¡¾Îó²îͨ¸æ¡¿Î¢Èí9Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2025-09-10Ò»¡¢Îó²î¸ÅÊö
2025Äê9ÔÂ10ÈÕ£¬×ðÁú¿Ê±¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË9ÔÂÇå¾²¸üУ¬±¾´Î¸üÐÂÐÞ¸´ÁË81¸öÎó²î£¬º¸ÇÌØÈ¨ÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐС¢ÐÅϢй¶µÈ¶àÖÖÎó²îÀàÐÍ¡£Îó²î¼¶±ðÂþÑÜÈçÏ£º8¸öÑÏÖØ¼¶±ðÎó²î£¬72¸öÖ÷Òª¼¶±ðÎó²î£¬1ÆäÖÐΣ¼¶±ðÎó²î£¨Îó²î¼¶±ðÒÀ¾Ý΢Èí¹Ù·½Êý¾Ý£©¡£
ÆäÖУ¬8¸öÎó²î±»Î¢Èí±ê¼ÇΪ¡°¸ü¿ÉÄܱ»Ê¹Óá±¼°¡°¼ì²âʹÓÃÇéÐΡ±£¬Åú×¢ÕâЩÎó²î±£´æ½Ï¸ßµÄʹÓÃΣº¦£¬½¨ÒéÓÅÏÈÐÞ¸´ÒÔ½µµÍDZÔÚÇå¾²Íþв¡£
CVE-ID | CVE ÎÊÌâ | Îó²î¼¶±ð |
CVE-2025-53803 | Windows ÄÚºËÄÚ´æÐÅϢй¶Îó²î | Ö÷Òª |
CVE-2025-53804 | Windows ÄÚºËģʽÇý¶¯³ÌÐòÐÅÏ¢Åû¶Îó²î | Ö÷Òª |
CVE-2025-54093 | Windows TCP/IP Çý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54098 | Windows Hyper-V ÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54110 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54916 | Windows NTFS Ô¶³ÌÖ´ÐдúÂëÎó²î | Ö÷Òª |
CVE-2025-54918 | Windows NTLM ÌØÈ¨ÌáÉýÎó²î | ÑÏÖØ |
CVE-2025-55234 | Windows SMB Elevation of Privilege Vulnerability | Ö÷Òª |
΢Èí9Ô¸üÐÂÐÞ¸´µÄÍêÕûÎó²îÁбíÈçÏ£º
CVE-ID | CVE ÎÊÌâ | Îó²î¼¶±ð |
CVE-2025-47997 | Microsoft SQL Server ÐÅϢй¶Îó²î | Ö÷Òª |
CVE-2025-49692 | Azure Connected Machine Agent ÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-49734 | PowerShell Direct ÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-53791 | »ùÓÚChromium µÄ Microsoft Edge Çå¾²¹¦Ð§ÈƹýÎó²î | ÖÐ |
CVE-2025-53796 | Windows ·ÓɺÍÔ¶³Ì»á¼û·þÎñ (RRAS) ÐÅÏ¢Åû¶Îó²î | Ö÷Òª |
CVE-2025-53797 | Windows ·ÓɺÍÔ¶³Ì»á¼û·þÎñ (RRAS) ÐÅÏ¢Åû¶Îó²î | Ö÷Òª |
CVE-2025-53798 | Windows ·ÓɺÍÔ¶³Ì»á¼û·þÎñ (RRAS) ÐÅÏ¢Åû¶Îó²î | Ö÷Òª |
CVE-2025-53799 | Windows ³ÉÏñ×é¼þÐÅϢй¶Îó²î | ÑÏÖØ |
CVE-2025-53800 | Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉýÎó²î | ÑÏÖØ |
CVE-2025-53801 | Microsoft DWM ½¹µã¿âȨÏÞÌáÉýÎó²î | Ö÷Òª |
CVE-2025-53802 | Windows Bluetooth ·þÎñÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-53803 | Windows ÄÚºËÄÚ´æÐÅϢй¶Îó²î | Ö÷Òª |
CVE-2025-53804 | Windows ÄÚºËģʽÇý¶¯³ÌÐòÐÅÏ¢Åû¶Îó²î | Ö÷Òª |
CVE-2025-53805 | HTTP.sys ¾Ü¾ø·þÎñÎó²î | Ö÷Òª |
CVE-2025-53806 | Windows ·ÓɺÍÔ¶³Ì»á¼û·þÎñ (RRAS) ÐÅÏ¢Åû¶Îó²î | Ö÷Òª |
CVE-2025-53807 | Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-53808 | Windows Defender ·À»ðǽ·þÎñÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-53809 | ÍâµØÇå¾²ÈÏÖ¤×Óϵͳ·þÎñ(LSASS) ¾Ü¾ø·þÎñÎó²î | Ö÷Òª |
CVE-2025-53810 | Windows Defender ·À»ðǽ·þÎñÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54091 | Windows Hyper-V ÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54092 | Windows Hyper-V ÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54093 | Windows TCP/IP Çý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54094 | Windows Defender ·À»ðǽ·þÎñÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54095 | Windows ·ÓɺÍÔ¶³Ì»á¼û·þÎñ (RRAS) ÐÅÏ¢Åû¶Îó²î | Ö÷Òª |
CVE-2025-54096 | Windows ·ÓɺÍÔ¶³Ì»á¼û·þÎñ (RRAS) ÐÅÏ¢Åû¶Îó²î | Ö÷Òª |
CVE-2025-54097 | Windows ·ÓɺÍÔ¶³Ì»á¼û·þÎñ (RRAS) ÐÅÏ¢Åû¶Îó²î | Ö÷Òª |
CVE-2025-54098 | Windows Hyper-V ÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54099 | WinSock µÄ Windows ¸¨Öú¹¦Ð§Çý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54101 | Windows SMB ¿Í»§¶ËÔ¶³ÌÖ´ÐдúÂëÎó²î | Ö÷Òª |
CVE-2025-54102 | Windows »¥Áª×°±¸Æ½Ì¨·þÎñÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54103 | Windows Management Service Elevation of Privilege Vulnerability | Ö÷Òª |
