¡¾·ì϶¹«¸æ¡¿Î¢Èí3Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2023-03-15Ò»¡¢·ì϶¸ÅÊö
2023Äê3ÔÂ14ÈÕ£¬Î¢Èí°ä²¼ÁË3Ô°²È«¸üУ¬±¾´Î¸üн¨¸´ÁËÔ̺¬2¸ö0 day·ì϶ÔÚÄÚµÄ83¸ö°²È«·ì϶£¨²»Ô̺¬Microsoft Edge·ì϶£©£¬ÆäÖÐÓÐ9¸ö·ì϶ÆÀ¼¶Îª¡°ÑϳÁ¡±¡£
·ì϶ÏêÇé
±¾´Î½¨¸´µÄ·ì϶ÖУ¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶ºÍºýŪ·ì϶µÈ¡£
΢Èí±¾´Î¹²½¨¸´ÁË2¸ö±»»ý¼«ÀûÓõÄ0 day·ì϶£¨Ö¸·ì϶Òѱ»¹«¿ªÅû¶»ò±»»ý¼«ÀûÓõ«Ã»ÓпÉÓõĹٷ½½¨¸´·¨Ê½£©£¬ÈçÏ£º
CVE-2023-23397£ºMicrosoft Outlook ÌØÈ¨ÌáÉý·ì϶
¸Ã·ì϶ÊÇMicrosoft Outlook for WindowsÖеÄÌØÈ¨ÌáÉý·ì϶£¬ ÆäCVSSv3ÆÀ·ÖΪ9.8¡£Äܹ»Í¨¹ý·¢ËÍÌØÔìµÄµç×ÓÓʼþÀ´ÀûÓø÷ì϶£¬¸Ãµç×ÓÓʼþÔÚOutlook ¿Í»§¶Ë¼ìË÷ºÍ´¦ÖÃʱ×Ô¶¯´¥·¢£¬¿ÉÄܵ¼ÖÂÊܺ¦ÕßÏνӵ½ÍþвÕß½ÚÔìµÄ±í²¿ UNC µØÎ»£¬´Ó¶øµ¼ÖÂÊܺ¦ÕßµÄ Net-NTLMv2 ¹þϣй¶£¬ÍþвÕßÄܹ»½«Æäת·¢¸øÁíÒ»¸ö·þÎñ£¬²¢ÒÔÊܺ¦ÕßµÄÉí·Ý½øÐÐÈÏÖ¤¡£¸Ã·ì϶ĿǰÔÝδ¹«¿ªÅû¶£¬µ«ÒÑ·¢ÏÖ±»ºÚ¿Í×éÖ¯STRONTIUM ÀûÓá£
CVE-2023-24880£ºWindows SmartScreen °²È«Ö°ÄÜÈÆ¹ý·ì϶
Äܹ»Í¨¹ýÔì×÷¶ñÒâÎļþÀ´Ì Web ÏóÕ÷ (MOTW) ·ÀÓù£¬´Ó¶øµ¼Ö°²È«Ö°ÄÜ£¨ÀýÈç Microsoft Office ÖеÄÊܱ£»¤ÊÓͼ£©Êܵ½°Ü»µ£¬ÕâЩְÄÜÒÀÀµÓÚ MOTW ÏóÕ÷¡£¸Ã·ì϶ĿǰÒѾ¹«¿ªÅû¶£¬ÇÒÒÑ·¢ÏÖ±»Magniber ÀÕË÷Èí¼þÀûÓ㬹ȸèTAG°µÊ¾¸Ã·ì϶Ϊ΢Èí2022Äê12Ô½¨¸´µÄCVE-2022-44698£¨Windows SmartScreen °²È«Ö°ÄÜÈÆ¹ý·ì϶£©µÄÈÆ¹ý¡£
±¾´Î°²È«¸üÐÂÖÐÆÀ¼¶ÎªÑϳÁµÄ9¸ö·ì϶Ô̺¬£º
l CVE-2023-23415£º»¥ÁªÍø½ÚÔìÐÂÎźÍ̸ (ICMP) Ô¶³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.8£¬Äܹ»ÏòÖ¸±êÖ÷»ú·¢ËÍÒ»¸öµÍ¼¶ºÍ̸ÃýÎó£¬ÔÚÁíÒ»¸öICMPÊý¾Ý°üµÄ±¨Í·ÖÐÔ̺¬Ò»¸öË鯬IPÊý¾Ý°ü¡£Òª´¥·¢Ò×Êܹ¥»÷µÄ´úÂëõè¾¶£¬Ö¸±êÖ÷»úÉϵÄÀûÓ÷¨Ê½±ØÐë°ó¶¨µ½ÔʼÌ×½Ó×Ö¡£
l CVE-2023-23397£ºMicrosoft Outlook ÌØÈ¨ÌáÉý·ì϶
l CVE-2023-23404£ºWindows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.1£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕßÄܹ»Ïò RAS ·þÎñÆ÷·¢ËÍÌØÔìÏνÓÒªÇó£¬Õâ¿ÉÄܵ¼Ö RAS ·þÎñÆ÷ÍÆËã»úÉϵÄÔ¶³Ì´úÂëÖ´ÐС£µ«ÀûÓø÷ì϶±ØÒªÓ®µÃ¾ºÕùǰÌá¡£
l CVE-2023-23411£ºWindows Hyper-V »Ø¾ø·þÎñ·ì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ6.5£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂHyper-V guestÓ°Ïì Hyper-V Ö÷»úµÄÖ°ÄÜ¡£
l CVE-2023-23416£ºWindows ¼ÓÃÜ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.4£¬ÍþвÕßÄܹ»Í¨¹ýÓÕµ¼¾¹ýÉí·ÝÑéÖ¤µÄÓû§ÔÚÊÜÓ°ÏìµÄϵͳÉϵ¼Èë¶ñÒâÖ¤ÊéÀ´ÀûÓø÷ì϶£¬¿ÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐС£
l CVE-2023-23392£ºHTTPºÍ̸ջԶ³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.8£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕßÄܹ»Í¨¹ý½«ÌØÔìµÄÊý¾Ý°ü·¢Ë͵½Ö¸±ê·þÎñÆ÷£¬ÀûÓà HTTP ºÍ̸ջ (http.sys) À´´¦ÖÃÊý¾Ý°ü¡£
l CVE-2023-21708£ºRemote Procedure Call RuntimeÔ¶³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.8£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕß±ØÒªÏò RPC Ö÷»ú·¢ËÍÌØÔìµÄ RPC ŲÓÃÀ´ÀûÓø÷ì϶£¬¿ÉÄܵ¼ÖÂÔÚ·þÎñÆ÷¶ËÒÔÓë RPC ·þÎñÒ»ÑùµÄȨÏÞÖ´ÐÐÔ¶³Ì´úÂë¡£Äܹ»Í¨¹ýÔÚÆóÒµ±íΧ·À»ðǽÉÏ×è¶ÏTCP 135¶Ë¿ÚÀ´Ï÷¼õÕë¶Ô¸Ã·ì϶µÄ¹¥»÷¡£
l CERT/CC£ºCVE-2023-1017 TPM2.0 Ä£¿é¿âÌØÈ¨ÌáÉý·ì϶
¸Ã·ì϶ΪµÚÈý·½Çý¶¯·¨Ê½Öеķì϶£¬ÆäCVSSv3ÆÀ·ÖΪ8.8£¬¿ÉÄܵ¼Ö¸ù·ÖÇøÖеÄÔ½½çдÈë¡£
l CERT/CC£ºCVE-2023-1018 TPM2.0 Ä£¿é¿âÌØÈ¨ÌáÉý·ì϶
¸Ã·ì϶ΪµÚÈý·½Çý¶¯·¨Ê½Öеķì϶£¬ÆäCVSSv3ÆÀ·ÖΪ8.8¡£
΢Èí3Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º
CVE | CVE ±êÌâ | ÑϳÁÐÔ |
CVE-2023-23415 | »¥ÁªÍø½ÚÔìÐÂÎźÍ̸ (ICMP) Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-23397 | Microsoft Outlook ÌØÈ¨ÌáÉý·ì϶ | ÑϳÁ |
CVE-2023-23404 | Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-23411 | Windows Hyper-V »Ø¾ø·þÎñ·ì϶ | ÑϳÁ |
