¡¾Â©¶´Í¨¸æ¡¿Î¢Èí9Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2024-09-11


Ò»¡¢Â©¶´¸ÅÊö

2024Äê9ÔÂ11ÈÕ £¬¶¶È¦Îª¶Ä¶øÉú¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË9ÔÂÄþ¾²¸üР£¬±¾´Î¸üй²ÐÞ¸´ÁË79¸ö©¶´ £¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛƭ©¶´µÈ¡£

±¾´ÎÄþ¾²¸üÐÂÖаüÂÞ4¸ö±»»ý¼«ÀûÓõÄ0 day©¶´ £¬ÆäÖÐ1¸öÒѾ­¹ûÈ»Åû¶£º

CVE-2024-38014£ºWindows Installer ÌØÈ¨ÌáÉý©¶´

Windows InstallerÖдæÔÚȨÏÞÌáÉý©¶´ £¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8 £¬ÀÖ³ÉÀûÓøÃ©¶´µÄÍþвÕ߿ɻñµÃ SYSTEM ȨÏÞ £¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-38217£ºWindows Mark of the WebÄþ¾²¹¦Ð§Èƹý©¶´

Windows Mark of the WebÖдæÔÚÄþ¾²¹¦Ð§Èƹý©¶´ £¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ5.4 £¬ÍþвÕß¿ÉÒÔÔÚÆä¿ØÖÆµÄ·þÎñÆ÷ÉÏÍйÜÒ»¸öÄܹ»Ì Web ±êÖ¾ (MOTW) ·ÀÓùµÄ¶ñÒâÎļþ £¬È»ºóÓÕʹĿ±êÓû§ÏÂÔØ²¢´ò¿ª¸ÃÎļþ £¬´Ó¶øµ¼ÖÂÄþ¾²¹¦Ð§£¨ÈçSmartScreenÓ¦Ó÷¨Ê½ÐÅÓþÄþ¾²¼ì²é»ò¾É°æWindows¸½¼þ·þÎñÄþ¾²Ìáʾ£©Èƹý¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶ £¬ÇÒÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-38226£ºMicrosoft Publisher Äþ¾²¹¦Ð§Èƹý©¶´

Microsoft Publisher´æÔÚÄþ¾²¹¦Ð§Èƹý©¶´ £¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.3 £¬ÍþвÕß¿Éͨ¹ýÓÕµ¼Êܺ¦ÕßÏÂÔØ²¢´ò¿ªÌØÖÆÎļþÀ´ÀûÓøÃ©¶´ £¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÈÆ¹ýÓÃÓÚ×èÖ¹²»ÊÜÐÅÈλò¶ñÒâÎļþµÄOfficeºê¼ÆÄ± £¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-43491£ºMicrosoft Windows UpdateÔ¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft·þÎñ¶ÑÕ»ÖдæÔÚUse-After-Free©¶´ £¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8 £¬¿ÉÄܵ¼Ö»عöÓ°ÏìWindows 10 1507ÉÏ¿ÉÑ¡×é¼þµÄһЩ©¶´µÄÐÞ¸´ £¬´Ó¶øµ¼ÖÂÍþвÕß¿ÉÒÔÀûÓà Windows 10 °æ±¾1507£¨Windows 10 Enterprise 2015 LTSB ºÍ Windows 10 IoT Enterprise 2015 LTSB£©ÏµÍ³ÉÏÕâЩ֮ǰÒÑÐÞ¸´/»º½âµÄ©¶´ £¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ £¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£ÊÜÓ°ÏìÓû§¿Éͨ¹ý°´Ë³Ðò°²×° 2024Äê9Ô·þÎñ¶ÑÕ»¸üР(SSU KB5043936) ºÍ2024Äê9ÔÂWindowsÄþ¾²¸üР(KB5043083) À´ÐÞ¸´¸Ã·þÎñ¶Ñջ©¶´¡£

