¡¾Îó²îͨ¸æ¡¿Î¢Èí2Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2024-02-19Ò»¡¢Îó²î¸ÅÊö
2024Äê2ÔÂ13ÈÕ£¬Î¢ÈíÐû²¼ÁË2ÔÂÇå¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË73¸öÎó²î£¨²»°üÀ¨2ÔÂ8ÈÕÐÞ¸´µÄMicrosoft EdgeºÍÆäËüÎó²î£©£¬Îó²îÀàÐÍ°üÀ¨ÌØȨÌáÉýÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾ø·þÎñÎó²îºÍÓÕÆÎó²îµÈ¡£
±¾´ÎÇå¾²¸üÐÂÖаüÀ¨2¸ö±»Æð¾¢Ê¹ÓõÄ0 dayÎó²î£º
CVE-2024-21351£ºWindows SmartScreen Çå¾²¹¦Ð§ÈƹýÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.6£¬ÍþвÕß¿ÉÏòÓû§·¢ËͶñÒâÎļþ²¢ÓÕµ¼Óû§·¿ªÎļþÀ´Ê¹ÓøÃÎó²î£¬ÀÖ³ÉʹÓÿÉÄܵ¼ÖÂÈƹý SmartScreenÇå¾²¹¦Ð§¡£¸ÃÎó²îÔÊÐíÍþвÕß½«´úÂë×¢Èë SmartScreen ²¢¿ÉÄÜ»ñµÃ´úÂëÖ´ÐÐȨÏÞ£¬´Ó¶ø¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢ÏµÍ³¿ÉÓÃÐÔÓ°Ï죬ÏÖÔÚ¸ÃÎó²îÒѼì²âµ½Îó²îʹÓá£
CVE-2024-21412£ºInternet ¿ì½Ý·½·¨ÎļþÇå¾²¹¦Ð§ÈƹýÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.1£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔÏòÄ¿µÄÓû§·¢ËÍÖ¼ÔÚÈƹýÏÔʾµÄÇå¾²¼ì²éµÄÌØÖÆÎļþ²¢ÓÕµ¼Óû§·¿ª¸ÃÎļþ£¬µ¼ÖÂÇå¾²¹¦Ð§Èƹý¡£ÒÑ·¢Ã÷APT×éÖ¯Water Hydra£¨ÓÖÃû DarkCasino£©ÔÚÕë¶Ô½ðÈÚÉúÒâÕßµÄÔ˶¯ÖÐÆð¾¢Ê¹ÓøÃÎó²î¡£
±¾´ÎÇå¾²¸üÐÂÖУ¬ÆÀ¼¶Îª¡°ÑÏÖØ¡±µÄ5¸öÎó²î°üÀ¨£º
CVE-2024-21380£ºMicrosoft Dynamics Business Central/NAV ÐÅϢй¶Îó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.0£¬ÀÖ³ÉʹÓøÃÎó²îÐèÒª¾ÓÉÉí·ÝÑéÖ¤¡¢Ó®µÃ¾ºÕùÌõ¼þ£¬²¢ÐèÒªÓû§½»»¥£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕß¿ÉÒÔ»á¼ûÓû§Êý¾Ý£¬µ¼ÖÂδÊÚȨ»á¼ûÊܺ¦ÕßµÄÕË»§»òй¶ÆäËüÉñÃØÐÅÏ¢¡£
CVE-2024-21410£ºMicrosoft Exchange Server ȨÏÞÌáÉýÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕß¿ÉÒÔ½«Óû§Ð¹Â¶µÄNet-NTLMv2¹þÏ£Öм̵½Ò×Êܹ¥»÷µÄExchange Server£¬²¢ÒÔÓû§Éí·Ý¾ÙÐÐÉí·ÝÑéÖ¤¡£ÊÜÓ°ÏìÓû§Ò²¿É²Î¿¼¹Ù·½ÌṩµÄÎĵµºÍ¾ç±¾Îª Exchange ServerÆôÓÃÉí·ÝÑéÖ¤À©Õ¹±£»¤ (EPA)À´»º½â¸ÃÎó²î£¬ÏÖÔÚ¸ÃÎó²îÒѼì²âµ½Îó²îʹÓá£
CVE-2024-21413£ºMicrosoft OutlookÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.8£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÈƹý Office Êܱ£»¤µÄÊÓͼ²¢ÒÔ±à¼Ä£Ê½¶ø²»ÊDZ£»¤Ä£Ê½·¿ª£¬Ô¤ÀÀ´°¸ñÊǸÃÎó²îµÄÒ»¸ö¹¥»÷Ç°ÑÔ¡£ÍþвÕß¿ÉÒÔ½¨ÉèÈƹýÊܱ£»¤ÊÓͼÐÒéµÄ¶ñÒâÁ´½Ó£¬´Ó¶øµ¼ÖÂÍâµØNTLMƾ֤ÐÅϢй¶ºÍÔ¶³Ì´úÂëÖ´ÐС£
CVE-2024-20684£ºWindows Hyper-V ¾Ü¾ø·þÎñÎó²î
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ6.5£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼Ö Hyper-V guestÓ°Ïì Hyper-V Ö÷»úµÄ¹¦Ð§¡£
CVE-2024-21357£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î
Windows Pragmatic General Multicast (PGM) ±¬·¢µÄ×é²¥Á÷Á¿ÔÚµÚ4 ²ãÔËÐв¢¿É·ÓÉ£¬ÍþвÕß¿ÉÒÔͨ¹ýÏòÒ×Êܹ¥»÷µÄ·þÎñÆ÷·¢ËÍÌØÖƵĶñÒâÁ÷Á¿À´Ê¹ÓøÃÎó²î¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.1£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°±»Ê¹ÓõĿÉÄÜÐԽϸߡ±¡£
³ýCVE-2024-21410ºÍCVE-2024-21357ÒÔÍ⣬±¾´ÎÇå¾²¸üÐÂÖУ¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹ÀÖС°±»Ê¹ÓõĿÉÄÜÐԽϸߡ±µÄÎó²î»¹°üÀ¨£º
CVE-2024-21338£ºWindows ÄÚºËÌØȨÌáÉýÎó²î
CVE-2024-21345£ºWindows ÄÚºËÌØȨÌáÉýÎó²î
CVE-2024-21346£ºWin32k ÌØȨÌáÉýÎó²î
CVE-2024-21371£ºWindows ÄÚºËÌØȨÌáÉýÎó²î
CVE-2024-21378£ºMicrosoft OutlookÔ¶³Ì´úÂëÖ´ÐÐÎó²î
CVE-2024-21379£ºMicrosoft WordÔ¶³Ì´úÂëÖ´ÐÐÎó²î
΢Èí2Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º
CVE ID | CVE ÎÊÌâ | ÑÏÖØÐÔ |
CVE-2024-21380 | Microsoft Dynamics Business Central/NAV ÐÅϢй¶Îó²î | ÑÏÖØ |
CVE-2024-21410 | Microsoft Exchange Server ȨÏÞÌáÉýÎó²î | ÑÏÖØ |
CVE-2024-21413 | Microsoft Outlook Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2024-20684 | Windows Hyper-V ¾Ü¾ø·þÎñÎó²î | ÑÏÖØ |
CVE-2024-21357 | Windows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2024-21386 | .NET ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2024-21404 | .NET ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2024-21401 | Microsoft Entra Jira Single-Sign-On Plugin ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21381 | Microsoft Azure Active Directory B2C ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-21329 | Azure Connected Machine Agent ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-20667 | Azure DevOps Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21397 | Microsoft Azure File SyncȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-20679 | Azure Stack Hub ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-21412 | Internet ¿ì½Ý·½·¨ÎļþÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2024-21349 | Microsoft ActiveX Êý¾Ý¹¤¾ßÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21403 | Microsoft Azure Kubernetes Service Confidential Container ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21376 | Microsoft Azure Kubernetes Service Confidential Container Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21315 | Microsoft Defender for Endpoint Protection ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21393 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2024-21389 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2024-21395 | Microsoft Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2024-21328 | Dynamics 365 Sales ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-21394 | Dynamics 365 Field Service ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-21396 | Dynamics 365 Sales ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-21327 | Microsoft Dynamics 365 Customer Engagement ¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2024-20673 | Microsoft Office Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21384 | Microsoft Office OneNote Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21378 | Microsoft Outlook Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21402 | Microsoft Outlook ȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21379 | Microsoft Word Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21374 | Microsoft Teams for Android ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-21353 | Microsoft WDAC ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21370 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21350 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21368 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21359 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21365 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21367 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21420 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21366 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21369 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21375 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21361 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21358 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21391 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21360 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21352 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21406 | Windows Printing Service ÓÕÆÎó²î | ¸ßΣ |
CVE-2024-21377 | Windows DNS ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-50387 | MITRE£ºCVE-2023-50387 DNSSEC ÑéÖ¤ÖØ´óÐԿɱ»Ê¹ÓÃÀ´ºÄ¾¡ CPU ×ÊÔ´²¢×èÖ¹ DNS ÆÊÎöÆ÷ | ¸ßΣ |
CVE-2024-21342 | Windows DNS Client ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2024-20695 | Skype for Business ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-21347 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21304 | Trusted Compute Base ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21343 | Windows Network Address Translation (NAT) ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2024-21348 | Internet Connection Sharing (ICS) ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2024-21344 | Windows Network Address Translation (NAT) ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2024-21371 | Windows Kernel ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21338 | Windows Kernel ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21341 | Windows Kernel Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21345 | Windows Kernel ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21362 | Windows Kernel Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2024-21340 | Windows Kernel ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2024-21356 | Windows