¡¾·ì϶¹«¸æ¡¿Î¢Èí2Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2024-02-19


Ò»¡¢·ì϶¸ÅÊö

2024Äê2ÔÂ13ÈÕ£¬Î¢Èí°ä²¼ÁË2Ô°²È«¸üУ¬±¾´Î¸üй²½¨¸´ÁË73¸ö·ì϶£¨²»Ô̺¬2ÔÂ8ÈÕ½¨¸´µÄMicrosoft EdgeºÍÆäËü·ì϶£©£¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶ºÍºýŪ·ì϶µÈ ¡£

±¾´Î°²È«¸üÐÂÖÐÔ̺¬2¸ö±»»ý¼«ÀûÓõÄ0 day·ì϶£º

CVE-2024-21351£ºWindows SmartScreen °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.6£¬ÍþвÕß¿ÉÏòÓû§·¢ËͶñÒâÎļþ²¢ÓÕµ¼Óû§´ò¿ªÎļþÀ´ÀûÓø÷ì϶£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÈÆ¹ý SmartScreen°²È«Ö°ÄÜ ¡£¸Ã·ì϶ÔÊÐíÍþвÕß½«´úÂë×¢Èë SmartScreen ²¢¿ÉÄÜ»ñµÃ´úÂëÖ´ÐÐȨÏÞ£¬´Ó¶ø¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢ÏµÍ³¿ÉÓÃÐÔÓ°Ï죬Ŀǰ¸Ã·ì϶ÒѼì²âµ½·ì϶ÀûÓà ¡£

CVE-2024-21412£ºInternet ¿ì½Ý·½Ê½Îļþ°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.1£¬Î´¾­Éí·ÝÑéÖ¤µÄÍþвÕßÄܹ»ÏòÖ¸±êÓû§·¢ËÍÖ¼ÔÚÈÆ¹ýÏÔʾµÄ°²È«²é³­µÄÌØÔìÎļþ²¢ÓÕµ¼Óû§´ò¿ª¸ÃÎļþ£¬µ¼Ö°²È«Ö°ÄÜÈÆ¹ý ¡£ÒÑ·¢ÏÖAPT×éÖ¯Water Hydra£¨±ðÃû DarkCasino£©ÔÚÕë¶Ô½ðÈÚÂòÂôÕߵĻÖлý¼«ÀûÓø÷ì϶ ¡£

±¾´Î°²È«¸üÐÂÖУ¬ÆÀ¼¶Îª¡°ÑϳÁ¡±µÄ5¸ö·ì϶Ô̺¬£º

CVE-2024-21380£ºMicrosoft Dynamics Business Central/NAV ÐÅϢй¶·ì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.0£¬³É¹¦ÀûÓø÷ì϶±ØÒª¾­¹ýÉí·ÝÑéÖ¤¡¢Ó®µÃ¾ºÕùǰÌᣬ²¢±ØÒªÓû§½»»¥£¬³É¹¦ÀûÓø÷ì϶µÄÍþвÕßÄܹ»½Ó¼ûÓû§Êý¾Ý£¬µ¼ÖÂδÊÚȨ½Ó¼ûÊܺ¦ÕßµÄÕË»§»òй¶ÆäËü»úÃÜÐÅÏ¢ ¡£

CVE-2024-21410£ºMicrosoft Exchange Server ȨÏÞÌáÉý·ì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8£¬³É¹¦ÀûÓø÷ì϶µÄÍþвÕßÄܹ»½«Óû§Ð¹Â¶µÄNet-NTLMv2¹þÏ£Öм̵½Ò×Êܹ¥»÷µÄExchange Server£¬²¢ÒÔÓû§Éí·Ý½øÐÐÉí·ÝÑéÖ¤ ¡£ÊÜÓ°ÏìÓû§Ò²¿É²Î¿¼¹Ù·½ÌṩµÄÎĵµºÍ¾ç±¾Îª Exchange ServerÆôÓÃÉí·ÝÑéÖ¤À©´ó±£»¤ (EPA)À´»º½â¸Ã·ì϶£¬Ä¿Ç°¸Ã·ì϶ÒѼì²âµ½·ì϶ÀûÓà ¡£

