¡¾Îó²îͨ¸æ¡¿Î¢Èí11Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2023-11-15Ò»¡¢Îó²î¸ÅÊö
2023Äê11ÔÂ14ÈÕ£¬Î¢ÈíÐû²¼ÁË11ÔÂÇå¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË58¸öÎó²î£¨²»°üÀ¨Ö®Ç°Ðû²¼µÄMicrosoft EdgeµÈÇå¾²¸üУ©£¬Îó²îÀàÐÍ°üÀ¨ÌØȨÌáÉýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾ø·þÎñÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²îºÍÓÕÆÎó²îµÈ¡£
±¾´ÎÇå¾²¸üй²ÐÞ¸´ÁË5¸ö0 dayÎó²î£¬ÆäÖÐ3¸öÒÑ·¢Ã÷ÔÚ¹¥»÷Öб»Ê¹Óã¬3¸öÒѾ¹ûÕæÅû¶¡£CVE-2023-36033ÏÖÔÚÒѾ¹ûÕæÅû¶£¬ÇÒÒÑ·¢Ã÷±»Ê¹Óá£ÏêÇéÈçÏ£º
CVE-2023-36036£ºWindows Cloud Files Mini Filter DriverÌØȨÌáÉýÎó²î£¨¸ßΣ£©
Windows ÔÆÎļþÃÔÄã¹ýÂËÆ÷Çý¶¯³ÌÐòÖб£´æÍâµØȨÏÞÌáÉýÎó²î£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.8£¬ÏÖÔÚÒÑ·¢Ã÷±»Ê¹Óá£
CVE-2023-36033£ºWindows DWM Core Library ÌØȨÌáÉýÎó²î£¨¸ßΣ£©
Windows DWM ½¹µã¿âÖб£´æÍâµØȨÏÞÌáÉýÎó²î£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.8£¬ÏÖÔÚÒѾ¹ûÕæÅû¶£¬ÇÒÒÑ·¢Ã÷±»Ê¹Óá£
CVE-2023-36025£ºWindows SmartScreenÇå¾²¹¦Ð§ÈƹýÎó²î£¨¸ßΣ£©
Windows SmartScreen±£´æÇå¾²¹¦Ð§ÈƹýÎó²î£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÈƹý Windows Defender SmartScreen ¼ì²é¼°ÆäÏà¹ØÌáÐÑ£¬Ê¹ÓøÃÎó²îÐèÒªÓû§½»»¥£¬ºÃ±ÈÓû§Ðëµ¥»÷ÌØÖÆµÄ Internet ¿ì½Ý·½·¨ (.URL) »òÖ¸Ïò Internet ¿ì½Ý·½·¨ÎļþµÄ³¬Á´½ÓµÈ¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.8£¬ÏÖÔÚÒÑ·¢Ã÷±»Ê¹Óá£
CVE-2023-36413£ºMicrosoft OfficeÇå¾²¹¦Ð§ÈƹýÎó²î£¨¸ßΣ£©
Microsoft OfficeÖб£´æÇå¾²¹¦Ð§ÈƹýÎó²î£¬¿ÉÒÔͨ¹ýÏòÓû§·¢ËͶñÒâÎļþ²¢ÓÕµ¼Óû§·¿ªÎļþÀ´Ê¹ÓøÃÎó²î£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÈƹý Office Êܱ£»¤µÄÊÓͼ²¢ÒÔ±à¼Ä£Ê½¶ø²»ÊDZ£»¤Ä£Ê½·¿ª¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ6.5£¬ÏÖÔÚÒѾ¹ûÕæÅû¶£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°¿ÉÄܱ»Ê¹Óᱡ£
CVE-2023-36038£ºASP.NET Core ¾Ü¾ø·þÎñÎó²î£¨¸ßΣ£©
ASP.NET Core±£´æ¾Ü¾ø·þÎñÎó²î£¬ÈôÊÇ×÷·Ï¶ÔIIS InProcessÍйÜÄ£×ÓÉÏÔËÐеÄ.NET 8 RC 1µÄhttpÇëÇó£¬Ôò¿ÉÒÔʹÓøÃÎó²î£¬Ê¹µÃÏ̼߳ÆÊýÔöÌí£¬²¢ÇÒ¿ÉÄ᷺ܻÆð OutOfMemoryException£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼Ö¾ܾø·þÎñ¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.2£¬ÏÖÔÚÒѾ¹ûÕæÅû¶¡£
ÆÀ¼¶ÎªÑÏÖصÄ3¸öÎó²îÏêÇéÈçÏ£º
CVE-2023-36052 £ºAzure CLI REST CommandÐÅϢй¶Îó²î£¨ÑÏÖØ£©
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.6£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÒÔ´ÓÊÜÓ°ÏìµÄCLIÏÂÁÉè²¢ÓÉAzure DevOps»òGitHub ActionsÐû²¼µÄÈÕÖ¾ÎļþÖлָ´Ã÷ÎÄÃÜÂëºÍÓû§Ãû¡£Ê¹ÓÃÊÜÓ°ÏìµÄ CLI ÏÂÁîµÄÓû§Ð뽫Æä Azure CLI °æ±¾¸üе½ 2.53.1»ò¸ü¸ß°æÔÀ´»º½â¸ÃÎó²î£¬ÕâÒ²ÊÊÓÃÓÚͨ¹ý Azure DevOps »ò GitHub Actions ʹÓÃÕâЩÏÂÁÉèÈÕÖ¾ÎļþµÄÓû§¡£
CVE-2023-36400£ºWindows HMAC Key DerivationÌØȨÌáÉýÎó²î£¨ÑÏÖØ£©
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.8£¬ÍþвÕß¿ÉÒÔ´ÓµÍȨÏÞµÄ Hyper-V guestÖ´Ðй¥»÷£¬´©Ô½guestµÄÇå¾²½çÏߣ¬ÔÚ Hyper-V Ö÷»úÖ´ÐÐÇéÐÎÉÏÖ´ÐдúÂë¡£ÀÖ³ÉʹÓøÃÎó²î¿ÉÒÔ»ñµÃSYSTEMȨÏÞ¡£
CVE-2023-36397£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨ÑÏÖØ£©
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.8£¬µ±WindowsÐÂÎÅÐÐÁзþÎñÔËÐÐÔÚPGM ServerÇéÐÎÖÐʱ£¬¿ÉÒÔͨ¹ýÍøÂç·¢ËÍÌØÖÆÎļþÀ´ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£Windows ÐÂÎÅÐÐÁзþÎñÊÇ Windows ×é¼þ£¨¿ÉÒÔͨ¹ý¹Ø±Õ¸Ã×é¼þÀ´»º½â¸ÃÎó²î£©£¬¿ÉÒÔͨ¹ý¼ì²éÊÇ·ñÖøÃûΪMessage QueuingµÄ·þÎñÔÚÔËÐУ¬ÒÔ¼°ÅÌËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£
΢Èí11Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º
CVE ID | CVE ÎÊÌâ | ÑÏÖØÐÔ |
CVE-2023-36052 | Azure CLI REST Command ÐÅϢй¶Îó²î | ÑÏÖØ |
CVE-2023-36400 | Windows HMAC Key Derivation ÌØȨÌáÉýÎó²î | ÑÏÖØ |
CVE-2023-36397 | Windows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-36049 | .NET¡¢.NET Framework ºÍ Visual Studio ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36560 | ASP.NET Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-36038 | ASP.NET Core ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-36558 | ASP.NET Core Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-38151 | Microsoft Host Integration Server 2020 Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-36021 | Microsoft On-Prem Êý¾ÝÍø¹ØÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-36437 | Azure DevOps Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24023 | Mitre£ºCVE-2023-24023 À¶ÑÀÎó²î | ¸ßΣ |
