¡¾Â©¶´Í¨¸æ¡¿Î¢Èí9Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2024-09-11Ò»¡¢Â©¶´¸ÅÊö
2024Äê9ÔÂ11ÈÕ£¬¶«Éƽ̨¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË9ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË79¸ö©¶´£¬Â©¶´ÀàÐÍ°üÂÞÌØȨÌáÉý©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢ鶩¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛÆ©¶´µÈ¡£
±¾´ÎÄþ¾²¸üÐÂÖаüÂÞ4¸ö±»»ý¼«ÀûÓõÄ0 day©¶´£¬ÆäÖÐ1¸öÒѾ¹ûÈ»Åû¶£º
CVE-2024-38014£ºWindows Installer ÌØȨÌáÉý©¶´
Windows InstallerÖдæÔÚȨÏÞÌáÉý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8£¬ÀÖ³ÉÀûÓø鶴µÄÍþвÕß¿É»ñµÃ SYSTEM ȨÏÞ£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£
CVE-2024-38217£ºWindows Mark of the WebÄþ¾²¹¦Ð§Èƹý©¶´
Windows Mark of the WebÖдæÔÚÄþ¾²¹¦Ð§Èƹý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ5.4£¬ÍþвÕß¿ÉÒÔÔÚÆä¿ØÖƵķþÎñÆ÷ÉÏÍйÜÒ»¸öÄܹ»Ì Web ±êÖ¾ (MOTW) ·ÀÓùµÄ¶ñÒâÎļþ£¬È»ºóÓÕʹĿ±êÓû§ÏÂÔز¢´ò¿ª¸ÃÎļþ£¬´Ó¶øµ¼ÖÂÄþ¾²¹¦Ð§£¨ÈçSmartScreenÓ¦Ó÷¨Ê½ÐÅÓþÄþ¾²¼ì²é»ò¾É°æWindows¸½¼þ·þÎñÄþ¾²Ìáʾ£©Èƹý¡£Ä¿Ç°¸Ã©¶´ÒѾ¹ûÈ»Åû¶£¬ÇÒÒѼì²âµ½Â©¶´ÀûÓá£
CVE-2024-38226£ºMicrosoft Publisher Äþ¾²¹¦Ð§Èƹý©¶´
Microsoft Publisher´æÔÚÄþ¾²¹¦Ð§Èƹý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.3£¬ÍþвÕß¿Éͨ¹ýÓÕµ¼Êܺ¦ÕßÏÂÔز¢´ò¿ªÌØÖÆÎļþÀ´ÀûÓø鶴£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÈƹýÓÃÓÚ×èÖ¹²»ÊÜÐÅÈλò¶ñÒâÎļþµÄOfficeºê¼Æı£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£
CVE-2024-43491£ºMicrosoft Windows UpdateÔ¶³Ì´úÂëÖ´ÐЩ¶´
Microsoft·þÎñ¶ÑÕ»ÖдæÔÚUse-After-Free©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬¿ÉÄܵ¼Ö»عöÓ°ÏìWindows 10 1507ÉÏ¿ÉÑ¡×é¼þµÄһЩ©¶´µÄÐÞ¸´£¬´Ó¶øµ¼ÖÂÍþвÕß¿ÉÒÔÀûÓà Windows 10 °æ±¾1507£¨Windows 10 Enterprise 2015 LTSB ºÍ Windows 10 IoT Enterprise 2015 LTSB£©ÏµÍ³ÉÏÕâЩ֮ǰÒÑÐÞ¸´/»º½âµÄ©¶´£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£ÊÜÓ°ÏìÓû§¿Éͨ¹ý°´Ë³Ðò°²×° 2024Äê9Ô·þÎñ¶ÑÕ»¸üР(SSU KB5043936) ºÍ2024Äê9ÔÂWindowsÄþ¾²¸üР(KB5043083) À´ÐÞ¸´¸Ã·þÎñ¶Ñջ©¶´¡£
³ýCVE-2024-43491Í⣬±¾´ÎÄþ¾²¸üÐÂÖÐÐÞ¸´µÄÆäËû6¸öÑÏÖØ©¶´Îª£º
CVE-2024-43464£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´
Microsoft SharePoint ServerÖдæÔÚ·´ÐòÁл¯Â©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.2£¬¾¹ýÉí·ÝÑéÖ¤ÇÒÓµÓÐÕ¾µãËùÓÐÕßȨÏÞµÄÍþвÕß¿ÉÒÔ½«ÌØÖÆÎļþÉÏ´«µ½Ä¿±ê SharePoint Server£¬²¢Í¨¹ýÌØÖÆAPI ÇëÇóÒÔ´¥·¢Îļþ²ÎÊýµÄ·´ÐòÁл¯£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔÚ SharePoint Server ÉÏÏÂÎÄÖÐʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£
CVE-2024-38018£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´
Microsoft SharePoint ServerÖдæÔÚ·´ÐòÁл¯Â©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬¾¹ýÉí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÀûÓø鶴ÔÚ SharePoint Server ÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£
CVE-2024-38119£ºWindows Network Address Translation (NAT) Ô¶³Ì´úÂëÖ´ÐЩ¶´
Windows ÍøÂçµØַת»» (NAT)´æÔÚUse-After-Free©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.5£¬ÏàÁÚÍøÂçµÄÍþвÕß¿ÉÀûÓø鶴µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬ÀÖ³ÉÀû¸Ã©¶´ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£
CVE-2024-38216/ CVE-2024-38220£ºAzure Stack Hub ÌØȨÌáÉý©¶´
CVE-2024-38194£ºAzure Web Apps ÌØȨÌáÉý©¶´
³ýCVE-2024-43464ºÍCVE-2024-38018Í⣬΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ©¶´»¹°üÂÞ£º
l CVE-2024-38227£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´
l CVE-2024-38228£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´
l CVE-2024-38237£ºKernel Streaming WOW Thunk Service DriverÌØȨÌáÉý©¶´
l CVE-2024-38238£ºKernel Streaming Service DriverÌØȨÌáÉý©¶´
l CVE-2024-38241£ºKernel Streaming Service DriverÌØȨÌáÉý©¶´
l CVE-2024-38242£ºKernel Streaming Service DriverÌØȨÌáÉý©¶´
l CVE-2024-38243£ºKernel Streaming Service DriverÌØȨÌáÉý©¶´
l CVE-2024-38244£ºKernel Streaming Service DriverÌØȨÌáÉý©¶´
l CVE-2024-38245£ºKernel Streaming Service DriverÌØȨÌáÉý©¶´
l CVE-2024-38246£ºWin32kÌØȨÌáÉý©¶´
l CVE-2024-38247£ºWindows Graphics ComponentÌØȨÌáÉý©¶´
l CVE-2024-38249£ºWindows Graphics ComponentÌØȨÌáÉý©¶´
l CVE-2024-38252£ºWindows Win32 Kernel SubsystemÌØȨÌáÉý©¶´
l CVE-2024-38253£ºWindows Win32 Kernel SubsystemÌØȨÌáÉý©¶´
l CVE-2024-43457£ºWindows Setup and DeploymentÌØȨÌáÉý©¶´
l CVE-2024-43461£ºWindows MSHTML PlatformÆÛÆ©¶´
l CVE-2024-43487£ºWindows Mark of the Web Äþ¾²¹¦Ð§Èƹý©¶´
΢Èí9Ô¸üÐÂÐÞ¸´µÄ©¶´ÁбíÈçÏ£º
CVE-ID | CVE ±êÌâ | ÑÏÖØÐÔ |
CVE-2024-38216 | Azure Stack Hub ÌØȨÌáÉý©¶´ | ÑÏÖØ |
CVE-2024-38220 | Azure Stack Hub ÌØȨÌáÉý©¶´ | ÑÏÖØ |
