΢Èí³¬¸ßΣ·ì϶¡°¿ñÔêÐí¿É¡±À´Ï®£¡GA»Æ½ð¼×Ìṩ½â¾ö¹æ»®
°ä²¼¹¦·ò 2024-08-11½üÈÕ£¬GA»Æ½ð¼×¼à²âµ½WindowsÔ¶³Ì×ÀÃæÐí¿É·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-38077£©ÓйØÐÅÏ¢¡£¸Ã·ì϶ӰÏìËùÓÐÆôÓà RDL ·þÎñµÄ Windows Server·þÎñÆ÷£¬Î´¾Éí·ÝÈÏÖ¤µÄ¹¥»÷Õß¿ÉÀûÓø÷ì϶Զ³ÌÖ´ÐдúÂ룬»ñÈ¡·þÎñÆ÷½ÚÔìȨÏÞ¡£Ä¿Ç°£¬¸Ã·ì϶µÄ¼¼ÊõµÀÀíºÍPOCα´úÂëÒѹ«¿ª¡£¼øÓÚ´Ë·ì϶ӰÏìÁìÓò½Ï´ó£¬½¨Ò龡¿ì×öºÃ×Բ鼰·À»¤¡£
·ì϶ÏêÇé
2024Äê07ÔÂ09ÈÕ£¬Î¢Èí¹Ù·½½¨²¹ÁËÒ»¸ö´æÔÚÓÚWindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-38077£©¡£Windows Ô¶³Ì×ÀÃæÊÚȨ·þÎñ£¨RDL£©ÊÇÓÃÓÚÖÎÀíÔ¶³Ì×ÀÃæ(RDP)µÄ³ÁÒª×é¼þ£¬Æäͨ¹ýÖÎÀíºÍ·ÖÅäÐí¿ÉÖ¤À´½ÚÔìºÍ¼à¿ØÔ¶³ÌÏνӵĺϷ¨ÐÔ¡£
¾¹ý×êÑÐÈ·ÈÏ£¬¸Ã·ì϶ÊÇÓÉÓÚRDL·þÎñδÕýȷУÑéÓû§ÊäÈëÊý¾Ý£¬µ¼ÖÂÔÚ½âÎöʱ²úÉúÒç³ö£¬¹¥»÷ÕßÄܹ»ÔÚδ¾¹ýÉí·ÝÑéÖ¤µÄÇé¿öÏ£¬Í¨¹ýÏò¿ªÆôRDL·þÎñµÄÖ÷»ú·¢ËÍÓйØÔ¶³ÌŲÓÃÀ´ÊµÏÖ·ì϶ÀûÓᣳɹ¦ÀûÓø÷ì϶¼´¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬´Ó¶øµ¼ÖÂÃô¸ÐÊý¾ÝµÄй¶£¬ÒÔ¼°¿ÉÄܵĶñÒâÈí¼þ´«²¼¡£¸Ã·ì϶ÏÕЩӰÏìËùÓÐWindows Server°æ±¾¡£

·ì϶¸´ÏÖ

½â¾ö¹æ»®
Ò»¡¢¹Ù·½½¨¸´¹æ»®
¹Ù·½ÒѰ䲼°²È«¸üУ¬½¨Ò齫ÊÜÓ°ÏìµÄWindowsÉý¼¶ÖÁ×îа汾£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38077
¶þ¡¢Ò»Ê±½¨¸´¹æ»®
¸Ã·þÎñĬÈÏδװÖã¬ÈçûÓÐÓйØÒµÎñÐèÒª£¬Äܹ»¹Ø¹ØRemote Desktop Licensing·þÎñ¡£
Èý¡¢GA»Æ½ð¼×½â¾ö¹æ»®
1¡¢GA»Æ½ð¼×¼ì²âÓë·À»¤Àà²úÆ·¹æ»®
£¨1£©GA»Æ½ð¼×¡°ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡±Éý¼¶µ½20240810°æ±¾¼´¿ÉÖ§³Ö¼ì²â¸Ã·ì϶¡£

£¨2£©GA»Æ½ð¼× ¡°ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡± Éý¼¶µ½20240810°æ±¾¼´¿ÉÖ§³Ö¼ì²â¸Ã·ì϶¡£

£¨3£©GA»Æ½ð¼×¡°ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©¡±Éý¼¶µ½20240810°æ±¾¼´¿ÉÖ§³Ö·À»¤¸Ã·ì϶¡£

2¡¢GA»Æ½ð¼×©ɨ²úÆ·¹æ»®
£¨1£©¡°GA»Æ½ð¼×Ìì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ¡±6075°æ±¾ÒÑ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃ裬Óû§Éý¼¶³ß¶È·ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃ裺
6070°æ±¾Éý¼¶°üΪ607000581-607000582.vup£¬Éý¼¶°üÏÂÔØµØÖ·£ºhttps://venustech.download.venuscloud.cn/

