English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26877
À§Çèµµ 40
Æ÷Æ® 139.445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í 'ÇØ´ç ½Ã½ºÅÛ¿¡´Â 2023³â 3¿ù Microsoft º¸¾È ¾÷µ¥ÀÌÆ®°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê½À´Ï´Ù. µû¶ó¼­ ´ÙÁß Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.

- TPM2.0ÀÇ ¸ðµâ ¶óÀ̺귯¸®¿¡ ¿µ¿ª ¿ÜºÎ ¾²±â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÏ°í CryptParameterDecryption ·çƾ¿¡¼­ TPM2.0 ¸í·ÉÀÇ ³¡À» ³Ñ¾î 2¹ÙÀÌÆ® µ¥ÀÌÅ͸¦ ¾µ ¼ö ÀÖ½À´Ï´Ù. ÀÌ Ãë¾àÁ¡À» ¾Ç¿ëÇÏ´Â µ¥ ¼º°øÇÑ °ø°ÝÀÚ´Â ¼­ºñ½º °ÅºÎ(TPM Ĩ/ÇÁ·Î¼¼½º Ãæµ¹ ¶Ç´Â »ç¿ë ºÒ°¡´É) ¶Ç´Â TPM ÄÁÅؽºÆ®¿¡¼­ ÀÓÀÇ ÄÚµå ½ÇÇàÀ» À¯¹ßÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2023-1017)
- TPM2.0 ¸ðµâ ¶óÀ̺귯¸®¿¡ ¿µ¿ª ¿ÜºÎ Àбâ Ãë¾àÁ¡ÀÌ Á¸ÀçÇϸç CryptParameterDecryption ·çƾ¿¡¼­ TPM2.0 ¸í·ÉÀÇ ³¡À» ³Ñ¾î¼­ 2¹ÙÀÌÆ® ÀбⰡ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ Ãë¾àÁ¡À» ¾Ç¿ëÇÏ´Â µ¥ ¼º°øÇÑ °ø°ÝÀÚ´Â TPM¿¡ ÀúÀåµÈ ¹Î°¨ÇÑ µ¥ÀÌÅ͸¦ ÀÐ°í ¾×¼¼½ºÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2023-1018)
- Remote Procedure Call Runtime ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡ ÇÏÁö ¾Ê°í ´ë½Å ÀÀ¿ë ÇÁ·Î±×·¥ÀÇ ÀÚüº¸°í µÈ ¹öÀü ¹øÈ£¿¡¸¸ ÀÇÁ¸ÇÕ´Ï´Ù. (CVE-2023-21708, CVE-2023-23405,CVE-2023-24869,CVE-2023-24908)

* Âü°í »çÀÌÆ®:
https://support.microsoft.com/en-us/help/4009469
https://support.microsoft.com/en-us/help/4009470
https://support.microsoft.com/en-us/help/4009471
https://support.microsoft.com/en-us/help/4000825

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Windows Server 2008 R2 SP1
Windows Server 2008 R2 x64 SP1
Windows 8.1
Windows Server 2012
Windows Server 2012 R2
Windows 10
Windows 11
Windows Server 2016
Windows Server 2019
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° 2023³â 3¿ù Microsoft º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÑ´Ù.

Https://support.microsoft.com/en-us/help/4009469
https://support.microsoft.com/en-us/help/4009470
https://support.microsoft.com/en-us/help/4009471
https://support.microsoft.com/en-us/help/4000825
-- ¶Ç´Â --
Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼­µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù.
°ü·Ã URL CVE-2023-1017,CVE-2023-1018,CVE-2023-21708,CVE-2023-23385,CVE-2023-23388,CVE-2023-23393,CVE-2023-23394,CVE-2023-23401,CVE-2023-23402 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)