¡¾Îó²îͨ¸æ¡¿Î¢Èí8Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2023-08-09

Ò»¡¢Îó²î¸ÅÊö

2023Äê8ÔÂ8ÈÕ£¬£¬£¬£¬£¬Î¢ÈíÐû²¼ÁË8ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬±¾´Î¸üй²ÐÞ¸´ÁË87¸öÎó²î£¬£¬£¬£¬£¬ÆäÖаüÀ¨2¸öÒѱ»Ê¹ÓõÄÎó²î¡¢23¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²îÒÔ¼°6¸öÆÀ¼¶ÎªÑÏÖØµÄÎó²î¡£¡£¡£¡£¡£

±¾´ÎÐÞ¸´µÄÎó²îÖУ¬£¬£¬£¬£¬Îó²îÀàÐͰüÀ¨ÌØÈ¨ÌáÉýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾øÐ§ÀÍÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²îºÍÓÕÆ­Îó²îµÈ¡£¡£¡£¡£¡£

΢Èí±¾´Î¹²ÐÞ¸´ÁË2¸öÒѱ»Ê¹ÓõÄÎó²î£º

ADV230003£ºMicrosoft Office Éî¶È·ÀÓù¸üУ¨ÐÞ¸´CVE-2023-36884£©

Microsoft Ðû²¼ÁË Microsoft OfficeÉî¶È·ÀÓù¸üУ¬£¬£¬£¬£¬ÒÔÐÞ¸´ÏÈǰÒÑ»º½â²¢±»Æð¾¢Ê¹ÓõÄCVE-2023-36884Ô¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Á´¡£¡£¡£¡£¡£CVE-2023-36884Ó°ÏìÁ˶à¸öWindowsºÍOffice²úÆ·£¬£¬£¬£¬£¬ÍþвÕß¿ÉÒÔ½¨ÉèÌØÖÆµÄ Microsoft OfficeÎĵµ²¢ÓÕµ¼Êܺ¦Õß·­¿ª¶ñÒâÎļþ£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÔÚÊܺ¦ÕßµÄÉÏÏÂÎÄÖÐÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¸ÃÎó²îÒѾ­¹ûÕæÅû¶ÇÒÒÑ·¢Ã÷±»Ê¹Óᣡ£¡£¡£¡£

CVE-2023-38180 £º.NET ºÍ Visual Studio ¾Ü¾øÐ§ÀÍÎó²î

¸ÃÎó²îµÄCVSSv3.1ÆÀ·ÖΪ7.5£¬£¬£¬£¬£¬¿ÉʹÓøÃÎó²îµ¼ÖÂ.NET Ó¦ÓóÌÐòºÍ Visual Studio¾Ü¾øÐ§ÀÍ£¬£¬£¬£¬£¬ÏÖÔÚ¸ÃÎó²îÒÑ·¢Ã÷±»Ê¹Óᣡ£¡£¡£¡£

΢Èí±¾´Î¸üÐÂÖÐÐÞ¸´µÄ6¸öÆÀ¼¶Îª¡°ÑÏÖØ¡±µÄÎó²îÈçÏ£º

CVE-2023-36895£ºMicrosoft OutlookÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3.1ÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬ÍþвÕß¿Éͨ¹ýÓÕµ¼Êܺ¦ÕßÏÂÔØ²¢·­¿ªÌØÖÆÎļþ£¨ÐèÒªÓû§½»»¥£©£¬£¬£¬£¬£¬´Ó¶øµ¼Ö¶ÔÊܺ¦ÕßÅÌËã»úÖ´ÐÐÍâµØ¹¥»÷£¬£¬£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£

