¡¾·ì϶¹«¸æ¡¿Î¢Èí10Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2024-10-09Ò»¡¢·ì϶¸ÅÊö
2024Äê10ÔÂ9ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Î¢Èí°ä²¼ÁË10Ô°²È«¸üУ¬±¾´Î¸üй²½¨¸´ÁË118¸ö·ì϶£¨²»Ô̺¬Ö®Ç°½¨¸´µÄ3¸öEdge·ì϶£©£¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶ºÍºýŪ·ì϶µÈ¡£
±¾´Î°²È«¸üÐÂÖÐÔ̺¬5¸öÒѾ¹«¿ªÅû¶µÄ0 day·ì϶£¬ÆäÖÐ2¸öÒÑ·¢ÏÖ±»ÀûÓãº
CVE-2024-43573£ºWindows MSHTML PlatformºýŪ·ì϶
Windows MSHTML ƽ̨£¨¸Ãƽ̨ÒÔǰ±»Internet Explorer ºÍ¾É°æ Microsoft Edge ʹÓã¬Æä×é¼þÈÔ×°ÖÃÔÚWindows ÖУ©´æÔÚ¿çÕ¾¾ç±¾·ì϶£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ6.5¡£ÍþвÕß¿ÉÓÕʹÊܺ¦Õßµã»÷ÌØÔìÁ´½Ó»òä¯ÀÀ¶ñÒâÒ³ÃæÊ±´¥·¢¸Ã·ì϶£¬´Ó¶ø¿ÉÄܵ¼Ö¶ñÒâ¾ç±¾ÔÚÓû§µÄä¯ÀÀÆ÷ÖÐÖ´ÐС£Ä¿Ç°¸Ã·ì϶ÒѾ¹«¿ªÅû¶£¬ÇÒÒѼì²âµ½·ì϶ÀûÓá£
CVE-2024-43572£ºMicrosoft Management ConsoleÔ¶³Ì´úÂëÖ´Ðзì϶
Microsoft ÖÎÀí½ÚÔį̀´æÔÚ´úÂëÖ´Ðзì϶£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8£¬ÍþвÕß¿Éͨ¹ýÓÕʹÊܺ¦Õß´ÓÍøÕ¾ÏÂÔØ²¢´ò¿ªÌØÔìµÄMicrosoft Saved Console (MSC) ÎļþÀ´ÀûÓø÷ì϶£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐС£Ä¿Ç°¸Ã·ì϶ÒѾ¹«¿ªÅû¶£¬ÇÒÒѼì²âµ½·ì϶ÀûÓá£
CVE-2024-6197£ºOpen Source Curl Ô¶³Ì´úÂëÖ´Ðзì϶
¿ªÔ´ CurlÖдæÔÚ·ì϶£¨¸Ã·ì϶ӰÏìcurl¡¢ºÅÁîÐй¤¾ßºÍǶÈëÔÚ¸÷ÀàÈí¼þÖÐµÄ libcurl£¬ÓÉÓÚWindowsÖи½´øcurlºÅÁîÐÐÒò¶øÒ×Êܸ÷ì϶ӰÏ죩£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8£¬¿ÉÄܵ¼ÖÂÔÚ Curl ³¢ÊÔÏνӵ½¶ñÒâ·þÎñÆ÷ʱִÐкÅÁĿǰ¸Ã·ì϶ÒѾ¹«¿ªÅû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס±¡£
CVE-2024-20659£ºWindows Hyper-V °²È«Ö°ÄÜÈÆ¹ý·ì϶
Windows Hyper-V´æÔÚ°²È«Ö°ÄÜÈÆ¹ý·ì϶£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.1£¬³É¹¦ÀûÓø÷ì϶±ØÒªÓû§³ÁÐÂÆô¶¯Æä»úе£¬ÔÚÄ³Ð©ÌØ¶¨Ó²¼þÉÏ£¬³É¹¦ÀûÓø÷ì϶¿ÉÄÜ»áÈÆ¹ý UEFI£¬Õâ¿ÉÄܵ¼ÖÂÐé¹¹»úÖÎÀí·¨Ê½ºÍ°²È«Äں˱»·ÛË顣Ŀǰ¸Ã·ì϶ÒѾ¹«¿ªÅû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס±¡£
CVE-2024-43583£ºWinlogon ÌØÈ¨ÌáÉý·ì϶
Winlogon´æÔÚÌØÈ¨ÌáÉý·ì϶£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8£¬³É¹¦ÀûÓø÷ì϶¿É»ñµÃWindows ÖеÄSYSTEM ȨÏÞ¡£Ä¿Ç°¸Ã·ì϶ÒѾ¹«¿ªÅû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£
±¾´Î°²È«¸üÐÂÖн¨¸´µÄ3¸öÑϳÁ·ì϶Ϊ£º
CVE-2024-43468£ºMicrosoft Configuration Manager Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft Configuration Manager´æÔÚSQL×¢Èë·ì϶£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕß¿Éͨ¹ýÏòÖ¸±ê»·¾³·¢ËͶñÒâÒªÇóÀ´ÀûÓø÷ì϶£¬ÕâЩҪÇóÒÔ²»°²È«µÄ·½Ê½´¦Ö㬴Ӷø¿ÉÄܵ¼ÖÂÔÚ·þÎñÆ÷»òµ×²ãÊý¾Ý¿âÉÏÖ´ÐкÅÁ΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס±¡£
CVE-2024-43488£ºVisual Studio Code extension for Arduino Ô¶³Ì´úÂëÖ´Ðзì϶
Visual Studio Code extension for ArduinoÖжÌȱ¶Ô¹Ø¼üÖ°ÄܵÄÉí·ÝÑéÖ¤£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8£¬¿ÉÄܵ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄÍþвÕßͨ¹ýÍøÂç¹¥»÷µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Ä¿Ç°Microsoft ÒÑÆëÈ«»º½â¸Ã·ì϶£¬ÊÜÓ°ÏìÓû§ÎÞÐè²ÉÈ¡ÈκδëÊ©¡£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס±¡£
CVE-2024-43582£ºRemote Desktop Protocol Server Ô¶³Ì´úÂëÖ´Ðзì϶
Remote Desktop Protocol ServerÖдæÔÚUse-After-Free·ì϶£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.1£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕß¿Éͨ¹ýÏò RPC Ö÷»ú·¢ËÍÌåʽÃýÎóµÄÊý¾Ý°ü£¬¿ÉÄܵ¼ÖÂÔÚ·þÎñÆ÷¶ËÒÔÓëRPC·þÎñÒ»ÑùµÄȨÏÞÖ´ÐÐÔ¶³Ì´úÂ룬³É¹¦ÀûÓø÷ì϶±ØÒªÓ®µÃ¾ºÕùǰÌᡣ΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס±¡£
³ýCVE-2024-43583±í£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ·ì϶»¹Ô̺¬£º
l CVE-2024-43581/ CVE-2024-43615£ºMicrosoft OpenSSH for Windows Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft OpenSSH for WindowsÖдæÔÚÎļþÃû»òõè¾¶µÄ±í²¿½ÚÔ죬ÕâЩ·ì϶µÄCVSSÆÀ·Ö¾ùΪ7.1£¬ÀûÓÃÄѶȽϸߣ¬±ØÒªÊܺ¦ÕßÖ´ÐÐÌØ¶¨µÄÎļþÖÎÀí²Ù×÷À´´¥·¢·ì϶£¬³É¹¦ÀûÓÿÉÄÜÔÚÖ¸±êϵͳÉϵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
l CVE-2024-43502£ºWindows ÄÚºËÌØÈ¨ÌáÉý·ì϶
l CVE-2024-43509£ºWindows Graphics ComponentÌØÈ¨ÌáÉý·ì϶
l CVE-2024-43556£ºWindows Graphics ComponentÌØÈ¨ÌáÉý·ì϶
l CVE-2024-43560£ºMicrosoft Windows Storage Port DriverÌØÈ¨ÌáÉý·ì϶
l CVE-2024-43609£ºMicrosoft Office ºýŪ·ì϶
΢Èí10Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑϳÁÐÔ |
