微軟Patch Tuesday修補兩個零時差漏洞
· 2023-09-13

Zero Day Initiative(ZDI)團隊將已發生實際攻擊的CVE-2023-36761列為優先修補漏洞,這項涉及Word的零時差漏洞讓攻擊者透過預覽窗格便能展開攻擊,不需要與使用者互動

至於CVE-2023-36802則是Microsoft Streaming Service Proxy的權限擴張漏洞,成功的攻擊將允許駭客取得系統權限。

上述漏洞雖已被利用,但僅被微軟列為重要(Important)漏洞。

本月微軟修補了5個重大(Critical)漏洞,最嚴重的是涉及Internet Connection Sharing(ICS)的遠端程式攻擊漏洞CVE-2023-38148,另有3個遠端程式攻擊漏洞與Visual Studio有關,分別是CVE-2023-36792、CVE-2023-36793與CVE-2023-36796,還有一個是Microsoft Azure Kubernetes Service的權限擴張漏洞CVE-2023-29332。

ICS為Windows中的一項網路服務,允許一臺連結網際網路的Windows電腦分享網路予其它在同一區域網路上的電腦,CVE-2023-38148漏洞讓駭客只要傳送一個特製的封包至ICS服務便能展開攻擊。而駭客若能成功利用Azure Kubernetes中的CVE-2023-29332漏洞,即可取得叢集管理員權限。

而CVE-2023-36792、CVE-2023-36793與CVE-2023-36796雖然是不同的Visual Studio漏洞,但攻擊場景類似,駭客只要說服目標對象於Visual Studio中開啟一個惡意檔案就能進行攻擊,以執行任意程式。

Popular articles
Gaming & Technology Expo Makes a Powerful Entrance in CDMX
Marketing
Indiana online casino bill stalls in House committee
Regulation
British gambling levy rates confirmed for each vertical
Regulation
Across 6 Cities: HUIDU Invites You to 8 World Cup Parties Redefining High-Value Social Networking
HUIDU Focus
UK MPs reopen 2025 gambling inquiry as reform stalls
Regulation
HUIDU Invites You to Booth T70 at iGB L!VE 2026 — Let’s Ignite London This July!
HUIDU Focus
Brazil Proposes Raising Gambling Tax Rate to 24%, With Revenue Allocated to Social Security and Healthcare
Regulation
GAT Expo Puerto Rico Will Pulse with the New Era of Gaming in the Caribbean
Marketing
B2B Tech Infrastructure Gains Momentum in Philippine Gaming Sector
Southeast Asia
1spin4win releases unique slot Don Catleone Hold and Win featuring gangster cats
Online Game
Are you ready to maximize your earnings? Try ProPush.me Constructor!
Marketing
GAT CDMX 2025 Institutional Academy: Leaders and Experts Analyze the Present and Future of the Gaming Industry in Mexico and Lat
Sports Game
Institutional Academy that exceeded expectations marked the opening of GAT CDMX
Online Game
Vietnam’s Controlled Gaming Shift Gains Ground, But Domestic Demand Still Lags
Southeast Asia
Online gambling, crypto pose ongoing money laundering risks in Philippines, analyst says
Southeast Asia
Home
Game
Cooperation
Find
My