CVE-2023-29328/ CVE-2023-29330£ºMicrosoft TeamsÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSv3.1ÆÀ·ÖΪ8.8£¬£¬£¬£¬£¬Ó°ÏìÁËMicrosoft Teams ×ÀÃæ°æ¡¢Android °æ¡¢ iOS°æºÍMac °æ¡£¡£¡£¡£¡£ÍþвÕß¿ÉÒÔͨ¹ýÓÕÆ­Êܺ¦Õß¼ÓÈëÆäÉèÖõĶñÒâTeams ¾Û»á£¬£¬£¬£¬£¬µ¼ÖÂÔÚÊܺ¦ÕßÓû§µÄÉÏÏÂÎÄÖÐÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬´Ó¶øÄܹ»»á¼û»òÐÞ¸ÄÊܺ¦ÕßµÄÐÅÏ¢£¬£¬£¬£¬£¬»ò¿ÉÄܵ¼Ö¿ͻ§¶ËÅÌËã»úÍ£»£»£»ú£¬£¬£¬£¬£¬Ê¹ÓøÃÎó²îÎÞÐèÌØÈ¨¡£¡£¡£¡£¡£

CVE-2023-35385/CVE-2023-36911/CVE-2023-36910£ºMicrosoftÐÂÎÅÐÐÁÐÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÕâЩÎó²îµÄCVSSv3.1ÆÀ·Ö¾ùΪ9.8£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý·¢ËͶñÒâÖÆ×÷µÄMSMQ Êý¾Ý°üµ½MSMQ ЧÀÍÆ÷À´Ê¹ÓÃÎó²î£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÃÕâЩÎó²î¿ÉÄܵ¼ÖÂÔÚÄ¿µÄЧÀÍÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£Ê¹ÓÃÕâЩÎó²îÐèÒªÆôÓÃ×÷ΪWindows ×é¼þµÄWindows ÐÂÎÅÐÐÁÐЧÀÍ£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý¼ì²éÊÇ·ñÖøÃûΪMessage QueuingµÄЧÀÍÔÚÔËÐУ¬£¬£¬£¬£¬ÒÔ¼°ÅÌËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£¡£¡£¡£¡£

ÆäËüÖµµÃ¹Ø×¢µÄÎó²î»¹°üÀ¨µ«²»ÏÞÓÚ£º

CVE-2023-21709£ºMicrosoft Exchange Server ȨÏÞÌáÉýÎó²î

¸ÃÎó²îµÄCVSSv3.1ÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬ÔÚ»ùÓÚÍøÂçµÄ¹¥»÷ÖУ¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý±©Á¦ÆÆ½âÓû§ÕÊ»§ÃÜÂëÒÔ¸ÃÓû§Éí·ÝµÇ¼¡£¡£¡£¡£¡£½¨ÒéʹÓÃÇ¿ÃÜÂëÀ´»º½â±©Á¦ÆÆ½â¹¥»÷¡£¡£¡£¡£¡£

CVE-2023-35388 /CVE-2023-38182£ºMicrosoft Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÕâЩÎó²îµÄCVSSv3.1ÆÀ·Ö¾ùΪ8.0£¬£¬£¬£¬£¬Í¨¹ý LAN »á¼ûÉí·ÝÑéÖ¤²¢ÓµÓÐÓÐÓà Exchange Óû§Æ¾Ö¤µÄÍþвÕß¿ÉÒÔͨ¹ý PowerShell Ô¶³Ì´¦Öóͷ£»á»°Ô¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£

΢Èí8Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE ID

CVE ÎÊÌâ

ÑÏÖØÐÔ

CVE-2023-36895

Microsoft   Outlook Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-29328

Microsoft   Teams Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-29330

Microsoft   Teams Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-35385

Microsoft ÐÂÎÅÐÐÁÐÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-36911

Microsoft ÐÂÎÅÐÐÁÐÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-36910

Microsoft ÐÂÎÅÐÐÁÐÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-38178

.NET Core ºÍ Visual Studio ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-35390

.NETºÍVisual StudioÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-36873

.NET   Framework ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-38180

.NET ºÍ Visual Studio ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-36899

ASP.NET ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2023-35391

ASP.NET   Core SignalR ºÍ Visual Studio ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-38176

