Outlook¸ßΣԶ³Ì´úÂëÖ´ÐÐÎó²î£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÌṩ½â¾ö¼Æ»®
Ðû²¼Ê±¼ä 2024-02-23Îó²îÏêÇé
¾ÓÉÑо¿È·ÈÏ£¬¸ÃÎó²îÈƹýÁËOutlookÖеÄÇå¾²ÏÞÖÆ£¬µ¼Ö¹¥»÷ÕßÖ»Ðè·¢ËÍÒ»¸ö´¹ÂÚÓʼþ£¬¼´¿ÉÔÚÊܺ¦ÕßÎÞÐèÈκν»»¥µÄÇéÐÎÏÂй¶ÆäNTLMÉí·Ýƾ֤ÐÅÏ¢¡£Í¨¹ý½øÒ»²½µÄÆƽâ»òÕßNTLM relay¹¥»÷£¬¼´¿ÉαÔìÊܺ¦ÕßÉí·Ý¾ÙÐÐÈÏÖ¤£¬´Ó¶ø»ñÈ¡¶ÔӦȨÏÞ¡£Í¬Ê±¸ÃÎó²îÔÚºÍí§ÒâCOMÎó²îÍŽáʹÓÃ(ÈçCVE-2022-30190)µÄʱ¼ä£¬¹¥»÷ÕßÖ»ÐèÓÕµ¼Êܺ¦Õßµã»÷Á´½Ó£¬¼´¿ÉÔÚÓû§µçÄÔÉÏÖ´ÐÐí§Òâ´úÂë¡£
¸ÃÎó²îʹÓÃÄѶȽϵͣ¬ÓëÈ¥Äê±»APT28×é֯ƵÈÔʹÓõÄMicrosoft Outlook ȨÏÞÌáÉýÎó²î(CVE-2023-23397)µÄ¹¥»÷³¡¾°ÀàËÆ£¬ºóÐø±»Ê¹ÓõĿÉÄÜÐԽϸߡ£ÏÖÔÚ¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬½¨Òé¿Í»§Æð¾¢×öºÃÅŲéºÍ·À»¤¡£
Ó°Ïì°æ±¾
Microsoft Office LTSC 2021 for 32-bit/64-bit editions
Microsoft Office 2019 for 32-bit/64-bit editions
Microsoft Office 2016 (32-bit/64-bit edition)
Microsoft 365 Apps for Enterprise for 32-bit/64-bit System
Îó²î¸´ÏÖ
ÏÖÔÚÒÑÀֳɸ´ÏÖÁ½ÖÖ¹¥»÷³¡¾°¡£
1¡¢NTLMй¶
½â¾ö¼Æ»®
1¡¢¹Ù·½ÐÞ¸´¼Æ»®
¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬½¨Ò齫ÊÜÓ°ÏìµÄofficeÉý¼¶ÖÁ×îа汾£ºhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21413£¬²¢ÇÒÔÚÉý¼¶Ö®Ç°²»ÒªÈÝÒ×µã»÷ÓʼþÖеÄÁ´½Ó»ò¸½¼þ¡£2¡¢ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½â¾ö¼Æ»®
ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©¿ÉÓÐÓ÷À»¤CVE-2024-21413Îó²îÔì³ÉµÄ¹¥»÷Σº¦¡£±ðµÄ£¬ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©ÄÚÖÃɳÏä¼ì²â¹¦Ð§£¬Éý¼¶µ½×îв¹¶¡¿ÉÓÐÓüì²âʹÓøÃÎó²îµÄ¶ñÒâÓʼþ¡£