<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>赛博昆仑CERT</title>
    <link>https://wechat2rss.xlab.app/feed/fb14ec6353e6ebbeb470d35d633471d0bca583a0.xml</link>
    <description>快速响应高危漏洞和安全事件，并为客户提供闭环的解决方案。&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (赛博昆仑CERT)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM6NHkvo8rOgmiblykxMalSJvibiaIsHDth5vpOggWARkLAYg/0</url>
      <title>赛博昆仑CERT</title>
      <link>https://wechat2rss.xlab.app/feed/fb14ec6353e6ebbeb470d35d633471d0bca583a0.xml</link>
    </image>
    <item>
      <title>【补丁日速递】2026年4月微软补丁日安全风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247485007&amp;idx=1&amp;sn=efc05c91c8b6ed846ad1c6df2dcffe2d</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>赛博昆仑CERT</span> <span>2026-04-15 09:43</span> <span style="display: inline-block;">广东</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=bd62fae2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Fn8iag6r4WbSbNDiaNX6RPaMRziaQ70TTV2kxgD3icc3olDVrvyCbce0jXiau3gib8aZu8ibNOVZEeRqXFfHvoplBHiaZKyWpuUXrWH7xpb4WFPM4al4%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="margin-bottom: 0px;text-align: center;"><span leaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="100000902" data-ratio="0.264" data-s="300,640" data-w="750" data-type="gif" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></span></p><div powered-by="xiumi.us" style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞安全风险通告-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p><span leaf="">2026年4月微软补丁日安全风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" data-imgfileid="100000893" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></span></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong></p><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">近日，赛博昆仑CERT监测到微软发布了2026年4月安全更新，总共修复了165个漏洞，高危漏洞154个，严重漏洞8个，中危漏洞2个，低危漏洞1个。本月昆仑实验室研究员共协助微软修复了2个安全漏洞</span><span leaf="">。</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="">CVE-2026-33822 wh1tc@Kunlun lab&amp; devoke &amp; Zhiniang Peng with HUST</span></p></li><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="">CVE-2026-32197 wh1tc@Kunlun lab&amp; devoke &amp; Zhiniang Peng with HUST</span></p></li></ul><p style="margin-top: 8px;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="color: rgb(255, 255, 255);background-color: rgb(88, 136, 169);font-size: 18px;letter-spacing: 2.5px;text-decoration-style: solid;text-decoration-color: rgb(255, 255, 255);"><span leaf="">重点关注漏洞</span></span></strong></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">经过赛博昆仑CERT的分析，这里列出部分值得关注的漏洞，详细信息如下：</span></span></p><ul style="width: 577.422px;" class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><span leaf="" style="line-height: 1.6em;text-indent: 0em;text-align: left;font-weight: bold;text-wrap: wrap;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2026-32201 Microsoft SharePoint Server 欺骗漏</span><span leaf="" style="line-height: 1.6em;text-indent: 0em;text-align: left;font-weight: bold;text-wrap: wrap;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">洞</span></p><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><span leaf="" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">在野 在Microsoft Office SharePoint中发现了一个输入验证不当导致的欺骗漏洞。未经授权的攻击者可以通过网络进行欺骗攻击。成功利用此漏洞后，攻击者可以查看部分敏感信息并篡改已公开的信息，但不会限制对资源的访问或影响系统可用性。该漏洞已检测到在野利用，建议用户尽快测试并部署此更新</span></span><span leaf="" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: normal;">。</span></span></p></li><ul class="list-paddingleft-1"></ul></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><span leaf="" style="line-height: 1.6em;text-indent: 0em;text-align: left;font-weight: bold;text-wrap: wrap;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2026-32157 Remote Desktop Client 远程代码执行漏洞</span></p><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><span leaf="" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">C</span></span><span leaf="" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">riti</span></span><span leaf="" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">cal 在Remote Desktop Client中发现了一个释放后重用（Use After Free）漏洞。未经授权的攻击者可以利用此漏洞通过网络执行代码。攻击者需要控制一个恶意的远程桌面服务器，并诱使受害者使用存在漏洞的远程桌面客户端连接到该服务器，从而在客户端计算机上执行任意代码。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新</span></span><span leaf="" style="font-weight: bold;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: normal;">。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><span leaf="" style="line-height: 1.6em;text-indent: 0em;text-align: left;font-weight: bold;text-wrap: wrap;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2026</span><span leaf="" style="line-height: 1.6em;text-indent: 0em;text-align: left;font-weight: bold;text-wrap: wrap;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">-33826</span><span leaf="" style="line-height: 1.6em;text-indent: 0em;text-align: left;font-weight: bold;text-wrap: wrap;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"> Windows Active Directory 远程代码执行漏洞</span></p><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">C</span></span><span leaf="" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">ritical 在Windows Active Directory中发现了一个输入验证不当漏洞。经过身份验证的攻击者需要处于与目标系统相同的受限Active Directory域中（即相邻网络）。攻击者</span></span><span leaf="" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">可以通过向RPC主机发送特制的RPC调用来触发该漏洞，从而在服务器端以RPC服务的同等权限执行远程代码。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新。</span></span></span></strong></span></strong></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><strong><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="line-height: 1.6em;text-indent: 0em;text-align: left;font-weight: bold;text-wrap: wrap;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2026-23666 .NET Framework 拒绝服务漏洞</span></strong></strong></p><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">Critical 在.NET Framework中发现了一个因共享资源同步不当导致的竞争条件漏洞。未经身份验证的攻击者可以通过网络触发此漏洞，从而导致目标系统拒绝服务。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更</span></span><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">新。</span></span></span></strong></span></strong></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><span leaf="" style="line-height: 1.6em;text-indent: 0em;text-align: left;font-weight: bold;text-wrap: wrap;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2026-32190 Microsoft Office 远程代码执行漏洞</span></p><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">Critical 在Microsoft Office中发现了一个释放后重用（Use After Free）漏洞。未经授权的攻击者可以利用此漏洞在本地执行任意代码。虽然名称中包含“远程”，但实际攻击需要在本地上下文中执行，攻击者需要诱骗用户在本地打开特制文件来触发此漏洞。值得注意的是，预览窗格（Preview Pane）也是此漏洞的攻击向量。该漏洞尚未检测到在野利用，建议用户尽快测试并部署此更</span></span><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">新。</span></span></span></strong></span></strong></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><span leaf="" style="line-height: 1.6em;text-indent: 0em;text-align: left;font-weight: bold;text-wrap: wrap;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2026-33114 Microsoft Word 远程代码执行漏</span><strong><strong><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="line-height: 1.6em;text-indent: 0em;text-align: left;font-weight: bold;text-wrap: wrap;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">洞</span></strong></strong></p><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">Critical在Microsoft Office Word中发现了一个不可信指针解引用漏洞。未经授权的攻击者可以利用此漏洞在本地执行任意代码。攻击者需要发送特制文件并诱骗用户将其打开以实施攻击。此外，预览窗格（Preview Pane）同样是此漏洞的一个攻击向量。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更</span></span><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">新。</span></span></span></strong></span></strong></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><span leaf="" style="line-height: 1.6em;text-indent: 0em;text-align: left;font-weight: bold;text-wrap: wrap;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2026-33115 Microsoft Word 远程代码执行漏</span><strong><strong><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="line-height: 1.6em;text-indent: 0em;text-align: left;font-weight: bold;text-wrap: wrap;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">洞</span></strong></strong></p><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">Critical 在Microsoft Office Word中发现了一个释放后重用（Use After Free）漏洞。未经授权的攻击者可以利用此漏洞在本地执行任意代码。与同类漏洞相似，攻击者可以通过诱骗用户打开特制恶意文件来触发该漏洞，且预览窗格（Preview Pane）也是此漏洞的重要攻击向量之一。该漏洞尚未检测到在野利用，建议用户尽快测试并部署此更</span></span><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">新。</span></span></span></strong></span></strong></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><span leaf="" style="line-height: 1.6em;text-indent: 0em;text-align: left;font-weight: bold;text-wrap: wrap;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2026-33827 Windows TCP/IP 远程代码执行漏洞</span></p><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">Critical在Windows TCP/IP中发现了一个因共享资源同步不当导致的竞争条件漏洞。未经身份验证的攻击者可以通过向启用了IPSec的Windows节点发送特制的IPv6数据包来利用此漏洞。成功利用此漏洞需要攻击者赢得竞争条件，并在利用前采取额外行动来准备目标环境，从而最终实现远程代码执行。该漏洞尚未检测到在野利用，建议用户尽快测试并部署此更</span></span><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">新。</span></span></span></strong></span></strong></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><span leaf="" style="line-height: 1.6em;text-indent: 0em;text-align: left;font-weight: bold;text-wrap: wrap;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions 远程代码执行漏洞</span></p><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">Critical 在Windows Internet Key Exchange (IKE) Service Extensions中发现了一个双重释放（Double Free）漏洞。未经身份验证的远程攻击者可以通过向启用了IKEv2（Internet Key Exchange version 2）的Windows系统发送特制数据包来利用此漏洞，从而在无需用户交互的情况下实现远程代码执行。该漏洞尚未检测到在野利用，但其CVSS评分高达9.8，威胁极大，建议用户尽快测试并部署此更</span></span><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="font-weight: bold;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span textstyle="" style="font-weight: normal;">新。</span></span></span></strong></span></strong></p></li></ul><p style="margin-top: 8px;margin-bottom: 0px;text-indent: 0em;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">修复建议</span></strong></strong></p><p style="margin-bottom: 0px;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">目前，官方已发布安全补丁，建议受影响的用户尽快升级至安全版本。</span></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">April 2026 Security Updates</span></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf=""><a href="https://msrc.microsoft.com/update-guide/releaseNote/" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/</a></span><span leaf="">2026-Apr</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">技术业务咨询</span></strong></strong></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">     赛博昆仑作为微软主动保护计划（Microsoft Active Protections Program，MAPP）的合作伙伴，可以获得微软最新的高级网络威胁信息和相关防御手段、技术的分享，在微软每月安全更新公开发布之前更早地获取漏洞信息，并对赛博昆仑-洞见平台及时进行更新，为客户提供更迅速有效的安全防护。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">同时，赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">联系邮箱：cert@cyberkl.com</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 2em;text-align: left;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 0em;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.694672131147541" data-s="300,640" data-type="png" data-w="976" style="text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;" data-imgfileid="100000904" src="https://wechat2rss.xlab.app/img-proxy/?k=437a2a36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FiaZ7t7b9DodueF1wjNpGZTibLmDnuUaJMXxnQThkJWfnlv7vlX9nlbHfFMRYxbq9KU0ORNTiaLxGQFzZ1FrCjn1aQ%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">参考链接</span></strong></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><span style="background-color: rgb(255, 255, 255);color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">    <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Apr" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2026-Apr</a></span></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">时间线</span></strong></strong></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-align: left;line-height: normal;text-indent: 0em;"><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">2026年4月15日</span><span leaf="">，微软官方发布安全通告</span></span><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf=""><br/></span><span leaf="">2026年4月15日</span><span leaf="">，赛博昆仑CERT发布安全风险通告</span></span></p><div style="margin-bottom: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><div style="padding-right: 20px;padding-left: 20px;font-size: 14px;letter-spacing: 1.8px;line-height: 1.9;color: rgb(91, 91, 91);"><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" data-imgfileid="100000901" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=03361454&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247485007%26idx%3D1%26sn%3Defc05c91c8b6ed846ad1c6df2dcffe2d">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 15 Apr 2026 09:43:00 +0800</pubDate>
    </item>
    <item>
      <title>【复现】泛微 E-cology10 远程代码执行漏洞风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247485002&amp;idx=1&amp;sn=072c5de7c403232e7fed4bc330c7de1e</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>赛博昆仑CERT</span> <span>2026-03-16 17:17</span> <span style="display: inline-block;">广东</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b55b7f7d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Fn8iag6r4WbSZARYj5QIcCZt0EXNTYPzuNs1ic9OchVUEsPGEIg9YqKZOMvPBibRsq5QEkEDf5w99BnC90tDWWzOpavpgGWYWT37BUvuAhzIMZM%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="text-align: center;margin-bottom: 0px;" nodeleaf="" data-pm-slice="0 0 []"><img class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="100001233" data-ratio="0.264" data-s="300,640" data-w="750" data-type="gif" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></p><div powered-by="xiumi.us" style="margin-bottom: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞</span></span><span style="letter-spacing: 2.2px;"><span leaf="">安全风险通告</span></span><span style="letter-spacing: 2.2px;"><span leaf="">-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2.8px;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf="">泛微 E-cology10 远程代码执行漏洞风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" data-imgfileid="100001231" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    泛微Ecology是由上海泛微网络科技股份有限公司开发的一套企业级协同管理与办公自动化(OA)平台，其中Ecology10是其新一代协同管理平台产品，广泛应用于政府机关、企事业单位等场景，用于流程审批、知识管理、门户建设及移动办公等业务。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">   近日，赛博昆仑CERT监测Ecology10存在远程代码执行漏洞。未经过身份的攻击者可以利用该漏洞在Ecology10服务器上执行任意代码，获取系统权限，窃取或篡改业务数据，进一步控制整个OA平台，严重威胁企业核心业务安全</span><span leaf="">。</span></span></p><table><tbody><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;word-break: break-all;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞名称</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 14px;">泛微 E-cology10 远程代码执行漏洞</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞公开编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 14px;">暂无</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">昆仑漏洞库编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">CYKL-2026-031151</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞类型</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">代码执行</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">公开时间</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 14px;">2026-3-12</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞等级</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">高危</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">评分</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 14px;">9</span></span><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 14px;">.8</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞所需权限</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">无权限要求</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞利用难度</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 14px;">低</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">PoC</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">EXP</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞细节</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">在野利用</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td></tr></tbody></table><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">影响范围</span></strong></strong></p><p style="margin-right: 0pt;margin-left: 0pt;padding: 0pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:12.0000pt;mso-font-kerning:1.0000pt;"><font face="宋体"><span leaf="">泛微</span></font><span leaf=""> Ecology10</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">&lt; v20260312安全补丁之前的版本</span></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">漏洞复现</span></strong></strong></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.49166666666666664" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100001351" src="https://wechat2rss.xlab.app/img-proxy/?k=417657a2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2Fn8iag6r4WbSbrwZtO7rOIk6gaSNp8kZXfo9JsRpKsb479aSZmygFrJA2gYoGic6ZKjclFBwk9MbZNMHfUxuNdJltfibWjfpvM6UPvt8HWrw7qE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">防护措施</span></strong></p><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);width: 577.599px;letter-spacing: 0.578px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);line-height: 1.6em;text-align: left;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 0em;color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;letter-spacing: 0.034em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">修复建议</span></span></strong></p></li></ul><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><span leaf="">目前，官方已发布修复建议，建议受影响的用户尽快联系厂商下载更新补丁。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.6em;text-align: left;text-indent: 2em;"><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-align: left;text-indent: 0em;font-weight: bold;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">技术业务咨询</span></span></strong></p></li></ul></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;"><span leaf="">赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">赛博昆仑CERT已开启年订阅服务，付费客户(可申请试用)将获取更多技术详情，并支持适配客户的需求。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">联系邮箱：</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">cert@cyberkl.com</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">时间线</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><span leaf="">    2026年3月12日，官方发布补丁</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;text-align: left;"><span leaf="">    2026年3月16日，赛博昆仑CERT发布漏洞风险通告</span></span></p><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="margin-bottom: 10px;text-align: center;"><strong><span leaf="">技术业务咨询</span></strong></p><p style="text-align: center;"><span leaf="">邮箱：cert@cyberkl.com</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" data-imgfileid="100001234" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></p></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=08d87c4b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247485002%26idx%3D1%26sn%3D072c5de7c403232e7fed4bc330c7de1e">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 16 Mar 2026 17:17:00 +0800</pubDate>
    </item>
    <item>
      <title>【补丁日速递】2026年3月微软补丁日安全风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484997&amp;idx=1&amp;sn=2f619c3f29fd2e1d7e176e77facd4b8e</link>
      <description></description>
      <content:encoded><![CDATA[<p><span>赛博昆仑CERT</span> <span>2026-03-11 09:40</span> <span style="display: inline-block;">广东</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=befc2040&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Fn8iag6r4WbSbE99eQvdSVs7bpoo6loREPvmMibznQJmVT2y6Cu4UaraticORd5QR5EmRiaic1GuyIcEiaC4daicfsq7azrKnj9U74R2DOOogBYpgiaY%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="margin-bottom: 0px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.264" data-s="300,640" data-type="gif" data-w="750" data-imgfileid="100000902" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></span></p><div powered-by="xiumi.us" style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞安全风险通告-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p><span leaf="">2026年3月微软补丁日安全风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" data-imgfileid="100000893" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></span></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong></p><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">近日，赛博昆仑CERT监测到微软发布了2026年3月安全更新，涉及以下应用：</span></span></p><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;"><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">Windows,Azure,Microsoft Office,Microsoft Authenticator for IOS</span></p><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;"><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">总共修复了83个漏洞，高危漏洞75个，严重漏洞8个。</span></p><p style="margin-top: 8px;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="color: rgb(255, 255, 255);background-color: rgb(88, 136, 169);font-size: 18px;letter-spacing: 2.5px;text-decoration-style: solid;text-decoration-color: rgb(255, 255, 255);"><span leaf="">重点关注漏洞</span></span></strong></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">经过赛博昆仑CERT的分析，这里列出部分值得关注的漏洞，详细信息如下：</span></span></p><ul style="width: 577.422px;" class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><strong><span leaf="" style="font-weight: bold;text-wrap: wrap;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2026-26113 Microsoft Office 远程代码执行漏洞</span></strong></strong></p><div style="line-height: 1.6em;text-align: left;text-indent: 2em;"><p><span leaf="" style="line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;">严重 在Microsoft Office中发现了一个不可信指针解引用漏洞。未经授权的攻击者可以利用此漏洞在本地执行代码。尽管被归类为远程代码执行漏洞，但攻击实际上是在本地进行的，这意味着攻击者需要诱骗受害者在本地计算机上执行代码来触发该漏洞。预览窗格也是此漏洞的攻击向量。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></p></div></li></ul><ul style="width: 577.422px;" class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><div style="line-height: 1.6em;text-align: left;text-indent: 2em;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><span leaf="" style="font-weight: bold;text-wrap: wrap;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2026-26110 Microsoft Office 远程代码执行漏洞</span></p><p><span leaf="" style="line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;">严重 在Microsoft Office中发现了一个类型混淆漏洞。未经授权的攻击者可以利用此漏洞在本地执行代码。尽管漏洞名称包含“远程”，但攻击实际上需要受害者在本地计算机上执行特定代码才能触发。预览窗格也是此漏洞的攻击向量。该漏洞尚未检测到在野利用，且利用可能性较低，建议用户尽快测试并部署此更新。</span></p></div></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><span leaf="" style="font-weight: bold;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2026-26144 Microsoft Excel 信息泄露漏洞</span></p><p><span leaf="" style="line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;">严重 在</span><span leaf="" style="line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;">Microsoft Excel中发现了一个输入未正确处理（跨站脚本）漏洞。未经身份验证的远程攻击者可</span><span leaf="" style="line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;">以通过网络泄露敏感信息。成功利用此漏洞可能导致Copilot Agent模式通过意外的网络出口外发数据，从而实现零点击的信息泄露攻击。需要注意的是，预览窗格不是此漏洞的攻击向量。该漏洞尚未检测到在野利用，且利用可能性较低，建议用户尽快测试并部署此更新。</span></p></li></ul><p style="margin-top: 8px;margin-bottom: 0px;text-indent: 0em;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">修复建议</span></strong></strong></p><p style="margin-bottom: 0px;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">目前，官方已发布安全补丁，建议受影响的用户尽快升级至安全版本。</span></span></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;letter-spacing:1.8px;">      March 2026 Security Updates</span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf=""><a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Ma" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2026-Ma</a></span><span leaf="">r</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">技术业务咨询</span></strong></strong></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">     赛博昆仑作为微软主动保护计划（Microsoft Active Protections Program，MAPP）的合作伙伴，可以获得微软最新的高级网络威胁信息和相关防御手段、技术的分享，在微软每月安全更新公开发布之前更早地获取漏洞信息，并对赛博昆仑-洞见平台及时进行更新，为客户提供更迅速有效的安全防护。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">同时，赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">联系邮箱：cert@cyberkl.com</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 2em;text-align: left;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 0em;text-align: center;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100000904" data-ratio="0.694672131147541" data-s="300,640" style="text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;" data-type="png" data-w="976" src="https://wechat2rss.xlab.app/img-proxy/?k=437a2a36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FiaZ7t7b9DodueF1wjNpGZTibLmDnuUaJMXxnQThkJWfnlv7vlX9nlbHfFMRYxbq9KU0ORNTiaLxGQFzZ1FrCjn1aQ%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">参考链接</span></strong></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><span style="background-color: rgb(255, 255, 255);color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Ma" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2026-Ma</a></span><span leaf="">r</span></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">时间线</span></strong></strong></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-align: left;line-height: normal;text-indent: 0em;"><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">    2026年3月11日，微软官方发布安全通告</span></span><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf=""><br/></span><span leaf="">    2026年3月11日，赛博昆仑CERT发布安全风险通告</span></span></p><div style="margin-bottom: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><div style="padding-right: 20px;padding-left: 20px;font-size: 14px;letter-spacing: 1.8px;line-height: 1.9;color: rgb(91, 91, 91);"><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" data-imgfileid="100000901" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=564a0f51&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484997%26idx%3D1%26sn%3D2f619c3f29fd2e1d7e176e77facd4b8e">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 11 Mar 2026 09:40:00 +0800</pubDate>
    </item>
    <item>
      <title>【补丁日速递】2026年2月微软补丁日安全风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484992&amp;idx=1&amp;sn=9d73f9cc02f0d8c30f918865d6a4c79f</link>
      <description></description>
      <content:encoded><![CDATA[<p><span></span> <span>2026-02-11 10:40</span> <span style="display: inline-block;">广东</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d3fda290&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Fn8iag6r4WbSZB6veNPPCNkiak4icWsMjUH4T6KuL8Z2Z6aB1N6lX0ic3icLk5Zb9CymJSuasRBbw7LLJQsDyV9pv29hWczQeKeeZBQ9sNyOcEdWA%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="margin-bottom: 0px;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.264" data-s="300,640" data-type="gif" data-w="750" data-imgfileid="100000902" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></span></p><div powered-by="xiumi.us" style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞安全风险通告-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p><span leaf="">2026年2月微软补丁日安全风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" data-imgfileid="100000893" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></span></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong></p><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">近日，赛博昆仑CERT监测到微软发布了2026年2月安全更新，涉及以下应用：Windows,Azure,Microsoft Office,Microsoft Visual Studio,Visual Studio Code,Microsoft Exchange Server,Microsoft Defender for Endpoint,Microsoft .NET Framework,Power BI Report Server,Microsoft 365 Apps,Microsoft Edge,Microsoft ACI Confidential Containers,GitHub Copilot Plugin for JetBrains IDEs,Microsoft SharePoint,Office Online Server</span><span leaf="">。</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-wrap: wrap;font-size: 11pt;font-family: DengXian;color: rgb(0, 0, 0);letter-spacing: normal;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">总共修复了54个漏洞，高危漏洞51个，严重漏洞2个，中危漏洞1个。</span></span></p><ul style="width: 577.422px;letter-spacing: 0.578px;text-wrap: wrap;" class="list-paddingleft-1"></ul><p style="margin-top: 8px;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="color: rgb(255, 255, 255);background-color: rgb(88, 136, 169);font-size: 18px;letter-spacing: 2.5px;text-decoration-style: solid;text-decoration-color: rgb(255, 255, 255);"><span leaf="">重点关注漏洞</span></span></strong></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">经过赛博昆仑CERT的分析，这里列出部分值得关注的漏洞，详细信息如下：</span></span></p><ul style="width: 577.422px;" class="list-paddingleft-1"></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2026-21519 Desktop Window Manager 权限提升漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在野 在 Desktop Window Manager (DWM) 中发现了一个类型混淆（Type Confusion）漏洞。经过身份验证的攻击者可以利用此漏洞在本地提升权限。该漏洞已检测到在野利用，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2026-21533 Windows Remote Desktop Services 权限提升漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在野 在 Windows Remote Desktop Services 中发现了一个权限管理不当漏洞。经过身份验证的攻击者可以利用此漏洞在本地提升权限，从而执行未授权的操作。该漏洞已检测到在野利用，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2026-21513 MSHTML Framework 安全特性绕过漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在野 在 MSHTML Framework 中发现了一个保护机制失效漏洞。未经身份验证的攻击者可以通过网络利用此漏洞绕过安全特性。该漏洞已检测到在野利用，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2026-21510 Windows Shell 安全特性绕过漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在野 在 Windows Shell 中发现了一个安全特性绕过漏洞。攻击者可以利用此漏洞绕过 Windows SmartScreen 和 Windows Shell 的安全提示，导致恶意内容在没有用户警告或同意的情况下执行。成功利用此漏洞需要攻击者诱导用户点击恶意链接或快捷方式文件。该漏洞已检测到在野利用，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2026-21514 Microsoft Word 安全特性绕过漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在野 在 Microsoft Word 中发现了一个安全特性绕过漏洞。该漏洞允许攻击者绕过 Microsoft 365 和 Office 中用于防止易受攻击的 COM/OLE 控件执行的缓解措施。攻击者需要向用户发送恶意 Office 文件并诱导其打开。预览窗格不是此漏洞的攻击向量。该漏洞已检测到在野利用，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2026-21525 Windows Remote Access Connection Manager 拒绝服务漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在野 在 Windows Remote Access Connection Manager 中发现了一个空指针解引用漏洞。未经身份验证的攻击者可以利用此漏洞在本地导致服务拒绝（DoS）。该漏洞已检测到在野利用，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2026-23655 Microsoft ACI Confidential Containers 信息泄露漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">Critical在 Azure Compute Gallery (Microsoft ACI Confidential Containers) 中发现了一个明文存储敏感信息的漏洞。经过身份验证的攻击者可以通过网络利用此漏洞获取敏感的令牌（Tokens）和密钥（Keys）。该漏洞尚未检测到在野利用，但鉴于信息泄露的严重性，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2026-21522 Microsoft ACI Confidential Containers 权限提升漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">Critical 在 Azure Compute Gallery (Microsoft ACI Confidential Containers) 中发现了一个命令注入漏洞。经过身份验证的攻击者可以利用此漏洞在受影响的 ACI 容器上下文中执行任意命令，从而获得与被攻陷容器相同的权限。在机密容器场景中，这可能允许攻击者访问受保护环境中的敏感数据。该漏洞尚未检测到在野利用，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li></ul><p style="margin-top: 8px;margin-bottom: 0px;text-indent: 0em;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">修复建议</span></strong></strong></p><p style="margin-bottom: 0px;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">目前，官方已发布安全补丁，建议受影响的用户尽快升级至安全版本。</span></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">February 2026 Security Updates</span></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf=""><a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Feb" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2026-Feb</a></span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">技术业务咨询</span></strong></strong></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">     赛博昆仑作为微软主动保护计划（Microsoft Active Protections Program，MAPP）的合作伙伴，可以获得微软最新的高级网络威胁信息和相关防御手段、技术的分享，在微软每月安全更新公开发布之前更早地获取漏洞信息，并对赛博昆仑-洞见平台及时进行更新，为客户提供更迅速有效的安全防护。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">同时，赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">联系邮箱：cert@cyberkl.com</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 2em;text-align: left;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 0em;text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.694672131147541" data-s="300,640" data-type="png" data-w="976" style="text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;" data-imgfileid="100000904" src="https://wechat2rss.xlab.app/img-proxy/?k=437a2a36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FiaZ7t7b9DodueF1wjNpGZTibLmDnuUaJMXxnQThkJWfnlv7vlX9nlbHfFMRYxbq9KU0ORNTiaLxGQFzZ1FrCjn1aQ%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">参考链接</span></strong></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><span style="background-color: rgb(255, 255, 255);color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">    <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Feb" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2026-Feb</a></span></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">时间线</span></strong></strong></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-align: left;line-height: normal;text-indent: 0em;"><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">    2026年2月11日</span><span leaf="">，微软官方发布安全通告</span></span><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf=""><br/></span><span leaf="">    2026年2月11日</span><span leaf="">，赛博昆仑CERT发布安全风险通告</span></span></p><div style="margin-bottom: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><div style="padding-right: 20px;padding-left: 20px;font-size: 14px;letter-spacing: 1.8px;line-height: 1.9;color: rgb(91, 91, 91);"><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" data-imgfileid="100000901" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=059412cf&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484992%26idx%3D1%26sn%3D9d73f9cc02f0d8c30f918865d6a4c79f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 11 Feb 2026 10:40:00 +0800</pubDate>
    </item>
    <item>
      <title>【补丁日速递】2026年1月微软补丁日安全风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484987&amp;idx=1&amp;sn=31bf1cc1389265e12f0e7ecd6974e6b0</link>
      <description></description>
      <content:encoded><![CDATA[<p><span></span> <span>2026-01-14 10:28</span> <span style="display: inline-block;">广东</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d3fde4b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FiaZ7t7b9DodtQfdRnOQ7CvLfHDOZhNAsqhcN59iaRkSlVdeVAG0pPXUAFmVaOWOicwiaYeWia42ks3CT1icJQtI8tUcw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="margin-bottom: 0px;text-align: center;"><span leaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-aistatus="1" data-imgfileid="100000902" data-ratio="0.264" data-s="300,640" data-w="750" data-type="gif" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></span></p><div powered-by="xiumi.us" style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞安全风险通告-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p><span leaf="">2026年1月微软补丁日安全风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100000893" data-ratio="1" style="height: 18px;vertical-align: middle;width: 18px;" data-type="svg" data-w="150" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></span></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;letter-spacing:1.8px;">    近日，赛博</span><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">昆仑CERT</span><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;letter-spacing:1.8px;">监测到微软发布了2026年1月安全更新，涉及以下应用：</span></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;letter-spacing:1.8px;">Windows,Azure,Microsoft Office,Microsoft SQL Server,azl3 libtpms 0.9.6-8 on Azure Linux 3.0,Office Online Server,Microsoft SharePoint,Microsoft 365 Apps,Microsoft Edge,azl3 kernel 6.6.117.1-1 on Azure Linux 3.0等。</span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-wrap: wrap;font-size: 11pt;font-family: DengXian;color: rgb(0, 0, 0);letter-spacing: normal;text-align: left;text-indent: 2em;"><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">总共修复了112个漏洞，高危漏洞104个，严重漏洞8个。本月昆仑实验室研究员共协助微软修复了4个安全漏洞</span><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">。</span></p><ul class="list-paddingleft-1"><li><p><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">CVE-2026-20946 wh1tc@Kunlun lab&amp; devoke &amp; Zhiniang Peng with HUST</span></p></li></ul><ul class="list-paddingleft-1"><li><p><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">CVE-2026-20953 wh1tc@Kunlun lab &amp; devoke &amp; Zhiniang Peng with HUST,wh1tc@Kunlun lab &amp; devoke &amp; Zhiniang Peng with HUST</span></p></li></ul><ul class="list-paddingleft-1"><li><p><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">CVE-2026-21219 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></p></li></ul><ul class="list-paddingleft-1"><li><p><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">CVE-2026-20948 wh1tc@Kunlun lab&amp; devoke &amp; Zhiniang Peng with HUST</span></p></li></ul><p style="margin-top: 8px;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="color: rgb(255, 255, 255);background-color: rgb(88, 136, 169);font-size: 18px;letter-spacing: 2.5px;text-decoration-style: solid;text-decoration-color: rgb(255, 255, 255);"><span leaf="">重点关注漏洞</span></span></strong></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">经过赛</span><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">博昆仑CERT的分</span><span leaf="">析，这里列出部分值得关注的漏洞，详细信息如下：</span></span></p><ul style="width: 577.422px;" class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2026-20805 Desktop Window Manager 信息泄露漏洞</span></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">在野 在 Desktop Window Manager (DWM) 中发现了一个信息泄露漏洞。经过身份验证的攻击者可以利用此漏洞在本地泄露敏感信息。该漏洞已检测到在野利用，建议用户尽快测试并部署此更新</span><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">。</span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2026-20822 Windows Graphics Component 权限提升漏洞</span></span></p><p><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">严重 在 Microsoft Graphics Component 中发现了一个释放后重用（Use After Free）漏洞。经过身份验证的攻击者可以利用此漏洞在本地提升权限。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新</span><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">。</span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2026-20876 Windows Virtualization-Based Security (VBS) Enclave 权限提升漏洞</span></span></p><p><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">严重 在 Windows 基于虚拟化的安全性 (VBS) Enclave 中发现了一个堆缓冲区溢出漏洞。经过身份验证的攻击者可以利用此漏洞在本地提升权限。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新</span><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">。</span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2026-20944 Microsoft Word 远程代码执行漏洞</span></span></p><p><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">严重 在 Microsoft Word 中发现了一个越界读取漏洞。未经授权的攻击者可以利用此漏洞在本地执行代码。攻击者需要发送恶意文件并诱说服用户打开。值得注意的是，预览窗格是此漏洞的攻击向量。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新</span><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">。</span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2026-20953 Microsoft Office 远程代码执行漏洞</span></span></p><p><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">严重 在 Microsoft Office 中发现了一个释放后重用（Use After Free）漏洞。未经授权的攻击者可以利用此漏洞在本地执行代码。攻击者可以通过发送特制邮件诱导用户点击链接或打开文件。预览窗格是此漏洞的攻击向量。在最严重的电子邮件攻击场景中，攻击者可能不需要受害者打开、阅读或点击链接即可触发漏洞（零点击）。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新</span><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">。</span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2026-20955 Microsoft Excel 远程代码执行漏洞</span></span></p><p><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">严重 在 Microsoft Excel 中发现了一个不可信指针解引用漏洞。未经授权的攻击者可以利用此漏洞在本地执行代码。攻击者必须发送恶意文件并诱骗用户打开才能利用此漏洞。预览窗格不是此漏洞的攻击向量。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新</span><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">。</span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2026-20805 Desktop Window Manager 信息泄露漏洞</span></span></p><p><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">在野 在 Desktop Window Manager (DWM) 中发现了一个信息泄露漏洞。经过身份验证的攻击者可以利用此漏洞在本地泄露敏感信息。该漏洞已检测到在野利用，建议用户尽快测试并部署此更新。</span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2026-20854 Windows Local Security Authority Subsystem Service (LSASS) 远程代码执行漏洞</span></span></p><p><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">严重 在 Windows Local Security Authority Subsystem Service (LSASS) 中发现了一个释放后重用（Use After Free）漏洞。经过身份验证的攻击者（低权限即可）可以通过修改特定目录属性并提供特制数据，导致系统引用无效内存，从而通过网络执行代码。利用此漏洞具有较高的复杂度，攻击者需要预先准备目标环境。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新</span><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">。</span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2026-20952 Microsoft Office 远程代码执行漏洞</span></span></p><p><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">严重 在 Microsoft Office 中发现了一个释放后重用（Use After Free）漏洞。未经授权的攻击者可以利用此漏洞在本地执行代码。预览窗格是此漏洞的攻击向量。虽然通常需要用户交互，但在特定攻击场景下（如特制邮件），可能不需要用户交互即可在受害者机器上执行远程代码。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新</span><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">。</span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2026-20957 Microsoft Excel 远程代码执行漏洞</span></span></p><p><span leaf="" style="line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">严重 在 Microsoft Excel 中发现了一个整数下溢（Integer Underflow）漏洞。未经授权的攻击者可以利用此漏洞在本地执行代码。攻击者必须发送恶意文件并诱骗用户打开才能利用此漏洞。预览窗格不是此漏洞的攻击向量。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新。</span></p></li></ul><p style="margin-top: 8px;margin-bottom: 0px;text-indent: 0em;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">修复建议</span></strong></strong></p><p style="margin-bottom: 0px;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">目前，官方已发布安全补丁，建议受影响的用户尽快升级至安全版本。</span></span></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;letter-spacing:1.8px;">      January 2026 Security Updates</span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf=""><a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jan" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2026-Jan</a></span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">技术业务咨询</span></strong></strong></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">     赛博昆仑作为微软主动保护计划（Microsoft Active Protections Program，MAPP）的合作伙伴，可以获得微软最新的高级网络威胁信息和相关防御手段、技术的分享，在微软每月安全更新公开发布之前更早地获取漏洞信息，并对赛博昆仑-洞见平台及时进行更新，为客户提供更迅速有效的安全防护。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">同时，赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">联系邮箱：cert@cyberkl.com</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 2em;text-align: left;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 0em;text-align: center;"><span leaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100000904" data-ratio="0.694672131147541" data-s="300,640" style="text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;" data-type="png" data-w="976" src="https://wechat2rss.xlab.app/img-proxy/?k=437a2a36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FiaZ7t7b9DodueF1wjNpGZTibLmDnuUaJMXxnQThkJWfnlv7vlX9nlbHfFMRYxbq9KU0ORNTiaLxGQFzZ1FrCjn1aQ%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">参考链接</span></strong></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><span style="background-color: rgb(255, 255, 255);color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jan" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2026-Jan</a></span></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">时间线</span></strong></strong></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-align: left;line-height: normal;text-indent: 0em;"><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">    2026年1月14日，微软官方发布安全通告</span></span><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf=""><br/></span><span leaf="">    2026年1月14日，赛博昆仑CERT发布安全风险通告</span></span></p><div style="margin-bottom: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><div style="padding-right: 20px;padding-left: 20px;font-size: 14px;letter-spacing: 1.8px;line-height: 1.9;color: rgb(91, 91, 91);"><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="text-align: center;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" data-imgfileid="100000901" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=ace1aecf&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484987%26idx%3D1%26sn%3D31bf1cc1389265e12f0e7ecd6974e6b0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 14 Jan 2026 10:28:00 +0800</pubDate>
    </item>
    <item>
      <title>【复现】帆软报表export/excel SQL注入漏洞风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484979&amp;idx=1&amp;sn=837d849a59a4a707a9421f9d10cd7cb5</link>
      <description></description>
      <content:encoded><![CDATA[<p><span></span> <span>2025-12-16 18:14</span> <span style="display: inline-block;">广东</span></p>




