¡¾Â©¶´Í¨¸æ¡¿Î¢Èí6Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2023-06-14

 

Ò»¡¢Â©¶´¸ÅÊö

2023Äê6ÔÂ13ÈÕ£¬Î¢ÈíÐû²¼ÁË6ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË78¸öÄþ¾²Â©¶´£¨²»°üÂÞMicrosoft Edge©¶´£©£¬ÆäÖÐÓÐ6¸ö©¶´ÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£

±¾´ÎÐÞ¸´µÄ©¶´ÖУ¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´ºÍÆÛƭ©¶´µÈ¡£

΢Èí±¾´ÎÄþ¾²¸üÐÂÖÐÎ´Éæ¼°0 day©¶´£¬ÖµµÃ¹Ø×¢µÄ©¶´°üÂÞµ«²»ÏÞÓÚ£º

CVE-2023-29357 £ºMicrosoft SharePoint Server ÌØÈ¨ÌáÉý©¶´

Microsoft SharePoint Server 2019ÖдæÔÚȨÏÞÌáÉý©¶´£¬¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ9.8¡£»ñµÃÆÛÆ­ÐÔJWTÉí·ÝÑéÖ¤ÁîÅÆµÄÍþвÕß¿ÉÒÔʹÓÃÕâЩÁîÅÆÖ´ÐÐÍøÂç¹¥»÷£¬´Ó¶øÈƹýÉí·ÝÑéÖ¤£¬²¢¿ÉÄÜ»ñµÃ¹ÜÀíԱȨÏÞ¡£

CVE-2023-32031 £ºMicrosoft Exchange Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬¾­¹ýÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔʵÑéͨ¹ýÍøÂçµ÷ÓÃÔÚ·þÎñÆ÷ÕË»§µÄÉÏÏÂÎÄÖд¥·¢¶ñÒâ´úÂë¡£

CVE-2023-24897£º.NET¡¢.NET Framework ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.8£¬¿ÉÒÔͨ¹ýÓÕµ¼Êܺ¦Õß´ÓÍøÕ¾ÏÂÔØ²¢´ò¿ªÌØÖÆÎļþµÄ©¶´ÀûÓ㬴Ӷøµ¼Ö¶ÔÊܺ¦ÕߵļÆËã»ú½øÐе±µØ¹¥»÷£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼ÖÂÈÎÒâ´úÂëÖ´ÐС£

CVE-2023-32013£ºWindows Hyper-V ¾Ü¾ø·þÎñ©¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ6.5¡£

CVE-2023-29363/CVE-2023-32014/CVE-2023-32015£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÕâЩ©¶´µÄCVSSv3ÆÀ·Ö¾ùΪ9.8£¬µ± Windows ÏûÏ¢ÐÐÁзþÎñÔËÐÐÔÚ PGM Server »·¾³ÖÐʱ£¬¿ÉÒÔͨ¹ýÍøÂç·¢ËÍÌØÖÆÎļþÀ´ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£Windows ÏûÏ¢ÐÐÁзþÎñÊÇÒ»¸ö Windows ×é¼þ£¬ÆôÓøÃ×é¼þµÄϵͳ²ÅÒ×ÊÜÕë¶ÔÕâЩ©¶´µÄ¹¥»÷£¬¿ÉÒÔ¼ì²éÊÇ·ñÓÐÃûΪMessage QueuingµÄ·þÎñÕýÔÚÔËÐжøÇÒ TCP ¶Ë¿Ú 1801 ÕýÔÚ»úÆ÷ÉÏÕìÌý¡£

CVE-2023-29362£ºRemote Desktop ClientÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬ÔÚÔ¶³Ì×ÀÃæÁ¬½ÓµÄÇé¿öÏ£¬µ±Êܺ¦ÕßʹÓÃÒ×Êܹ¥»÷µÄÔ¶³Ì×ÀÃæ¿Í»§¶ËÁ¬½Óµ½¹¥»÷·þÎñÆ÷ʱ£¬¿ØÖÆÔ¶³Ì×ÀÃæ·þÎñÆ÷µÄÍþвÕß¿ÉÒÔÔÚ RDP ¿Í»§¶Ë¼ÆËã»úÉÏ´¥·¢Ô¶³Ì´úÂëÖ´ÐÐ (RCE)¡£

CVE-2023-28310£ºMicrosoft Exchange Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.0£¬Óë Exchange Server´¦ÓÚͬһÄÚÍøµÄ¾­¹ýÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔͨ¹ý PowerShell Ô¶³Ì»á»°ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£

´ËÍ⣬΢Èí»¹Ðû²¼ÁË´óÁ¿ Microsoft Office ¸üУ¬ÒÔÐÞ¸´Excel ¡¢OneNote ºÍOutlookµÈ¶à¸ö²úÎïÖеÄ©¶´£¬ÀûÓÃÕâЩ©¶´ÐèÒªÓû§½»»¥£¬²¿ÃÅ©¶´ÈçÏ£º

