¡¾Îó²îͨ¸æ¡¿Î¢Èí11Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2025-11-12

Ò»¡¢Îó²î¸ÅÊö


2025Äê11ÔÂ12ÈÕ£¬£¬£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨¼¯ÍÅVSRC¼à²âµ½Î¢ÈíÐû²¼ÁË11ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬±¾´Î¸üÐÂÐÞ¸´ÁË63¸öÎó²î£¬£¬£¬£¬£¬º­¸ÇÌØÈ¨ÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐС¢ÐÅϢй¶µÈ¶àÖÖÎó²îÀàÐÍ ¡£¡£¡£Îó²î¼¶±ðÂþÑÜÈçÏ£º5¸öÑÏÖØ¼¶±ðÎó²î£¬£¬£¬£¬£¬58¸öÖ÷Òª¼¶±ðÎó²î£¨Îó²î¼¶±ðÒÀ¾Ý΢Èí¹Ù·½Êý¾Ý£© ¡£¡£¡£


ÆäÖУ¬£¬£¬£¬£¬6¸öÎó²î±»Î¢Èí±ê¼ÇΪ¡°¸ü¿ÉÄܱ»Ê¹Óá±¼°¡°¼ì²âʹÓÃÇéÐΡ±£¬£¬£¬£¬£¬Åú×¢ÕâЩÎó²î±£´æ½Ï¸ßµÄʹÓÃΣº¦£¬£¬£¬£¬£¬½¨ÒéÓÅÏÈÐÞ¸´ÒÔ½µµÍDZÔÚÇå¾²Íþв ¡£¡£¡£


CVE-ID

CVE ÎÊÌâ

Îó²î¼¶±ð

CVE-2025-59512

Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability

Ö÷Òª

CVE-2025-60705

Windows ¿Í»§¶Ë»º´æÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-60719

WinSock µÄ Windows ¸¨Öú¹¦Ð§Çý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-62213

WinSock µÄ Windows ¸¨Öú¹¦Ð§Çý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-62217

WinSock µÄ Windows ¸¨Öú¹¦Ð§Çý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-62215

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

Ö÷Òª


΢Èí11Ô¸üÐÂÐÞ¸´µÄÍêÕûÎó²îÁбíÈçÏ£º


CVE-ID

CVE ÎÊÌâ

Îó²î¼¶±ð

CVE-2025-30398

Nuance PowerScribe 360 ÐÅϢй¶Îó²î

ÑÏÖØ

CVE-2025-47179

ÉèÖÃÖÎÀíÆ÷ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-59240

Microsoft Excel ÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-59499

Microsoft SQL Server ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-59504

Azure Monitor ÊðÀíÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Ö÷Òª

CVE-2025-59505

Windows Smart Card Reader Elevation of Privilege Vulnerability

Ö÷Òª

CVE-2025-59506

DirectX ͼÐÎÄÚºËÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-59507

Windows ÓïÒôÔËÐÐÊ±ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-59508

Windows Speech Recognition Elevation of Privilege Vulnerability

Ö÷Òª

CVE-2025-59509

Windows Speech Recognition Information Disclosure Vulnerability

Ö÷Òª

CVE-2025-59510

Windows ·ÓɺÍÔ¶³Ì»á¼ûЧÀÍ (RRAS) ¾Ü¾øÐ§ÀÍÎó²î

Ö÷Òª

CVE-2025-59511

Windows WLAN ЧÀÍÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-59512

Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability

Ö÷Òª

CVE-2025-59513

Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability

Ö÷Òª

CVE-2025-59514

Microsoft Á÷ʽ´¦Öóͷ£ÊðÀíÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-59515

