¡¾·ì϶¹«¸æ¡¿Î¢Èí4Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2024-04-10Ò»¡¢·ì϶¸ÅÊö
2024Äê4ÔÂ9ÈÕ£¬Î¢Èí°ä²¼ÁË4Ô°²È«¸üУ¬±¾´Î¸üй²½¨¸´ÁË150¸ö·ì϶£¨²»Ô̺¬Ö®Ç°½¨¸´µÄMicrosoft Edge ºÍMariner·ì϶£©£¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶ºÍºýŪ·ì϶µÈ¡£
±¾´Î°²È«¸üÐÂÖÐÔ̺¬2¸ö±»»ý¼«ÀûÓõÄ0 day·ì϶£º
CVE-2024-26234£ºProxy DriverºýŪ·ì϶
¸Ã·ì϶µÄCVSSÆÀ·ÖΪ6.7£¬ÓëSophos X-Ops ·¢ÏÖµÄÓÐЧMicrosoftÓ²¼þ¿¯ÐÐÉÌÖ¤ÊéÊðÃûµÄ¶ñÒâÇý¶¯·¨Ê½»î¶¯Óйأ¬¸ÃÇý¶¯·¨Ê½±»ÓÃÀ´²¿Êð¶ñÒâºóÃÅ£¬Ä¿Ç°¸Ã·ì϶ÒÑ·¢ÏÖ±»ÀûÓò¢Òѹ«¿ªÅû¶¡£
CVE-2024-29988£ºSmartScreen Prompt°²È«Ö°ÄÜÈÆ¹ý·ì϶
¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8£¬ÍþвÕßÄܹ»ÏòÖ¸±êÓû§·¢ËÍÌØÔìÎļþ£¬²¢ÓÕµ¼Óû§Ê¹ÓÃÒªÇó²»ÏÔʾUI µÄÆô¶¯Æ÷ÀûÓ÷¨Ê½À´Æô¶¯¶ñÒâÎļþ£¬¿ÉÄÜÔÚÎļþ´ò¿ªÊ±ÈƹýMicrosoft Defender Smartscreen ÌáÐÑ£¬ÔÚÖ¸±êϵͳÉÏÖ´ÐжñÒâ´úÂ롣Ŀǰ΢Èí¹Ù·½²¢Î´½«¸Ã·ì϶ÏóÕ÷ΪÒѱ»ÀûÓ㬵«¸Ã·ì϶¿ÉÄÜ´æÔÚÔÚÒ°ÀûÓá£
±¾´Î°²È«¸üÐÂÖÐÆÀ¼¶ÎªÑϳÁµÄ3¸ö·ì϶Ô̺¬£º
CVE-2024-29053£ºMicrosoft Defender for IoT Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft Defender for IoTÖдæÔÚõè¾¶±éÀú·ì϶£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8£¬ÓÐȨ½Ó¼ûÎļþÉÏ´«Ö°Äܵľ¹ýÉí·ÝÑéÖ¤µÄÍþвÕßÄܹ»Í¨¹ý½«¶ñÒâÎļþÉÏ´«µ½·þÎñÆ÷ÉϵÄÃô¸ÐµØÎ»À´ÀûÓøÃõè¾¶±éÀú·ì϶£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
CVE-2024-21323£ºMicrosoft Defender for IoT Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft Defender for IoTÖдæÔÚõè¾¶±éÀú·ì϶£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8£¬¾¹ýÉí·ÝÑéÖ¤²¢»ñµÃÆô¶¯¸üйý³ÌËùÐèµÄȨÏÞµÄÍþвÕß¿ÉÏòDefender for IoT ´«¸ÐÆ÷·¢ËÍ tar ÎļþÀ´ÀûÓø÷ì϶¡£ÌáÈ¡¹ý³ÌʵÏÖºó£¬ÍþвÕß¾ÍÄܹ»·¢ËÍδÊðÃûµÄ¸üаü£¬²¢¸²¸ÇËûÃÇÑ¡ÔñµÄÈκÎÎļþ¡£
CVE-2024-21322£ºMicrosoft Defender for IoT Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft Defender for IoTÖдæÔÚºÅÁî×¢Èë·ì϶£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.2£¬ÓµÓÐWeb ÀûÓ÷¨Ê½µÄÖÎÀíȨÏÞµÄÍþвÕß¿ÉÀûÓø÷ì϶µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
³ýCVE-2024-29988±í£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ·ì϶»¹Ô̺¬£º
l CVE-2024-26209£ºMicrosoft ±¾µØ°²È«»ú¹¹×Óϵͳ·þÎñÖдæÔÚÐÅϢй¶·ì϶£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂй¶δ³õʼ»¯µÄÄÚ´æ¡£
l CVE-2024-26218£ºWindows ÄÚºËÖдæÔÚÌáȨ·ì϶£¬³É¹¦ÀûÓø÷ì϶Äܹ»»ñµÃSYSTEMȨÏÞ¡£
l CVE-2024-26211£ºWindows Ô¶³Ì½Ó¼ûÁ¬ÊÕÊÜÀíÆ÷ÖдæÔÚÌØÈ¨ÌáÉý·ì϶£¬³É¹¦ÀûÓø÷ì϶Äܹ»»ñµÃSYSTEMȨÏÞ¡£
l CVE-2024-26230ºÍCVE-2024-26239£ºWindows Telephony Server ÖдæÔÚÌØÈ¨ÌáÉý·ì϶£¬³É¹¦ÀûÓø÷ì϶Äܹ»»ñµÃSYSTEMȨÏÞ¡£
l CVE-2024-29056£ºWindows Éí·ÝÑéÖ¤ÖдæÔÚÌØÈ¨ÌáÉý·ì϶£¬³É¹¦ÀûÓø÷ì϶µÄÍþвÕßÄܹ»²é¿´Ä³Ð©Ãô¸ÐÐÅÏ¢¡£
l CVE-2024-26241£ºWin32kÖдæÔÚÌáȨ·ì϶£¬³É¹¦ÀûÓø÷ì϶Äܹ»»ñµÃSYSTEMȨÏÞ¡£
l CVE-2024-28921ºÍCVE-2024-28903£º°²È«Æô¶¯ÖдæÔÚ°²È«Ö°ÄÜÈÆ¹ý·ì϶£¬³É¹¦ÀûÓÃÕâЩ·ì϶¿ÉÄܵ¼ÖÂÍþвÕßÈÆ¹ý°²È«Æô¶¯¡£
l CVE-2024-26158£ºMicrosoft Install ServiceÌØÈ¨ÌáÉý·ì϶
l CVE-2024-26212£ºDHCP Server Service»Ø¾ø·þÎñ·ì϶
l CVE-2024-26256£ºlibarchive Ô¶³Ì´úÂëÖ´Ðзì϶
±¾´Î¸üÐÂÖÐÆäËûÖµµÃ¹Ø×¢µÄ·ì϶»¹Ô̺¬µ«²»ÏÞÓÚ£º
CVE-2024-26245£ºWindows SMB´æÔÚÌØÈ¨ÌáÉý·ì϶£¬³É¹¦ÀûÓø÷ì϶Äܹ»»ñµÃSYSTEMȨÏÞ¡£
CVE-2024-20670£ºOutlook for Windows´æÔÚºýŪ·ì϶£¬ÍþвÕß¿ÉÏòÊܺ¦Õß·¢ËͶñÒâURL²¢ÓÕµ¼Êܺ¦ÕßÖ´ÐиÃURL£¬Èçͨ¹ý·¢ËÍÌØÔìµÄµç×ÓÓʼþ£¬´Ó¶øµ¼ÖÂÊܺ¦ÕßÓëÍþвÕß½ÚÔìµÄ²»ÊÜÐÅÀµµØÎ»³ÉÁ¢Ïνӣ¬´Ó¶ø½«Êܺ¦ÕßµÄ Net-NTLMv2 ¹þϣй¶µ½²»ÊÜÐÅÀµµÄÍøÂ磬¶øºóÍþвÕßÄܹ»½«ÆäÖм̵½ÁíÒ»¸ö·þÎñ²¢ÒÔÊܺ¦ÕßÉí·Ý½øÐÐÉí·ÝÑéÖ¤¡£
Microsoft SharePoint ÁãÈÕ·ì϶£¨ÔÝÎÞCVE£©£º×êÑÐÈËÔ±ÔÚSharePointÖз¢ÏÖÁËÁ½ÖÖÌÓ±ÜÉøÈë¼ì²âµÄм¼Êõ£¬ÔÊÐíÓû§ÈƹýÉó¼ÆÈÕÖ¾£¬Ô¤·ÀÔÚ±íйÎļþʱ´¥·¢ÏÂÔØÊÂÎñ¡£
΢Èí4Ô¸üÐÂÉæ¼°µÄÆëÈ«·ì϶ÁбíÈçÏ£º
CVE ID | CVE ±êÌâ | ÑϳÁÐÔ |
CVE-2024-29053 | Microsoft Defender for IoT Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2024-21323 | Microsoft Defender for IoT Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2024-21322 | Microsoft Defender for IoT Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
CVE-2024-21409 | .NET¡¢.NET Framework ºÍ Visual Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-29993 | Azure CycleCloud ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-29063 | Azure AIËÑË÷ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-28917 | Azure Arc-enabled Kubernetes Extension Cluster-Scope ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21424 | Azure Compute Gallery ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-26193 | Azure Migrate Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-29989 | Azure Monitor Agent ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-2201 | Ó¢ÌØ¶û£ºCVE-2024-2201 ·ÖÖ§º¹Çà×¢Èë | ¸ßΣ |
