¡¾Îó²îͨ¸æ¡¿Î¢Èí5Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2025-05-14

Ò»¡¢Îó²î¸ÅÊö


2025Äê5ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬bevictorΰµÂ¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË5ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬£¬±¾´Î¸üÐÂÐÞ¸´ÁË78¸öÎó²î£¬£¬£¬£¬£¬£¬º­¸ÇȨÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐС¢Çå¾²¹¦Ð§ÈƹýµÈ¶àÖÖÎó²îÀàÐÍ¡£¡£¡£¡£Îó²î¼¶±ðÂþÑÜÈçÏ£º11¸öÑÏÖØ¼¶±ðÎó²î£¬£¬£¬£¬£¬£¬66¸öÖ÷Òª¼¶±ðÎó²î£¬£¬£¬£¬£¬£¬1¸öµÍΣ¼¶±ðÎó²î£¨Îó²î¼¶±ðÒÀ¾Ý΢Èí¹Ù·½Êý¾Ý£©¡£¡£¡£¡£


ÆäÖУ¬£¬£¬£¬£¬£¬13¸öÎó²î±»Î¢Èí±ê¼ÇΪ¡°¸ü¿ÉÄܱ»Ê¹Óá±¼°¡°¼ì²âʹÓÃÇéÐΡ±£¬£¬£¬£¬£¬£¬Åú×¢ÕâЩÎó²î±£´æ½Ï¸ßµÄʹÓÃΣº¦£¬£¬£¬£¬£¬£¬½¨ÒéÓÅÏÈÐÞ¸´ÒÔ½µµÍDZÔÚÇå¾²Íþв¡£¡£¡£¡£


CVE-ID

CVE ÎÊÌâ

Îó²î¼¶±ð

CVE-2025-30397

¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î

Ö÷Òª

CVE-2025-30400

Microsoft DWM ½¹µã¿âȨÏÞÌáÉýÎó²î

Ö÷Òª

CVE-2025-32701

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌáÉýȨÏÞÎó²î

Ö÷Òª

CVE-2025-32706

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌáÉýȨÏÞÎó²î

Ö÷Òª

CVE-2025-32709

WinSock µÄ Windows ¸¨Öú¹¦Ð§Çý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-30388

Windows ͼÐÎ×é¼þÔ¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-24063

ÄÚºËÁ÷ʽ´¦Öóͷ£Ð§ÀÍÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-29841

ͨÓôòÓ¡ÖÎÀíЧÀÍÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-29971

Web Íþв·ÀÓù (WTD.sys) ¾Ü¾øÐ§ÀÍÎó²î

Ö÷Òª

CVE-2025-29976

Microsoft SharePoint Server ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-30382

Microsoft SharePoint Server Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-30385

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌáÉýȨÏÞÎó²î

Ö÷Òª

CVE-2025-30386

Microsoft Office Ô¶³ÌÖ´ÐдúÂëÎó²î

ÑÏÖØ


΢Èí5Ô¸üÐÂÐÞ¸´µÄÍêÕûÎó²îÁбíÈçÏ£º


CVE-ID

CVE ÎÊÌâ

Îó²î¼¶±ð

CVE-2025-21264

Visual Studio Code Çå¾²¹¦Ð§ÈƹýÎó²î

Ö÷Òª

CVE-2025-24063

ÄÚºËÁ÷ʽ´¦Öóͷ£Ð§ÀÍÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-26646

.NET¡¢Visual Studio ºÍ Visual Studio ¹¹½¨¹¤¾ßÓÕÆ­Îó²î

Ö÷Òª

CVE-2025-26677

Windows Ô¶³Ì×ÀÃæÐ­Ò飨RD Íø¹Ø£©¾Ü¾øÐ§ÀÍÎó²î

Ö÷Òª

CVE-2025-26684

Microsoft Defender ȨÏÞÌáÉýÎó²î

Ö÷Òª

CVE-2025-26685

Microsoft Defender for Identity ÓÕÆ­Îó²î

Ö÷Òª

CVE-2025-27468

Windows ÄÚºËģʽÇý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-27488

Microsoft Windows Hardware Lab Kit (HLK) ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-29813

