¡¾Îó²îͨ¸æ¡¿Î¢Èí12Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2023-12-13
 

Ò»¡¢Îó²î¸ÅÊö

2023Äê12ÔÂ12ÈÕ £¬Î¢ÈíÐû²¼ÁË12ÔÂÇå¾²¸üР£¬±¾´Î¸üй²ÐÞ¸´ÁË36¸öÎó²î£¨²»°üÀ¨12ÔÂ7ÈÕÐÞ¸´µÄ8¸öMicrosoft EdgeÎó²î£© £¬Îó²îÀàÐÍ°üÀ¨ÌØȨÌáÉýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾ø·þÎñÎó²îºÍÓÕÆ­Îó²îµÈ¡£

±¾´ÎÇå¾²¸üÐÂÐÞ¸´ÁË1¸öÒÑÓÚ8ÔÂÅû¶µ«Ö®Ç°ÉÐδÐÞ¸´µÄAMD 0 dayÎó²î£º

CVE-2023-20588- AMD£ºAMDÍƲâÐÔй¶Îó²î£¨ÖÐΣ£©

ijЩ AMD ´¦Öóͷ£Æ÷Éϱ£´æ³ýÁã¹ýʧ £¬¿ÉÄܵ¼Ö·µ»ØÍƲâÊý¾Ý £¬Ôì³ÉÐÅϢй¶¡£

ÆÀ¼¶ÎªÑÏÖصÄ4¸öÎó²î°üÀ¨£º

CVE-2023-36019£ºMicrosoft Power Platform ConnectorÓÕÆ­Îó²î£¨ÑÏÖØ£©

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.6 £¬¿Éͨ¹ýÓÕµ¼Óû§µ¥»÷ÌØÖÆµÄ URLÀ´Ê¹ÓøÃÎó²î £¬¿ÉÄܵ¼Ö¶ñÒâ¾ç±¾ÔÚÊܺ¦ÕßÅÌËã»úÉϵÄä¯ÀÀÆ÷ÖÐÖ´ÐС£Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐÔ½ÏС¡±¡£

CVE-2023-35630£ºInternet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8 £¬ÀÖ³ÉʹÓøÃÎó²îÐèÒªÐÞ¸ÄDHCPv6 DHCPv6_MESSAGE_INFORMATION_REQUESTÊäÈëÐÂÎÅÖеÄoption->length×ֶΡ£¸ÃÎó²î²»¿É¿ç¶à¸öÍøÂ磨ÈçWAN£©Ê¹Óà £¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐÔ½ÏС¡±¡£

CVE-2023-35641£ºInternet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8 £¬¿Éͨ¹ýÏòÔËÐÐ Internet ÅþÁ¬¹²Ïí·þÎñµÄ·þÎñÆ÷·¢ËͶñÒâÖÆ×÷µÄ DHCP ÐÂÎÅÀ´Ê¹ÓøÃÎó²î¡£¸ÃÎó²î²»¿É¿ç¶à¸öÍøÂ磨ÈçWAN£©Ê¹Óà £¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐԽϴ󡱡£

CVE-2023-35628£ºWindows MSHTML PlatformÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.1 £¬¿ÉÒÔÔÚÎÞÐèÓû§½»»¥µÄÇéÐÎÏÂÔ¶³ÌʹÓà £¬µ«¹¥»÷ÖØƯºó½Ï¸ß¡£ÍþвÕß¿Éͨ¹ýµç×ÓÓʼþ»òÆäËû·½·¨ÏòÊܺ¦Õß·¢ËͶñÒâÁ´½Ó²¢ÓÕµ¼Óû§µ¥»÷¶ñÒâÁ´½ÓÀ´Ê¹ÓøÃÎó²î£»»òÕß¿ÉÒÔͨ¹ý·¢ËÍÌØÖƵç×ÓÓʼþÀ´Ê¹ÓøÃÎó²î £¬¸Ãµç×ÓÓʼþ¿ÉÄÜ»áÔÚOutlook ¿Í»§¶Ë¼ìË÷ºÍ´¦Öóͷ£Ê±×Ô¶¯´¥·¢ £¬¶øÎÞÐèÊܺ¦Õß·­¿ª¡¢ÔĶÁ»òµ¥»÷Á´½Ó £¬Õâ¿ÉÄܻᵼÖÂÔÚÔ¤ÀÀ´°¸ñÖÐÉó²éµç×ÓÓʼþ֮ǰ±»Ê¹Óá£ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÔÚÊܺ¦ÕßµÄÅÌËã»úÉÏÔ¶³ÌÖ´ÐдúÂ롣΢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐԽϴ󡱡£

