¡¾·ì϶¹«¸æ¡¿Î¢Èí2Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2024-02-19Ò»¡¢·ì϶¸ÅÊö
2024Äê2ÔÂ13ÈÕ£¬Î¢Èí°ä²¼ÁË2Ô°²È«¸üУ¬±¾´Î¸üй²½¨¸´ÁË73¸ö·ì϶£¨²»Ô̺¬2ÔÂ8ÈÕ½¨¸´µÄMicrosoft EdgeºÍÆäËü·ì϶£©£¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶ºÍºýŪ·ì϶µÈ¡£
±¾´Î°²È«¸üÐÂÖÐÔ̺¬2¸ö±»»ý¼«ÀûÓõÄ0 day·ì϶£º
CVE-2024-21351£ºWindows SmartScreen °²È«Ö°ÄÜÈÆ¹ý·ì϶
¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.6£¬ÍþвÕß¿ÉÏòÓû§·¢ËͶñÒâÎļþ²¢ÓÕµ¼Óû§´ò¿ªÎļþÀ´ÀûÓø÷ì϶£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÈÆ¹ý SmartScreen°²È«Ö°ÄÜ¡£¸Ã·ì϶ÔÊÐíÍþвÕß½«´úÂë×¢Èë SmartScreen ²¢¿ÉÄÜ»ñµÃ´úÂëÖ´ÐÐȨÏÞ£¬´Ó¶ø¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢ÏµÍ³¿ÉÓÃÐÔÓ°Ï죬Ŀǰ¸Ã·ì϶ÒѼì²âµ½·ì϶ÀûÓá£
CVE-2024-21412£ºInternet ¿ì½Ý·½Ê½Îļþ°²È«Ö°ÄÜÈÆ¹ý·ì϶
¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.1£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕßÄܹ»ÏòÖ¸±êÓû§·¢ËÍÖ¼ÔÚÈÆ¹ýÏÔʾµÄ°²È«²é³µÄÌØÔìÎļþ²¢ÓÕµ¼Óû§´ò¿ª¸ÃÎļþ£¬µ¼Ö°²È«Ö°ÄÜÈÆ¹ý¡£ÒÑ·¢ÏÖAPT×éÖ¯Water Hydra£¨±ðÃû DarkCasino£©ÔÚÕë¶Ô½ðÈÚÂòÂôÕߵĻÖлý¼«ÀûÓø÷ì϶¡£
±¾´Î°²È«¸üÐÂÖУ¬ÆÀ¼¶Îª¡°ÑϳÁ¡±µÄ5¸ö·ì϶Ô̺¬£º
CVE-2024-21380£ºMicrosoft Dynamics Business Central/NAV ÐÅϢй¶·ì϶
¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.0£¬³É¹¦ÀûÓø÷ì϶±ØÒª¾¹ýÉí·ÝÑéÖ¤¡¢Ó®µÃ¾ºÕùǰÌᣬ²¢±ØÒªÓû§½»»¥£¬³É¹¦ÀûÓø÷ì϶µÄÍþвÕßÄܹ»½Ó¼ûÓû§Êý¾Ý£¬µ¼ÖÂδÊÚȨ½Ó¼ûÊܺ¦ÕßµÄÕË»§»òй¶ÆäËü»úÃÜÐÅÏ¢¡£
CVE-2024-21410£ºMicrosoft Exchange Server ȨÏÞÌáÉý·ì϶
¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8£¬³É¹¦ÀûÓø÷ì϶µÄÍþвÕßÄܹ»½«Óû§Ð¹Â¶µÄNet-NTLMv2¹þÏ£Öм̵½Ò×Êܹ¥»÷µÄExchange Server£¬²¢ÒÔÓû§Éí·Ý½øÐÐÉí·ÝÑéÖ¤¡£ÊÜÓ°ÏìÓû§Ò²¿É²Î¿¼¹Ù·½ÌṩµÄÎĵµºÍ¾ç±¾Îª Exchange ServerÆôÓÃÉí·ÝÑéÖ¤À©´ó±£»¤ (EPA)À´»º½â¸Ã·ì϶£¬Ä¿Ç°¸Ã·ì϶ÒѼì²âµ½·ì϶ÀûÓá£
CVE-2024-21413£ºMicrosoft OutlookÔ¶³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂÈÆ¹ý Office Êܱ£»¤µÄÊÓͼ²¢ÒÔ±à×ëģʽ¶ø²»ÊDZ£»¤Ä£Ê½´ò¿ª£¬Ô¤ÀÀ´°¸ñÊǸ÷ì϶µÄÒ»¸ö¹¥»÷ý½é¡£ÍþвÕßÄܹ»´´½¨ÈƹýÊܱ£»¤ÊÓͼºÍ̸µÄ¶ñÒâÁ´½Ó£¬´Ó¶øµ¼Ö±¾µØNTLMÍ´´¦ÐÅϢй¶ºÍÔ¶³Ì´úÂëÖ´ÐС£
CVE-2024-20684£ºWindows Hyper-V »Ø¾ø·þÎñ·ì϶
¸Ã·ì϶µÄCVSSÆÀ·ÖΪ6.5£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼Ö Hyper-V guestÓ°Ïì Hyper-V Ö÷»úµÄÖ°ÄÜ¡£
CVE-2024-21357£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´Ðзì϶
Windows Pragmatic General Multicast (PGM) ²úÉúµÄ×é²¥Á÷Á¿ÔÚµÚ4 ²ãÔËÐв¢¿É·ÓÉ£¬ÍþвÕßÄܹ»Í¨¹ýÏòÒ×Êܹ¥»÷µÄ·þÎñÆ÷·¢ËÍÌØÔìµÄ¶ñÒâÁ÷Á¿À´ÀûÓø÷ì϶¡£¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.1£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£
³ýCVE-2024-21410ºÍCVE-2024-21357ÒÔ±í£¬±¾´Î°²È«¸üÐÂÖУ¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÓ×°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ·ì϶»¹Ô̺¬£º
CVE-2024-21338£ºWindows ÄÚºËÌØÈ¨ÌáÉý·ì϶
CVE-2024-21345£ºWindows ÄÚºËÌØÈ¨ÌáÉý·ì϶
CVE-2024-21346£ºWin32k ÌØÈ¨ÌáÉý·ì϶
CVE-2024-21371£ºWindows ÄÚºËÌØÈ¨ÌáÉý·ì϶
CVE-2024-21378£ºMicrosoft OutlookÔ¶³Ì´úÂëÖ´Ðзì϶
CVE-2024-21379£ºMicrosoft WordÔ¶³Ì´úÂëÖ´Ðзì϶
΢Èí2Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑϳÁÐÔ |
CVE-2024-21380 | Microsoft Dynamics Business Central/NAV ÐÅϢй¶·ì϶ | ÑϳÁ |
CVE-2024-21410 | Microsoft Exchange Server ȨÏÞÌáÉý·ì϶ | ÑϳÁ |
CVE-2024-21413 | Microsoft Outlook Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2024-20684 | Windows Hyper-V »Ø¾ø·þÎñ·ì϶ | ÑϳÁ |
CVE-2024-21357 | Windows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2024-21386 | .NET »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-21404 | .NET »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-21401 | Microsoft Entra Jira Single-Sign-On Plugin ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21381 | Microsoft Azure Active Directory B2C ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-21329 | Azure Connected Machine Agent ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-20667 | Azure DevOps Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21397 | Microsoft Azure File SyncȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-20679 | Azure Stack Hub ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-21412 | Internet ¿ì½Ý·½Ê½Îļþ°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-21349 | Microsoft ActiveX Êý¾Ý¶ÔÏóÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21403 | Microsoft Azure Kubernetes Service Confidential Container ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21376 | Microsoft Azure Kubernetes Service Confidential Container Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21315 | Microsoft Defender for Endpoint Protection ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21393 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾·ì϶ | ¸ßΣ |
CVE-2024-21389 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾·ì϶ | ¸ßΣ |
CVE-2024-21395 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾·ì϶ | ¸ßΣ |
CVE-2024-21328 | Dynamics 365 Sales ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-21394 | Dynamics 365 Field Service ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-21396 | Dynamics 365 Sales ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-21327 | Microsoft Dynamics 365 Customer Engagement ¿çÕ¾¾ç±¾·ì϶ | ¸ßΣ |
CVE-2024-20673 | Microsoft Office Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21384 | Microsoft Office OneNote Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21378 | Microsoft Outlook Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21402 | Microsoft Outlook ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21379 | Microsoft Word Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21374 | Microsoft Teams for Android ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-21353 | Microsoft WDAC ODBC Driver Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21370 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21350 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21368 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21359 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21365 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21367 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21420 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21366 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21369 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21375 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21361 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21358 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21391 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21360 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21352 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21406 | Windows Printing Service ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-21377 | Windows DNS ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-50387 | MITRE£ºCVE-2023-50387 DNSSEC ÑéÖ¤¸´ÔÓÐԿɱ»ÀûÓÃÀ´ºÄ¾¡ CPU ×ÊÔ´²¢ÖÕ³¡ DNS ½âÎöÆ÷ | ¸ßΣ |
CVE-2024-21342 | Windows DNS Client »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-20695 | Skype for Business ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-21347 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21304 | Trusted Compute Base ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21343 | Windows Network Address Translation (NAT) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-21348 | Internet Connection Sharing (ICS) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-21344 | Windows Network Address Translation (NAT) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-21371 | Windows Kernel ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21338 | Windows