MS 11¿ù º¸¾È À§Çù¿¡ µû¸¥ Á¤±â º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í
°ü¸®ÀÚ ( hosting@hhosting.co.kr ) 2025-11-14 09:15:37
Á¶È¸¼ö 181
¡à 11¿ù º¸¾È¾÷µ¥ÀÌÆ® °³¿ä (ÃÑ 14 Á¾ )
o µî±Þ : ±ä±Þ (Critical) 9 Á¾ , Áß¿ä (Important) 5 Á¾
o ¹ßÇ¥ÀÏ : 2025.11.11.(È)
o ¾÷µ¥ÀÌÆ® ³»¿ë
Á¦Ç°±º
Á߿䵵
¿µÇâ
Windows 11 25H2
±ä±Þ
±ÇÇÑ »ó½Â
Windows 11 24H2
±ä±Þ
±ÇÇÑ »ó½Â
Windows 11 23H2
±ä±Þ
±ÇÇÑ »ó½Â
Windows Server 2025, Windows Server 2025(Server Core ¼³Ä¡)
±ä±Þ
±ÇÇÑ »ó½Â
Windows Server 2022 23H2 ¹öÀü(Server Core ¼³Ä¡),
Windows Server 2022, Windows Server 2022(Server Core ¼³Ä¡)
±ä±Þ
±ÇÇÑ »ó½Â
Windows Server 2019
±ä±Þ
±ÇÇÑ »ó½Â
Windows Server 2016
±ä±Þ
±ÇÇÑ »ó½Â
Microsoft Office
±ä±Þ
¿ø°Ý ÄÚµå ½ÇÇà
Microsoft SharePoint
Áß¿ä
¿ø°Ý ÄÚµå ½ÇÇà
Microsoft Visual Studio
±ä±Þ
¿ø°Ý ÄÚµå ½ÇÇà
Microsoft Dynamics 365
Áß¿ä
½ºÇªÇÎ
Microsoft SQL Server
Áß¿ä
±ÇÇÑ »ó½Â
Microsoft Azure
Áß¿ä
¿ø°Ý ÄÚµå ½ÇÇà
Microsoft System Center
Áß¿ä
±ÇÇÑ »ó½Â
[Âü°í »çÀÌÆ®]
[1] (ÇѱÛ) https://msrc.microsoft.com/update-guide/ko-kr/
[2] (¿µ¹®) https://msrc.microsoft.com/update-guide/en-us/
[3] https://msrc.microsoft.com/update-guide/ko-kr/releaseNote/2025-Nov
o Ãë¾àÁ¡ ¿ä¾à Á¤º¸ (ÃÑ 134°³)
Á¦Ç° Ä«Å×°í¸®
CVE ¹øÈ£
CVE Á¦¸ñ
Mariner
CVE-2025-64437
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes
Mariner
CVE-2025-64436
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Mariner
CVE-2025-64435
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation
Mariner
CVE-2025-64434
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing
Mariner
CVE-2025-64433
KubeVirt Arbitrary Container File Read
Mariner
CVE-2025-64432
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer
Mariner
CVE-2025-64329
containerd CRI server: Host memory exhaustion through Attach goroutine leak
GitHub Copilot and Visual Studio Code
CVE-2025-62453
GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
Windows Routing and Remote Access Service (RRAS)
CVE-2025-62452
Windows RRAS(Routing and Remote Access Service) ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Visual Studio Code CoPilot Chat Extension
CVE-2025-62449
Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability
Visual Studio Code CoPilot Chat Extension
CVE-2025-62222
¿¡ÀÌÀüÆ® AI ¹× Visual Studio Code ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Windows Subsystem for Linux GUI
CVE-2025-62220
Windows Subsystem for Linux GUI Remote Code Execution Vulnerability
Microsoft Wireless Provisioning System
CVE-2025-62219
Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability
Microsoft Wireless Provisioning System
CVE-2025-62218
Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock
CVE-2025-62217
WinSock¿ë Windows º¸Á¶ ±â´É µå¶óÀ̹ö ±ÇÇÑ »ó½Â Ãë¾à¼º
Microsoft Office
CVE-2025-62216
Microsoft Office ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Windows Kernel
CVE-2025-62215
Windows Ä¿³Î ±ÇÇÑ »ó½Â Ãë¾à¼º
