¡¾Â©¶´Í¨¸æ¡¿Î¢Èí3Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2025-03-12

Ò»¡¢Â©¶´¸ÅÊö


2025Äê3ÔÂ12ÈÕ£¬¶«É­Æ½Ì¨¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË3ÔÂÄþ¾²¸üУ¬±¾´Î¸üÐÂÐÞ¸´ÁË57¸ö©¶´£¬º­¸ÇȨÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐС¢ÆÛÆ­µÈ¶àÖÖ©¶´ÀàÐÍ ¡£Â©¶´¼¶±ðÂþÑÜÈçÏ£º6¸öÑÏÖØ¼¶±ð©¶´£¬50¸öÖØÒª¼¶±ð©¶´£¬1¸öµÍΣ¼¶±ð©¶´£¨Â©¶´¼¶±ðÒÀ¾Ý΢Èí¹Ù·½Êý¾Ý£© ¡£


ÆäÖУ¬16¸ö©¶´±»Î¢Èí±ê־Ϊ¡°¸ü¿ÉÄܱ»ÀûÓá±¼°¡°¼ì²âÀûÓÃÇéÐΡ±£¬±íÃ÷ÕâЩ©¶´´æÔڽϸߵÄÀûÓ÷çÏÕ£¬½¨ÒéÓÅÏÈÐÞ¸´ÒÔ½µµÍDZÔÚÄþ¾²Íþв ¡£


CVE-ID

CVE ±êÌâ

©¶´¼¶±ð

CVE-2025-24983

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24984

Windows NTFS ÐÅϢй¶©¶´

ÖØÒª

CVE-2025-24985

Windows FAST FAT ÎļþϵͳÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-24991

Windows NTFS ÐÅϢй¶©¶´

ÖØÒª

CVE-2025-24993

Windows NTFS Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-26633

Microsoft ¹ÜÀí¿ØÖÆÌ¨Äþ¾²¹¦Ð§Èƹý©¶´

ÖØÒª

CVE-2025-21180

Windows exFAT ÎļþϵͳԶ³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-21247

MapUrlToZone Äþ¾²¹¦Ð§Èƹý©¶´

ÖØÒª

CVE-2025-24035

Windows Ô¶³Ì×ÀÃæ·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2025-24044

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24045

Windows Ô¶³Ì×ÀÃæ·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2025-24061

Windows Web ²éѯ±êÖ¾Äþ¾²¹¦Ð§Èƹý©¶´

ÖØÒª

CVE-2025-24066

ÄÚºËÁ÷ʽ´¦Ö÷þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24067

ÄÚºËÁ÷ʽ´¦Ö÷þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24992

Windows NTFS ÐÅϢй¶©¶´

ÖØÒª

CVE-2025-24995

Kernel Streaming WOW Thunk ·þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

ÖØÒª


΢Èí3Ô¸üÐÂÐÞ¸´µÄÍêÕû©¶´ÁбíÈçÏ£º


CVE-ID

CVE ±êÌâ

©¶´¼¶±ð

CVE-2025-21180

Windows exFAT ÎļþϵͳԶ³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-21199

Azure ±¸·ÝºÍÕ¾µã»Ö¸´ÊðÀí°²×°·¨Ê½ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-21247

MapUrlToZone Äþ¾²¹¦Ð§Èƹý©¶´

ÖØÒª

CVE-2025-24035

Windows Ô¶³Ì×ÀÃæ·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2025-24043

WinDbg Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-24044

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24045

Windows Ô¶³Ì×ÀÃæ·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2025-24046

ÄÚºËÁ÷ʽ´¦Ö÷þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24048

Windows Hyper-V ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24049

Azure ÃüÁîÐм¯³É (CLI) ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24050

Windows Hyper-V ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24051

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-24054

NTLM ¹þϣй¶ÆÛƭ©¶´

ÖØÒª

CVE-2025-24055

Windows USB ÊÓÆµÀàϵͳÇý¶¯·¨Ê½ÐÅÏ¢Åû¶©¶´

ÖØÒª

CVE-2025-24056

Windows µç»°·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-24057

Microsoft Office Ô¶³ÌÖ´ÐдúÂë©¶´

ÑÏÖØ

CVE-2025-24059

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌáÉýȨÏÞ©¶´

ÖØÒª

CVE-2025-24061

Windows Web ²éѯ±êÖ¾Äþ¾²¹¦Ð§Èƹý©¶´

ÖØÒª

CVE-2025-24064

Windows ÓòÃû·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2025-24066

ÄÚºËÁ÷ʽ´¦Ö÷þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24067

ÄÚºËÁ÷ʽ´¦Ö÷þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24070

ASP.NET Core ºÍ Visual Studio

ÖØÒª

CVE-2025-24071

Microsoft Windows Îļþ×ÊÔ´¹ÜÀíÆ÷ÆÛƭ©¶´

ÖØÒª

CVE-2025-24072

Microsoft µ±µØÄþ¾²»ú¹¹ (LSA) ·þÎñÆ÷ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24075

