<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Windows作業系統 &#8211; 科技島-掌握科技新聞、科技職場最新資訊</title>
	<atom:link href="https://www.technice.com.tw/tag/windows%e4%bd%9c%e6%a5%ad%e7%b3%bb%e7%b5%b1/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.technice.com.tw</link>
	<description>專注於科技新聞、科技職場、科技知識相關資訊，包含生成式AI、人工智慧、Web 3.0、區塊鏈、科技職缺百科、生物科技、軟體發展、雲端技術等豐富內容，適合熱衷科技及從事科技專業人事第一手資訊的平台。</description>
	<lastBuildDate>Wed, 15 Mar 2023 09:34:35 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.4.2</generator>

<image>
	<url>https://www.technice.com.tw/wp-content/uploads/2022/12/cropped-wordpress_512x512-150x150.png</url>
	<title>Windows作業系統 &#8211; 科技島-掌握科技新聞、科技職場最新資訊</title>
	<link>https://www.technice.com.tw</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>微軟修復Outlook零時差漏洞　預防駭客繞過身分認證</title>
		<link>https://www.technice.com.tw/uncategorized/42317/</link>
					<comments>https://www.technice.com.tw/uncategorized/42317/#respond</comments>
		
		<dc:creator><![CDATA[科技新知]]></dc:creator>
		<pubDate>Wed, 15 Mar 2023 09:34:34 +0000</pubDate>
				<category><![CDATA[其他]]></category>
		<category><![CDATA[Windows作業系統]]></category>
		<category><![CDATA[安全漏洞]]></category>
		<category><![CDATA[微軟（Microsoft）]]></category>
		<guid isPermaLink="false">https://www.technice.com.tw/?p=42317</guid>

					<description><![CDATA[<p><img width="1200" height="627" src="https://www.technice.com.tw/wp-content/uploads/2023/03/158370337_fb-link_normal_none.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="158370337 fb link normal none" decoding="async" srcset="https://www.technice.com.tw/wp-content/uploads/2023/03/158370337_fb-link_normal_none.jpg 1200w, https://www.technice.com.tw/wp-content/uploads/2023/03/158370337_fb-link_normal_none-300x157.jpg 300w, https://www.technice.com.tw/wp-content/uploads/2023/03/158370337_fb-link_normal_none-1024x535.jpg 1024w, https://www.technice.com.tw/wp-content/uploads/2023/03/158370337_fb-link_normal_none-768x401.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" title="微軟修復Outlook零時差漏洞　預防駭客繞過身分認證 4"></p>
<p>編譯／鄭智懷 在美國當地時間14日，科技巨頭微軟（Microsoft）發布Windows作業系統與軟體工具的7 &#8230;<content><!-- wp:paragraph --></p>
<p>編譯／鄭智懷</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>在美國當地時間14日，科技巨頭微軟（Microsoft）發布Windows作業系統與軟體工具的74個安全漏洞的補丁，以防駭客用來攻擊客戶。其中有6個漏洞威脅程度為嚴重、67個漏洞威脅程度被列為重要，只有1個漏洞威脅程度是中等。在74個安全漏洞中，最值得注意的是命名為CVE -2023-23397的Outlook漏洞，其允許駭客繞過身分認證，輕易入侵受害者資訊設備。</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>網路媒體BleepingComputer報導，由俄國軍事情報局（GRU）支持的駭客集團在2022年4月中旬至12月之間，積極利用CVE -2023-23397展開15個政府、軍事、能源與運輸單位的網路攻擊。烏克蘭電腦應急響應小組（CERT-UA）發現，並向各界通報本起攻擊活動。</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":42318,"sizeSlug":"large","linkDestination":"none"} --></p>
<figure class="wp-block-image size-large"><img src="https://www.technice.com.tw/wp-content/uploads/2023/03/158370337_fb-link_normal_none-1024x535.jpg" alt="" class="wp-image-42318"/><figcaption class="wp-element-caption">在美國當地時間14日，微軟（Microsoft）發布Windows作業系統與軟體工具的74個安全漏洞的補丁，以防駭客用來攻擊客戶。其中有6個漏洞威脅程度為嚴重、67個漏洞威脅程度被列為重要，只有1個漏洞威脅程度是中等。示意圖:RF123</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>微軟在報告中提到，「攻擊者透過發送特製電子郵件以利用此漏洞」。當Outlook用戶檢索和處理時就會觸發CVE -2023-23397，即使是在預覽該惡意郵件之前都會導致駭客得以繞過NTLM身分驗證，以展開後續攻擊。</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>據悉，CVE -2023-23397影響所有Windows作業系統的Outlook版本；不過，Android、iOS 與macOS系統下的Outlook並不受該漏洞影響。另外，Outlook線上版與Microsoft 365等線上服務並不支援NTLM身分驗證，引此也不受本漏洞影響。</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>微軟建議，為了降低損失，客戶應立即透過更新，修補CVE-2023-23397。同時，該公司還發布一款專用的PowerShell 腳本，協助用戶在Exchange軟體中搜尋是否已成為駭客利用該漏洞攻擊的目標。假使發現潛在的惡意郵件，該腳本還可以幫助客戶修改或刪除之。</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>資料來源：<a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-outlook-zero-day-used-by-russian-hackers-since-april-2022/">BleepingComputer</a>、<a href="https://securityaffairs.com/143486/security/microsoft-patch-tuesday-march-2023.html">Security Affairs</a></p>
<p><!-- /wp:paragraph --></content></p>
<p>這篇文章 <a rel="nofollow" href="https://www.technice.com.tw/uncategorized/42317/">微軟修復Outlook零時差漏洞　預防駭客繞過身分認證</a> 最早出現於 <a rel="nofollow" href="https://www.technice.com.tw">科技島-掌握科技新聞、科技職場最新資訊</a>。</p>
]]></description>
		
					<wfw:commentRss>https://www.technice.com.tw/uncategorized/42317/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
