¡¾Â©¶´Í¨¸æ¡¿Î¢Èí7Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2023-07-12Ò»¡¢Â©¶´¸ÅÊö
2023Äê7ÔÂ11ÈÕ£¬Î¢ÈíÐû²¼ÁË7ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË132¸ö©¶´£¬ÆäÖаüÂÞ6¸öÒѱ»ÀûÓõÄ©¶´¡¢37¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬ÒÔ¼°9¸öÆÀ¼¶ÎªÑÏÖØµÄ©¶´¡£
±¾´ÎÐÞ¸´µÄ©¶´ÖУ¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´ºÍÆÛÆÂ©¶´µÈ¡£
΢Èí±¾´Î¹²ÐÞ¸´ÁË6¸öÒѱ»ÀûÓõÄ©¶´£¬ÆäÖÐCVE-2023-36884Òѱ»¹ûÈ»Åû¶£¬ÏêÇéÈçÏ£º
CVE-2023-32046£ºWindows MSHTML PlatformȨÏÞÌáÉý©¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.8£¬ÀûÓøÃ©¶´ÐèÒªÓû§½»»¥£¬¿ÉÒÔͨ¹ýµç×ÓÓʼþ»ò¶ñÒâÍøÕ¾´ò¿ªÌØÖÆÎļþÀ´ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓÿɻñµÃÔËÐÐÊÜÓ°ÏìÓ¦Ó÷¨Ê½µÄÓû§µÄȨÏÞ¡£Ä¿Ç°¸Ã©¶´ÒÑ·¢ÏÖ±»ÀûÓá£
CVE-2023-32049£ºWindows SmartScreenÄþ¾²¹¦Ð§Èƹý©¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬ÀûÓøÃ©¶´ÐèÒªÓû§½»»¥£¬¿ÉÒÔͨ¹ýÓÕµ¼Óû§µ¥»÷ÌØÖÆURLÀ´Ö´Ðй¥»÷£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÈÆ¹ý¡°´ò¿ªÎļþ-Äþ¾²¾¯¸æ¡±Ìáʾ¡£Ä¿Ç°¸Ã©¶´ÒÑ·¢ÏÖ±»ÀûÓá£
CVE-2023-36874£ºWindows Error Reporting ServiceÌØÈ¨ÌáÉý©¶´
¸Ã©¶´´æÔÚÓÚWindows ´íÎó³ÂËß·þÎñÖУ¬ÆäCVSSv3ÆÀ·ÖΪ7.8£¬¶ÔÄ¿±ê¼ÆËã»ú¾ßÓе±µØ·ÃÎÊȨÏÞÇÒÄܹ»ÔÚ¼ÆËã»úÉÏ´´½¨Îļþ¼ÐºÍÐÔÄܸú×Ù£¬²¢¾ßÓÐÆÕͨÓû§Ä¬ÈÏȨÏÞµÄÍþвÕß¿ÉÀûÓøÃ©¶´»ñµÃ¹ÜÀíԱȨÏÞ¡£Ä¿Ç°¸Ã©¶´ÒÑ·¢ÏÖ±»ÀûÓá£
CVE-2023-36884 £ºOffice ºÍ Windows HTML Ô¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´Ó°ÏìÁ˶à¸öWindowsºÍOffice²úÎÆäCVSSv3ÆÀ·ÖΪ8.3£¬ÍþвÕß¿ÉÒÔ´´½¨ÌØÖÆµÄ Microsoft OfficeÎĵµ²¢ÓÕµ¼Êܺ¦Õß´ò¿ª¶ñÒâÎļþ£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔÚÊܺ¦ÕßµÄÉÏÏÂÎÄÖÐÔ¶³ÌÖ´ÐдúÂë¡£¸Ã©¶´ÒѾ¹ûÈ»Åû¶ÇÒÒÑ·¢ÏÖ±»ÀûÓã¬Ä¿Ç°Î¢ÈíÔÝδÐû²¼¸Ã©¶´µÄÄþ¾²¸üУ¬µ«ÒÑÐû²¼Á˸é¶´µÄ»º½â´ëÊ©¡£
CVE-2023-35311 £ºMicrosoft Outlook Äþ¾²¹¦Ð§Èƹý©¶´
¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ8.8£¬ÀûÓøÃ©¶´ÐèÒªÓû§½»»¥£¬¿ÉÒÔͨ¹ýÓÕµ¼Óû§µ¥»÷ÌØÖÆURLÀ´Ö´Ðй¥»÷£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÒÔÈÆ¹ý Microsoft Outlook Äþ¾²Í¨ÖªÌáʾ¡£Ä¿Ç°¸Ã©¶´ÒÑ·¢ÏÖ±»ÀûÓá£
ADV230001£º¹ØÓÚ¶ñÒâʹÓà Microsoft Ç©ÃûÇý¶¯·¨Ê½µÄÖ¸ÄÏ
΢Èí×î½ü»ñϤ£¬¾Î¢ÈíWindows Ó²¼þ¿ª·¢ÈËÔ±¼Æ»®£¨MWHDP£©ÈÏÖ¤µÄÇý¶¯·¨Ê½ÔÚºóÀûÓûÖб»¶ñÒâʹÓá£ÔÚÕâЩ¹¥»÷ÖУ¬¹¥»÷ÕßÔÚʹÓÃÇý¶¯·¨Ê½Ö®Ç°¾ÍÒѾ»ñµÃÁËÊÜѬȾϵͳµÄ¹ÜÀíȨÏÞ£¬ÊÓ²ìÏÔʾ£¬Î¢ÈíºÏ×÷»ï°éÖÐÐÄ (MPC) µÄ¶à¸ö¿ª·¢ÕßÕÊ»§ÕýÔÚÌá½»¶ñÒâÇý¶¯·¨Ê½ÒÔ»ñȡ΢ÈíÇ©Ãû£¬Ä¿Ç°Î¢ÈíÒѾµõÏú/½ûÓÃÁËÀÄÓà Windows ¼ÆÄ±Â©¶´°²×°¶ñÒâÄÚºËģʽÇý¶¯·¨Ê½µÄ´úÂëÇ©ÃûÖ¤ÊéºÍ¿ª·¢ÈËÔ±ÕÊ»§¡£
΢Èí7Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º
CVE-ID | CVE±êÌâ | ÑÏÖØÐÔ |
CVE-2023-33160 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-33157 | Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-35315 | Windows Layer-2 Bridge Network Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-32057 | Microsoft ÏûÏ¢ÐÐÁÐÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-35297 | Windows Pragmatic ͨÓÃ×é²¥ (PGM) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-35352 | Windows Ô¶³Ì×ÀÃæÄþ¾²¹¦Ð§Èƹý©¶´ | ÑÏÖØ |
CVE-2023-35367 | Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-35366 | Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-35365 | Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2023-33127 | .NET ºÍ Visual Studio ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-33170 | ASP.NET ºÍ Visual Studio Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-36871 | Azure Active Directory Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-35348 | Active Directory ÁªºÏÉí·ÝÑéÖ¤·þÎñÄþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-33171 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾½Å±¾Â©¶´ | ¸ßΣ |
CVE-2023-35335 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾½Å±¾Â©¶´ | ¸ßΣ |
