΢Èí9Ô¶à¸ö°²È«·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-09-16

¡ñ·ì϶¸ÅÊö


΢ÈíÓÚÖܶþ°ä²¼ÁË9Ô°²È«¸üв¹¶¡£¬½¨¸´ÁË81¸ö´Óµ¥Ò»µÄºýŪ¹¥»÷µ½Ô¶³ÌÖ´ÐдúÂëµÄ°²È«ÎÊÌ⣬²úÆ·Éæ¼°.NET Core¡¢.NET Framework¡¢Active Directory¡¢Adobe Flash Player¡¢ASP.NET¡¢Common Log File System Driver¡¢Microsoft Browsers¡¢Microsoft Edge¡¢Microsoft Exchange Server¡¢Microsoft Graphics Component¡¢Microsoft JET Database Engine¡¢Microsoft Office¡¢Microsoft Office SharePoint¡¢Microsoft Scripting Engine¡¢Microsoft Windows¡¢Microsoft Yammer¡¢Project Rome¡¢Servicing Stack Updates¡¢Skype for Business and Microsoft Lync¡¢Team Foundation Server¡¢Visual Studio¡¢Windows Hyper-V¡¢Windows KernelÒÔ¼°Windows RDP¡£


ÀûÓÃÉÏÊö·ì϶£¬¹¥»÷ÕßÄܹ»ÌáÉýȨÏÞ£¬ºýŪ£¬Èƹý°²È«Ö°ÄÜÏÞ¶È£¬»ñÈ¡Ãô¸ÐÐÅÏ¢£¬Ö´ÐÐÔ¶³Ì´úÂë»òÌáÒ黨¾ø·þÎñ¹¥»÷µÈ¡£ÌáÐÑ¿í´óMicrosoftÓû§¾¡¿ìÏÂÔØ²¹¶¡¸üУ¬Ô¤·ÀÒý·¢·ì϶ÓйصÄÍøÂ簲ȫÊÂÎñ¡£


CVE 񅧏

ÑϳÁˮƽ

CVE ±êÌâ

·ìϼûèÊö

²úÆ·

CVE-2019-1257

ÑϳÁ

Microsoft SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft SharePointÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄÒ»ÌׯóÒµÒµÎñºÏ×÷ƽ̨¡£¸Ãƽ̨ÓÃÓÚ¶ÔÒµÎñÐÅÏ¢½øÐÐÕûºÏ£¬²¢¿ÉÄܹ²Ïí¹¤×÷¡¢ÓëËûÈËЭͬ¹¤×÷¡¢×éÖ¯ÏîÄ¿ºÍ¹¤×÷×é¡¢ËÑË÷ÈËÔ±ºÍÐÅÏ¢¡£ Microsoft SharePointÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½ÎÞ·¨²é³­ÀûÓ÷¨Ê½°üµÄÔ´ÏóÕ÷¡£¹¥»÷Õ߿ɽèÖúÌØÔìµÄSharePointÀûÓ÷¨Ê½°üÀûÓø÷ì϶ÔÚSharePointÀûÓ÷¨Ê½³ØºÍSharePoint·þÎñÆ÷³¡ÕÊ»§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂë¡£

Microsoft Office SharePoint

CVE-2019-1295

ÑϳÁ

Microsoft SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft SharePointÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄÒ»ÌׯóÒµÒµÎñºÏ×÷ƽ̨¡£¸Ãƽ̨ÓÃÓÚ¶ÔÒµÎñÐÅÏ¢½øÐÐÕûºÏ£¬²¢¿ÉÄܹ²Ïí¹¤×÷¡¢ÓëËûÈËЭͬ¹¤×÷¡¢×éÖ¯ÏîÄ¿ºÍ¹¤×÷×é¡¢ËÑË÷ÈËÔ±ºÍÐÅÏ¢¡£ Microsoft SharePointÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶ԴÓÚAPIδǡ±¾µØÔ¤·À²»°²È«µÄÊý¾ÝÊäÈë¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚSharePointÀûÓ÷¨Ê½³ØºÍSharePoint·þÎñÆ÷³¡ÕÊ»§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂë¡£