CVE-2023-36016 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2023-36007 | Microsoft Send Customer Voice survey from Dynamics 365 ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-36031 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2023-36410 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2023-36030 | Microsoft Dynamics 365 Sales ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-36027 | Microsoft Edge£¨»ùÓÚ Chromium£©È¨ÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36024 | Microsoft Edge£¨»ùÓÚ Chromium£©È¨ÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36439 | Microsoft Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-36050 | Microsoft Exchange Server ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-36039 | Microsoft Exchange Server ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-36035 | Microsoft Exchange Server ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-36413 | Microsoft Office Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-36045 | Microsoft Office Graphics Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-36041 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-36037 | Microsoft Excel Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-38177 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-36423 | Microsoft Remote Registry Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-36401 | Microsoft Remote Registry Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-36402 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-36394 | Windows Search Service ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36719 | Microsoft Speech Application Programming Interface (SAPI) ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36043 | Open Management Infrastructure ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-36393 | Windows User Interface Application Core Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-36042 | Visual Studio ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-36018 | Visual Studio Code Jupyter Extension ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-36047 | Windows Authentication ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36428 | Microsoft Local Security Authority Subsystem Service ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-36046 | Windows Authentication ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-36036 | Windows Cloud Files Mini Filter Driver ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36424 | Windows Common Log File System Driver ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36396 | Windows Compressed Folder Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-36422 | Microsoft Windows Defender ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36395 | Windows Deployment Services ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-36392 | DHCP Server Service ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-36425 | Windows ÂþÑÜʽÎļþϵͳ (DFS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-36033 | Windows DWM Core Library ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36427 | Windows Hyper-V ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36407 | Windows Hyper-V ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36406 | Windows Hyper-V ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-36408 | Windows Hyper-V ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36705 | Windows Installer ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36405 | Windows ÄÚºËÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36404 | Windows ÄÚºËÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-36403 | Windows ÄÚºËÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36398 | Windows NTFSÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-36028 | Microsoft Protected Extensible Authentication Protocol (PEAP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-36017 | Windows Scripting Engine ÄÚ´æËð»µÎó²î | ¸ßΣ |