Visual Studio
CVE-2025-62214
Visual Studio ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Windows Ancillary Function Driver for WinSock
CVE-2025-62213
WinSock¿ë Windows º¸Á¶ ±â´É µå¶óÀ̹ö ±ÇÇÑ »ó½Â Ãë¾à¼º
Dynamics 365 Field Service (online)
CVE-2025-62211
Dynamics 365 Field Service(¿Â¶óÀÎ) ½ºÇªÇÎ Ãë¾à¼º
Dynamics 365 Field Service (online)
CVE-2025-62210
Dynamics 365 Field Service(¿Â¶óÀÎ) ½ºÇªÇÎ Ãë¾à¼º
Windows License Manager
CVE-2025-62209
Windows License Manager Information Disclosure Vulnerability
Windows License Manager
CVE-2025-62208
Windows License Manager Information Disclosure Vulnerability
Microsoft Dynamics 365 (on-premises)
CVE-2025-62206
Microsoft Dynamics 365(¿Â-ÇÁ·¹¹Ì½º) Á¤º¸ °ø°³ Ãë¾à¼º
Microsoft Office Word
CVE-2025-62205
Microsoft Office ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Microsoft Office SharePoint
CVE-2025-62204
Microsoft SharePoint ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Microsoft Office Excel
CVE-2025-62203
Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Microsoft Office Excel
CVE-2025-62202
Microsoft Excel Á¤º¸ À¯Ãâ Ãë¾à¼º
Microsoft Office Excel
CVE-2025-62201
Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Microsoft Office Excel
CVE-2025-62200
Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Microsoft Office
CVE-2025-62199
Microsoft Office ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Mariner
CVE-2025-60753
An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).
Microsoft Office Excel
CVE-2025-60728
Microsoft Excel Á¤º¸ À¯Ãâ Ãë¾à¼º
Microsoft Office Excel
CVE-2025-60727
Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Microsoft Office Excel
CVE-2025-60726
Microsoft Excel Á¤º¸ À¯Ãâ Ãë¾à¼º
Microsoft Graphics Component
CVE-2025-60724
GDI+ ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Windows DirectX
CVE-2025-60723
DirectX Graphics Ä¿³Î ¼ºñ½º °ÅºÎ Ãë¾à¼º
OneDrive for Android
CVE-2025-60722
Microsoft OneDrive for Android Elevation of Privilege Vulnerability
Windows Administrator Protection
CVE-2025-60721
Windows Administrator Protection Elevation of Privilege Vulnerability
Windows TDX.sys
CVE-2025-60720
Windows Transport Driver Interface(TDI) º¯È¯ µå¶óÀ̹ö ±ÇÇÑ »ó½Â Ãë¾à¼º
Windows Ancillary Function Driver for WinSock
CVE-2025-60719
WinSock¿ë Windows º¸Á¶ ±â´É µå¶óÀ̹ö ±ÇÇÑ »ó½Â Ãë¾à¼º
Windows Administrator Protection
CVE-2025-60718
Windows Administrator Protection Elevation of Privilege Vulnerability
Windows Broadcast DVR User Service
CVE-2025-60717
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability
Windows DirectX
CVE-2025-60716
DirectX Graphics Ä¿³Î ±ÇÇÑ »ó½Â Ãë¾à¼º
Windows Routing and Remote Access Service (RRAS)
CVE-2025-60715
Windows RRAS(Routing and Remote Access Service) ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Windows OLE
CVE-2025-60714