CVE-2024-21413£ºMicrosoft OutlookÔ¶³Ì´úÂëÖ´Ðзì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂÈÆ¹ý Office Êܱ£»¤µÄÊÓͼ²¢ÒÔ±à×ëģʽ¶ø²»ÊDZ£»¤Ä£Ê½´ò¿ª£¬Ô¤ÀÀ´°¸ñÊǸ÷ì϶µÄÒ»¸ö¹¥»÷ý½é ¡£ÍþвÕßÄܹ»´´½¨ÈƹýÊܱ£»¤ÊÓͼºÍ̸µÄ¶ñÒâÁ´½Ó£¬´Ó¶øµ¼Ö±¾µØNTLMÍ´´¦ÐÅϢй¶ºÍÔ¶³Ì´úÂëÖ´ÐÐ ¡£

CVE-2024-20684£ºWindows Hyper-V »Ø¾ø·þÎñ·ì϶

¸Ã·ì϶µÄCVSSÆÀ·ÖΪ6.5£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼Ö Hyper-V guestÓ°Ïì Hyper-V Ö÷»úµÄÖ°ÄÜ ¡£

CVE-2024-21357£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´Ðзì϶

Windows Pragmatic General Multicast (PGM) ²úÉúµÄ×é²¥Á÷Á¿ÔÚµÚ4 ²ãÔËÐв¢¿É·ÓÉ£¬ÍþвÕßÄܹ»Í¨¹ýÏòÒ×Êܹ¥»÷µÄ·þÎñÆ÷·¢ËÍÌØÔìµÄ¶ñÒâÁ÷Á¿À´ÀûÓø÷ì϶ ¡£¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.1£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ± ¡£

³ýCVE-2024-21410ºÍCVE-2024-21357ÒÔ±í£¬±¾´Î°²È«¸üÐÂÖУ¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÓ×°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ·ì϶»¹Ô̺¬£º

CVE-2024-21338£ºWindows ÄÚºËÌØÈ¨ÌáÉý·ì϶

CVE-2024-21345£ºWindows ÄÚºËÌØÈ¨ÌáÉý·ì϶

CVE-2024-21346£ºWin32k ÌØÈ¨ÌáÉý·ì϶

CVE-2024-21371£ºWindows ÄÚºËÌØÈ¨ÌáÉý·ì϶

CVE-2024-21378£ºMicrosoft OutlookÔ¶³Ì´úÂëÖ´Ðзì϶

CVE-2024-21379£ºMicrosoft WordÔ¶³Ì´úÂëÖ´Ðзì϶

΢Èí2Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º

CVE ID

CVE ±êÌâ

ÑϳÁÐÔ

CVE-2024-21380

Microsoft   Dynamics Business Central/NAV ÐÅϢй¶·ì϶

ÑϳÁ

CVE-2024-21410

Microsoft   Exchange Server ȨÏÞÌáÉý·ì϶

ÑϳÁ

CVE-2024-21413

Microsoft   Outlook Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-20684

Windows   Hyper-V »Ø¾ø·þÎñ·ì϶

ÑϳÁ

CVE-2024-21357

Windows   Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2024-21386

.NET »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-21404

.NET »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-21401

Microsoft   Entra Jira Single-Sign-On Plugin ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2024-21381

Microsoft   Azure Active Directory B2C ºýŪ·ì϶

¸ßΣ

CVE-2024-21329

Azure   Connected Machine Agent ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2024-20667

Azure   DevOps Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21397

Microsoft   Azure File SyncȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2024-20679

Azure   Stack Hub ºýŪ·ì϶

¸ßΣ

CVE-2024-21412

Internet ¿ì½Ý·½Ê½Îļþ°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-21349

Microsoft   ActiveX Êý¾Ý¶ÔÏóÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21403