CVE-2023-23416 | Windows ¼ÓÃÜ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-23392 | HTTPºÍ̸ջԶ³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-21708 | Remote Procedure Call RuntimeÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-1017 | CERT/CC£ºCVE-2023-1017 TPM2.0 Ä£¿é¿âÌØÈ¨ÌáÉý·ì϶ | ÑϳÁ |
CVE-2023-1018 | CERT/CC£ºCVE-2023-1018 TPM2.0 Ä£¿é¿âÌØÈ¨ÌáÉý·ì϶ | ÑϳÁ |
CVE-2023-23408 | Azure Apache Ambari ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-23409 | ¿Í»§¶Ë·þÎñÆ÷ÔËÐÐʱ×Óϵͳ (CSRSS) ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-23394 | ¿Í»§¶Ë·þÎñÆ÷ÔËÐÐʱ×Óϵͳ (CSRSS) ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-23388 | Windows À¶ÑÀÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-24920 | Microsoft Dynamics 365 (on-premises) ¿çÕ¾¾ç±¾·ì϶ | ¸ßΣ |
CVE-2023-24879 | Microsoft Dynamics 365 (on-premises) ¿çÕ¾¾ç±¾·ì϶ | ¸ßΣ |
CVE-2023-24919 | Microsoft Dynamics 365 (on-premises) ¿çÕ¾¾ç±¾·ì϶ | ¸ßΣ |
CVE-2023-24891 | Microsoft Dynamics 365 (on-premises) ¿çÕ¾¾ç±¾·ì϶ | ¸ßΣ |
CVE-2023-24922 | Microsoft Dynamics 365 ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-24921 | Microsoft Dynamics 365 (on-premises) ¿çÕ¾¾ç±¾·ì϶ | ¸ßΣ |
CVE-2023-24892 | Microsoft Edge£¨»ùÓÚ Chromium£©Webview2 ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-24910 | Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-23398 | Microsoft Excel ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-23396 | Microsoft Excel »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-23399 | Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-23395 | Microsoft SharePoint Server ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-24890 | Microsoft OneDrive for iOS °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-24930 | Microsoft OneDrive for MacOS ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-24882 | Microsoft OneDrive for Android ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-24923 | Microsoft OneDrive for Android ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-24907 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24857 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-24868 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24872 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24876 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24913 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24864 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-24866 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-24906 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-24867 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24863 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-24858 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-24911 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-24870 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-24909 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-23406 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-23413 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24856 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-24865 