CNNVD 通报微软多个安全漏洞
作者: 日期:2023年06月15日 阅:1,822

近日,CNNVD(国家信息安全漏洞库)正式通报微软多个安全漏洞,其中微软产品本身漏洞77个,影响到微软产品的其他厂商漏洞8个。包括Microsoft SharePoint 安全漏洞(CNNVD-202306-940、CVE-2023-29357)、Microsoft Windows PGM 安全漏洞(CNNVD-202306-959、CVE-2023-29363)等多个漏洞。成功利用上述漏洞的攻击者可以在目标系统上执行任意代码、获取用户数据,提升权限等。微软多个产品和系统受漏洞影响。目前,微软官方已经发布了漏洞修复补丁,建议用户及时确认是否受到漏洞影响,尽快采取修补措施。
一、漏洞介绍2023年6月13日,微软发布了2023年6月份安全更新,共85个漏洞的补丁程序,CNNVD对这些漏洞进行了收录。本次更新主要涵盖了Microsoft Windows 和 Windows 组件、Microsoft Visual Studio和Microsoft .NET、Microsoft Visual Studio和Microsoft、Microsoft Windows iSCSI、Microsoft Windows Hyper-V、Microsoft Windows Bus Filter Driver等。CNNVD对其危害等级进行了评价,其中超危漏洞4个,高危漏洞54个,中危漏洞24个,低危漏洞3个。微软多个产品和系统版本受漏洞影响,具体影响范围可访问微软官方网站查询:https://portal.msrc.microsoft.com/zh-cn/security-guidance