CVE-2025-54104 | Windows Defender ·À»ðǽ·þÎñÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54105 | Microsoft ÊðÀíÎļþÏµÍ³ÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54106 | Windows ·ÓɺÍÔ¶³Ì»á¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | Ö÷Òª |
CVE-2025-54107 | MapUrlToZone Çå¾²¹¦Ð§ÈƹýÎó²î | Ö÷Òª |
CVE-2025-54108 | ¹¦Ð§»á¼ûÖÎÀí·þÎñ(camsvc) ÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54109 | Windows Defender ·À»ðǽ·þÎñÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54110 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54111 | Windows UI XAML Phone DatePickerFlyout ÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54112 | Microsoft ÐéÄâÓ²ÅÌÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54113 | Windows ·ÓɺÍÔ¶³Ì»á¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | Ö÷Òª |
CVE-2025-54114 | Windows ÅþÁ¬×°±¸Æ½Ì¨·þÎñ (Cdpsvc) ¾Ü¾ø·þÎñÎó²î | Ö÷Òª |
CVE-2025-54115 | Windows Hyper-V ÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54116 | Windows MultiPoint ·þÎñÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54894 | ÍâµØÇå¾²ÈÏÖ¤×Óϵͳ·þÎñÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54895 | SPNEGO À©Õ¹ÐÉÌ (NEGOEX) Çå¾²»úÖÆÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54896 | Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î | Ö÷Òª |
CVE-2025-54897 | Microsoft SharePoint Ô¶³ÌÖ´ÐдúÂëÎó²î | Ö÷Òª |
CVE-2025-54898 | Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î | Ö÷Òª |
CVE-2025-54899 | Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î | Ö÷Òª |
CVE-2025-54900 | Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î | Ö÷Òª |
CVE-2025-54901 | Microsoft Excel ÐÅϢй¶Îó²î | Ö÷Òª |
CVE-2025-54902 | Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î | Ö÷Òª |
CVE-2025-54903 | Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î | Ö÷Òª |
CVE-2025-54904 | Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î | Ö÷Òª |
CVE-2025-54905 | Microsoft Word ÐÅϢй¶Îó²î | Ö÷Òª |
CVE-2025-54906 | Microsoft Office Ô¶³ÌÖ´ÐдúÂëÎó²î | Ö÷Òª |
CVE-2025-54907 | Microsoft Office Visio Ô¶³ÌÖ´ÐдúÂëÎó²î | Ö÷Òª |
CVE-2025-54908 | Microsoft PowerPoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î | Ö÷Òª |
CVE-2025-54910 | Microsoft Office Ô¶³ÌÖ´ÐдúÂëÎó²î | ÑÏÖØ |
CVE-2025-54911 | Windows BitLocker ÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54912 | Windows BitLocker ÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54913 | Windows UI XAML µØÍ¼ MapControlSettings ÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54915 | Windows Defender ·À»ðǽ·þÎñÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-54916 | Windows NTFS Ô¶³ÌÖ´ÐдúÂëÎó²î | Ö÷Òª |
CVE-2025-54917 | MapUrlToZone Çå¾²¹¦Ð§ÈƹýÎó²î | Ö÷Òª |
CVE-2025-54918 | Windows NTLM ÌØÈ¨ÌáÉýÎó²î | ÑÏÖØ |
CVE-2025-54919 | Windows ͼÐÎ×é¼þÔ¶³ÌÖ´ÐдúÂëÎó²î | Ö÷Òª |
CVE-2025-55223 | DirectX ͼÐÎÄÚºËÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-55224 | Windows Hyper-V Ô¶³ÌÖ´ÐдúÂëÎó²î | ÑÏÖØ |
CVE-2025-55225 | Windows ·ÓɺÍÔ¶³Ì»á¼û·þÎñ (RRAS) ÐÅÏ¢Åû¶Îó²î | Ö÷Òª |
CVE-2025-55226 | ͼÐÎÄÚºËÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2025-55227 | Microsoft SQL Server ÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-55228 | Windows ͼÐÎ×é¼þÔ¶³ÌÖ´ÐдúÂëÎó²î | ÑÏÖØ |
CVE-2025-55232 | Microsoft ¸ßÐÔÄÜÅÌËã (HPC) ´ò°üÔ¶³Ì´úÂëÖ´ÐÐÎó²î | Ö÷Òª |
CVE-2025-55234 | Windows SMB Elevation of Privilege Vulnerability | Ö÷Òª |
CVE-2025-55236 | ͼÐÎÄÚºËÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2025-55243 | Microsoft OfficePlus ÓÕÆÎó²î | Ö÷Òª |
CVE-2025-55245 | Õë¶ÔWindows ÌØÈ¨ÌáÉýÎó²îµÄ Xbox Live Éí·ÝÑéÖ¤ÖÎÀíÆ÷ | Ö÷Òª |
