¡¾Â©¶´Í¨¸æ¡¿Î¢Èí8Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2024-08-14


Ò»¡¢Â©¶´¸ÅÊö

2024Äê8ÔÂ14ÈÕ£¬¶¶È¦Îª¶Ä¶øÉú¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË8ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË89¸ö©¶´£¨²»°üÂÞ±¾ÔÂÔçЩʱºòÅû¶µÄ Microsoft Edge ©¶´£©£¬Â©¶´ÀàÐÍ°üÂÞÌØȨÌáÉý©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢ鶩¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛƭ©¶´µÈ ¡£

±¾´ÎÄþ¾²¸üÐÂÖаüÂÞ10¸ö0 day©¶´£¬ÆäÖÐ6¸ö±»»ý¼«ÀûÓã¬4¸öÒѾ­¹ûÈ»Åû¶£º

CVE-2024-38178£ºScripting EngineÄÚ´æËð»µÂ©¶´

Windows½Å±¾ÒýÇæÖдæÔÚÀàÐÍ»ìÏý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.5£¬¿Éͨ¹ýÓÕµ¼Ä¿±êÓû§µã»÷ÌØÖÆURLÀ´ÀûÓø鶴£¨¸Ã¶ñÒâÁ´½ÓÐèÔÚInternet Explorer ģʽÏ嵀 Microsoft EdgeÖд¥·¢£©£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓà ¡£

CVE-2024-38193£ºWindows Ancillary Function Driver for WinSockÌØȨÌáÉý©¶´

Windows Ancillary Function Driver for WinSockÖдæÔÚUse-After-Free©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8£¬ÀÖ³ÉÀûÓø鶴¿É½«È¨ÏÞÌáÉýΪSYSTEM ȨÏÞ£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓà ¡£

CVE-2024-38213£ºWindows Mark of the Web Äþ¾²¹¦Ð§Èƹý©¶´

Windows Mark of the Web ÖдæÔÚÄþ¾²¹¦Ð§Èƹý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ6.5£¬ÍþвÕß¿Éͨ¹ýÏòÄ¿±êÓû§·¢ËͶñÒâÎļþ²¢ÓÕʹÓû§´ò¿ªÀ´ÀûÓø鶴£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÈƹýSmartScreenÍþв·À»¤£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓà ¡£

CVE-2024-38106£ºWindows KernelÌØȨÌáÉý©¶´

WindowsÄں˴æÔÚȨÏÞÌáÉý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.0£¬ÀÖ³ÉÀûÓø鶴¿ÉÒÔ»ñµÃSYSTEM ȨÏÞ£¬µ«ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓà ¡£

CVE-2024-38107£ºWindows Power Dependency Coordinator ÌØȨÌáÉý©¶´

Windows µçÔ´ÒÀÀµÐÔЭµ÷Æ÷ÖдæÔÚUse-After-Free©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8£¬ÀÖ³ÉÀûÓø鶴¿É½«È¨ÏÞÌáÉýΪSYSTEM ȨÏÞ£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓà ¡£

CVE-2024-38189£ºMicrosoft Project Ô¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft ProjectÖдæÔÚÊäÈëÑéÖ¤²»Í×£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬¿Éͨ¹ýÓÕµ¼Êܺ¦ÕßÔÚϵͳÉÏ´ò¿ª¶ñÒâµÄ Microsoft Office Project Îļþ£¨Èçͨ¹ý¶ñÒâµç×ÓÓʼþ¡¢WebÍøÕ¾»ò¼´Ê±ÏûÏ¢µÈ£©£¬µ«ÐèÒª¸ÃϵͳÖеġ°×èÖ¹´Ó»¥ÁªÍø»ñÈ¡µÄOfficeÎļþÖÐÔËÐкꡱ¼ÆıÒѱ»½ûÓ㬶øÇÒδÆôÓá°VBAºê֪ͨÉèÖá±£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓà ¡£