³ýCVE-2024-43491Íâ £¬±¾´ÎÄþ¾²¸üÐÂÖÐÐÞ¸´µÄÆäËû6¸öÑÏÖØÂ©¶´Îª£º

CVE-2024-43464£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft SharePoint ServerÖдæÔÚ·´ÐòÁл¯Â©¶´ £¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.2 £¬¾­¹ýÉí·ÝÑéÖ¤ÇÒÓµÓÐÕ¾µãËùÓÐÕßȨÏÞµÄÍþвÕß¿ÉÒÔ½«ÌØÖÆÎļþÉÏ´«µ½Ä¿±ê SharePoint Server £¬²¢Í¨¹ýÌØÖÆAPI ÇëÇóÒÔ´¥·¢Îļþ²ÎÊýµÄ·´ÐòÁл¯ £¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔÚ SharePoint Server ÉÏÏÂÎÄÖÐʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£

CVE-2024-38018£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft SharePoint ServerÖдæÔÚ·´ÐòÁл¯Â©¶´ £¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8 £¬¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÀûÓøÃ©¶´ÔÚ SharePoint Server ÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£

CVE-2024-38119£ºWindows Network Address Translation (NAT) Ô¶³Ì´úÂëÖ´ÐЩ¶´

Windows ÍøÂçµØÖ·×ª»» (NAT)´æÔÚUse-After-Free©¶´ £¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.5 £¬ÏàÁÚÍøÂçµÄÍþвÕß¿ÉÀûÓøÃ©¶´µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐЩ¶´ £¬ÀÖ³ÉÀû¸Ã©¶´ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£

CVE-2024-38216/ CVE-2024-38220£ºAzure Stack Hub ÌØÈ¨ÌáÉý©¶´

CVE-2024-38194£ºAzure Web Apps ÌØÈ¨ÌáÉý©¶´

³ýCVE-2024-43464ºÍCVE-2024-38018Íâ £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ©¶´»¹°üÂÞ£º

l CVE-2024-38227£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

l  CVE-2024-38228£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

l  CVE-2024-38237£ºKernel Streaming WOW Thunk Service DriverÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38238£ºKernel Streaming Service DriverÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38241£ºKernel Streaming Service DriverÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38242£ºKernel Streaming Service DriverÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38243£ºKernel Streaming Service DriverÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38244£ºKernel Streaming Service DriverÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38245£ºKernel Streaming Service DriverÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38246£ºWin32kÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38247£ºWindows Graphics ComponentÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38249£ºWindows Graphics ComponentÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38252£ºWindows Win32 Kernel SubsystemÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38253£ºWindows Win32 Kernel SubsystemÌØÈ¨ÌáÉý©¶´

l  CVE-2024-43457£ºWindows Setup and DeploymentÌØÈ¨ÌáÉý©¶´

l  CVE-2024-43461£ºWindows MSHTML PlatformÆÛƭ©¶´

l  CVE-2024-43487£ºWindows Mark of the Web Äþ¾²¹¦Ð§Èƹý©¶´

΢Èí9Ô¸üÐÂÐÞ¸´µÄ©¶´ÁбíÈçÏ£º

CVE-ID

CVE ±êÌâ

ÑÏÖØÐÔ

CVE-2024-38216

Azure   Stack Hub ÌØÈ¨ÌáÉý©¶´

ÑÏÖØ

CVE-2024-38220

Azure   Stack Hub ÌØÈ¨ÌáÉý©¶´

ÑÏÖØ

CVE-2024-38194

Azure Web   Apps ÌØÈ¨ÌáÉý©¶´

ÑÏÖØ

CVE-2024-43464

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38018

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38119

Windows   Network Address Translation (NAT) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-43491

Microsoft   Windows Update Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-43469

Azure   CycleCloud Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38188

Azure   Network Watcher VM Agent ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-43470

Azure   Network Watcher VM Agent ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38225

Microsoft   Dynamics 365 Business Central ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-43492

Microsoft   AutoUpdate (MAU) ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-43476

Microsoft   Dynamics 365 (on-premises) ¿çÕ¾½Å±¾Â©¶´

¸ßΣ

CVE-2024-38247

Windows   Graphics Component ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38250

Windows   Graphics Component ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38249

Windows   Graphics Component ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38259

Microsoft   Management Console Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-43465

Microsoft   Excel ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38226

Microsoft   Publisher Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38227

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38228

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-43466

Microsoft   SharePoint Server ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-43463

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-43482

Microsoft   Outlook for iOS ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38245

Kernel   Streaming Service Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38241

Kernel   Streaming Service Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38242

Kernel   Streaming Service Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38244

Kernel   Streaming Service Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38243

