¡¾Â©¶´Í¨¸æ¡¿Î¢Èí11Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2023-11-15Ò»¡¢Â©¶´¸ÅÊö
2023Äê11ÔÂ14ÈÕ£¬Î¢ÈíÐû²¼ÁË11ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË58¸ö©¶´£¨²»°üÂÞ֮ǰÐû²¼µÄMicrosoft EdgeµÈÄþ¾²¸üУ©£¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´ºÍÆÛÆÂ©¶´µÈ¡£
±¾´ÎÄþ¾²¸üй²ÐÞ¸´ÁË5¸ö0 day©¶´£¬ÆäÖÐ3¸öÒÑ·¢ÏÖÔÚ¹¥»÷Öб»ÀûÓã¬3¸öÒѾ¹ûÈ»Åû¶¡£CVE-2023-36033ĿǰÒѾ¹ûÈ»Åû¶£¬ÇÒÒÑ·¢ÏÖ±»ÀûÓá£ÏêÇéÈçÏ£º
CVE-2023-36036£ºWindows Cloud Files Mini Filter DriverÌØÈ¨ÌáÉý©¶´£¨¸ßΣ£©
Windows ÔÆÎļþÃÔÄã¹ýÂËÆ÷Çý¶¯·¨Ê½ÖдæÔÚµ±µØÈ¨ÏÞÌáÉý©¶´£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.8£¬Ä¿Ç°ÒÑ·¢ÏÖ±»ÀûÓá£
CVE-2023-36033£ºWindows DWM Core Library ÌØÈ¨ÌáÉý©¶´£¨¸ßΣ£©
Windows DWM ºËÐÄ¿âÖдæÔÚµ±µØÈ¨ÏÞÌáÉý©¶´£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.8£¬Ä¿Ç°ÒѾ¹ûÈ»Åû¶£¬ÇÒÒÑ·¢ÏÖ±»ÀûÓá£
CVE-2023-36025£ºWindows SmartScreenÄþ¾²¹¦Ð§Èƹý©¶´£¨¸ßΣ£©
Windows SmartScreen´æÔÚÄþ¾²¹¦Ð§Èƹý©¶´£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÈÆ¹ý Windows Defender SmartScreen ¼ì²é¼°ÆäÏà¹ØÌáʾ£¬ÀûÓøÃ©¶´ÐèÒªÓû§½»»¥£¬ºÃ±ÈÓû§Ðëµ¥»÷ÌØÖÆµÄ Internet ¿ì½Ý·½Ê½ (.URL) »òÖ¸Ïò Internet ¿ì½Ý·½Ê½ÎļþµÄ³¬Á´½ÓµÈ¡£¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬Ä¿Ç°ÒÑ·¢ÏÖ±»ÀûÓá£
CVE-2023-36413£ºMicrosoft OfficeÄþ¾²¹¦Ð§Èƹý©¶´£¨¸ßΣ£©
Microsoft OfficeÖдæÔÚÄþ¾²¹¦Ð§Èƹý©¶´£¬¿ÉÒÔͨ¹ýÏòÓû§·¢ËͶñÒâÎļþ²¢ÓÕµ¼Óû§´ò¿ªÎļþÀ´ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÈÆ¹ý Office Êܱ£»¤µÄÊÓͼ²¢ÒÔ±à¼Ä£Ê½¶ø²»ÊDZ£»¤Ä£Ê½´ò¿ª¡£¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ6.5£¬Ä¿Ç°ÒѾ¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°¿ÉÄܱ»ÀûÓᱡ£
CVE-2023-36038£ºASP.NET Core ¾Ü¾ø·þÎñ©¶´£¨¸ßΣ£©
ASP.NET Core´æÔھܾø·þÎñ©¶´£¬Èç¹ûÈ¡Ïû¶ÔIIS InProcessÍйÜÄ£ÐÍÉÏÔËÐеÄ.NET 8 RC 1µÄhttpÇëÇó£¬Ôò¿ÉÒÔÀûÓøÃ©¶´£¬Ê¹µÃÏ̼߳ÆÊýÔö¼Ó£¬¶øÇÒ¿ÉÄ᷺ܻÆð OutOfMemoryException£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼Ö¾ܾø·þÎñ¡£¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.2£¬Ä¿Ç°ÒѾ¹ûÈ»Åû¶¡£
ÆÀ¼¶ÎªÑÏÖØµÄ3¸ö©¶´ÏêÇéÈçÏ£º
CVE-2023-36052 £ºAzure CLI REST CommandÐÅϢй¶©¶´£¨ÑÏÖØ£©
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.6£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÒÔ´ÓÊÜÓ°ÏìµÄCLIÃüÁî´´½¨²¢ÓÉAzure DevOps»òGitHub ActionsÐû²¼µÄÈÕÖ¾ÎļþÖлָ´Ã÷ÎÄÃÜÂëºÍÓû§Ãû¡£Ê¹ÓÃÊÜÓ°ÏìµÄ CLI ÃüÁîµÄÓû§Ð뽫Æä Azure CLI °æ±¾¸üе½ 2.53.1»ò¸ü¸ß°æÔÀ´»º½â¸Ã©¶´£¬ÕâÒ²ÊÊÓÃÓÚͨ¹ý Azure DevOps »ò GitHub Actions ʹÓÃÕâЩÃüÁî´´½¨ÈÕÖ¾ÎļþµÄÓû§¡£
CVE-2023-36400£ºWindows HMAC Key DerivationÌØÈ¨ÌáÉý©¶´£¨ÑÏÖØ£©
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬ÍþвÕß¿ÉÒÔ´ÓµÍȨÏÞµÄ Hyper-V guestÖ´Ðй¥»÷£¬´©Ô½guestµÄÄþ¾²½çÏÞ£¬ÔÚ Hyper-V Ö÷»úÖ´Ðл·¾³ÉÏÖ´ÐдúÂë¡£ÀÖ³ÉÀûÓøÃ©¶´¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£
CVE-2023-36397£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨ÑÏÖØ£©
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ9.8£¬µ±WindowsÏûÏ¢ÐÐÁзþÎñÔËÐÐÔÚPGM Server»·¾³ÖÐʱ£¬¿ÉÒÔͨ¹ýÍøÂç·¢ËÍÌØÖÆÎļþÀ´ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£Windows ÏûÏ¢ÐÐÁзþÎñÊÇ Windows ×é¼þ£¨¿ÉÒÔͨ¹ý¹Ø±Õ¸Ã×é¼þÀ´»º½â¸Ã©¶´£©£¬¿ÉÒÔͨ¹ý¼ì²éÊÇ·ñÓÐÃûΪMessage QueuingµÄ·þÎñÔÚÔËÐУ¬ÒÔ¼°¼ÆËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£
΢Èí11Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑÏÖØÐÔ |
CVE-2023-36052 | Azure CLI REST Command ÐÅϢй¶©¶´ | ÑÏÖØ |
CVE-2023-36400 | Windows HMAC Key Derivation ÌØÈ¨ÌáÉý©¶´ | ÑÏÖØ |
CVE-2023-36397 | Windows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-36049 | .NET¡¢.NET Framework ºÍ Visual Studio ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36560 | ASP.NET Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-36038 | ASP.NET Core ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-36558 | ASP.NET Core Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-38151 | Microsoft Host Integration Server 2020 Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-36021 | Microsoft On-Prem Êý¾ÝÍø¹ØÄþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-36437 | Azure DevOps Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-24023 | Mitre£ºCVE-2023-24023 À¶ÑÀ©¶´ | ¸ßΣ |