Microsoft Office SharePoint

CVE-2019-1296

ÑϳÁ

Microsoft SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft SharePointÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄÒ»ÌׯóÒµÒµÎñºÏ×÷ƽ̨¡£¸Ãƽ̨ÓÃÓÚ¶ÔÒµÎñÐÅÏ¢½øÐÐÕûºÏ£¬²¢¿ÉÄܹ²Ïí¹¤×÷¡¢ÓëËûÈËЭͬ¹¤×÷¡¢×éÖ¯ÏîÄ¿ºÍ¹¤×÷×é¡¢ËÑË÷ÈËÔ±ºÍÐÅÏ¢¡£ Microsoft SharePointÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶ԴÓÚÆäÖÐAPIÕýÈ·Ô¤·À²»°²È«µÄÊý¾ÝÊäÈë¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚSharePointÀûÓ÷¨Ê½³ØºÍSharePoint·þÎñÆ÷³¡ÕÊ»§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂë¡£

Microsoft Office SharePoint

CVE-2019-1208

ÑϳÁ

VBScript Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft Internet Explorer£¨IE£©ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄÒ»¿îWindows²Ù×÷ϵͳ¸½´øµÄWebä¯ÀÀÆ÷¡£VBScript EngineÊÇÆäÖеÄÒ»¸öVBScript¾ç±¾Ëµ»°ÒýÇæ¡£ Microsoft IE 9¡¢10ºÍ11ÖÐVBScriptÒýÇæ´¦ÖÃÄÚ´æ¶ÔÏóµÄ·½Ê½´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂ룬°Ü»µÄÚ´æ¡£

Microsoft Scripting Engine

CVE-2019-1217

ÑϳÁ

Chakra Scripting Engine ÄÚ´æ·ÛËé·ì϶

Microsoft ChakraCoreºÍMicrosoft Edge¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£ChakraCoreÊÇʹÓÃÔÚEdgeä¯ÀÀÆ÷ÖеÄÒ»¸ö¿ªÔ´µÄChakraJavaScript¾ç±¾ÒýÇæµÄÖ÷ÌⲿÃÅ£¬Ò²¿É×÷Ϊµ¥¶ÀµÄJavaScriptÒýÇæÊ¹Óá£Microsoft EdgeÊÇÒ»¿îWindows 10Ö®ºó°æ±¾ÏµÍ³¸½´øµÄWebä¯ÀÀÆ÷¡£ Microsoft EdgeºÍChakraCoreÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂ룬°Ü»µÄÚ´æ¡£

Microsoft Scripting Engine

CVE-2019-1221

ÑϳÁ

Scripting Engine ÄÚ´æ·ÛËé·ì϶

¾ç±¾ÒýÇæÔÚ Internet Explorer Öд¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½°Ü»µÄÚ´æ¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß±ã¿É½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£

ÔÚ»ùÓÚ Web µÄ¹¥»÷Çé¾°ÖУ¬¹¥»÷Õß¿ÉÄÜÕ¼ÓÐÒ»¸öÖ¼ÔÚͨ¹ý Internet Explorer ÀûÓô˷ì϶µÄ¾­ÌØÊâÉè¼ÆµÄÍøÕ¾£¬¶øºóÓÕʹÓû§²é¿´¸ÃÍøÕ¾¡£¹¥»÷ÕßÒ²¿ÉÄÜÔÚÍÐ¹Ü IE ³öÏÖÒýÇæµÄÀûÓ÷¨Ê½»ò Microsoft Office ÎĵµÖÐǶÈë±êÓÓ×°°²È«³õʼ»¯¡±µÄ ActiveX ¿Ø¼þ¡£¹¥»÷Õß»¹¿ÉÄÜÀûÓÃÔâµ½ÈëÇÖµÄÍøÕ¾ÒÔ¼°½ÓÊÜ»òÍйÜÓû§ÌṩµÄÄÚÈÝ»ò¸æ°×µÄÍøÕ¾¡£ÕâÐ©ÍøÕ¾¿ÉÄÜÔ̺¬Äܹ»ÀûÓô˷ì϶µÄ¾­ÌØÊâÉè¼ÆµÄÄÚÈÝ¡£

Microsoft Scripting Engine

CVE-2019-1236

ÑϳÁ

VBScript Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft Internet Explorer£¨IE£©ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄÒ»¿îWindows²Ù×÷ϵͳ¸½´øµÄWebä¯ÀÀÆ÷¡£VBScript EngineÊÇÆäÖеÄÒ»¸öVBScript¾ç±¾Ëµ»°ÒýÇæ¡£ Microsoft IE 9¡¢10ºÍ11ÖÐVBScriptÒýÇæ´¦ÖÃÄÚ´æ¶ÔÏóµÄ·½Ê½´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂ룬°Ü»µÄÚ´æ¡£

