¡¾·ì϶¹«¸æ¡¿Î¢Èí11Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2024-11-13


Ò»¡¢·ì϶¸ÅÊö

2024Äê11ÔÂ13ÈÕ £¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Î¢Èí°ä²¼ÁË11Ô°²È«¸üР£¬±¾´Î¸üй²½¨¸´ÁË89¸ö·ì϶£¨²»Ô̺¬Ö®Ç°½¨¸´µÄEdge·ì϶£© £¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶ºÍºýŪ·ì϶µÈ¡£

±¾´Î°²È«¸üÐÂÖн¨¸´ÁË4¸ö0 day·ì϶ £¬ÆäÖÐ2¸öÒÑ·¢´Ë¿Ì¹¥»÷Öб»ÀûÓà £¬3¸öÒѾ­¹«¿ªÅû¶£º

CVE-2024-43451£ºNTLM ¹þϣй¶ºýŪ·ì϶

Windows´æÔÚNTLM ¹þϣй¶ºýŪ·ì϶ £¬ÆäCVSSÆÀ·ÖΪ6.5 £¬ÀûÓø÷ì϶±ØÒªÓû§½»»¥ £¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÏò¹¥»÷Õßй¶Óû§µÄ NTLMv2 ¹þÏ£ £¬¹¥»÷ÕßÄܹ»Ê¹ÓÃËüÀ´ÑéÖ¤Óû§Éí·Ý¡£Ä¿Ç°¸Ã·ì϶ÒѾ­¹«¿ªÅû¶ £¬ÇÒÒѼì²âµ½·ì϶ÀûÓá£

CVE-2024-49039£ºWindows Task SchedulerÌØÈ¨ÌáÉý·ì϶

Windows ¹¤×÷´òË㷨ʽÖдæÔÚÉí·ÝÑéÖ¤²»µ± £¬¿ÉÄܵ¼ÖÂȨÏÞÌáÉý £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8 £¬¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÔÚÖ¸±êϵͳÉÏÔËÐжñÒâÉè¼ÆµÄÀûÓ÷¨Ê½ £¬ÀûÓø÷ì϶ÌáÉýÆäȨÏÞ £¬³É¹¦ÀûÓÃÔÊÐí¹¥»÷ÕßÖ´ÐÐͨ³£½öÏÞÓÚÌØÈ¨ÕË»§µÄRPCÖ°ÄÜ¡£Ä¿Ç°¸Ã·ì϶ÒѼì²âµ½·ì϶ÀûÓá£

CVE-2024-49040£ºMicrosoft Exchange Server ºýŪ·ì϶

Microsoft Exchange ServerÖдæÔÚºýŪ·ì϶ £¬ÆäCVSSÆÀ·ÖΪ7.5 £¬¸Ã·ì϶ÔÊÐí¹¥»÷ÕßÔÚ·¢Ë͸ø±¾µØÊÕ¼þÈ˵ĵç×ÓÓʼþÖÐαÔì·¢¼þÈ˵ĵç×ÓÓʼþµØÖ· £¬µ¼ÖºýŪ¹¥»÷¡£Ä¿Ç°¸Ã·ì϶ÒѾ­¹«¿ªÅû¶ £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£

CVE-2024-49019£ºActive Directory Ö¤Êé·þÎñÌØÈ¨ÌáÉý·ì϶

Active Directory Ö¤Êé·þÎñ´æÔÚÈõÉí·ÝÑéÖ¤ÎÊÌâ £¬¿ÉÄܵ¼ÖÂÌØÈ¨ÌáÉý £¬ÆäCVSSÆÀ·ÖΪ7.8 £¬¸Ã·ì϶ÔÊÐí¹¥»÷Õßͨ¹ýÀÄÓÃÄÚÖÃĬÈϰ汾1Ö¤ÊéÄ£°åÀ´»ñÈ¡ÓòÖÎÀíԱȨÏÞ¡£Ä¿Ç°¸Ã·ì϶ÒѾ­¹«¿ªÅû¶ £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£

±¾´Î°²È«¸üÐÂÖн¨¸´µÄ4¸öÑϳÁ·ì϶Ϊ£º

CVE-2024-43498£º.NET & Visual StudioÔ¶³Ì´úÂëÖ´Ðзì϶

.NET ºÍ Visual StudioÖдæÔÚÀàÐÍ»ìºÏ·ì϶ £¬ÆäCVSSÆÀ·ÖΪ9.8 £¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÏò´æÔÚ·ì϶µÄ .NET Web ÀûÓ÷¨Ê½·¢ËÍÌØÔìÒªÇó»ò½«ÌØÔìÎļþ¼ÓÔØµ½´æÔÚ·ì϶µÄ×ÀÃæÀûÓ÷¨Ê½ÖÐÀ´ÀûÓø÷ì϶ £¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס±¡£

