΢Èí6Ô¶à¸ö°²È«·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-06-14

·ì϶¸ÅÊö



2019Äê6ÔÂ11ÈÕ £¬Microsoft°ä²¼ÁËÁùÔ·ݰ²È«²¹¶¡¸üС£ÔÚ¹Ù·½µÄ°²È«¸üв¼¸æÖÐÒ»¹²Åû¶ÁË88¸ö·ì϶µÄÓйØÐÅÏ¢ £¬ÆäÖÐ21¸ö»ñµÃÁË¡°ÑϳÁ¡±ÆÀ¼¶ £¬ÕâÊÇ΢ÈíÓÐÊ·ÒÔÀ´·ì϶ÑϳÁˮƽ×î¸ßµÄÒ»´ÎÅÅÃû¡£½ØÖÁĿǰΪֹ £¬ÉÐδ·¢ÏÖÕâ88¸ö·ì϶µÄÔÚÒ°ÀûÓá£


³É¹¦ÀûÓÃÉÏÊö·ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡¢»ñÈ¡Óû§Êý¾Ý¡£Î¢Èí¶à¸ö²úÆ·ºÍϵͳÊÜ·ì϶ӰÏ졣Ŀǰ £¬Î¢Èí¹Ù·½ÒѾ­°ä²¼·ì϶½¨¸´²¹¶¡ £¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½·ì϶ӰÏì £¬²ÉÈ¡½¨²¹´ëÊ©¡£


1¡¢Windows Hyper-VÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0620£©£¨CVE-2019-0709£©£¨CVE-2019-0722£©


·ì϶¼ò½é£ºµ±Ö÷»ú·þÎñÆ÷É쵀 Windows Hyper-V ÎÞ·¨ÕýÈ·ÑéÖ¤À´±öϵͳÉϾ­Éí·ÝÑéÖ¤µÄÓû§ÊäÈëʱ £¬´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷ÕßÄܹ»ÔÚÀ´±ö²Ù×÷ϵͳÉÏÔËÐо­ÌØÊâÉè¼ÆµÄ¶ñÒⷨʽ £¬×îÖÕÔÚÖ÷»ú·þÎñÆ÷ϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0620
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0709

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0722


2¡¢Jet Êý¾Ý¿âÒýÇæÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0904£©£¨CVE-2019-0905£©£¨CVE-2019-0906£©£¨CVE-2019-0907£©£¨CVE-2019-0908£©£¨CVE-2019-0909£©


·ì϶¼ò½é£ºµ± Windows Jet Êý¾Ý¿âÒýÇæ²»ÕýÈ·µØ´¦ÖÃÄÚ´æÖеĶÔÏóʱ £¬»á´¥·¢Ô¶³Ì´úÂëÖ´Ðзì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÊܺ¦ÕßϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0904
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0905
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0906
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0907
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0908

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0909


3¡¢ActiveX Data Objects (ADO)Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0888£©


·ì϶¼ò½é£ºActiveX Data Objects (ADO)´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£ ¹¥»÷Õ߿ɴ´½¨º¬ÓжñÒâ´úÂëµÄÍøÕ¾ £¬²¢ÓÕʹÓû§½øÐнӼû £¬×îÖÕʵÏÖÔ¶³Ì´úÂëÖ´ÐС£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0888


4¡¢Microsoft Word Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-1034£©£¨CVE-2019-1035£©


·ì϶¼ò½é£ºµ± Microsoft WordÎÞ·¨ÕýÈ·´¦ÖÃÄÚ´æÖеĶÔÏóʱ £¬»á´¥·¢Ô¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿Éͨ¹ýÏòÓû§·¢Ë;­ÌØÊâÉè¼ÆµÄÎļþ²¢ÓÕʹÓû§´ò¿ª¸ÃÎļþÒÔÀûÓô˷ì϶¡£³É¹¦ÀûÓ÷ì϶µÄ¹¥»÷Õß¿ÉÔÚÓû§ÏµÍ³ÉÏÖ´ÐÐËÁÒâ´úÂë¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1034

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1035


5¡¢Chakra ¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶£¨CVE-2019-1002£©£¨CVE-2019-1003£©£¨CVE-2019-0989£©£¨CVE-2019-0991£©£¨CVE-2019-0992£©£¨CVE-2019-0993£©


·ì϶¼ò½é£ºChakra ¾ç±¾ÒýÇæÔÚ Microsoft Edge Öд¦ÖÃÄÚ´æÖеĶÔÏóʱ¿ÉÄÜ´¥·¢¸Ã·ì϶¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíԱȨÏ޵Ǽ £¬¹¥»÷Õß±ãÄܹ»ËÁÒâ×°Ö÷¨Ê½¡¢²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý £¬»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1002
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1003
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0989
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0991
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0992

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0993


6¡¢Microsoft Speech API Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0985£©


·ì϶¼ò½é£ºµ±Microsoft Speech API²»ÕýÈ·µØ´¦ÖÃÎı¾µ½ÓïÒô£¨TTS£©ÊäÈëʱ £¬´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£ ¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖʹ¹¥»÷Õß¿ÉÄÜÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½À´·ÛËéÄÚ´æ¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0985


