¡¾Â©¶´Í¨¸æ¡¿Î¢Èí7Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2024-07-10

 

Ò»¡¢Â©¶´¸ÅÊö

2024Äê7ÔÂ10ÈÕ£¬¶¶È¦Îª¶Ä¶øÉú¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË7ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË142¸ö©¶´£¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛƭ©¶´µÈ  ¡£

±¾´ÎÄþ¾²¸üÐÂÐÞ¸´ÁË4¸ö0 day©¶´£¬ÆäÖÐÁ½¸ö±»»ý¼«ÀûÓã¬ÁíÍâÁ½¸öÒѾ­¹ûÈ»Åû¶£º

CVE-2024-38080 £ºWindows Hyper-VÌØÈ¨ÌáÉý©¶´

Windows Hyper-V ÖдæÔÚÕûÊýÒç³ö»ò»·ÈÆÂ©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8£¬ÍþвÕß¿ÉÀûÓøÃ©¶´½«µ±µØÈ¨ÏÞÌáÉýΪSYSTEM ȨÏÞ£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓà  ¡£

CVE-2024-38112 £ºWindows MSHTML PlatformÆÛƭ©¶´

Windows MSHTML Platform´æÔÚÆÛÆ­Â©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.5£¬ÀûÓÃÄѶȽϸߣ¬ÍþвÕß¿ÉÏòÊܺ¦Õß·¢ËͶñÒâÎļþ£¬²¢ÓÕµ¼Êܺ¦ÕßÖ´ÐиÃÎļþÀ´ÀûÓøÃ©¶´£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓà  ¡£

CVE-2024-35264 £º.NET ºÍ Visual StudioÔ¶³Ì´úÂëÖ´ÐЩ¶´

.NET ºÍ Visual StudioÖдæÔÚUse-After-Free©¶´£¬ÍþвÕß¿ÉÒÔͨ¹ýÔÚ´¦ÖÃÇëÇóÖ÷Ìåʱ¹Ø±Õ http/3 Á÷À´ÀûÓøÃ©¶´£¬´Ó¶øµ¼Ö¾ºÕùÌõ¼þ£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬µ«ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ  ¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±  ¡£

CVE-2024-37985 £ºArm -רÓÐԤȡÆ÷µÄϵͳʶ±ðºÍÌØÐÔ

΢ÈíÐÞ¸´ÁË֮ǰÅû¶µÄ¿ÉÓÃÓÚÇÔÈ¡ÃØÃÜÐÅÏ¢µÄFetchBench²àÐŵÀ¹¥»÷£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ5.9£¬ÀÖ³ÉÀûÓøÃ©¶´µÄÍþвÕß¿ÉÒÔ´Ó·þÎñÆ÷ÉÏÔËÐеÄÌØÈ¨½ø³Ì¼ì²ì¶ÑÄڴ棬µ¼ÖÂÐÅϢй¶  ¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±  ¡£

±¾´ÎÄþ¾²¸üÐÂÖÐÐÞ¸´µÄ5¸öÑÏÖØÂ©¶´Îª£º

CVE-2024-38023£ºMicrosoft SharePoint ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft SharePoint ServerÖдæÔÚ·´ÐòÁл¯Â©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.2£¬¾ßÓÐÕ¾µãËùÓÐÕßȨÏ޵ľ­¹ýÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔ½«ÌØÖÆÎļþÉÏ´«µ½Ä¿±ê SharePoint Server£¬²¢Í¨¹ýÌØÖÆAPI ÇëÇóÒÔ´¥·¢Îļþ²ÎÊýµÄ·´ÐòÁл¯£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔÚ SharePoint Server ÉÏÏÂÎÄÖÐÔ¶³ÌÖ´ÐдúÂë  ¡£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±  ¡£

CVE-2024-38060£ºWindows Imaging ComponentÔ¶³Ì´úÂëÖ´ÐЩ¶´

Windows ͼÏñ´¦ÖÃ×é¼þÖдæÔÚ¶Ñ»º³åÇøÒç³ö©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬¾­¹ýÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔͨ¹ý½«¶ñÒâTIFFÎļþÉÏ´«µ½·þÎñÆ÷À´ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ  ¡£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±  ¡£

CVE-2024-38076£ºWindows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐЩ¶´

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖдæÔÚ¶Ñ»º³åÇøÒç³ö©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬ÍþвÕß¿ÉÒÔÏòÉèÖÃΪԶ³Ì×ÀÃæÊÚȨ·þÎñÆ÷µÄ·þÎñÆ÷·¢ËÍÌØÖÆÊý¾Ý°ü£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ  ¡£Èç¹û²»ÐèÒª£¬¿É½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ×÷Ϊ»º½â´ëÊ©£¬Microsoft½¨ÒéÊÜÓ°ÏìÓû§°²×°¸Ã©¶´µÄÄþ¾²¸üУ¬¼´Ê¹¼Æ»®½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ  ¡£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±  ¡£

