΢Èí2Ô¶à¸ö°²È«·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-02-12·ì϶¸ÅÊö
΢ÈíÓÚÖܶþ°ä²¼ÁË2Ô°²È«¸üв¹¶¡£¬°ä²¼ÁËÕë¶Ô99¸ö·ì϶µÄ½¨¸´·¨Ê½¡£ÔÚÕâЩ·ì϶ÖУ¬ÓÐ10¸ö±»·ÖÀàΪÑϳÁ£¬87¸ö±»·ÖÀàΪ³ÁÒª£¬2¸ö±»·ÖÀàΪÖеȡ£
Õâ´Î¸üÐÂÖÐÔ̺¬Ò»¸öÕë¶ÔCVE-2020-0674 Internet ExplorerÁãÈÕ·ì϶µÄ°²È«¸üУ¬¸Ã·ì϶ÔÚÒ°±í±»»ý¼«ÀûÓá£2020Äê1ÔÂ17ÈÕ£¬Microsoft°ä²¼ÁËÓйØInternet ExplorerÁãÈÕÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶£¨CVE-2020-0674£©µÄ²¼¸æ£ºhttps://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV200001£¬¸Ã²¼¸æÒѹ«¿ªÅû¶²¢±»¹¥»÷Õß»ý¼«ÀûÓá£
¡°ÕâÊÇÒ»¸öÔ¶³ÌÖ´ÐдúÂë·ì϶£¬¸Ã¾ç±¾ÒýÇæ´¦ÖÃÔÚInternet ExplorerÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚ£¬¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½À´·ÛËéÄÚ´æ¡£¡±³É¹¦ÀûÓô˰²È«·ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓëµÇ¼ÊÜËðWindowsÉ豸µÄÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ÈôÊÇÓû§Ê¹ÓÃÖÎÀíȨÏ޵Ǽ£¬Ôò¹¥»÷ÕßÄܹ»ÆëÈ«½ÚÔìϵͳ£¬´Ó¶øÔÊÐí·¨Ê½×°Öã¬Êý¾Ý²Ù×÷»ò´´½¨ÓµÓÐÆëÈ«Óû§È¨ÏÞµÄÕÊ»§µÄ¿ÉÄÜÐÔ¡£
΢Èí²¹³ä˵£º¡°ÔÚ»ùÓÚWebµÄ¹¥»÷Çé¾°ÖУ¬¹¥»÷Õß¿ÉÄÜÕ¼ÓÐÒ»¸öÖ¼ÔÚͨ¹ýInternet ExplorerÀûÓô˷ì϶µÄÌØÔìÍøÕ¾£¬¶øºóÓÕʹÓû§²é¿´¸ÃÍøÕ¾£¬ÀýÈ磬ͨ¹ý·¢Ë͵ç×ÓÓʼþ¡£¡±
´Ë±í£¬Microsoft»¹ÉêÃ÷ÆäËûÈý¸ö·ì϶Òѹ«¿ªÅû¶£¬µ«²¢Î´ÔÚÒ°±í±»ÀûÓá£Ô̺¬£ºCVE-2020-0683 -Windows InstallerÌØÈ¨ÌáÉý·ì϶£¬CVE-2020-0686 -Windows InstallerÌØÈ¨ÌáÉý·ì϶£¬CVE-2020-0706 -Microsoftä¯ÀÀÆ÷ÐÅϢй¶·ì϶¡£
ÒÔÏÂÊÇÒѽâ¾öµÄÑϳÁ·ì϶µÄÆëÈ«ÁбíÒÔ¼°2020Äê2Ô²¹¶¡ÐÇÆÚ¶þ¸üÐÂÖеĽ¨Òé¡£
| CVE±àºÅ | ÑϳÁˮƽ | CVE±êÌâ | ·ìϼûèÊö | ±êÇ© |
| CVE-2020-0713 | ÑϳÁ | ¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶ | ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½°Ü»µÄÚ´æ¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß±ã¿É½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ´Ë°²È«¸üз¨Ê½Í¨¹ýÅú¸Ä ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£ | Microsoft¾ç±¾ÒýÇæ |
| CVE-2020-0711 | ÑϳÁ | ¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶ | ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½°Ü»µÄÚ´æ¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß±ã¿É½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ´Ë°²È«¸üз¨Ê½Í¨¹ýÅú¸Ä ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£ | Microsoft¾ç±¾ÒýÇæ |
