¡¾Îó²îͨ¸æ¡¿Î¢Èí3Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2025-03-12

Ò»¡¢Îó²î¸ÅÊö


2025Äê3ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË3ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬£¬±¾´Î¸üÐÂÐÞ¸´ÁË57¸öÎó²î£¬£¬£¬£¬£¬£¬º­¸ÇȨÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐС¢ÓÕÆ­µÈ¶àÖÖÎó²îÀàÐÍ¡£¡£¡£¡£Îó²î¼¶±ðÂþÑÜÈçÏ£º6¸öÑÏÖØ¼¶±ðÎó²î£¬£¬£¬£¬£¬£¬50¸öÖ÷Òª¼¶±ðÎó²î£¬£¬£¬£¬£¬£¬1¸öµÍΣ¼¶±ðÎó²î£¨Îó²î¼¶±ðÒÀ¾Ý΢Èí¹Ù·½Êý¾Ý£©¡£¡£¡£¡£


ÆäÖУ¬£¬£¬£¬£¬£¬16¸öÎó²î±»Î¢Èí±ê¼ÇΪ¡°¸ü¿ÉÄܱ»Ê¹Óá±¼°¡°¼ì²âʹÓÃÇéÐΡ±£¬£¬£¬£¬£¬£¬Åú×¢ÕâЩÎó²î±£´æ½Ï¸ßµÄʹÓÃΣº¦£¬£¬£¬£¬£¬£¬½¨ÒéÓÅÏÈÐÞ¸´ÒÔ½µµÍDZÔÚÇå¾²Íþв¡£¡£¡£¡£


CVE-ID

CVE ÎÊÌâ

Îó²î¼¶±ð

CVE-2025-24983

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24984

Windows NTFS ÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-24985

Windows FAST FAT ÎļþϵͳÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Ö÷Òª

CVE-2025-24991

Windows NTFS ÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-24993

Windows NTFS Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-26633

Microsoft ÖÎÀí¿ØÖÆÌ¨Çå¾²¹¦Ð§ÈƹýÎó²î

Ö÷Òª

CVE-2025-21180

Windows exFAT ÎļþϵͳԶ³Ì´úÂëÖ´ÐÐÎó²î

Ö÷Òª

CVE-2025-21247

MapUrlToZone Çå¾²¹¦Ð§ÈƹýÎó²î

Ö÷Òª

CVE-2025-24035

Windows Ô¶³Ì×ÀÃæÐ§ÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2025-24044

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24045

Windows Ô¶³Ì×ÀÃæÐ§ÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2025-24061

Windows Web ÅÌÎʱê¼ÇÇå¾²¹¦Ð§ÈƹýÎó²î

Ö÷Òª

CVE-2025-24066

ÄÚºËÁ÷ʽ´¦Öóͷ£Ð§ÀÍÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24067

ÄÚºËÁ÷ʽ´¦Öóͷ£Ð§ÀÍÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24992

Windows NTFS ÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-24995

Kernel Streaming WOW Thunk ЧÀÍÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª


΢Èí3Ô¸üÐÂÐÞ¸´µÄÍêÕûÎó²îÁбíÈçÏ£º


CVE-ID

CVE ÎÊÌâ

Îó²î¼¶±ð

CVE-2025-21180

Windows exFAT ÎļþϵͳԶ³Ì´úÂëÖ´ÐÐÎó²î

Ö÷Òª

CVE-2025-21199

Azure ±¸·ÝºÍÕ¾µã»Ö¸´ÊðÀí×°ÖóÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-21247

MapUrlToZone Çå¾²¹¦Ð§ÈƹýÎó²î

Ö÷Òª

CVE-2025-24035

Windows Ô¶³Ì×ÀÃæÐ§ÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2025-24043

WinDbg Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Ö÷Òª

CVE-2025-24044

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24045

Windows Ô¶³Ì×ÀÃæÐ§ÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2025-24046

ÄÚºËÁ÷ʽ´¦Öóͷ£Ð§ÀÍÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24048

Windows Hyper-V ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24049

Azure ÏÂÁîÐм¯³É (CLI) ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24050

Windows Hyper-V ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24051

Windows ·ÓɺÍÔ¶³Ì»á¼ûЧÀÍ (RRAS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Ö÷Òª

