¡¾Â©¶´Í¨¸æ¡¿Î¢Èí5Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2024-05-15


Ò»¡¢Â©¶´¸ÅÊö

2024Äê5ÔÂ14ÈÕ£¬Î¢ÈíÐû²¼ÁË5ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË61¸ö©¶´£¨²»°üÂÞ֮ǰÐÞ¸´µÄMicrosoft Edge©¶´£©£¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛƭ©¶´µÈ¡£

±¾´ÎÄþ¾²¸üÐÂÐÞ¸´ÁË3¸ö0 day©¶´£¬ÆäÖÐÁ½¸öÒÑ·¢ÏÖ±»ÀûÓã¬CVE-2024-30046ÒѹûÈ»Åû¶£º

CVE-2024-30040£ºWindows MSHTML PlatformÄþ¾²¹¦Ð§Èƹý©¶´

Windows MSHTMLƽ̨´æÔÚÄþ¾²¹¦Ð§Èƹý©¶´£¬ÆäCVSSÆÀ·ÖΪ8.2£¬¿ÉÄܵ¼ÖÂÈÆ¹ý Microsoft 365 ºÍ Microsoft Office ÖеÄOLE»º½â´ëÊ©£¬ÍþвÕß¿Éͨ¹ýÓÕµ¼Óû§´ò¿ª¶ñÒâÎĵµÀ´»ñµÃ´úÂëÖ´ÐÐȨÏÞ£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔÚÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐÈÎÒâ´úÂ롣Ŀǰ¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-30051£ºWindows DWM Core LibraryÌØÈ¨ÌáÉý©¶´

Windows DWM ºËÐÄ¿âÖдæÔÚ»º³åÇøÒç³ö©¶´£¬ÆäCVSSÆÀ·ÖΪ7.8£¬µ±µØµÍȨÏÞÍþвÕß¿ÉÀûÓøÃ©¶´ÊµÏÖȨÏÞÌáÉý£¬ÀÖ³ÉÀûÓøÃ©¶´¿É»ñµÃSYSTEMȨÏÞ¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬ÇÒÒÑ·¢ÏÖQakbot¶ñÒâÈí¼þµöÓã¹¥»÷ʹÓöñÒâÎĵµÀ´ÀûÓøÃ©¶´²¢ÔÚWindowsÉ豸ÉÏ»ñµÃSYSTEMȨÏÞ¡£

CVE-2024-30046£ºVisual Studio¾Ü¾ø·þÎñ©¶´

Visual StudioÖдæÔÚ¾ºÕùÌõ¼þ©¶´£¬ÆäCVSSÆÀ·ÖΪ5.9£¬ÀÖ³ÉÀûÓÿÉÄܵ¼Ö¾ܾø·þÎñ¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£

±¾´ÎÄþ¾²¸üÐÂÖÐÐÞ¸´µÄ1¸öÑÏÖØÂ©¶´Îª£º

CVE-2024-30044£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft SharePoint ServerÖдæÔÚ·´ÐòÁл¯Â©¶´£¬ÆäCVSSÆÀ·ÖΪ8.8£¬¾ßÓÐÍøÕ¾ËùÓÐÕßȨÏ޵ľ­¹ýÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔ½«ÌØÖÆÎļþÉÏ´«µ½Ä¿±ê Sharepoint Server£¬²¢ÖÆ×÷ÌØÖÆAPIÇëÇóÒÔ´¥·¢Îļþ²ÎÊýµÄ·´ÐòÁл¯£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔÚ Sharepoint ServerµÄÉÏÏÂÎÄÖе¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Ä¿Ç°¸Ã©¶´ÔÝδ¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£

³ýÉÏÊöÍâ©¶´Í⣬΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ©¶´»¹°üÂÞ£º

l  CVE-2024-29996/CVE-2024-30025/CVE-2024-30037£ºWindows Common Log File System DriverÌØÈ¨ÌáÉý©¶´

