¡¾Îó²îͨ¸æ¡¿Î¢Èí4Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2023-04-12Ò»¡¢Îó²î¸ÅÊö
2023Äê4ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬Î¢ÈíÐû²¼ÁË4ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬±¾´Î¸üÐÂÐÞ¸´Á˰üÀ¨1¸ö0 dayÎó²îÔÚÄÚµÄ97¸öÇå¾²Îó²î£¨²»°üÀ¨Microsoft EdgeÎó²î£©£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ7¸öÎó²îÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£¡£¡£¡£¡£
±¾´ÎÐÞ¸´µÄÎó²îÖУ¬£¬£¬£¬£¬£¬£¬Îó²îÀàÐͰüÀ¨ÌØÈ¨ÌáÉýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾øÐ§ÀÍÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²îºÍÓÕÆÎó²îµÈ¡£¡£¡£¡£¡£
΢Èí±¾´Î¹²ÐÞ¸´ÁË1¸ö±»Æð¾¢Ê¹ÓõÄ0 dayÎó²î£¬£¬£¬£¬£¬£¬£¬ÈçÏ£º
CVE-2023-28252 £ºWindows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î
Windows CLFS Çý¶¯³ÌÐòÖб£´æÔ½½çдÈëÎó²î£¬£¬£¬£¬£¬£¬£¬ÍâµØµÍȨÏÞÓû§¿ÉÒÔͨ¹ý»ù½ñÈÕÖ¾Îļþ£¨.blf ÎļþÀ©Õ¹Ãû£©µÄ²Ù×÷´¥·¢¸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿Éµ¼ÖÂÍâµØÈ¨ÏÞÌáÉýΪSYSTEM¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÒÑ·¢Ã÷±»Nokoyawa ÀÕË÷Èí¼þʹÓᣡ£¡£¡£¡£
±¾´ÎÇå¾²¸üÐÂÖÐÆÀ¼¶ÎªÑÏÖØµÄ7¸öÎó²î°üÀ¨£º
CVE-2023-21554£ºMicrosoft ÐÂÎÅÐÐÁÐÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý·¢ËͶñÒâÖÆ×÷µÄMSMQ Êý¾Ý°üµ½MSMQ ЧÀÍÆ÷À´Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÔÚЧÀÍÆ÷¶ËÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£Ê¹ÓøÃÎó²îÐèÒªÆôÓÃ×÷ΪWindows ×é¼þµÄWindows ÐÂÎÅÐÐÁÐЧÀÍ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý¼ì²éÊÇ·ñÖøÃûΪMessage QueuingµÄЧÀÍÔÚÔËÐУ¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÅÌËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£¡£¡£¡£¡£
CVE-2023-28231£ºDHCP Server Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.8£¬£¬£¬£¬£¬£¬£¬¾ÓÉÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔʹÓÃÕë¶Ô DHCP ЧÀ͵ÄÌØÖÆ RPC ŲÓÃÀ´Ê¹ÓøÃÎó²î¡£¡£¡£¡£¡£
CVE-2023-28219/ CVE-2023-28220£º¶þ²ãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.1£¬£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔÏò RAS ЧÀÍÆ÷·¢ËͶñÒâÅþÁ¬ÇëÇ󣬣¬£¬£¬£¬£¬£¬Õâ¿ÉÄܵ¼Ö RAS ЧÀÍÆ÷ÅÌËã»úÉϵÄÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬£¬µ«Ê¹ÓøÃÎó²îÐèÒªÓ®µÃ¾ºÕùÌõ¼þ¡£¡£¡£¡£¡£
CVE-2023-28250£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬£¬µ±ÆôÓÃWindowsÐÂÎÅÐÐÁÐЧÀÍʱ£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕß¿ÉÒÔͨ¹ýÍøÂç·¢ËÍÌØÖÆµÄÎļþ£¬£¬£¬£¬£¬£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬£¬²¢´¥·¢¶ñÒâ´úÂë¡£¡£¡£¡£¡£Ê¹ÓøÃÎó²îÐèÒªÆôÓÃ×÷ΪWindows ×é¼þµÄWindows ÐÂÎÅÐÐÁÐЧÀÍ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý¼ì²éÊÇ·ñÖøÃûΪMessage QueuingµÄЧÀÍÔÚÔËÐУ¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÅÌËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£¡£¡£¡£¡£
CVE-2023-28232£ºWindows µã¶ÔµãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.5£¬£¬£¬£¬£¬£¬£¬µ±Óû§½« Windows ¿Í»§¶ËÅþÁ¬µ½¶ñÒâЧÀÍÆ÷ʱ£¬£¬£¬£¬£¬£¬£¬¿ÉÄܻᴥ·¢´ËÎó²î£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£
CVE-2023-28291£ºÔʼͼÏñÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.4£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÓÕʹÍâµØÓû§·¿ª¶ñÒâÎļþ/Á´½ÓÀ´Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÎó²î»¹°üÀ¨Microsoft Office¡¢Word ºÍ Publisher Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-28285¡¢CVE-2023-28311¡¢CVE-2023-28295ºÍCVE-2023-28287£©µÈ£¬£¬£¬£¬£¬£¬£¬Ö»Ðè·¿ª¶ñÒâÎĵµ¼´¿ÉʹÓÃÕâЩÎó²î£¬£¬£¬£¬£¬£¬£¬Ó¦×¢ÖØÐÞ¸´´ËÀàÎó²î¡£¡£¡£¡£¡£
΢Èí4Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º
CVE | CVE ÎÊÌâ | ÑÏÖØË®Æ½ |
