¡¾·ì϶¹«¸æ¡¿Î¢Èí12Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2023-12-13Ò»¡¢·ì϶¸ÅÊö
2023Äê12ÔÂ12ÈÕ£¬Î¢Èí°ä²¼ÁË12Ô°²È«¸üУ¬±¾´Î¸üй²½¨¸´ÁË36¸ö·ì϶£¨²»Ô̺¬12ÔÂ7ÈÕ½¨¸´µÄ8¸öMicrosoft Edge·ì϶£©£¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶ºÍºýŪ·ì϶µÈ¡£
±¾´Î°²È«¸üн¨¸´ÁË1¸öÒÑÓÚ8ÔÂÅû¶µ«Ö®Ç°ÉÐ佨¸´µÄAMD 0 day·ì϶£º
CVE-2023-20588- AMD£ºAMD´§Ä¦ÐÔй¶·ì϶£¨ÖÐΣ£©
ijЩ AMD ´¦ÖÃÆ÷ÉÏ´æÔÚ³ýÁãÃýÎ󣬿ÉÄܵ¼Ö·µ»Ø´§Ä¦Êý¾Ý£¬Ôì³ÉÐÅϢй¶¡£
ÆÀ¼¶ÎªÑϳÁµÄ4¸ö·ì϶Ô̺¬£º
CVE-2023-36019£ºMicrosoft Power Platform ConnectorºýŪ·ì϶£¨ÑϳÁ£©
¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.6£¬¿Éͨ¹ýÓÕµ¼Óû§µ¥»÷ÌØÔìµÄ URLÀ´ÀûÓø÷ì϶£¬¿ÉÄܵ¼Ö¶ñÒâ¾ç±¾ÔÚÊܺ¦ÕßÍÆËã»úÉϵÄä¯ÀÀÆ÷ÖÐÖ´ÐС£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס±¡£
CVE-2023-35630£ºInternet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´Ðзì϶£¨¸ßΣ£©
¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8£¬³É¹¦ÀûÓø÷ì϶±ØÒªÅú¸ÄDHCPv6 DHCPv6_MESSAGE_INFORMATION_REQUESTÊäÈëÐÂÎÅÖеÄoption->length×ֶΡ£¸Ã·ì϶²»ÄÜ¿ç¶à¸öÍøÂ磨ÈçWAN£©ÀûÓã¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס±¡£
CVE-2023-35641£ºInternet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´Ðзì϶£¨¸ßΣ£©
¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8£¬¿Éͨ¹ýÏòÔËÐÐ Internet Ïνӹ²Ïí·þÎñµÄ·þÎñÆ÷·¢ËͶñÒâÔì×÷µÄ DHCP ÐÂÎÅÀ´ÀûÓø÷ì϶¡£¸Ã·ì϶²»ÄÜ¿ç¶à¸öÍøÂ磨ÈçWAN£©ÀûÓã¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϴ󡱡£
CVE-2023-35628£ºWindows MSHTML PlatformÔ¶³Ì´úÂëÖ´Ðзì϶£¨¸ßΣ£©
¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.1£¬Äܹ»ÔÚÎÞÐèÓû§½»»¥µÄÇé¿öÏÂÔ¶³ÌÀûÓ㬵«¹¥»÷¸´ÔӶȽϸߡ£ÍþвÕß¿Éͨ¹ýµç×ÓÓʼþ»òÆäËû·½Ê½ÏòÊܺ¦Õß·¢ËͶñÒâÁ´½Ó²¢ÓÕµ¼Óû§µ¥»÷¶ñÒâÁ´½ÓÀ´ÀûÓø÷ì϶£»»òÕßÄܹ»Í¨¹ý·¢ËÍÌØÔìµç×ÓÓʼþÀ´ÀûÓø÷ì϶£¬¸Ãµç×ÓÓʼþ¿ÉÄÜ»áÔÚOutlook ¿Í»§¶Ë¼ìË÷ºÍ´¦ÖÃʱ×Ô¶¯´¥·¢£¬¶øÎÞÐèÊܺ¦Õß´ò¿ª¡¢ÔĶÁ»òµ¥»÷Á´½Ó£¬Õâ¿ÉÄܻᵼÖÂÔÚÔ¤ÀÀ´°¸ñÖв鿴µç×ÓÓʼþ֮ǰ±»ÀûÓᣳɹ¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂÔÚÊܺ¦ÕßµÄÍÆËã»úÉÏÔ¶³ÌÖ´ÐдúÂ롣΢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϴ󡱡£
³ýÁËCVE-2023-35641ºÍCVE-2023-35628±í£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÓ×°±»ÀûÓõĿÉÄÜÐԽϴ󡱵ķì϶»¹Ô̺¬£º
CVE-2023-35631£ºWin32k ÌØÈ¨ÌáÉý·ì϶
CVE-2023-35632£ºWindows Ancillary Function Driver for WinSockÌØÈ¨ÌáÉý·ì϶
CVE-2023-35633£ºWindows KernelÌØÈ¨ÌáÉý·ì϶
CVE-2023-35644£ºWindows Sysmain ServiceÌØÈ¨ÌáÉý·ì϶
CVE-2023-36005£ºWindows Telephony Server ÌØÈ¨ÌáÉý·ì϶
CVE-2023-36010£ºMicrosoft Defender»Ø¾ø·þÎñ·ì϶
CVE-2023-36011£ºWin32k ÌØÈ¨ÌáÉý·ì϶
CVE-2023-36391£ºLocal Security Authority Subsystem ServiceȨÌáÉý·ì϶
CVE-2023-36696£ºWindows Cloud Files Mini Filter DriverÌØÈ¨ÌáÉý·ì϶
΢Èí12Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑϳÁÐÔ |
CVE-2023-36019 | Microsoft Power Platform Connector ºýŪ·ì϶ | ÑϳÁ |
CVE-2023-35630 | Internet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-35641 | Internet Connection Sharing (ICS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-35628 | Windows MSHTML Platform Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2023-35624 | Azure Connected Machine Agent ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-35625 | Azure Machine Learning Compute Instance for SDK Óû§ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-20588 | AMD£ºCVE-2023-20588 AMD ´§Ä¦ÐÔй¶°²È«Í¨Öª | ¸ßΣ |
CVE-2023-35634 | Windows Bluetooth Driver Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-35621 | Microsoft Dynamics 365 Finance and Operations »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36020 | Microsoft Dynamics 365 (on-premises) ¿çÕ¾µã¾ç±¾·ì϶ | ¸ßΣ |