Microsoft   Azure Kubernetes Service Confidential Container ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21376

Microsoft   Azure Kubernetes Service Confidential Container Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21315

Microsoft   Defender for Endpoint Protection ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2024-21393

Microsoft   Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾·ì϶

¸ßΣ

CVE-2024-21389

Microsoft   Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾·ì϶

¸ßΣ

CVE-2024-21395

Microsoft   Dynamics 365£¨on-premises£©¿çÕ¾¾ç±¾·ì϶

¸ßΣ

CVE-2024-21328

Dynamics   365 Sales ºýŪ·ì϶

¸ßΣ

CVE-2024-21394

Dynamics   365 Field Service ºýŪ·ì϶

¸ßΣ

CVE-2024-21396

Dynamics   365 Sales ºýŪ·ì϶

¸ßΣ

CVE-2024-21327

Microsoft   Dynamics 365 Customer Engagement ¿çÕ¾¾ç±¾·ì϶

¸ßΣ

CVE-2024-20673

Microsoft   Office Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21384

Microsoft   Office OneNote Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21378

Microsoft   Outlook Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21402

Microsoft   Outlook ȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2024-21379

Microsoft   Word Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21374

Microsoft   Teams for Android ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-21353

Microsoft   WDAC ODBC Driver Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21370

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21350

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21368

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21359

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21365

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21367

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21420

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21366

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21369

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21375

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21361

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21358

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21391

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21360

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21352

Microsoft   WDAC OLE DB provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21406

Windows   Printing Service ºýŪ·ì϶

¸ßΣ

CVE-2024-21377

Windows   DNS ÐÅϢй¶·ì϶

¸ßΣ

CVE-2023-50387

MITRE£ºCVE-2023-50387 DNSSEC ÑéÖ¤¸´ÔÓÐԿɱ»ÀûÓÃÀ´ºÄ¾¡ CPU ×ÊÔ´²¢ÖÕ³¡ DNS ½âÎöÆ÷

¸ßΣ

CVE-2024-21342

Windows   DNS Client »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-20695

Skype for   Business ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-21347

Microsoft   ODBC Driver Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21304

Trusted   Compute Base ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21343

Windows   Network Address Translation (NAT) »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-21348

Internet   Connection Sharing (ICS) »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-21344

Windows Network   Address Translation (NAT) »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-21371

Windows   Kernel ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21338

Windows   Kernel ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21341

Windows   Kernel Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21345

Windows   Kernel ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21362

Windows   Kernel °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2024-21340

Windows   Kernel ÐÅϢй¶·ì϶

¸ßΣ

CVE-2024-21356

Windows   Lightweight Directory Access Protocol (LDAP) »Ø¾ø·þÎñ·ì϶

¸ßΣ

CVE-2024-21363

Microsoft   Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21355

Microsoft   Message Queuing (MSMQ) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21405

Microsoft   Message Queuing (MSMQ) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21354

Microsoft   Message Queuing (MSMQ) ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21372

Windows   OLE Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21339

Windows   USB Generic Parent Driver Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2024-21346

Win32k ÌØÈ¨ÌáÉý·ì϶

¸ßΣ

CVE-2024-21364

Microsoft   Azure Site RecoveryÌØÈ¨ÌáÉý·ì϶

ÖÐΣ

CVE-2024-21399

Microsoft   Edge£¨»ùÓÚ Chromium£©Ô¶³Ì´úÂëÖ´Ðзì϶

ÖÐΣ

CVE-2024-21351

Windows   SmartScreen °²È«Ö°ÄÜÈÆ¹ý·ì϶

ÖÐΣ

CVE-2024-21626

runc ÎļþÃèÊö·ûй©

δ֪

CVE-2024-1284

Chromium£ºCVE-2024-1284 ÔÚ Mojo ÖпªÊͺóʹÓÃ

δ֪

CVE-2024-1060

Chromium£ºCVE-2024-1060 ÔÚ Canvas ÖпªÊͺóʹÓÃ

δ֪

CVE-2024-1077

Chromium£ºCVE-2024-1077 ÔÚ Network ÖпªÊͺóʹÓÃ

δ֪

CVE-2024-1283

Chromium£ºCVE-2024-1283 Skia ÖеĶѻº³åÇøÒç³ö

δ֪

CVE-2024-1059

Chromium£ºCVE-2024-1059 ÔÚ WebRTC ÖпªÊͺóʹÓÃ

δ֪

 

