¡¾Â©¶´Í¨¸æ¡¿Î¢Èí9Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2024-09-11


Ò»¡¢Â©¶´¸ÅÊö

2024Äê9ÔÂ11ÈÕ£¬¶«É­Æ½Ì¨¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË9ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË79¸ö©¶´£¬Â©¶´ÀàÐÍ°üÂÞÌØȨÌáÉý©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢ鶩¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛƭ©¶´µÈ¡£

±¾´ÎÄþ¾²¸üÐÂÖаüÂÞ4¸ö±»»ý¼«ÀûÓõÄ0 day©¶´£¬ÆäÖÐ1¸öÒѾ­¹ûÈ»Åû¶£º

CVE-2024-38014£ºWindows Installer ÌØȨÌáÉý©¶´

Windows InstallerÖдæÔÚȨÏÞÌáÉý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8£¬ÀÖ³ÉÀûÓø鶴µÄÍþвÕß¿É»ñµÃ SYSTEM ȨÏÞ£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-38217£ºWindows Mark of the WebÄþ¾²¹¦Ð§Èƹý©¶´

Windows Mark of the WebÖдæÔÚÄþ¾²¹¦Ð§Èƹý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ5.4£¬ÍþвÕß¿ÉÒÔÔÚÆä¿ØÖƵķþÎñÆ÷ÉÏÍйÜÒ»¸öÄܹ»Ì Web ±êÖ¾ (MOTW) ·ÀÓùµÄ¶ñÒâÎļþ£¬È»ºóÓÕʹĿ±êÓû§ÏÂÔز¢´ò¿ª¸ÃÎļþ£¬´Ó¶øµ¼ÖÂÄþ¾²¹¦Ð§£¨ÈçSmartScreenÓ¦Ó÷¨Ê½ÐÅÓþÄþ¾²¼ì²é»ò¾É°æWindows¸½¼þ·þÎñÄþ¾²Ìáʾ£©Èƹý¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬ÇÒÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-38226£ºMicrosoft Publisher Äþ¾²¹¦Ð§Èƹý©¶´

Microsoft Publisher´æÔÚÄþ¾²¹¦Ð§Èƹý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.3£¬ÍþвÕß¿Éͨ¹ýÓÕµ¼Êܺ¦ÕßÏÂÔز¢´ò¿ªÌØÖÆÎļþÀ´ÀûÓø鶴£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÈƹýÓÃÓÚ×èÖ¹²»ÊÜÐÅÈλò¶ñÒâÎļþµÄOfficeºê¼Æı£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-43491£ºMicrosoft Windows UpdateÔ¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft·þÎñ¶ÑÕ»ÖдæÔÚUse-After-Free©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬¿ÉÄܵ¼Ö»عöÓ°ÏìWindows 10 1507ÉÏ¿ÉÑ¡×é¼þµÄһЩ©¶´µÄÐÞ¸´£¬´Ó¶øµ¼ÖÂÍþвÕß¿ÉÒÔÀûÓà Windows 10 °æ±¾1507£¨Windows 10 Enterprise 2015 LTSB ºÍ Windows 10 IoT Enterprise 2015 LTSB£©ÏµÍ³ÉÏÕâЩ֮ǰÒÑÐÞ¸´/»º½âµÄ©¶´£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£ÊÜÓ°ÏìÓû§¿Éͨ¹ý°´Ë³Ðò°²×° 2024Äê9Ô·þÎñ¶ÑÕ»¸üР(SSU KB5043936) ºÍ2024Äê9ÔÂWindowsÄþ¾²¸üР(KB5043083) À´ÐÞ¸´¸Ã·þÎñ¶Ñջ©¶´¡£

³ýCVE-2024-43491Í⣬±¾´ÎÄþ¾²¸üÐÂÖÐÐÞ¸´µÄÆäËû6¸öÑÏÖØ©¶´Îª£º

CVE-2024-43464£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft SharePoint ServerÖдæÔÚ·´ÐòÁл¯Â©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.2£¬¾­¹ýÉí·ÝÑéÖ¤ÇÒÓµÓÐÕ¾µãËùÓÐÕßȨÏÞµÄÍþвÕß¿ÉÒÔ½«ÌØÖÆÎļþÉÏ´«µ½Ä¿±ê SharePoint Server£¬²¢Í¨¹ýÌØÖÆAPI ÇëÇóÒÔ´¥·¢Îļþ²ÎÊýµÄ·´ÐòÁл¯£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔÚ SharePoint Server ÉÏÏÂÎÄÖÐʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£

