¡¾Â©¶´Í¨¸æ¡¿Î¢Èí2Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2025-02-12

Ò»¡¢Â©¶´¸ÅÊö


2025Äê2ÔÂ12ÈÕ£¬¶«É­Æ½Ì¨¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË2ÔÂÄþ¾²¸üУ¬±¾´Î¸üÐÂÐÞ¸´ÁË63¸ö©¶´£¬º­¸ÇȨÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐС¢ÆÛÆ­µÈ¶àÖÖ©¶´ÀàÐÍ¡£Â©¶´¼¶±ðÂþÑÜÈçÏ£º4¸öÑÏÖØ¼¶±ð©¶´£¬56¸öÖØÒª¼¶±ð©¶´£¬1ÆäÖÐΣ¼¶±ð©¶´£¬2¸öµÍΣ¼¶±ð©¶´£¨Â©¶´¼¶±ðÒÀ¾Ý΢Èí¹Ù·½Êý¾Ý£©¡£


ÆäÖУ¬11¸ö©¶´±»Î¢Èí±ê־Ϊ¡°¸ü¿ÉÄܱ»ÀûÓá±¼°¡°¼ì²âÀûÓÃÇéÐΡ±£¬±íÃ÷ÕâЩ©¶´´æÔڽϸߵÄÀûÓ÷çÏÕ£¬½¨ÒéÓÅÏÈÐÞ¸´ÒÔ½µµÍDZÔÚÄþ¾²Íþв¡£


CVE-ID

CVE ±êÌâ

©¶´¼¶±ð

CVE-2025-21400

Microsoft SharePoint Server Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-21377

NTLM ¹þϣй¶ÆÛƭ©¶´

ÖØÒª

CVE-2025-21418

WinSock µÄ Windows ¸¨Öú¹¦Ð§Çý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21414

Windows Core Messaging ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21358

Windows Core Messaging ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21184

Windows Core Messaging ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21367

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21391

Windows ´æ´¢ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21419

Windows °²×°·¨Ê½ÎļþÇåÀíÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21420

Windows ´ÅÅÌÇåÀí¹¤¾ßÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21376

Windows ÇáÁ¿¼¶Ä¿Â¼·ÃÎÊЭÒé (LDAP) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ


΢Èí2Ô¸üÐÂÐÞ¸´µÄÍêÕû©¶´ÁбíÈçÏ£º


CVE-ID

CVE ±êÌâ

©¶´¼¶±ð

CVE-2025-21177

Microsoft Dynamics 365 Sales ÌØÈ¨ÌáÉý©¶´

ÑÏÖØ

CVE-2025-21179

DHCP ¿Í»§¶Ë·þÎñ¾Ü¾ø·þÎñ©¶´

ÖØÒª

CVE-2025-21181

Microsoft ÏûÏ¢ÐÐÁÐ (MSMQ) ¾Ü¾ø·þÎñ©¶´

ÖØÒª

CVE-2025-21182

Windows »Ø¸´Îļþϵͳ (ReFS) ɾ³ýÖØ¸´·þÎñÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21183

Windows »Ø¸´Îļþϵͳ (ReFS) ɾ³ýÖØ¸´·þÎñÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21184

Windows Core Messaging ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21188

Azure ÍøÂçÊӲ취ʽ VM À©Õ¹ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21190

Windows µç»°·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-21194

Microsoft Surface Äþ¾²¹¦Ð§Èƹý©¶´

ÖØÒª

CVE-2025-21198

Microsoft ¸ßÐÔÄܼÆËã (HPC) ´ò°üÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-21200

Windows µç»°·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-21201

Windows Telephony Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-21206

Visual Studio Installer ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21208

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-21212

Internet Á¬½Ó¹²Ïí (ICS) ¾Ü¾ø·þÎñ©¶´

ÖØÒª

CVE-2025-21216

Internet Á¬½Ó¹²Ïí (ICS) ¾Ü¾ø·þÎñ©¶´

ÖØÒª

CVE-2025-21253

Microsoft Edge£¨iOS ºÍ Android °æ£©ÆÛƭ©¶´

ÖÐ

CVE-2025-21254

Internet Á¬½Ó¹²Ïí (ICS) ¾Ü¾ø·þÎñ©¶´

ÖØÒª

CVE-2025-21259

Microsoft Outlook ÆÛƭ©¶´

ÖØÒª

CVE-2025-21267

»ùÓÚ Chromium µÄ Microsoft Edge ÆÛƭ©¶´

µÍ

CVE-2025-21279

»ùÓÚ Chromium µÄ Microsoft Edge Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-21283

»ùÓÚ Chromium µÄ Microsoft Edge Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-21322

Microsoft PC Manager ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21337

Windows NTFS ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21342

»ùÓÚ Chromium µÄ Microsoft Edge Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-21347

