¡¾Â©¶´Í¨¸æ¡¿Î¢Èí2Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2024-02-19


Ò»¡¢Â©¶´¸ÅÊö

2024Äê2ÔÂ13ÈÕ£¬Î¢ÈíÐû²¼ÁË2ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË73¸ö©¶´£¨²»°üÂÞ2ÔÂ8ÈÕÐÞ¸´µÄMicrosoft EdgeºÍÆäËü©¶´£©£¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛƭ©¶´µÈ¡£

±¾´ÎÄþ¾²¸üÐÂÖаüÂÞ2¸ö±»»ý¼«ÀûÓõÄ0 day©¶´£º

CVE-2024-21351£ºWindows SmartScreen Äþ¾²¹¦Ð§Èƹý©¶´

¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.6£¬ÍþвÕß¿ÉÏòÓû§·¢ËͶñÒâÎļþ²¢ÓÕµ¼Óû§´ò¿ªÎļþÀ´ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÈÆ¹ý SmartScreenÄþ¾²¹¦Ð§¡£¸Ã©¶´ÔÊÐíÍþвÕß½«´úÂë×¢Èë SmartScreen ²¢¿ÉÄÜ»ñµÃ´úÂëÖ´ÐÐȨÏÞ£¬´Ó¶ø¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢ÏµÍ³¿ÉÓÃÐÔÓ°Ï죬Ŀǰ¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-21412£ºInternet ¿ì½Ý·½Ê½ÎļþÄþ¾²¹¦Ð§Èƹý©¶´

¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.1£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔÏòÄ¿±êÓû§·¢ËÍÖ¼ÔÚÈÆ¹ýÏÔʾµÄÄþ¾²¼ì²éµÄÌØÖÆÎļþ²¢ÓÕµ¼Óû§´ò¿ª¸ÃÎļþ£¬µ¼ÖÂÄþ¾²¹¦Ð§Èƹý¡£ÒÑ·¢ÏÖAPT×éÖ¯Water Hydra£¨ÓÖÃû DarkCasino£©ÔÚÕë¶Ô½ðÈÚ½»Ò×ÕߵĻÖлý¼«ÀûÓøÃ©¶´¡£

±¾´ÎÄþ¾²¸üÐÂÖУ¬ÆÀ¼¶Îª¡°ÑÏÖØ¡±µÄ5¸ö©¶´°üÂÞ£º

CVE-2024-21380£ºMicrosoft Dynamics Business Central/NAV ÐÅϢй¶©¶´

¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.0£¬ÀÖ³ÉÀûÓøÃ©¶´ÐèÒª¾­¹ýÉí·ÝÑéÖ¤¡¢Ó®µÃ¾ºÕùÌõ¼þ£¬²¢ÐèÒªÓû§½»»¥£¬ÀÖ³ÉÀûÓøÃ©¶´µÄÍþвÕß¿ÉÒÔ·ÃÎÊÓû§Êý¾Ý£¬µ¼ÖÂδÊÚȨ·ÃÎÊÊܺ¦ÕßµÄÕË»§»òй¶ÆäËü»úÃÜÐÅÏ¢¡£

CVE-2024-21410£ºMicrosoft Exchange Server ȨÏÞÌáÉý©¶´

¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬ÀÖ³ÉÀûÓøÃ©¶´µÄÍþвÕß¿ÉÒÔ½«Óû§Ð¹Â¶µÄNet-NTLMv2¹þÏ£Öм̵½Ò×Êܹ¥»÷µÄExchange Server£¬²¢ÒÔÓû§Éí·Ý½øÐÐÉí·ÝÑéÖ¤¡£ÊÜÓ°ÏìÓû§Ò²¿É²Î¿¼¹Ù·½ÌṩµÄÎĵµºÍ½Å±¾Îª Exchange ServerÆôÓÃÉí·ÝÑéÖ¤À©Õ¹±£»¤ (EPA)À´»º½â¸Ã©¶´£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-21413£ºMicrosoft OutlookÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼ÖÂÈÆ¹ý Office Êܱ£»¤µÄÊÓͼ²¢ÒԱ༭ģʽ¶ø²»ÊDZ£»¤Ä£Ê½´ò¿ª£¬Ô¤ÀÀ´°¸ñÊǸé¶´µÄÒ»¸ö¹¥»÷ý½é¡£ÍþвÕß¿ÉÒÔ´´½¨ÈƹýÊܱ£»¤ÊÓͼЭÒéµÄ¶ñÒâÁ´½Ó£¬´Ó¶øµ¼Öµ±µØNTLMƾ¾ÝÐÅϢй¶ºÍÔ¶³Ì´úÂëÖ´ÐС£

