Windows TCP/IP¸ßΣԶ³Ì´úÂëÖ´Ðзì϶À´Ï®£¡£¡OG¶«·½ÌüÌṩ½â¾ö¹æ»®
°ä²¼¹¦·ò 2024-08-20Windows ÊÇÓÉ΢Èí¹«Ë¾¿ª·¢µÄһϵÁÐͼÐÎÓû§½çÃæ²Ù×÷ϵͳ¡£×Ô 1985 Äê³õ´Î°ä²¼ÒÔÀ´£¬£¬Windows ÒѾ¾ÀúÁ˶à¸ö°æ±¾ºÍÖØ´ó¸üУ¬£¬³ÉΪȫÇòʹÓÃ×î¿í·ºµÄ²Ù×÷ϵͳ֮һ¡£
½üÈÕ£¬£¬OG¶«·½Ìü¼à²âµ½Î¢ÈíÔÚ°ËÔ·ݰ²È«²¹¶¡ÖÐÐÞ¸´ÁËÒ»¸öÓ°ÏìWindows TCP/IPºÍ̸ջµÄÔ¶³Ì´úÂëÖ´Ðзì϶¡£¸Ã·ì϶CVSSÆÀ·ÖΪ9.8£¬£¬²¢ÇÒ±»Î¢Èí¹Ù·½ÏóÕ÷ΪExploitation More Likely(¸ß¿ÉÄÜÐÔÀûÓÃ)¡£
¾¹ý×êÑÐÈ·ÈÏ£¬£¬¸Ã·ì϶ÊÇÓÉÓÚWindowsµÄTCP/IP×é¼þÃýÎóµÄ´¦ÖÃÁËIPv6Êý¾Ý£¬£¬´Ó¶øÔÚºóÐøµÄÁ÷³ÌÖе¼ÖÂÁËÕûÊýÒç³ö¡£¹¥»÷ÕßÄܹ»ÔÚδ¾Éí·ÝÑéÖ¤µÄÇé¿öÏ£¬£¬Í¨¹ýÏòÊܺ¦Õß·´¸´·¢ËÍÌØ¶¨½á¹¹µÄIPv6Êý¾Ý°üÀ´´¥·¢·ì϶£¬£¬´Ó¶øÔì³ÉÀ¶ÆÁËÀ»ú(BSOD)ÉõÖÁ´úÂëÖ´ÐС£
¸Ã·ì϶ÀûÓÃÎ޸У¬£¬Ö»ÐèÖ÷ÕÅÖ÷»úÆôÓÃIPv6ºÍ̸¼´¿É´¥·¢£¬£¬²¢ÇÒÏÕЩӰÏìËùÓг£¼ûWindows°æ±¾¡£Ë¼¿¼µ½Windowsͨ³£Ä¬ÈÏÆôÓÃIPv6Ö°ÄÜ£¬£¬½¨Òé¿Í»§»ý¼«×öºÃÅŲéºÍ·À»¤£¬£¬¾¡¿ì×°Öùٷ½²¹¶¡£¬£¬ÒÔ·À±¸Ç±ÔÚ·çÏÕ¡£

·ì϶¸´ÏÖ


½â¾ö¹æ»®
Ò»¡¢¡¢¹Ù·½ÐÞ¸´¹æ»®
¹Ù·½ÒѰ䲼°²È«¸üУ¬£¬½¨Ò齫ÊÜÓ°ÏìµÄWindowsÉý¼¶ÖÁ×îа汾£º£º£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063
¶þ¡¢¡¢Ò»Ê±ÐÞ¸´¹æ»®
ÔÚ²»Ó°ÏìÕý³£ÒµÎñµÄÇé¿öÏ£¬£¬Äܹ»ÁÙʱ½«IPv6Ö°Äܹرա£
Èý¡¢¡¢OG¶«·½Ìü½â¾ö¹æ»®
1¡¢¡¢OG¶«·½Ìü¼ì²âÀà²úÆ·¹æ»®
£¨1£©OG¶«·½Ìü¡°ÌìãÙÍþв·ÖÎöÒ»Ìå»ú£¨TAR£©¡±Éý¼¶µ½20240819°æ±¾¼´¿ÉÖ§³Ö¼ì²â¸Ã·ì϶¡£

£¨2£©OG¶«·½Ìü ¡°ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©¡± Éý¼¶µ½20240819°æ±¾¼´¿ÉÖ§³Ö¼ì²â¸Ã·ì϶¡£

