¡¾·ì϶¹«¸æ¡¿Î¢Èí10Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2023-10-11Ò»¡¢·ì϶¸ÅÊö
2023Äê10ÔÂ10ÈÕ£¬Î¢Èí°ä²¼ÁË10Ô°²È«¸üУ¬±¾´Î¸üй²½¨¸´ÁË104¸ö·ì϶£¨²»Ô̺¬Microsoft Edge-Chromium·ì϶£©£¬ÆäÖÐÔ̺¬3¸öÒѱ»ÀûÓõķì϶¡¢45¸öÔ¶³Ì´úÂëÖ´Ðзì϶ÒÔ¼°12¸öÆÀ¼¶ÎªÑϳÁµÄ·ì϶¡£
±¾´Î½¨¸´µÄ·ì϶ÖУ¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶ºÍºýŪ·ì϶µÈ¡£
΢Èí±¾´Î¹²½¨¸´ÁË3¸öÒѱ»ÀûÓõķì϶£º
CVE-2023-41763£ºSkype for Business ȨÏÞÌáÉý·ì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ5.3£¬Ô¶³ÌÍþвÕßÄܹ»¶ÔÖ¸±ê Skype for Business ·þÎñÆ÷½øÐÐÌØÔìÍøÂçŲÓã¬Õâ¿ÉÄܵ¼Ö½âÎöÏòËÁÒâµØÖ··¢³öµÄ http ÒªÇ󣬴Ӷø¿ÉÄܵ¼ÖÂIP µØÖ·»ò¶Ë±êÓïµÈÃô¸ÐÐÅϢй¶£¬ÍþвÕß¿ÉÄÜÀûÓÃÕâЩÐÅÏ¢À´½Ó¼ûÄÚ²¿ÍøÂ硣Ŀǰ¸Ã·ì϶ÒѾ¹«¿ªÅû¶£¬ÇÒÒÑ·¢ÏÖ±»ÀûÓá£
CVE-2023-36563£ºMicrosoft WordPad ÐÅϢй¶·ì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ6.5£¬ÍþвÕßÄܹ»Í¨¹ýµÇ¼ϵͳÔËÐÐÌØÔìµÄÀûÓ÷¨Ê½»òÕßÓÕµ¼±¾µØÓû§´ò¿ª¶ñÒâÎļþÀ´ÀûÓø÷ì϶£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼Ö NTLM ¹þϣֵй¶¡£Ä¿Ç°¸Ã·ì϶ÒѾ¹«¿ªÅû¶£¬ÇÒÒÑ·¢ÏÖ±»ÀûÓá£
MITRE£ºCVE-2023-44487-HTTP/2 ¼±¾ç³ÁÖù¥»÷
΢ÈíÒѰ䲼Õë¶ÔHTTP/2 µÄÉ¢²¼Ê½»Ø¾ø·þÎñ (DDoS) ¹¥»÷£¨³ÆÎª¡°HTTP/2 Rapid Reset¡±£¬×·×ÙΪCVE-2023-44487£©µÄ»º½â´ëÊ©£¬¸Ã¹¥»÷ͨ¹ýÀÄÓà HTTP/2 µÄÒªÇóÈ¡µÞÖ°ÄÜ£¬¿ÉÄܵ¼Ö·þÎñÆ÷×ÊÔ´ºÄ¾¡£¬Ôì³É»Ø¾ø·þÎñ¡£¸Ã·ì϶×Ô8ÔÂÒÔÀ´Òѱ»¿í·ºÀûÓá£
΢Èí±¾´Î¸üн¨¸´µÄ12¸öÆÀ¼¶Îª¡°ÑϳÁ¡±µÄ·ì϶Ô̺¬£º
9¸öΪµÚ2²ãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-41770¡¢CVE-2023-41765¡¢CVE-2023-41767¡¢CVE-2023-38166¡¢CVE-2023-41774¡¢CVE-2023-41773¡¢CVE-2023-41771¡¢CVE-2023-41769ºÍCVE-2023-41768£©£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕßÄܹ»Ïò·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) ·þÎñÆ÷·¢ËÍÌØÔìµÄºÍ̸ÐÂÎÅ£¬¿ÉÄܵ¼Ö RAS ·þÎñÆ÷ÍÆËã»úÉϵÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©£¬µ«ÀûÓÃÕâЩ·ì϶¿ÉÄܱØÒªÓ®µÃ¾ºÕùǰÌá¡£
2¸öΪMicrosoftÐÂÎŶÓÁÐÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-35349ºÍCVE-2023-36697£©£¬³É¹¦ÀûÓÃCVE-2023-35349¿ÉÄܵ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄÍþвÕßÔÚÖ¸±ê·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë¡£³É¹¦ÀûÓÃCVE-2023-36697¿ÉÄܵ¼Ö¾¹ýÉí·ÝÑéÖ¤µÄÓòÓû§ÔÚÖ¸±ê·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂ룬µ«ÍþвÕß±ØÒªÓÕµ¼Ö¸±êÍÆËã»úÉϵÄÓû§Ïνӵ½¶ñÒâ·þÎñÆ÷£¬»òÕß·ÛËéºÏ·¨µÄMSMQ·þÎñÆ÷Ö÷»ú£¬Ê¹Æä×÷Ϊ¶ñÒâ·þÎñÆ÷ÔËÐС£Windows ÐÂÎŶÓÁзþÎñÊÇ Windows ×é¼þ£¬Äܹ»Í¨¹ý²é³ÊÇ·ñÓÐÃûΪMessage QueuingµÄ·þÎñÔÚÔËÐУ¬ÒÔ¼°ÍÆËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£
ÒÔ¼°MicrosoftÐé¹¹¿ÉÐÅÆ½Ì¨Ä£¿é£¨TPM£©Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-36718£©£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐУ¬µ«ÍþвÕß±ØÐëͨ¹ýguestģʽÓû§µÄÉí·ÝÑéÖ¤ÄÜÁ¦ÌÓÀëÐé¹¹»ú¡£
΢Èí10Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑϳÁÐÔ |
CVE-2023-41770 | Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-41765 | Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-41767 | Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-38166 | Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-41774 | Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-41773 | Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-41771 | Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-41769 | Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-41768 | Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-35349 | Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-36697 | Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-36718 | Microsoft Virtual Trusted Platform Module Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-36722 | Active DirectoryÓò·þÎñÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36737 | Azure Network Watcher VM Agent ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36419 | Azure HDInsight Apache Oozie ¹¤×÷Á÷µ÷¶È·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36561 | Azure DevOps ·þÎñÆ÷ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36418 | Azure RTOS GUIX Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36414 | Azure Identity SDK Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36415 | Azure Identity SDK Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-41766 | Windows ¿Í»§¶Ë·þÎñÆ÷ÔËÐÐʱ×Óϵͳ (CSRSS) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-44487 | MITRE£ºCVE-2023-44487 HTTP/2 ¼±¾ç³ÁÖù¥»÷ | ¸ßΣ |
CVE-2023-36566 | Microsoft ͨÓÃÊý¾ÝÄ£ÐÍ SDK »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36429 | Microsoft Dynamics 365£¨On-Premises£©ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36416 | Microsoft Dynamics 365£¨On-Premises£©¿çÕ¾¾ç±¾·ì϶ | ¸ßΣ |