Windows OLE ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Windows Routing and Remote Access Service (RRAS)
CVE-2025-60713
Windows RRAS(¶ó¿ìÆÃ ¹× ¿ø°Ý ¾×¼¼½º ¼ºñ½º) ±ÇÇÑ »ó½Â Ãë¾à¼º
Microsoft Edge (Chromium-based)
CVE-2025-60711
Microsoft Edge(Chromium ±â¹Ý) ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Host Process for Windows Tasks
CVE-2025-60710
Host Process for Windows Tasks Elevation of Privilege Vulnerability
Windows Common Log File System Driver
CVE-2025-60709
Windows °ø¿ë ·Î±× ÆÄÀÏ ½Ã½ºÅÛ µå¶óÀ̹ö ±ÇÇÑ »ó½Â Ãë¾à¼º
Storvsp.sys Driver
CVE-2025-60708
Storvsp.sys Driver Denial of Service Vulnerability
Multimedia Class Scheduler Service (MMCSS)
CVE-2025-60707
Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege Vulnerability
Role: Windows Hyper-V
CVE-2025-60706
Windows Hyper-V Á¤º¸ À¯Ãâ Ãë¾à¼º
Windows Client-Side Caching (CSC) Service
CVE-2025-60705
Windows Ŭ¶óÀÌ¾ðÆ® ÂÊ Ä³½Ì ±ÇÇÑ »ó½Â Ãë¾à¼º
Windows Kerberos
CVE-2025-60704
Windows Kerberos ±ÇÇÑ »ó½Â Ãë¾à¼º
Windows Remote Desktop
CVE-2025-60703
Windows ¿ø°Ý µ¥½ºÅ©Åé ¼ºñ½º ±ÇÇÑ »ó½Â Ãë¾à¼º
Windows Broadcast DVR User Service
CVE-2025-59515
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability
Microsoft Streaming Service
CVE-2025-59514
Microsoft ½ºÆ®¸®¹Ö ¼ºñ½º ÇÁ·Ï½Ã ±ÇÇÑ »ó½Â Ãë¾à¼º
Windows Bluetooth RFCOM Protocol Driver
CVE-2025-59513
Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability
Customer Experience Improvement Program (CEIP)
CVE-2025-59512
Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability
Windows WLAN Service
CVE-2025-59511
Windows WLAN ¼ºñ½º ±ÇÇÑ »ó½Â Ãë¾à¼º
Windows Routing and Remote Access Service (RRAS)
CVE-2025-59510
Windows ¶ó¿ìÆÃ ¹× ¿ø°Ý ¾×¼¼½º ¼ºñ½º(RRAS) ¼ºñ½º °ÅºÎ Ãë¾à¼º
Windows Speech
CVE-2025-59509
Windows Speech Recognition Information Disclosure Vulnerability
Windows Speech
CVE-2025-59508
Windows Speech Recognition Elevation of Privilege Vulnerability
Windows Speech
CVE-2025-59507
Windows À½¼º ·±Å¸ÀÓ ±ÇÇÑ »ó½Â Ãë¾à¼º
Windows DirectX
CVE-2025-59506
DirectX Graphics Ä¿³Î ±ÇÇÑ »ó½Â Ãë¾à¼º
Windows Smart Card
CVE-2025-59505
Windows Smart Card Reader Elevation of Privilege Vulnerability
Azure Monitor Agent
CVE-2025-59504
Azure Monitor ¿¡ÀÌÀüÆ® ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Azure Compute Gallery
CVE-2025-59503
Azure Compute Resource Provider Elevation of Privilege Vulnerability
Microsoft Configuration Manager
CVE-2025-59501
Microsoft Configuration Manager Spoofing Vulnerability
Azure Notification Service
CVE-2025-59500
Azure Notification Service Elevation of Privilege Vulnerability
SQL Server
CVE-2025-59499
Microsoft SQL Server ±ÇÇÑ »ó½Â Ãë¾à¼º
Internet Explorer
CVE-2025-59295
Windows URL ±¸¹® ºÐ¼® ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Windows Server Update Service
CVE-2025-59287
Windows Server ¾÷µ¥ÀÌÆ® ¼ºñ½º(WSUS) ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Azure Event Grid
CVE-2025-59273