  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d196631b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FiaZ7t7b9Dods83jicz2zEf9s0fEWHnpusEgZH5Xz44YSLib0nnm30vhXibqdo6kn8lgfAPmdnHPm7Ficib8jHC1q11Hg%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="text-align: center;margin-bottom: 0px;" nodeleaf="" data-pm-slice="0 0 []"><img data-imgfileid="100001233" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.264" data-s="300,640" data-type="gif" data-w="750" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></p><div powered-by="xiumi.us" style="margin-bottom: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞</span></span><span style="letter-spacing: 2.2px;"><span leaf="">安全风险通告</span></span><span style="letter-spacing: 2.2px;"><span leaf="">-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2.8px;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf="">帆软报表export/excel SQL注入漏洞风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;" nodeleaf=""><img data-imgfileid="100001231" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    FineReport 是一款用于报表制作，分析和展示的工具，用户通过使用 FineRep</span><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">ort 可以</span><span leaf="">轻松的构建出灵活的数据分析和报表系统，大大缩短项目周期，减少实施成本，最终解决企业信息孤岛的问题，使数据真正产生其应用价值。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">    赛博昆仑CERT监测到帆软报表存在export/excel SQL注入的漏洞情报，未经过身份认证的攻击者可以通过先获取到sessionId ，然后在export/excel路由中触发帆软报表的模板执行，当服务器存在FRDemo数据连接时，可以通过执行SQL语句写入webshell，从而获取服务器的权限。</span></p><table><tbody><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;word-break: break-all;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞名称</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">帆软报表export/excel SQL注入漏洞</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞公开编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf=""><span textstyle="" style="font-size: 13px;">暂无</span></span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">昆仑漏洞库编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144"><p><font face="宋体"><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">CYKL-2025-0128497</span></span></font></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞类型</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf=""><span textstyle="" style="font-size: 13px;">模板注入</span></span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">公开时间</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">2025-12-15</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞等级</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">高危</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">评分</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf=""><span textstyle="" style="font-size: 13px;">暂无</span></span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞所需权限</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf=""><span textstyle="" style="font-size: 13px;">无权限要求</span></span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞利用难度</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">低</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">PoC</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf=""><span textstyle="" style="font-size: 13px;">未知</span></span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">EXP</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf=""><span textstyle="" style="font-size: 13px;">未知</span></span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞细节</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf=""><span textstyle="" style="font-size: 13px;">未知</span></span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">在野利用</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf=""><span textstyle="" style="font-size: 13px;">未知</span></span></span></p></td></tr></tbody></table><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">利用条件</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><font face="微软雅黑"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">服务器存在内置的</span></font><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">FRDemo</span></font><font face="微软雅黑"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">数</span></font><font face="微软雅黑"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">据连接或</span></font></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><font face="微软雅黑"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">存在其他</span></font><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">sqlite</span></font><font face="微软雅黑"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">类型的数据连接并知道连接名称</span></font></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">影响范围</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">FineReport</span></font><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">&lt;=</span></font><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">11.5.4（2025.09.29及之前）</span></font></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">FineBI</span></font><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">&lt;=</span></font><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">7.0.4（2025.09.12及之前）</span></font></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">FineBI</span></font><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">&lt;=</span></font><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">6.1.7.3（2025.09.29及之前）</span></font></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">FineBI</span></font><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">&lt;=</span></font><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">6.0.23.2（2025.09.26及之前）</span></font></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">FineDataLink</span></font><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">&lt;=</span></font><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">5.0.4.2（2025.10.16及之前）</span></font></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">FineDataLink</span></font><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">&lt;=</span></font><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">4.2.11.2（2025.10.16及之前） </span></font></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">漏洞复现</span></strong></strong></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001328" class="rich_pages wxw-img" data-ratio="0.4925925925925926" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=6183b0b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9Dods83jicz2zEf9s0fEWHnpusEng3Wn6F1C2NkBYXfy3n78Hukdicl1TdOesrZ1I0XmkficRTibnsecRgRQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001327" data-ratio="0.5527638190954773" data-s="300,640" data-type="png" data-w="1791" type="block" style="pointer-events: initial;" src="https://wechat2rss.xlab.app/img-proxy/?k=6e01b3dd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9Dods83jicz2zEf9s0fEWHnpusEFZPrKgVxEs77WZAgcKCOy6JIMPQfXG6FRWZmq3X8zpicpCDrVxB53Bw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;background-color: rgb(255, 255, 255);"><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">缓解措施</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;" data-pm-slice="0 0 []"><span data-type="text"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">如无法升级工程，请使用以下方案进行临时规避：</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><span data-type="text"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">1. 非运维平台部署的项目：请前往单机工程节点/每个集群工程节点，进入工程/webroot/WEB-INF/lib目录，删除sqlite相关驱动，并重启工程生效</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><span data-type="text"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">2. 运维平台部署的项目，或无法删除驱动重启的项目：请管理员登录帆软应用，点击「管理系统&gt;数据连接&gt;数据连接管理」，删除自行创建的sqlite类型的数据连接，删除产品内置的sqlite类型数据连接：FRDemo、BI Demo，无需重启工程即可生效</span></span></p></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">防护措施</span></strong></p><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);width: 577.599px;letter-spacing: 0.578px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);line-height: 1.6em;text-align: left;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 0em;color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;letter-spacing: 0.034em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">修复建议</span></span></strong></p></li></ul><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><span leaf="">目前，官方已发布修复建议，</span><span leaf="" data-pm-slice="0 0 []">建议受影响的用户参考官方通告进行处置</span><span leaf="">：<a href="https://help.fanruan.com/finereport/doc-view-4833.html" target="_blank">https://help.fanruan.com/finereport/doc-view-4833.html</a></span><span leaf="">。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.6em;text-align: left;text-indent: 2em;"><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-align: left;text-indent: 0em;font-weight: bold;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">技术业务咨询</span></span></strong></p></li></ul></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;"><span leaf="">赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">赛博昆仑CERT已开启年订阅服务，付费客户(可申请试用)将获取更多技术详情，并支持适配客户的需求。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">联系邮箱：</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">cert@cyberkl.com</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><span leaf="" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;">参考链接</span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span leaf="" style="background-color: rgb(255, 255, 255);line-height: normal;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;text-align: left;">    <a href="https://help.fanruan.com/finereport/doc-view-4833.html" target="_blank">https://help.fanruan.com/finereport/doc-view-4833.html</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">时间线</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;text-align: left;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">       2025年12月15日</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="background-color: rgb(255, 255, 255);line-height: normal;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;text-align: left;">，官方更</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">新漏洞通告</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;text-align: left;"><span leaf="">       2025年12月16日，赛博昆仑CERT发布漏洞风险通告</span></span></p><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="margin-bottom: 10px;text-align: center;"><strong><span leaf="">技术业务咨询</span></strong></p><p style="text-align: center;"><span leaf="">邮箱：cert@cyberkl.com</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001234" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></p></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>


