¡¾Â©¶´Í¨¸æ¡¿Î¢Èí11Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2024-11-13


Ò»¡¢Â©¶´¸ÅÊö

2024Äê11ÔÂ13ÈÕ£¬¶«É­Æ½Ì¨¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË11ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË89¸ö©¶´£¨²»°üÂÞ֮ǰÐÞ¸´µÄEdge©¶´£©£¬Â©¶´ÀàÐÍ°üÂÞÌØȨÌáÉý©¶´¡¢Äþ¾²¹¦Ð§Èƹý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢ鶩¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛƭ©¶´µÈ¡£

±¾´ÎÄþ¾²¸üÐÂÖÐÐÞ¸´ÁË4¸ö0 day©¶´£¬ÆäÖÐ2¸öÒÑ·¢ÏÖÔÚ¹¥»÷Öб»ÀûÓã¬3¸öÒѾ­¹ûÈ»Åû¶£º

CVE-2024-43451£ºNTLM ¹þϣй¶ÆÛƭ©¶´

Windows´æÔÚNTLM ¹þϣй¶ÆÛƭ©¶´£¬ÆäCVSSÆÀ·ÖΪ6.5£¬ÀûÓø鶴ÐèÒªÓû§½»»¥£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÏò¹¥»÷Õßй¶Óû§µÄ NTLMv2 ¹þÏ££¬¹¥»÷Õß¿ÉÒÔʹÓÃËüÀ´ÑéÖ¤Óû§Éí·Ý¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬ÇÒÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-49039£ºWindows Task SchedulerÌØȨÌáÉý©¶´

Windows ÈÎÎñ¼Æ»®·¨Ê½ÖдæÔÚÉí·ÝÑéÖ¤²»Í×£¬¿ÉÄܵ¼ÖÂȨÏÞÌáÉý£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÔÚÄ¿±êϵͳÉÏÔËÐжñÒâÉè¼ÆµÄÓ¦Ó÷¨Ê½£¬ÀûÓø鶴ÌáÉýÆäȨÏÞ£¬ÀÖ³ÉÀûÓÃÔÊÐí¹¥»÷ÕßÖ´ÐÐͨ³£½öÏÞÓÚÌØȨÕË»§µÄRPC¹¦Ð§¡£Ä¿Ç°¸Ã©¶´ÒѼì²âµ½Â©¶´ÀûÓá£

CVE-2024-49040£ºMicrosoft Exchange Server ÆÛƭ©¶´

Microsoft Exchange ServerÖдæÔÚÆÛƭ©¶´£¬ÆäCVSSÆÀ·ÖΪ7.5£¬¸Ã©¶´ÔÊÐí¹¥»÷ÕßÔÚ·¢Ë͸øµ±µØÊÕ¼þÈ˵ĵç×ÓÓʼþÖÐαÔì·¢¼þÈ˵ĵç×ÓÓʼþµØÖ·£¬µ¼ÖÂÆÛÆ­¹¥»÷¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£

CVE-2024-49019£ºActive Directory Ö¤Êé·þÎñÌØȨÌáÉý©¶´

Active Directory Ö¤Êé·þÎñ´æÔÚÈõÉí·ÝÑéÖ¤ÎÊÌ⣬¿ÉÄܵ¼ÖÂÌØȨÌáÉý£¬ÆäCVSSÆÀ·ÖΪ7.8£¬¸Ã©¶´ÔÊÐí¹¥»÷Õßͨ¹ýÀÄÓÃÄÚÖÃĬÈÏ°æ±¾1Ö¤ÊéÄ£°åÀ´»ñÈ¡Óò¹ÜÀíԱȨÏÞ¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£

±¾´ÎÄþ¾²¸üÐÂÖÐÐÞ¸´µÄ4¸öÑÏÖØ©¶´Îª£º

CVE-2024-43498£º.NET & Visual StudioÔ¶³Ì´úÂëÖ´ÐЩ¶´

.NET ºÍ Visual StudioÖдæÔÚÀàÐÍ»ìÏý©¶´£¬ÆäCVSSÆÀ·ÖΪ9.8£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÏò´æÔÚ©¶´µÄ .NET Web Ó¦Ó÷¨Ê½·¢ËÍÌØÖÆÇëÇó»ò½«ÌØÖÆÎļþ¼ÓÔص½´æÔÚ©¶´µÄ×ÀÃæÓ¦Ó÷¨Ê½ÖÐÀ´ÀûÓø鶴£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏС¡±¡£