CVE-2024-29988 | SmartScreen Prompt °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-29990 | Microsoft Azure Kubernetes Service Confidential ContainerÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-28905 | Microsoft Brokering File System ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-28907 | Microsoft Brokering File System ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-26213 | Microsoft Brokering File System ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-28904 | Microsoft Brokering File System ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-29055 | Microsoft Defender for IoT ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-29054 | Microsoft Defender for IoT ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21324 | Microsoft Defender for IoT ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-26158 | Microsoft Install Service ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-26257 | Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-20670 | Outlook for Windows ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-26251 | Microsoft SharePoint Server ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-26214 | Microsoft WDAC SQL Server ODBC Çý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26244 | Microsoft WDAC OLE DB Provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26210 | Microsoft WDAC OLE DB Provider for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26233 | Windows DNS Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26231 | Windows DNS Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26227 | Windows DNS Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26223 | Windows DNS Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26221 | Windows DNS Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26224 | Windows DNS Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26222 | Windows DNS Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-29064 | Windows Hyper-V »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-28937 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28938 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-29044 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28935 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28940 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28943 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28941 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶µÄ | ¸ßΣ |
CVE-2024-28910 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28944 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28908 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28909 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-29985 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28906 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28926 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28933 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶µÄ | ¸ßΣ |
CVE-2024-28934 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶µÄ | ¸ßΣ |
CVE-2024-28927 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28930 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶µÄ | ¸ßΣ |
CVE-2024-29046 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28932 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶µÄ | ¸ßΣ |
CVE-2024-29047 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28931 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶µÄ | ¸ßΣ |
CVE-2024-29984 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28929 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶µÄ | ¸ßΣ |
CVE-2024-28939 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28942 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-29043 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶µÄ | ¸ßΣ |
CVE-2024-28936 | Microsoft ODBC Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶µÄ | ¸ßΣ |
