¡¾Â©¶´Í¨¸æ¡¿Î¢Èí11Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2024-11-13Ò»¡¢Â©¶´¸ÅÊö
2024Äê11ÔÂ13ÈÕ£¬¶«Éƽ̨¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË11ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË89¸ö©¶´£¨²»°üÂÞ֮ǰÐÞ¸´µÄEdge©¶´£©£¬Â©¶´ÀàÐÍ°üÂÞÌØȨÌáÉý©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢ鶩¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛÆ©¶´µÈ¡£
±¾´ÎÄþ¾²¸üÐÂÖÐÐÞ¸´ÁË4¸ö0 day©¶´£¬ÆäÖÐ2¸öÒÑ·¢ÏÖÔÚ¹¥»÷Öб»ÀûÓã¬3¸öÒѾ¹ûÈ»Åû¶£º
CVE-2024-43451£ºNTLM ¹þϣй¶ÆÛÆ©¶´
Windows´æÔÚNTLM ¹þϣй¶ÆÛÆ©¶´£¬ÆäCVSSÆÀ·ÖΪ6.5£¬ÀûÓø鶴ÐèÒªÓû§½»»¥£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÏò¹¥»÷Õßй¶Óû§µÄ NTLMv2 ¹þÏ££¬¹¥»÷Õß¿ÉÒÔʹÓÃËüÀ´ÑéÖ¤Óû§Éí·Ý¡£Ä¿Ç°¸Ã©¶´ÒѾ¹ûÈ»Åû¶£¬ÇÒÒѼì²âµ½Â©¶´ÀûÓá£
CVE-2024-49039£ºWindows Task SchedulerÌØȨÌáÉý©¶´
Windows ÈÎÎñ¼Æ»®·¨Ê½ÖдæÔÚÉí·ÝÑéÖ¤²»Í×£¬¿ÉÄܵ¼ÖÂȨÏÞÌáÉý£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÔÚÄ¿±êϵͳÉÏÔËÐжñÒâÉè¼ÆµÄÓ¦Ó÷¨Ê½£¬ÀûÓø鶴ÌáÉýÆäȨÏÞ£¬ÀÖ³ÉÀûÓÃÔÊÐí¹¥»÷ÕßÖ´ÐÐͨ³£½öÏÞÓÚÌØȨÕË»§µÄRPC¹¦Ð§¡£Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£
CVE-2024-49040£ºMicrosoft Exchange Server ÆÛÆ©¶´
Microsoft Exchange ServerÖдæÔÚÆÛÆ©¶´£¬ÆäCVSSÆÀ·ÖΪ7.5£¬¸Ã©¶´ÔÊÐí¹¥»÷ÕßÔÚ·¢Ë͸øµ±µØÊÕ¼þÈ˵ĵç×ÓÓʼþÖÐαÔì·¢¼þÈ˵ĵç×ÓÓʼþµØÖ·£¬µ¼ÖÂÆÛƹ¥»÷¡£Ä¿Ç°¸Ã©¶´ÒѾ¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£
CVE-2024-49019£ºActive Directory Ö¤Êé·þÎñÌØȨÌáÉý©¶´
Active Directory Ö¤Êé·þÎñ´æÔÚÈõÉí·ÝÑéÖ¤ÎÊÌ⣬¿ÉÄܵ¼ÖÂÌØȨÌáÉý£¬ÆäCVSSÆÀ·ÖΪ7.8£¬¸Ã©¶´ÔÊÐí¹¥»÷Õßͨ¹ýÀÄÓÃÄÚÖÃĬÈÏ°æ±¾1Ö¤ÊéÄ£°åÀ´»ñÈ¡Óò¹ÜÀíԱȨÏÞ¡£Ä¿Ç°¸Ã©¶´ÒѾ¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£
±¾´ÎÄþ¾²¸üÐÂÖÐÐÞ¸´µÄ4¸öÑÏÖØ©¶´Îª£º
CVE-2024-43498£º.NET & Visual StudioÔ¶³Ì´úÂëÖ´ÐЩ¶´
.NET ºÍ Visual StudioÖдæÔÚÀàÐÍ»ìÏý©¶´£¬ÆäCVSSÆÀ·ÖΪ9.8£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÏò´æÔÚ©¶´µÄ .NET Web Ó¦Ó÷¨Ê½·¢ËÍÌØÖÆÇëÇó»ò½«ÌØÖÆÎļþ¼ÓÔص½´æÔÚ©¶´µÄ×ÀÃæÓ¦Ó÷¨Ê½ÖÐÀ´ÀûÓø鶴£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£
CVE-2024-49056£ºAirlift.microsoft.com ÌØȨÌáÉý©¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.3£¬Í¨¹ý airlift.microsoft.com Éϼٶ¨²»ÐбäÊý¾ÝÈƹýÉí·ÝÑéÖ¤£¬ÊÚȨ¹¥»÷Õß¿ÉÒÔͨ¹ýÍøÂçÌáÉýȨÏÞ¡£¸Ã©¶´ÎÞÐèÓû§½ÓÄÉÈκδëÊ©¼´¿É½â¾ö¡£
CVE-2024-43639£ºWindows KDC ProxyÔ¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓÃÌØÖÆÓ¦Ó÷¨Ê½ÀûÓÃWindows KerberosÖеļÓÃÜÐÒ驶´¶ÔÄ¿±êÖ´ÐÐÔ¶³Ì´úÂë¡£
CVE-2024-43625£ºMicrosoft Windows VMSwitch ÌØȨÌáÉý©¶´
Microsoft Hyper-V ÖÐµÄ VmSwitch ×é¼þ´æÔÚUse-After-Free©¶´£¬ÆäCVSSÆÀ·ÖΪ8.1£¬¹¥»÷Õß¿Éͨ¹ýÏòVMswitch Çý¶¯·¨Ê½·¢ËÍһϵÁÐÌض¨µÄÍøÂçÇëÇ󣬴Ӷø´¥·¢ Hyper-V Ö÷»úÖеÄÊͷźóÖØÓ鶴£¬ÀÖ³ÉÀûÓø鶴µÄ¹¥»÷Õß¿ÉÒÔ»ñµÃ SYSTEM ȨÏÞ¡£
³ýCVE-2024-49040ºÍCVE-2024-49019Í⣬΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ©¶´»¹°üÂÞÒÔÏ©¶´£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ©¶´»ñµÃ SYSTEM ȨÏÞ¡¢µ¼Ö¾ܾø·þÎñ»òÈƹýOfficeÊܱ£»¤ÊÓͼµÄÌض¨¹¦Ð§£º
CVE-2024-43623£ºWindows NT OS KernelÌØȨÌáÉý©¶´
CVE-2024-43629£ºWindows DWM Core LibraryÌØȨÌáÉý©¶´
CVE-2024-43630£ºWindows KernelÌØȨÌáÉý©¶´
CVE-2024-43636£ºWin32kÌØȨÌáÉý©¶´
CVE-2024-43642£ºWindows SMB ¾Ü¾ø·þÎñ©¶´
CVE-2024-49033£ºMicrosoft WordÄþ¾²¹¦Ð§Èƹý©¶´
΢Èí11Ô¸üÐÂÐÞ¸´µÄÍêÕû©¶´ÁбíÈçÏ£º
CVE-ID | CVE ±êÌâ | ÑÏÖØÐÔ |
CVE-2024-43498 | .NET & Visual Studio Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2024-49056 | Airlift.microsoft.com ÌØȨÌáÉý©¶´ | ÑÏÖØ |
CVE-2024-43639 | Windows KDC ProxyÔ¶³Ì´úÂëÖ´ÐЩ¶´ | ÑÏÖØ |
CVE-2024-43625 | Microsoft Windows VMSwitch ÌØȨÌáÉý©¶´ | ÑÏÖØ |
CVE-2024-43499 | .NET & Visual Studio ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-43602 | Azure CycleCloud Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-43598 | LightGBM Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-5535 | OpenSSL£ºCVE-2024-5535 SSL_select_next_proto »º³åÇøÁýÕÖ | ¸ßΣ |
CVE-2024-49040 | Microsoft Exchange Server ÆÛÆ©¶´ | ¸ßΣ |
