¡¾Â©¶´Í¨¸æ¡¿Î¢Èí8Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2024-08-14


Ò»¡¢Â©¶´¸ÅÊö

2024Äê8ÔÂ14ÈÕ£¬¶«É­Æ½Ì¨¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË8ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË89¸ö©¶´£¨²»°üÂÞ±¾ÔÂÔçЩʱºòÅû¶µÄ Microsoft Edge ©¶´£©£¬Â©¶´ÀàÐͰüÂÞÌØÈ¨ÌáÉý©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢй¶©¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛƭ©¶´µÈ¡£

±¾´ÎÄþ¾²¸üÐÂÖаüÂÞ10¸ö0 day©¶´£¬ÆäÖÐ6¸ö±»»ý¼«ÀûÓã¬4¸öÒѾ­¹ûÈ»Åû¶£º

CVE-2024-38178£ºScripting EngineÄÚ´æËð»µÂ©¶´

Windows½Å±¾ÒýÇæÖдæÔÚÀàÐÍ»ìÏý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.5£¬¿Éͨ¹ýÓÕµ¼Ä¿±êÓû§µã»÷ÌØÖÆURLÀ´ÀûÓøÃ©¶´£¨¸Ã¶ñÒâÁ´½ÓÐèÔÚInternet Explorer ģʽÏ嵀 Microsoft EdgeÖд¥·¢£©£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-38193£ºWindows Ancillary Function Driver for WinSockÌØÈ¨ÌáÉý©¶´

Windows Ancillary Function Driver for WinSockÖдæÔÚUse-After-Free©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8£¬ÀÖ³ÉÀûÓøÃ©¶´¿É½«È¨ÏÞÌáÉýΪSYSTEM ȨÏÞ£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-38213£ºWindows Mark of the Web Äþ¾²¹¦Ð§Èƹý©¶´

Windows Mark of the Web ÖдæÔÚÄþ¾²¹¦Ð§Èƹý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ6.5£¬ÍþвÕß¿Éͨ¹ýÏòÄ¿±êÓû§·¢ËͶñÒâÎļþ²¢ÓÕʹÓû§´ò¿ªÀ´ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÈÆ¹ýSmartScreenÍþв·À»¤£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-38106£ºWindows KernelÌØÈ¨ÌáÉý©¶´

WindowsÄں˴æÔÚȨÏÞÌáÉý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.0£¬ÀÖ³ÉÀûÓøÃ©¶´¿ÉÒÔ»ñµÃSYSTEM ȨÏÞ£¬µ«ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-38107£ºWindows Power Dependency Coordinator ÌØÈ¨ÌáÉý©¶´

Windows µçÔ´ÒÀÀµÐÔЭµ÷Æ÷ÖдæÔÚUse-After-Free©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8£¬ÀÖ³ÉÀûÓøÃ©¶´¿É½«È¨ÏÞÌáÉýΪSYSTEM ȨÏÞ£¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-38189£ºMicrosoft Project Ô¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft ProjectÖдæÔÚÊäÈëÑéÖ¤²»Í×£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬¿Éͨ¹ýÓÕµ¼Êܺ¦ÕßÔÚϵͳÉÏ´ò¿ª¶ñÒâµÄ Microsoft Office Project Îļþ£¨Èçͨ¹ý¶ñÒâµç×ÓÓʼþ¡¢WebÍøÕ¾»ò¼´Ê±ÏûÏ¢µÈ£©£¬µ«ÐèÒª¸ÃϵͳÖеġ°×èÖ¹´Ó»¥ÁªÍø»ñÈ¡µÄOfficeÎļþÖÐÔËÐкꡱ¼ÆÄ±Òѱ»½ûÓ㬶øÇÒδÆôÓá°VBAºê֪ͨÉèÖá±£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-38199£ºWindows Line Printer Daemon (LPD) ServiceÔ¶³Ì´úÂëÖ´ÐЩ¶´

WindowsÐÐʽ´òÓ¡»úÊØ»¤·¨Ê½ (LPD) ·þÎñÖдæÔÚUse-After-Free©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔͨ¹ýÍøÂçÏò¹²ÏíµÄÒ×Êܹ¥»÷µÄWindows Line Printer Daemon (LPD) ·þÎñ·¢ËÍÌØÖÆµÄ´òÓ¡ÈÎÎñ£¬ÀÖ³ÉÀûÓÿÉÄÜÔÚ·þÎñÆ÷Éϵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£ ΢Èí½¨ÒéÓû§²»Òª°²×°»òÆôÓÃWindows Line Printer Daemon (LPD) ·þÎñ£¬Ä¬ÈÏÇé¿öÏÂϵͳÉÏδ°²×°»òÆôÓà LPD£¬×ÔWindows Server 2012 Æð£¬LPD ÒÑÐû²¼ÆúÓá£

