¡¾·ì϶¹«¸æ¡¿Î¢Èí7Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2023-07-12

Ò»¡¢·ì϶¸ÅÊö

2023Äê7ÔÂ11ÈÕ£¬Î¢Èí°ä²¼ÁË7Ô°²È«¸üУ¬±¾´Î¸üй²½¨¸´ÁË132¸ö·ì϶£¬ÆäÖÐÔ̺¬6¸öÒѱ»ÀûÓõķì϶¡¢37¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¬ÒÔ¼°9¸öÆÀ¼¶ÎªÑϳÁµÄ·ì϶ ¡£

±¾´Î½¨¸´µÄ·ì϶ÖУ¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶ºÍºýŪ·ì϶µÈ ¡£

΢Èí±¾´Î¹²½¨¸´ÁË6¸öÒѱ»ÀûÓõķì϶£¬ÆäÖÐCVE-2023-36884Òѱ»¹«¿ªÅû¶£¬ÏêÇéÈçÏ£º

CVE-2023-32046£ºWindows MSHTML PlatformȨÏÞÌáÉý·ì϶

¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.8£¬ÀûÓø÷ì϶±ØÒªÓû§½»»¥£¬Äܹ»Í¨¹ýµç×ÓÓʼþ»ò¶ñÒâÍøÕ¾´ò¿ªÌØÔìÎļþÀ´ÀûÓø÷ì϶£¬³É¹¦ÀûÓÿɻñµÃÔËÐÐÊÜÓ°ÏìÀûÓ÷¨Ê½µÄÓû§µÄȨÏÞ ¡£Ä¿Ç°¸Ã·ì϶ÒÑ·¢ÏÖ±»ÀûÓà ¡£

CVE-2023-32049£ºWindows SmartScreen°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.8£¬ÀûÓø÷ì϶±ØÒªÓû§½»»¥£¬Äܹ»Í¨¹ýÓÕµ¼Óû§µ¥»÷ÌØÔìURLÀ´Ö´Ðй¥»÷£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÈÆ¹ý¡°´ò¿ªÎļþ-°²È«ÖҸ桱ÌáÐÑ ¡£Ä¿Ç°¸Ã·ì϶ÒÑ·¢ÏÖ±»ÀûÓà ¡£

CVE-2023-36874£ºWindows Error Reporting ServiceÌØÈ¨ÌáÉý·ì϶

¸Ã·ì϶´æÔÚÓÚWindows ÃýÎó»ã±¨·þÎñÖУ¬ÆäCVSSv3ÆÀ·ÖΪ7.8£¬¶ÔÖ¸±êÍÆËã»úÓµÓб¾µØ½Ó¼ûȨÏÞÇÒ¿ÉÄÜÔÚÍÆËã»úÉÏ´´½¨Îļþ¼ÐºÍ»úÄܸú×Ù£¬²¢ÓµÓÐͨ³£Óû§Ä¬ÈÏȨÏÞµÄÍþвÕß¿ÉÀûÓø÷ì϶»ñµÃÖÎÀíԱȨÏÞ ¡£Ä¿Ç°¸Ã·ì϶ÒÑ·¢ÏÖ±»ÀûÓà ¡£

CVE-2023-36884 £ºOffice ºÍ Windows HTML Ô¶³Ì´úÂëÖ´Ðзì϶

¸Ã·ì϶ӰÏìÁ˶à¸öWindowsºÍOffice²úÆ·£¬ÆäCVSSv3ÆÀ·ÖΪ8.3£¬ÍþвÕßÄܹ»´´½¨ÌØÔìµÄ Microsoft OfficeÎĵµ²¢ÓÕµ¼Êܺ¦Õß´ò¿ª¶ñÒâÎļþ£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔÚÊܺ¦ÕߵĸߵÍÎÄÖÐÔ¶³ÌÖ´ÐдúÂë ¡£¸Ã·ì϶ÒѾ­¹«¿ªÅû¶ÇÒÒÑ·¢ÏÖ±»ÀûÓã¬Ä¿Ç°Î¢ÈíÔÝδ°ä²¼¸Ã·ì϶µÄ°²È«¸üУ¬µ«ÒѰ䲼Á˸÷ì϶µÄ»º½â´ëÊ© ¡£