<p><a href="2247484979">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=850d7efb&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484979%26idx%3D1%26sn%3D837d849a59a4a707a9421f9d10cd7cb5">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 16 Dec 2025 18:14:00 +0800</pubDate>
    </item>
    <item>
      <title>【补丁日速递】2025年12月微软补丁日安全风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484972&amp;idx=1&amp;sn=fdf9ef53c61ce497da59c76de9e3d688</link>
      <description></description>
      <content:encoded><![CDATA[<p><span></span> <span>2025-12-10 10:05</span> <span style="display: inline-block;">广东</span></p>




  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=978b3ca7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FiaZ7t7b9DodsFNSe0NTRAQ28S2NejPSqnYK8T3oY6qxB3xXPcfCMJdMNBLk5OxQD9CW8xLiap4T7nibFuciagBs5gw%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <p style="margin-bottom: 0px;text-align: center;"><span leaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100000902" data-ratio="0.264" data-s="300,640" data-w="750" data-type="gif" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></span></p><div powered-by="xiumi.us" style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞安全风险通告-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p><span leaf="">2025年12月微软补丁日安全风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><span leaf=""><img data-imgfileid="100000893" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></span></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong></p><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">近日，赛博昆仑CERT监测到微软发布了2025年12月安全更新，涉及以下应用：</span><span leaf="">Windows,Azure,Microsoft Office,Azure Linux等</span><span leaf="">。</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-wrap: wrap;font-size: 11pt;font-family: DengXian;color: rgb(0, 0, 0);letter-spacing: normal;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">总共修复了57个漏洞，高危漏洞54个，严重漏洞2个，中危漏洞0个，低危漏洞1个。本月昆仑实验室研究员共协助微软修复了4个安全漏洞。</span></span></p><ul style="width: 577.422px;letter-spacing: 0.578px;text-wrap: wrap;" class="list-paddingleft-1"><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="">CVE-2025-62561 wh1tc in Kunlun lab &amp; devoke &amp; Zhiniang Peng with HUST</span></p></li><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="">CVE-2025-62564 wh1tc in Kunlun lab &amp; devoke &amp; Zhiniang Peng with HUST</span></p></li><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="">CVE-2025-62468 k0shl with Kunlun Lab</span></p></li><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="">CVE-2025-62556 wh1tc in Kunlun lab &amp; devoke &amp; Zhiniang Peng with HUST</span></p></li></ul><p style="margin-top: 8px;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="color: rgb(255, 255, 255);background-color: rgb(88, 136, 169);font-size: 18px;letter-spacing: 2.5px;text-decoration-style: solid;text-decoration-color: rgb(255, 255, 255);"><span leaf="">重点关注漏洞</span></span></strong></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">经过赛博昆仑CERT的分析，这里列出部分值得关注的漏洞，详细信息如下：</span></span></p><ul style="width: 577.422px;" class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2025-62221 Windows Cloud Files Mini Filter Driver 权限提升漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在野 在Windows Cloud Files Mini Filter Driver中发现了一个释放后重用（Use After Free）漏洞。经过身份验证的攻击者可以利用此漏洞在本地提升权限至SYSTEM级别。该漏洞已检测到在野利用，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2025-62554 Microsoft Office 远程代码执行漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">严重 在Microsoft Office中发现了一个类型混淆（Type Confusion）漏洞。未经授权的攻击者可以通过诱骗用户打开特制文件来在本地执行代码。预览窗格是此漏洞的一个攻击向量，在某些情况下，攻击者甚至无需用户交互即可触发漏洞。该漏洞尚未检测到在野利用，利用可能性较低，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><span leaf="" style="font-weight: bold;text-wrap: wrap;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-62557 Microsoft Office 远程代码执行漏洞</span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><span leaf="" style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;">严重 在Microsoft Office中发现了一个释放后重用（Use After Free）漏洞。未经授权的攻击者可以通过诱骗用户打开特制文件来在本地执行代码。预览窗格是此漏洞的一个攻击向量，在某些情况下，攻击者甚至无需用户交互即可触发漏洞。该漏洞尚未检测到在野利用，利用可能性较低，建议用户尽快测试并部署此更新</span></p></li></ul><p style="margin-top: 8px;margin-bottom: 0px;text-indent: 0em;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">修复建议</span></strong></strong></p><p style="margin-bottom: 0px;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">目前，官方已发布安全补丁，建议受影响的用户尽快升级至安全版本。</span></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">December 2025 Security Updates</span></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf=""><a href="https://msrc.microsoft.com/update-guide/releaseNote/2025-Dec" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2025-Dec</a></span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">技术业务咨询</span></strong></strong></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">     赛博昆仑作为微软主动保护计划（Microsoft Active Protections Program，MAPP）的合作伙伴，可以获得微软最新的高级网络威胁信息和相关防御手段、技术的分享，在微软每月安全更新公开发布之前更早地获取漏洞信息，并对赛博昆仑-洞见平台及时进行更新，为客户提供更迅速有效的安全防护。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">同时，赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">联系邮箱：cert@cyberkl.com</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 2em;text-align: left;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 0em;text-align: center;"><span leaf=""><img data-imgfileid="100000904" class="rich_pages wxw-img" data-ratio="0.694672131147541" data-s="300,640" data-type="png" data-w="976" style="text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;" src="https://wechat2rss.xlab.app/img-proxy/?k=437a2a36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FiaZ7t7b9DodueF1wjNpGZTibLmDnuUaJMXxnQThkJWfnlv7vlX9nlbHfFMRYxbq9KU0ORNTiaLxGQFzZ1FrCjn1aQ%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">参考链接</span></strong></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><span style="background-color: rgb(255, 255, 255);color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">    <a href="https://msrc.microsoft.com/update-guide/releaseNote/2025-Dec" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2025-Dec</a></span></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">时间线</span></strong></strong></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-align: left;line-height: normal;text-indent: 0em;"><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">    2025年12月10日，微软官方发布安全通告</span></span><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf=""><br/></span><span leaf="">    2025年12月10日，赛博昆仑CERT发布安全风险通告</span></span></p><div style="margin-bottom: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><div style="padding-right: 20px;padding-left: 20px;font-size: 14px;letter-spacing: 1.8px;line-height: 1.9;color: rgb(91, 91, 91);"><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="text-align: center;"><span leaf=""><img data-imgfileid="100000901" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>


<p><a href="2247484972">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2049d72c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484972%26idx%3D1%26sn%3Dfdf9ef53c61ce497da59c76de9e3d688">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 10 Dec 2025 10:05:00 +0800</pubDate>
    </item>
    <item>
      <title>【复现】React Server Components远程代码执行漏洞(CVE-2025-55182)风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484967&amp;idx=1&amp;sn=289c62bd373166618cde6703422c3454</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2025-12-05 09:46</span> <span style="display: inline-block;">广东</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=ef3a11b1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FiaZ7t7b9Dodse1nl4QPicRBRfs6GvAg4t6jdhBduCWYLsvdSQoKicavrviaSojLicevdVvLWcxDgSUla7Ox3qCz0O6w%2F0%3Fwx_fmt%3Djpeg"/></p>


<p style="text-align: center;margin-bottom: 0px;" nodeleaf="" data-pm-slice="0 0 []"><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100001233" data-ratio="0.264" data-s="300,640" data-w="750" data-type="gif" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></p><div powered-by="xiumi.us" style="margin-bottom: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞</span></span><span style="letter-spacing: 2.2px;"><span leaf="">安全风险通告</span></span><span style="letter-spacing: 2.2px;"><span leaf="">-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2.8px;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf="">React Server Components远程代码执行漏洞(CVE-2025-55182)风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;" nodeleaf=""><img data-imgfileid="100001231" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    React 是由 Meta 开源、用于构建用户界面的 JavaScript 库。其“React Server Components”（RSC）架构允许组件在服务端渲染并序列化输出，通过“Flight”协议以 JSON-like 流式格式发送到客户端，实现零客户端 JS 体积的交互体验。RSC 已被 Next.js、Shopify Hydrogen、Gatsby 5 等主流框架采用，广泛应用于电商、SaaS、内容站点。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    赛博昆仑CERT监测到React Server Components 远程代码执行漏洞(CVE-2025-55182)，由于react server反序列化rsc数据的过程中存在缺陷，未经过身份认证的攻击者可利用该漏洞执行任意代码。该漏洞影响范围较广，使用了</span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">React Server Components作为服务端组件的应用都可能受到影响，目前已确认next.js在默认条件下即可被利用。</span></span></span></p><table><tbody><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;word-break: break-all;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞名称</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2.8px;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">React Server Components远程代码执行漏洞</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞公开编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144"><p><span leaf="" data-pm-slice="1 1 [&#34;table&#34;,{&#34;interlaced&#34;:null,&#34;align&#34;:null,&#34;class&#34;:null,&#34;style&#34;:null},&#34;table_body&#34;,null,&#34;table_row&#34;,{&#34;class&#34;:null,&#34;style&#34;:&#34;height:39px;&#34;},&#34;table_cell&#34;,{&#34;colspan&#34;:3,&#34;rowspan&#34;:1,&#34;colwidth&#34;:[144,144,144],&#34;width&#34;:null,&#34;valign&#34;:null,&#34;align&#34;:null,&#34;style&#34;:&#34;font-size: 10pt;word-break: break-all;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 2.8px;background-color: rgb(255, 255, 255);visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">CV</span></span><span leaf="" data-pm-slice="1 1 [&#34;table&#34;,{&#34;interlaced&#34;:null,&#34;align&#34;:null,&#34;class&#34;:null,&#34;style&#34;:null},&#34;table_body&#34;,null,&#34;table_row&#34;,{&#34;class&#34;:null,&#34;style&#34;:&#34;height:39px;&#34;},&#34;table_cell&#34;,{&#34;colspan&#34;:3,&#34;rowspan&#34;:1,&#34;colwidth&#34;:[144,144,144],&#34;width&#34;:null,&#34;valign&#34;:null,&#34;align&#34;:null,&#34;style&#34;:&#34;font-size: 10pt;word-break: break-all;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 2.8px;background-color: rgb(255, 255, 255);visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">E-20</span></span><span leaf="" data-pm-slice="1 1 [&#34;table&#34;,{&#34;interlaced&#34;:null,&#34;align&#34;:null,&#34;class&#34;:null,&#34;style&#34;:null},&#34;table_body&#34;,null,&#34;table_row&#34;,{&#34;class&#34;:null,&#34;style&#34;:&#34;height:39px;&#34;},&#34;table_cell&#34;,{&#34;colspan&#34;:3,&#34;rowspan&#34;:1,&#34;colwidth&#34;:[144,144,144],&#34;width&#34;:null,&#34;valign&#34;:null,&#34;align&#34;:null,&#34;style&#34;:&#34;font-size: 10pt;word-break: break-all;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 2.8px;background-color: rgb(255, 255, 255);visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">25-55182</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">昆仑漏洞库编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">CYKL-2025-011829</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞类型</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">反序列化</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">公开时间</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">2025-12-4</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞等级</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">高危</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">评分</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">10</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞所需权限</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">无权限要求</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞利用难度</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">低</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">PoC</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">已知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">EXP</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞细节</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">在野利用</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td></tr></tbody></table><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">影响范围</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><span leaf="" data-pm-slice="1 1 [&#34;table&#34;,{&#34;interlaced&#34;:null,&#34;align&#34;:null,&#34;class&#34;:null,&#34;style&#34;:null},&#34;table_body&#34;,null,&#34;table_row&#34;,{&#34;class&#34;:null,&#34;style&#34;:&#34;height:39px;&#34;},&#34;table_cell&#34;,{&#34;colspan&#34;:3,&#34;rowspan&#34;:1,&#34;colwidth&#34;:[144,144,144],&#34;width&#34;:null,&#34;valign&#34;:null,&#34;align&#34;:null,&#34;style&#34;:&#34;font-size: 10pt;word-break: break-all;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 2.8px;background-color: rgb(255, 255, 255);visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">Rea</span><span leaf="" data-pm-slice="1 1 [&#34;table&#34;,{&#34;interlaced&#34;:null,&#34;align&#34;:null,&#34;class&#34;:null,&#34;style&#34;:null},&#34;table_body&#34;,null,&#34;table_row&#34;,{&#34;class&#34;:null,&#34;style&#34;:&#34;height:39px;&#34;},&#34;table_cell&#34;,{&#34;colspan&#34;:3,&#34;rowspan&#34;:1,&#34;colwidth&#34;:[144,144,144],&#34;width&#34;:null,&#34;valign&#34;:null,&#34;align&#34;:null,&#34;style&#34;:&#34;font-size: 10pt;word-break: break-all;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 2.8px;background-color: rgb(255, 255, 255);visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">ct Ser</span><span leaf="" data-pm-slice="1 1 [&#34;table&#34;,{&#34;interlaced&#34;:null,&#34;align&#34;:null,&#34;class&#34;:null,&#34;style&#34;:null},&#34;table_body&#34;,null,&#34;table_row&#34;,{&#34;class&#34;:null,&#34;style&#34;:&#34;height:39px;&#34;},&#34;table_cell&#34;,{&#34;colspan&#34;:3,&#34;rowspan&#34;:1,&#34;colwidth&#34;:[144,144,144],&#34;width&#34;:null,&#34;valign&#34;:null,&#34;align&#34;:null,&#34;style&#34;:&#34;font-size: 10pt;word-break: break-all;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 2.8px;background-color: rgb(255, 255, 255);visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">ver Components </span><span data-pm-slice="0 0 []"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">19.0.0</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><span data-pm-slice="0 0 []"><span data-pm-slice="0 0 []"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">19.1.0&lt;=</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">React Server Components&lt;=19.1.1</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><span data-pm-slice="0 0 []"><span data-pm-slice="0 0 []"><span data-pm-slice="0 0 []"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">19.2.0&lt;=</span><span data-pm-slice="0 0 []"><span data-pm-slice="0 0 []"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">React Server Components&lt;=19.2.1</span></span></span></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);" data-pm-slice="2 2 []"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">v15.0.0 &lt;=</span><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin: 0px; padding: 0px; outline: 0px; max-width: 100%; box-sizing: border-box !important; overflow-wrap: break-word !important;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Next.js&lt;=</span><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"> v15.0.4</span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">v15.1.0 &lt;=</span><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin: 0px; padding: 0px; outline: 0px; max-width: 100%; box-sizing: border-box !important; overflow-wrap: break-word !important;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Next.js &lt;=</span><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"> v15.1.8</span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">v15.2.x &lt;=</span><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin: 0px; padding: 0px; outline: 0px; max-width: 100%; box-sizing: border-box !important; overflow-wrap: break-word !important;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Next.js &lt;=</span><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"> v15.5.6</span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">v16.0.0&lt;=</span><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin: 0px; padding: 0px; outline: 0px; max-width: 100%; box-sizing: border-box !important; overflow-wrap: break-word !important;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Next.js &lt;</span><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin: 0px; padding: 0px; outline: 0px; max-width: 100%; box-sizing: border-box !important; overflow-wrap: break-word !important;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">=</span><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"> v16.0.6</span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">v14.3.0-canary.77 &lt;= </span><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin: 0px; padding: 0px; outline: 0px; max-width: 100%; box-sizing: border-box !important; overflow-wrap: break-word !important;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Next.js</span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-indent: 0em;margin-bottom: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">利用条件</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><span style="color: rgb(55, 65, 81);font-family: fontSans, &#34;fontSans Fallback&#34;, ui-sans-serif, system-ui, sans-serif, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;font-size: 14px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">无，默认条件即可利用</span></span></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">漏洞复现</span></strong></strong></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;background-color: rgb(255, 255, 255);"><span leaf="">目前，赛博昆仑CERT已成功复现</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-indent: 31.5994px;background-color: rgb(255, 255, 255);font-size: 13.3333px;letter-spacing: 0.578px;"><span leaf="">React Server Components远程代码执行漏洞，复现环境默认配置下的next.js 16.0.6</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001318" data-ratio="0.3712962962962963" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=0ba75973&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9Dodse1nl4QPicRBRfs6GvAg4t62zQLRmKJGLLFibPYdKN0j6AePLbK1Dc6ULicZYJrhQdMG5EJ501GiaibPA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001315" data-ratio="0.6222222222222222" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c0794d4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9Dodse1nl4QPicRBRfs6GvAg4t6xEjbClfGD2mBpwx5eWye7tbiaf2jRaAiaGKrMLqc2uN8Cuy7mozJ3RGw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">防护措施</span></strong></p><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);width: 577.599px;letter-spacing: 0.578px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);line-height: 1.6em;text-align: left;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 0em;color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;letter-spacing: 0.034em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">修复建议</span></span></strong></p></li></ul><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><span leaf="">目前，官方已发布修复建议，下载地址</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><span leaf=""><a href="https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components" target="_blank">https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components</a></span><span leaf="">。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.6em;text-align: left;text-indent: 2em;"><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-align: left;text-indent: 0em;font-weight: bold;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">技术业务咨询</span></span></strong></p></li></ul></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;"><span leaf="">赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">赛博昆仑CERT已开启年订阅服务，付费客户(可申请试用)将获取更多技术详情，并支持适配客户的需求。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">联系邮箱：</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">cert@cyberkl.com</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">时间线</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><span leaf="">    2025年12月4日，官方发布公告</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;text-align: left;"><span leaf="">    2025年12月5日，赛博昆仑CERT发布漏洞风险通告</span></span></p><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="margin-bottom: 10px;text-align: center;"><strong><span leaf="">技术业务咨询</span></strong></p><p style="text-align: center;"><span leaf="">邮箱：cert@cyberkl.com</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001234" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></p></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>


<p><a href="2247484967">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=96283d90&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484967%26idx%3D1%26sn%3D289c62bd373166618cde6703422c3454">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 05 Dec 2025 09:46:00 +0800</pubDate>
    </item>
    <item>
      <title>【复现】TongWeb ejbserver反序列化漏洞风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484960&amp;idx=1&amp;sn=bb4bce6fbb24e6c7d577576a1950346a</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2025-11-13 10:54</span> <span style="display: inline-block;">广东</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=034955de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FiaZ7t7b9DodvawuyUj1PsuibicyerClVlHgHuFmDywvk0rxYbKbbDXlRb3JlnHwehhtaNbzH2L9gzmfiaHoVjUjhlQ%2F0%3Fwx_fmt%3Djpeg"/></p>