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÖдæÔÚ¶à¸öÔ½½ç¶Áȡ©¶´£¬ÀÖ³ÉÀûÓÿɻñµÃSYSTEMȨÏÞ¡£

l  CVE-2024-30032/ CVE-2024-30035£ºWindows DWM Core LibraryÌØÈ¨ÌáÉý©¶´

Windows DWM ºËÐÄ¿âÖдæÔÚ¶à¸öUse-After-Free©¶´£¬ÀÖ³ÉÀûÓÿɻñµÃSYSTEMȨÏÞ¡£

l  CVE-2024-30034£ºWindows Cloud Files Mini Filter DriverÐÅϢй¶©¶´

Windows Cloud Files Mini FilterÇý¶¯·¨Ê½ÖдæÔÚÀàÐÍ»ìÏý©¶´£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼ÖÂijЩÄÚºËÄÚ´æÐÅϢй¶¡£

l  CVE-2024-30038£ºWin32k ÌØÈ¨ÌáÉý©¶´

Win32k.sys Çý¶¯·¨Ê½ÖдæÔÚ»º³åÇøÒç³ö©¶´£¬¾­¹ýÉí·ÝÑéÖ¤µÄµ±µØÍþвÕß¿ÉÀûÓøÃ©¶´½«È¨ÏÞÌáÉýΪSYSTEM»ò¹ÜÀíԱȨÏÞ¡£

l  CVE-2024-30049£ºWindows Win32 Kernel SubsystemÌØÈ¨ÌáÉý©¶´

Windows Win32 ÄÚºË×ÓϵͳÖдæÔÚUse-After-Free©¶´£¬ÀÖ³ÉÀûÓÿɻñµÃSYSTEMȨÏÞ¡£

l  CVE-2024-30050£ºWindows Mark of the Web Äþ¾²¹¦Ð§Èƹý©¶´

ÍþвÕß¿ÉÒÔÖÆ×÷¶ñÒâÎļþ²¢ÓÕµ¼Ä¿±êÓû§ÏÂÔØ²¢´ò¿ª¸ÃÎļþÀ´ÀûÓøÃ©¶´£¬´Ó¶ø¿ÉÄÜÌÓ±ÜWeb ±êÖ¾ (MOTW) ·ÀÓù£¬µ¼ÖÂÄþ¾²¹¦Ð§£¨ÀýÈçÒÀÀµ MOTW ±êÖ¾µÄ Microsoft Office ÖеÄÊܱ£»¤ÊÓͼ£©Èƹý¡£

΢Èí5Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º

CVE ID

CVE ±êÌâ

ÑÏÖØÐÔ

CVE-2024-30044

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-30045

.NET & Visual Studio Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30053

Azure Migrate ¿çÕ¾½Å±¾Â©¶´

¸ßΣ

CVE-2024-30041

Microsoft Bing Search ÆÛƭ©¶´

¸ßΣ

CVE-2024-30007

Microsoft Brokering File System ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30048

Dynamics 365 Customer Insights ÆÛƭ©¶´

¸ßΣ

CVE-2024-30047

Dynamics 365 Customer Insights ÆÛƭ©¶´

¸ßΣ

CVE-2024-30059

Microsoft Intune for Android Mobile Application Management ¸Ä¶¯Â©¶´

¸ßΣ

CVE-2024-30042

Microsoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30043

Microsoft SharePoint Server ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-30006

Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29994

Microsoft Windows SCSI Class System File ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30033

Windows Search Service ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-30054

Microsoft Power BI Client JavaScript SDK ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-30046

Visual Studio ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-32004

GitHub£ºCVE-2024-32004 ¿ËÂ¡ÌØÖÆµ±µØ´æ´¢¿âʱԶ³Ì´úÂëÖ´ÐÐ

¸ßΣ

CVE-2024-32002

CVE-2024-32002 Ö§³Ö·ûºÅÁ´½ÓµÄ²»Çø·Ö¾ÞϸдµÄÎļþϵͳÉϵĵݹé¿Ë¡ÈÝÒ×Êܵ½Ô¶³Ì´úÂëÖ´ÐÐ

¸ßΣ

CVE-2024-30034

Windows Cloud Files Mini Filter Driver ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-30031