二、漏洞详情此次更新共包括70个新增漏洞的补丁程序,其中超危漏洞4个,高危漏洞43个,中危漏洞21个,低危漏洞2个。

序号漏洞名称CNNVD编号CVE编号危害等级官方链接
1Microsoft SharePoint 安全漏洞CNNVD-202306-940CVE-2023-29357超危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29357
2Microsoft Windows PGM 安全漏洞CNNVD-202306-959CVE-2023-29363超危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29363
3Microsoft Windows PGM 安全漏洞CNNVD-202306-993CVE-2023-32014超危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32014
4Microsoft Windows PGM 安全漏洞CNNVD-202306-995CVE-2023-32015超危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32015
5Microsoft Azure DevOps Server 安全漏洞CNNVD-202306-921CVE-2023-21565高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21565
6Microsoft Visual Studio和Microsoft .NET安全漏洞CNNVD-202306-924CVE-2023-24895高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24895
7Microsoft Visual Studio和Microsoft .NET安全漏洞CNNVD-202306-908CVE-2023-24897高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24897
8多款Microsoft产品安全漏洞CNNVD-202306-853CVE-2023-24936高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24936
9Microsoft Exchange Server 安全漏洞CNNVD-202306-904CVE-2023-28310高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28310
10Microsoft .NET Framework安全漏洞CNNVD-202306-918CVE-2023-29326高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29326
11Microsoft .NET Core安全漏洞CNNVD-202306-854CVE-2023-29331高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29331
12Microsoft Windows NTFS 安全漏洞CNNVD-202306-938CVE-2023-29346高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29346
13Microsoft Windows Group Policy 安全漏洞CNNVD-202306-942CVE-2023-29351高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29351
14Microsoft Windows GDI+ 安全漏洞CNNVD-202306-947CVE-2023-29358高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29358
15Microsoft Windows GDI+ 安全漏洞CNNVD-202306-949CVE-2023-29359高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29359
16Microsoft Windows TPM Device Driver 安全漏洞CNNVD-202306-954CVE-2023-29360高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29360
17Microsoft Windows Cloud Files Mini Filter Driver 安全漏洞CNNVD-202306-953CVE-2023-29361高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29361
18Microsoft Remote Desktop Client 安全漏洞CNNVD-202306-952CVE-2023-29362高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29362
19Microsoft Windows Authentication 安全漏洞CNNVD-202306-958CVE-2023-29364高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29364
20Microsoft Windows Media Foundation 安全漏洞CNNVD-202306-961CVE-2023-29365高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29365
21Microsoft Windows Geolocation Service 安全漏洞CNNVD-202306-963CVE-2023-29366高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29366
22Microsoft iSCSI Target WMI Provider 安全漏洞CNNVD-202306-965CVE-2023-29367高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29367
23Microsoft Windows Filtering 安全漏洞CNNVD-202306-967CVE-2023-29368高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29368
24Microsoft Windows Media Foundation 安全漏洞CNNVD-202306-972CVE-2023-29370高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29370
25Microsoft Windows GDI+ 安全漏洞CNNVD-202306-976CVE-2023-29371高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29371
26Microsoft OLE DB Provider for SQL Server 安全漏洞CNNVD-202306-978CVE-2023-29372高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29372
27Microsoft ODBC Driver 安全漏洞CNNVD-202306-975CVE-2023-29373高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29373
28Microsoft Windows Resilient File System (ReFS) 安全漏洞CNNVD-202306-932CVE-2023-32008高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32008
29Microsoft Windows Collaborative Translation   Framework 安全漏洞CNNVD-202306-930CVE-2023-32009高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32009
30Microsoft Windows Bus Filter Driver 安全漏洞CNNVD-202306-971CVE-2023-32010高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32010
31Microsoft Windows iSCSI 安全漏洞CNNVD-202306-986CVE-2023-32011高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32011
32Microsoft PostScript Printer Driver 安全漏洞CNNVD-202306-1000CVE-2023-32017高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32017
33Microsoft Windows Hello 安全漏洞CNNVD-202306-1002CVE-2023-32018高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32018
34Microsoft Windows SMB Server 安全漏洞CNNVD-202306-1016CVE-2023-32021高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32021
35Microsoft Windows Server 安全漏洞CNNVD-202306-1019CVE-2023-32022高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32022
36Microsoft Excel 安全漏洞CNNVD-202306-913CVE-2023-32029高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32029
37Microsoft .NET 安全漏洞CNNVD-202306-1023CVE-2023-32030高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32030
38Microsoft Exchange Server 安全漏洞CNNVD-202306-915CVE-2023-32031高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32031
39Microsoft .NET 安全漏洞CNNVD-202306-1024CVE-2023-33126高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33126
40Microsoft Visual Studio和Microsoft .NET 安全漏洞CNNVD-202306-861CVE-2023-33128高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33128
41Microsoft SharePoint 安全漏洞CNNVD-202306-1027CVE-2023-33130高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33130
42Microsoft Outlook 安全漏洞CNNVD-202306-1038CVE-2023-33131高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33131
43Microsoft Excel 缓冲区错误漏洞CNNVD-202306-1031CVE-2023-33133高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33133
44Microsoft Visual Studio和Microsoft .NET 安全漏洞CNNVD-202306-980CVE-2023-33135高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33135
45Microsoft Excel 安全漏洞CNNVD-202306-916CVE-2023-33137高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33137
46Microsoft Office 安全漏洞CNNVD-202306-920CVE-2023-33146高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33146
47Microsoft ASP.NET Core 安全漏洞CNNVD-202306-1008CVE-2023-33141高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33141
48Microsoft Azure DevOps Server 安全漏洞CNNVD-202306-922CVE-2023-21569中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21569
49Microsoft Windows CryptoAPI 安全漏洞CNNVD-202306-910CVE-2023-24938中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24938
50Windows Remote Desktop Security 安全漏洞CNNVD-202306-939CVE-2023-29352中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29352
51Microsoft SysInternals 安全漏洞CNNVD-202306-912CVE-2023-29353中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29353
52Microsoft Windows DHCP Server 安全漏洞CNNVD-202306-944CVE-2023-29355中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29355
53Microsoft Windows Remote Procedure Call Runtime 安全漏洞CNNVD-202306-970CVE-2023-29369中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29369
54Microsoft Windows Container Manager Service 安全漏洞CNNVD-202306-988CVE-2023-32012中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32012
55Microsoft Windows Hyper-V 安全漏洞CNNVD-202306-991CVE-2023-32013中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32013
56Microsoft Windows Installer 安全漏洞CNNVD-202306-996CVE-2023-32016中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32016
57Microsoft Windows Kernel 安全漏洞CNNVD-202306-1010CVE-2023-32019中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32019
58Microsoft SharePoint 安全漏洞CNNVD-202306-1029CVE-2023-33129中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33129
59Microsoft SharePoint 安全漏洞CNNVD-202306-985CVE-2023-33132中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33132
60Microsoft Visual Studio 安全漏洞CNNVD-202306-919CVE-2023-33139中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33139
61Microsoft Office OneNote 安全漏洞CNNVD-202306-990CVE-2023-33140中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33140
62Microsoft SharePoint 安全漏洞CNNVD-202306-998CVE-2023-33142中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33142
63Microsoft Visual Studio Code 安全漏洞CNNVD-202306-1012CVE-2023-33144中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33144
64Microsoft Edge 安全漏洞CNNVD-202306-1015CVE-2023-33145中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33145
65Microsoft Dynamics 安全漏洞CNNVD-202306-905CVE-2023-24896中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24896
66Microsoft Windows CryptoAPI安全漏洞CNNVD-202306-907CVE-2023-24937中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24937
67Microsoft NuGet Client 安全漏洞CNNVD-202306-856CVE-2023-29337中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29337
68Microsoft .NET Framework和Microsoft Visual Studio 安全漏洞CNNVD-202306-858CVE-2023-32032中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32032
69Microsoft Windows DNS 安全漏洞CNNVD-202306-1013CVE-2023-32020低危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32020
70Microsoft Power Apps 安全漏洞CNNVD-202306-914CVE-2023-32024低危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32024