2¡¢¡¢OG¶«·½Ìü©ɨ²úÆ·¹æ»®
£¨1£©¡°OG¶«·½ÌüÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ¡±6075°æ±¾ÒÑ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü£¬£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃ裬£¬Óû§Éý¼¶³ß¶È·ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃ裺£º£º
6070°æ±¾Éý¼¶°üΪ607000582-607000583.vup£¬£¬Éý¼¶°üÏÂÔØµØÖ·£º£º£º
https://venustech.download.venuscloud.cn/
£¨2£©OG¶«·½ÌüÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ608XϵÁа汾ÒÑ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü£¬£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐÐɨÃ裬£¬Óû§Éý¼¶³ß¶È·ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃ裺£º£º
6080°æ±¾Éý¼¶°üΪÖ÷»ú²å¼þ°ü6080000133-S6080000134.svs©ɨ²å¼þ°üÏÂÔØµØÖ·£º£º£º
https://venustech.download.venuscloud.cn/
3¡¢¡¢OG¶«·½Ìü×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¹æ»®
OG¶«·½Ìü×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±²É¼¯²¢¸üеý±¨ÐÅÏ¢£¬£¬¶ÔÈë¿â×ʲú·ì϶Windows TCP/IP¸ßΣԶ³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-38063£©½øÐÐÖÎÀí¡£

4¡¢¡¢OG¶«·½Ìü°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¹æ»®
Óû§Äܹ»Í¨¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬£¬½øÐйØÁªÕ½ÊõÅäÖ㬣¬½áºÏÏÖʵ»·¾³ÖÐϵͳÈÕÖ¾ºÍ°²È«É豸µÄ¸æ¾¯ÐÅÏ¢½øÐгÖÐø¼à¿Ø£¬£¬´Ó¶ø·¢ÏÖ¡°Windows TCP/IP¸ßΣԶ³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-38063£©¡±µÄ·ì϶ÀûÓù¥»÷ÐÐΪ¡£
£¨1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬£¬Í¨¹ý´àÈõÐÔ·¢ÏÖÖ°ÄÜÕë¶Ô¡°Windows TCP/IP¸ßΣԶ³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-38063£©¡±·ì϶ɨÃ蹤×÷£¬£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´Ë·ì϶ӰÏìµÄÖØÒª×ʲú¡£

£¨2£©Æ½Ì¨¡°¹ØÁª·ÖÎö¡±Ä£¿éÖУ¬£¬Ôö³¤¡°L2_WindowsTCP/IP¸ßΣԶ³Ì´úÂëÖ´Ðзì϶¡±£¬£¬Í¨¹ýOG¶«·½Ìü¼ì²âÉ豸¡¢¡¢Ö¸±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬£¬·¢ÏÖÍⲿ¹¥»÷ÐÐΪ£º£º£º

ͨ¹ý¶ÈÎö¹æ¶¨×Ô¶¯½«"L2_WindowsTCP/IP¸ßΣԶ³Ì´úÂëÖ´Ðзì϶"·ì϶ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ôö³¤µ½¹Û²ìÁÐ±í¡°¸ß·çÏÕÏνӡ±ÖУ¬£¬×÷ΪÄÚ²¿µý±¨Êý¾ÝʹÓá£
£¨3£©Ôö³¤¡°L3_WindowsTCP/IP¸ßΣԶ³Ì´úÂëÖ´Ðзì϶ÀûÓóɹ¦¡±£¬£¬Ç°ÌáÈÕÖ¾Ãû³ÆµÈÓÚ»òÔ̺¬¡°L2_WindowsTCP/IP¸ßΣԶ³Ì´úÂëÖ´Ðзì϶¡±£¬£¬¹¥»÷Á˾ֵÈÓÚ¡°¹¥»÷³É¹¦¡±£¬£¬Ö÷ÕŵØÖ·ÒýÓÃ×ʲú·ì϶»òÔ´µØÖ·Æ¥ÅäÍþвµý±¨£¬£¬´Ó¶øÌáÉý¹ØÁª¹æ¶¨µÄÏàÐŶȡ£

£¨4£©ATT&CK¹¥»÷Á´Ìõ·ÖÎöÓëSOAR´ëÖý¨Òé
ƾ¾Ý¶ÔCVE-2024-38063·ì϶µÄ¹¥»÷ÀûÓùý³Ì½øÐзÖÎö£¬£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍ¼¼Êõ½×¶Î£¬£¬¸²¸ÇµÄTTPÔ̺¬£º£º£º
TA0001³õʼ½Ó¼û£º£º£ºT1190ÀûÓÃÃæÏò¹«¼ÒµÄÀûÓ÷¨Ê½
TA0002Ö´ÐУº£º£ºT1059ºÅÁîºÍ¾ç±¾Ú¹ÊÍÆ÷

ͨ¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´ëÖÃÄÜÁ¦£¬£¬Õë¶Ô¸Ã·ì϶ÀûÓõĸ澯ÊÂÎñ±àÅž籾£¬£¬½øÐÐ×Ô¶¯»¯´ëÖá£


¾©¹«Íø°²±¸11010802024551ºÅ