¡¾·ì϶¹«¸æ¡¿Î¢Èí1Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2024-01-10Ò»¡¢·ì϶¸ÅÊö
2024Äê1ÔÂ9ÈÕ£¬Î¢Èí°ä²¼ÁË1Ô°²È«¸üУ¬±¾´Î¸üй²½¨¸´ÁË49¸ö·ì϶£¨²»Ô̺¬1ÔÂ5ÈÕ½¨¸´µÄ4¸öMicrosoft Edge·ì϶£©£¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶ºÍºýŪ·ì϶µÈ¡£
±¾´Î°²È«¸üÐÂÖÐûÓб»»ý¼«ÀûÓûò¹«¿ªÅû¶µÄ·ì϶£¬ÆäÖÐÆÀ¼¶ÎªÑϳÁµÄ2¸ö·ì϶Ô̺¬£º
CVE-2024-20674£ºWindows Kerberos °²È«Ö°ÄÜÈÆ¹ý·ì϶£¨ÑϳÁ£©
¶ÔÊÜÏÞÍøÂçÕ¼ÓнӼûȨÏÞµÄÍþвÕß¿Éͨ¹ý³ÉÁ¢machine-in-the-middle (MITM£¬ÖÐÑë»ú)¹¥»÷»òÆäËü±¾µØÍøÂçºýŪ¼¼ÊõÀ´ÀûÓø÷ì϶£¬¶øºóÏò¿Í»§¶ËÊܺ¦»úе·¢ËͶñÒâKerberos ÐÂÎÅÒÔ¼ÙÒâKerberosÉí·ÝÑéÖ¤·þÎñÆ÷£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂÈÆ¹ýÉí·ÝÑéÖ¤Ö°ÄÜ¡£¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.0£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϴ󡱡£
CVE-2024-20700£ºWindows Hyper-V Ô¶³Ì´úÂëÖ´Ðзì϶£¨¸ßΣ£©
¸Ã·ì϶µÄ¹¥»÷¸´ÔӶȽϸߣ¬³É¹¦ÀûÓø÷ì϶±ØÒªÓ®µÃ¾ºÕùǰÌᣬÇÒ±ØÒª»ñµÃ¶ÔÊÜÏÞÍøÂçµÄ½Ó¼ûȨÏÞ£¬ÆäCVSSÆÀ·ÖΪ7.5£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס±¡£
ÆäËüÖµµÃ¹Ø×¢µÄ·ì϶»¹Ô̺¬µ«²»ÏÞÓÚ£º
CVE-2024-21307£ºRemote Desktop ClientÔ¶³Ì´úÂëÖ´Ðзì϶£¨¸ßΣ£©
¸Ã·ì϶µÄ¹¥»÷¸´ÔӶȽϸߣ¬³É¹¦ÀûÓô˸ö´±ØÒªÓ®µÃ¾ºÕùǰÌᣬÇÒ±ØÒªÓû§½»»¥£¬Î´ÊÚȨÍþвÕß±ØÐëÆÚ´ýÓû§Æô¶¯Ïνӡ£¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.5£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϴ󡱡£
CVE-2024-21318£ºMicrosoft SharePoint ServerÔ¶³Ì´úÂëÖ´Ðзì϶£¨¸ßΣ£©
¾¹ýÉí·ÝÑéÖ¤µÄÍþвÕߣ¨ÖÁÉÙÊÇÍøÕ¾ËùÓÐÕߣ©¿ÉÀûÓø÷ì϶עÈëËÁÒâ´úÂ룬²¢ÔÚ SharePoint Server µÄ¸ßµÍÎÄÖÐÖ´ÐиôúÂë¡£¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϴ󡱡£
³ýCVE-2024-20674¡¢CVE-2024-21307ºÍCVE-2024-21318±í£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÓ×°±»ÀûÓõĿÉÄÜÐԽϴ󡱵ķì϶»¹Ô̺¬£º
CVE-2024-20652£ºWindows HTMLƽ̨°²È«Ö°ÄÜÈÆ¹ý·ì϶£¨¸ßΣ£©
CVE-2024-20653£ºMicrosoft Common Log File SystemÌØÈ¨ÌáÉý·ì϶£¨¸ßΣ£©
CVE-2024-20683£ºWin32k ÌØÈ¨ÌáÉý·ì϶£¨¸ßΣ£©
CVE-2024-20686£ºWin32k ÌØÈ¨ÌáÉý·ì϶£¨¸ßΣ£©
CVE-2024-20698£ºWindows ÄÚºËÌØÈ¨ÌáÉý·ì϶£¨¸ßΣ£©
CVE-2024-21310£ºWindows Cloud Files Mini Filter DriverÌØÈ¨ÌáÉý·ì϶£¨¸ßΣ£©
΢Èí1Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑϳÁÐÔ |
CVE-2024-20674 | Windows Kerberos °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ÑϳÁ |
CVE-2024-20700 | Windows Hyper-V Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2024-0057 | NET¡¢.NET Framework ºÍ Visual Studio °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-20672 | .NET Core ºÍ Visual Studio »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-21312 | .NET Framework »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-20676 | Azure Storage Mover Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21306 | Microsoft Bluetooth Driver ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-21325 | Microsoft Printer Metadata Troubleshooter Tool Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21319 | Microsoft Identity »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-20677 | Microsoft Office Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21318 | Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-20658 | Microsoft Virtual Hard Disk ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21307 | Remote Desktop Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-0056 | Microsoft.Data.SqlClient ºÍ System.Data.SqlClient SQLÊý¾ÝÌṩ·¨Ê½°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2022-35737 | MITRE£ºCVE-2022-35737 SQLite ÔÊÐíÊý×éÌìǵÒç³ö | ¸ßΣ |
CVE-2024-21305 | Hypervisor-Protected Code Integrity (HVCI) °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-20656 | Visual Studio ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-20687 | Microsoft AllJoyn API »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-20666 | BitLocker °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-21310 | Windows Cloud Files Mini Filter Driver ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-20694 | Windows CoreMessaging ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-20653 | Microsoft Common Log File System ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-20682 | Windows Cryptographic Services Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-21311 | Windows Cryptographic Services ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-20657 | Windows Group Policy ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-20699 | Windows Hyper-V »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-20698 | Windows Kernel ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21309 | Windows Kernel-Mode Driver ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-20697 | Windows Libarchive Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-20696 | Windows Libarchive Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-20692 | Microsoft Local Security Authority Subsystem Service ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-20660 | Microsoft Message Queuing ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-20664 | Microsoft Message Queuing ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-20680 | Windows Message Queuing Client (MSMQC) ÐÅϢй¶ | ¸ßΣ |
CVE-2024-20663 | Windows Message Queuing Client (MSMQC) ÐÅϢй¶ | ¸ßΣ |
CVE-2024-21314 | Microsoft Message Queuing ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-20661 | Microsoft Message Queuing »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-20690 | Windows Nearby Sharing ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-20654 | Microsoft ODBC Driver Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-20662 | Windows Online Certificate Status Protocol (OCSP) ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-20655 | Microsoft Online Certificate Status Protocol (OCSP) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-20652 | Windows HTML Platforms °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-21316 | Windows Server Key Distribution °²È«Ö°ÄÜÈÆ¹ý | ¸ßΣ |
CVE-2024-20681 | Windows Subsystem for Linux ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21313 | Windows TCP/IP ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-20691 | Windows Themes ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-21320 | Windows Themes ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-20686 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-20683 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-0222 | Chromium£ºCVE-2024-0222 ÔÚ ANGLE ÖпªÊͺóʹÓà | δ֪ |
CVE-2024-0223 | Chromium£ºCVE-2024-0223 ANGLE ¶Ñ»º³åÇøÒç³ö | δ֪ |
CVE-2024-0224 | Chromium£ºCVE-2024-0224 ÔÚ WebAudio ÖпªÊͺóʹÓà | δ֪ |
CVE-2024-0225 | Chromium£ºCVE-2024-0225 ÔÚ WebGPU ÖпªÊͺóʹÓà | δ֪ |
¶þ¡¢Ó°ÏìÁìÓò
ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º
SQL Server
.NET and Visual Studio
Windows Scripting
Windows Common Log File System Driver
Windows ODBC Driver
Windows Online Certificate Status Protocol (OCSP) SnapIn
Visual Studio
Windows Group Policy
Microsoft Virtual Hard Drive
Windows Message Queuing
Windows BitLocker
.NET Core & Visual Studio
Windows Authentication Methods
Azure Storage Mover
Microsoft Office
Windows Subsystem for Linux
Windows Cryptographic Services
Windows Win32K
Windows Win32 Kernel Subsystem
Windows AllJoyn API
Windows Nearby Sharing
Windows Themes
Windows Local Security Authority Subsystem Service (LSASS)
Windows Collaborative Translation Framework
Windows Libarchive
Windows Kernel
Windows Hyper-V
Unified Extensible Firmware Interface
Microsoft Bluetooth Driver
Remote Desktop Client
Windows Kernel-Mode Drivers
Windows Cloud Files Mini Filter Driver
.NET Framework
Windows TCP/IP
Windows Server Key Distribution Service
Microsoft Office SharePoint
Microsoft Identity Services
Microsoft Devices
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2024Äê1Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2024-Jan
²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2022Äê2Ô£©
2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Jan
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-20674
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-01-10 | ³õ´Î°ä²¼ |
Îå¡¢¸½Â¼
5.1 GA»Æ½ð¼×¼ò½é
GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£
5.2 ¹ØÓÚGA»Æ½ð¼×
GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