Windows Broadcast DVR User Service Elevation of Privilege Vulnerability

Ö÷Òª

CVE-2025-60703

Windows Ô¶³Ì×ÀÃæÐ§ÀÍÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-60704

Windows Kerberos ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-60705

Windows ¿Í»§¶Ë»º´æÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-60706

Windows Hyper-V ÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-60707

Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege Vulnerability

Ö÷Òª

CVE-2025-60708

Storvsp.sys Driver Denial of Service Vulnerability

Ö÷Òª

CVE-2025-60709

Windows ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌáÉýȨÏÞÎó²î

Ö÷Òª

CVE-2025-60710

Host Process for Windows Tasks Elevation of Privilege Vulnerability

Ö÷Òª

CVE-2025-60713

Windows ·ÓɺÍÔ¶³Ì»á¼ûЧÀÍ (RRAS) ÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-60714

Windows OLE Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-60715

Windows ·ÓɺÍÔ¶³Ì»á¼ûЧÀÍ (RRAS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Ö÷Òª

CVE-2025-60716

DirectX ͼÐÎÄÚºËÌØÈ¨ÌáÉýÎó²î

ÑÏÖØ

CVE-2025-60717

Windows Broadcast DVR User Service Elevation of Privilege Vulnerability

Ö÷Òª

CVE-2025-60718

Windows Administrator Protection Elevation of Privilege Vulnerability

Ö÷Òª

CVE-2025-60719

WinSock µÄ Windows ¸¨Öú¹¦Ð§Çý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-60720

Windows ´«ÊäÇý¶¯³ÌÐò½Ó¿Ú (TDI) ת»»Çý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-60721

Windows Administrator Protection Elevation of Privilege Vulnerability

Ö÷Òª

CVE-2025-60722

Microsoft OneDrive for Android Elevation of Privilege Vulnerability

Ö÷Òª

CVE-2025-60723

DirectX ͼÐÎÄں˾ܾøÐ§ÀÍÎó²î

Ö÷Òª

CVE-2025-60724

GDI Ô¶³ÌÖ´ÐдúÂëÎó²î

ÑÏÖØ

CVE-2025-60726

Microsoft Excel ÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-60727

Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-60728

Microsoft Excel ÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-62199

Microsoft Office Ô¶³ÌÖ´ÐдúÂëÎó²î

ÑÏÖØ

CVE-2025-62200

Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-62201

Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-62202

Microsoft Excel ÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-62203

Microsoft Excel Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-62204

Microsoft SharePoint Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-62205

Microsoft Office Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-62206

Microsoft Dynamics 365£¨ÍâµØ£©ÐÅϢй¶Îó²î

Ö÷Òª

CVE-2025-62208

Windows License Manager Information Disclosure Vulnerability

Ö÷Òª

CVE-2025-62209

Windows License Manager Information Disclosure Vulnerability

Ö÷Òª

CVE-2025-62210

Dynamics 365 Field Service£¨ÔÚÏߣ©ÓÕÆ­Îó²î

Ö÷Òª

CVE-2025-62211

Dynamics 365 Field Service£¨ÔÚÏߣ©ÓÕÆ­Îó²î

Ö÷Òª

CVE-2025-62213

WinSock µÄ Windows ¸¨Öú¹¦Ð§Çý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-62214

Visual Studio Ô¶³ÌÖ´ÐдúÂëÎó²î

ÑÏÖØ

CVE-2025-62215

Windows ÄÚºËÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-62216

Microsoft Office Ô¶³ÌÖ´ÐдúÂëÎó²î

Ö÷Òª

CVE-2025-62217

WinSock µÄ Windows ¸¨Öú¹¦Ð§Çý¶¯³ÌÐòÌØÈ¨ÌáÉýÎó²î

Ö÷Òª

CVE-2025-62218

Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability

Ö÷Òª

CVE-2025-62219

Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability

Ö÷Òª

CVE-2025-62220

Windows Subsystem for Linux GUI Remote Code Execution Vulnerability

Ö÷Òª

CVE-2025-62222

ÖÇÄÜÌåAI Óë Visual Studio Code Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Ö÷Òª

CVE-2025-62449

Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability

Ö÷Òª

CVE-2025-62452

Windows ·ÓɺÍÔ¶³Ì»á¼ûЧÀÍ (RRAS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Ö÷Òª

