¡¾·ì϶¹«¸æ¡¿Î¢Èí9Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2024-09-11


Ò»¡¢·ì϶¸ÅÊö

2024Äê9ÔÂ11ÈÕ £¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Î¢Èí°ä²¼ÁË9Ô°²È«¸üР£¬±¾´Î¸üй²½¨¸´ÁË79¸ö·ì϶ £¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶ºÍºýŪ·ì϶µÈ¡£

±¾´Î°²È«¸üÐÂÖÐÔ̺¬4¸ö±»»ý¼«ÀûÓõÄ0 day·ì϶ £¬ÆäÖÐ1¸öÒѾ­¹«¿ªÅû¶£º

CVE-2024-38014£ºWindows Installer ÌØÈ¨ÌáÉý·ì϶

Windows InstallerÖдæÔÚȨÏÞÌáÉý·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8 £¬³É¹¦ÀûÓø÷ì϶µÄÍþвÕ߿ɻñµÃ SYSTEM ȨÏÞ £¬Ä¿Ç°¸Ã·ì϶ÒѼì²âµ½·ì϶ÀûÓá£

CVE-2024-38217£ºWindows Mark of the Web°²È«Ö°ÄÜÈÆ¹ý·ì϶

Windows Mark of the WebÖдæÔÚ°²È«Ö°ÄÜÈÆ¹ý·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ5.4 £¬ÍþвÕßÄܹ»ÔÚÆä½ÚÔìµÄ·þÎñÆ÷ÉÏÍйÜÒ»¸ö¿ÉÄÜÌ Web ÏóÕ÷ (MOTW) ·ÀÓùµÄ¶ñÒâÎļþ £¬¶øºóÓÕʹָ±êÓû§ÏÂÔØ²¢´ò¿ª¸ÃÎļþ £¬´Ó¶øµ¼Ö°²È«Ö°ÄÜ£¨ÈçSmartScreenÀûÓ÷¨Ê½ÅµÑÔ°²È«²é³­»ò¾É°æWindows¸½¼þ·þÎñ°²È«ÌáÐÑ£©Èƹý¡£Ä¿Ç°¸Ã·ì϶ÒѾ­¹«¿ªÅû¶ £¬ÇÒÒѼì²âµ½·ì϶ÀûÓá£

CVE-2024-38226£ºMicrosoft Publisher °²È«Ö°ÄÜÈÆ¹ý·ì϶

Microsoft Publisher´æÔÚ°²È«Ö°ÄÜÈÆ¹ý·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.3 £¬ÍþвÕß¿Éͨ¹ýÓÕµ¼Êܺ¦ÕßÏÂÔØ²¢´ò¿ªÌØÔìÎļþÀ´ÀûÓø÷ì϶ £¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÈÆ¹ýÓÃÓÚ×èÖ¹²»ÊÜÐÅÀµ»ò¶ñÒâÎļþµÄOfficeºêÕ½Êõ £¬Ä¿Ç°¸Ã·ì϶ÒѼì²âµ½·ì϶ÀûÓá£

CVE-2024-43491£ºMicrosoft Windows UpdateÔ¶³Ì´úÂëÖ´Ðзì϶

Microsoft·þÎñ²Ö¿âÖдæÔÚUse-After-Free·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8 £¬¿ÉÄܵ¼Ö»عöÓ°ÏìWindows 10 1507ÉÏ¿ÉÑ¡×é¼þµÄһЩ·ì϶µÄ½¨¸´ £¬´Ó¶øµ¼ÖÂÍþвÕßÄܹ»ÀûÓà Windows 10 °æ±¾1507£¨Windows 10 Enterprise 2015 LTSB ºÍ Windows 10 IoT Enterprise 2015 LTSB£©ÏµÍ³ÉÏÕâЩ֮ǰÒѽ¨¸´/»º½âµÄ·ì϶ £¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ £¬Ä¿Ç°¸Ã·ì϶ÒѼì²âµ½·ì϶ÀûÓá£ÊÜÓ°ÏìÓû§¿Éͨ¹ý°´°¤´Î×°Öà 2024Äê9Ô·þÎñ²Ö¿â¸üР(SSU KB5043936) ºÍ2024Äê9ÔÂWindows°²È«¸üР(KB5043083) À´½¨¸´¸Ã·þÎñ²Ö¿â·ì϶¡£

³ýCVE-2024-43491±í £¬±¾´Î°²È«¸üÐÂÖн¨¸´µÄÆäËû6¸öÑϳÁ·ì϶Ϊ£º

CVE-2024-43464£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft SharePoint ServerÖдæÔÚ·´ÐòÁл¯·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.2 £¬¾­¹ýÉí·ÝÑéÖ¤ÇÒÕ¼ÓÐÕ¾µãËùÓÐÕßȨÏÞµÄÍþвÕßÄܹ»½«ÌØÔìÎļþÉÏ´«µ½Ö¸±ê SharePoint Server £¬²¢Í¨¹ýÌØÔìAPI ÒªÇóÒÔ´¥·¢Îļþ²ÎÊýµÄ·´ÐòÁл¯ £¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔÚ SharePoint Server ¸ßµÍÎÄÖÐʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£

