¡¾Îó²îͨ¸æ¡¿Î¢Èí11Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2024-11-13Ò»¡¢Îó²î¸ÅÊö
2024Äê11ÔÂ13ÈÕ£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË11ÔÂÇå¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË89¸öÎó²î£¨²»°üÀ¨Ö®Ç°ÐÞ¸´µÄEdgeÎó²î£©£¬Îó²îÀàÐÍ°üÀ¨ÌØȨÌáÉýÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾ø·þÎñÎó²îºÍÓÕÆÎó²îµÈ¡£
±¾´ÎÇå¾²¸üÐÂÖÐÐÞ¸´ÁË4¸ö0 dayÎó²î£¬ÆäÖÐ2¸öÒÑ·¢Ã÷ÔÚ¹¥»÷Öб»Ê¹Óã¬3¸öÒѾ¹ûÕæÅû¶£º
CVE-2024-43451£ºNTLM ¹þϣй¶ÓÕÆÎó²î
Windows±£´æNTLM ¹þϣй¶ÓÕÆÎó²î£¬ÆäCVSSÆÀ·ÖΪ6.5£¬Ê¹ÓøÃÎó²îÐèÒªÓû§½»»¥£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÏò¹¥»÷Õßй¶Óû§µÄ NTLMv2 ¹þÏ££¬¹¥»÷Õß¿ÉÒÔʹÓÃËüÀ´ÑéÖ¤Óû§Éí·Ý¡£ÏÖÔÚ¸ÃÎó²îÒѾ¹ûÕæÅû¶£¬ÇÒÒѼì²âµ½Îó²îʹÓá£
CVE-2024-49039£ºWindows Task SchedulerÌØȨÌáÉýÎó²î
Windows ʹÃüÍýÏë³ÌÐòÖб£´æÉí·ÝÑéÖ¤²»µ±£¬¿ÉÄܵ¼ÖÂȨÏÞÌáÉý£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8£¬¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÔÚÄ¿µÄϵͳÉÏÔËÐжñÒâÉè¼ÆµÄÓ¦ÓóÌÐò£¬Ê¹ÓøÃÎó²îÌáÉýÆäȨÏÞ£¬ÀÖ³ÉʹÓÃÔÊÐí¹¥»÷ÕßÖ´ÐÐͨ³£½öÏÞÓÚÌØȨÕË»§µÄRPC¹¦Ð§¡£ÏÖÔÚ¸ÃÎó²îÒѼì²âµ½Îó²îʹÓá£
CVE-2024-49040£ºMicrosoft Exchange Server ÓÕÆÎó²î
Microsoft Exchange ServerÖб£´æÓÕÆÎó²î£¬ÆäCVSSÆÀ·ÖΪ7.5£¬¸ÃÎó²îÔÊÐí¹¥»÷ÕßÔÚ·¢Ë͸øÍâµØÊÕ¼þÈ˵ĵç×ÓÓʼþÖÐαÔì·¢¼þÈ˵ĵç×ÓÓʼþµØµã£¬µ¼ÖÂÓÕƹ¥»÷¡£ÏÖÔÚ¸ÃÎó²îÒѾ¹ûÕæÅû¶£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ ¡°±»Ê¹ÓõĿÉÄÜÐԽϸߡ±¡£
CVE-2024-49019£ºActive Directory Ö¤Êé·þÎñÌØȨÌáÉýÎó²î
Active Directory Ö¤Êé·þÎñ±£´æÈõÉí·ÝÑéÖ¤ÎÊÌ⣬¿ÉÄܵ¼ÖÂÌØȨÌáÉý£¬ÆäCVSSÆÀ·ÖΪ7.8£¬¸ÃÎó²îÔÊÐí¹¥»÷Õßͨ¹ýÀÄÓÃÄÚÖÃĬÈÏ°æ±¾1Ö¤ÊéÄ£°åÀ´»ñÈ¡ÓòÖÎÀíԱȨÏÞ¡£ÏÖÔÚ¸ÃÎó²îÒѾ¹ûÕæÅû¶£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ ¡°±»Ê¹ÓõĿÉÄÜÐԽϸߡ±¡£
±¾´ÎÇå¾²¸üÐÂÖÐÐÞ¸´µÄ4¸öÑÏÖØÎó²îΪ£º
CVE-2024-43498£º.NET & Visual StudioÔ¶³Ì´úÂëÖ´ÐÐÎó²î
.NET ºÍ Visual StudioÖб£´æÀàÐÍ»ìÏýÎó²î£¬ÆäCVSSÆÀ·ÖΪ9.8£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÏò±£´æÎó²îµÄ .NET Web Ó¦ÓóÌÐò·¢ËÍÌØÖÆÇëÇó»ò½«ÌØÖÆÎļþ¼ÓÔص½±£´æÎó²îµÄ×ÀÃæÓ¦ÓóÌÐòÖÐÀ´Ê¹ÓøÃÎó²î£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ ¡°±»Ê¹ÓõĿÉÄÜÐÔ½ÏС¡±¡£
CVE-2024-49056£ºAirlift.microsoft.com ÌØȨÌáÉýÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.3£¬Í¨¹ý airlift.microsoft.com Éϼٶ¨²»¿É±äÊý¾ÝÈƹýÉí·ÝÑéÖ¤£¬ÊÚȨ¹¥»÷Õß¿ÉÒÔͨ¹ýÍøÂçÌáÉýȨÏÞ¡£¸ÃÎó²îÎÞÐèÓû§½ÓÄÉÈκβ½·¥¼´¿É½â¾ö¡£
CVE-2024-43639£ºWindows KDC ProxyÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓÃÌØÖÆÓ¦ÓóÌÐòʹÓÃWindows KerberosÖеļÓÃÜÐÒéÎó²î¶ÔÄ¿µÄÖ´ÐÐÔ¶³Ì´úÂë¡£
CVE-2024-43625£ºMicrosoft Windows VMSwitch ÌØȨÌáÉýÎó²î
Microsoft Hyper-V ÖÐµÄ VmSwitch ×é¼þ±£´æUse-After-FreeÎó²î£¬ÆäCVSSÆÀ·ÖΪ8.1£¬¹¥»÷Õß¿Éͨ¹ýÏòVMswitch Çý¶¯³ÌÐò·¢ËÍһϵÁÐÌض¨µÄÍøÂçÇëÇ󣬴Ӷø´¥·¢ Hyper-V Ö÷»úÖеÄÊͷźóÖØÓÃÎó²î£¬ÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃ SYSTEM ȨÏÞ¡£
³ýCVE-2024-49040ºÍCVE-2024-49019Í⣬΢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀÖÐÆäËû ¡°±»Ê¹ÓõĿÉÄÜÐԽϸߡ±µÄÎó²î»¹°üÀ¨ÒÔÏÂÎó²î£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²î»ñµÃ SYSTEM ȨÏÞ¡¢µ¼Ö¾ܾø·þÎñ»òÈƹýOfficeÊܱ£»¤ÊÓͼµÄÌض¨¹¦Ð§£º
CVE-2024-43623£ºWindows NT OS KernelÌØȨÌáÉýÎó²î
CVE-2024-43629£ºWindows DWM Core LibraryÌØȨÌáÉýÎó²î
CVE-2024-43630£ºWindows KernelÌØȨÌáÉýÎó²î
CVE-2024-43636£ºWin32kÌØȨÌáÉýÎó²î
CVE-2024-43642£ºWindows SMB ¾Ü¾ø·þÎñÎó²î
CVE-2024-49033£ºMicrosoft WordÇå¾²¹¦Ð§ÈƹýÎó²î
΢Èí11Ô¸üÐÂÐÞ¸´µÄÍêÕûÎó²îÁбíÈçÏ£º
CVE-ID | CVE ÎÊÌâ | ÑÏÖØÐÔ |
CVE-2024-43498 | .NET & Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2024-49056 | Airlift.microsoft.com ÌØȨÌáÉýÎó²î | ÑÏÖØ |
CVE-2024-43639 | Windows KDC ProxyÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2024-43625 | Microsoft Windows VMSwitch ÌØȨÌáÉýÎó²î | ÑÏÖØ |
CVE-2024-43499 | .NET & Visual Studio ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2024-43602 | Azure CycleCloud Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-43598 | LightGBM Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-5535 | OpenSSL£ºCVE-2024-5535 SSL_select_next_proto »º³åÇøÁýÕÖ | ¸ßΣ |
