΢Èí6Ô²¹¶¡ÈÕÐè¹Ø×¢µÄ¸ßΣÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-06-15

Îó²î±àºÅºÍ¼¶±ð


CVE-2018-8248  Ö÷Òª


CVE-2018-8231  ÑÏÖØ  ³§ÉÌ×ÔÆÀ£º8.1


CVE-2018-8225  ÑÏÖØ  ³§ÉÌ×ÔÆÀ£º8.1


CVE-2018-8267  ÑÏÖØ  ³§ÉÌ×ÔÆÀ£º6.4


Îó²î¸ÅÊö


6ÔÂ12ÈÕ£¬Î¢ÈíÐû²¼ÁË2018Äê6Ô·ݵÄÔ¶ÈÀýÐÐÇ徲ͨ¸æ£¬ÐÞ¸´ÁËÆä¶à¿î²úÆ·±£´æµÄ122¸öÇå¾²Îó²î¡£Í¨¸æÖаüÀ¨ÁËMicrosoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8248£©£¬Microsoft Windows HTTPЭÒé¿ÍÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8231£©£¬Windows DNSAPIÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8225£©¼°Microsoft  Internet Explorer¾ç±¾ÒýÇæÄÚ´æÆÆËðÎó²î£¨CVE-2018-8267£©¡£


ÀÖ³ÉʹÓÃMicrosoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²îµÄ¹¥»÷Õߣ¬ÄÜÔÚÄ¿½ñÓû§ÇéÐÎÏÂÖ´ÐÐí§Òâ´úÂ룬ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíԱȨÏ޵Ǽ£¬¹¥»÷ÕßÉõÖÁ¿ÉÒÔÍêÈ«¿ØÖƸÃÓû§µÄϵͳ¡£Microsoft Office 2010 Service Pack 2¡¢Microsoft Office 2013 RT Service Pack 1¡¢Microsoft Office 2013 Service Pack 1¡¢Microsoft Office 2016¡¢Microsoft Office 2016 Click-to-Run (C2R)µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£

 

ÀÖ³ÉʹÓÃMicrosoft Windows HTTP 2.0ЭÒé¿ÍÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²îµÄ¹¥»÷Õߣ¬¿ÉÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ룬²¢¿ØÖƸÃÓû§µÄϵͳ¡£Windows 10¡¢Windows 10 Version 1607¡¢Windows 10 Version 1703¡¢Windows 10 Version 1709¡¢Windows 10 Version 1803¡¢Windows Server 2016¡¢Windows Server 2016 (Server Core installation)¡¢Windows Server version 1709 (Server Core Installation)¡¢Windows Server version 1803 (Server Core Installation)µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£

 

ÀÖ³ÉʹÓÃWindows DNSAPIÔ¶³Ì´úÂëÖ´ÐÐÎó²îµÄ¹¥»÷Õߣ¬¿ÉÒÔÔÚÍâµØÏµÍ³ÕÊ»§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂ룬¶ø¹¥»÷ÕßËùÒª×öµÄ¾ÍÊǽ«Ê¹ÓöñÒâDNS·þÎñÆ÷ÏòÄ¿µÄ·¢ËÍË𻵵ÄDNSÏìÓ¦¡£Windows 7¡¢Windows 8.1¡¢Windows RT 8.1ºÍWindows 10ÒÔ¼°Windows Server 2008¡¢Windows Server 2008 R2¡¢Windows Server 2012¡¢Windows Server 2012 R2¡¢Windows Server 2016¡¢Windows Server°æ±¾1709ºÍ°æ±¾1803µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£


ÀÖ³ÉʹÓÃMicrosoft  Internet Explorer¾ç±¾ÒýÇæÄÚ´æÆÆËðÎó²îµÄ¹¥»÷Õߣ¬¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬ÔòÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£È»ºó¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£¬Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£¬»ò½¨Éè¾ßÓÐÍêÕûÓû§È¨ÏÞµÄÐÂÕÊ»§¡£Windows Server 2012¡¢Windows Server 2016¡¢Windows 10¡¢Windows 7¡¢Windows 8.1¡¢Windows RT 8.1¡¢Windows Server 2008 R2¡¢Windows Server 2012 R2ÒÔ¼°Windows Server 2008µÄInternet Explorer 9 ¡¢Internet Explorer 10ºÍInternet Explorer 11µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£


Îó²îÏÈÈÝ


Microsoft ExcelÊÇÃÀ¹ú΢Èí¹«Ë¾ÎªÊ¹ÓÃWindowsºÍApple Macintosh²Ù×÷ϵͳµÄµçÄÔ±àдµÄÒ»¿îµç×Ó±í¸ñÈí¼þ¡£Microsoft Excel±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¸ÃÎó²îÔ´ÓÚ¸ÃÈí¼þδÄÜ׼ȷ´¦Öóͷ£ÄÚ´æÖеŤ¾ß£¬¹¥»÷Õß¿Éͨ¹ýÏòÓû§·¢Ë;­ÓÉÌØÊâ½á¹¹µÄÎļþ²¢ÓÕʹÓû§·­¿ª¸ÃÎļþ£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£


