Õâ¸ö0dayÎó²îÒѱ»ÔÚҰʹÓà MG±ùÇòÍ»ÆÆÊÔÍæÌṩ¼ì²â¼Æ»®
Ðû²¼Ê±¼ä 2023-07-24
²¶»ñµÄ´¹ÂÚÎĵµ½çÃæ
¾ÝϤ£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îΪ΢ÈíÓÚ7ÔÂÇå¾²¸üÐÂÖÐÅû¶µÄOfficeºÍWindows HTMLÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬±£´æÓÚ¶à¸öWindowsϵͳºÍOffice²úÆ·ÖС£¡£¡£¡£¡£¡£¡£ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©ÒѼà²âµ½Îó²îÐÅÏ¢Åû¶ǰÒѱ¬·¢ÔÚҰʹÓãºStorm-0978×éÖ¯£¨ÓÖ³ÆRomCom×éÖ¯£©ÔÚ¶Ô±±Ô¼·å»áµÄ¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬Ê¹ÓøÃÎó²îÖÆ×÷ÁËÒÔÎÚ¿ËÀ¼ÌìÏ´ó»áΪÖ÷ÌâµÄÓÕ¶üÎļþ£¬£¬£¬£¬£¬£¬£¬Ìᳫ´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£¡£
Îó²î¹¥»÷Á÷³Ì
CVE-2023-36884Îó²î½¹µã˼Ð÷ÔÚÓÚʹÓÃMicrosoft OfficeÎĵµOOXML¹æ·¶ÖпÉÌæ»»ÃûÌÿ飨Alternative Format Chunk£©ÄÚǶ´øÓÐÆäËû¹¥»÷×é¼þµÄrtfÎĵµÍê³ÉOffice·ÀÓù»úÖÆÈÆ¹ý£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÅäºÏÆäËûÎó²îʵÏÖÎÞ¸ÐÖª¡¢ÎÞ½»»¥µÄÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£
ÔçÆÚ´¹ÂÚ¹¥»÷Ñù±¾Ö÷ҪʹÓÃCVE-2017-0199¡¢CVE-2021-40444¡¢CVE-2022-30190µÈÂß¼Îó²î£¬£¬£¬£¬£¬£¬£¬ºóÐø¹¥»÷ÔØºÉÔ¶³Ì»ñÈ¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬ÕûÌå¹¥»÷Á÷³Ì½ÏÁ¿Öش󡣡£¡£¡£¡£¡£¡£
¶øÕâÁ½ÖÜÄÚÂ½Ðø²¶»ñµ½µÄ´ó¶¼¹¥»÷Ñù±¾£¬£¬£¬£¬£¬£¬£¬ÄÚǶµÄrtf¾ù½ÓÄÉÄ£°å»¯µÄCVE-2017-11882£¬£¬£¬£¬£¬£¬£¬À´Ö´ÐÐrtfͬʱÊͷŵÄPEÎļþ¡£¡£¡£¡£¡£¡£¡£

²¿·Ö²¶»ñÑù±¾²»°üÀ¨ÓÕ¶üÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬²¢´øÓÐеÄrtf»ìÏý¼¼ÇÉ£ºÊ¹ÓÃrtfÎļþÖаüÀ¨µÄole¹¤¾ßÀú³Ì¶Ô16½øÖÆÊý¾ÝµÄ³¤¶ÈÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬Ê¹¾²Ì¬ÆÊÎöÀú³ÌÊý¾Ý´í룬£¬£¬£¬£¬£¬£¬ÎÞ·¨¶ÔÆë»¹ÔÔÓÐole¹¤¾ß£¬£¬£¬£¬£¬£¬£¬¾ß±¸½ÏÇ¿µÄÃâɱÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£
Îó²îΣº¦
ÔÚÏÖʵ´¹ÂÚ¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÓÃÓÚÈÆ¹ýofficeÇå¾²»úÖÆ¼°Ìṩһ²ãÃâɱ£¬£¬£¬£¬£¬£¬£¬ÎªÆäËûoffice³£Óô¹ÂÚ¹¥»÷Îó²îÌṩÁ˱£»£»£»£»¤¿Ç£¬£¬£¬£¬£¬£¬£¬ÊµÏÖÁËÎÞ¸ÐÖª¡¢ÎÞ½»»¥µÄÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬£¬´ó·ù½µµÍ´¹ÂÚ¹¥»÷ʹÓÃÃż÷£¬£¬£¬£¬£¬£¬£¬²»·¨Õ߿ɽÏΪÇáËɵؽ«ÔÓвâÊÔÓù¥»÷ÔØºÉÌæ»»ÎªC2¹¤¾ß£¬£¬£¬£¬£¬£¬£¬Ðγɴ¹ÂÚ¹¥»÷Èë¿Ú£¬£¬£¬£¬£¬£¬£¬Î£º¦¼«´ó£¬£¬£¬£¬£¬£¬£¬ÐèÒª×öºÃ·ÀÓù²½·¥¡£¡£¡£¡£¡£¡£¡£
