΢Èí9Ô¶à¸ö°²È«·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-09-16¡ñ·ì϶¸ÅÊö
΢ÈíÓÚÖܶþ°ä²¼ÁË9Ô°²È«¸üв¹¶¡£¬½¨¸´ÁË81¸ö´Óµ¥Ò»µÄºýŪ¹¥»÷µ½Ô¶³ÌÖ´ÐдúÂëµÄ°²È«ÎÊÌ⣬²úÆ·Éæ¼°.NET Core¡¢.NET Framework¡¢Active Directory¡¢Adobe Flash Player¡¢ASP.NET¡¢Common Log File System Driver¡¢Microsoft Browsers¡¢Microsoft Edge¡¢Microsoft Exchange Server¡¢Microsoft Graphics Component¡¢Microsoft JET Database Engine¡¢Microsoft Office¡¢Microsoft Office SharePoint¡¢Microsoft Scripting Engine¡¢Microsoft Windows¡¢Microsoft Yammer¡¢Project Rome¡¢Servicing Stack Updates¡¢Skype for Business and Microsoft Lync¡¢Team Foundation Server¡¢Visual Studio¡¢Windows Hyper-V¡¢Windows KernelÒÔ¼°Windows RDP¡£
ÀûÓÃÉÏÊö·ì϶£¬¹¥»÷ÕßÄܹ»ÌáÉýȨÏÞ£¬ºýŪ£¬Èƹý°²È«Ö°ÄÜÏÞ¶È£¬»ñÈ¡Ãô¸ÐÐÅÏ¢£¬Ö´ÐÐÔ¶³Ì´úÂë»òÌáÒ黨¾ø·þÎñ¹¥»÷µÈ¡£ÌáÐÑ¿í´óMicrosoftÓû§¾¡¿ìÏÂÔØ²¹¶¡¸üУ¬Ô¤·ÀÒý·¢·ì϶ÓйصÄÍøÂ簲ȫÊÂÎñ¡£
CVE 񅧏
ÑϳÁˮƽ
CVE ±êÌâ
·ìϼûèÊö
²úÆ·
CVE-2019-1257
ÑϳÁ
Microsoft SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft SharePointÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄÒ»ÌׯóÒµÒµÎñºÏ×÷ƽ̨¡£¸Ãƽ̨ÓÃÓÚ¶ÔÒµÎñÐÅÏ¢½øÐÐÕûºÏ£¬²¢¿ÉÄܹ²Ïí¹¤×÷¡¢ÓëËûÈËÐͬ¹¤×÷¡¢×éÖ¯ÏîÄ¿ºÍ¹¤×÷×é¡¢ËÑË÷ÈËÔ±ºÍÐÅÏ¢¡£ Microsoft SharePointÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½ÎÞ·¨²é³ÀûÓ÷¨Ê½°üµÄÔ´ÏóÕ÷¡£¹¥»÷Õ߿ɽèÖúÌØÔìµÄSharePointÀûÓ÷¨Ê½°üÀûÓø÷ì϶ÔÚSharePointÀûÓ÷¨Ê½³ØºÍSharePoint·þÎñÆ÷³¡ÕÊ»§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂë¡£
Microsoft Office SharePoint
CVE-2019-1295
ÑϳÁ
Microsoft SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft SharePointÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄÒ»ÌׯóÒµÒµÎñºÏ×÷ƽ̨¡£¸Ãƽ̨ÓÃÓÚ¶ÔÒµÎñÐÅÏ¢½øÐÐÕûºÏ£¬²¢¿ÉÄܹ²Ïí¹¤×÷¡¢ÓëËûÈËÐͬ¹¤×÷¡¢×éÖ¯ÏîÄ¿ºÍ¹¤×÷×é¡¢ËÑË÷ÈËÔ±ºÍÐÅÏ¢¡£ Microsoft SharePointÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶ԴÓÚAPIδǡ±¾µØÔ¤·À²»°²È«µÄÊý¾ÝÊäÈë¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚSharePointÀûÓ÷¨Ê½³ØºÍSharePoint·þÎñÆ÷³¡ÕÊ»§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂë¡£
Microsoft Office SharePoint
CVE-2019-1296
ÑϳÁ
