¡¾Îó²îͨ¸æ¡¿Î¢Èí4Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2023-04-12


Ò»¡¢Îó²î¸ÅÊö

2023Äê4ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬ £¬Î¢ÈíÐû²¼ÁË4ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬£¬ £¬±¾´Î¸üÐÂÐÞ¸´Á˰üÀ¨1¸ö0 dayÎó²îÔÚÄÚµÄ97¸öÇå¾²Îó²î£¨²»°üÀ¨Microsoft EdgeÎó²î£©£¬£¬£¬£¬£¬£¬ £¬ÆäÖÐÓÐ7¸öÎó²îÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£¡£¡£¡£¡£

±¾´ÎÐÞ¸´µÄÎó²îÖУ¬£¬£¬£¬£¬£¬ £¬Îó²îÀàÐͰüÀ¨ÌØÈ¨ÌáÉýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾øÐ§ÀÍÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²îºÍÓÕÆ­Îó²îµÈ¡£¡£¡£¡£¡£

΢Èí±¾´Î¹²ÐÞ¸´ÁË1¸ö±»Æð¾¢Ê¹ÓõÄ0 dayÎó²î£¬£¬£¬£¬£¬£¬ £¬ÈçÏ£º

CVE-2023-28252 £ºWindows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Windows CLFS Çý¶¯³ÌÐòÖб£´æÔ½½çдÈëÎó²î£¬£¬£¬£¬£¬£¬ £¬ÍâµØµÍȨÏÞÓû§¿ÉÒÔͨ¹ý»ù½ñÈÕÖ¾Îļþ£¨.blf ÎļþÀ©Õ¹Ãû£©µÄ²Ù×÷´¥·¢¸ÃÎó²î£¬£¬£¬£¬£¬£¬ £¬ÀÖ³ÉʹÓøÃÎó²î¿Éµ¼ÖÂÍâµØÈ¨ÏÞÌáÉýΪSYSTEM¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬ £¬ÏÖÔÚÒÑ·¢Ã÷±»Nokoyawa ÀÕË÷Èí¼þʹÓᣡ£¡£¡£¡£

±¾´ÎÇå¾²¸üÐÂÖÐÆÀ¼¶ÎªÑÏÖØµÄ7¸öÎó²î°üÀ¨£º

CVE-2023-21554£ºMicrosoft ÐÂÎÅÐÐÁÐÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬ £¬¿ÉÒÔͨ¹ý·¢ËͶñÒâÖÆ×÷µÄMSMQ Êý¾Ý°üµ½MSMQ ЧÀÍÆ÷À´Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬ £¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÔÚЧÀÍÆ÷¶ËÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£Ê¹ÓøÃÎó²îÐèÒªÆôÓÃ×÷ΪWindows ×é¼þµÄWindows ÐÂÎÅÐÐÁÐЧÀÍ£¬£¬£¬£¬£¬£¬ £¬¿ÉÒÔͨ¹ý¼ì²éÊÇ·ñÖøÃûΪMessage QueuingµÄЧÀÍÔÚÔËÐУ¬£¬£¬£¬£¬£¬ £¬ÒÔ¼°ÅÌËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£¡£¡£¡£¡£

CVE-2023-28231£ºDHCP Server Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.8£¬£¬£¬£¬£¬£¬ £¬¾­ÓÉÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔʹÓÃÕë¶Ô DHCP ЧÀ͵ÄÌØÖÆ RPC ŲÓÃÀ´Ê¹ÓøÃÎó²î¡£¡£¡£¡£¡£

CVE-2023-28219/ CVE-2023-28220£º¶þ²ãËíµÀЭÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.1£¬£¬£¬£¬£¬£¬ £¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔÏò RAS ЧÀÍÆ÷·¢ËͶñÒâÅþÁ¬ÇëÇ󣬣¬£¬£¬£¬£¬ £¬Õâ¿ÉÄܵ¼Ö RAS ЧÀÍÆ÷ÅÌËã»úÉϵÄÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬ £¬µ«Ê¹ÓøÃÎó²îÐèÒªÓ®µÃ¾ºÕùÌõ¼þ¡£¡£¡£¡£¡£