Azure Event Grid ½Ã½ºÅÛ ±ÇÇÑ »ó½Â Ãë¾à¼º
Microsoft Office Excel
CVE-2025-59240
Microsoft Excel Á¤º¸ À¯Ãâ Ãë¾à¼º
Windows USB Video Driver
CVE-2025-55676
Windows USB ºñµð¿À Ŭ·¡½º ½Ã½ºÅÛ µå¶óÀ̹ö Á¤º¸ °ø°³ Ãë¾à¼º
Microsoft Configuration Manager
CVE-2025-55320
±¸¼º °ü¸®ÀÚ ±ÇÇÑ »ó½Â Ãë¾à¼º
ASP.NET Core
CVE-2025-55315
ASP.NET º¸¾È ±â´É ¹ÙÀÌÆÐ½º Ãë¾à¼º
Microsoft Office Word
CVE-2025-53784
Microsoft Word ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Microsoft Teams
CVE-2025-53783
Microsoft Teams ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Microsoft Office PowerPoint
CVE-2025-53761
Microsoft PowerPoint ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Microsoft Office SharePoint
CVE-2025-53760
Microsoft SharePoint ±ÇÇÑ »ó½Â Ãë¾à¼º
Microsoft Office Excel
CVE-2025-53759
Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Microsoft Office Excel
CVE-2025-53741
Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Microsoft Office
CVE-2025-53740
Microsoft Office ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Microsoft Office Excel
CVE-2025-53739
Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Microsoft Office Word
CVE-2025-53738
Microsoft Word ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Microsoft Office Excel
CVE-2025-53737
Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Microsoft Office Word
CVE-2025-53736
Microsoft Word Á¤º¸ À¯Ãâ Ãë¾à¼º
Microsoft Office Excel
CVE-2025-53735
Microsoft Excel ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Microsoft Office Word
CVE-2025-53733
Microsoft Word ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Microsoft Office
CVE-2025-53731
Microsoft Office ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º
Mariner
CVE-2025-52881
runc: LSM labels can be bypassed with malicious config using dummy procfs files
Mariner
CVE-2025-52565
container escape due to /dev/console mount and related races
Windows File Explorer
CVE-2025-50154
Microsoft Windows ÆÄÀÏ Å½»ö±â ½ºÇªÇÎ Ãë¾à¼º
Windows Secure Boot
CVE-2025-47827
MITRE CVE-2025-47827: IGEL OS 11 ÀÌÀü ¹öÀü¿¡¼ º¸¾È ºÎÆÃ ¹ÙÀÌÆÐ½º
Microsoft Configuration Manager
CVE-2025-47179
±¸¼º °ü¸®ÀÚ ±ÇÇÑ »ó½Â Ãë¾à¼º
Mariner
CVE-2025-40109
crypto: rng - Ensure set_ent is always present
Mariner
CVE-2025-40107
can: hi311x: fix null pointer dereference when resuming from sleep before interface was enabled
Mariner
CVE-2025-31133
runc container escape via "masked path" abuse due to mount race conditions
Nuance PowerScribe
CVE-2025-30398
Nuance PowerScribe 360 Á¤º¸ °ø°³ Ãë¾à¼º
Microsoft PowerShell
CVE-2025-25004
PowerShell ±ÇÇÑ »ó½Â Ãë¾à¼º
Mariner
CVE-2025-12875
mruby array.c ary_fill_exec out-of-bounds write
Mariner
CVE-2025-12863
Libxml2: namespace use-after-free in xmlsettreedoc() function of libxml2
Microsoft Edge (Chromium-based)
CVE-2025-12729
Chromium: CVE-2025-12729 Omnibox¿¡¼ ºÎÀûÀýÇÑ ±¸Çö
