¡¾·ì϶¹«¸æ¡¿Î¢Èí11Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2024-11-13Ò»¡¢·ì϶¸ÅÊö
2024Äê11ÔÂ13ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Î¢Èí°ä²¼ÁË11Ô°²È«¸üУ¬±¾´Î¸üй²½¨¸´ÁË89¸ö·ì϶£¨²»Ô̺¬Ö®Ç°½¨¸´µÄEdge·ì϶£©£¬·ì϶ÀàÐÍÔ̺¬ÌØÈ¨ÌáÉý·ì϶¡¢°²È«Ö°ÄÜÈÆ¹ý·ì϶¡¢Ô¶³Ì´úÂëÖ´Ðзì϶¡¢ÐÅϢй¶·ì϶¡¢»Ø¾ø·þÎñ·ì϶ºÍºýŪ·ì϶µÈ¡£
±¾´Î°²È«¸üÐÂÖн¨¸´ÁË4¸ö0 day·ì϶£¬ÆäÖÐ2¸öÒÑ·¢´Ë¿Ì¹¥»÷Öб»ÀûÓã¬3¸öÒѾ¹«¿ªÅû¶£º
CVE-2024-43451£ºNTLM ¹þϣй¶ºýŪ·ì϶
Windows´æÔÚNTLM ¹þϣй¶ºýŪ·ì϶£¬ÆäCVSSÆÀ·ÖΪ6.5£¬ÀûÓø÷ì϶±ØÒªÓû§½»»¥£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÏò¹¥»÷Õßй¶Óû§µÄ NTLMv2 ¹þÏ££¬¹¥»÷ÕßÄܹ»Ê¹ÓÃËüÀ´ÑéÖ¤Óû§Éí·Ý¡£Ä¿Ç°¸Ã·ì϶ÒѾ¹«¿ªÅû¶£¬ÇÒÒѼì²âµ½·ì϶ÀûÓá£
CVE-2024-49039£ºWindows Task SchedulerÌØÈ¨ÌáÉý·ì϶
Windows ¹¤×÷´òË㷨ʽÖдæÔÚÉí·ÝÑéÖ¤²»µ±£¬¿ÉÄܵ¼ÖÂȨÏÞÌáÉý£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8£¬¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÔÚÖ¸±êϵͳÉÏÔËÐжñÒâÉè¼ÆµÄÀûÓ÷¨Ê½£¬ÀûÓø÷ì϶ÌáÉýÆäȨÏÞ£¬³É¹¦ÀûÓÃÔÊÐí¹¥»÷ÕßÖ´ÐÐͨ³£½öÏÞÓÚÌØÈ¨ÕË»§µÄRPCÖ°ÄÜ¡£Ä¿Ç°¸Ã·ì϶ÒѼì²âµ½·ì϶ÀûÓá£
CVE-2024-49040£ºMicrosoft Exchange Server ºýŪ·ì϶
Microsoft Exchange ServerÖдæÔÚºýŪ·ì϶£¬ÆäCVSSÆÀ·ÖΪ7.5£¬¸Ã·ì϶ÔÊÐí¹¥»÷ÕßÔÚ·¢Ë͸ø±¾µØÊÕ¼þÈ˵ĵç×ÓÓʼþÖÐαÔì·¢¼þÈ˵ĵç×ÓÓʼþµØÖ·£¬µ¼ÖºýŪ¹¥»÷¡£Ä¿Ç°¸Ã·ì϶ÒѾ¹«¿ªÅû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£
CVE-2024-49019£ºActive Directory Ö¤Êé·þÎñÌØÈ¨ÌáÉý·ì϶
Active Directory Ö¤Êé·þÎñ´æÔÚÈõÉí·ÝÑéÖ¤ÎÊÌ⣬¿ÉÄܵ¼ÖÂÌØÈ¨ÌáÉý£¬ÆäCVSSÆÀ·ÖΪ7.8£¬¸Ã·ì϶ÔÊÐí¹¥»÷Õßͨ¹ýÀÄÓÃÄÚÖÃĬÈϰ汾1Ö¤ÊéÄ£°åÀ´»ñÈ¡ÓòÖÎÀíԱȨÏÞ¡£Ä¿Ç°¸Ã·ì϶ÒѾ¹«¿ªÅû¶£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±¡£
±¾´Î°²È«¸üÐÂÖн¨¸´µÄ4¸öÑϳÁ·ì϶Ϊ£º
CVE-2024-43498£º.NET & Visual StudioÔ¶³Ì´úÂëÖ´Ðзì϶
.NET ºÍ Visual StudioÖдæÔÚÀàÐÍ»ìºÏ·ì϶£¬ÆäCVSSÆÀ·ÖΪ9.8£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÏò´æÔÚ·ì϶µÄ .NET Web ÀûÓ÷¨Ê½·¢ËÍÌØÔìÒªÇó»ò½«ÌØÔìÎļþ¼ÓÔØµ½´æÔÚ·ì϶µÄ×ÀÃæÀûÓ÷¨Ê½ÖÐÀ´ÀûÓø÷ì϶£¬³É¹¦ÀûÓÿÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ ¡°±»ÀûÓõĿÉÄÜÐÔ½ÏÓס±¡£
CVE-2024-49056£ºAirlift.microsoft.com ÌØÈ¨ÌáÉý·ì϶
¸Ã·ì϶µÄCVSSÆÀ·ÖΪ7.3£¬Í¨¹ý airlift.microsoft.com Éϼٶ¨²»³É±äÊý¾ÝÈÆ¹ýÉí·ÝÑéÖ¤£¬ÊÚȨ¹¥»÷ÕßÄܹ»Í¨¹ýÍøÂçÌáÉýȨÏÞ¡£¸Ã·ì϶ÎÞÐèÓû§²ÉÈ¡ÈκδëÊ©¼´¿É½â¾ö¡£
CVE-2024-43639£ºWindows KDC ProxyÔ¶³Ì´úÂëÖ´Ðзì϶
¸Ã·ì϶µÄCVSSÆÀ·ÖΪ9.8£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Ê¹ÓÃÌØÔìÀûÓ÷¨Ê½ÀûÓÃWindows KerberosÖеļÓÃܺÍ̸·ì϶¶ÔÖ¸±êÖ´ÐÐÔ¶³Ì´úÂë¡£
CVE-2024-43625£ºMicrosoft Windows VMSwitch ÌØÈ¨ÌáÉý·ì϶
Microsoft Hyper-V ÖÐµÄ VmSwitch ×é¼þ´æÔÚUse-After-Free·ì϶£¬ÆäCVSSÆÀ·ÖΪ8.1£¬¹¥»÷Õß¿Éͨ¹ýÏòVMswitch Çý¶¯·¨Ê½·¢ËÍһϵÁÐÌØ¶¨µÄÍøÂçÒªÇ󣬴Ӷø´¥·¢ Hyper-V Ö÷»úÖеĿªÊͺó³ÁÓ÷ì϶£¬³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃ SYSTEM ȨÏÞ¡£
³ýCVE-2024-49040ºÍCVE-2024-49019±í£¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀÖÐÆäËû ¡°±»ÀûÓõĿÉÄÜÐԽϸߡ±µÄ·ì϶»¹Ô̺¬ÒÔÏ·ì϶£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶»ñµÃ SYSTEM ȨÏÞ¡¢µ¼Ö»ؾø·þÎñ»òÈÆ¹ýOfficeÊܱ£»¤ÊÓͼµÄÌØ¶¨Ö°ÄÜ£º
CVE-2024-43623£ºWindows NT OS KernelÌØÈ¨ÌáÉý·ì϶
CVE-2024-43629£ºWindows DWM Core LibraryÌØÈ¨ÌáÉý·ì϶
CVE-2024-43630£ºWindows KernelÌØÈ¨ÌáÉý·ì϶
CVE-2024-43636£ºWin32kÌØÈ¨ÌáÉý·ì϶
CVE-2024-43642£ºWindows SMB »Ø¾ø·þÎñ·ì϶
CVE-2024-49033£ºMicrosoft Word°²È«Ö°ÄÜÈÆ¹ý·ì϶
΢Èí11Ô¸üн¨¸´µÄÆëÈ«·ì϶ÁбíÈçÏ£º
| CVE-ID | CVE ±êÌâ | ÑϳÁÐÔ |
| CVE-2024-43498 | .NET & Visual Studio Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
| CVE-2024-49056 | Airlift.microsoft.com ÌØÈ¨ÌáÉý·ì϶ | ÑϳÁ |
| CVE-2024-43639 | Windows KDC ProxyÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
| CVE-2024-43625 | Microsoft Windows VMSwitch ÌØÈ¨ÌáÉý·ì϶ | ÑϳÁ |
| CVE-2024-43499 | .NET & Visual Studio »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
| CVE-2024-43602 | Azure CycleCloud Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-43598 | LightGBM Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-5535 | OpenSSL£ºCVE-2024-5535 SSL_select_next_proto »º³åÇø¸²¸Ç | ¸ßΣ |
| CVE-2024-49040 | Microsoft Exchange Server ºýŪ·ì϶ | ¸ßΣ |
