¡¾Îó²îͨ¸æ¡¿Î¢Èí6Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2023-06-14

 

Ò»¡¢Îó²î¸ÅÊö

2023Äê6ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬Î¢ÈíÐû²¼ÁË6ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬£¬±¾´Î¸üй²ÐÞ¸´ÁË78¸öÇå¾²Îó²î£¨²»°üÀ¨Microsoft EdgeÎó²î£©£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ6¸öÎó²îÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£¡£¡£¡£¡£

±¾´ÎÐÞ¸´µÄÎó²îÖУ¬£¬£¬£¬£¬£¬Îó²îÀàÐͰüÀ¨ÌØÈ¨ÌáÉýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾øÐ§ÀÍÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²îºÍÓÕÆ­Îó²îµÈ¡£¡£¡£¡£¡£

΢Èí±¾´ÎÇå¾²¸üÐÂÖÐÎ´Éæ¼°0 dayÎó²î£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÎó²î°üÀ¨µ«²»ÏÞÓÚ£º

CVE-2023-29357 £ºMicrosoft SharePoint Server ÌØÈ¨ÌáÉýÎó²î

Microsoft SharePoint Server 2019Öб£´æÈ¨ÏÞÌáÉýÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.8¡£¡£¡£¡£¡£»£»£»£»£»£»ñµÃÓÕÆ­ÐÔJWTÉí·ÝÑéÖ¤ÁîÅÆµÄÍþвÕß¿ÉÒÔʹÓÃÕâЩÁîÅÆÖ´ÐÐÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬´Ó¶øÈƹýÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬²¢¿ÉÄÜ»ñµÃÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£

CVE-2023-32031 £ºMicrosoft Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.8£¬£¬£¬£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔʵÑéͨ¹ýÍøÂçŲÓÃÔÚЧÀÍÆ÷ÕË»§µÄÉÏÏÂÎÄÖд¥·¢¶ñÒâ´úÂë¡£¡£¡£¡£¡£

CVE-2023-24897£º.NET¡¢.NET Framework ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÓÕµ¼Êܺ¦Õß´ÓÍøÕ¾ÏÂÔØ²¢·­¿ªÌØÖÆÎļþµÄÎó²îʹÓ㬣¬£¬£¬£¬£¬´Ó¶øµ¼Ö¶ÔÊܺ¦ÕßµÄÅÌËã»ú¾ÙÐÐÍâµØ¹¥»÷£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£

CVE-2023-32013£ºWindows Hyper-V ¾Ü¾øÐ§ÀÍÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ6.5¡£¡£¡£¡£¡£

CVE-2023-29363/CVE-2023-32014/CVE-2023-32015£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÕâЩÎó²îµÄCVSSv3ÆÀ·Ö¾ùΪ9.8£¬£¬£¬£¬£¬£¬µ± Windows ÐÂÎÅÐÐÁÐЧÀÍÔËÐÐÔÚ PGM Server ÇéÐÎÖÐʱ£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÍøÂç·¢ËÍÌØÖÆÎļþÀ´ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£Windows ÐÂÎÅÐÐÁÐЧÀÍÊÇÒ»¸ö Windows ×é¼þ£¬£¬£¬£¬£¬£¬ÆôÓøÃ×é¼þµÄϵͳ²ÅÒ×ÊÜÕë¶ÔÕâЩÎó²îµÄ¹¥»÷£¬£¬£¬£¬£¬£¬¿ÉÒÔ¼ì²éÊÇ·ñÖøÃûΪMessage QueuingµÄЧÀÍÕýÔÚÔËÐв¢ÇÒ TCP ¶Ë¿Ú 1801 ÕýÔÚ»úеÉÏÕìÌý¡£¡£¡£¡£¡£