CVE-2024-38194 | Azure Web Apps ÌØȨÌáÉý©¶´ | ÑÏÖØ |
CVE-2024-43464 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2024-38018 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2024-38119 | Windows Network Address Translation (NAT) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2024-43491 | Microsoft Windows Update Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2024-43469 | Azure CycleCloud Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-38188 | Azure Network Watcher VM Agent ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43470 | Azure Network Watcher VM Agent ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38225 | Microsoft Dynamics 365 Business Central ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43492 | Microsoft AutoUpdate (MAU) ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43476 | Microsoft Dynamics 365 (on-premises) ¿çÕ¾½Å±¾Â©¶´ | ¸ßΣ |
CVE-2024-38247 | Windows Graphics Component ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38250 | Windows Graphics Component ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38249 | Windows Graphics Component ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38259 | Microsoft Management Console Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-43465 | Microsoft Excel ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38226 | Microsoft Publisher Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-38227 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-38228 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-43466 | Microsoft SharePoint Server ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-43463 | Microsoft Office Visio Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-43482 | Microsoft Outlook for iOS ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-38245 | Kernel Streaming Service Driver ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38241 | Kernel Streaming Service Driver ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38242 | Kernel Streaming Service Driver ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38244 | Kernel Streaming Service Driver ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38243 | Kernel Streaming Service Driver ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38237 | Kernel Streaming WOW Thunk Service Driver ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38238 | Kernel Streaming Service Driver ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43479 | Microsoft Power Automate Desktop Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-38235 | Windows Hyper-V ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-37338 | Microsoft SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-37980 | Microsoft SQL Server ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26191 | Microsoft SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-37339 | Microsoft SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-37337 | Microsoft SQL Server Native Scoring ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-26186 | Microsoft SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-37342 | Microsoft SQL Server Native Scoring ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-43474 | Microsoft SQL Server ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-37335 | Microsoft SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-37966 | Microsoft SQL Server Native Scoring ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-37340 | Microsoft SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-37965 | Microsoft SQL Server ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-37341 | Microsoft SQL Server ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43475 | Microsoft Windows Admin Center ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-38257 | Microsoft AllJoyn API ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-38254 | Windows Authentication ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-38236 | DHCP Server Service ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-38014 | Windows Installer ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38239 | Windows Kerberos ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38256 | Windows Kernel-Mode Driver ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-43495 | Windows libarchive Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-38217 | Windows Mark of the Web Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-43461 | Windows MSHTML Platform ÆÛÆ©¶´ | ¸ßΣ |
