¡¾Â©¶´Í¨¸æ¡¿Î¢Èí1Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2024-01-10


Ò»¡¢Â©¶´¸ÅÊö

2024Äê1ÔÂ9ÈÕ£¬Î¢ÈíÐû²¼ÁË1ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË49¸ö©¶´£¨²»°üÂÞ1ÔÂ5ÈÕÐÞ¸´µÄ4¸öMicrosoft Edge©¶´£©£¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛƭ©¶´µÈ¡£

±¾´ÎÄþ¾²¸üÐÂÖÐûÓб»»ý¼«ÀûÓûò¹ûÈ»Åû¶µÄ©¶´£¬ÆäÖÐÆÀ¼¶ÎªÑÏÖØµÄ2¸ö©¶´°üÂÞ£º

CVE-2024-20674£ºWindows Kerberos Äþ¾²¹¦Ð§Èƹý©¶´£¨ÑÏÖØ£©

¶ÔÊÜÏÞÍøÂçÓµÓзÃÎÊȨÏÞµÄÍþвÕß¿Éͨ¹ý½¨Á¢machine-in-the-middle (MITM£¬Öмä»ú)¹¥»÷»òÆäËüµ±µØÍøÂçÆÛÆ­¼¼ÊõÀ´ÀûÓøÃ©¶´£¬È»ºóÏò¿Í»§¶ËÊܺ¦»úÆ÷·¢ËͶñÒâKerberos ÏûÏ¢ÒÔð³äKerberosÉí·ÝÑéÖ¤·þÎñÆ÷£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÄܵ¼ÖÂÈÆ¹ýÉí·ÝÑéÖ¤¹¦Ð§¡£¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.0£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϴ󡱡£

CVE-2024-20700£ºWindows Hyper-V Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨¸ßΣ£©

¸Ã©¶´µÄ¹¥»÷ÅÓ´ó¶È½Ï¸ß£¬ÀÖ³ÉÀûÓøÃ©¶´ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬ÇÒÐèÒª»ñµÃ¶ÔÊÜÏÞÍøÂçµÄ·ÃÎÊȨÏÞ£¬ÆäCVSSÆÀ·ÖΪ7.5£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£

ÆäËüÖµµÃ¹Ø×¢µÄ©¶´»¹°üÂÞµ«²»ÏÞÓÚ£º

CVE-2024-21307£ºRemote Desktop ClientÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨¸ßΣ£©

¸Ã©¶´µÄ¹¥»÷ÅÓ´ó¶È½Ï¸ß£¬ÀÖ³ÉÀûÓô˸ö´ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬ÇÒÐèÒªÓû§½»»¥£¬Î´ÊÚȨÍþвÕß±ØÐëÆÚ´ýÓû§Æô¶¯Á¬½Ó¡£¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.5£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϴ󡱡£

CVE-2024-21318£ºMicrosoft SharePoint ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨¸ßΣ£©

¾­¹ýÉí·ÝÑéÖ¤µÄÍþвÕߣ¨ÖÁÉÙÊÇÍøÕ¾ËùÓÐÕߣ©¿ÉÀûÓøÃ©¶´×¢ÈëÈÎÒâ´úÂ룬²¢ÔÚ SharePoint Server µÄÉÏÏÂÎÄÖÐÖ´ÐиôúÂë¡£¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϴ󡱡£

³ýCVE-2024-20674¡¢CVE-2024-21307ºÍCVE-2024-21318Í⣬΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖС°±»ÀûÓõĿÉÄÜÐԽϴ󡱵Ä©¶´»¹°üÂÞ£º

CVE-2024-20652£ºWindows HTMLƽ̨Äþ¾²¹¦Ð§Èƹý©¶´£¨¸ßΣ£©

CVE-2024-20653£ºMicrosoft Common Log File SystemÌØÈ¨ÌáÉý©¶´£¨¸ßΣ£©

CVE-2024-20683£ºWin32k ÌØÈ¨ÌáÉý©¶´£¨¸ßΣ£©

CVE-2024-20686£ºWin32k ÌØÈ¨ÌáÉý©¶´£¨¸ßΣ£©

CVE-2024-20698£ºWindows ÄÚºËÌØÈ¨ÌáÉý©¶´£¨¸ßΣ£©

CVE-2024-21310£ºWindows Cloud Files Mini Filter DriverÌØÈ¨ÌáÉý©¶´£¨¸ßΣ£©

΢Èí1Ô¸üÐÂÉæ¼°µÄÍêÕû©¶´ÁбíÈçÏ£º

CVE ID

CVE ±êÌâ

ÑÏÖØÐÔ

CVE-2024-20674

Windows   Kerberos Äþ¾²¹¦Ð§Èƹý©¶´

ÑÏÖØ

CVE-2024-20700

Windows   Hyper-V Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-0057

NET¡¢.NET Framework ºÍ Visual Studio Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-20672

