¡¾·ì϶¹«¸æ¡¿Î¢Èí4Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2023-04-12Ò»¡¢·ì϶¸ÅÊö
2023Äê4ÔÂ11ÈÕ£¬Î¢Èí°ä²¼ÁË4Ô°²È«¸üУ¬±¾´Î¸üн¨¸´ÁËÔ̺¬1¸ö0 day·ì϶ÔÚÄÚµÄ97¸ö°²È«·ì϶£¨²»Ô̺¬Microsoft Edge·ì϶£©£¬ÆäÖÐÓÐ7¸ö·ì϶ÆÀ¼¶Îª¡°ÑϳÁ¡±¡£
±¾´Î½¨¸´µÄ·ì϶ÖУ¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶ºÍºýŪ·ì϶µÈ¡£
΢Èí±¾´Î¹²½¨¸´ÁË1¸ö±»»ý¼«ÀûÓõÄ0 day·ì϶£¬ÈçÏ£º
CVE-2023-28252 £ºWindows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶
Windows CLFS Çý¶¯·¨Ê½ÖдæÔÚÔ½½çдÈë·ì϶£¬±¾µØµÍȨÏÞÓû§Äܹ»Í¨¹ý»ù½ñÌìÖ¾Îļþ£¨.blf ÎļþÀ©´óÃû£©µÄ²Ù×÷´¥·¢¸Ã·ì϶£¬³É¹¦ÀûÓø÷ì϶¿Éµ¼Ö±¾µØÈ¨ÏÞÌáÉýΪSYSTEM¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.8£¬Ä¿Ç°ÒÑ·¢ÏÖ±»Nokoyawa ÀÕË÷Èí¼þÀûÓá£
±¾´Î°²È«¸üÐÂÖÐÆÀ¼¶ÎªÑϳÁµÄ7¸ö·ì϶Ô̺¬£º
CVE-2023-21554£ºMicrosoft ÐÂÎŶÓÁÐÔ¶³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.8£¬Äܹ»Í¨¹ý·¢ËͶñÒâÔì×÷µÄMSMQ Êý¾Ý°üµ½MSMQ ·þÎñÆ÷À´ÀûÓø÷ì϶£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂÔÚ·þÎñÆ÷¶ËÔ¶³ÌÖ´ÐдúÂë¡£ÀûÓø÷ì϶±ØÒªÆôÓÃ×÷ΪWindows ×é¼þµÄWindows ÐÂÎŶÓÁзþÎñ£¬Äܹ»Í¨¹ý²é³ÊÇ·ñÓÐÃûΪMessage QueuingµÄ·þÎñÔÚÔËÐУ¬ÒÔ¼°ÍÆËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£
CVE-2023-28231£ºDHCP Server Service Ô¶³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.8£¬¾¹ýÉí·ÝÑéÖ¤µÄÍþвÕßÄܹ»ÀûÓÃÕë¶Ô DHCP ·þÎñµÄÌØÔì RPC ŲÓÃÀ´ÀûÓø÷ì϶¡£
CVE-2023-28219/ CVE-2023-28220£º¶þ²ãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.1£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕßÄܹ»Ïò RAS ·þÎñÆ÷·¢ËͶñÒâÏνÓÒªÇó£¬Õâ¿ÉÄܵ¼Ö RAS ·þÎñÆ÷ÍÆËã»úÉϵÄÔ¶³Ì´úÂëÖ´ÐУ¬µ«ÀûÓø÷ì϶±ØÒªÓ®µÃ¾ºÕùǰÌá¡£
CVE-2023-28250£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ9.8£¬µ±ÆôÓÃWindowsÐÂÎŶÓÁзþÎñʱ£¬³É¹¦ÀûÓø÷ì϶µÄÍþвÕßÄܹ»Í¨¹ýÍøÂç·¢ËÍÌØÔìµÄÎļþ£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐУ¬²¢´¥·¢¶ñÒâ´úÂë¡£ÀûÓø÷ì϶±ØÒªÆôÓÃ×÷ΪWindows ×é¼þµÄWindows ÐÂÎŶÓÁзþÎñ£¬Äܹ»Í¨¹ý²é³ÊÇ·ñÓÐÃûΪMessage QueuingµÄ·þÎñÔÚÔËÐУ¬ÒÔ¼°ÍÆËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£
CVE-2023-28232£ºWindows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.5£¬µ±Óû§½« Windows ¿Í»§¶ËÏνӵ½¶ñÒâ·þÎñÆ÷ʱ£¬¿ÉÄܻᴥ·¢´Ë·ì϶£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
CVE-2023-28291£ºÔʼͼÏñÀ©´óÔ¶³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.4£¬Äܹ»Í¨¹ýÓÕʹ±¾µØÓû§´ò¿ª¶ñÒâÎļþ/Á´½ÓÀ´ÀûÓø÷ì϶£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐС£
´Ë±í£¬ÖµµÃ¹Ø×¢µÄ·ì϶»¹Ô̺¬Microsoft Office¡¢Word ºÍ Publisher Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-28285¡¢CVE-2023-28311¡¢CVE-2023-28295ºÍCVE-2023-28287£©µÈ£¬Ö»Ðè´ò¿ª¶ñÒâÎĵµ¼´¿ÉÀûÓÃÕâЩ·ì϶£¬¸Ã°ÑÎȽ¨¸´´ËÀà·ì϶¡£
΢Èí4Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º
CVE | CVE ±êÌâ | ÑϳÁˮƽ |
CVE-2023-21554 | Microsoft ÐÂÎŶÓÁÐÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-28231 | DHCP Server Service Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-28219 | ¶þ²ãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-28220 | ¶þ²ãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-28250 | Windows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-28232 | Windows µã¶ÔµãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-28291 | ÔʼͼÏñÀ©´óÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-28260 | .NET DLL½Ù³ÖÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28312 | Azure »úе½ø½¨ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-28300 | Azure ·þÎñÏÎ½ÓÆ÷°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-28227 | Windows À¶ÑÀÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24860 | Microsoft Defender »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-28314 | Microsoft Dynamics 365 (on-premises) ¿çÕ¾¾ç±¾·ì϶ | ¸ßΣ |
CVE-2023-28309 | Microsoft Dynamics 365 (on-premises) ¿çÕ¾¾ç±¾·ì϶ | ¸ßΣ |
CVE-2023-28313 | Microsoft Dynamics 365 ¿Í»§ÓïÒô¿çÕ¾¾ç±¾·ì϶ | ¸ßΣ |
CVE-2023-24912 | Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-21769 | Microsoft ÐÂÎŶÓÁлؾø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-28285 | Microsoft Office ͼÐÎÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28295 | Microsoft Publisher Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28287 | Microsoft Publisher Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28288 | Microsoft SharePoint Server ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-28311 | Microsoft Word Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28243 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24883 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-24927 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24925 