CVE-2024-29045 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28915 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28913 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28945 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-29048 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28912 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28914 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-29983 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-28911 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-29982 | Microsoft OLE DB Driver for SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-29056 | Windows Authentication ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-21447 | Windows Authentication ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-20665 | BitLocker °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-26256 | libarchive Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26228 | Windows Cryptographic Services °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-29050 | Windows Cryptographic Services Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26237 | Windows Defender Credential Guard ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-26212 | DHCP Server Service »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-26215 | DHCP Server Service »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-26195 | DHCP Server Service Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26202 | DHCP Server Service Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-29066 | Windows É¢²¼Ê½Îļþϵͳ (DFS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26226 | Windows É¢²¼Ê½Îļþϵͳ (DFS) ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-26172 | Windows DWM Core Library ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-26216 | Windows File Server Resource Management Service ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-26219 | HTTP.sys »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-26253 | Windows rndismp6.sys Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26252 | Windows rndismp6.sys Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26183 | Windows Kerberos »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-26248 | Windows Kerberos ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-20693 | Windows Kernel ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-26245 | Windows SMB ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-26229 | Windows CSC Service ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-26218 | Windows Kernel ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-26209 | Microsoft Local Security Authority Subsystem Service ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-26232 | Microsoft Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26208 | Microsoft Message Queuing (MSMQ) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26220 | Windows Mobile Hotspot ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-26234 | Proxy Driver ºýŪ·ì϶ | ¸ßΣ |
CVE-2024-28902 | Windows Remote Access Connection Manager ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-28900 | Windows Remote Access Connection Manager ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-28901 | Windows Remote Access Connection Manager ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-26255 | Windows Remote Access Connection Manager ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-26230 | Windows Telephony Server ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-26239 | Windows Telephony Server ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-26207 | Windows Remote Access Connection Manager ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-26217 | Windows Remote Access Connection Manager ÐÅϢй¶·ì϶ | ¸ßΣ |
CVE-2024-26211 | Windows Remote Access Connection Manager ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-20678 | Remote Procedure Call Runtime Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26200 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26179 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-26205 | Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
CVE-2024-29061 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-28921 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-20689 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-26250 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-28922 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-29062 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-20669 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-28898 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-20688 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-23593 | Lenovo£ºCVE-2024-23593 Zero Out Boot Manager ²¢½µÖÁ UEFI Shell | ¸ßΣ |
CVE-2024-28896 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-28919 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-23594 | Lenovo£ºCVE-2024-23594 LenovoBT.efi ÖеIJֿ⻺³åÇøÒç³ö | ¸ßΣ |
