¡¾·ì϶¹«¸æ¡¿Î¢Èí8Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2023-08-09

Ò»¡¢·ì϶¸ÅÊö

2023Äê8ÔÂ8ÈÕ £¬Î¢Èí°ä²¼ÁË8Ô°²È«¸üР£¬±¾´Î¸üй²½¨¸´ÁË87¸ö·ì϶ £¬ÆäÖÐÔ̺¬2¸öÒѱ»ÀûÓõķì϶¡¢23¸öÔ¶³Ì´úÂëÖ´Ðзì϶ÒÔ¼°6¸öÆÀ¼¶ÎªÑϳÁµÄ·ì϶¡£

±¾´Î½¨¸´µÄ·ì϶ÖÐ £¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶ºÍºýŪ·ì϶µÈ¡£

΢Èí±¾´Î¹²½¨¸´ÁË2¸öÒѱ»ÀûÓõķì϶£º

ADV230003£ºMicrosoft Office Éî¶È·ÀÓù¸üУ¨½¨¸´CVE-2023-36884£©

Microsoft °ä²¼ÁË Microsoft OfficeÉî¶È·ÀÓù¸üР£¬ÒÔ½¨¸´ÏÈǰÒÑ»º½â²¢±»»ý¼«ÀûÓõÄCVE-2023-36884Ô¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Á´¡£CVE-2023-36884Ó°ÏìÁ˶à¸öWindowsºÍOffice²úÆ· £¬ÍþвÕßÄܹ»´´½¨ÌØÔìµÄ Microsoft OfficeÎĵµ²¢ÓÕµ¼Êܺ¦Õß´ò¿ª¶ñÒâÎļþ £¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔÚÊܺ¦ÕߵĸߵÍÎÄÖÐÔ¶³ÌÖ´ÐдúÂë¡£¸Ã·ì϶ÒѾ­¹«¿ªÅû¶ÇÒÒÑ·¢ÏÖ±»ÀûÓá£

CVE-2023-38180 £º.NET ºÍ Visual Studio »Ø¾ø·þÎñ·ì϶

¸Ã·ì϶µÄCVSSv3.1ÆÀ·ÖΪ7.5 £¬¿ÉÀûÓø÷ì϶µ¼ÖÂ.NET ÀûÓ÷¨Ê½ºÍ Visual Studio»Ø¾ø·þÎñ £¬Ä¿Ç°¸Ã·ì϶ÒÑ·¢ÏÖ±»ÀûÓá£

΢Èí±¾´Î¸üÐÂÖн¨¸´µÄ6¸öÆÀ¼¶Îª¡°ÑϳÁ¡±µÄ·ì϶ÈçÏ£º

CVE-2023-36895£ºMicrosoft OutlookÔ¶³Ì´úÂëÖ´Ðзì϶

¸Ã·ì϶µÄCVSSv3.1ÆÀ·ÖΪ7.8 £¬ÍþвÕß¿Éͨ¹ýÓÕµ¼Êܺ¦ÕßÏÂÔØ²¢´ò¿ªÌØÔìÎļþ£¨±ØÒªÓû§½»»¥£© £¬´Ó¶øµ¼Ö¶ÔÊܺ¦ÕßÍÆËã»úÖ´Ðб¾µØ¹¥»÷ £¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐС£

CVE-2023-29328/ CVE-2023-29330£ºMicrosoft TeamsÔ¶³Ì´úÂëÖ´Ðзì϶

¸Ã·ì϶µÄCVSSv3.1ÆÀ·ÖΪ8.8 £¬Ó°ÏìÁËMicrosoft Teams ×ÀÃæ°æ¡¢Android °æ¡¢ iOS°æºÍMac °æ¡£ÍþвÕßÄܹ»Í¨¹ýÓÕÆ­Êܺ¦Õß²ÎÓëÆäÉèÖõĶñÒâTeams »áÒé £¬µ¼ÖÂÔÚÊܺ¦ÕßÓû§µÄ¸ßµÍÎÄÖÐÔ¶³ÌÖ´ÐдúÂë £¬´Ó¶ø¿ÉÄܽӼû»òÅú¸ÄÊܺ¦ÕßµÄÐÅÏ¢ £¬»ò¿ÉÄܵ¼Ö¿ͻ§¶ËÍÆËã»úÍ£»ú £¬ÀûÓø÷ì϶ÎÞÐèÌØÈ¨¡£