¶þ¡¢Ó°ÏìÁìÓò

ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º

Azure DevOps

Microsoft Office

Azure Stack

Windows Hyper-V

Skype for Business

Trusted Compute Base

Microsoft Defender for Endpoint

Microsoft Dynamics

Azure Connected Machine Agent

Windows Kernel

Windows USB Serial Driver

Role: DNS Server

Windows Internet Connection Sharing (ICS)

Windows Win32K - ICOMP

SQL Server

Microsoft ActiveX

Microsoft WDAC OLE DB provider for SQL

Windows SmartScreen

Microsoft WDAC ODBC Driver

Windows Message Queuing

Windows LDAP - Lightweight Directory Access Protocol

Azure Site Recovery

Windows OLE

Microsoft Teams for Android

Microsoft Azure Kubernetes Service

Microsoft Windows DNS

Microsoft Office Outlook

Microsoft Office Word

Azure Active Directory

Microsoft Office OneNote

.NET

Azure File Sync

Microsoft Edge (Chromium-based)

Microsoft Windows

Microsoft Exchange Server

Internet Shortcut Files

 

Èý¡¢°²È«´ëÊ©

3.1 Éý¼¶°æ±¾

Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´ ¡£

£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öà ¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüР¡£

4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üР¡£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öà ¡£

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüР¡£

2024Äê2Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Feb

²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º

1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó ¡£

image.png

Àý1£ºÎ¢Èí·ì϶ÁаµÊ¾Àý£¨2022Äê2Ô£©

2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó ¡£

image.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý

3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öà ¡£

image.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ

4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú ¡£

3.2 һʱ´ëÊ©

Õë¶ÔCVE-2024-21410£¬ÔÚ Exchange Server 2019 ÀÛ»ý¸üÐÂ14 (CU14) ¸üÐÂ֮ǰ£¬Exchange Server ĬÈÏÇé¿öϲ»ÆôÓà NTLM Í´´¦Öм̱£»¤£¨³ÆÎªÉí·ÝÑéÖ¤À©´ó±£»¤»ò EPA£©£¬Exchange Server 2019 CU14 ĬÈÏÔÚ Exchange ServerÉÏÆôÓà EPA£¬Microsoft ½¨ÒéÔÚ Exchange Server 2019 ÉÏ×°Öà CU14 £¬»ò²ÎÔÄExchange À©´ó±£»¤Îĵµ²¢Ê¹ÓÃExchangeExtendedProtectionManagement.ps1¾ç±¾Îª Exchange ServerÆôÓÃÉí·ÝÑéÖ¤À©´ó±£»¤ (EPA)À´»º½â¸Ã·ì϶ ¡£

¸ü¶à·ì϶ÏêÇé¼°»º½â´ëÊ©¿É²Î¿¼¹Ù·½²¼¸æ£º

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-21410

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ ¡£

l  ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È ¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä ¡£

3.4 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2024-Feb

https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2024-patch-tuesday-fixes-2-zero-days-73-flaws/

 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-02-19

³õ´Î°ä²¼

 

 

Îå¡¢¸½Â¼

5.1 GA»Æ½ð¼×¼ò½é

GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò» ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË ¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊÐ ¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦ ¡£

5.2 ¹ØÓÚGA»Æ½ð¼×

GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½ ¡£

¹Ø×¢ÎÒÃÇ£º

image.png