¡¾·ì϶¹«¸æ¡¿Î¢Èí6Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2023-06-14
Ò»¡¢·ì϶¸ÅÊö
2023Äê6ÔÂ13ÈÕ£¬Î¢Èí°ä²¼ÁË6Ô°²È«¸üУ¬±¾´Î¸üй²½¨¸´ÁË78¸ö°²È«·ì϶£¨²»Ô̺¬Microsoft Edge·ì϶£©£¬ÆäÖÐÓÐ6¸ö·ì϶ÆÀ¼¶Îª¡°ÑϳÁ¡±¡£
±¾´Î½¨¸´µÄ·ì϶ÖУ¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶ºÍºýŪ·ì϶µÈ¡£
΢Èí±¾´Î°²È«¸üÐÂÖÐÎ´Éæ¼°0 day·ì϶£¬ÖµµÃ¹Ø×¢µÄ·ì϶Ô̺¬µ«²»ÏÞÓÚ£º
CVE-2023-29357 £ºMicrosoft SharePoint Server ÌØÈ¨ÌáÉý·ì϶
Microsoft SharePoint Server 2019ÖдæÔÚȨÏÞÌáÉý·ì϶£¬¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.8¡£»ñµÃºýŪÐÔJWTÉí·ÝÑéÖ¤ÁîÅÆµÄÍþвÕßÄܹ»Ê¹ÓÃÕâЩÁîÅÆÖ´ÐÐÍøÂç¹¥»÷£¬´Ó¶øÈƹýÉí·ÝÑéÖ¤£¬²¢¿ÉÄÜ»ñµÃÖÎÀíԱȨÏÞ¡£
CVE-2023-32031 £ºMicrosoft Exchange Server Ô¶³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.8£¬¾¹ýÉí·ÝÑéÖ¤µÄÓû§Äܹ»³¢ÊÔͨ¹ýÍøÂçŲÓÃÔÚ·þÎñÆ÷ÕË»§µÄ¸ßµÍÎÄÖд¥·¢¶ñÒâ´úÂë¡£
CVE-2023-24897£º.NET¡¢.NET Framework ºÍ Visual Studio Ô¶³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.8£¬Äܹ»Í¨¹ýÓÕµ¼Êܺ¦Õß´ÓÍøÕ¾ÏÂÔØ²¢´ò¿ªÌØÔìÎļþµÄ·ì϶ÀûÓ㬴Ӷøµ¼Ö¶ÔÊܺ¦ÕßµÄÍÆËã»ú½øÐб¾µØ¹¥»÷£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐС£
CVE-2023-32013£ºWindows Hyper-V »Ø¾ø·þÎñ·ì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ6.5¡£
CVE-2023-29363/CVE-2023-32014/CVE-2023-32015£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´Ðзì϶
ÕâЩ·ì϶µÄCVSSv3ÆÀ·Ö¾ùΪ9.8£¬µ± Windows ÐÂÎŶÓÁзþÎñÔËÐÐÔÚ PGM Server »·¾³ÖÐʱ£¬Äܹ»Í¨¹ýÍøÂç·¢ËÍÌØÔìÎļþÀ´ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£Windows ÐÂÎŶÓÁзþÎñÊÇÒ»¸ö Windows ×é¼þ£¬ÆôÓøÃ×é¼þµÄϵͳ²ÅÒ×ÊÜÕë¶ÔÕâЩ·ì϶µÄ¹¥»÷£¬Äܹ»²é³ÊÇ·ñÓÐÃûΪMessage QueuingµÄ·þÎñÔÚÔËÐв¢ÇÒ TCP ¶Ë¿Ú 1801 ÔÚ»úеÉÏÕìÌý¡£
CVE-2023-29362£ºRemote Desktop ClientÔ¶³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.8£¬ÔÚÔ¶³Ì×ÀÃæÏνӵÄÇé¿öÏ£¬µ±Êܺ¦ÕßʹÓÃÒ×Êܹ¥»÷µÄÔ¶³Ì×ÀÃæ¿Í»§¶ËÏνӵ½¹¥»÷·þÎñÆ÷ʱ£¬½ÚÔìÔ¶³Ì×ÀÃæ·þÎñÆ÷µÄÍþвÕßÄܹ»ÔÚ RDP ¿Í»§¶ËÍÆËã»úÉÏ´¥·¢Ô¶³Ì´úÂëÖ´ÐÐ (RCE)¡£
CVE-2023-28310£ºMicrosoft Exchange Server Ô¶³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.0£¬Óë Exchange Server´¦ÓÚͳһÄÚÍøµÄ¾¹ýÉí·ÝÑéÖ¤µÄÍþвÕßÄܹ»Í¨¹ý PowerShell Ô¶³Ì»á»°ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£
´Ë±í£¬Î¢Èí»¹°ä²¼ÁË´óÁ¿ Microsoft Office ¸üУ¬ÒÔ½¨¸´Excel ¡¢OneNote ºÍOutlookµÈ¶à¸ö²úÆ·Öеķì϶£¬ÀûÓÃÕâЩ·ì϶±ØÒªÓû§½»»¥£¬²¿ÃÅ·ì϶ÈçÏ£º
CVE-2023-33133£ºMicrosoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶
CVE-2023-33137£ºMicrosoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶
CVE-2023-33140£ºMicrosoft OneNote ºýŪ·ì϶
CVE-2023-33131£ºMicrosoft Outlook Ô¶³Ì´úÂëÖ´Ðзì϶
΢Èí6Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º
CVE-ID | ±êÌâ | ÑϳÁÐÔ |
CVE-2023-24897 | .NET¡¢.NET Framework ºÍ Visual Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-29357 | Microsoft SharePoint Server ÌØÈ¨ÌáÉý·ì϶ | ÑϳÁ |
CVE-2023-32013 | Windows Hyper-V »Ø¾ø·þÎñ·ì϶ | ÑϳÁ |
CVE-2023-29363 | Windows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-32014 | Windows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-32015 | Windows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-24895 | .NET¡¢.NET Framework ºÍ Visual Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-33126 | .NET ºÍ Visual Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-33135 | .NET ºÍ Visual Studio ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-32032 | .NET ºÍ Visual Studio ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-32030 | .NET ºÍ Visual Studio »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-33128 | .NET ºÍ Visual Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-29331 | .NET¡¢.NET Framework ºÍ Visual Studio »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-29326 | .NET Framework Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-33141 | Yet Another Reverse Proxy (YARP) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-21569 | Azure DevOps ·þÎñÆ÷ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-21565 | Azure DevOps ·þÎñÆ÷ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-24896 | Dynamics 365 