Azure DevOps Server ÌØÈ¨ÌáÉýÎó²î

ÑÏÖØ

CVE-2025-29825

»ùÓÚChromium µÄ Microsoft Edge ÓÕÆ­Îó²î

µÍ

CVE-2025-29826

Microsoft Dataverse ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-29827

Azure ×Ô¶¯»¯ÌØÈ¨ÌáÉýÎó²î

ÑÏÖØ

CVE-2025-29829

Windows ÊÜÐÅÈÎÔËÐÐʱ½Ó¿ÚÇý¶¯³ÌÐòÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-29830

Windows ·ÓɺÍÔ¶³Ì»á¼ûЧÀÍ (RRAS) ÐÅÏ¢Åû¶Îó²î

Ö÷Òª

CVE-2025-29831

Windows Ô¶³Ì×ÀÃæÐ§ÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Ö÷Òª

CVE-2025-29832

Windows ·ÓɺÍÔ¶³Ì»á¼ûЧÀÍ (RRAS) ÐÅÏ¢Åû¶Îó²î

Ö÷Òª

CVE-2025-29833

Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability

ÑÏÖØ

CVE-2025-29835

Windows Ô¶³Ì»á¼ûÅþÁ¬ÖÎÀíÆ÷ÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-29836

Windows ·ÓɺÍÔ¶³Ì»á¼ûЧÀÍ (RRAS) ÐÅÏ¢Åû¶Îó²î

Ö÷Òª

CVE-2025-29837

Windows Installer ÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-29838

Windows ExecutionContext Çý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-29839

Windows ¶à UNC Ìṩ³ÌÐòÇý¶¯³ÌÐòÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-29840

Windows Media Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-29841

ͨÓôòÓ¡ÖÎÀíЧÀÍÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-29842

UrlMon Çå¾²¹¦Ð§ÈƹýÎó²î

Ö÷Òª

CVE-2025-29954

Windows ÇáÁ¿¼¶Ä¿Â¼»á¼ûЭÒé (LDAP) ¾Ü¾øÐ§ÀÍÎó²î

Ö÷Òª

CVE-2025-29955

Windows Hyper-V ¾Ü¾øÐ§ÀÍÎó²î

Ö÷Òª

CVE-2025-29956

Windows SMB ÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-29957

Windows °²ÅÅЧÀ;ܾøÐ§ÀÍÎó²î

Ö÷Òª

CVE-2025-29958

Windows ·ÓɺÍÔ¶³Ì»á¼ûЧÀÍ (RRAS) ÐÅÏ¢Åû¶Îó²î

Ö÷Òª

CVE-2025-29959

Windows ·ÓɺÍÔ¶³Ì»á¼ûЧÀÍ (RRAS) ÐÅÏ¢Åû¶Îó²î

Ö÷Òª

CVE-2025-29960

Windows ·ÓɺÍÔ¶³Ì»á¼ûЧÀÍ (RRAS) ÐÅÏ¢Åû¶Îó²î

Ö÷Òª

CVE-2025-29961

Windows ·ÓɺÍÔ¶³Ì»á¼ûЧÀÍ (RRAS) ÐÅÏ¢Åû¶Îó²î

Ö÷Òª

CVE-2025-29962

Windows Media Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-29963

Windows Media Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-29964

Windows Media Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-29966

Ô¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³ÌÖ´ÐдúÂëÎó²î

ÑÏÖØ

CVE-2025-29967

Ô¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³ÌÖ´ÐдúÂëÎó²î

ÑÏÖØ

CVE-2025-29968

Active Directory Ö¤ÊéЧÀÍ (AD CS) ¾Ü¾øÐ§ÀÍÎó²î

Ö÷Òª

CVE-2025-29969

MS-EVEN RPC Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Ö÷Òª

CVE-2025-29970

Microsoft ÊðÀíÎļþÏµÍ³ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-29971

Web Íþв·ÀÓù (WTD.sys) ¾Ü¾øÐ§ÀÍÎó²î

Ö÷Òª

CVE-2025-29972

Azure ´æ´¢×ÊÔ´Ìṩ³ÌÐòÓÕÆ­Îó²î

ÑÏÖØ

CVE-2025-29973

Microsoft Azure Îļþͬ²½ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-29974

Windows ÄÚºËÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-29975

Microsoft PC Manager ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-29976

Microsoft SharePoint Server ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-29977

Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-29978

Microsoft PowerPoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Ö÷Òª

CVE-2025-29979

Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-30375

Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-30376

Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-30377

Microsoft Office Ô¶³ÌÖ´ÐдúÂëÎó²î

ÑÏÖØ

CVE-2025-30378

Microsoft SharePoint Server Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-30379

Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-30381

Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-30382

Microsoft SharePoint Server Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-30383

Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-30384

Microsoft SharePoint Server Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-30385

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌáÉýȨÏÞÎó²î

Ö÷Òª

CVE-2025-30386

Microsoft Office Ô¶³ÌÖ´ÐдúÂëÎó²î

ÑÏÖØ

CVE-2025-30387

Document Intelligence Studio On-Prem ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-30388

Windows ͼÐÎ×é¼þÔ¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-30393

Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-30394

Windows Ô¶³Ì×ÀÃæÐ­Ò飨RD Íø¹Ø£©¾Ü¾øÐ§ÀÍÎó²î

Ö÷Òª

CVE-2025-30397

¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î

Ö÷Òª

CVE-2025-30400

Microsoft DWM ½¹µã¿âȨÏÞÌáÉýÎó²î

Ö÷Òª

CVE-2025-32701

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌáÉýȨÏÞÎó²î

Ö÷Òª

CVE-2025-32702

Visual Studio Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-32703

Visual Studio ÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-32704

Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-32705

Microsoft Outlook Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Ö÷Òª

CVE-2025-32706

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌáÉýȨÏÞÎó²î

Ö÷Òª

CVE-2025-32707

NTFS ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-32709

WinSock µÄ Windows ¸¨Öú¹¦Ð§Çý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-33072

Microsoft msagsfeedback.azurewebsites.net ÐÅϢй¶Îó²î

ÑÏÖØ

CVE-2025-47732

Microsoft Dataverse Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2025-47733

Microsoft Power Apps ÐÅϢй¶Îó²î

ÑÏÖØ


¶þ¡¢Ó°Ïì¹æÄ£


ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/ЧÀÍ/×é¼þ°üÀ¨£º


Visual Studio Code

Windows Kernel

.NET, Visual Studio, and Build Tools for Visual Studio

Remote Desktop Gateway Service

Microsoft Defender for Endpoint

Microsoft Defender for Identity

Windows Secure Kernel Mode

Windows Hardware Lab Kit

Azure DevOps

Microsoft Edge (Chromium-based)

Microsoft Dataverse

Azure Automation

Windows Trusted Runtime Interface Driver

Windows Routing and Remote Access Service (RRAS)

Windows Virtual Machine Bus

Windows Installer

Windows Drivers

Windows File Server

Windows Media

Universal Print Management Service

UrlMon

Windows LDAP - Lightweight Directory Access Protocol

Role: Windows Hyper-V

Windows SMB

Windows Deployment Services

Windows Remote Desktop

Active Directory Certificate Services (AD CS)

Windows Fundamentals

Microsoft Brokering File System

Web Threat Defense (WTD.sys)

Azure Storage Resource Provider

Azure File Sync

Microsoft PC Manager

Microsoft Office SharePoint

Microsoft Office Excel

Microsoft Office PowerPoint

Microsoft Office

Windows Common Log File System Driver

Azure

Windows Win32K - GRFX

Microsoft Scripting Engine

Windows DWM

Visual Studio

Microsoft Office Outlook

Windows NTFS

Windows Ancillary Function Driver for WinSock

Microsoft Power Apps


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£


£¨Ò»£©Windows Update×Ô¶¯¸üÐÂ


Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϰ취ÊÖ¶¯¾ÙÐиüУº


1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£

4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£


£¨¶þ£©ÊÖ¶¯×°ÖøüÐÂ


Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£


2025Äê5ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2025-May


²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º


1.·­¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬£¬£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó¡£¡£¡£¡£


ͼƬ1.png

Àý1£ºÎ¢ÈíÎó²îÁÐ±í£¨Ê¾Àý£©


2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿ÁÐÑ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áз­¿ª²¹¶¡ÏÂÔØÁ´½Ó¡£¡£¡£¡£


ͼƬ2.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý


3.µã»÷¡¾Çå¾²¸üС¿£¬£¬£¬£¬£¬£¬·­¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬£¬£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öᣡ£¡£¡£


ͼƬ3.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ


4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú¡£¡£¡£¡£


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£

ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£

ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£

ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£

ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://msrc.microsoft.com/update-guide/releaseNote/2025-May