CVE-2023-35311 £ºMicrosoft Outlook °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ8.8£¬ÀûÓø÷ì϶±ØÒªÓû§½»»¥£¬Äܹ»Í¨¹ýÓÕµ¼Óû§µ¥»÷ÌØÔìURLÀ´Ö´Ðй¥»÷£¬³É¹¦ÀûÓø÷ì϶Äܹ»Èƹý Microsoft Outlook °²È«Í¨ÖªÌáÐÑ ¡£Ä¿Ç°¸Ã·ì϶ÒÑ·¢ÏÖ±»ÀûÓà ¡£

ADV230001£º¹ØÓÚ¶ñÒâʹÓà Microsoft ÊðÃûÇý¶¯·¨Ê½µÄÖ¸ÄÏ

΢Èí×î½ü»ñϤ£¬¾­Î¢ÈíWindows Ó²¼þ¿ª·¢ÈËÔ±´òË㣨MWHDP£©ÈÏÖ¤µÄÇý¶¯·¨Ê½ÔÚºóÀûÓûÖб»¶ñÒâʹÓà ¡£ÔÚÕâЩ¹¥»÷ÖУ¬¹¥»÷ÕßÔÚʹÓÃÇý¶¯·¨Ê½Ö®Ç°¾ÍÒѾ­»ñµÃÁËÊÜϰȾϵͳµÄÖÎÀíȨÏÞ£¬µ÷²éÏÔʾ£¬Î¢ÈíºÏ×÷ͬ°éÖÐÐÄ (MPC) µÄ¶à¸ö¿ª·¢ÕßÕÊ»§ÔÚÌá·´Ä¿ÒâÇý¶¯·¨Ê½ÒÔ»ñȡ΢ÈíÊðÃû£¬Ä¿Ç°Î¢ÈíÒѾ­³·³ý/½ûÓÃÁËÀÄÓà Windows Õ½Êõ·ì϶װÖöñÒâÄÚºËģʽÇý¶¯·¨Ê½µÄ´úÂëÊðÃûÖ¤ÊéºÍ¿ª·¢ÈËÔ¹ØÊ»§ ¡£

΢Èí7Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º

CVE-ID

CVE±êÌâ

ÑϳÁÐÔ

CVE-2023-33160

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-33157

Microsoft   SharePointÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-35315

Windows   Layer-2 Bridge Network Driver Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-32057

Microsoft ÐÂÎŶÓÁÐÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-35297

Windows   Pragmatic ͨÓÃ×é²¥ (PGM) Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-35352

Windows Ô¶³Ì×ÀÃæ°²È«Ö°ÄÜÈÆ¹ý·ì϶

ÑϳÁ

CVE-2023-35367

Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-35366

Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-35365

Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-33127

.NET ºÍ Visual Studio ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-33170

ASP.NET ºÍ Visual Studio °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2023-36871

Azure   Active Directory °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2023-35348

Active   Directory Áª³ÆÉí·ÝÑéÖ¤·þÎñ°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2023-33171

Microsoft   Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾·ì϶

¸ßΣ

CVE-2023-35335

Microsoft   Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾·ì϶

¸ßΣ

CVE-2023-33149

Microsoft   Office Graphics Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-21756

Windows   Win32k ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35333

MediaWiki   PandocUpload À©´óÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-33148

Microsoft   Office ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2023-36884

Office ºÍ Windows HTML Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-33150

Microsoft   Office °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2023-33152

Microsoft   ActiveX Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-33158

Microsoft   Excel Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-33161

Microsoft   Excel Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-33162

Microsoft   Excel ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-33151

Microsoft   Outlook ºýŪ·ì϶

¸ßΣ

CVE-2023-33153

Microsoft   Outlook Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35311

Microsoft   Outlook °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2023-33134

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-33165

Microsoft   SharePoint Server °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2023-33159

Microsoft   SharePoint Server ºýŪ·ì϶

¸ßΣ

CVE-2023-32052

Microsoft   Power Apps ºýŪ·ì϶

¸ßΣ

CVE-2023-32085

Microsoft   PostScript and PCL6 Class Printer Driver ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-35302

Microsoft   PostScript and PCL6 Class Printer Driver Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35296

Microsoft   PostScript and PCL6 Class Printer Driver ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-35324

Microsoft   PostScript and PCL6 Class Printer Driver ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-32040

Microsoft   PostScript and PCL6 Class Printer Driver ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-35306

Microsoft   PostScript and PCL6 Class Printer Driver ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-32039

Microsoft   PostScript and PCL6 Class Printer Driver ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-35303

USB Audio   Class System Driver Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36872

VP9 Video   Extensions ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-32051