CVE-2023-33149 | Microsoft Office Graphics Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-21756 | Windows Win32k ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35333 | MediaWiki PandocUpload À©Õ¹Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-33148 | Microsoft Office ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2023-36884 | Office ºÍ Windows HTML Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-33150 | Microsoft Office Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-33152 | Microsoft ActiveX Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-33158 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-33161 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-33162 | Microsoft Excel ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-33151 | Microsoft Outlook ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-33153 | Microsoft Outlook Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-35311 | Microsoft Outlook Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-33134 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-33165 | Microsoft SharePoint Server Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-33159 | Microsoft SharePoint Server ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-32052 | Microsoft Power Apps ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-32085 | Microsoft PostScript and PCL6 Class Printer Driver ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-35302 | Microsoft PostScript and PCL6 Class Printer Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-35296 | Microsoft PostScript and PCL6 Class Printer Driver ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-35324 | Microsoft PostScript and PCL6 Class Printer Driver ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-32040 | Microsoft PostScript and PCL6 Class Printer Driver ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-35306 | Microsoft PostScript and PCL6 Class Printer Driver ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-32039 | Microsoft PostScript and PCL6 Class Printer Driver ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-35303 | USB Audio Class System Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-36872 | VP9 Video Extensions ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-32051 | Raw Image Extension Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-35373 | Mono Authenticode ÑéÖ¤ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-35374 | Paint 3D Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-32047 | Paint 3D Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-35310 | Windows DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-35346 | Windows DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-35345 | Windows DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-35344 | Windows DNS Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-36868 | Azure Service Fabric on Windows ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-36867 | Visual Studio Code GitHub Pull Requests and Issues Extension Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-35351 | Windows Active Directory Ö¤Êé·þÎñ (AD CS) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-35350 | Windows Active Directory Ö¤Êé·þÎñ (AD CS) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-32055 | Active Template Library ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2023-29347 | Windows Admin Center ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2023-35347 | Microsoft °²×°·þÎñȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35329 | Windows Éí·ÝÑéÖ¤¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-35326 | Windows CDPÓû§×é¼þÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-35362 | Windows Clip ·þÎñÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-33155 | Windows Cloud Files Mini Filter Driver ÐòÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-32033 | Microsoft Failover Cluster Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-35340 | Windows CNG ÃÜÔ¿¸ôÀë·þÎñÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35299 | Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35320 | Connected User Experiences and Telemetry ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35353 | Connected User Experiences and Telemetry ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35339 | Windows CryptoAPI ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-33174 | Windows ¼ÓÃÜÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-33156 | Microsoft Defender ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35322 | Windows ²¿Êð·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-35321 | Windows ²¿Êð·þÎñ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