CVE-2023-21554 | Microsoft ÐÂÎÅÐÐÁÐÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-28231 | DHCP Server Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-28219 | ¶þ²ãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-28220 | ¶þ²ãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-28250 | Windows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-28232 | Windows µã¶ÔµãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-28291 | ÔʼͼÏñÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-28260 | .NET DLLÐ®ÖÆÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28312 | Azure »úеѧϰÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-28300 | Azure ЧÀÍÅþÁ¬Æ÷Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-28227 | Windows À¶ÑÀÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24860 | Microsoft Defender ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2023-28314 | Microsoft Dynamics 365 (on-premises) ¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2023-28309 | Microsoft Dynamics 365 (on-premises) ¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2023-28313 | Microsoft Dynamics 365 ¿Í»§ÓïÒô¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2023-24912 | Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-21769 | Microsoft ÐÂÎÅÐÐÁоܾøÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2023-28285 | Microsoft Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28295 | Microsoft Publisher Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28287 | Microsoft Publisher Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28288 | Microsoft SharePoint Server ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-28311 | Microsoft Word Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28243 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24883 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-24927 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24925 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24924 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24885 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24928 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24884 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24926 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24929 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24887 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24886 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28275 | Microsoft WDAC OLE DB provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28256 | Windows DNS ЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28278 | Windows DNS ЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28307 | Windows DNS ЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28306 | Windows DNS ЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28223 | WindowsÓòÃûЧÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28254 | Windows DNS ЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28305 | Windows DNS ЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28308 | Windows DNS ЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28255 | Windows DNS ЧÀÍÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28277 | Windows DNS ЧÀÍÆ÷ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-23384 | Microsoft SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-23375 | Microsoft ODBC ºÍ OLE DB Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28304 | Microsoft ODBC ºÍ OLE DB Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28299 | Visual Studio ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-28262 | Visual Studio ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28263 | Visual Studio ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-28296 | Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24893 | Visual Studio Code Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28302 | Microsoft ÐÂÎÅÐÐÁоܾøÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2023-28236 