CVE-2024-38199£ºWindows Line Printer Daemon (LPD) ServiceÔ¶³Ì´úÂëÖ´ÐЩ¶´

WindowsÐÐʽ´òÓ¡»úÊØ»¤·¨Ê½ (LPD) ·þÎñÖдæÔÚUse-After-Free©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔͨ¹ýÍøÂçÏò¹²ÏíµÄÒ×Êܹ¥»÷µÄWindows Line Printer Daemon (LPD) ·þÎñ·¢ËÍÌØÖƵĴòÓ¡ÈÎÎñ£¬ÀÖ³ÉÀûÓÿÉÄÜÔÚ·þÎñÆ÷Éϵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ ¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡± ¡£ ΢Èí½¨ÒéÓû§²»Òª°²×°»òÆôÓÃWindows Line Printer Daemon (LPD) ·þÎñ£¬Ä¬ÈÏÇé¿öÏÂϵͳÉÏδ°²×°»òÆôÓà LPD£¬×ÔWindows Server 2012 Æð£¬LPD ÒÑÐû²¼ÆúÓà ¡£

CVE-2024-21302£ºWindows Secure Kernel ModeÌØȨÌáÉý©¶´

MicrosoftÖ§³Ö Virtualization Based Security (VBS)µÄ ¶à¸öWindows ϵͳ£¨°üÂÞ Azure ÐéÄâ»ú SKUS µÄ×Ó¼¯£©ÖдæÔÚÌØȨÌáÉý©¶´£¬ÀÖ³ÉÀûÓÿɻñµÃ SYSTEM ȨÏÞ£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ6.7£¬¿ÉÄܵ¼Ö¾ßÓйÜÀíԱȨÏÞµÄÍþвÕßÄܹ»½«µ±Ç°°æ±¾µÄ Windows ϵͳÎļþÌ滻Ϊ¹ýʱ°æ±¾ ¡£Í¨¹ýÀûÓø鶴£¬ÍþвÕß¿ÉÒÔÖØÐÂÒýÈë֮ǰÒÑÐÞ¸´/»º½âµÄ©¶´¡¢ÈƹýVBSÄþ¾²¹¦Ð§²¢ÇÔÈ¡ÊÜVBS ±£»¤µÄÊý¾Ý£¨Windows Downdate ½µ¼¶¹¥»÷£© ¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡± ¡£

CVE-2024-38202£ºWindows Update StackÌØȨÌáÉý©¶´

Windows Update ÖдæÔÚÌØȨÌáÉý©¶´£¬ÀÖ³ÉÀûÓÿɻñµÃ SYSTEM ȨÏÞ£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.3, ¿ÉÄܵ¼Ö¾ßÓлù±¾Óû§È¨ÏÞµÄÍþвÕßÄܹ»ÖØÐÂÒýÈë֮ǰÒÑÐÞ¸´/»º½âµÄ©¶´»òÈƹýVBS µÄijЩ¹¦Ð§£¨Windows Downdate ½µ¼¶¹¥»÷£©£¬ÀÖ³ÉÀûÓø鶴ÐèÒªÓÕµ¼¹ÜÀíÔ±»ò¾ßÓÐίÅÉȨÏÞµÄÓû§Ö´ÐÐϵͳ»¹Ô­£¬´Ó¶ø´¥·¢¸Ã©¶´ ¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡± ¡£Î¢ÈíÕýÔÚ¿ª·¢Äþ¾²¸üÐÂÀ´»º½â¸Ã©¶´£¬µ«Ä¿Ç°ÉÐδÐû²¼ ¡£