£¨2£©GA»Æ½ð¼×Ìì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ608XϵÁа汾ÒÑ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃ裬Óû§Éý¼¶³ß¶È·ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃ裺
6080°æ±¾Éý¼¶°üΪÖ÷»ú²å¼þ°ü6080000130-S6080000131.svs©ɨ²å¼þ°üÏÂÔØµØÖ·£º
https://venustech.download.venuscloud.cn/
£¨3£©Í¨¹ýGA»Æ½ð¼×Ìì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳµÄÅäÖú˲éÄ£¿é¶Ô¸Ã·ì϶ӰÏìµÄWindows°æ±¾½øÐлñÈ¡£¬Ê¹ÓÃÖÇÄÜ»¯·ÖÎöÑÐÅлúÔìÑéÖ¤¸Ã·ì϶ÊÇ·ñ´æÔÚ£¬ÈôÊÇ´æÔڸ÷ì϶½¨Òé¸üе½°²È«°æ±¾¡£
ÇëʹÓÃGA»Æ½ð¼×Ìì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬ÊµÊ±¶Ô¸Ã·ì϶½øÐмì²â£¬ÒԱ㾡¿ì²ÉÈ¡·À±¸´ëÊ©¡£
3¡¢GA»Æ½ð¼××ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¹æ»®
GA»Æ½ð¼××ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±²É¼¯²¢¸üеý±¨ÐÅÏ¢£¬¶ÔÈë¿â×ʲú·ì϶WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-38077£©½øÐÐÖÎÀí¡£

4¡¢GA»Æ½ð¼×°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¹æ»®
Óû§Äܹ»Í¨¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬½øÐйØÁªÕ½ÊõÅäÖ㬽áºÏÏÖʵ»·¾³ÖÐϵͳÈÕÖ¾ºÍ°²È«É豸µÄ¸æ¾¯ÐÅÏ¢½øÐгÖÐø¼à¿Ø£¬´Ó¶ø·¢ÏÖ¡°WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´ÐÓ×±µÄ·ì϶ÀûÓù¥»÷ÐÐΪ¡£
£¨1£©Í¨¹ý´àÈõÐÔ·¢ÏÖÖ°ÄÜÕë¶Ô¡°WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-38077£©¡±·ì϶ɨÃ蹤×÷£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´Ë·ì϶ӰÏìµÄ³ÁÒª×ʲú¡£

£¨2£©Æ½Ì¨¡°¹ØÁª·ÖÎö¡±Ä£¿éÖУ¬Ôö³¤¡°L2_WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶¡±£¬Í¨¹ýGA»Æ½ð¼×¼ì²âÉ豸¡¢Ö¸±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬·¢ÏÖ±í²¿¹¥»÷ÐÐΪ£º

ͨ¹ý¶ÈÎö¹æ¶¨×Ô¶¯½«L2_WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ôö³¤µ½¹Û²ìÁÐ±í¡°¸ß·çÏÕÏνӡ±ÖУ¬×÷ΪÄÚ²¿µý±¨Êý¾ÝʹÓã»
£¨3£©Ôö³¤¡°L3_WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶ÀûÓóɹ¦¡±£¬Ç°ÌáÈÕÖ¾Ãû³ÆµÅ×Ú»òÔ̺¬¡°L2_WindowsÔ¶³Ì×ÀÃæÊÚȨ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶ÀûÓá±£¬¹¥»÷Á˾ֵÅ×Ú¡°¹¥»÷³É¹¦¡±£¬Ö÷ÕŵØÖ·ÒýÓÃ×ʲú·ì϶»òÔ´µØÖ·Æ¥ÅäÍþвµý±¨£¬´Ó¶øÌáÉý¹ØÁª¹æ¶¨µÄÏàÐŶȡ£

£¨4£©Æ¾¾Ý¶ÔCVE-2024-38077·ì϶µÄ¹¥»÷ÀûÓùý³Ì½øÐзÖÎö£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍ¼¼Êõ½×¶Î£¬¸²¸ÇµÄTTPÔ̺¬£º
TA0001³õʼ½Ó¼û£ºT1190ÀûÓÃÃæÏò¹«¼ÒµÄÀûÓ÷¨Ê½
TA0002Ö´ÐУºT1059ºÅÁîºÍ¾ç±¾Ú¹ÊÍÆ÷
TA0004ȨÏÞÌáÉý£ºT1548ÀÄÓÃÌáȨ½ÚÔì»úÔì
TA0010Êý¾Ý±íй£ºT1041Êý¾Ýͨ¹ýC2ͨ·±íй

ͨ¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´ëÖÃÄÜÁ¦£¬Õë¶Ô¸Ã·ì϶ÀûÓõĸ澯ÊÂÎñ±àÅž籾£¬½øÐÐ×Ô¶¯»¯´ëÖá£


¾©¹«Íø°²±¸11010802024551ºÅ