¡¾Îó²îͨ¸æ¡¿Î¢Èí4Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2023-04-12Ò»¡¢Îó²î¸ÅÊö
2023Äê4ÔÂ11ÈÕ£¬Î¢ÈíÐû²¼ÁË4ÔÂÇå¾²¸üУ¬±¾´Î¸üÐÂÐÞ¸´Á˰üÀ¨1¸ö0 dayÎó²îÔÚÄÚµÄ97¸öÇå¾²Îó²î£¨²»°üÀ¨Microsoft EdgeÎó²î£©£¬ÆäÖÐÓÐ7¸öÎó²îÆÀ¼¶Îª¡°ÑÏÖØ¡±¡£
±¾´ÎÐÞ¸´µÄÎó²îÖУ¬Îó²îÀàÐͰüÀ¨ÌØÈ¨ÌáÉýÎó²î¡¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡¢ÐÅϢй¶Îó²î¡¢¾Ü¾ø·þÎñÎó²î¡¢Çå¾²¹¦Ð§ÈƹýÎó²îºÍÓÕÆÎó²îµÈ¡£
΢Èí±¾´Î¹²ÐÞ¸´ÁË1¸ö±»Æð¾¢Ê¹ÓõÄ0 dayÎó²î£¬ÈçÏ£º
CVE-2023-28252 £ºWindows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î
Windows CLFS Çý¶¯³ÌÐòÖб£´æÔ½½çдÈëÎó²î£¬ÍâµØµÍȨÏÞÓû§¿ÉÒÔͨ¹ý»ù½ñÈÕÖ¾Îļþ£¨.blf ÎļþÀ©Õ¹Ãû£©µÄ²Ù×÷´¥·¢¸ÃÎó²î£¬ÀÖ³ÉʹÓøÃÎó²î¿Éµ¼ÖÂÍâµØÈ¨ÏÞÌáÉýΪSYSTEM¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.8£¬ÏÖÔÚÒÑ·¢Ã÷±»Nokoyawa ÀÕË÷Èí¼þʹÓá£
±¾´ÎÇå¾²¸üÐÂÖÐÆÀ¼¶ÎªÑÏÖØµÄ7¸öÎó²î°üÀ¨£º
CVE-2023-21554£ºMicrosoft ÐÂÎÅÐÐÁÐÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.8£¬¿ÉÒÔͨ¹ý·¢ËͶñÒâÖÆ×÷µÄMSMQ Êý¾Ý°üµ½MSMQ ·þÎñÆ÷À´Ê¹ÓøÃÎó²î£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂÔÚ·þÎñÆ÷¶ËÔ¶³ÌÖ´ÐдúÂ롣ʹÓøÃÎó²îÐèÒªÆôÓÃ×÷ΪWindows ×é¼þµÄWindows ÐÂÎÅÐÐÁзþÎñ£¬¿ÉÒÔͨ¹ý¼ì²éÊÇ·ñÖøÃûΪMessage QueuingµÄ·þÎñÔÚÔËÐУ¬ÒÔ¼°ÅÌËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£
CVE-2023-28231£ºDHCP Server Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.8£¬¾ÓÉÉí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔʹÓÃÕë¶Ô DHCP ·þÎñµÄÌØÖÆ RPC ŲÓÃÀ´Ê¹ÓøÃÎó²î¡£
CVE-2023-28219/ CVE-2023-28220£º¶þ²ãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.1£¬Î´¾Éí·ÝÑéÖ¤µÄÍþвÕß¿ÉÒÔÏò RAS ·þÎñÆ÷·¢ËͶñÒâÅþÁ¬ÇëÇó£¬Õâ¿ÉÄܵ¼Ö RAS ·þÎñÆ÷ÅÌËã»úÉϵÄÔ¶³Ì´úÂëÖ´ÐУ¬µ«Ê¹ÓøÃÎó²îÐèÒªÓ®µÃ¾ºÕùÌõ¼þ¡£
CVE-2023-28250£ºWindows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ9.8£¬µ±ÆôÓÃWindowsÐÂÎÅÐÐÁзþÎñʱ£¬ÀÖ³ÉʹÓøÃÎó²îµÄÍþвÕß¿ÉÒÔͨ¹ýÍøÂç·¢ËÍÌØÖÆµÄÎļþ£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐУ¬²¢´¥·¢¶ñÒâ´úÂ롣ʹÓøÃÎó²îÐèÒªÆôÓÃ×÷ΪWindows ×é¼þµÄWindows ÐÂÎÅÐÐÁзþÎñ£¬¿ÉÒÔͨ¹ý¼ì²éÊÇ·ñÖøÃûΪMessage QueuingµÄ·þÎñÔÚÔËÐУ¬ÒÔ¼°ÅÌËã»úÉÏÊÇ·ñÕìÌýTCP ¶Ë¿Ú1801¡£
CVE-2023-28232£ºWindows µã¶ÔµãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.5£¬µ±Óû§½« Windows ¿Í»§¶ËÅþÁ¬µ½¶ñÒâ·þÎñÆ÷ʱ£¬¿ÉÄܻᴥ·¢´ËÎó²î£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
CVE-2023-28291£ºÔʼͼÏñÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ8.4£¬¿ÉÒÔͨ¹ýÓÕʹÍâµØÓû§·¿ª¶ñÒâÎļþ/Á´½ÓÀ´Ê¹ÓøÃÎó²î£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܵ¼ÖÂí§Òâ´úÂëÖ´ÐС£
±ðµÄ£¬ÖµµÃ¹Ø×¢µÄÎó²î»¹°üÀ¨Microsoft Office¡¢Word ºÍ Publisher Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-28285¡¢CVE-2023-28311¡¢CVE-2023-28295ºÍCVE-2023-28287£©µÈ£¬Ö»Ðè·¿ª¶ñÒâÎĵµ¼´¿ÉʹÓÃÕâЩÎó²î£¬Ó¦×¢ÖØÐÞ¸´´ËÀàÎó²î¡£
΢Èí4Ô¸üÐÂÉæ¼°µÄÍêÕûÎó²îÁбíÈçÏ£º
CVE | CVE ÎÊÌâ | ÑÏÖØË®Æ½ |
CVE-2023-21554 | Microsoft ÐÂÎÅÐÐÁÐÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-28231 | DHCP Server Service Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-28219 | ¶þ²ãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-28220 | ¶þ²ãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-28250 | Windows Pragmatic General Multicast (PGM) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-28232 | Windows µã¶ÔµãËíµÀÐÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-28291 | ÔʼͼÏñÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2023-28260 | .NET DLLÐ®ÖÆÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28312 | Azure »úеѧϰÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-28300 | Azure ·þÎñÅþÁ¬Æ÷Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-28227 | Windows À¶ÑÀÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24860 | Microsoft Defender ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-28314 | Microsoft Dynamics 365 (on-premises) ¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2023-28309 | Microsoft Dynamics 365 (on-premises) ¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2023-28313 | Microsoft Dynamics 365 ¿Í»§ÓïÒô¿çÕ¾¾ç±¾Îó²î | ¸ßΣ |
