¡¾Îó²îͨ¸æ¡¿Î¢Èí5Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2023-05-10

Ò»¡¢Îó²î¸ÅÊö

2023Äê5ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬£¬Î¢ÈíÐû²¼ÁË5ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬±¾´Î¸üÐÂÐÞ¸´Á˰üÀ¨3¸ö0 dayÎó²îÔÚÄÚµÄ38¸öÇå¾²Îó²î£¨²»°üÀ¨Microsoft EdgeÎó²î£©£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ6¸öÎó²îÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£¡£¡£¡£¡£¡£¡£

±¾´ÎÐÞ¸´µÄÎó²îÖУ¬£¬£¬£¬£¬£¬£¬Îó²îÀàÐͰüÀ¨ÌØÈ¨ÌáÉýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾øÐ§ÀÍÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²îºÍÓÕÆ­Îó²îµÈ¡£¡£¡£¡£¡£¡£¡£

΢Èí±¾´Î¹²ÐÞ¸´ÁË3¸ö0 dayÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÁ½¸öÒÑÔÚ¹¥»÷Öб»Ê¹Ó㬣¬£¬£¬£¬£¬£¬ÁíÒ»¸öÒѱ»¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬ÈçÏ£º

CVE-2023-29336£ºWin32k ÌØÈ¨ÌáÉýÎó²î

Win32kÄÚºËÇý¶¯³ÌÐòÖб£´æÈ¨ÏÞÌáÉýÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÒÔ»ñµÃSYSTEM ȨÏÞ£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚ¸ÃÎó²îÒÑ·¢Ã÷±»Ê¹Óᣡ£¡£¡£¡£¡£¡£

CVE-2023-24932£ºÇå¾²Æô¶¯Çå¾²¹¦Ð§ÈƹýÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ6.7£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕß¿ÉÒÔÈÆ¹ýÇå¾²Æô¶¯£¬£¬£¬£¬£¬£¬£¬µ«Ê¹ÓøÃÎó²îÐèÒª¶ÔÄ¿µÄ×°±¸¾ßÓÐÎïÆÊÎö¼ûȨÏÞ»òÍâµØÖÎÀíԱȨÏÞ£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚ¸ÃÎó²îÒÑ·¢Ã÷±»Ê¹Óᣡ£¡£¡£¡£¡£¡£Î¢ÈíÒѾ­Ðû²¼ÁËCVE-2023-24932µÄ³õʼÐÞ¸´³ÌÐò£¬£¬£¬£¬£¬£¬£¬µ«Ä¬ÈÏÇéÐÎÏ´¦ÓÚ½ûÓÃ״̬²¢ÇÒ²»»áÌṩ±£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬£¬ÔÚÆôÓô˸üÐÂ֮ǰ£¬£¬£¬£¬£¬£¬£¬¿Í»§ÐèÒª×Ðϸƾ֤ÊÖ¶¯°ì·¨¸üÐÂ¿ÉÆô¶¯Ã½Ìå²¢Ó¦ÓÃ×÷·Ï¡£¡£¡£¡£¡£¡£¡£

CVE-2023-29325£ºWindows OLE Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.1£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÏòÊܺ¦Õß·¢ËÍÌØÖÆµç×ÓÓʼþ»òÆäËü·½·¨À´Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÔÚÊܺ¦ÕߵĻúеÉÏÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬£¬£¬µ«Ê¹ÓøÃÎó²îÐèÒªÓ®µÃ¾ºÕùÌõ¼þ¡£¡£¡£¡£¡£¡£¡£×¢ÖØ£¬£¬£¬£¬£¬£¬£¬Microsoft OutlookÓ¦ÓóÌÐòÔ¤ÀÀ´°¸ñ¿ÉÄÜÊǸÃÎó²îµÄÒ»¸ö¹¥»÷ǰÑÔ¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÏÖÔÚÒѾ­¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬µ«ÔÝδ·¢Ã÷±»Ê¹Óᣡ£¡£¡£¡£¡£¡£

