΢Èí1Ô¶à¸ö°²È«·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-01-16

·ì϶¸ÅÊö


΢ÈíÓÚÖܶþ°ä²¼ÁË1Ô°²È«¸üв¹¶¡£¬°ä²¼ÁËÕë¶Ô49¸ö·ì϶µÄ½¨¸´·¨Ê½¡£ÔÚÕâЩ·ì϶ÖУ¬ÓÐ7¸ö±»·ÖÀàΪÑϳÁ£¬41¸ö±»·ÖÀàΪ³ÁÒª£¬1¸ö±»·ÖÀàΪÖеÈ¡£²úÆ·Éæ¼°Microsoft Windows¡¢Internet Explorer¡¢Microsoft Office¡¢Microsoft Office ServicesºÍWebÀûÓá¢ASP.NET Core¡¢.NET Core¡¢.NET Framework¡¢OneDrive for Android¡¢Microsoft Dynamics¡£


ÒÔÏÂÊÇÒѽâ¾öµÄÑϳÁ·ì϶µÄÆëÈ«ÁбíÒÔ¼°2020Äê1Ô²¹¶¡ÐÇÆÚ¶þ¸üÐÂÖеĽ¨Òé¡£


CVE񅧏

ÑϳÁˮƽ

CVE±êÌâ

·ìϼûèÊö

²úÆ·

CVE-2020-0606

ÑϳÁ

.NET FrameworkÔ¶³ÌÖ´ÐдúÂë·ì϶

ÕâÊÇASP.NET ÓëÆäËû¿ò¼Ü£¨ÈçEntity Framework£©Ò»Â·×÷ΪÄ £¿é»¯Web¿ò¼ÜµÄ³ÁÐÂʵÏÖ¡£Ð¿ò¼ÜʹÓÃеĿªÔ´.NET±àÒëÆ÷ƽ̨£¨´úºÅ¡° Roslyn¡±£©¡£

.NET FrameworkÊÇMicrosoft¿ª·¢µÄÒ»ÖÖÈí¼þ¿ò¼Ü£¬ÖØÒªÔÚ WindowsÉÏÔËÐС£ËüÔ̺¬Ò»¸ö³ÆÎª¿ò¼ÜÀà¿â£¨FCL£©µÄ´óÐÍÀà¿â£¬²¢ÌṩÁ˼¸ÖÖ±à³Ì˵»°Ö®¼äµÄ˵»°»¥²Ù×÷ÐÔ£¨Ã¿ÖÖ˵»°¶¼Äܹ»Ê¹ÓÃÒÔÆäËû˵»°±àдµÄ´úÂ룩¡£Îª.NET Framework±àдµÄ·¨Ê½ÔÚ³ÆÎª¹«¹²Ëµ»°ÔËÐÐʱ£¨CLR£©µÄÈí¼þ»·¾³£¨ÓëÓ²¼þ»·¾³Ïà·´£©ÖÐÖ´ÐС£FCLºÍCLR¹²Í¬×é³É.NET Framework¡£

.NET FrameworkÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶²úÉúµÄÔ­ÒòÖØÒªÊÇ.NET FrameworkÔÚ¶ÔÎļþÔ´ÏóÕ÷½øÐв鳭ʱ´æÔÚÎÊÌâ¡£¹¥»÷ÕßÄܹ»ÓÕµ¼Óû§Ê¹ÓÃÊÜÓ°ÏìµÄ.NET Framework´ò¿ªÌØÔìµÄÎļþ£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£

.NET Framework

CVE-2020-0605

ÑϳÁ

.NET FrameworkÔ¶³ÌÖ´ÐдúÂë·ì϶

ÕâÊÇASP.NET ÓëÆäËû¿ò¼Ü£¨ÈçEntity Framework£©Ò»Â·×÷ΪÄ £¿é»¯Web¿ò¼ÜµÄ³ÁÐÂʵÏÖ¡£Ð¿ò¼ÜʹÓÃеĿªÔ´.NET±àÒëÆ÷ƽ̨£¨´úºÅ¡° Roslyn¡±£©¡£

