¡¾·ì϶¹«¸æ¡¿Î¢Èí3Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2024-03-13


Ò»¡¢·ì϶¸ÅÊö

2024Äê3ÔÂ12ÈÕ£¬Î¢Èí°ä²¼ÁË3Ô°²È«¸üУ¬±¾´Î¸üй²½¨¸´ÁË60¸ö·ì϶£¨²»Ô̺¬3ÔÂ7ÈÕ½¨¸´µÄ4¸öMicrosoft Edge·ì϶£©£¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶ºÍºýŪ·ì϶µÈ¡£

±¾´Î°²È«¸üÐÂÖв»Ô̺¬±»»ý¼«ÀûÓõÄ0 day·ì϶£¬ÆäÖÐÆÀ¼¶Îª¡°ÑϳÁ¡±µÄ2¸ö·ì϶Ô̺¬£º

CVE-2024-21407£ºWindows Hyper-VÔ¶³Ì´úÂëÖ´Ðзì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.1£¬ÀûÓø÷ì϶±ØÒªGuest VMÉϾ­¹ýÉí·ÝÑéÖ¤µÄÍþвÕßÏòÐé¹¹»úÉϵÄÓ²¼þ×ÊÔ´·¢ËÍÌØÔìµÄÎļþ²Ù×÷ÒªÇ󣬳ɹ¦ÀûÓÿÉÄܵ¼ÖÂÔÚÖ÷»ú·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë¡£

CVE-2024-21408£ºWindows Hyper-V »Ø¾ø·þÎñ·ì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ5.5£¬Ó°ÏìÁËWindows Server 2016/2019/2022¡¢Windows 10/11µÈ¶à¸ö°æ±¾£¬³É¹¦ÀûÓÿÉÄܵ¼Ö»ؾø·þÎñ¡£

±¾´Î°²È«¸üÐÂÖÐÆäËû±ØÒª¹Ø×¢µÄ·ì϶»¹Ô̺¬µ«²»ÏÞÓÚ£º

CVE-2024-21400£ºMicrosoft Azure Kubernetes Service Confidential ContainerÌØÈ¨ÌáÉý·ì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.0£¬ÍþвÕßÄܹ»½Ó¼û²»ÊÜÐÅÀµµÄ AKS Kubernetes ½ÚµãºÍ AKS»úÃÜÈÝÆ÷£¬´Ó¶øÊÕÊÜÆä¿ÉÄܰ󶨵ÄÍøÂç²Ö¿âÖ®±íµÄ»úÃÜguestsºÍÈÝÆ÷¡£³É¹¦ÀûÓø÷ì϶µÄÍþвÕßÄܹ»ÇÔȡƾ֤²¢Ó°Ïì Azure Kubernetes ·þÎñ»úÃÜÈÝÆ÷ (AKSCC) ÖÎÀíµÄ°²È«ÁìÓòÖ®±íµÄ×ÊÔ´¡£

CVE-2024-26199£ºMicrosoft OfficeÌØÈ¨ÌáÉý·ì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8£¬¾­¹ýÉí·ÝÑéÖ¤µÄÓû§¿ÉÀûÓø÷ì϶»ñµÃSYSTEMȨÏÞ¡£

CVE-2024-20671£ºMicrosoft Defender °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ5.5£¬¾­¹ýÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÀûÓø÷ì϶×èÖ¹ Microsoft Defender Æô¶¯¡£¸Ã·ì϶ÒÑÔÚWindows Defender°æ±¾4.18.24010.12Öн¨¸´£¬¿Éͨ¹ý Windows É豸ÉÏ×Ô¶¯×°ÖÃµÄ Windows Defender ·´¶ñÒâÈí¼þƽ̨¸üнøÐн¨¸´¡£

CVE-2024-21411£ºSkype for Consumer Ô¶³Ì´úÂëÖ´Ðзì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8£¬ÍþвÕßÄܹ»Í¨¹ý¼´Ê±ÐÂÎÅÏòÓû§·¢ËͶñÒâÁ´½Ó»ò¶ñÒâͼÏñ£¬¶øºóÓÕʹÓû§µ¥»÷¸ÃÁ´½Ó»òͼÏñÀ´ÀûÓø÷ì϶£¬³É¹¦ÀûÓø÷ì϶µÄÍþвÕßÄܹ»»ñµÃ¶ÁÈ¡¡¢Ð´ÈëºÍɾ³ýµÈȨÏÞ¡£