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28216 | Windows ¸ß¼¶ÍâµØÀú³ÌŲÓà (ALPC) ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28218 | Windows Ancillary Function Driver for WinSock ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28269 | Windows Æô¶¯ÖÎÀíÆ÷Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-28249 | Windows Æô¶¯ÖÎÀíÆ÷Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-28273 | Windows Clip ЧÀÍÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28229 | Windows CNG ÃÜÔ¿¸ôÀëЧÀÍÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28266 | Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-28252 | Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28226 | Windows ×¢²áÒýÇæÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-28221 | Windows ¹ýʧ±¨¸æÐ§ÀÍÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28276 | Windows ×éÕ½ÂÔÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-28238 | Windows Internet ÃÜÔ¿½»Á÷ (IKE) ÐÒéÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28244 | Windows Kerberos ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28271 | Windows ÄÚºËÄÚ´æÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-28248 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28222 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28272 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28293 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28253 | Windows ÄÚºËÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-28237 | Windows ÄÚºËÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28298 | Windows Äں˾ܾøÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2023-28270 | Windows ËøÆÁÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-28235 | Windows ËøÆÁÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-28268 | Netlogon RPC ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28217 | Windows ÍøÂçµØµãת»» (NAT) ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2023-28247 | Windows ÍøÂçÎļþϵͳÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-28240 | Windows ÍøÂç¸ºÔØÆ½ºâÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28225 | Windows NTLM ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28224 | Windows ÒÔÌ«Íøµã¶ÔµãÐÒé (PPPoE) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28292 | ÔʼͼÏñÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28228 | Windows ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-28267 | Ô¶³Ì×ÀÃæÐÒé¿Í»§¶ËÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-28246 | Windows ×¢²á±íÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-21729 | Ô¶³ÌÀú³ÌŲÓÃÔËÐÐʱÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-21727 | Ô¶³ÌÀú³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28297 | Windows Ô¶³ÌÀú³ÌŲÓÃЧÀÍ (RPCSS) ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-24931 | Windows Ç徲ͨµÀ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2023-28233 | Windows Ç徲ͨµÀ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2023-28241 | Windows Çå¾²Ì×½Ó×ÖËíµÀÐÒé (SSTP) ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2023-28234 | Windows Ç徲ͨµÀ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2023-28274 | Windows Win32k ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-24914 | Win32k ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28284 | Microsoft Edge£¨»ùÓÚ Chromium£©Çå¾²¹¦Ð§ÈƹýÎó²î | ÖÐΣ |
CVE-2023-28301 | Microsoft Edge£¨»ùÓÚ Chromium£©¸Ä¶¯Îó²î | µÍΣ |
CVE-2023-24935 | Microsoft Edge£¨»ùÓÚ Chromium£©ÓÕÆÎó²î | µÍΣ |
CVE-2023-1823 | Chromium£ºCVE-2023-1823 ÔÚ FedCM ÖÐʵÑé²»µ± | δ֪ |
CVE-2023-1810 | Chromium£ºCVE-2023-1810 VisualsÖеĶѻº³åÇøÒç³ö | δ֪ |