CVE-2024-21302£ºWindows Secure Kernel ModeÌØÈ¨ÌáÉý©¶´

MicrosoftÖ§³Ö Virtualization Based Security (VBS)µÄ ¶à¸öWindows ϵͳ£¨°üÂÞ Azure ÐéÄâ»ú SKUS µÄ×Ó¼¯£©ÖдæÔÚÌØÈ¨ÌáÉý©¶´£¬ÀÖ³ÉÀûÓÿɻñµÃ SYSTEM ȨÏÞ£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ6.7£¬¿ÉÄܵ¼Ö¾ßÓйÜÀíԱȨÏÞµÄÍþвÕßÄܹ»½«µ±Ç°°æ±¾µÄ Windows ϵͳÎļþÌæ»»Îª¹ýʱ°æ±¾¡£Í¨¹ýÀûÓøÃ©¶´£¬ÍþвÕß¿ÉÒÔÖØÐÂÒýÈë֮ǰÒÑÐÞ¸´/»º½âµÄ©¶´¡¢ÈƹýVBSÄþ¾²¹¦Ð§²¢ÇÔÈ¡ÊÜVBS ±£»¤µÄÊý¾Ý£¨Windows Downdate ½µ¼¶¹¥»÷£©¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£

CVE-2024-38202£ºWindows Update StackÌØÈ¨ÌáÉý©¶´

Windows Update ÖдæÔÚÌØÈ¨ÌáÉý©¶´£¬ÀÖ³ÉÀûÓÿɻñµÃ SYSTEM ȨÏÞ£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.3, ¿ÉÄܵ¼Ö¾ßÓлù±¾Óû§È¨ÏÞµÄÍþвÕßÄܹ»ÖØÐÂÒýÈë֮ǰÒÑÐÞ¸´/»º½âµÄ©¶´»òÈÆ¹ýVBS µÄijЩ¹¦Ð§£¨Windows Downdate ½µ¼¶¹¥»÷£©£¬ÀÖ³ÉÀûÓøÃ©¶´ÐèÒªÓÕµ¼¹ÜÀíÔ±»ò¾ßÓÐίÅÉȨÏÞµÄÓû§Ö´ÐÐϵͳ»¹Ô­£¬´Ó¶ø´¥·¢¸Ã©¶´¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£Î¢ÈíÕýÔÚ¿ª·¢Äþ¾²¸üÐÂÀ´»º½â¸Ã©¶´£¬µ«Ä¿Ç°ÉÐδÐû²¼¡£

CVE-2024-38200£ºMicrosoft Office ÆÛƭ©¶´

Microsoft OfficeÖдæÔÚÐÅϢй¶©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ6.5£¬ÍþвÕß¿Éͨ¹ýÓÕµ¼Óû§µã»÷¶ñÒâÁ´½Ó£¨Èçͨ¹ýµç×ÓÓʼþ»ò¼´Ê±Í¨Ñ¶ÏûÏ¢£©²¢´ò¿ªÌØÖÆÎļþ£¨ÍйÜÔÚ¶ñÒâÍøÕ¾ÉÏ£©À´ÀûÓøÃ©¶´£¬È»ºóÆÈʹ Office ½¨Á¢ÓëÔ¶³Ì¹²ÏíµÄ³öÕ¾Á¬½Ó£¬´ÓÖÐÇÔÈ¡·¢Ë굀 NTLM ¹þÏ££¬µ¼ÖÂÃô¸ÐÐÅϢй¶¡£¿Éͨ¹ý½«Óû§Ìí¼Óµ½Êܱ£»¤Óû§Äþ¾²×飬ÒÔ·ÀֹʹÓà NTLM ×÷ΪÉí·ÝÑéÖ¤»úÖÆ£¬»òʹÓÃÍâΧ·À»ðǽ¡¢µ±µØ·À»ðǽºÍ VPN ÉèÖÃ×èÖ¹ TCP 445/SMB ´ÓÍøÂç³öÕ¾£¨Õ⽫×èÖ¹ÏòÔ¶³ÌÎļþ¹²Ïí·¢ËÍ NTLM Éí·ÝÑéÖ¤ÏûÏ¢£©À´»º½â¸Ã©¶´¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£