CVE-2023-36025 | Windows SmartScreenÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-36399 | Windows Storage ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2023-36014 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÖÐΣ |
CVE-2023-36022 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÖÐΣ |
CVE-2023-36029 | Microsoft Edge£¨»ùÓÚ Chromium£©ÓÕÆÎó²î | ÖÐΣ |
CVE-2023-36034 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÖÐΣ |
CVE-2023-5996 | Chromium£ºCVE-2023-5996 ÔÚ WebAudio ÖÐÊͷźóʹÓà | δ֪ |
CVE-2023-5480 | Chromium£ºCVE-2023-5480 Ö§¸¶ÖÐʵÑé²»µ± | δ֪ |
CVE-2023-5856 | Chromium£ºCVE-2023-5856 ÔÚ²àÃæ°åÖÐÊͷźóʹÓà | δ֪ |
CVE-2023-5855 | Chromium£ºCVE-2023-5855 ÔÚÔĶÁģʽÏÂÊͷźóʹÓà | δ֪ |
CVE-2023-5854 | Chromium£ºCVE-2023-5854 ÔÚÉèÖÃÎļþÖÐÊͷźóʹÓà | δ֪ |
CVE-2023-5859 | Chromium£ºCVE-2023-5859 »ÖлÖеÄÇå¾² UI ²»×¼È· | δ֪ |
CVE-2023-5858 | Chromium£ºCVE-2023-5858 WebApp Provider ÖеÄʵÑé²»µ± | δ֪ |
CVE-2023-5857 | Chromium£ºCVE-2023-5857 ÏÂÔØÖеIJ»µ±ÊµÑé | δ֪ |
CVE-2023-5850 | Chromium£ºCVE-2023-5850 ÏÂÔØÖеÄÇå¾² UI ²»×¼È· | δ֪ |
CVE-2023-5849 | Chromium£ºCVE-2023-5849 USB ÖеÄÕûÊýÒç³ö | δ֪ |
CVE-2023-5482 | Chromium£ºCVE-2023-5482 USB ÖÐÊý¾ÝÑé֤ȱ·¦ | δ֪ |
CVE-2023-5853 | Chromium£ºCVE-2023-5853 ÏÂÔØÖеÄÇå¾² UI ²»×¼È· | δ֪ |
CVE-2023-5852 | Chromium£ºCVE-2023-5852 ÔÚ´òÓ¡ÖÐÊͷźóʹÓà | δ֪ |
CVE-2023-5851 | Chromium£ºCVE-2023-5851 ÏÂÔØÖÐʵÑé²»µ± | δ֪ |
CVE-2020-1747 | δ֪ | δ֪ |
CVE-2023-46316 | δ֪ | δ֪ |
CVE-2023-46753 | δ֪ | δ֪ |
CVE-2020-8554 | δ֪ | δ֪ |
CVE-2020-14343 | δ֪ | δ֪ |
¶þ¡¢Ó°Ïì¹æÄ£
ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/·þÎñ/×é¼þ°üÀ¨£º
Microsoft Dynamics
Microsoft Edge (Chromium-based)
Windows Scripting
Visual Studio Code
Azure
Windows SmartScreen
Windows Protected EAP (PEAP)
Microsoft Dynamics 365 Sales
Windows DWM Core Library
Microsoft Exchange Server
Windows Cloud Files Mini Filter Driver
Microsoft Office Excel
ASP.NET
Visual Studio
Open Management Infrastructure
Microsoft Office
Windows Authentication Methods
.NET Framework
Windows DHCP Server
Tablet Windows User Interface
Microsoft Windows Search Component
Windows Deployment Services
Windows Compressed Folder
Windows Internet Connection Sharing (ICS)
Windows NTFS
Windows Storage
Windows HMAC Key Derivation
Microsoft Remote Registry Service
Microsoft WDAC OLE DB provider for SQL
Windows Kernel
Windows Hyper-V
Windows Defender
Windows Common Log File System Driver
Windows Distributed File System (DFS)
Azure DevOps
Windows Installer
Microsoft Windows Speech
Microsoft Office SharePoint
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔÏ°취ÊÖ¶¯¾ÙÐиüУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔز¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£
2023Äê11ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2023-Nov
²¹¶¡ÏÂÔØʾÀý£º
1.·¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2022Äê2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý
3.µã»÷¡¾Çå¾²¸üС¿£¬·¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öá£
Àý3£º²¹¶¡ÏÂÔؽçÃæ
4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔ̽«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2023-Nov
https://www.bleepingcomputer.com/news/microsoft/microsoft-november-2023-patch-tuesday-fixes-5-zero-days-58-flaws/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-11-15 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ò½é
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½¨ÉèÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Çå¾²·þÎñ½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Æ𾢡£
5.2 ¹ØÓÚÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º