CVE-2024-38018£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft SharePoint ServerÖдæÔÚ·´ÐòÁл¯Â©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÀûÓø鶴ÔÚ SharePoint Server ÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£

CVE-2024-38119£ºWindows Network Address Translation (NAT) Ô¶³Ì´úÂëÖ´ÐЩ¶´

Windows ÍøÂçµØַת»» (NAT)´æÔÚUse-After-Free©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.5£¬ÏàÁÚÍøÂçµÄÍþвÕß¿ÉÀûÓø鶴µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬ÀÖ³ÉÀû¸Ã©¶´ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£

CVE-2024-38216/ CVE-2024-38220£ºAzure Stack Hub ÌØȨÌáÉý©¶´

CVE-2024-38194£ºAzure Web Apps ÌØȨÌáÉý©¶´

³ýCVE-2024-43464ºÍCVE-2024-38018Í⣬΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ©¶´»¹°üÂÞ£º

l CVE-2024-38227£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

l  CVE-2024-38228£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

l  CVE-2024-38237£ºKernel Streaming WOW Thunk Service DriverÌØȨÌáÉý©¶´

l  CVE-2024-38238£ºKernel Streaming Service DriverÌØȨÌáÉý©¶´

l  CVE-2024-38241£ºKernel Streaming Service DriverÌØȨÌáÉý©¶´

l  CVE-2024-38242£ºKernel Streaming Service DriverÌØȨÌáÉý©¶´

l  CVE-2024-38243£ºKernel Streaming Service DriverÌØȨÌáÉý©¶´

l  CVE-2024-38244£ºKernel Streaming Service DriverÌØȨÌáÉý©¶´

l  CVE-2024-38245£ºKernel Streaming Service DriverÌØȨÌáÉý©¶´

l  CVE-2024-38246£ºWin32kÌØȨÌáÉý©¶´

l  CVE-2024-38247£ºWindows Graphics ComponentÌØȨÌáÉý©¶´

l  CVE-2024-38249£ºWindows Graphics ComponentÌØȨÌáÉý©¶´

l  CVE-2024-38252£ºWindows Win32 Kernel SubsystemÌØȨÌáÉý©¶´

l  CVE-2024-38253£ºWindows Win32 Kernel SubsystemÌØȨÌáÉý©¶´

l  CVE-2024-43457£ºWindows Setup and DeploymentÌØȨÌáÉý©¶´

l  CVE-2024-43461£ºWindows MSHTML PlatformÆÛƭ©¶´

l  CVE-2024-43487£ºWindows Mark of the Web Äþ¾²¹¦Ð§Èƹý©¶´

΢Èí9Ô¸üÐÂÐÞ¸´µÄ©¶´ÁбíÈçÏ£º

CVE-ID

CVE ±êÌâ

ÑÏÖØÐÔ

CVE-2024-38216

Azure   Stack Hub ÌØȨÌáÉý©¶´

ÑÏÖØ

CVE-2024-38220

Azure   Stack Hub ÌØȨÌáÉý©¶´

ÑÏÖØ

CVE-2024-38194

Azure Web   Apps ÌØȨÌáÉý©¶´

ÑÏÖØ

CVE-2024-43464

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38018

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38119

Windows   Network Address Translation (NAT) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-43491

Microsoft   Windows Update Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-43469

Azure   CycleCloud Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38188

Azure   Network Watcher VM Agent ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-43470

Azure   Network Watcher VM Agent ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38225

Microsoft   Dynamics 365 Business Central ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-43492

Microsoft   AutoUpdate (MAU) ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-43476

Microsoft   Dynamics 365 (on-premises) ¿çÕ¾½Å±¾Â©¶´

¸ßΣ

CVE-2024-38247

Windows   Graphics Component ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38250

Windows   Graphics Component ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38249

Windows   Graphics Component ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38259

Microsoft   Management Console Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-43465