CVE-2024-38200£ºMicrosoft Office ÆÛƭ©¶´

Microsoft OfficeÖдæÔÚÐÅϢ鶩¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ6.5£¬ÍþвÕß¿Éͨ¹ýÓÕµ¼Óû§µã»÷¶ñÒâÁ´½Ó£¨Èçͨ¹ýµç×ÓÓʼþ»ò¼´Ê±Í¨Ñ¶ÏûÏ¢£©²¢´ò¿ªÌØÖÆÎļþ£¨ÍйÜÔÚ¶ñÒâÍøÕ¾ÉÏ£©À´ÀûÓø鶴£¬È»ºóÆÈʹ Office ½¨Á¢ÓëÔ¶³Ì¹²ÏíµÄ³öÕ¾Á¬½Ó£¬´ÓÖÐÇÔÈ¡·¢Ë굀 NTLM ¹þÏ££¬µ¼ÖÂÃô¸ÐÐÅϢй¶ ¡£¿Éͨ¹ý½«Óû§Ìí¼Óµ½Êܱ£»¤Óû§Äþ¾²×飬ÒÔ·ÀֹʹÓà NTLM ×÷ΪÉí·ÝÑéÖ¤»úÖÆ£¬»òʹÓÃÍâΧ·À»ðǽ¡¢µ±µØ·À»ðǽºÍ VPN ÉèÖÃ×èÖ¹ TCP 445/SMB ´ÓÍøÂç³öÕ¾£¨Õ⽫×èÖ¹ÏòÔ¶³ÌÎļþ¹²Ïí·¢ËÍ NTLM Éí·ÝÑéÖ¤ÏûÏ¢£©À´»º½â¸Ã©¶´ ¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡± ¡£

±¾´ÎÄþ¾²¸üÐÂÖÐÐÞ¸´µÄ9¸öÑÏÖØ©¶´Îª£º

l  CVE-2024-38063£ºWindows TCP/IP Ô¶³Ì´úÂëÖ´ÐЩ¶´

Windows TCP/IPÖдæÔÚÕûÊýÏÂÒ究´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÏò Windows ¼ÆËã»úÖظ´·¢ËÍ°üÂÞÌØÖÆÊý¾Ý°üµÄ IPv6 Êý¾Ý°ü£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ ¡£Èç¹ûÄ¿±ê¼ÆËã»úÉϽûÓà IPv6£¬ÏµÍ³²»»áÊܵ½Ó°Ïì ¡£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ± ¡£

l  CVE-2024-38160£ºWindows Network VirtualizationÔ¶³Ì´úÂëÖ´ÐЩ¶´

Windows ÍøÂçÐéÄ⻯´æÔڶѻº³åÇøÒç³ö©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.1£¬ÍþвÕß¿ÉÒÔÀûÓà Windows Server 2016 µÄ wnv.sys ×é¼þÖÐδ¾­¼ì²éµÄ·µ»ØÖµÀ´ÀûÓø鶴£¬Í¨¹ýÀûÓÃÄÚ´æÃèÊö·ûÁбí (MDL) µÄÄÚÈÝ£¬¿ÉÄܵ¼ÖÂδ¾­ÊÚȨµÄÄÚ´æдÈ룬ÉõÖÁÊͷŵ±Ç°ÕýÔÚʹÓõÄÓÐЧ¿é£¬´Ó¶øµ¼Ö¿ͻ§»úµ½Ö÷»úÌÓÒÝ£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡± ¡£

l  CVE-2024-38159£ºWindows Network VirtualizationÔ¶³Ì´úÂëÖ´ÐЩ¶´

Windows ÍøÂçÐéÄ⻯´æÔÚUse-After-Free©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.1£¬ÍþвÕß¿ÉÒÔÀûÓà Windows Server 2016 µÄ wnv.sys ×é¼þÖÐδ¾­¼ì²éµÄ·µ»ØÖµÀ´ÀûÓø鶴£¬Í¨¹ýÀûÓÃÄÚ´æÃèÊö·ûÁбí (MDL) µÄÄÚÈÝ£¬¿ÉÄܵ¼ÖÂδ¾­ÊÚȨµÄÄÚ´æдÈ룬ÉõÖÁÊͷŵ±Ç°ÕýÔÚʹÓõÄÓÐЧ¿é£¬´Ó¶øµ¼Ö¿ͻ§»úµ½Ö÷»úÌÓÒÝ£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡± ¡£

l  CVE-2024-38140£ºWindows Reliable Multicast Transport Driver (RMCAST) Ô¶³Ì´úÂëÖ´ÐЩ¶´