CVE-2023-29362£ºRemote Desktop ClientÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.8£¬£¬£¬£¬£¬£¬ÔÚÔ¶³Ì×ÀÃæÅþÁ¬µÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬µ±Êܺ¦ÕßʹÓÃÒ×Êܹ¥»÷µÄÔ¶³Ì×ÀÃæ¿Í»§¶ËÅþÁ¬µ½¹¥»÷ЧÀÍÆ÷ʱ£¬£¬£¬£¬£¬£¬¿ØÖÆÔ¶³Ì×ÀÃæÐ§ÀÍÆ÷µÄÍþвÕß¿ÉÒÔÔÚ RDP ¿Í»§¶ËÅÌËã»úÉÏ´¥·¢Ô¶³Ì´úÂëÖ´ÐÐ (RCE)¡£¡£¡£¡£¡£

CVE-2023-28310£ºMicrosoft Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.0£¬£¬£¬£¬£¬£¬Óë Exchange Server´¦ÓÚͳһÄÚÍøµÄ¾­ÓÉÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔͨ¹ý PowerShell Ô¶³Ì»á»°ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£

±ðµÄ£¬£¬£¬£¬£¬£¬Î¢Èí»¹Ðû²¼ÁË´ó×Ú Microsoft Office ¸üУ¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´Excel ¡¢OneNote ºÍOutlookµÈ¶à¸ö²úÆ·ÖеÄÎó²î£¬£¬£¬£¬£¬£¬Ê¹ÓÃÕâЩÎó²îÐèÒªÓû§½»»¥£¬£¬£¬£¬£¬£¬²¿·ÖÎó²îÈçÏ£º

CVE-2023-33133£ºMicrosoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î

CVE-2023-33137£ºMicrosoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î

CVE-2023-33140£ºMicrosoft OneNote ÓÕÆ­Îó²î

CVE-2023-33131£ºMicrosoft Outlook Ô¶³Ì´úÂëÖ´ÐÐÎó²î

΢Èí6Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE-ID

ÎÊÌâ

ÑÏÖØÐÔ

CVE-2023-24897

.NET¡¢.NET Framework ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-29357

Microsoft   SharePoint Server ÌØÈ¨ÌáÉýÎó²î

ÑÏÖØ

CVE-2023-32013

Windows   Hyper-V ¾Ü¾øÐ§ÀÍÎó²î

ÑÏÖØ

CVE-2023-29363

Windows   Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-32014

Windows   Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-32015

Windows   Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-24895

.NET¡¢.NET Framework ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-33126

.NET ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-33135

.NET ºÍ Visual Studio ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-32032

.NET ºÍ Visual Studio ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-32030

.NET ºÍ Visual Studio ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-33128

.NET ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-29331

.NET¡¢.NET Framework ºÍ Visual Studio ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-29326

.NET   Framework Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-33141

Yet   Another Reverse Proxy (YARP) ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-21569

Azure   DevOps ЧÀÍÆ÷ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-21565

Azure   DevOps ЧÀÍÆ÷ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-24896

Dynamics   365 Finance ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-33145

Microsoft   Edge£¨»ùÓÚChromium£©ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-32031

Microsoft   Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-28310

Microsoft   Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-33146

Microsoft   Office Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-33133

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-32029

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-33137

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-33140

Microsoft   OneNote ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-33131

Microsoft   Outlook Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-33142

Microsoft   SharePoint Server ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-33129

Microsoft   SharePoint ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-33130

Microsoft   SharePoint Server ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-33132

Microsoft   SharePoint Server ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-32024

Microsoft   Power Apps ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-32017

Microsoft   PostScript ´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-29372