Raw Image   Extension Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35373

Mono   Authenticode ÑéÖ¤ºýŪ·ì϶

¸ßΣ

CVE-2023-35374

Paint 3D Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-32047

Paint 3D Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35310

Windows   DNS Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35346

Windows   DNS Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35345

Windows   DNS Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35344

Windows   DNS Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36868

Azure   Service Fabric on Windows ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36867

Visual   Studio Code GitHub Pull Requests and Issues Extension Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35351

Windows   Active Directory Ö¤Êé·þÎñ (AD CS) Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35350

Windows   Active Directory Ö¤Êé·þÎñ (AD CS) Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-32055

Active   Template Library ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2023-29347

Windows   Admin Center ºýŪ·ì϶

¸ßΣ

CVE-2023-35347

Microsoft ×°Ö÷þÎñȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2023-35329

Windows Éí·ÝÑéÖ¤»Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-35326

Windows   CDPÓû§×é¼þÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-35362

Windows   Clip ·þÎñÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-33155

Windows   Cloud Files Mini Filter Driver ÐòÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-32033

Microsoft   Failover Cluster Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35340

Windows   CNG ÃÜÔ¿¸ôÀë·þÎñÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35299

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35320

Connected   User Experiences and Telemetry ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35353

Connected   User Experiences and Telemetry ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35339

Windows   CryptoAPI »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-33174

Windows ¼ÓÃÜÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-33156

Microsoft   Defender ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2023-35322

Windows ²¿Êð·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35321

Windows ²¿Êð·þÎñ»Ø¾ø·þÎñ·ì϶

¸ßΣ

ADV230002

Microsoft ½â¾öÇ÷Ïò¿Æ¼¼ EFI Ä£¿éÖеݲȫְÄÜÈÆ¹ýÎÊÌâµÄÖ¸ÄÏ

¸ßΣ

CVE-2023-36874

Windows ÃýÎó»ã±¨·þÎñÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-32083

Microsoft   Failover Cluster ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-35343

Windows µØÀí¶¨Î»·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-32084

HTTP.sys »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-35298

HTTP.sys »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-35342

Windows   Image Acquisition ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2023-32053

Windows   Installer ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2023-32050

Windows   Installer ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2023-35304

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35363

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35305

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35356

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35357

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35358

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-32037

Windows   Layer-2 Bridge Network Driver ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-35331

Windows   Local Security Authority (LSA) »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-35341

Microsoft   DirectMusic ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-35309

Microsoft ÐÂÎŶÓÁÐÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-32045

Microsoft ÐÂÎŶÓÁлؾø·þÎñ·ì϶

¸ßΣ

CVE-2023-32044

Microsoft ÐÂÎŶÓÁлؾø·þÎñ·ì϶

¸ßΣ

CVE-2023-32046

Windows   MSHTML ƽ̨ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2023-35336

Windows   MSHTML ƽ̨°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2023-35308

Windows   MSHTML ƽ̨°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2023-21526

Windows   Netlogon ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-33163

Windows ÍøÂç¸ºÔØÆ½ºâÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35361

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35364

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35360

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-32038

Microsoft   ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-32042

OLE×Ô¶¯»¯ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-35323

Windows OLEÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-35313

Windows ÔÚÏßÖ¤Êé״̬ºÍ̸ (OCSP) SnapIn Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-33154

Windows ·ÖÇøÖÎÀíÇý¶¯·¨Ê½È¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2023-35338

Windows ¶ÔµÈÃû³Æ½âÎöºÍ̸»Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-35325

Windows ´òÓ¡ºó¶Ü´¦Ö÷¨Ê½ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-32043

Windows Ô¶³Ì×ÀÃæ°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2023-35332

Windows Ô¶³Ì×ÀÃæºÍ̸°²È«Ö°ÄÜÈÆ¹ý

¸ßΣ

CVE-2023-35300

Remote   Procedure Call Runtime Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-33168

Remote   Procedure Call Runtime »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-33173

Remote   Procedure Call Runtime »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-33172

Remote   Procedure Call Runtime »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-32035

Remote   Procedure Call Runtime »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-33166

Remote   Procedure Call Runtime »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-32034

Remote   Procedure Call Runtime »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-33167

Remote   Procedure Call Runtime »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-33169

Remote   Procedure Call Runtime »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-35318

Remote   Procedure Call Runtime »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-33164

Remote   Procedure Call Runtime »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-35319

Remote   Procedure Call Runtime »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-35316

Remote   Procedure Call Runtime ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-35314

Remote   Procedure Call Runtime »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-35317

Windows   Server Update Service (WSUS) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-32056