CVE-2024-49031 | Microsoft Office Graphics Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49032 | Microsoft Office Graphics Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49029 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49026 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49027 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49028 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49030 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49033 | Microsoft Word Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-49051 | Microsoft PC Manager ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-38264 | Microsoft ÐéÄâÓ²ÅÌ (VHDX) ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-43450 | Windows DNS ÆÛÆ©¶´ | ¸ßΣ |
CVE-2024-49019 | Active Directory Ö¤Êé·þÎñÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43633 | Windows Hyper-V ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-43624 | Windows Hyper-V ¹²ÏíÐéÄâ´ÅÅÌÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-48998 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-48997 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-48993 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49001 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49000 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-48999 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49043 | Microsoft.SqlServer.XEvent.Configuration.dll Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-43462 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-48995 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-48994 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-38255 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-48996 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-43459 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49002 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49013 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49014 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49011 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49012 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49015 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49018 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49021 | Microsoft SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49016 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49017 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49010 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49005 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49007 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49003 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49004 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49006 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49009 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49008 | SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49048 | TorchGeo Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49044 | Visual Studio ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-49050 | Visual Studio Code Python Extension Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-43644 | Windows Client-Side Caching ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43645 | Windows Defender Ó¦Ó÷¨Ê½¿ØÖÆ (WDAC) Äþ¾²¹¦Ð§Èƹý©¶´ | ¸ßΣ |
CVE-2024-43636 | Win32k ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43629 | Windows DWM Core Library ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43630 | Windows ÄÚºËÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43623 | Windows NT OS Kernel ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43451 | NTLM ¹þϣй¶ÆÛÆ©¶´ | ¸ßΣ |
CVE-2024-38203 | Windows Package Library Manager ÐÅϢ鶩¶´ | ¸ßΣ |
CVE-2024-43641 | Windows ×¢²á±íÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43452 | Windows ×¢²á±íÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43631 | Windows Secure Kernel Mode ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43646 | Windows Secure Kernel Mode ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43640 | Windows Kernel-Mode Driver ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43642 | Windows SMB ¾Ü¾ø·þÎñ©¶´ | ¸ßΣ |
