¡¾Îó²îͨ¸æ¡¿Î¢Èí12Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2023-12-13Ò»¡¢Îó²î¸ÅÊö
2023Äê12ÔÂ12ÈÕ£¬Î¢ÈíÐû²¼ÁË12ÔÂÇå¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË36¸öÎó²î£¨²»°üÀ¨12ÔÂ7ÈÕÐÞ¸´µÄ8¸öMicrosoft EdgeÎó²î£©£¬Îó²îÀàÐÍ°üÀ¨ÌØȨÌáÉýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾ø·þÎñÎó²îºÍÓÕÆÎó²îµÈ¡£
±¾´ÎÇå¾²¸üÐÂÐÞ¸´ÁË1¸öÒÑÓÚ8ÔÂÅû¶µ«Ö®Ç°ÉÐδÐÞ¸´µÄAMD 0 dayÎó²î£º
CVE-2023-20588- AMD£ºAMDÍƲâÐÔй¶Îó²î£¨ÖÐΣ£©
ijЩ AMD ´¦Öóͷ£Æ÷Éϱ£´æ³ýÁã¹ýʧ£¬¿ÉÄܵ¼Ö·µ»ØÍƲâÊý¾Ý£¬Ôì³ÉÐÅϢй¶¡£
ÆÀ¼¶ÎªÑÏÖصÄ4¸öÎó²î°üÀ¨£º
CVE-2023-36019£ºMicrosoft Power Platform ConnectorÓÕÆÎó²î£¨ÑÏÖØ£©
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.6£¬¿Éͨ¹ýÓÕµ¼Óû§µ¥»÷ÌØÖÆµÄ URLÀ´Ê¹ÓøÃÎó²î£¬¿ÉÄܵ¼Ö¶ñÒâ¾ç±¾ÔÚÊܺ¦ÕßÅÌËã»úÉϵÄä¯ÀÀÆ÷ÖÐÖ´ÐС£Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐÔ½ÏС¡±¡£
CVE-2023-35630£ºInternet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8£¬ÀÖ³ÉʹÓøÃÎó²îÐèÒªÐÞ¸ÄDHCPv6 DHCPv6_MESSAGE_INFORMATION_REQUESTÊäÈëÐÂÎÅÖеÄoption->length×ֶΡ£¸ÃÎó²î²»¿É¿ç¶à¸öÍøÂ磨ÈçWAN£©Ê¹Óã¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐÔ½ÏС¡±¡£
CVE-2023-35641£ºInternet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8£¬¿Éͨ¹ýÏòÔËÐÐ Internet ÅþÁ¬¹²Ïí·þÎñµÄ·þÎñÆ÷·¢ËͶñÒâÖÆ×÷µÄ DHCP ÐÂÎÅÀ´Ê¹ÓøÃÎó²î¡£¸ÃÎó²î²»¿É¿ç¶à¸öÍøÂ磨ÈçWAN£©Ê¹Óã¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐԽϴ󡱡£
CVE-2023-35628£ºWindows MSHTML PlatformÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.1£¬¿ÉÒÔÔÚÎÞÐèÓû§½»»¥µÄÇéÐÎÏÂÔ¶³ÌʹÓ㬵«¹¥»÷ÖØƯºó½Ï¸ß¡£ÍþвÕß¿Éͨ¹ýµç×ÓÓʼþ»òÆäËû·½·¨ÏòÊܺ¦Õß·¢ËͶñÒâÁ´½Ó²¢ÓÕµ¼Óû§µ¥»÷¶ñÒâÁ´½ÓÀ´Ê¹ÓøÃÎó²î£»»òÕß¿ÉÒÔͨ¹ý·¢ËÍÌØÖƵç×ÓÓʼþÀ´Ê¹ÓøÃÎó²î£¬¸Ãµç×ÓÓʼþ¿ÉÄÜ»áÔÚOutlook ¿Í»§¶Ë¼ìË÷ºÍ´¦Öóͷ£Ê±×Ô¶¯´¥·¢£¬¶øÎÞÐèÊܺ¦Õß·¿ª¡¢ÔĶÁ»òµ¥»÷Á´½Ó£¬Õâ¿ÉÄܻᵼÖÂÔÚÔ¤ÀÀ´°¸ñÖÐÉó²éµç×ÓÓʼþ֮ǰ±»Ê¹Óá£ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÔÚÊܺ¦ÕßµÄÅÌËã»úÉÏÔ¶³ÌÖ´ÐдúÂ롣΢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐԽϴ󡱡£
³ýÁËCVE-2023-35641ºÍCVE-2023-35628Í⣬΢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀÖС°±»Ê¹ÓõĿÉÄÜÐԽϴ󡱵ÄÎó²î»¹°üÀ¨£º
CVE-2023-35631£ºWin32k ÌØȨÌáÉýÎó²î
CVE-2023-35632£ºWindows Ancillary Function Driver for WinSockÌØȨÌáÉýÎó²î
CVE-2023-35633£ºWindows KernelÌØȨÌáÉýÎó²î
CVE-2023-35644£ºWindows Sysmain ServiceÌØȨÌáÉýÎó²î
CVE-2023-36005£ºWindows Telephony Server ÌØȨÌáÉýÎó²î
CVE-2023-36010£ºMicrosoft Defender¾Ü¾ø·þÎñÎó²î
CVE-2023-36011£ºWin32k ÌØȨÌáÉýÎó²î
CVE-2023-36391£ºLocal Security Authority Subsystem ServiceȨÌáÉýÎó²î
CVE-2023-36696£ºWindows Cloud Files Mini Filter DriverÌØȨÌáÉýÎó²î
΢Èí12Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º
CVE ID | CVE ÎÊÌâ | ÑÏÖØÐÔ |
CVE-2023-36019 | Microsoft Power Platform Connector ÓÕÆÎó²î | ÑÏÖØ |
CVE-2023-35630 | Internet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-35641 | Internet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-35628 | Windows MSHTML Platform Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-35624 | Azure Connected Machine Agent ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2023-35625 | Azure Machine Learning Compute Instance for SDK Óû§ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-20588 | AMD£ºCVE-2023-20588 AMD ÍƲâÐÔй¶Ç徲֪ͨ | ¸ßΣ |
CVE-2023-35634 | Windows Bluetooth Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-35621 | Microsoft Dynamics 365 Finance and Operations ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-36020 | Microsoft Dynamics 365 (on-premises) ¿çÕ¾µã¾ç±¾Îó²î | ¸ßΣ |
