漏洞描述:
微软发布了4月安全更新,本次更新修复了125个漏洞,涵盖权限提升、远程代码执行、安全功能绕过等多种漏洞类型,漏洞级别分布如下:
11个严重级别漏洞,112个重要级别漏洞,2个低危级别漏洞(漏洞级别依据微软官方数据)。
其中,12个漏洞被微软标记为“更可能被利用”及“检测利用情形”,表明这些漏洞存在较高的利用风险,建议优先修复以降低潜在安全威胁。
微软4月更新修复的完整漏洞列表如下:
影响范围:
受影响的产品/功能/服务/组件包括:
Visual Studio Code
Windows Standards-Based Storage Management Service
Windows Local Security Authority (LSA)
Windows NTFS
Windows Routing and Remote Access Service (RRAS)
Windows Update Stack
Windows Telephony Service
Windows DWM Core Library
Microsoft Edge (Chromium-based)
Azure Local Cluster
Windows Hello
Windows BitLocker
Windows USB Print Driver
Windows Digital Media
Windows Cryptographic Services
Microsoft Office
Windows Kerberos
Windows Kernel
Windows Secure Channel
Windows Local Session Manager (LSM)
Windows LDAP - Lightweight Directory Access Protocol
Windows upnphost.dll
Windows Media
Windows Remote Desktop Services
Windows Subsystem for Linux
Windows Defender Application Control (WDAC)
RPC Endpoint Mapper Service
Windows Win32K - GRFX
ASP.NET Core
Windows TCP/IP
Microsoft Virtual Hard DriveMicrosoft Streaming Service
Windows Mark of the Web (MOTW)
Windows HTTP.sys
Remote Desktop Gateway Service
Windows Universal Plug and Play (UPnP) Device Host
Remote Desktop Client
Azure Local
Windows Bluetooth Service
Windows Hyper-V
Windows Installer
Windows Kernel-Mode Drivers
Windows Shell
OpenSSH for Windows
Windows Virtualization-Based Security (VBS) Enclave
Windows Power Dependency Coordinator
Windows Security Zone Mapping
Windows Resilient File System (ReFS)
Windows Active Directory Certificate Services
System Center
Microsoft Office Word
Microsoft Office Excel
Microsoft Office SharePoint
Microsoft Edge for iOS
Microsoft AutoUpdate (MAU)
Visual Studio
Visual Studio Tools for Applications and SQL Server Management Studio
Outlook for Android
Active Directory Domain Services
Windows Mobile Broadband
Windows Kernel Memory
Power Automate
Azure Portal Windows Admin Center
Dynamics Business Central
Microsoft Office OneNote
Windows Common Log File System Driver
修复建议:
Microsoft官方下载相应补丁进行更新
2025年4月安全更新下载链接:
https://msrc.microsoft.com/update-guide/releaseNote/2025-Apr
推荐站内搜索:最好用的开发软件、免费开源系统、渗透测试工具云盘下载、最新渗透测试资料、最新黑客工具下载……
还没有评论,来说两句吧...