¡¾Îó²îͨ¸æ¡¿Î¢Èí2Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2024-02-19Ò»¡¢Îó²î¸ÅÊö
2024Äê2ÔÂ13ÈÕ£¬£¬£¬Î¢ÈíÐû²¼ÁË2ÔÂÇå¾²¸üУ¬£¬£¬±¾´Î¸üй²ÐÞ¸´ÁË73¸öÎó²î£¨²»°üÀ¨2ÔÂ8ÈÕÐÞ¸´µÄMicrosoft EdgeºÍÆäËüÎó²î£©£¬£¬£¬Îó²îÀàÐͰüÀ¨ÌØÈ¨ÌáÉýÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾øÐ§ÀÍÎó²îºÍÓÕÆÎó²îµÈ¡£¡£¡£¡£¡£
±¾´ÎÇå¾²¸üÐÂÖаüÀ¨2¸ö±»Æð¾¢Ê¹ÓõÄ0 dayÎó²î£º
CVE-2024-21351£ºWindows SmartScreen Çå¾²¹¦Ð§ÈƹýÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.6£¬£¬£¬ÍþвÕß¿ÉÏòÓû§·¢ËͶñÒâÎļþ²¢ÓÕµ¼Óû§·¿ªÎļþÀ´Ê¹ÓøÃÎó²î£¬£¬£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÈÆ¹ý SmartScreenÇå¾²¹¦Ð§¡£¡£¡£¡£¡£¸ÃÎó²îÔÊÐíÍþвÕß½«´úÂë×¢Èë SmartScreen ²¢¿ÉÄÜ»ñµÃ´úÂëÖ´ÐÐȨÏÞ£¬£¬£¬´Ó¶ø¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢ÏµÍ³¿ÉÓÃÐÔÓ°Ï죬£¬£¬ÏÖÔÚ¸ÃÎó²îÒѼì²âµ½Îó²îʹÓᣡ£¡£¡£¡£
CVE-2024-21412£ºInternet ¿ì½Ý·½·¨ÎļþÇå¾²¹¦Ð§ÈƹýÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.1£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔÏòÄ¿µÄÓû§·¢ËÍÖ¼ÔÚÈÆ¹ýÏÔʾµÄÇå¾²¼ì²éµÄÌØÖÆÎļþ²¢ÓÕµ¼Óû§·¿ª¸ÃÎļþ£¬£¬£¬µ¼ÖÂÇå¾²¹¦Ð§Èƹý¡£¡£¡£¡£¡£ÒÑ·¢Ã÷APT×éÖ¯Water Hydra£¨ÓÖÃû DarkCasino£©ÔÚÕë¶Ô½ðÈÚÉúÒâÕߵĻÖÐÆð¾¢Ê¹ÓøÃÎó²î¡£¡£¡£¡£¡£
±¾´ÎÇå¾²¸üÐÂÖУ¬£¬£¬ÆÀ¼¶Îª¡°ÑÏÖØ¡±µÄ5¸öÎó²î°üÀ¨£º
CVE-2024-21380£ºMicrosoft Dynamics Business Central/NAV ÐÅϢй¶Îó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.0£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²îÐèÒª¾ÓÉÉí·ÝÑéÖ¤¡¢Ó®µÃ¾ºÕùÌõ¼þ£¬£¬£¬²¢ÐèÒªÓû§½»»¥£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕß¿ÉÒÔ»á¼ûÓû§Êý¾Ý£¬£¬£¬µ¼ÖÂδÊÚȨ»á¼ûÊܺ¦ÕßµÄÕË»§»òй¶ÆäËüÉñÃØÐÅÏ¢¡£¡£¡£¡£¡£
CVE-2024-21410£ºMicrosoft Exchange Server ȨÏÞÌáÉýÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕß¿ÉÒÔ½«Óû§Ð¹Â¶µÄNet-NTLMv2¹þÏ£Öм̵½Ò×Êܹ¥»÷µÄExchange Server£¬£¬£¬²¢ÒÔÓû§Éí·Ý¾ÙÐÐÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£ÊÜÓ°ÏìÓû§Ò²¿É²Î¿¼¹Ù·½ÌṩµÄÎĵµºÍ¾ç±¾Îª Exchange ServerÆôÓÃÉí·ÝÑéÖ¤À©Õ¹±£»£»£»£»£»¤ (EPA)À´»º½â¸ÃÎó²î£¬£¬£¬ÏÖÔÚ¸ÃÎó²îÒѼì²âµ½Îó²îʹÓᣡ£¡£¡£¡£
CVE-2024-21413£ºMicrosoft OutlookÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÈÆ¹ý Office Êܱ£»£»£»£»£»¤µÄÊÓͼ²¢ÒÔ±à¼Ä£Ê½¶ø²»ÊDZ£»£»£»£»£»¤Ä£Ê½·¿ª£¬£¬£¬Ô¤ÀÀ´°¸ñÊǸÃÎó²îµÄÒ»¸ö¹¥»÷ǰÑÔ¡£¡£¡£¡£¡£ÍþвÕß¿ÉÒÔ½¨ÉèÈÆ¹ýÊܱ£»£»£»£»£»¤ÊÓͼÐÒéµÄ¶ñÒâÁ´½Ó£¬£¬£¬´Ó¶øµ¼ÖÂÍâµØNTLMƾ֤ÐÅϢй¶ºÍÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£
CVE-2024-20684£ºWindows Hyper-V ¾Ü¾øÐ§ÀÍÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ6.5£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼Ö Hyper-V guestÓ°Ïì Hyper-V Ö÷»úµÄ¹¦Ð§¡£¡£¡£¡£¡£
CVE-2024-21357£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î
Windows Pragmatic General Multicast (PGM) ±¬·¢µÄ×é²¥Á÷Á¿ÔÚµÚ4 ²ãÔËÐв¢¿É·ÓÉ£¬£¬£¬ÍþвÕß¿ÉÒÔͨ¹ýÏòÒ×Êܹ¥»÷µÄЧÀÍÆ÷·¢ËÍÌØÖÆµÄ¶ñÒâÁ÷Á¿À´Ê¹ÓøÃÎó²î¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.1£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐԽϸߡ±¡£¡£¡£¡£¡£
³ýCVE-2024-21410ºÍCVE-2024-21357ÒÔÍ⣬£¬£¬±¾´ÎÇå¾²¸üÐÂÖУ¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀÖС°±»Ê¹ÓõĿÉÄÜÐԽϸߡ±µÄÎó²î»¹°üÀ¨£º
CVE-2024-21338£ºWindows ÄÚºËÌØÈ¨ÌáÉýÎó²î
CVE-2024-21345£ºWindows ÄÚºËÌØÈ¨ÌáÉýÎó²î
CVE-2024-21346£ºWin32k ÌØÈ¨ÌáÉýÎó²î
CVE-2024-21371£ºWindows ÄÚºËÌØÈ¨ÌáÉýÎó²î
CVE-2024-21378£ºMicrosoft OutlookÔ¶³Ì´úÂëÖ´ÐÐÎó²î
CVE-2024-21379£ºMicrosoft WordÔ¶³Ì´úÂëÖ´ÐÐÎó²î
΢Èí2Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º
CVE ID | CVE ÎÊÌâ | ÑÏÖØÐÔ |
CVE-2024-21380 | Microsoft Dynamics Business Central/NAV ÐÅϢй¶Îó²î | ÑÏÖØ |
CVE-2024-21410 | Microsoft Exchange Server ȨÏÞÌáÉýÎó²î | ÑÏÖØ |
CVE-2024-21413 | Microsoft Outlook Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2024-20684 | Windows Hyper-V ¾Ü¾øÐ§ÀÍÎó²î | ÑÏÖØ |