CVE-2023-36433 | Microsoft Dynamics 365£¨On-Premises£©ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36778 | Microsoft Exchange Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36594 | Windows Graphics Component ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-38159 | Windows Graphics Component ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36565 | Microsoft Office Graphics ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36569 | Microsoft Office ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36568 | Microsoft Office Click-To-Run ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-38171 | Microsoft QUIC »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36435 | Microsoft QUIC »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36577 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36710 | Windows Media Foundation Core Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36564 | Windows Search °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-36563 | Microsoft WordPad ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36786 | Skype for Business Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36780 | Skype for Business Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36789 | Skype for Business Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-41763 | Skype for Business ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36728 | Microsoft SQL Server »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36417 | Microsoft SQL ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36785 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36598 | Microsoft WDAC ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36730 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36420 | Microsoft ODBC Driver for SQL Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36585 | Active Template Library »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36709 | Microsoft AllJoyn API »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36902 | Windows Runtime Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36713 | Windows Common Log File System Driver ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36723 | Windows Container Manager Service ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36707 | Windows Deployment ·þÎñ»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36567 | Windows Deployment ·þÎñÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36706 | Windows Deployment ·þÎñÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36703 | DHCP Server Service »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36721 | Windows ÃýÎó»ã±¨·þÎñÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36436 | Windows MSHTMLƽ̨Զ³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36557 | PrintHTML API Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36434 | Windows IIS ·þÎñÆ÷ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36726 | Windows Internet ÃÜÔ¿»¥»» (IKE) À©´óÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36576 | Windows ÄÚºËÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36712 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36698 | Windows Äں˰²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-36584 | Windows Mark of the Web °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-36571 | Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36570 | Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36431 | Microsoft Message Queuing »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36591 | Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36590 | Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36589 | Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36583 | Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36592 | Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36606 | Microsoft Message Queuing »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36593 | Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36582 | Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36574 | Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36575 | Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36573 | Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36572 | Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36581 | Microsoft Message Queuing »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36579 | Microsoft Message Queuing »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36578 | Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36702 | Microsoft DirectMusic Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36720 | Windows Mixed Reality Developer Tools »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36729 | Named Pipe File System ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36605 | Windows Named Pipe Filesystem ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36725 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36724 | Windows µçÔ´ÖÎÀí·þÎñÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36790 | Windows RDP Encoder Mirror Driver ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-29348 | Windows Remote Desktop Gateway (RD Gateway)ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36596 | Remote Procedure Call ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36701 | Microsoft µ¯ÐÔÎļþϵͳ (ReFS) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36711 | Windows Runtime C++ Template Library ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36704 | Windows Setup Files Cleanup Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36438 | Windows TCP/IP ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36603 | Windows TCP/IP »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36602 | Windows TCP/IP »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36717 | Windows Virtual Trusted Platform Module »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36731 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36732 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36776 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36743 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-41772 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-5346 | Chromium£ºCVE-2023-5346 V8 ÖеÄÀàÐÍ»ìºÏ | δ֪ |
¶þ¡¢Ó°ÏìÁìÓò
ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º
Windows RDP
Windows Message Queuing
Azure SDK
Microsoft Dynamics
SQL Server
Azure Real Time Operating System
Azure
Windows IIS
Microsoft QUIC
Windows HTML Platform
Windows TCP/IP
Azure DevOps
Microsoft WordPad
Microsoft Windows Search Component
Microsoft Office
Microsoft Common Data Model SDK
Windows Deployment Services
Windows Kernel
Microsoft WDAC OLE DB provider for SQL
Windows Mark of the Web (MOTW)
Windows Active Template Library
Microsoft Graphics Component
Windows Remote Procedure Call
Windows Named Pipe File System
Windows Resilient File System (ReFS)
Windows Microsoft DirectMusic
Windows DHCP Server
Windows Setup Files Cleanup
Windows AllJoyn API
Microsoft Windows Media Foundation
Windows Runtime C++ Template Library
Windows Common Log File System Driver
Windows TPM
Windows Virtual Trusted Platform Module
Windows Mixed Reality Developer Tools
Windows Error Reporting
Active Directory Domain Services
Windows Container Manager Service
Windows Power Management Service
Windows NT OS Kernel
Windows IKE Extension
Windows Win32K
Microsoft Exchange Server
Skype for Business
Windows Client/Server Runtime Subsystem
Windows Layer 2 Tunneling Protocol
Client Server Run-time Subsystem (CSRSS)
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2023Äê10Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2023-oct
²¹¶¡ÏÂÔØÊ¾Àý£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2022Äê2Ô£©
2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£
3.2 һʱ´ëÊ©
¹ØÓÚHTTP/2 ¼±¾ç³ÁÖù¥»÷£¨CVE-2023-44487£©·ì϶£¬Î¢ÈíµÄ»º½â´ëÊ©¿É²Î¿¼£º
https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/
Cloudflare¡¢Google¡¢AWS¡¢NGINXµÈÕë¶Ô¸Ã·ì϶µÄ»º½âºÍÏìÓ¦¿É²Î¿¼£º
https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2023-oct
https://www.bleepingcomputer.com/news/microsoft/microsoft-october-2023-patch-tuesday-fixes-3-zero-days-104-flaws/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-10-11 | ³õ´Î°ä²¼ |
Îå¡¢¸½Â¼
5.1 GA»Æ½ð¼×¼ò½é
GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£
5.2 ¹ØÓÚGA»Æ½ð¼×
GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