.NET FrameworkÊÇMicrosoft¿ª·¢µÄÒ»ÖÖÈí¼þ¿ò¼Ü£¬ÖØÒªÔÚ WindowsÉÏÔËÐС£ËüÔ̺¬Ò»¸ö³ÆÎª¿ò¼ÜÀà¿â£¨FCL£©µÄ´óÐÍÀà¿â£¬²¢ÌṩÁ˼¸ÖÖ±à³Ì˵»°Ö®¼äµÄ˵»°»¥²Ù×÷ÐÔ£¨Ã¿ÖÖ˵»°¶¼Äܹ»Ê¹ÓÃÒÔÆäËû˵»°±àдµÄ´úÂ룩¡£Îª.NET Framework±àдµÄ·¨Ê½ÔÚ³ÆÎª¹«¹²Ëµ»°ÔËÐÐʱ£¨CLR£©µÄÈí¼þ»·¾³£¨ÓëÓ²¼þ»·¾³Ïà·´£©ÖÐÖ´ÐС£FCLºÍCLR¹²Í¬×é³É.NET Framework¡£

¸Ã·ì϶²úÉúµÄÔ­ÒòÖØÒªÊÇ.NET FrameworkÔÚ¶ÔÎļþÔ´ÏóÕ÷½øÐв鳭ʱ´æÔÚÎÊÌâ¡£¹¥»÷ÕßÄܹ»ÓÕµ¼Óû§Ê¹ÓÃÊÜÓ°ÏìµÄ.NET Framework´ò¿ªÌØÔìµÄÎļþ£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£

.NET Framework

CVE-2020-0646

ÑϳÁ

.NET FrameworkÔ¶³ÌÖ´ÐдúÂë×¢Èë·ì϶

ASP.NETÊÇÊ¢¿ªÔ´´úÂë·þÎñÆ÷¶Ë WebÀûÓ÷¨Ê½¿ò¼Ü£¬Ö¼ÔÚÓÃÓÚWeb¿ª·¢ÒÔÌìÉúMicrosoft¿ª·¢µÄ¶¯Ì¬ÍøÒ³£¬ÒÔÔÊÐí·¨Ê½Ô±¹¹½¨¶¯Ì¬ÍøÕ¾£¬ÀûÓ÷¨Ê½ºÍ·þÎñ¡£ASP.NETµÄºó¼ÌÕßÊÇASP.NET Core¡£ËüÊÇASP.NET ÓëÆäËû¿ò¼Ü£¨ÈçEntity Framework£©Ò»Â·×÷ΪÄ £¿é»¯Web¿ò¼ÜµÄ³ÁÐÂʵÏÖ¡£Ð¿ò¼ÜʹÓÃеĿªÔ´.NET±àÒëÆ÷ƽ̨£¨´úºÅ¡° Roslyn¡±£©¡£

¸Ã·ì϶²úÉúµÄÔ­ÒòÖØÒªÊÇ.NET FrameworkÎÞ·¨ÕýÈ·ÑéÖ¤ÊäÈ룬ÔÚÓû§ÊäÈëÖÐÄܹ»²åÈë¿ÉÖ´ÐеĺÅÁî¡£¹¥»÷ÕßÄܹ»ÀûÓÃÌØ¶¨µÄ.NET²½Öè½«ÌØ¶¨ÊäÈë´«ÈëÀûÓ÷¨Ê½£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£

.NET Framework

CVE-2020-0603

ÑϳÁ

ASP.NET CoreÔ¶³ÌÖ´ÐдúÂë·ì϶

ASP.NETÊÇÊ¢¿ªÔ´´úÂë·þÎñÆ÷¶Ë WebÀûÓ÷¨Ê½¿ò¼Ü£¬Ö¼ÔÚÓÃÓÚWeb¿ª·¢ÒÔÌìÉúMicrosoft¿ª·¢µÄ¶¯Ì¬ÍøÒ³£¬ÒÔÔÊÐí·¨Ê½Ô±¹¹½¨¶¯Ì¬ÍøÕ¾£¬ÀûÓ÷¨Ê½ºÍ·þÎñ¡£ASP.NETµÄºó¼ÌÕßÊÇASP.NET Core¡£

