΢Èí6Ô²¹¶¡ÈÕÐè¹Ø×¢µÄ¸ßΣ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-06-15·ì϶±àºÅºÍ¼¶±ð
CVE-2018-8248 ³ÁÒª
CVE-2018-8231 ÑϳÁ ³§ÉÌ×ÔÆÀ£º8.1
CVE-2018-8225 ÑϳÁ ³§ÉÌ×ÔÆÀ£º8.1
CVE-2018-8267 ÑϳÁ ³§ÉÌ×ÔÆÀ£º6.4
·ì϶¸ÅÊö
6ÔÂ12ÈÕ£¬Î¢Èí°ä²¼ÁË2018Äê6Ô·ݵÄÔ¶ÈÀýÐа²È«²¼¸æ£¬½¨¸´ÁËÆä¶à¿î²úÆ·´æÔÚµÄ122¸ö°²È«·ì϶¡£²¼¸æÖÐÔ̺¬ÁËMicrosoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-8248£©£¬Microsoft Windows HTTPºÍ̸²Ö¿âÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-8231£©£¬Windows DNSAPIÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-8225£©¼°Microsoft Internet Explorer¾ç±¾ÒýÇæÄÚ´æ·ÛËé·ì϶£¨CVE-2018-8267£©¡£
³É¹¦ÀûÓÃMicrosoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶µÄ¹¥»÷Õߣ¬ÄÜÔÚµ±Ç°Óû§»·¾³ÏÂÖ´ÐÐËÁÒâ´úÂ룬ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíԱȨÏ޵Ǽ£¬¹¥»÷ÕßÉõÖÁÄܹ»ÆëÈ«½ÚÔì¸ÃÓû§µÄϵͳ¡£Microsoft Office 2010 Service Pack 2¡¢Microsoft Office 2013 RT Service Pack 1¡¢Microsoft Office 2013 Service Pack 1¡¢Microsoft Office 2016¡¢Microsoft Office 2016 Click-to-Run (C2R)µÈ°æ±¾¾ùÊÜ·ì϶ӰÏì¡£
³É¹¦ÀûÓÃMicrosoft Windows HTTP 2.0ºÍ̸²Ö¿âÔ¶³Ì´úÂëÖ´Ðзì϶µÄ¹¥»÷Õߣ¬¿ÉÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂ룬²¢½ÚÔì¸ÃÓû§µÄϵͳ¡£Windows 10¡¢Windows 10 Version 1607¡¢Windows 10 Version 1703¡¢Windows 10 Version 1709¡¢Windows 10 Version 1803¡¢Windows Server 2016¡¢Windows Server 2016 (Server Core installation)¡¢Windows Server version 1709 (Server Core Installation)¡¢Windows Server version 1803 (Server Core Installation)µÈ°æ±¾¾ùÊÜ·ì϶ӰÏì¡£
³É¹¦ÀûÓÃWindows DNSAPIÔ¶³Ì´úÂëÖ´Ðзì϶µÄ¹¥»÷Õߣ¬Äܹ»ÔÚ±¾µØÏµÍ³ÕÊ»§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂ룬¶ø¹¥»÷ÕßËùÒª×öµÄ¾ÍÊǽ«Ê¹ÓöñÒâDNS·þÎñÆ÷ÏòÖ¸±ê·¢ËͰܻµµÄDNSÏìÓ¦¡£Windows 7¡¢Windows 8.1¡¢Windows RT 8.1ºÍWindows 10ÒÔ¼°Windows Server 2008¡¢Windows Server 2008 R2¡¢Windows Server 2012¡¢Windows Server 2012 R2¡¢Windows Server 2016¡¢Windows Server°æ±¾1709ºÍ°æ±¾1803µÈ°æ±¾¾ùÊÜ·ì϶ӰÏì¡£
³É¹¦ÀûÓÃMicrosoft Internet Explorer¾ç±¾ÒýÇæÄÚ´æ·ÛËé·ì϶µÄ¹¥»÷Õߣ¬Äܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬Ôò³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¶øºó¹¥»÷ÕßÄܹ»×°Ö÷¨Ê½£¬²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£¬»ò´´½¨ÓµÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£Windows Server 2012¡¢Windows Server 2016¡¢Windows 10¡¢Windows 7¡¢Windows 8.1¡¢Windows RT 8.1¡¢Windows Server 2008 R2¡¢Windows Server 2012 R2ÒÔ¼°Windows Server 2008µÄInternet Explorer 9 ¡¢Internet Explorer 10ºÍInternet Explorer 11µÈ°æ±¾¾ùÊÜ·ì϶ӰÏì¡£