Microsoft WindowsÊÇÃÀ¹ú΢Èí¹«Ë¾Ñз¢µÄÒ»Ì×½ÓÄÉÁËͼÐλ¯Ä£Ê½µÄ²Ù×÷ϵͳ¡£WindowsÖеÄHTTPЭÒéÊÇÒ»ÖÖͨѶЭÒ飬¼´³¬Îı¾´«ÊäЭÒé¡£Microsoft Windows HTTPЭÒé±£´æ¿ÍÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¸ÃÎó²îÔ´ÓÚHTTP ЭÒé¿ÍջδÄÜ׼ȷ´¦Öóͷ£ÄÚ´æÖеŤ¾ß£¬¹¥»÷Õß¿ÉÒÔÏòÄ¿µÄhttp.sys·þÎñÆ÷·¢Ë;­ÓÉÌØÊâ½á¹¹µÄÊý¾Ý°ü£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£


ÔÚ΢Èí±¾ÔÂÐÞ¸´µÄËùÓÐÎó²îÖУ¬±»ÒÔΪ×îÑÏÖØµÄÎó²îÊÇCVE-2018-8225¡£Ëü±»ÐÎòΪһ¸öWindows DNSAPIÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¸ÃÎó²îÊÇÓÉÓÚWindows ÓòÃûϵͳ£¨DNS£© DNSAPI.dllÎÞ·¨×¼È·´¦Öóͷ£DNSÏìÓ¦µ¼ÖµÄ¡£¹¥»÷Õß¿ÉÒÔÔÚÍâµØÏµÍ³ÕÊ»§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂ룬¶ø¹¥»÷ÕßËùÒª×öµÄ¾ÍÊǽ«Ê¹ÓöñÒâDNS·þÎñÆ÷ÏòÄ¿µÄ·¢ËÍË𻵵ÄDNSÏìÓ¦¡£


½öÓÐÒ»¸öÎó²îÔÚÐû²¼Ê±±»ÁÐΪ¹ûÕæ£¬ÕâÊÇÒ»¸ö¾ç±¾ÒýÇæÄÚ´æÆÆËðÎó²î£¬Îó²î±àºÅΪCVE-2018-8267£¬¾ç±¾ÒýÇæÔÚInternet ExplorerÖд¦Öóͷ£ÄÚ´æÖеŤ¾ßµÄ·½·¨Öб£´æµÄÔ¶³ÌÖ´ÐдúÂëÎó²î¡£ÔÚ»ùÓÚWebµÄ¹¥»÷ÇéÐÎÖУ¬¹¥»÷Õß¿ÉÄÜÍйܾ­ÓÉÌØÖÆµÄÍøÕ¾£¬¸ÃÍøÕ¾Ö¼ÔÚͨ¹ýInternet ExplorerʹÓôËÎó²î£¬È»ºóÓÕʹÓû§Éó²é¸ÃÍøÕ¾¡£¹¥»÷Õß»¹¿ÉÒÔÔÚÍйÜIE·ºÆðÒýÇæµÄÓ¦ÓóÌÐò»òMicrosoft OfficeÎĵµÖÐǶÈë±ê¼ÇΪ¡®Çå¾²³õʼ»¯¡¯µÄActiveX¿Ø¼þ¡£¹¥»÷Õß»¹¿ÉÒÔʹÓÃÊܵ½ÍþвµÄÍøÕ¾ºÍ½ÓÊÜ»òÍйÜÓû§ÌṩµÄÄÚÈÝ»ò¹ã¸æµÄÍøÕ¾¡£ÕâÐ©ÍøÕ¾¿ÉÄܰüÀ¨¿ÉʹÓôËÎó²îµÄÌØÖÆÄÚÈÝ¡£


ÐÞ¸´½¨Ò飺


ÏÖÔÚ£¬Î¢Èí¹Ù·½ÒѾ­Ðû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ï죬¾¡¿ì½ÓÄÉÐÞ²¹²½·¥£¬ÒÔ×èֹDZÔÚµÄÇå¾²Íþв¡£ÏëÒª¾ÙÐиüУ¬Ö»Ðèתµ½ÉèÖáú¸üкÍÇå¾²¡úWindows¸üСú¼ì²é¸üУ¬»òÕßÒ²¿ÉÒÔͨ¹ýÊÖ¶¯¾ÙÐиüС£

ÏÖÔÚÒѾ­·¢Ã÷ÓÐʹÓÃCVE-2018-8248Îó²îµÄľÂí£¬Ïà¹ØÁ´½Ó£ºhttps://www.symantec.com/security-center/writeup/2018-061314-3210-99¡£


²Î¿¼Á´½Ó£º


https://portal.msrc.microsoft.com/en-us/security-guidance/acknowledgments