<p style="text-align: center;margin-bottom: 0px;" nodeleaf="" data-pm-slice="0 0 []"><img data-imgfileid="100001233" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.264" data-s="300,640" data-type="gif" data-w="750" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></p><div powered-by="xiumi.us" style="margin-bottom: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞</span></span><span style="letter-spacing: 2.2px;"><span leaf="">安全风险通告</span></span><span style="letter-spacing: 2.2px;"><span leaf="">-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2.8px;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf="">TongWeb ejbserver反序列化漏洞风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;" nodeleaf=""><img data-imgfileid="100001231" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    TongWeb是一款全面符合Java EE、Jakarta EE最新标准规范、轻量易于使用、性能强大、具有高可靠性和高安全性的应用服务器产品，可适应各类企业应用的基础环境及多种主流应用框架，支撑从开发到生产的全应用生命周期,包括便捷的开发、随需应变的灵活部署、丰富的运行时监视、高效的管理等</span><span leaf="">。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    近日，赛博昆仑CERT监测到Tongweb ejbserver接口存在反序列化漏洞，由于默认情况下允许通过web端口访问ejbserver，并且反序列化黑白名单为空，导致未经过身份认证的攻击者可利用该漏洞在Tongweb服务器上通过反序列化执行代码，从而完全控制服务器</span><span leaf="">。</span></span></p><table><tbody><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;word-break: break-all;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞名称</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144"><p><font face="宋体"><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 14px;">TongWeb ejb</span></span></font><font face="宋体"><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 14px;">server</span></span></font><font face="宋体"><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 14px;">反序列化漏洞</span></span></font></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞公开编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">暂无</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">昆仑漏洞库编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144"><p><font face="宋体"><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 14px;">CYKL-</span></span><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 14px;">2</span></span><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 14px;">025-03264</span></span><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 14px;">2</span></span></font></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞类型</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="" style="color: rgb(0, 122, 170);">反序</span><span leaf="" style="color: rgb(0, 122, 170);">列</span><span leaf="" style="color: rgb(0, 122, 170);">化</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">公开时间</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">2025-11-05</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞等级</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">高危</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">评分</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">暂无</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞所需权限</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">无权限要求</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞利用难度</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">低</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">PoC</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">EXP</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞细节</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">在野利用</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td></tr></tbody></table><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">影响范围</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><span leaf="">7.0.0.0&lt;=TongWeb&lt;=7.0.4.9_M9</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><span leaf="">6.1.7.0&lt;=TongWeb&lt;=6.1.8.13</span></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">漏洞复现</span></strong></strong></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;background-color: rgb(255, 255, 255);"><span leaf="">目前，赛博昆仑CERT已成功复现</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-indent: 31.5994px;background-color: rgb(255, 255, 255);font-size: 13.3333px;letter-spacing: 0.578px;"><span leaf="">TongWeb ejbserver反序列化漏洞</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001309" data-ratio="0.6081474296799224" data-s="300,640" type="block" data-type="png" data-w="1031" src="https://wechat2rss.xlab.app/img-proxy/?k=31b9dbed&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9DodvawuyUj1PsuibicyerClVlHgS7QeR71BZQrjk6TOMckNPlTHywgf5fYBw7ibrjPGAxXltC48icBQTjUg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001308" data-ratio="0.2019704433497537" data-s="300,640" type="block" data-type="png" data-w="609" src="https://wechat2rss.xlab.app/img-proxy/?k=e37cfc45&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9DodvawuyUj1PsuibicyerClVlHgZUfwQaaibibyqTLlhHmP3HIN7AQ5SJxCgVaohIVOGZQzAKHM8ZHick4zg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">防护措施</span></strong></p><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);width: 577.599px;letter-spacing: 0.578px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;"><p><b style="mso-bidi-font-weight:normal;"><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:微软雅黑;mso-hansi-font-family:微软雅黑;color:rgb(31,35,41);mso-ansi-font-weight:bold;font-size:12.0000pt;"><font face="宋体"><span leaf="">缓解措施</span></font></span></b></p><p><span leaf="" style="background-color: rgb(255, 255, 255);text-align: left;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;">非必要情况不开启EJB服务</span></p></li></ul><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;">1：若应用使用了</span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;">EJB 远程服务，添加启动配置：</span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;">-D</span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;">tongejb.serialization.class.blacklist  添加反序列化黑名单</span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;">-D</span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;">tongejb.serialization.class.whitelist 添加反序列化白名单</span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><br/></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;">-Dremote.clientIp.whitelist </span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;">设置客户端IP白名单</span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;">2：</span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;">若应用没有用到 EJB 服务，添加启动配置关闭</span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;">EJB服务</span></p><p><span leaf="" style="background-color: rgb(255, 255, 255);text-align: left;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;">-Dcom.tongweb.tongejb.server.httpd.ServerServlet.activated=false 设置为false</span></p><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);width: 577.599px;letter-spacing: 0.578px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);line-height: 1.6em;text-align: left;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 0em;color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;letter-spacing: 0.034em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">修复建议</span></span></strong></p></li></ul><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><span leaf="">目前，官方已发布修复补丁，建议受影响的用户尽快安装安全补丁</span><span leaf="">。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><span leaf="">下载地址：</span></span></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:1.8px;"><a href="https://www.tongtech.com/dft/download.html" target="_blank">https://www.tongtech.com/dft/download.html</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.6em;text-align: left;text-indent: 2em;"><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-align: left;text-indent: 0em;font-weight: bold;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">技术业务咨询</span></span></strong></p></li></ul></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;"><span leaf="">赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">赛博昆仑CERT已开启年订阅服务，付费客户(可申请试用)将获取更多技术详情，并支持适配客户的需求。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">联系邮箱：</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">cert@cyberkl.com</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">时间线</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><span leaf="">2025年11月5日，官方发布公告</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;text-align: left;"><span leaf="">    2025年11月13日，赛博昆仑CERT发布漏洞风险通告</span></span></p><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="margin-bottom: 10px;text-align: center;"><strong><span leaf="">技术业务咨询</span></strong></p><p style="text-align: center;"><span leaf="">邮箱：cert@cyberkl.com</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001234" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></p></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>


<p><a href="2247484960">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a30de64d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484960%26idx%3D1%26sn%3Dbb4bce6fbb24e6c7d577576a1950346a">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 13 Nov 2025 10:54:00 +0800</pubDate>
    </item>
    <item>
      <title>【补丁日速递】2025年11月微软补丁日安全风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484953&amp;idx=1&amp;sn=f31d75170853296c6b47a9b3ab30057f</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2025-11-12 09:56</span> <span style="display: inline-block;">广东</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=be6f98b2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FiaZ7t7b9DoduCvC9nbibWvtOEza6riasEJlRJw77xyxWITR0dRbnf35SYHZx0ehay6NkmZ9v5WYz8r6ia4v64F6tdw%2F0%3Fwx_fmt%3Djpeg"/></p>


<p style="margin-bottom: 0px;text-align: center;"><span leaf=""><img data-imgfileid="100000902" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.264" data-s="300,640" data-type="gif" data-w="750" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></span></p><div powered-by="xiumi.us" style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞安全风险通告-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p><span leaf="">2025年11月微软补丁日安全风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><span leaf=""><img data-imgfileid="100000893" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></span></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong></p><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">近日，赛博昆仑CERT监测到微软发布了2025年11月安全更新，涉及以下应用：Windo</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">ws,Azure,</span><span leaf="">Microsoft Office,Microsoft Visual Studio,Nuance PowerScribe,Microsoft Dynamics,Microsoft SharePoint,Microsoft Configuration Manager,Visual Studio Code,Microsoft Edge等</span><span leaf="">。</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-wrap: wrap;font-size: 11pt;font-family: DengXian;color: rgb(0, 0, 0);letter-spacing: normal;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">总共修复了63个漏洞，高危漏洞58个，严重漏洞5个。本月昆仑实验室研究员共协助微软修复了1个安全漏洞</span><span leaf="">。</span></span></p><ul style="width: 577.422px;letter-spacing: 0.578px;text-wrap: wrap;" class="list-paddingleft-1"><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-align: left;text-indent: 0em;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2025-60727 wh1tc in Kunlun lab &amp; devoke &amp; Zhiniang Peng with HUST</span></span></p></li></ul><p style="margin-top: 8px;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="color: rgb(255, 255, 255);background-color: rgb(88, 136, 169);font-size: 18px;letter-spacing: 2.5px;text-decoration-style: solid;text-decoration-color: rgb(255, 255, 255);"><span leaf="">重点关注漏洞</span></span></strong></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">经过赛博昆仑CERT的分析，这里列出部分值得关注的漏洞，详细信息如下：</span></span></p><ul style="width: 577.422px;" class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2025-62215 Windows Kernel 权限提升漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: justify;text-indent: 2em;"><strong><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span leaf="" style="line-height: 1.6em;text-wrap: wrap;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-weight: bold;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;"><span textstyle="" style="font-weight: normal;">在野 在Windows 内核中发现了一个条件竞争漏洞。经过身份验证的攻击者可以利用此漏洞在本地提升权限。成功利用此漏洞需要攻击者赢得竞争条件，攻击成功后可以获得SYSTEM权限。该漏洞已检测到在野利用，建议用户尽快测试并部署此更新。</span></span></strong></strong></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><strong><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span leaf="">CVE-2025-62199 Microsoft Office 远程代码执行漏洞</span></strong></strong></p><p style="text-indent: 2em;text-align: justify;"><strong><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span leaf="" style="line-height: 1.6em;text-wrap: wrap;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-weight: bold;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;"><span textstyle="" style="font-weight: normal;">Critical 在Microsoft Office中发现了一个释放后重用（Use After Free）漏洞。未经授权的攻击者可以利用此漏洞在本地执行代码。攻击者可以通过诱骗用户下载并打开特制文件来利用此漏洞，预览窗格也是此漏洞的攻击向量。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新</span></span><span leaf="" style="line-height: 1.6em;text-wrap: wrap;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-weight: bold;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;"><span textstyle="" style="font-weight: normal;">。</span></span></strong></strong></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><strong><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span leaf="">CVE-2025-60716 DirectX Graphics Kernel 权限提升漏洞</span></strong></strong></p><p style="line-height: 1.6em;text-align: justify;text-indent: 2em;"><strong><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span leaf="" style="line-height: 1.6em;text-wrap: wrap;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-weight: bold;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="font-weight: normal;">Critical在Windows DirectX图形内核中发现了一个释放后重用（Use After Free）漏洞。经过身份验证的攻击者可以利用此漏洞在本地提升权限。成功利用此漏洞需要攻击者赢得竞争条件，攻击成功后可以获得SYSTEM权限。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></span></strong></strong></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><strong><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span leaf="">CVE-2025-60724 GDI+ 远程代码执行漏洞</span></strong></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span leaf="" style="line-height: 1.6em;text-align: left;text-wrap: wrap;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-weight: bold;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="font-weight: normal;">Criti</span></span><span leaf="" style="line-height: 1.6em;text-align: left;text-wrap: wrap;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-weight: bold;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="font-weight: normal;">cal 在Microsoft图形组件（GDI+）中发现了一个基于堆的缓冲区溢出漏洞。未经身份验证的远程攻击者可以利用此漏洞执行代码。在最坏的情况下，攻击者可以通过向</span></span><span leaf="" style="line-height: 1.6em;text-align: left;text-wrap: wrap;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-weight: bold;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="font-weight: normal;">解析文档的Web服务上传包含特制图元文件（metafile）的文档来触发此漏洞，且无需用户交互。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></span></strong></strong></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><strong><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span leaf="">CVE-2025-62214 Visual Studio 远程代码执行漏洞</span></strong></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span leaf="" style="line-height: 1.6em;text-align: left;text-wrap: wrap;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-weight: bold;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="font-weight: normal;">Critical 在Visual Studio中发现了一个命令注入漏洞。经过身份验证的攻击者可以利用此漏洞在本地执行代码。利用此漏洞的攻击复杂度较高，需要提示注入、Copilot Agent交互和触发构建等多个步骤，并需要用户交互。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></span></strong></strong></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><strong><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span leaf="">CVE-2025-30398 Nuance PowerScribe 360 信息泄露漏洞</span></strong></strong></p><strong><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span leaf="" style="line-height: 1.6em;text-align: left;text-wrap: wrap;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-weight: bold;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="font-weight: normal;">    Critical在Nuance PowerScribe 360中发现了一个缺少授权的漏洞。未经身份验证的攻击者可以通过向特定API端点发出调用来利用此漏洞，从而泄露敏感的PowerScribe配置设置。成功利用此漏洞需要攻击者等待用户发起连接。该漏洞尚未检测到在野利用，但利用可能性较低，建议受影响的用户联系供应商以获取更新。</span></span></strong></strong></li></ul><p style="margin-top: 8px;margin-bottom: 0px;text-indent: 0em;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">修复建议</span></strong></strong></p><p style="margin-bottom: 0px;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">目前，官方已发布安全补丁，建议受影响的用户尽快升级至安全版本。</span></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">November 2025 Security Updates</span></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf=""><a href="https://msrc.microsoft.com/update-guide/releaseNote/" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/</a></span><span leaf="">2025-Nov</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">技术业务咨询</span></strong></strong></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">     赛博昆仑作为微软主动保护计划（Microsoft Active Protections Program，MAPP）的合作伙伴，可以获得微软最新的高级网络威胁信息和相关防御手段、技术的分享，在微软每月安全更新公开发布之前更早地获取漏洞信息，并对赛博昆仑-洞见平台及时进行更新，为客户提供更迅速有效的安全防护。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">同时，赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">联系邮箱：cert@cyberkl.com</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 2em;text-align: left;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 0em;text-align: center;"><span leaf=""><img data-imgfileid="100000904" class="rich_pages wxw-img" data-ratio="0.694672131147541" data-s="300,640" data-type="png" data-w="976" style="text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;" src="https://wechat2rss.xlab.app/img-proxy/?k=437a2a36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FiaZ7t7b9DodueF1wjNpGZTibLmDnuUaJMXxnQThkJWfnlv7vlX9nlbHfFMRYxbq9KU0ORNTiaLxGQFzZ1FrCjn1aQ%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">参考链接</span></strong></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><span style="background-color: rgb(255, 255, 255);color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><a href="https://msrc.microsoft.com/update-guide/releaseNote/2025-Nov" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2025-Nov</a></span></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">时间线</span></strong></strong></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-align: left;line-height: normal;text-indent: 0em;"><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">    2025年11月12日，微软官方发布安全通告</span></span><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf=""><br/></span><span leaf="">    2025年11月12日，赛博昆仑CERT发布安全风险通告</span></span></p><div style="margin-bottom: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><div style="padding-right: 20px;padding-left: 20px;font-size: 14px;letter-spacing: 1.8px;line-height: 1.9;color: rgb(91, 91, 91);"><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="text-align: center;"><span leaf=""><img data-imgfileid="100000901" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>


<p><a href="2247484953">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e7bd5f92&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484953%26idx%3D1%26sn%3Df31d75170853296c6b47a9b3ab30057f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 12 Nov 2025 09:56:00 +0800</pubDate>
    </item>
    <item>
      <title>【复现】Windows Server Update Service远程代码执行漏洞(CVE-2025-59287)风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484948&amp;idx=1&amp;sn=f8f6b3e55768ab8d5e09d021d91da747</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2025-10-27 15:47</span> <span style="display: inline-block;">广东</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e1375e2b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FiaZ7t7b9DodtlwK95KeS9QjVCunpuLoBIeNibG4PiavwccUxnlhdKlL2ZDp4eqIUEO7w5dSMpmmllqAy54fdXgwVw%2F0%3Fwx_fmt%3Djpeg"/></p>


<p style="text-align: center;margin-bottom: 0px;" nodeleaf="" data-pm-slice="0 0 []"><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100001233" data-ratio="0.264" data-s="300,640" data-w="750" data-type="gif" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></p><div powered-by="xiumi.us" style="margin-bottom: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞</span></span><span style="letter-spacing: 2.2px;"><span leaf="">安全风险通告</span></span><span style="letter-spacing: 2.2px;"><span leaf="">-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2.8px;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf="">Windows Server Update Service远程代码执行漏洞(CVE-2025-59287)风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;" nodeleaf=""><img data-imgfileid="100001231" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    Windows Server Update Services（WSUS） 是微软提供的一款 企业级补丁集中管理系统，主要用于在 局域网环境中统一下载、分发和管理 Windows 更新（Windows Update）。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    赛博昆仑CERT监测到Windows Server Update Services远程代码执行漏洞（CVE-2025-59287）的poc已公开，未经身份验证的攻击者通过向 WSUS 服务发送恶意的请求，利用反序列化漏洞在目标系统上执行任意代码，从而完全控制受影响的系统。</span></span></p><table><tbody><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;word-break: break-all;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞名称</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144" style="font-size: 10pt;word-break: break-all;"><p><span leaf=""><span textstyle="" style="color: rgb(0, 122, 170);">Windows Server Update Service远程代码执行漏洞</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞公开编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">CVE-2025-59287</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">昆仑漏洞库编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">CYKL-2025-028997</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞类型</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">反序列化</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">公开时间</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">2025-10-14</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞等级</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">高危</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">评分</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span leaf=""><span textstyle="" style="color: rgb(0, 122, 170);">9.8</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞所需权限</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">无权限要求</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞利用难度</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span leaf=""><span textstyle="" style="color: rgb(0, 122, 170);">低</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">PoC</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">已知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">EXP</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">已知</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞细节</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">已知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">在野利用</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">已知</span></span></p></td></tr></tbody></table><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">影响范围</span></strong></strong></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;font-size:12.0000pt;"><font face="宋体"><span leaf="">Windows Server 2012 R2 (Server Core installation) &lt; 6.3.9600.22826</span></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;font-size:12.0000pt;"><font face="宋体"><span leaf="">Windows Server 2012 R2 &lt; 6.3.9600.22826</span></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;font-size:12.0000pt;"><font face="宋体"><span leaf="">Windows Server 2012 (Server Core installation) &lt; 6.2.9200.25728</span></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;font-size:12.0000pt;"><font face="宋体"><span leaf="">Windows Server 2012 &lt; 6.2.9200.25728</span></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;font-size:12.0000pt;"><font face="宋体"><span leaf="">Windows Server 2016 (Server Core installation) &lt; 10.0.14393.8524</span></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;font-size:12.0000pt;"><font face="宋体"><span leaf="">Windows Server 2016 &lt; 10.0.14393.8524</span></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;font-size:12.0000pt;"><font face="宋体"><span leaf="">Windows Server 2025 &lt; 10.0.26100.6905</span></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;font-size:12.0000pt;"><font face="宋体"><span leaf="">Windows Server 2022, 23H2 Edition (Server Core installation) &lt; 10.0.25398.1916</span></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;font-size:12.0000pt;"><font face="宋体"><span leaf="">Windows Server 2025 (Server Core installation) &lt; 10.0.26100.6905</span></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;font-size:12.0000pt;"><font face="宋体"><span leaf="">Windows Server 2022 (Server Core installation) &lt; 10.0.20348.4297</span></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;font-size:12.0000pt;"><font face="宋体"><span leaf="">Windows Server 2022 &lt; 10.0.20348.4297</span></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;font-size:12.0000pt;"><font face="宋体"><span leaf="">Windows Server 2019 (Server Core installation) &lt; 10.0.17763.7922</span></font></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;font-size:12.0000pt;"><font face="宋体"><span leaf="">Windows Server 2019 &lt; 10.0.17763.7922</span></font></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">漏洞复现</span></strong></strong></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;background-color: rgb(255, 255, 255);"><span leaf="">目前，赛博昆仑CERT已成功复现</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-indent: 31.5994px;background-color: rgb(255, 255, 255);font-size: 13.3333px;letter-spacing: 0.578px;"><span leaf="">Windows Server Update Service远程代码执行漏洞</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001297" data-ratio="0.14629629629629629" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ff87275f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9DodtlwK95KeS9QjVCunpuLoBIeiaCCnXicibXHPPUhaJvZkJAviaOWs1O7hK33G8rkKIrxslRH5ibbbtOv2w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001296" data-ratio="0.6675925925925926" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=711b99c7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9DodtlwK95KeS9QjVCunpuLoBIuO2WjVLrgHLoibl2qoHxuOMh8c6911c5icNYrBu9GQZ6vfysH6tMibfoA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">防护措施</span></strong></p><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);width: 577.599px;letter-spacing: 0.578px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);line-height: 1.6em;text-align: left;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 0em;color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;letter-spacing: 0.034em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">修复建议</span></span></strong></p></li></ul><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><span leaf="">目前，官方已发布安全补丁，建议受影响的用户尽快安装最新版本补丁。</span></span></p><p style="text-align: left;"><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;">     下载地址：</span></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:1.8px;"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287" target="_blank">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.6em;text-align: left;text-indent: 2em;"><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-align: left;text-indent: 0em;font-weight: bold;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">技术业务咨询</span></span></strong></p></li></ul></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;"><span leaf="">赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">赛博昆仑CERT已开启年订阅服务，付费客户(可申请试用)将获取更多技术详情，并支持适配客户的需求。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">联系邮箱：</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">cert@cyberkl.com</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">参考链接</span></strong></strong></p></span></p><p><span style="mso-spacerun:&#39;yes&#39;;font-family:微软雅黑;mso-bidi-font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="微软雅黑"><span leaf="" style="background-color: rgb(255, 255, 255);line-height: normal;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287" target="_blank">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287</a></span></font></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">时间线</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;text-align: left;"><span leaf="">    2025年10月27日，赛博昆仑CERT发布漏洞风险通告</span></span></p><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="margin-bottom: 10px;text-align: center;"><strong><span leaf="">技术业务咨询</span></strong></p><p style="text-align: center;"><span leaf="">邮箱：cert@cyberkl.com</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001234" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></p></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>


<p><a href="2247484948">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a98e1d22&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484948%26idx%3D1%26sn%3Df8f6b3e55768ab8d5e09d021d91da747">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 27 Oct 2025 15:47:00 +0800</pubDate>
    </item>
    <item>
      <title>【补丁日速递】2025年10月微软补丁日安全风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484942&amp;idx=1&amp;sn=c71956fc349c94d4014a71e85a42e058</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2025-10-15 09:53</span> <span style="display: inline-block;">广东</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=462251fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FiaZ7t7b9DodtkaMXpCQR90JZVLUFp9q9RibASD6icXwqwJn2scXp9bFzE7PdGKxwEib1FuXdicy2jZVo438980QEK1A%2F0%3Fwx_fmt%3Djpeg"/></p>


