¡¾Â©¶´Í¨¸æ¡¿Î¢Èí12Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2024-12-11


Ò»¡¢Â©¶´¸ÅÊö

2024Äê12ÔÂ11ÈÕ£¬¶«É­Æ½Ì¨¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË12ÔÂÄþ¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË71¸ö©¶´£¨²»°üÂÞ֮ǰÐÞ¸´µÄEdge©¶´£©£¬Â©¶´ÀàÐÍ°üÂÞÌØȨÌáÉý©¶´¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´¡¢ÐÅϢ鶩¶´¡¢¾Ü¾ø·þÎñ©¶´ºÍÆÛƭ©¶´µÈ ¡£

±¾´ÎÄþ¾²¸üÐÂÖÐÐÞ¸´ÁË1¸öÒѾ­¹ûÈ»Åû¶ÇÒÒÑ·¢ÏÖ±»»ý¼«ÀûÓõÄ0 day©¶´£º

CVE-2024-49138£ºWindows Common Log File System DriverÌØȨÌáÉý©¶´

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÖдæÔÚ»ùÓڶѵĻº³åÇøÒç³ö©¶´£¬ÆäCVSSÆÀ·ÖΪ7.8£¬ÀÖ³ÉÀûÓø鶴µÄ¿É»ñµÃSYSTEM ȨÏÞ ¡£Ä¿Ç°¸Ã©¶´ÒѾ­¹ûÈ»Åû¶ÇÒÒÑ·¢ÏÖ±»ÀûÓà ¡£

±¾´ÎÄþ¾²¸üÐÂÖÐÐÞ¸´µÄ16¸öÑÏÖØ©¶´Îª£º

CVE-2024-49117£ºWindows Hyper-V Ô¶³Ì´úÂëÖ´ÐЩ¶´

Windows Hyper-V´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬guestÐéÄâ»úÉϾ­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÏòÐéÄâ»úÉϵÄÓ²¼þ×ÊÔ´·¢ËÍÌØÖƵÄÎļþ²Ù×÷ÇëÇó£¬ÀÖ³ÉÀûÓÿÉÄܵ¼ÖÂÔÚÖ÷»ú·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë ¡£

CVE-2024-49124£ºLightweight Directory Access Protocol (LDAP) Client Ô¶³Ì´úÂëÖ´ÐЩ¶´

Lightweight Directory Access Protocol (LDAP) Clien´æÔÚ¾ºÕùÌõ¼þ©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.1£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÏò´æÔÚ©¶´µÄ·þÎñÆ÷·¢ËÍÌØÖÆÇëÇó£¬ÀÖ³ÉÀûÓø鶴¿Éµ¼Ö¹¥»÷ÕߵĴúÂëÔÚ SYSTEM ÕÊ»§ÉÏÏÂÎÄÖÐÔËÐÐ ¡£

CVE-2024-49112£ºWindows Lightweight Directory Access Protocol (LDAP) Ô¶³Ì´úÂëÖ´ÐЩ¶´

Windows ÇáÁ¿¼¶Ä¿Â¼·ÃÎÊЭÒé (LDAP)´æÔÚUse-After-Free©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.1£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÏò´æÔÚ©¶´µÄ·þÎñÆ÷·¢ËÍÌØÖÆÇëÇó£¬ÀÖ³ÉÀûÓø鶴¿Éµ¼Ö¹¥»÷ÕߵĴúÂëÔÚ SYSTEM ÕÊ»§ÉÏÏÂÎÄÖÐÔËÐÐ ¡£

CVE-2024-49127£ºWindows Lightweight Directory Access Protocol (LDAP) Ô¶³Ì´úÂëÖ´ÐЩ¶´

Windows ÇáÁ¿¼¶Ä¿Â¼·ÃÎÊЭÒé (LDAP)´æÔÚÕûÊýÒç³ö»ò»·ÈÆ©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.8£¬ÀÖ³ÉÀûÓø鶴µÄδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÒ»×éÌØÖÆµÄ LDAP µ÷ÓÃÀ´»ñÈ¡´úÂëÖ´ÐÐȨÏÞ£¬´Ó¶øÔÚ LDAP ·þÎñµÄÉÏÏÂÎÄÖÐÖ´ÐÐÈÎÒâ´úÂë ¡£

CVE-2024-49126£ºWindows Local Security Authority Subsystem Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