Windows ¿É¿¿¶à²¥´«ÊäÇý¶¯·¨Ê½ (RMCAST) ´æÔÚUse-After-Free©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔͨ¹ýÏò·þÎñÆ÷É쵀 Windows Pragmatic General Multicast (PGM) ¿ª·ÅÌ×½Ó×Ö·¢ËÍÌØÖƵÄÊý¾Ý°üÀ´ÀûÓø鶴£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ ¡£¸Ã©¶´½öÔÚÓз¨Ê½¼àÌýPGM¶Ë¿ÚµÄÇé¿öϲſɱ»ÀûÓã¬Èç¹ûPGMÒÑ°²×°»òÆôÓ㬵«Ã»Óз¨Ê½×÷Ϊ½ÓÊÕÆ÷Ö÷¶¯¼àÌý£¬Ôò¸Ã©¶´²»Ðб»ÀûÓà ¡£²»½¨Ò齫 PGM ½ÓÊÕÆ÷̻¶ÔÚ¹«¹²»¥ÁªÍøÉÏ£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡± ¡£

l  CVE-2024-38109£ºAzure Health Bot ÌØȨÌáÉý©¶´

l  CVE-2024-38206£ºMicrosoft Copilot Studio ÐÅϢ鶩¶´

l  CVE-2024-38166£ºMicrosoft Dynamics 365 ¿çÕ¾½Å±¾Â©¶´

l  CVE-2022-3775£ºRedhat-CVE-2022-3775 grub2 - äÖȾijЩ Unicode ÐòÁÐʱ»ùÓڶѵÄÔ½½çдÈë

l  CVE-2023-40547£ºRedhat£ºCVE-2023-40547 Shim - HTTP Æô¶¯Ö§³ÖÖÐµÄ RCE ¿ÉÄܵ¼ÖÂÄþ¾²Æô¶¯Èƹý

³ýCVE-2024-38063Í⣬΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ©¶´»¹°üÂÞ£º

l  CVE-2024-38133£ºWindows ÄÚºËÌØȨÌáÉý©¶´

l  CVE-2024-38148£ºWindows Secure Channel¾Ü¾ø·þÎñ©¶´

l  CVE-2024-38163£ºWindows Update StackÌØȨÌáÉý©¶´

l  CVE-2024-38198£ºWindows Print SpoolerÌØȨÌáÉý©¶´

l  CVE-2024-38196£ºWindows Common Log File System DriverÌØȨÌáÉý©¶´

l  CVE-2024-38141£ºWindows Ancillary Function Driver for WinSockÌØȨÌáÉý©¶´

l  CVE-2024-38125/ CVE-2024-38144£ºKernel Streaming WOW Thunk Service DriverÌØȨÌáÉý©¶´

l  CVE-2024-38147/ CVE-2024-38150£ºMicrosoft DWM Core LibraryÌØȨÌáÉý©¶´

΢Èí8Ô¸üÐÂÉæ¼°µÄ²¿ÃÅ©¶´ÁбíÈçÏ£¬ÆäÖв»°üÂÞChrome·Ö·¢µÄ9¸öMicrosoft Edge (Chromium-based)©¶´£º

CVE ID

CVE ±êÌâ

ÑÏÖØÐÔ

CVE-2024-38109

Azure   Health Bot ÌØȨÌáÉý©¶´

ÑÏÖØ

CVE-2024-38206

Microsoft   Copilot Studio ÐÅϢ鶩¶´

ÑÏÖØ

CVE-2024-38166

Microsoft   Dynamics 365 ¿çÕ¾½Å±¾Â©¶´

ÑÏÖØ

CVE-2024-38140

Windows   Reliable Multicast Transport Driver (RMCAST) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38160

Windows   Network VirtualizationÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38159

Windows   Network VirtualizationÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2022-3775