此次更新共包括7个更新漏洞的补丁程序,其中高危漏洞4个,中危漏洞3个。

序号漏洞名称CNNVD编号CVE编号危害等级官方链接
1Microsoft Windows Print Spooler Components 安全漏洞CNNVD-202107-137CVE-2021-34527高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527
2Microsoft Windows Kerberos 安全漏洞CNNVD-202211-2288CVE-2022-37967高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-37967
3Microsoft Windows Netlogon 安全漏洞CNNVD-202211-2274CVE-2022-38023高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-38023
4Microsoft Excel 安全漏洞CNNVD-202303-1038CVE-2023-23398高危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23398
5Microsoft Service Fabric 安全漏洞CNNVD-202303-1016CVE-2023-23383中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23383
6Microsoft Excel 资源管理错误漏洞CNNVD-202303-1033CVE-2023-23396中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23396
7Microsoft Defender SmartScreen 安全漏洞CNNVD-202303-1034CVE-2023-24880中危https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24880

此次更新共包括8个影响微软产品的其他厂商漏洞的补丁程序,其中高危漏洞7个,低危漏洞1个。

序号漏洞名称CNNVD编号CVE编号危害等级厂商官方链接
1Git 路径遍历漏洞CNNVD-202304-2045CVE-2023-25652高危githubhttps://github.com/git/git/security/advisories/GHSA-2hvf-7c8p-28fx
2Autodesk FBX-SDK 缓冲区错误漏洞CNNVD-202304-1342CVE-2023-27909高危Autodeskhttps://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0004
3Autodesk FBX-SDK 缓冲区错误漏洞CNNVD-202304-1343CVE-2023-27910高危Autodeskhttps://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0004
4Autodesk FBX-SDK 缓冲区错误漏洞CNNVD-202304-1347CVE-2023-27911高危Autodeskhttps://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0004
5Git 注入漏洞CNNVD-202304-2063CVE-2023-29007高危githubhttps://github.com/git/git/security/advisories/GHSA-v48j-4xgg-4844
6Git for Windows 代码问题漏洞CNNVD-202304-2061CVE-2023-29011高危githubhttps://github.com/git-for-windows/git/security/advisories/GHSA-g4fv-xjqw-q7jm
7Git for Windows 代码问题漏洞CNNVD-202304-2059CVE-2023-29012高危githubhttps://github.com/git-for-windows/git/security/advisories/GHSA-gq5x-v87v-8f7g
8Git for Windows 格式化字符串错误漏洞CNNVD-202304-2046CVE-2023-25815低危githubhttps://github.com/git-for-windows/git/security/advisories/GHSA-9w66-8mq8-5vm8

三、修复建议

目前,微软官方已经发布补丁修复了上述漏洞,建议用户及时确认漏洞影响,尽快采取修补措施。微软官方补丁下载地址:

https://msrc.microsoft.com/update-guide/en-us

CNNVD将继续跟踪上述漏洞的相关情况,及时发布相关信息。如有需要,可与CNNVD联系。联系方式: cnnvdvul@itsec.gov.cn

文章来源:CNNVD

申明:本文系厂商投稿收录,所涉观点不代表安全牛立场!


相关文章