±¾´ÎÄþ¾²¸üÐÂÖÐÐÞ¸´µÄ9¸öÑÏÖØÂ©¶´Îª£º

l  CVE-2024-38063£ºWindows TCP/IP Ô¶³Ì´úÂëÖ´ÐЩ¶´

Windows TCP/IPÖдæÔÚÕûÊýÏÂÒç©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÏò Windows ¼ÆËã»úÖØ¸´·¢ËͰüÂÞÌØÖÆÊý¾Ý°üµÄ IPv6 Êý¾Ý°ü£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Èç¹ûÄ¿±ê¼ÆËã»úÉϽûÓà IPv6£¬ÏµÍ³²»»áÊܵ½Ó°Ï졣΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£

l  CVE-2024-38160£ºWindows Network VirtualizationÔ¶³Ì´úÂëÖ´ÐЩ¶´

Windows ÍøÂçÐéÄ⻯´æÔÚ¶Ñ»º³åÇøÒç³ö©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.1£¬ÍþвÕß¿ÉÒÔÀûÓà Windows Server 2016 µÄ wnv.sys ×é¼þÖÐδ¾­¼ì²éµÄ·µ»ØÖµÀ´ÀûÓøÃ©¶´£¬Í¨¹ýÀûÓÃÄÚ´æÃèÊö·ûÁбí (MDL) µÄÄÚÈÝ£¬¿ÉÄܵ¼ÖÂδ¾­ÊÚȨµÄÄÚ´æÐ´È룬ÉõÖÁÊͷŵ±Ç°ÕýÔÚʹÓõÄÓÐЧ¿é£¬´Ó¶øµ¼Ö¿ͻ§»úµ½Ö÷»úÌÓÒÝ£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£

l  CVE-2024-38159£ºWindows Network VirtualizationÔ¶³Ì´úÂëÖ´ÐЩ¶´

Windows ÍøÂçÐéÄ⻯´æÔÚUse-After-Free©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.1£¬ÍþвÕß¿ÉÒÔÀûÓà Windows Server 2016 µÄ wnv.sys ×é¼þÖÐδ¾­¼ì²éµÄ·µ»ØÖµÀ´ÀûÓøÃ©¶´£¬Í¨¹ýÀûÓÃÄÚ´æÃèÊö·ûÁбí (MDL) µÄÄÚÈÝ£¬¿ÉÄܵ¼ÖÂδ¾­ÊÚȨµÄÄÚ´æÐ´È룬ÉõÖÁÊͷŵ±Ç°ÕýÔÚʹÓõÄÓÐЧ¿é£¬´Ó¶øµ¼Ö¿ͻ§»úµ½Ö÷»úÌÓÒÝ£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£

l  CVE-2024-38140£ºWindows Reliable Multicast Transport Driver (RMCAST) Ô¶³Ì´úÂëÖ´ÐЩ¶´

Windows ¿É¿¿¶à²¥´«ÊäÇý¶¯·¨Ê½ (RMCAST) ´æÔÚUse-After-Free©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔͨ¹ýÏò·þÎñÆ÷É쵀 Windows Pragmatic General Multicast (PGM) ¿ª·ÅÌ×½Ó×Ö·¢ËÍÌØÖÆµÄÊý¾Ý°üÀ´ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¸Ã©¶´½öÔÚÓз¨Ê½¼àÌýPGM¶Ë¿ÚµÄÇé¿öϲſɱ»ÀûÓã¬Èç¹ûPGMÒѰ²×°»òÆôÓ㬵«Ã»Óз¨Ê½×÷Ϊ½ÓÊÕÆ÷Ö÷¶¯¼àÌý£¬Ôò¸Ã©¶´²»Ðб»ÀûÓᣲ»½¨Ò齫 PGM ½ÓÊÕÆ÷̻¶ÔÚ¹«¹²»¥ÁªÍøÉÏ£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£

l  CVE-2024-38109£ºAzure Health Bot ÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38206£ºMicrosoft Copilot Studio ÐÅϢй¶©¶´

l  CVE-2024-38166£ºMicrosoft Dynamics 365 ¿çÕ¾½Å±¾Â©¶´

l  CVE-2022-3775£ºRedhat-CVE-2022-3775 grub2 - äÖȾijЩ Unicode ÐòÁÐʱ»ùÓڶѵÄÔ½½çдÈë

l  CVE-2023-40547£ºRedhat£ºCVE-2023-40547 Shim - HTTP Æô¶¯Ö§³ÖÖÐµÄ RCE ¿ÉÄܵ¼ÖÂÄþ¾²Æô¶¯Èƹý

