΢Èí³¬¸ßΣÎó²î¡°¿ñÔêÔÊÐí¡±À´Ï®£¡ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÌṩ½â¾ö¼Æ»®
Ðû²¼Ê±¼ä 2024-08-11¿ËÈÕ£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼à²âµ½WindowsÔ¶³Ì×ÀÃæÔÊÐí·þÎñÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-38077£©Ïà¹ØÐÅÏ¢¡£¸ÃÎó²îÓ°ÏìËùÓÐÆôÓà RDL ·þÎñµÄ Windows Server·þÎñÆ÷£¬Î´¾Éí·ÝÈÏÖ¤µÄ¹¥»÷Õß¿ÉʹÓøÃÎó²îÔ¶³ÌÖ´ÐдúÂ룬»ñÈ¡·þÎñÆ÷¿ØÖÆȨÏÞ¡£ÏÖÔÚ£¬¸ÃÎó²îµÄÊÖÒÕÔÀíºÍPOCα´úÂëÒѹûÕæ¡£¼øÓÚ´ËÎó²îÓ°Ïì¹æÄ£½Ï´ó£¬½¨Ò龡¿ì×öºÃ×Բ鼰·À»¤¡£
Îó²îÏêÇé
2024Äê07ÔÂ09ÈÕ£¬Î¢Èí¹Ù·½ÐÞ²¹ÁËÒ»¸ö±£´æÓÚWindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-38077£©¡£Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñ£¨RDL£©ÊÇÓÃÓÚÖÎÀíÔ¶³Ì×ÀÃæ(RDP)µÄÖ÷Òª×é¼þ£¬Æäͨ¹ýÖÎÀíºÍ·ÖÅÉÔÊÐíÖ¤À´¿ØÖƺͼà¿ØÔ¶³ÌÅþÁ¬µÄÕýµ±ÐÔ¡£
¾ÓÉÑо¿È·ÈÏ£¬¸ÃÎó²îÊÇÓÉÓÚRDL·þÎñδ׼ȷУÑéÓû§ÊäÈëÊý¾Ý£¬µ¼ÖÂÔÚÆÊÎöʱ±¬·¢Òç³ö£¬¹¥»÷Õß¿ÉÒÔÔÚδ¾ÓÉÉí·ÝÑéÖ¤µÄÇéÐÎÏ£¬Í¨¹ýÏò¿ªÆôRDL·þÎñµÄÖ÷»ú·¢ËÍÏà¹ØÔ¶³ÌŲÓÃÀ´Íê³ÉÎó²îʹÓá£ÀÖ³ÉʹÓøÃÎó²î¼´¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬´Ó¶øµ¼ÖÂÃô¸ÐÊý¾ÝµÄй¶£¬ÒÔ¼°¿ÉÄܵĶñÒâÈí¼þÈö²¥¡£¸ÃÎó²îÏÕЩӰÏìËùÓÐWindows Server°æ±¾¡£
Îó²î¸´ÏÖ
½â¾ö¼Æ»®
Ò»¡¢¹Ù·½ÐÞ¸´¼Æ»®
¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬½¨Ò齫ÊÜÓ°ÏìµÄWindowsÉý¼¶ÖÁ×îа汾£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38077
¶þ¡¢ÔÝʱÐÞ¸´¼Æ»®
¸Ã·þÎñĬÈÏδװÖã¬ÈçûÓÐÏà¹ØÓªÒµÐèÇ󣬿ÉÒԹرÕRemote Desktop Licensing·þÎñ¡£
Èý¡¢ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½â¾ö¼Æ»®
1¡¢ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ì²âÓë·À»¤Àà²úÆ·¼Æ»®
£¨1£©ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¡°ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©¡±Éý¼¶µ½20240810°æ±¾¼´¿ÉÖ§³Ö¼ì²â¸ÃÎó²î¡£
£¨2£©ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø ¡°ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡± Éý¼¶µ½20240810°æ±¾¼´¿ÉÖ§³Ö¼ì²â¸ÃÎó²î¡£
£¨3£©ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¡°ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©¡±Éý¼¶µ½20240810°æ±¾¼´¿ÉÖ§³Ö·À»¤¸ÃÎó²î¡£
2¡¢ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø©ɨ²úÆ·¼Æ»®
£¨1£©¡°ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳ¡±6075°æ±¾ÒѽôÆÈÐû²¼Õë¶Ô¸ÃÎó²îµÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃ裬Óû§Éý¼¶±ê×¼Îó²î¿âºó¼´¿É¶Ô¸ÃÎó²î¾ÙÐÐɨÃ裺
6070°æ±¾Éý¼¶°üΪ607000581-607000582.vup£¬Éý¼¶°üÏÂÔصص㣺https://venustech.download.venuscloud.cn/

£¨2£©ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳ608XϵÁа汾ÒѽôÆÈÐû²¼Õë¶Ô¸ÃÎó²îµÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃ裬Óû§Éý¼¶±ê×¼Îó²î¿âºó¼´¿É¶Ô¸ÃÎó²î¾ÙÐÐɨÃ裺
