¡¾Îó²îͨ¸æ¡¿Î¢Èí1Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2024-01-10


Ò»¡¢Îó²î¸ÅÊö

2024Äê1ÔÂ9ÈÕ£¬Î¢ÈíÐû²¼ÁË1ÔÂÇå¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË49¸öÎó²î£¨²»°üÀ¨1ÔÂ5ÈÕÐÞ¸´µÄ4¸öMicrosoft EdgeÎó²î£©£¬Îó²îÀàÐÍ°üÀ¨ÌØȨÌáÉýÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾ø·þÎñÎó²îºÍÓÕÆ­Îó²îµÈ¡£

±¾´ÎÇå¾²¸üÐÂÖÐûÓб»Æð¾¢Ê¹Óûò¹ûÕæÅû¶µÄÎó²î£¬ÆäÖÐÆÀ¼¶ÎªÑÏÖصÄ2¸öÎó²î°üÀ¨£º

CVE-2024-20674£ºWindows Kerberos Çå¾²¹¦Ð§ÈƹýÎó²î£¨ÑÏÖØ£©

¶ÔÊÜÏÞÍøÂçÓµÓлá¼ûȨÏÞµÄÍþвÕß¿Éͨ¹ý½¨Éèmachine-in-the-middle (MITM£¬ÖÐÐÄ»ú)¹¥»÷»òÆäËüÍâµØÍøÂçÓÕÆ­ÊÖÒÕÀ´Ê¹ÓøÃÎó²î£¬È»ºóÏò¿Í»§¶ËÊܺ¦»úе·¢ËͶñÒâKerberos ÐÂÎÅÒÔð³äKerberosÉí·ÝÑéÖ¤·þÎñÆ÷£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÈƹýÉí·ÝÑéÖ¤¹¦Ð§¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.0£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐԽϴ󡱡£

CVE-2024-20700£ºWindows Hyper-V Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©

¸ÃÎó²îµÄ¹¥»÷ÖØƯºó½Ï¸ß£¬ÀÖ³ÉʹÓøÃÎó²îÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬ÇÒÐèÒª»ñµÃ¶ÔÊÜÏÞÍøÂçµÄ»á¼ûȨÏÞ£¬ÆäCVSSÆÀ·ÖΪ7.5£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐÔ½ÏС¡±¡£

ÆäËüÖµµÃ¹Ø×¢µÄÎó²î»¹°üÀ¨µ«²»ÏÞÓÚ£º

CVE-2024-21307£ºRemote Desktop ClientÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©

¸ÃÎó²îµÄ¹¥»÷ÖØƯºó½Ï¸ß£¬ÀÖ³ÉʹÓô˸ö´ÐèÒªÓ®µÃ¾ºÕùÌõ¼þ£¬ÇÒÐèÒªÓû§½»»¥£¬Î´ÊÚȨÍþвÕß±ØÐèÆÚ´ýÓû§Æô¶¯ÅþÁ¬¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.5£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐԽϴ󡱡£

CVE-2024-21318£ºMicrosoft SharePoint ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©

¾­ÓÉÉí·ÝÑéÖ¤µÄÍþвÕߣ¨ÖÁÉÙÊÇÍøÕ¾ËùÓÐÕߣ©¿ÉʹÓøÃÎó²î×¢Èëí§Òâ´úÂ룬²¢ÔÚ SharePoint Server µÄÉÏÏÂÎÄÖÐÖ´ÐиôúÂë¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐԽϴ󡱡£

³ýCVE-2024-20674¡¢CVE-2024-21307ºÍCVE-2024-21318Í⣬΢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀÖС°±»Ê¹ÓõĿÉÄÜÐԽϴ󡱵ÄÎó²î»¹°üÀ¨£º

CVE-2024-20652£ºWindows HTMLƽ̨Çå¾²¹¦Ð§ÈƹýÎó²î£¨¸ßΣ£©

CVE-2024-20653£ºMicrosoft Common Log File SystemÌØȨÌáÉýÎó²î£¨¸ßΣ£©

CVE-2024-20683£ºWin32k ÌØȨÌáÉýÎó²î£¨¸ßΣ£©

CVE-2024-20686£ºWin32k ÌØȨÌáÉýÎó²î£¨¸ßΣ£©

CVE-2024-20698£ºWindows ÄÚºËÌØȨÌáÉýÎó²î£¨¸ßΣ£©

CVE-2024-21310£ºWindows Cloud Files Mini Filter DriverÌØȨÌáÉýÎó²î£¨¸ßΣ£©

΢Èí1Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE ID

CVE ÎÊÌâ

ÑÏÖØÐÔ

CVE-2024-20674

Windows   Kerberos Çå¾²¹¦Ð§ÈƹýÎó²î

ÑÏÖØ

CVE-2024-20700

Windows   Hyper-V Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2024-0057

NET¡¢.NET Framework ºÍ Visual Studio Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-20672

.NET Core ºÍ Visual Studio ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-21312

.NET   Framework ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-20676

Azure   Storage Mover Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21306

Microsoft   Bluetooth Driver ÓÕÆ­Îó²î

¸ßΣ

CVE-2024-21325

Microsoft   Printer Metadata Troubleshooter Tool Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21319