Windows   Server Update Service (WSUS) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-32049

Windows   SmartScreen°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2023-35330

Windows À©´óЭÉ̻ؾø·þÎñ·ì϶

¸ßΣ

CVE-2023-35328

Windows ÊÂÎñÖÎÀíÆ÷ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-32041

Windows   Update Orchestrator·þÎñÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-35312

Microsoft   VOLSNAP.SYS ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-32054

Volume   Shadow Copy ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-35337

Win32k ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

ADV230001

¹ØÓÚ¶ñÒâʹÓà Microsoft ÊðÃûÇý¶¯·¨Ê½µÄÖ¸ÄÏ

ÎÞ

  

¶þ¡¢Ó°ÏìÁìÓò

ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º

Windows Certificates

Windows EFI Partition

Windows Netlogon

Microsoft Graphics Component

Windows Admin Center

Windows Cluster Server

Windows Remote Procedure Call

Windows Layer 2 Tunneling Protocol

Windows ODBC Driver

Microsoft Printer Drivers

Windows Update Orchestrator Service

Windows OLE

Windows Remote Desktop

Windows Message Queuing

Windows MSHTML Platform

Paint 3D

Windows SmartScreen

Windows Installer

Microsoft Windows Codecs Library

Microsoft Power Apps

Windows Volume Shadow Copy

Windows Active Template Library

Windows Server Update Service

Windows Failover Cluster

Windows HTTP.sys

.NET and Visual Studio

Microsoft Office SharePoint

Microsoft Office

Microsoft Office Outlook

Microsoft Office Access

Windows Partition Management Driver

Windows Cloud Files Mini Filter Driver

Windows Defender

Microsoft Office Excel

Windows Network Load Balancing

ASP.NET and .NET

Microsoft Dynamics

Windows Cryptographic Services

Windows PGM

Windows Common Log File System Driver

Windows Kernel

Role: DNS Server

Windows VOLSNAP.SYS

Windows Online Certificate Status Protocol (OCSP) SnapIn

Windows Layer-2 Bridge Network Driver

Windows Connected User Experiences and Telemetry

Windows Deployment Services

Windows Print Spooler Components

Windows CDP User Components

Windows Transaction Manager

Windows Authentication Methods

Windows SPNEGO Extended Negotiation

Windows Local Security Authority (LSA)

Microsoft Media-Wiki Extensions

Windows Win32K

Windows Peer Name Resolution Protocol

Windows CryptoAPI

Windows CNG Key Isolation Service

Windows Media

Windows Image Acquisition

Windows Geolocation Service

Windows App Store

Azure Active Directory

Windows Active Directory Certificate Services

Windows NT OS Kernel

Windows Clip Service

Windows Routing and Remote Access Service (RRAS)

Mono Authenticode

Visual Studio Code

Service Fabric

Windows Error Reporting


Èý¡¢°²È«´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´ ¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öà ¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüР¡£

4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üР¡£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öà ¡£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüР¡£

2023Äê7Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2023-Jul

²¹¶¡ÏÂÔØÊ¾Àý£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó ¡£

image.png

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2022Äê2Ô£©

2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó ¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öà ¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú ¡£

 

3.2 һʱ´ëÊ©

Õë¶ÔCVE-2023-36884£¬Î¢ÈíÒѾ­°ä²¼ÁËÓйػº½â´ëÊ©£¬¿É²Î¿¼£º

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884

https://www.microsoft.com/en-us/security/blog/2023/07/11/storm-0978-attacks-reveal-financial-and-espionage-motives/

¹ØÓÚ¶ñÒâʹÓà Microsoft ÊðÃûÇý¶¯·¨Ê½µÄÖ¸ÄÏ£¬¸ü¶àÐÅÏ¢¿É²Î¿¼£º

https://msrc.microsoft.com/update-guide/en-US/vulnerability/ADV230001

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ ¡£

l  ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È ¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä ¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2023-Jul

https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2023-patch-tuesday-warns-of-6-zero-days-132-flaws/

https://www.bleepingcomputer.com/news/security/microsoft-unpatched-office-zero-day-exploited-in-nato-summit-attacks/

  

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-07-12

³õ´Î°ä²¼

 

Îå¡¢¸½Â¼

5.1 GA»Æ½ð¼×¼ò½é

GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò» ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË ¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊÐ ¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦ ¡£

5.2 ¹ØÓÚGA»Æ½ð¼×

GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½ ¡£

¹Ø×¢ÎÒÃÇ£º

image.png