¡¾Â©¶´Í¨¸æ¡¿Î¢Èí3Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2024-03-13Ò»¡¢Â©¶´¸ÅÊö
2024Äê3ÔÂ12ÈÕ£¬Î¢ÈíÐû²¼ÁË3ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË60¸ö©¶´£¨²»°üÂÞ3ÔÂ7ÈÕÐÞ¸´µÄ4¸öMicrosoft Edge©¶´£©£¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛÆÂ©¶´µÈ¡£
±¾´ÎÄþ¾²¸üÐÂÖв»°üÂÞ±»»ý¼«ÀûÓõÄ0 day©¶´£¬ÆäÖÐÆÀ¼¶Îª¡°ÑÏÖØ¡±µÄ2¸ö©¶´°üÂÞ£º
CVE-2024-21407£ºWindows Hyper-VÔ¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.1£¬ÀûÓøÃ©¶´ÐèÒªGuest VMÉϾ¹ýÉí·ÝÑéÖ¤µÄÍþвÕßÏòÐéÄâ»úÉϵÄÓ²¼þ×ÊÔ´·¢ËÍÌØÖÆµÄÎļþ²Ù×÷ÇëÇó£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔÚÖ÷»ú·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë¡£
CVE-2024-21408£ºWindows Hyper-V ¾Ü¾ø·þÎñ©¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ5.5£¬Ó°ÏìÁËWindows Server 2016/2019/2022¡¢Windows 10/11µÈ¶à¸ö°æ±¾£¬ÀÖ³ÉÀûÓÿÉÄܵ¼Ö¾ܾø·þÎñ¡£
±¾´ÎÄþ¾²¸üÐÂÖÐÆäËûÐèÒª¹Ø×¢µÄ©¶´»¹°üÂÞµ«²»ÏÞÓÚ£º
CVE-2024-21400£ºMicrosoft Azure Kubernetes Service Confidential ContainerÌØÈ¨ÌáÉý©¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.0£¬ÍþвÕß¿ÉÒÔ·ÃÎʲ»ÊÜÐÅÈ뵀 AKS Kubernetes ½ÚµãºÍ AKS»úÃÜÈÝÆ÷£¬´Ó¶ø½Ó¹ÜÆä¿ÉÄܰ󶨵ÄÍøÂç¶ÑÕ»Ö®ÍâµÄ»úÃÜguestsºÍÈÝÆ÷¡£ÀÖ³ÉÀûÓøÃ©¶´µÄÍþвÕß¿ÉÒÔÇÔȡƾ֤²¢Ó°Ïì Azure Kubernetes ·þÎñ»úÃÜÈÝÆ÷ (AKSCC) ¹ÜÀíµÄÄþ¾²·¶Î§Ö®ÍâµÄ×ÊÔ´¡£
CVE-2024-26199£ºMicrosoft OfficeÌØÈ¨ÌáÉý©¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8£¬¾¹ýÉí·ÝÑéÖ¤µÄÓû§¿ÉÀûÓøÃ©¶´»ñµÃSYSTEMȨÏÞ¡£
CVE-2024-20671£ºMicrosoft Defender Äþ¾²¹¦Ð§Èƹý©¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ5.5£¬¾¹ýÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÀûÓøÃ©¶´×èÖ¹ Microsoft Defender Æô¶¯¡£¸Ã©¶´ÒÑÔÚWindows Defender°æ±¾4.18.24010.12ÖÐÐÞ¸´£¬¿Éͨ¹ý Windows É豸ÉÏ×Ô¶¯°²×°µÄ Windows Defender ·´¶ñÒâÈí¼þƽ̨¸üнøÐÐÐÞ¸´¡£
CVE-2024-21411£ºSkype for Consumer Ô¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬ÍþвÕß¿ÉÒÔͨ¹ý¼´Ê±ÏûÏ¢ÏòÓû§·¢ËͶñÒâÁ´½Ó»ò¶ñÒâͼÏñ£¬È»ºóÓÕʹÓû§µ¥»÷¸ÃÁ´½Ó»òͼÏñÀ´ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓøÃ©¶´µÄÍþвÕß¿ÉÒÔ»ñµÃ¶ÁÈ¡¡¢Ð´ÈëºÍɾ³ýµÈȨÏÞ¡£
CVE-2024-21334£ºOpen Management Infrastructure (OMI) Ô¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³ÌÍþвÕß¿ÉÒÔ´Ó Internet ·ÃÎÊ OMI ʵÀý²¢·¢ËÍÌØÖÆÇëÇóÒÔ´¥·¢ÊͷźóʹÓé¶´£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ÔËÐÐÊÜÓ°ÏìµÄ SCOM (System Center Operations Manager) °æ±¾µÄ¿Í»§Ó¦¸üе½ OMI °æ±¾1.8.1-0¡£
CVE-2024-26198£ºMicrosoft Exchange Server Ô¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔͨ¹ý½«ÌØÖÆÎļþ·ÅÖõ½ÔÚÏßĿ¼»òµ±µØÍøÂçλÖã¬È»ºóÓÕµ¼Óû§´ò¿ªÎļþÀ´ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓÿÉÄܵ¼Ö¼ÓÔØ¶ñÒâ DLL£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖС°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ©¶´°üÂÞ£º
CVE-2024-21433£ºWindows Print SpoolerÌØÈ¨ÌáÉý©¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.0£¬ÀûÓøÃ©¶´ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬ÀÖ³ÉÀûÓøÃ©¶´µÄÍþвÕ߿ɻñµÃSYSTEMȨÏÞ¡£
CVE-2024-21437£ºWindows Graphics ComponentÌØÈ¨ÌáÉý©¶´
Windows ͼÐÎ×é¼þ´æÔÚȨÏÞÌáÉý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8£¬ÀÖ³ÉÀûÓøÃ©¶´µÄÍþвÕ߿ɻñµÃSYSTEMȨÏÞ¡£
CVE-2024-26160£ºWindows Cloud Files Mini Filter DriverÐÅϢй¶©¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ5.5£¬ÀÖ³ÉÀûÓøÃ©¶´µÄÍþвÕß¿ÉÒÔ´ÓÓû§Ä£Ê½½ø³Ì¶ÁÈ¡ÄÚºËÄÚ´æµÄÄÚÈÝ¡£
CVE-2024-26170£ºWindows Composite Image File System (CimFS) ÌØÈ¨ÌáÉý©¶´
Windows ¸´ºÏÓ³ÏñÎļþϵͳ (CimFS)´æÔÚȨÏÞÌáÉý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8£¬ÀÖ³ÉÀûÓøÃ©¶´µÄÍþвÕ߿ɻñµÃÊÜÏÞSYSTEMȨÏÞ¡£
CVE-2024-26182£ºWindows KernelÌØÈ¨ÌáÉý©¶´
Windows Äں˴æÔÚÌØÈ¨ÌáÉý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8£¬ÀÖ³ÉÀûÓøÃ©¶´µÄÍþвÕ߿ɻñµÃSYSTEMȨÏÞ¡£
