À­Ë¹Î¬¼Ó˹9888

¡¾Îó²îͨ¸æ¡¿½üÆÚ¹Ø×¢¶È½Ï¸ßµÄÇå¾²Îó²îºÏ¼¯
¸üÐÂʱ¼ä£º2024-10-25 ȪԴ£ºÔ­´´ ±à¼­£ºÖÎÀíÔ± ä¯ÀÀ£º140

½üÆÚ£¬À­Ë¹Î¬¼Ó˹9888ÐÇÂÞÍøÂç¿Õ¼äÇ徲ʵÑéÊÒ¼à²âµ½Éí·ÝÑéÖ¤ÈƹýÎó²î£¨CVE-2024-6800£©¡£Í¬Ê±×î½üÒ»¶Îʱ¼äÈ«Çò¹æÄ£ÄÚ·¢Ã÷Á˶à¸öÓ°Ïì¹æÄ£¹ã¡¢Î£º¦Ë®Æ½¸ßµÄÇå¾²Îó²î£¬À­Ë¹Î¬¼Ó˹9888½«ÆäÊáÀíÕûºÏ£¬ÖúÁ¦Óû§È«·½Î»¸ÐÖªÍøÂçÇ徲̬ÊÆ£¬ÓÐÓõÖÓùÍøÂç¹¥»÷£¬ÌáÉýÍøÂçÇå¾²·À»¤ÄÜÁ¦¡£




Éí·ÝÑéÖ¤ÈƹýÎó²îCVE-2024-6800



GitHub Enterprise ServerÊÇÒ»¸öÓÃÓÚÆóÒµÈí¼þ¿ª·¢µÄ×ÔÍйÜƽ̨£¬ÍŶӿÉͨ¹ýÆäÇ¿Ê¢µÄAPIÉú²úÁ¦¡¢Ð­×÷¹¤¾ßÒÔ¼°¼¯³ÉÄÜÁ¦À´¹¹½¨ºÍÐû²¼Èí¼þ¡£8ÔÂ21ÈÕ£¬À­Ë¹Î¬¼Ó˹9888ÐÇÂÞÍøÂç¿Õ¼äÇ徲ʵÑéÊÒ¼à²âµ½GitHub Enterprise ServerÖÐÐÞ¸´ÁËÒ»¸öÉí·ÝÑéÖ¤ÈƹýÎó²î£¨CVE-2024-6800£©£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.5¡£



Ó°Ïì·½·¨


µ±GitHub Enterprise ServerΪÌض¨µÄÉí·ÝÌṩÕߣ¨IdP£©ÉèÖÃSAML SSO¼¯³É£¬²¢ÇÒÕâЩIdPʹÓùûÕæ̻¶µÄ¡¢ÒÑÊðÃûµÄÍŽáÔªÊý¾ÝXMLÎļþ£¨Í¨³£°üÀ¨ÓÃÓÚÑéÖ¤SAMLÏìÓ¦µÄ¹«Ô¿ºÍÆäËûÉèÖÃÐÅÏ¢£©Ê±£¬¹¥»÷Õß¿ÉαÔìSAMLÏìÓ¦ÔÚGHESÉϾÙÐÐÉí·ÝÑéÖ¤ºÍÊÚȨ£¬´Ó¶ø½¨Éè»ò»ñÈ¡¾ßÓÐÕ¾µãÖÎÀíԱȨÏÞµÄÓû§ÕË»§¡£



Çå¾²²½·¥


¡ö Éý¼¶°æ±¾

ÏÖÔÚ3.1°æ±¾ÖиÃÎó²îÒѾ­ÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½GitHub Enterprise ServerÐÞ¸´°æ±¾3.10.16¡¢3.11.14¡¢3.12.8¡¢3.13.3»ò¸ü¸ß°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://enterprise.github.com/releases/3.13.3/download