Windows ²¿Êð·þÎñ¾Ü¾ø·þÎñ©¶´

ÖØÒª

CVE-2025-21349

Windows Ô¶³Ì×ÀÃæÅäÖ÷þÎñ¸Ä¶¯Â©¶´

ÖØÒª

CVE-2025-21350

Windows Kerberos ¾Ü¾ø·þÎñ©¶´

ÖØÒª

CVE-2025-21351

Windows Active Directory Óò·þÎñ API ·þÎñ¾Ü¾øÂ©¶´

ÖØÒª

CVE-2025-21352

Internet Á¬½Ó¹²Ïí (ICS) ¾Ü¾ø·þÎñ©¶´

ÖØÒª

CVE-2025-21358

Windows Core Messaging ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21359

Windows ÄÚºËÄþ¾²¹¦Ð§Èƹý©¶´

ÖØÒª

CVE-2025-21367

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21368

Microsoft Digest Éí·ÝÑéÖ¤Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-21369

Microsoft Digest Éí·ÝÑéÖ¤Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-21371

Windows µç»°·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-21373

Windows Installer ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21375

Kernel Streaming WOW Thunk ·þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21376

Windows ÇáÁ¿¼¶Ä¿Â¼·ÃÎÊЭÒé (LDAP) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2025-21377

NTLM ¹þϣй¶ÆÛƭ©¶´

ÖØÒª

CVE-2025-21379

DHCP ¿Í»§¶Ë·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2025-21381

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë©¶´

ÑÏÖØ

CVE-2025-21383

Microsoft Excel ÐÅϢй¶©¶´

ÖØÒª

CVE-2025-21386

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-21387

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-21390

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-21391

Windows ´æ´¢ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21392

Microsoft Office Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-21394

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-21397

Microsoft Office Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-21400

Microsoft SharePoint Server Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-21404

»ùÓÚ Chromium µÄ Microsoft Edge ÆÛƭ©¶´

µÍ

CVE-2025-21406

Windows µç»°·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-21407

Windows µç»°·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-21408

»ùÓÚ Chromium µÄ Microsoft Edge Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-21410

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-21414

Windows Core Messaging ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21418

WinSock µÄ Windows ¸¨Öú¹¦Ð§Çý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21419

Windows °²×°·¨Ê½ÎļþÇåÀíÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21420

Windows ´ÅÅÌÇåÀí¹¤¾ßÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24036

Microsoft AutoUpdate (MAU) ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24039

Visual Studio Code ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24042

Visual Studio Code JS µ÷ÊÔÀ©Õ¹ÌØÈ¨ÌáÉý©¶´

ÖØÒª


¶þ¡¢Ó°Ï췶Χ


ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

Microsoft Dynamics 365 Sales

Windows DHCP Client

Windows Message Queuing

Windows Resilient File System (ReFS) Deduplication Service

Windows CoreMessaging

Azure Network Watcher

Windows Telephony Service

Microsoft Surface

Microsoft High Performance Compute Pack (HPC) Linux Node Agent

Windows Telephony Server

Visual Studio

Windows Routing and Remote Access Service (RRAS)

Windows Internet Connection Sharing (ICS)

Microsoft Edge for iOS and Android

Outlook for Android

Microsoft Edge (Chromium-based)

Microsoft PC Manager

Microsoft Windows

Windows Update Stack

Windows Remote Desktop Services

Windows Kerberos

Active Directory Domain Services

Windows Kernel

Windows Win32 Kernel Subsystem

Microsoft Digest Authentication

Windows Installer

Microsoft Streaming Service

Windows LDAP - Lightweight Directory Access Protocol

Windows NTLM

Windows DHCP Server

Microsoft Office Excel

Windows Storage

Microsoft Office

Microsoft Office SharePoint

Windows DWM Core Library

Windows Ancillary Function Driver for WinSock

Windows Setup Files Cleanup

Windows Disk Cleanup Tool

Microsoft AutoUpdate (MAU)

Visual Studio Code


Èý¡¢Äþ¾²´ëÊ©


3.1 Éý¼¶°æ±¾


Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£


£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ


Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº


1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£


£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ


Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£


2025Äê2ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2025-Feb

²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º


1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£



ͼƬ1.jpg

Àý1£ºÎ¢Èí©¶´ÁÐ±í£¨Ê¾Àý£©


2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿ÁÐÑ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áдò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£


ͼƬ2.jpg

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý


3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£


ͼƬ3.jpg

Àý3£º²¹¶¡ÏÂÔØ½çÃæ


4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£


3.2 ÁÙʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£


3.4 ²Î¿¼Á´½Ó


https://msrc.microsoft.com/update-guide/releaseNote/2025-Feb