¡¾·ì϶¹«¸æ¡¿Î¢Èí7Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2025-07-09Ò»¡¢·ì϶¸ÅÊö
2025Äê7ÔÂ9ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Î¢Èí°ä²¼ÁË7Ô°²È«¸üУ¬±¾´Î¸üн¨¸´ÁË130¸ö·ì϶£¬º¸ÇÌØÈ¨ÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐÓ×¢ÐÅϢй¶µÈ¶àÖÖ·ì϶ÀàÐÍ¡£·ì϶¼¶±ðÉ¢²¼ÈçÏ£º12¸öÑϳÁ¼¶±ð·ì϶£¬117¸ö³ÁÒª¼¶±ð·ì϶£¬1¸öÖÐΣ¼¶±ð·ì϶£¨·ì϶¼¶±ðƾ¾Ý΢Èí¹Ù·½Êý¾Ý£©¡£
ÆäÖУ¬17¸ö·ì϶±»Î¢ÈíÏóÕ÷Ϊ¡°¸ü¿ÉÄܱ»ÀûÓá±¼°¡°¼ì²âÀûÓÃÇé¾°¡±£¬Åú×¢ÕâЩ·ì϶´æÔڽϸߵÄÀûÓ÷çÏÕ£¬½¨ÒéÓÅÏȽ¨¸´ÒÔ½µµÍDZÔÚ°²È«Íþв¡£
CVE-ID | CVE ±êÌâ | ·ì϶¼¶±ð |
CVE-2025-47978 | Windows Kerberos »Ø¾ø·þÎñ·ì϶ | ³ÁÒª |
CVE-2025-47981 | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | ÑϳÁ |
CVE-2025-47987 | Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability | ³ÁÒª |
CVE-2025-48001 | BitLocker °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ³ÁÒª |
CVE-2025-48799 | Windows Update ·þÎñȨÏÞÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-48800 | BitLocker °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ³ÁÒª |
CVE-2025-48804 | BitLocker °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ³ÁÒª |
CVE-2025-48818 | BitLocker °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ³ÁÒª |
CVE-2025-49695 | Microsoft Office Ô¶³ÌÖ´ÐдúÂë·ì϶ | ÑϳÁ |
CVE-2025-49696 | Microsoft Office Ô¶³ÌÖ´ÐдúÂë·ì϶ | ÑϳÁ |
CVE-2025-49701 | Microsoft SharePoint Ô¶³ÌÖ´ÐдúÂë·ì϶ | ³ÁÒª |
CVE-2025-49704 | Microsoft SharePoint Ô¶³ÌÖ´ÐдúÂë·ì϶ | ÑϳÁ |
CVE-2025-49718 | Microsoft SQL Server ÐÅϢй¶·ì϶ | ³ÁÒª |
CVE-2025-49724 | Windows ÏνÓÉ豸ƽ̨·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49727 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49735 | Windows KDC ´úÀí·þÎñ (KPSSVC) Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2025-49744 | Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
΢Èí7Ô¸üн¨¸´µÄÆëÈ«·ì϶ÁбíÈçÏ£º
CVE-ID | CVE ±êÌâ | ·ì϶¼¶±ð |
CVE-2025-21195 | Azure Service Fabric ÔËÐÐÊ±ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-26636 | Windows ÄÚºËÐÅϢй¶·ì϶ | ³ÁÒª |
CVE-2025-33054 | Ô¶³Ì×ÀÃæºýŪ·ì϶ | ³ÁÒª |
CVE-2025-47159 | Windows »ùÓÚÐé¹¹»¯µÄ°²È«ÐÔ (VBS) ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-47178 | Microsoft Configuration Manager Ô¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-47971 | Microsoft Ðé¹¹Ó²ÅÌÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-47972 | Windows ÊäÈë·¨±à×ëÆ÷ (IME) ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-47973 | Microsoft Ðé¹¹Ó²ÅÌÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-47975 | Windows µ¥Ò»ËÑË÷ºÍ·¢ÏÖºÍ̸ (SSDP) ·þÎñÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-47976 | Windows µ¥Ò»ËÑË÷ºÍ·¢ÏÖºÍ̸ (SSDP) ·þÎñÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-47978 | Windows Kerberos »Ø¾ø·þÎñ·ì϶ | ³ÁÒª |
CVE-2025-47980 | Windows ³ÉÏñ×é¼þÐÅϢй¶·ì϶ | ÑϳÁ |
CVE-2025-47981 | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | ÑϳÁ |
CVE-2025-47982 | Windows ´æ´¢ VSP Çý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-47984 | Windows GDI ÐÅϢй¶·ì϶ | ³ÁÒª |
CVE-2025-47985 | Windows ÊÂÎñ¸ú×ÙÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-47986 | ͨÓôòÓ¡ÖÎÀí·þÎñÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-47987 | Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability | ³ÁÒª |
CVE-2025-47988 | Azure Monitor ´úÀíÔ¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-47991 | Windows ÊäÈë·¨±à×ëÆ÷ (IME) ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-47993 | Microsoft PC Manager ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-47994 | Microsoft Office ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-47996 | Windows MBT ´«ÊäÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-47998 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-47999 | Windows Hyper-V »Ø¾ø·þÎñ·ì϶ | ³ÁÒª |