<p style="margin-bottom: 0px;text-align: center;"><span leaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100000902" data-ratio="0.264" data-s="300,640" data-w="750" data-type="gif" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></span></p><div powered-by="xiumi.us" style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞安全风险通告-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p><span leaf="">2025年10月微软补丁日安全风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><span leaf=""><img data-imgfileid="100000893" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></span></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong></p><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">近日，赛博昆仑CERT监测到微软发布了2025年10月安全更新，涉及以下应用：Windows,Azure,Microsoft Office,Microsoft Visual Studio,Office Online Server,Arc Enabled Servers - Azure Connected Machine Agent,ASP.NET Core,Microsoft Configuration Manager 2503,Xbox Gaming Services,PowerShell,Microsoft Mesh for Meta Quest,Microsoft Edge,Microsoft SharePoint,Microsoft Configuration Manager 2403,Remote Desktop等</span><span leaf="">。</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-wrap: wrap;font-size: 11pt;font-family: DengXian;color: rgb(0, 0, 0);letter-spacing: normal;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">总共修复了175个漏洞，高危漏洞158个，严重漏洞15个，中危漏洞2个。本月昆仑实验室研究员共协助微软修复了21个安全漏洞</span><span leaf="">。</span></span></p><ul style="width: 577.422px;letter-spacing: 0.578px;text-wrap: wrap;" class="list-paddingleft-1"></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-55701 k0shl with Kunlun Lab</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-58728 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-58732 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-58735 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-59196 k0shl with Kunlun Lab</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-59202 k0shl with Kunlun Lab</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-59277 k0shl with Kunlun Lab</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-59282 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-59290 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-53768 R4nger with CyberKunLun &amp; Zhiniang Peng with HUST</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-55326 Azure Yang with Kunlun Lab</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-58730 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-58731 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-58733 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-58734 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-58736 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-58737 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-58738 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-59193 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-59275 k0shl with Kunlun Lab</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 13px;">CVE-2025-59278 k0shl with Kunlun Lab</span></span></p></li></ul><p style="margin-top: 8px;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="color: rgb(255, 255, 255);background-color: rgb(88, 136, 169);font-size: 18px;letter-spacing: 2.5px;text-decoration-style: solid;text-decoration-color: rgb(255, 255, 255);"><span leaf="">重点关注漏洞</span></span></strong></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">经过赛博昆仑CERT的分析，这里列出部分值得关注的漏洞，详细信息如下：</span></span></p><ul style="width: 577.422px;" class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">CVE-2025-24990 Windows Agere Modem Driver 权限提升漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;" data-pm-slice="3 3 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;}]"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">在野</span> 在 Windows 自带的第三方 Agere Modem 驱动程序中发现了一个不可信指针解引用漏洞。即使调制解调器未被主动使用，经过身份验证的攻击者也可以利用此漏洞在本地提升至管理员权限。微软已在十月累积更新中移除了此驱动程序（ltmdm64.sys），这意味着依赖此驱动的传真调制解调器硬件将不再工作。该漏洞已检测到在野利用，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">CVE-2025-59230 Windows Remote Access Connection Manager 权限提升漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;" data-pm-slice="3 3 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;}]"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">在野</span> 在 Windows 远程访问连接管理器中发现了一个不正确的访问控制漏洞。经过身份验证的攻击者可以利用此漏洞在本地将权限提升至 SYSTEM 级别。该漏洞已检测到在野利用，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">CVE-2025-59234 Microsoft Office 远程代码执行漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;" data-pm-slice="3 3 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;}]"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">Critical </span>Microsoft Office 中发现了一个释放后重用漏洞。未经授权的攻击者可以通过诱骗用户打开特制文件来利用此漏洞，从而在本地执行代码。值得注意的是，预览窗格也是此漏洞的一个攻击向量。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">CVE-2025-59236 Microsoft Excel 远程代码执行漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;" data-pm-slice="3 3 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;}]"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">Critical </span>在 Microsoft Excel 中发现了一个释放后重用漏洞。未经授权的攻击者可以通过诱骗用户打开特制文件来利用此漏洞，从而在本地执行代码。与某些Office漏洞不同，预览窗格不是此漏洞的攻击向量。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></span></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">CVE-2025-49708 Microsoft Graphics Component 权限提升漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;" data-pm-slice="3 3 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;}]"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">Critical </span>在 Microsoft Graphics Component 中发现了一个释放后重用漏洞。经过身份验证的攻击者可以利用此漏洞通过网络提升权限至 SYSTEM 级别。该漏洞可导致范围变更，攻击者在获得本地 guest 虚拟机访问权限后，可以利用此漏洞攻击宿主操作系统，从而实现虚拟机逃逸。成功利用将影响在同一宿主机上运行的其他虚拟机。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">CVE-2025-59291 Confidential Azure Container Instances 权限提升漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;" data-pm-slice="3 3 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;}]"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">Critical </span>在 Confidential Azure Container Instances 中发现了一个权限提升漏洞。拥有高权限的攻击者可以诱骗系统将恶意文件共享挂载到敏感位置，从而在机密 ACI 容器内执行代码，实现从宿主机到机密容器的权限升级。为缓解此漏洞，使用机密虚拟节点的用户必须将 Helm chart 更新至 1.3012.25080101 或更高版本，并使用最低基础结构片段 SVN 为 4 重新生成机密计算环境 (CCE) 策略</span><span leaf="">。</span></span></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">CVE-2025-59292 Azure Compute Gallery 权限提升漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;" data-pm-slice="3 3 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;}]"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">Critical </span>在 Azure Compute Gallery 中发现了一个权限提升漏洞。该漏洞与机密容器实例有关，拥有高权限的攻击者可以诱骗系统将恶意文件共享挂载到敏感位置，从而实现从宿主机到机密容器的权限升级。为缓解此漏洞，使用机密虚拟节点的用户必须将 Helm chart 更新至 1.3012.25080101 或更高版本，并使用最低基础结构片段 SVN 为 4 重新生成机密计算环境 (CCE) 策略</span><span leaf="">。</span></span></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">CVE-2025-59227 Microsoft Office 远程代码执行漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;" data-pm-slice="3 3 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;}]"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">Critical </span>在 Microsoft Office 中发现了一个释放后重用漏洞。未经授权的攻击者可以通过诱骗用户打开特制文件来利用此漏洞，从而在本地执行代码。预览窗格是此漏洞的一个攻击向量。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.6em;text-indent: 0em;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;strong&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 0.578px;text-wrap: wrap;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">CVE-2025-59287 Windows Server Update Service (WSUS) 远程代码执行漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;" data-pm-slice="3 3 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;}]"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">Critical </span>在 Windows Server Update Service (WSUS) 中发现了一个不安全的反序列化漏洞。未经身份验证的远程攻击者可以发送一个特制事件，触发遗留序列化机制中的不安全对象反序列化，从而导致远程代码执行。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li></ul><p style="margin-top: 8px;margin-bottom: 0px;text-indent: 0em;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">修复建议</span></strong></strong></p><p style="margin-bottom: 0px;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">目前，官方已发布安全补丁，建议受影响的用户尽快升级至安全版本。</span></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">October 2025 Security Updates</span></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf=""><a href="https://msrc.microsoft.com/update-guide/releaseNote/2025-Oct" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2025-Oct</a></span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">技术业务咨询</span></strong></strong></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">     赛博昆仑作为微软主动保护计划（Microsoft Active Protections Program，MAPP）的合作伙伴，可以获得微软最新的高级网络威胁信息和相关防御手段、技术的分享，在微软每月安全更新公开发布之前更早地获取漏洞信息，并对赛博昆仑-洞见平台及时进行更新，为客户提供更迅速有效的安全防护。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">同时，赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">联系邮箱：cert@cyberkl.com</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 2em;text-align: left;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 0em;text-align: center;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100000904" data-ratio="0.694672131147541" data-s="300,640" style="text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;" data-type="png" data-w="976" src="https://wechat2rss.xlab.app/img-proxy/?k=437a2a36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FiaZ7t7b9DodueF1wjNpGZTibLmDnuUaJMXxnQThkJWfnlv7vlX9nlbHfFMRYxbq9KU0ORNTiaLxGQFzZ1FrCjn1aQ%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">参考链接</span></strong></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><span style="background-color: rgb(255, 255, 255);color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">    <a href="https://msrc.microsoft.com/update-guide/releaseNote/" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/</a></span></span><span style="background-color: rgb(255, 255, 255);color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">2025-Oct</span></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">时间线</span></strong></strong></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-align: left;line-height: normal;text-indent: 0em;"><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">    2025年10月15日</span><span leaf="">，微软官方发布安全通告</span></span><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf=""><br/></span><span leaf="">    2025年10月15日</span><span leaf="">，赛博昆仑CERT发布安全风险通告</span></span></p><div style="margin-bottom: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><div style="padding-right: 20px;padding-left: 20px;font-size: 14px;letter-spacing: 1.8px;line-height: 1.9;color: rgb(91, 91, 91);"><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="text-align: center;"><span leaf=""><img data-imgfileid="100000901" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>


<p><a href="2247484942">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5c49fbd2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484942%26idx%3D1%26sn%3Dc71956fc349c94d4014a71e85a42e058">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 15 Oct 2025 09:53:00 +0800</pubDate>
    </item>
    <item>
      <title>【复现】Chaos-Mesh命令注入漏洞风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484937&amp;idx=1&amp;sn=e8ce60d2db3fb999aa7309e51871c652</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2025-09-18 16:01</span> <span style="display: inline-block;">广东</span>
</p>




<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=30c21e21&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FiaZ7t7b9DodvNVv5MlNDcf5WEIe9gzzZ6aiajuPw1p3RBCoU4FrvjDsWFLUlKnAe5wicFqz5aibsK7SDjbvlnJjcjA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;margin-bottom: 0px;" nodeleaf="" data-pm-slice="0 0 []"><img data-imgfileid="100001233" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.264" data-s="300,640" data-type="gif" data-w="750" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></p><div powered-by="xiumi.us" style="margin-bottom: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞</span></span><span style="letter-spacing: 2.2px;"><span leaf="">安全风险通告</span></span><span style="letter-spacing: 2.2px;"><span leaf="">-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2.8px;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf="">Chaos-Mesh命令注入漏洞风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;" nodeleaf=""><img data-imgfileid="100001231" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong></p><p style="text-indent: 2em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;"></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    Chaos Mesh 是由 PingCAP 开源的云原生混沌工程平台，目前由云原生计算基金会（CNCF）孵化。该平台专门为 Kubernetes 环境设计，支持模拟各种故障场景，包括网络延迟、Pod 故障、存储异常等，帮助开发团队提升系统的容错性和可恢复性。Chaos Mesh 在云原生生态系统中占据重要地位，被广泛应用于微服务架构的可靠性测试</span><span leaf="">。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    赛博昆仑CERT监测到Chaos-Mesh 存在命令注入漏洞，漏洞位于 Chaos Controller Manager GraphQL 服务器中，该服务位于 10082 端口且无需经过身份认证。未经过身份认证的攻击者可通过构造恶意GraphQL 查询请求在Chaos Daemon中执行任意系统命令，由于Chaos  Daemon 的设计使其能够在集群中的任何其他 Pod 上执行任意命令，最终攻击者可能进一步完全接管整个集群。</span></span></p><table><tbody><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;word-break: break-all;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞名称</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">Chaos-Mesh命令注入漏洞</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞公开编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144"><p><font face="微软雅黑"><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">CVE-2025-59361</span></span></font></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">昆仑漏洞库编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">CYKL-2025-024087</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞类型</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">命令</span><span leaf="" style="color: rgb(0, 122, 170);">执行</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">公开时间</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">2025-09-16</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞等级</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">高危</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">评分</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">9.8</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞所需权限</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">无权限要求</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞利用难度</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">低</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">PoC</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">已知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">EXP</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞细节</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">已知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">在野利用</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td></tr></tbody></table><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">影响范围</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;">Chaos-Mesh</span><font face="宋体"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;">&lt; v2.7.3</span></font></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">漏洞复现</span></strong></strong></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001286" data-ratio="0.17391304347826086" data-s="300,640" type="block" data-type="png" data-w="828" src="https://wechat2rss.xlab.app/img-proxy/?k=595665fd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9DodvNVv5MlNDcf5WEIe9gzzZ6ibYHQKyU1Gxd4yaicxvyb3H5AibUNtUjNumW7mf3c9mCTX1d79a4SXm5A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;background-color: rgb(88, 136, 169);"></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">防护措施</span></strong></p><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);width: 577.599px;letter-spacing: 0.578px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);line-height: 1.6em;text-align: left;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 0em;color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;letter-spacing: 0.034em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">修复建议</span></span></strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span></p></li></ul><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><span leaf="">目前，官方已发布新版本，建议受影响的用户尽快升级到安全版本。</span></span></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:1.8px;">下载地址：<a href="https://github.com/chaos-mesh/chaos-mesh" target="_blank">https://github.com/chaos-mesh/chaos-mesh</a></span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.6em;text-align: left;text-indent: 2em;"><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-align: left;text-indent: 0em;font-weight: bold;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">技术业务咨询</span></span></strong></p></li></ul></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;"><span leaf="">赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">赛博昆仑CERT已开启年订阅服务，付费客户(可申请试用)将获取更多技术详情，并支持适配客户的需求。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">联系邮箱：</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">cert@cyberkl.com</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><span leaf="" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);font-weight: bold;-webkit-tap-highlight-color: transparent;outline: 0px;">参考链接</span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><font face="微软雅黑"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 31.5994px;color: rgb(91, 91, 91);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;"><a href="https://jfrog.com/blog/chaotic-deputy-critical-vulnerabilities-in-chaos-mesh-lead-to-kubernetes-cluster-takeover/" target="_blank">https://jfrog.com/blog/chaotic-deputy-critical-vulnerabilities-in-chaos-mesh-lead-to-kubernetes-cluster-takeover/</a></span></font></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><font face="微软雅黑"></font></p></div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">时间线</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;text-align: left;"><span leaf="">    2025年9月18日，赛博昆仑CERT发布漏洞风险通告</span></span></p><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="margin-bottom: 10px;text-align: center;"><strong><span leaf="">技术业务咨询</span></strong></p><p style="text-align: center;"><span leaf="">邮箱：cert@cyberkl.com</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001234" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></p></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247484937">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8a80d439&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484937%26idx%3D1%26sn%3De8ce60d2db3fb999aa7309e51871c652">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 18 Sep 2025 16:01:00 +0800</pubDate>
    </item>
    <item>
      <title>【补丁日速递】2025年9月微软补丁日安全风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484932&amp;idx=1&amp;sn=8a135f686f161c31ff696fa9728ff91d</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2025-09-10 10:41</span> <span style="display: inline-block;">广东</span>
</p>




<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b362bb94&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FiaZ7t7b9DoduIXJSpVb2uClAQ3oDDQTl57FNCNlGJWNCtvwRVRS6YHxYNDyDeM3RtjiasbGblapITiartb69UrB1w%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="margin-bottom: 0px;text-align: center;"><span leaf=""><img data-imgfileid="100000902" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.264" data-s="300,640" data-type="gif" data-w="750" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></span></p><div powered-by="xiumi.us" style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞安全风险通告-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p><span leaf="">2025年9月微软补丁日安全风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><span leaf=""><img data-imgfileid="100000893" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></span></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-align: left;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span></p><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">近日，赛博昆仑CERT监测到微软发布了2025年9月安全更新，涉及以下应用：Windows,Azure,Microsoft Office,CBL Mariner,Microsoft AutoUpda</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">te for Mac,Xbox Gaming Services,Office Online Server,Microsoft En</span><span leaf="">tra ID,Microsoft Edge ,Microsoft SQL Server,Microsoft SharePoint,Microsoft HPC Pack,Dynamics 365 FastTrack Implementation,Azure Linux,Microsoft 365 Apps</span><span leaf="">。</span></span><o:p></o:p></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-wrap: wrap;font-size: 11pt;font-family: DengXian;color: rgb(0, 0, 0);letter-spacing: normal;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">总共修复了86个漏洞，高危漏洞72个，严重漏洞13个，中危漏洞1个。本月昆仑实验室研究员共协助微软修复了13个安全漏洞</span><span leaf="">。</span></span></p><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="" style="letter-spacing:1.8px;color:rgb(91, 91, 91);font-size:14px;">CVE-2025-54111 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></p></li><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="" style="letter-spacing:1.8px;color:rgb(91, 91, 91);font-size:14px;">CVE-2025-54896 wh1tc with Kunlun Lab &amp; Zhiniang Peng with HUST </span></p></li><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="" style="letter-spacing:1.8px;color:rgb(91, 91, 91);font-size:14px;">CVE-2025-54898 wh1tc in Kunlun lab &amp; devoke &amp; Zhiniang Peng with HUST</span></p></li><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="" style="letter-spacing:1.8px;color:rgb(91, 91, 91);font-size:14px;">CVE-2025-54906 wh1tc in Kunlun lab &amp; devoke &amp; Zhiniang Peng with HUST</span></p></li><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="" style="letter-spacing:1.8px;color:rgb(91, 91, 91);font-size:14px;">CVE-2025-54913 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></p></li><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="" style="letter-spacing:1.8px;color:rgb(91, 91, 91);font-size:14px;">CVE-2025-53808 k0shl with Kunlun Lab</span></p></li><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="" style="letter-spacing:1.8px;color:rgb(91, 91, 91);font-size:14px;">CVE-2025-53810 k0shl with Kunlun Lab</span></p></li><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="" style="letter-spacing:1.8px;color:rgb(91, 91, 91);font-size:14px;">CVE-2025-54094 k0shl with Kunlun Lab</span></p></li><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="" style="letter-spacing:1.8px;color:rgb(91, 91, 91);font-size:14px;">CVE-2025-54104 k0shl with Kunlun Lab</span></p></li><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="" style="letter-spacing:1.8px;color:rgb(91, 91, 91);font-size:14px;">CVE-2025-54108 Azure Yang with Kunlun Lab</span></p></li><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="" style="letter-spacing:1.8px;color:rgb(91, 91, 91);font-size:14px;">CVE-2025-54109 k0shl with Kunlun Lab</span></p></li><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="" style="letter-spacing:1.8px;color:rgb(91, 91, 91);font-size:14px;">CVE-2025-54900 wh1tc with Kunlun lab &amp; devoke &amp; Zhiniang Peng with HUST</span></p></li><li style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf="" style="letter-spacing:1.8px;color:rgb(91, 91, 91);font-size:14px;">CVE-2025-54915 k0shl with Kunlun Lab</span></p></li></ul><p style="margin-top: 8px;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="color: rgb(255, 255, 255);background-color: rgb(88, 136, 169);font-size: 18px;letter-spacing: 2.5px;text-decoration-style: solid;text-decoration-color: rgb(255, 255, 255);"><span leaf="">重点关注漏洞</span></span></strong></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">经过赛博昆仑CERT的分析，这里列出部分值得关注的漏洞，详细信息如下：</span></span></p><ul style="width: 577.422px;" class="list-paddingleft-1"></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2025-54918 Windows NTLM 权限提升漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">严重</span> 在 Windows NTLM 中发现了一个因身份验证不当导致的权限提升漏洞。经过身份验证的攻击者可以通过网络利用此漏洞，无需用户交互即可将权限提升至SYSTEM级别。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2025-55226 Graphics Kernel 远程代码执行漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">严重</span> 在 Graphics Kernel 中发现了一个条件竞争漏洞。经过身份验证的攻击者可以通过诱骗用户打开特制文件来利用此漏洞。成功利用此漏洞需要攻击者赢得竞争条件，从而在本地执行任意代码。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2025-55228 Windows Graphics Component 远程代码执行漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">严重</span> 在 Windows Graphics Component (Win32K - GRFX) 中发现了一个条件竞争和释放后重用(UAF)漏洞。在Hyper-V环境中，已获得低权限的攻击者可以利用此漏洞，从虚拟机(guest)环境逃逸到宿主机(host)环境并执行代码。成功利用此漏洞需要攻击者赢得竞争条件。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2025-55236 Graphics Kernel 远程代码执行漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">严重</span> 在 Graphics Kernel 中发现了一个检查时间/使用时间(TOCTOU)条件竞争和类型混淆漏洞。经过身份验证的攻击者可以通过诱骗用户打开特制文件来利用此漏洞，从而在本地执行任意代码。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2025-53800 Windows Graphics Component 权限提升漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">严重</span> 在 Windows Graphics Component 中发现了一个因资源初始化不当导致的权限提升漏洞。经过身份验证的攻击者可以利用此漏洞在本地执行代码，无需用户交互即可获得SYSTEM权限。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2025-54910 Microsoft Office 远程代码执行漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">严重</span> 在 Microsoft Office 中发现了一个基于堆的缓冲区溢出漏洞。攻击者可以通过诱骗用户打开特制文件来利用此漏洞。值得注意的是，预览窗格也是一个攻击向量，这意味着仅预览恶意文件就可能触发漏洞，从而导致远程代码执行。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2025-55224 Windows Hyper-V 远程代码执行漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">严重</span> 在 Windows Hyper-V 中发现了一个由图形组件(Win32K - GRFX)中的条件竞争和释放后重用(UAF)漏洞引发的远程代码执行漏洞。攻击者可以在Hyper-V虚拟机(guest)内部利用此漏洞，成功利用后可以突破虚拟机的安全边界，在宿主机(host)上执行任意代码。成功利用此漏洞需要攻击者赢得竞争条件。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2025-53799 Windows Imaging Component 信息泄露漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">严重</span> 在 Windows Imaging Component 中发现了一个因使用未初始化资源导致的信息泄露漏洞。攻击者可以通过发送特制文件并诱骗用户打开来利用此漏洞。成功利用此漏洞可能导致攻击者读取部分堆内存。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新</span><span leaf="">。</span></span></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2025-55238 Dynamics 365 FastTrack Implementation Assets 信息泄露漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><span textstyle="" style="color: rgb(217, 33, 66);">严重</span> 在 Dynamics 365 FastTrack Implementation Assets 中发现了一个因访问控制不当导致的信息泄露漏洞。未经授权的攻击者可能利用此漏洞获取敏感信息。微软已经完全修复了这个漏洞。使用此服务的用户无需采取任何行动</span><span leaf="">。</span></span></p></li></ul><p><span style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;text-indent: 0em;"></span></p><p style="margin-top: 8px;margin-bottom: 0px;text-indent: 0em;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">修复建议</span></strong></strong></p><p style="margin-bottom: 0px;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">目前，官方已发布安全补丁，建议受影响的用户尽快升级至安全版本。</span></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">September 2025 Security Updates</span></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf=""><a href="https://msrc.microsoft.com/update-guide/releaseNote/2025-Sep" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2025-Sep</a></span></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">技术业务咨询</span></strong></strong></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">     赛博昆仑作为微软主动保护计划（Microsoft Active Protections Program，MAPP）的合作伙伴，可以获得微软最新的高级网络威胁信息和相关防御手段、技术的分享，在微软每月安全更新公开发布之前更早地获取漏洞信息，并对赛博昆仑-洞见平台及时进行更新，为客户提供更迅速有效的安全防护。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">同时，赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">联系邮箱：cert@cyberkl.com</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 2em;text-align: left;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 0em;text-align: center;"><span leaf=""><img data-imgfileid="100000904" class="rich_pages wxw-img" data-ratio="0.694672131147541" data-s="300,640" data-type="png" data-w="976" style="text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;" src="https://wechat2rss.xlab.app/img-proxy/?k=437a2a36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FiaZ7t7b9DodueF1wjNpGZTibLmDnuUaJMXxnQThkJWfnlv7vlX9nlbHfFMRYxbq9KU0ORNTiaLxGQFzZ1FrCjn1aQ%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">参考链接</span></strong><span style="background-color: rgb(255, 255, 255);color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><span style="background-color: rgb(255, 255, 255);color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">    <a href="https://msrc.microsoft.com/update-guide/releaseNote/2025-Sep" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2025-Sep</a></span></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">时间线</span></strong></strong></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-align: left;line-height: normal;text-indent: 0em;"><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">    2025年9月10日，微软官方发布安全通告</span></span></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(91, 91, 91);font-size:14px;letter-spacing:1.8px;">    2025年9月10日，赛博昆仑CERT发布安全风险通告</span></p><p><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span><span lang="EN-US"></span></p><div style="margin-bottom: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><div style="padding-right: 20px;padding-left: 20px;font-size: 14px;letter-spacing: 1.8px;line-height: 1.9;color: rgb(91, 91, 91);"><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="text-align: center;"><span leaf=""><img data-imgfileid="100000901" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247484932">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f84c7ee8&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484932%26idx%3D1%26sn%3D8a135f686f161c31ff696fa9728ff91d">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 10 Sep 2025 10:41:00 +0800</pubDate>
    </item>
    <item>
      <title>【复现】SmartBi远程代码执行漏洞风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484927&amp;idx=1&amp;sn=74121441d711a2028471851b7e19adb0</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2025-08-18 18:40</span> <span style="display: inline-block;">广东</span>
</p>