CVE-2024-49056£ºAirlift.microsoft.com ÌØȨÌáÉý©¶´

¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.3£¬Í¨¹ý airlift.microsoft.com Éϼٶ¨²»ÐбäÊý¾ÝÈƹýÉí·ÝÑéÖ¤£¬ÊÚȨ¹¥»÷Õß¿ÉÒÔͨ¹ýÍøÂçÌáÉýȨÏÞ¡£¸Ã©¶´ÎÞÐèÓû§½ÓÄÉÈκδëÊ©¼´¿É½â¾ö¡£

CVE-2024-43639£ºWindows KDC ProxyÔ¶³Ì´úÂëÖ´ÐЩ¶´

¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓÃÌØÖÆÓ¦Ó÷¨Ê½ÀûÓÃWindows KerberosÖеļÓÃÜЭÒ驶´¶ÔÄ¿±êÖ´ÐÐÔ¶³Ì´úÂë¡£

CVE-2024-43625£ºMicrosoft Windows VMSwitch ÌØȨÌáÉý©¶´

Microsoft Hyper-V ÖÐµÄ VmSwitch ×é¼þ´æÔÚUse-After-Free©¶´£¬ÆäCVSSÆÀ·ÖΪ8.1£¬¹¥»÷Õß¿Éͨ¹ýÏòVMswitch Çý¶¯·¨Ê½·¢ËÍһϵÁÐÌض¨µÄÍøÂçÇëÇ󣬴Ӷø´¥·¢ Hyper-V Ö÷»úÖеÄÊͷźóÖØÓ鶴£¬ÀÖ³ÉÀûÓø鶴µÄ¹¥»÷Õß¿ÉÒÔ»ñµÃ SYSTEM ȨÏÞ¡£

³ýCVE-2024-49040ºÍCVE-2024-49019Í⣬΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ©¶´»¹°üÂÞÒÔÏ©¶´£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ©¶´»ñµÃ SYSTEM ȨÏÞ¡¢µ¼Ö¾ܾø·þÎñ»òÈƹýOfficeÊܱ£»¤ÊÓͼµÄÌض¨¹¦Ð§£º

