¡¾Îó²îͨ¸æ¡¿Î¢Èí6Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2023-06-14
Ò»¡¢Îó²î¸ÅÊö
2023Äê6ÔÂ13ÈÕ£¬Î¢ÈíÐû²¼ÁË6ÔÂÇå¾²¸üУ¬±¾´Î¸üй²ÐÞ¸´ÁË78¸öÇå¾²Îó²î£¨²»°üÀ¨Microsoft EdgeÎó²î£©£¬ÆäÖÐÓÐ6¸öÎó²îÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£
±¾´ÎÐÞ¸´µÄÎó²îÖУ¬Îó²îÀàÐͰüÀ¨ÌØÈ¨ÌáÉýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾ø·þÎñÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²îºÍÓÕÆÎó²îµÈ¡£
΢Èí±¾´ÎÇå¾²¸üÐÂÖÐÎ´Éæ¼°0 dayÎó²î£¬ÖµµÃ¹Ø×¢µÄÎó²î°üÀ¨µ«²»ÏÞÓÚ£º
CVE-2023-29357 £ºMicrosoft SharePoint Server ÌØÈ¨ÌáÉýÎó²î
Microsoft SharePoint Server 2019Öб£´æÈ¨ÏÞÌáÉýÎó²î£¬¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.8¡£»ñµÃÓÕÆÐÔJWTÉí·ÝÑéÖ¤ÁîÅÆµÄÍþвÕß¿ÉÒÔʹÓÃÕâЩÁîÅÆÖ´ÐÐÍøÂç¹¥»÷£¬´Ó¶øÈƹýÉí·ÝÑéÖ¤£¬²¢¿ÉÄÜ»ñµÃÖÎÀíԱȨÏÞ¡£
CVE-2023-32031 £ºMicrosoft Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.8£¬¾ÓÉÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔʵÑéͨ¹ýÍøÂçŲÓÃÔÚ·þÎñÆ÷ÕË»§µÄÉÏÏÂÎÄÖд¥·¢¶ñÒâ´úÂë¡£
CVE-2023-24897£º.NET¡¢.NET Framework ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.8£¬¿ÉÒÔͨ¹ýÓÕµ¼Êܺ¦Õß´ÓÍøÕ¾ÏÂÔØ²¢·¿ªÌØÖÆÎļþµÄÎó²îʹÓ㬴Ӷøµ¼Ö¶ÔÊܺ¦ÕßµÄÅÌËã»ú¾ÙÐÐÍâµØ¹¥»÷£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂí§Òâ´úÂëÖ´ÐС£
CVE-2023-32013£ºWindows Hyper-V ¾Ü¾ø·þÎñÎó²î
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ6.5¡£
CVE-2023-29363/CVE-2023-32014/CVE-2023-32015£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î
ÕâЩÎó²îµÄCVSSv3ÆÀ·Ö¾ùΪ9.8£¬µ± Windows ÐÂÎÅÐÐÁзþÎñÔËÐÐÔÚ PGM Server ÇéÐÎÖÐʱ£¬¿ÉÒÔͨ¹ýÍøÂç·¢ËÍÌØÖÆÎļþÀ´ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£Windows ÐÂÎÅÐÐÁзþÎñÊÇÒ»¸ö Windows ×é¼þ£¬ÆôÓøÃ×é¼þµÄϵͳ²ÅÒ×ÊÜÕë¶ÔÕâЩÎó²îµÄ¹¥»÷£¬¿ÉÒÔ¼ì²éÊÇ·ñÖøÃûΪMessage QueuingµÄ·þÎñÕýÔÚÔËÐв¢ÇÒ TCP ¶Ë¿Ú 1801 ÕýÔÚ»úеÉÏÕìÌý¡£
CVE-2023-29362£ºRemote Desktop ClientÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.8£¬ÔÚÔ¶³Ì×ÀÃæÅþÁ¬µÄÇéÐÎÏ£¬µ±Êܺ¦ÕßʹÓÃÒ×Êܹ¥»÷µÄÔ¶³Ì×ÀÃæ¿Í»§¶ËÅþÁ¬µ½¹¥»÷·þÎñÆ÷ʱ£¬¿ØÖÆÔ¶³Ì×ÀÃæ·þÎñÆ÷µÄÍþвÕß¿ÉÒÔÔÚ RDP ¿Í»§¶ËÅÌËã»úÉÏ´¥·¢Ô¶³Ì´úÂëÖ´ÐÐ (RCE)¡£
CVE-2023-28310£ºMicrosoft Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.0£¬Óë Exchange Server´¦ÓÚͳһÄÚÍøµÄ¾ÓÉÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔͨ¹ý PowerShell Ô¶³Ì»á»°ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£
±ðµÄ£¬Î¢Èí»¹Ðû²¼ÁË´ó×Ú Microsoft Office ¸üУ¬ÒÔÐÞ¸´Excel ¡¢OneNote ºÍOutlookµÈ¶à¸ö²úÆ·ÖеÄÎó²î£¬Ê¹ÓÃÕâЩÎó²îÐèÒªÓû§½»»¥£¬²¿·ÖÎó²îÈçÏ£º
CVE-2023-33133£ºMicrosoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î
CVE-2023-33137£ºMicrosoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î
CVE-2023-33140£ºMicrosoft OneNote ÓÕÆÎó²î
CVE-2023-33131£ºMicrosoft Outlook Ô¶³Ì´úÂëÖ´ÐÐÎó²î
΢Èí6Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º
CVE-ID | ÎÊÌâ | ÑÏÖØÐÔ |
CVE-2023-24897 | .NET¡¢.NET Framework ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-29357 | Microsoft SharePoint Server ÌØÈ¨ÌáÉýÎó²î | ÑÏÖØ |
CVE-2023-32013 | Windows Hyper-V ¾Ü¾ø·þÎñÎó²î | ÑÏÖØ |