Windows µ±µØÄþ¾²»ú¹¹×Óϵͳ·þÎñ (LSASS)´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.1£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÍøÂçµ÷ÓÃÔÚ·þÎñÆ÷ÕÊ»§ÉÏÏÂÎÄÖд¥·¢¶ñÒâ´úÂ룬ÀÖ³ÉÀûÓø鶴¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬ÀÖ³ÉÀûÓø鶴ÐèÒª¹¥»÷ÕßÓ®µÃ¾ºÕùÌõ¼þ ¡£

CVE-2024-49118£ºMicrosoft Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft ÏûÏ¢ÐÐÁÐ (MSMQ)´æÔÚUse-After-Free©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.1£¬¹¥»÷Õß¿Éͨ¹ýÏò MSMQ ·þÎñÆ÷·¢ËÍÌØÖƵĶñÒâMSMQ Êý¾Ý°ü£¬¿ÉÄܵ¼Ö·þÎñÆ÷¶ËÔ¶³Ì´úÂëÖ´ÐÐ ¡£¸Ã©¶´µÄ¹¥»÷ÅÓ´ó¶È½Ï¸ß£¬¿ÉÄÜÐèÒª¹¥»÷ÕßÓ®µÃ¾ºÕùÌõ¼þ ¡£

CVE-2024-49122£ºMicrosoft Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft ÏûÏ¢ÐÐÁÐ (MSMQ)´æÔÚUse-After-Free©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.1£¬¹¥»÷Õß¿Éͨ¹ýÏòMSMQ·þÎñÆ÷·¢ËÍÌØÖƵĶñÒâMSMQ Êý¾Ý°üÀûÓø鶴£¬¿ÉÄܵ¼ÖÂÔÚ·þÎñÆ÷¶ËÔ¶³ÌÖ´ÐдúÂë ¡£ÀÖ³ÉÀûÓø鶴ÐèÒª¹¥»÷ÕßÓ®µÃ¾ºÕùÌõ¼þ£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ± ¡£

CVE-2024-49132/ CVE-2024-49115/ CVE-2024-49116/ CVE-2024-49123/ CVE-2024-49128/ CVE-2024-49106/ CVE-2024-49108£ºWindows Remote Desktop Services Ô¶³Ì´úÂëÖ´ÐЩ¶´

Windows Ô¶³Ì×ÀÃæ·þÎñ´æÔÚUse-After-Free©¶´»òÃô¸ÐÊý¾Ý´æ´¢ÔÚδÕýÈ·Ëø¶¨µÄÄÚ´æÖУ¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬ÕâЩ©¶´µÄCVSSÆÀ·Ö¾ùΪ8.1£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÁ¬½Óµ½ÔËÐÐÔ¶³Ì×ÀÃæÍø¹Ø½ÇÉ«µÄÄ¿±êϵͳ£¬ÀûÓþºÕùÌõ¼þ£¬´¥·¢Use-After-Free©¶´£¬ÀÖ³ÉÀûÓÃÕâЩ©¶´µÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿±êϵͳÉÏÖ´ÐÐÈÎÒâ´úÂ룬µ«ÐèÒª¹¥»÷ÕßÓ®µÃ¾ºÕùÌõ¼þ ¡£

CVE-2024-49119£ºWindows Remote Desktop Services Ô¶³Ì´úÂëÖ´ÐЩ¶´

Windows Ô¶³Ì×ÀÃæ·þÎñ´æÔÚÀàÐÍ»ìÏý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.1£¬ÀÖ³ÉÀûÓø鶴µÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿±êϵͳÉÏÖ´ÐÐÈÎÒâ´úÂ룬µ«ÐèÒª¹¥»÷ÕßÓ®µÃ¾ºÕùÌõ¼þ ¡£

CVE-2024-49120£ºWindows Remote Desktop Services Ô¶³Ì´úÂëÖ´ÐЩ¶´

Windows Ô¶³Ì×ÀÃæ·þÎñ´æÔÚ²»Äþ¾²µÄĬÈϱäÁ¿³õʼ»¯ÎÊÌ⣬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.1£¬ÀÖ³ÉÀûÓø鶴µÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿±êϵͳÉÏÖ´ÐÐÈÎÒâ´úÂ룬µ«ÐèÒª¹¥»÷ÕßÓ®µÃ¾ºÕùÌõ¼þ ¡£

