¡¾·ì϶¹«¸æ¡¿Î¢Èí11Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2023-11-15Ò»¡¢·ì϶¸ÅÊö
2023Äê11ÔÂ14ÈÕ£¬Î¢Èí°ä²¼ÁË11Ô°²È«¸üУ¬±¾´Î¸üй²½¨¸´ÁË58¸ö·ì϶£¨²»Ô̺¬Ö®Ç°°ä²¼µÄMicrosoft EdgeµÈ°²È«¸üУ©£¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶ºÍºýŪ·ì϶µÈ¡£
±¾´Î°²È«¸üй²½¨¸´ÁË5¸ö0 day·ì϶£¬ÆäÖÐ3¸öÒÑ·¢´Ë¿Ì¹¥»÷Öб»ÀûÓã¬3¸öÒѾ¹«¿ªÅû¶¡£CVE-2023-36033ĿǰÒѾ¹«¿ªÅû¶£¬ÇÒÒÑ·¢ÏÖ±»ÀûÓá£ÏêÇéÈçÏ£º
CVE-2023-36036£ºWindows Cloud Files Mini Filter DriverÌØÈ¨ÌáÉý·ì϶£¨¸ßΣ£©
Windows ÔÆÎļþÃÔÄã¹ýÂËÆ÷Çý¶¯·¨Ê½ÖдæÔÚ±¾µØÈ¨ÏÞÌáÉý·ì϶£¬³É¹¦ÀûÓø÷ì϶Äܹ»»ñµÃSYSTEMȨÏÞ¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.8£¬Ä¿Ç°ÒÑ·¢ÏÖ±»ÀûÓá£
CVE-2023-36033£ºWindows DWM Core Library ÌØÈ¨ÌáÉý·ì϶£¨¸ßΣ£©
Windows DWM Ö÷Ìâ¿âÖдæÔÚ±¾µØÈ¨ÏÞÌáÉý·ì϶£¬³É¹¦ÀûÓø÷ì϶Äܹ»»ñµÃSYSTEMȨÏÞ¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.8£¬Ä¿Ç°ÒѾ¹«¿ªÅû¶£¬ÇÒÒÑ·¢ÏÖ±»ÀûÓá£
CVE-2023-36025£ºWindows SmartScreen°²È«Ö°ÄÜÈÆ¹ý·ì϶£¨¸ßΣ£©
Windows SmartScreen´æÔÚ°²È«Ö°ÄÜÈÆ¹ý·ì϶£¬³É¹¦ÀûÓø÷ì϶¿ÉÈÆ¹ý Windows Defender SmartScreen ²é³¼°ÆäÓйØÌáÐÑ£¬ÀûÓø÷ì϶±ØÒªÓû§½»»¥£¬ºÃ±ÈÓû§Ðëµ¥»÷ÌØÔìµÄ Internet ¿ì½Ý·½Ê½ (.URL) »òÖ¸Ïò Internet ¿ì½Ý·½Ê½ÎļþµÄ³¬Á´½ÓµÈ¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.8£¬Ä¿Ç°ÒÑ·¢ÏÖ±»ÀûÓá£
CVE-2023-36413£ºMicrosoft Office°²È«Ö°ÄÜÈÆ¹ý·ì϶£¨¸ßΣ£©
Microsoft OfficeÖдæÔÚ°²È«Ö°ÄÜÈÆ¹ý·ì϶£¬Äܹ»Í¨¹ýÏòÓû§·¢ËͶñÒâÎļþ²¢ÓÕµ¼Óû§´ò¿ªÎļþÀ´ÀûÓø÷ì϶£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÈÆ¹ý Office Êܱ£»¤µÄÊÓͼ²¢ÒÔ±à×ëģʽ¶ø²»ÊDZ£»¤Ä£Ê½´ò¿ª¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ6.5£¬Ä¿Ç°ÒѾ¹«¿ªÅû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°¿ÉÄܱ»ÀûÓᱡ£
CVE-2023-36038£ºASP.NET Core »Ø¾ø·þÎñ·ì϶£¨¸ßΣ£©
ASP.NET Core´æÔڻؾø·þÎñ·ì϶£¬ÈôÊÇÈ¡µÞ¶ÔIIS InProcessÍйÜÄ£ÐÍÉÏÔËÐеÄ.NET 8 RC 1µÄhttpÒªÇó£¬ÔòÄܹ»ÀûÓø÷ì϶£¬Ê¹µÃÏ̼߳ÆÊýÔö³¤£¬²¢ÇÒ¿ÉÄÜ»á³öÏÖ OutOfMemoryException£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼Ö»ؾø·þÎñ¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.2£¬Ä¿Ç°ÒѾ¹«¿ªÅû¶¡£
ÆÀ¼¶ÎªÑϳÁµÄ3¸ö·ì϶ÏêÇéÈçÏ£º
CVE-2023-36052 £ºAzure CLI REST CommandÐÅϢй¶·ì϶£¨ÑϳÁ£©
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.6£¬³É¹¦ÀûÓø÷ì϶Äܹ»´ÓÊÜÓ°ÏìµÄCLIºÅÁî´´½¨²¢ÓÉAzure DevOps»òGitHub Actions°ä²¼µÄÈÕÖ¾ÎļþÖи´ÔÃ÷ÎÄÃÜÂëºÍÓû§Ãû¡£Ê¹ÓÃÊÜÓ°ÏìµÄ CLI ºÅÁîµÄÓû§Ð뽫Æä Azure CLI °æ±¾¸üе½ 2.53.1»ò¸ü¸ß°æÕý±¾»º½â¸Ã·ì϶£¬ÕâÒ²ºÏÓÃÓÚͨ¹ý Azure DevOps »ò GitHub Actions ʹÓÃÕâЩºÅÁî´´½¨ÈÕÖ¾ÎļþµÄÓû§¡£
CVE-2023-36400£ºWindows HMAC Key DerivationÌØÈ¨ÌáÉý·ì϶£¨ÑϳÁ£©
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.8£¬ÍþвÕßÄܹ»´ÓµÍȨÏÞµÄ Hyper-V guestÖ´Ðй¥»÷£¬´©Ô½guestµÄ°²È«Ììǵ£¬ÔÚ Hyper-V Ö÷»úÖ´Ðл·¾³ÉÏÖ´ÐдúÂë¡£³É¹¦ÀûÓø÷ì϶Äܹ»»ñµÃSYSTEMȨÏÞ¡£
CVE-2023-36397£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´Ðзì϶£¨ÑϳÁ£©
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.8£¬µ±WindowsÐÂÎŶÓÁзþÎñÔËÐÐÔÚPGM Server»·¾³ÖÐʱ£¬Äܹ»Í¨¹ýÍøÂç·¢ËÍÌØÔìÎļþÀ´ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£Windows ÐÂÎŶÓÁзþÎñÊÇ Windows ×é¼þ£¨Äܹ»Í¨¹ý¹Ø¹Ø¸Ã×é¼þÀ´»º½â¸Ã·ì϶£©£¬Äܹ»Í¨¹ý²é³ÊÇ·ñÓÐÃûΪMessage QueuingµÄ·þÎñÔÚÔËÐУ¬ÒÔ¼°ÍÆËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£
΢Èí11Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑϳÁÐÔ |
CVE-2023-36052 | Azure CLI REST Command ÐÅϢй¶·ì϶ | ÑϳÁ |
CVE-2023-36400 | Windows HMAC Key Derivation ÌØÈ¨ÌáÉý·ì϶ | ÑϳÁ |
CVE-2023-36397 | Windows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-36049 | .NET¡¢.NET Framework ºÍ Visual Studio ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36560 | ASP.NET °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-36038 | ASP.NET Core »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36558 | ASP.NET Core °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-38151 | Microsoft Host Integration Server 2020 Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36021 | Microsoft On-Prem Êý¾ÝÍø¹Ø°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-36437 | Azure DevOps Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24023 | Mitre£ºCVE-2023-24023 À¶ÑÀ·ì϶ | ¸ßΣ |