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-23403 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-23401 | Windows Media Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-23402 | Windows Media Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-23391 | Office for Android ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-23400 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-23383 | Service Fabric Explorer ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-23618 | GitHub£ºCVE-2023-23618 Git for Windows Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-22743 | GitHub£ºCVE-2023-22743 Git for Windows Installer ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-23946 | GitHub£ºCVE-2023-23946 mingit Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-22490 | GitHub£ºCVE-2023-22490 mingit ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-23412 | Windows ÕÊ»§Í¼Æ¬ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-24871 | Windows À¶ÑÀ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-23393 | Windows BrokerInfrastructure ·þÎñÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-23389 | Microsoft Defender ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-23410 | Windows HTTP.sys ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-24859 | Windows Internet ÃÜÔ¿»¥»» (IKE) À©´ó»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-23420 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-23422 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-23421 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-23423 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-23417 | Windows ·ÖÇøÖÎÀíÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-23407 | Windows ÒÔÌ«Íøµã¶ÔµãºÍ̸ (PPPoE) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-23385 | Windows ÒÔÌ«Íøµã¶ÔµãºÍ̸ (PPPoE) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-23414 | Windows ÒÔÌ«Íøµã¶ÔµãºÍ̸ (PPPoE) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-23405 | Remote Procedure Call RuntimeÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24869 | Remote Procedure Call RuntimeÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24908 | Remote Procedure Call RuntimeÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-23419 | Windows µ¯ÐÔÎļþϵͳ (ReFS) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-23418 | Windows µ¯ÐÔÎļþϵͳ (ReFS) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-24862 | Windows °²È«Í¨Â·»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-24861 | Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-24880 | Windows SmartScreen °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ÖÐΣ |
CVE-2023-0567 | PHP Password_verify()ÑéÖ¤ÃýÎó·ì϶ | δ֪ |
CVE-2023-20052 | ClamAV ÐÅϢй¶·ì϶ | δ֪ |
CVE-2023-20032 | ClamAV Ô¶³Ì´úÂëÖ´Ðзì϶ | δ֪ |
CVE-2023-1236 | Chromium£ºCVE-2023-1236 ÄÚ²¿ÊµÏÖ²»µ± | δ֪ |
CVE-2023-1235 | Chromium£ºDevTools ÖÐµÄ CVE-2023-1235 ÀàÐÍ»ìºÏ | δ֪ |
CVE-2023-1213 | Chromium£ºCVE-2023-1213 ÔÚ Swiftshader ÖпªÊͺóʹÓà | δ֪ |
CVE-2023-1234 | Chromium£ºCVE-2023-1234 Intents ÖеIJ»µ±Ö´ÐÐ | δ֪ |
CVE-2023-1223 | Chromium£ºCVE-2023-1223 ×Ô¶¯Ìî³äÖеÄÕ½ÊõÖ´Ðв»¼° | δ֪ |
