平台
微软补丁星期二 – 2023 年 3 月

2023 年 3 月 14 日

作者: Esben Dochy

分类: 星期二补丁
补丁星期二再次降临。 一如既往,我们的团队汇总了每月的补丁星期二报告,以帮助您管理更新进度。 审计报告让您快速清晰地了解您的 Windows 机器及其修补状态。 2023 年 3 月版的补丁星期二为我们带来了 80 个修复,其中 9 个被评为关键修复。 我们在下面列出了最重要的变化。
长话短说 | 直接查看 2023 年 3 月补丁星期二审核报告

Microsoft Outlook 特权提升漏洞

本月最紧迫的漏洞是 Microsoft Outlook 中的一个漏洞。 CVE-2023-23397 已经被利用,所以尽快更新很重要。 请记住,不幸的是,Lansweeper 无法报告解决此漏洞的知识库更新。 微软提到了以下关于利用过程的内容:

外部攻击者可以发送特制的电子邮件,导致受害者连接到攻击者控制的外部 UNC 位置。 这会将受害者的 Net-NTLMv2 散列泄露给攻击者,然后攻击者可以将其中继到另一个服务并作为受害者进行身份验证。

另一条有用的信息是 Outlook 预览窗格不是攻击媒介。 可以在预览窗格中查看电子邮件之前利用此漏洞。

最后,还有其他缓解选项,例如将用户添加到受保护用户安全组,这会阻止使用 NTLM 作为身份验证机制,或者通过使用外围防火墙、本地防火墙和阻止 TCP 445/SMB 从您的网络出站 通过您的 VPN 设置。

ICMP远程代码执行漏洞

CVE-2023-23415 是本月修复的另一个严重漏洞。 它的 CVSS 基本分数为 9.8,接近可能达到的最严重评级。 根据 Microsoft 的说法,此 Internet 控制消息协议 (ICMP) 远程代码执行漏洞尚未被利用,但将来更有可能被利用。

微软列出,为了利用此漏洞,攻击者需要向目标机器发送一个低级协议错误,该错误在其标头中的另一个 ICMP 数据包中包含一个分段的 IP 数据包。

微软列出,为了利用此漏洞,攻击者需要向目标机器发送一个低级协议错误,该错误在其标头中的另一个 ICMP 数据包中包含一个分段的 IP 数据包。

第三个严重漏洞是 HTTP 协议栈中的一个漏洞。 CVE-2023-23392 的 CVSS 评分也为 9.8,同样尚未被利用,但未来更有可能被利用。 “好”消息是只有 Windows Server 2022 易受攻击。

要利用此漏洞,未经身份验证的攻击者可以使用 HTTP 协议栈 (http.sys) 将特制数据包发送到目标服务器以处理数据包。

虽然更新是防止利用的简单方法,但您可以选择通过禁用 HTTP/3(如果已启用)来缓解漏洞。

2023 年 3 月星期二运行补丁审核

为了帮助管理您的更新进度,我们创建了补丁星期二审计,检查您网络中的资产是否使用最新的补丁更新。 该报告已用颜色编码,以查看哪些机器是最新的,哪些仍需要更新。 一如既往,我们敦促系统管理员尽快更新他们的环境,以确保所有端点的安全。

Lansweeper 周二补丁报告会自动添加到 Lansweeper Cloud 站点。 Lansweeper Cloud 包含在我们所有的许可证中,无需任何额外费用,并允许您将所有安装联合到一个视图中,因此您需要做的就是查看一份报告,该报告会在每个周二的补丁中自动添加!

