΢Èí´¹Î£½¨¸´IE¼°Defender·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-09-24

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-1367£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-1255£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


CVE-2019-1367
IE9¡¢10ºÍ11
CVE-2019-1255

Defender 1.1.16300.1


·ì϶¸ÅÊö


΢Èí°ä²¼´¹Î£°²È«¸üУ¬½¨¸´IEÖеÄRCE 0day¼°Windows DefenderÖеÄDoS·ì϶¡£


CVE-2019-1367


´Ë·ì϶ÊÇÓÉInternetExplorer¾ç±¾ÒýÇæÖд¦ÖÃÄÚ´æ¶ÔÏóµÄ·½Ê½ÖеÄÄÚ´æ°Ü»µÒýÆðµÄ¡£ÒªÀûÓô˷ì϶£¬¹¥»÷Õß±ØÐëÊèµ¼Óû§´ò¿ªÒѾ­Íйܷì϶µÄ¶ñÒâÍøÕ¾¡£ÀûÓô˷ì϶Äܹ»µ¼Ö¹¥»÷Õß»ñµÃÓû§È·µ±Ç°È¨ÏÞ£¬²¢Ö´ÐÐËÁÒâ´úÂë¡£ÈôÊǵ±Ç°Óû§Õ¼ÓÐÖÎÀíȨÏÞ¹¥»÷ÕßÄܹ»ÔÚϵͳÉÏÖ´Ðи÷Àà²Ù×÷£¬´Ó´´½¨ÓµÓÐÆëȫȨÏÞµÄÐÂÕÊ»§µ½×°Ö÷¨Ê½ÉõÖÁÅú¸ÄÊý¾Ý¡£


CVE-2019-1255


´Ë·ì϶ÊÇWindows DefenderÖеĻؾø·þÎñ·ì϶£¬¸Ã·ì϶ÓëDefender´¦ÖÃÎļþµÄ·½Ê½ÓйØ£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶×èÖ¹ºÏ·¨ÕË»§Ö´ÐкϷ¨µÄϵͳÎļþ¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£ 


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£º


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1255?ranMID=24542&ranEAID=je6NUbpObpQ&ranSiteID=je6NUbpObpQ-FFyqiDVVceJ.9YKJh7SFaQ&epi=je6NUbpObpQ-FFyqiDVVceJ.9YKJh7SFaQ&irgwc=1&OCID=AID2000142_aff_7593_1243925&tduid=(ir__6uzmmvnfpkkfrjuzkk0sohzz0n2xgzdoytt2n2t200)(7593)(1243925)(je6NUbpObpQ-FFyqiDVVceJ.9YKJh7SFaQ)()&irclickid=_6uzmmvnfpkkfrjuzkk0sohzz0n2xgzdoytt2n2t200


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1367?ranMID=24542&ranEAID=je6NUbpObpQ&ranSiteID=je6NUbpObpQ-_818kqJ.tMcmbzNDDr5bdg&epi=je6NUbpObpQ-_818kqJ.tMcmbzNDDr5bdg&irgwc=1&OCID=AID2000142_aff_7593_1243925&tduid=(ir__6uzmmvnfpkkfrjuzkk0sohzz0n2xgzdvt1t2n2t200)(7593)(1243925)(je6NUbpObpQ-_818kqJ.tMcmbzNDDr5bdg)()&irclickid=_6uzmmvnfpkkfrjuzkk0sohzz0n2xgzdvt1t2n2t200¡£


²Î¿¼Á´½Ó


https://www.zdnet.com/article/microsoft-releases-out-of-band-security-update-to-fix-ie-zero-day-defender-bug/