¡¾·ì϶¹«¸æ¡¿Î¢Èí2Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2025-02-12

Ò»¡¢¡¢¡¢·ì϶¸ÅÊö


2025Äê2ÔÂ12ÈÕ£¬£¬£¬OG¶«·½Ìü¼¯ÍÅVSRC¼à²âµ½Î¢Èí°ä²¼ÁË2Ô°²È«¸üУ¬£¬£¬±¾´Î¸üÐÂÐÞ¸´ÁË63¸ö·ì϶£¬£¬£¬º­¸ÇȨÏÞÌáÉý¡¢¡¢¡¢Ô¶³Ì´úÂëÖ´ÐС¢¡¢¡¢ºýŪµÈ¶àÖÖ·ì϶ÀàÐÍ¡£·ì϶¼¶±ðÉ¢²¼ÈçÏ £º£º£º4¸öÑÏÖØ¼¶±ð·ì϶£¬£¬£¬56¸öÖØÒª¼¶±ð·ì϶£¬£¬£¬1¸öÖÐΣ¼¶±ð·ì϶£¬£¬£¬2¸öµÍΣ¼¶±ð·ì϶£¨·ì϶¼¶±ðƾ¾Ý΢Èí¹Ù·½Êý¾Ý£©¡£


ÆäÖУ¬£¬£¬11¸ö·ì϶±»Î¢ÈíÏóÕ÷Ϊ¡°¸ü¿ÉÄܱ»ÀûÓá±¼°¡°¼ì²âÀûÓÃÇé¾°¡±£¬£¬£¬Åú×¢ÕâЩ·ì϶´æÔڽϸߵÄÀûÓ÷çÏÕ£¬£¬£¬½¨ÒéÓÅÏÈÐÞ¸´ÒÔ½µµÍDZÔÚ°²È«Íþв¡£


CVE-ID

CVE ±êÌâ

·ì϶¼¶±ð

CVE-2025-21400

Microsoft SharePoint Server Ô¶³ÌÖ´ÐдúÂë·ì϶

ÖØÒª

CVE-2025-21377

NTLM ¹þϣй¶ºýŪ·ì϶

ÖØÒª

CVE-2025-21418

WinSock µÄ Windows ¸¨ÖúÖ°ÄÜÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21414

Windows Core Messaging ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21358

Windows Core Messaging ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21184

Windows Core Messaging ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21367

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21391

Windows ´æ´¢ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21419

Windows ×°Ö÷¨Ê½ÎļþËãÕÊÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21420

Windows ´Å¼ÆËãÕʹ¤¾ßÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21376

Windows ÇáÁ¿¼¶Ä¿Â¼½Ó¼ûºÍ̸ (LDAP) Ô¶³Ì´úÂëÖ´Ðзì϶

ÑÏÖØ


΢Èí2Ô¸üÐÂÐÞ¸´µÄÆëÈ«·ì϶ÁбíÈçÏ £º£º£º


CVE-ID

CVE ±êÌâ

·ì϶¼¶±ð

CVE-2025-21177

Microsoft Dynamics 365 Sales ÌØÈ¨ÌáÉý·ì϶

ÑÏÖØ

CVE-2025-21179

DHCP ¿Í»§¶Ë·þÎñ»Ø¾ø·þÎñ·ì϶

ÖØÒª

CVE-2025-21181

Microsoft ÐÂÎŶÓÁÐ (MSMQ) »Ø¾ø·þÎñ·ì϶

ÖØÒª

CVE-2025-21182

Windows ¸´Ô­Îļþϵͳ (ReFS) ɾ³ý·´¸´·þÎñÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21183

Windows ¸´Ô­Îļþϵͳ (ReFS) ɾ³ý·´¸´·þÎñÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21184

Windows Core Messaging ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21188

Azure ÍøÂç¹Û²ì·¨Ê½ VM À©´óÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21190

Windows µç»°·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

ÖØÒª

CVE-2025-21194

Microsoft Surface °²È«Ö°ÄÜÈÆ¹ý·ì϶

ÖØÒª

CVE-2025-21198

Microsoft ¸ß»úÄÜÍÆËã (HPC) ´ò°üÔ¶³Ì´úÂëÖ´Ðзì϶

ÖØÒª

CVE-2025-21200

Windows µç»°·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

ÖØÒª

CVE-2025-21201

Windows Telephony Server Ô¶³Ì´úÂëÖ´Ðзì϶

ÖØÒª

CVE-2025-21206

Visual Studio Installer ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21208

Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶

ÖØÒª

CVE-2025-21212

Internet Ïνӹ²Ïí (ICS) »Ø¾ø·þÎñ·ì϶

ÖØÒª

CVE-2025-21216

Internet Ïνӹ²Ïí (ICS) »Ø¾ø·þÎñ·ì϶

ÖØÒª

CVE-2025-21253

Microsoft Edge£¨iOS ºÍ Android °æ£©ºýŪ·ì϶

ÖÐ

CVE-2025-21254

Internet Ïνӹ²Ïí (ICS) »Ø¾ø·þÎñ·ì϶

ÖØÒª

CVE-2025-21259

Microsoft Outlook ºýŪ·ì϶

ÖØÒª

CVE-2025-21267

»ùÓÚ Chromium µÄ Microsoft Edge ºýŪ·ì϶

µÍ

CVE-2025-21279

»ùÓÚ Chromium µÄ Microsoft Edge Ô¶³ÌÖ´ÐдúÂë·ì϶

ÖØÒª

CVE-2025-21283

»ùÓÚ Chromium µÄ Microsoft Edge Ô¶³ÌÖ´ÐдúÂë·ì϶

ÖØÒª

CVE-2025-21322

Microsoft PC Manager ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21337

Windows NTFS ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21342

»ùÓÚ Chromium µÄ Microsoft Edge Ô¶³ÌÖ´ÐдúÂë·ì϶

ÖØÒª

CVE-2025-21347

Windows ²¿Êð·þÎñ»Ø¾ø·þÎñ·ì϶

ÖØÒª

CVE-2025-21349

Windows Ô¶³Ì×ÀÃæÅäÖ÷þÎñ´Û¸Ä·ì϶

ÖØÒª

CVE-2025-21350

Windows Kerberos »Ø¾ø·þÎñ·ì϶

ÖØÒª

CVE-2025-21351

Windows Active Directory Óò·þÎñ API ·þÎñ»Ø¾ø·ì϶

ÖØÒª

CVE-2025-21352

Internet Ïνӹ²Ïí (ICS) »Ø¾ø·þÎñ·ì϶

ÖØÒª

CVE-2025-21358

Windows Core Messaging ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21359

Windows Äں˰²È«Ö°ÄÜÈÆ¹ý·ì϶

ÖØÒª

CVE-2025-21367

Windows Win32 ÄÚºË×ÓÏµÍ³ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21368

Microsoft Digest Éí·ÝÑéÖ¤Ô¶³Ì´úÂëÖ´Ðзì϶

ÖØÒª

CVE-2025-21369

Microsoft Digest Éí·ÝÑéÖ¤Ô¶³Ì´úÂëÖ´Ðзì϶

ÖØÒª

CVE-2025-21371

Windows µç»°·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

ÖØÒª

CVE-2025-21373

Windows Installer ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21375

Kernel Streaming WOW Thunk ·þÎñÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21376

Windows ÇáÁ¿¼¶Ä¿Â¼½Ó¼ûºÍ̸ (LDAP) Ô¶³Ì´úÂëÖ´Ðзì϶

ÑÏÖØ

CVE-2025-21377

NTLM ¹þϣй¶ºýŪ·ì϶

ÖØÒª

CVE-2025-21379

DHCP ¿Í»§¶Ë·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

ÑÏÖØ

CVE-2025-21381

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë·ì϶

ÑÏÖØ

CVE-2025-21383

Microsoft Excel ÐÅϢй¶·ì϶

ÖØÒª

CVE-2025-21386

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë·ì϶

ÖØÒª

CVE-2025-21387

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë·ì϶

ÖØÒª

CVE-2025-21390

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë·ì϶

ÖØÒª

CVE-2025-21391

Windows ´æ´¢ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21392

Microsoft Office Ô¶³ÌÖ´ÐдúÂë·ì϶

ÖØÒª

CVE-2025-21394

Microsoft Excel Ô¶³ÌÖ´ÐдúÂë·ì϶

ÖØÒª

CVE-2025-21397

Microsoft Office Ô¶³ÌÖ´ÐдúÂë·ì϶

ÖØÒª

CVE-2025-21400

Microsoft SharePoint Server Ô¶³ÌÖ´ÐдúÂë·ì϶

ÖØÒª

CVE-2025-21404

»ùÓÚ Chromium µÄ Microsoft Edge ºýŪ·ì϶

µÍ

CVE-2025-21406

Windows µç»°·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

ÖØÒª

CVE-2025-21407

Windows µç»°·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶

ÖØÒª

CVE-2025-21408

»ùÓÚ Chromium µÄ Microsoft Edge Ô¶³ÌÖ´ÐдúÂë·ì϶

ÖØÒª

CVE-2025-21410

Windows ·ÓɺÍÔ¶³Ì½Ó¼û·þÎñ (RRAS) Ô¶³Ì´úÂëÖ´Ðзì϶

ÖØÒª

CVE-2025-21414

Windows Core Messaging ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21418