Microsoft   Excel ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38226

Microsoft   Publisher Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38227

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38228

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-43466

Microsoft   SharePoint Server ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-43463

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-43482

Microsoft   Outlook for iOS ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38245

Kernel   Streaming Service Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38241

Kernel   Streaming Service Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38242

Kernel   Streaming Service Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38244

Kernel   Streaming Service Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38243

Kernel   Streaming Service Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38237

Kernel   Streaming WOW Thunk Service Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38238

Kernel   Streaming Service Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-43479

Microsoft   Power Automate Desktop Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38235

Windows   Hyper-V ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-37338

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37980

Microsoft   SQL Server ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-26191

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37339

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37337

Microsoft   SQL Server Native Scoring ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-26186

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37342

Microsoft   SQL Server Native Scoring ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-43474

Microsoft   SQL Server ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-37335

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37966

Microsoft   SQL Server Native Scoring ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-37340

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37965

Microsoft   SQL Server ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-37341

Microsoft   SQL Server ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-43475

Microsoft   Windows Admin Center ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38257

Microsoft   AllJoyn API ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38254

Windows   Authentication ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38236

DHCP   Server Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38014

Windows   Installer ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38239

Windows   Kerberos ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38256

Windows   Kernel-Mode Driver ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-43495

Windows   libarchive Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38217

Windows   Mark of the Web Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-43461

Windows   MSHTML Platform ÆÛƭ©¶´

¸ßΣ

CVE-2024-38232

Windows   Networking ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38233

Windows   Networking ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38234

Windows   Networking ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-43458

Windows   Networking ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38046

PowerShell   ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38240

Windows   Remote Access Connection Manager ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38231

Windows   Remote Desktop Licensing Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38258

Windows   Remote Desktop Licensing Service ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-43467

Windows   Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-43454

Windows   Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38263

Windows   Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38260

Windows   Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-43455

Windows   Remote Desktop Licensing Service ÆÛƭ©¶´

¸ßΣ

CVE-2024-30073

Windows   Security Zone Mapping Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-43457

Windows   Setup and Deployment ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38230

Windows   Standards-Based Storage Management ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38248

Windows   Storage ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-21416

Windows   TCP/IP Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38045

Windows   TCP/IP Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38246

Win32k ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38252

Windows   Win32 Kernel Subsystem ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38253

Windows   Win33 Kernel Subsystem ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-43487

Windows   Mark of the Web Äþ¾²¹¦Ð§Èƹý©¶´

ÖÐΣ

 

¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

Windows TCP/IP

SQL Server

Windows Security Zone Mapping

Windows Installer

Microsoft Office SharePoint

Windows PowerShell

Windows Network Address Translation (NAT)

Azure Network Watcher

Azure Web Apps

Azure Stack

Windows Mark of the Web (MOTW)

Dynamics Business Central

Microsoft Office Publisher

Windows Standards-Based Storage Management Service

Windows Remote Desktop Licensing Service

Windows Network Virtualization

Role: Windows Hyper-V

Windows DHCP Server

Microsoft Streaming Service

Windows Kerberos

Windows Remote Access Connection Manager

Windows Win32K - GRFX

Microsoft Graphics Component

Windows Storage

Windows Win32K - ICOMP

Windows Authentication Methods

Windows Kernel-Mode Drivers

Windows AllJoyn API

Microsoft Management Console

Windows Setup and Deployment

Windows MSHTML Platform

Microsoft Office Visio

Microsoft Office Excel

Azure CycleCloud

Windows Admin Center

Microsoft Dynamics 365 (on-premises)

Power Automate

Microsoft Outlook for iOS

Windows Update

Microsoft AutoUpdate (MAU)

Windows Libarchive

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔز¢°²×°¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2024Äê9ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Sep

²¹¶¡ÏÂÔØʾÀý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí©¶´ÁÐ±í£¨Ê¾Àý£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿ÁÐÑ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áдò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý

3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£

image.png

Àý3£º²¹¶¡ÏÂÔؽçÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£

3.2 ÁÙʱ´ëÊ©

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼Æı£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏ޶ȡ£

l  ÆôÓÃÇ¿ÃÜÂë¼Æı²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Sep

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43491

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-09-11

Ê×´ÎÐû²¼

 


Îå¡¢¸½Â¼

5.1 ¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png