| CVE-2024-49031 | Microsoft Office Graphics Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49032 | Microsoft Office Graphics Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49029 | Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49026 | Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49027 | Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49028 | Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49030 | Microsoft Excel Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49033 | Microsoft Word °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
| CVE-2024-49051 | Microsoft PC Manager ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-38264 | Microsoft Ðé¹¹Ó²ÅÌ (VHDX) »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
| CVE-2024-43450 | Windows DNS ºýŪ·ì϶ | ¸ßΣ |
| CVE-2024-49019 | Active Directory Ö¤Êé·þÎñÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43633 | Windows Hyper-V »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
| CVE-2024-43624 | Windows Hyper-V ¹²ÏíÐé¹¹´ÅÅÌÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-48998 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-48997 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-48993 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49001 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49000 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-48999 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49043 | Microsoft.SqlServer.XEvent.Configuration.dll Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-43462 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-48995 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-48994 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-38255 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-48996 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-43459 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49002 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49013 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49014 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49011 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49012 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49015 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49018 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49021 | Microsoft SQL Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49016 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49017 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49010 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49005 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49007 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49003 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49004 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49006 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49009 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49008 | SQL Server Native Client Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49048 | TorchGeo Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49044 | Visual Studio ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-49050 | Visual Studio Code Python Extension Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-43644 | Windows Client-Side Caching ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43645 | Windows Defender ÀûÓ÷¨Ê½½ÚÔì (WDAC) °²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
| CVE-2024-43636 | Win32k ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43629 | Windows DWM Core Library ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43630 | Windows ÄÚºËÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43623 | Windows NT OS Kernel ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43451 | NTLM ¹þϣй¶ºýŪ·ì϶ | ¸ßΣ |
| CVE-2024-38203 | Windows Package Library Manager ÐÅϢй¶·ì϶ | ¸ßΣ |
| CVE-2024-43641 | Windows ×¢²á±íÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43452 | Windows ×¢²á±íÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43631 | Windows Secure Kernel Mode ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43646 | Windows Secure Kernel Mode ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43640 | Windows Kernel-Mode Driver ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43642 | Windows SMB »Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