WinSock µÄ Windows ¸¨ÖúÖ°ÄÜÇý¶¯·¨Ê½ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21419

Windows ×°Ö÷¨Ê½ÎļþËãÕÊÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-21420

Windows ´Å¼ÆËãÕʹ¤¾ßÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-24036

Microsoft AutoUpdate (MAU) ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-24039

Visual Studio Code ÌØÈ¨ÌáÉý·ì϶

ÖØÒª

CVE-2025-24042

Visual Studio Code JS µ÷ÊÔÀ©´óÌØÈ¨ÌáÉý·ì϶

ÖØÒª


¶þ¡¢¡¢¡¢Ó°ÏìÁìÓò


ÊÜÓ°ÏìµÄ²úÆ·/Ö°ÄÜ/·þÎñ/×é¼þÔ̺¬ £º£º£º

Microsoft Dynamics 365 Sales

Windows DHCP Client

Windows Message Queuing

Windows Resilient File System (ReFS) Deduplication Service

Windows CoreMessaging

Azure Network Watcher

Windows Telephony Service

Microsoft Surface

Microsoft High Performance Compute Pack (HPC) Linux Node Agent

Windows Telephony Server

Visual Studio

Windows Routing and Remote Access Service (RRAS)

Windows Internet Connection Sharing (ICS)

Microsoft Edge for iOS and Android

Outlook for Android

Microsoft Edge (Chromium-based)

Microsoft PC Manager

Microsoft Windows

Windows Update Stack

Windows Remote Desktop Services

Windows Kerberos

Active Directory Domain Services

Windows Kernel

Windows Win32 Kernel Subsystem

Microsoft Digest Authentication

Windows Installer

Microsoft Streaming Service

Windows LDAP - Lightweight Directory Access Protocol

Windows NTLM

Windows DHCP Server

Microsoft Office Excel

Windows Storage

Microsoft Office

Microsoft Office SharePoint

Windows DWM Core Library

Windows Ancillary Function Driver for WinSock

Windows Setup Files Cleanup

Windows Disk Cleanup Tool

Microsoft AutoUpdate (MAU)

Visual Studio Code


Èý¡¢¡¢¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


Ŀǰ΢ÈíÒѰ䲼Óйذ²È«¸üУ¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£


£¨Ò»£© Windows Update×Ô¶¯¸üÐÂ


Microsoft UpdateĬÈÏÆôÓ㬣¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϲ½ÖèÊÖ¶¯½øÐиüР£º£º£º


1¡¢¡¢¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢¡¢¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢¡¢¡¢Windows 8.1¡¢¡¢¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬¾ßÌå²½ÖèΪ¡°½ÚÖÆÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢¡¢¡¢Ñ¡Ôñ¡°²é³­¸üС±£¬£¬£¬ÆÚ´ýϵͳ×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüС£

4¡¢¡¢¡¢¸üÐÂʵÏÖºóÖØÆôÍÆËã»ú£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬£¬£¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£


£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ


Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£


2025Äê2Ô°²È«¸üÐÂÏÂÔØÁ´½Ó £º£º£º

https://msrc.microsoft.com/update-guide/releaseNote/2025-Feb

²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£© £º£º£º


1.´ò¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬µã»÷·ì϶ÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£



ͼƬ1.jpg

Àý1 £º£º£ºÎ¢Èí·ì϶ÁÐ±í£¨Ê¾Àý£©


2.ÔÚ΢Èí²¼¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿ÁÐÑ¡ÔñÏàÓ¦µÄϵͳÀàÐÍ£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áдò¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£


ͼƬ2.jpg

Àý2 £º£º£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý


3.µã»÷¡¾°²È«¸üС¿£¬£¬£¬´ò¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬ÏÂÔØÏàÓ¦²¹¶¡²¢½øÐÐ×°Öá£


ͼƬ3.jpg

Àý3 £º£º£º²¹¶¡ÏÂÔØ½çÃæ


4.×°ÖÃʵÏÖºóÖØÆôÍÆËã»ú¡£


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬Ï÷¼õϵͳ·ì϶£¬£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÖÆ£¬£¬£¬Åú¸Ä·À»ðǽսÊõ£¬£¬£¬¹Ø±Õ·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢¡¢¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÖÆºÍ×îСȨÏÞ×¼Ôò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://msrc.microsoft.com/update-guide/releaseNote/2025-Feb