CVE-2024-38074£ºWindows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐЩ¶´

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖдæÔÚÕûÊýÏÂÒç©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬ÍþвÕß¿ÉÒÔÏòÉèÖÃΪԶ³Ì×ÀÃæÊÚȨ·þÎñÆ÷µÄ·þÎñÆ÷·¢ËÍÌØÖÆÊý¾Ý°ü£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ  ¡£Èç¹û²»ÐèÒª£¬¿É½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ×÷Ϊ»º½â´ëÊ©£¬Microsoft½¨ÒéÊÜÓ°ÏìÓû§°²×°¸Ã©¶´µÄÄþ¾²¸üУ¬¼´Ê¹¼Æ»®½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ  ¡£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±  ¡£

CVE-2024-38077£ºWindows Remote Desktop Licensing ServiceÔ¶³Ì´úÂëÖ´ÐЩ¶´

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖдæÔÚ¶Ñ»º³åÇøÒç³ö©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔÁ¬½Óµ½Ô¶³Ì×ÀÃæÊÚȨ·þÎñ²¢·¢ËͶñÒâÏûÏ¢£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ  ¡£Èç¹û²»ÐèÒª£¬¿É½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ×÷Ϊ»º½â´ëÊ©£¬Microsoft½¨ÒéÊÜÓ°ÏìÓû§°²×°¸Ã©¶´µÄÄþ¾²¸üУ¬¼´Ê¹¼Æ»®½ûÓÃÔ¶³Ì×ÀÃæÊÚȨ·þÎñ  ¡£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±  ¡£

³ýCVE-2024-38023ºÍCVE-2024-38060Í⣬΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ©¶´»¹°üÂÞ£º

CVE-2024-38021£ºMicrosoft Office Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÍþвÕß¿ÉÒÔÖÆ×÷Ò»¸öÈÆ¹ýÊܱ£»¤ÊÓͼЭÒéµÄ¶ñÒâÁ´½ÓÀ´ÀûÓøÃ©¶´£¬´Ó¶øÔÚÓû§½»»¥µÄÇé¿öϵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ  ¡£

CVE-2024-38024/ CVE-2024-38094£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft SharePoint ServerÖдæÔÚ¶à¸ö·´ÐòÁл¯Â©¶´£¬¾ßÓÐÕ¾µãËùÓÐÕßȨÏ޵ľ­¹ýÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔÀûÓøÃ©¶´×¢ÈëÈÎÒâ´úÂë²¢ÔÚ SharePoint Server ÉÏÏÂÎÄÖÐÖ´ÐÐ  ¡£

CVE-2024-38052£ºKernel Streaming WOW Thunk Service DriverÌØÈ¨ÌáÉý©¶´

Kernel Streaming WOW Thunk Service DriverÖдæÔÚÊäÈëÑéÖ¤²»Íש¶´£¬ÀÖ³ÉÀûÓøÃ©¶´¿É»ñµÃSYSTEM ȨÏÞ  ¡£

CVE-2024-38054£ºKernel Streaming WOW Thunk Service DriverÌØÈ¨ÌáÉý©¶´

Kernel Streaming WOW Thunk Service DriverÖдæÔÚ¶Ñ»º³åÇøÒç³ö©¶´£¬ÀÖ³ÉÀûÓøÃ©¶´¿É»ñµÃSYSTEM ȨÏÞ  ¡£

CVE-2024-38059£ºWin32k ÌØÈ¨ÌáÉý©¶´

Win32kÖдæÔÚUse-After-Free©¶´£¬ÀÖ³ÉÀûÓøÃ©¶´¿É»ñµÃSYSTEM ȨÏÞ  ¡£

CVE-2024-38066£ºWindows Win32k ÌØÈ¨ÌáÉý©¶´

Windows Win32kÖдæÔÚUse-After-Free©¶´£¬ÀÖ³ÉÀûÓøÃ©¶´¿É»ñµÃSYSTEM ȨÏÞ  ¡£

CVE-2024-38079£ºWindows Graphics ComponentÌØÈ¨ÌáÉý©¶´

Windows ͼÐÎ×é¼þÖдæÔÚ¶Ñ»º³åÇøÒç³ö©¶´£¬µ±µØÍþвÕß¿ÉÒÔÔËÐпÉÀûÓøÃ©¶´µÄÌØÖÆÓ¦Ó÷¨Ê½£¬ÀÖ³ÉÀûÓÿÉÒÔ»ñµÃSYSTEM ȨÏÞ  ¡£

