¡¾Îó²îͨ¸æ¡¿Î¢Èí7Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2024-07-10

 

Ò»¡¢Îó²î¸ÅÊö

2024Äê7ÔÂ10ÈÕ£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË7ÔÂÇå¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË142¸öÎó²î£¬Îó²îÀàÐÍ°üÀ¨ÌØȨÌáÉýÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾ø·þÎñÎó²îºÍÓÕÆ­Îó²îµÈ¡£

±¾´ÎÇå¾²¸üÐÂÐÞ¸´ÁË4¸ö0 dayÎó²î£¬ÆäÖÐÁ½¸ö±»Æð¾¢Ê¹Óã¬ÁíÍâÁ½¸öÒѾ­¹ûÕæÅû¶£º

CVE-2024-38080 £ºWindows Hyper-VÌØȨÌáÉýÎó²î

Windows Hyper-V Öб£´æÕûÊýÒç³ö»òΧÈÆÎó²î£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8£¬ÍþвÕß¿ÉʹÓøÃÎó²î½«ÍâµØȨÏÞÌáÉýΪSYSTEM ȨÏÞ£¬ÏÖÔÚ¸ÃÎó²îÒѼì²âµ½Îó²îʹÓá£

CVE-2024-38112 £ºWindows MSHTML PlatformÓÕÆ­Îó²î

Windows MSHTML Platform±£´æÓÕÆ­Îó²î£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.5£¬Ê¹ÓÃÄѶȽϸߣ¬ÍþвÕß¿ÉÏòÊܺ¦Õß·¢ËͶñÒâÎļþ£¬²¢ÓÕµ¼Êܺ¦ÕßÖ´ÐиÃÎļþÀ´Ê¹ÓøÃÎó²î£¬ÏÖÔÚ¸ÃÎó²îÒѼì²âµ½Îó²îʹÓá£

CVE-2024-35264 £º.NET ºÍ Visual StudioÔ¶³Ì´úÂëÖ´ÐÐÎó²î

.NET ºÍ Visual StudioÖб£´æUse-After-FreeÎó²î£¬ÍþвÕß¿ÉÒÔͨ¹ýÔÚ´¦Öóͷ£ÇëÇóÖ÷Ìåʱ¹Ø±Õ http/3 Á÷À´Ê¹ÓøÃÎó²î£¬´Ó¶øµ¼Ö¾ºÕùÌõ¼þ£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬µ«ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ¡£ÏÖÔÚ¸ÃÎó²îÒѾ­¹ûÕæÅû¶£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ ¡°±»Ê¹ÓõĿÉÄÜÐÔ½ÏС¡±¡£

CVE-2024-37985 £ºArm -רÓÐԤȡÆ÷µÄϵͳʶ±ðºÍÌØÕ÷

΢ÈíÐÞ¸´ÁË֮ǰÅû¶µÄ¿ÉÓÃÓÚÇÔÈ¡ÉñÃØÐÅÏ¢µÄFetchBench²àÐŵÀ¹¥»÷£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ5.9£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕß¿ÉÒÔ´Ó·þÎñÆ÷ÉÏÔËÐеÄÌØȨÀú³ÌÉó²é¶ÑÄڴ棬µ¼ÖÂÐÅϢй¶¡£ÏÖÔÚ¸ÃÎó²îÒѾ­¹ûÕæÅû¶£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ ¡°±»Ê¹ÓõĿÉÄÜÐÔ½ÏС¡±¡£

±¾´ÎÇå¾²¸üÐÂÖÐÐÞ¸´µÄ5¸öÑÏÖØÎó²îΪ£º

CVE-2024-38023£ºMicrosoft SharePoint ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft SharePoint ServerÖб£´æ·´ÐòÁл¯Îó²î£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.2£¬¾ßÓÐÕ¾µãËùÓÐÕßȨÏ޵ľ­ÓÉÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔ½«ÌØÖÆÎļþÉÏ´«µ½Ä¿µÄ SharePoint Server£¬²¢Í¨¹ýÌØÖÆAPI ÇëÇóÒÔ´¥·¢Îļþ²ÎÊýµÄ·´ÐòÁл¯£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÔÚ SharePoint Server ÉÏÏÂÎÄÖÐÔ¶³ÌÖ´ÐдúÂ롣΢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ ¡°±»Ê¹ÓõĿÉÄÜÐԽϸߡ±¡£