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24924 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24885 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24928 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24884 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24926 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24929 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24887 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24886 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28275 | Microsoft WDAC OLE DB provider for SQL ServerÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28256 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28278 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28307 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28306 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28223 | WindowsÓòÃû·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28254 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28305 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28308 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28255 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28277 | Windows DNS ·þÎñÆ÷ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-23384 | Microsoft SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-23375 | Microsoft ODBC ºÍ OLE DB Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28304 | Microsoft ODBC ºÍ OLE DB Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28299 | Visual Studio ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-28262 | Visual Studio ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-28263 | Visual Studio ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-28296 | Visual Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-24893 | Visual Studio Code Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28302 | Microsoft ÐÂÎŶÓÁлؾø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-28236 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-28216 | Windows ¸ß¼¶±¾µØ¹ý³ÌŲÓà (ALPC) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-28218 | Windows Ancillary Function Driver for WinSock ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-28269 | Windows Æô¶¯ÖÎÀíÆ÷°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-28249 | Windows Æô¶¯ÖÎÀíÆ÷°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-28273 | Windows Clip ·þÎñÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-28229 | Windows CNG ÃÜÔ¿¸ôÀë·þÎñÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-28266 | Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-28252 | Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-28226 | Windows ×¢²áÒýÇæ°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-28221 | Windows ÃýÎó»ã±¨·þÎñÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-28276 | Windows ×éÕ½Êõ°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-28238 | Windows Internet ÃÜÔ¿»¥»» (IKE) ºÍ̸À©´óÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28244 | Windows Kerberos ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-28271 | Windows ÄÚºËÄÚ´æÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-28248 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-28222 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-28272 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-28293 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-28253 | Windows ÄÚºËÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-28237 | Windows ÄÚºËÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28298 | Windows Äں˻ؾø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-28270 | Windows ËøÆÁ°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-28235 | Windows ËøÆÁ°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2023-28268 | Netlogon RPC ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-28217 | Windows ÍøÂçµØÖ·×ª»» (NAT) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-28247 | Windows ÍøÂçÎļþϵͳÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-28240 | Windows ÍøÂç¸ºÔØÆ½ºâÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28225 | Windows NTLM ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-28224 | Windows ÒÔÌ«Íøµã¶ÔµãºÍ̸ (PPPoE) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28292 | ÔʼͼÏñÀ©´óÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28228 | Windows ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-28267 | Ô¶³Ì×ÀÃæºÍ̸¿Í»§¶ËÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-28246 | Windows ×¢²á±íÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-21729 | Ô¶³Ì¹ý³ÌŲÓÃÔËÐÐʱÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-21727 | Ô¶³Ì¹ý³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-28297 | Windows Ô¶³Ì¹ý³ÌŲÓ÷þÎñ (RPCSS) ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-24931 | Windows °²È«Í¨Â·»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-28233 | Windows °²È«Í¨Â·»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-28241 | Windows °²È«Ì×½Ó×ÖËí·ºÍ̸ (SSTP) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-28234 | Windows °²È«Í¨Â·»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-28274 | Windows Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-24914 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-28284 | Microsoft Edge£¨»ùÓÚ Chromium£©°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ÖÐΣ |
CVE-2023-28301 | Microsoft Edge£¨»ùÓÚ Chromium£©´Û¸Ä·ì϶ | µÍΣ |
CVE-2023-24935 | Microsoft Edge£¨»ùÓÚ Chromium£©ºýŪ·ì϶ | µÍΣ |
CVE-2023-1823 | Chromium£ºCVE-2023-1823 ÔÚ FedCM ÖÐÖ´Ðв»µ± | δ֪ |
CVE-2023-1810 | Chromium£ºCVE-2023-1810 VisualsÖеĶѻº³åÇøÒç³ö | δ֪ |
CVE-2023-1819 | Chromium£ºCVE-2023-1819 AccessibilityÖеÄÔ½½ç¶ÁÈ¡ | δ֪ |
CVE-2023-1818 | Chromium£ºCVE-2023-1818 Vulkan ÖеĿªÊͺóʹÓà | δ֪ |
CVE-2023-1814 | Chromium£ºCVE-2023-1814 °²È«ä¯ÀÀÖв»ÊÜÐÅÀµµÄÊäÈëÑéÖ¤²»³ä·Ö | δ֪ |
CVE-2023-1821 | Chromium£ºCVE-2023-1821 WebShare ÖеÄÖ´Ðв»µ± | δ֪ |
CVE-2023-1811 | Chromium£ºCVE-2023-1811 Frames ÖеĿªÊͺóʹÓà | δ֪ |
CVE-2023-1820 | Chromium£ºCVE-2023-1820 ä¯ÀÀÆ÷º¹ÇàÖеĶѻº³åÇøÒç³ö | δ֪ |
CVE-2023-1816 | Chromium£ºCVE-2023-1816 »ÖлÖеݲȫ UI ²»ÕýÈ· | δ֪ |
CVE-2023-1815 | Chromium£ºCVE-2023-1815 Networking APIsÖеĿªÊͺóʹÓà | δ֪ |
CVE-2023-1822 | Chromium£ºCVE-2023-1822 µ¼º½Öеݲȫ UI ²»ÕýÈ· | δ֪ |
CVE-2023-1813 | Chromium£ºCVE-2023-1813 À©´óÖеÄÖ´Ðв»µ± | δ֪ |
CVE-2023-1812 | Chromium£ºCVE-2023-1812 DOM °ó¶¨ÖеÄÔ½½çÄÚ´æ½Ó¼û | δ֪ |
CVE-2023-1817 | Chromium£º CVE-2023-1817 IntentsÖеÄÕ½ÊõÖ´Ðв»¼° | δ֪ |
¶þ¡¢Ó°ÏìÁìÓò
ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º
.NET Core
Azure Machine Learning
Azure Service Connector
Microsoft Bluetooth Driver
Microsoft Defender for Endpoint
Microsoft Dynamics
Microsoft Dynamics 365 Customer Voice
Microsoft Edge (Chromium-based)
Microsoft Graphics Component
Microsoft Message Queuing
Microsoft Office
Microsoft Office Publisher
Microsoft Office SharePoint
Microsoft Office Word
Microsoft PostScript Printer Driver
Microsoft Printer Drivers
Microsoft WDAC OLE DB provider for SQL
Microsoft Windows DNS
Visual Studio
Visual Studio Code
Windows Active Directory
Windows ALPC
Windows Ancillary Function Driver for WinSock
Windows Boot Manager
Windows Clip Service
Windows CNG Key Isolation Service
Windows Common Log File System Driver
Windows DHCP Server
Windows Enroll Engine
Windows Error Reporting
Windows Group Policy
Windows Internet Key Exchange (IKE) Protocol
Windows Kerberos
Windows Kernel
Windows Layer 2 Tunneling Protocol
Windows Lock Screen
Windows Netlogon
Windows Network Address Translation (NAT)
Windows Network File System
Windows Network Load Balancing
Windows NTLM
Windows PGM
Windows Point-to-Point Protocol over Ethernet (PPPoE)
Windows Point-to-Point Tunneling Protocol
Windows Raw Image Extension
Windows RDP Client
Windows Registry
Windows RPC API
Windows Secure Boot
Windows Secure Channel
Windows Secure Socket Tunneling Protocol (SSTP)
Windows Transport Security Layer (TLS)
Windows Win32K
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2023Äê4Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2023-Apr
²¹¶¡ÏÂÔØÊ¾Àý£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2022Äê2Ô£©
2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£
3.2 һʱ´ëÊ©
Õë¶ÔCVE-2023-28252£¬¿É²Î¿¼ÒÔÏÂÁ´½Ó»ñ¸ü¶à·ì϶ÐÅÏ¢¼°IoC£º
https://securelist.com/nokoyawa-ransomware-attacks-with-windows-zero-day/109483/
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2023-Apr
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28252
https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2023-patch-tuesday-fixes-1-zero-day-97-flaws/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-04-12 | ³õ´Î°ä²¼ |
Îå¡¢¸½Â¼
5.1 GA»Æ½ð¼×¼ò½é
GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£
5.2 ¹ØÓÚGA»Æ½ð¼×
GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