CVE-2023-28250£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬ £¬µ±ÆôÓÃWindowsÐÂÎÅÐÐÁÐЧÀÍʱ£¬£¬£¬£¬£¬£¬ £¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕß¿ÉÒÔͨ¹ýÍøÂç·¢ËÍÌØÖÆµÄÎļþ£¬£¬£¬£¬£¬£¬ £¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬ £¬²¢´¥·¢¶ñÒâ´úÂë¡£¡£¡£¡£¡£Ê¹ÓøÃÎó²îÐèÒªÆôÓÃ×÷ΪWindows ×é¼þµÄWindows ÐÂÎÅÐÐÁÐЧÀÍ£¬£¬£¬£¬£¬£¬ £¬¿ÉÒÔͨ¹ý¼ì²éÊÇ·ñÖøÃûΪMessage QueuingµÄЧÀÍÔÚÔËÐУ¬£¬£¬£¬£¬£¬ £¬ÒÔ¼°ÅÌËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£¡£¡£¡£¡£

CVE-2023-28232£ºWindows µã¶ÔµãËíµÀЭÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.5£¬£¬£¬£¬£¬£¬ £¬µ±Óû§½« Windows ¿Í»§¶ËÅþÁ¬µ½¶ñÒâЧÀÍÆ÷ʱ£¬£¬£¬£¬£¬£¬ £¬¿ÉÄܻᴥ·¢´ËÎó²î£¬£¬£¬£¬£¬£¬ £¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£

CVE-2023-28291£ºÔ­Ê¼Í¼ÏñÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.4£¬£¬£¬£¬£¬£¬ £¬¿ÉÒÔͨ¹ýÓÕʹÍâµØÓû§·­¿ª¶ñÒâÎļþ/Á´½ÓÀ´Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬ £¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£

±ðµÄ£¬£¬£¬£¬£¬£¬ £¬ÖµµÃ¹Ø×¢µÄÎó²î»¹°üÀ¨Microsoft Office¡¢Word ºÍ Publisher Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-28285¡¢CVE-2023-28311¡¢CVE-2023-28295ºÍCVE-2023-28287£©µÈ£¬£¬£¬£¬£¬£¬ £¬Ö»Ðè·­¿ª¶ñÒâÎĵµ¼´¿ÉʹÓÃÕâЩÎó²î£¬£¬£¬£¬£¬£¬ £¬Ó¦×¢ÖØÐÞ¸´´ËÀàÎó²î¡£¡£¡£¡£¡£

΢Èí4Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE

CVE ÎÊÌâ

ÑÏÖØË®Æ½

CVE-2023-21554

Microsoft ÐÂÎÅÐÐÁÐÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-28231

DHCP   Server Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-28219

¶þ²ãËíµÀЭÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-28220

¶þ²ãËíµÀЭÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-28250

Windows   Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-28232

Windows µã¶ÔµãËíµÀЭÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-28291

ԭʼͼÏñÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-28260

.NET DLLÐ®ÖÆÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28312

Azure »úеѧϰÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-28300

Azure ЧÀÍÅþÁ¬Æ÷Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2023-28227

Windows À¶ÑÀÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-24860

Microsoft   Defender ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-28314

Microsoft   Dynamics 365 (on-premises) ¿çÕ¾¾ç±¾Îó²î

¸ßΣ

CVE-2023-28309

Microsoft   Dynamics 365 (on-premises) ¿çÕ¾¾ç±¾Îó²î

¸ßΣ

CVE-2023-28313

Microsoft   Dynamics 365 ¿Í»§ÓïÒô¿çÕ¾¾ç±¾Îó²î

¸ßΣ

CVE-2023-24912

Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-21769

Microsoft ÐÂÎÅÐÐÁоܾøÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-28285

Microsoft   Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28295

Microsoft   Publisher Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28287

Microsoft   Publisher Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28288

Microsoft   SharePoint Server ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-28311

Microsoft   Word Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28243

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-24883

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-24927

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-24925

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-24924

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-24885

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-24928

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-24884

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-24926

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-24929

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-24887

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-24886

Microsoft   PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28275

Microsoft   WDAC OLE DB provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28256

Windows   DNS ЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28278

Windows   DNS ЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28307

Windows   DNS ЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28306

Windows   DNS ЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28223

WindowsÓòÃûЧÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28254

Windows   DNS ЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28305

Windows   DNS ЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28308

Windows   DNS ЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28255

Windows   DNS ЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28277

Windows   DNS ЧÀÍÆ÷ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-23384

Microsoft   SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-23375

Microsoft   ODBC ºÍ OLE DB Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28304