CVE-2023-36016 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾·ì϶ | ¸ßΣ |
CVE-2023-36007 | Microsoft Send Customer Voice survey from Dynamics 365 ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-36031 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾·ì϶ | ¸ßΣ |
CVE-2023-36410 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾·ì϶ | ¸ßΣ |
CVE-2023-36030 | Microsoft Dynamics 365 Sales ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-36027 | Microsoft Edge£¨»ùÓÚ Chromium£©È¨ÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36024 | Microsoft Edge£¨»ùÓÚ Chromium£©È¨ÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36439 | Microsoft Exchange Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36050 | Microsoft Exchange Server ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-36039 | Microsoft Exchange Server ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-36035 | Microsoft Exchange Server ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-36413 | Microsoft Office °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-36045 | Microsoft Office Graphics Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36041 | Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36037 | Microsoft Excel °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-38177 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36423 | Microsoft Remote Registry Service Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36401 | Microsoft Remote Registry Service Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36402 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36394 | Windows Search Service ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36719 | Microsoft Speech Application Programming Interface (SAPI) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36043 | Open Management Infrastructure ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36393 | Windows User Interface Application Core Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36042 | Visual Studio »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36018 | Visual Studio Code Jupyter Extension ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-36047 | Windows Authentication ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36428 | Microsoft Local Security Authority Subsystem Service ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36046 | Windows Authentication »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36036 | Windows Cloud Files Mini Filter Driver ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36424 | Windows Common Log File System Driver ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36396 | Windows Compressed Folder Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36422 | Microsoft Windows Defender ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36395 | Windows Deployment Services »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36392 | DHCP Server Service »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36425 | Windows É¢²¼Ê½Îļþϵͳ (DFS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36033 | Windows DWM Core Library ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36427 | Windows Hyper-V ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36407 | Windows Hyper-V ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36406 | Windows Hyper-V ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36408 | Windows Hyper-V ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36705 | Windows Installer ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36405 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36404 | Windows ÄÚºËÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36403 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36398 | Windows NTFSÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36028 | Microsoft Protected Extensible Authentication Protocol (PEAP) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36017 | Windows Scripting Engine ÄÚ´æ°Ü»µ·ì϶ | ¸ßΣ |
CVE-2023-36025 | Windows SmartScreen°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-36399 | Windows Storage ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36014 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´Ðзì϶ | ÖÐΣ |
CVE-2023-36022 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´Ðзì϶ | ÖÐΣ |
CVE-2023-36029 | Microsoft Edge£¨»ùÓÚ Chromium£©ºýŪ·ì϶ | ÖÐΣ |
CVE-2023-36034 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´Ðзì϶ | ÖÐΣ |
CVE-2023-5996 | Chromium£ºCVE-2023-5996 ÔÚ WebAudio ÖпªÊͺóʹÓà | δ֪ |
CVE-2023-5480 | Chromium£ºCVE-2023-5480 Ö§¸¶ÖÐÖ´Ðв»µ± | δ֪ |
CVE-2023-5856 | Chromium£ºCVE-2023-5856 ÔÚ²àÃæ°åÖпªÊͺóʹÓà | δ֪ |
CVE-2023-5855 | Chromium£ºCVE-2023-5855 ÔÚÔĶÁģʽÏ¿ªÊͺóʹÓà | δ֪ |
CVE-2023-5854 | Chromium£ºCVE-2023-5854 ÔÚÅäÖÃÎļþÖпªÊͺóʹÓà | δ֪ |
CVE-2023-5859 | Chromium£ºCVE-2023-5859 »ÖлÖеݲȫ UI ²»ÕýÈ· | δ֪ |
CVE-2023-5858 | Chromium£ºCVE-2023-5858 WebApp Provider ÖеÄÖ´Ðв»µ± | δ֪ |
CVE-2023-5857 | Chromium£ºCVE-2023-5857 ÏÂÔØÖеIJ»µ±Ö´ÐÐ | δ֪ |
CVE-2023-5850 | Chromium£ºCVE-2023-5850 ÏÂÔØÖеݲȫ UI ²»ÕýÈ· | δ֪ |
CVE-2023-5849 | Chromium£ºCVE-2023-5849 USB ÖеÄÕûÊýÒç³ö | δ֪ |
CVE-2023-5482 | Chromium£ºCVE-2023-5482 USB ÖÐÊý¾ÝÑéÖ¤²»¼° | δ֪ |
CVE-2023-5853 | Chromium£ºCVE-2023-5853 ÏÂÔØÖеݲȫ UI ²»ÕýÈ· | δ֪ |
CVE-2023-5852 | Chromium£ºCVE-2023-5852 ÔÚ´òÓ¡ÖпªÊͺóʹÓà | δ֪ |
CVE-2023-5851 | Chromium£ºCVE-2023-5851 ÏÂÔØÖÐÖ´Ðв»µ± | δ֪ |
CVE-2020-1747 | δ֪ | δ֪ |
CVE-2023-46316 | δ֪ | δ֪ |
CVE-2023-46753 | δ֪ | δ֪ |
CVE-2020-8554 | δ֪ | δ֪ |
CVE-2020-14343 | δ֪ | δ֪ |
¶þ¡¢Ó°ÏìÁìÓò
ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º
Microsoft Dynamics
Microsoft Edge (Chromium-based)
Windows Scripting
Visual Studio Code
Azure
Windows SmartScreen
Windows Protected EAP (PEAP)
Microsoft Dynamics 365 Sales
Windows DWM Core Library
Microsoft Exchange Server
Windows Cloud Files Mini Filter Driver
Microsoft Office Excel
ASP.NET
Visual Studio
Open Management Infrastructure
Microsoft Office
Windows Authentication Methods
.NET Framework
Windows DHCP Server
Tablet Windows User Interface
Microsoft Windows Search Component
Windows Deployment Services
Windows Compressed Folder
Windows Internet Connection Sharing (ICS)
Windows NTFS
Windows Storage
Windows HMAC Key Derivation
Microsoft Remote Registry Service
Microsoft WDAC OLE DB provider for SQL
Windows Kernel
Windows Hyper-V
Windows Defender
Windows Common Log File System Driver
Windows Distributed File System (DFS)
Azure DevOps
Windows Installer
Microsoft Windows Speech
Microsoft Office SharePoint
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2023Äê11Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2023-Nov
²¹¶¡ÏÂÔØÊ¾Àý£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2022Äê2Ô£©
2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2023-Nov
https://www.bleepingcomputer.com/news/microsoft/microsoft-november-2023-patch-tuesday-fixes-5-zero-days-58-flaws/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-11-15 | ³õ´Î°ä²¼ |
Îå¡¢¸½Â¼
5.1 GA»Æ½ð¼×¼ò½é
GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£
5.2 ¹ØÓÚGA»Æ½ð¼×
GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