CVE-2023-29363 | Windows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-32014 | Windows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-32015 | Windows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-24895 | .NET¡¢.NET Framework ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-33126 | .NET ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-33135 | .NET ºÍ Visual Studio ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-32032 | .NET ºÍ Visual Studio ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-32030 | .NET ºÍ Visual Studio ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-33128 | .NET ºÍ Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-29331 | .NET¡¢.NET Framework ºÍ Visual Studio ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-29326 | .NET Framework Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-33141 | Yet Another Reverse Proxy (YARP) ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-21569 | Azure DevOps ·þÎñÆ÷ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-21565 | Azure DevOps ·þÎñÆ÷ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-24896 | Dynamics 365 Finance ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-33145 | Microsoft Edge£¨»ùÓÚChromium£©ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-32031 | Microsoft Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28310 | Microsoft Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-33146 | Microsoft Office Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-33133 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-32029 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-33137 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-33140 | Microsoft OneNote ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-33131 | Microsoft Outlook Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-33142 | Microsoft SharePoint Server ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-33129 | Microsoft SharePoint ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-33130 | Microsoft SharePoint Server ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-33132 | Microsoft SharePoint Server ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-32024 | Microsoft Power Apps ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-32017 | Microsoft PostScript ´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-29372 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-29370 | Windows Media Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-29365 | Windows Media Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-29337 | NuGet ClientÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-29362 | Remote Desktop Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-29352 | Windows Ô¶³Ì×ÀÃæÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-32020 | Windows DNS ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-29007 | GitHub£ºCVE-2023-29007 ͨ¹ý `git submodule deinit` ¾ÙÐÐí§ÒâÉèÖÃ×¢Èë | ¸ßΣ |
CVE-2023-33139 | Visual Studio ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-25652 | GitHub£ºCVE-2023-25652¡°git apply --reject¡±²¿·Ö¿ØÖÆí§ÒâÎļþдÈë | ¸ßΣ |
CVE-2023-25815 | GitHub£ºCVE-2023-25815 Git ÔÚ·ÇÌØÈ¨Î»ÖòéÕÒÍâµØ»¯ÐÂÎÅ | ¸ßΣ |