CVE-2025-24054

NTLM ¹þϣй¶ÓÕÆ­Îó²î

Ö÷Òª

CVE-2025-24055

Windows USB ÊÓÆµÀàϵͳÇý¶¯³ÌÐòÐÅÏ¢Åû¶Îó²î

Ö÷Òª

CVE-2025-24056

Windows µç»°Ð§ÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Ö÷Òª

CVE-2025-24057

Microsoft Office Ô¶³ÌÖ´ÐдúÂëÎó²î

ÑÏÖØ

CVE-2025-24059

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌáÉýȨÏÞÎó²î

Ö÷Òª

CVE-2025-24061

Windows Web ÅÌÎʱê¼ÇÇå¾²¹¦Ð§ÈƹýÎó²î

Ö÷Òª

CVE-2025-24064

Windows ÓòÃûЧÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2025-24066

ÄÚºËÁ÷ʽ´¦Öóͷ£Ð§ÀÍÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24067

ÄÚºËÁ÷ʽ´¦Öóͷ£Ð§ÀÍÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24070

ASP.NET Core ºÍ Visual Studio

Ö÷Òª

CVE-2025-24071

Microsoft Windows Îļþ×ÊÔ´ÖÎÀíÆ÷ÓÕÆ­Îó²î

Ö÷Òª

CVE-2025-24072

Microsoft ÍâµØÇå¾²»ú¹¹ (LSA) ЧÀÍÆ÷ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24075

Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-24076

Microsoft Windows ¿ç×°±¸Ð§ÀÍÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24077

Microsoft Word Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-24078

Microsoft Word Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-24079

Microsoft Word Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-24080

Microsoft Office Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-24081

Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-24082

Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-24083

Microsoft Office Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-24084

ÊÊÓÃÓÚ Linux µÄ Windows ×Óϵͳ (WSL2) ÄÚºËÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2025-24983

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24984

Windows NTFS ÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-24985

Windows FAST FAT ÎļþϵͳÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Ö÷Òª

CVE-2025-24986

Azure Promptflow Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Ö÷Òª

CVE-2025-24987

Windows USB ÊÓÆµÀàϵͳÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24988

Windows USB ÊÓÆµÀàϵͳÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24991

Windows NTFS ÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-24992

Windows NTFS ÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-24993

Windows NTFS Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-24994

Microsoft Windows ¿ç×°±¸Ð§ÀÍÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24995

Kernel Streaming WOW Thunk ЧÀÍÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-24996

NTLM ¹þϣй¶ÓÕÆ­Îó²î

Ö÷Òª

CVE-2025-24997

DirectX ͼÐÎÄÚºËÎļþ¾Ü¾øÐ§ÀÍÎó²î

Ö÷Òª

CVE-2025-24998

Visual Studio ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-25003

Visual Studio ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-25008

Windows Server Elevation of Privilege Vulnerability

Ö÷Òª

CVE-2025-26627

Azure Arc ×°ÖóÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-26629

Microsoft Office Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-26630

Microsoft Access Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-26631

Visual Studio Code ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-26633

Microsoft ÖÎÀí¿ØÖÆÌ¨Çå¾²¹¦Ð§ÈƹýÎó²î

Ö÷Òª

CVE-2025-26643

»ùÓÚ Chromium µÄ Microsoft Edge ÓÕÆ­Îó²î

µÍ

CVE-2025-26645

Ô¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³ÌÖ´ÐдúÂëÎó²î

ÑÏÖØ


¶þ¡¢Ó°Ïì¹æÄ£


ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/ЧÀÍ/×é¼þ°üÀ¨£º

Windows exFAT File System

Azure Agent Installer

Windows MapUrlToZone

Windows Remote Desktop Services

.NET

Windows Win32 Kernel Subsystem

Microsoft Streaming Service

Role: Windows Hyper-V

Azure CLI

Windows Routing and Remote Access Service (RRAS)

Windows NTLM

Windows USB Video Driver

Windows Telephony Server

Microsoft Office

Windows Common Log File System Driver

Windows Mark of the Web (MOTW)

Role: DNS Server

Windows Kernel-Mode Drivers

ASP.NET Core & Visual Studio

Windows File Explorer

Microsoft Local Security Authority Server (lsasrv)

Microsoft Office Excel

Windows Cross Device Service

Microsoft Office Word

Windows Subsystem for Linux

Windows NTFS

Windows Fast FAT Driver

Azure PromptFlow

Kernel Streaming WOW Thunk Service Driver

Windows Kernel Memory

Visual Studio

Microsoft Windows

Azure Arc

Microsoft Office Access

Visual Studio Code

Microsoft Management Console

Microsoft Edge (Chromium-based)

Remote Desktop Client


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£


£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ


Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϰ취ÊÖ¶¯¾ÙÐиüУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£
4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£


£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ


Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£
2025Äê3ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2025-Mar
²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º
1.·­¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬£¬£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£¡£¡£¡£

 

ͼƬ1.png

Àý1£ºÎ¢ÈíÎó²îÁÐ±í£¨Ê¾Àý£©


2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿ÁÐÑ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áз­¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£

 

ͼƬ2.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý


3.µã»÷¡¾Çå¾²¸üС¿£¬£¬£¬£¬£¬£¬·­¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬£¬£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öᣡ£¡£¡£

 

ͼƬ3.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ


4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£¡£¡£¡£


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£

ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://msrc.microsoft.com/update-guide/releaseNote/2025-Mar