7¡¢Microsoft Windows°²È«ÌصãÈÆ¹ý·ì϶£¨CVE-2019-1019£©


·ì϶¼ò½é£º WindowsÖÐNetlogonÐÂÎÅ¿ÉÄÜ»ñÈ¡»á»°ÃÜÔ¿²¢¶ÔÐÂÎŽøÐÐÊðÃû £¬¸ÃÐÂÎÅ´æÔÚÒ»¸ö°²È«ÌصãÈÆ¹ý·ì϶¡£ÎªÁËÀûÓô˷ì϶ £¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄÉè¼ÆµÄÉí·ÝÑéÖ¤ÒªÇ󡣳ɹ¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ê¹ÓÃԭʼÓû§È¨ÏÞ½Ó¼ûÁíÒ»Ì¨ÍÆËã»ú¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1019


8¡¢Microsoft IIS·þÎñÆ÷»Ø¾ø·þÎñ·ì϶£¨CVE-2019-0941£©


·ì϶¼ò½é£ºMicrosoft IIS ServerÖдæÔÚÒ»¸ö»Ø¾ø·þÎñ·ì϶£¨CVE-2019-0941£© £¬µ±¿ÉѡҪÇóɸѡְÄÜÎÞ·¨ÕýÈ·´¦ÖÃÒªÇóʱ £¬¸Ã·ì϶½«»áÆô³Ì¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜ»á¶ÔÅäÖÃΪʹÓÃÒªÇóɸѡµÄÒ³ÃæÔì³Éһʱ»Ø¾ø·þÎñ¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0941


9¡¢Windows NTLM´Û¸Ä·ì϶£¨CVE-2019-1040£©


·ì϶¼ò½é£ºMicrosoft WindowsµÄNTLMÖдæÔڴ۸ķì϶ £¬¹¥»÷ÕßÄܹ»Í¨¹ýÖÐÑëÈ˹¥»÷³É¹¦ÈƹýNTLM MIC£¨ÐÂÎÅÆëÈ«ÐԲ鳭£©µÄ± £»¤ £¬ÊµÏÖNTLM°²È«Ö°ÄܵĽµ¼¶¡£¸Ã·ì϶Äܹ»Ôì³É·ÖÆçˮƽµÄ·çÏÕ £¬×îΪÑϳÁʱ¿ÉÔÚʹÓÃͨ³£ÓòÕ˺ŵÄÇé¿öϽÚÔìÓòÄÚµÄËùÓлúе¡£¹¥»÷ÕßÏëÒª³É¹¦ÀûÓô˷ì϶ £¬±ØÒª´Û¸ÄNTLM»¥»»ÐÅÏ¢ £¬¶øºóÔÚ±£ÕÏÊðÃûÒÀÈ»ÓÐЧµÄǰÌáÏÂÅú¸ÄNTLMÊý¾Ý°üµÄ±êÖ¾¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1040


10¡¢Windows»Ø¾ø·þÎñ·ì϶£¨CVE-2019-1025£©


·ì϶¼ò½é£ºWindowsµÄÄÚ´æ´¦Ö÷½Ê½ÖдæÔڻؾø·þÎñ·ì϶ £¬µ±ÃýÎ󵨴¦ÖÃÄÚ´æ¶ÔÏóʱ½«»á´¥·¢¸Ã·ì϶¡£ÒªÀûÓô˷ì϶ £¬¹¥»÷Õß±ØÐëµÇ¼µ½ÊÜÓ°ÏìµÄϵͳ²¢ÔËÐо­ÌØÊâÉè¼ÆµÄÀûÓ÷¨Ê½»òÓÕÆ­Óû§´ò¿ªÍøÂç¹²ÏíÉϵÄÌØ¶¨Îļþ¡£¸Ã·ì϶²»ÔÊÐí¹¥»÷ÕßÖ±½ÓÖ´ÐдúÂë»òÌáÉýÓû§È¨ÏÞ £¬µ«¿ÉÄܻᵼÖÂÖ¸±êϵͳÖÕ³¡ÏìÓ¦¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1025



½¨¸´½¨Òé



Ŀǰ £¬Î¢Èí¹Ù·½ÒѾ­°ä²¼²¹¶¡½¨¸´ÁËÉÏÊö·ì϶ £¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½·ì϶ӰÏì £¬¾¡¿ì²ÉÈ¡½¨²¹´ëÊ© £¬ÒÔÔ¤·ÀDZÔڵݲȫÍþв¡£ÏëÒª½øÐиüР£¬Ö»Ðèתµ½ÉèÖáú¸üкͰ²È«¡úWindows ¸üСú²é³­¸üР£¬»òÕßÒ²Äܹ»Í¨¹ýÊÖ¶¯½øÐиüС£



²Î¿¼Á´½Ó



https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/253dc509-9a5b-e911-a98e-000d3a33c573