CVE-2024-38232 | Windows Networking ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-38233 | Windows Networking ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-38234 | Windows Networking ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-43458 | Windows Networking ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-38046 | PowerShell ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38240 | Windows Remote Access Connection Manager ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38231 | Windows Remote Desktop Licensing Service ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-38258 | Windows Remote Desktop Licensing Service ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-43467 | Windows Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-43454 | Windows Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-38263 | Windows Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-38260 | Windows Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-43455 | Windows Remote Desktop Licensing Service ÆÛÆ©¶´ | ¸ßΣ |
CVE-2024-30073 | Windows Security Zone Mapping Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-43457 | Windows Setup and Deployment ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38230 | Windows Standards-Based Storage Management ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-38248 | Windows Storage ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21416 | Windows TCP/IP Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-38045 | Windows TCP/IP Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-38246 | Win32k ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38252 | Windows Win32 Kernel Subsystem ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38253 | Windows Win33 Kernel Subsystem ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43487 | Windows Mark of the Web Äþ¾²¹¦Ð§Èƹý©¶´ | ÖÐΣ |
¶þ¡¢Ó°Ï췶Χ
ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º
Windows TCP/IP
SQL Server
Windows Security Zone Mapping
Windows Installer
Microsoft Office SharePoint
Windows PowerShell
Windows Network Address Translation (NAT)
Azure Network Watcher
Azure Web Apps
Azure Stack
Windows Mark of the Web (MOTW)
Dynamics Business Central
Microsoft Office Publisher
Windows Standards-Based Storage Management Service
Windows Remote Desktop Licensing Service
Windows Network Virtualization
Role: Windows Hyper-V
Windows DHCP Server
Microsoft Streaming Service
Windows Kerberos
Windows Remote Access Connection Manager
Windows Win32K - GRFX
Microsoft Graphics Component
Windows Storage
Windows Win32K - ICOMP
Windows Authentication Methods
Windows Kernel-Mode Drivers
Windows AllJoyn API
Microsoft Management Console
Windows Setup and Deployment
Windows MSHTML Platform
Microsoft Office Visio
Microsoft Office Excel
Azure CycleCloud
Windows Admin Center
Microsoft Dynamics 365 (on-premises)
Power Automate
Microsoft Outlook for iOS
Windows Update
Microsoft AutoUpdate (MAU)
Windows Libarchive
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔز¢°²×°¡£
£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2024Äê9ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2024-Sep
²¹¶¡ÏÂÔØʾÀý£¨²Î¿¼£©£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢Èí©¶´ÁÐ±í£¨Ê¾Àý£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿ÁÐÑ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áдò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý
3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£
Àý3£º²¹¶¡ÏÂÔؽçÃæ
4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£
3.2 ÁÙʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼Æı£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏ޶ȡ£
l ÆôÓÃÇ¿ÃÜÂë¼Æı²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Sep
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43491
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-09-11 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¶«Éƽ̨¼ò½é
¶«Éƽ̨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«Éƽ̨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶«Éƽ̨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦¡£
5.2 ¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º