.NET Core ºÍ Visual Studio ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-21312

.NET   Framework ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-20676

Azure   Storage Mover Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21306

Microsoft   Bluetooth Driver ÆÛƭ©¶´

¸ßΣ

CVE-2024-21325

Microsoft   Printer Metadata Troubleshooter Tool Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21319

Microsoft   Identity ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-20677

Microsoft   Office Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21318

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-20658

Microsoft   Virtual Hard Disk ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-21307

Remote   Desktop Client Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-0056

Microsoft.Data.SqlClient   ºÍ System.Data.SqlClient SQLÊý¾ÝÌṩ·¨Ê½Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2022-35737

MITRE£ºCVE-2022-35737 SQLite ÔÊÐíÊý×é½çÏÞÒç³ö

¸ßΣ

CVE-2024-21305

Hypervisor-Protected   Code Integrity (HVCI) Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-20656

Visual   Studio ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-20687

Microsoft   AllJoyn API ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-20666

BitLocker Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-21310

Windows   Cloud Files Mini Filter Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-20694

Windows   CoreMessaging ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-20653

Microsoft   Common Log File System ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-20682

Windows   Cryptographic Services Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-21311

Windows   Cryptographic Services ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-20657

Windows   Group Policy ȨÏÞÌáÉý©¶´

¸ßΣ

CVE-2024-20699

Windows   Hyper-V ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-20698

Windows   Kernel ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-21309

Windows   Kernel-Mode Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-20697

Windows   Libarchive Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-20696

Windows   Libarchive Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-20692

Microsoft   Local Security Authority Subsystem Service ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-20660

Microsoft   Message Queuing ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-20664

Microsoft   Message Queuing ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-20680

Windows   Message Queuing Client (MSMQC) ÐÅϢй¶

¸ßΣ

CVE-2024-20663

Windows   Message Queuing Client (MSMQC) ÐÅϢй¶

¸ßΣ

CVE-2024-21314

Microsoft   Message Queuing ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-20661

Microsoft   Message Queuing ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-20690

Windows   Nearby Sharing ÆÛƭ©¶´

¸ßΣ

CVE-2024-20654

Microsoft   ODBC Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-20662

Windows   Online Certificate Status Protocol (OCSP) ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-20655

Microsoft   Online Certificate Status Protocol (OCSP) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-20652

Windows   HTML Platforms Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-21316

Windows   Server Key Distribution Äþ¾²¹¦Ð§Èƹý

¸ßΣ

CVE-2024-20681

Windows   Subsystem for Linux ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-21313

Windows   TCP/IP ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-20691

Windows   Themes ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-21320

Windows   Themes ÆÛƭ©¶´

¸ßΣ

CVE-2024-20686

Win32k ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-20683

Win32k ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-0222

Chromium£ºCVE-2024-0222 ÔÚ ANGLE ÖÐÊͷźóʹÓÃ

δ֪

CVE-2024-0223

Chromium£ºCVE-2024-0223 ANGLE ¶Ñ»º³åÇøÒç³ö

δ֪

CVE-2024-0224

Chromium£ºCVE-2024-0224 ÔÚ WebAudio ÖÐÊͷźóʹÓÃ

δ֪

CVE-2024-0225

Chromium£ºCVE-2024-0225 ÔÚ WebGPU ÖÐÊͷźóʹÓÃ

δ֪



¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

SQL Server

.NET and Visual Studio

Windows Scripting

Windows Common Log File System Driver

Windows ODBC Driver

Windows Online Certificate Status Protocol (OCSP) SnapIn

Visual Studio

Windows Group Policy

Microsoft Virtual Hard Drive

Windows Message Queuing

Windows BitLocker

.NET Core & Visual Studio

Windows Authentication Methods

Azure Storage Mover

Microsoft Office

Windows Subsystem for Linux

Windows Cryptographic Services

Windows Win32K

Windows Win32 Kernel Subsystem

Windows AllJoyn API

Windows Nearby Sharing

Windows Themes

Windows Local Security Authority Subsystem Service (LSASS)

Windows Collaborative Translation Framework

Windows Libarchive

Windows Kernel

Windows Hyper-V

Unified Extensible Firmware Interface

Microsoft Bluetooth Driver

Remote Desktop Client

Windows Kernel-Mode Drivers

Windows Cloud Files Mini Filter Driver

.NET Framework

Windows TCP/IP

Windows Server Key Distribution Service

Microsoft Office SharePoint

Microsoft Identity Services

Microsoft Devices

 

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2024Äê1ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Jan

²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí©¶´ÁÐÌåÏÖÀý£¨2022Äê2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£

3.2 ÁÙʱ´ëÊ©

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Jan

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-20674

 

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-01-10

Ê×´ÎÐû²¼

 

 

Îå¡¢¸½Â¼

5.1 ¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png