¡¾Îó²îͨ¸æ¡¿Î¢Èí2Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2024-02-19


Ò»¡¢Îó²î¸ÅÊö

2024Äê2ÔÂ13ÈÕ£¬Î¢ÈíÐû²¼ÁË2ÔÂÇå¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË73¸öÎó²î£¨²»°üÀ¨2ÔÂ8ÈÕÐÞ¸´µÄMicrosoft EdgeºÍÆäËüÎó²î£©£¬Îó²îÀàÐÍ°üÀ¨ÌØȨÌáÉýÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾ø·þÎñÎó²îºÍÓÕÆ­Îó²îµÈ¡£

±¾´ÎÇå¾²¸üÐÂÖаüÀ¨2¸ö±»Æð¾¢Ê¹ÓõÄ0 dayÎó²î£º

CVE-2024-21351£ºWindows SmartScreen Çå¾²¹¦Ð§ÈƹýÎó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.6£¬ÍþвÕß¿ÉÏòÓû§·¢ËͶñÒâÎļþ²¢ÓÕµ¼Óû§·­¿ªÎļþÀ´Ê¹ÓøÃÎó²î£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÈƹý SmartScreenÇå¾²¹¦Ð§¡£¸ÃÎó²îÔÊÐíÍþвÕß½«´úÂë×¢Èë SmartScreen ²¢¿ÉÄÜ»ñµÃ´úÂëÖ´ÐÐȨÏÞ£¬´Ó¶ø¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢ÏµÍ³¿ÉÓÃÐÔÓ°Ï죬ÏÖÔÚ¸ÃÎó²îÒѼì²âµ½Îó²îʹÓá£

CVE-2024-21412£ºInternet ¿ì½Ý·½·¨ÎļþÇå¾²¹¦Ð§ÈƹýÎó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.1£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔÏòÄ¿µÄÓû§·¢ËÍÖ¼ÔÚÈƹýÏÔʾµÄÇå¾²¼ì²éµÄÌØÖÆÎļþ²¢ÓÕµ¼Óû§·­¿ª¸ÃÎļþ£¬µ¼ÖÂÇå¾²¹¦Ð§Èƹý¡£ÒÑ·¢Ã÷APT×éÖ¯Water Hydra£¨ÓÖÃû DarkCasino£©ÔÚÕë¶Ô½ðÈÚÉúÒâÕßµÄÔ˶¯ÖÐÆð¾¢Ê¹ÓøÃÎó²î¡£

±¾´ÎÇå¾²¸üÐÂÖУ¬ÆÀ¼¶Îª¡°ÑÏÖØ¡±µÄ5¸öÎó²î°üÀ¨£º

CVE-2024-21380£ºMicrosoft Dynamics Business Central/NAV ÐÅϢй¶Îó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.0£¬ÀÖ³ÉʹÓøÃÎó²îÐèÒª¾­ÓÉÉí·ÝÑéÖ¤¡¢Ó®µÃ¾ºÕùÌõ¼þ£¬²¢ÐèÒªÓû§½»»¥£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕß¿ÉÒÔ»á¼ûÓû§Êý¾Ý£¬µ¼ÖÂδÊÚȨ»á¼ûÊܺ¦ÕßµÄÕË»§»òй¶ÆäËüÉñÃØÐÅÏ¢¡£

CVE-2024-21410£ºMicrosoft Exchange Server ȨÏÞÌáÉýÎó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕß¿ÉÒÔ½«Óû§Ð¹Â¶µÄNet-NTLMv2¹þÏ£Öм̵½Ò×Êܹ¥»÷µÄExchange Server£¬²¢ÒÔÓû§Éí·Ý¾ÙÐÐÉí·ÝÑéÖ¤¡£ÊÜÓ°ÏìÓû§Ò²¿É²Î¿¼¹Ù·½ÌṩµÄÎĵµºÍ¾ç±¾Îª Exchange ServerÆôÓÃÉí·ÝÑéÖ¤À©Õ¹±£»¤ (EPA)À´»º½â¸ÃÎó²î£¬ÏÖÔÚ¸ÃÎó²îÒѼì²âµ½Îó²îʹÓá£

CVE-2024-21413£ºMicrosoft OutlookÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÈƹý Office Êܱ£»¤µÄÊÓͼ²¢ÒԱ༭ģʽ¶ø²»ÊDZ£»¤Ä£Ê½·­¿ª£¬Ô¤ÀÀ´°¸ñÊǸÃÎó²îµÄÒ»¸ö¹¥»÷Ç°ÑÔ¡£ÍþвÕß¿ÉÒÔ½¨ÉèÈƹýÊܱ£»¤ÊÓͼЭÒéµÄ¶ñÒâÁ´½Ó£¬´Ó¶øµ¼ÖÂÍâµØNTLMƾ֤ÐÅϢй¶ºÍÔ¶³Ì´úÂëÖ´ÐС£

CVE-2024-20684£ºWindows Hyper-V ¾Ü¾ø·þÎñÎó²î

¸ÃÎó²îµÄCVSSÆÀ·ÖΪ6.5£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼Ö Hyper-V guestÓ°Ïì Hyper-V Ö÷»úµÄ¹¦Ð§¡£