CVE-2024-38085£ºWindows Graphics ComponentÌØÈ¨ÌáÉý©¶´

Windows ͼÐÎ×é¼þÖдæÔÚUse-After-Free©¶´£¬ÀÖ³ÉÀûÓøÃ©¶´¿É»ñµÃSYSTEM ȨÏÞ  ¡£

CVE-2024-38099£ºWindows Remote Desktop Licensing Service¾Ü¾ø·þÎñ©¶´

Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñÖдæÔÚÉí·ÝÑéÖ¤²»Íש¶´£¬ÀÖ³ÉÀûÓøÃ©¶´ÐèÒªÍþвÕßÓµÓи߼¶ÄæÏò¹¤³Ì¼¼ÄÜÀ´Ê¶±ð²¢»ñµÃ¶ÔÌØ¶¨Ô¶³Ì¹ý³Ìµ÷Óà (RPC) ¶ËµãµÄδ¾­ÊÚȨµÄ·ÃÎÊ£¬ÀÖ³ÉÀûÓÿÉÄܵ¼Ö¾ܾø·þÎñ  ¡£

CVE-2024-38100£ºWindows File ExplorerÌØÈ¨ÌáÉý©¶´

Windows Îļþ×ÊÔ´¹ÜÀíÆ÷´æÔÚ·ÃÎÊ¿ØÖƲ»Íש¶´£¬ÀÖ³ÉÀûÓôË©¶´µÄÍþвÕß¿ÉÒÔ»ñµÃ¹ÜÀíԱȨÏÞ  ¡£

΢Èí7Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º

CVE ID

CVE ±êÌâ

ÑÏÖØÐÔ

CVE-2024-38023

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38060

Windows Imaging Component Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38076

Windows Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38074

Windows Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38077

Windows Remote Desktop Licensing Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-30105

.NET Core ºÍ Visual Studio ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38081

.NET¡¢.NET Framework ºÍ Visual Studio ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-35264

.NET ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38095

.NET ºÍ Visual Studio ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38092

Azure CycleCloud ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-35266

Azure DevOps Server ÆÛƭ©¶´

¸ßΣ

CVE-2024-35267

Azure DevOps Server ÆÛƭ©¶´

¸ßΣ

CVE-2024-38086

Azure Kinect SDK Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-35261

Azure Network Watcher VM Extension ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-37985

Arm£ºCVE-2024-37985 רÓÐԤȡÆ÷µÄϵͳʶ±ðºÍÌØÐÔ

¸ßΣ

CVE-2024-38027

Windows Line Printer Daemon Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38089

Microsoft Defender for IoT ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30061

Microsoft Dynamics 365 (On-Premises) ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38079

Windows Graphics Component ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38051

Windows Graphics Component Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38021

Microsoft Office Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38024

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-32987

Microsoft SharePoint Server ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38094

Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38057

Kernel Streaming WOW Thunk Service Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38054

Kernel Streaming WOW Thunk Service Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38052

Kernel Streaming WOW Thunk Service Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38055

Microsoft Windows Codecs Library ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38056

Microsoft Windows Codecs Library ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38091

Microsoft WS-Discovery ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38048

Windows Network Driver Interface Specification   (NDIS) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-3596

CERT/CC£ºCVE-2024-3596 RADIUS ЭÒéÆÛƭ©¶´

¸ßΣ

CVE-2024-38061

DCOM Remote Cross-Session Activation ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38080

Windows Hyper-V ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-28928

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38088

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-20701

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21317

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21331

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21308

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21333

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-35256

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21303

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21335

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-35271

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-35272

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21332

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38087

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21425

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21449

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37324

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37330

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37326

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37329

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37328

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37327

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37334

Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37321

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37320

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37319

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37322

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37333

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37336

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37323

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37331

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21398

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21373

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37318

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21428

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21415

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37332

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21414

SQL Server Native Client OLE DB Provider Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38058

BitLocker Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38100

Windows File Explorer ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-21417

Windows Text Services Framework ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30098

Windows Cryptographic Services Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38044

DHCP Server Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38049

Windows Distributed Transaction Coordinator Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38069

Windows Enroll Engine Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38104

Windows Fax Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38034

Windows Filtering Platform ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38022

Windows Image Acquisition ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38105

Windows Layer-2 Bridge Network Driver ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38053

Windows Layer-2 Bridge Network Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38102

Windows Layer-2 Bridge Network Driver ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38101

Windows Layer-2 Bridge Network Driver ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-35270

Windows iSCSI Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38041

Windows Kernel ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38062

Windows Kernel-Mode Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38070

Windows LockDown Policy (WLDP) Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38017

Microsoft Message Queuing ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38112