±¾´ÎÇå¾²¸üÐÂÖÐÆÀ¼¶ÎªÑÏÖØµÄ6¸öÎó²î°üÀ¨£º

l  CVE-2023-24955£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.2£¬£¬£¬£¬£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄÍþвÕß×÷ÎªÍøÕ¾ËùÓÐÕß¿ÉÒÔÔÚ SharePoint ServerÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£

l  CVE-2023-28283£ºWindows ÇáÁ¿¼¶Ä¿Â¼»á¼ûЭÒé(LDAP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.1£¬£¬£¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔͨ¹ýÒ»×éÌØÖÆµÄ LDAP ŲÓûñµÃ´úÂëÖ´ÐÐȨÏÞ£¬£¬£¬£¬£¬£¬£¬´Ó¶øÔÚ LDAP ЧÀ͵ÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬£¬µ«Ê¹ÓøÃÎó²îÐèÒªÓ®µÃ¾ºÕùÌõ¼þ¡£¡£¡£¡£¡£¡£¡£

l  CVE-2023-24941£ºWindows ÍøÂçÎļþϵͳԶ³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý¶ÔÍøÂçÎļþϵͳ (NFS) ЧÀ;ÙÐÐδ¾­Éí·ÝÑéÖ¤µÄÌØÖÆÅ²ÓÃÒÔ´¥·¢Ô¶³Ì´úÂëÖ´ÐÐ (RCE)¡£¡£¡£¡£¡£¡£¡£

l  CVE-2023-29325£ºWindows OLE Ô¶³Ì´úÂëÖ´ÐÐÎó²î

l  CVE-2023-24943£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬£¬µ± Windows Message Queuing ЧÀÍÔÚ PGM Server ÇéÐÎÖÐÔËÐÐʱ£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÍøÂç·¢ËÍÌØÖÆÎļþÀ´ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£Ö»ÓÐ PGM Server Ò×ÊܸÃÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£¡£

l  CVE-2023-24903£ºWindows Çå¾²Ì×½Ó×ÖËíµÀЭÒé (SSTP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.1£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÏò SSTP ЧÀÍÆ÷·¢ËÍÌØÖÆµÄSSTP Êý¾Ý°üÀ´Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÔÚЧÀÍÆ÷¶ËÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬£¬£¬µ«Ê¹ÓøÃÎó²îÐèÒªÓ®µÃ¾ºÕùÌõ¼þ¡£¡£¡£¡£¡£¡£¡£

΢Èí5Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE-ID

CVE ÎÊÌâ

ÑÏÖØË®Æ½

CVE-2023-24955

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-28283

Windows ÇáÁ¿¼¶Ä¿Â¼»á¼ûЭÒé(LDAP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-24941

Windows ÍøÂçÎļþϵͳԶ³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-29325

Windows   OLE Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-24943

Windows   Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-24903

Windows Çå¾²Ì×½Ó×ÖËíµÀЭÒé (SSTP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-24947

Windows À¶ÑÀÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-24948

Windows À¶ÑÀÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-24944

Windows À¶ÑÀÇý¶¯³ÌÐòÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-29350

Microsoft   Edge£¨»ùÓÚ Chromium£©ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-24899

Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-29344

Microsoft   Office Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-29333

Microsoft   Access ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-24953

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-24954

Microsoft   SharePoint Server ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-24950

Microsoft SharePoint   Server ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-29335

Microsoft   Word Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2023-24881

Microsoft   Teams ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-29340

AV1 ÊÓÆµÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-29341

AV1 ÊÓÆµÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-24905

Remote   Desktop ClientÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-29343

SysInternals   Sysmon for Windows ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-29338

Visual   Studio Code ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-24946

Windows ±¸·ÝЧÀÍÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-24904

Windows   Installer ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-24945

Windows   iSCSI Ä¿µÄЧÀÍÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-24949

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-29324

Windows   MSHTML ƽ̨Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2023-24901

Windows   NFS Portmapper ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-24939

Server for   NFS ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-24900

Windows   NTLM Çå¾²Ö§³ÖÌṩ³ÌÐòÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-24940

Windows   Pragmatic General Multicast (PGM) ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-28290

Microsoft   Remote Desktop app for Windows ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-24942

Remote   Procedure Call Runtime ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-28251

Windows Çý¶¯³ÌÐòµõÏúÁбíÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2023-24932