¡ö ͨÓý¨Òé

ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔÌ­¹¥»÷Ãæ¡£

ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£




WPSÁ½¸öÒªº¦Îó²î

CVE-2024-7262¡¢CVE-2024-7263



WPS Office±»·¢Ã÷±£´æÁ½¸öÒªº¦Îó²î£¬¿ÉÄܵ¼ÖÂÓû§ÔâÊÜÔ¶³Ì´úÂëÖ´Ðй¥»÷¡£ÕâÁ½¸öÎó²îµÄCVSSÆÀ·ÖΪ9.3£¬Åú×¢ËüÃǵÄÑÏÖØÐԺܸߣ¬ÇÒÒ×ÓÚ±»Ê¹Óá£



Îó²îλÖÃ


ÕâÁ½¸öÎó²î¶¼±£´æÓÚWPS OfficeµÄ`promecefpluginhost.exe`×é¼þÖС£

CVE-2024-7262Ó°Ïì°æ±¾Îª12.2.0.13110ÖÁ12.2.0.13489¡£

CVE-2024-7263Ó°Ïì°æ±¾Îª12.2.0.13110ÖÁ12.2.0.17153£¨²»°üÀ¨17153£©¡£



Σº¦»º½â²½·¥


¼øÓÚÕâЩÎó²îµÄÑÏÖØÐÔÒÔ¼°CVE-2024-7262Òѱ»È·ÈϵĻîԾʹÓã¬ËùÓÐWPS OfficeÓû§±ØÐ辡¿ì½«Èí¼þ¸üе½×îпÉÓð汾£¨12.2.0.17153»ò¸ü¸ß°æ±¾£©¡£

±ðµÄ£¬WPS½¨ÒéÓû§½ÓÄÉÒÔÏÂÌØÊâÇå¾²²½·¥£º

¡¤²»ÒªËæÒâ·­¿ªÈªÔ´²»Ã÷µÄÎļþ£ºÌØÊâÊǵç×Ó±í¸ñ¡¢ÎĵµºÍÆäËû¿ÉÄÜ°üÀ¨¶ñÒâ´úÂëµÄÎļþ¡£

¡¤ÆôÓ÷À»ðǽºÍ·´²¡¶¾Èí¼þ£ºÈ·±£ÕâЩÇå¾²¹¤¾ß´¦ÓÚ×îÐÂ״̬£¬²¢°´ÆÚɨÃèϵͳÒÔ¼ì²âºÍɨ³ýDZÔÚÍþв¡£

¡¤¼á³ÖСÐÄ£º¹Ø×¢WPS OfficeºÍÆäËû³£ÓÃÈí¼þµÄÇ徲ͨ¸æ£¬ÊµÊ±Ó¦Óò¹¶¡ºÍ¸üС£




WindowsϵͳÑÏÖØÇå¾²Îó²î

CVE-2024-38063



Windows ϵͳÆسöÑÏÖØÇå¾²Îó²î£¬±àºÅΪCVE-2024-38063¡£Îó²îµÄ CVSS3.1 ·ÖÊýΪ 9.8£¬ÊôÓÚ¡¸Ö÷Òª¡¹¼¶±ð£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÌØÖÆµÄ IPv6 Êý¾Ý°üÔ¶³ÌÈëÇÖ×°±¸£¬Ö´ÐÐí§Òâ´úÂë¡£



Îó²îÐÎò


Windows TCP/IP ×é¼þÖз¢Ã÷ÁËÒ»¸öÕûÊýÒç³öÎó²î¡£Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÖظ´·¢ËÍ°üÀ¨ÌØÖÆÊý¾Ý°üµÄ IPv6 Êý¾Ý°üµ½ Windows »úеÉÏ£¬´Ó¶øÔÚÄ¿µÄϵͳÉÏÖ´ÐÐÔ¶³Ì´úÂë¡£Õâ¸öÎó²îÓ°ÏìÁËËùÓÐÊÜÖ§³ÖµÄ Windows °æ±¾£¬°üÀ¨¼´½«Ðû²¼µÄ Windows 11 °æ±¾ 24H2£¬×é³ÉÁËÑÏÖصÄÇå¾²Íþв¡£