³ýÁËCVE-2023-35641ºÍCVE-2023-35628Íâ £¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀÖС°±»Ê¹ÓõĿÉÄÜÐԽϴ󡱵ÄÎó²î»¹°üÀ¨£º

CVE-2023-35631£ºWin32k ÌØȨÌáÉýÎó²î

CVE-2023-35632£ºWindows Ancillary Function Driver for WinSockÌØȨÌáÉýÎó²î

CVE-2023-35633£ºWindows KernelÌØȨÌáÉýÎó²î

CVE-2023-35644£ºWindows Sysmain ServiceÌØȨÌáÉýÎó²î

CVE-2023-36005£ºWindows Telephony Server ÌØȨÌáÉýÎó²î

CVE-2023-36010£ºMicrosoft Defender¾Ü¾ø·þÎñÎó²î

CVE-2023-36011£ºWin32k ÌØȨÌáÉýÎó²î

CVE-2023-36391£ºLocal Security Authority Subsystem ServiceȨÌáÉýÎó²î

CVE-2023-36696£ºWindows Cloud Files Mini Filter DriverÌØȨÌáÉýÎó²î

΢Èí12Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE ID

CVE ÎÊÌâ

ÑÏÖØÐÔ

CVE-2023-36019

Microsoft Power Platform Connector ÓÕÆ­Îó²î

ÑÏÖØ

CVE-2023-35630

Internet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-35641

Internet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-35628

Windows MSHTML Platform Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2023-35624

Azure Connected Machine Agent ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2023-35625

Azure Machine Learning Compute   Instance for SDK Óû§ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-20588

AMD£ºCVE-2023-20588 AMD ÍƲâÐÔй¶Ç徲֪ͨ

¸ßΣ

CVE-2023-35634

Windows Bluetooth Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-35621

Microsoft Dynamics 365 Finance and   Operations ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2023-36020

Microsoft Dynamics 365 (on-premises) ¿çÕ¾µã¾ç±¾Îó²î

¸ßΣ

CVE-2023-35636

Microsoft Outlook ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-35619

Microsoft Outlook for Mac ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-36009

Microsoft Word ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-36006

Microsoft WDAC OLE DB provider for   SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-35622

Windows DNS ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-36696

Windows Cloud Files Mini Filter   Driver ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2023-36010

Microsoft Defender ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2023-35643

DHCP Server Service ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-35638

DHCP Server Service ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2023-36012

DHCP Server Service ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-36004

Windows DPAPI£¨Êý¾Ý±£»¤Ó¦ÓóÌÐò±à³Ì½Ó¿Ú£©ÓÕÆ­Îó²î

¸ßΣ

CVE-2023-35642

Internet Connection Sharing (ICS) ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2023-35632

Windows Ancillary Function Driver for   WinSock ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2023-35633

Windows ÄÚºËÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2023-35635

Windows Äں˾ܾø·þÎñÎó²î

¸ßΣ

CVE-2023-35644

Windows Sysmain Service ȨÏÞÌáÉý

¸ßΣ

CVE-2023-36391

Local Security Authority Subsystem   Service ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2023-21740

Windows Media Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-35639

Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-36005

Windows Telephony Server ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2023-35629