CVE-2024-38018£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft SharePoint ServerÖдæÔÚ·´ÐòÁл¯·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8 £¬¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÀûÓø÷ì϶ÔÚ SharePoint Server ÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£

CVE-2024-38119£ºWindows Network Address Translation (NAT) Ô¶³Ì´úÂëÖ´Ðзì϶

Windows ÍøÂçµØÖ·×ª»» (NAT)´æÔÚUse-After-Free·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.5 £¬ÏàÁÚÍøÂçµÄÍþвÕß¿ÉÀûÓø÷ì϶µ¼ÖÂÔ¶³Ì´úÂëÖ´Ðзì϶ £¬³É¹¦Àû¸Ã·ì϶±ØÒªÓ®µÃ¾ºÕùǰÌá £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס±¡£

CVE-2024-38216/ CVE-2024-38220£ºAzure Stack Hub ÌØÈ¨ÌáÉý·ì϶

CVE-2024-38194£ºAzure Web Apps ÌØÈ¨ÌáÉý·ì϶

³ýCVE-2024-43464ºÍCVE-2024-38018±í £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ·ì϶»¹Ô̺¬£º

l CVE-2024-38227£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

l  CVE-2024-38228£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

l  CVE-2024-38237£ºKernel Streaming WOW Thunk Service DriverÌØÈ¨ÌáÉý·ì϶

l  CVE-2024-38238£ºKernel Streaming Service DriverÌØÈ¨ÌáÉý·ì϶

l  CVE-2024-38241£ºKernel Streaming Service DriverÌØÈ¨ÌáÉý·ì϶

l  CVE-2024-38242£ºKernel Streaming Service DriverÌØÈ¨ÌáÉý·ì϶

l  CVE-2024-38243£ºKernel Streaming Service DriverÌØÈ¨ÌáÉý·ì϶

l  CVE-2024-38244£ºKernel Streaming Service DriverÌØÈ¨ÌáÉý·ì϶

l  CVE-2024-38245£ºKernel Streaming Service DriverÌØÈ¨ÌáÉý·ì϶

l  CVE-2024-38246£ºWin32kÌØÈ¨ÌáÉý·ì϶

l  CVE-2024-38247£ºWindows Graphics ComponentÌØÈ¨ÌáÉý·ì϶

l  CVE-2024-38249£ºWindows Graphics ComponentÌØÈ¨ÌáÉý·ì϶

l  CVE-2024-38252£ºWindows Win32 Kernel SubsystemÌØÈ¨ÌáÉý·ì϶

l  CVE-2024-38253£ºWindows Win32 Kernel SubsystemÌØÈ¨ÌáÉý·ì϶

l  CVE-2024-43457£ºWindows Setup and DeploymentÌØÈ¨ÌáÉý·ì϶

l  CVE-2024-43461£ºWindows MSHTML PlatformºýŪ·ì϶

l  CVE-2024-43487£ºWindows Mark of the Web °²È«Ö°ÄÜÈÆ¹ý·ì϶

΢Èí9Ô¸üн¨¸´µÄ·ì϶ÁбíÈçÏ£º

CVE-ID

CVE ±êÌâ

ÑϳÁÐÔ

CVE-2024-38216

Azure   Stack Hub ÌØÈ¨ÌáÉý·ì϶

ÑϳÁ

CVE-2024-38220

Azure   Stack Hub ÌØÈ¨ÌáÉý·ì϶

ÑϳÁ

CVE-2024-38194

Azure Web   Apps ÌØÈ¨ÌáÉý·ì϶

ÑϳÁ

CVE-2024-43464

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-38018

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-38119

Windows   Network Address Translation (NAT) Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-43491

Microsoft   Windows Update Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-43469

Azure   CycleCloud Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38188

Azure   Network Watcher VM Agent ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-43470

Azure   Network Watcher VM Agent ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38225

Microsoft   Dynamics 365 Business Central ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-43492

Microsoft   AutoUpdate (MAU) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-43476

Microsoft   Dynamics 365 (on-premises) ¿çÕ¾¾ç±¾·ì϶

¸ßΣ

CVE-2024-38247

Windows   Graphics Component ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38250

Windows   Graphics Component ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38249

Windows   Graphics Component ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38259

Microsoft   Management Console Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-43465

Microsoft   Excel ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38226

Microsoft   Publisher °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-38227

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38228

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-43466

Microsoft   SharePoint Server »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-43463