ÐÞ¸´½¨Òé


ÏÖÔÚ£¬¹Ù·½ÒÑÐû²¼Çå¾²²¹¶¡£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶ÖÁÇå¾²°æ±¾¡£

Çå¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2024-Aug

³ý¾¡¿ì×°ÖÃ΢ÈíÐû²¼µÄ²¹¶¡³¹µ×ÐÞ¸´Îó²îÍ⣬Óû§Ò²¿Éͨ¹ý½ûÓÃIPv6 ЭÒéÀ´»º½â¸ÃÎó²î´øÀ´µÄΣº¦¡£




AMD³¬µÈȨÏÞÎó²îCVE-2023-31315



AMD´¦Öóͷ£Æ÷±»ÆسöÒ»¸öÒѾ­±£´æÊýÊ®ÄêµÄÎó²îSinkclose¡£¸ÃÎó²îÓ°ÏìÁË×Ô2006ÄêÒÔÀ´Ðû²¼µÄÏÕЩËùÓÐAMD´¦Öóͷ£Æ÷£¬ÊýÒÔÒڼƵÄÌõ¼Ç±¾¡¢Ì¨Ê½»úºÍЧÀÍÆ÷ÃæÁÙÍþв¡£



ÑÏÖØˮƽ


´ËÎó²îÔÊÐí¹¥»÷Õß½«È¨ÏÞ´Óring 0£¨²Ù×÷ϵͳÄںˣ©ÌáÉýµ½ring-2£¬ÔÚ´¦Öóͷ£Æ÷µÄ×î¸ßÌØȨģʽ¡ª¡ªÏµÍ³ÖÎÀíģʽ£¨System Management Mode,SMM£©ÏÂÖ´ÐжñÒâ´úÂ룬ÔÚϵͳ¹Ì¼þÖÐÖ²Èë¶ñÒâÈí¼þ¡£¹¥»÷Õß¿ÉÈƹýϵͳÖÎÀíģʽµÄ±£»¤»úÖÆ£¬´Ó¶øÔڹ̼þ²ãÃæÖ²ÈëÄÑÒÔ¼ì²âºÍÒƳýµÄ¶ñÒâÈí¼þ£¬Á¥ÊôÓÚÄÑÒÔÐÞ¸´µÄ¡°³¬µÈȨÏÞÎó²î¡±¡£



ÐÞ¸´²½·¥


AMDÒѾ­Ðû²¼ÁËÕë¶Ô¶à¸ö×îÐÂÍƳöµÄEPYCÊý¾ÝÖÐÐÄ´¦Öóͷ£Æ÷ºÍRyzenϵÁд¦Öóͷ£Æ÷µÄ΢Âë¸üв¹¶¡£¬½¨ÒéÓû§¾¡¿ìÉý¼¶ÖÁÇå¾²°æ±¾¡£

µ«Ryzen 1000¡¢2000ºÍ3000ϵÁÐÒÔ¼°Threadripper 1000ºÍ2000ÊôÓÚ¡°Áè¼ÝÖ§³Ö´°¿ÚÆڵľɲúÆ·¡±£¬Óû§ÏÖÔÚÖ»ÄܽÓÄɱê×¼µÄÇå¾²²½·¥¡£

ÉùÃ÷£º±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬½­ËÕÀ­Ë¹Î¬¼Ó˹9888ÐÇÂÞÍøÂç¿Õ¼äÇ徲ʵÑéÊÒ²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£




´´Á¢¸üÇå¾²µÄÊý×ÖδÀ´ Éí·ÝÓë»á¼ûÇå¾² ¡¤ Êý¾ÝÇå¾² ¡¤ Çå¾²ÖÎÀíÓëÔËÓª ¡¤ Ç徲ЧÀÍ ¡¤ ¾ü¹¤±£ÃÜ Éó²é¸ü¶à
¡¾ÍøÕ¾µØͼ¡¿¡¾sitemap¡¿