MG±ùÇòÍ»ÆÆÊÔÍæ¼ì²â¼Æ»®
1¡¢Îļþ»¹Ô¼ì²â
¸ÃÎó²îÅäºÏÆäËûofficeÎó²îʹÓ㬣¬£¬£¬£¬£¬£¬ÓÃÓÚ´¹ÂÚÓʼþ¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©½ÓÄÉË«Ïò¼ì²âÒýÇæ£¬£¬£¬£¬£¬£¬£¬¿É¶Ô°ÙÓàÖÖÎļþ¾ÙÐл¹Ô£¬£¬£¬£¬£¬£¬£¬ÄÚÖÃɳÏ䣬£¬£¬£¬£¬£¬£¬¿É¶Ô³£¼û°ÙÓàÖÖÓʼþ¸½¼þÃûÌþÙÐл¹ÔºÍɳÏä¼ì²â£¬£¬£¬£¬£¬£¬£¬Í¬Ê±¾ß±¸ÌáÈ¡ÕýÎÄÃÜÂëÆÆ½âÄÜÁ¦£¬£¬£¬£¬£¬£¬£¬¿É×Ô¶¯Ê¹ÓÃÓʼþÕýÎÄÃÜÂë±¬ÆÆÑ¹Ëõ°ü¸½¼þ£¬£¬£¬£¬£¬£¬£¬±¬ÆÆÀֳɺó¶Ô¸½¼þ¼°¸½¼þ×ÓÎļþ¾ÙÐмì²â¡£¡£¡£¡£¡£¡£¡£
2¡¢ÐÐΪ¼ì²â
ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©ÄÚÖÃɳÏ䣬£¬£¬£¬£¬£¬£¬³ý¾²Ì¬¼ì²âÍ⣬£¬£¬£¬£¬£¬£¬»¹¿É¶ÔofficeÎļþ¾ÙÐÐÐÐΪ¼ì²âºÍÎó²îʹÓüì²â¡£¡£¡£¡£¡£¡£¡£É³Ïä½ÓÄɵÚÈý´úÓ²¼þ·ÂÕæÊÖÒÕ£¬£¬£¬£¬£¬£¬£¬¿É¶Ô¶ñÒâÑù±¾¾ÙÐÐÓÕÆ£¬£¬£¬£¬£¬£¬£¬Í¨¹ýofficeÎļþÖ´ÐÐÐÐΪ£¬£¬£¬£¬£¬£¬£¬À´Åж϶ñÒâÐÐΪ¡£¡£¡£¡£¡£¡£¡£

ÐÐΪ¼ì²â¸æ¾¯½çÃæ
3¡¢»º½â²½·¥
ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©ÒÑÖ§³ÖCVE-2023-36884Îó²îʹÓüì²â£¬£¬£¬£¬£¬£¬£¬ÇëÓû§²»Òª·¿ªÈªÔ´²»Ã÷µÄofficeÎĵµ£¬£¬£¬£¬£¬£¬£¬ÒѰ²ÅÅTARÓû§¿É½«¿ÉÒÉÎĵµÀëÏßÉÏ´«µ½TAR×°±¸¼ì²â¡£¡£¡£¡£¡£¡£¡£
ÍâµØ»º½â²½·¥£º
¿ÉÉèÖÃÏà¹Ø×¢²á±íÏîÀ´×èÖ¹Ïà¹ØÎó²î±»Ê¹ÓÃ,°ì·¨ÈçÏÂ:
н¨Ò»¸öÎı¾Îĵµ,ÊäÈëÈçÏÂÄÚÈݲ¢ÉúÑÄ¡£¡£¡£¡£¡£¡£¡£
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet
Explorer\Main\FeatureControl\FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION]
"Excel.exe"=dword:00000001
"Graph.exe"=dword:00000001
"MSAccess.exe"=dword:00000001
"MSPub.exe"=dword:00000001
"Powerpnt.exe"=dword:00000001
"Visio.exe"=dword:00000001
"WinProj.exe"=dword:00000001
"WinWord.exe"=dword:00000001
"Wordpad.exe"=dword:00000001
½«ÉúÑĵÄÎļþºó׺ÐÞ¸ÄΪ.reg¡£¡£¡£¡£¡£¡£¡£
Ë«»÷Ð޸ĺóµÄÎļþ,µ¼Èë×¢²á±í¼´¿É¡£¡£¡£¡£¡£¡£¡£
µ¼ÈëÍê³Éºó½¨ÒéÖØÆôËùÓз¿ªµÄOffice³ÌÐòÒÔÈ·±£ÉèÖÃÉúЧ¡£¡£¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