¡¾·ì϶¹«¸æ¡¿Î¢Èí12Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2023-12-13
 

Ò»¡¢·ì϶¸ÅÊö

2023Äê12ÔÂ12ÈÕ£¬Î¢Èí°ä²¼ÁË12Ô°²È«¸üУ¬±¾´Î¸üй²½¨¸´ÁË36¸ö·ì϶£¨²»Ô̺¬12ÔÂ7ÈÕ½¨¸´µÄ8¸öMicrosoft Edge·ì϶£©£¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶ºÍºýŪ·ì϶µÈ¡£

±¾´Î°²È«¸üн¨¸´ÁË1¸öÒÑÓÚ8ÔÂÅû¶µ«Ö®Ç°ÉÐ佨¸´µÄAMD 0 day·ì϶£º

CVE-2023-20588- AMD£ºAMD´§Ä¦ÐÔй¶·ì϶£¨ÖÐΣ£©

ijЩ AMD ´¦ÖÃÆ÷ÉÏ´æÔÚ³ýÁãÃýÎ󣬿ÉÄܵ¼Ö·µ»Ø´§Ä¦Êý¾Ý£¬Ôì³ÉÐÅϢй¶¡£

ÆÀ¼¶ÎªÑϳÁµÄ4¸ö·ì϶Ô̺¬£º

CVE-2023-36019£ºMicrosoft Power Platform ConnectorºýŪ·ì϶£¨ÑϳÁ£©

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.6£¬¿Éͨ¹ýÓÕµ¼Óû§µ¥»÷ÌØÔìµÄ URLÀ´ÀûÓø÷ì϶£¬¿ÉÄܵ¼Ö¶ñÒâ¾ç±¾ÔÚÊܺ¦ÕßÍÆËã»úÉϵÄä¯ÀÀÆ÷ÖÐÖ´ÐС£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס±¡£

CVE-2023-35630£ºInternet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´Ðзì϶£¨¸ßΣ£©

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8£¬³É¹¦ÀûÓø÷ì϶±ØÒªÅú¸ÄDHCPv6 DHCPv6_MESSAGE_INFORMATION_REQUESTÊäÈëÐÂÎÅÖеÄoption->length×ֶΡ£¸Ã·ì϶²»ÄÜ¿ç¶à¸öÍøÂ磨ÈçWAN£©ÀûÓã¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס±¡£

CVE-2023-35641£ºInternet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´Ðзì϶£¨¸ßΣ£©

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8£¬¿Éͨ¹ýÏòÔËÐÐ Internet Ïνӹ²Ïí·þÎñµÄ·þÎñÆ÷·¢ËͶñÒâÔì×÷µÄ DHCP ÐÂÎÅÀ´ÀûÓø÷ì϶¡£¸Ã·ì϶²»ÄÜ¿ç¶à¸öÍøÂ磨ÈçWAN£©ÀûÓã¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϴ󡱡£

CVE-2023-35628£ºWindows MSHTML PlatformÔ¶³Ì´úÂëÖ´Ðзì϶£¨¸ßΣ£©

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.1£¬Äܹ»ÔÚÎÞÐèÓû§½»»¥µÄÇé¿öÏÂÔ¶³ÌÀûÓ㬵«¹¥»÷¸´ÔӶȽϸß¡£ÍþвÕß¿Éͨ¹ýµç×ÓÓʼþ»òÆäËû·½Ê½ÏòÊܺ¦Õß·¢ËͶñÒâÁ´½Ó²¢ÓÕµ¼Óû§µ¥»÷¶ñÒâÁ´½ÓÀ´ÀûÓø÷ì϶£»»òÕßÄܹ»Í¨¹ý·¢ËÍÌØÔìµç×ÓÓʼþÀ´ÀûÓø÷ì϶£¬¸Ãµç×ÓÓʼþ¿ÉÄÜ»áÔÚOutlook ¿Í»§¶Ë¼ìË÷ºÍ´¦ÖÃʱ×Ô¶¯´¥·¢£¬¶øÎÞÐèÊܺ¦Õß´ò¿ª¡¢ÔĶÁ»òµ¥»÷Á´½Ó£¬Õâ¿ÉÄܻᵼÖÂÔÚÔ¤ÀÀ´°¸ñÖв鿴µç×ÓÓʼþ֮ǰ±»ÀûÓᣳɹ¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂÔÚÊܺ¦ÕßµÄÍÆËã»úÉÏÔ¶³ÌÖ´ÐдúÂ롣΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϴ󡱡£

³ýÁËCVE-2023-35641ºÍCVE-2023-35628±í£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÓ×°±»ÀûÓõĿÉÄÜÐԽϴ󡱵ķì϶»¹Ô̺¬£º