Windows MSHTML Platform ÆÛƭ©¶´

¸ßΣ

CVE-2024-30013

Windows MultiPoint Services Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-30081

Windows NTLM ÆÛƭ©¶´

¸ßΣ

CVE-2024-38068

Windows Online Certificate Status Protocol (OCSP)   Server ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38067

Windows Online Certificate Status Protocol (OCSP)   Server ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38031

Windows Online Certificate Status Protocol (OCSP)   Server ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38028

Microsoft Windows Performance Data Helper Library   Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38019

Microsoft Windows Performance Data Helper Library   Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38025

Microsoft Windows Performance Data Helper Library   Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38043

PowerShell ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38047

PowerShell ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38033

PowerShell ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-30071

Windows Remote Access Connection Manager ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-30079

Windows Remote Access Connection Manager ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38015

Windows Remote Desktop Gateway (RD Gateway) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38071

Windows Remote Desktop Licensing Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38073

Windows Remote Desktop Licensing Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38072

Windows Remote Desktop Licensing Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38099

Windows Remote Desktop Licensing Service ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38065

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37986

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37981

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37987

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-28899

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-26184

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38011

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37984

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37988

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37977

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37978

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37974

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38010

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37989

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37970

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37975

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37972

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37973

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37971

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-37969

Secure Boot Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38013

Microsoft Windows Server Backup ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38064

Windows TCP/IP ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38030

Windows Themes ÆÛƭ©¶´

¸ßΣ

CVE-2024-38085

Windows Graphics Component ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38066

Windows Win32k ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38059

Win32k ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38050

Windows Workstation Service ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38032

Microsoft Xbox Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38078

Xbox Wireless Adapter Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-39684

Github£ºCVE-2024-39684 TenCent   RapidJSON ÌØÈ¨ÌáÉý©¶´

ÖÐΣ

CVE-2024-38517

Github£ºCVE-2024-38517 TenCent   RapidJSON ÌØÈ¨ÌáÉý©¶´

ÖÐΣ

CVE-2024-38020

Microsoft Outlook ÆÛƭ©¶´

ÖÐΣ

 


¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

SQL Server

Windows CoreMessaging

Windows Secure Boot

Windows MultiPoint Services

Microsoft Dynamics

Windows Remote Access Connection Manager

Windows NTLM

Windows Cryptographic Services

.NET and Visual Studio

Microsoft Office SharePoint

Azure Network Watcher

Azure DevOps

Windows iSCSI

Windows Server Backup

Windows Remote Desktop

Windows Message Queuing

Windows Performance Monitor

Microsoft Office Outlook

Microsoft Office

Windows Image Acquisition

Line Printer Daemon Service (LPD)

Windows Themes

Windows Online Certificate Status Protocol (OCSP)

XBox Crypto Graphic Services

Windows PowerShell

Windows Filtering

Windows Kernel

Windows DHCP Server

NDIS

Windows Distributed Transaction Coordinator

Windows Workstation Service

Microsoft Graphics Component

Microsoft Streaming Service

Windows Internet Connection Sharing (ICS)

Microsoft Windows Codecs Library

Windows BitLocker

Windows Win32K - ICOMP

Role: Active Directory Certificate Services; Active Directory Domain Services

Windows Kernel-Mode Drivers

Windows TCP/IP

Windows Win32K - GRFX

Windows Enroll Engine

Windows LockDown Policy (WLDP)

Windows Remote Desktop Licensing Service

Active Directory Federation Services

Role: Windows Hyper-V

Windows Win32 Kernel Subsystem

Azure Kinect SDK

Microsoft Defender for IoT

Microsoft WS-Discovery

Azure CycleCloud

Windows COM Session

Windows Fax and Scan Service

Windows MSHTML Platform

 


Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´  ¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°  ¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüР ¡£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üР ¡£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°  ¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüР ¡£

2024Äê7ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Jul

²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó  ¡£

image.png

Àý1£ºÎ¢Èí©¶´ÁÐ±í£¨Ê¾Àý£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó  ¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°  ¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú  ¡£

3.2 ÁÙʱ´ëÊ©

ÔÝÎÞ  ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ  ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ  ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ  ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È  ¡£

l  ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐÞ¸Ä  ¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Jul

https://blog.qualys.com/vulnerabilities-threat-research/2024/07/09/microsoft-patch-tuesday-july-2024-security-update-review

https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2024-patch-tuesday-fixes-142-flaws-4-zero-days/

 


ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-07-10

Ê×´ÎÐû²¼

 


Îå¡¢¸½Â¼

5.1 ¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ  ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»  ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË  ¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ  ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊÐ  ¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦  ¡£

5.2 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½  ¡£

¹Ø×¢ÎÒÃÇ£º

image.png