Finance ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-33145 | Microsoft Edge£¨»ùÓÚChromium£©ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-32031 | Microsoft Exchange Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28310 | Microsoft Exchange Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-33146 | Microsoft Office Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-33133 | Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-32029 | Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-33137 | Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-33140 | Microsoft OneNote ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-33131 | Microsoft Outlook Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-33142 | Microsoft SharePoint Server ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-33129 | Microsoft SharePoint »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-33130 | Microsoft SharePoint Server ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-33132 | Microsoft SharePoint Server ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-32024 | Microsoft Power Apps ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-32017 | Microsoft PostScript ´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-29372 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-29370 | Windows Media Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-29365 | Windows Media Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-29337 | NuGet ClientÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-29362 | Remote Desktop Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-29352 | Windows Ô¶³Ì×ÀÃæ°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-32020 | Windows DNS ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-29007 | GitHub£ºCVE-2023-29007 ͨ¹ý `git submodule deinit` ½øÐÐËÁÒâÅäÖÃ×¢Èë | ¸ßΣ |
CVE-2023-33139 | Visual Studio ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-25652 | GitHub£ºCVE-2023-25652¡°git apply --reject¡±²¿ÃŽÚÔìËÁÒâÎļþдÈë | ¸ßΣ |
CVE-2023-25815 | GitHub£ºCVE-2023-25815 Git ÔÚ·ÇÌØÈ¨µØÎ»²éÕÒ±¾µØ»¯ÐÂÎÅ | ¸ßΣ |
CVE-2023-27911 | AutoDesk£ºAutodesk? FBX? SDK 2020 »ò¸üÔç°æ±¾ÖÐµÄ CVE-2023-27911 ¶Ñ»º³åÇøÒç¶Âí½Å | ¸ßΣ |
CVE-2023-27910 | AutoDesk£ºAutodesk? FBX? SDK 2020 »ò¸üÔç°æ±¾ÖÐµÄ CVE-2023-27910 ²Ö¿â»º³åÇøÒç¶Âí½Å | ¸ßΣ |
CVE-2023-29011 | GitHub: CVE-2023-29011 `connect.exe` µÄÅäÖÃÎļþÈÝÒ×±»¶ñÒâ¸éÖà | ¸ßΣ |
CVE-2023-29012 | GitHub:CVE-2023-29012 Git CMDÃýÎóµØÔÚµ±Ç°Ä¿Â¼ÖÐÖ´ÐÓ×°doskey.exe¡±£¨ÈôÊÇ´æÔÚ£© | ¸ßΣ |
CVE-2023-27909 | AutoDesk£ºAutodesk? FBX? SDK 2020 »ò¸üÔç°æ±¾ÖÐµÄ CVE-2023-27909 Ô½½çдÈë·ì϶ | ¸ßΣ |
CVE-2023-33144 | Visual Studio CodeºýŪ·ì϶ | ¸ßΣ |
CVE-2023-29364 | Windows Éí·ÝÑéÖ¤ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-32010 | Windows Bus Filter Driver ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-29361 | Windows Cloud Files Mini Filter Driver ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-32009 | Windows Collaborative Translation Framework ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-32012 | Windows Container Manager Service ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-24937 | Windows CryptoAPI »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-24938 | Windows CryptoAPI »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-29355 | DHCP Server Service ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-29368 | Windows Filtering Platform ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-29358 | Windows GDI ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-29366 | Windows Geolocation Service Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-29351 | Windows ×éÕ½ÊõÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-32018 | Windows Hello Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-32016 | Windows Installer ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-32011 | Windows iSCSI ·¢ÏÖ·þÎñ»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-32019 | Windows ÄÚºËÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-29346 | NTFS ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-29373 | Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-29367 | iSCSI Target WMI Provider Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-29369 | Remote Procedure Call Runtime »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-32008 | Windows Resilient File System (ReFS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-32022 | Windows Server ·þÎñ°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-32021 | Windows SMB Witness ·þÎñ°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-29360 | Windows TPM É豸Çý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-29371 | Windows GDI ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-29359 | GDI ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-24936 | .NET¡¢.NET Framework ºÍ Visual Studio ÌØÈ¨ÌáÉý·ì϶ | ÖÐΣ |
CVE-2023-33143 | Microsoft Edge£¨»ùÓÚ Chromium£©ÌØÈ¨ÌáÉý·ì϶ | ÖÐΣ |
CVE-2023-29345 | Microsoft Edge£¨»ùÓÚ Chromium£©°²È«Ö°ÄÜÈÆ¹ý·ì϶ | µÍΣ |
CVE-2023-29353 | Sysinternals Process Monitor for Windows »Ø¾ø·þÎñ·ì϶ | µÍΣ |
CVE-2023-2941 | Chromium£ºCVE-2023-2941 ÔÚÀ©´ó API ÖÐÖ´Ðв»µ± | δ֪ |
CVE-2023-2937 | Chromium£ºCVE-2023-2937 »ÖлִÐв»µ± | δ֪ |
CVE-2023-2936 | Chromium£ºV8 ÖÐµÄ CVE-2023-2936 ÀàÐÍ»ìºÏ | δ֪ |
CVE-2023-2935 | Chromium£ºV8 ÖÐµÄ CVE-2023-2935 ÀàÐÍ»ìºÏ | δ֪ |
CVE-2023-2940 | Chromium£ºCVE-2023-2940 ÏÂÔØÖеÄÖ´Ðв»µ± | δ֪ |
CVE-2023-2939 | Chromium£ºCVE-2023-2939 ×°Ö÷¨Ê½ÖеÄÊý¾ÝÑéÖ¤²»¼° | δ֪ |
CVE-2023-2938 | Chromium£ºCVE-2023-2938 »ÖлִÐв»µ± | δ֪ |
CVE-2023-2931 | Chromium£ºCVE-2023-2931 ÔÚ PDF ÖпªÊͺóʹÓà | δ֪ |
CVE-2023-2930 | Chromium£ºCVE-2023-2930 ÔÚÀ©´óÖпªÊͺóʹÓà | δ֪ |
CVE-2023-2929 | Chromium£ºCVE-2023-2929 ÔÚ Swiftshader ÖÐÔ½½çдÈë | δ֪ |
CVE-2023-2934 | Chromium£ºCVE-2023-2934 Mojo ÖеÄÔ½½çÄÚ´æ½Ó¼û | δ֪ |
CVE-2023-2933 | Chromium£ºCVE-2023-2933 ÔÚ PDF ÖпªÊͺóʹÓà | δ֪ |
CVE-2023-2932 | Chromium£ºCVE-2023-2932 ÔÚ PDF ÖпªÊͺóʹÓà | δ֪ |
CVE-2023-3079 | Chromium£ºV8 ÖÐµÄ CVE-2023-3079 ÀàÐÍ»ìºÏ | δ֪ |
¶þ¡¢Ó°ÏìÁìÓò
ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º
Azure DevOps
.NET and Visual Studio
Microsoft Dynamics
Windows CryptoAPI
Microsoft Exchange Server
.NET Framework
.NET Core
NuGet Client
Microsoft Edge (Chromium-based)
Windows NTFS
Windows Group Policy
Remote Desktop Client
SysInternals
Windows DHCP Server
Microsoft Office SharePoint
Windows GDI
Windows Win32K
Windows TPM Device Driver
Windows Cloud Files Mini Filter Driver
Windows PGM
Windows Authentication Methods
Microsoft Windows Codecs Library
Windows Geolocation Service
Windows OLE
Windows Filtering
Windows Remote Procedure Call Runtime
Microsoft WDAC OLE DB provider for SQL
Windows ODBC Driver
Windows Resilient File System (ReFS)
Windows Collaborative Translation Framework
Windows Bus Filter Driver
Windows iSCSI
Windows Container Manager Service
Windows Hyper-V
Windows Installer
Microsoft Printer Drivers
Windows Hello
Windows Kernel
Role: DNS Server
Windows SMB
Windows Server Service
Microsoft Power Apps
Microsoft Office Excel
Microsoft Office Outlook
Visual Studio
Microsoft Office OneNote
ASP .NET
Visual Studio Code
Microsoft Office
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2023Äê6Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2023-Jun
²¹¶¡ÏÂÔØÊ¾Àý£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2022Äê2Ô£©
2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2023-Jun
https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2023-patch-tuesday-fixes-78-flaws-38-rce-bugs/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-06-14 | ³õ´Î°ä²¼ |
Îå¡¢¸½Â¼
5.1 GA»Æ½ð¼×¼ò½é
GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£
5.2 ¹ØÓÚGA»Æ½ð¼×
GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