΢Èí2Ô¶à¸öÇå¾²Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-02-12

Îó²î¸ÅÊö


΢ÈíÓÚÖܶþÐû²¼ÁË2ÔÂÇå¾²¸üв¹¶¡£¬Ðû²¼ÁËÕë¶Ô99¸öÎó²îµÄÐÞ¸´³ÌÐò¡£ÔÚÕâЩÎó²îÖУ¬ÓÐ10¸ö±»·ÖÀàΪÑÏÖØ£¬87¸ö±»·ÖÀàΪÖ÷Òª£¬2¸ö±»·ÖÀàΪÖеÈ¡£


´Ë´Î¸üÐÂÖаüÀ¨Ò»¸öÕë¶ÔCVE-2020-0674 Internet ExplorerÁãÈÕÎó²îµÄÇå¾²¸üУ¬¸ÃÎó²îÔÚÒ°Íâ±»Æð¾¢Ê¹Óá£2020Äê1ÔÂ17ÈÕ£¬MicrosoftÐû²¼ÁËÓйØInternet ExplorerÁãÈÕÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î£¨CVE-2020-0674£©µÄͨ¸æ£ºhttps://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV200001£¬¸Ãͨ¸æÒѹûÕæÅû¶²¢±»¹¥»÷Õ߯ð¾¢Ê¹Óá£


¡°ÕâÊÇÒ»¸öÔ¶³ÌÖ´ÐдúÂëÎó²î£¬¸Ã¾ç±¾ÒýÇæ´¦Öóͷ£ÔÚInternet ExplorerÄÚ´æÖй¤¾ßµÄ·½·¨Öб£´æ£¬¸ÃÎó²î¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷Õß¿ÉÒÔÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂëµÄ·½·¨À´ÆÆËðÄÚ´æ¡£¡±ÀÖ³ÉʹÓôËÇå¾²Îó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëµÇ¼ÊÜËðWindows×°±¸µÄÓû§ÏàͬµÄÓû§È¨ÏÞ¡£ÈôÊÇÓû§Ê¹ÓÃÖÎÀíȨÏ޵Ǽ£¬Ôò¹¥»÷Õß¿ÉÒÔÍêÈ«¿ØÖÆÏµÍ³£¬´Ó¶øÔÊÐí³ÌÐò×°Öã¬Êý¾Ý²Ù×÷»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÕÊ»§µÄ¿ÉÄÜÐÔ¡£


΢ÈíÔö²¹Ëµ£º¡°ÔÚ»ùÓÚWebµÄ¹¥»÷ÇéÐÎÖУ¬¹¥»÷Õß¿ÉÄÜÓµÓÐÒ»¸öÖ¼ÔÚͨ¹ýInternet ExplorerʹÓôËÎó²îµÄÌØÖÆÍøÕ¾£¬È»ºóÓÕʹÓû§Éó²é¸ÃÍøÕ¾£¬ÀýÈ磬ͨ¹ý·¢Ë͵ç×ÓÓʼþ¡£¡±


±ðµÄ£¬Microsoft»¹ÉùÃ÷ÆäËûÈý¸öÎó²îÒѹûÕæÅû¶£¬µ«²¢Î´ÔÚÒ°ÍⱻʹÓᣰüÀ¨£ºCVE-2020-0683 -Windows InstallerÌØÈ¨ÌáÉýÎó²î£¬CVE-2020-0686 -Windows InstallerÌØÈ¨ÌáÉýÎó²î£¬CVE-2020-0706 -Microsoftä¯ÀÀÆ÷ÐÅϢй¶Îó²î¡£