CVE-2025-55316 | Azure Connected Machine Agent ÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
CVE-2025-55317 | Microsoft AutoUpdate (MAU) ÌØÈ¨ÌáÉýÎó²î | Ö÷Òª |
¶þ¡¢Ó°Ïì¹æÄ£
ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/·þÎñ/×é¼þ°üÀ¨£º
SQL Server
Azure Windows Virtual Machine Agent
Windows PowerShell
Microsoft Edge (Chromium-based)
Windows Routing and Remote Access Service (RRAS)
Windows Routing and Remote Access Service (RRAS)
Windows Routing and Remote Access Service (RRAS)
Windows Imaging Component
Microsoft Graphics Component
Windows DWM
Windows Bluetooth Service
Windows Kernel
Windows Kernel
Windows Internet Information Services
Windows Routing and Remote Access Service (RRAS)
Microsoft Graphics Component
Windows Defender Firewall Service
Windows Local Security Authority Subsystem Service (LSASS)
Windows Defender Firewall Service
Role: Windows Hyper-V
Role: Windows Hyper-V
Windows TCP/IP
Windows Defender Firewall Service
Windows Routing and Remote Access Service (RRAS)
Windows Routing and Remote Access Service (RRAS)
Windows Routing and Remote Access Service (RRAS)
Role: Windows Hyper-V
Windows Ancillary Function Driver for WinSock
Windows SMBv3 Client
Windows Connected Devices Platform Service
Windows Management Services
Windows Defender Firewall Service
Microsoft Brokering File System
Windows Routing and Remote Access Service (RRAS)
Windows MapUrlToZone
Capability Access Management Service (camsvc)
Windows Defender Firewall Service
Windows Kernel
Windows UI XAML Phone DatePickerFlyout
Microsoft Virtual Hard Drive
Windows Routing and Remote Access Service (RRAS)
Windows Connected Devices Platform Service
Role: Windows Hyper-V
Windows MultiPoint Services
Windows Local Security Authority Subsystem Service (LSASS)
Windows SPNEGO Extended Negotiation
Microsoft Office Excel
Microsoft Office SharePoint
Microsoft Office Excel
Microsoft Office Excel
Microsoft Office Excel
Microsoft Office Excel
Microsoft Office Excel
Microsoft Office Excel
Microsoft Office Excel
Microsoft Office Word
Microsoft Office
Microsoft Office Visio
Microsoft Office PowerPoint
Microsoft Office
Windows BitLocker
Windows BitLocker
Windows UI XAML Maps MapControlSettings
Windows Defender Firewall Service
Windows NTFS
Windows MapUrlToZone
Windows NTLM
Windows Win32K - GRFX
Graphics Kernel
Windows Win32K - GRFX
Windows Routing and Remote Access Service (RRAS)
Graphics Kernel
SQL Server
Windows Win32K - GRFX
Microsoft High Performance Compute Pack (HPC)
Windows SMB
Graphics Kernel
Microsoft Office
Xbox
Azure Arc
Microsoft AutoUpdate (MAU)
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£©Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϰ취ÊÖ¶¯¾ÙÐиüУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£©ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£
2025Äê9ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2025-Sep
²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º
1.·¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

Àý1£ºÎ¢ÈíÎó²îÁÐ±í£¨Ê¾Àý£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿ÁÐÑ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áз¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾Çå¾²¸üС¿£¬·¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öá£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔ̽«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£
? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£
? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2025-Sep


¾©¹«Íø°²±¸11010802024551ºÅ