<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=10f15ac9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FiaZ7t7b9DoduYAcIA0gUjJRhCia0mudiaFQMfqbwZHN6wm9YUs8Xzqr4AcrX9hgP9dmkibSC3ayC77PUteINk4eLng%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;margin-bottom: 0px;" nodeleaf="" data-pm-slice="0 0 []"><img data-imgfileid="100001233" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.264" data-s="300,640" data-type="gif" data-w="750" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></p><div powered-by="xiumi.us" style="margin-bottom: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞</span></span><span style="letter-spacing: 2.2px;"><span leaf="">安全风险通告</span></span><span style="letter-spacing: 2.2px;"><span leaf="">-</span></span></p></div></div></div></div><p><span leaf="" style="background-color:rgb(255, 255, 255);font-family:&#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:2.8px;color:rgb(88, 136, 169);font-size:24px;">SmartBi远程代码执行漏洞风险通告</span></p><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;" nodeleaf=""><img data-imgfileid="100001231" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong></p><p style="text-indent: 2em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;"></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    SmartBi 是一款专业的企业级商业智能（BI）平台，致力于为用户提供高效、灵活的数据分析与可视化解决方案。它支持多源数据整合、自助式分析以及智能报表生成，帮助团队快速洞察业务趋势，赋能数据驱动的决策</span><span leaf="">。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    赛博昆仑CERT监测smartbi存在远程代码执行漏洞。未经过身份认证的攻击者绕过认证并调用后台接口实现远程代码执行</span><span leaf="">。</span></span></p><table><tbody><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;word-break: break-all;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞名称</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">SmartBi远程代码执行漏洞</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞公开编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">暂无</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">昆仑漏洞库编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">CYKL-2025-022190</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞类型</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">认证绕过</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">公开时间</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">2025年-8月</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞等级</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">高危</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">评分</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">9.8</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞所需权限</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">无权限要求</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞利用难度</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">低</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">PoC</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">EXP</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞细节</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">在野利用</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td></tr></tbody></table><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">影响范围</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">Smartbi &lt;= 11.0.99471.25193</span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">漏洞复现</span></strong></strong></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001276" class="rich_pages wxw-img" data-ratio="0.3731481481481482" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=b53a3787&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9DoduYAcIA0gUjJRhCia0mudiaFQhNGiaehmYSxWrmPLy7K09C0eicdyq9wh4b3FlEFJyLVwPSKlvjLYxIog%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;background-color: rgb(88, 136, 169);"></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">防护措施</span></strong></p><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);width: 577.599px;letter-spacing: 0.578px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);line-height: 1.6em;text-align: left;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 0em;color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;letter-spacing: 0.034em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">修复建议</span></span></strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span></p></li></ul><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><span leaf="">目前，官方已发布修复建议，建议受影响的用户尽快升级至安全版本。</span></span></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:1.8px;">下载地址： </span></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:1.8px;"><a href="https://www.smartbi.com.cn/patchinfo" target="_blank">https://www.smartbi.com.cn/patchinfo</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.6em;text-align: left;text-indent: 2em;"><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-align: left;text-indent: 0em;font-weight: bold;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">技术业务咨询</span></span></strong></p></li></ul></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;"><span leaf="">赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">赛博昆仑CERT已开启年订阅服务，付费客户(可申请试用)将获取更多技术详情，并支持适配客户的需求。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">联系邮箱：</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">cert@cyberkl.com</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;color: rgb(91, 91, 91);font-size: 14px;"></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">时间线</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><span leaf="">   </span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;text-align: left;"><span leaf="">    2025年8月18日，赛博昆仑CERT发布漏洞风险通告</span></span></p><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="margin-bottom: 10px;text-align: center;"><strong><span leaf="">技术业务咨询</span></strong></p><p style="text-align: center;"><span leaf="">邮箱：cert@cyberkl.com</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001234" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></p></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247484927">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e8ede08d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484927%26idx%3D1%26sn%3D74121441d711a2028471851b7e19adb0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 18 Aug 2025 18:40:00 +0800</pubDate>
    </item>
    <item>
      <title>【补丁日速递】2025年8月微软补丁日安全风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484922&amp;idx=1&amp;sn=9b7ce4e9850ff8de762b733c743cd21e</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2025-08-13 10:24</span> <span style="display: inline-block;">广东</span>
</p>




<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b31edbd3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FiaZ7t7b9DodvYZicIOXwEJVACJd3xGY1vEJIVTCevGFz9aibib9ibdVuJYUaP6eP5Fia5ibrqq0DPnJ9iaCOibjer8KrHUw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="margin-bottom: 0px;text-align: center;"><span leaf=""><img data-imgfileid="100000902" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.264" data-s="300,640" data-type="gif" data-w="750" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></span></p><div powered-by="xiumi.us" style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-color: rgb(155, 187, 209);border-top: 2px solid rgb(88, 136, 169);border-top-left-radius: 0px;border-bottom: 2px solid rgb(88, 136, 169);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 5px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;transform: translate3d(20px, 0px, 0px);"><div style="display: inline-block;width: auto;vertical-align: top;flex: 0 0 auto;align-self: flex-start;min-width: 10%;height: auto;line-height: 0;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(243, 245, 247);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="margin-right: 10px;margin-left: 10px;display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;align-self: flex-start;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(237, 248, 255);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(216, 226, 233);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div></div></div></div></div><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞安全风险通告-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p><span leaf="">2025年8月微软补丁日安全风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;border-width: 0px;height: auto;"><div powered-by="xiumi.us" style="margin-top: 2px;margin-bottom: 2px;"><p style="border-top: 1px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p><p style="margin-top: 3px;border-top: 4px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><span leaf=""><img data-imgfileid="100000893" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></span></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;"><div powered-by="xiumi.us" style="margin-top: 2px;margin-bottom: 2px;"><p style="border-top: 4px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p><p style="margin-top: 3px;border-top: 1px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div></div></div></div></div><div powered-by="xiumi.us" style="transform: perspective(0px);transform-style: flat;"><div style="transform: rotateX(180deg) rotateY(180deg);justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-color: rgb(155, 187, 209);border-top: 2px solid rgb(88, 136, 169);border-top-left-radius: 0px;border-bottom: 2px solid rgb(88, 136, 169);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 5px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;transform: translate3d(20px, 0px, 0px);"><div style="display: inline-block;width: auto;vertical-align: top;flex: 0 0 auto;align-self: flex-start;min-width: 10%;height: auto;line-height: 0;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: flex-start;"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(243, 245, 247);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div><div style="margin-right: 10px;margin-left: 10px;display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;align-self: flex-start;"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(237, 248, 255);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(216, 226, 233);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div><p powered-by="xiumi.us"><span leaf=""><br/></span></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-align: left;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;letter-spacing:1.8px;">    近日，赛博昆仑CERT监测到微软发布了2025年8月安全更新，涉及以下应用：Windows,Azure,Microsoft Office,Microsoft Visual Studio,Microsoft 365 Apps,Teams Panels,Office Online Server,Microsoft Edge,Microsoft SharePoint,CBL Mariner,Teams for D365 Guides Hololens,Teams Phones,Microsoft SQL Server,Microsoft Dynamics,Microsoft Exchange Server,Teams for D365 Remote Assist HoloLens,Azure VM,Microsoft 365 Copilot&#39;s Business Chat,Web Deploy 4.0,Microsoft Teams</span></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;letter-spacing:1.8px;">    总共修复了111个漏洞，高危漏洞91个，严重漏洞17个，中危漏洞2个，低危漏洞1个。本月昆仑实验室研究员共协助微软修复了10个安全漏洞。</span></p><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></p><ul style="width: 577.422px;letter-spacing: 0.578px;text-wrap: wrap;" class="list-paddingleft-1"></ul><ul class="list-paddingleft-1"><li><p><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">CVE-2025-50177 Azure Yang with Kunlun Lab</span></p></li><li><p><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">CVE-2025-53143 k0shl with Kunlun Lab</span></p></li><li><p><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">CVE-2025-53144 k0shl with Kunlun Lab</span></p></li><li><p><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">CVE-2025-53145 k0shl with Kunlun Lab</span></p></li><li><p><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">CVE-2025-53736 wh1tc in Kunlun lab, devoke, Zhiniang Peng with HUST,wh1tc in Kunlun lab, devoke, Zhiniang Peng with HUST</span></p></li><li><p><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">CVE-2025-53737 wh1tc in Kunlun lab &amp; devoke &amp; Zhiniang Peng with HUST</span></p></li><li><p><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">CVE-2025-53739 wh1tc in Kunlun lab, devoke &amp; Zhiniang Peng with HUST,wh1tc in Kunlun lab, devoke &amp; Zhiniang Peng with HUST</span></p></li><li><p><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">CVE-2025-50155 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></p></li><li><p><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">CVE-2025-53789 R4nger with CyberKunLun &amp; Zhiniang Peng with HUST</span></p></li><li><p><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">CVE-2025-49712 Railgun with Kunlun Lab</span></p></li></ul><p style="margin-top: 8px;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="color: rgb(255, 255, 255);background-color: rgb(88, 136, 169);font-size: 18px;letter-spacing: 2.5px;text-decoration-style: solid;text-decoration-color: rgb(255, 255, 255);"><span leaf="">重点关注漏洞</span></span></strong><span leaf=""><br/></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">经过赛博昆仑CERT的分析，这里列出部分值得关注的漏洞，详细信息如下：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-53781 Azure Virtual Machines 信息泄露漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">严重 在 Azure 虚拟机中发现了一个信息泄露漏洞。经过身份验证的攻击者可以利用此漏洞通过网络泄露敏感信息。微软已经完全修复了这个漏洞。使用此服务的用户无需采取任何行动。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-50165 Windows Graphics Component 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">Windows 图形组件中发现了一个不可信指针解引用漏洞。未经身份验证的攻击者可以通过特制的JPEG图像（可嵌入Office或其他文件中）在目标系统上远程执行代码，无需用户交互。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-50176 DirectX Graphics Kernel 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在 DirectX 图形内核中发现了一个类型混淆漏洞。任何经过身份验证的攻击者都可以利用此漏洞在本地执行代码，无需管理员权限。尽管标题为“远程代码执行”，但攻击本身是本地发起的。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-50177 Microsoft Message Queuing (MSMQ) 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在 Microsoft 消息队列 (MSMQ) 中发现了一个释放后重用（Use After Free）漏洞。未经身份验证的攻击者可以通过向 MSMQ 服务器快速发送一系列特制的 HTTP 数据包来触发竞争条件，从而在服务器端远程执行代码。此漏洞影响启用了MSMQ服务的系统。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-53731 Microsoft Office 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在 Microsoft Office 中发现了一个释放后重用（Use After Free）漏洞。未经授权的攻击者可以利用此漏洞在本地执行代码。攻击者可以通过诱使用户打开特制文件来利用此漏洞，预览窗格也是一个攻击向量。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-53733 Microsoft Word 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;" data-pm-slice="3 3 [&#34;list&#34;,{&#34;type&#34;:&#34;ul&#34;,&#34;style&#34;:&#34;width: 577.422px;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;&#34;}]"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在 Microsoft Word 中发现了一个不正确的数字类型转换漏洞。未经授权的攻击者可以利用此漏洞在本地执行代码。攻击者可以通过诱使用户打开特制 Word 文件来利用此漏洞，预览窗格也是一个攻击向量。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-53740 Microsoft Office 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在 Microsoft Office 中发现了一个释放后重用（Use After Free）漏洞。未经授权的攻击者可以利用此漏洞在本地执行代码。攻击者可以通过诱使用户打开特制文件来利用此漏洞，预览窗格也是一个攻击向量。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-53766 GDI+ 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在 Windows GDI+ 中发现了一个堆缓冲区溢出漏洞。未经身份验证的攻击者可以在无需用户交互的情况下，通过诱使用户下载并打开包含特制图元文件的文档来远程执行代码。在最坏的情况下，攻击者可以通过将此类文档上传到Web服务来触发漏洞，从而在服务器上执行代码。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></span></p></li></ul><ul class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-53778 Windows NTLM 权限提升漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在 Windows NTLM 中发现了一个身份验证不当的漏洞。经过身份验证的攻击者可以利用此漏洞通过网络将权限提升至 SYSTEM 级别。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-53784 Microsoft Word 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在 Microsoft Word 中发现了一个释放后重用（Use After Free）漏洞。未经授权的攻击者可以利用此漏洞在本地执行代码。攻击者可以通过诱使用户打开特制 Word 文件来利用此漏洞，预览窗格也是一个攻击向量。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-53793 Azure Stack Hub 信息泄露漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在 Azure Stack Hub 中发现了一个因身份验证不当和路径遍历导致的漏洞。未经身份验证的攻击者可以利用此漏洞通过网络泄露系统内部配置信息。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户按照发布说明将 Azure Stack Hub 环境更新至最新版本。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-48807 Windows Hyper-V 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在 Windows Hyper-V 中发现了一个通信通道限制不当的漏洞。位于嵌套虚拟机上的授权攻击者可以利用此漏洞，在主机管理员执行特定操作时触发竞争条件，从而从虚拟机逃逸并在作为其主机的客户机上获得管理员权限并执行代码。利用条件较为复杂，需要用户交互。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-53792 Azure Portal 权限提升漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在 Azure Portal 中发现了一个授权不当的漏洞。未经身份验证的攻击者可以利用此漏洞在网络上提升权限。微软已经完全修复了这个漏洞。使用此服务的用户无需采取任何行动。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-53767 Azure OpenAI 权限提升漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在 Azure OpenAI 中发现了一个服务器端请求伪造(SSRF)漏洞。未经身份验证的攻击者可以利用此漏洞在网络上提升权限。微软已经完全修复了这个漏洞。使用此服务的用户无需采取任何行动。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-53774 Microsoft 365 Copilot BizChat 信息泄露漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在 Microsoft 365 Copilot BizChat 中发现了一个命令注入漏洞。未经身份验证的攻击者可以利用此漏洞泄露信息或执行部分命令。微软已经完全修复了这个漏洞。使用此服务的用户无需采取任何行动。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-53787 Microsoft 365 Copilot BizChat 信息泄露漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在 Microsoft 365 Copilot BizChat 中发现了一个命令注入漏洞。未经身份验证的攻击者可以利用此漏洞泄露信息或执行部分命令。微软已经完全修复了这个漏洞。使用此服务的用户无需采取任何行动。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-49707 Azure Virtual Machines 欺骗漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">在 Azure 虚拟机中发现了一个访问控制不当的漏洞。具有高权限的授权攻击者可以利用此漏洞在本地进行欺骗攻击。微软已经完全修复了这个漏洞。使用此服务的用户无需采取任何行动。</span></span></p></li></ul><p><span style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;text-indent: 0em;"></span></p><p style="margin-top: 8px;margin-bottom: 0px;text-indent: 0em;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">修复建议</span></strong></strong></p><p style="margin-bottom: 0px;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">目前，官方已发布安全补丁，建议受影响的用户尽快升级至安全版本。</span></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></p><p style="text-indent: 2em;"><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;">August 2025 Security Updates</span></p><p style="text-indent: 2em;"><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><a href="https://msrc.microsoft.com/update-guide/releaseNote/2025-Aug" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2025-Aug</a></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">技术业务咨询</span></strong></strong></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">     赛博昆仑作为微软主动保护计划（Microsoft Active Protections Program，MAPP）的合作伙伴，可以获得微软最新的高级网络威胁信息和相关防御手段、技术的分享，在微软每月安全更新公开发布之前更早地获取漏洞信息，并对赛博昆仑-洞见平台及时进行更新，为客户提供更迅速有效的安全防护。</span><span leaf=""><br/></span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">同时，赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">联系邮箱：cert@cyberkl.com</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 2em;text-align: left;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 0em;text-align: center;"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100000904" data-ratio="0.694672131147541" data-s="300,640" style="text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;" data-type="png" data-w="976" src="https://wechat2rss.xlab.app/img-proxy/?k=437a2a36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FiaZ7t7b9DodueF1wjNpGZTibLmDnuUaJMXxnQThkJWfnlv7vlX9nlbHfFMRYxbq9KU0ORNTiaLxGQFzZ1FrCjn1aQ%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">参考链接</span></strong><span style="background-color: rgb(255, 255, 255);color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span><span style="background-color: rgb(255, 255, 255);color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><br/></span></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><span style="background-color: rgb(255, 255, 255);color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">    </span><span leaf=""><a href="https://msrc.microsoft.com/update-guide/releaseNote/2025-Aug" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2025-Aug</a></span></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">时间线</span></strong></strong><span leaf=""><br/></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-align: left;line-height: normal;text-indent: 0em;"><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">    </span><span leaf="">2025年8月13日</span><span leaf="">，微软官方发布安全通告</span></span><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf=""><br/></span><span leaf="">    </span><span leaf="">2025年8月13日</span><span leaf="">，赛博昆仑CERT发布安全风险通告</span></span><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span><span lang="EN-US"></span></p><div style="margin-bottom: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><div style="padding-right: 20px;padding-left: 20px;font-size: 14px;letter-spacing: 1.8px;line-height: 1.9;color: rgb(91, 91, 91);"><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="text-align: center;"><span leaf=""><img data-imgfileid="100000901" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></span></p><p style="text-align: center;"><span leaf=""><br/></span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247484922">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b812d499&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484922%26idx%3D1%26sn%3D9b7ce4e9850ff8de762b733c743cd21e">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 13 Aug 2025 10:24:00 +0800</pubDate>
    </item>
    <item>
      <title>【复现】契约锁文件写入致远程代码执行漏洞风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484917&amp;idx=1&amp;sn=af0cf86fe3943f11fba7eb4847c0d2da</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2025-07-11 14:08</span> <span style="display: inline-block;">广东</span>
</p>