CVE-2023-27911 | AutoDesk£ºAutodesk? FBX? SDK 2020 »ò¸üÔç°æ±¾ÖÐµÄ CVE-2023-27911 ¶Ñ»º³åÇøÒç³öÎó²î | ¸ßΣ |
CVE-2023-27910 | AutoDesk£ºAutodesk? FBX? SDK 2020 »ò¸üÔç°æ±¾ÖÐµÄ CVE-2023-27910 ¿ÍÕ»»º³åÇøÒç³öÎó²î | ¸ßΣ |
CVE-2023-29011 | GitHub: CVE-2023-29011 `connect.exe` µÄÉèÖÃÎļþÈÝÒ×±»¶ñÒâ°²ÅÅ | ¸ßΣ |
CVE-2023-29012 | GitHub:CVE-2023-29012 Git CMD¹ýʧµØÔÚÄ¿½ñĿ¼ÖÐÖ´ÐС°doskey.exe¡±£¨ÈôÊDZ£´æ£© | ¸ßΣ |
CVE-2023-27909 | AutoDesk£ºAutodesk? FBX? SDK 2020 »ò¸üÔç°æ±¾ÖÐµÄ CVE-2023-27909 Ô½½çдÈëÎó²î | ¸ßΣ |
CVE-2023-33144 | Visual Studio CodeÓÕÆÎó²î | ¸ßΣ |
CVE-2023-29364 | Windows Éí·ÝÑéÖ¤ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-32010 | Windows Bus Filter Driver ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-29361 | Windows Cloud Files Mini Filter Driver ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-32009 | Windows Collaborative Translation Framework ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-32012 | Windows Container Manager Service ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-24937 | Windows CryptoAPI ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-24938 | Windows CryptoAPI ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-29355 | DHCP Server Service ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-29368 | Windows Filtering Platform ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-29358 | Windows GDI ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-29366 | Windows Geolocation Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-29351 | Windows ×éÕ½ÂÔÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-32018 | Windows Hello Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-32016 | Windows Installer ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-32011 | Windows iSCSI ·¢Ã÷·þÎñ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-32019 | Windows ÄÚºËÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-29346 | NTFS ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-29373 | Microsoft ODBC Çý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-29367 | iSCSI Target WMI Provider Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-29369 | Remote Procedure Call Runtime ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-32008 | Windows Resilient File System (ReFS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-32022 | Windows Server ·þÎñÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-32021 | Windows SMB Witness ·þÎñÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-29360 | Windows TPM ×°±¸Çý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-29371 | Windows GDI ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-29359 | GDI ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-24936 | .NET¡¢.NET Framework ºÍ Visual Studio ÌØÈ¨ÌáÉýÎó²î | ÖÐΣ |
CVE-2023-33143 | Microsoft Edge£¨»ùÓÚ Chromium£©ÌØÈ¨ÌáÉýÎó²î | ÖÐΣ |
CVE-2023-29345 | Microsoft Edge£¨»ùÓÚ Chromium£©Çå¾²¹¦Ð§ÈƹýÎó²î | µÍΣ |
CVE-2023-29353 | Sysinternals Process Monitor for Windows ¾Ü¾ø·þÎñÎó²î | µÍΣ |
CVE-2023-2941 | Chromium£ºCVE-2023-2941 ÔÚÀ©Õ¹ API ÖÐʵÑé²»µ± | δ֪ |