Microsoft   ODBC ºÍ OLE DB Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28299

Visual   Studio ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-28262

Visual   Studio ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-28263

Visual   Studio ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-28296

Visual   Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-24893

Visual   Studio Code Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28302

Microsoft ÐÂÎÅÐÐÁоܾøÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-28236

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-28216

Windows ¸ß¼¶ÍâµØÀú³ÌŲÓà (ALPC) ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-28218

Windows   Ancillary Function Driver for WinSock ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-28269

Windows Æô¶¯ÖÎÀíÆ÷Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2023-28249

Windows Æô¶¯ÖÎÀíÆ÷Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2023-28273

Windows   Clip ЧÀÍÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-28229

Windows   CNG ÃÜÔ¿¸ôÀëЧÀÍÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-28266

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-28252

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-28226

Windows ×¢²áÒýÇæÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2023-28221

Windows ¹ýʧ±¨¸æÐ§ÀÍÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-28276

Windows ×éÕ½ÂÔÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2023-28238

Windows   Internet ÃÜÔ¿½»Á÷ (IKE) ЭÒéÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28244

Windows   Kerberos ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-28271

Windows ÄÚºËÄÚ´æÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-28248

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-28222

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-28272

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-28293

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-28253

Windows ÄÚºËÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-28237

Windows ÄÚºËÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28298

Windows Äں˾ܾøÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-28270

Windows ËøÆÁÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2023-28235

Windows ËøÆÁÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2023-28268

Netlogon   RPC ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-28217

Windows ÍøÂçµØµãת»» (NAT) ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-28247

Windows ÍøÂçÎļþϵͳÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-28240

Windows ÍøÂç¸ºÔØÆ½ºâÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28225

Windows   NTLM ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-28224

Windows ÒÔÌ«Íøµã¶ÔµãЭÒé (PPPoE) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28292

ԭʼͼÏñÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28228

Windows ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-28267

Ô¶³Ì×ÀÃæÐ­Òé¿Í»§¶ËÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-28246

Windows ×¢²á±íÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-21729

Ô¶³ÌÀú³ÌŲÓÃÔËÐÐʱÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-21727

Ô¶³ÌÀú³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28297

Windows Ô¶³ÌÀú³ÌŲÓÃЧÀÍ (RPCSS) ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-24931

Windows Ç徲ͨµÀ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-28233

Windows Ç徲ͨµÀ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-28241

Windows Çå¾²Ì×½Ó×ÖËíµÀЭÒé (SSTP) ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-28234