<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=857d4b50&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FiaZ7t7b9DodvKbjn5nNAicZ9u2FgECuKCT7WEcyVGSAGCO9UcSS1L6bqfgWI2iagoV7VHp2y9Kbx1gajLvOxPHkEA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;margin-bottom: 0px;" nodeleaf="" data-pm-slice="0 0 []"><img data-imgfileid="100001233" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.264" data-s="300,640" data-type="gif" data-w="750" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></p><div powered-by="xiumi.us" style="margin-bottom: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-color: rgb(155, 187, 209);border-top: 2px solid rgb(88, 136, 169);border-top-left-radius: 0px;border-bottom: 2px solid rgb(88, 136, 169);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 5px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;transform: translate3d(20px, 0px, 0px);"><div style="display: inline-block;width: auto;vertical-align: top;flex: 0 0 auto;align-self: flex-start;min-width: 10%;height: auto;line-height: 0;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(243, 245, 247);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="margin-right: 10px;margin-left: 10px;display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;align-self: flex-start;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(237, 248, 255);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(216, 226, 233);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div></div></div></div></div><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞</span></span><span style="letter-spacing: 2.2px;"><span leaf="">安全风险通告</span></span><span style="letter-spacing: 2.2px;"><span leaf="">-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2.8px;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf="">契约锁文件写入致远程代码执行漏洞风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;border-width: 0px;height: auto;"><div powered-by="xiumi.us" style="margin-top: 2px;margin-bottom: 2px;"><p style="border-top: 1px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p><p style="margin-top: 3px;border-top: 4px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;" nodeleaf=""><img data-imgfileid="100001231" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;"><div powered-by="xiumi.us" style="margin-top: 2px;margin-bottom: 2px;"><p style="border-top: 4px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p><p style="margin-top: 3px;border-top: 1px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div></div></div></div></div><div powered-by="xiumi.us" style="transform: perspective(0px);transform-style: flat;"><div style="transform: rotateX(180deg) rotateY(180deg);justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-color: rgb(155, 187, 209);border-top: 2px solid rgb(88, 136, 169);border-top-left-radius: 0px;border-bottom: 2px solid rgb(88, 136, 169);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 5px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;transform: translate3d(20px, 0px, 0px);"><div style="display: inline-block;width: auto;vertical-align: top;flex: 0 0 auto;align-self: flex-start;min-width: 10%;height: auto;line-height: 0;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: flex-start;"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(243, 245, 247);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div><div style="margin-right: 10px;margin-left: 10px;display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;align-self: flex-start;"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(237, 248, 255);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(216, 226, 233);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div><p powered-by="xiumi.us"><span leaf=""><br/></span></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    契约锁，是一个电子签章及印章管控平台，提供的电子文件具有与纸质文件一样的法律效力。平台上签署大体的流程是：由合同发起方上传需签署的合同文档，文档会进入“契约锁”的数据库，以加密形式存储；选择好所发对象后，会通过包含链接的短信、微信等方式进行提醒，签署方点击链接后可用手机完成签名操作，或者直接用“契约锁”App端完成该流程。</span><span leaf="">    </span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    近日，赛博昆仑CERT监测契约锁存在任意文件写入漏洞。由于存在解析差异导致契约锁对zip检测的安全机制可以被绕过，未经过身份验证的攻击者可以利用该漏洞写入任意文件，并最终可以导致远程代码执行完全控制服务器</span><span leaf="">。</span></span></p><table><tbody><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;word-break: break-all;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞名称</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144"><div><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span textstyle="" style="font-size: 13px;color: rgb(0, 122, 170);">契约锁文件写入致远程代码执行漏洞</span></span></p></div></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞公开编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">暂无</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">昆仑漏洞库编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf=""><span textstyle="" style="color: rgb(0, 122, 170);">CYKL-2025-017107</span></span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞类型</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">文件写入</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">公开时间</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">2025年-7月</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞等级</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">高危</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">评分</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">暂无</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞所需权限</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">无权限要求</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞利用难度</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">低</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">PoC</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">EXP</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞细节</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">在野利用</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf=""><br/></span></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">影响范围</span></strong></strong></p><p style=""><font face="宋体"><span leaf="" style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">契</span></font><span style="background-color: rgb(255, 255, 255);-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><font face="宋体"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">约锁</span></font><font face="宋体"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">4.3.8-5.x.x 并且补丁版本 &lt; 2.1.8</span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;font-size:12.0000pt;"><o:p></o:p></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><font face="宋体"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">契约锁</span></font><font face="宋体"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;">4.0.x-4.3.7 并且补丁版本 &lt; 1.3.8</span></font></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">漏洞复现</span></strong></strong></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"></span><span style="color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;background-color: rgb(255, 255, 255);"><span leaf="">目前，赛博昆仑CERT已成功复现</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-indent: 31.5994px;background-color: rgb(255, 255, 255);font-size: 13.3333px;letter-spacing: 0.578px;"><span leaf="">契约锁文件写入致远程代码执行漏洞</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001263" data-ratio="0.4601851851851852" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8ef095c6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9DodvKbjn5nNAicZ9u2FgECuKCTjwnWtfllHiabKOyo6jGpjWicw1zX06icTKawESKRDbd9vTrOhPkW8paRA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001268" data-ratio="0.3560732113144759" data-s="300,640" type="block" data-type="png" data-w="601" src="https://wechat2rss.xlab.app/img-proxy/?k=3e71a006&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9DodvKbjn5nNAicZ9u2FgECuKCTzkskflUQ16BsW4ia8VHl6ff29HOzB2bEiaSXvh3CNX8ic2Z5InbIqI64Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><p><span leaf=""><br/></span></p></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;background-color: rgb(88, 136, 169);"></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">防护措施</span></strong></p><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);width: 577.599px;letter-spacing: 0.578px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);line-height: 1.6em;text-align: left;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 0em;color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;letter-spacing: 0.034em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">缓解措施</span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);line-height: 1.6em;text-align: left;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 0em;color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;letter-spacing: 0.034em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: normal;">非必要，避免将该系统直接暴露在互联网</span></span></span></strong></p></li><li style="-webkit-tap-highlight-color: transparent;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);line-height: 1.6em;text-align: left;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 0em;color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;letter-spacing: 0.034em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">修复建议</span></span></strong></p></li></ul><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:1.8px;">    契约锁官方已发布安全补丁，请及时更新安全补丁：</span></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:1.8px;">    下载地址：</span></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:1.8px;">    <a href="https://www.qiyuesuo.com/more/security/servicepack" target="_blank">https://www.qiyuesuo.com/more/security/servicepack</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.6em;text-align: left;text-indent: 2em;"><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-align: left;text-indent: 0em;font-weight: bold;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">技术业务咨询</span></span></strong></p></li></ul></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;"><span leaf="">赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">赛博昆仑CERT已开启年订阅服务，付费客户(可申请试用)将获取更多技术详情，并支持适配客户的需求。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">联系邮箱：</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">cert@cyberkl.com</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;color: rgb(91, 91, 91);font-size: 14px;"></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">时间线</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><span leaf="">    2025年7月，官方发布补丁</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;text-align: left;"><span leaf="">    2025年7月11日，赛博昆仑CERT发布漏洞风险通告</span></span></p><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="margin-bottom: 10px;text-align: center;"><strong><span leaf="">技术业务咨询</span></strong></p><p style="text-align: center;"><span leaf="">邮箱：cert@cyberkl.com</span></p><p style="text-align: center;"><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001234" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></p><p style="text-align: center;"><span leaf=""><br/></span></p></div><p style="background-color: rgb(255, 255, 255);"><span leaf=""><br/></span></p></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>



<p><a href="2247484917">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2387e245&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484917%26idx%3D1%26sn%3Daf0cf86fe3943f11fba7eb4847c0d2da">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 11 Jul 2025 14:08:00 +0800</pubDate>
    </item>
    <item>
      <title>【复现】泛微Ecology前台SQL注入漏洞风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484909&amp;idx=1&amp;sn=f7c17bd3c58d6e06afe0eee7178e533f</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2025-07-09 10:01</span> <span style="display: inline-block;">广东</span>
</p>

<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=c22e8e79&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FiaZ7t7b9DodsFVkuzNUGGmFexrmhVGUMaG39g1hoGo0sXvvs5iblzYkwvich2YXf019pkKCxjO5uibcqAa4cUADLGA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;margin-bottom: 0px;" nodeleaf="" data-pm-slice="0 0 []"><img data-imgfileid="100001233" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.264" data-s="300,640" data-type="gif" data-w="750" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></p><div powered-by="xiumi.us" style="margin-bottom: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-color: rgb(155, 187, 209);border-top: 2px solid rgb(88, 136, 169);border-top-left-radius: 0px;border-bottom: 2px solid rgb(88, 136, 169);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 5px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;transform: translate3d(20px, 0px, 0px);"><div style="display: inline-block;width: auto;vertical-align: top;flex: 0 0 auto;align-self: flex-start;min-width: 10%;height: auto;line-height: 0;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(243, 245, 247);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="margin-right: 10px;margin-left: 10px;display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;align-self: flex-start;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(237, 248, 255);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(216, 226, 233);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div></div></div></div></div><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞</span></span><span style="letter-spacing: 2.2px;"><span leaf="">安全风险通告</span></span><span style="letter-spacing: 2.2px;"><span leaf="">-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p><span leaf="">泛微Ecology前台SQL注入漏洞风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;border-width: 0px;height: auto;"><div powered-by="xiumi.us" style="margin-top: 2px;margin-bottom: 2px;"><p style="border-top: 1px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p><p style="margin-top: 3px;border-top: 4px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;" nodeleaf=""><img data-imgfileid="100001231" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;"><div powered-by="xiumi.us" style="margin-top: 2px;margin-bottom: 2px;"><p style="border-top: 4px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p><p style="margin-top: 3px;border-top: 1px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div></div></div></div></div><div powered-by="xiumi.us" style="transform: perspective(0px);transform-style: flat;"><div style="transform: rotateX(180deg) rotateY(180deg);justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-color: rgb(155, 187, 209);border-top: 2px solid rgb(88, 136, 169);border-top-left-radius: 0px;border-bottom: 2px solid rgb(88, 136, 169);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 5px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;transform: translate3d(20px, 0px, 0px);"><div style="display: inline-block;width: auto;vertical-align: top;flex: 0 0 auto;align-self: flex-start;min-width: 10%;height: auto;line-height: 0;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: flex-start;"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(243, 245, 247);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div><div style="margin-right: 10px;margin-left: 10px;display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;align-self: flex-start;"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(237, 248, 255);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(216, 226, 233);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div><p powered-by="xiumi.us"><span leaf=""><br/></span></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    泛微协同管理应用平台(e-cology)是一套兼具企业信息门户、知识文档管理、工作流程管理、人力资源管理、客户关系管理、项目管理、财务管理、资产管理、供应链管理、数据中心功能的企业大型协同管理平台，形成了一系列的通用解决方案和行业解决方案。</span><span leaf="">    </span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    </span><span leaf="">赛博昆仑CERT监测到泛微E-cology9 存在SQL注入漏洞，未经过身份认证的攻击者可以利用该漏洞获取到数据库的敏感信息，可能造成信息泄露或权限提升，结合后台远程代码执行漏洞可以完全控制服务器。泛微已经发布新补丁v10.76修复了该前台sql注入漏洞。</span></span></p><table><tbody><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;word-break: break-all;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞名称</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">泛微Ecology前台sql注入漏洞</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞公开编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">暂无</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">昆仑漏洞库编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">CYKL-2025-017104</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞类型</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">SQL注入</span><span leaf=""><br/></span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">公开时间</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">2025年7月</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞等级</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">高危</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">评分</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">暂无</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞所需权限</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">无权限要求</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞利用难度</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">低</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">PoC</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">EXP</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞细节</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">在野利用</span></strong></span></p></td><td data-colwidth="144" width="144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">已知</span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf=""><br/></span></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">影响范围</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;"><span leaf="">e-cology9 并且 补丁版本 &lt; 10.76</span></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><span leaf=""><br/></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">漏洞复现</span></strong></strong></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"></span><span style="color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;background-color: rgb(255, 255, 255);"><span leaf="">目前，赛博昆仑CERT已成功复现</span><span leaf="">泛微Ecology前台sql注入执行漏洞，延时8秒。</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-indent: 31.5994px;background-color: rgb(255, 255, 255);font-size: 13.3333px;letter-spacing: 0.578px;"><span leaf=""><br/></span></span></p><div style="text-indent: 0em;margin-bottom: 0px;"><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001254" data-ratio="0.39225422045680236" data-s="300,640" type="block" data-type="png" data-w="2014" src="https://wechat2rss.xlab.app/img-proxy/?k=934c3b01&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9DodsFVkuzNUGGmFexrmhVGUMa3rEXgaIa8fwMib4KqFaErErebfevibtibcl7TY7s4iaT2bLEO0ZZtnwJMg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf=""><br/></span></p></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001255" data-ratio="0.6174545454545455" data-s="300,640" type="block" data-type="png" data-w="1375" src="https://wechat2rss.xlab.app/img-proxy/?k=e60d844f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9DodsFVkuzNUGGmFexrmhVGUManHsaIMdRM1twaCwZJp1eQKEfLsK2N9MoSAiaYSIpBublxqekszZOgug%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf=""><br/></span></p></div><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;background-color: rgb(88, 136, 169);"></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">防护措施</span></strong></p><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);width: 577.599px;letter-spacing: 0.578px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);line-height: 1.6em;text-align: left;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 0em;color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;letter-spacing: 0.034em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">修复建议</span></span></strong><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span></p></li></ul><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><span leaf="">目前，官方已发布安全补丁，建议受影响的用户尽快联系厂商获取安全补丁。</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.6em;text-align: left;text-indent: 2em;"><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-align: left;text-indent: 0em;font-weight: bold;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">技术业务咨询</span></span></strong></p></li></ul></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;"><span leaf="">赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">赛博昆仑CERT已开启年订阅服务，付费客户(可申请试用)将获取更多技术详情，并支持适配客户的需求。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">联系邮箱：</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">cert@cyberkl.com</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;color: rgb(91, 91, 91);font-size: 14px;"></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">时间线</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><span leaf="">    2025年7月，官方发布补丁v10.76修复漏洞</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;text-align: left;"><span leaf="">    2025年7月9日，赛博昆仑CERT发布漏洞风险通告</span></span></p><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="margin-bottom: 10px;text-align: center;"><strong><span leaf="">技术业务咨询</span></strong></p><p style="text-align: center;"><span leaf="">邮箱：cert@cyberkl.com</span></p><p style="text-align: center;"><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001234" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></p><p style="text-align: center;"><span leaf=""><br/></span></p></div><p powered-by="xiumi.us" style="text-align: center;"><span leaf=""><br/></span></p></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=bd1c51d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9DodsFVkuzNUGGmFexrmhVGUMa3rEXgaIa8fwMib4KqFaErErebfevibtibcl7TY7s4iaT2bLEO0ZZtnwJMg%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7206cb67&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9DodsFVkuzNUGGmFexrmhVGUManHsaIMdRM1twaCwZJp1eQKEfLsK2N9MoSAiaYSIpBublxqekszZOgug%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></p>



<p><a href="2247484909">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7927121b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484909%26idx%3D1%26sn%3Df7c17bd3c58d6e06afe0eee7178e533f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 09 Jul 2025 10:01:00 +0800</pubDate>
    </item>
    <item>
      <title>【补丁日速递】2025年7月微软补丁日安全风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484909&amp;idx=2&amp;sn=ecc04e93f5d52b415fed23c4610b6123</link>
      <description></description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2025-07-09 10:01</span> <span style="display: inline-block;">广东</span>
</p>

<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=0831b1ee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FiaZ7t7b9DodsFVkuzNUGGmFexrmhVGUMa0JlnK5T9tcAtaOZQf5ibVUnXwFCImqxTiaibXFUpuNSNs4RaDmict2Wpeg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="margin-bottom: 0px;text-align: center;"><span leaf=""><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100000902" data-ratio="0.264" data-s="300,640" data-w="750" data-type="gif" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></span></p><div powered-by="xiumi.us" style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-color: rgb(155, 187, 209);border-top: 2px solid rgb(88, 136, 169);border-top-left-radius: 0px;border-bottom: 2px solid rgb(88, 136, 169);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 5px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;transform: translate3d(20px, 0px, 0px);"><div style="display: inline-block;width: auto;vertical-align: top;flex: 0 0 auto;align-self: flex-start;min-width: 10%;height: auto;line-height: 0;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(243, 245, 247);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="margin-right: 10px;margin-left: 10px;display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;align-self: flex-start;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(237, 248, 255);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(216, 226, 233);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div></div></div></div></div><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞安全风险通告-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p><span leaf="">2025年7月微软补丁日安全风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;border-width: 0px;height: auto;"><div powered-by="xiumi.us" style="margin-top: 2px;margin-bottom: 2px;"><p style="border-top: 1px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p><p style="margin-top: 3px;border-top: 4px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;"><span leaf=""><img data-imgfileid="100000893" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></span></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;"><div powered-by="xiumi.us" style="margin-top: 2px;margin-bottom: 2px;"><p style="border-top: 4px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p><p style="margin-top: 3px;border-top: 1px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div></div></div></div></div><div powered-by="xiumi.us" style="transform: perspective(0px);transform-style: flat;"><div style="transform: rotateX(180deg) rotateY(180deg);justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-color: rgb(155, 187, 209);border-top: 2px solid rgb(88, 136, 169);border-top-left-radius: 0px;border-bottom: 2px solid rgb(88, 136, 169);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 5px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;transform: translate3d(20px, 0px, 0px);"><div style="display: inline-block;width: auto;vertical-align: top;flex: 0 0 auto;align-self: flex-start;min-width: 10%;height: auto;line-height: 0;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: flex-start;"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(243, 245, 247);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div><div style="margin-right: 10px;margin-left: 10px;display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;align-self: flex-start;"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(237, 248, 255);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(216, 226, 233);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div><p powered-by="xiumi.us"><span leaf=""><br/></span></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-align: left;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span></p><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">近日，</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">赛</span><span leaf="">博昆仑CERT监测到微软发布了2025年7月安全更新，涉及以下应用：Windows,Azure,Microsoft Office,Microsoft Visual Studio,M</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">icrosoft Configuration Manager 2503,Office Online Server,Micros</span><span leaf="">oft SharePoint,Microsoft Edge,Microsoft SQL Server,Microsoft Tea</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">ms,Remote Desktop client for Windows Desktop,Microsoft 365 Apps,Pytho</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">n extension for Visual Studio Code,CBL Mariner,Microsoft PC Manager等。</span></span><o:p></o:p></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-wrap: wrap;font-size: 11pt;font-family: DengXian;color: rgb(0, 0, 0);letter-spacing: normal;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">总共</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">修</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">复</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">了129个漏洞</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">，</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">高危漏洞116个</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">，</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">严重</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">漏洞12个</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">，</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">中危漏洞1</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">个。本月昆仑实验室</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">研究员共协助微软修复了19个</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">安全漏</span><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">洞</span><span leaf="">。</span></span></p><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></p><ul style="width: 577.422px;letter-spacing: 0.578px;text-wrap: wrap;" class="list-paddingleft-1"></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-47976 k0shl with Kunlun Lab</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-47986 R4nger with CyberKunLun &amp; Zhiniang Peng with HUST</span></p></li><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-49687 R4nger with CyberKunLun &amp; Zhiniang Peng with HUST</span></p></li><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-49690 R4nger with CyberKunLun &amp; Zhiniang Peng with HUST</span></p></li><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-47991 R4nger with CyberKunLun &amp; Zhiniang Peng with HUST</span></p></li><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-48812 Wh1tc with Kunlun Lab &amp; Zhiniang Peng with HUST</span></p></li><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-49711 wh1tc with Kunlun Lab &amp; Zhiniang Peng with HUST</span></p></li><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-49723 R4nger with CyberKunLun &amp; Zhiniang Peng with HUST</span></p></li><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-49726 Zhiniang Peng with HUST &amp; R4nger with CyberKunLun</span></p></li><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-49735 ʌ!ɔ⊥ojv with Kunlun Lab</span></p></li><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-47975 k0shl with Kunlun Lab</span></p></li><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-48815 k0shl with Kunlun Lab</span></p></li><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-48819 k0shl with Kunlun Lab</span></p></li><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-48821 k0shl with Kunlun Lab</span></p></li><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-49665 R4nger with CyberKunLun &amp; Zhiniang Peng with HUST</span></p></li><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-49679 YanZiShuang@BigCJTeam of cyberkl</span></p></li><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-49698 Zhiniang Peng with HUST, devoke with HUST, wh1tc with Kunlun Lab</span></p></li><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-49701 cjm00n with Kunlun Lab &amp; Zhiniang Peng</span></p></li><li><p style="margin-bottom: 0px;letter-spacing: 0.578px;text-wrap: wrap;line-height: 1.6em;text-align: left;text-indent: 0px;"><span leaf="" style="text-wrap: wrap;line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);">CVE-2025-49725 R4nger with CyberKunLun &amp; Zhiniang Peng with HUST</span></p></li></ul><p style="margin-top: 8px;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="color: rgb(255, 255, 255);background-color: rgb(88, 136, 169);font-size: 18px;letter-spacing: 2.5px;text-decoration-style: solid;text-decoration-color: rgb(255, 255, 255);"><span leaf="">重点关注漏洞</span></span></strong><span leaf=""><br/></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">经过赛博昆仑CERT的分析，这里列出部分值得关注的漏洞，详细信息如下：</span></span></p><ul style="width: 577.422px;" class="list-paddingleft-1"><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="line-height: 1.6em;text-indent: 0em;text-align: left;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">CVE-2025-49717 Microsoft SQL Server 远程代码执行漏洞</span></span></strong></span></strong></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="" style="line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="color: rgb(217, 33, 66);">严重</span></span><span leaf=""> 在 Microsoft SQL Server 中发现了一个堆缓冲区溢出漏洞。经过身份验证的攻击者可以通过网络发送特制查询，从而可能从 SQL Server 上下文逃逸并在主机上执行代码。成功利用此漏洞需要攻击者在利用前采取额外行动准备目标环境。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-49735 Windows KDC Proxy Service (KPSSVC) 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;text-wrap: wrap;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="" style="line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="color: rgb(217, 33, 66);">严</span></span><span leaf="" style="line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="color: rgb(217, 33, 66);">重</span></span><span leaf=""> 在 Windows KDC 代理服务 (KPSSVC) 中发现了一个释放后重用漏洞。未经身份验证的攻击者可以利用该漏洞，通过发送特制网络请求在目标系统上执行远程代码。此漏洞仅影响配置为 KDC 代理服务器的 Windows 服务器。成功利用此漏洞需要攻击者赢得竞争条件。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="text-align: left;"><span leaf="" style="letter-spacing: 1.8px;color: rgb(0, 122, 170);font-size: 14px;"><span textstyle="" style="font-weight: bold;">CVE-2025-47980 Windows Imaging Component 信息泄露漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="" style="line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="color: rgb(217, 33, 66);">严重</span></span><span leaf=""> 在 Windows Imaging Component 中发现了一个敏感信息泄露漏洞。未经授权的攻击者可以利用此漏洞在本地泄露信息，成功利用后可能读取部分堆内存。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-47981 SPNEGO Extended Negotiation (NEGOEX) Security Mechanism 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="" style="line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="color: rgb(217, 33, 66);">严重</span></span><span leaf=""> 在 Windows SPNEGO 扩展协商 (NEGOEX) 中发现了一个堆缓冲区溢出漏洞。未经身份验证的攻击者可以通过向服务器发送恶意消息来利用此漏洞，从而执行远程代码。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-48822 Windows Hyper-V Discrete Device Assignment (DDA) 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="" style="line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="color: rgb(217, 33, 66);">严重</span></span><span leaf=""> 在 Windows Hyper-V 中发现了一个越界读取漏洞。未经授权的攻击者可以通过诱骗用户导入恶意的 INF 文件来在本地执行代码。建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-49695 Microsoft Office 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="" style="line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="color: rgb(217, 33, 66);">严重</span></span><span leaf=""> 在 Microsoft Office 中发现了一个释放后重用漏洞。未经授权的攻击者可以利用此漏洞在本地执行代码。预览窗格是此漏洞的一个攻击向量，因此可能无需用户交互即可触发。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-49696 Microsoft Office 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="" style="line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="color: rgb(217, 33, 66);">严重</span></span><span leaf=""> 在 Microsoft Office 中发现了一个越界读取和堆缓冲区溢出漏洞。未经授权的攻击者可以利用此漏洞在本地执行代码。预览窗格是此漏洞的一个攻击向量，因此可能无需用户交互即可触发。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-49697 Microsoft Office 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="" style="line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="color: rgb(217, 33, 66);">严重</span></span><span leaf=""> 在 Microsoft Office 中发现了一个堆缓冲区溢出漏洞。未经授权的攻击者可以利用此漏洞在本地执行代码。预览窗格是此漏洞的一个攻击向量。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-49698/CVE-2025-49703 Microsoft Word 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="" style="line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="color: rgb(217, 33, 66);">严重</span></span><span leaf=""> 在 Microsoft Word 中发现了一个释放后重用（Use After Free）漏洞。未经授权的攻击者可以利用此漏洞在本地执行代码。攻击者需要发送恶意文件并诱骗用户打开，预览窗格也是此漏洞的一个攻击向量。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-49702 Microsoft Office 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="" style="line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="color: rgb(217, 33, 66);">严重</span></span><span leaf=""> 在 Microsoft Office 中发现了一个类型混淆漏洞。未经授权的攻击者可以利用此漏洞在本地执行代码。攻击者需要发送恶意文件并诱骗用户打开。预览窗格也是此漏洞的一个攻击向量。该漏洞尚未检测到在野利用，但利用可能性较低，建议用户尽快测试并部署此更新。</span></span></p></li><li style="color: rgb(0, 122, 170);font-size: 14px;letter-spacing: 1.8px;"><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-weight: bold;">CVE-2025-49704 Microsoft SharePoint 远程代码执行漏洞</span></span></p><p style="line-height: 1.6em;text-align: left;text-indent: 2em;"><strong><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="letter-spacing: 0.578px;"><span style="letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></strong></span></strong><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="" style="line-height: 1.6em;text-align: left;color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;letter-spacing: 1.8px;text-indent: 0em;"><span textstyle="" style="color: rgb(217, 33, 66);">严重</span></span><span leaf=""> 在 Microsoft SharePoint 中发现了一个代码注入漏洞。拥有网站所有者或更高权限的攻击者可以通过网络向 SharePoint 服务器注入并执行任意代码。该漏洞尚未检测到在野利用，但利用可能性较高，建议用户尽快测试并部署此更新。</span></span></p></li></ul><p style="line-height:1.6em;text-align:left;text-indent:2em;"><span style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;text-indent: 0em;"></span></p><p style="margin-top: 8px;margin-bottom: 0px;text-indent: 0em;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">修复建议</span></strong></strong></p><p style="margin-bottom: 0px;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">目前，官方已发布安全补丁，建议受影响的用户尽快升级至安全版本。</span></span></p><p style="margin-bottom: 0px;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">July 2025 Security Updates</span></span></p><p style="margin-bottom: 0px;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf=""><a href="https://msrc.microsoft.com/update-guide/releaseNote/2025-Jul" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2025-Jul</a></span></span></p><p style="margin-bottom: 0px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">技术业务咨询</span></strong></strong></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">     赛博昆仑作为微软主动保护计划（Microsoft Active Protections Program，MAPP）的合作伙伴，可以获得微软最新的高级网络威胁信息和相关防御手段、技术的分享，在微软每月安全更新公开发布之前更早地获取漏洞信息，并对赛博昆仑-洞见平台及时进行更新，为客户提供更迅速有效的安全防护。</span><span leaf=""><br/></span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">同时，赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="margin-bottom: 0px;font-size: 12pt;font-family: 宋体;color: rgb(0, 0, 0);text-align: left;text-wrap: wrap;line-height: 1.6em;text-indent: 2em;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">联系邮箱：cert@cyberkl.com</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 2em;text-align: left;"><span style="color: rgb(91, 91, 91);font-family: 微软雅黑, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-indent: 0em;text-align: center;"><span leaf=""><img data-imgfileid="100000904" class="rich_pages wxw-img" data-ratio="0.694672131147541" data-s="300,640" data-type="png" data-w="976" style="text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;" src="https://wechat2rss.xlab.app/img-proxy/?k=437a2a36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FiaZ7t7b9DodueF1wjNpGZTibLmDnuUaJMXxnQThkJWfnlv7vlX9nlbHfFMRYxbq9KU0ORNTiaLxGQFzZ1FrCjn1aQ%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">参考链接</span></strong><span style="background-color: rgb(255, 255, 255);color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span><span style="background-color: rgb(255, 255, 255);color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf=""><br/></span></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><span style="background-color: rgb(255, 255, 255);color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">    </span><span leaf=""><a href="https://msrc.microsoft.com/update-guide/releaseNote/2025-Jul" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2025-Jul</a></span></span></p><p style="margin-bottom: 0px;text-indent: 0em;text-align: left;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">时间线</span></strong></strong><span leaf=""><br/></span></p><p style="margin-right: 0cm;margin-bottom: 0px;margin-left: 0cm;text-align: left;line-height: normal;text-indent: 0em;"><span style="color: rgb(91, 91, 91);background-color: rgb(255, 255, 255);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">    </span></span></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(91, 91, 91);font-size:14px;letter-spacing:1.8px;">    2025年7月09日，微软官方发布安全通告</span></p><p><span leaf="" style="background-color:rgb(255, 255, 255);color:rgb(91, 91, 91);font-size:14px;letter-spacing:1.8px;">    2025年7月09日，赛博昆仑CERT发布安全风险通告</span></p><div style="margin-bottom: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);text-wrap: wrap;line-height: 1.6em;text-indent: 0em;"><div style="padding-right: 20px;padding-left: 20px;font-size: 14px;letter-spacing: 1.8px;line-height: 1.9;color: rgb(91, 91, 91);"><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="text-align: center;"><span leaf=""><img data-imgfileid="100000901" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></span></p><p style="text-align: center;"><span leaf=""><br/></span></p></div></div></div></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=437a2a36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FiaZ7t7b9DodueF1wjNpGZTibLmDnuUaJMXxnQThkJWfnlv7vlX9nlbHfFMRYxbq9KU0ORNTiaLxGQFzZ1FrCjn1aQ%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></p>