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-43482

Microsoft   Outlook for iOS ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-38245

Kernel   Streaming Service Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38241

Kernel   Streaming Service Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38242

Kernel   Streaming Service Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38244

Kernel   Streaming Service Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38243

Kernel   Streaming Service Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38237

Kernel   Streaming WOW Thunk Service Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38238

Kernel   Streaming Service Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-43479

Microsoft   Power Automate Desktop Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38235

Windows   Hyper-V »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-37338

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37980

Microsoft   SQL Server ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-26191

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37339

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37337

Microsoft   SQL Server Native Scoring ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-26186

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37342

Microsoft   SQL Server Native Scoring ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-43474

Microsoft   SQL Server ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-37335

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37966

Microsoft   SQL Server Native Scoring ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-37340

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-37965

Microsoft   SQL Server ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-37341

Microsoft   SQL Server ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-43475

Microsoft   Windows Admin Center ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-38257

Microsoft   AllJoyn API ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-38254

Windows   Authentication ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-38236

DHCP   Server Service »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38014

Windows   Installer ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38239

Windows   Kerberos ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38256

Windows   Kernel-Mode Driver ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-43495

Windows   libarchive Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38217

Windows   Mark of the Web °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-43461

Windows   MSHTML Platform ºýŪ·ì϶

¸ßΣ

CVE-2024-38232

Windows   Networking »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38233

Windows   Networking »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38234

Windows   Networking »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-43458

Windows   Networking ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-38046

PowerShell   ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38240

Windows   Remote Access Connection Manager ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38231

Windows   Remote Desktop Licensing Service »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38258

Windows   Remote Desktop Licensing Service ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-43467

Windows   Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-43454

Windows   Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38263

Windows   Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38260

Windows   Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-43455

Windows   Remote Desktop Licensing Service ºýŪ·ì϶

¸ßΣ

CVE-2024-30073

Windows   Security Zone Mapping °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-43457

Windows   Setup and Deployment ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38230

Windows   Standards-Based Storage Management »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-38248

Windows   Storage ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21416

Windows   TCP/IP Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38045

Windows   TCP/IP Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-38246

Win32k ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38252

Windows   Win32 Kernel Subsystem ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-38253

Windows   Win33 Kernel Subsystem ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-43487

Windows   Mark of the Web °²È«Ö°ÄÜÈÆ¹ý·ì϶

ÖÐΣ

 

¶þ¡¢Ó°ÏìÁìÓò

ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º

Windows TCP/IP

SQL Server

Windows Security Zone Mapping

Windows Installer

Microsoft Office SharePoint

Windows PowerShell

Windows Network Address Translation (NAT)

Azure Network Watcher

Azure Web Apps

Azure Stack

Windows Mark of the Web (MOTW)

Dynamics Business Central

Microsoft Office Publisher

Windows Standards-Based Storage Management Service

Windows Remote Desktop Licensing Service

Windows Network Virtualization

Role: Windows Hyper-V

Windows DHCP Server

Microsoft Streaming Service

Windows Kerberos

Windows Remote Access Connection Manager

Windows Win32K - GRFX

Microsoft Graphics Component

Windows Storage

Windows Win32K - ICOMP

Windows Authentication Methods

Windows Kernel-Mode Drivers

Windows AllJoyn API

Microsoft Management Console

Windows Setup and Deployment

Windows MSHTML Platform

Microsoft Office Visio

Microsoft Office Excel

Azure CycleCloud

Windows Admin Center

Microsoft Dynamics 365 (on-premises)

Power Automate

Microsoft Outlook for iOS

Windows Update

Microsoft AutoUpdate (MAU)

Windows Libarchive

 

Èý¡¢°²È«´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üР£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓà £¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ £¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü £¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡± £¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС± £¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС± £¬ÆÚ´ýϵͳ×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú £¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüР£¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó £¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡± £¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2024Äê9Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Sep

²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó £¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí·ì϶ÁÐ±í£¨Ê¾Àý£©

2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿ÁÐÑ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ £¬µã»÷ÓҲࡾÏÂÔØ¡¿Áдò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾°²È«¸üС¿ £¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ £¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£

3.2 һʱ´ëÊ©

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡ £¬Ï÷¼õϵͳ·ì϶ £¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔì £¬Åú¸Ä·À»ðǽսÊõ £¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ £¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø £¬Ï÷¼õ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶°²È«²úÆ· £¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí £¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò £¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Sep

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43491

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-09-11

³õ´Î°ä²¼

 


Îå¡¢¸½Â¼

5.1 GA»Æ½ð¼×¼ò½é

GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Äê £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏà £¬¹«Ë¾Ô±¹¤6000ÓàÈË £¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ £¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£

5.2 ¹ØÓÚGA»Æ½ð¼×

GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯ £¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶ £¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png