Microsoft USBHUB 3.0 Device Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2023-36011

Win32k ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2023-35631

Win32k ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2023-36003

XAML Diagnostics ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2023-35618

Microsoft Edge£¨»ùÓÚ Chromium£©È¨ÏÞÌáÉýÎó²î

ÖÐΣ

CVE-2023-36880

Microsoft Edge£¨»ùÓÚChromium£©ÐÅϢй¶Îó²î

µÍΣ

CVE-2023-38174

Microsoft Edge£¨»ùÓÚChromium£©ÐÅϢй¶Îó²î

µÍΣ

CVE-2023-6509

Chromium£ºCVE-2023-6509 ÔÚSide Panel SearchÖÐUse-after-free

δ֪

CVE-2023-6512

Chromium£ºCVE-2023-6512 Web ä¯ÀÀÆ÷ UI ÖеÄʵÑé²»µ±

δ֪

CVE-2023-6508

Chromium£ºCVE-2023-6508 ÔÚMedia StreamÖÐUse-after-free

δ֪

CVE-2023-6511

Chromium£ºCVE-2023-6511 ×Ô¶¯Ìî³äÖеÄʵÑé²»µ±

δ֪

CVE-2023-6510

Chromium£ºCVE-2023-6510 ÔÚMedia CaptureÖÐUse-after-free

δ֪

 


¶þ¡¢Ó°Ïì¹æÄ£

ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/·þÎñ/×é¼þ°üÀ¨£º

Windows Media

Microsoft Edge (Chromium-based)

Microsoft Office Outlook

Microsoft Dynamics

Microsoft Windows DNS

Azure Connected Machine Agent

Azure Machine Learning

Windows MSHTML Platform

Windows USB Mass Storage Class Driver

Windows Internet Connection Sharing (ICS)

Windows Win32K

Windows Kernel

Microsoft Bluetooth Driver

Windows DHCP Server

Windows ODBC Driver

Windows Kernel-Mode Drivers

XAML Diagnostics

Windows DPAPI (Data Protection Application Programming Interface)

Windows Telephony Server

Microsoft WDAC OLE DB provider for SQL

Microsoft Office Word

Windows Defender

Microsoft Power Platform Connector

Windows Local Security Authority Subsystem Service (LSASS)

Windows Cloud Files Mini Filter Driver

 

Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üР£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓà £¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ £¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔÏ°취ÊÖ¶¯¾ÙÐиüУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü £¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡± £¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС± £¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС± £¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú £¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüР£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó £¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡± £¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔز¢×°Öá£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£

2023Äê12ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2023-Dec

²¹¶¡ÏÂÔØʾÀý£º

1.·­¿ªÉÏÊöÏÂÔØÁ´½Ó £¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2022Äê2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ £¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·­¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý

3.µã»÷¡¾Çå¾²¸üС¿ £¬·­¿ª²¹¶¡ÏÂÔØÒ³Ãæ £¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öá£

image.png

Àý3£º²¹¶¡ÏÂÔؽçÃæ

4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£

3.2 ÔÝʱ²½·¥

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡ £¬ïÔ̭ϵͳÎó²î £¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ £¬Ð޸ķÀ»ðǽսÂÔ £¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ £¬ïÔÌ­½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬ïÔÌ­¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ· £¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí £¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò £¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2023-Dec

https://www.bleepingcomputer.com/news/microsoft/microsoft-december-2023-patch-tuesday-fixes-34-flaws-1-zero-day/

https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7007.html

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-12-13

Ê×´ÎÐû²¼

 

 

Îå¡¢¸½Â¼

5.1 ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ò½é

ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½¨ÉèÓÚ1996Äê £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Çå¾²·þÎñ½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø´óÏà £¬¹«Ë¾Ô±¹¤6000ÓàÈË £¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ù·þÎñ £¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Æ𾢡£

5.2 ¹ØÓÚÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø

ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯ £¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î £¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png