Lightweight Directory Access Protocol (LDAP) ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2024-21363 | Microsoft Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21355 | Microsoft Message Queuing (MSMQ) ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21405 | Microsoft Message Queuing (MSMQ) ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21354 | Microsoft Message Queuing (MSMQ) ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21372 | Windows OLE Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21339 | Windows USB Generic Parent Driver Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2024-21346 | Win32k ÌØȨÌáÉýÎó²î | ¸ßΣ |
CVE-2024-21364 | Microsoft Azure Site RecoveryÌØȨÌáÉýÎó²î | ÖÐΣ |
CVE-2024-21399 | Microsoft Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÖÐΣ |
CVE-2024-21351 | Windows SmartScreen Çå¾²¹¦Ð§ÈƹýÎó²î | ÖÐΣ |
CVE-2024-21626 | runc ÎļþÐÎò·û×ß© | δ֪ |
CVE-2024-1284 | Chromium£ºCVE-2024-1284 ÔÚ Mojo ÖÐÊͷźóʹÓà | δ֪ |
CVE-2024-1060 | Chromium£ºCVE-2024-1060 ÔÚ Canvas ÖÐÊͷźóʹÓà | δ֪ |
CVE-2024-1077 | Chromium£ºCVE-2024-1077 ÔÚ Network ÖÐÊͷźóʹÓà | δ֪ |
CVE-2024-1283 | Chromium£ºCVE-2024-1283 Skia ÖеĶѻº³åÇøÒç³ö | δ֪ |
CVE-2024-1059 | Chromium£ºCVE-2024-1059 ÔÚ WebRTC ÖÐÊͷźóʹÓà | δ֪ |
¶þ¡¢Ó°Ïì¹æÄ£
ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/·þÎñ/×é¼þ°üÀ¨£º
Azure DevOps
Microsoft Office
Azure Stack
Windows Hyper-V
Skype for Business
Trusted Compute Base
Microsoft Defender for Endpoint
Microsoft Dynamics
Azure Connected Machine Agent
Windows Kernel
Windows USB Serial Driver
Role: DNS Server
Windows Internet Connection Sharing (ICS)
Windows Win32K - ICOMP
SQL Server
Microsoft ActiveX
Microsoft WDAC OLE DB provider for SQL
Windows SmartScreen
Microsoft WDAC ODBC Driver
Windows Message Queuing
Windows LDAP - Lightweight Directory Access Protocol
Azure Site Recovery
Windows OLE
Microsoft Teams for Android
Microsoft Azure Kubernetes Service
Microsoft Windows DNS
Microsoft Office Outlook
Microsoft Office Word
Azure Active Directory
Microsoft Office OneNote
.NET
Azure File Sync
Microsoft Edge (Chromium-based)
Microsoft Windows
Microsoft Exchange Server
Internet Shortcut Files
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔظüв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔÏ°취ÊÖ¶¯¾ÙÐиüУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔز¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£
2024Äê2ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2024-Feb
²¹¶¡ÏÂÔØʾÀý£¨²Î¿¼£©£º
1.·¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£
Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2022Äê2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£
Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØʾÀý
3.µã»÷¡¾Çå¾²¸üС¿£¬·¿ª²¹¶¡ÏÂÔØÒ³Ã棬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öá£
Àý3£º²¹¶¡ÏÂÔؽçÃæ
4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£
3.2 ÔÝʱ²½·¥
Õë¶ÔCVE-2024-21410£¬ÔÚ Exchange Server 2019 ÀÛ»ý¸üÐÂ14 (CU14) ¸üÐÂ֮ǰ£¬Exchange Server ĬÈÏÇéÐÎϲ»ÆôÓà NTLM ƾ֤Öм̱£»¤£¨³ÆΪÉí·ÝÑéÖ¤À©Õ¹±£»¤»ò EPA£©£¬Exchange Server 2019 CU14 ĬÈÏÔÚ Exchange ServerÉÏÆôÓà EPA£¬Microsoft ½¨ÒéÔÚ Exchange Server 2019 ÉÏ×°Öà CU14 £¬»ò²ÎÔÄExchange À©Õ¹±£»¤Îĵµ²¢Ê¹ÓÃExchangeExtendedProtectionManagement.ps1¾ç±¾Îª Exchange ServerÆôÓÃÉí·ÝÑéÖ¤À©Õ¹±£»¤ (EPA)À´»º½â¸ÃÎó²î¡£
¸ü¶àÎó²îÏêÇé¼°»º½â²½·¥¿É²Î¿¼¹Ù·½Í¨¸æ£º
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-21410
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔ̽«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Feb
https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2024-patch-tuesday-fixes-2-zero-days-73-flaws/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-02-19 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼ò½é
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø½¨ÉèÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Çå¾²·þÎñ½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Æ𾢡£
5.2 ¹ØÓÚÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º