CVE-2024-49056£ºAirlift.microsoft.com ÌØÈ¨ÌáÉý·ì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.3 £¬Í¨¹ý airlift.microsoft.com Éϼٶ¨²»³É±äÊý¾ÝÈÆ¹ýÉí·ÝÑéÖ¤ £¬ÊÚȨ¹¥»÷ÕßÄܹ»Í¨¹ýÍøÂçÌáÉýȨÏÞ¡£¸Ã·ì϶ÎÞÐèÓû§²ÉÈ¡ÈκδëÊ©¼´¿É½â¾ö¡£

CVE-2024-43639£ºWindows KDC ProxyÔ¶³Ì´úÂëÖ´Ðзì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8 £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Ê¹ÓÃÌØÔìÀûÓ÷¨Ê½ÀûÓÃWindows KerberosÖеļÓÃܺÍ̸·ì϶¶ÔÖ¸±êÖ´ÐÐÔ¶³Ì´úÂë¡£

CVE-2024-43625£ºMicrosoft Windows VMSwitch ÌØÈ¨ÌáÉý·ì϶

Microsoft Hyper-V ÖÐµÄ VmSwitch ×é¼þ´æÔÚUse-After-Free·ì϶ £¬ÆäCVSSÆÀ·ÖΪ8.1 £¬¹¥»÷Õß¿Éͨ¹ýÏòVMswitch Çý¶¯·¨Ê½·¢ËÍһϵÁÐÌØ¶¨µÄÍøÂçÒªÇó £¬´Ó¶ø´¥·¢ Hyper-V Ö÷»úÖеĿªÊͺó³ÁÓ÷ì϶ £¬³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃ SYSTEM ȨÏÞ¡£

³ýCVE-2024-49040ºÍCVE-2024-49019±í £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ·ì϶»¹Ô̺¬ÒÔÏ·ì϶ £¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶»ñµÃ SYSTEM ȨÏÞ¡¢µ¼Ö»ؾø·þÎñ»òÈÆ¹ýOfficeÊܱ  £»¤ÊÓͼµÄÌØ¶¨Ö°ÄÜ£º

