Outlook¸ßΣԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬¿Ðý¹ú¼ÊÓÎÏ·Ìṩ½â¾ö¼Æ»®
Ðû²¼Ê±¼ä 2024-02-23Îó²îÏêÇé
¾ÓÉÑо¿È·ÈÏ£¬£¬¸ÃÎó²îÈÆ¹ýÁËOutlookÖеÄÇå¾²ÏÞÖÆ£¬£¬µ¼Ö¹¥»÷ÕßÖ»Ðè·¢ËÍÒ»¸ö´¹ÂÚÓʼþ£¬£¬¼´¿ÉÔÚÊܺ¦ÕßÎÞÐèÈκν»»¥µÄÇéÐÎÏÂй¶ÆäNTLMÉí·Ýƾ֤ÐÅÏ¢¡£¡£Í¨¹ý½øÒ»²½µÄÆÆ½â»òÕßNTLM relay¹¥»÷£¬£¬¼´¿ÉαÔìÊܺ¦ÕßÉí·Ý¾ÙÐÐÈÏÖ¤£¬£¬´Ó¶ø»ñÈ¡¶ÔӦȨÏÞ¡£¡£Í¬Ê±¸ÃÎó²îÔÚºÍí§ÒâCOMÎó²îÁ¬ÏµÊ¹ÓÃ(ÈçCVE-2022-30190)µÄʱ¼ä£¬£¬¹¥»÷ÕßÖ»ÐèÓÕµ¼Êܺ¦Õßµã»÷Á´½Ó£¬£¬¼´¿ÉÔÚÓû§µçÄÔÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£
¸ÃÎó²îʹÓÃÄѶȽϵͣ¬£¬ÓëÈ¥Äê±»APT28×é֯ƵÈÔʹÓõÄMicrosoft Outlook ȨÏÞÌáÉýÎó²î(CVE-2023-23397)µÄ¹¥»÷³¡¾°ÀàËÆ£¬£¬ºóÐø±»Ê¹ÓõĿÉÄÜÐԽϸߡ£¡£ÏÖÔÚ¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬½¨Òé¿Í»§Æð¾¢×öºÃÅŲéºÍ·À»¤¡£¡£
Ó°Ïì°æ±¾
Microsoft Office LTSC 2021 for 32-bit/64-bit editions
Microsoft Office 2019 for 32-bit/64-bit editions
Microsoft Office 2016 (32-bit/64-bit edition)
Microsoft 365 Apps for Enterprise for 32-bit/64-bit System
Îó²î¸´ÏÖ
ÏÖÔÚÒÑÀֳɸ´ÏÖÁ½ÖÖ¹¥»÷³¡¾°¡£¡£
1¡¢NTLMй¶
½â¾ö¼Æ»®
1¡¢¹Ù·½ÐÞ¸´¼Æ»®
¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬½¨Ò齫ÊÜÓ°ÏìµÄofficeÉý¼¶ÖÁ×îа汾£ºhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21413£¬£¬²¢ÇÒÔÚÉý¼¶Ö®Ç°²»ÒªÈÝÒ×µã»÷ÓʼþÖеÄÁ´½Ó»ò¸½¼þ¡£¡£2¡¢¿Ðý¹ú¼ÊÓÎÏ·½â¾ö¼Æ»®
ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ¡¢ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡¢ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©¡¢ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©¿ÉÓÐÓ÷À»¤CVE-2024-21413Îó²îÔì³ÉµÄ¹¥»÷Σº¦¡£¡£±ðµÄ£¬£¬ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©ÄÚÖÃɳÏä¼ì²â¹¦Ð§£¬£¬Éý¼¶µ½×îв¹¶¡¿ÉÓÐÓüì²âʹÓøÃÎó²îµÄ¶ñÒâÓʼþ¡£¡£