³ýCVE-2024-38063Í⣬΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ©¶´»¹°üÂÞ£º

l  CVE-2024-38133£ºWindows ÄÚºËÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38148£ºWindows Secure Channel¾Ü¾ø·þÎñ©¶´

l  CVE-2024-38163£ºWindows Update StackÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38198£ºWindows Print SpoolerÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38196£ºWindows Common Log File System DriverÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38141£ºWindows Ancillary Function Driver for WinSockÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38125/ CVE-2024-38144£ºKernel Streaming WOW Thunk Service DriverÌØÈ¨ÌáÉý©¶´

l  CVE-2024-38147/ CVE-2024-38150£ºMicrosoft DWM Core LibraryÌØÈ¨ÌáÉý©¶´

΢Èí8Ô¸üÐÂÉæ¼°µÄ²¿ÃÅ©¶´ÁбíÈçÏ£¬ÆäÖв»°üÂÞChrome·Ö·¢µÄ9¸öMicrosoft Edge (Chromium-based)©¶´£º

CVE ID

CVE ±êÌâ

ÑÏÖØÐÔ

CVE-2024-38109

Azure   Health Bot ÌØÈ¨ÌáÉý©¶´

ÑÏÖØ

CVE-2024-38206

Microsoft   Copilot Studio ÐÅϢй¶©¶´

ÑÏÖØ

CVE-2024-38166

Microsoft   Dynamics 365 ¿çÕ¾½Å±¾Â©¶´

ÑÏÖØ

CVE-2024-38140

Windows   Reliable Multicast Transport Driver (RMCAST) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38160

Windows   Network VirtualizationÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38159

Windows   Network VirtualizationÔ¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2022-3775

Redhat£ºCVE-2022-3775 grub2 - äÖȾijЩ Unicode ÐòÁÐʱ»ùÓڶѵÄÔ½½çдÈë

ÑÏÖØ

CVE-2023-40547

Redhat£ºCVE-2023-40547 Shim - HTTP Æô¶¯Ö§³ÖÖÐµÄ RCE ¿ÉÄܵ¼ÖÂÄþ¾²Æô¶¯Èƹý

ÑÏÖØ

CVE-2024-38063

Windows   TCP/IP Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-38168

.NET ºÍ Visual Studio ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38167

.NET ºÍ Visual Studio ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38162

Azure   Connected Machine Agent ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38098

Azure   Connected Machine Agent ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38195

Azure   CycleCloud Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38158

Azure IoT   SDK Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38157

Azure IoT   SDK Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38108

Azure   Stack Hub ÆÛƭ©¶´

¸ßΣ

CVE-2024-38201

Azure   Stack Hub ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38199

Windows   Line Printer Daemon (LPD) ServiceÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38123

Windows À¶ÑÀÇý¶¯·¨Ê½ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38211

Microsoft   Dynamics 365£¨on-premises£©¿çÕ¾µã½Å±¾Â©¶´

¸ßΣ

CVE-2024-38218

Microsoft   Edge£¨»ùÓÚ HTML£©ÄÚ´æËð»µÂ©¶´

¸ßΣ

CVE-2024-38118

Microsoft   Local Security Authority (LSA) Server ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38122

Microsoft   Local Security Authority (LSA) Server ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38200

Microsoft   Office ÆÛƭ©¶´

¸ßΣ

CVE-2024-38084

Microsoft   OfficePlus ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38172

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38170

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38173

Microsoft   Outlook Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38171

Microsoft   PowerPoint Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38189

Microsoft   Project Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38169

Microsoft   Office Visio Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38134

Kernel   Streaming WOW Thunk Service Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38144

Kernel   Streaming WOW Thunk Service Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38125

Kernel   Streaming WOW Thunk Service Driver ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38197

Microsoft   Teams for iOS ÆÛƭ©¶´

¸ßΣ

CVE-2024-38152

Windows   OLE Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-37968

Windows   DNS ÆÛƭ©¶´

¸ßΣ

CVE-2024-38141

Windows   Ancillary Function Driver for WinSock ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38193

Windows   Ancillary Function Driver for WinSock ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38177

Windows   App Installer ÆÛƭ©¶´

¸ßΣ

CVE-2024-38131

Clipboard   Virtual Channel Extension Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38215

Windows   Cloud Files Mini Filter Çý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38196

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38165

Windows ѹËõÎļþ¼Ð¸Ä¶¯Â©¶´

¸ßΣ

CVE-2024-38138

Windows ²¿Êð·þÎñÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38150

Windows   DWM ºËÐÄ¿âÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38147

Microsoft   DWM ºËÐÄ¿âÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38223

Windows   Initial Machine Configuration ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38114

Windows IP   ·ÓɹÜÀíµ¥ÔªÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38116

Windows IP   ·ÓɹÜÀíµ¥ÔªÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38115

Windows IP   ·ÓɹÜÀíµ¥ÔªÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-29995

