¡¾Îó²îͨ¸æ¡¿Î¢Èí11Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2024-11-13


Ò»¡¢Îó²î¸ÅÊö

2024Äê11ÔÂ13ÈÕ£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË11ÔÂÇå¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË89¸öÎó²î£¨²»°üÀ¨Ö®Ç°ÐÞ¸´µÄEdgeÎó²î£©£¬Îó²îÀàÐÍ°üÀ¨ÌØȨÌáÉýÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾ø·þÎñÎó²îºÍÓÕÆ­Îó²îµÈ¡£

±¾´ÎÇå¾²¸üÐÂÖÐÐÞ¸´ÁË4¸ö0 dayÎó²î£¬ÆäÖÐ2¸öÒÑ·¢Ã÷ÔÚ¹¥»÷Öб»Ê¹Óã¬3¸öÒѾ­¹ûÕæÅû¶£º

CVE-2024-43451£ºNTLM ¹þϣй¶ÓÕÆ­Îó²î

Windows±£´æNTLM ¹þϣй¶ÓÕÆ­Îó²î£¬ÆäCVSSÆÀ·ÖΪ6.5£¬Ê¹ÓøÃÎó²îÐèÒªÓû§½»»¥£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÏò¹¥»÷Õßй¶Óû§µÄ NTLMv2 ¹þÏ££¬¹¥»÷Õß¿ÉÒÔʹÓÃËüÀ´ÑéÖ¤Óû§Éí·Ý¡£ÏÖÔÚ¸ÃÎó²îÒѾ­¹ûÕæÅû¶£¬ÇÒÒѼì²âµ½Îó²îʹÓá£

CVE-2024-49039£ºWindows Task SchedulerÌØȨÌáÉýÎó²î

Windows ʹÃüÍýÏë³ÌÐòÖб£´æÉí·ÝÑéÖ¤²»µ±£¬¿ÉÄܵ¼ÖÂȨÏÞÌáÉý£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8£¬¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÔÚÄ¿µÄϵͳÉÏÔËÐжñÒâÉè¼ÆµÄÓ¦ÓóÌÐò£¬Ê¹ÓøÃÎó²îÌáÉýÆäȨÏÞ£¬ÀÖ³ÉʹÓÃÔÊÐí¹¥»÷ÕßÖ´ÐÐͨ³£½öÏÞÓÚÌØȨÕË»§µÄRPC¹¦Ð§¡£ÏÖÔÚ¸ÃÎó²îÒѼì²âµ½Îó²îʹÓá£

CVE-2024-49040£ºMicrosoft Exchange Server ÓÕÆ­Îó²î

Microsoft Exchange ServerÖб£´æÓÕÆ­Îó²î£¬ÆäCVSSÆÀ·ÖΪ7.5£¬¸ÃÎó²îÔÊÐí¹¥»÷ÕßÔÚ·¢Ë͸øÍâµØÊÕ¼þÈ˵ĵç×ÓÓʼþÖÐαÔì·¢¼þÈ˵ĵç×ÓÓʼþµØµã£¬µ¼ÖÂÓÕÆ­¹¥»÷¡£ÏÖÔÚ¸ÃÎó²îÒѾ­¹ûÕæÅû¶£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ ¡°±»Ê¹ÓõĿÉÄÜÐԽϸߡ±¡£

CVE-2024-49019£ºActive Directory Ö¤Êé·þÎñÌØȨÌáÉýÎó²î

Active Directory Ö¤Êé·þÎñ±£´æÈõÉí·ÝÑéÖ¤ÎÊÌ⣬¿ÉÄܵ¼ÖÂÌØȨÌáÉý£¬ÆäCVSSÆÀ·ÖΪ7.8£¬¸ÃÎó²îÔÊÐí¹¥»÷Õßͨ¹ýÀÄÓÃÄÚÖÃĬÈÏ°æ±¾1Ö¤ÊéÄ£°åÀ´»ñÈ¡ÓòÖÎÀíԱȨÏÞ¡£ÏÖÔÚ¸ÃÎó²îÒѾ­¹ûÕæÅû¶£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ ¡°±»Ê¹ÓõĿÉÄÜÐԽϸߡ±¡£

±¾´ÎÇå¾²¸üÐÂÖÐÐÞ¸´µÄ4¸öÑÏÖØÎó²îΪ£º

CVE-2024-43498£º.NET & Visual StudioÔ¶³Ì´úÂëÖ´ÐÐÎó²î

.NET ºÍ Visual StudioÖб£´æÀàÐÍ»ìÏýÎó²î£¬ÆäCVSSÆÀ·ÖΪ9.8£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÏò±£´æÎó²îµÄ .NET Web Ó¦ÓóÌÐò·¢ËÍÌØÖÆÇëÇó»ò½«ÌØÖÆÎļþ¼ÓÔص½±£´æÎó²îµÄ×ÀÃæÓ¦ÓóÌÐòÖÐÀ´Ê¹ÓøÃÎó²î£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ ¡°±»Ê¹ÓõĿÉÄÜÐÔ½ÏС¡±¡£