Çå¾²Æô¶¯Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2023-24898

Windows   SMB ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-29336

Win32k ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-24902

Win32k ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-29354

Microsoft   Edge£¨»ùÓÚ Chromium£©Çå¾²¹¦Ð§ÈƹýÎó²î

ÖÐΣ

CVE-2023-2468

Chromium£ºCVE-2023-2468 »­Öл­ÊµÑé²»µ±

δ֪

CVE-2023-2459

Chromium£ºCVE-2023-2459 PromptsÖеÄʵÑé²»µ±

δ֪

CVE-2023-2467

Chromium£ºCVE-2023-2467 PromptsÖеÄʵÑé²»µ±

δ֪

CVE-2023-2463

Chromium£ºCVE-2023-2463 ÔÚÈ«ÆÁģʽÏÂʵÑé²»µ±

δ֪

CVE-2023-2462

Chromium£ºCVE-2023-2462 PromptsÖеÄʵÑé²»µ±

δ֪

CVE-2023-2460

Chromium£ºCVE-2023-2460 À©Õ¹Öв»ÊÜÐÅÈεÄÊäÈëÑé֤ȱ·¦

δ֪

CVE-2023-2465

Chromium£ºCVE-2023-2465 CORS ÖÐʵÑé²»µ±

δ֪

CVE-2023-2466

Chromium£ºCVE-2023-2466 PromptsÖеÄʵÑé²»µ±

δ֪

CVE-2023-2464

Chromium£ºCVE-2023-2464 »­Öл­ÊµÑé²»µ±

δ֪

 

¶þ¡¢Ó°Ïì¹æÄ£

ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/ЧÀÍ/×é¼þ°üÀ¨£º

Microsoft Teams

Windows SMB

Microsoft Graphics Component

Windows NTLM

Windows NFS Portmapper

Windows Win32K

Windows Secure Socket Tunneling Protocol (SSTP)

Windows Installer

Remote Desktop Client

Windows Secure Boot

Reliable Multicast Transport Driver (RMCAST)

Windows Network File System

Windows Remote Procedure Call Runtime

Microsoft Bluetooth Driver

Windows iSCSI Target Service

Windows Backup Engine

Windows Kernel

Microsoft Office SharePoint

Microsoft Office Excel

Windows LDAP - Lightweight Directory Access Protocol

Windows RDP Client

Windows MSHTML Platform

Windows OLE

Microsoft Office Access

Microsoft Office Word

Visual Studio Code

Microsoft Windows Codecs Library

SysInternals

Microsoft Office

Microsoft Edge (Chromium-based)

 

Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£¡£¡£¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£¡£¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϰ취ÊÖ¶¯¾ÙÐиüУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬£¬£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£¡£¡£

4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£¡£¡£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£¡£¡£

2023Äê5ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2023-May

²¹¶¡ÏÂÔØÊ¾Àý£º

1.·­¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬£¬£¬£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£¡£¡£¡£¡£¡£¡£

image.png

Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2022Äê2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·­¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£¡£¡£¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Çå¾²¸üС¿£¬£¬£¬£¬£¬£¬£¬·­¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öᣡ£¡£¡£¡£¡£¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£¡£¡£¡£¡£¡£¡£

 

3.2 ÔÝʱ²½·¥

Õë¶ÔCVE-2023-24932£¬£¬£¬£¬£¬£¬£¬Ïà¹ØÉèÖÃÖ¸Äϼ°¸ü¶àÎó²îÐÅÏ¢¿É²Î¿¼£º

https://msrc.microsoft.com/blog/2023/05/guidance-related-to-secure-boot-manager-changes-associated-with-cve-2023-24932/

Õë¶ÔCVE-2023-24941£¬£¬£¬£¬£¬£¬£¬»º½â²½·¥¿É²Î¿¼£º

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24941

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2023-May

https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2023-patch-tuesday-fixes-3-zero-days-38-flaws/

https://www.bleepingcomputer.com/news/microsoft/microsoft-issues-optional-fix-for-secure-boot-zero-day-used-by-malware/

  

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-05-10

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼

5.1 ¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£¡£

5.2 ¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png