¡¾·ì϶¹«¸æ¡¿Î¢Èí12Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2024-12-11


Ò»¡¢·ì϶¸ÅÊö

2024Äê12ÔÂ11ÈÕ £¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Î¢Èí°ä²¼ÁË12Ô°²È«¸üР£¬±¾´Î¸üй²½¨¸´ÁË71¸ö·ì϶£¨²»Ô̺¬Ö®Ç°½¨¸´µÄEdge·ì϶£© £¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶ºÍºýŪ·ì϶µÈ ¡£

±¾´Î°²È«¸üÐÂÖн¨¸´ÁË1¸öÒѾ­¹«¿ªÅû¶ÇÒÒÑ·¢ÏÖ±»»ý¼«ÀûÓõÄ0 day·ì϶£º

CVE-2024-49138£ºWindows Common Log File System DriverÌØÈ¨ÌáÉý·ì϶

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÖдæÔÚ»ùÓڶѵĻº³åÇøÒç¶Âí½Å £¬ÆäCVSSÆÀ·ÖΪ7.8 £¬³É¹¦ÀûÓø÷ì϶µÄ¿É»ñµÃSYSTEM ȨÏÞ ¡£Ä¿Ç°¸Ã·ì϶ÒѾ­¹«¿ªÅû¶ÇÒÒÑ·¢ÏÖ±»ÀûÓà ¡£

±¾´Î°²È«¸üÐÂÖн¨¸´µÄ16¸öÑϳÁ·ì϶Ϊ£º

CVE-2024-49117£ºWindows Hyper-V Ô¶³Ì´úÂëÖ´Ðзì϶

Windows Hyper-V´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8 £¬guestÐé¹¹»úÉϾ­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÏòÐé¹¹»úÉϵÄÓ²¼þ×ÊÔ´·¢ËÍÌØÔìµÄÎļþ²Ù×÷ÒªÇó £¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔÚÖ÷»ú·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë ¡£

CVE-2024-49124£ºLightweight Directory Access Protocol (LDAP) Client Ô¶³Ì´úÂëÖ´Ðзì϶

Lightweight Directory Access Protocol (LDAP) Clien´æÔÚ¾ºÕùǰÌá·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.1 £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Ïò´æÔÚ·ì϶µÄ·þÎñÆ÷·¢ËÍÌØÔìÒªÇó £¬³É¹¦ÀûÓø÷ì϶¿Éµ¼Ö¹¥»÷ÕߵĴúÂëÔÚ SYSTEM ÕÊ»§¸ßµÍÎÄÖÐÔËÐÐ ¡£

CVE-2024-49112£ºWindows Lightweight Directory Access Protocol (LDAP) Ô¶³Ì´úÂëÖ´Ðзì϶

Windows ÇáÁ¿¼¶Ä¿Â¼½Ó¼ûºÍ̸ (LDAP)´æÔÚUse-After-Free·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.1 £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Ïò´æÔÚ·ì϶µÄ·þÎñÆ÷·¢ËÍÌØÔìÒªÇó £¬³É¹¦ÀûÓø÷ì϶¿Éµ¼Ö¹¥»÷ÕߵĴúÂëÔÚ SYSTEM ÕÊ»§¸ßµÍÎÄÖÐÔËÐÐ ¡£

CVE-2024-49127£ºWindows Lightweight Directory Access Protocol (LDAP) Ô¶³Ì´úÂëÖ´Ðзì϶

Windows ÇáÁ¿¼¶Ä¿Â¼½Ó¼ûºÍ̸ (LDAP)´æÔÚÕûÊýÒç³ö»ò»·±§·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8 £¬³É¹¦ÀûÓø÷ì϶µÄδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ýÒ»×éÌØÔìµÄ LDAP ŲÓÃÀ´»ñÈ¡´úÂëÖ´ÐÐȨÏÞ £¬´Ó¶øÔÚ LDAP ·þÎñµÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë ¡£

CVE-2024-49126£ºWindows Local Security Authority Subsystem Service Ô¶³Ì´úÂëÖ´Ðзì϶

