Õâ¸ö0day·ì϶Òѱ»ÔÚÒ°ÀûÓà 8827Ì«Ñô¼¯ÍÅÌṩ¼ì²â¹æ»®

°ä²¼¹¦·ò 2023-07-24
½üÈÕ£¬£¬£¬£¬£¬Ä³Óû§´¦²¿ÊðµÄ8827Ì«Ñô¼¯ÍÅÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©É豸²¶»ñµ½ÀûÓñàºÅΪ CVE-2023-36884¸ßΣ0day·ì϶µÄÑù±¾¡£¡£¡£¡£¡£¡£ ¡£½ØÖÁĿǰ£¬£¬£¬£¬£¬ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©ÒÑÏÖÍø¹²²¶»ñ9ÀýÔÚÒ°ÀûÓᣡ£¡£¡£¡£¡£ ¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

²¶»ñµÄ´¹µöÎĵµ½çÃæ


¾ÝϤ£¬£¬£¬£¬£¬¸Ã·ì϶Ϊ΢ÈíÓÚ7Ô°²È«¸üÐÂÖÐÅû¶µÄOfficeºÍWindows HTMLÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬´æÔÚÓÚ¶à¸öWindowsϵͳºÍOffice²úÆ·ÖÓ×£¡£¡£¡£¡£¡£ ¡£ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©ÒѼà²âµ½·ì϶ÐÅÏ¢Åû¶ǰÒѲúÉúÔÚÒ°ÀûÓãºStorm-0978×éÖ¯£¨ÓÖ³ÆRomCom×éÖ¯£©ÔÚ¶Ô±±Ô¼·å»áµÄ¹¥»÷ÖУ¬£¬£¬£¬£¬ÀûÓø÷ì϶Ôì×÷ÁËÒÔÎÚ¿ËÀ¼ÊÀ½ç´ó»áΪÖ÷ÌâµÄµö¶üÎļþ£¬£¬£¬£¬£¬ÌáÒé´¹µö¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£


 ·ì϶¹¥»÷Á÷³Ì 


CVE-2023-36884·ì϶Ö÷Ìâ˼·ÔÚÓÚÀûÓÃMicrosoft OfficeÎĵµOOXML¹æ·¶ÖпɴúÌæÌåʽ¿é£¨Alternative Format Chunk£©ÄÚǶ´øÓÐÆäËû¹¥»÷×é¼þµÄrtfÎĵµÊµÏÖOffice·ÀÓù»úÔìÈÆ¹ý£¬£¬£¬£¬£¬Äܹ»¹²Í¬ÆäËû·ì϶ʵÏÖÎÞ¸ÐÖª¡¢ÎÞ½»»¥µÄÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£ ¡£


ÔçÆÚ´¹µö¹¥»÷Ñù±¾ÖØÒªÊ¹ÓÃCVE-2017-0199¡¢CVE-2021-40444¡¢CVE-2022-30190µÈÂß¼­·ì϶£¬£¬£¬£¬£¬ºóÐø¹¥»÷ÔØºÉÔ¶³Ì»ñÈ¡£¡£¡£¡£¡£¡£ ¡£¬£¬£¬£¬£¬ÕûÌå¹¥»÷Á÷³Ì±ÈÁ¦¸´ÔÓ¡£¡£¡£¡£¡£¡£ ¡£


¶øÕâÁ½ÖÜÄÚÂ½Ðø²¶»ñµ½µÄÎÞÊý¹¥»÷Ñù±¾£¬£¬£¬£¬£¬ÄÚǶµÄrtf¾ùѡȡģ°å»¯µÄCVE-2017-11882£¬£¬£¬£¬£¬À´Ö´ÐÐrtfͬʱ¿ªÊ͵ÄPEÎļþ¡£¡£¡£¡£¡£¡£ ¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


²¿ÃŲ¶»ñÑù±¾²»Ô̺¬µö¶üÐÅÏ¢£¬£¬£¬£¬£¬²¢´øÓÐеÄrtf»ìºÏ¼¼ÇÉ£ºÀûÓÃrtfÎļþÖÐÔ̺¬µÄole¶ÔÏó¹ý³Ì¶Ô16½øÔìÊý¾ÝµÄ³¤¶ÈÏÞ¶È£¬£¬£¬£¬£¬Ê¹¾²Ì¬½âÎö¹ý³ÌÊý¾Ý´í룬£¬£¬£¬£¬ÎÞ·¨¶ÔÆë»¹Ô­Ô­ÓÐole¶ÔÏ󣬣¬£¬£¬£¬¾ß±¸½ÏÇ¿µÄÃâɱÄÜÁ¦¡£¡£¡£¡£¡£¡£ ¡£