CVE-2024-49056£ºAirlift.microsoft.com ÌØȨÌáÉýÎó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.3£¬Í¨¹ý airlift.microsoft.com Éϼٶ¨²»¿É±äÊý¾ÝÈƹýÉí·ÝÑéÖ¤£¬ÊÚȨ¹¥»÷Õß¿ÉÒÔͨ¹ýÍøÂçÌáÉýȨÏÞ¡£¸ÃÎó²îÎÞÐèÓû§½ÓÄÉÈκβ½·¥¼´¿É½â¾ö¡£

CVE-2024-43639£ºWindows KDC ProxyÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓÃÌØÖÆÓ¦ÓóÌÐòʹÓÃWindows KerberosÖеļÓÃÜЭÒéÎó²î¶ÔÄ¿µÄÖ´ÐÐÔ¶³Ì´úÂë¡£

CVE-2024-43625£ºMicrosoft Windows VMSwitch ÌØȨÌáÉýÎó²î

Microsoft Hyper-V ÖÐµÄ VmSwitch ×é¼þ±£´æUse-After-FreeÎó²î£¬ÆäCVSSÆÀ·ÖΪ8.1£¬¹¥»÷Õß¿Éͨ¹ýÏòVMswitch Çý¶¯³ÌÐò·¢ËÍһϵÁÐÌض¨µÄÍøÂçÇëÇ󣬴Ӷø´¥·¢ Hyper-V Ö÷»úÖеÄÊͷźóÖØÓÃÎó²î£¬ÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃ SYSTEM ȨÏÞ¡£

³ýCVE-2024-49040ºÍCVE-2024-49019Í⣬΢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀÖÐÆäËû ¡°±»Ê¹ÓõĿÉÄÜÐԽϸߡ±µÄÎó²î»¹°üÀ¨ÒÔÏÂÎó²î£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²î»ñµÃ SYSTEM ȨÏÞ¡¢µ¼Ö¾ܾø·þÎñ»òÈƹýOfficeÊܱ£»¤ÊÓͼµÄÌض¨¹¦Ð§£º