Redhat£ºCVE-2022-3775 grub2 - äÖȾijЩ Unicode ÐòÁÐʱ»ùÓڶѵÄÔ½½çдÈë

ÑÏÖØ

CVE-2023-40547

Redhat£ºCVE-2023-40547 Shim - HTTP Æô¶¯Ö§³ÖÖÐµÄ RCE ¿ÉÄܵ¼ÖÂÄþ¾²Æô¶¯Èƹý

ÑÏÖØ

CVE-2024-38063

Windows   TCP/IP Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38168

.NET ºÍ Visual Studio ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38167

.NET ºÍ Visual Studio ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38162

Azure   Connected Machine Agent ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38098

Azure   Connected Machine Agent ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38195

Azure   CycleCloud Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38158

Azure IoT   SDK Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38157

Azure IoT   SDK Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38108

Azure   Stack Hub ÆÛƭ©¶´

¸ßΣ

CVE-2024-38201

Azure   Stack Hub ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38199

Windows   Line Printer Daemon (LPD) ServiceÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38123

Windows À¶ÑÀÇý¶¯·¨Ê½ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38211

Microsoft   Dynamics 365£¨on-premises£©¿çÕ¾µã½Å±¾Â©¶´

¸ßΣ

CVE-2024-38218

Microsoft   Edge£¨»ùÓÚ HTML£©ÄÚ´æËð»µÂ©¶´

¸ßΣ

CVE-2024-38118

Microsoft   Local Security Authority (LSA) Server ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38122

Microsoft   Local Security Authority (LSA) Server ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38200

Microsoft   Office ÆÛƭ©¶´

¸ßΣ

CVE-2024-38084

Microsoft   OfficePlus ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38172

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38170

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38173

Microsoft   Outlook Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38171

Microsoft   PowerPoint Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38189

Microsoft   Project Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38169

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38134

Kernel   Streaming WOW Thunk Service Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38144

Kernel   Streaming WOW Thunk Service Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38125

Kernel   Streaming WOW Thunk Service Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38197

Microsoft   Teams for iOS ÆÛƭ©¶´

¸ßΣ

CVE-2024-38152

Windows   OLE Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37968

Windows   DNS ÆÛƭ©¶´

¸ßΣ

CVE-2024-38141

Windows   Ancillary Function Driver for WinSock ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38193

Windows   Ancillary Function Driver for WinSock ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38177

Windows   App Installer ÆÛƭ©¶´

¸ßΣ

CVE-2024-38131

Clipboard   Virtual Channel Extension Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38215

Windows   Cloud Files Mini Filter Çý¶¯·¨Ê½ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38196

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38165

Windows ѹËõÎļþ¼Ð¸Ä¶¯Â©¶´

¸ßΣ

CVE-2024-38138

Windows ²¿Êð·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38150

Windows   DWM ºËÐÄ¿âÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38147

Microsoft   DWM ºËÐÄ¿âÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38223

Windows   Initial Machine Configuration ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38114

Windows IP   ·ÓɹÜÀíµ¥ÔªÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38116

Windows IP   ·ÓɹÜÀíµ¥ÔªÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38115

Windows IP   ·ÓɹÜÀíµ¥ÔªÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29995

Windows   Kerberos ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38151

Windows ÄÚºËÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38133

Windows ÄÚºËÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38127

Windows   Hyper-V ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38153

Windows ÄÚºËÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38106

Windows ÄÚºËÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38187

Windows ÄÚºËģʽÇý¶¯·¨Ê½ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38191

ÄÚºËÁ÷·þÎñÇý¶¯·¨Ê½ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38184

Windows ÄÚºËģʽÇý¶¯·¨Ê½ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38186

Windows ÄÚºËģʽÇý¶¯·¨Ê½ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38185

Windows ÄÚºËģʽÇý¶¯·¨Ê½ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38146

Windows   Layer-2 Bridge Network Driver ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38145

Windows   Layer-3 Bridge Network Driver ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38161

Windows   Mobile Broadband Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38132

Windows ÍøÂçµØַת»» (NAT) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38126

Windows ÍøÂçµØַת»» (NAT) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38135

Windows µ¯ÐÔÎļþϵͳ (ReFS) ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38117

NTFS ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38107

Windows   Power Dependency Coordinator ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38198

Windows   Print Spooler ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38137