Microsoft   Identity ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-20677

Microsoft   Office Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21318

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-20658

Microsoft   Virtual Hard Disk ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2024-21307

Remote   Desktop Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-0056

Microsoft.Data.SqlClient   ºÍ System.Data.SqlClient SQLÊý¾ÝÌṩ³ÌÐòÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2022-35737

MITRE£ºCVE-2022-35737 SQLite ÔÊÐíÊý×é½çÏßÒç³ö

¸ßΣ

CVE-2024-21305

Hypervisor-Protected   Code Integrity (HVCI) Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-20656

Visual   Studio ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-20687

Microsoft   AllJoyn API ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-20666

BitLocker Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-21310

Windows   Cloud Files Mini Filter Driver ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-20694

Windows   CoreMessaging ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-20653

Microsoft   Common Log File System ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-20682

Windows   Cryptographic Services Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21311

Windows   Cryptographic Services ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-20657

Windows   Group Policy ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2024-20699

Windows   Hyper-V ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-20698

Windows   Kernel ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-21309

Windows   Kernel-Mode Driver ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-20697

Windows   Libarchive Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-20696

Windows   Libarchive Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-20692

Microsoft   Local Security Authority Subsystem Service ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-20660

Microsoft   Message Queuing ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-20664

Microsoft   Message Queuing ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-20680

Windows   Message Queuing Client (MSMQC) ÐÅϢй¶

¸ßΣ

CVE-2024-20663

Windows   Message Queuing Client (MSMQC) ÐÅϢй¶

¸ßΣ

CVE-2024-21314

Microsoft   Message Queuing ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-20661

Microsoft   Message Queuing ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-20690

Windows   Nearby Sharing ÓÕÆ­Îó²î

¸ßΣ

CVE-2024-20654

Microsoft   ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-20662

Windows   Online Certificate Status Protocol (OCSP) ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-20655

Microsoft   Online Certificate Status Protocol (OCSP) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-20652

Windows   HTML Platforms Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-21316

Windows   Server Key Distribution Çå¾²¹¦Ð§Èƹý

¸ßΣ

CVE-2024-20681

Windows   Subsystem for Linux ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-21313

Windows   TCP/IP ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-20691

Windows   Themes ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-21320

Windows   Themes ÓÕÆ­Îó²î

¸ßΣ

CVE-2024-20686

Win32k ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-20683

Win32k ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-0222

Chromium£ºCVE-2024-0222 ÔÚ ANGLE ÖÐÊͷźóʹÓÃ

δ֪

CVE-2024-0223

Chromium£ºCVE-2024-0223 ANGLE ¶Ñ»º³åÇøÒç³ö

δ֪

CVE-2024-0224

Chromium£ºCVE-2024-0224 ÔÚ WebAudio ÖÐÊͷźóʹÓÃ

δ֪

CVE-2024-0225

Chromium£ºCVE-2024-0225 ÔÚ WebGPU ÖÐÊͷźóʹÓÃ

δ֪



¶þ¡¢Ó°Ïì¹æÄ£

ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/·þÎñ/×é¼þ°üÀ¨£º

SQL Server

.NET and Visual Studio

Windows Scripting

Windows Common Log File System Driver

Windows ODBC Driver

Windows Online Certificate Status Protocol (OCSP) SnapIn

Visual Studio

Windows Group Policy

Microsoft Virtual Hard Drive

Windows Message Queuing

Windows BitLocker

.NET Core & Visual Studio

Windows Authentication Methods

Azure Storage Mover

Microsoft Office

Windows Subsystem for Linux

Windows Cryptographic Services

Windows Win32K

Windows Win32 Kernel Subsystem

Windows AllJoyn API

Windows Nearby Sharing

Windows Themes

Windows Local Security Authority Subsystem Service (LSASS)

Windows Collaborative Translation Framework

Windows Libarchive

Windows Kernel

Windows Hyper-V

Unified Extensible Firmware Interface

Microsoft Bluetooth Driver

Remote Desktop Client

Windows Kernel-Mode Drivers

Windows Cloud Files Mini Filter Driver

.NET Framework

Windows TCP/IP

Windows Server Key Distribution Service

Microsoft Office SharePoint

Microsoft Identity Services

Microsoft Devices

 

 

Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔÏ°취ÊÖ¶¯¾ÙÐиüУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔز¢×°Öá£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£

2024Äê1ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Jan

²¹¶¡ÏÂÔØʾÀý£¨²Î¿¼£©£º

1.·­¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2022Äê2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·­¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý

3.µã»÷¡¾Çå¾²¸üС¿£¬·­¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öá£

image.png

Àý3£º²¹¶¡ÏÂÔؽçÃæ

4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£

3.2 ÔÝʱ²½·¥

ÔÝÎÞ¡£

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔ̭ϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔÌ­½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔÌ­¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Jan

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-20674

 

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-01-10

Ê×´ÎÐû²¼

 

 

Îå¡¢¸½Â¼

5.1 ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ò½é

ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½¨ÉèÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Çå¾²·þÎñ½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Æ𾢡£

5.2 ¹ØÓÚÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø

ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png