³ýCVE-2024-49122Í⣬΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ©¶´»¹°üÂÞ£º

CVE-2024-49070£ºMicrosoft SharePoint Ô¶³Ì´úÂëÖ´ÐЩ¶´

Microsoft SharePoint´æÔÚ·´ÐòÁл¯Â©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.4£¬ÀÖ³ÉÀûÓø鶴¿ÉÄܵ¼Öµ±µØÈÎÒâ´úÂëÖ´ÐÐ ¡£

CVE-2024-49088£ºWindows Common Log File System DriverÌØȨÌáÉý©¶´

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½´æÔÚȨÏÞÌáÉý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8£¬¹¥»÷Õß¿ÉÀûÓø鶴»ñµÃ SYSTEM ȨÏÞ ¡£

CVE-2024-49090£ºWindows Common Log File System DriverÌØȨÌáÉý©¶´

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½´æÔÚȨÏÞÌáÉý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8£¬¹¥»÷Õß¿ÉÀûÓø鶴»ñµÃ SYSTEM ȨÏÞ ¡£

CVE-2024-49093£ºWindows µ¯ÐÔÎļþϵͳ (ReFS) ÌØȨÌáÉý©¶´

Windows Resilient File System (ReFS)´æÔÚȨÏÞÌáÉý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬¹¥»÷Õß¿ÉÀûÓø鶴»ñµÃ SYSTEM ȨÏÞ ¡£

CVE-2024-49114£ºWindows Cloud Files Mini Filter Çý¶¯·¨Ê½ÌØȨÌáÉý©¶´

Windows Cloud Files Mini Filter Çý¶¯·¨Ê½´æÔÚȨÏÞÌáÉý©¶´£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.8£¬¹¥»÷Õß¿ÉÀûÓø鶴»ñµÃ SYSTEM ȨÏÞ ¡£

΢Èí12Ô¸üÐÂÐÞ¸´µÄÍêÕû©¶´ÁбíÈçÏ£º

CVE 񅧏

CVE ±êÌâ

ÑÏÖØÐÔ

CVE-2024-49117

Windows Hyper-V Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-49124

Lightweight Directory Access Protocol (LDAP) Client Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-49112

Windows Lightweight Directory Access Protocol (LDAP) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-49127

Windows Lightweight Directory Access Protocol (LDAP) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-49126

Windows Local Security Authority Subsystem Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-49118

Microsoft Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-49122

Microsoft Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-49132

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-49115

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-49116

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-49123

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-49128

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-49106

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-49108

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-49119

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-49120

Windows Remote Desktop Services Ô¶³Ì´úÂëÖ´ÐЩ¶´

ÑÏÖØ

CVE-2024-49063

Microsoft/Muzic Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-49057

Microsoft Defender for Endpoint on Android ÆÛƭ©¶´

¸ßΣ

CVE-2024-49059

Microsoft Office ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-43600

Microsoft Office ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49142

Microsoft Access Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-49069

Microsoft Excel Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-49079

Input Method Editor (IME) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-49064

Microsoft SharePoint ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-49062

Microsoft SharePoint ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-49068

Microsoft SharePoint ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49070

Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-49065

Microsoft Office Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-49091

Windows Domain Name Service Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-43594

System Center Operations Manager ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49114

Windows Cloud Files Mini Filter Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49088

Windows Common Log File System Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49138

Windows Common Log File System Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49090

Windows Common Log File System Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49082

Windows File Explorer ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-49080

Windows IP Routing Management Snapin Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-49084

Windows Kernel ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49074

Windows Kernel-Mode Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49121

Windows Lightweight Directory Access Protocol (LDAP) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-49113

Windows Lightweight Directory Access Protocol (LDAP) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-49096

Microsoft Message Queuing (MSMQ) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-49073

Windows Mobile Broadband Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49077

Windows Mobile Broadband Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49083

Windows Mobile Broadband Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49092

Windows Mobile Broadband Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49087

Windows Mobile Broadband Driver ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-49110

Windows Mobile Broadband Driver ȨÌáÉý©¶´

¸ßΣ

CVE-2024-49078

Windows Mobile Broadband Driver ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49095

Windows PrintWorkflowUserSvc ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49097

Windows PrintWorkflowUserSvc ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49129

Windows Remote Desktop Gateway (RD Gateway) ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-49075

