¡¾·ì϶¹«¸æ¡¿Î¢Èí3Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2025-03-12

Ò»¡¢·ì϶¸ÅÊö


2025Äê3ÔÂ12ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Î¢Èí°ä²¼ÁË3Ô°²È«¸üУ¬±¾´Î¸üн¨¸´ÁË57¸ö·ì϶£¬º­¸ÇȨÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐÓ×¢ºýŪµÈ¶àÖÖ·ì϶ÀàÐÍ¡£·ì϶¼¶±ðÉ¢²¼ÈçÏ£º6¸öÑϳÁ¼¶±ð·ì϶£¬50¸ö³ÁÒª¼¶±ð·ì϶£¬1¸öµÍΣ¼¶±ð·ì϶£¨·ì϶¼¶±ðƾ¾Ý΢Èí¹Ù·½Êý¾Ý£©¡£


ÆäÖУ¬16¸ö·ì϶±»Î¢ÈíÏóÕ÷Ϊ¡°¸ü¿ÉÄܱ»ÀûÓá±¼°¡°¼ì²âÀûÓÃÇé¾°¡±£¬Åú×¢ÕâЩ·ì϶´æÔڽϸߵÄÀûÓ÷çÏÕ£¬½¨ÒéÓÅÏȽ¨¸´ÒÔ½µµÍDZÔÚ°²È«Íþв¡£


CVE-ID

CVE ±êÌâ

·ì϶¼¶±ð

CVE-2025-24983

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24984

Windows NTFS ÐÅϢй¶·ì϶

³ÁÒª

CVE-2025-24985

Windows FAST FAT ÎļþϵͳÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-24991

Windows NTFS ÐÅϢй¶·ì϶

³ÁÒª

CVE-2025-24993

Windows NTFS Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-26633

Microsoft ÖÎÀí½ÚÔį̀°²È«Ö°ÄÜÈÆ¹ý·ì϶

³ÁÒª

CVE-2025-21180

Windows exFAT ÎļþϵͳԶ³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-21247

MapUrlToZone °²È«Ö°ÄÜÈÆ¹ý·ì϶

³ÁÒª

CVE-2025-24035

Windows Ô¶³Ì×ÀÃæ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2025-24044

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24045

Windows Ô¶³Ì×ÀÃæ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2025-24061

Windows Web ²éÎÊÏóÕ÷°²È«Ö°ÄÜÈÆ¹ý·ì϶

³ÁÒª

CVE-2025-24066

ÄÚºËÁ÷ʽ´¦Ö÷þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24067

ÄÚºËÁ÷ʽ´¦Ö÷þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24992

Windows NTFS ÐÅϢй¶·ì϶

³ÁÒª

CVE-2025-24995

Kernel Streaming WOW Thunk ·þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

³ÁÒª


΢Èí3Ô¸üн¨¸´µÄÆëÈ«·ì϶ÁбíÈçÏ£º


CVE-ID

CVE ±êÌâ

·ì϶¼¶±ð

CVE-2025-21180

Windows exFAT ÎļþϵͳԶ³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-21199

Azure ±¸·ÝºÍÕ¾µã¸´Ô­´úÀí×°Ö÷¨Ê½ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21247