Kernel ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21341 | Windows Kernel Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21345 | Windows Kernel ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21362 | Windows Kernel °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-21340 | Windows Kernel ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-21356 | Windows Lightweight Directory Access Protocol (LDAP) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-21363 | Microsoft Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21355 | Microsoft Message Queuing (MSMQ) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21405 | Microsoft Message Queuing (MSMQ) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21354 | Microsoft Message Queuing (MSMQ) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21372 | Windows OLE Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21339 | Windows USB Generic Parent Driver Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21346 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21364 | Microsoft Azure Site RecoveryÌØÈ¨ÌáÉý·ì϶ | ÖÐΣ |
CVE-2024-21399 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´Ðзì϶ | ÖÐΣ |
CVE-2024-21351 | Windows SmartScreen °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ÖÐΣ |
CVE-2024-21626 | runc ÎļþÃèÊö·ûй© | δ֪ |
CVE-2024-1284 | Chromium£ºCVE-2024-1284 ÔÚ Mojo ÖпªÊͺóʹÓà | δ֪ |
CVE-2024-1060 | Chromium£ºCVE-2024-1060 ÔÚ Canvas ÖпªÊͺóʹÓà | δ֪ |
CVE-2024-1077 | Chromium£ºCVE-2024-1077 ÔÚ Network ÖпªÊͺóʹÓà | δ֪ |
CVE-2024-1283 | Chromium£ºCVE-2024-1283 Skia ÖеĶѻº³åÇøÒç³ö | δ֪ |
CVE-2024-1059 | Chromium£ºCVE-2024-1059 ÔÚ WebRTC ÖпªÊͺóʹÓà | δ֪ |
¶þ¡¢Ó°ÏìÁìÓò
ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º
Azure DevOps
Microsoft Office
Azure Stack
Windows Hyper-V
Skype for Business
Trusted Compute Base
Microsoft Defender for Endpoint
Microsoft Dynamics
Azure Connected Machine Agent
Windows Kernel
Windows USB Serial Driver
Role: DNS Server
Windows Internet Connection Sharing (ICS)
Windows Win32K - ICOMP
SQL Server
Microsoft ActiveX
Microsoft WDAC OLE DB provider for SQL
Windows SmartScreen
Microsoft WDAC ODBC Driver
Windows Message Queuing
Windows LDAP - Lightweight Directory Access Protocol
Azure Site Recovery
Windows OLE
Microsoft Teams for Android
Microsoft Azure Kubernetes Service
Microsoft Windows DNS
Microsoft Office Outlook
Microsoft Office Word
Azure Active Directory
Microsoft Office OneNote
.NET
Azure File Sync
Microsoft Edge (Chromium-based)
Microsoft Windows
Microsoft Exchange Server
Internet Shortcut Files
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2024Äê2Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2024-Feb
²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2022Äê2Ô£©
2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£
3.2 һʱ´ëÊ©
Õë¶ÔCVE-2024-21410£¬ÔÚ Exchange Server 2019 ÀÛ»ý¸üÐÂ14 (CU14) ¸üÐÂ֮ǰ£¬Exchange Server ĬÈÏÇé¿öϲ»ÆôÓà NTLM Í´´¦Öм̱£»¤£¨³ÆÎªÉí·ÝÑéÖ¤À©´ó±£»¤»ò EPA£©£¬Exchange Server 2019 CU14 ĬÈÏÔÚ Exchange ServerÉÏÆôÓà EPA£¬Microsoft ½¨ÒéÔÚ Exchange Server 2019 ÉÏ×°Öà CU14 £¬»ò²ÎÔÄExchange À©´ó±£»¤Îĵµ²¢Ê¹ÓÃExchangeExtendedProtectionManagement.ps1¾ç±¾Îª Exchange ServerÆôÓÃÉí·ÝÑéÖ¤À©´ó±£»¤ (EPA)À´»º½â¸Ã·ì϶¡£
¸ü¶à·ì϶ÏêÇé¼°»º½â´ëÊ©¿É²Î¿¼¹Ù·½²¼¸æ£º
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-21410
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Feb
https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2024-patch-tuesday-fixes-2-zero-days-73-flaws/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-02-19 | ³õ´Î°ä²¼ |
Îå¡¢¸½Â¼
5.1 GA»Æ½ð¼×¼ò½é
GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£
5.2 ¹ØÓÚGA»Æ½ð¼×
GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