¡¾Â©¶´Í¨¸æ¡¿Î¢Èí1Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2024-01-10Ò»¡¢Â©¶´¸ÅÊö
2024Äê1ÔÂ9ÈÕ£¬Î¢ÈíÐû²¼ÁË1ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË49¸ö©¶´£¨²»°üÂÞ1ÔÂ5ÈÕÐÞ¸´µÄ4¸öMicrosoft Edge©¶´£©£¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛÆÂ©¶´µÈ¡£
±¾´ÎÄþ¾²¸üÐÂÖÐûÓб»»ý¼«ÀûÓûò¹ûÈ»Åû¶µÄ©¶´£¬ÆäÖÐÆÀ¼¶ÎªÑÏÖØµÄ2¸ö©¶´°üÂÞ£º
CVE-2024-20674£ºWindows Kerberos Äþ¾²¹¦Ð§Èƹý©¶´£¨ÑÏÖØ£©
¶ÔÊÜÏÞÍøÂçÓµÓзÃÎÊȨÏÞµÄÍþвÕß¿Éͨ¹ý½¨Á¢machine-in-the-middle (MITM£¬Öмä»ú)¹¥»÷»òÆäËüµ±µØÍøÂçÆÛƼ¼ÊõÀ´ÀûÓøÃ©¶´£¬È»ºóÏò¿Í»§¶ËÊܺ¦»úÆ÷·¢ËͶñÒâKerberos ÏûÏ¢ÒÔð³äKerberosÉí·ÝÑéÖ¤·þÎñÆ÷£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼ÖÂÈÆ¹ýÉí·ÝÑéÖ¤¹¦Ð§¡£¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.0£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϴ󡱡£
CVE-2024-20700£ºWindows Hyper-V Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨¸ßΣ£©
¸Ã©¶´µÄ¹¥»÷ÅÓ´ó¶È½Ï¸ß£¬ÀÖ³ÉÀûÓøÃ©¶´ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬ÇÒÐèÒª»ñµÃ¶ÔÊÜÏÞÍøÂçµÄ·ÃÎÊȨÏÞ£¬ÆäCVSSÆÀ·ÖΪ7.5£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£
ÆäËüÖµµÃ¹Ø×¢µÄ©¶´»¹°üÂÞµ«²»ÏÞÓÚ£º
CVE-2024-21307£ºRemote Desktop ClientÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨¸ßΣ£©
¸Ã©¶´µÄ¹¥»÷ÅÓ´ó¶È½Ï¸ß£¬ÀÖ³ÉÀûÓô˸ö´ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬ÇÒÐèÒªÓû§½»»¥£¬Î´ÊÚȨÍþвÕß±ØÐëÆÚ´ýÓû§Æô¶¯Á¬½Ó¡£¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.5£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϴ󡱡£
CVE-2024-21318£ºMicrosoft SharePoint ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨¸ßΣ£©
¾¹ýÉí·ÝÑéÖ¤µÄÍþвÕߣ¨ÖÁÉÙÊÇÍøÕ¾ËùÓÐÕߣ©¿ÉÀûÓøÃ©¶´×¢ÈëÈÎÒâ´úÂ룬²¢ÔÚ SharePoint Server µÄÉÏÏÂÎÄÖÐÖ´ÐиôúÂë¡£¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϴ󡱡£
³ýCVE-2024-20674¡¢CVE-2024-21307ºÍCVE-2024-21318Í⣬΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖС°±»ÀûÓõĿÉÄÜÐԽϴ󡱵Ä©¶´»¹°üÂÞ£º
CVE-2024-20652£ºWindows HTMLƽ̨Äþ¾²¹¦Ð§Èƹý©¶´£¨¸ßΣ£©
CVE-2024-20653£ºMicrosoft Common Log File SystemÌØÈ¨ÌáÉý©¶´£¨¸ßΣ£©
CVE-2024-20683£ºWin32k ÌØÈ¨ÌáÉý©¶´£¨¸ßΣ£©
CVE-2024-20686£ºWin32k ÌØÈ¨ÌáÉý©¶´£¨¸ßΣ£©
CVE-2024-20698£ºWindows ÄÚºËÌØÈ¨ÌáÉý©¶´£¨¸ßΣ£©
CVE-2024-21310£ºWindows Cloud Files Mini Filter DriverÌØÈ¨ÌáÉý©¶´£¨¸ßΣ£©
΢Èí1Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑÏÖØÐÔ |
CVE-2024-20674 | Windows Kerberos Äþ¾²¹¦Ð§Èƹý©¶´ | ÑÏÖØ |
CVE-2024-20700 | Windows Hyper-V Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2024-0057 | NET¡¢.NET Framework ºÍ Visual Studio Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-20672 | .NET Core ºÍ Visual Studio ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-21312 | .NET Framework ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-20676 | Azure Storage Mover Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21306 | Microsoft Bluetooth Driver ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2024-21325 | Microsoft Printer Metadata Troubleshooter Tool Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21319 | Microsoft Identity ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-20677 | Microsoft Office Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21318 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-20658 | Microsoft Virtual Hard Disk ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21307 | Remote Desktop Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-0056 | Microsoft.Data.SqlClient ºÍ System.Data.SqlClient SQLÊý¾ÝÌṩ·¨Ê½Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2022-35737 | MITRE£ºCVE-2022-35737 SQLite ÔÊÐíÊý×é½çÏÞÒç³ö | ¸ßΣ |
CVE-2024-21305 | Hypervisor-Protected Code Integrity (HVCI) Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-20656 | Visual Studio ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-20687 | Microsoft AllJoyn API ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-20666 | BitLocker Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-21310 | Windows Cloud Files Mini Filter Driver ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-20694 | Windows CoreMessaging ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2024-20653 | Microsoft Common Log File System ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-20682 | Windows Cryptographic Services Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-21311 | Windows Cryptographic Services ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2024-20657 | Windows Group Policy ȨÏÞÌáÉý©¶´ | ¸ßΣ |