CVE-2025-48000 | Windows »¥ÁªÉ豸ƽ̨·þÎñÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-48001 | BitLocker °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ³ÁÒª |
CVE-2025-48002 | Windows Hyper-V ÐÅϢй¶·ì϶ | ³ÁÒª |
CVE-2025-48003 | BitLocker °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ³ÁÒª |
CVE-2025-48799 | Windows Update ·þÎñȨÏÞÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-48800 | BitLocker °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ³ÁÒª |
CVE-2025-48802 | Windows SMB ·þÎñÆ÷ºýŪ·ì϶ | ³ÁÒª |
CVE-2025-48803 | Windows »ùÓÚÐé¹¹»¯µÄ°²È«ÐÔ (VBS) ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-48804 | BitLocker °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ³ÁÒª |
CVE-2025-48805 | Microsoft MPEG-2 Video À©´ó·¨Ê½Ô¶³ÌÖ´ÐдúÂë·ì϶ | ³ÁÒª |
CVE-2025-48806 | Microsoft MPEG-2 Video À©´ó·¨Ê½Ô¶³ÌÖ´ÐдúÂë·ì϶ | ³ÁÒª |
CVE-2025-48808 | Windows ÄÚºËÐÅϢй¶·ì϶ | ³ÁÒª |
CVE-2025-48809 | Windows °²È«ÄÚºËģʽÐÅϢй¶·ì϶ | ³ÁÒª |
CVE-2025-48810 | Windows °²È«ÄÚºËģʽÐÅϢй¶·ì϶ | ³ÁÒª |
CVE-2025-48811 | Windows »ùÓÚÐé¹¹»¯µÄ°²È«ÐÔ (VBS) Enclave ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-48812 | Microsoft Excel ÐÅϢй¶·ì϶ | ³ÁÒª |
CVE-2025-48814 | Ô¶³Ì×ÀÃæÊÚȨ·þÎñ°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ³ÁÒª |
CVE-2025-48815 | Windows µ¥Ò»ËÑË÷ºÍ·¢ÏÖºÍ̸ (SSDP) ·þÎñÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-48816 | HID ÀàÇý¶¯Æ÷ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-48817 | Ô¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³ÌÖ´ÐдúÂë·ì϶ | ³ÁÒª |
CVE-2025-48818 | BitLocker °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ³ÁÒª |
CVE-2025-48819 | Windows ͨÓü´²å¼´Óà (UPnP) É豸Ö÷»úÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-48820 | Windows AppX ²¿Êð·þÎñÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-48821 | Windows ͨÓü´²å¼´Óà (UPnP) É豸Ö÷»úÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-48822 | Windows Hyper-V ÀëÉ¢É豸·ÖÅä (DDA) Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2025-48823 | Windows ¼ÓÃÜ·þÎñÐÅϢй¶·ì϶ | ³ÁÒª |
CVE-2025-48824 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49657 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49658 | Windows Transport Driver Interface (TDI) Translation Driver Information Disclosure Vulnerability | ³ÁÒª |
CVE-2025-49659 | Windows ´«ÊäÇý¶¯·¨Ê½½Ó¿Ú (TDI) ת»»Çý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49660 | Windows ÊÂÎñ¸ú×ÙÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49661 | WinSock µÄ Windows ¸¨ÖúÖ°ÄÜÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49663 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49664 | Windows Óû§Ä£Ê½Çý¶¯·¨Ê½¿ò¼ÜÖ÷»úÐÅϢй¶·ì϶ | ³ÁÒª |
CVE-2025-49665 | ¹¤×÷ÇøÖÐ×ªÕ¾ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49666 | Windows Server ×°ÖÃºÍÆô¶¯ÊÂÎñÍøÂçÔ¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49667 | Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49668 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49669 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49670 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49671 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) ÐÅÏ¢Åû¶·ì϶ | ³ÁÒª |