Microsoft SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft SharePointÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄÒ»ÌׯóÒµÒµÎñºÏ×÷ƽ̨¡£¸Ãƽ̨ÓÃÓÚ¶ÔÒµÎñÐÅÏ¢½øÐÐÕûºÏ£¬²¢¿ÉÄܹ²Ïí¹¤×÷¡¢ÓëËûÈËÐͬ¹¤×÷¡¢×éÖ¯ÏîÄ¿ºÍ¹¤×÷×é¡¢ËÑË÷ÈËÔ±ºÍÐÅÏ¢¡£ Microsoft SharePointÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶ԴÓÚÆäÖÐAPIÕýÈ·Ô¤·À²»°²È«µÄÊý¾ÝÊäÈë¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚSharePointÀûÓ÷¨Ê½³ØºÍSharePoint·þÎñÆ÷³¡ÕÊ»§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂë¡£
Microsoft Office SharePoint
CVE-2019-1208
ÑϳÁ
VBScript Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft Internet Explorer£¨IE£©ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄÒ»¿îWindows²Ù×÷ϵͳ¸½´øµÄWebä¯ÀÀÆ÷¡£VBScript EngineÊÇÆäÖеÄÒ»¸öVBScript¾ç±¾Ëµ»°ÒýÇæ¡£ Microsoft IE 9¡¢10ºÍ11ÖÐVBScriptÒýÇæ´¦ÖÃÄÚ´æ¶ÔÏóµÄ·½Ê½´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂ룬°Ü»µÄÚ´æ¡£
Microsoft Scripting Engine
CVE-2019-1217
ÑϳÁ
Chakra Scripting Engine ÄÚ´æ·ÛËé·ì϶
Microsoft ChakraCoreºÍMicrosoft Edge¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£ChakraCoreÊÇʹÓÃÔÚEdgeä¯ÀÀÆ÷ÖеÄÒ»¸ö¿ªÔ´µÄChakraJavaScript¾ç±¾ÒýÇæµÄÖ÷ÌⲿÃÅ£¬Ò²¿É×÷Ϊµ¥¶ÀµÄJavaScriptÒýÇæÊ¹Óá£Microsoft EdgeÊÇÒ»¿îWindows 10Ö®ºó°æ±¾ÏµÍ³¸½´øµÄWebä¯ÀÀÆ÷¡£ Microsoft EdgeºÍChakraCoreÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂ룬°Ü»µÄÚ´æ¡£
Microsoft Scripting Engine
CVE-2019-1221
ÑϳÁ
Scripting Engine ÄÚ´æ·ÛËé·ì϶
¾ç±¾ÒýÇæÔÚ Internet Explorer Öд¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½°Ü»µÄÚ´æ¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß±ã¿É½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£
ÔÚ»ùÓÚ Web µÄ¹¥»÷Çé¾°ÖУ¬¹¥»÷Õß¿ÉÄÜÕ¼ÓÐÒ»¸öÖ¼ÔÚͨ¹ý Internet Explorer ÀûÓô˷ì϶µÄ¾ÌØÊâÉè¼ÆµÄÍøÕ¾£¬¶øºóÓÕʹÓû§²é¿´¸ÃÍøÕ¾¡£¹¥»÷ÕßÒ²¿ÉÄÜÔÚÍÐ¹Ü IE ³öÏÖÒýÇæµÄÀûÓ÷¨Ê½»ò Microsoft Office ÎĵµÖÐǶÈë±êÓÓ×°°²È«³õʼ»¯¡±µÄ ActiveX ¿Ø¼þ¡£¹¥»÷Õß»¹¿ÉÄÜÀûÓÃÔâµ½ÈëÇÖµÄÍøÕ¾ÒÔ¼°½ÓÊÜ»òÍйÜÓû§ÌṩµÄÄÚÈÝ»ò¸æ°×µÄÍøÕ¾¡£ÕâÐ©ÍøÕ¾¿ÉÄÜÔ̺¬Äܹ»ÀûÓô˷ì϶µÄ¾ÌØÊâÉè¼ÆµÄÄÚÈÝ¡£
Microsoft Scripting Engine
CVE-2019-1236
ÑϳÁ
VBScript Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft Internet Explorer£¨IE£©ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄÒ»¿îWindows²Ù×÷ϵͳ¸½´øµÄWebä¯ÀÀÆ÷¡£VBScript EngineÊÇÆäÖеÄÒ»¸öVBScript¾ç±¾Ëµ»°ÒýÇæ¡£ Microsoft IE 9¡¢10ºÍ11ÖÐVBScriptÒýÇæ´¦ÖÃÄÚ´æ¶ÔÏóµÄ·½Ê½´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂ룬°Ü»µÄÚ´æ¡£
Microsoft Scripting Engine
CVE-2019-1237
ÑϳÁ
Chakra Scripting Engine ÄÚ´æ·ÛËé·ì϶