Windows   Kerberos ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38151

Windows ÄÚºËÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38133

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38127

Windows   Hyper-V ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38153

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38106

Windows ÄÚºËÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38187

Windows ÄÚºËģʽÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38191

ÄÚºËÁ÷·þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38184

Windows ÄÚºËģʽÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38186

Windows ÄÚºËģʽÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38185

Windows ÄÚºËģʽÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38146

Windows   Layer-2 Bridge Network Driver ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38145

Windows   Layer-3 Bridge Network Driver ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38161

Windows   Mobile Broadband Driver Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38132

Windows ÍøÂçµØÖ·×ª»» (NAT) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38126

Windows ÍøÂçµØÖ·×ª»» (NAT) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38135

Windows µ¯ÐÔÎļþϵͳ (ReFS) ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38117

NTFS ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38107

Windows   Power Dependency Coordinator ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38198

Windows   Print Spooler ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38137

Windows   Resource Manager PSM Service Extension ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38136

Windows   Resource Manager PSM Service Extension ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38130

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38128

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38154

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38121

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38214

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38120

Windows ·ÓɺÍÔ¶³Ì·ÃÎÊ·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-38178

Scripting   Engine ÄÚ´æËð»µÂ©¶´

¸ßΣ

CVE-2022-2601

Redhat£ºCVE-2022-2601 grub2 - grub_font_construct_glyph() ÖеĻº³åÇøÒç³ö¿ÉÄܵ¼ÖÂÔ½½çдÈë²¢¿ÉÄÜÈÆ¹ýÄþ¾²Æô¶¯

¸ßΣ

CVE-2024-21302

Windows Äþ¾²ÄÚºËÄ£Ê½ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38142

Windows Äþ¾²ÄÚºËÄ£Ê½ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38155

Security   Center Broker ÐÅϢй¶©¶´

¸ßΣ

CVE-2024-38180

Windows   SmartScreen Äþ¾²¹¦Ð§Èƹý©¶´

¸ßΣ

CVE-2024-38148

Windows   Secure Channel ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-38202

Windows   Update Stack ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38163

Windows   Update Stack ÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38143

Windows   WLAN AutoConfig ·þÎñÌØÈ¨ÌáÉý©¶´

¸ßΣ

CVE-2024-38213

Windows   Mark of the Web Äþ¾²¹¦Ð§Èƹý©¶´

ÖÐΣ

CVE-2024-38219

Microsoft   Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÖÐΣ

CVE-2024-38222

Microsoft   Edge£¨»ùÓÚ Chromium£©ÐÅϢй¶©¶´

δ֪

 

¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

Windows Secure Kernel Mode

Windows Kerberos

Microsoft Windows DNS

Windows TCP/IP

Microsoft Office

Azure Connected Machine Agent

Windows Kernel

Windows Power Dependency Coordinator

Azure Stack

Azure Health Bot

Windows IP Routing Management Snapin

Windows NTFS

Microsoft Local Security Authority Server (lsasrv)

Windows Routing and Remote Access Service (RRAS)

Microsoft Bluetooth Driver

Microsoft Streaming Service

Windows Network Address Translation (NAT)

Windows Clipboard Virtual Channel Extension

Windows NT OS Kernel

Windows Resource Manager

Windows Deployment Services

Reliable Multicast Transport Driver (RMCAST)

Windows Ancillary Function Driver for WinSock

Windows WLAN Auto Config Service

Windows Layer-2 Bridge Network Driver

Windows DWM Core Library

Windows Transport Security Layer (TLS)

Microsoft WDAC OLE DB provider for SQL

Windows Security Center

Azure IoT SDK

Windows Network Virtualization

Windows Mobile Broadband

Windows Update Stack

Windows Compressed Folder

Microsoft Dynamics

.NET and Visual Studio

Microsoft Office Visio

Microsoft Office Excel

Microsoft Office PowerPoint

Microsoft Office Outlook

Windows App Installer

Windows Scripting

Windows SmartScreen

Windows Kernel-Mode Drivers

Microsoft Office Project

Azure CycleCloud

Windows Common Log File System Driver

Microsoft Teams

Windows Print Spooler Components

Line Printer Daemon Service (LPD)

Microsoft Copilot Studio

Windows Mark of the Web (MOTW)

Windows Cloud Files Mini Filter Driver

Microsoft Edge (Chromium-based)

Windows Initial Machine Configuration

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2024Äê8ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Aug

²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí©¶´ÁÐ±í£¨Ê¾Àý£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£

3.2 ÁÙʱ´ëÊ©

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼ÆÄ±£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Aug

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38063

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38202

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-08-14

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼

5.1 ¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png