Azure   Arc-Enabled Servers ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-36869

Azure   DevOps Server ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-38188

Azure   Apache Hadoop ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-35393

Azure   Apache Hive ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-35394

Azure HDInsight   Jupyter Notebook ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-36881

Azure   Apache Ambari ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-36877

Azure   Apache Oozie ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-38167

Microsoft   Dynamics Business Central ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-35389

Microsoft   Dynamics 365 On-Premises Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-38185

Microsoft   Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-35388

Microsoft   Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-35368

Microsoft   Exchange Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-38181

Microsoft   Exchange Server ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-38182

Microsoft   Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-21709

Microsoft   Exchange Server ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2023-36897

Visual   Studio Tools for Office Runtime ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-36896

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-35371

Microsoft   Office Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-36893

Microsoft   Outlook ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-36891

Microsoft   SharePoint Server ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-36894

Microsoft   SharePoint Server ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-36890

Microsoft   SharePoint Server ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-36892

Microsoft   SharePoint Server ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-35372

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-36865

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-36866

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-36882

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-20569

AMD£ºCVE-2023-20569 ·µ»ØµØµãÕ¹ÍûÆ÷

¸ßΣ

CVE-2023-38170

HEVC Video   Extensions Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-36876

Reliability   Analysis Metrics Calculation (RacTask) ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2023-36908

Windows   Hyper-V ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-38169

Microsoft   OLE DB Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-36898

Tablet   Windows User Interface Application Core Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-35387

Windows   Bluetooth A2DP driver ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-36904

Windows   Cloud Files Mini Filter Driver ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-36900

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-36907

Windows ¼ÓÃÜЧÀÍÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-36906

Windows ¼ÓÃÜЧÀÍÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-38175

Microsoft   Windows Defender ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2023-35381

Windows ´«ÕæÐ§ÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-36889

Windows ×éÕ½ÂÔÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2023-35384

Windows   HTMLƽ̨Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2023-35359

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-38154

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-35382

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-35386

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-35380

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-38184

Windows ÇáÁ¿¼¶Ä¿Â¼»á¼ûЭÒé (LDAP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-36909

Microsoft ÐÂÎÅÐÐÁоܾøÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-35376

Microsoft ÐÂÎÅÐÐÁоܾøÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-38172

Microsoft ÐÂÎÅÐÐÁоܾøÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-35383

Microsoft ÐÂÎÅÐÐÁÐÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-36913

Microsoft ÐÂÎÅÐÐÁÐÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-35377

Microsoft ÐÂÎÅÐÐÁоܾøÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-38254

Microsoft ÐÂÎÅÐÐÁоܾøÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-36912

Microsoft ÐÂÎÅÐÐÁоܾøÐ§ÀÍÎó²î

¸ßΣ

CVE-2023-38186

Windows   Mobile ×°±¸ÖÎÀíȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2023-35378

Windows   Projected File System ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-35379

Reliability   Analysis Metrics Calculation Engine (RACEng) ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-36914

Windows   Smart Card Resource Management Server Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2023-36903