CVE-2024-21357£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Windows Pragmatic General Multicast (PGM) ±¬·¢µÄ×é²¥Á÷Á¿ÔÚµÚ4 ²ãÔËÐв¢¿É·ÓÉ£¬ÍþвÕß¿ÉÒÔͨ¹ýÏòÒ×Êܹ¥»÷µÄ·þÎñÆ÷·¢ËÍÌØÖƵĶñÒâÁ÷Á¿À´Ê¹ÓøÃÎó²î¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.1£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐԽϸߡ±¡£

³ýCVE-2024-21410ºÍCVE-2024-21357ÒÔÍ⣬±¾´ÎÇå¾²¸üÐÂÖУ¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀÖС°±»Ê¹ÓõĿÉÄÜÐԽϸߡ±µÄÎó²î»¹°üÀ¨£º

CVE-2024-21338£ºWindows ÄÚºËÌØȨÌáÉýÎó²î

CVE-2024-21345£ºWindows ÄÚºËÌØȨÌáÉýÎó²î

CVE-2024-21346£ºWin32k ÌØȨÌáÉýÎó²î

CVE-2024-21371£ºWindows ÄÚºËÌØȨÌáÉýÎó²î

CVE-2024-21378£ºMicrosoft OutlookÔ¶³Ì´úÂëÖ´ÐÐÎó²î

CVE-2024-21379£ºMicrosoft WordÔ¶³Ì´úÂëÖ´ÐÐÎó²î

΢Èí2Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE ID

CVE ÎÊÌâ

ÑÏÖØÐÔ

CVE-2024-21380

Microsoft   Dynamics Business Central/NAV ÐÅϢй¶Îó²î

ÑÏÖØ

CVE-2024-21410

Microsoft   Exchange Server ȨÏÞÌáÉýÎó²î

ÑÏÖØ

CVE-2024-21413

Microsoft   Outlook Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2024-20684

Windows   Hyper-V ¾Ü¾ø·þÎñÎó²î

ÑÏÖØ

CVE-2024-21357

Windows   Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2024-21386

.NET ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-21404

.NET ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-21401

Microsoft   Entra Jira Single-Sign-On Plugin ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2024-21381

Microsoft   Azure Active Directory B2C ÓÕÆ­Îó²î

¸ßΣ

CVE-2024-21329

Azure   Connected Machine Agent ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2024-20667

Azure   DevOps Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21397

Microsoft   Azure File SyncȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2024-20679

Azure   Stack Hub ÓÕÆ­Îó²î

¸ßΣ

CVE-2024-21412

Internet ¿ì½Ý·½·¨ÎļþÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-21349

Microsoft   ActiveX Êý¾Ý¹¤¾ßÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21403

Microsoft   Azure Kubernetes Service Confidential Container ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-21376

Microsoft   Azure Kubernetes Service Confidential Container Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21315

Microsoft   Defender for Endpoint Protection ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2024-21393

Microsoft   Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾Îó²î

¸ßΣ

CVE-2024-21389

Microsoft   Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾Îó²î

¸ßΣ

CVE-2024-21395

Microsoft   Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾Îó²î

¸ßΣ

CVE-2024-21328

Dynamics   365 Sales ÓÕÆ­Îó²î

¸ßΣ

CVE-2024-21394

Dynamics   365 Field Service ÓÕÆ­Îó²î

¸ßΣ

CVE-2024-21396

Dynamics   365 Sales ÓÕÆ­Îó²î

¸ßΣ

CVE-2024-21327

Microsoft   Dynamics 365 Customer Engagement ¿çÕ¾¾ç±¾Îó²î

¸ßΣ

CVE-2024-20673

Microsoft   Office Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21384

Microsoft   Office OneNote Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21378

Microsoft   Outlook Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21402

Microsoft   Outlook ȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2024-21379

Microsoft   Word Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21374

Microsoft   Teams for Android ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-21353

Microsoft   WDAC ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21370

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21350

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21368

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21359

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21365

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21367

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21420

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21366

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21369

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21375

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21361

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21358

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21391

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21360

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21352

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21406

Windows   Printing Service ÓÕÆ­Îó²î

¸ßΣ

CVE-2024-21377

Windows   DNS ÐÅϢй¶Îó²î

¸ßΣ

CVE-2023-50387

MITRE£ºCVE-2023-50387 DNSSEC ÑéÖ¤ÖØ´óÐԿɱ»Ê¹ÓÃÀ´ºÄ¾¡ CPU ×ÊÔ´²¢×èÖ¹ DNS ÆÊÎöÆ÷

¸ßΣ

CVE-2024-21342

Windows   DNS Client ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-20695

Skype for   Business ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-21347

Microsoft   ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21304

Trusted   Compute Base ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-21343

Windows   Network Address Translation (NAT) ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-21348

Internet   Connection Sharing (ICS) ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-21344

Windows Network   Address Translation (NAT) ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-21371