CVE-2024-26185£ºWindows ѹËõÎļþ¼Ð¸Ä¶¯Â©¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ6.5£¬Ó°ÏìÁËWindows 11¶à¸ö°æ±¾¡£ÍþвÕß¿Éͨ¹ýÔÚµç×ÓÓʼþÖÐÏòÓû§·¢ËÍÌØÖÆÎļþ²¢ÓÕµ¼Óû§´ò¿ª¸ÃÎļþ£¬»òÓÕµ¼Óû§µ¥»÷¶ñÒâÍøÕ¾»òwebÁ´½Ó²¢´ò¿ªÌØÖÆÎļþÀ´ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼ÖÂÆÆ»µÏµÍ³ÍêÕûÐÔ¡£
΢Èí3Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑÏÖØÐÔ |
CVE-2024-21407 | Windows Hyper-V Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2024-21408 | Windows Hyper-V ¾Ü¾ø·þÎñ©¶´ | ÑÏÖØ |
CVE-2024-21392 | .NET ºÍ Visual Studio ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-26203 | Azure Data Studio ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21421 | Azure SDK ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-28746 | Intel£ºCVE-2023-28746 ¼Ä´æÆ÷ÎļþÊý¾Ý²ÉÑù (RFDS) | ¸ßΣ |
CVE-2024-21390 | Microsoft Authenticator ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21400 | Microsoft Azure Kubernetes Service Confidential Container ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26164 | Microsoft Django Backend for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21419 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾½Å±¾Â©¶´ | ¸ßΣ |
CVE-2024-26198 | Microsoft Exchange Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21437 | Windows Graphics Component ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26201 | Microsoft Intune Linux Agent ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26199 | Microsoft Office ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21426 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26190 | Microsoft QUIC ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-21448 | Microsoft Teams for Android ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2024-21451 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21441 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26161 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26166 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21444 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21450 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21434 | Microsoft Windows SCSI Class System File ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21330 | Open Management Infrastructure (OMI) ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21334 | Open Management Infrastructure (OMI) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26204 | Outlook for Android ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2024-21411 | Skype for Consumer Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21418 | Software for Open Networking in the Cloud (SONiC) ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26165 | Visual Studio Code ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21438 | Microsoft AllJoyn API ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-26160 | Windows Cloud Files Mini Filter Driver ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2024-26170 | Windows Composite Image File System (CimFS) ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26185 | Windows ѹËõÎļþ¼Ð¸Ä¶¯Â©¶´ | ¸ßΣ |
CVE-2024-20671 | Microsoft Defender Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-26169 | Windows Error Reporting Service ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21431 | Hypervisor-Protected Code Integrity (HVCI) Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-21436 | Windows Installer ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21427 | Windows Kerberos Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-26177 | Windows ÄÚºËÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2024-26176 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26174 | Windows ÄÚºËÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2024-26182 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26181 | Windows Äں˾ܾø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-26178 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26173 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21443 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21446 | NTFS ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21440 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26162 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-26159 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21435 | Windows OLE Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21433 | Windows Print Spooler ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-26197 | Windows Standards-Based Storage Management Service ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-21439 | Windows Telephony Server ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21432 | Windows Update Stack ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21429 | Windows USB Hub Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21442 | Windows USB Print Driver ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21445 | Windows USB Print Driver ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21430 | Windows USB Attached SCSI (UAS) Protocol Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-2174 | Chromium£ºCVE-2024-2174 V8 ÖеÄʵʩ²»Í× | δ֪ |
CVE-2024-2173 | Chromium£ºCVE-2024-2173 V8 ÖеÄÄÚ´æ·ÃÎÊÔ½½ç | δ֪ |
CVE-2024-2176 | Chromium£ºCVE-2024-2176 ÔÚ FedCM ÖÐÊͷźóʹÓà | δ֪ |
CVE-2024-26167 | Microsoft Edge for Android ÆÛÆÂ©¶´ | δ֪ |
¶þ¡¢Ó°Ï췶Χ
ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º
Windows Defender
Open Management Infrastructure
Microsoft Authenticator
.NET
Microsoft Azure Kubernetes Service
Role: Windows Hyper-V
Skype for Consumer
Software for Open Networking in the Cloud (SONiC)
Microsoft Dynamics
Azure SDK
Microsoft Office SharePoint
Windows Kerberos
Windows USB Hub Driver
Windows USB Serial Driver
Windows Hypervisor-Protected Code Integrity
Windows Update Stack
Windows Print Spooler Components
Microsoft Windows SCSI Class System File
Windows OLE
Windows Installer
Microsoft Graphics Component
Windows AllJoyn API
Windows Telephony Server
Windows ODBC Driver
Microsoft WDAC OLE DB provider for SQL
Windows USB Print Driver
Windows Kernel
Windows NTFS
Microsoft Teams for Android
Microsoft WDAC ODBC Driver
Windows Cloud Files Mini Filter Driver
SQL Server
Visual Studio Code
Microsoft Edge for Android
Windows Error Reporting
Windows Composite Image File System
Windows Compressed Folder
Microsoft QUIC
Windows Standards-Based Storage Management Service
Microsoft Exchange Server
Microsoft Office
Microsoft Intune
Azure Data Studio
Outlook for Android
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£
£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2024Äê3ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2024-Mar
²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2022Äê2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£
Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£
3.2 ÁÙʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Mar
https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2024-patch-tuesday-fixes-60-flaws-18-rce-bugs/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-03-13 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¶¶È¦Îª¶Ä¶øÉú¼ò½é
¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
5.2 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º