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-29370

Windows   Media Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-29365

Windows   Media Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-29337

NuGet   ClientÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-29362

Remote   Desktop Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-29352

Windows Ô¶³Ì×ÀÃæÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2023-32020

Windows   DNS ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-29007

GitHub£ºCVE-2023-29007 ͨ¹ý `git submodule deinit` ¾ÙÐÐí§ÒâÉèÖÃ×¢Èë

¸ßΣ

CVE-2023-33139

Visual   Studio ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-25652

GitHub£ºCVE-2023-25652¡°git apply --reject¡±²¿·Ö¿ØÖÆí§ÒâÎļþдÈë

¸ßΣ

CVE-2023-25815

GitHub£ºCVE-2023-25815 Git ÔÚ·ÇÌØÈ¨Î»ÖòéÕÒÍâµØ»¯ÐÂÎÅ

¸ßΣ

CVE-2023-27911

AutoDesk£ºAutodesk? FBX? SDK 2020 »ò¸üÔç°æ±¾ÖÐµÄ   CVE-2023-27911 ¶Ñ»º³åÇøÒç³öÎó²î

¸ßΣ

CVE-2023-27910

AutoDesk£ºAutodesk? FBX? SDK 2020 »ò¸üÔç°æ±¾ÖÐµÄ   CVE-2023-27910 ¿ÍÕ»»º³åÇøÒç³öÎó²î

¸ßΣ

CVE-2023-29011

GitHub:   CVE-2023-29011 `connect.exe` µÄÉèÖÃÎļþÈÝÒ×±»¶ñÒâ°²ÅÅ

¸ßΣ

CVE-2023-29012

GitHub:CVE-2023-29012   Git CMD¹ýʧµØÔÚÄ¿½ñĿ¼ÖÐÖ´ÐС°doskey.exe¡±£¨ÈôÊDZ£´æ£©

¸ßΣ

CVE-2023-27909

AutoDesk£ºAutodesk? FBX? SDK 2020 »ò¸üÔç°æ±¾ÖÐµÄ   CVE-2023-27909 Ô½½çдÈëÎó²î

¸ßΣ

CVE-2023-33144

Visual   Studio CodeÓÕÆ­Îó²î

¸ßΣ

CVE-2023-29364

Windows Éí·ÝÑéÖ¤ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-32010

Windows   Bus Filter Driver ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-29361

Windows   Cloud Files Mini Filter Driver ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-32009

Windows   Collaborative Translation Framework ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-32012

Windows   Container Manager Service ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-24937

Windows   CryptoAPI ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-24938

Windows   CryptoAPI ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-29355

DHCP   Server Service ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-29368

Windows   Filtering Platform ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-29358

Windows   GDI ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-29366

Windows   Geolocation Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-29351

Windows ×éÕ½ÂÔÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-32018

Windows   Hello Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-32016

Windows   Installer ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-32011

Windows   iSCSI ·¢Ã÷ЧÀ;ܾøÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-32019

Windows ÄÚºËÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-29346

NTFS ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-29373

Microsoft   ODBC Çý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-29367

iSCSI   Target WMI Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-29369

Remote   Procedure Call Runtime ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-32008

Windows   Resilient File System (ReFS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-32022

Windows   Server ЧÀÍÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2023-32021

Windows   SMB Witness ЧÀÍÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2023-29360