CVE-2023-36016 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾½Å±¾Â©¶´ | ¸ßΣ |
CVE-2023-36007 | Microsoft Send Customer Voice survey from Dynamics 365 ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-36031 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾½Å±¾Â©¶´ | ¸ßΣ |
CVE-2023-36410 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾½Å±¾Â©¶´ | ¸ßΣ |
CVE-2023-36030 | Microsoft Dynamics 365 Sales ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-36027 | Microsoft Edge£¨»ùÓÚ Chromium£©È¨ÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36024 | Microsoft Edge£¨»ùÓÚ Chromium£©È¨ÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36439 | Microsoft Exchange Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-36050 | Microsoft Exchange Server ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-36039 | Microsoft Exchange Server ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-36035 | Microsoft Exchange Server ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-36413 | Microsoft Office Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-36045 | Microsoft Office Graphics Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-36041 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-36037 | Microsoft Excel Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-38177 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-36423 | Microsoft Remote Registry Service Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-36401 | Microsoft Remote Registry Service Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-36402 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-36394 | Windows Search Service ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36719 | Microsoft Speech Application Programming Interface (SAPI) ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36043 | Open Management Infrastructure ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-36393 | Windows User Interface Application Core Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-36042 | Visual Studio ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-36018 | Visual Studio Code Jupyter Extension ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-36047 | Windows Authentication ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36428 | Microsoft Local Security Authority Subsystem Service ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-36046 | Windows Authentication ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-36036 | Windows Cloud Files Mini Filter Driver ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36424 | Windows Common Log File System Driver ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36396 | Windows Compressed Folder Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-36422 | Microsoft Windows Defender ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36395 | Windows Deployment Services ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-36392 | DHCP Server Service ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-36425 | Windows ÂþÑÜʽÎļþϵͳ (DFS) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-36033 | Windows DWM Core Library ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36427 | Windows Hyper-V ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36407 | Windows Hyper-V ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36406 | Windows Hyper-V ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-36408 | Windows Hyper-V ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36705 | Windows Installer ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36405 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36404 | Windows ÄÚºËÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-36403 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36398 | Windows NTFSÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-36028 | Microsoft Protected Extensible Authentication Protocol (PEAP) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-36017 | Windows Scripting Engine ÄÚ´æËð»µÂ©¶´ | ¸ßΣ |