Windows   Resource Manager PSM Service Extension ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38136

Windows   Resource Manager PSM Service Extension ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38130

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38128

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38154

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38121

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38214

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38120

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38178

Scripting   Engine ÄÚ´æËð»µÂ©¶´

¸ßΣ

CVE-2022-2601

Redhat£ºCVE-2022-2601 grub2 - grub_font_construct_glyph() ÖеĻº³åÇøÒç³ö¿ÉÄܵ¼ÖÂÔ½½çдÈë²¢¿ÉÄÜÈƹýÄþ¾²Æô¶¯

¸ßΣ

CVE-2024-21302

Windows Äþ¾²ÄÚºËģʽÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38142

Windows Äþ¾²ÄÚºËģʽÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38155

Security   Center Broker ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-38180

Windows   SmartScreen Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38148

Windows   Secure Channel ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38202

Windows   Update Stack ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38163

Windows   Update Stack ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38143

Windows   WLAN AutoConfig ·þÎñÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-38213

Windows   Mark of the Web Äþ¾²¹¦Ð§Èƹý©¶´

ÖÐΣ

CVE-2024-38219

Microsoft   Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÖÐΣ

CVE-2024-38222

Microsoft   Edge£¨»ùÓÚ Chromium£©ÐÅϢ鶩¶´

δ֪

 

¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

Windows Secure Kernel Mode

Windows Kerberos

Microsoft Windows DNS

Windows TCP/IP

Microsoft Office

Azure Connected Machine Agent

Windows Kernel

Windows Power Dependency Coordinator

Azure Stack

Azure Health Bot

Windows IP Routing Management Snapin

Windows NTFS

Microsoft Local Security Authority Server (lsasrv)

Windows Routing and Remote Access Service (RRAS)

Microsoft Bluetooth Driver

Microsoft Streaming Service

Windows Network Address Translation (NAT)

Windows Clipboard Virtual Channel Extension

Windows NT OS Kernel

Windows Resource Manager

Windows Deployment Services

Reliable Multicast Transport Driver (RMCAST)

Windows Ancillary Function Driver for WinSock

Windows WLAN Auto Config Service

Windows Layer-2 Bridge Network Driver

Windows DWM Core Library

Windows Transport Security Layer (TLS)

Microsoft WDAC OLE DB provider for SQL

Windows Security Center

Azure IoT SDK

Windows Network Virtualization

Windows Mobile Broadband

Windows Update Stack

Windows Compressed Folder

Microsoft Dynamics

.NET and Visual Studio

Microsoft Office Visio

Microsoft Office Excel

Microsoft Office PowerPoint

Microsoft Office Outlook

Windows App Installer

Windows Scripting

Windows SmartScreen

Windows Kernel-Mode Drivers

Microsoft Office Project

Azure CycleCloud

Windows Common Log File System Driver

Microsoft Teams

Windows Print Spooler Components

Line Printer Daemon Service (LPD)

Microsoft Copilot Studio

Windows Mark of the Web (MOTW)

Windows Cloud Files Mini Filter Driver

Microsoft Edge (Chromium-based)

Windows Initial Machine Configuration

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´ ¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×° ¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüР¡£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üР¡£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔز¢°²×° ¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüР¡£

2024Äê8ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Aug

²¹¶¡ÏÂÔØʾÀý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó ¡£

image.png

Àý1£ºÎ¢Èí©¶´ÁÐ±í£¨Ê¾Àý£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó ¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý

3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×° ¡£

image.png

Àý3£º²¹¶¡ÏÂÔؽçÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú ¡£

3.2 ÁÙʱ´ëÊ©

ÔÝÎÞ ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼Æı£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È ¡£

l  ÆôÓÃÇ¿ÃÜÂë¼Æı²¢ÉèÖÃΪ¶¨ÆÚÐÞ¸Ä ¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Aug

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38063

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38202

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-08-14

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼

5.1 ¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò» ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË ¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊÐ ¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦ ¡£

5.2 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½ ¡£

¹Ø×¢ÎÒÃÇ£º

image.png