CVE-2024-38060£ºWindows Imaging ComponentÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Windows ͼÏñ´¦Öóͷ£×é¼þÖб£´æ¶Ñ»º³åÇøÒç³öÎó²î£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8£¬¾­ÓÉÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔͨ¹ý½«¶ñÒâTIFFÎļþÉÏ´«µ½·þÎñÆ÷À´Ê¹ÓøÃÎó²î£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ ¡°±»Ê¹ÓõĿÉÄÜÐԽϸߡ±¡£

CVE-2024-38076£ºWindows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖб£´æ¶Ñ»º³åÇøÒç³öÎó²î£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8£¬ÍþвÕß¿ÉÒÔÏòÉèÖÃΪԶ³Ì×ÀÃæÊÚȨ·þÎñÆ÷µÄ·þÎñÆ÷·¢ËÍÌØÖÆÊý¾Ý°ü£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ÈôÊDz»ÐèÒª£¬¿É½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ×÷Ϊ»º½â²½·¥£¬Microsoft½¨ÒéÊÜÓ°ÏìÓû§×°ÖøÃÎó²îµÄÇå¾²¸üУ¬×ÝÈ»ÍýÏë½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ¡£Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ ¡°±»Ê¹ÓõĿÉÄÜÐÔ½ÏС¡±¡£

CVE-2024-38074£ºWindows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖб£´æÕûÊýÏÂÒçÎó²î£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8£¬ÍþвÕß¿ÉÒÔÏòÉèÖÃΪԶ³Ì×ÀÃæÊÚȨ·þÎñÆ÷µÄ·þÎñÆ÷·¢ËÍÌØÖÆÊý¾Ý°ü£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ÈôÊDz»ÐèÒª£¬¿É½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ×÷Ϊ»º½â²½·¥£¬Microsoft½¨ÒéÊÜÓ°ÏìÓû§×°ÖøÃÎó²îµÄÇå¾²¸üУ¬×ÝÈ»ÍýÏë½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ¡£Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ ¡°±»Ê¹ÓõĿÉÄÜÐÔ½ÏС¡±¡£

CVE-2024-38077£ºWindows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖб£´æ¶Ñ»º³åÇøÒç³öÎó²î£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔÅþÁ¬µ½Ô¶³Ì×ÀÃæÊÚȨ·þÎñ²¢·¢ËͶñÒâÐÂÎÅ£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ÈôÊDz»ÐèÒª£¬¿É½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ×÷Ϊ»º½â²½·¥£¬Microsoft½¨ÒéÊÜÓ°ÏìÓû§×°ÖøÃÎó²îµÄÇå¾²¸üУ¬×ÝÈ»ÍýÏë½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ¡£Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ ¡°±»Ê¹ÓõĿÉÄÜÐÔ½ÏС¡±¡£

³ýCVE-2024-38023ºÍCVE-2024-38060Í⣬΢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀÖÐÆäËû¡°±»Ê¹ÓõĿÉÄÜÐԽϸߡ±µÄÎó²î»¹°üÀ¨£º

CVE-2024-38021£ºMicrosoft Office Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÍþвÕß¿ÉÒÔÖÆ×÷Ò»¸öÈƹýÊܱ£»¤ÊÓͼЭÒéµÄ¶ñÒâÁ´½ÓÀ´Ê¹ÓøÃÎó²î£¬´Ó¶øÔÚÓû§½»»¥µÄÇéÐÎϵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