CVE-2023-24912 | Windows ͼÐÎ×é¼þÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-21769 | Microsoft ÐÂÎÅÐÐÁоܾø·þÎñÎó²î | ¸ßΣ |
CVE-2023-28285 | Microsoft Office ͼÐÎÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28295 | Microsoft Publisher Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28287 | Microsoft Publisher Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28288 | Microsoft SharePoint Server ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-28311 | Microsoft Word Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28243 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24883 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-24927 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24925 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24924 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24885 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24928 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24884 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24926 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24929 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24887 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24886 | Microsoft PostScript ºÍ PCL6 Àà´òÓ¡»úÇý¶¯³ÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28275 | Microsoft WDAC OLE DB provider for SQL ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28256 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28278 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28307 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28306 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28223 | WindowsÓòÃû·þÎñÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28254 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28305 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28308 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28255 | Windows DNS ·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28277 | Windows DNS ·þÎñÆ÷ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-23384 | Microsoft SQL Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-23375 | Microsoft ODBC ºÍ OLE DB Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28304 | Microsoft ODBC ºÍ OLE DB Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28299 | Visual Studio ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-28262 | Visual Studio ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28263 | Visual Studio ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-28296 | Visual Studio Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-24893 | Visual Studio Code Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28302 | Microsoft ÐÂÎÅÐÐÁоܾø·þÎñÎó²î | ¸ßΣ |
