¡¾Îó²îͨ¸æ¡¿Î¢Èí1Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2024-01-10Ò»¡¢Îó²î¸ÅÊö
2024Äê1ÔÂ9ÈÕ£¬Î¢ÈíÐû²¼ÁË1ÔÂÇå¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË49¸öÎó²î£¨²»°üÀ¨1ÔÂ5ÈÕÐÞ¸´µÄ4¸öMicrosoft EdgeÎó²î£©£¬Îó²îÀàÐÍ°üÀ¨ÌØȨÌáÉýÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾ø·þÎñÎó²îºÍÓÕÆÎó²îµÈ¡£
±¾´ÎÇå¾²¸üÐÂÖÐûÓб»Æð¾¢Ê¹Óûò¹ûÕæÅû¶µÄÎó²î£¬ÆäÖÐÆÀ¼¶ÎªÑÏÖصÄ2¸öÎó²î°üÀ¨£º
CVE-2024-20674£ºWindows Kerberos Çå¾²¹¦Ð§ÈƹýÎó²î£¨ÑÏÖØ£©
¶ÔÊÜÏÞÍøÂçÓµÓлá¼ûȨÏÞµÄÍþвÕß¿Éͨ¹ý½¨Éèmachine-in-the-middle (MITM£¬ÖÐÐÄ»ú)¹¥»÷»òÆäËüÍâµØÍøÂçÓÕÆÊÖÒÕÀ´Ê¹ÓøÃÎó²î£¬È»ºóÏò¿Í»§¶ËÊܺ¦»úе·¢ËͶñÒâKerberos ÐÂÎÅÒÔð³äKerberosÉí·ÝÑéÖ¤·þÎñÆ÷£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÈƹýÉí·ÝÑéÖ¤¹¦Ð§¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.0£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐԽϴ󡱡£
CVE-2024-20700£ºWindows Hyper-V Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©
¸ÃÎó²îµÄ¹¥»÷ÖØƯºó½Ï¸ß£¬ÀÖ³ÉʹÓøÃÎó²îÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬ÇÒÐèÒª»ñµÃ¶ÔÊÜÏÞÍøÂçµÄ»á¼ûȨÏÞ£¬ÆäCVSSÆÀ·ÖΪ7.5£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐÔ½ÏС¡±¡£
ÆäËüÖµµÃ¹Ø×¢µÄÎó²î»¹°üÀ¨µ«²»ÏÞÓÚ£º
CVE-2024-21307£ºRemote Desktop ClientÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©
¸ÃÎó²îµÄ¹¥»÷ÖØƯºó½Ï¸ß£¬ÀÖ³ÉʹÓô˸ö´ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬ÇÒÐèÒªÓû§½»»¥£¬Î´ÊÚȨÍþвÕß±ØÐèÆÚ´ýÓû§Æô¶¯ÅþÁ¬¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.5£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐԽϴ󡱡£
CVE-2024-21318£ºMicrosoft SharePoint ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©
¾ÓÉÉí·ÝÑéÖ¤µÄÍþвÕߣ¨ÖÁÉÙÊÇÍøÕ¾ËùÓÐÕߣ©¿ÉʹÓøÃÎó²î×¢Èëí§Òâ´úÂ룬²¢ÔÚ SharePoint Server µÄÉÏÏÂÎÄÖÐÖ´ÐиôúÂë¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐԽϴ󡱡£
³ýCVE-2024-20674¡¢CVE-2024-21307ºÍCVE-2024-21318Í⣬΢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀÖС°±»Ê¹ÓõĿÉÄÜÐԽϴ󡱵ÄÎó²î»¹°üÀ¨£º
CVE-2024-20652£ºWindows HTMLƽ̨Çå¾²¹¦Ð§ÈƹýÎó²î£¨¸ßΣ£©
CVE-2024-20653£ºMicrosoft Common Log File SystemÌØȨÌáÉýÎó²î£¨¸ßΣ£©
CVE-2024-20683£ºWin32k ÌØȨÌáÉýÎó²î£¨¸ßΣ£©
CVE-2024-20686£ºWin32k ÌØȨÌáÉýÎó²î£¨¸ßΣ£©
CVE-2024-20698£ºWindows ÄÚºËÌØȨÌáÉýÎó²î£¨¸ßΣ£©
CVE-2024-21310£ºWindows Cloud Files Mini Filter DriverÌØȨÌáÉýÎó²î£¨¸ßΣ£©
΢Èí1Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º
CVE ID | CVE ÎÊÌâ | ÑÏÖØÐÔ |
CVE-2024-20674 | Windows Kerberos Çå¾²¹¦Ð§ÈƹýÎó²î | ÑÏÖØ |
CVE-2024-20700 | Windows Hyper-V Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2024-0057 | NET¡¢.NET Framework ºÍ Visual Studio Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2024-20672 | .NET Core ºÍ Visual Studio ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2024-21312 | .NET Framework ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2024-20676 | Azure Storage Mover Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21306 | Microsoft Bluetooth Driver ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-21325 | Microsoft Printer Metadata Troubleshooter Tool Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21319 | Microsoft Identity ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2024-20677 | Microsoft Office Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21318 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-20658 | Microsoft Virtual Hard Disk ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21307 | Remote Desktop Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-0056 | Microsoft.Data.SqlClient ºÍ System.Data.SqlClient SQLÊý¾ÝÌṩ³ÌÐòÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2022-35737 | MITRE£ºCVE-2022-35737 SQLite ÔÊÐíÊý×é½çÏßÒç³ö | ¸ßΣ |
CVE-2024-21305 | Hypervisor-Protected Code Integrity (HVCI) Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2024-20656 | Visual Studio ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-20687 | Microsoft AllJoyn API ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2024-20666 | BitLocker Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2024-21310 | Windows Cloud Files Mini Filter Driver ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-20694 | Windows CoreMessaging ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-20653 | Microsoft Common Log File System ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-20682 | Windows Cryptographic Services Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21311 | Windows Cryptographic Services ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-20657 | Windows Group