CVE-2024-38024/ CVE-2024-38094£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft SharePoint ServerÖб£´æ¶à¸ö·´ÐòÁл¯Îó²î£¬¾ßÓÐÕ¾µãËùÓÐÕßȨÏ޵ľ­ÓÉÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔʹÓøÃÎó²î×¢Èëí§Òâ´úÂë²¢ÔÚ SharePoint Server ÉÏÏÂÎÄÖÐÖ´ÐС£

CVE-2024-38052£ºKernel Streaming WOW Thunk Service DriverÌØȨÌáÉýÎó²î

Kernel Streaming WOW Thunk Service DriverÖб£´æÊäÈëÑéÖ¤²»µ±Îó²î£¬ÀÖ³ÉʹÓøÃÎó²î¿É»ñµÃSYSTEM ȨÏÞ¡£

CVE-2024-38054£ºKernel Streaming WOW Thunk Service DriverÌØȨÌáÉýÎó²î

Kernel Streaming WOW Thunk Service DriverÖб£´æ¶Ñ»º³åÇøÒç³öÎó²î£¬ÀÖ³ÉʹÓøÃÎó²î¿É»ñµÃSYSTEM ȨÏÞ¡£

CVE-2024-38059£ºWin32k ÌØȨÌáÉýÎó²î

Win32kÖб£´æUse-After-FreeÎó²î£¬ÀÖ³ÉʹÓøÃÎó²î¿É»ñµÃSYSTEM ȨÏÞ¡£

CVE-2024-38066£ºWindows Win32k ÌØȨÌáÉýÎó²î

Windows Win32kÖб£´æUse-After-FreeÎó²î£¬ÀÖ³ÉʹÓøÃÎó²î¿É»ñµÃSYSTEM ȨÏÞ¡£

CVE-2024-38079£ºWindows Graphics ComponentÌØȨÌáÉýÎó²î

Windows ͼÐÎ×é¼þÖб£´æ¶Ñ»º³åÇøÒç³öÎó²î£¬ÍâµØÍþвÕß¿ÉÒÔÔËÐпÉʹÓøÃÎó²îµÄÌØÖÆÓ¦ÓóÌÐò£¬ÀÖ³ÉʹÓÿÉÒÔ»ñµÃSYSTEM ȨÏÞ¡£

CVE-2024-38085£ºWindows Graphics ComponentÌØȨÌáÉýÎó²î

Windows ͼÐÎ×é¼þÖб£´æUse-After-FreeÎó²î£¬ÀÖ³ÉʹÓøÃÎó²î¿É»ñµÃSYSTEM ȨÏÞ¡£

CVE-2024-38099£ºWindows Remote Desktop Licensing Service¾Ü¾ø·þÎñÎó²î

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖб£´æÉí·ÝÑéÖ¤²»µ±Îó²î£¬ÀÖ³ÉʹÓøÃÎó²îÐèÒªÍþвÕßÓµÓи߼¶ÄæÏò¹¤³ÌÊÖÒÕÀ´Ê¶±ð²¢»ñµÃ¶ÔÌض¨Ô¶³ÌÀú³ÌŲÓà (RPC) ¶ËµãµÄδ¾­ÊÚȨµÄ»á¼û£¬ÀÖ³ÉʹÓÿÉÄܵ¼Ö¾ܾø·þÎñ¡£

CVE-2024-38100£ºWindows File ExplorerÌØȨÌáÉýÎó²î

Windows Îļþ×ÊÔ´ÖÎÀíÆ÷±£´æ»á¼û¿ØÖƲ»µ±Îó²î£¬ÀÖ³ÉʹÓôËÎó²îµÄÍþвÕß¿ÉÒÔ»ñµÃÖÎÀíԱȨÏÞ¡£

΢Èí7Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE ID

CVE ÎÊÌâ

ÑÏÖØÐÔ

CVE-2024-38023

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2024-38060

Windows Imaging Component Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2024-38076

Windows Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2024-38074

Windows Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2024-38077

Windows Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2024-30105

.NET Core ºÍ Visual Studio ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-38081

.NET¡¢.NET Framework ºÍ Visual Studio ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-35264