CVE-2023-2937 | Chromium£ºCVE-2023-2937 »ÖлʵÑé²»µ± | δ֪ |
CVE-2023-2936 | Chromium£ºV8 ÖÐµÄ CVE-2023-2936 ÀàÐÍ»ìÏý | δ֪ |
CVE-2023-2935 | Chromium£ºV8 ÖÐµÄ CVE-2023-2935 ÀàÐÍ»ìÏý | δ֪ |
CVE-2023-2940 | Chromium£ºCVE-2023-2940 ÏÂÔØÖеÄʵÑé²»µ± | δ֪ |
CVE-2023-2939 | Chromium£ºCVE-2023-2939 ×°ÖóÌÐòÖеÄÊý¾ÝÑé֤ȱ·¦ | δ֪ |
CVE-2023-2938 | Chromium£ºCVE-2023-2938 »ÖлʵÑé²»µ± | δ֪ |
CVE-2023-2931 | Chromium£ºCVE-2023-2931 ÔÚ PDF ÖÐÊͷźóʹÓà | δ֪ |
CVE-2023-2930 | Chromium£ºCVE-2023-2930 ÔÚÀ©Õ¹ÖÐÊͷźóʹÓà | δ֪ |
CVE-2023-2929 | Chromium£ºCVE-2023-2929 ÔÚ Swiftshader ÖÐÔ½½çдÈë | δ֪ |
CVE-2023-2934 | Chromium£ºCVE-2023-2934 Mojo ÖеÄÔ½½çÄÚ´æ»á¼û | δ֪ |
CVE-2023-2933 | Chromium£ºCVE-2023-2933 ÔÚ PDF ÖÐÊͷźóʹÓà | δ֪ |
CVE-2023-2932 | Chromium£ºCVE-2023-2932 ÔÚ PDF ÖÐÊͷźóʹÓà | δ֪ |
CVE-2023-3079 | Chromium£ºV8 ÖÐµÄ CVE-2023-3079 ÀàÐÍ»ìÏý | δ֪ |
¶þ¡¢Ó°Ïì¹æÄ£
ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/·þÎñ/×é¼þ°üÀ¨£º
Azure DevOps
.NET and Visual Studio
Microsoft Dynamics
Windows CryptoAPI
Microsoft Exchange Server
.NET Framework
.NET Core
NuGet Client
Microsoft Edge (Chromium-based)
Windows NTFS
Windows Group Policy
Remote Desktop Client
SysInternals
Windows DHCP Server
Microsoft Office SharePoint
Windows GDI
Windows Win32K
Windows TPM Device Driver
Windows Cloud Files Mini Filter Driver
Windows PGM
Windows Authentication Methods
Microsoft Windows Codecs Library
Windows Geolocation Service
Windows OLE
Windows Filtering
Windows Remote Procedure Call Runtime
Microsoft WDAC OLE DB provider for SQL
Windows ODBC Driver
Windows Resilient File System (ReFS)
Windows Collaborative Translation Framework
Windows Bus Filter Driver
Windows iSCSI
Windows Container Manager Service
Windows Hyper-V
Windows Installer
Microsoft Printer Drivers
Windows Hello
Windows Kernel
Role: DNS Server
Windows SMB
Windows Server Service
Microsoft Power Apps
Microsoft Office Excel
Microsoft Office Outlook
Visual Studio
Microsoft Office OneNote
ASP .NET
Visual Studio Code
Microsoft Office
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϰ취ÊÖ¶¯¾ÙÐиüУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£
2023Äê6ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2023-Jun
²¹¶¡ÏÂÔØÊ¾Àý£º
1.·¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2022Äê2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾Çå¾²¸üС¿£¬·¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öá£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔ̽«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2023-Jun
https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2023-patch-tuesday-fixes-78-flaws-38-rce-bugs/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-06-14 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ×ðÁú¿Ê±¼ò½é
×ðÁú¿Ê±½¨ÉèÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Çå¾²·þÎñ½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°×ðÁú¿Ê±´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬×ðÁú¿Ê±ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£
5.2 ¹ØÓÚ×ðÁú¿Ê±
×ðÁú¿Ê±Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