CVE-2023-35636 | Microsoft Outlook ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-35619 | Microsoft Outlook for Mac ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-36009 | Microsoft Word ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36006 | Microsoft WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-35622 | Windows DNS ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-36696 | Windows Cloud Files Mini Filter Driver ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36010 | Microsoft Defender »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-35643 | DHCP Server Service ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-35638 | DHCP Server Service »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-36012 | DHCP Server Service ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2023-36004 | Windows DPAPI£¨Êý¾Ý±£»¤ÀûÓ÷¨Ê½±à³Ì½Ó¿Ú£©ºýŪ·ì϶ | ¸ßΣ |
CVE-2023-35642 | Internet Connection Sharing (ICS) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-35632 | Windows Ancillary Function Driver for WinSock ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-35633 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-35635 | Windows Äں˻ؾø·þÎñ·ì϶ | ¸ßΣ |
CVE-2023-35644 | Windows Sysmain Service ȨÏÞÌáÉý | ¸ßΣ |
CVE-2023-36391 | Local Security Authority Subsystem Service ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-21740 | Windows Media Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-35639 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36005 | Windows Telephony Server ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-35629 | Microsoft USBHUB 3.0 Device Driver Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2023-36011 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-35631 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-36003 | XAML Diagnostics ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2023-35618 | Microsoft Edge£¨»ùÓÚ Chromium£©È¨ÏÞÌáÉý·ì϶ | ÖÐΣ |
CVE-2023-36880 | Microsoft Edge£¨»ùÓÚChromium£©ÐÅϢй¶·ì϶ | µÍΣ |
CVE-2023-38174 | Microsoft Edge£¨»ùÓÚChromium£©ÐÅϢй¶·ì϶ | µÍΣ |
CVE-2023-6509 | Chromium£ºCVE-2023-6509 ÔÚSide Panel SearchÖÐUse-after-free | δ֪ |
CVE-2023-6512 | Chromium£ºCVE-2023-6512 Web ä¯ÀÀÆ÷ UI ÖеÄÖ´Ðв»µ± | δ֪ |
CVE-2023-6508 | Chromium£ºCVE-2023-6508 ÔÚMedia StreamÖÐUse-after-free | δ֪ |
CVE-2023-6511 | Chromium£ºCVE-2023-6511 ×Ô¶¯Ìî³äÖеÄÖ´Ðв»µ± | δ֪ |
CVE-2023-6510 | Chromium£ºCVE-2023-6510 ÔÚMedia CaptureÖÐUse-after-free | δ֪ |
¶þ¡¢Ó°ÏìÁìÓò
ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º
Windows Media
Microsoft Edge (Chromium-based)
Microsoft Office Outlook
Microsoft Dynamics
Microsoft Windows DNS
Azure Connected Machine Agent
Azure Machine Learning
Windows MSHTML Platform
Windows USB Mass Storage Class Driver
Windows Internet Connection Sharing (ICS)
Windows Win32K
Windows Kernel
Microsoft Bluetooth Driver
Windows DHCP Server
Windows ODBC Driver
Windows Kernel-Mode Drivers
XAML Diagnostics
Windows DPAPI (Data Protection Application Programming Interface)
Windows Telephony Server
Microsoft WDAC OLE DB provider for SQL
Microsoft Office Word
Windows Defender
Microsoft Power Platform Connector
Windows Local Security Authority Subsystem Service (LSASS)
Windows Cloud Files Mini Filter Driver
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2023Äê12Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2023-Dec
²¹¶¡ÏÂÔØÊ¾Àý£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2022Äê2Ô£©
2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2023-Dec
https://www.bleepingcomputer.com/news/microsoft/microsoft-december-2023-patch-tuesday-fixes-34-flaws-1-zero-day/
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7007.html
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-12-13 | ³õ´Î°ä²¼ |
Îå¡¢¸½Â¼
5.1 GA»Æ½ð¼×¼ò½é
GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£
5.2 ¹ØÓÚGA»Æ½ð¼×
GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