ADV230002 | Microsoft ½â¾öÇ÷ÊÆ¿Æ¼¼ EFI Ä£¿éÖеÄÄþ¾²¹¦Ð§ÈƹýÎÊÌâµÄÖ¸ÄÏ | ¸ßΣ |
CVE-2023-36874 | Windows ´íÎó³ÂËß·þÎñÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-32083 | Microsoft Failover Cluster ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-35343 | Windows µØÀí¶¨Î»·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-32084 | HTTP.sys ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-35298 | HTTP.sys ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-35342 | Windows Image Acquisition ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2023-32053 | Windows Installer ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2023-32050 | Windows Installer ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35304 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35363 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35305 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35356 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35357 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35358 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-32037 | Windows Layer-2 Bridge Network Driver ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-35331 | Windows Local Security Authority (LSA) ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-35341 | Microsoft DirectMusic ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-35309 | Microsoft ÏûÏ¢ÐÐÁÐÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-32045 | Microsoft ÏûÏ¢ÐÐÁоܾø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-32044 | Microsoft ÏûÏ¢ÐÐÁоܾø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-32046 | Windows MSHTML ƽ̨ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35336 | Windows MSHTML ƽ̨Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-35308 | Windows MSHTML ƽ̨Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-21526 | Windows Netlogon ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-33163 | Windows ÍøÂç¸ºÔØÆ½ºâÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-35361 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35364 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35360 | Windows ÄÚºËÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-32038 | Microsoft ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-32042 | OLE×Ô¶¯»¯ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-35323 | Windows OLEÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-35313 | Windows ÔÚÏßÖ¤Êé״̬ÐÒé (OCSP) SnapIn Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-33154 | Windows ·ÖÇø¹ÜÀíÇý¶¯·¨Ê½È¨ÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35338 | Windows ¶ÔµÈÃû³Æ½âÎöÐÒé¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-35325 | Windows ´òÓ¡ºǫ́´¦Ö÷¨Ê½ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-32043 | Windows Ô¶³Ì×ÀÃæÄþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-35332 | Windows Ô¶³Ì×ÀÃæÐÒéÄþ¾²¹¦Ð§Èƹý | ¸ßΣ |
CVE-2023-35300 | Remote Procedure Call Runtime Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2023-33168 | Remote Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-33173 | Remote Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-33172 | Remote Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-32035 | Remote Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-33166 | Remote Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-32034 | Remote Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-33167 | Remote Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-33169 | Remote Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-35318 | Remote Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-33164 | Remote Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-35319 | Remote Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-35316 | Remote Procedure Call Runtime ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-35314 | Remote Procedure Call Runtime ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-35317 | Windows Server Update Service (WSUS) ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-32056 | Windows Server Update Service (WSUS) ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-32049 | Windows SmartScreenÄþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2023-35330 | Windows À©Õ¹ÐÉܾ̾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2023-35328 | Windows ÊÂÎñ¹ÜÀíÆ÷ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-32041 | Windows Update Orchestrator·þÎñÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2023-35312 | Microsoft VOLSNAP.SYS ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-32054 | Volume Shadow Copy ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2023-35337 | Win32k ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
ADV230001 | ¹ØÓÚ¶ñÒâʹÓà Microsoft Ç©ÃûÇý¶¯·¨Ê½µÄÖ¸ÄÏ | ÎÞ |
¶þ¡¢Ó°Ï췶Χ
ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º
Windows Certificates
Windows EFI Partition
Windows Netlogon
Microsoft Graphics Component
Windows Admin Center
Windows Cluster Server
Windows Remote Procedure Call
Windows Layer 2 Tunneling Protocol
Windows ODBC Driver
Microsoft Printer Drivers
Windows Update Orchestrator Service
Windows OLE
Windows Remote Desktop
Windows Message Queuing
Windows MSHTML Platform
Paint 3D
Windows SmartScreen
Windows Installer
Microsoft Windows Codecs Library
Microsoft Power Apps
Windows Volume Shadow Copy
Windows Active Template Library
Windows Server Update Service
Windows Failover Cluster
Windows HTTP.sys
.NET and Visual Studio
Microsoft Office SharePoint
Microsoft Office
Microsoft Office Outlook
Microsoft Office Access
Windows Partition Management Driver
Windows Cloud Files Mini Filter Driver
Windows Defender
Microsoft Office Excel
Windows Network Load Balancing
ASP.NET and .NET
Microsoft Dynamics
Windows Cryptographic Services
Windows PGM
Windows Common Log File System Driver
Windows Kernel
Role: DNS Server
Windows VOLSNAP.SYS
Windows Online Certificate Status Protocol (OCSP) SnapIn
Windows Layer-2 Bridge Network Driver
Windows Connected User Experiences and Telemetry
Windows Deployment Services
Windows Print Spooler Components
Windows CDP User Components
Windows Transaction Manager
Windows Authentication Methods
Windows SPNEGO Extended Negotiation
Windows Local Security Authority (LSA)
Microsoft Media-Wiki Extensions
Windows Win32K
Windows Peer Name Resolution Protocol
Windows CryptoAPI
Windows CNG Key Isolation Service
Windows Media
Windows Image Acquisition
Windows Geolocation Service
Windows App Store
Azure Active Directory
Windows Active Directory Certificate Services
Windows NT OS Kernel
Windows Clip Service
Windows Routing and Remote Access Service (RRAS)
Mono Authenticode
Visual Studio Code
Service Fabric
Windows Error Reporting
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£
£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2023Äê7ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2023-Jul
²¹¶¡ÏÂÔØÊ¾Àý£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2022Äê2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£
Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£
3.2 ÁÙʱ´ëÊ©
Õë¶ÔCVE-2023-36884£¬Î¢ÈíÒѾÐû²¼ÁËÏà¹Ø»º½â´ëÊ©£¬¿É²Î¿¼£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884
https://www.microsoft.com/en-us/security/blog/2023/07/11/storm-0978-attacks-reveal-financial-and-espionage-motives/
¹ØÓÚ¶ñÒâʹÓà Microsoft Ç©ÃûÇý¶¯·¨Ê½µÄÖ¸ÄÏ£¬¸ü¶àÐÅÏ¢¿É²Î¿¼£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/ADV230001
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2023-Jul
https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2023-patch-tuesday-warns-of-6-zero-days-132-flaws/
https://www.bleepingcomputer.com/news/security/microsoft-unpatched-office-zero-day-exploited-in-nato-summit-attacks/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-07-12 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¶«Éƽ̨¼ò½é
¶«Éƽ̨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«Éƽ̨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶«Éƽ̨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
5.2 ¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º