CVE-2023-28236 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28216 | Windows ¸ß¼¶ÍâµØÀú³ÌŲÓà (ALPC) ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28218 | Windows Ancillary Function Driver for WinSock ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28269 | Windows Æô¶¯ÖÎÀíÆ÷Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-28249 | Windows Æô¶¯ÖÎÀíÆ÷Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-28273 | Windows Clip ·þÎñÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28229 | Windows CNG ÃÜÔ¿¸ôÀë·þÎñÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28266 | Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-28252 | Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28226 | Windows ×¢²áÒýÇæÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-28221 | Windows ¹ýʧ±¨¸æ·þÎñÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28276 | Windows ×éÕ½ÂÔÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-28238 | Windows Internet ÃÜÔ¿½»Á÷ (IKE) ÐÒéÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28244 | Windows Kerberos ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28271 | Windows ÄÚºËÄÚ´æÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-28248 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28222 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28272 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28293 | Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28253 | Windows ÄÚºËÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-28237 | Windows ÄÚºËÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28298 | Windows Äں˾ܾø·þÎñÎó²î | ¸ßΣ |
CVE-2023-28270 | Windows ËøÆÁÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-28235 | Windows ËøÆÁÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2023-28268 | Netlogon RPC ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28217 | Windows ÍøÂçµØµãת»» (NAT) ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-28247 | Windows ÍøÂçÎļþϵͳÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-28240 | Windows ÍøÂç¸ºÔØÆ½ºâÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28225 | Windows NTLM ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28224 | Windows ÒÔÌ«Íøµã¶ÔµãÐÒé (PPPoE) Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28292 | ÔʼͼÏñÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28228 | Windows ÓÕÆÎó²î | ¸ßΣ |
CVE-2023-28267 | Ô¶³Ì×ÀÃæÐÒé¿Í»§¶ËÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-28246 | Windows ×¢²á±íÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-21729 | Ô¶³ÌÀú³ÌŲÓÃÔËÐÐʱÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2023-21727 | Ô¶³ÌÀú³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2023-28297 | Windows Ô¶³ÌÀú³ÌŲÓ÷þÎñ (RPCSS) ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-24931 | Windows Ç徲ͨµÀ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-28233 | Windows Ç徲ͨµÀ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-28241 | Windows Çå¾²Ì×½Ó×ÖËíµÀÐÒé (SSTP) ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-28234 | Windows Ç徲ͨµÀ¾Ü¾ø·þÎñÎó²î | ¸ßΣ |
CVE-2023-28274 | Windows Win32k ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-24914 | Win32k ÌØÈ¨ÌáÉýÎó²î | ¸ßΣ |
CVE-2023-28284 | Microsoft Edge£¨»ùÓÚ Chromium£©Çå¾²¹¦Ð§ÈƹýÎó²î | ÖÐΣ |
CVE-2023-28301 | Microsoft Edge£¨»ùÓÚ Chromium£©¸Ä¶¯Îó²î | µÍΣ |
CVE-2023-24935 | Microsoft Edge£¨»ùÓÚ Chromium£©ÓÕÆÎó²î | µÍΣ |
CVE-2023-1823 | Chromium£ºCVE-2023-1823 ÔÚ FedCM ÖÐʵÑé²»µ± | δ֪ |
CVE-2023-1810 | Chromium£ºCVE-2023-1810 VisualsÖеĶѻº³åÇøÒç³ö | δ֪ |
CVE-2023-1819 | Chromium£ºCVE-2023-1819 AccessibilityÖеÄÔ½½ç¶ÁÈ¡ | δ֪ |
CVE-2023-1818 | Chromium£ºCVE-2023-1818 Vulkan ÖеÄÊͷźóʹÓà | δ֪ |
CVE-2023-1814 | Chromium£ºCVE-2023-1814 Çå¾²ä¯ÀÀÖв»ÊÜÐÅÍеÄÊäÈëÑéÖ¤²»³ä·Ö | δ֪ |
CVE-2023-1821 | Chromium£ºCVE-2023-1821 WebShare ÖеÄʵÑé²»µ± | δ֪ |
CVE-2023-1811 | Chromium£ºCVE-2023-1811 Frames ÖеÄÊͷźóʹÓà | δ֪ |
CVE-2023-1820 | Chromium£ºCVE-2023-1820 ä¯ÀÀÆ÷ÀúÊ·ÖеĶѻº³åÇøÒç³ö | δ֪ |
CVE-2023-1816 | Chromium£ºCVE-2023-1816 »ÖлÖеÄÇå¾² UI ²»×¼È· | δ֪ |
