¡¾·ì϶¹«¸æ¡¿Î¢Èí2Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2025-02-12

Ò»¡¢·ì϶¸ÅÊö


2025Äê2ÔÂ12ÈÕ   £¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Î¢Èí°ä²¼ÁË2Ô°²È«¸üР  £¬±¾´Î¸üн¨¸´ÁË63¸ö·ì϶   £¬º­¸ÇȨÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐÓ×¢ºýŪµÈ¶àÖÖ·ì϶ÀàÐÍ¡£·ì϶¼¶±ðÉ¢²¼ÈçÏ£º4¸öÑϳÁ¼¶±ð·ì϶   £¬56¸ö³ÁÒª¼¶±ð·ì϶   £¬1¸öÖÐΣ¼¶±ð·ì϶   £¬2¸öµÍΣ¼¶±ð·ì϶£¨·ì϶¼¶±ðƾ¾Ý΢Èí¹Ù·½Êý¾Ý£©¡£


ÆäÖÐ   £¬11¸ö·ì϶±»Î¢ÈíÏóÕ÷Ϊ¡°¸ü¿ÉÄܱ»ÀûÓá±¼°¡°¼ì²âÀûÓÃÇé¾°¡±   £¬Åú×¢ÕâЩ·ì϶´æÔڽϸߵÄÀûÓ÷çÏÕ   £¬½¨ÒéÓÅÏȽ¨¸´ÒÔ½µµÍDZÔÚ°²È«Íþв¡£


CVE-ID

CVE ±êÌâ

·ì϶¼¶±ð

CVE-2025-21400

Microsoft SharePoint Server Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-21377

NTLM ¹þϣй¶ºýŪ·ì϶

³ÁÒª

CVE-2025-21418

WinSock µÄ Windows ¸¨ÖúÖ°ÄÜÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21414

Windows Core Messaging ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21358

Windows Core Messaging ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21184

Windows Core Messaging ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21367

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21391

Windows ´æ´¢ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21419

Windows ×°Ö÷¨Ê½ÎļþËãÕÊÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21420

Windows ´Å¼ÆËãÕʹ¤¾ßÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21376

Windows ÇáÁ¿¼¶Ä¿Â¼½Ó¼ûºÍ̸ (LDAP) Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ


΢Èí2Ô¸üн¨¸´µÄÆëÈ«·ì϶ÁбíÈçÏ£º


CVE-ID

CVE ±êÌâ

·ì϶¼¶±ð

CVE-2025-21177

Microsoft Dynamics 365 Sales ÌØÈ¨ÌáÉý·ì϶

ÑϳÁ

CVE-2025-21179

DHCP ¿Í»§¶Ë·þÎñ»Ø¾ø·þÎñ·ì϶

³ÁÒª

CVE-2025-21181

Microsoft ÐÂÎŶÓÁÐ (MSMQ) »Ø¾ø·þÎñ·ì϶

³ÁÒª

CVE-2025-21182

Windows ¸´Ô­Îļþϵͳ (ReFS) ɾ³ý³Á¸´·þÎñÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21183

Windows ¸´Ô­Îļþϵͳ (ReFS) ɾ³ý³Á¸´·þÎñÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21184

Windows Core Messaging ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21188

Azure ÍøÂç¹Û²ì·¨Ê½ VM À©´óÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21190

Windows µç»°·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-21194

Microsoft Surface °²È«Ö°ÄÜÈÆ¹ý·ì϶

³ÁÒª

CVE-2025-21198

Microsoft ¸ß»úÄÜÍÆËã (HPC) ´ò°üÔ¶³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-21200

Windows µç»°·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-21201

Windows Telephony Server Ô¶³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-21206

Visual Studio Installer ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21208

Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-21212

Internet Ïνӹ²Ïí (ICS) »Ø¾ø·þÎñ·ì϶

³ÁÒª

CVE-2025-21216

Internet Ïνӹ²Ïí (ICS) »Ø¾ø·þÎñ·ì϶

³ÁÒª

CVE-2025-21253

Microsoft Edge£¨iOS ºÍ Android °æ£©ºýŪ·ì϶

ÖÐ

CVE-2025-21254

Internet Ïνӹ²Ïí (ICS) »Ø¾ø·þÎñ·ì϶

³ÁÒª

CVE-2025-21259

Microsoft Outlook ºýŪ·ì϶

³ÁÒª

CVE-2025-21267

»ùÓÚ Chromium µÄ Microsoft Edge ºýŪ·ì϶

µÍ

CVE-2025-21279

»ùÓÚ Chromium µÄ Microsoft Edge Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-21283

»ùÓÚ Chromium µÄ Microsoft Edge Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-21322

Microsoft PC Manager ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21337

Windows NTFS ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21342

»ùÓÚ Chromium µÄ Microsoft Edge Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-21347

Windows ²¿Êð·þÎñ»Ø¾ø·þÎñ·ì϶

³ÁÒª

CVE-2025-21349

Windows Ô¶³Ì×ÀÃæÅäÖ÷þÎñ´Û¸Ä·ì϶

³ÁÒª

CVE-2025-21350

Windows Kerberos »Ø¾ø·þÎñ·ì϶

³ÁÒª

CVE-2025-21351

Windows Active Directory Óò·þÎñ API ·þÎñ»Ø¾ø·ì϶

³ÁÒª

CVE-2025-21352

Internet Ïνӹ²Ïí (ICS) »Ø¾ø·þÎñ·ì϶

³ÁÒª

CVE-2025-21358

Windows Core Messaging ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21359