CVE-2024-20684£ºWindows Hyper-V ¾Ü¾ø·þÎñ©¶´

¸Ã©¶´µÄCVSSÆÀ·ÖΪ6.5£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼Ö Hyper-V guestÓ°Ïì Hyper-V Ö÷»úµÄ¹¦Ð§¡£

CVE-2024-21357£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐЩ¶´

Windows Pragmatic General Multicast (PGM) ·¢ÉúµÄ×é²¥Á÷Á¿ÔÚµÚ4 ²ãÔËÐв¢¿É·ÓÉ£¬ÍþвÕß¿ÉÒÔͨ¹ýÏòÒ×Êܹ¥»÷µÄ·þÎñÆ÷·¢ËÍÌØÖÆµÄ¶ñÒâÁ÷Á¿À´ÀûÓøÃ©¶´¡£¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.1£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£

³ýCVE-2024-21410ºÍCVE-2024-21357ÒÔÍ⣬±¾´ÎÄþ¾²¸üÐÂÖУ¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖС°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ©¶´»¹°üÂÞ£º

CVE-2024-21338£ºWindows ÄÚºËÌØÈ¨ÌáÉý©¶´

CVE-2024-21345£ºWindows ÄÚºËÌØÈ¨ÌáÉý©¶´

CVE-2024-21346£ºWin32k ÌØÈ¨ÌáÉý©¶´

CVE-2024-21371£ºWindows ÄÚºËÌØÈ¨ÌáÉý©¶´

CVE-2024-21378£ºMicrosoft OutlookÔ¶³Ì´úÂëÖ´ÐЩ¶´

CVE-2024-21379£ºMicrosoft WordÔ¶³Ì´úÂëÖ´ÐЩ¶´

΢Èí2Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º

CVE ID

CVE ±êÌâ

ÑÏÖØÐÔ

CVE-2024-21380

Microsoft   Dynamics Business Central/NAV ÐÅϢй¶©¶´

ÑÏÖØ

CVE-2024-21410

Microsoft   Exchange Server ȨÏÞÌáÉý©¶´

ÑÏÖØ

CVE-2024-21413

Microsoft   Outlook Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-20684

Windows   Hyper-V ¾Ü¾ø·þÎñ©¶´

ÑÏÖØ

CVE-2024-21357

Windows   Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-21386

.NET ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-21404

.NET ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-21401

Microsoft   Entra Jira Single-Sign-On Plugin ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-21381

Microsoft   Azure Active Directory B2C ÆÛƭ©¶´

¸ßΣ

CVE-2024-21329

Azure   Connected Machine Agent ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-20667

Azure   DevOps Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21397

Microsoft   Azure File SyncȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-20679

Azure   Stack Hub ÆÛƭ©¶´

¸ßΣ

CVE-2024-21412

Internet ¿ì½Ý·½Ê½ÎļþÄþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-21349

Microsoft   ActiveX Êý¾Ý¹¤¾ßÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21403

Microsoft   Azure Kubernetes Service Confidential Container ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-21376

Microsoft   Azure Kubernetes Service Confidential Container Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21315

Microsoft   Defender for Endpoint Protection ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-21393

Microsoft   Dynamics 365£¨on-premises£©¿çÕ¾½Å±¾Â©¶´

¸ßΣ

CVE-2024-21389

Microsoft   Dynamics 365£¨on-premises£©¿çÕ¾½Å±¾Â©¶´

¸ßΣ

CVE-2024-21395

Microsoft   Dynamics 365£¨on-premises£©¿çÕ¾½Å±¾Â©¶´

¸ßΣ

CVE-2024-21328

Dynamics   365 Sales ÆÛƭ©¶´

¸ßΣ

CVE-2024-21394

Dynamics   365 Field Service ÆÛƭ©¶´

¸ßΣ

CVE-2024-21396

Dynamics   365 Sales ÆÛƭ©¶´

¸ßΣ

CVE-2024-21327

Microsoft   Dynamics 365 Customer Engagement ¿çÕ¾½Å±¾Â©¶´

¸ßΣ

CVE-2024-20673

Microsoft   Office Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21384

Microsoft   Office OneNote Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21378

Microsoft   Outlook Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21402

Microsoft   Outlook ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-21379

Microsoft   Word Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21374

Microsoft   Teams for Android ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-21353

Microsoft   WDAC ODBC Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21370

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21350

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21368

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21359

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21365

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21367

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21420

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21366

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21369

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21375

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21361

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21358

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21391

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21360

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21352

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21406

Windows   Printing Service ÆÛƭ©¶´

¸ßΣ

CVE-2024-21377

Windows   DNS ÐÅϢй¶©¶´

¸ßΣ

CVE-2023-50387

MITRE£ºCVE-2023-50387 DNSSEC ÑéÖ¤ÅÓ´óÐԿɱ»ÀûÓÃÀ´ºÄ¾¡ CPU ×ÊÔ´²¢Í£Ö¹ DNS ½âÎöÆ÷

¸ßΣ

CVE-2024-21342

Windows   DNS Client ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-20695

Skype for   Business ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-21347

Microsoft   ODBC Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21304

Trusted   Compute Base ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-21343