CVE-2024-28923 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-28903 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-26189 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-26240 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-28924 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-28897 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-28925 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-26175 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-28920 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-26194 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-26180 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-26171 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-26168 | Secure Boot °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
CVE-2024-29052 | Windows Storage ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-26242 | Windows Telephony Server ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-26236 | Windows Update Stack ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-26235 | Windows Update Stack ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-26243 | Windows USB Print Driver ȨÏÞÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-26254 | Microsoft Virtual Machine Bus(VMBus) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
CVE-2024-26241 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
CVE-2024-20685 | Azure Private 5G Core »Ø¾ø·þÎñ·ì϶ | ÖÐΣ |
CVE-2024-29992 | Azure Identity Library for .NET ÐÅϢй¶·ì϶ | ÖÐΣ |
CVE-2024-29049 | Microsoft Edge£¨»ùÓÚ Chromium£©Webview2 ºýŪ·ì϶ | ÖÐΣ |
CVE-2024-29981 | Microsoft Edge£¨»ùÓÚ Chromium£©ºýŪ·ì϶ | µÍΣ |
CVE-2024-3156 | Chromium£ºCVE-2024-3156 V8 ÖеÄÖ´Ðв»µ± | δ֪ |
CVE-2024-3159 | Chromium£ºCVE-2024-3159 V8 ÖеÄÄÚ´æ½Ó¼ûÔ½½ç | δ֪ |
CVE-2024-3158 | Chromium£ºCVE-2024-3158 ÔÚÊéÇ©ÖÐ Use-after-free | δ֪ |
CVE-2019-3816 | δ֪ | δ֪ |
CVE-2019-3833 | δ֪ | δ֪ |
¶þ¡¢Ó°ÏìÁìÓò
ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º
Windows BitLocker
Windows Secure Boot
Microsoft Office Outlook
Windows Remote Procedure Call
Azure Private 5G Core
Windows Kernel
Microsoft Defender for IoT
.NET and Visual Studio
Azure Compute Gallery
Windows Authentication Methods
Microsoft Install Service
Windows DWM Core Library
Windows Routing and Remote Access Service (RRAS)
Windows Kerberos
Azure Migrate
Windows DHCP Server
Windows Remote Access Connection Manager
Windows Message Queuing
Windows Local Security Authority Subsystem Service (LSASS)
Microsoft WDAC OLE DB provider for SQL
Microsoft Brokering File System
Microsoft WDAC ODBC Driver
Windows File Server Resource Management Service
Windows HTTP.sys
Windows Mobile Hotspot
Role: DNS Server
Windows Distributed File System (DFS)
Windows Cryptographic Services
Windows Proxy Driver
Windows Update Stack
Windows Defender Credential Guard
Windows Win32K - ICOMP
Windows Telephony Server
Windows USB Print Driver
Microsoft Office SharePoint
Windows Internet Connection Sharing (ICS)
Windows Virtual Machine Bus
Windows Compressed Folder
Microsoft Office Excel
SQL Server
Azure Arc
Microsoft Edge (Chromium-based)
Windows Storage
Azure AI Search
Role: Windows Hyper-V
Internet Shortcut Files
Azure Monitor
Microsoft Azure Kubernetes Service
Azure SDK
Azure
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2024Äê4Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2024-Apr
²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

Àý1£ºÎ¢Èí·ì϶ÁÐ±í£¨Ê¾Àý£©
2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦´ò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
l ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
l ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
l ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Apr
https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2024-patch-tuesday-fixes-150-security-flaws-67-rces/
https://news.sophos.com/en-us/2024/04/09/smoke-and-screen-mirrors-a-strange-signed-backdoor/
https://www.varonis.com/blog/sidestepping-detection-while-exfiltrating-sharepoint-data
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-04-10 | ³õ´Î°ä²¼ |
Îå¡¢¸½Â¼
5.1 GA»Æ½ð¼×¼ò½é
GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£
5.2 ¹ØÓÚGA»Æ½ð¼×
GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