¡¾·ì϶¹«¸æ¡¿Î¢Èí10Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2023-10-11


Ò»¡¢·ì϶¸ÅÊö

2023Äê10ÔÂ10ÈÕ£¬Î¢Èí°ä²¼ÁË10Ô°²È«¸üУ¬±¾´Î¸üй²½¨¸´ÁË104¸ö·ì϶£¨²»Ô̺¬Microsoft Edge-Chromium·ì϶£©£¬ÆäÖÐÔ̺¬3¸öÒѱ»ÀûÓõķì϶¡¢45¸öÔ¶³Ì´úÂëÖ´Ðзì϶ÒÔ¼°12¸öÆÀ¼¶ÎªÑϳÁµÄ·ì϶¡£

±¾´Î½¨¸´µÄ·ì϶ÖУ¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶ºÍºýŪ·ì϶µÈ¡£

΢Èí±¾´Î¹²½¨¸´ÁË3¸öÒѱ»ÀûÓõķì϶£º

CVE-2023-41763£ºSkype for Business ȨÏÞÌáÉý·ì϶

¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ5.3£¬Ô¶³ÌÍþвÕßÄܹ»¶ÔÖ¸±ê Skype for Business ·þÎñÆ÷½øÐÐÌØÔìÍøÂçŲÓã¬Õâ¿ÉÄܵ¼Ö½âÎöÏòËÁÒâµØÖ··¢³öµÄ http ÒªÇ󣬴Ӷø¿ÉÄܵ¼ÖÂIP µØÖ·»ò¶Ë±êÓïµÈÃô¸ÐÐÅϢй¶£¬ÍþвÕß¿ÉÄÜÀûÓÃÕâЩÐÅÏ¢À´½Ó¼ûÄÚ²¿ÍøÂ硣Ŀǰ¸Ã·ì϶ÒѾ­¹«¿ªÅû¶£¬ÇÒÒÑ·¢ÏÖ±»ÀûÓá£

CVE-2023-36563£ºMicrosoft WordPad ÐÅϢй¶·ì϶

¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ6.5£¬ÍþвÕßÄܹ»Í¨¹ýµÇ¼ϵͳÔËÐÐÌØÔìµÄÀûÓ÷¨Ê½»òÕßÓÕµ¼±¾µØÓû§´ò¿ª¶ñÒâÎļþÀ´ÀûÓø÷ì϶£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼Ö NTLM ¹þϣֵй¶¡£Ä¿Ç°¸Ã·ì϶ÒѾ­¹«¿ªÅû¶£¬ÇÒÒÑ·¢ÏÖ±»ÀûÓá£

MITRE£ºCVE-2023-44487-HTTP/2 ¼±¾ç³ÁÖù¥»÷

΢ÈíÒѰ䲼Õë¶ÔHTTP/2 µÄÉ¢²¼Ê½»Ø¾ø·þÎñ (DDoS) ¹¥»÷£¨³ÆÎª¡°HTTP/2 Rapid Reset¡±£¬×·×ÙΪCVE-2023-44487£©µÄ»º½â´ëÊ©£¬¸Ã¹¥»÷ͨ¹ýÀÄÓà HTTP/2 µÄÒªÇóÈ¡µÞÖ°ÄÜ£¬¿ÉÄܵ¼Ö·þÎñÆ÷×ÊÔ´ºÄ¾¡£¬Ôì³É»Ø¾ø·þÎñ¡£¸Ã·ì϶×Ô8ÔÂÒÔÀ´Òѱ»¿í·ºÀûÓá£

΢Èí±¾´Î¸üн¨¸´µÄ12¸öÆÀ¼¶Îª¡°ÑϳÁ¡±µÄ·ì϶Ô̺¬£º

9¸öΪµÚ2²ãËí·ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-41770¡¢CVE-2023-41765¡¢CVE-2023-41767¡¢CVE-2023-38166¡¢CVE-2023-41774¡¢CVE-2023-41773¡¢CVE-2023-41771¡¢CVE-2023-41769ºÍCVE-2023-41768£©£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕßÄܹ»Ïò·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) ·þÎñÆ÷·¢ËÍÌØÔìµÄºÍ̸ÐÂÎÅ£¬¿ÉÄܵ¼Ö RAS ·þÎñÆ÷ÍÆËã»úÉϵÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©£¬µ«ÀûÓÃÕâЩ·ì϶¿ÉÄܱØÒªÓ®µÃ¾ºÕùǰÌá¡£