CVE-2025-49672 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49673 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49674 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49675 | Kernel Streaming WOW Thunk ·þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49676 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49677 | Microsoft ´úÀíÎļþÏµÍ³ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49678 | NTFS ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49679 | Windows Shell ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49680 | Windows Performance Recorder (WPR) »Ø¾ø·þÎñ·ì϶ | ³ÁÒª |
CVE-2025-49681 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) ÐÅÏ¢Åû¶·ì϶ | ³ÁÒª |
CVE-2025-49682 | Windows Media ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49683 | Microsoft Ðé¹¹Ó²ÅÌÔ¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49684 | Windows ´æ´¢¶Ë¿ÚÇý¶¯·¨Ê½ÐÅϢй¶·ì϶ | ³ÁÒª |
CVE-2025-49685 | Windows Search ·þÎñÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49686 | Windows TCP/IP Çý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49687 | Windows ÊäÈë·¨±à×ëÆ÷ (IME) ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49688 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49689 | Microsoft Ðé¹¹Ó²ÅÌÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49690 | Ö°ÄܽӼûÖÎÀí·þÎñ(camsvc) ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49691 | Windows Miracast ÎÞÏßÏÔʾԶ³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49693 | Microsoft ´úÀíÎļþÏµÍ³ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49694 | Microsoft ´úÀíÎļþÏµÍ³ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49695 | Microsoft Office Ô¶³ÌÖ´ÐдúÂë·ì϶ | ÑϳÁ |
CVE-2025-49696 | Microsoft Office Ô¶³ÌÖ´ÐдúÂë·ì϶ | ÑϳÁ |
CVE-2025-49697 | Microsoft Office Ô¶³ÌÖ´ÐдúÂë·ì϶ | ÑϳÁ |
CVE-2025-49698 | Microsoft Word Ô¶³ÌÖ´ÐдúÂë·ì϶ | ÑϳÁ |
CVE-2025-49699 | Microsoft Office Ô¶³ÌÖ´ÐдúÂë·ì϶ | ³ÁÒª |
CVE-2025-49700 | Microsoft Word Ô¶³ÌÖ´ÐдúÂë·ì϶ | ³ÁÒª |
CVE-2025-49701 | Microsoft SharePoint Ô¶³ÌÖ´ÐдúÂë·ì϶ | ³ÁÒª |
CVE-2025-49702 | Microsoft Office Ô¶³ÌÖ´ÐдúÂë·ì϶ | ÑϳÁ |
CVE-2025-49703 | Microsoft Word Ô¶³ÌÖ´ÐдúÂë·ì϶ | ÑϳÁ |
CVE-2025-49704 | Microsoft SharePoint Ô¶³ÌÖ´ÐдúÂë·ì϶ | ÑϳÁ |
CVE-2025-49705 | Microsoft PowerPoint Ô¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49706 | Microsoft SharePoint Server ºýŪ·ì϶ | ³ÁÒª |
CVE-2025-49711 | Microsoft Excel Ô¶³ÌÖ´ÐдúÂë·ì϶ | ³ÁÒª |
CVE-2025-49713 | »ùÓÚChromium µÄ Microsoft Edge Ô¶³ÌÖ´ÐдúÂë·ì϶ | ³ÁÒª |
CVE-2025-49714 | Visual Studio Code Python À©´ó·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49716 | Windows Netlogon »Ø¾ø·þÎñ·ì϶ | ³ÁÒª |
CVE-2025-49717 | Microsoft SQL Server Ô¶³ÌÖ´ÐдúÂë·ì϶ | ÑϳÁ |
CVE-2025-49718 | Microsoft SQL Server ÐÅϢй¶·ì϶ | ³ÁÒª |
CVE-2025-49719 | Microsoft SQL Server ÐÅϢй¶·ì϶ | ³ÁÒª |
CVE-2025-49721 | Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | ³ÁÒª |
CVE-2025-49722 | Windows ´òÓ¡ºó¶Ü´¦Ö÷¨Ê½»Ø¾ø·þÎñ·ì϶ | ³ÁÒª |
CVE-2025-49723 | Windows StateRepository API ·þÎñÆ÷Îļþ´Û¸Ä·ì϶ | ³ÁÒª |
CVE-2025-49724 | Windows ÏνÓÉ豸ƽ̨·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49725 | Windows Í¨ÖªÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49726 | Windows Í¨ÖªÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49727 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49729 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49730 | Microsoft Windows QoS µ÷¶È·¨Ê½Çý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49731 | Microsoft Teams ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49732 | Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49733 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49735 | Windows KDC ´úÀí·þÎñ (KPSSVC) Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2025-49737 | Microsoft Teams ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49738 | Microsoft PC Manager ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49739 | Visual Studio ÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49740 | Windows SmartScreen °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ³ÁÒª |