| CVE-2020-0710 | ÑϳÁ | ¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶ | ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½°Ü»µÄÚ´æ¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß±ã¿É½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ´Ë°²È«¸üз¨Ê½Í¨¹ýÅú¸Ä ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£ | Microsoft¾ç±¾ÒýÇæ |
| CVE-2020-0712 | ÑϳÁ | ¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶ | ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½°Ü»µÄÚ´æ¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß±ã¿É½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ´Ë°²È«¸üз¨Ê½Í¨¹ýÅú¸Ä ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£ | Microsoft¾ç±¾ÒýÇæ |
| CVE-2020-0767 | ÑϳÁ | ¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶ | ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½°Ü»µÄÚ´æ¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß±ã¿É½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ´Ë°²È«¸üз¨Ê½Í¨¹ýÅú¸Ä ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£ | Microsoft¾ç±¾ÒýÇæ |
| CVE-2020-0681 | ÑϳÁ | Ô¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³ÌÖ´ÐдúÂë·ì϶ | µ±Óû§Ïνӵ½¶ñÒâ·þÎñÆ÷ʱ£¬Windows Ô¶³Ì×ÀÃæ¿Í»§¶ËÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÏνӿͻ§¶ËµÄÍÆËã»úÖÐÖ´ÐÐËÁÒâ´úÂë¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ÈôÒªÀûÓô˷ì϶£¬¹¥»÷Õß±ØÒª½ÚÔì·þÎñÆ÷£¬¶øºóÓÕµ¼Óû§Ïνӵ½¸Ã·þÎñÆ÷¡£¹¥»÷ÕßÎÞ·¨Ç¿ÆÅ×û§Ïνӵ½¶ñÒâ·þÎñÆ÷£¬ËûÃDZØÒªÍ¨¹ýÉç»á¹¤³Ì¡¢DNS ²¡¶¾»òʹÓÃÖÐÑëÈË (MITM) ¼¼ÊõÓÕµ¼Óû§Ïνӡ£¹¥»÷Õß»¹¿ÉÄÜ·çÏպϷ¨·þÎñÆ÷£¬ÔÚÆäÉÏÍйܶñÒâ´úÂ룬²¢ÆÚ´ýÓû§Ïνӡ£ ´Ë°²È«¸üÐÂͨ¹ý¸üÕý Windows Ô¶³Ì×ÀÃæ¿Í»§¶Ë´¦ÖÃÏνÓÒªÇóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£ | ΢ÈíWindows |