<p><a href="2247484909">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f31998da&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484909%26idx%3D2%26sn%3Decc04e93f5d52b415fed23c4610b6123">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 09 Jul 2025 10:01:00 +0800</pubDate>
    </item>
    <item>
      <title>【复现】Gogs 远程命令注入漏洞风险通告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzkxMDQyMTIzMA==&amp;mid=2247484900&amp;idx=1&amp;sn=987e33d854d2403c3a6e423aa4282b73</link>
      <description>Gogs 远程命令注入漏洞风险通告</description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2025-06-26 17:55</span> <span style="display: inline-block;">广东</span>
</p>

<p>Gogs 远程命令注入漏洞风险通告</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=5c4130d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FiaZ7t7b9DodvLhzDULyUjMOGtgFzoibPfoQibIvNCxrfD30lbR8icdpmrckZ0hw1AM8IG5zNVf3hMeNialEphGbvcaw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;margin-bottom: 0px;" nodeleaf="" data-pm-slice="0 0 []"><img data-imgfileid="100001233" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.264" data-s="300,640" data-type="gif" data-w="750" src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></p><div powered-by="xiumi.us" style="margin-bottom: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us" style="justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-color: rgb(155, 187, 209);border-top: 2px solid rgb(88, 136, 169);border-top-left-radius: 0px;border-bottom: 2px solid rgb(88, 136, 169);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 5px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;transform: translate3d(20px, 0px, 0px);"><div style="display: inline-block;width: auto;vertical-align: top;flex: 0 0 auto;align-self: flex-start;min-width: 10%;height: auto;line-height: 0;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: flex-start;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(243, 245, 247);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="margin-right: 10px;margin-left: 10px;display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;align-self: flex-start;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(237, 248, 255);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(216, 226, 233);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div></div></div></div></div><div powered-by="xiumi.us" style="margin-top: -2px;margin-bottom: -2px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-image: linear-gradient(rgb(255, 255, 255) 70%, rgba(255, 255, 255, 0) 97%);border-left: 1px solid rgb(88, 136, 169);border-bottom-left-radius: 0px;border-right: 1px solid rgb(88, 136, 169);border-top-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: auto;vertical-align: top;background-color: rgb(88, 136, 169);min-width: 10%;flex: 0 0 auto;height: auto;border-width: 0px;border-radius: 2px;border-style: none;border-color: rgb(62, 62, 62);overflow: hidden;align-self: flex-start;"><div powered-by="xiumi.us" style="margin-top: 4px;margin-bottom: 4px;"><div style="padding-right: 8px;padding-left: 8px;color: rgb(255, 255, 255);font-size: 12px;letter-spacing: 2.2px;"><p><span leaf="">-</span><span style="letter-spacing: 2.2px;"><span leaf="">赛博昆仑漏洞</span></span><span style="letter-spacing: 2.2px;"><span leaf="">安全风险通告</span></span><span style="letter-spacing: 2.2px;"><span leaf="">-</span></span></p></div></div></div></div><div powered-by="xiumi.us" style="margin-top: 7px;margin-bottom: 2px;"><div style="font-size: 24px;letter-spacing: 2.8px;color: rgb(88, 136, 169);text-shadow: rgb(255, 255, 255) 0px 1px, rgb(255, 255, 255) 0px -1px, rgb(255, 255, 255) 1px 1px, rgb(255, 255, 255) 1px 0px, rgb(255, 255, 255) 1px -1px, rgb(255, 255, 255) -1px -1px, rgb(255, 255, 255) -1px 0px, rgb(255, 255, 255) -1px 1px, rgb(155, 187, 209) 0px 2px, rgb(155, 187, 209) 0px -2px, rgb(155, 187, 209) 1px -2px, rgb(155, 187, 209) 1px 2px, rgb(155, 187, 209) -1px -2px, rgb(155, 187, 209) -1px 2px, rgb(155, 187, 209) 2px -2px, rgb(155, 187, 209) 2px -1px, rgb(155, 187, 209) 2px 0px, rgb(155, 187, 209) 2px 1px, rgb(155, 187, 209) 2px 2px, rgb(155, 187, 209) -2px -2px, rgb(155, 187, 209) -2px -1px, rgb(155, 187, 209) -2px 0px, rgb(155, 187, 209) -2px 1px, rgb(155, 187, 209) -2px 2px;line-height: 1.45;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2.8px;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf="">Gogs 远程命令注入漏洞风险通告</span></p></div></div><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 10px;justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 330.984px;vertical-align: top;flex: 0 0 auto;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;align-self: flex-start;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;justify-content: center;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;border-width: 0px;height: auto;"><div powered-by="xiumi.us" style="margin-top: 2px;margin-bottom: 2px;"><p style="border-top: 1px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p><p style="margin-top: 3px;border-top: 4px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div><div style="padding-right: 8px;padding-left: 8px;display: inline-block;vertical-align: middle;width: auto;border-bottom: 1px none rgb(117, 160, 190);border-bottom-right-radius: 0px;align-self: center;flex: 0 0 auto;min-width: 10%;height: auto;"><div powered-by="xiumi.us" style="line-height: 0;"><p style="vertical-align: middle;display: inline-block;line-height: 0;width: 18px;height: auto;border-width: 0px;box-shadow: rgb(0, 0, 0) 0px 0px 0px;" nodeleaf=""><img data-imgfileid="100001231" class="rich_pages wxw-img" data-ratio="1" data-type="svg" data-w="150" style="height: 18px;vertical-align: middle;width: 18px;" src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></p></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;height: auto;"><div powered-by="xiumi.us" style="margin-top: 2px;margin-bottom: 2px;"><p style="border-top: 4px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p><p style="margin-top: 3px;border-top: 1px solid rgb(117, 160, 190);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div></div></div></div></div></div></div><div powered-by="xiumi.us" style="transform: perspective(0px);transform-style: flat;"><div style="transform: rotateX(180deg) rotateY(180deg);justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;width: 468.18px;vertical-align: top;background-color: rgb(155, 187, 209);border-top: 2px solid rgb(88, 136, 169);border-top-left-radius: 0px;border-bottom: 2px solid rgb(88, 136, 169);border-bottom-right-radius: 0px;align-self: flex-start;flex: 0 0 auto;"><div powered-by="xiumi.us" style="margin-top: 5px;margin-bottom: 5px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;transform: translate3d(20px, 0px, 0px);"><div style="display: inline-block;width: auto;vertical-align: top;flex: 0 0 auto;align-self: flex-start;min-width: 10%;height: auto;line-height: 0;"><div powered-by="xiumi.us" style="display: flex;flex-flow: row;text-align: center;justify-content: center;"><div style="display: inline-block;vertical-align: top;width: auto;min-width: 10%;flex: 0 0 auto;height: auto;align-self: flex-start;"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(243, 245, 247);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div><div style="margin-right: 10px;margin-left: 10px;display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;align-self: flex-start;"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(237, 248, 255);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div><div style="display: inline-block;vertical-align: top;width: auto;flex: 0 0 0%;height: auto;"><div powered-by="xiumi.us"><p style="display: inline-block;width: 8px;height: 8px;vertical-align: top;overflow: hidden;border-width: 0px;border-radius: 10px;border-style: none;border-color: rgb(62, 62, 62);background-color: rgb(216, 226, 233);"><svg viewBox="0 0 1 1" style="float:left;line-height:0;width:0;vertical-align:top;"></svg></p></div><p powered-by="xiumi.us"><span leaf=""><br/></span></p></div></div></div></div></div></div></div></div></div><p style="margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">漏洞描</span></strong><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">述</span></strong></p><p style="text-indent: 2em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;"></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    Gogs 是一款开源的自托管 Git 服务，它提供了简单易用的 Web 界面，帮助用户轻松管理代码仓库，支持多种认证方式和权限管理，适用于个人开发者及团队协作。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="">    赛博昆仑CERT监测到Gogs 远程命令注入漏洞(CVE-2024-56731)， CVE-2024-39931 的补丁中仅添加了对路径是否为 .git 目录的检查可以通过创建符号链接进行绕过，经过身份认证的攻击者可通过创建符号链接，进而重写 .git 目录下的任意文件，最终实现远程命令执行</span></span></p><table><tbody><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;word-break: break-all;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞名称</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">Gogs 远程命令执行漏洞</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞公开编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144"><p><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">CVE-2024-56731</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">昆仑漏洞库编号</span></strong></span></p></td><td colspan="3" data-colwidth="144,144,144"><span data-v-4471a619="" data-pm-slice="0 0 []"><span leaf="" style="color: rgb(0, 122, 170);"><span textstyle="" style="font-size: 13px;">CYKL-2024-038130</span></span></span></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞类型</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">命令</span><span leaf="" style="color: rgb(0, 122, 170);">执行</span><span leaf=""><br/></span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">公开时间</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">2025年6月24日</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞等级</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">高危</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">评分</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">9.9</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞所需权限</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">普通用户权限</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞利用难度</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">低</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">PoC</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">EXP</span></strong><strong><span leaf="">状态</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td></tr><tr style="height:39px;"><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">漏洞细节</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><strong><span leaf="">在野利用</span></strong></span></p></td><td data-colwidth="144" width="144" style="font-size: 10pt;text-align: left;"><p><span style="color: rgb(0, 122, 170);"><span leaf="">未知</span></span></p></td></tr></tbody></table><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf=""><br/></span></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">影响范围</span></strong></strong></p><p style="text-indent: 0em;margin-bottom: 0px;"><span leaf="" style="color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;background-color: rgb(255, 255, 255);">Gogs &lt; 0.13.3</span></p><p style="text-indent: 0em;margin-bottom: 0px;"><span leaf="" style="color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;background-color: rgb(255, 255, 255);"><br/></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong><span leaf="">漏洞复现</span></strong></strong></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"></span><span style="color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;background-color: rgb(255, 255, 255);"><span leaf="">目前，赛博昆仑CERT已复现</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin-bottom: 8px;outline: 0px;font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Gogs 远程命令注入漏洞</span></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;"><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100001251" data-ratio="0.562962962962963" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ecc51fc6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9DodvLhzDULyUjMOGtgFzoibPfonxXHibJo5IN8pcUdsu4XvYqvicwznicdToSnNICauK7bCgysv0NEWNcng%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf=""><br/></span></p></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;background-color: rgb(88, 136, 169);"></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><span leaf="">防护措施</span></strong></p><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);width: 577.599px;letter-spacing: 0.578px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);line-height: 1.6em;text-align: left;text-indent: 0em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;"><span textstyle="" style="font-size: 16px;font-weight: bold;">缓</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;"><span textstyle="" style="font-size: 16px;font-weight: bold;">解措</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;"><span textstyle="" style="font-size: 16px;font-weight: bold;">施</span></span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);line-height: 1.6em;text-align: left;text-indent: 0em;"><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;">在 Gogs 配置文</span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;">件 app.ini 中关闭用户注册功能</span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;">，修改后重启 Gogs 服务</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);line-height: 1.6em;text-align: left;text-indent: 0em;"><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;">[auth]</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);line-height: 1.6em;text-align: left;text-indent: 0em;"><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;">DISABLE_REGISTRATION = true</span></p></li><li style="-webkit-tap-highlight-color: transparent;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 10.5pt;font-family: &#34;Times New Roman&#34;, serif;color: rgb(0, 0, 0);line-height: 1.6em;text-align: left;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;text-indent: 0em;color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;letter-spacing: 0.034em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">修复建议</span></span></strong></p></li></ul><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:1.8px;">    目前官方</span><span leaf="" style="color: rgb(91, 91, 91);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;">已有</span><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:1.8px;">可更新</span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;">版本，</span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;">建议受</span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;">影响</span><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:1.8px;">用</span><span leaf="" style="-webkit-tap-highlight-color: transparent;outline: 0px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;color: rgb(91, 91, 91);font-size: 14px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;">户升级至最</span><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:1.8px;">新版本：</span></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:1.8px;">    Gogs &gt;= 0.13.3</span></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:1.8px;">    官方补丁下载地址：</span></p><p><span leaf="" style="color:rgb(91, 91, 91);font-size:14px;font-family:mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing:1.8px;">    <a href="https://github.com/gogs/gogs/releases/tag/v0.13.3" target="_blank">https://github.com/gogs/gogs/releases/tag/v0.13.3</a></span></p><p><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: 1.6em;text-align: left;text-indent: 2em;"><ul style="-webkit-tap-highlight-color: transparent;outline: 0px;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-align: left;text-indent: 0em;font-weight: bold;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.6em;text-indent: 0em;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);"><span leaf="">技术业务咨询</span></span></strong></p></li></ul></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);letter-spacing: 0.578px;line-height: 1.6em;text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;"><span leaf="">赛博昆仑支持对用户提供轻量级的检测规则或热补方式，可提供定制化服务适配多种产品及规则，帮助用户进行漏洞检测和修复。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 2em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">赛博昆仑CERT已开启年订阅服务，付费客户(可申请试用)将获取更多技术详情，并支持适配客户的需求。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">联系邮箱：</span></span><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-size: 14px;letter-spacing: 1.8px;text-indent: 0em;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span leaf="">cert@cyberkl.com</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;text-indent: 2em;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);letter-spacing: 1.8px;text-decoration-style: solid;text-decoration-color: rgb(91, 91, 91);font-size: 14px;"><span leaf="">公众号：赛博昆仑CERT</span></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 1.8px;color: rgb(91, 91, 91);font-size: 14px;"></span></p><p style="text-indent: 0em;margin-bottom: 0px;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 0em;background-color: rgb(255, 255, 255);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;text-indent: 2.2571em;color: rgb(255, 255, 255);letter-spacing: 2.5px;text-align: center;background-color: rgb(88, 136, 169);"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">时间线</span></strong></strong></p><p style="-webkit-tap-highlight-color: transparent;margin-bottom: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);line-height: normal;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(91, 91, 91);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 14px;letter-spacing: 1.8px;text-indent: 31.5994px;text-align: left;"><span leaf="">    2025年06月26日，赛博昆仑CERT发布漏洞风险通告</span></span></p><div powered-by="xiumi.us"><div powered-by="xiumi.us" style="padding-right: 25px;padding-left: 25px;letter-spacing: 1px;font-size: 13px;color: rgb(88, 136, 169);"><p style="margin-bottom: 10px;text-align: center;"><strong><span leaf="">技术业务咨询</span></strong></p><p style="text-align: center;"><span leaf="">邮箱：cert@cyberkl.com</span></p><p style="text-align: center;"><span leaf=""><br/></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001234" class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.3984375" data-s="300,640" data-type="gif" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></p><p style="text-align: center;"><span leaf=""><br/></span></p></div><p style="background-color: rgb(255, 255, 255);"><span leaf=""><br/></span></p></div><p style="display: none;"><mp-style-type data-value="10000"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=81938699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGbGCkwVUIJSHBPI0z1Utrp1h5ys6ygT3albl3PgjejJcRRRiaDFFbMBA%2F640%3Fwx_fmt%3Dgif"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e95beb14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_svg%2F7j1UQofaR9fsNXgsOXHVKZMJ1PCicm8s4RHQVjCJEjX63AsNibMx3So4wSMAvubEOoU2vLqYY7hIibIJbkEaPIDs5A4ianh5jibxw%2F640%3Fwx_fmt%3Dsvg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5301ebe0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FiaZ7t7b9DodvLhzDULyUjMOGtgFzoibPfonxXHibJo5IN8pcUdsu4XvYqvicwznicdToSnNICauK7bCgysv0NEWNcng%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=0e42d561&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FiaZ7t7b9Dodvib7ddpGMC6vx4COAy4sBoGLJ1DKwHPSc2JX7FQat3De8XiaajuAHkJzOY9ic9bnaHiaLJqVHIe0E2wg%2F640%3Fwx_fmt%3Dgif"/></p>



<p><a href="2247484900">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=60a93dc5&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzkxMDQyMTIzMA%3D%3D%26mid%3D2247484900%26idx%3D1%26sn%3D987e33d854d2403c3a6e423aa4282b73">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 26 Jun 2025 17:55:49 +0800</pubDate>
    </item>
  </channel>
</rss>