Microsoft ChakraCoreºÍMicrosoft Edge¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£ChakraCoreÊÇʹÓÃÔÚEdgeä¯ÀÀÆ÷ÖеÄÒ»¸ö¿ªÔ´µÄChakraJavaScript¾ç±¾ÒýÇæµÄÖ÷ÌⲿÃÅ£¬Ò²¿É×÷Ϊµ¥¶ÀµÄJavaScriptÒýÇæÊ¹Óá£Microsoft EdgeÊÇÒ»¿îWindows 10Ö®ºó°æ±¾ÏµÍ³¸½´øµÄWebä¯ÀÀÆ÷¡£ Microsoft ChakraCoreºÍMicrosoft EdgeÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂ룬°Ü»µÄÚ´æ¡£
Microsoft Scripting Engine
CVE-2019-1300
ÑϳÁ
Chakra Scripting Engine ÄÚ´æ·ÛËé·ì϶
Microsoft ChakraCoreºÍMicrosoft Edge¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£ChakraCoreÊÇʹÓÃÔÚEdgeä¯ÀÀÆ÷ÖеÄÒ»¸ö¿ªÔ´µÄChakraJavaScript¾ç±¾ÒýÇæµÄÖ÷ÌⲿÃÅ£¬Ò²¿É×÷Ϊµ¥¶ÀµÄJavaScriptÒýÇæÊ¹Óá£Microsoft EdgeÊÇÒ»¿îWindows 10Ö®ºó°æ±¾ÏµÍ³¸½´øµÄWebä¯ÀÀÆ÷¡£ Microsoft ChakraCoreºÍMicrosoft EdgeÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂ룬°Ü»µÄÚ´æ¡£
Microsoft Scripting Engine
CVE-2019-1280
ÑϳÁ
LNK Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft WindowsºÍMicrosoft Windows Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft WindowsÊÇÒ»Ì×Ó×ÎÒÉ豸ʹÓõIJÙ×÷ϵͳ¡£Microsoft Windows ServerÊÇÒ»Ì×·þÎñÆ÷²Ù×÷ϵͳ¡£ Microsoft WindowsºÍMicrosoft Windows ServerÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õ߿ɽèÖú´øÓжñÒâ.LNKÎļþºÍ¹ØÁªµÄ¶ñÒâ¶þ½øÔìÎļþµÄÒÆ³ýÇý¶¯Æ÷»òÔ¶³Ì¹²ÏíÀûÓø÷ì϶ִÐдúÂë¡£
Microsoft Windows
CVE-2019-1306
ÑϳÁ
Azure DevOps and Team Foundation Server Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft Team Foundation ServerºÍMicrosoft Azure DevOps
Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft
Team Foundation ServerÊÇÒ»Ì×ÀûÓ÷¨Ê½ÐÔÃüÖÜÆÚÖÎÀí£¨ALM£©¹¤¾ßÌ×¼þÖеÄÍŶӺÏ×÷ƽ̨¡£¸Ãƽ̨Ô̺¬µÄ´úÂëÖÎÀí¡¢ÏîÄ¿ÖÎÀíµÈÖ°ÄÜ¡£Microsoft Azure DevOps ServerÊÇÒ»Ì×Èí¼þ¿ª·¢ºÏ×÷¹¤¾ß¡£¸Ã²úÆ·Ô̺¬¹²Ïí´úÂë¡¢¹¤×÷¸ú×ÙºÍÈí¼þ°ä²¼µÈÖ°ÄÜ¡£ Microsoft Team Foundation Server 2018 Update 3.2°æ±¾¡¢Azure DevOps Server 2019 Update 1°æ±¾ºÍ2019.0.1°æ±¾ÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓÐÕýÈ·ÑéÖ¤ÊäÈë¡£¹¥»÷Õß¿Éͨ¹ýÉÏ´«ÌØÔìµÄÎļþÀûÓø÷ì϶ÔÚTFS»òADO·þÎñÕË»§µÄ¸ßµÍÎÄÖÐÔÚ·þÎñÆ÷ÉÏÖ´ÐдúÂë¡£
Team Foundation Server
CVE-2019-0787
ÑϳÁ
Remote Desktop Client Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft WindowsºÍMicrosoft Windows Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft WindowsÊÇÒ»Ì×Ó×ÎÒÉ豸ʹÓõIJÙ×÷ϵͳ¡£Microsoft Windows ServerÊÇÒ»Ì×·þÎñÆ÷²Ù×÷ϵͳ¡£Windows