| CVE-2024-43447 | Windows SMBv3 Server Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-49039 | Windows Task Scheduler ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43628 | Windows Telephony Service Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-43621 | Windows Telephony Service Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-43620 | Windows Telephony Service Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-43627 | Windows Telephony Service Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-43635 | Windows Telephony Service Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-43622 | Windows Telephony Service Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
| CVE-2024-43626 | Windows Telephony Service ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43530 | Windows Update Stack ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43643 | Windows USB Video Class System Driver ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43449 | Windows USB Video Class System Driver ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43637 | Windows USB Video Class System Driver ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43634 | Windows USB Video Class System Driver ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-43638 | Windows USB Video Class System Driver ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-49046 | Windows Win32 Kernel Subsystem ÌØÈ¨ÌáÉý·ì϶ | ¸ßΣ |
| CVE-2024-49049 | Visual Studio Code Remote Extension ÌØÈ¨ÌáÉý·ì϶ | ÖÐΣ |
| ADV240001 | Microsoft SharePoint Server ×ÝÉî·ÀÓù¸üР| ÎÞ |
| CVE-2024-10826 | Chromium£ºCVE-2024-10826 ÔÚ Family Experiences ÖÐUse-after-free | δ֪ |
| CVE-2024-10827 | Chromium£ºCVE-2024-10827 SerialÖеÄUse-after-free | δ֪ |
?
¶þ¡¢Ó°ÏìÁìÓò
ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º
Windows Package Library Manager
SQL Server
Microsoft Virtual Hard Drive
Windows SMBv3 Client/Server
Windows USB Video Driver
Microsoft Windows DNS
Windows NTLM
Windows Registry
.NET and Visual Studio
Windows Update Stack
LightGBM
Azure CycleCloud
Azure Database for PostgreSQL
Windows Telephony Service
Windows NT OS Kernel
Role: Windows Hyper-V
Windows VMSwitch
Windows DWM Core Library
Windows Kernel
Windows Secure Kernel Mode
Windows Kerberos
Windows SMB
Windows CSC Service
Windows Defender Application Control (WDAC)
Windows Active Directory Certificate Services
Microsoft Office Excel
Microsoft Graphics Component
Microsoft Office Word
Windows Task Scheduler
Microsoft Exchange Server
Visual Studio
Windows Win32 Kernel Subsystem
TorchGeo
Visual Studio Code
Microsoft PC Manager
Airlift.microsoft.com
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
2024Äê11Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2024-Nov
²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º
1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£

Àý1£ºÎ¢Èí·ì϶ÁÐ±í£¨Ê¾Àý£©
2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿ÁÐÑ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áдò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾°²È«¸üС¿£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2024-Nov
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49019
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43639
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2024-11-13 | ³õ´Î°ä²¼ |
Îå¡¢¸½Â¼
5.1 GA»Æ½ð¼×¼ò½é
GA»Æ½ð¼×³ÉÁ¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°GA»Æ½ð¼×´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐÓ×°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£
5.2 ¹ØÓÚGA»Æ½ð¼×
GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÒѰ䲼1000¶à¸ö·ì϶¹«¸æÎ¢·çÏÕÔ¤¾¯£¬ÎÒÃǽ«³ÖÐø¸ú×ÙÈ«Çò×îеÄÍøÂ簲ȫÊÂÎñºÍ·ì϶£¬ÎªÆóÒµµÄÐÅÏ¢°²È«±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