CVE-2024-21334£ºOpen Management Infrastructure (OMI) Ô¶³Ì´úÂëÖ´Ðзì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕßÄܹ»´Ó Internet ½Ó¼û OMI Ê·ý²¢·¢ËÍÌØÔìÒªÇóÒÔ´¥·¢¿ªÊͺóʹÓ÷ì϶£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ÔËÐÐÊÜÓ°ÏìµÄ SCOM (System Center Operations Manager) °æ±¾µÄ¿Í»§Ó¦¸üе½ OMI °æ±¾1.8.1-0¡£

CVE-2024-26198£ºMicrosoft Exchange Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕßÄܹ»Í¨¹ý½«ÌØÔìÎļþ¸éÖõ½ÔÚÏßĿ¼»ò±¾µØÍøÂçµØÎ»£¬¶øºóÓÕµ¼Óû§´ò¿ªÎļþÀ´ÀûÓø÷ì϶£¬³É¹¦ÀûÓÿÉÄܵ¼Ö¼ÓÔØ¶ñÒâ DLL£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÓ×°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ·ì϶Ô̺¬£º

CVE-2024-21433£ºWindows Print SpoolerÌØÈ¨ÌáÉý·ì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.0£¬ÀûÓø÷ì϶±ØÒªÓ®µÃ¾ºÕùǰÌᣬ³É¹¦ÀûÓø÷ì϶µÄÍþвÕ߿ɻñµÃSYSTEMȨÏÞ¡£

CVE-2024-21437£ºWindows Graphics ComponentÌØÈ¨ÌáÉý·ì϶

Windows ͼÐÎ×é¼þ´æÔÚȨÏÞÌáÉý·ì϶£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8£¬³É¹¦ÀûÓø÷ì϶µÄÍþвÕ߿ɻñµÃSYSTEMȨÏÞ¡£

CVE-2024-26160£ºWindows Cloud Files Mini Filter DriverÐÅϢй¶·ì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ5.5£¬³É¹¦ÀûÓø÷ì϶µÄÍþвÕßÄܹ»´ÓÓû§Ä£Ê½¹ý³Ì¶ÁÈ¡ÄÚºËÄÚ´æµÄÄÚÈÝ¡£

CVE-2024-26170£ºWindows Composite Image File System (CimFS) ÌØÈ¨ÌáÉý·ì϶

Windows ¸´ºÏÓ³ÏñÎļþϵͳ (CimFS)´æÔÚȨÏÞÌáÉý·ì϶£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8£¬³É¹¦ÀûÓø÷ì϶µÄÍþвÕ߿ɻñµÃÊÜÏÞSYSTEMȨÏÞ¡£

CVE-2024-26182£ºWindows KernelÌØÈ¨ÌáÉý·ì϶

Windows Äں˴æÔÚÌØÈ¨ÌáÉý·ì϶£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8£¬³É¹¦ÀûÓø÷ì϶µÄÍþвÕ߿ɻñµÃSYSTEMȨÏÞ¡£

CVE-2024-26185£ºWindows ѹËõÎļþ¼Ð´Û¸Ä·ì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ6.5£¬Ó°ÏìÁËWindows 11¶à¸ö°æ±¾¡£ÍþвÕß¿Éͨ¹ýÔÚµç×ÓÓʼþÖÐÏòÓû§·¢ËÍÌØÔìÎļþ²¢ÓÕµ¼Óû§´ò¿ª¸ÃÎļþ£¬»òÓÕµ¼Óû§µ¥»÷¶ñÒâÍøÕ¾»òwebÁ´½Ó²¢´ò¿ªÌØÔìÎļþÀ´ÀûÓø÷ì϶£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼Ö·ÛËéϵͳÆëÈ«ÐÔ¡£

΢Èí3Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º

CVE ID

CVE ±êÌâ

ÑϳÁÐÔ

CVE-2024-21407

Windows   Hyper-V Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-21408

Windows   Hyper-V »Ø¾ø·þÎñ·ì϶

ÑϳÁ

CVE-2024-21392

.NET ºÍ Visual Studio »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-26203

Azure Data   Studio ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2024-21421

Azure SDK ºýŪ·ì϶

¸ßΣ

CVE-2023-28746

Intel£ºCVE-2023-28746 ¼Ä·ÅÆ÷ÎļþÊý¾Ý²ÉÑù (RFDS)

¸ßΣ

CVE-2024-21390

Microsoft   Authenticator ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2024-21400

Microsoft   Azure Kubernetes Service Confidential Container ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-26164