6080°æ±¾Éý¼¶°üΪÖ÷»ú²å¼þ°ü6080000130-S6080000131.svs©ɨ²å¼þ°üÏÂÔصص㣺
https://venustech.download.venuscloud.cn/£¨3£©Í¨¹ýÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳµÄÉèÖú˲éÄ£¿é¶Ô¸ÃÎó²îÓ°ÏìµÄWindows°æ±¾¾ÙÐлñÈ¡£¬Ê¹ÓÃÖÇÄÜ»¯ÆÊÎöÑÐÅлúÖÆÑéÖ¤¸ÃÎó²îÊÇ·ñ±£´æ£¬ÈôÊDZ£´æ¸ÃÎó²î½¨Òé¸üе½Çå¾²°æ±¾¡£
ÇëʹÓÃÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳ²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬ÊµÊ±¶Ô¸ÃÎó²î¾ÙÐмì²â£¬ÒԱ㾡¿ì½ÓÄÉÌá·À²½·¥¡£
3¡¢ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø×ʲúÓëųÈõÐÔÖÎÀíƽ̨²úÆ·¼Æ»®
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø×ʲúÓëųÈõÐÔÖÎÀíƽ̨ʵʱÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢£¬¶ÔÈë¿â×ʲúÎó²îWindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-38077£©¾ÙÐÐÖÎÀí¡£
4¡¢ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÇå¾²ÖÎÀíºÍ̬ÊƸÐ֪ƽ̨²úÆ·¼Æ»®
Óû§¿ÉÒÔͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍ̬ÊƸÐ֪ƽ̨£¬¾ÙÐйØÁªÕ½ÂÔÉèÖã¬ÍŽáÏÖÕæÏàÐÎÖÐϵͳÈÕÖ¾ºÍÇå¾²×°±¸µÄ¸æ¾¯ÐÅÏ¢¾ÙÐÐÒ»Á¬¼à¿Ø£¬´Ó¶ø·¢Ã÷¡°WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´ÐС±µÄÎó²îʹÓù¥»÷ÐÐΪ¡£
£¨1£©Í¨¹ýųÈõÐÔ·¢Ã÷¹¦Ð§Õë¶Ô¡°WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-38077£©¡±Îó²îɨÃèʹÃü£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´ËÎó²îÓ°ÏìµÄÖ÷Òª×ʲú¡£
£¨2£©Æ½Ì¨¡°¹ØÁªÆÊÎö¡±Ä£¿éÖУ¬Ìí¼Ó¡°L2_WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡±£¬Í¨¹ýÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ì²â×°±¸¡¢Ä¿µÄÖ÷»úϵͳµÈ×°±¸µÄ¸æ¾¯ÈÕÖ¾£¬·¢Ã÷Íⲿ¹¥»÷ÐÐΪ£º
̫ͨ¹ýÎö¹æÔò×Ô¶¯½«L2_WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´ÐÐÎó²îʹÓõĿÉÒÉÐÐΪԴµØµãÌí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ßΣº¦ÅþÁ¬¡±ÖУ¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓã»
£¨3£©Ìí¼Ó¡°L3_WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´ÐÐÎó²îʹÓÃÀֳɡ±£¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ»ò°üÀ¨¡°L2_WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´ÐÐÎó²îʹÓá±£¬¹¥»÷Ч¹û¼´ÊÇ¡°¹¥»÷Àֳɡ±£¬Ä¿µÄµØµãÒýÓÃ×ʲúÎó²î»òÔ´µØµãÆ¥ÅäÍþвÇ鱨£¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶȡ£
£¨4£©Æ¾Ö¤¶ÔCVE-2024-38077Îó²îµÄ¹¥»÷ʹÓÃÀú³Ì¾ÙÐÐÆÊÎö£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍÊÖÒս׶Σ¬ÁýÕÖµÄTTP°üÀ¨£º
TA0001³õʼ»á¼û£ºT1190ʹÓÃÃæÏò¹«ÖÚµÄÓ¦ÓóÌÐò
TA0002Ö´ÐУºT1059ÏÂÁîºÍ¾ç±¾Ú¹ÊÍÆ÷
TA0004ȨÏÞÌáÉý£ºT1548ÀÄÓÃÌáȨ¿ØÖÆ»úÖÆ
TA0010Êý¾ÝÍâй£ºT1041Êý¾Ýͨ¹ýC2ͨµÀÍâй
ͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍ̬ÊƸÐ֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´¦Öóͷ£ÄÜÁ¦£¬Õë¶Ô¸ÃÎó²îʹÓõĸ澯ÊÂÎñ±àÅž籾£¬¾ÙÐÐ×Ô¶¯»¯´¦Öóͷ£¡£