Policy ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-20699 | Windows Hyper-V ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2024-20698 | Windows Kernel ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21309 | Windows Kernel-Mode Driver ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-20697 | Windows Libarchive Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-20696 | Windows Libarchive Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-20692 | Microsoft Local Security Authority Subsystem Service ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-20660 | Microsoft Message Queuing ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-20664 | Microsoft Message Queuing ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-20680 | Windows Message Queuing Client (MSMQC) ÐÅϢй¶ | ¸ßΣ |
CVE-2024-20663 | Windows Message Queuing Client (MSMQC) ÐÅϢй¶ | ¸ßΣ |
CVE-2024-21314 | Microsoft Message Queuing ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-20661 | Microsoft Message Queuing ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2024-20690 | Windows Nearby Sharing ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-20654 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-20662 | Windows Online Certificate Status Protocol (OCSP) ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-20655 | Microsoft Online Certificate Status Protocol (OCSP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-20652 | Windows HTML Platforms Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2024-21316 | Windows Server Key Distribution Çå¾²¹¦Ð§Èƹý | ¸ßΣ |
CVE-2024-20681 | Windows Subsystem for Linux ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21313 | Windows TCP/IP ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-20691 | Windows Themes ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-21320 | Windows Themes ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-20686 | Win32k ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-20683 | Win32k ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-0222 | Chromium£ºCVE-2024-0222 ÔÚ ANGLE ÖÐÊͷźóʹÓà | δ֪ |
CVE-2024-0223 | Chromium£ºCVE-2024-0223 ANGLE ¶Ñ»º³åÇøÒç³ö | δ֪ |
CVE-2024-0224 | Chromium£ºCVE-2024-0224 ÔÚ WebAudio ÖÐÊͷźóʹÓà | δ֪ |
CVE-2024-0225 | Chromium£ºCVE-2024-0225 ÔÚ WebGPU ÖÐÊͷźóʹÓà | δ֪ |
¶þ¡¢Ó°Ïì¹æÄ£
ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/·þÎñ/×é¼þ°üÀ¨£º
SQL Server
.NET and Visual Studio
Windows Scripting
Windows Common Log File System Driver
Windows ODBC Driver
Windows Online Certificate Status Protocol (OCSP) SnapIn
Visual Studio
Windows Group Policy
Microsoft Virtual Hard Drive
Windows Message Queuing
Windows BitLocker
.NET Core & Visual Studio
Windows Authentication Methods
Azure Storage Mover
Microsoft Office
Windows Subsystem for Linux
Windows Cryptographic Services
Windows Win32K
Windows Win32 Kernel Subsystem
Windows AllJoyn API
Windows Nearby Sharing
Windows Themes
Windows Local Security Authority Subsystem Service (LSASS)
Windows Collaborative Translation Framework
Windows Libarchive
Windows Kernel
Windows Hyper-V
Unified Extensible Firmware Interface
Microsoft Bluetooth Driver
Remote Desktop Client
Windows Kernel-Mode Drivers
Windows Cloud Files Mini Filter Driver
.NET Framework
Windows TCP/IP
Windows Server Key Distribution Service
Microsoft Office SharePoint
Microsoft Identity Services
Microsoft Devices
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔÏ°취ÊÖ¶¯¾ÙÐиüУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔز¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£
2024Äê1ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2024-Jan
²¹¶¡ÏÂÔØʾÀý£¨²Î¿¼£©£º
1.·¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2022Äê2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý
3.µã»÷¡¾Çå¾²¸üС¿£¬·¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öá£
Àý3£º²¹¶¡ÏÂÔؽçÃæ
4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔ̽«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Jan
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-20674
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-01-10 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ò½é
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½¨ÉèÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Çå¾²·þÎñ½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Æ𾢡£
5.2 ¹ØÓÚÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º