CVE-2024-21357 | Windows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2024-21386 | .NET ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2024-21404 | .NET ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2024-21401 | Microsoft Entra Jira Single-Sign-On Plugin ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21381 | Microsoft Azure Active Directory B2C ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-21329 | Azure Connected Machine Agent ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-20667 | Azure DevOps Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21397 | Microsoft Azure File SyncȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-20679 | Azure Stack Hub ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-21412 | Internet ¿ì½Ý·½·¨ÎļþÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2024-21349 | Microsoft ActiveX Êý¾Ý¹¤¾ßÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21403 | Microsoft Azure Kubernetes Service Confidential Container ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21376 | Microsoft Azure Kubernetes Service Confidential Container Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21315 | Microsoft Defender for Endpoint Protection ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21393 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2024-21389 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2024-21395 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2024-21328 | Dynamics 365 Sales ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-21394 | Dynamics 365 Field Service ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-21396 | Dynamics 365 Sales ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-21327 | Microsoft Dynamics 365 Customer Engagement ¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2024-20673 | Microsoft Office Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21384 | Microsoft Office OneNote Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21378 | Microsoft Outlook Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21402 | Microsoft Outlook ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21379 | Microsoft Word Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21374 | Microsoft Teams for Android ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-21353 | Microsoft WDAC ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21370 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21350 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21368 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21359 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21365 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21367 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21420 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21366 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21369 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21375 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21361 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21358 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21391 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21360 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21352 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21406 | Windows Printing Service ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-21377 | Windows DNS ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-50387 | MITRE£ºCVE-2023-50387 DNSSEC ÑéÖ¤ÖØ´óÐԿɱ»Ê¹ÓÃÀ´ºÄ¾¡ CPU ×ÊÔ´²¢×èÖ¹ DNS ÆÊÎöÆ÷ | ¸ßΣ |
CVE-2024-21342 | Windows DNS Client ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2024-20695 | Skype for Business ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-21347 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21304 | Trusted Compute Base ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21343 | Windows Network Address Translation (NAT) ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2024-21348 | Internet Connection Sharing (ICS) ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2024-21344 | Windows Network Address Translation (NAT) ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2024-21371 | Windows Kernel ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21338 | Windows Kernel ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21341 | Windows Kernel Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21345 | Windows Kernel ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21362 | Windows Kernel Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2024-21340 | Windows Kernel ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-21356 | Windows Lightweight Directory Access Protocol (LDAP) ¾Ü¾øÐ§ÀÍÎó²î | ¸ßΣ |