Kernel   Streaming Service Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38237

Kernel   Streaming WOW Thunk Service Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38238

Kernel   Streaming Service Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-43479

Microsoft   Power Automate Desktop Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38235

Windows   Hyper-V ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-37338

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37980

Microsoft   SQL Server ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-26191

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37339

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37337

Microsoft   SQL Server Native Scoring ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-26186

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37342

Microsoft   SQL Server Native Scoring ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-43474

Microsoft   SQL Server ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-37335

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37966

Microsoft   SQL Server Native Scoring ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-37340

Microsoft   SQL Server Native Scoring Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37965

Microsoft   SQL Server ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-37341

Microsoft   SQL Server ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-43475

Microsoft   Windows Admin Center ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38257

Microsoft   AllJoyn API ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38254

Windows   Authentication ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38236

DHCP   Server Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38014

Windows   Installer ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38239

Windows   Kerberos ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38256

Windows   Kernel-Mode Driver ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-43495

Windows   libarchive Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38217

Windows   Mark of the Web Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-43461

Windows   MSHTML Platform ÆÛƭ©¶´

¸ßΣ

CVE-2024-38232

Windows   Networking ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38233

Windows   Networking ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38234

Windows   Networking ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-43458

Windows   Networking ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38046

PowerShell   ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38240

Windows   Remote Access Connection Manager ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38231

Windows   Remote Desktop Licensing Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38258

Windows   Remote Desktop Licensing Service ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-43467

Windows   Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-43454

Windows   Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38263

Windows   Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38260

Windows   Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-43455

Windows   Remote Desktop Licensing Service ÆÛƭ©¶´

¸ßΣ

CVE-2024-30073

Windows   Security Zone Mapping Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-43457

Windows   Setup and Deployment ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38230

Windows   Standards-Based Storage Management ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38248

Windows   Storage ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-21416

Windows   TCP/IP Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38045

Windows   TCP/IP Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38246

Win32k ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38252

Windows   Win32 Kernel Subsystem ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38253

Windows   Win33 Kernel Subsystem ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-43487

Windows   Mark of the Web Äþ¾²¹¦Ð§Èƹý©¶´

ÖÐΣ

 

¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

Windows TCP/IP

SQL Server

Windows Security Zone Mapping

Windows Installer

Microsoft Office SharePoint

Windows PowerShell

Windows Network Address Translation (NAT)

Azure Network Watcher

Azure Web Apps

Azure Stack

Windows Mark of the Web (MOTW)

Dynamics Business Central

Microsoft Office Publisher

Windows Standards-Based Storage Management Service

Windows Remote Desktop Licensing Service

Windows Network Virtualization

Role: Windows Hyper-V

Windows DHCP Server

Microsoft Streaming Service

Windows Kerberos

Windows Remote Access Connection Manager

Windows Win32K - GRFX

Microsoft Graphics Component

Windows Storage

Windows Win32K - ICOMP

Windows Authentication Methods

Windows Kernel-Mode Drivers

Windows AllJoyn API

Microsoft Management Console

Windows Setup and Deployment

Windows MSHTML Platform

Microsoft Office Visio

Microsoft Office Excel

Azure CycleCloud

Windows Admin Center

Microsoft Dynamics 365 (on-premises)

Power Automate

Microsoft Outlook for iOS

Windows Update

Microsoft AutoUpdate (MAU)

Windows Libarchive

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üР£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓà £¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ £¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü £¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡± £¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС± £¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС± £¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú £¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üР£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó £¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡± £¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2024Äê9ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Sep

²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó £¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí©¶´ÁÐ±í£¨Ê¾Àý£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿ÁÐÑ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ £¬µã»÷ÓҲࡾÏÂÔØ¡¿Áдò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Äþ¾²¸üС¿ £¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ £¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£

3.2 ÁÙʱ´ëÊ©

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡ £¬¼õÉÙϵͳ©¶´ £¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ £¬Ð޸ķÀ»ðǽ¼ÆÄ± £¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ £¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎï £¬ÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí £¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Sep

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43491

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-09-11

Ê×´ÎÐû²¼

 


Îå¡¢¸½Â¼

5.1 ¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Äê £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏà £¬¹«Ë¾Ô±¹¤6000ÓàÈË £¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ £¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯ £¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´ £¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png