ÒÔÏÂÊÇÒѽâ¾öµÄÑÏÖØÎó²îµÄÍêÕûÁбíÒÔ¼°2020Äê2Ô²¹¶¡ÐÇÆÚ¶þ¸üÐÂÖеĽ¨Òé¡£



CVE±àºÅ ÑÏÖØË®Æ½ CVEÎÊÌâ Îó²îÐÎò ±êÇ©
CVE-2020-0713 ÑÏÖØ ¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î ChakraCore ¾ç±¾ÒýÇæ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨Öб£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¸ÃÎó²î¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷Õß¿ÉÒÔÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂëµÄ·½·¨Ëð»µÄÚ´æ¡£ÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£ ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß±ã¿É¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°ÖóÌÐò£»Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß½¨ÉèÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ´ËÇå¾²¸üгÌÐòͨ¹ýÐÞ¸Ä ChakraCore ¾ç±¾ÒýÇæ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£ Microsoft¾ç±¾ÒýÇæ
CVE-2020-0711 ÑÏÖØ ¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î ChakraCore ¾ç±¾ÒýÇæ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨Öб£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¸ÃÎó²î¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷Õß¿ÉÒÔÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂëµÄ·½·¨Ëð»µÄÚ´æ¡£ÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£ ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß±ã¿É¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°ÖóÌÐò£»Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß½¨ÉèÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ´ËÇå¾²¸üгÌÐòͨ¹ýÐÞ¸Ä ChakraCore ¾ç±¾ÒýÇæ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£ Microsoft¾ç±¾ÒýÇæ
CVE-2020-0710 ÑÏÖØ ¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î ChakraCore ¾ç±¾ÒýÇæ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨Öб£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¸ÃÎó²î¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷Õß¿ÉÒÔÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂëµÄ·½·¨Ëð»µÄÚ´æ¡£ÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£ ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß±ã¿É¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°ÖóÌÐò£»Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß½¨ÉèÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ´ËÇå¾²¸üгÌÐòͨ¹ýÐÞ¸Ä ChakraCore ¾ç±¾ÒýÇæ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£ Microsoft¾ç±¾ÒýÇæ
CVE-2020-0712 ÑÏÖØ ¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î ChakraCore ¾ç±¾ÒýÇæ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨Öб£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¸ÃÎó²î¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷Õß¿ÉÒÔÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂëµÄ·½·¨Ëð»µÄÚ´æ¡£ÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£ ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß±ã¿É¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°ÖóÌÐò£»Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß½¨ÉèÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ´ËÇå¾²¸üгÌÐòͨ¹ýÐÞ¸Ä ChakraCore ¾ç±¾ÒýÇæ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£ Microsoft¾ç±¾ÒýÇæ
CVE-2020-0767 ÑÏÖØ ¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î ChakraCore ¾ç±¾ÒýÇæ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨Öб£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¸ÃÎó²î¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷Õß¿ÉÒÔÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂëµÄ·½·¨Ëð»µÄÚ´æ¡£ÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£ ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß±ã¿É¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°ÖóÌÐò£»Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß½¨ÉèÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ´ËÇå¾²¸üгÌÐòͨ¹ýÐÞ¸Ä ChakraCore ¾ç±¾ÒýÇæ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£ Microsoft¾ç±¾ÒýÇæ