Windows Remote Desktop Services ¾Ü¾ø·þÎñ©¶´

¸ßΣ

CVE-2024-49093

Windows Resilient File System (ReFS) ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49085

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-49086

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-49089

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-49125

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-49104

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-49102

Windows Routing and Remote Access Service (RRAS) Ô¶³Ì´úÂëÖ´ÐЩ¶´

¸ßΣ

CVE-2024-49072

Windows Task Scheduler ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49076

Windows Virtualization-Based Security (VBS) Enclave ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49081

Wireless Wide Area Network Service (WwanSvc) Elevation ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49103

Windows Wireless Wide Area Network Service (WwanSvc) ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-49111

Wireless Wide Area Network Service (WwanSvc) ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49109

Wireless Wide Area Network Service (WwanSvc) ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49101

Wireless Wide Area Network Service (WwanSvc) ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49094

Wireless Wide Area Network Service (WwanSvc) ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49098

Windows Wireless Wide Area Network Service (WwanSvc) ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-49099

Windows Wireless Wide Area Network Service (WwanSvc) ÐÅϢ鶩¶´

¸ßΣ

CVE-2024-49107

WmsRepair Service ÌØȨÌáÉý©¶´

¸ßΣ

CVE-2024-49041

Microsoft Edge£¨»ùÓÚ Chromium£©ÆÛƭ©¶´

ÖÐΣ

ADV240002

Microsoft Office ×ÝÉî·ÀÓù¸üÐÂ

ÖÐΣ

CVE-2024-12053

Chromium£ºCVE-2024-12053 V8 ÖеÄÀàÐÍ»ìÏý

δ֪

 

¶þ¡¢Ó°Ï췶Χ

ÊÜÓ°ÏìµÄ²úÎï/¹¦Ð§/·þÎñ/×é¼þ°üÂÞ£º

System Center Operations Manager

Microsoft Office

Microsoft Edge (Chromium-based)

Microsoft Defender for Endpoint

Microsoft Office SharePoint

GitHub

Microsoft Office Word

Microsoft Office Excel

Windows Task Scheduler

Windows Mobile Broadband

Windows Kernel-Mode Drivers

Windows Remote Desktop Services

Windows Virtualization-Based Security (VBS) Enclave

Microsoft Office Publisher

Windows IP Routing Management Snapin

Windows Wireless Wide Area Network Service

Windows File Explorer

Windows Kernel

Windows Routing and Remote Access Service (RRAS)

Windows Common Log File System Driver

Role: DNS Server

Windows Resilient File System (ReFS)

Windows PrintWorkflowUserSvc

Windows Message Queuing

Remote Desktop Client

WmsRepair Service

Windows LDAP - Lightweight Directory Access Protocol

Windows Cloud Files Mini Filter Driver

Role: Windows Hyper-V

Windows Local Security Authority Subsystem Service (LSASS)

Windows Remote Desktop

Microsoft Office Access

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´ ¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×° ¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüР¡£

4¡¢¸üÐÂÍê³ÉºóÖØÆô¼ÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üР¡£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔز¢°²×° ¡£

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüР¡£

2024Äê12ÔÂÄþ¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Dec

²¹¶¡ÏÂÔØʾÀý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷©¶´ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó ¡£

image.png 

Àý1£ºÎ¢Èí©¶´ÁÐ±í£¨Ê¾Àý£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÎï¡¿ÁÐÑ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áдò¿ª²¹¶¡ÏÂÔØÁ´½Ó ¡£

image.png 

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý

3.µã»÷¡¾Äþ¾²¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐа²×° ¡£

image.png 

Àý3£º²¹¶¡ÏÂÔؽçÃæ

4.°²×°Íê³ÉºóÖØÆô¼ÆËã»ú ¡£

3.2 ÁÙʱ´ëÊ©

ÔÝÎÞ ¡£

3.3 ͨÓý¨Òé

l¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ ¡£

l¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼Æı£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ ¡£

lʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ ¡£

l¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È ¡£

lÆôÓÃÇ¿ÃÜÂë¼Æı²¢ÉèÖÃΪ¶¨ÆÚÐÞ¸Ä ¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Dec

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49138

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-12-11

Ê×´ÎÐû²¼

 

 

Îå¡¢¸½Â¼

5.1 ¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò» ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË ¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊÐ ¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦ ¡£

5.2 ¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯£¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´£¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½ ¡£

¹Ø×¢ÎÒÃÇ£º

image.png