CVE-2023-35385/CVE-2023-36911/CVE-2023-36910£ºMicrosoftÐÂÎŶÓÁÐÔ¶³Ì´úÂëÖ´Ðзì϶

ÕâЩ·ì϶µÄCVSSv3.1ÆÀ·Ö¾ùΪ9.8 £¬Äܹ»Í¨¹ý·¢ËͶñÒâÔì×÷µÄMSMQ Êý¾Ý°üµ½MSMQ ·þÎñÆ÷À´ÀûÓ÷ì϶ £¬³É¹¦ÀûÓÃÕâЩ·ì϶¿ÉÄܵ¼ÖÂÔÚÖ¸±ê·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë¡£ÀûÓÃÕâЩ·ì϶±ØÒªÆôÓÃ×÷ΪWindows ×é¼þµÄWindows ÐÂÎŶÓÁзþÎñ £¬Äܹ»Í¨¹ý²é³­ÊÇ·ñÓÐÃûΪMessage QueuingµÄ·þÎñÔÚÔËÐÐ £¬ÒÔ¼°ÍÆËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£

ÆäËüÖµµÃ¹Ø×¢µÄ·ì϶»¹Ô̺¬µ«²»ÏÞÓÚ£º

CVE-2023-21709£ºMicrosoft Exchange Server ȨÏÞÌáÉý·ì϶

¸Ã·ì϶µÄCVSSv3.1ÆÀ·ÖΪ9.8 £¬ÔÚ»ùÓÚÍøÂçµÄ¹¥»÷ÖÐ £¬Äܹ»Í¨¹ý±©Á¦ÆÆ½âÓû§ÕÊ»§ÃÜÂëÒÔ¸ÃÓû§Éí·ÝµÇ¼¡£½¨ÒéʹÓÃÇ¿ÃÜÂëÀ´»º½â±©Á¦ÆÆ½â¹¥»÷¡£

CVE-2023-35388 /CVE-2023-38182£ºMicrosoft Exchange Server Ô¶³Ì´úÂëÖ´Ðзì϶

ÕâЩ·ì϶µÄCVSSv3.1ÆÀ·Ö¾ùΪ8.0 £¬Í¨¹ý LAN ½Ó¼ûÉí·ÝÑéÖ¤²¢Õ¼ÓÐÓÐЧ Exchange Óû§Í´´¦µÄÍþвÕßÄܹ»Í¨¹ý PowerShell Ô¶³Ì´¦Öòǻ°Ô¶³ÌÖ´ÐдúÂë¡£

΢Èí8Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º

CVE ID

CVE ±êÌâ

ÑϳÁÐÔ

CVE-2023-36895

Microsoft   Outlook Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-29328

Microsoft   Teams Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-29330

Microsoft   Teams Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-35385

Microsoft ÐÂÎŶÓÁÐÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-36911

Microsoft ÐÂÎŶÓÁÐÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-36910

Microsoft ÐÂÎŶÓÁÐÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-38178

.NET Core ºÍ Visual Studio »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-35390

.NETºÍVisual StudioÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36873

.NET   Framework ºýŪ·ì϶

¸ßΣ

CVE-2023-38180

.NET ºÍ Visual Studio »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36899

ASP.NET ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2023-35391

ASP.NET   Core SignalR ºÍ Visual Studio ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-38176

Azure   Arc-Enabled Servers ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36869

Azure   DevOps Server ºýŪ·ì϶

¸ßΣ

CVE-2023-38188

Azure   Apache Hadoop ºýŪ·ì϶

¸ßΣ

CVE-2023-35393

Azure   Apache Hive ºýŪ·ì϶

¸ßΣ

CVE-2023-35394

Azure HDInsight   Jupyter Notebook ºýŪ·ì϶

¸ßΣ

CVE-2023-36881

Azure   Apache Ambari ºýŪ·ì϶

¸ßΣ

CVE-2023-36877

Azure   Apache Oozie ºýŪ·ì϶

¸ßΣ

CVE-2023-38167

Microsoft   Dynamics Business Central ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35389