Windows ±¾µØ°²È«»ú¹¹×Óϵͳ·þÎñ (LSASS)´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.1 £¬¹¥»÷ÕßÄܹ»Í¨¹ýÍøÂçŲÓÃÔÚ·þÎñÆ÷ÕÊ»§¸ßµÍÎÄÖд¥·¢¶ñÒâ´úÂë £¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ £¬³É¹¦ÀûÓø÷ì϶±ØÒª¹¥»÷ÕßÓ®µÃ¾ºÕùǰÌá ¡£

CVE-2024-49118£ºMicrosoft Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft ÐÂÎŶÓÁÐ (MSMQ)´æÔÚUse-After-Free·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.1 £¬¹¥»÷Õß¿Éͨ¹ýÏò MSMQ ·þÎñÆ÷·¢ËÍÌØÔìµÄ¶ñÒâMSMQ Êý¾Ý°ü £¬¿ÉÄܵ¼Ö·þÎñÆ÷¶ËÔ¶³Ì´úÂëÖ´ÐÐ ¡£¸Ã·ì϶µÄ¹¥»÷¸´ÔӶȽϸß £¬¿ÉÄܱØÒª¹¥»÷ÕßÓ®µÃ¾ºÕùǰÌá ¡£

CVE-2024-49122£ºMicrosoft Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft ÐÂÎŶÓÁÐ (MSMQ)´æÔÚUse-After-Free·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.1 £¬¹¥»÷Õß¿Éͨ¹ýÏòMSMQ·þÎñÆ÷·¢ËÍÌØÔìµÄ¶ñÒâMSMQ Êý¾Ý°üÀûÓø÷ì϶ £¬¿ÉÄܵ¼ÖÂÔÚ·þÎñÆ÷¶ËÔ¶³ÌÖ´ÐдúÂë ¡£³É¹¦ÀûÓø÷ì϶±ØÒª¹¥»÷ÕßÓ®µÃ¾ºÕùǰÌá £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ± ¡£

CVE-2024-49132/ CVE-2024-49115/ CVE-2024-49116/ CVE-2024-49123/ CVE-2024-49128/ CVE-2024-49106/ CVE-2024-49108£ºWindows Remote Desktop Services Ô¶³Ì´úÂëÖ´Ðзì϶

Windows Ô¶³Ì×ÀÃæ·þÎñ´æÔÚUse-After-Free·ì϶»òÃô¸ÐÊý¾Ý´æ´¢ÔÚδÕýÈ·Ëø¶¨µÄÄÚ´æÖÐ £¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ £¬ÕâЩ·ì϶µÄCVSSÆÀ·Ö¾ùΪ8.1 £¬¹¥»÷ÕßÄܹ»Í¨¹ýÏνӵ½ÔËÐÐÔ¶³Ì×ÀÃæÍø¹Ø½ÇÉ«µÄÖ¸±êϵͳ £¬ÀûÓþºÕùǰÌá £¬´¥·¢Use-After-Free·ì϶ £¬³É¹¦ÀûÓÃÕâЩ·ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë £¬µ«±ØÒª¹¥»÷ÕßÓ®µÃ¾ºÕùǰÌá ¡£

CVE-2024-49119£ºWindows Remote Desktop Services Ô¶³Ì´úÂëÖ´Ðзì϶

Windows Ô¶³Ì×ÀÃæ·þÎñ´æÔÚÀàÐÍ»ìºÏ·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.1 £¬³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë £¬µ«±ØÒª¹¥»÷ÕßÓ®µÃ¾ºÕùǰÌá ¡£

CVE-2024-49120£ºWindows Remote Desktop Services Ô¶³Ì´úÂëÖ´Ðзì϶

Windows Ô¶³Ì×ÀÃæ·þÎñ´æÔÚ²»°²È«µÄĬÈϱäÁ¿³õʼ»¯ÎÊÌâ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.1 £¬³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë £¬µ«±ØÒª¹¥»÷ÕßÓ®µÃ¾ºÕùǰÌá ¡£