CVE-2023-35631£ºWin32k ÌØÈ¨ÌáÉý·ì϶

CVE-2023-35632£ºWindows Ancillary Function Driver for WinSockÌØÈ¨ÌáÉý·ì϶

CVE-2023-35633£ºWindows KernelÌØÈ¨ÌáÉý·ì϶

CVE-2023-35644£ºWindows Sysmain ServiceÌØÈ¨ÌáÉý·ì϶

CVE-2023-36005£ºWindows Telephony Server ÌØÈ¨ÌáÉý·ì϶

CVE-2023-36010£ºMicrosoft Defender»Ø¾ø·þÎñ·ì϶

CVE-2023-36011£ºWin32k ÌØÈ¨ÌáÉý·ì϶

CVE-2023-36391£ºLocal Security Authority Subsystem ServiceȨÌáÉý·ì϶

CVE-2023-36696£ºWindows Cloud Files Mini Filter DriverÌØÈ¨ÌáÉý·ì϶

΢Èí12Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º

CVE ID

CVE ±êÌâ

ÑϳÁÐÔ

CVE-2023-36019

Microsoft Power Platform Connector ºýŪ·ì϶

ÑϳÁ

CVE-2023-35630

Internet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-35641

Internet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-35628

Windows MSHTML Platform Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-35624

Azure Connected Machine Agent ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2023-35625

Azure Machine Learning Compute   Instance for SDK Óû§ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-20588

AMD£ºCVE-2023-20588 AMD ´§Ä¦ÐÔй¶°²È«Í¨Öª

¸ßΣ

CVE-2023-35634

Windows Bluetooth Driver Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35621

Microsoft Dynamics 365 Finance and   Operations »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36020

Microsoft Dynamics 365 (on-premises) ¿çÕ¾µã¾ç±¾·ì϶

¸ßΣ

CVE-2023-35636

Microsoft Outlook ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-35619

Microsoft Outlook for Mac ºýŪ·ì϶

¸ßΣ

CVE-2023-36009

Microsoft Word ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36006

Microsoft WDAC OLE DB provider for   SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35622

Windows DNS ºýŪ·ì϶

¸ßΣ

CVE-2023-36696

Windows Cloud Files Mini Filter   Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36010

Microsoft Defender »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-35643

DHCP Server Service ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-35638

DHCP Server Service »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36012

DHCP Server Service ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36004

Windows DPAPI£¨Êý¾Ý±£»¤ÀûÓ÷¨Ê½±à³Ì½Ó¿Ú£©ºýŪ·ì϶

¸ßΣ

CVE-2023-35642

Internet Connection Sharing (ICS) »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-35632

Windows Ancillary Function Driver for   WinSock ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35633

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35635

Windows Äں˻ؾø·þÎñ·ì϶

¸ßΣ

CVE-2023-35644

Windows Sysmain Service ȨÏÞÌáÉý

¸ßΣ

CVE-2023-36391

Local Security Authority Subsystem   Service ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-21740

Windows Media Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35639

Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36005

Windows Telephony Server ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2023-35629

Microsoft USBHUB 3.0 Device Driver Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36011

Win32k ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35631

Win32k ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36003

XAML Diagnostics ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35618

Microsoft Edge£¨»ùÓÚ Chromium£©È¨ÏÞÌáÉý·ì϶

ÖÐΣ

CVE-2023-36880

Microsoft Edge£¨»ùÓÚChromium£©ÐÅϢй¶·ì϶

µÍΣ

CVE-2023-38174

Microsoft Edge£¨»ùÓÚChromium£©ÐÅϢй¶·ì϶

µÍΣ

CVE-2023-6509

Chromium£ºCVE-2023-6509 ÔÚSide Panel SearchÖÐUse-after-free

δ֪

CVE-2023-6512

Chromium£ºCVE-2023-6512 Web ä¯ÀÀÆ÷ UI ÖеÄÖ´Ðв»µ±

δ֪

CVE-2023-6508

Chromium£ºCVE-2023-6508 ÔÚMedia StreamÖÐUse-after-free

δ֪

CVE-2023-6511

Chromium£ºCVE-2023-6511 ×Ô¶¯Ìî³äÖеÄÖ´Ðв»µ±

δ֪

CVE-2023-6510

Chromium£ºCVE-2023-6510 ÔÚMedia CaptureÖÐUse-after-free

δ֪

 


¶þ¡¢Ó°ÏìÁìÓò

ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º

Windows Media

Microsoft Edge (Chromium-based)

Microsoft Office Outlook

Microsoft Dynamics

Microsoft Windows DNS

Azure Connected Machine Agent

Azure Machine Learning

Windows MSHTML Platform

Windows USB Mass Storage Class Driver

Windows Internet Connection Sharing (ICS)

Windows Win32K

Windows Kernel

Microsoft Bluetooth Driver

Windows DHCP Server

Windows ODBC Driver

Windows Kernel-Mode Drivers

XAML Diagnostics

Windows DPAPI (Data Protection Application Programming Interface)

Windows Telephony Server

Microsoft WDAC OLE DB provider for SQL

Microsoft Office Word

Windows Defender

Microsoft Power Platform Connector

Windows Local Security Authority Subsystem Service (LSASS)

Windows Cloud Files Mini Filter Driver

 

Èý¡¢°²È«´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2023Äê12Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2023-Dec

²¹¶¡ÏÂÔØÊ¾Àý£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2022Äê2Ô£©

2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£

3.2 һʱ´ëÊ©

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2023-Dec

https://www.bleepingcomputer.com/news/microsoft/microsoft-december-2023-patch-tuesday-fixes-34-flaws-1-zero-day/

https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7007.html

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-12-13

³õ´Î°ä²¼

 

 

Îå¡¢¸½Â¼

5.1 GA»Æ½ð¼×¼ò½é

GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£

5.2 ¹ØÓÚGA»Æ½ð¼×

GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png