CVE-2023-33133£ºMicrosoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´

CVE-2023-33137£ºMicrosoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´

CVE-2023-33140£ºMicrosoft OneNote ÆÛƭ©¶´

CVE-2023-33131£ºMicrosoft Outlook Ô¶³Ì´úÂëÖ´ÐЩ¶´

΢Èí6Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º

CVE-ID

±êÌâ

ÑÏÖØÐÔ

CVE-2023-24897

.NET¡¢.NET Framework ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-29357

Microsoft   SharePoint Server ÌØÈ¨ÌáÉý©¶´

ÑÏÖØ

CVE-2023-32013

Windows   Hyper-V ¾Ü¾ø·þÎñ©¶´

ÑÏÖØ

CVE-2023-29363

Windows   Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-32014

Windows   Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-32015

Windows   Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2023-24895

.NET¡¢.NET Framework ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-33126

.NET ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-33135

.NET ºÍ Visual Studio ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-32032

.NET ºÍ Visual Studio ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-32030

.NET ºÍ Visual Studio ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-33128

.NET ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-29331

.NET¡¢.NET Framework ºÍ Visual Studio ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-29326

.NET   Framework Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-33141

Yet   Another Reverse Proxy (YARP) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-21569

Azure   DevOps ·þÎñÆ÷ÆÛƭ©¶´

¸ßΣ

CVE-2023-21565

Azure   DevOps ·þÎñÆ÷ÆÛƭ©¶´

¸ßΣ

CVE-2023-24896

Dynamics   365 Finance ÆÛƭ©¶´

¸ßΣ

CVE-2023-33145

Microsoft   Edge£¨»ùÓÚChromium£©ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-32031

Microsoft   Exchange Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-28310

Microsoft   Exchange Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-33146

Microsoft   Office Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-33133

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-32029

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-33137

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-33140

Microsoft   OneNote ÆÛƭ©¶´

¸ßΣ

CVE-2023-33131

Microsoft   Outlook Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-33142

Microsoft   SharePoint Server ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-33129

Microsoft   SharePoint ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-33130

Microsoft   SharePoint Server ÆÛƭ©¶´

¸ßΣ

CVE-2023-33132

Microsoft   SharePoint Server ÆÛƭ©¶´

¸ßΣ

CVE-2023-32024

Microsoft   Power Apps ÆÛƭ©¶´

¸ßΣ

CVE-2023-32017

Microsoft   PostScript ´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-29372

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-29370

Windows   Media Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-29365

Windows   Media Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-29337

NuGet   ClientÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-29362

Remote   Desktop Client Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-29352

Windows Ô¶³Ì×ÀÃæÄþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-32020

Windows   DNS ÆÛƭ©¶´

¸ßΣ

CVE-2023-29007

GitHub£ºCVE-2023-29007 ͨ¹ý `git submodule deinit` ½øÐÐÈÎÒâÅäÖÃ×¢Èë

¸ßΣ

CVE-2023-33139

Visual   Studio ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-25652

GitHub£ºCVE-2023-25652¡°git apply --reject¡±²¿ÃÅ¿ØÖÆÈÎÒâÎļþдÈë

¸ßΣ

CVE-2023-25815

GitHub£ºCVE-2023-25815 Git ÔÚ·ÇÌØÈ¨Î»ÖòéÕÒµ±µØ»¯ÏûÏ¢

¸ßΣ

CVE-2023-27911

AutoDesk£ºAutodesk? FBX? SDK 2020 »ò¸üÔç°æ±¾ÖÐµÄ   CVE-2023-27911 ¶Ñ»º³åÇøÒç³ö©¶´

¸ßΣ

CVE-2023-27910

AutoDesk£ºAutodesk? FBX? SDK 2020 »ò¸üÔç°æ±¾ÖÐµÄ   CVE-2023-27910 ¶ÑÕ»»º³åÇøÒç³ö©¶´

¸ßΣ

CVE-2023-29011

GitHub:   CVE-2023-29011 `connect.exe` µÄÅäÖÃÎļþÈÝÒ×±»¶ñÒâ·ÅÖÃ

¸ßΣ

CVE-2023-29012

GitHub:CVE-2023-29012   Git CMD´íÎóµØÔÚµ±Ç°Ä¿Â¼ÖÐÖ´ÐС°doskey.exe¡±£¨Èç¹û´æÔÚ£©

¸ßΣ

CVE-2023-27909

AutoDesk£ºAutodesk? FBX? SDK 2020 »ò¸üÔç°æ±¾ÖÐµÄ   CVE-2023-27909 Ô½½çдÈë©¶´

¸ßΣ

CVE-2023-33144

Visual   Studio CodeÆÛƭ©¶´

¸ßΣ

CVE-2023-29364

Windows Éí·ÝÑéÖ¤ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-32010

Windows   Bus Filter Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-29361

Windows   Cloud Files Mini Filter Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-32009

Windows   Collaborative Translation Framework ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-32012

Windows   Container Manager Service ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-24937

Windows   CryptoAPI ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-24938

Windows   CryptoAPI ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-29355

DHCP   Server Service ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-29368

Windows   Filtering Platform ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-29358