CVE-2024-43623£ºWindows NT OS KernelÌØÈ¨ÌáÉý·ì϶

CVE-2024-43629£ºWindows DWM Core LibraryÌØÈ¨ÌáÉý·ì϶

CVE-2024-43630£ºWindows KernelÌØÈ¨ÌáÉý·ì϶

CVE-2024-43636£ºWin32kÌØÈ¨ÌáÉý·ì϶

CVE-2024-43642£ºWindows SMB »Ø¾ø·þÎñ·ì϶

CVE-2024-49033£ºMicrosoft Word°²È«Ö°ÄÜÈÆ¹ý·ì϶

΢Èí11Ô¸üн¨¸´µÄÆëÈ«·ì϶ÁбíÈçÏ£º

CVE-IDCVE ±êÌâÑϳÁÐÔ
CVE-2024-43498.NET & Visual Studio Ô¶³Ì´úÂëÖ´Ðзì϶ÑϳÁ
CVE-2024-49056Airlift.microsoft.com ÌØÈ¨ÌáÉý·ì϶ÑϳÁ
CVE-2024-43639Windows KDC ProxyÔ¶³Ì´úÂëÖ´Ðзì϶ÑϳÁ
CVE-2024-43625Microsoft Windows VMSwitch ÌØÈ¨ÌáÉý·ì϶ÑϳÁ
CVE-2024-43499.NET & Visual Studio »Ø¾ø·þÎñ·ì϶¸ßΣ
CVE-2024-43602Azure CycleCloud Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-43598LightGBM Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-5535OpenSSL£ºCVE-2024-5535  SSL_select_next_proto »º³åÇø¸²¸Ç¸ßΣ
CVE-2024-49040Microsoft Exchange Server ºýŪ·ì϶¸ßΣ
CVE-2024-49031Microsoft Office Graphics Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49032Microsoft Office Graphics Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49029Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49026Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49027Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49028Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49030Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49033Microsoft Word °²È«Ö°ÄÜÈÆ¹ý·ì϶¸ßΣ
CVE-2024-49051Microsoft PC Manager ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-38264Microsoft Ðé¹¹Ó²ÅÌ (VHDX) »Ø¾ø·þÎñ·ì϶¸ßΣ
CVE-2024-43450Windows DNS ºýŪ·ì϶¸ßΣ
CVE-2024-49019Active Directory Ö¤Êé·þÎñÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43633Windows Hyper-V »Ø¾ø·þÎñ·ì϶¸ßΣ
CVE-2024-43624Windows Hyper-V ¹²ÏíÐé¹¹´ÅÅÌÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-48998SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-48997SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-48993SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49001SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49000SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-48999SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49043Microsoft.SqlServer.XEvent.Configuration.dll  Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-43462SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-48995SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-48994SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-38255SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-48996SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-43459SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49002SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49013SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49014SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49011SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49012SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49015SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49018SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49021Microsoft SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49016SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49017SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49010SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49005SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49007SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49003SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49004SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49006SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49009SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49008SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49048TorchGeo Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49044Visual Studio ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-49050Visual Studio Code Python Extension  Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-43644Windows Client-Side Caching ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43645Windows Defender ÀûÓ÷¨Ê½½ÚÔì (WDAC) °²È«Ö°ÄÜÈÆ¹ý·ì϶¸ßΣ
CVE-2024-43636Win32k ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43629Windows DWM Core Library ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43630Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43623Windows NT OS Kernel ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43451NTLM ¹þϣй¶ºýŪ·ì϶¸ßΣ
CVE-2024-38203Windows Package Library Manager ÐÅϢй¶·ì϶¸ßΣ
CVE-2024-43641Windows ×¢²á±íÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43452Windows ×¢²á±íÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43631Windows Secure Kernel Mode ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43646Windows Secure Kernel Mode ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43640Windows Kernel-Mode Driver ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43642Windows SMB »Ø¾ø·þÎñ·ì϶¸ßΣ
CVE-2024-43447Windows SMBv3 Server Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-49039Windows Task Scheduler ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43628Windows Telephony Service Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-43621Windows Telephony Service Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-43620Windows Telephony Service Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-43627Windows Telephony Service Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-43635Windows Telephony Service Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-43622Windows Telephony Service Ô¶³Ì´úÂëÖ´Ðзì϶¸ßΣ
CVE-2024-43626Windows Telephony Service ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43530Windows Update Stack ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43643Windows USB Video Class System Driver  ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43449Windows USB Video Class System Driver  ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43637Windows USB Video Class System Driver  ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43634Windows USB Video Class System Driver  ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-43638Windows USB Video Class System Driver  ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-49046Windows Win32 Kernel Subsystem ÌØÈ¨ÌáÉý·ì϶¸ßΣ
CVE-2024-49049Visual Studio Code Remote Extension ÌØÈ¨ÌáÉý·ì϶ÖÐΣ
ADV240001Microsoft SharePoint Server ×ÝÉî·ÀÓù¸üÐÂÎÞ
CVE-2024-10826Chromium£ºCVE-2024-10826 ÔÚ Family  Experiences ÖÐUse-after-freeδ֪
CVE-2024-10827Chromium£ºCVE-2024-10827  SerialÖеÄUse-after-freeδ֪


?

¶þ¡¢Ó°ÏìÁìÓò

ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º

Windows Package Library Manager

SQL Server

Microsoft Virtual Hard Drive

Windows SMBv3 Client/Server

Windows USB Video Driver

Microsoft Windows DNS

Windows NTLM

Windows Registry

.NET and Visual Studio

Windows Update Stack

LightGBM

Azure CycleCloud

Azure Database for PostgreSQL

Windows Telephony Service

Windows NT OS Kernel

Role: Windows Hyper-V

Windows VMSwitch

Windows DWM Core Library

Windows Kernel

Windows Secure Kernel Mode

Windows Kerberos

Windows SMB

Windows CSC Service

Windows Defender Application Control (WDAC)

Windows Active Directory Certificate Services

Microsoft Office Excel

Microsoft Graphics Component

Microsoft Office Word

Windows Task Scheduler

Microsoft Exchange Server

Visual Studio

Windows Win32 Kernel Subsystem

TorchGeo

Visual Studio Code

Microsoft PC Manager

Airlift.microsoft.com



Èý¡¢°²È«´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üР£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓà £¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ £¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü £¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡± £¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС± £¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС± £¬ÆÚ´ýϵͳ×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú £¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüР£¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó £¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡± £¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2024Äê11Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Nov

²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó £¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

 

image.png


Àý1£ºÎ¢Èí·ì϶ÁÐ±í£¨Ê¾Àý£©

2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿ÁÐÑ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ £¬µã»÷ÓҲࡾÏÂÔØ¡¿Áдò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

 image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾°²È«¸üС¿ £¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ £¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

 

image.png


Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£

3.2 һʱ´ëÊ©

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

 ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡ £¬Ï÷¼õϵͳ·ì϶ £¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£

 ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔì £¬Åú¸Ä·À»ðǽսÊõ £¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ £¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø £¬Ï÷¼õ¹¥»÷Ãæ¡£

 Ê¹ÓÃÆóÒµ¼¶°²È«²úÆ· £¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£

 ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí £¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò £¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£

 ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Nov

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49019

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43639


ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-11-13

³õ´Î°ä²¼



Îå¡¢¸½Â¼

5.1 GA»Æ½ð¼×¼ò½é

GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Äê £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏà £¬¹«Ë¾Ô±¹¤6000ÓàÈË £¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ £¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£

5.2 ¹ØÓÚGA»Æ½ð¼×

GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯ £¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶ £¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

 

image.png