English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26893
À§Çèµµ 40
Æ÷Æ® 139.445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â 2024³â 8¿ù Microsoft º¸¾È ¾÷µ¥ÀÌÆ®°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê½À´Ï´Ù. µû¶ó¼­ ´ÙÁß Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹Þ½À´Ï´Ù.

- Azure °¡»ó ¸Ó½Å SKUSÀÇ ÇÏÀ§ ÁýÇÕÀÌ Æ÷ÇÔµÈ VBS(Virtualization Based Security)¸¦ Áö¿øÇÏ´Â G1Windows ±â¹Ý ½Ã½ºÅÛ¿¡ ±ÇÇÑ ½Â°Ý Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù. ÀÌ·Î ÀÎÇØ °ü¸®ÀÚ ±ÇÇÑÀÌ ÀÖ´Â °ø°ÝÀÚ°¡ Windows ½Ã½ºÅÛ ÆÄÀÏÀÇ ÇöÀç ¹öÀüÀ» ÀÌÀü ¹öÀüÀ¸·Î ¹Ù²Ü ¼ö ÀÖ½À´Ï´Ù. ÀÌ Ãë¾àÁ¡À» ¾Ç¿ëÇÏ¸é °ø°ÝÀÚ°¡ ÀÌÀü¿¡ ¿ÏÈ­µÈ Ãë¾àÁ¡À» ´Ù½Ã µµÀÔÇÏ°í VBSÀÇ ÀϺΠ±â´ÉÀ» ÇÇÇÏ°í VBS·Î º¸È£µÇ´Â µ¥ÀÌÅ͸¦ ÃßÃâÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2024-21302)
- grub_font_construct_glyph() ¿¡¼­ ¹öÆÛ ¿À¹öÇ÷ο찡 ¹ß°ßµÇ¾ú½À´Ï´Ù. ¾ÇÀÇÀû ÀÎ Á¶ÀÛ µÈ pf2 ±Û²ÃÀº max_glyph_size °ªÀ» °è»êÇÒ ¶§ ¿À¹öÇ÷θ¦ ¹ß»ý½ÃÅ°°í glyph¿¡ ÇÊ¿äÇÑ °Íº¸´Ù ÀÛÀº ¹öÆÛ¸¦ ÇÒ´ç ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ·Î ÀÎÇØ ¹öÆÛ ¿À¹öÇ÷οì¿Í Èü ±â¹Ý ¿µ¿ª ¿ÜºÎ ¾²±â°¡ ¹ß»ýÇÕ´Ï´Ù. °ø°ÝÀÚ°¡ ÀÌ Ãë¾àÁ¡À» È°¿ëÇÏ¿© º¸¾È ºÎÆà ¸ÞÄ¿´ÏÁòÀ» ÇÇÇÒ ¼ö ÀÖ½À´Ï´Ù. (CVE-2022-2601)

* Âü°í »çÀÌÆ®:
https://support.microsoft.com/en-us/help/4009469
https://support.microsoft.com/en-us/help/4009470
https://support.microsoft.com/en-us/help/4009471
https://support.microsoft.com/en-us/help/4000825

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Windows Server 2008 R2 SP1
Windows Server 2008 R2 x64 SP1
Windows 8.1
Windows Server 2012
Windows Server 2012 R2
Windows 10
Windows 11
Windows Server 2016
Windows Server 2019
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° 2024³â 8¿ù Microsoft º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÑ´Ù.

Https://support.microsoft.com/en-us/help/4009469
https://support.microsoft.com/en-us/help/4009470
https://support.microsoft.com/en-us/help/4009471
https://support.microsoft.com/en-us/help/4000825
-- ¶Ç´Â --
Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼­µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù.
°ü·Ã URL CVE-2022-2601,CVE-2023-40547,CVE-2024-21302,CVE-2024-38107,CVE-2024-38114,CVE-2024-38178,CVE-2024-38180,CVE-2024-38196,CVE-2024-38223 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)