运行三月补丁星期二审核

2023 年 3 月星期二补丁 CVE 代码和标题

CVE NumberCVE Title
CVE-2023-24930Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability
CVE-2023-24923Microsoft OneDrive for Android Information Disclosure Vulnerability
CVE-2023-24922Microsoft Dynamics 365 Information Disclosure Vulnerability
CVE-2023-24921Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-24920Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-24919Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-24913Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
CVE-2023-24911Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVE-2023-24910Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2023-24909Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
CVE-2023-24908Remote Procedure Call Runtime Remote Code Execution Vulnerability
CVE-2023-24907Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
CVE-2023-24906Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVE-2023-24892Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
CVE-2023-24891Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-24890Microsoft OneDrive for iOS Security Feature Bypass Vulnerability
CVE-2023-24882Microsoft OneDrive for Android Information Disclosure Vulnerability
CVE-2023-24880Windows SmartScreen Security Feature Bypass Vulnerability
CVE-2023-24879Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-24876Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
CVE-2023-24872Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
CVE-2023-24871Windows Bluetooth Service Remote Code Execution Vulnerability
CVE-2023-24870Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVE-2023-24869Remote Procedure Call Runtime Remote Code Execution Vulnerability
CVE-2023-24868Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
CVE-2023-24867Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
CVE-2023-24866Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVE-2023-24865Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVE-2023-24864Microsoft PostScript and PCL6 Class Printer Driver Elevation of Privilege Vulnerability
CVE-2023-24863Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVE-2023-24862Windows Secure Channel Denial of Service Vulnerability
CVE-2023-24861Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2023-24859Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
CVE-2023-24858Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVE-2023-24857Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVE-2023-24856Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVE-2023-23946GitHub: CVE-2023-23946 mingit Remote Code Execution Vulnerability
CVE-2023-23618GitHub: CVE-2023-23618 Git for Windows Remote Code Execution Vulnerability
CVE-2023-23423Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-23422Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-23421Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-23420Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-23419Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2023-23418Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2023-23417Windows Partition Management Driver Elevation of Privilege Vulnerability
CVE-2023-23416Windows Cryptographic Services Remote Code Execution Vulnerability
CVE-2023-23415Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability
CVE-2023-23414Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
CVE-2023-23413Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
CVE-2023-23412Windows Accounts Picture Elevation of Privilege Vulnerability
CVE-2023-23411Windows Hyper-V Denial of Service Vulnerability
CVE-2023-23410Windows HTTP.sys Elevation of Privilege Vulnerability
CVE-2023-23409Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
CVE-2023-23408Azure Apache Ambari Spoofing Vulnerability
CVE-2023-23407Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
CVE-2023-23406Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
CVE-2023-23405Remote Procedure Call Runtime Remote Code Execution Vulnerability
CVE-2023-23404Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-23403Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
CVE-2023-23402Windows Media Remote Code Execution Vulnerability
CVE-2023-23401Windows Media Remote Code Execution Vulnerability
CVE-2023-23400Windows DNS Server Remote Code Execution Vulnerability
CVE-2023-23399Microsoft Excel Remote Code Execution Vulnerability
CVE-2023-23398Microsoft Excel Spoofing Vulnerability
CVE-2023-23397Microsoft Outlook Elevation of Privilege Vulnerability
CVE-2023-23396Microsoft Excel Denial of Service Vulnerability
CVE-2023-23395Microsoft SharePoint Server Spoofing Vulnerability
CVE-2023-23394Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
CVE-2023-23393Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability
CVE-2023-23392HTTP Protocol Stack Remote Code Execution Vulnerability
CVE-2023-23391Office for Android Spoofing Vulnerability
CVE-2023-23389Microsoft Defender Elevation of Privilege Vulnerability
CVE-2023-23388Windows Bluetooth Driver Elevation of Privilege Vulnerability
CVE-2023-23385Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability
CVE-2023-23383Service Fabric Explorer Spoofing Vulnerability
CVE-2023-22743GitHub: CVE-2023-22743 Git for Windows Installer Elevation of Privilege Vulnerability
CVE-2023-22490GitHub: CVE-2023-22490 mingit Information Disclosure Vulnerability
CVE-2023-21708Remote Procedure Call Runtime Remote Code Execution Vulnerability
CVE-2023-1018CERT/CC: CVE-2023-1018 TPM2.0 Module Library Elevation of Privilege Vulnerability
CVE-2023-1017CERT/CC: CVE-2023-1017 TPM2.0 Module Library Elevation of Privilege Vulnerability
CVE-2022-43552Open Source Curl Remote Code Execution Vulnerability
CVE-2022-23825AMD: CVE-2022-23825 AMD CPU Branch Type Confusion
CVE-2022-23816AMD: CVE-2022-23816 AMD CPU Branch Type Confusion
CVE-2022-23257Windows Hyper-V Remote Code Execution Vulnerability

每月收到最新的周二补丁报告

邮箱
订阅
京公网安备 11010802033190号    |    备案号:京ICP备09015132号-115