| CVE-2020-0734 | ÑϳÁ | Ô¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³ÌÖ´ÐдúÂë·ì϶ | µ±Óû§Ïνӵ½¶ñÒâ·þÎñÆ÷ʱ£¬Windows Ô¶³Ì×ÀÃæ¿Í»§¶ËÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÏνӿͻ§¶ËµÄÍÆËã»úÖÐÖ´ÐÐËÁÒâ´úÂë¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ÈôÒªÀûÓô˷ì϶£¬¹¥»÷Õß±ØÒª½ÚÔì·þÎñÆ÷£¬¶øºóÓÕµ¼Óû§Ïνӵ½¸Ã·þÎñÆ÷¡£¹¥»÷ÕßÎÞ·¨Ç¿ÆÅ×û§Ïνӵ½¶ñÒâ·þÎñÆ÷£¬ËûÃDZØÒªÍ¨¹ýÉç»á¹¤³Ì¡¢DNS ²¡¶¾»òʹÓÃÖÐÑëÈË (MITM) ¼¼ÊõÓÕµ¼Óû§Ïνӡ£¹¥»÷Õß»¹¿ÉÄÜ·çÏպϷ¨·þÎñÆ÷£¬ÔÚÆäÉÏÍйܶñÒâ´úÂ룬²¢ÆÚ´ýÓû§Ïνӡ£ ´Ë°²È«¸üÐÂͨ¹ý¸üÕý Windows Ô¶³Ì×ÀÃæ¿Í»§¶Ë´¦ÖÃÏνÓÒªÇóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£ | Ô¶³Ì×ÀÃæ¿Í»§¶Ë |
| CVE-2020-0662 | ÑϳÁ | WindowsÔ¶³ÌÖ´ÐдúÂë·ì϶ | Windows ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ê¹ÓÃÌáÉýµÄÌØÈ¨ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£ ÈôÒªÀûÓô˷ì϶£¬ÓµÓÐÓòÓû§ÕÊ»§µÄ¹¥»÷ÕßÄܹ»´´½¨¾ÌØÊâÉè¼ÆµÄÒªÇ󣬴ӶøÊ¹ Windows ÀûÓÃÌáÉýµÄÌØÈ¨Ö´ÐÐËÁÒâ´úÂë¡£ ´Ë°²È«¸üз¨Ê½Í¨¹ý¸üÕý Windows ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´Õâ¸ö·ì϶¡£ | Windows Hyper-V |
| CVE-2020-0738 | ÑϳÁ | Media FoundationÄÚ´æ°Ü»µ·ì϶ | µ± Windows ýÌå»ù´¡²»ÕýÈ·µØ´¦ÖÃÄÚ´æÖжÔÏóʱ£¬´æÔÚÄÚ´æ°Ü»µ·ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ¹¥»÷Õß¿ÉÄÜͨ¹ý¶àÖÖ·½Ê½ÀûÓô˷ì϶£¬Ô̺¬ÓÕʹÓû§´ò¿ª¾ÌØÊâÉè¼ÆµÄÎĵµ»òÓÕʹÓû§½Ó¼û¶ñÒâÍøÒ³¡£ ´Ë°²È«¸üÐÂͨ¹ý¸üÕý Windows ýÌå»ù´¡´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£ | WindowsýÌå |
| CVE-2020-0729 | ÑϳÁ | LNKÔ¶³ÌÖ´ÐдúÂë·ì϶ | ÈôÊÇ´¦ÖÃÁË .LNK Îļþ£¬Ôò Microsoft Windows ÖдæÔÚÒ»¸öÔ¶³ÌÖ´ÐдúÂë·ì϶£¬¿ÉÄÜÔÊÐíÔ¶³ÌÖ´ÐдúÂë¡£ ³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜ»á»ñµÃÓë±¾µØÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ÓëÕ¼ÓÐÖÎÀíÓû§È¨ÏÞµÄÓû§Ïà±È£¬ÕÊ»§±»ÅäÖÃΪռÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì¸üÓס£ ¹¥»÷Õß¿ÉÄÜ»áÏòÓû§ÏÔʾÔ̺¬¶ñÒâ .LNK ÎļþºÍ¹ØÁªµÄ¶ñÒâ¶þ½øÔìÎļþµÄ¿ÉÒÆ³ýÇý¶¯Æ÷»òÔ¶³Ì¹²Ïí¡£µ±Óû§ÔÚ Windows ×ÊÔ´ÖÎÀíÆ÷Öдò¿ª´ËÇý¶¯Æ÷£¨»òÔ¶³Ì¹²Ïí£©£¬»ò´ò¿ª¿É·ÖÎö .LNK ÎļþµÄÆäËûÈκÎÀûÓ÷¨Ê½Ê±£¬¶ñÒâ¶þ½øÔìÎļþ»áÔÚÖ¸±êϵͳÉÏÖ´Ðй¥»÷ÕßÑ¡ÔñµÄ´úÂë¡£ ´Ë°²È«¸üз¨Ê½Í¨¹ý¸üÕý´¦Öÿì½Ý·½Ê½ LNK ÒýÓõķ½Ê½À´½¨¸´´Ë·ì϶¡£ | Windows Shell |
½¨¸´½¨Òé
Ŀǰ£¬Î¢Èí¹Ù·½ÒѾ°ä²¼²¹¶¡½¨¸´ÁËÉÏÊö·ì϶£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½·ì϶ӰÏ죬 ¾¡¿ì²ÉÈ¡½¨²¹´ëÊ©£¬ÒÔÔ¤·ÀDZÔڵݲȫÍþв¡£ÏëÒª½øÐиüУ¬Ö»Ðèתµ½ÉèÖáú¸üкͰ²È«¡úWindows ¸üСú²é³¸üУ¬»òÕßÒ²Äܹ»Í¨¹ýÊÖ¶¯½øÐиüС£
²Î¿¼Á´½Ó
https://portal.msrc.microsoft.com/zh-cn/security-guidance


¾©¹«Íø°²±¸11010802024551ºÅ