CVE-2024-43623£ºWindows NT OS KernelÌØȨÌáÉý©¶´

CVE-2024-43629£ºWindows DWM Core LibraryÌØȨÌáÉý©¶´

CVE-2024-43630£ºWindows KernelÌØȨÌáÉý©¶´

CVE-2024-43636£ºWin32kÌØȨÌáÉý©¶´

CVE-2024-43642£ºWindows SMB ¾Ü¾ø·þÎñ©¶´

CVE-2024-49033£ºMicrosoft WordÄþ¾²¹¦Ð§Èƹý©¶´

΢Èí11Ô¸üÐÂÐÞ¸´µÄÍêÕû©¶´ÁбíÈçÏ£º

CVE-IDCVE ±êÌâÑÏÖØÐÔ
CVE-2024-43498.NET & Visual Studio Ô¶³Ì´úÂëÖ´ÐЩ¶´ÑÏÖØ
CVE-2024-49056Airlift.microsoft.com ÌØȨÌáÉý©¶´ÑÏÖØ
CVE-2024-43639Windows KDC ProxyÔ¶³Ì´úÂëÖ´ÐЩ¶´ÑÏÖØ
CVE-2024-43625Microsoft Windows VMSwitch ÌØȨÌáÉý©¶´ÑÏÖØ
CVE-2024-43499.NET & Visual Studio ¾Ü¾ø·þÎñ©¶´¸ßΣ
CVE-2024-43602Azure CycleCloud Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-43598LightGBM Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-5535OpenSSL£ºCVE-2024-5535  SSL_select_next_proto »º³åÇøÁýÕÖ¸ßΣ
CVE-2024-49040Microsoft Exchange Server ÆÛƭ©¶´¸ßΣ
CVE-2024-49031Microsoft Office Graphics Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49032Microsoft Office Graphics Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49029Microsoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49026Microsoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49027Microsoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49028Microsoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49030Microsoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49033Microsoft Word Äþ¾²¹¦Ð§Èƹý©¶´¸ßΣ
CVE-2024-49051Microsoft PC Manager ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-38264Microsoft ÐéÄâÓ²ÅÌ (VHDX) ¾Ü¾ø·þÎñ©¶´¸ßΣ
CVE-2024-43450Windows DNS ÆÛƭ©¶´¸ßΣ
CVE-2024-49019Active Directory Ö¤Êé·þÎñÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43633Windows Hyper-V ¾Ü¾ø·þÎñ©¶´¸ßΣ
CVE-2024-43624Windows Hyper-V ¹²ÏíÐéÄâ´ÅÅÌÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-48998SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-48997SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-48993SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49001SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49000SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-48999SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49043Microsoft.SqlServer.XEvent.Configuration.dll  Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-43462SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-48995SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-48994SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-38255SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-48996SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-43459SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49002SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49013SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49014SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49011SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49012SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49015SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49018SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49021Microsoft SQL Server Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49016SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49017SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49010SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49005SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49007SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49003SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49004SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49006SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49009SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49008SQL Server Native Client Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49048TorchGeo Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49044Visual Studio ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-49050Visual Studio Code Python Extension  Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-43644Windows Client-Side Caching ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43645Windows Defender Ó¦Ó÷¨Ê½¿ØÖÆ (WDAC) Äþ¾²¹¦Ð§Èƹý©¶´¸ßΣ
CVE-2024-43636Win32k ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43629Windows DWM Core Library ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43630Windows ÄÚºËÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43623Windows NT OS Kernel ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43451NTLM ¹þϣй¶ÆÛƭ©¶´¸ßΣ
CVE-2024-38203Windows Package Library Manager ÐÅϢ鶩¶´¸ßΣ
CVE-2024-43641Windows ×¢²á±íÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43452Windows ×¢²á±íÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43631Windows Secure Kernel Mode ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43646Windows Secure Kernel Mode ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43640Windows Kernel-Mode Driver ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43642Windows SMB ¾Ü¾ø·þÎñ©¶´¸ßΣ
CVE-2024-43447Windows SMBv3 Server Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-49039Windows Task Scheduler ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43628Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-43621Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-43620Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-43627Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-43635Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-43622Windows Telephony Service Ô¶³Ì´úÂëÖ´ÐЩ¶´¸ßΣ
CVE-2024-43626Windows Telephony Service ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43530Windows Update Stack ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43643Windows USB Video Class System Driver  ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43449Windows USB Video Class System Driver  ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43637Windows USB Video Class System Driver  ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43634Windows USB Video Class System Driver  ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-43638Windows USB Video Class System Driver  ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-49046Windows Win32 Kernel Subsystem ÌØȨÌáÉý©¶´¸ßΣ
CVE-2024-49049Visual Studio Code Remote Extension ÌØȨÌáÉý©¶´ÖÐΣ
ADV240001Microsoft SharePoint Server ×ÝÉî·ÀÓù¸üÐÂÎÞ
CVE-2024-10826Chromium£ºCVE-2024-10826 ÔÚ Family  Experiences ÖÐUse-after-freeδ֪
CVE-2024-10827Chromium£ºCVE-2024-10827  SerialÖеÄUse-after-freeδ֪


?

¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

Windows Package Library Manager

SQL Server

Microsoft Virtual Hard Drive

Windows SMBv3 Client/Server

Windows USB Video Driver

Microsoft Windows DNS

Windows NTLM

Windows Registry

.NET and Visual Studio

Windows Update Stack

LightGBM

Azure CycleCloud

Azure Database for PostgreSQL

Windows Telephony Service

Windows NT OS Kernel

Role: Windows Hyper-V

Windows VMSwitch

Windows DWM Core Library

Windows Kernel

Windows Secure Kernel Mode

Windows Kerberos

Windows SMB

Windows CSC Service

Windows Defender Application Control (WDAC)

Windows Active Directory Certificate Services

Microsoft Office Excel

Microsoft Graphics Component

Microsoft Office Word

Windows Task Scheduler

Microsoft Exchange Server

Visual Studio

Windows Win32 Kernel Subsystem

TorchGeo

Visual Studio Code

Microsoft PC Manager

Airlift.microsoft.com



Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔز¢°²×°¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2024Äê11ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Nov

²¹¶¡ÏÂÔØʾÀý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

 

image.png


Àý1£ºÎ¢Èí©¶´ÁÐ±í£¨Ê¾Àý£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿ÁÐÑ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áдò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

 image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý

3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×°¡£

 

image.png


Àý3£º²¹¶¡ÏÂÔؽçÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú¡£

3.2 ÁÙʱ´ëÊ©

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

 ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

 ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼Æı£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£

 Ê¹ÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

 ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏ޶ȡ£

 ÆôÓÃÇ¿ÃÜÂë¼Æı²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Nov

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49019

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43639


ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-11-13

Ê×´ÎÐû²¼



Îå¡¢¸½Â¼

5.1 ¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

 

image.png