CVE-2024-43468 | Microsoft Configuration Manager Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2024-43488 | Visual Studio Code extension for Arduino Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2024-43582 | Remote Desktop Protocol Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2024-38229 | .NET ºÍ Visual Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43485 | .NET ºÍ Visual Studio »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43484 | .NET¡¢.NET Framework ºÍ Visual Studio »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43483 | .NET¡¢.NET Framework ºÍ Visual Studio »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43591 | Azure Command Line Integration (CLI) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-38097 | Azure Monitor Agent ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-38179 | Azure Stack Hyperconverged Infrastructure (HCI) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43506 | BranchCache »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-38149 | BranchCache »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43585 | Code Integrity Guard °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-43497 | DeepSpeed Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43515 | Internet Small Computer Systems Interface (iSCSI) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43517 | Microsoft ActiveX Data Objects Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43614 | Microsoft Defender for Endpoint for Linux ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-43534 | Windows Graphics Component ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-43508 | Windows Graphics Component ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-43556 | Windows Graphics Component ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43509 | Windows Graphics Component ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43572 | Microsoft Management Console Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43616 | Microsoft Office Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43576 | Microsoft Office Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43609 | Microsoft Office ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-43504 | Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43503 | Microsoft SharePoint ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43505 | Microsoft Office Visio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43544 | Microsoft Simple Certificate Enrollment Protocol »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43541 | Microsoft Simple Certificate Enrollment Protocol »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43519 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43574 | Microsoft Speech Application Programming Interface (SAPI) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43615 | Microsoft OpenSSH for Windows Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43581 | Microsoft OpenSSH for Windows Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-38029 | Microsoft OpenSSH for Windows Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43604 | Outlook for Android ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43612 | Power BI Report Server ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-43481 | Power BI Report Server ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-43533 | Remote Desktop Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43599 | Remote Desktop Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43521 | Windows Hyper-V »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-20659 | Windows Hyper-V °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-43567 | Windows Hyper-V »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43575 | Windows Hyper-V »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43532 | Remote Registry Service ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43480 | Azure Service Fabric for Linux Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43571 | Sudo for Windows ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-43590 | Visual C++ Redistributable Installer ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43603 | Visual Studio Collector Service »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43601 | Visual Studio Code for Linux Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43563 | Windows Ancillary Function Driver for WinSock ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43513 | BitLocker °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-43501 | Windows Common Log File System Driver ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43546 | Windows Cryptographic ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-6197 | Open Source Curl Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-37982 | Windows Resume Extensible Firmware Interface °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-37976 | Windows Resume Extensible Firmware Interface °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-37983 | Windows Resume Extensible Firmware Interface °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-30092 | Windows Hyper-V Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43547 | Windows Kerberos ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-38129 | Windows Kerberos ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43502 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43511 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43520 | Windows Äں˻ؾø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43527 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43570 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-37979 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43554 | Windows Kernel-Mode Driver ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-43535 | Windows Kernel-Mode Driver ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43522 | Windows Local Security Authority (LSA) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43555 | Windows Mobile Broadband Driver »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43540 | Windows Mobile Broadband Driver »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43536 | Windows Mobile Broadband Driver Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43538 | Windows Mobile Broadband Driver »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43525 | Windows Mobile Broadband Driver Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43559 | Windows Mobile Broadband Driver »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43561 | Windows Mobile Broadband Driver »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43558 | Windows Mobile Broadband Driver »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43542 | Windows Mobile Broadband Driver »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43557 | Windows Mobile Broadband Driver »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43526 | Windows Mobile Broadband Driver Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43543 | Windows Mobile Broadband Driver Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43523 | Windows Mobile Broadband Driver Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43524 | Windows Mobile Broadband Driver Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43537 | Windows Mobile Broadband Driver »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-38124 | Windows Netlogon ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43562 | Windows ÍøÂçµØÖ·×ª»» (NAT) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43565 | Windows ÍøÂçµØÖ·×ª»» (NAT) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43553 | NT OS ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43514 | Windows Resilient File System (ReFS) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43545 | Windows Online Certificate Status Protocol (OCSP) ·þÎñÆ÷»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43529 | Windows Print Spooler ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-38262 | Windows Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43456 | Windows Remote Desktop Services ´Û¸Ä·ì϶ | ¸ßΣ |