³ýCVE-2024-49122±í £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ·ì϶»¹Ô̺¬£º

CVE-2024-49070£ºMicrosoft SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft SharePoint´æÔÚ·´ÐòÁл¯·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.4 £¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼Ö±¾µØËÁÒâ´úÂëÖ´ÐÐ ¡£

CVE-2024-49088£ºWindows Common Log File System DriverÌØÈ¨ÌáÉý·ì϶

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½´æÔÚȨÏÞÌáÉý·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8 £¬¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñµÃ SYSTEM ȨÏÞ ¡£

CVE-2024-49090£ºWindows Common Log File System DriverÌØÈ¨ÌáÉý·ì϶

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½´æÔÚȨÏÞÌáÉý·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8 £¬¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñµÃ SYSTEM ȨÏÞ ¡£

CVE-2024-49093£ºWindows µ¯ÐÔÎļþϵͳ (ReFS) ÌØÈ¨ÌáÉý·ì϶

Windows Resilient File System (ReFS)´æÔÚȨÏÞÌáÉý·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8 £¬¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñµÃ SYSTEM ȨÏÞ ¡£

CVE-2024-49114£ºWindows Cloud Files Mini Filter Çý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

Windows Cloud Files Mini Filter Çý¶¯·¨Ê½´æÔÚȨÏÞÌáÉý·ì϶ £¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.8 £¬¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñµÃ SYSTEM ȨÏÞ ¡£

΢Èí12Ô¸üн¨¸´µÄÆëÈ«·ì϶ÁбíÈçÏ£º

CVE 񅧏

CVE ±êÌâ

ÑϳÁÐÔ

CVE-2024-49117

Windows Hyper-V Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-49124

Lightweight Directory Access Protocol (LDAP) Client Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-49112

Windows Lightweight Directory Access Protocol (LDAP) Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-49127

Windows Lightweight Directory Access Protocol (LDAP) Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-49126

Windows Local Security Authority Subsystem Service Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-49118

Microsoft Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-49122

Microsoft Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-49132

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-49115

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-49116

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-49123

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-49128

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-49106

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-49108

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-49119

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-49120

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-49063

Microsoft/Muzic Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-49057

Microsoft Defender for Endpoint on Android ºýŪ·ì϶

¸ßΣ

CVE-2024-49059

Microsoft Office ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-43600

Microsoft Office ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49142

Microsoft Access Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-49069

Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-49079

Input Method Editor (IME) Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-49064

Microsoft SharePoint ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-49062

Microsoft SharePoint ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-49068

Microsoft SharePoint ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49070

Microsoft SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-49065

Microsoft Office Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-49091

Windows Domain Name Service Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-43594

System Center Operations Manager ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49114

Windows Cloud Files Mini Filter Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49088

Windows Common Log File System Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49138

Windows Common Log File System Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49090

Windows Common Log File System Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49082

Windows File Explorer ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-49080

Windows IP Routing Management Snapin Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-49084

Windows Kernel ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49074

Windows Kernel-Mode Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49121

Windows Lightweight Directory Access Protocol (LDAP) »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-49113

Windows Lightweight Directory Access Protocol (LDAP) »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-49096

Microsoft Message Queuing (MSMQ) »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-49073

Windows Mobile Broadband Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49077

Windows Mobile Broadband Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49083

Windows Mobile Broadband Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49092

Windows Mobile Broadband Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49087

Windows Mobile Broadband Driver ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-49110

Windows Mobile Broadband Driver ȨÌáÉý·ì϶

¸ßΣ

CVE-2024-49078

Windows Mobile Broadband Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49095

Windows PrintWorkflowUserSvc ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49097

Windows PrintWorkflowUserSvc ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49129

Windows Remote Desktop Gateway (RD Gateway) »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-49075

Windows Remote Desktop Services »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-49093

Windows Resilient File System (ReFS) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49085

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-49086

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-49089

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-49125

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-49104

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-49102

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-49072

Windows Task Scheduler ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49076

Windows Virtualization-Based Security (VBS) Enclave ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49081

Wireless Wide Area Network Service (WwanSvc) Elevation ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49103