.NET ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-38095

.NET ºÍ Visual Studio ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-38092

Azure CycleCloud ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-35266

Azure DevOps Server ÓÕÆ­Îó²î

¸ßΣ

CVE-2024-35267

Azure DevOps Server ÓÕÆ­Îó²î

¸ßΣ

CVE-2024-38086

Azure Kinect SDK Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-35261

Azure Network Watcher VM Extension ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-37985

Arm£ºCVE-2024-37985 רÓÐԤȡÆ÷µÄϵͳʶ±ðºÍÌØÕ÷

¸ßΣ

CVE-2024-38027

Windows Line Printer Daemon Service ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-38089

Microsoft Defender for IoT ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-30061

Microsoft Dynamics 365 (On-Premises) ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-38079

Windows Graphics Component ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-38051

Windows Graphics Component Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-38021

Microsoft Office Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-38024

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-32987

Microsoft SharePoint Server ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-38094

Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-38057

Kernel Streaming WOW Thunk Service Driver ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-38054

Kernel Streaming WOW Thunk Service Driver ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-38052

Kernel Streaming WOW Thunk Service Driver ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-38055

Microsoft Windows Codecs Library ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-38056

Microsoft Windows Codecs Library ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-38091

Microsoft WS-Discovery ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-38048

Windows Network Driver Interface Specification   (NDIS) ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-3596

CERT/CC£ºCVE-2024-3596 RADIUS ЭÒéÓÕÆ­Îó²î

¸ßΣ

CVE-2024-38061

DCOM Remote Cross-Session Activation ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-38080

Windows Hyper-V ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-28928

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-38088

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-20701

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21317

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21331

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21308

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21333

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-35256

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21303

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21335

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-35271

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-35272

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21332

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-38087

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21425

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21449

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-37324

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-37330

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-37326

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-37329

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-37328

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-37327

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-37334

Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-37321

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-37320

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-37319

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-37322

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-37333

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-37336

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-37323

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-37331

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21398

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21373

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-37318

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21428

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21415

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-37332

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21414

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-38058

BitLocker Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-38100

Windows File Explorer ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-21417

Windows Text Services Framework ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-30098

Windows Cryptographic Services Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-38044

DHCP Server Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-38049

Windows Distributed Transaction Coordinator Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-38069

Windows Enroll Engine Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-38104

Windows Fax Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-38034

Windows Filtering Platform ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-38022

Windows Image Acquisition ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-38105

Windows Layer-2 Bridge Network Driver ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-38053

Windows Layer-2 Bridge Network Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-38102

Windows Layer-2 Bridge Network Driver ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-38101

Windows Layer-2 Bridge Network Driver ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-35270

Windows iSCSI Service ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-38041

Windows Kernel ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-38062

Windows Kernel-Mode Driver ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-38070

Windows LockDown Policy (WLDP) Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-38017

Microsoft Message Queuing ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-38112

Windows MSHTML Platform ÓÕÆ­Îó²î

¸ßΣ

CVE-2024-30013

Windows MultiPoint Services Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-30081

Windows NTLM ÓÕÆ­Îó²î

¸ßΣ

CVE-2024-38068

Windows Online Certificate Status Protocol (OCSP)   Server ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-38067

Windows Online Certificate Status Protocol (OCSP)   Server ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-38031

Windows Online Certificate Status Protocol (OCSP)   Server ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-38028

Microsoft Windows Performance Data Helper Library   Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-38019

Microsoft Windows Performance Data Helper Library   Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-38025

Microsoft Windows Performance Data Helper Library   Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-38043

PowerShell ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-38047

PowerShell ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-38033

PowerShell ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-30071

Windows Remote Access Connection Manager ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-30079

Windows Remote Access Connection Manager ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-38015

Windows Remote Desktop Gateway (RD Gateway) ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-38071

Windows Remote Desktop Licensing Service ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-38073

Windows Remote Desktop Licensing Service ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-38072

Windows Remote Desktop Licensing Service ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-38099

