVE-2024-38100£ºWindows File ExplorerÌØȨÌáÉý©¶´

Windows Îļþ×ÊÔ´¹ÜÀíÆ÷´æÔÚ·ÃÎÊ¿ØÖƲ»Íש¶´£¬ÀÖ³ÉÀûÓôË©¶´µÄÍþвÕß¿ÉÒÔ»ñµÃ¹ÜÀíԱȨÏÞ¡£

΢Èí7Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º

CVE ID

CVE ±êÌâ

ÑÏÖØÐÔ

CVE-2024-38023

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38060

Windows Imaging Component Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38076

Windows Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38074

Windows Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38077

Windows Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-30105

.NET Core ºÍ Visual Studio ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38081

.NET¡¢.NET Framework ºÍ Visual Studio ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-35264

.NET ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38095

.NET ºÍ Visual Studio ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38092

Azure CycleCloud ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-35266

Azure DevOps Server ÆÛƭ©¶´

¸ßΣ

CVE-2024-35267

Azure DevOps Server ÆÛƭ©¶´

¸ßΣ

CVE-2024-38086

Azure Kinect SDK Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-35261

Azure Network Watcher VM Extension ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-37985

Arm£ºCVE-2024-37985 רÓÐԤȡÆ÷µÄϵͳʶ±ðºÍÌØÐÔ

¸ßΣ

CVE-2024-38027

Windows Line Printer Daemon Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38089

Microsoft Defender for IoT ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-30061

Microsoft Dynamics 365 (On-Premises) ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38079

Windows Graphics Component ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38051

Windows Graphics Component Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38021

Microsoft Office Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38024

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-32987

Microsoft SharePoint Server ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38094

Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38057

Kernel Streaming WOW Thunk Service Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38054

Kernel Streaming WOW Thunk Service Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38052

Kernel Streaming WOW Thunk Service Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38055

Microsoft Windows Codecs Library ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38056

Microsoft Windows Codecs Library ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38091

Microsoft WS-Discovery ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38048

Windows Network Driver Interface Specification   (NDIS) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-3596

CERT/CC£ºCVE-2024-3596 RADIUS ЭÒéÆÛƭ©¶´

¸ßΣ

CVE-2024-38061

DCOM Remote Cross-Session Activation ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38080

Windows Hyper-V ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-28928

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38088

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-20701

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21317

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21331

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21308

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21333

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-35256

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21303

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21335

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-35271

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-35272

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21332

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38087

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21425

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21449

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37324

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37330

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37326

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37329

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37328

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37327

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37334

Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37321

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37320

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37319

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37322

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37333

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37336

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37323

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37331

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21398

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21373

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37318

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21428

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21415

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37332

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21414

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38058

BitLocker Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38100

Windows File Explorer ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-21417

Windows Text Services Framework ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-30098

Windows Cryptographic Services Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38044

DHCP Server Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38049

Windows Distributed Transaction Coordinator Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38069

Windows Enroll Engine Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38104

Windows Fax Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38034

Windows Filtering Platform ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38022

Windows Image Acquisition ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38105

Windows Layer-2 Bridge Network Driver ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38053

Windows Layer-2 Bridge Network Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38102

Windows Layer-2 Bridge Network Driver ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38101

Windows Layer-2 Bridge Network Driver ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-35270

Windows iSCSI Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38041

Windows Kernel ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38062

Windows Kernel-Mode Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38070

Windows LockDown Policy (WLDP) Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38017

Microsoft Message Queuing ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38112

Windows MSHTML Platform ÆÛƭ©¶´

¸ßΣ

CVE-2024-30013

Windows MultiPoint Services Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30081

Windows NTLM ÆÛƭ©¶´

¸ßΣ

CVE-2024-38068

Windows Online Certificate Status Protocol (OCSP)   Server ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38067

Windows Online Certificate Status Protocol (OCSP)   Server ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38031

Windows Online Certificate Status Protocol (OCSP)   Server ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38028

Microsoft Windows Performance Data Helper Library   Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38019