CVE-2023-35636 | Microsoft Outlook ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-35619 | Microsoft Outlook for Mac ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-36009 | Microsoft Word ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-36006 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-35622 | Windows DNS ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-36696 | Windows Cloud Files Mini Filter Driver ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36010 | Microsoft Defender ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-35643 | DHCP Server Service ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-35638 | DHCP Server Service ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-36012 | DHCP Server Service ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-36004 | Windows DPAPI£¨Êý¾Ý±£»¤Ó¦ÓóÌÐò±à³Ì½Ó¿Ú£©ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-35642 | Internet Connection Sharing (ICS) ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-35632 | Windows Ancillary Function Driver for WinSock ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-35633 | Windows ÄÚºËÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-35635 | Windows Äں˾ܾø·þÎñÎó²î | ¸ßΣ |
CVE-2023-35644 | Windows Sysmain Service ȨÏÞÌáÉý | ¸ßΣ |
CVE-2023-36391 | Local Security Authority Subsystem Service ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-21740 | Windows Media Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-35639 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-36005 | Windows Telephony Server ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2023-35629 | Microsoft USBHUB 3.0 Device Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-36011 | Win32k ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-35631 | Win32k ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36003 | XAML Diagnostics ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-35618 | Microsoft Edge£¨»ùÓÚ Chromium£©È¨ÏÞÌáÉýÎó²î | ÖÐΣ |
CVE-2023-36880 | Microsoft Edge£¨»ùÓÚChromium£©ÐÅϢй¶Îó²î | µÍΣ |
CVE-2023-38174 | Microsoft Edge£¨»ùÓÚChromium£©ÐÅϢй¶Îó²î | µÍΣ |
CVE-2023-6509 | Chromium£ºCVE-2023-6509 ÔÚSide Panel SearchÖÐUse-after-free | δ֪ |
CVE-2023-6512 | Chromium£ºCVE-2023-6512 Web ä¯ÀÀÆ÷ UI ÖеÄʵÑé²»µ± | δ֪ |
CVE-2023-6508 | Chromium£ºCVE-2023-6508 ÔÚMedia StreamÖÐUse-after-free | δ֪ |
CVE-2023-6511 | Chromium£ºCVE-2023-6511 ×Ô¶¯Ìî³äÖеÄʵÑé²»µ± | δ֪ |
CVE-2023-6510 | Chromium£ºCVE-2023-6510 ÔÚMedia CaptureÖÐUse-after-free | δ֪ |
¶þ¡¢Ó°Ïì¹æÄ£
ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/·þÎñ/×é¼þ°üÀ¨£º
Windows Media
Microsoft Edge (Chromium-based)
Microsoft Office Outlook
Microsoft Dynamics
Microsoft Windows DNS
Azure Connected Machine Agent
Azure Machine Learning
Windows MSHTML Platform
Windows USB Mass Storage Class Driver
Windows Internet Connection Sharing (ICS)
Windows Win32K
Windows Kernel
Microsoft Bluetooth Driver
Windows DHCP Server
Windows ODBC Driver
Windows Kernel-Mode Drivers
XAML Diagnostics
Windows DPAPI (Data Protection Application Programming Interface)
Windows Telephony Server
Microsoft WDAC OLE DB provider for SQL
Microsoft Office Word
Windows Defender
Microsoft Power Platform Connector
Windows Local Security Authority Subsystem Service (LSASS)
Windows Cloud Files Mini Filter Driver
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔÏ°취ÊÖ¶¯¾ÙÐиüУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔز¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£
2023Äê12ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2023-Dec
²¹¶¡ÏÂÔØʾÀý£º
1.·¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2022Äê2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý
3.µã»÷¡¾Çå¾²¸üС¿£¬·¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öá£
Àý3£º²¹¶¡ÏÂÔؽçÃæ
4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔ̽«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2023-Dec
https://www.bleepingcomputer.com/news/microsoft/microsoft-december-2023-patch-tuesday-fixes-34-flaws-1-zero-day/
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7007.html
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-12-13 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ò½é
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½¨ÉèÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Çå¾²·þÎñ½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Æ𾢡£
5.2 ¹ØÓÚÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º