Outlook¸ßΣԶ³Ì´úÂëÖ´Ðзì϶£¬GA»Æ½ð¼×Ìṩ½â¾ö¹æ»®
°ä²¼¹¦·ò 2024-02-23·ì϶ÏêÇé
¾¹ý×êÑÐÈ·ÈÏ£¬¸Ã·ìÏ¶ÈÆ¹ýÁËOutlookÖеݲȫÏÞ¶È£¬µ¼Ö¹¥»÷ÕßÖ»Ðè·¢ËÍÒ»¸ö´¹µöÓʼþ£¬¼´¿ÉÔÚÊܺ¦ÕßÎÞÐèÈκν»»¥µÄÇé¿öÏÂй¶ÆäNTLMÉí·ÝÍ´´¦ÐÅÏ¢¡£Í¨¹ý½øÒ»²½µÄÆÆ½â»òÕßNTLM relay¹¥»÷£¬¼´¿ÉαÔìÊܺ¦ÕßÉí·Ý½øÐÐÈÏÖ¤£¬´Ó¶ø»ñÈ¡¶ÔӦȨÏÞ¡£Í¬Ê±¸Ã·ì϶ÔÚºÍËÁÒâCOM·ì϶½áºÏʹÓÃ(ÈçCVE-2022-30190)µÄʱ³½£¬¹¥»÷ÕßÖ»ÐèÓÕµ¼Êܺ¦Õßµã»÷Á´½Ó£¬¼´¿ÉÔÚÓû§µçÄÔÉÏÖ´ÐÐËÁÒâ´úÂë¡£
¸Ã·ì϶ÀûÓÃÄѶȽϵͣ¬ÓëÈ¥Äê±»APT28×é֯ƵÈÔÀûÓõÄMicrosoft Outlook ȨÏÞÌáÉý·ì϶(CVE-2023-23397)µÄ¹¥»÷³¡¾°ÀàËÆ£¬ºóÐø±»ÀûÓõĿÉÄÜÐԽϸߡ£Ä¿Ç°¹Ù·½ÒѰ䲼°²È«¸üУ¬½¨Òé¿Í»§»ý¼«×öºÃÅŲéºÍ·À»¤¡£

Ó°Ïì°æ±¾
Microsoft Office LTSC 2021 for 32-bit/64-bit editions
Microsoft Office 2019 for 32-bit/64-bit editions
Microsoft Office 2016 (32-bit/64-bit edition)
Microsoft 365 Apps for Enterprise for 32-bit/64-bit System
·ì϶¸´ÏÖ
ĿǰÒѳɹ¦¸´ÏÖÁ½ÖÖ¹¥»÷³¡¾°¡£
1¡¢NTLMй¶


½â¾ö¹æ»®
1¡¢¹Ù·½½¨¸´¹æ»®
¹Ù·½ÒѰ䲼°²È«¸üУ¬½¨Ò齫ÊÜÓ°ÏìµÄofficeÉý¼¶ÖÁ×îа汾£ºhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21413£¬²¢ÇÒÔÚÉý¼¶Ö®Ç°²»ÒªµÈÏеã»÷ÓʼþÖеÄÁ´½Ó»ò¸½¼þ¡£2¡¢GA»Æ½ð¼×½â¾ö¹æ»®
ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©¿ÉÓÐЧ·À»¤CVE-2024-21413·ì϶Ôì³ÉµÄ¹¥»÷·çÏÕ¡£´Ë±í£¬ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©ÄÚÖÃɳÏä¼ì²âÖ°ÄÜ£¬Éý¼¶µ½×îв¹¶¡¿ÉÓÐЧ¼ì²âÀûÓø÷ì϶µÄ¶ñÒâÓʼþ¡£



¾©¹«Íø°²±¸11010802024551ºÅ