Microsoft Windows Performance Data Helper Library   Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38025

Microsoft Windows Performance Data Helper Library   Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38043

PowerShell ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38047

PowerShell ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38033

PowerShell ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-30071

Windows Remote Access Connection Manager ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-30079

Windows Remote Access Connection Manager ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38015

Windows Remote Desktop Gateway (RD Gateway) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38071

Windows Remote Desktop Licensing Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38073

Windows Remote Desktop Licensing Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38072

Windows Remote Desktop Licensing Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38099

Windows Remote Desktop Licensing Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38065

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37986

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37981

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37987

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-28899

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-26184

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38011

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37984

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37988

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37977

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37978

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37974

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38010

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37989

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37970

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37975

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37972

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37973

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37971

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37969

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38013

Microsoft Windows Server Backup ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38064

Windows TCP/IP ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38030

Windows Themes ÆÛƭ©¶´

¸ßΣ

CVE-2024-38085

Windows Graphics Component ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38066

Windows Win32k ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38059

Win32k ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38050

Windows Workstation Service ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38032

Microsoft Xbox Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38078

Xbox Wireless Adapter Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-39684

Github£ºCVE-2024-39684 TenCent   RapidJSON ÌØȨÌáÉý©¶´

ÖÐΣ

CVE-2024-38517

Github£ºCVE-2024-38517 TenCent   RapidJSON ÌØȨÌáÉý©¶´

ÖÐΣ

CVE-2024-38020

Microsoft Outlook ÆÛƭ©¶´

ÖÐΣ

 


¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

SQL Server

Windows CoreMessaging

Windows Secure Boot

Windows MultiPoint Services

Microsoft Dynamics

Windows Remote Access Connection Manager

Windows NTLM

Windows Cryptographic Services

.NET and Visual Studio

Microsoft Office SharePoint

Azure Network Watcher

Azure DevOps

Windows iSCSI

Windows Server Backup

Windows Remote Desktop

Windows Message Queuing

Windows Performance Monitor

Microsoft Office Outlook

Microsoft Office

Windows Image Acquisition

Line Printer Daemon Service (LPD)

Windows Themes

Windows Online Certificate Status Protocol (OCSP)

XBox Crypto Graphic Services

Windows PowerShell

Windows Filtering

Windows Kernel

Windows DHCP Server

NDIS

Windows Distributed Transaction Coordinator

Windows Workstation Service

Microsoft Graphics Component

Microsoft Streaming Service

Windows Internet Connection Sharing (ICS)

Microsoft Windows Codecs Library

Windows BitLocker

Windows Win32K - ICOMP

Role: Active Directory Certificate Services; Active Directory Domain Services

Windows Kernel-Mode Drivers

Windows TCP/IP

Windows Win32K - GRFX

Windows Enroll Engine

Windows LockDown Policy (WLDP)

Windows Remote Desktop Licensing Service

Active Directory Federation Services

Role: Windows Hyper-V

Windows Win32 Kernel Subsystem

Azure Kinect SDK

Microsoft Defender for IoT

Microsoft WS-Discovery

Azure CycleCloud

Windows COM Session

Windows Fax and Scan Service

Windows MSHTML Platform

 


Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔز¢°²×°¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2024Äê7ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Jul

²¹¶¡ÏÂÔØʾÀý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí©¶´ÁÐ±í£¨Ê¾Àý£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý

3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£

image.png

Àý3£º²¹¶¡ÏÂÔؽçÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£

3.2 ÁÙʱ´ëÊ©

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼Æı£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏ޶ȡ£

l  ÆôÓÃÇ¿ÃÜÂë¼Æı²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Jul

https://blog.qualys.com/vulnerabilities-threat-research/2024/07/09/microsoft-patch-tuesday-july-2024-security-update-review

https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2024-patch-tuesday-fixes-142-flaws-4-zero-days/

 


ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-07-10

Ê×´ÎÐû²¼

 


Îå¡¢¸½Â¼

5.1 ¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png