Windows System   Assessment Tool ÌØÈ¨ÌáÉýÎó²î

¸ßΣ

CVE-2023-36905

Windows ÎÞÏß¹ãÓòÍøÐ§ÀÍ (WwanSvc) ÐÅϢй¶Îó²î

¸ßΣ

ADV230004

ÄÚ´æÍêÕûÐÔϵͳͣµ±É¨Ã蹤¾ßÉî¶È·ÀÓù¸üÐÂ

ÖÐΣ

CVE-2023-38157

Microsoft   Edge£¨»ùÓÚ Chromium£©Çå¾²¹¦Ð§ÈƹýÎó²î

ÖÐΣ

ADV230003

Microsoft   Office Éî¶È·ÀÓù¸üÐÂ

ÖÐΣ

CVE-2023-35945

Envoy ¾Ü¾øÐ§ÀÍÎó²î

δ֪

CVE-2023-4068

Chromium£ºCVE-2023-4068 V8 ÖеÄÀàÐÍ»ìÏý

δ֪

CVE-2023-4072

Chromium£ºCVE-2023-4072 WebGL ÖеĶÁдԽ½ç

δ֪

CVE-2023-4071

Chromium£ºCVE-2023-4071 Visuals ÖеĶѻº³åÇøÒç³ö

δ֪

CVE-2023-4073

Chromium£ºCVE-2023-4073 ANGLE ÖеÄÄÚ´æ»á¼ûÔ½½ç

δ֪

CVE-2023-4075

Chromium£ºCVE-2023-4075 ÔÚ Cast ÖÐÊͷźóʹÓÃ

δ֪

CVE-2023-4074

Chromium£ºCVE-2023-4074 ÔÚ Blink ʹÃüµ÷ÀíÖÐÊͷźóʹÓÃ

δ֪

CVE-2023-4076

Chromium£ºCVE-2023-4076 ÔÚ WebRTC ÖÐÊͷźóʹÓÃ

δ֪

CVE-2023-4077

Chromium£ºCVE-2023-4077 À©Õ¹ÖеÄÊý¾ÝÑé֤ȱ·¦

δ֪

CVE-2023-4078

Chromium£ºCVE-2023-4078 À©Õ¹ÖеÄʵÑé²»µ±

δ֪

CVE-2023-4070

Chromium£ºCVE-2023-4070 V8 ÖеÄÀàÐÍ»ìÏý

δ֪

CVE-2023-4069

Chromium£ºCVE-2023-4069 V8 ÖеÄÀàÐÍ»ìÏý

δ֪

 

¶þ¡¢Ó°Ïì¹æÄ£

ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/ЧÀÍ/×é¼þ°üÀ¨£º

Microsoft Office

Memory Integrity System Readiness Scan Tool

Microsoft Exchange Server

Microsoft Teams

Windows Kernel

Microsoft Office Excel

Microsoft Office Visio

Windows Message Queuing

Windows Projected File System

Windows Reliability Analysis Metrics Calculation Engine

Windows Fax and Scan Service

Windows HTML Platform

Windows Bluetooth A2DP driver

Microsoft Dynamics

.NET Core

ASP.NET and Visual Studio

Azure HDInsights

Azure DevOps

.NET Framework

Reliability Analysis Metrics Calculation Engine

Microsoft WDAC OLE DB provider for SQL

Windows Group Policy

Microsoft Office SharePoint

Microsoft Office Outlook

Tablet Windows User Interface

ASP.NET

Windows Common Log File System Driver

Windows System Assessment Tool

Windows Cloud Files Mini Filter Driver

Windows Wireless Wide Area Network Service

Windows Cryptographic Services

Role: Windows Hyper-V

Windows Smart Card

Microsoft Edge (Chromium-based)

Dynamics Business Central Control

SQL Server

Microsoft Windows Codecs Library

Windows Defender

Azure Arc

ASP .NET

Windows LDAP - Lightweight Directory Access Protocol

Windows Mobile Device Management

 

Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϰ취ÊÖ¶¯¾ÙÐиüУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£

4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£

2023Äê8ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2023-Aug

²¹¶¡ÏÂÔØÊ¾Àý£º

1.·­¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£¡£¡£¡£¡£

image.png

Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2022Äê2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·­¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Çå¾²¸üС¿£¬£¬£¬£¬£¬·­¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öᣡ£¡£¡£¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£¡£¡£¡£¡£

 

3.2 ÔÝʱ²½·¥

Õë¶ÔCVE-2023-21709£¬£¬£¬£¬£¬¿É²Î¿¼£º

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21709

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2023-Aug

https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2023-patch-tuesday-warns-of-2-zero-days-87-flaws/

  

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-08-09

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼

5.1 ¼øºÚµ£±£Íø¼ò½é

¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£

5.2 ¹ØÓÚ¼øºÚµ£±£Íø

¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png