Outlook¸ßΣԶ³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅÌṩ½â¾ö¹æ»®

°ä²¼¹¦·ò 2024-02-23
Microsoft Office OutlookÊÇ΢Èí¿ª·¢µÄ°ì¹«Èí¼þÌ××°ÖеÄÒ»¸ö×é¼þ£¬£¬£¬£¬£¬ÖØÒªÖ°ÄÜÊÇÊÕ·¢µç×ÓÓʼþ£¬£¬£¬£¬£¬Í¬Ê±ÓµÓÐÖÎÀíÁªÏµÈËÐÅÏ¢¡¢ÆÌÅÅÈճ̡¢·ÖÅ乤×÷µÈÖ°ÄÜ¡£¡£¡£¡£¡£¡£ ¡£


·ì϶ÏêÇé


½üÈÕ£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍŽ𾦰²È«×êÑÐÍŶӼà²âµ½Î¢ÈíÖÙ´º·Ý°²È«²¹¶¡ÖÐÒ»¸öCVSSÆÀ·ÖΪ9.8µÄ·ì϶£¨Microsoft OutlookÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2024-21413£©POC±»¹«¿ª¡£¡£¡£¡£¡£¡£ ¡£
¾­¹ý×êÑÐÈ·ÈÏ£¬£¬£¬£¬£¬¸Ã·ìÏ¶ÈÆ¹ýÁËOutlookÖеݲȫÏÞ¶È£¬£¬£¬£¬£¬µ¼Ö¹¥»÷ÕßÖ»Ðè·¢ËÍÒ»¸ö´¹µöÓʼþ£¬£¬£¬£¬£¬¼´¿ÉÔÚÊܺ¦ÕßÎÞÐèÈκν»»¥µÄÇé¿öÏÂй¶ÆäNTLMÉí·ÝÍ´´¦ÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£Í¨¹ý½øÒ»²½µÄÆÆ½â»òÕßNTLM relay¹¥»÷£¬£¬£¬£¬£¬¼´¿ÉαÔìÊܺ¦ÕßÉí·Ý½øÐÐÈÏÖ¤£¬£¬£¬£¬£¬´Ó¶ø»ñÈ¡¶ÔӦȨÏÞ¡£¡£¡£¡£¡£¡£ ¡£Í¬Ê±¸Ã·ì϶ÔÚºÍËÁÒâCOM·ì϶½áºÏʹÓÃ(ÈçCVE-2022-30190)µÄʱ³½£¬£¬£¬£¬£¬¹¥»÷ÕßÖ»ÐèÓÕµ¼Êܺ¦Õßµã»÷Á´½Ó£¬£¬£¬£¬£¬¼´¿ÉÔÚÓû§µçÄÔÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ ¡£
¸Ã·ì϶ÀûÓÃÄѶȽϵÍ£¬£¬£¬£¬£¬ÓëÈ¥Äê±»APT28×é֯ƵÈÔÀûÓõÄMicrosoft Outlook È¨ÏÞÌáÉý·ì϶(CVE-2023-23397)µÄ¹¥»÷³¡¾°ÀàËÆ£¬£¬£¬£¬£¬ºóÐø±»ÀûÓõĿÉÄÜÐԽϸß¡£¡£¡£¡£¡£¡£ ¡£Ä¿Ç°¹Ù·½ÒѰ䲼°²È«¸üУ¬£¬£¬£¬£¬½¨Òé¿Í»§»ý¼«×öºÃÅŲéºÍ·À»¤¡£¡£¡£¡£¡£¡£ ¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ó°Ïì°æ±¾


Microsoft Office LTSC 2021 for 32-bit/64-bit editions

Microsoft Office 2019 for 32-bit/64-bit editions

Microsoft Office 2016 (32-bit/64-bit edition)

Microsoft 365 Apps for Enterprise for 32-bit/64-bit System


·ì϶¸´ÏÖ


ĿǰÒѳɹ¦¸´ÏÖÁ½ÖÖ¹¥»÷³¡¾°¡£¡£¡£¡£¡£¡£ ¡£


1¡¢NTLMй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


2¡¢½áºÏÆäËû·ì϶´¥·¢RCE


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


½â¾ö¹æ»®


1¡¢¹Ù·½½¨¸´¹æ»®

¹Ù·½ÒѰ䲼°²È«¸üУ¬£¬£¬£¬£¬½¨Ò齫ÊÜÓ°ÏìµÄofficeÉý¼¶ÖÁ×îа汾£ºhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21413£¬£¬£¬£¬£¬²¢ÇÒÔÚÉý¼¶Ö®Ç°²»ÒªµÈÏеã»÷ÓʼþÖеÄÁ´½Ó»ò¸½¼þ¡£¡£¡£¡£¡£¡£ ¡£


2¡¢8827Ì«Ñô¼¯ÍŽâ¾ö¹æ»®


ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©¿ÉÓÐЧ·À»¤CVE-2024-21413·ì϶Ôì³ÉµÄ¹¥»÷·çÏÕ¡£¡£¡£¡£¡£¡£ ¡£´Ë±í£¬£¬£¬£¬£¬ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©ÄÚÖÃɳÏä¼ì²âÖ°ÄÜ£¬£¬£¬£¬£¬Éý¼¶µ½×îв¹¶¡¿ÉÓÐЧ¼ì²âÀûÓø÷ì϶µÄ¶ñÒâÓʼþ¡£¡£¡£¡£¡£¡£ ¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website