Microsoft Edge (Chromium-based)
CVE-2025-12728
Chromium: CVE-2025-12728 Omnibox¿¡¼ ºÎÀûÀýÇÑ ±¸Çö
Microsoft Edge (Chromium-based)
CVE-2025-12727
Chromium: CVE-2025-12727 V8¿¡¼ ºÎÀûÀýÇÑ ±¸Çö
Microsoft Edge (Chromium-based)
CVE-2025-12726
Chromium: CVE-2025-12726 º¸±â¿¡¼ ºÎÀûÀýÇÑ ±¸Çö
Microsoft Edge (Chromium-based)
CVE-2025-12725
Chromium: CVE-2025-12725 WebGPU¿¡¼ ¹üÀ§¸¦ ¹þ¾î³ ¾²±â
Microsoft Edge (Chromium-based)
CVE-2025-12447
Chromium: CVE-2025-12447 Incorrect security UI in Omnibox
Microsoft Edge (Chromium-based)
CVE-2025-12446
Chromium: CVE-2025-12446 Incorrect security UI in SplitView
Microsoft Edge (Chromium-based)
CVE-2025-12445
Chromium: CVE-2025-12445 Policy bypass in Extensions
Microsoft Edge (Chromium-based)
CVE-2025-12444
Chromium: CVE-2025-12444 Incorrect security UI in Fullscreen UI
Microsoft Edge (Chromium-based)
CVE-2025-12443
Chromium: CVE-2025-12433 Inappropriate implementation in V8
Microsoft Edge (Chromium-based)
CVE-2025-12441
Chromium: CVE-2025-12441 Out of bounds read in V8
Microsoft Edge (Chromium-based)
CVE-2025-12440
Chromium: CVE-2025-12440 Inappropriate implementation in Autofill
Microsoft Edge (Chromium-based)
CVE-2025-12439
Chromium: CVE-2025-12439 Inappropriate implementation in App-Bound Encryption
Microsoft Edge (Chromium-based)
CVE-2025-12438
Chromium: CVE-2025-12438 Use after free in Ozone
Microsoft Edge (Chromium-based)
CVE-2025-12437
Chromium: CVE-2025-12437 Use after free in PageInfo
Microsoft Edge (Chromium-based)
CVE-2025-12436
Chromium: CVE-2025-12436 Policy bypass in Extensions
Microsoft Edge (Chromium-based)
CVE-2025-12435
Chromium: CVE-2025-12435 Incorrect security UI in Omnibox
Microsoft Edge (Chromium-based)
CVE-2025-12434
Chromium: CVE-2025-12434 Race in Storage
Microsoft Edge (Chromium-based)
CVE-2025-12433
Chromium: CVE-2025-12433 Inappropriate implementation in V8
Microsoft Edge (Chromium-based)
CVE-2025-12432
Chromium: CVE-2025-12432 Race in V8
Microsoft Edge (Chromium-based)
CVE-2025-12431
Chromium: CVE-2025-12431 Inappropriate implementation in Extensions
Microsoft Edge (Chromium-based)
CVE-2025-12430
Chromium: CVE-2025-12430 Object lifecycle issue in Media
Microsoft Edge (Chromium-based)
CVE-2025-12429
Chromium: CVE-2025-12429 Inappropriate implementation in V8
Microsoft Edge (Chromium-based)
CVE-2025-12428
Chromium: CVE-2025-12428 Type Confusion in V8
Microsoft Edge (Chromium-based)
CVE-2025-12036
Chromium: CVE-2025-12036 Inappropriate implementation in V8
Microsoft Edge (Chromium-based)
CVE-2025-11756
Chromium: CVE-2025-11756 Use after free in Safe Browsing
Mariner
CVE-2025-10966
missing SFTP host verification with wolfSSH
Mariner
CVE-2024-25621
containerd affected by a local privilege escalation via wide permissions on CRI directory
Microsoft Edge (Chromium-based)
CVE-2023-4863
Chromium: CVE-2023-4863 WebP¿¡¼ Èü ¹öÆÛ ¿À¹öÇ÷Î
¡à ÀÛ¼º: À§ÇùºÐ¼®´Ü Ãë¾àÁ¡ºÐ¼®ÆÀ