Windows   GDI ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-29366

Windows   Geolocation Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-29351

Windows ×é¼ÆÄ±ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-32018

Windows   Hello Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-32016

Windows   Installer ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-32011

Windows   iSCSI ·¢ÏÖ·þÎñ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-32019

Windows ÄÚºËÐÅϢй¶©¶´

¸ßΣ

CVE-2023-29346

NTFS ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-29373

Microsoft   ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-29367

iSCSI   Target WMI Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-29369

Remote   Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2023-32008

Windows   Resilient File System (ReFS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2023-32022

Windows   Server ·þÎñÄþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-32021

Windows   SMB Witness ·þÎñÄþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2023-29360

Windows   TPM É豸Çý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-29371

Windows   GDI ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-29359

GDI ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2023-24936

.NET¡¢.NET Framework ºÍ Visual Studio ÌØÈ¨ÌáÉý©¶´

ÖÐΣ

CVE-2023-33143

Microsoft   Edge£¨»ùÓÚ Chromium£©ÌØÈ¨ÌáÉý©¶´

ÖÐΣ

CVE-2023-29345

Microsoft   Edge£¨»ùÓÚ Chromium£©Äþ¾²¹¦Ð§Èƹý©¶´

µÍΣ

CVE-2023-29353

Sysinternals   Process Monitor for Windows ¾Ü¾ø·þÎñ©¶´

µÍΣ

CVE-2023-2941

Chromium£ºCVE-2023-2941 ÔÚÀ©Õ¹ API ÖÐʵʩ²»Í×

δ֪

CVE-2023-2937

Chromium£ºCVE-2023-2937 »­Öл­ÊµÊ©²»Í×

δ֪

CVE-2023-2936

Chromium£ºV8 ÖÐµÄ CVE-2023-2936 ÀàÐÍ»ìÏý

δ֪

CVE-2023-2935

Chromium£ºV8 ÖÐµÄ CVE-2023-2935 ÀàÐÍ»ìÏý

δ֪

CVE-2023-2940

Chromium£ºCVE-2023-2940 ÏÂÔØÖеÄʵʩ²»Í×

δ֪

CVE-2023-2939

Chromium£ºCVE-2023-2939 °²×°·¨Ê½ÖеÄÊý¾ÝÑéÖ¤²»×ã

δ֪

CVE-2023-2938

Chromium£ºCVE-2023-2938 »­Öл­ÊµÊ©²»Í×

δ֪

CVE-2023-2931

Chromium£ºCVE-2023-2931 ÔÚ PDF ÖÐÊͷźóʹÓÃ

δ֪

CVE-2023-2930

Chromium£ºCVE-2023-2930 ÔÚÀ©Õ¹ÖÐÊͷźóʹÓÃ

δ֪

CVE-2023-2929

Chromium£ºCVE-2023-2929 ÔÚ Swiftshader ÖÐÔ½½çдÈë

δ֪

CVE-2023-2934

Chromium£ºCVE-2023-2934 Mojo ÖеÄÔ½½çÄÚ´æ·ÃÎÊ

δ֪

CVE-2023-2933

Chromium£ºCVE-2023-2933 ÔÚ PDF ÖÐÊͷźóʹÓÃ

δ֪

CVE-2023-2932

Chromium£ºCVE-2023-2932 ÔÚ PDF ÖÐÊͷźóʹÓÃ

δ֪

CVE-2023-3079

Chromium£ºV8 ÖÐµÄ CVE-2023-3079 ÀàÐÍ»ìÏý

δ֪

 

¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

Azure DevOps

.NET and Visual Studio

Microsoft Dynamics

Windows CryptoAPI

Microsoft Exchange Server

.NET Framework

.NET Core

NuGet Client

Microsoft Edge (Chromium-based)

Windows NTFS

Windows Group Policy

Remote Desktop Client

SysInternals

Windows DHCP Server

Microsoft Office SharePoint

Windows GDI

Windows Win32K

Windows TPM Device Driver

Windows Cloud Files Mini Filter Driver

Windows PGM

Windows Authentication Methods

Microsoft Windows Codecs Library

Windows Geolocation Service

Windows OLE

Windows Filtering

Windows Remote Procedure Call Runtime

Microsoft WDAC OLE DB provider for SQL

Windows ODBC Driver

Windows Resilient File System (ReFS)

Windows Collaborative Translation Framework

Windows Bus Filter Driver

Windows iSCSI

Windows Container Manager Service

Windows Hyper-V

Windows Installer

Microsoft Printer Drivers

Windows Hello

Windows Kernel

Role: DNS Server

Windows SMB

Windows Server Service

Microsoft Power Apps

Microsoft Office Excel

Microsoft Office Outlook

Visual Studio

Microsoft Office OneNote

ASP .NET

Visual Studio Code

Microsoft Office

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2023Äê6ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2023-Jun

²¹¶¡ÏÂÔØÊ¾Àý£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2022Äê2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£

 

3.2 ÁÙʱ´ëÊ©

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2023-Jun

https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2023-patch-tuesday-fixes-78-flaws-38-rce-bugs/

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-06-14

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼

5.1 ¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png