CVE-2024-43623£ºWindows NT OS KernelÌØȨÌáÉýÎó²î

CVE-2024-43629£ºWindows DWM Core LibraryÌØȨÌáÉýÎó²î

CVE-2024-43630£ºWindows KernelÌØȨÌáÉýÎó²î

CVE-2024-43636£ºWin32kÌØȨÌáÉýÎó²î

CVE-2024-43642£ºWindows SMB ¾Ü¾ø·þÎñÎó²î

CVE-2024-49033£ºMicrosoft WordÇå¾²¹¦Ð§ÈƹýÎó²î

΢Èí11Ô¸üÐÂÐÞ¸´µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE-IDCVE ÎÊÌâÑÏÖØÐÔ
CVE-2024-43498.NET & Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²îÑÏÖØ
CVE-2024-49056Airlift.microsoft.com ÌØȨÌáÉýÎó²îÑÏÖØ
CVE-2024-43639Windows KDC ProxyÔ¶³Ì´úÂëÖ´ÐÐÎó²îÑÏÖØ
CVE-2024-43625Microsoft Windows VMSwitch ÌØȨÌáÉýÎó²îÑÏÖØ
CVE-2024-43499.NET & Visual Studio ¾Ü¾ø·þÎñÎó²î¸ßΣ
CVE-2024-43602Azure CycleCloud Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-43598LightGBM Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-5535OpenSSL£ºCVE-2024-5535  SSL_select_next_proto »º³åÇøÁýÕÖ¸ßΣ
CVE-2024-49040Microsoft Exchange Server ÓÕÆ­Îó²î¸ßΣ
CVE-2024-49031Microsoft Office Graphics Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49032Microsoft Office Graphics Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49029Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49026Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49027Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49028Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49030Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49033Microsoft Word Çå¾²¹¦Ð§ÈƹýÎó²î¸ßΣ
CVE-2024-49051Microsoft PC Manager ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-38264Microsoft ÐéÄâÓ²ÅÌ (VHDX) ¾Ü¾ø·þÎñÎó²î¸ßΣ
CVE-2024-43450Windows DNS ÓÕÆ­Îó²î¸ßΣ
CVE-2024-49019Active Directory Ö¤Êé·þÎñÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43633Windows Hyper-V ¾Ü¾ø·þÎñÎó²î¸ßΣ
CVE-2024-43624Windows Hyper-V ¹²ÏíÐéÄâ´ÅÅÌÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-48998SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-48997SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-48993SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49001SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49000SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-48999SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49043Microsoft.SqlServer.XEvent.Configuration.dll  Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-43462SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-48995SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-48994SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-38255SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-48996SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-43459SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49002SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49013SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49014SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49011SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49012SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49015SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49018SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49021Microsoft SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49016SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49017SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49010SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49005SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49007SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49003SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49004SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49006SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49009SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49008SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49048TorchGeo Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49044Visual Studio ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-49050Visual Studio Code Python Extension  Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-43644Windows Client-Side Caching ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43645Windows Defender Ó¦ÓóÌÐò¿ØÖÆ (WDAC) Çå¾²¹¦Ð§ÈƹýÎó²î¸ßΣ
CVE-2024-43636Win32k ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43629Windows DWM Core Library ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43630Windows ÄÚºËÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43623Windows NT OS Kernel ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43451NTLM ¹þϣй¶ÓÕÆ­Îó²î¸ßΣ
CVE-2024-38203Windows Package Library Manager ÐÅϢй¶Îó²î¸ßΣ
CVE-2024-43641Windows ×¢²á±íÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43452Windows ×¢²á±íÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43631Windows Secure Kernel Mode ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43646Windows Secure Kernel Mode ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43640Windows Kernel-Mode Driver ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43642Windows SMB ¾Ü¾ø·þÎñÎó²î¸ßΣ
CVE-2024-43447Windows SMBv3 Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-49039Windows Task Scheduler ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43628Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-43621Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-43620Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-43627Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-43635Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-43622Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î¸ßΣ
CVE-2024-43626Windows Telephony Service ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43530Windows Update Stack ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43643Windows USB Video Class System Driver  ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43449Windows USB Video Class System Driver  ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43637Windows USB Video Class System Driver  ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43634Windows USB Video Class System Driver  ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-43638Windows USB Video Class System Driver  ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-49046Windows Win32 Kernel Subsystem ÌØȨÌáÉýÎó²î¸ßΣ
CVE-2024-49049Visual Studio Code Remote Extension ÌØȨÌáÉýÎó²îÖÐΣ
ADV240001Microsoft SharePoint Server ×ÝÉî·ÀÓù¸üÐÂÎÞ
CVE-2024-10826Chromium£ºCVE-2024-10826 ÔÚ Family  Experiences ÖÐUse-after-freeδ֪
CVE-2024-10827Chromium£ºCVE-2024-10827  SerialÖеÄUse-after-freeδ֪


?

¶þ¡¢Ó°Ïì¹æÄ£

ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/·þÎñ/×é¼þ°üÀ¨£º

Windows Package Library Manager

SQL Server

Microsoft Virtual Hard Drive

Windows SMBv3 Client/Server

Windows USB Video Driver

Microsoft Windows DNS

Windows NTLM

Windows Registry

.NET and Visual Studio

Windows Update Stack

LightGBM

Azure CycleCloud

Azure Database for PostgreSQL

Windows Telephony Service

Windows NT OS Kernel

Role: Windows Hyper-V

Windows VMSwitch

Windows DWM Core Library

Windows Kernel

Windows Secure Kernel Mode

Windows Kerberos

Windows SMB

Windows CSC Service

Windows Defender Application Control (WDAC)

Windows Active Directory Certificate Services

Microsoft Office Excel

Microsoft Graphics Component

Microsoft Office Word

Windows Task Scheduler

Microsoft Exchange Server

Visual Studio

Windows Win32 Kernel Subsystem

TorchGeo

Visual Studio Code

Microsoft PC Manager

Airlift.microsoft.com



Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔÏ°취ÊÖ¶¯¾ÙÐиüУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔز¢×°Öá£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£

2024Äê11ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Nov

²¹¶¡ÏÂÔØʾÀý£¨²Î¿¼£©£º

1.·­¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

 

image.png


Àý1£ºÎ¢ÈíÎó²îÁÐ±í£¨Ê¾Àý£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿ÁÐÑ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áз­¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

 image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý

3.µã»÷¡¾Çå¾²¸üС¿£¬·­¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öá£

 

image.png


Àý3£º²¹¶¡ÏÂÔؽçÃæ

4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£

3.2 ÔÝʱ²½·¥

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

 °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔ̭ϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£

 ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔÌ­½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔÌ­¹¥»÷Ãæ¡£

 Ê¹ÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£

 ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£

 ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Nov

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49019

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43639


ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-11-13

Ê×´ÎÐû²¼



Îå¡¢¸½Â¼

5.1 ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ò½é

ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½¨ÉèÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Çå¾²·þÎñ½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Æ𾢡£

5.2 ¹ØÓÚÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø

ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

 

image.png