Microsoft   Dynamics 365 On-Premises Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-38185

Microsoft   Exchange Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35388

Microsoft   Exchange Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35368

Microsoft   Exchange Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-38181

Microsoft   Exchange Server ºýŪ·ì϶

¸ßΣ

CVE-2023-38182

Microsoft   Exchange Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-21709

Microsoft   Exchange Server ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2023-36897

Visual   Studio Tools for Office Runtime ºýŪ·ì϶

¸ßΣ

CVE-2023-36896

Microsoft   Excel Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35371

Microsoft   Office Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36893

Microsoft   Outlook ºýŪ·ì϶

¸ßΣ

CVE-2023-36891

Microsoft   SharePoint Server ºýŪ·ì϶

¸ßΣ

CVE-2023-36894

Microsoft   SharePoint Server ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36890

Microsoft   SharePoint Server ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36892

Microsoft   SharePoint Server ºýŪ·ì϶

¸ßΣ

CVE-2023-35372

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36865

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36866

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36882

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-20569

AMD£ºCVE-2023-20569 ·µ»ØµØÖ·Ô¤²âÆ÷

¸ßΣ

CVE-2023-38170

HEVC Video   Extensions Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36876

Reliability   Analysis Metrics Calculation (RacTask) ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2023-36908

Windows   Hyper-V ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-38169

Microsoft   OLE DB Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36898

Tablet   Windows User Interface Application Core Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35387

Windows   Bluetooth A2DP driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36904

Windows   Cloud Files Mini Filter Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36900

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36907

Windows ¼ÓÃÜ·þÎñÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36906

Windows ¼ÓÃÜ·þÎñÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-38175

Microsoft   Windows Defender ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2023-35381

Windows ´«Õæ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36889

Windows ×éÕ½Êõ°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2023-35384

Windows   HTMLƽ̨°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2023-35359

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-38154

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35382

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35386

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35380

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-38184

Windows ÇáÁ¿¼¶Ä¿Â¼½Ó¼ûºÍ̸ (LDAP) Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36909

Microsoft ÐÂÎŶÓÁлؾø·þÎñ·ì϶

¸ßΣ

CVE-2023-35376

Microsoft ÐÂÎŶÓÁлؾø·þÎñ·ì϶

¸ßΣ

CVE-2023-38172

Microsoft ÐÂÎŶÓÁлؾø·þÎñ·ì϶

¸ßΣ

CVE-2023-35383

Microsoft ÐÂÎŶÓÁÐÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36913

Microsoft ÐÂÎŶÓÁÐÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-35377

Microsoft ÐÂÎŶÓÁлؾø·þÎñ·ì϶

¸ßΣ

CVE-2023-38254

Microsoft ÐÂÎŶÓÁлؾø·þÎñ·ì϶

¸ßΣ

CVE-2023-36912

Microsoft ÐÂÎŶÓÁлؾø·þÎñ·ì϶

¸ßΣ

CVE-2023-38186

Windows   Mobile É豸ÖÎÀíȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2023-35378

Windows   Projected File System ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35379

Reliability   Analysis Metrics Calculation Engine (RACEng) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36914

Windows   Smart Card Resource Management Server °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2023-36903

Windows System   Assessment Tool ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36905

