KB5028407:如何管理與 CVE-2023-32019 相關的漏洞

套用到
Windows 11 SE, version 22H2 Windows 11 Home and Pro, version 22H2 Windows 11 Enterprise Multi-Session, version 22H2 Windows 11 Enterprise and Education, version 22H2 Windows 11 IoT Enterprise, version 22H2 Windows 11 SE, version 21H2 Windows 11 Home and Pro, version 21H2 Windows 11 Enterprise and Education, version 21H2 Windows 11 IoT Enterprise, version 21H2 Windows 10 Enterprise and Education, version 20H2 Windows 10 IoT Enterprise, version 20H2 Windows 10 Home and Pro, version 21H2 Windows 10 Enterprise and Education, version 21H2 Windows 10 IoT Enterprise, version 21H2 Windows 10 Home and Pro, version 22H2 Windows 10 Enterprise Multi-Session, version 22H2 Windows 10 Enterprise and Education, version 22H2 Windows 10 IoT Enterprise, version 22H2 Windows Server 2022 Windows Server 2019 Windows 10 Enterprise, version 1809 Windows Server 2016 Windows 10 Education, version 1607 Windows 10 Professional version 1607 Windows 10 Enterprise, version 1607 Windows 10 Enterprise version 1607 Windows 10 Professional Education version 1607 Windows 10 Pro Education, version 1607

注意

重要 本文所述的解決方案已預設啟用。 要套用預設啟用的解析度,請安裝 2023 年 8 月 8 日或之後的 Windows 更新。 不需要進一步的使用者操作。

摘要

經過認證的使用者 (攻擊者) 可能導致 Windows 核心的資訊洩漏漏洞。 此漏洞不需要管理員或其他提升權限。

成功利用此漏洞的攻擊者可能會查看伺服器上運行的特權程序的堆積記憶體。

成功利用此漏洞需要攻擊者與系統中另一位使用者執行的特權程序協調攻擊。

欲了解更多關於此漏洞的資訊,請參閱 CVE-2023-32019 |Windows 核心資訊揭露漏洞

解決方法

我們建議您安裝 2023 年 8 月 8 日或之後發布的 Windows 安全更新,以解決與 CVE-2023-32019 相關的漏洞。 2023 年 8 月 8 日或之後發布的 Windows 安全更新預設已啟用該解析度。

如果您安裝了 2023 年 6 月或 7 月發布的 Windows 安全更新,您必須透過根據下方 Windows 作業系統設定登錄檔鍵值來啟用該解決方案的保護。

針對 Windows 11,版本 22H2

登記處位置: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides

DWORD 名稱: 4237806220

價值資料: 1

針對 Windows 11,版本 21H2

登記處位置: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides

DWORD 名稱: 4204251788

價值資料: 1

針對 Windows 10,版本為 20H2、21H2 和 22H2

登記處位置: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides

DWORD 名稱: 4103588492

價值資料: 1

針對 Windows Server 2022

登記處位置: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides

DWORD 名稱: 4137142924

價值資料: 1

針對 Windows 10 版本 1809 及 Windows Server 2019 版本

登記處位置: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\設定管理員

DWORD 名稱: LazyRetryOnCommitFailure

價值資料: 0

針對 Windows 10、版本 1607 及 Windows Server 2016

登記處位置: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\設定管理員

DWORD 名稱: LazyRetryOnCommitFailure

價值資料: 0

參考

了解用來說明 Microsoft 軟體更新的標準術語

變更日誌
變更日期 變更描述
2023 年 8 月 9 日 在文章頂部及「解決」部分新增了關於已預設啟用的解決方案的備註。 不需要進一步的使用者操作。
2023年8月18日 移除了「解決」區塊中關於破壞性變更驗證的建議,因為經過多次調查與測試,未發現與此更新相關的問題。