提交需求
*
*

*
*
*
立即提交
點擊”立即提交”,表明我理(lǐ)解并同意 《美創科(kē)技(jì )隐私條款》

logo

    産(chǎn)品與服務(wù)
    解決方案
    技(jì )術支持
    合作(zuò)發展
    關于美創

    申請試用(yòng)
      【漏洞通告】Windows 錯誤報告服務(wù)權限提升漏洞(CVE-2023-36874)
      發布時間:2023-08-29 閱讀次數: 1691 次
      漏洞描述
      Windows錯誤報告服務(wù)是一項用(yòng)于收集和分(fēn)析系統和應用(yòng)程序錯誤的服務(wù)。當發生應用(yòng)程序崩潰、操作(zuò)系統故障或其他(tā)錯誤時,Windows錯誤報告服務(wù)會自動收集有(yǒu)關錯誤的信息。
      美創安(ān)全實驗室監測到Microsoft發布了Windows的風險通告,漏洞編号:CVE-2023-36874,漏洞等級:高危。由于Windows 錯誤報告服務(wù)對數據的驗證不恰當,經過身份認證的本地攻擊者可(kě)以構造惡意程序觸發該漏洞,成功利用(yòng)此漏洞可(kě)以提升權限至SYSTEM目前,該漏洞的技(jì )術細節POCEXP均已公(gōng)開,且已出現在野利用(yòng)
      影響範圍
      影響版本:
      • Windows Server 2019
      • Windows 10 Version 1809 for ARM64-based Systems
      • Windows 10 Version 1809 for x64-based Systems
      • Windows 10 Version 1809 for 32-bit Systems
      • Windows Server 2012 R2 (Server Core installation)
      • Windows Server 2012 R2
      • Windows Server 2012 (Server Core installation)
      • Windows Server 2012
      • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
      • Windows Server 2008 R2 for x64-based Systems Service Pack 1
      • Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
      • Windows 11 version 21H2 for ARM64-based Systems
      • Windows 11 version 21H2 for x64-based Systems
      • Windows Server 2022 (Server Core installation)
      • Windows Server 2022
      • Windows Server 2019 (Server Core installation)
      • Windows Server 2008 for x64-based Systems Service Pack 2
      • Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
      • Windows Server 2008 for 32-bit Systems Service Pack 2
      • Windows Server 2016 (Server Core installation)
      • Windows Server 2016
      • Windows 10 Version 1607 for x64-based Systems
      • Windows 10 Version 1607 for 32-bit Systems
      • Windows 10 for x64-based Systems
      • Windows 10 for 32-bit Systems
      • Windows 10 Version 22H2 for 32-bit Systems
      • Windows 10 Version 22H2 for ARM64-based Systems
      • Windows 10 Version 22H2 for x64-based Systems
      • Windows 11 Version 22H2 for x64-based Systems
      • Windows 11 Version 22H2 for ARM64-based Systems
      • Windows 10 Version 21H2 for x64-based Systems
      • Windows 10 Version 21H2 for ARM64-based Systems
      • Windows 10 Version 21H2 for 32-bit Systems

      處置建議
      1.Windows自動更新(xīn)

      Windows系統默認啓用(yòng) Microsoft update,當檢測到可(kě)用(yòng)更新(xīn)時,将會自動下載更新(xīn)并在下一次啓動時安(ān)裝(zhuāng)。

      2.手動安(ān)裝(zhuāng)補丁
      對于不能(néng)自動更新(xīn)的系統版本,可(kě)參考以下鏈接下載适用(yòng)于該系統的補丁并安(ān)裝(zhuāng):

      https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36874

      免費試用(yòng)
      服務(wù)熱線(xiàn)

      馬上咨詢

      400-811-3777

      回到頂部