一、漏洞詳情
MSHTML是微軟公司的一個(gè)COM組件,該組件封裝了HTML語(yǔ)言中的所有元素及其屬性,通過(guò)其提供的標(biāo)準(zhǔn)接口,可以訪(fǎng)問(wèn)指定網(wǎng)頁(yè)的所有元素。
近日監(jiān)測(cè)到Windows MSHTML Platform安全特性繞過(guò)漏洞(CVE-2023-29324),在Windows MSHTML中,由于Windows處理路徑函數(shù)CreateUri錯(cuò)誤的轉(zhuǎn)換了某些路徑,導(dǎo)致攻擊者可以構(gòu)造惡意路徑繞過(guò)Microsoft Outlook權(quán)限提升漏洞(CVE-2023-23397)防護(hù)措施。
建議受影響用戶(hù)做好資產(chǎn)自查以及預(yù)防工作,以免遭受黑客攻擊。
二、影響范圍
Windows Server 2012 R2 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server Core installation)
Windows Server 2012
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2016 (Server Core installation)
Windows Server 2016
Windows 10 Version 1607 for x64-based Systems
Windows 10 Version 1607 for 32-bit Systems
Windows 10 for x64-based Systems
Windows 10 for 32-bit Systems
Windows 10 Version 22H2 for 32-bit Systems
Windows 10 Version 22H2 for ARM64-based Systems
Windows 10 Version 22H2 for x64-based Systems
Windows 11 Version 22H2 for x64-based Systems
Windows 11 Version 22H2 for ARM64-based Systems
Windows 10 Version 21H2 for x64-based Systems
Windows 10 Version 21H2 for ARM64-based Systems
Windows 10 Version 21H2 for 32-bit Systems
Windows 11 version 21H2 for ARM64-based Systems
Windows 11 version 21H2 for x64-based Systems
Windows 10 Version 20H2 for ARM64-based Systems
Windows 10 Version 20H2 for 32-bit Systems
Windows 10 Version 20H2 for x64-based Systems
Windows Server 2022 (Server Core installation)
Windows Server 2022
Windows Server 2019 (Server Core installation)
Windows Server 2019
Windows 10 Version 1809 for ARM64-based Systems
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems
三、修復(fù)建議
可參下載適用于該系統(tǒng)的5月補(bǔ)丁并安裝。