Windows   Network Address Translation (NAT) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-21348

Internet   Connection Sharing (ICS) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-21344

Windows Network   Address Translation (NAT) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-21371

Windows   Kernel ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-21338

Windows   Kernel ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-21341

Windows   Kernel Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21345

Windows   Kernel ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-21362

Windows   Kernel Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-21340

Windows   Kernel ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-21356

Windows   Lightweight Directory Access Protocol (LDAP) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-21363

Microsoft   Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21355

Microsoft   Message Queuing (MSMQ) ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-21405

Microsoft   Message Queuing (MSMQ) ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-21354

Microsoft   Message Queuing (MSMQ) ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-21372

Windows   OLE Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21339

Windows   USB Generic Parent Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21346

Win32k ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-21364

Microsoft   Azure Site RecoveryÌØÈ¨ÌáÉý©¶´

ÖÐΣ

CVE-2024-21399

Microsoft   Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÖÐΣ

CVE-2024-21351

Windows   SmartScreen Äþ¾²¹¦Ð§Èƹý©¶´

ÖÐΣ

CVE-2024-21626

runc ÎļþÃèÊö·ûй©

δ֪

CVE-2024-1284

Chromium£ºCVE-2024-1284 ÔÚ Mojo ÖÐÊͷźóʹÓÃ

δ֪

CVE-2024-1060

Chromium£ºCVE-2024-1060 ÔÚ Canvas ÖÐÊͷźóʹÓÃ

δ֪

CVE-2024-1077

Chromium£ºCVE-2024-1077 ÔÚ Network ÖÐÊͷźóʹÓÃ

δ֪

CVE-2024-1283

Chromium£ºCVE-2024-1283 Skia ÖеĶѻº³åÇøÒç³ö

δ֪

CVE-2024-1059

Chromium£ºCVE-2024-1059 ÔÚ WebRTC ÖÐÊͷźóʹÓÃ

δ֪

 

¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

Azure DevOps

Microsoft Office

Azure Stack

Windows Hyper-V

Skype for Business

Trusted Compute Base

Microsoft Defender for Endpoint

Microsoft Dynamics

Azure Connected Machine Agent

Windows Kernel

Windows USB Serial Driver

Role: DNS Server

Windows Internet Connection Sharing (ICS)

Windows Win32K - ICOMP

SQL Server

Microsoft ActiveX

Microsoft WDAC OLE DB provider for SQL

Windows SmartScreen

Microsoft WDAC ODBC Driver

Windows Message Queuing

Windows LDAP - Lightweight Directory Access Protocol

Azure Site Recovery

Windows OLE

Microsoft Teams for Android

Microsoft Azure Kubernetes Service

Microsoft Windows DNS

Microsoft Office Outlook

Microsoft Office Word

Azure Active Directory

Microsoft Office OneNote

.NET

Azure File Sync

Microsoft Edge (Chromium-based)

Microsoft Windows

Microsoft Exchange Server

Internet Shortcut Files

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2024Äê2ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Feb

²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2022Äê2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£

3.2 ÁÙʱ´ëÊ©

Õë¶ÔCVE-2024-21410£¬ÔÚ Exchange Server 2019 ÀÛ»ý¸üÐÂ14 (CU14) ¸üÐÂ֮ǰ£¬Exchange Server ĬÈÏÇé¿öϲ»ÆôÓà NTLM ƾ¾ÝÖм̱£»¤£¨³ÆÎªÉí·ÝÑéÖ¤À©Õ¹±£»¤»ò EPA£©£¬Exchange Server 2019 CU14 ĬÈÏÔÚ Exchange ServerÉÏÆôÓà EPA£¬Microsoft ½¨ÒéÔÚ Exchange Server 2019 Éϰ²×° CU14 £¬»ò²ÎÔÄExchange À©Õ¹±£»¤Îĵµ²¢Ê¹ÓÃExchangeExtendedProtectionManagement.ps1½Å±¾Îª Exchange ServerÆôÓÃÉí·ÝÑéÖ¤À©Õ¹±£»¤ (EPA)À´»º½â¸Ã©¶´¡£

¸ü¶à©¶´ÏêÇé¼°»º½â´ëÊ©¿É²Î¿¼¹Ù·½Í¨¸æ£º

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-21410

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Feb

https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2024-patch-tuesday-fixes-2-zero-days-73-flaws/

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-02-19

Ê×´ÎÐû²¼

 

 

Îå¡¢¸½Â¼

5.1 ¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png