Windows Wireless Wide Area Network Service (WwanSvc) ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-49111

Wireless Wide Area Network Service (WwanSvc) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49109

Wireless Wide Area Network Service (WwanSvc) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49101

Wireless Wide Area Network Service (WwanSvc) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49094

Wireless Wide Area Network Service (WwanSvc) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49098

Windows Wireless Wide Area Network Service (WwanSvc) ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-49099

Windows Wireless Wide Area Network Service (WwanSvc) ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-49107

WmsRepair Service ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-49041

Microsoft Edge£¨»ùÓÚ Chromium£©ºýŪ·ì϶

ÖÐΣ

ADV240002

Microsoft Office ×ÝÉî·ÀÓù¸üÐÂ

ÖÐΣ

CVE-2024-12053

Chromium£ºCVE-2024-12053 V8 ÖеÄÀàÐÍ»ìºÏ

δ֪

 

¶þ¡¢Ó°ÏìÁìÓò

ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º

System Center Operations Manager

Microsoft Office

Microsoft Edge (Chromium-based)

Microsoft Defender for Endpoint

Microsoft Office SharePoint

GitHub

Microsoft Office Word

Microsoft Office Excel

Windows Task Scheduler

Windows Mobile Broadband

Windows Kernel-Mode Drivers

Windows Remote Desktop Services

Windows Virtualization-Based Security (VBS) Enclave

Microsoft Office Publisher

Windows IP Routing Management Snapin

Windows Wireless Wide Area Network Service

Windows File Explorer

Windows Kernel

Windows Routing and Remote Access Service (RRAS)

Windows Common Log File System Driver

Role: DNS Server

Windows Resilient File System (ReFS)

Windows PrintWorkflowUserSvc

Windows Message Queuing

Remote Desktop Client

WmsRepair Service

Windows LDAP - Lightweight Directory Access Protocol

Windows Cloud Files Mini Filter Driver

Role: Windows Hyper-V

Windows Local Security Authority Subsystem Service (LSASS)

Windows Remote Desktop

Microsoft Office Access

 

Èý¡¢°²È«´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üР£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´ ¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓà £¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ £¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öà ¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü £¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡± £¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС± £¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС± £¬ÆÚ´ýϵͳ×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüР¡£

4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú £¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üР¡£¶ÔÓÚûÓгɹ¦×°ÖõĸüР£¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó £¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡± £¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öà ¡£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüР¡£

2024Äê12Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Dec

²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó £¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó ¡£

image.png 

Àý1£ºÎ¢Èí·ì϶ÁÐ±í£¨Ê¾Àý£©

2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿ÁÐÑ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ £¬µã»÷ÓҲࡾÏÂÔØ¡¿Áдò¿ª²¹¶¡ÏÂÔØÁ´½Ó ¡£

image.png 

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾°²È«¸üС¿ £¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ £¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öà ¡£

image.png 

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú ¡£

3.2 һʱ´ëÊ©

ÔÝÎÞ ¡£

3.3 ͨÓý¨Òé

l¶¨ÆÚ¸üÐÂϵͳ²¹¶¡ £¬Ï÷¼õϵͳ·ì϶ £¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ ¡£

l¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔì £¬Åú¸Ä·À»ðǽսÊõ £¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ £¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø £¬Ï÷¼õ¹¥»÷Ãæ ¡£

lʹÓÃÆóÒµ¼¶°²È«²úÆ· £¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ ¡£

l¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí £¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò £¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È ¡£

lÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä ¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Dec

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49138

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-12-11

³õ´Î°ä²¼

 

 

Îå¡¢¸½Â¼

5.1 GA»Æ½ð¼×¼ò½é

GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Äê £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò» ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏà £¬¹«Ë¾Ô±¹¤6000ÓàÈË £¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË ¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊÐ ¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ £¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦ ¡£

5.2 ¹ØÓÚGA»Æ½ð¼×

GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æºÍ·çÏÕÔ¤¾¯ £¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶ £¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½ ¡£

¹Ø×¢ÎÒÃÇ£º

image.png