Windows Remote Desktop Licensing Service ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-38065

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-37986

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-37981

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-37987

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-28899

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-26184

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-38011

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-37984

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-37988

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-37977

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-37978

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-37974

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-38010

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-37989

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-37970

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-37975

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-37972

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-37973

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-37971

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-37969

Secure Boot Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-38013

Microsoft Windows Server Backup ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-38064

Windows TCP/IP ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-38030

Windows Themes ÓÕÆ­Îó²î

¸ßΣ

CVE-2024-38085

Windows Graphics Component ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-38066

Windows Win32k ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-38059

Win32k ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-38050

Windows Workstation Service ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-38032

Microsoft Xbox Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-38078

Xbox Wireless Adapter Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-39684

Github£ºCVE-2024-39684 TenCent   RapidJSON ÌØȨÌáÉýÎó²î

ÖÐΣ

CVE-2024-38517

Github£ºCVE-2024-38517 TenCent   RapidJSON ÌØȨÌáÉýÎó²î

ÖÐΣ

CVE-2024-38020

Microsoft Outlook ÓÕÆ­Îó²î

ÖÐΣ

 


¶þ¡¢Ó°Ïì¹æÄ£

ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/·þÎñ/×é¼þ°üÀ¨£º

SQL Server

Windows CoreMessaging

Windows Secure Boot

Windows MultiPoint Services

Microsoft Dynamics

Windows Remote Access Connection Manager

Windows NTLM

Windows Cryptographic Services

.NET and Visual Studio

Microsoft Office SharePoint

Azure Network Watcher

Azure DevOps

Windows iSCSI

Windows Server Backup

Windows Remote Desktop

Windows Message Queuing

Windows Performance Monitor

Microsoft Office Outlook

Microsoft Office

Windows Image Acquisition

Line Printer Daemon Service (LPD)

Windows Themes

Windows Online Certificate Status Protocol (OCSP)

XBox Crypto Graphic Services

Windows PowerShell

Windows Filtering

Windows Kernel

Windows DHCP Server

NDIS

Windows Distributed Transaction Coordinator

Windows Workstation Service

Microsoft Graphics Component

Microsoft Streaming Service

Windows Internet Connection Sharing (ICS)

Microsoft Windows Codecs Library

Windows BitLocker

Windows Win32K - ICOMP

Role: Active Directory Certificate Services; Active Directory Domain Services

Windows Kernel-Mode Drivers

Windows TCP/IP

Windows Win32K - GRFX

Windows Enroll Engine

Windows LockDown Policy (WLDP)

Windows Remote Desktop Licensing Service

Active Directory Federation Services

Role: Windows Hyper-V

Windows Win32 Kernel Subsystem

Azure Kinect SDK

Microsoft Defender for IoT

Microsoft WS-Discovery

Azure CycleCloud

Windows COM Session

Windows Fax and Scan Service

Windows MSHTML Platform

 


Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔÏ°취ÊÖ¶¯¾ÙÐиüУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔز¢×°Öá£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£

2024Äê7ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Jul

²¹¶¡ÏÂÔØʾÀý£¨²Î¿¼£©£º

1.·­¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢ÈíÎó²îÁÐ±í£¨Ê¾Àý£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·­¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý

3.µã»÷¡¾Çå¾²¸üС¿£¬·­¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öá£

image.png

Àý3£º²¹¶¡ÏÂÔؽçÃæ

4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£

3.2 ÔÝʱ²½·¥

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔ̭ϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔÌ­½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔÌ­¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Jul

https://blog.qualys.com/vulnerabilities-threat-research/2024/07/09/microsoft-patch-tuesday-july-2024-security-update-review

https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2024-patch-tuesday-fixes-142-flaws-4-zero-days/

 


ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-07-10

Ê×´ÎÐû²¼

 


Îå¡¢¸½Â¼

5.1 ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ò½é

ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½¨ÉèÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Çå¾²·þÎñ½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Æ𾢡£

5.2 ¹ØÓÚÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø

ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png