Windows CNG Key Isolation Service ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-29996

Windows Common Log File System Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30037

Windows Common Log File System Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30025

Windows Common Log File System Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30020

Windows Cryptographic Services Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30016

Windows Cryptographic Services ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-30036

Windows Deployment Services ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-30019

DHCP Server Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-30008

Windows DWM Core Library ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-30051

Windows DWM Core Library ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30035

Windows DWM Core Library ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30032

Windows DWM Core Library ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30011

Windows Hyper-V ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-30017

Windows Hyper-V Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30010

Windows Hyper-V Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30018

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30002

Windows Mobile Broadband Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29997

Windows Mobile Broadband Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30003

Windows Mobile Broadband Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30012

Windows Mobile Broadband Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29999

Windows Mobile Broadband Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29998

Windows Mobile Broadband Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30000

Windows Mobile Broadband Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30005

Windows Mobile Broadband Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30004

Windows Mobile Broadband Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30021

Windows Mobile Broadband Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30001

Windows Mobile Broadband Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30040

Windows MSHTML Platform Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-30027

NTFS ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30039

Windows Remote Access Connection Manager ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-30009

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30024

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30015

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30029

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30023

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30014

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30022

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-26238

Microsoft PLUGScheduler Scheduled Task ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30030

Win32k ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30038

Win32k ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30049

Windows Win32 Kernel Subsystem ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30028

Win32k ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30050

Windows Mark of the Web Äþ¾²¹¦Ð§Èƹý©¶´

ÖÐΣ

CVE-2024-30055

Microsoft Edge£¨»ùÓÚ Chromium£©ÆÛƭ©¶´

µÍΣ

CVE-2024-4558

Chromium£ºCVE-2024-4558 ÔÚ ANGLE ÖÐ Use-after-free

δ֪

CVE-2024-4331

Chromium£ºCVE-2024-4331 ÔÚ»­Öл­ÖÐ Use-after-free

δ֪

CVE-2024-4671

Chromium£ºCVE-2024-4671 ÔÚVisuals ÖÐ Use-after-free

δ֪

CVE-2024-4368

Chromium£ºCVE-2024-4368 ÔÚ Dawn ÖÐ Use-after-free

δ֪

CVE-2024-4559

Chromium£ºCVE-2024-4559 WebAudio ÖеĶѻº³åÇøÒç³ö

δ֪

 

¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

Windows Task Scheduler

Microsoft Windows SCSI Class System File

Windows Common Log File System Driver

Windows Mobile Broadband

Microsoft WDAC OLE DB provider for SQL

Microsoft Brokering File System

Windows DWM Core Library

Windows Routing and Remote Access Service (RRAS)

Windows Hyper-V

Windows Cryptographic Services

Windows Kernel

Windows DHCP Server

Windows NTFS

Windows Win32K - ICOMP

Windows Win32K - GRFX

Windows CNG Key Isolation Service

Microsoft Windows Search Component

Windows Cloud Files Mini Filter Driver

Windows Deployment Services

Windows Remote Access Connection Manager

Windows MSHTML Platform

Microsoft Bing

Microsoft Office Excel

Microsoft Office SharePoint

.NET and Visual Studio

Visual Studio

Microsoft Dynamics 365 Customer Insights

Windows Mark of the Web (MOTW)

Azure Migrate

Power BI

Microsoft Edge (Chromium-based)

Microsoft Intune

 

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2024Äê5ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-May

²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí©¶´ÁÐ±í£¨Ê¾Àý£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£

3.2 ÁÙʱ´ëÊ©

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-May

https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2024-patch-tuesday-fixes-3-zero-days-61-flaws/

https://securelist.com/cve-2024-30051/112618/

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-05-15

Ê×´ÎÐû²¼

 

 

Îå¡¢¸½Â¼

5.1 ¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png