Windows Ç徲ͨµÀ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-28274

Windows   Win32k ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-24914

Win32k ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-28284

Microsoft   Edge£¨»ùÓÚ Chromium£©Çå¾²¹¦Ð§ÈƹýÎó²î

ÖÐΣ

CVE-2023-28301

Microsoft   Edge£¨»ùÓÚ Chromium£©¸Ä¶¯Îó²î

µÍΣ

CVE-2023-24935

Microsoft   Edge£¨»ùÓÚ Chromium£©ÓÕÆ­Îó²î

µÍΣ

CVE-2023-1823

Chromium£ºCVE-2023-1823 ÔÚ FedCM ÖÐʵÑé²»µ±

δ֪

CVE-2023-1810

Chromium£ºCVE-2023-1810 VisualsÖеĶѻº³åÇøÒç³ö

δ֪

CVE-2023-1819

Chromium£ºCVE-2023-1819 AccessibilityÖеÄÔ½½ç¶ÁÈ¡

δ֪

CVE-2023-1818

Chromium£ºCVE-2023-1818 Vulkan ÖеÄÊͷźóʹÓÃ

δ֪

CVE-2023-1814

Chromium£ºCVE-2023-1814 Çå¾²ä¯ÀÀÖв»ÊÜÐÅÈεÄÊäÈëÑéÖ¤²»³ä·Ö

δ֪

CVE-2023-1821

Chromium£ºCVE-2023-1821 WebShare ÖеÄʵÑé²»µ±

δ֪

CVE-2023-1811

Chromium£ºCVE-2023-1811 Frames ÖеÄÊͷźóʹÓÃ

δ֪

CVE-2023-1820

Chromium£ºCVE-2023-1820 ä¯ÀÀÆ÷ÀúÊ·ÖеĶѻº³åÇøÒç³ö

δ֪

CVE-2023-1816

Chromium£ºCVE-2023-1816 »­Öл­ÖеÄÇå¾² UI ²»×¼È·

δ֪

CVE-2023-1815

Chromium£ºCVE-2023-1815 Networking APIsÖеÄÊͷźóʹÓÃ

δ֪

CVE-2023-1822

Chromium£ºCVE-2023-1822 µ¼º½ÖеÄÇå¾² UI ²»×¼È·

δ֪

CVE-2023-1813

Chromium£ºCVE-2023-1813 À©Õ¹ÖеÄʵÑé²»µ±

δ֪

CVE-2023-1812

Chromium£ºCVE-2023-1812 DOM °ó¶¨ÖеÄÔ½½çÄÚ´æ»á¼û

δ֪

CVE-2023-1817

Chromium£º CVE-2023-1817 IntentsÖеÄÕ½ÂÔÖ´ÐÐȱ·¦

δ֪

 

¶þ¡¢Ó°Ïì¹æÄ£

ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/ЧÀÍ/×é¼þ°üÀ¨£º

.NET Core

Azure Machine Learning

Azure Service Connector

Microsoft Bluetooth Driver

Microsoft Defender for Endpoint

Microsoft Dynamics

Microsoft Dynamics 365 Customer Voice

Microsoft Edge (Chromium-based)

Microsoft Graphics Component

Microsoft Message Queuing

Microsoft Office

Microsoft Office Publisher

Microsoft Office SharePoint

Microsoft Office Word

Microsoft PostScript Printer Driver

Microsoft Printer Drivers

Microsoft WDAC OLE DB provider for SQL

Microsoft Windows DNS

Visual Studio

Visual Studio Code

Windows Active Directory

Windows ALPC

Windows Ancillary Function Driver for WinSock

Windows Boot Manager

Windows Clip Service

Windows CNG Key Isolation Service

Windows Common Log File System Driver

Windows DHCP Server

Windows Enroll Engine

Windows Error Reporting

Windows Group Policy

Windows Internet Key Exchange (IKE) Protocol

Windows Kerberos

Windows Kernel

Windows Layer 2 Tunneling Protocol

Windows Lock Screen

Windows Netlogon

Windows Network Address Translation (NAT)

Windows Network File System

Windows Network Load Balancing

Windows NTLM

Windows PGM

Windows Point-to-Point Protocol over Ethernet (PPPoE)

Windows Point-to-Point Tunneling Protocol

Windows Raw Image Extension

Windows RDP Client

Windows Registry

Windows RPC API

Windows Secure Boot

Windows Secure Channel

Windows Secure Socket Tunneling Protocol (SSTP)

Windows Transport Security Layer (TLS)

Windows Win32K

 

Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬£¬ £¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬ £¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬ £¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϰ취ÊÖ¶¯¾ÙÐиüУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬ £¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬£¬ £¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬ £¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬£¬ £¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£

4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬£¬ £¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬£¬ £¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬£¬ £¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬ £¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£

2023Äê4ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2023-Apr

²¹¶¡ÏÂÔØÊ¾Àý£º

1.·­¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬£¬£¬ £¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£¡£¡£¡£¡£

image.png

Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2022Äê2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬£¬£¬ £¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·­¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Çå¾²¸üС¿£¬£¬£¬£¬£¬£¬ £¬·­¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬£¬£¬ £¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öᣡ£¡£¡£¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£¡£¡£¡£¡£

 

3.2 ÔÝʱ²½·¥

Õë¶ÔCVE-2023-28252£¬£¬£¬£¬£¬£¬ £¬¿É²Î¿¼ÒÔÏÂÁ´½Ó»ñ¸ü¶àÎó²îÐÅÏ¢¼°IoC£º

https://securelist.com/nokoyawa-ransomware-attacks-with-windows-zero-day/109483/

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬ £¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬£¬ £¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬ £¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬ £¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ £¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ £¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ £¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ £¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬£¬ £¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2023-Apr

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28252

https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2023-patch-tuesday-fixes-1-zero-day-97-flaws/

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-04-12

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼

5.1 ¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬ £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬£¬£¬ £¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬£¬ £¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬ £¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬£¬£¬£¬£¬ £¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬ £¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£

5.2 ¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬£¬£¬ £¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬£¬£¬ £¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png