·ì϶½éÉÜ
Microsoft ExcelÊÇÃÀ¹ú΢Èí¹«Ë¾ÎªÊ¹ÓÃWindowsºÍApple Macintosh²Ù×÷ϵͳµÄµçÄÔ±àдµÄÒ»¿îµç×Ó±í¸ñÈí¼þ¡£Microsoft Excel´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶ԴÓÚ¸ÃÈí¼þδÄÜÕýÈ·´¦ÖÃÄÚ´æÖеĶÔÏ󣬹¥»÷Õß¿Éͨ¹ýÏòÓû§·¢Ë;¹ýÌØÊâ»ú¹ØµÄÎļþ²¢ÓÕʹÓû§´ò¿ª¸ÃÎļþ£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´Ðзì϶¡£
Microsoft WindowsÊÇÃÀ¹ú΢Èí¹«Ë¾Ñз¢µÄÒ»Ì×ѡȡÁËͼÐλ¯Ä£Ê½µÄ²Ù×÷ϵͳ¡£WindowsÖеÄHTTPºÍ̸ÊÇÒ»ÖÖͨѶºÍ̸£¬¼´³¬Îı¾´«ÊäºÍ̸¡£Microsoft Windows HTTPºÍ̸´æÔÚ²Ö¿âÔ¶³Ì´úÂëÖ´Ðзì϶¡£¸Ã·ì϶ԴÓÚHTTP ºÍ̸²Ö¿âδÄÜÕýÈ·´¦ÖÃÄÚ´æÖеĶÔÏ󣬹¥»÷ÕßÄܹ»ÏòÖ¸±êhttp.sys·þÎñÆ÷·¢Ë;¹ýÌØÊâ»ú¹ØµÄÊý¾Ý°ü£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´Ðзì϶¡£
ÔÚ΢Èí±¾Ô½¨¸´µÄËùÓзì϶ÖУ¬±»ÒÔΪ×îÑϳÁµÄ·ì϶ÊÇCVE-2018-8225¡£Ëü±»ÃèÊöΪһ¸öWindows DNSAPIÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶ÊÇÓÉÓÚWindows ÓòÃûϵͳ£¨DNS£© DNSAPI.dllÎÞ·¨ÕýÈ·´¦ÖÃDNSÏìÓ¦µ¼Öµġ£¹¥»÷ÕßÄܹ»ÔÚ±¾µØÏµÍ³ÕÊ»§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂ룬¶ø¹¥»÷ÕßËùÒª×öµÄ¾ÍÊǽ«Ê¹ÓöñÒâDNS·þÎñÆ÷ÏòÖ¸±ê·¢ËͰܻµµÄDNSÏìÓ¦¡£
½öÓÐÒ»¸ö·ì϶Ôڰ䲼ʱ±»ÁÐΪ¹«¿ª£¬ÕâÊÇÒ»¸ö¾ç±¾ÒýÇæÄÚ´æ·ÛËé·ì϶£¬·ì϶±àºÅΪCVE-2018-8267£¬¾ç±¾ÒýÇæÔÚInternet ExplorerÖд¦ÖÃÄÚ´æÖеĶÔÏóµÄ·½Ê½ÖдæÔÚµÄÔ¶³ÌÖ´ÐдúÂë·ì϶¡£ÔÚ»ùÓÚWebµÄ¹¥»÷Çé¾°ÖУ¬¹¥»÷Õß¿ÉÄÜÍйܾ¹ýÌØÔìµÄÍøÕ¾£¬¸ÃÍøÕ¾Ö¼ÔÚͨ¹ýInternet ExplorerÀûÓô˷ì϶£¬¶øºóÓÕʹÓû§²é¿´¸ÃÍøÕ¾¡£¹¥»÷Õß»¹Äܹ»ÔÚÍйÜIE³öÏÖÒýÇæµÄÀûÓ÷¨Ê½»òMicrosoft OfficeÎĵµÖÐǶÈëÏóÕ÷Ϊ¡®°²È«³õʼ»¯¡¯µÄActiveX¿Ø¼þ¡£¹¥»÷Õß»¹Äܹ»ÀûÓÃÊܵ½ÍþвµÄÍøÕ¾ºÍ½ÓÊÜ»òÍйÜÓû§ÌṩµÄÄÚÈÝ»ò¸æ°×µÄÍøÕ¾¡£ÕâÐ©ÍøÕ¾¿ÉÄÜÔ̺¬¿ÉÀûÓô˷ì϶µÄÌØÔìÄÚÈÝ¡£
½¨¸´½¨Ò飺
Ŀǰ£¬Î¢Èí¹Ù·½ÒѾ°ä²¼²¹¶¡½¨¸´ÁËÉÏÊö·ì϶£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½·ì϶ӰÏ죬¾¡¿ì²ÉÈ¡½¨²¹´ëÊ©£¬ÒÔÔ¤·ÀDZÔڵݲȫÍþв¡£ÏëÒª½øÐиüУ¬Ö»Ðèתµ½ÉèÖáú¸üкͰ²È«¡úWindows¸üСú²é³¸üУ¬»òÕßÒ²Äܹ»Í¨¹ýÊÖ¶¯½øÐиüС£
ĿǰÒѾ·¢ÏÖÓÐÀûÓÃCVE-2018-8248·ì϶µÄľÂí£¬ÓйØÁ´½Ó£ºhttps://www.symantec.com/security-center/writeup/2018-061314-3210-99¡£
²Î¿¼Á´½Ó£º
https://portal.msrc.microsoft.com/en-us/security-guidance/acknowledgments


¾©¹«Íø°²±¸11010802024551ºÅ