CVE-2024-49040 | Microsoft Exchange Server ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-49031 | Microsoft Office Graphics Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49032 | Microsoft Office Graphics Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49029 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49026 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49027 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49028 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49030 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49033 | Microsoft Word Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2024-49051 | Microsoft PC Manager ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-38264 | Microsoft ÐéÄâÓ²ÅÌ (VHDX) ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2024-43450 | Windows DNS ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-49019 | Active Directory Ö¤Êé·þÎñÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43633 | Windows Hyper-V ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2024-43624 | Windows Hyper-V ¹²ÏíÐéÄâ´ÅÅÌÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-48998 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-48997 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-48993 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49001 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49000 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-48999 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49043 | Microsoft.SqlServer.XEvent.Configuration.dll Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-43462 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-48995 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-48994 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-38255 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-48996 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-43459 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49002 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49013 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49014 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49011 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49012 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49015 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49018 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49021 | Microsoft SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49016 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49017 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49010 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49005 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49007 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49003 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49004 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49006 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49009 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49008 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49048 | TorchGeo Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49044 | Visual Studio ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-49050 | Visual Studio Code Python Extension Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-43644 | Windows Client-Side Caching ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43645 | Windows Defender Ó¦ÓóÌÐò¿ØÖÆ (WDAC) Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2024-43636 | Win32k ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43629 | Windows DWM Core Library ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43630 | Windows ÄÚºËÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43623 | Windows NT OS Kernel ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43451 | NTLM ¹þϣй¶ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-38203 | Windows Package Library Manager ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-43641 | Windows ×¢²á±íÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43452 | Windows ×¢²á±íÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43631 | Windows Secure Kernel Mode ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43646 | Windows Secure Kernel Mode ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43640 | Windows Kernel-Mode Driver ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43642 | Windows SMB ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2024-43447 | Windows SMBv3 Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-49039 | Windows Task Scheduler ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43628 | Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-43621 | Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-43620 | Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-43627 | Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-43635 | Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-43622 | Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-43626 | Windows Telephony Service ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43530 | Windows Update Stack ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43643 | Windows USB Video Class System Driver ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43449 | Windows USB Video Class System Driver ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43637 | Windows USB Video Class System Driver ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43634 | Windows USB Video Class System Driver ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-43638 | Windows USB Video Class System Driver ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-49046 | Windows Win32 Kernel Subsystem ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-49049 | Visual Studio Code Remote Extension ÌØȨÌáÉýÎó²î | ÖÐΣ |
ADV240001 | Microsoft SharePoint Server ×ÝÉî·ÀÓù¸üР| ÎÞ |
CVE-2024-10826 | Chromium£ºCVE-2024-10826 ÔÚ Family Experiences ÖÐUse-after-free | δ֪ |
CVE-2024-10827 | Chromium£ºCVE-2024-10827 SerialÖеÄUse-after-free | δ֪ |
?
¶þ¡¢Ó°Ïì¹æÄ£
ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/·þÎñ/×é¼þ°üÀ¨£º
Windows Package Library Manager
SQL Server
Microsoft Virtual Hard Drive
Windows SMBv3 Client/Server
Windows USB Video Driver
Microsoft Windows DNS
Windows NTLM
Windows Registry
.NET and Visual Studio
Windows Update Stack
LightGBM
Azure CycleCloud
Azure Database for PostgreSQL
Windows Telephony Service
Windows NT OS Kernel
Role: Windows Hyper-V
Windows VMSwitch
Windows DWM Core Library
Windows Kernel
Windows Secure Kernel Mode
Windows Kerberos
Windows SMB
Windows CSC Service
Windows Defender Application Control (WDAC)
Windows Active Directory Certificate Services
Microsoft Office Excel
Microsoft Graphics Component
Microsoft Office Word
Windows Task Scheduler
Microsoft Exchange Server
Visual Studio
Windows Win32 Kernel Subsystem
TorchGeo
Visual Studio Code
Microsoft PC Manager
Airlift.microsoft.com
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔÏ°취ÊÖ¶¯¾ÙÐиüУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔز¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£
2024Äê11ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2024-Nov
²¹¶¡ÏÂÔØʾÀý£¨²Î¿¼£©£º
1.·¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢ÈíÎó²îÁÐ±í£¨Ê¾Àý£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿ÁÐÑ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áз¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý
3.µã»÷¡¾Çå¾²¸üС¿£¬·¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öá£
Àý3£º²¹¶¡ÏÂÔؽçÃæ
4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
°´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔ̽«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Nov
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49019
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43639
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-11-13 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ò½é
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½¨ÉèÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Çå¾²·þÎñ½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Æ𾢡£
5.2 ¹ØÓÚÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º