Windows   TPM ×°±¸Çý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-29371

Windows   GDI ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-29359

GDI ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-24936

.NET¡¢.NET Framework ºÍ Visual Studio ÌØÈ¨ÌáÉýÎó²î

ÖÐΣ

CVE-2023-33143

Microsoft   Edge£¨»ùÓÚ Chromium£©ÌØÈ¨ÌáÉýÎó²î

ÖÐΣ

CVE-2023-29345

Microsoft   Edge£¨»ùÓÚ Chromium£©Çå¾²¹¦Ð§ÈƹýÎó²î

µÍΣ

CVE-2023-29353

Sysinternals   Process Monitor for Windows ¾Ü¾øÐ§ÀÍÎó²î

µÍΣ

CVE-2023-2941

Chromium£ºCVE-2023-2941 ÔÚÀ©Õ¹ API ÖÐʵÑé²»µ±

δ֪

CVE-2023-2937

Chromium£ºCVE-2023-2937 »­Öл­ÊµÑé²»µ±

δ֪

CVE-2023-2936

Chromium£ºV8 ÖÐµÄ CVE-2023-2936 ÀàÐÍ»ìÏý

δ֪

CVE-2023-2935

Chromium£ºV8 ÖÐµÄ CVE-2023-2935 ÀàÐÍ»ìÏý

δ֪

CVE-2023-2940

Chromium£ºCVE-2023-2940 ÏÂÔØÖеÄʵÑé²»µ±

δ֪

CVE-2023-2939

Chromium£ºCVE-2023-2939 ×°ÖóÌÐòÖеÄÊý¾ÝÑé֤ȱ·¦

δ֪

CVE-2023-2938

Chromium£ºCVE-2023-2938 »­Öл­ÊµÑé²»µ±

δ֪

CVE-2023-2931

Chromium£ºCVE-2023-2931 ÔÚ PDF ÖÐÊͷźóʹÓÃ

δ֪

CVE-2023-2930

Chromium£ºCVE-2023-2930 ÔÚÀ©Õ¹ÖÐÊͷźóʹÓÃ

δ֪

CVE-2023-2929

Chromium£ºCVE-2023-2929 ÔÚ Swiftshader ÖÐÔ½½çдÈë

δ֪

CVE-2023-2934

Chromium£ºCVE-2023-2934 Mojo ÖеÄÔ½½çÄÚ´æ»á¼û

δ֪

CVE-2023-2933

Chromium£ºCVE-2023-2933 ÔÚ PDF ÖÐÊͷźóʹÓÃ

δ֪

CVE-2023-2932

Chromium£ºCVE-2023-2932 ÔÚ PDF ÖÐÊͷźóʹÓÃ

δ֪

CVE-2023-3079

Chromium£ºV8 ÖÐµÄ CVE-2023-3079 ÀàÐÍ»ìÏý

δ֪

 

¶þ¡¢Ó°Ïì¹æÄ£

ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/ЧÀÍ/×é¼þ°üÀ¨£º

Azure DevOps

.NET and Visual Studio

Microsoft Dynamics

Windows CryptoAPI

Microsoft Exchange Server

.NET Framework

.NET Core

NuGet Client

Microsoft Edge (Chromium-based)

Windows NTFS

Windows Group Policy

Remote Desktop Client

SysInternals

Windows DHCP Server

Microsoft Office SharePoint

Windows GDI

Windows Win32K

Windows TPM Device Driver

Windows Cloud Files Mini Filter Driver

Windows PGM

Windows Authentication Methods

Microsoft Windows Codecs Library

Windows Geolocation Service

Windows OLE

Windows Filtering

Windows Remote Procedure Call Runtime

Microsoft WDAC OLE DB provider for SQL

Windows ODBC Driver

Windows Resilient File System (ReFS)

Windows Collaborative Translation Framework

Windows Bus Filter Driver

Windows iSCSI

Windows Container Manager Service

Windows Hyper-V

Windows Installer

Microsoft Printer Drivers

Windows Hello

Windows Kernel

Role: DNS Server

Windows SMB

Windows Server Service

Microsoft Power Apps

Microsoft Office Excel

Microsoft Office Outlook

Visual Studio

Microsoft Office OneNote

ASP .NET

Visual Studio Code

Microsoft Office

 

Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϰ취ÊÖ¶¯¾ÙÐиüУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£

4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£

2023Äê6ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2023-Jun

²¹¶¡ÏÂÔØÊ¾Àý£º

1.·­¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬£¬£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£¡£¡£¡£¡£

image.png

Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2022Äê2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·­¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Çå¾²¸üС¿£¬£¬£¬£¬£¬£¬·­¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬£¬£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öᣡ£¡£¡£¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£¡£¡£¡£¡£

 

3.2 ÔÝʱ²½·¥

ÔÝÎÞ¡£¡£¡£¡£¡£

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2023-Jun

https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2023-patch-tuesday-fixes-78-flaws-38-rce-bugs/

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-06-14

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼

5.1 ¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£

5.2 ¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png