CVE-2025-49741 | Microsoft Edge £¨»ùÓÚ Chromium£©ÐÅϢй¶·ì϶ | ³ÁÒª |
CVE-2025-49742 | Windows ͼÐÎ×é¼þÔ¶³ÌÖ´ÐдúÂë·ì϶ | ³ÁÒª |
CVE-2025-49744 | Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉý·ì϶ | ³ÁÒª |
CVE-2025-49753 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ³ÁÒª |
CVE-2025-49756 | Office ¿ª·¢Õ߯½Ì¨°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ³ÁÒª |
CVE-2025-49760 | Windows Storage Spoofing Vulnerability | ÖÐ |
¶þ¡¢Ó°ÏìÁìÓò
ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º
Service Fabric
Windows Kernel
Remote Desktop Client
Windows Visual Basic Scripting
Microsoft Intune
Virtual Hard Disk (VHDX)
Microsoft Input Method Editor (IME)
Windows SSDP Service
Windows Kerberos
Windows Imaging Component
Windows SPNEGO Extended Negotiation
Windows Storage VSP Driver
Windows GDI
Windows Event Tracing
Universal Print Management Service
Windows Cred SSProvider Protocol
Azure Monitor Agent
Microsoft PC Manager
Microsoft Office
Windows MBT Transport driver
Windows Routing and Remote Access Service (RRAS)
Role: Windows Hyper-V
Windows Connected Devices Platform Service
Windows BitLocker
Windows Update Service
Windows SMB
Windows Virtualization-Based Security (VBS) Enclave
Microsoft MPEG-2 Video Extension
Windows Secure Kernel Mode
Microsoft Office Excel
Windows Remote Desktop Licensing Service
HID class driver
Windows Universal Plug and Play (UPnP) Device Host
Windows AppX Deployment Service
Windows Cryptographic Services
Windows TDX.sys
Windows Ancillary Function Driver for WinSock
Windows User-Mode Driver Framework Host
Workspace Broker
Windows Win32K - ICOMP
Kernel Streaming WOW Thunk Service Driver
Microsoft Brokering File System
Windows NTFS
Windows Shell
Windows Performance Recorder
Windows Media
Storage Port Driver
Microsoft Windows Search Component
Windows TCP/IP
Capability Access Management Service (camsvc)
Microsoft Office Word
Microsoft Office SharePoint
Microsoft Office PowerPoint
Microsoft Edge (Chromium-based)
Visual Studio Code - Python extension
Windows Netlogon
SQL Server
Windows Fast FAT Driver
Windows Print Spooler Components
Windows StateRepository API
Windows Notification
Windows Win32K - GRFX
Microsoft Windows QoS scheduler
Microsoft Teams
Microsoft Graphics Component
Windows KDC Proxy Service (KPSSVC)
Visual Studio
Windows SmartScreen
Office Developer Platform
Windows Storage
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£
£¨Ò»£©Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£©ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2025Äê7Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2025-Jul
²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

Àý1£ºÎ¢Èí·ì϶ÁÐ±í£¨Ê¾Àý£©
2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿ÁÐÑ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áдò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
?¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
?¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
?ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
?¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
?ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2025-Jul


¾©¹«Íø°²±¸11010802024551ºÅ