CVE-2024-43447 | Windows SMBv3 Server Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-49039 | Windows Task Scheduler ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43628 | Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-43621 | Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-43620 | Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-43627 | Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-43635 | Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-43622 | Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐЩ¶´ | ¸ßΣ |
CVE-2024-43626 | Windows Telephony Service ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43530 | Windows Update Stack ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43643 | Windows USB Video Class System Driver ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43449 | Windows USB Video Class System Driver ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43637 | Windows USB Video Class System Driver ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43634 | Windows USB Video Class System Driver ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-43638 | Windows USB Video Class System Driver ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-49046 | Windows Win32 Kernel Subsystem ÌØȨÌáÉý©¶´ | ¸ßΣ |
CVE-2024-49049 | Visual Studio Code Remote Extension ÌØȨÌáÉý©¶´ | ÖÐΣ |
ADV240001 | Microsoft SharePoint Server ×ÝÉî·ÀÓù¸üР| ÎÞ |
CVE-2024-10826 | Chromium£ºCVE-2024-10826 ÔÚ Family Experiences ÖÐUse-after-free | δ֪ |
CVE-2024-10827 | Chromium£ºCVE-2024-10827 SerialÖеÄUse-after-free | δ֪ |
?
¶þ¡¢Ó°Ï췶Χ
ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º
Windows Package Library Manager
SQL Server
Microsoft Virtual Hard Drive
Windows SMBv3 Client/Server
Windows USB Video Driver
Microsoft Windows DNS
Windows NTLM
Windows Registry
.NET and Visual Studio
Windows Update Stack
LightGBM
Azure CycleCloud
Azure Database for PostgreSQL
Windows Telephony Service
Windows NT OS Kernel
Role: Windows Hyper-V
Windows VMSwitch
Windows DWM Core Library
Windows Kernel
Windows Secure Kernel Mode
Windows Kerberos
Windows SMB
Windows CSC Service
Windows Defender Application Control (WDAC)
Windows Active Directory Certificate Services
Microsoft Office Excel
Microsoft Graphics Component
Microsoft Office Word
Windows Task Scheduler
Microsoft Exchange Server
Visual Studio
Windows Win32 Kernel Subsystem
TorchGeo
Visual Studio Code
Microsoft PC Manager
Airlift.microsoft.com
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔز¢°²×°¡£
£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2024Äê11ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2024-Nov
²¹¶¡ÏÂÔØʾÀý£¨²Î¿¼£©£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢Èí©¶´ÁÐ±í£¨Ê¾Àý£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿ÁÐÑ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áдò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý
3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£
Àý3£º²¹¶¡ÏÂÔؽçÃæ
4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£
3.2 ÁÙʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼Æı£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏ޶ȡ£
ÆôÓÃÇ¿ÃÜÂë¼Æı²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Nov
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49019
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43639
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-11-13 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ¶«Éƽ̨¼ò½é
¶«Éƽ̨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«Éƽ̨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶«Éƽ̨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦¡£
5.2 ¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º