Windows ÎÞÏß¹ãÓòÍø·þÎñ (WwanSvc) ÐÅϢй¶·ì϶

¸ßΣ

ADV230004

ÄÚ´æÆëÈ«ÐÔϵͳ¾ÍÐ÷ɨÃ蹤¾ßÉî¶È·ÀÓù¸üÐÂ

ÖÐΣ

CVE-2023-38157

Microsoft   Edge£¨»ùÓÚ Chromium£©°²È«Ö°ÄÜÈÆ¹ý·ì϶

ÖÐΣ

ADV230003

Microsoft   Office Éî¶È·ÀÓù¸üÐÂ

ÖÐΣ

CVE-2023-35945

Envoy »Ø¾ø·þÎñ·ì϶

δ֪

CVE-2023-4068

Chromium£ºCVE-2023-4068 V8 ÖеÄÀàÐÍ»ìºÏ

δ֪

CVE-2023-4072

Chromium£ºCVE-2023-4072 WebGL ÖеĶÁдԽ½ç

δ֪

CVE-2023-4071

Chromium£ºCVE-2023-4071 Visuals ÖеĶѻº³åÇøÒç³ö

δ֪

CVE-2023-4073

Chromium£ºCVE-2023-4073 ANGLE ÖеÄÄÚ´æ½Ó¼ûÔ½½ç

δ֪

CVE-2023-4075

Chromium£ºCVE-2023-4075 ÔÚ Cast ÖпªÊͺóʹÓÃ

δ֪

CVE-2023-4074

Chromium£ºCVE-2023-4074 ÔÚ Blink ¹¤×÷µ÷¶ÈÖпªÊͺóʹÓÃ

δ֪

CVE-2023-4076

Chromium£ºCVE-2023-4076 ÔÚ WebRTC ÖпªÊͺóʹÓÃ

δ֪

CVE-2023-4077

Chromium£ºCVE-2023-4077 À©´óÖеÄÊý¾ÝÑéÖ¤²»¼°

δ֪

CVE-2023-4078

Chromium£ºCVE-2023-4078 À©´óÖеÄÖ´Ðв»µ±

δ֪

CVE-2023-4070

Chromium£ºCVE-2023-4070 V8 ÖеÄÀàÐÍ»ìºÏ

δ֪

CVE-2023-4069

Chromium£ºCVE-2023-4069 V8 ÖеÄÀàÐÍ»ìºÏ

δ֪

 

¶þ¡¢Ó°ÏìÁìÓò

ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º

Microsoft Office

Memory Integrity System Readiness Scan Tool

Microsoft Exchange Server

Microsoft Teams

Windows Kernel

Microsoft Office Excel

Microsoft Office Visio

Windows Message Queuing

Windows Projected File System

Windows Reliability Analysis Metrics Calculation Engine

Windows Fax and Scan Service

Windows HTML Platform

Windows Bluetooth A2DP driver

Microsoft Dynamics

.NET Core

ASP.NET and Visual Studio

Azure HDInsights

Azure DevOps

.NET Framework

Reliability Analysis Metrics Calculation Engine

Microsoft WDAC OLE DB provider for SQL

Windows Group Policy

Microsoft Office SharePoint

Microsoft Office Outlook

Tablet Windows User Interface

ASP.NET

Windows Common Log File System Driver

Windows System Assessment Tool

Windows Cloud Files Mini Filter Driver

Windows Wireless Wide Area Network Service

Windows Cryptographic Services

Role: Windows Hyper-V

Windows Smart Card

Microsoft Edge (Chromium-based)

Dynamics Business Central Control

SQL Server

Microsoft Windows Codecs Library

Windows Defender

Azure Arc

ASP .NET

Windows LDAP - Lightweight Directory Access Protocol

Windows Mobile Device Management

 

Èý¡¢°²È«´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üР£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓà £¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ £¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü £¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡± £¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС± £¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС± £¬ÆÚ´ýϵͳ×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú £¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüР£¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó £¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡± £¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2023Äê8Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2023-Aug

²¹¶¡ÏÂÔØÊ¾Àý£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó £¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2022Äê2Ô£©

2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ £¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾°²È«¸üС¿ £¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ £¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£

 

3.2 һʱ´ëÊ©

Õë¶ÔCVE-2023-21709 £¬¿É²Î¿¼£º

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21709

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡ £¬Ï÷¼õϵͳ·ì϶ £¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔì £¬Åú¸Ä·À»ðǽսÊõ £¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ £¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø £¬Ï÷¼õ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶°²È«²úÆ· £¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí £¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò £¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2023-Aug

https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2023-patch-tuesday-warns-of-2-zero-days-87-flaws/

  

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-08-09

³õ´Î°ä²¼

 

Îå¡¢¸½Â¼

5.1 GA»Æ½ð¼×¼ò½é

GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Äê £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏà £¬¹«Ë¾Ô±¹¤6000ÓàÈË £¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ £¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£

5.2 ¹ØÓÚGA»Æ½ð¼×

GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯ £¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶ £¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png