Microsoft Scripting Engine

CVE-2019-1237

ÑϳÁ

Chakra Scripting Engine ÄÚ´æ·ÛËé·ì϶

Microsoft ChakraCoreºÍMicrosoft Edge¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£ChakraCoreÊÇʹÓÃÔÚEdgeä¯ÀÀÆ÷ÖеÄÒ»¸ö¿ªÔ´µÄChakraJavaScript¾ç±¾ÒýÇæµÄÖ÷ÌⲿÃÅ£¬Ò²¿É×÷Ϊµ¥¶ÀµÄJavaScriptÒýÇæÊ¹Óá£Microsoft EdgeÊÇÒ»¿îWindows 10Ö®ºó°æ±¾ÏµÍ³¸½´øµÄWebä¯ÀÀÆ÷¡£ Microsoft ChakraCoreºÍMicrosoft EdgeÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂ룬°Ü»µÄÚ´æ¡£

Microsoft Scripting Engine

CVE-2019-1300

ÑϳÁ

Chakra Scripting Engine ÄÚ´æ·ÛËé·ì϶

Microsoft ChakraCoreºÍMicrosoft Edge¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£ChakraCoreÊÇʹÓÃÔÚEdgeä¯ÀÀÆ÷ÖеÄÒ»¸ö¿ªÔ´µÄChakraJavaScript¾ç±¾ÒýÇæµÄÖ÷ÌⲿÃÅ£¬Ò²¿É×÷Ϊµ¥¶ÀµÄJavaScriptÒýÇæÊ¹Óá£Microsoft EdgeÊÇÒ»¿îWindows 10Ö®ºó°æ±¾ÏµÍ³¸½´øµÄWebä¯ÀÀÆ÷¡£ Microsoft ChakraCoreºÍMicrosoft EdgeÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂ룬°Ü»µÄÚ´æ¡£

Microsoft Scripting Engine

CVE-2019-1280

ÑϳÁ

LNK Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft WindowsºÍMicrosoft Windows Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft WindowsÊÇÒ»Ì×Ó×ÎÒÉ豸ʹÓõIJÙ×÷ϵͳ¡£Microsoft Windows ServerÊÇÒ»Ì×·þÎñÆ÷²Ù×÷ϵͳ¡£ Microsoft WindowsºÍMicrosoft Windows ServerÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õ߿ɽèÖú´øÓжñÒâ.LNKÎļþºÍ¹ØÁªµÄ¶ñÒâ¶þ½øÔìÎļþµÄÒÆ³ýÇý¶¯Æ÷»òÔ¶³Ì¹²ÏíÀûÓø÷ì϶ִÐдúÂë¡£

Microsoft Windows

CVE-2019-1306

ÑϳÁ

Azure DevOps and Team Foundation Server Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft Team Foundation ServerºÍMicrosoft Azure DevOps Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft Team Foundation ServerÊÇÒ»Ì×ÀûÓ÷¨Ê½ÐÔÃüÖÜÆÚÖÎÀí£¨ALM£©¹¤¾ßÌ×¼þÖеÄÍŶӺÏ×÷ƽ̨¡£¸Ãƽ̨Ô̺¬µÄ´úÂëÖÎÀí¡¢ÏîÄ¿ÖÎÀíµÈÖ°ÄÜ¡£Microsoft Azure DevOps ServerÊÇÒ»Ì×Èí¼þ¿ª·¢ºÏ×÷¹¤¾ß¡£¸Ã²úÆ·Ô̺¬¹²Ïí´úÂë¡¢¹¤×÷¸ú×ÙºÍÈí¼þ°ä²¼µÈÖ°ÄÜ¡£ Microsoft Team Foundation Server 2018 Update 3.2°æ±¾¡¢Azure DevOps Server 2019 Update 1°æ±¾ºÍ2019.0.1°æ±¾ÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓÐÕýÈ·ÑéÖ¤ÊäÈë¡£¹¥»÷Õß¿Éͨ¹ýÉÏ´«ÌØÔìµÄÎļþÀûÓø÷ì϶ÔÚTFS»òADO·þÎñÕË»§µÄ¸ßµÍÎÄÖÐÔÚ·þÎñÆ÷ÉÏÖ´ÐдúÂë¡£

