보안 권고문

MS 제품군 2024년 5월 정기 보안 업데이트 권고

개요

 

Microsoft (https://www.microsoft.com) 에서는 공급한 제품의 취약점을 해결하는 보안 업데이트를 발표하였습니다. 해당하는 제품 사용자는 최신 버전으로 업데이트하시기 바랍니다.

 

대상 제품

 

Azure Monitor Agent
Windows 11 23H2
Windows 11 v22H2
Windows 11 v21H2
Windows 10 22H2
Windows 10 21H2
Windows Server 2022 23H2 버전(Server Core 설치)
Windows Server 2022, Windows Server 2022(Server Core 설치)
Windows Server 2019
Windows Server 2016
Microsoft Office
Microsoft SharePoint
Microsoft .NET
Microsoft Visual Studio
Microsoft Dynamics 365
Microsoft Azure

 

해결된 취약점

 

긴급(Critical) 등급 1종, 중요(Important) 등급 11종의 취약점이 발견되었습니다.

Azure Monitor에서 발생하는 중요 등급의 권한 상승 취약점 (CVE-2024-30060)

Microsoft Edge (Chromium-based) 정보 공개 취약성 (CVE-2024-29987)

Google Chrome에서 Picture In Picture의 Use After Free 취약성 (CVE-2024-4331)

Google Chrome에서 WebAudio의 힙 버퍼 오버플로우 취약성 (CVE-2024-4559)

Google Chrome에서 Dawn의 Use After Free 취약성 (CVE-2024-4948)

Microsoft Edge (Chromium-based) 보안 기능 우회 취약성 (CVE-2024-29991)

Microsoft Edge (Chromium-based) 스푸핑 취약성 (CVE-2024-30055)

Microsoft Edge(Chromium 기반) 정보 공개 취약성 (CVE-2024-30056)

Google Chrome에서 V8의 Use After Free 취약성 (CVE-2024-4949)

Google Chrome에서 V8의 Use After Free 취약성 (CVE-2024-3914)

Google Chrome에서 ANGLE의 Use After Free 취약성 (CVE-2024-4558)

Google Chrome에서 Dawn의 Use After Free 취약성 (CVE-2024-4368)

Azure Monitor Agent 권한 상승 취약성 (CVE-2024-30060)

Microsoft Edge for Android (Chromium-based) 정보 공개 취약성 (CVE-2024-29986)

Google Chrome에서 Downloads의 부적절한 구현 취약성 (CVE-2024-4950)

 

취약점 패치

 

2024년 05월 16일 업데이트를 통해 제품별 취약점 패치가 다음과 같이 제공되었습니다. Windows Update 기능을 이용한 자동 설치 또는 아래 제품정보의 URL을 참고하여 다운로드 후 설치하십시오.

https://msrc.microsoft.com/update-guide/

 

참고 사이트

 

[1] (한글) https://msrc.microsoft.com/update-guide/ko-kr/
[2] (영문) https://msrc.microsoft.com/update-guide/en-us/
[3] https://msrc.microsoft.com/update-guide/ko-kr/releaseNote/2024-May