CVE-2020-0681 ÑÏÖØ Ô¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³ÌÖ´ÐдúÂëÎó²î µ±Óû§ÅþÁ¬µ½¶ñÒâ·þÎñÆ÷ʱ£¬Windows Ô¶³Ì×ÀÃæ¿Í»§¶ËÖб£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÅþÁ¬¿Í»§¶ËµÄÅÌËã»úÖÐÖ´ÐÐí§Òâ´úÂë¡£¹¥»÷Õß¿ÉËæºó×°ÖóÌÐò£»Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß½¨ÉèÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ÈôҪʹÓôËÎó²î£¬¹¥»÷ÕßÐèÒª¿ØÖÆ·þÎñÆ÷£¬È»ºóÓÕµ¼Óû§ÅþÁ¬µ½¸Ã·þÎñÆ÷¡£¹¥»÷ÕßÎÞ·¨Ç¿ÆÈÓû§ÅþÁ¬µ½¶ñÒâ·þÎñÆ÷£¬ËûÃÇÐèҪͨ¹ýÉç»á¹¤³Ì¡¢DNS ²¡¶¾»òʹÓÃÖÐÐÄÈË (MITM) ÊÖÒÕÓÕµ¼Óû§ÅþÁ¬¡£¹¥»÷Õß»¹¿ÉÄÜΣº¦Õýµ±·þÎñÆ÷£¬ÔÚÆäÉÏÍйܶñÒâ´úÂ룬²¢ÆÚ´ýÓû§ÅþÁ¬¡£ ´ËÇå¾²¸üÐÂͨ¹ý¸üÕý Windows Ô¶³Ì×ÀÃæ¿Í»§¶Ë´¦Öóͷ£ÅþÁ¬ÇëÇóµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£ ΢ÈíWindows
CVE-2020-0734 ÑÏÖØ Ô¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³ÌÖ´ÐдúÂëÎó²î µ±Óû§ÅþÁ¬µ½¶ñÒâ·þÎñÆ÷ʱ£¬Windows Ô¶³Ì×ÀÃæ¿Í»§¶ËÖб£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÅþÁ¬¿Í»§¶ËµÄÅÌËã»úÖÐÖ´ÐÐí§Òâ´úÂë¡£¹¥»÷Õß¿ÉËæºó×°ÖóÌÐò£»Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß½¨ÉèÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ÈôҪʹÓôËÎó²î£¬¹¥»÷ÕßÐèÒª¿ØÖÆ·þÎñÆ÷£¬È»ºóÓÕµ¼Óû§ÅþÁ¬µ½¸Ã·þÎñÆ÷¡£¹¥»÷ÕßÎÞ·¨Ç¿ÆÈÓû§ÅþÁ¬µ½¶ñÒâ·þÎñÆ÷£¬ËûÃÇÐèҪͨ¹ýÉç»á¹¤³Ì¡¢DNS ²¡¶¾»òʹÓÃÖÐÐÄÈË (MITM) ÊÖÒÕÓÕµ¼Óû§ÅþÁ¬¡£¹¥»÷Õß»¹¿ÉÄÜΣº¦Õýµ±·þÎñÆ÷£¬ÔÚÆäÉÏÍйܶñÒâ´úÂ룬²¢ÆÚ´ýÓû§ÅþÁ¬¡£ ´ËÇå¾²¸üÐÂͨ¹ý¸üÕý Windows Ô¶³Ì×ÀÃæ¿Í»§¶Ë´¦Öóͷ£ÅþÁ¬ÇëÇóµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£ Ô¶³Ì×ÀÃæ¿Í»§¶Ë
CVE-2020-0662 ÑÏÖØ WindowsÔ¶³ÌÖ´ÐдúÂëÎó²î Windows ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨Öб£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÌáÉýµÄÌØÈ¨ÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£ ÈôҪʹÓôËÎó²î£¬¾ßÓÐÓòÓû§ÕÊ»§µÄ¹¥»÷Õß¿ÉÒÔ½¨Éè¾­ÌØÊâÉè¼ÆµÄÇëÇ󣬴ӶøÊ¹ Windows ʹÓÃÌáÉýµÄÌØÈ¨Ö´ÐÐí§Òâ´úÂë¡£ ´ËÇå¾²¸üгÌÐòͨ¹ý¸üÕý Windows ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨À´ÐÞ¸´Õâ¸öÎó²î¡£ Windows Hyper-V
CVE-2020-0738 ÑÏÖØ Media FoundationÄÚ´æËð»µÎó²î µ± Windows ýÌå»ù´¡²»×¼È·µØ´¦Öóͷ£ÄÚ´æÖй¤¾ßʱ£¬±£´æÄÚ´æËð»µÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß½¨ÉèÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ¹¥»÷Õß¿ÉÄÜͨ¹ý¶àÖÖ·½·¨Ê¹ÓôËÎó²î£¬°üÀ¨ÓÕʹÓû§·­¿ª¾­ÌØÊâÉè¼ÆµÄÎĵµ»òÓÕʹÓû§»á¼û¶ñÒâÍøÒ³¡£ ´ËÇå¾²¸üÐÂͨ¹ý¸üÕý Windows ýÌå»ù´¡´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£ WindowsýÌå
CVE-2020-0729 ÑÏÖØ LNKÔ¶³ÌÖ´ÐдúÂëÎó²î ÈôÊÇ´¦Öóͷ£ÁË .LNK Îļþ£¬Ôò Microsoft Windows Öб£´æÒ»¸öÔ¶³ÌÖ´ÐдúÂëÎó²î£¬¿ÉÄÜÔÊÐíÔ¶³ÌÖ´ÐдúÂë¡£ ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÄÜ»á»ñµÃÓëÍâµØÓû§ÏàͬµÄÓû§È¨ÏÞ¡£ÓëÓµÓÐÖÎÀíÓû§È¨ÏÞµÄÓû§Ïà±È£¬ÕÊ»§±»ÉèÖÃΪӵÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì¸üС¡£ ¹¥»÷Õß¿ÉÄÜ»áÏòÓû§ÏÔʾ°üÀ¨¶ñÒâ .LNK ÎļþºÍ¹ØÁªµÄ¶ñÒâ¶þ½øÖÆÎļþµÄ¿ÉÒÆ³ýÇý¶¯Æ÷»òÔ¶³Ì¹²Ïí¡£µ±Óû§ÔÚ Windows ×ÊÔ´ÖÎÀíÆ÷Öз­¿ª´ËÇý¶¯Æ÷£¨»òÔ¶³Ì¹²Ïí£©£¬»ò·­¿ª¿ÉÆÊÎö .LNK ÎļþµÄÆäËûÈκÎÓ¦ÓóÌÐòʱ£¬¶ñÒâ¶þ½øÖÆÎļþ»áÔÚÄ¿µÄϵͳÉÏÖ´Ðй¥»÷ÕßÑ¡ÔñµÄ´úÂë¡£ ´ËÇå¾²¸üгÌÐòͨ¹ý¸üÕý´¦Öóͷ£¿ì½Ý·½·¨ LNK ÒýÓõķ½·¨À´ÐÞ¸´´ËÎó²î¡£ Windows Shell



ÐÞ¸´½¨Òé



ÏÖÔÚ£¬Î¢Èí¹Ù·½ÒѾ­Ðû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ï죬 ¾¡¿ì½ÓÄÉÐÞ²¹²½·¥£¬ÒÔ×èֹDZÔÚµÄÇå¾²Íþв¡£ÏëÒª¾ÙÐиüУ¬Ö»Ðèתµ½ÉèÖáú¸üкÍÇå¾²¡úWindows ¸üСú¼ì²é¸üУ¬»òÕßÒ²¿ÉÒÔͨ¹ýÊÖ¶¯¾ÙÐиüС£


²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/zh-cn/security-guidance