CVE-2024-20699 | Windows Hyper-V ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-20698 | Windows Kernel ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21309 | Windows Kernel-Mode Driver ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-20697 | Windows Libarchive Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-20696 | Windows Libarchive Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-20692 | Microsoft Local Security Authority Subsystem Service ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2024-20660 | Microsoft Message Queuing ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2024-20664 | Microsoft Message Queuing ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2024-20680 | Windows Message Queuing Client (MSMQC) ÐÅϢй¶ | ¸ßΣ |
CVE-2024-20663 | Windows Message Queuing Client (MSMQC) ÐÅϢй¶ | ¸ßΣ |
CVE-2024-21314 | Microsoft Message Queuing ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2024-20661 | Microsoft Message Queuing ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-20690 | Windows Nearby Sharing ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2024-20654 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-20662 | Windows Online Certificate Status Protocol (OCSP) ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2024-20655 | Microsoft Online Certificate Status Protocol (OCSP) Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-20652 | Windows HTML Platforms Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-21316 | Windows Server Key Distribution Äþ¾²¹¦Ð§Èƹý | ¸ßΣ |
CVE-2024-20681 | Windows Subsystem for Linux ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-21313 | Windows TCP/IP ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2024-20691 | Windows Themes ÐÅϢй¶©¶´ | ¸ßΣ |
CVE-2024-21320 | Windows Themes ÆÛÆÂ©¶´ | ¸ßΣ |
CVE-2024-20686 | Win32k ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-20683 | Win32k ÌØÈ¨ÌáÉý©¶´ | ¸ßΣ |
CVE-2024-0222 | Chromium£ºCVE-2024-0222 ÔÚ ANGLE ÖÐÊͷźóʹÓà | δ֪ |
CVE-2024-0223 | Chromium£ºCVE-2024-0223 ANGLE ¶Ñ»º³åÇøÒç³ö | δ֪ |
CVE-2024-0224 | Chromium£ºCVE-2024-0224 ÔÚ WebAudio ÖÐÊͷźóʹÓà | δ֪ |
CVE-2024-0225 | Chromium£ºCVE-2024-0225 ÔÚ WebGPU ÖÐÊͷźóʹÓà | δ֪ |
¶þ¡¢Ó°Ï췶Χ
ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º
SQL Server
.NET and Visual Studio
Windows Scripting
Windows Common Log File System Driver
Windows ODBC Driver
Windows Online Certificate Status Protocol (OCSP) SnapIn
Visual Studio
Windows Group Policy
Microsoft Virtual Hard Drive
Windows Message Queuing
Windows BitLocker
.NET Core & Visual Studio
Windows Authentication Methods
Azure Storage Mover
Microsoft Office
Windows Subsystem for Linux
Windows Cryptographic Services
Windows Win32K
Windows Win32 Kernel Subsystem
Windows AllJoyn API
Windows Nearby Sharing
Windows Themes
Windows Local Security Authority Subsystem Service (LSASS)
Windows Collaborative Translation Framework
Windows Libarchive
Windows Kernel
Windows Hyper-V
Unified Extensible Firmware Interface
Microsoft Bluetooth Driver
Remote Desktop Client
Windows Kernel-Mode Drivers
Windows Cloud Files Mini Filter Driver
.NET Framework
Windows TCP/IP
Windows Server Key Distribution Service
Microsoft Office SharePoint
Microsoft Identity Services
Microsoft Devices
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£
£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2024Äê1ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2024-Jan
²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2022Äê2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£
Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£
3.2 ÁÙʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Jan
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-20674
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-01-10 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¶«Éƽ̨¼ò½é
¶«Éƽ̨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«Éƽ̨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶«Éƽ̨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
5.2 ¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º