CVE-2023-1815 | Chromium£ºCVE-2023-1815 Networking APIsÖеÄÊͷźóʹÓà | δ֪ |
CVE-2023-1822 | Chromium£ºCVE-2023-1822 µ¼º½ÖеÄÇå¾² UI ²»×¼È· | δ֪ |
CVE-2023-1813 | Chromium£ºCVE-2023-1813 À©Õ¹ÖеÄʵÑé²»µ± | δ֪ |
CVE-2023-1812 | Chromium£ºCVE-2023-1812 DOM °ó¶¨ÖеÄÔ½½çÄÚ´æ»á¼û | δ֪ |
CVE-2023-1817 | Chromium£º CVE-2023-1817 IntentsÖеÄÕ½ÂÔÖ´ÐÐȱ·¦ | δ֪ |
¶þ¡¢Ó°Ïì¹æÄ£
ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/·þÎñ/×é¼þ°üÀ¨£º
.NET Core
Azure Machine Learning
Azure Service Connector
Microsoft Bluetooth Driver
Microsoft Defender for Endpoint
Microsoft Dynamics
Microsoft Dynamics 365 Customer Voice
Microsoft Edge (Chromium-based)
Microsoft Graphics Component
Microsoft Message Queuing
Microsoft Office
Microsoft Office Publisher
Microsoft Office SharePoint
Microsoft Office Word
Microsoft PostScript Printer Driver
Microsoft Printer Drivers
Microsoft WDAC OLE DB provider for SQL
Microsoft Windows DNS
Visual Studio
Visual Studio Code
Windows Active Directory
Windows ALPC
Windows Ancillary Function Driver for WinSock
Windows Boot Manager
Windows Clip Service
Windows CNG Key Isolation Service
Windows Common Log File System Driver
Windows DHCP Server
Windows Enroll Engine
Windows Error Reporting
Windows Group Policy
Windows Internet Key Exchange (IKE) Protocol
Windows Kerberos
Windows Kernel
Windows Layer 2 Tunneling Protocol
Windows Lock Screen
Windows Netlogon
Windows Network Address Translation (NAT)
Windows Network File System
Windows Network Load Balancing
Windows NTLM
Windows PGM
Windows Point-to-Point Protocol over Ethernet (PPPoE)
Windows Point-to-Point Tunneling Protocol
Windows Raw Image Extension
Windows RDP Client
Windows Registry
Windows RPC API
Windows Secure Boot
Windows Secure Channel
Windows Secure Socket Tunneling Protocol (SSTP)
Windows Transport Security Layer (TLS)
Windows Win32K
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£
£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϰ취ÊÖ¶¯¾ÙÐиüУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£
4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£
2023Äê4ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/releaseNote/2023-Apr
²¹¶¡ÏÂÔØÊ¾Àý£º
1.·¿ªÉÏÊöÏÂÔØÁ´½Ó£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£

Àý1£ºÎ¢ÈíÎó²îÁÐÌåÏÖÀý£¨2022Äê2Ô£©
2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿Ñ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬µã»÷ÓҲࡾÏÂÔØ¡¿´¦·¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý
3.µã»÷¡¾Çå¾²¸üС¿£¬·¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öá£

Àý3£º²¹¶¡ÏÂÔØ½çÃæ
4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£
3.2 ÔÝʱ²½·¥
Õë¶ÔCVE-2023-28252£¬¿É²Î¿¼ÒÔÏÂÁ´½Ó»ñ¸ü¶àÎó²îÐÅÏ¢¼°IoC£º
https://securelist.com/nokoyawa-ransomware-attacks-with-windows-zero-day/109483/
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔ̽«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£
3.4 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2023-Apr
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28252
https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2023-patch-tuesday-fixes-1-zero-day-97-flaws/
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-04-12 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ×ðÁú¿Ê±¼ò½é
×ðÁú¿Ê±½¨ÉèÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Çå¾²·þÎñ½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°×ðÁú¿Ê±´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬×ðÁú¿Ê±ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£
5.2 ¹ØÓÚ×ðÁú¿Ê±
×ðÁú¿Ê±Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