CVE-2024-43500 | Windows Resilient File System (ReFS) ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-43592 | Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43589 | Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-38212 | Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43593 | Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-38261 | Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43611 | Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43453 | Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-38265 | Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43607 | Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43549 | Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43608 | Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43564 | Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43584 | Windows Scripting Engine °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-43550 | Windows Secure Channel ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-43516 | Windows Secure Kernel Mode ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43528 | Windows Secure Kernel Mode ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43552 | Windows Shell Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43512 | Windows Standards-Based Storage Management Service »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-43551 | Windows Storage ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43560 | Microsoft Windows Storage Port Driver ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43518 | Windows Telephony Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-43583 | Winlogon ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-43573 | Windows MSHTML Platform ºýŪ·ì϶ | ÖÐΣ |
CVE-2024-9369 | Chromium£ºCVE-2024-9369 Mojo ÖеÄÊý¾ÝÑéÖ¤²»¼° | δ֪ |
CVE-2024-9370 | Chromium£ºCVE-2024-9370 V8 ÖеIJ»Êʵ±ÊµÏÖ | δ֪ |
CVE-2024-7025 | Chromium£ºCVE-2024-7025 ²¼¾ÖÖеÄÕûÊýÒç³ö | δ֪ |
¶þ¡¢Ó°ÏìÁìÓò
ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º
Role: Windows Hyper-V
Windows Hyper-V
Windows EFI Partition
Windows Kernel
OpenSSH for Windows
Azure Monitor
Windows Netlogon
Windows Kerberos
BranchCache
Azure Stack
Windows Routing and Remote Access Service (RRAS)
.NET and Visual Studio
Windows Remote Desktop Licensing Service
Windows Remote Desktop Services
Microsoft Configuration Manager
Service Fabric
Power BI
.NET, .NET Framework, Visual Studio
Visual Studio Code
DeepSpeed
Windows Resilient File System (ReFS)
Windows Common Log File System Driver
Microsoft Office SharePoint
Microsoft Office Excel
Microsoft Office Visio
Microsoft Graphics Component
Windows Standards-Based Storage Management Service
Windows BitLocker
Windows NTFS
Internet Small Computer Systems Interface (iSCSI)
Windows Secure Kernel Mode
Microsoft ActiveX
Windows Telephony Server
Microsoft WDAC OLE DB provider for SQL
Windows Local Security Authority (LSA)
Windows Mobile Broadband
Windows Print Spooler Components
RPC Endpoint Mapper Service
Remote Desktop Client
Windows Kernel-Mode Drivers
Microsoft Simple Certificate Enrollment Protocol
Windows Online Certificate Status Protocol (OCSP)
Windows Cryptographic Services
Windows Secure Channel
Windows Storage
Windows Shell
Windows NT OS Kernel
Windows Storage Port Driver
Windows Network Address Translation (NAT)
Windows Ancillary Function Driver for WinSock
Sudo for Windows
Microsoft Management Console
Windows MSHTML Platform
Microsoft Windows Speech
Microsoft Office
Windows Remote Desktop
Winlogon
Windows Scripting
Code Integrity Guard
Visual C++ Redistributable Installer
Azure CLI
Visual Studio
Outlook for Android
Microsoft Defender for Endpoint
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2024Äê10Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2024-Oct
²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

Àý1£ºÎ¢Èí·ì϶ÁÐ±í£¨Ê¾Àý£©
2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿ÁÐÑ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áдò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Oct
https://www.bleepingcomputer.com/news/microsoft/microsoft-october-2024-patch-tuesday-fixes-5-zero-days-118-flaws/
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43581
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-10-09 | ³õ´Î°ä²¼ |
Îå¡¢¸½Â¼
5.1 GA»Æ½ð¼×¼ò½é
GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£
5.2 ¹ØÓÚGA»Æ½ð¼×
GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