CVE-2024-21363 | Microsoft Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21355 | Microsoft Message Queuing (MSMQ) ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21405 | Microsoft Message Queuing (MSMQ) ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21354 | Microsoft Message Queuing (MSMQ) ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21372 | Windows OLE Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21339 | Windows USB Generic Parent Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21346 | Win32k ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21364 | Microsoft Azure Site RecoveryÌØÈ¨ÌáÉýÎó²î | ÖÐΣ |
CVE-2024-21399 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÖÐΣ |
CVE-2024-21351 | Windows SmartScreen Çå¾²¹¦Ð§ÈƹýÎó²î | ÖÐΣ |
CVE-2024-21626 | runc ÎļþÐÎò·û×ß© | δ֪ |
CVE-2024-1284 | Chromium£ºCVE-2024-1284 ÔÚ Mojo ÖÐÊͷźóʹÓà | δ֪ |
CVE-2024-1060 | Chromium£ºCVE-2024-1060 ÔÚ Canvas ÖÐÊͷźóʹÓà | δ֪ |
CVE-2024-1077 | Chromium£ºCVE-2024-1077 ÔÚ Network ÖÐÊͷźóʹÓà | δ֪ |
CVE-2024-1283 | Chromium£ºCVE-2024-1283 Skia ÖеĶѻº³åÇøÒç³ö | δ֪ |
CVE-2024-1059 | Chromium£ºCVE-2024-1059 ÔÚ WebRTC ÖÐÊͷźóʹÓà | δ֪ |
¶þ¡¢Ó°Ïì¹æÄ£
ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/ЧÀÍ/×é¼þ°üÀ¨£º
Azure DevOps
Microsoft Office
Azure Stack
Windows Hyper-V
Skype for Business
Trusted Compute Base
Microsoft Defender for Endpoint
Microsoft Dynamics
Azure Connected Machine Agent
Windows Kernel
Windows USB Serial Driver
Role: DNS Server
Windows Internet Connection Sharing (ICS)
Windows Win32K - ICOMP
SQL Server
Microsoft ActiveX
Microsoft WDAC OLE DB provider for SQL
Windows SmartScreen
Microsoft WDAC ODBC Driver
Windows Message Queuing
Windows LDAP - Lightweight Directory Access Protocol
Azure Site Recovery
Windows OLE
Microsoft Teams for Android
Microsoft Azure Kubernetes Service
Microsoft Windows DNS
Microsoft Office Outlook
Microsoft Office Word
Azure Active Directory
Microsoft Office OneNote
.NET
Azure File Sync
Microsoft Edge (Chromium-based)
Microsoft Windows
Microsoft Exchange Server
Internet Shortcut Files
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬣¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϰ취ÊÖ¶¯¾ÙÐиüУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£
4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£
2024Äê2ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2024-Feb
²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º
1.·¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£¡£¡£¡£¡£
Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2022Äê2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾Çå¾²¸üС¿£¬£¬£¬·¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öᣡ£¡£¡£¡£
Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£¡£¡£¡£¡£
3.2 ÔÝʱ²½·¥
Õë¶ÔCVE-2024-21410£¬£¬£¬ÔÚ Exchange Server 2019 ÀÛ»ý¸üÐÂ14 (CU14) ¸üÐÂ֮ǰ£¬£¬£¬Exchange Server ĬÈÏÇéÐÎϲ»ÆôÓà NTLM ƾ֤Öм̱£»£»£»£»£»¤£¨³ÆÎªÉí·ÝÑéÖ¤À©Õ¹±£»£»£»£»£»¤»ò EPA£©£¬£¬£¬Exchange Server 2019 CU14 ĬÈÏÔÚ Exchange ServerÉÏÆôÓà EPA£¬£¬£¬Microsoft ½¨ÒéÔÚ Exchange Server 2019 ÉÏ×°Öà CU14 £¬£¬£¬»ò²ÎÔÄExchange À©Õ¹±£»£»£»£»£»¤Îĵµ²¢Ê¹ÓÃExchangeExtendedProtectionManagement.ps1¾ç±¾Îª Exchange ServerÆôÓÃÉí·ÝÑéÖ¤À©Õ¹±£»£»£»£»£»¤ (EPA)À´»º½â¸ÃÎó²î¡£¡£¡£¡£¡£
¸ü¶àÎó²îÏêÇé¼°»º½â²½·¥¿É²Î¿¼¹Ù·½Í¨¸æ£º
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-21410
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Feb
https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2024-patch-tuesday-fixes-2-zero-days-73-flaws/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-02-19 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¼øºÚµ£±£Íø¼ò½é
¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£
5.2 ¹ØÓÚ¼øºÚµ£±£Íø
¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£
¹Ø×¢ÎÒÃÇ£º