CVE-2023-1222 | Chromium£ºCVE-2023-1222 Web Audio API ÖеĶѻº³åÇøÒç³ö | δ֪ |
CVE-2023-1221 | Chromium£ºCVE-2023-1221 À©´ó API ÖеÄÕ½ÊõÖ´Ðв»¼° | δ֪ |
CVE-2023-1229 | Chromium£ºCVE-2023-1229 ÔÚPermission promptsÖÐÖ´Ðв»µ± | δ֪ |
CVE-2023-1228 | Chromium£ºCVE-2023-1228 IntentsÖеÄÕ½ÊõÖ´Ðв»¼° | δ֪ |
CVE-2023-1224 | Chromium£ºCVE-2023-1224 Web Ö§¸¶ API ÖеÄÕ½ÊõÖ´Ðв»¼° | δ֪ |
CVE-2023-1220 | Chromium£ºUMA ÖÐµÄ CVE-2023-1220 ¶Ñ»º³åÇøÒç³ö | δ֪ |
CVE-2023-1216 | Chromium£ºCVE-2023-1216 ÔÚ DevTools ÖпªÊͺóʹÓà | δ֪ |
CVE-2023-1215 | Chromium£ºCVE-2023-1215 CSS ÖеÄÀàÐÍ»ìºÏ | δ֪ |
CVE-2023-1214 | Chromium£ºV8 ÖÐµÄ CVE-2023-1214 ÀàÐÍ»ìºÏ | δ֪ |
CVE-2023-1219 | Chromium£ºÖ¸±êÖÐµÄ CVE-2023-1219 ¶Ñ»º³åÇøÒç³ö | δ֪ |
CVE-2023-1218 | Chromium£ºCVE-2023-1218 ÔÚ WebRTC ÖÐÃâ·ÑʹÓà | δ֪ |
CVE-2023-1217 | Chromium£ºCVE-2023-217±ÀÀ£»ã±¨ÖеIJֿ⻺³åÇøÒç³ö | δ֪ |
CVE-2023-1230 | Chromium£ºCVE-2023-1230 WebApp ×°ÖÃÖеIJ»µ±Ö´ÐÐ | δ֪ |
CVE-2023-1232 | Chromium£ºCVE-2023-1232 Resource Timing ÖеÄÕ½ÊõÖ´Ðв»¼° | δ֪ |
CVE-2023-1233 | Chromium£ºCVE-2023-1233 Resource Timing ÖеÄÕ½ÊõÖ´Ðв»¼° | δ֪ |
CVE-2023-1231 | Chromium£ºCVE-2023-1231 ÔÚ×Ô¶¯Ìî³äÖÐÖ´Ðв»µ± | δ֪ |
¶þ¡¢Ó°ÏìÁìÓò
ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º
Azure
Client Server Run-time Subsystem (CSRSS)
Internet Control Message Protocol (ICMP)
Microsoft Bluetooth Driver
Microsoft Dynamics
Microsoft Edge (Chromium-based)
Microsoft Graphics Component
Microsoft Office Excel
Microsoft Office Outlook
Microsoft Office SharePoint
Microsoft OneDrive
Microsoft PostScript Printer Driver
Microsoft Printer Drivers
Microsoft Windows Codecs Library
Office for Android
Remote Access Service Point-to-Point Tunneling Protocol
Role: DNS Server
Role: Windows Hyper-V
Service Fabric
Visual Studio
Windows Accounts Control
Windows Bluetooth Service
Windows Central Resource Manager
Windows Cryptographic Services
Windows Defender
Windows HTTP Protocol Stack
Windows HTTP.sys
Windows Internet Key Exchange (IKE) Protocol
Windows Kernel
Windows Partition Management Driver
Windows Point-to-Point Protocol over Ethernet (PPPoE)
Windows Remote Procedure Call
Windows Remote Procedure Call Runtime
Windows Resilient File System (ReFS)
Windows Secure Channel
Windows SmartScreen
Windows TPM
Windows Win32K
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2023Äê3Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2023-Mar
²¹¶¡ÏÂÔØÊ¾Àý£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2022Äê2Ô£©
2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£
3.2 һʱ´ëÊ©
Õë¶ÔCVE-2023-23397£¨Microsoft Outlook ÌØÈ¨ÌáÉý·ì϶£©£¬ÊÜÓ°ÏìÓû§¿É²Î¿¼¹Ù·½²¼¸æÊµÊ±×°Öò¹¶¡£¬Ò²¿É²Î¿¼Î¢Èí°²È«ÏìÓ¦ÖÐÐİ䲼µÄ»º½âÖ¸ÄÏ¡£
https://msrc.microsoft.com/blog/2023/03/microsoft-mitigates-outlook-elevation-of-privilege-vulnerability/
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2023-Mar
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397
https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2023-patch-tuesday-fixes-2-zero-days-83-flaws/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-03-15 | ³õ´Î°ä²¼ |
Îå¡¢¸½Â¼
5.1 GA»Æ½ð¼×¼ò½é
GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£
5.2 ¹ØÓÚGA»Æ½ð¼×
GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