¸Ã·ì϶²úÉúµÄÔ­ÒòÖØÒªÊÇASP.NET CoreÔÚ´¦ÖÃÄÚ´æ¶ÔÏóʱ´æÔÚÎÊÌâ¡£¹¥»÷ÕßÄܹ»ÓÕµ¼Óû§Ê¹ÓÃÊÜÓ°ÏìµÄASP.NET Core´ò¿ªÌØÔìµÄÎļþ£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£

ASP.NET

CVE-2020-0610

ÑϳÁ

WindowsÔ¶³Ì×ÀÃæÍø¹Ø£¨RDÍø¹Ø£©Ô¶³ÌÖ´ÐдúÂë·ì϶

Óû§¿ªÆôÔ¶³Ì×ÀÃæÖ°ÄÜ£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýRDPÏòÓû§·¢Ë;«ÐÄÔì×÷µÄ¶ñÒâÒªÇ󣬼´¿ÉÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂ룬¸Ã¹ý³Ì²»±ØÒªÓû§½»»¥¡£´Ë¸üÐÂͨ¹ý¸üÕý RDP Íø¹Ø´¦ÖÃÏνÓÒªÇóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£

Windows RDP

CVE-2020-0609

ÑϳÁ

WindowsÔ¶³Ì×ÀÃæÍø¹Ø£¨RDÍø¹Ø£©Ô¶³ÌÖ´ÐдúÂë·ì϶

Óû§¿ªÆôÔ¶³Ì×ÀÃæÖ°ÄÜ£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýRDPÏòÓû§·¢Ë;«ÐÄÔì×÷µÄ¶ñÒâÒªÇ󣬼´¿ÉÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂ룬¸Ã¹ý³Ì²»±ØÒªÓû§½»»¥¡£´Ë¸üÐÂͨ¹ý¸üÕý RDP Íø¹Ø´¦ÖÃÏνÓÒªÇóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£

Windows RDP

CVE-2020-0611

ÑϳÁ

Ô¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³ÌÖ´ÐдúÂë·ì϶

¹¥»÷ÕßʹÓýÚÔìµÄ¶ñÒâ·þÎñÆ÷£¬ÓÕµ¼Óû§Ïνӵ½¶ñÒâ·þÎñÆ÷£¬Äܹ»ÔÚÏνӿͻ§¶ËµÄÍÆËã»úÉÏÖ´ÐÐËÁÒâ´úÂë¡£¹¥»÷Õß»¹¿ÉÄÜ·çÏպϷ¨·þÎñÆ÷£¬ÔÚÆäÉÏÍйܶñÒâ´úÂ룬²¢ÆÚ´ýÓû§ÏνÓ¡£´Ë°²È«¸üÐÂͨ¹ý¸üÕý Windows Ô¶³Ì×ÀÃæ¿Í»§¶Ë´¦ÖÃÏνÓÒªÇóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£

Windows RDP


½¨¸´½¨Òé


Ŀǰ£¬Î¢Èí¹Ù·½ÒѾ­°ä²¼²¹¶¡½¨¸´ÁËÉÏÊö·ì϶£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½·ì϶ӰÏ죬¾¡¿ì²ÉÈ¡½¨²¹´ëÊ©£¬ÒÔÔ¤·ÀDZÔڵݲȫÍþв¡£ÏëÒª½øÐиüУ¬Ö»Ðèתµ½ÉèÖáú¸üкͰ²È«¡úWindows ¸üСú²é³­¸üУ¬»òÕßÒ²Äܹ»Í¨¹ýÊÖ¶¯½øÐиüС£


²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/zh-cn/security-guidance