Microsoft   Django Backend for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21419

Microsoft   Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾·ì϶

¸ßΣ

CVE-2024-26198

Microsoft   Exchange Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21437

Windows   Graphics Component ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-26201

Microsoft   Intune Linux Agent ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2024-26199

Microsoft   Office ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2024-21426

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-26190

Microsoft   QUIC »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-21448

Microsoft   Teams for Android ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-21451

Microsoft   ODBC Driver Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21441

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-26161

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-26166

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21444

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21450

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21434

Microsoft   Windows SCSI Class System File ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21330

Open   Management Infrastructure (OMI) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21334

Open   Management Infrastructure (OMI) Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-26204

Outlook   for Android ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-21411

Skype for   Consumer Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21418

Software   for Open Networking in the Cloud (SONiC) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-26165

Visual   Studio Code ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21438

Microsoft   AllJoyn API »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-26160

Windows   Cloud Files Mini Filter Driver ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-26170

Windows   Composite Image File System (CimFS) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-26185

Windows ѹËõÎļþ¼Ð´Û¸Ä·ì϶

¸ßΣ

CVE-2024-20671

Microsoft   Defender °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-26169

Windows   Error Reporting Service ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21431

Hypervisor-Protected   Code Integrity (HVCI) °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-21436

Windows   Installer ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2024-21427

Windows   Kerberos °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-26177

Windows ÄÚºËÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-26176

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-26174

Windows ÄÚºËÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-26182

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-26181

Windows Äں˻ؾø·þÎñ·ì϶

¸ßΣ

CVE-2024-26178

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-26173

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21443

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21446

NTFS ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21440

Microsoft   ODBC Driver Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-26162

Microsoft   ODBC Driver Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-26159

Microsoft   ODBC Driver Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21435

Windows   OLE Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21433

Windows   Print Spooler ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-26197

Windows   Standards-Based Storage Management Service »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-21439

Windows   Telephony Server ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2024-21432

Windows   Update Stack ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21429

Windows   USB Hub Driver Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21442

Windows   USB Print Driver ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2024-21445

Windows   USB Print Driver ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2024-21430

Windows   USB Attached SCSI (UAS) Protocol Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-2174

Chromium£ºCVE-2024-2174 V8 ÖеÄÖ´Ðв»µ±

δ֪

CVE-2024-2173

Chromium£ºCVE-2024-2173 V8 ÖеÄÄÚ´æ½Ó¼ûÔ½½ç

δ֪

CVE-2024-2176

Chromium£ºCVE-2024-2176 ÔÚ FedCM ÖпªÊͺóʹÓÃ

δ֪

CVE-2024-26167

Microsoft   Edge for Android ºýŪ·ì϶

δ֪

 

 

¶þ¡¢Ó°ÏìÁìÓò

ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º

Windows Defender

Open Management Infrastructure

Microsoft Authenticator

.NET

Microsoft Azure Kubernetes Service

Role: Windows Hyper-V

Skype for Consumer

Software for Open Networking in the Cloud (SONiC)

Microsoft Dynamics

Azure SDK

Microsoft Office SharePoint

Windows Kerberos

Windows USB Hub Driver

Windows USB Serial Driver

Windows Hypervisor-Protected Code Integrity

Windows Update Stack

Windows Print Spooler Components

Microsoft Windows SCSI Class System File

Windows OLE

Windows Installer

Microsoft Graphics Component

Windows AllJoyn API

Windows Telephony Server

Windows ODBC Driver

Microsoft WDAC OLE DB provider for SQL

Windows USB Print Driver

Windows Kernel

Windows NTFS

Microsoft Teams for Android

Microsoft WDAC ODBC Driver

Windows Cloud Files Mini Filter Driver

SQL Server

Visual Studio Code

Microsoft Edge for Android

Windows Error Reporting

Windows Composite Image File System

Windows Compressed Folder

Microsoft QUIC

Windows Standards-Based Storage Management Service

Microsoft Exchange Server

Microsoft Office

Microsoft Intune

Azure Data Studio

Outlook for Android

 


Èý¡¢°²È«´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2024Äê3Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Mar

²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2022Äê2Ô£©

2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£

3.2 һʱ´ëÊ©

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Mar

https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2024-patch-tuesday-fixes-60-flaws-18-rce-bugs/

  

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-03-13

³õ´Î°ä²¼

 


Îå¡¢¸½Â¼

5.1 GA»Æ½ð¼×¼ò½é

GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£

5.2 ¹ØÓÚGA»Æ½ð¼×

GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png