Windows Äں˰²È«Ö°ÄÜÈÆ¹ý·ì϶

³ÁÒª

CVE-2025-21367

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21368

Microsoft Digest Éí·ÝÑéÖ¤Ô¶³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-21369

Microsoft Digest Éí·ÝÑéÖ¤Ô¶³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-21371

Windows µç»°·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-21373

Windows Installer ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21375

Kernel Streaming WOW Thunk ·þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21376

Windows ÇáÁ¿¼¶Ä¿Â¼½Ó¼ûºÍ̸ (LDAP) Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2025-21377

NTLM ¹þϣй¶ºýŪ·ì϶

³ÁÒª

CVE-2025-21379

DHCP ¿Í»§¶Ë·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2025-21381

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë·ì϶

ÑϳÁ

CVE-2025-21383

Microsoft Excel ÐÅϢй¶·ì϶

³ÁÒª

CVE-2025-21386

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-21387

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-21390

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-21391

Windows ´æ´¢ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21392

Microsoft Office Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-21394

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-21397

Microsoft Office Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-21400

Microsoft SharePoint Server Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-21404

»ùÓÚ Chromium µÄ Microsoft Edge ºýŪ·ì϶

µÍ

CVE-2025-21406

Windows µç»°·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-21407

Windows µç»°·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-21408

»ùÓÚ Chromium µÄ Microsoft Edge Ô¶³ÌÖ´ÐдúÂë·ì϶

³ÁÒª

CVE-2025-21410

Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶

³ÁÒª

CVE-2025-21414

Windows Core Messaging ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21418

WinSock µÄ Windows ¸¨ÖúÖ°ÄÜÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21419

Windows ×°Ö÷¨Ê½ÎļþËãÕÊÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-21420

Windows ´Å¼ÆËãÕʹ¤¾ßÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24036

Microsoft AutoUpdate (MAU) ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24039

Visual Studio Code ÌØÈ¨ÌáÉý·ì϶

³ÁÒª

CVE-2025-24042

Visual Studio Code JS µ÷ÊÔÀ©´óÌØÈ¨ÌáÉý·ì϶

³ÁÒª


¶þ¡¢Ó°ÏìÁìÓò


ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬£º

Microsoft Dynamics 365 Sales

Windows DHCP Client

Windows Message Queuing

Windows Resilient File System (ReFS) Deduplication Service

Windows CoreMessaging

Azure Network Watcher

Windows Telephony Service

Microsoft Surface

Microsoft High Performance Compute Pack (HPC) Linux Node Agent

Windows Telephony Server

Visual Studio

Windows Routing and Remote Access Service (RRAS)

Windows Internet Connection Sharing (ICS)

Microsoft Edge for iOS and Android

Outlook for Android

Microsoft Edge (Chromium-based)

Microsoft PC Manager

Microsoft Windows

Windows Update Stack

Windows Remote Desktop Services

Windows Kerberos

Active Directory Domain Services

Windows Kernel

Windows Win32 Kernel Subsystem

Microsoft Digest Authentication

Windows Installer

Microsoft Streaming Service

Windows LDAP - Lightweight Directory Access Protocol

Windows NTLM

Windows DHCP Server

Microsoft Office Excel

Windows Storage

Microsoft Office

Microsoft Office SharePoint

Windows DWM Core Library

Windows Ancillary Function Driver for WinSock

Windows Setup Files Cleanup

Windows Disk Cleanup Tool

Microsoft AutoUpdate (MAU)

Visual Studio Code


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üР  £¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ì½¨¸´¡£


£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ


Microsoft UpdateĬÈÏÆôÓà   £¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ   £¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüУº


1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü   £¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±   £¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±   £¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³­¸üС±   £¬ÆÚ´ýϵͳ×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¸üÐÂʵÏÖºó³ÁÆôÍÆËã»ú   £¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüР  £¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó   £¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±   £¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£


£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ


Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£


2025Äê2Ô°²È«¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2025-Feb

²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º


1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó   £¬µã»÷·ì϶ÁбíÖÐÒª½¨¸´µÄCVEÁ´½Ó¡£



ͼƬ1.jpg

Àý1£ºÎ¢Èí·ì϶ÁÐ±í£¨Ê¾Àý£©


2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿ÁÐÑ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ   £¬µã»÷ÓҲࡾÏÂÔØ¡¿Áдò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£


ͼƬ2.jpg

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý


3.µã»÷¡¾°²È«¸üС¿   £¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ   £¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£


ͼƬ3.jpg

Àý3£º²¹¶¡ÏÂÔØ½çÃæ


4.×°ÖÃʵÏÖºó³ÁÆôÍÆËã»ú¡£


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡   £¬Ï÷¼õϵͳ·ì϶   £¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔì   £¬Åú¸Ä·À»ðǽսÊõ   £¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ   £¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø   £¬Ï÷¼õ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·   £¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí   £¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò   £¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://msrc.microsoft.com/update-guide/releaseNote/2025-Feb