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-24076

Microsoft Windows ¿çÉ豸·þÎñÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24077

Microsoft Word Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-24078

Microsoft Word Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-24079

Microsoft Word Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-24080

Microsoft Office Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-24081

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-24082

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-24083

Microsoft Office Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-24084

ÊÊÓÃÓÚ Linux µÄ Windows ×Óϵͳ (WSL2) ÄÚºËÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2025-24983

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24984

Windows NTFS ÐÅϢй¶©¶´

ÖØÒª

CVE-2025-24985

Windows FAST FAT ÎļþϵͳÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-24986

Azure Promptflow Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÖØÒª

CVE-2025-24987

Windows USB ÊÓÆµÀàϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24988

Windows USB ÊÓÆµÀàϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24991

Windows NTFS ÐÅϢй¶©¶´

ÖØÒª

CVE-2025-24992

Windows NTFS ÐÅϢй¶©¶´

ÖØÒª

CVE-2025-24993

Windows NTFS Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-24994

Microsoft Windows ¿çÉ豸·þÎñÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24995

Kernel Streaming WOW Thunk ·þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-24996

NTLM ¹þϣй¶ÆÛƭ©¶´

ÖØÒª

CVE-2025-24997

DirectX ͼÐÎÄÚºËÎļþ¾Ü¾ø·þÎñ©¶´

ÖØÒª

CVE-2025-24998

Visual Studio ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-25003

Visual Studio ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-25008

Windows Server Elevation of Privilege Vulnerability

ÖØÒª

CVE-2025-26627

Azure Arc °²×°·¨Ê½ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-26629

Microsoft Office Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-26630

Microsoft Access Ô¶³ÌÖ´ÐдúÂë©¶´

ÖØÒª

CVE-2025-26631

Visual Studio Code ÌØÈ¨ÌáÉý©¶´

ÖØÒª

CVE-2025-26633

Microsoft ¹ÜÀí¿ØÖÆÌ¨Äþ¾²¹¦Ð§Èƹý©¶´

ÖØÒª

CVE-2025-26643

»ùÓÚ Chromium µÄ Microsoft Edge ÆÛƭ©¶´

µÍ

CVE-2025-26645

Ô¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³ÌÖ´ÐдúÂë©¶´

ÑÏÖØ


¶þ¡¢Ó°Ï췶Χ


ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

Windows exFAT File System

Azure Agent Installer

Windows MapUrlToZone

Windows Remote Desktop Services

.NET

Windows Win32 Kernel Subsystem

Microsoft Streaming Service

Role: Windows Hyper-V

Azure CLI

Windows Routing and Remote Access Service (RRAS)

Windows NTLM

Windows USB Video Driver

Windows Telephony Server

Microsoft Office

Windows Common Log File System Driver

Windows Mark of the Web (MOTW)

Role: DNS Server

Windows Kernel-Mode Drivers

ASP.NET Core & Visual Studio

Windows File Explorer

Microsoft Local Security Authority Server (lsasrv)

Microsoft Office Excel

Windows Cross Device Service

Microsoft Office Word

Windows Subsystem for Linux

Windows NTFS

Windows Fast FAT Driver

Azure PromptFlow

Kernel Streaming WOW Thunk Service Driver

Windows Kernel Memory

Visual Studio

Microsoft Windows

Azure Arc

Microsoft Office Access

Visual Studio Code

Microsoft Management Console

Microsoft Edge (Chromium-based)

Remote Desktop Client


Èý¡¢Äþ¾²´ëÊ©


3.1 Éý¼¶°æ±¾


Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´ ¡£


£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ


Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×° ¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüР¡£
4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üР¡£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×° ¡£


£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ


Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüР¡£
2025Äê3ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2025-Mar
²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó ¡£

 

ͼƬ1.png

Àý1£ºÎ¢Èí©¶´ÁÐ±í£¨Ê¾Àý£©


2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿ÁÐÑ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áдò¿ª²¹¶¡ÏÂÔØÁ´½Ó ¡£

 

ͼƬ2.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý


3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×° ¡£

 

ͼƬ3.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ


4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú ¡£


3.2 ÁÙʱ´ëÊ©


ÔÝÎÞ ¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ ¡£
¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ ¡£
ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È ¡£

ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐÞ¸Ä ¡£


3.4 ²Î¿¼Á´½Ó


https://msrc.microsoft.com/update-guide/releaseNote/2025-Mar