CVE-2023-36025 | Windows SmartScreenÄþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-36399 | Windows Storage ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36014 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÖÐΣ |
CVE-2023-36022 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÖÐΣ |
CVE-2023-36029 | Microsoft Edge£¨»ùÓÚ Chromium£©ÆÛÆÂ©¶´ | ÖÐΣ |
CVE-2023-36034 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÖÐΣ |
CVE-2023-5996 | Chromium£ºCVE-2023-5996 ÔÚ WebAudio ÖÐÊͷźóʹÓà | δ֪ |
CVE-2023-5480 | Chromium£ºCVE-2023-5480 Ö§¸¶ÖÐʵʩ²»Í× | δ֪ |
CVE-2023-5856 | Chromium£ºCVE-2023-5856 ÔÚ²àÃæ°åÖÐÊͷźóʹÓà | δ֪ |
CVE-2023-5855 | Chromium£ºCVE-2023-5855 ÔÚÔĶÁģʽÏÂÊͷźóʹÓà | δ֪ |
CVE-2023-5854 | Chromium£ºCVE-2023-5854 ÔÚÅäÖÃÎļþÖÐÊͷźóʹÓà | δ֪ |
CVE-2023-5859 | Chromium£ºCVE-2023-5859 »ÖлÖеÄÄþ¾² UI ²»ÕýÈ· | δ֪ |
CVE-2023-5858 | Chromium£ºCVE-2023-5858 WebApp Provider ÖеÄʵʩ²»Í× | δ֪ |
CVE-2023-5857 | Chromium£ºCVE-2023-5857 ÏÂÔØÖеIJ»Í×ʵʩ | δ֪ |
CVE-2023-5850 | Chromium£ºCVE-2023-5850 ÏÂÔØÖеÄÄþ¾² UI ²»ÕýÈ· | δ֪ |
CVE-2023-5849 | Chromium£ºCVE-2023-5849 USB ÖеÄÕûÊýÒç³ö | δ֪ |
CVE-2023-5482 | Chromium£ºCVE-2023-5482 USB ÖÐÊý¾ÝÑéÖ¤²»×ã | δ֪ |
CVE-2023-5853 | Chromium£ºCVE-2023-5853 ÏÂÔØÖеÄÄþ¾² UI ²»ÕýÈ· | δ֪ |
CVE-2023-5852 | Chromium£ºCVE-2023-5852 ÔÚ´òÓ¡ÖÐÊͷźóʹÓà | δ֪ |
CVE-2023-5851 | Chromium£ºCVE-2023-5851 ÏÂÔØÖÐʵʩ²»Í× | δ֪ |
CVE-2020-1747 | δ֪ | δ֪ |
CVE-2023-46316 | δ֪ | δ֪ |
CVE-2023-46753 | δ֪ | δ֪ |
CVE-2020-8554 | δ֪ | δ֪ |
CVE-2020-14343 | δ֪ | δ֪ |
¶þ¡¢Ó°Ï췶Χ
ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º
Microsoft Dynamics
Microsoft Edge (Chromium-based)
Windows Scripting
Visual Studio Code
Azure
Windows SmartScreen
Windows Protected EAP (PEAP)
Microsoft Dynamics 365 Sales
Windows DWM Core Library
Microsoft Exchange Server
Windows Cloud Files Mini Filter Driver
Microsoft Office Excel
ASP.NET
Visual Studio
Open Management Infrastructure
Microsoft Office
Windows Authentication Methods
.NET Framework
Windows DHCP Server
Tablet Windows User Interface
Microsoft Windows Search Component
Windows Deployment Services
Windows Compressed Folder
Windows Internet Connection Sharing (ICS)
Windows NTFS
Windows Storage
Windows HMAC Key Derivation
Microsoft Remote Registry Service
Microsoft WDAC OLE DB provider for SQL
Windows Kernel
Windows Hyper-V
Windows Defender
Windows Common Log File System Driver
Windows Distributed File System (DFS)
Azure DevOps
Windows Installer
Microsoft Windows Speech
Microsoft Office SharePoint
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£
£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2023Äê11ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2023-Nov
²¹¶¡ÏÂÔØÊ¾Àý£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2022Äê2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£
Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£
3.2 ÁÙʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2023-Nov
https://www.bleepingcomputer.com/news/microsoft/microsoft-november-2023-patch-tuesday-fixes-5-zero-days-58-flaws/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-11-15 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¶¶È¦Îª¶Ä¶øÉú¼ò½é
¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
5.2 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º