CVE-2023-1819 | Chromium£ºCVE-2023-1819 AccessibilityÖеÄÔ½½ç¶ÁÈ¡ | δ֪ |
CVE-2023-1818 | Chromium£ºCVE-2023-1818 Vulkan ÖеÄÊͷźóʹÓà | δ֪ |
CVE-2023-1814 | Chromium£ºCVE-2023-1814 Çå¾²ä¯ÀÀÖв»ÊÜÐÅÈεÄÊäÈëÑéÖ¤²»³ä·Ö | δ֪ |
CVE-2023-1821 | Chromium£ºCVE-2023-1821 WebShare ÖеÄʵÑé²»µ± | δ֪ |
CVE-2023-1811 | Chromium£ºCVE-2023-1811 Frames ÖеÄÊͷźóʹÓà | δ֪ |
CVE-2023-1820 | Chromium£ºCVE-2023-1820 ä¯ÀÀÆ÷ÀúÊ·ÖеĶѻº³åÇøÒç³ö | δ֪ |
CVE-2023-1816 | Chromium£ºCVE-2023-1816 »ÖлÖеÄÇå¾² UI ²»×¼È· | δ֪ |
CVE-2023-1815 | Chromium£ºCVE-2023-1815 Networking APIsÖеÄÊͷźóʹÓà | δ֪ |
CVE-2023-1822 | Chromium£ºCVE-2023-1822 µ¼º½ÖеÄÇå¾² UI ²»×¼È· | δ֪ |
CVE-2023-1813 | Chromium£ºCVE-2023-1813 À©Õ¹ÖеÄʵÑé²»µ± | δ֪ |
CVE-2023-1812 | Chromium£ºCVE-2023-1812 DOM °ó¶¨ÖеÄÔ½½çÄÚ´æ»á¼û | δ֪ |
CVE-2023-1817 | Chromium£º CVE-2023-1817 IntentsÖеÄÕ½ÂÔÖ´ÐÐȱ·¦ | δ֪ |
¶þ¡¢Ó°Ïì¹æÄ£
ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/ЧÀÍ/×é¼þ°üÀ¨£º
.NET Core
Azure Machine Learning
Azure Service Connector
Microsoft Bluetooth Driver
Microsoft Defender for Endpoint
Microsoft Dynamics
Microsoft Dynamics 365 Customer Voice
Microsoft Edge (Chromium-based)
Microsoft Graphics Component
Microsoft Message Queuing
Microsoft Office
Microsoft Office Publisher
Microsoft Office SharePoint
Microsoft Office Word
Microsoft PostScript Printer Driver
Microsoft Printer Drivers
Microsoft WDAC OLE DB provider for SQL
Microsoft Windows DNS
Visual Studio
Visual Studio Code
Windows Active Directory
Windows ALPC
Windows Ancillary Function Driver for WinSock
Windows Boot Manager
Windows Clip Service
Windows CNG Key Isolation Service
Windows Common Log File System Driver
Windows DHCP Server
Windows Enroll Engine
Windows Error Reporting
Windows Group Policy
Windows Internet Key Exchange (IKE) Protocol
Windows Kerberos
Windows Kernel
Windows Layer 2 Tunneling Protocol
Windows Lock Screen
Windows Netlogon
Windows Network Address Translation (NAT)
Windows Network File System
Windows Network Load Balancing
Windows NTLM
Windows PGM
Windows Point-to-Point Protocol over Ethernet (PPPoE)
Windows Point-to-Point Tunneling Protocol
Windows Raw Image Extension
Windows RDP Client
Windows Registry
Windows RPC API
Windows Secure Boot
Windows Secure Channel
Windows Secure Socket Tunneling Protocol (SSTP)
Windows Transport Security Layer (TLS)
Windows Win32K
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϰ취ÊÖ¶¯¾ÙÐиüУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬£¬£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£
4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£
2023Äê4ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2023-Apr
²¹¶¡ÏÂÔØÊ¾Àý£º
1.·¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬£¬£¬£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£¡£¡£¡£¡£
Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2022Äê2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾Çå¾²¸üС¿£¬£¬£¬£¬£¬£¬£¬·¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öᣡ£¡£¡£¡£
Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£¡£¡£¡£¡£
3.2 ÔÝʱ²½·¥
Õë¶ÔCVE-2023-28252£¬£¬£¬£¬£¬£¬£¬¿É²Î¿¼ÒÔÏÂÁ´½Ó»ñ¸ü¶àÎó²îÐÅÏ¢¼°IoC£º
https://securelist.com/nokoyawa-ransomware-attacks-with-windows-zero-day/109483/
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2023-Apr
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28252
https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2023-patch-tuesday-fixes-1-zero-day-97-flaws/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-04-12 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¼øºÚµ£±£Íø¼ò½é
¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£
5.2 ¹ØÓÚ¼øºÚµ£±£Íø
¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£
¹Ø×¢ÎÒÃÇ£º