CVE-2025-62453

GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability

Ö÷Òª


¶þ¡¢Ó°Ïì¹æÄ£


ÊÜÓ°ÏìµÄ²úÆ·/¹¦Ð§/ЧÀÍ/×é¼þ°üÀ¨£º

Nuance PowerScribe

Microsoft Configuration Manager

Microsoft Office Excel

SQL Server

Azure Monitor Agent

Windows Smart Card

Windows DirectX

Windows Speech

Windows Routing and Remote Access Service (RRAS)

Windows WLAN Service

Customer Experience Improvement Program (CEIP)

Windows Bluetooth RFCOM Protocol Driver

Microsoft Streaming Service

Windows Broadcast DVR User Service

Windows Remote Desktop

Windows Kerberos

Windows Client-Side Caching (CSC) Service

Role: Windows Hyper-V

Multimedia Class Scheduler Service (MMCSS)

Storvsp.sys Driver

Windows Common Log File System Driver

Host Process for Windows Tasks

Windows OLE

Windows Administrator Protection

Windows Ancillary Function Driver for WinSock

Windows TDX.sys

OneDrive for Android

Microsoft Graphics Component

Microsoft Office

Microsoft Office SharePoint

Microsoft Office Word

Microsoft Dynamics 365 (on-premises)

Windows License Manager

Dynamics 365 Field Service (online)

Visual Studio

Windows Kernel

Microsoft Wireless Provisioning System

Windows Subsystem for Linux GUI

Visual Studio Code CoPilot Chat Extension

GitHub Copilot and Visual Studio Code


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


ÏÖÔÚ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´ ¡£¡£¡£


£¨Ò»£©Windows Update×Ô¶¯¸üÐÂ


Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öà ¡£¡£¡£Ò²¿ÉÑ¡Ôñͨ¹ýÒÔϰ취ÊÖ¶¯¾ÙÐиüУº


1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬ÆÚ´ýϵͳ×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüР¡£¡£¡£

4¡¢¸üÐÂÍê³ÉºóÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üР¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öà ¡£¡£¡£


£¨¶þ£©ÊÖ¶¯×°ÖøüÐÂ


Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüР¡£¡£¡£

2025Äê11ÔÂÇå¾²¸üÐÂÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2025-Nov


²¹¶¡ÏÂÔØÊ¾Àý£¨²Î¿¼£©£º


1.·­¿ªÉÏÊöÏÂÔØÁ´½Ó£¬£¬£¬£¬£¬µã»÷Îó²îÁбíÖÐÒªÐÞ¸´µÄCVEÁ´½Ó ¡£¡£¡£


ͼƬ1.png

Àý1£ºÎ¢ÈíÎó²îÁÐ±í£¨Ê¾Àý£©


2.ÔÚ΢Èíͨ¸æÒ³Ãæµ×²¿×ó²à¡¾²úÆ·¡¿ÁÐÑ¡ÔñÏìÓ¦µÄϵͳÀàÐÍ£¬£¬£¬£¬£¬µã»÷ÓҲࡾÏÂÔØ¡¿Áз­¿ª²¹¶¡ÏÂÔØÁ´½Ó ¡£¡£¡£


ͼƬ2.png

Àý2£ºCVE-2022-21989²¹¶¡ÏÂÔØÊ¾Àý


3.µã»÷¡¾Çå¾²¸üС¿£¬£¬£¬£¬£¬·­¿ª²¹¶¡ÏÂÔØÒ³Ãæ£¬£¬£¬£¬£¬ÏÂÔØÏìÓ¦²¹¶¡²¢¾ÙÐÐ×°Öà ¡£¡£¡£


ͼƬ3.png

Àý3£º²¹¶¡ÏÂÔØ½çÃæ


4.×°ÖÃÍê³ÉºóÖØÆôÅÌËã»ú ¡£¡£¡£


3.2 ÔÝʱ²½·¥


ÔÝÎÞ ¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶ ¡£¡£¡£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ ¡£¡£¡£

ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ ¡£¡£¡£

ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ ¡£¡£¡£

ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È ¡£¡£¡£

ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐÞ¸Ä ¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://msrc.microsoft.com/update-guide/releaseNote/2025-Nov