MapUrlToZone °²È«Ö°ÄÜÈÆ¹ý·ì϶

³ÁÒª

CVE-2025-24035

Windows Ô¶³Ì×ÀÃæ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2025-24043

WinDbg Ô¶³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-24044

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24045

Windows Ô¶³Ì×ÀÃæ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2025-24046

ÄÚºËÁ÷ʽ´¦Ö÷þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24048

Windows Hyper-V ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24049

Azure ºÅÁîÐм¯³É (CLI) ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24050

Windows Hyper-V ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24051

Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-24054

NTLM ¹þϣй¶ºýŪ·ì϶

³ÁÒª

CVE-2025-24055

Windows USB ÊÓÆÂ·àϵͳÇý¶¯·¨Ê½ÐÅÏ¢Åû¶·ì϶

³ÁÒª

CVE-2025-24056

Windows µç»°·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-24057

Microsoft Office Ô¶³ÌÖ´ÐдúÂë·ì϶

ÑϳÁ

CVE-2025-24059

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌáÉýȨÏÞ·ì϶

³ÁÒª

CVE-2025-24061

Windows Web ²éÎÊÏóÕ÷°²È«Ö°ÄÜÈÆ¹ý·ì϶

³ÁÒª

CVE-2025-24064

Windows ÓòÃû·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2025-24066

ÄÚºËÁ÷ʽ´¦Ö÷þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24067

ÄÚºËÁ÷ʽ´¦Ö÷þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24070

ASP.NET Core ºÍ Visual Studio

³ÁÒª

CVE-2025-24071

Microsoft Windows Îļþ×ÊÔ´ÖÎÀíÆ÷ºýŪ·ì϶

³ÁÒª

CVE-2025-24072

Microsoft ±¾µØ°²È«»ú¹¹ (LSA) ·þÎñÆ÷ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24075

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-24076

Microsoft Windows ¿çÉ豸·þÎñÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24077

Microsoft Word Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-24078

Microsoft Word Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-24079

Microsoft Word Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-24080

Microsoft Office Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-24081

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-24082

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-24083

Microsoft Office Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-24084

ºÏÓÃÓÚ Linux µÄ Windows ×Óϵͳ (WSL2) ÄÚºËÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2025-24983

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24984

Windows NTFS ÐÅϢй¶·ì϶

³ÁÒª

CVE-2025-24985

Windows FAST FAT ÎļþϵͳÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-24986

Azure Promptflow Ô¶³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-24987

Windows USB ÊÓÆÂ·àϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24988

Windows USB ÊÓÆÂ·àϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24991

Windows NTFS ÐÅϢй¶·ì϶

³ÁÒª

CVE-2025-24992

Windows NTFS ÐÅϢй¶·ì϶

³ÁÒª

CVE-2025-24993

Windows NTFS Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-24994

Microsoft Windows ¿çÉ豸·þÎñÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24995

Kernel Streaming WOW Thunk ·þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24996

NTLM ¹þϣй¶ºýŪ·ì϶

³ÁÒª

CVE-2025-24997

DirectX ͼÐÎÄÚºËÎļþ»Ø¾ø·þÎñ·ì϶

³ÁÒª

CVE-2025-24998

Visual Studio ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-25003

Visual Studio ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-25008

Windows Server Elevation of Privilege Vulnerability

³ÁÒª

CVE-2025-26627

Azure Arc ×°Ö÷¨Ê½ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-26629

Microsoft Office Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-26630

Microsoft Access Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-26631

Visual Studio Code ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-26633

Microsoft ÖÎÀí½ÚÔį̀°²È«Ö°ÄÜÈÆ¹ý·ì϶

³ÁÒª

CVE-2025-26643

»ùÓÚ Chromium µÄ Microsoft Edge ºýŪ·ì϶

µÍ

CVE-2025-26645

Ô¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³ÌÖ´ÐдúÂë·ì϶

ÑϳÁ


¶þ¡¢Ó°ÏìÁìÓò


ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º

Windows exFAT File System

Azure Agent Installer

Windows MapUrlToZone

Windows Remote Desktop Services

.NET

Windows Win32 Kernel Subsystem

Microsoft Streaming Service

Role: Windows Hyper-V

Azure CLI

Windows Routing and Remote Access Service (RRAS)

Windows NTLM

Windows USB Video Driver

Windows Telephony Server

Microsoft Office

Windows Common Log File System Driver

Windows Mark of the Web (MOTW)

Role: DNS Server

Windows Kernel-Mode Drivers

ASP.NET Core & Visual Studio

Windows File Explorer

Microsoft Local Security Authority Server (lsasrv)

Microsoft Office Excel

Windows Cross Device Service

Microsoft Office Word

Windows Subsystem for Linux

Windows NTFS

Windows Fast FAT Driver

Azure PromptFlow

Kernel Streaming WOW Thunk Service Driver

Windows Kernel Memory

Visual Studio

Microsoft Windows

Azure Arc

Microsoft Office Access

Visual Studio Code

Microsoft Management Console

Microsoft Edge (Chromium-based)

Remote Desktop Client


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£


£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ


Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³­¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£


£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ


Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2025Äê3Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2025-Mar
²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

 

ͼƬ1.png

Àý1£ºÎ¢Èí·ì϶ÁÐ±í£¨Ê¾Àý£©


2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿ÁÐÑ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áдò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

 

ͼƬ2.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý


3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

 

ͼƬ3.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ


4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£

ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://msrc.microsoft.com/update-guide/releaseNote/2025-Mar