Team Foundation Server

CVE-2019-0787

ÑϳÁ

Remote Desktop Client Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft WindowsºÍMicrosoft Windows Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft WindowsÊÇÒ»Ì×Ó×ÎÒÉ豸ʹÓõIJÙ×÷ϵͳ¡£Microsoft Windows ServerÊÇÒ»Ì×·þÎñÆ÷²Ù×÷ϵͳ¡£Windows Remote Desktop ClientÊÇÆäÖеÄÒ»¸öWindowsÔ¶³Ì×ÀÃæ¿Í»§¶Ë·¨Ê½¡£ Microsoft Windows Remote Desktop ClientÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿Éͨ¹ýÔÚÉç»á¹¤³Ì¡¢DNS²¡¶¾»òʹÓÃÖÐÑëÈË(MITM)¼¼ÊõÓÕµ¼Óû§ÏνӶñÒâµÄ·þÎñÆ÷ÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£

Windows RDP

CVE-2019-0788

ÑϳÁ

Remote Desktop Client Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft WindowsºÍMicrosoft Windows Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft WindowsÊÇÒ»Ì×Ó×ÎÒÉ豸ʹÓõIJÙ×÷ϵͳ¡£Microsoft Windows ServerÊÇÒ»Ì×·þÎñÆ÷²Ù×÷ϵͳ¡£Windows Remote Desktop ClientÊÇÆäÖеÄÒ»¸öWindowsÔ¶³Ì×ÀÃæ¿Í»§¶Ë·¨Ê½¡£ Microsoft Windows Remote Desktop ClientÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿Éͨ¹ýÔÚÉç»á¹¤³Ì¡¢DNS ²¡¶¾»òʹÓÃÖÐÑëÈË (MITM) ¼¼ÊõÓÕµ¼Óû§ÏνӶñÒâµÄ·þÎñÆ÷ÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£

Windows RDP

CVE-2019-1290

ÑϳÁ

Remote Desktop Client Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft WindowsºÍMicrosoft Windows Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft WindowsÊÇÒ»Ì×Ó×ÎÒÉ豸ʹÓõIJÙ×÷ϵͳ¡£Microsoft Windows ServerÊÇÒ»Ì×·þÎñÆ÷²Ù×÷ϵͳ¡£Windows Remote Desktop ClientÊÇÆäÖеÄÒ»¸öWindowsÔ¶³Ì×ÀÃæ¿Í»§¶Ë·¨Ê½¡£Microsoft Windows Remote Desktop ClientÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿Éͨ¹ýÔÚÉç»á¹¤³Ì¡¢DNS ²¡¶¾»òʹÓÃÖÐÑëÈË (MITM) ¼¼ÊõÓÕµ¼Óû§ÏνӶñÒâµÄ·þÎñÆ÷ÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£

Windows RDP

CVE-2019-1291

ÑϳÁ

Remote Desktop Client Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft WindowsºÍMicrosoft Windows Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft WindowsÊÇÒ»Ì×Ó×ÎÒÉ豸ʹÓõIJÙ×÷ϵͳ¡£Microsoft Windows ServerÊÇÒ»Ì×·þÎñÆ÷²Ù×÷ϵͳ¡£Windows Remote Desktop ClientÊÇÆäÖеÄÒ»¸öWindowsÔ¶³Ì×ÀÃæ¿Í»§¶Ë·¨Ê½¡£ Microsoft Windows Remote Desktop ClientÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚÏνӿͻ§¶ËµÄÍÆËã»úÉÏÖ´ÐÐËÁÒâ´úÂë¡£

Windows RDP


¡ñ½¨¸´½¨Òé


Ŀǰ£¬Î¢Èí¹Ù·½ÒѾ­°ä²¼²¹¶¡½¨¸´ÁËÉÏÊö·ì϶£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½·ì϶ӰÏì¡£


¾¡¿ì²ÉÈ¡½¨²¹´ëÊ©£¬ÒÔÔ¤·ÀDZÔڵݲȫÍþв¡£ÏëÒª½øÐиüУ¬Ö»Ðèתµ½ÉèÖáú¸üкͰ²È«¡úWindows ¸üСú²é³­¸üУ¬»òÕßÒ²Äܹ»Í¨¹ýÊÖ¶¯½øÐиüС£


¡ñ²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/releasenotedetail/24f46f0a-489c-e911-a994-000d3a33c573