Windows   Kernel ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-21338

Windows   Kernel ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-21341

Windows   Kernel Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21345

Windows   Kernel ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-21362

Windows   Kernel Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2024-21340

Windows   Kernel ÐÅϢй¶Îó²î

¸ßΣ

CVE-2024-21356

Windows   Lightweight Directory Access Protocol (LDAP) ¾Ü¾ø·þÎñÎó²î

¸ßΣ

CVE-2024-21363

Microsoft   Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21355

Microsoft   Message Queuing (MSMQ) ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-21405

Microsoft   Message Queuing (MSMQ) ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-21354

Microsoft   Message Queuing (MSMQ) ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-21372

Windows   OLE Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21339

Windows   USB Generic Parent Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2024-21346

Win32k ÌØȨÌáÉýÎó²î

¸ßΣ

CVE-2024-21364

Microsoft   Azure Site RecoveryÌØȨÌáÉýÎó²î

ÖÐΣ

CVE-2024-21399

Microsoft   Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÖÐΣ

CVE-2024-21351

Windows   SmartScreen Çå¾²¹¦Ð§ÈƹýÎó²î

ÖÐΣ

CVE-2024-21626

runc ÎļþÐÎò·û×ß©

δ֪

CVE-2024-1284

Chromium£ºCVE-2024-1284 ÔÚ Mojo ÖÐÊͷźóʹÓÃ

δ֪

CVE-2024-1060

Chromium£ºCVE-2024-1060 ÔÚ Canvas ÖÐÊͷźóʹÓÃ

δ֪

CVE-2024-1077

Chromium£ºCVE-2024-1077 ÔÚ Network ÖÐÊͷźóʹÓÃ

δ֪

CVE-2024-1283

Chromium£ºCVE-2024-1283 Skia ÖеĶѻº³åÇøÒç³ö

δ֪

CVE-2024-1059

Chromium£ºCVE-2024-1059 ÔÚ WebRTC ÖÐÊͷźóʹÓÃ

δ֪

 

¶þ¡¢Ó°Ïì¹æÄ£

ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/·þÎñ/×é¼þ°üÀ¨£º

Azure DevOps

Microsoft Office

Azure Stack

Windows Hyper-V

Skype for Business

Trusted Compute Base

Microsoft Defender for Endpoint

Microsoft Dynamics

Azure Connected Machine Agent

Windows Kernel

Windows USB Serial Driver

Role: DNS Server

Windows Internet Connection Sharing (ICS)

Windows Win32K - ICOMP

SQL Server

Microsoft ActiveX

Microsoft WDAC OLE DB provider for SQL

Windows SmartScreen

Microsoft WDAC ODBC Driver

Windows Message Queuing

Windows LDAP - Lightweight Directory Access Protocol

Azure Site Recovery

Windows OLE

Microsoft Teams for Android

Microsoft Azure Kubernetes Service

Microsoft Windows DNS

Microsoft Office Outlook

Microsoft Office Word

Azure Active Directory

Microsoft Office OneNote

.NET

Azure File Sync

Microsoft Edge (Chromium-based)

Microsoft Windows

Microsoft Exchange Server

Internet Shortcut Files

 

Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔÏ°취ÊÖ¶¯¾ÙÐиüУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔز¢×°Öá£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£

2024Äê2ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Feb

²¹¶¡ÏÂÔØʾÀý£¨²Î¿¼£©£º

1.·­¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2022Äê2Ô£©

2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·­¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý

3.µã»÷¡¾Çå¾²¸üС¿£¬·­¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öá£

image.png

Àý3£º²¹¶¡ÏÂÔؽçÃæ

4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£

3.2 ÔÝʱ²½·¥

Õë¶ÔCVE-2024-21410£¬ÔÚ Exchange Server 2019 ÀÛ»ý¸üÐÂ14 (CU14) ¸üÐÂ֮ǰ£¬Exchange Server ĬÈÏÇéÐÎϲ»ÆôÓà NTLM ƾ֤Öм̱£»¤£¨³ÆΪÉí·ÝÑéÖ¤À©Õ¹±£»¤»ò EPA£©£¬Exchange Server 2019 CU14 ĬÈÏÔÚ Exchange ServerÉÏÆôÓà EPA£¬Microsoft ½¨ÒéÔÚ Exchange Server 2019 ÉÏ×°Öà CU14 £¬»ò²ÎÔÄExchange À©Õ¹±£»¤Îĵµ²¢Ê¹ÓÃExchangeExtendedProtectionManagement.ps1¾ç±¾Îª Exchange ServerÆôÓÃÉí·ÝÑéÖ¤À©Õ¹±£»¤ (EPA)À´»º½â¸ÃÎó²î¡£

¸ü¶àÎó²îÏêÇé¼°»º½â²½·¥¿É²Î¿¼¹Ù·½Í¨¸æ£º

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-21410

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔ̭ϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔÌ­½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔÌ­¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Feb

https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2024-patch-tuesday-fixes-2-zero-days-73-flaws/

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-02-19

Ê×´ÎÐû²¼

 

 

Îå¡¢¸½Â¼

5.1 ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ò½é

ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½¨ÉèÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Çå¾²·þÎñ½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Æ𾢡£

5.2 ¹ØÓÚÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø

ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png