2¸öΪMicrosoftÐÂÎŶÓÁÐÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-35349ºÍCVE-2023-36697£©£¬³É¹¦ÀûÓÃCVE-2023-35349¿ÉÄܵ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄÍþвÕßÔÚÖ¸±ê·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë¡£³É¹¦ÀûÓÃCVE-2023-36697¿ÉÄܵ¼Ö¾­¹ýÉí·ÝÑéÖ¤µÄÓòÓû§ÔÚÖ¸±ê·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂ룬µ«ÍþвÕß±ØÒªÓÕµ¼Ö¸±êÍÆËã»úÉϵÄÓû§Ïνӵ½¶ñÒâ·þÎñÆ÷£¬»òÕß·ÛËéºÏ·¨µÄMSMQ·þÎñÆ÷Ö÷»ú£¬Ê¹Æä×÷Ϊ¶ñÒâ·þÎñÆ÷ÔËÐС£Windows ÐÂÎŶÓÁзþÎñÊÇ Windows ×é¼þ£¬Äܹ»Í¨¹ý²é³­ÊÇ·ñÓÐÃûΪMessage QueuingµÄ·þÎñÔÚÔËÐУ¬ÒÔ¼°ÍÆËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£

ÒÔ¼°MicrosoftÐé¹¹¿ÉÐÅÆ½Ì¨Ä£¿é£¨TPM£©Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-36718£©£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐУ¬µ«ÍþвÕß±ØÐëͨ¹ýguestģʽÓû§µÄÉí·ÝÑéÖ¤ÄÜÁ¦ÌÓÀëÐé¹¹»ú¡£

΢Èí10Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º

CVE ID

CVE ±êÌâ

ÑϳÁÐÔ

CVE-2023-41770

Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-41765

Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-41767

Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-38166

Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-41774

Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-41773

Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-41771

Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-41769

Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-41768

Layer 2 Tunneling Protocol Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-35349

Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-36697

Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-36718

Microsoft Virtual Trusted Platform   Module Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2023-36722

Active DirectoryÓò·þÎñÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36737

Azure Network Watcher VM Agent ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36419

Azure HDInsight Apache Oozie ¹¤×÷Á÷µ÷¶È·¨Ê½ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36561

Azure DevOps ·þÎñÆ÷ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36418

Azure RTOS GUIX Studio Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36414

Azure Identity SDK Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36415

Azure Identity SDK Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-41766

Windows ¿Í»§¶Ë·þÎñÆ÷ÔËÐÐʱ×Óϵͳ (CSRSS) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-44487

MITRE£ºCVE-2023-44487 HTTP/2 ¼±¾ç³ÁÖù¥»÷

¸ßΣ

CVE-2023-36566

Microsoft ͨÓÃÊý¾ÝÄ£ÐÍ SDK »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36429

Microsoft Dynamics 365£¨On-Premises£©ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36416

Microsoft Dynamics 365£¨On-Premises£©¿çÕ¾¾ç±¾·ì϶

¸ßΣ

CVE-2023-36433

Microsoft Dynamics 365£¨On-Premises£©ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36778

Microsoft Exchange Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36594

Windows Graphics Component ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-38159

Windows Graphics Component ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36565

Microsoft Office Graphics ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36569

Microsoft Office ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36568

Microsoft Office Click-To-Run ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-38171

Microsoft QUIC »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36435

Microsoft QUIC »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36577

Microsoft WDAC OLE DB provider for   SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36710

Windows Media Foundation Core Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36564

Windows Search °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2023-36563

Microsoft WordPad ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36786

Skype for Business Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36780

Skype for Business Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36789

Skype for Business Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-41763

Skype for Business ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36728

Microsoft SQL Server »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36417

Microsoft SQL ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36785

Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36598

Microsoft WDAC ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36730

Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36420

Microsoft ODBC Driver for SQL Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36585

Active Template Library »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36709

Microsoft AllJoyn API »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36902

Windows Runtime Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36713

Windows Common Log File System Driver   ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36723

Windows Container Manager Service ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36707

Windows Deployment ·þÎñ»Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36567

Windows Deployment ·þÎñÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36706

Windows Deployment ·þÎñÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36703