Remote Desktop ClientÊÇÆäÖеÄÒ»¸öWindowsÔ¶³Ì×ÀÃæ¿Í»§¶Ë·¨Ê½¡£ Microsoft Windows Remote Desktop ClientÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿Éͨ¹ýÔÚÉç»á¹¤³Ì¡¢DNS²¡¶¾»òʹÓÃÖÐÑëÈË(MITM)¼¼ÊõÓÕµ¼Óû§ÏνӶñÒâµÄ·þÎñÆ÷ÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£
Windows RDP
CVE-2019-0788
ÑϳÁ
Remote Desktop Client Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft WindowsºÍMicrosoft Windows Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft WindowsÊÇÒ»Ì×Ó×ÎÒÉ豸ʹÓõIJÙ×÷ϵͳ¡£Microsoft Windows ServerÊÇÒ»Ì×·þÎñÆ÷²Ù×÷ϵͳ¡£Windows
Remote Desktop ClientÊÇÆäÖеÄÒ»¸öWindowsÔ¶³Ì×ÀÃæ¿Í»§¶Ë·¨Ê½¡£ Microsoft Windows Remote Desktop ClientÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿Éͨ¹ýÔÚÉç»á¹¤³Ì¡¢DNS ²¡¶¾»òʹÓÃÖÐÑëÈË (MITM) ¼¼ÊõÓÕµ¼Óû§ÏνӶñÒâµÄ·þÎñÆ÷ÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£
Windows RDP
CVE-2019-1290
ÑϳÁ
Remote Desktop Client Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft WindowsºÍMicrosoft Windows Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft WindowsÊÇÒ»Ì×Ó×ÎÒÉ豸ʹÓõIJÙ×÷ϵͳ¡£Microsoft Windows ServerÊÇÒ»Ì×·þÎñÆ÷²Ù×÷ϵͳ¡£Windows
Remote Desktop ClientÊÇÆäÖеÄÒ»¸öWindowsÔ¶³Ì×ÀÃæ¿Í»§¶Ë·¨Ê½¡£Microsoft Windows Remote Desktop ClientÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿Éͨ¹ýÔÚÉç»á¹¤³Ì¡¢DNS ²¡¶¾»òʹÓÃÖÐÑëÈË (MITM) ¼¼ÊõÓÕµ¼Óû§ÏνӶñÒâµÄ·þÎñÆ÷ÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£
Windows RDP
CVE-2019-1291
ÑϳÁ
Remote Desktop Client Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft WindowsºÍMicrosoft Windows Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft WindowsÊÇÒ»Ì×Ó×ÎÒÉ豸ʹÓõIJÙ×÷ϵͳ¡£Microsoft Windows ServerÊÇÒ»Ì×·þÎñÆ÷²Ù×÷ϵͳ¡£Windows
Remote Desktop ClientÊÇÆäÖеÄÒ»¸öWindowsÔ¶³Ì×ÀÃæ¿Í»§¶Ë·¨Ê½¡£ Microsoft Windows Remote Desktop ClientÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚÏνӿͻ§¶ËµÄÍÆËã»úÉÏÖ´ÐÐËÁÒâ´úÂë¡£
Windows RDP
¡ñ½¨¸´½¨Òé
Ŀǰ£¬Î¢Èí¹Ù·½ÒѾ°ä²¼²¹¶¡½¨¸´ÁËÉÏÊö·ì϶£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½·ì϶ӰÏì¡£
¾¡¿ì²ÉÈ¡½¨²¹´ëÊ©£¬ÒÔÔ¤·ÀDZÔڵݲȫÍþв¡£ÏëÒª½øÐиüУ¬Ö»Ðèתµ½ÉèÖáú¸üкͰ²È«¡úWindows ¸üСú²é³¸üУ¬»òÕßÒ²Äܹ»Í¨¹ýÊÖ¶¯½øÐиüС£
¡ñ²Î¿¼Á´½Ó
https://portal.msrc.microsoft.com/en-US/security-guidance/releasenotedetail/24f46f0a-489c-e911-a994-000d3a33c573


¾©¹«Íø°²±¸11010802024551ºÅ