·ì϶·çÏÕ 


ÔÚÏÖʵ´¹µö¹¥»÷ÖУ¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÓÃÓÚÈÆ¹ýoffice°²È«»úÔì¼°Ìṩһ²ãÃâɱ£¬£¬£¬£¬£¬ÎªÆäËûoffice³£Óô¹µö¹¥»÷·ì϶ÌṩÁ˱£»£»£»£»£»£»£»£»¤¿Ç£¬£¬£¬£¬£¬ÊµÏÖÁËÎÞ¸ÐÖª¡¢ÎÞ½»»¥µÄÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬´ó·ù½µµÍ´¹µö¹¥»÷ÀûÓÃÃż÷£¬£¬£¬£¬£¬·¸·¨Õ߿ɽÏΪÇáËɵؽ«Ô­ÓвâÊÔÓù¥»÷ÔØºÉ´úÌæÎªC2¹¤¾ß£¬£¬£¬£¬£¬Ðγɴ¹µö¹¥»÷Èë¿Ú£¬£¬£¬£¬£¬·çÏÕ¼«´ó£¬£¬£¬£¬£¬±ØÒª×öºÃ·ÀÓù´ëÊ©¡£¡£¡£¡£¡£¡£ ¡£


 8827Ì«Ñô¼¯Íżì²â¹æ»® 


1¡¢Îļþ»¹Ô­¼ì²â


¸Ã·ì϶¹²Í¬ÆäËûoffice·ì϶ʹÓ㬣¬£¬£¬£¬ÓÃÓÚ´¹µöÓʼþ¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©Ñ¡È¡Ë«Ïò¼ì²âÒýÇæ£¬£¬£¬£¬£¬¿É¶Ô°ÙÓàÖÖÎļþ½øÐл¹Ô­£¬£¬£¬£¬£¬ÄÚÖÃɳÏ䣬£¬£¬£¬£¬¿É¶Ô³£¼û°ÙÓàÖÖÓʼþ¸½¼þÌåʽ½øÐл¹Ô­ºÍɳÏä¼ì²â£¬£¬£¬£¬£¬Í¬Ê±¾ß±¸ÌáÈ¡ÕýÎÄÃÜÂëÆÆ½âÄÜÁ¦£¬£¬£¬£¬£¬¿É×Ô¶¯Ê¹ÓÃÓʼþÕýÎÄÃÜÂë±¬ÆÆÑ¹Ëõ°ü¸½¼þ£¬£¬£¬£¬£¬±¬ÆÆ³É¹¦ºó¶Ô¸½¼þ¼°¸½¼þ×ÓÎļþ½øÐмì²â¡£¡£¡£¡£¡£¡£ ¡£


2¡¢ÐÐΪ¼ì²â


ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©ÄÚÖÃɳÏ䣬£¬£¬£¬£¬³ý¾²Ì¬¼ì²â±í£¬£¬£¬£¬£¬»¹¿É¶ÔofficeÎļþ½øÐÐÐÐΪ¼ì²âºÍ·ì϶ÀûÓüì²â¡£¡£¡£¡£¡£¡£ ¡£É³ÏäѡȡµÚÈý´úÓ²¼þ·ÂÕæ¼¼Êõ£¬£¬£¬£¬£¬¿É¶Ô¶ñÒâÑù±¾½øÐкýŪ£¬£¬£¬£¬£¬Í¨¹ýofficeÎļþÖ´ÐÐÐÐΪ£¬£¬£¬£¬£¬À´Åж¨¶ñÒâÐÐΪ¡£¡£¡£¡£¡£¡£ ¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ÐÐΪ¼ì²â¸æ¾¯½çÃæ


3¡¢»º½â´ëÊ©


ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©ÒÑÖ§³ÖCVE-2023-36884·ì϶ÀûÓüì²â£¬£¬£¬£¬£¬ÇëÓû§²»Òª´ò¿ªÀ´Àú²»Ã÷µÄofficeÎĵµ£¬£¬£¬£¬£¬ÒѲ¿ÊðTARÓû§¿É½«¿ÉÒÉÎĵ·ëÏßÉÏ´«µ½TARÉ豸¼ì²â¡£¡£¡£¡£¡£¡£ ¡£


±¾µØ»º½â´ëÊ©£º


¿ÉÅäÖÃÓйØ×¢²á±íÏîÀ´×èÖ¹Óйطì϶±»ÀûÓÃ,²½ÖèÈçÏÂ:


н¨Ò»¸öÎı¾Îĵµ,ÊäÈëÈçÏÂÄÚÈݲ¢±£Áô¡£¡£¡£¡£¡£¡£ ¡£


Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet

Explorer\Main\FeatureControl\FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION]

"Excel.exe"=dword:00000001

"Graph.exe"=dword:00000001

"MSAccess.exe"=dword:00000001

"MSPub.exe"=dword:00000001

"Powerpnt.exe"=dword:00000001

"Visio.exe"=dword:00000001

"WinProj.exe"=dword:00000001

"WinWord.exe"=dword:00000001

"Wordpad.exe"=dword:00000001


½«±£ÁôµÄÎļþºó׺Åú¸ÄΪ.reg¡£¡£¡£¡£¡£¡£ ¡£


Ë«»÷Åú¸ÄºóµÄÎļþ,µ¼Èë×¢²á±í¼´¿É¡£¡£¡£¡£¡£¡£ ¡£


µ¼ÈëʵÏÖºó½¨Òé³ÁÆôËùÓдò¿ªµÄOffice·¨Ê½ÒÔÈ·±£ÉèÖÃÉúЧ¡£¡£¡£¡£¡£¡£ ¡£