DHCP Server Service »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36721

Windows ÃýÎó»ã±¨·þÎñÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36436

Windows MSHTMLƽ̨Զ³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36557

PrintHTML API Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36434

Windows IIS ·þÎñÆ÷ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36726

Windows Internet ÃÜÔ¿»¥»» (IKE) À©´óÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36576

Windows ÄÚºËÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36712

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36698

Windows Äں˰²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2023-36584

Windows Mark of the Web °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2023-36571

Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36570

Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36431

Microsoft Message Queuing »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36591

Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36590

Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36589

Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36583

Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36592

Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36606

Microsoft Message Queuing »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36593

Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36582

Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36574

Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36575

Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36573

Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36572

Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36581

Microsoft Message Queuing »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36579

Microsoft Message Queuing »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36578

Microsoft Message Queuing Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36702

Microsoft DirectMusic Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36720

Windows Mixed Reality Developer Tools   »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36729

Named Pipe File System ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36605

Windows Named Pipe Filesystem ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36725

Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36724

Windows µçÔ´ÖÎÀí·þÎñÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36790

Windows RDP Encoder Mirror Driver ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-29348

Windows Remote Desktop Gateway (RD   Gateway)ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36596

Remote Procedure Call ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36701

Microsoft µ¯ÐÔÎļþϵͳ (ReFS) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36711

Windows Runtime C++ Template Library ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36704

Windows Setup Files Cleanup Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2023-36438

Windows TCP/IP ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-36603

Windows TCP/IP »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36602

Windows TCP/IP »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36717

Windows Virtual Trusted Platform   Module »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2023-36731

Win32k ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36732

Win32k ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36776

Win32k ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-36743

Win32k ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-41772

Win32k ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2023-5346

Chromium£ºCVE-2023-5346 V8 ÖеÄÀàÐÍ»ìºÏ

δ֪

 

¶þ¡¢Ó°ÏìÁìÓò

ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º

Windows RDP

Windows Message Queuing

Azure SDK

Microsoft Dynamics

SQL Server

Azure Real Time Operating System

Azure

Windows IIS

Microsoft QUIC

Windows HTML Platform

Windows TCP/IP

Azure DevOps

Microsoft WordPad

Microsoft Windows Search Component

Microsoft Office

Microsoft Common Data Model SDK

Windows Deployment Services

Windows Kernel

Microsoft WDAC OLE DB provider for SQL

Windows Mark of the Web (MOTW)

Windows Active Template Library

Microsoft Graphics Component

Windows Remote Procedure Call

Windows Named Pipe File System

Windows Resilient File System (ReFS)

Windows Microsoft DirectMusic

Windows DHCP Server

Windows Setup Files Cleanup

Windows AllJoyn API

Microsoft Windows Media Foundation

Windows Runtime C++ Template Library

Windows Common Log File System Driver

Windows TPM

Windows Virtual Trusted Platform Module

Windows Mixed Reality Developer Tools

Windows Error Reporting

Active Directory Domain Services

Windows Container Manager Service

Windows Power Management Service

Windows NT OS Kernel

Windows IKE Extension

Windows Win32K

Microsoft Exchange Server

Skype for Business

Windows Client/Server Runtime Subsystem

Windows Layer 2 Tunneling Protocol

Client Server Run-time Subsystem (CSRSS)

 

Èý¡¢°²È«´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

2023Äê10Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2023-oct

²¹¶¡ÏÂÔØÊ¾Àý£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

image.png

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2022Äê2Ô£©

2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£

3.2 һʱ´ëÊ©

¹ØÓÚHTTP/2 ¼±¾ç³ÁÖù¥»÷£¨CVE-2023-44487£©·ì϶£¬Î¢ÈíµÄ»º½â´ëÊ©¿É²Î¿¼£º

https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/

Cloudflare¡¢Google¡¢AWS¡¢NGINXµÈÕë¶Ô¸Ã·ì϶µÄ»º½âºÍÏìÓ¦¿É²Î¿¼£º

https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2023-oct

https://www.bleepingcomputer.com/news/microsoft/microsoft-october-2023-patch-tuesday-fixes-3-zero-days-104-flaws/

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-10-11

³õ´Î°ä²¼

 

Îå¡¢¸½Â¼

5.1 GA»Æ½ð¼×¼ò½é

GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£

5.2 ¹ØÓÚGA»Æ½ð¼×

GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png