΢Èí6Ô²¹¶¡ÈÕÐè¹Ø×¢µÄ¸ßΣ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-06-15

·ì϶±àºÅºÍ¼¶±ð


CVE-2018-8248  ³ÁÒª


CVE-2018-8231  ÑϳÁ  ³§ÉÌ×ÔÆÀ£º8.1


CVE-2018-8225  ÑϳÁ  ³§ÉÌ×ÔÆÀ£º8.1


CVE-2018-8267  ÑϳÁ  ³§ÉÌ×ÔÆÀ£º6.4


·ì϶¸ÅÊö


6ÔÂ12ÈÕ£¬Î¢Èí°ä²¼ÁË2018Äê6Ô·ݵÄÔ¶ÈÀýÐа²È«²¼¸æ£¬½¨¸´ÁËÆä¶à¿î²úÆ·´æÔÚµÄ122¸ö°²È«·ì϶ ¡£²¼¸æÖÐÔ̺¬ÁËMicrosoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-8248£©£¬Microsoft Windows HTTPºÍ̸²Ö¿âÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-8231£©£¬Windows DNSAPIÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-8225£©¼°Microsoft  Internet Explorer¾ç±¾ÒýÇæÄÚ´æ·ÛËé·ì϶£¨CVE-2018-8267£© ¡£


³É¹¦ÀûÓÃMicrosoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶µÄ¹¥»÷Õߣ¬ÄÜÔÚµ±Ç°Óû§»·¾³ÏÂÖ´ÐÐËÁÒâ´úÂ룬ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíԱȨÏ޵Ǽ£¬¹¥»÷ÕßÉõÖÁÄܹ»ÆëÈ«½ÚÔì¸ÃÓû§µÄϵͳ ¡£Microsoft Office 2010 Service Pack 2¡¢Microsoft Office 2013 RT Service Pack 1¡¢Microsoft Office 2013 Service Pack 1¡¢Microsoft Office 2016¡¢Microsoft Office 2016 Click-to-Run (C2R)µÈ°æ±¾¾ùÊÜ·ì϶ӰÏì ¡£

 

³É¹¦ÀûÓÃMicrosoft Windows HTTP 2.0ºÍ̸²Ö¿âÔ¶³Ì´úÂëÖ´Ðзì϶µÄ¹¥»÷Õߣ¬¿ÉÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂ룬²¢½ÚÔì¸ÃÓû§µÄϵͳ ¡£Windows 10¡¢Windows 10 Version 1607¡¢Windows 10 Version 1703¡¢Windows 10 Version 1709¡¢Windows 10 Version 1803¡¢Windows Server 2016¡¢Windows Server 2016 (Server Core installation)¡¢Windows Server version 1709 (Server Core Installation)¡¢Windows Server version 1803 (Server Core Installation)µÈ°æ±¾¾ùÊÜ·ì϶ӰÏì ¡£

 

³É¹¦ÀûÓÃWindows DNSAPIÔ¶³Ì´úÂëÖ´Ðзì϶µÄ¹¥»÷Õߣ¬Äܹ»ÔÚ±¾µØÏµÍ³ÕÊ»§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂ룬¶ø¹¥»÷ÕßËùÒª×öµÄ¾ÍÊǽ«Ê¹ÓöñÒâDNS·þÎñÆ÷ÏòÖ¸±ê·¢ËͰܻµµÄDNSÏìÓ¦ ¡£Windows 7¡¢Windows 8.1¡¢Windows RT 8.1ºÍWindows 10ÒÔ¼°Windows Server 2008¡¢Windows Server 2008 R2¡¢Windows Server 2012¡¢Windows Server 2012 R2¡¢Windows Server 2016¡¢Windows Server°æ±¾1709ºÍ°æ±¾1803µÈ°æ±¾¾ùÊÜ·ì϶ӰÏì ¡£


³É¹¦ÀûÓÃMicrosoft  Internet Explorer¾ç±¾ÒýÇæÄÚ´æ·ÛËé·ì϶µÄ¹¥»÷Õߣ¬Äܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ ¡£ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬Ôò³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»½ÚÔìÊÜÓ°ÏìµÄϵͳ ¡£¶øºó¹¥»÷ÕßÄܹ»×°Ö÷¨Ê½£¬²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£¬»ò´´½¨ÓµÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§ ¡£Windows Server 2012¡¢Windows Server 2016¡¢Windows 10¡¢Windows 7¡¢Windows 8.1¡¢Windows RT 8.1¡¢Windows Server 2008 R2¡¢Windows Server 2012 R2ÒÔ¼°Windows Server 2008µÄInternet Explorer 9 ¡¢Internet Explorer 10ºÍInternet Explorer 11µÈ°æ±¾¾ùÊÜ·ì϶ӰÏì ¡£


·ì϶½éÉÜ


Microsoft ExcelÊÇÃÀ¹ú΢Èí¹«Ë¾ÎªÊ¹ÓÃWindowsºÍApple Macintosh²Ù×÷ϵͳµÄµçÄÔ±àдµÄÒ»¿îµç×Ó±í¸ñÈí¼þ ¡£Microsoft Excel´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶ԴÓÚ¸ÃÈí¼þδÄÜÕýÈ·´¦ÖÃÄÚ´æÖеĶÔÏ󣬹¥»÷Õß¿Éͨ¹ýÏòÓû§·¢Ë;­¹ýÌØÊâ»ú¹ØµÄÎļþ²¢ÓÕʹÓû§´ò¿ª¸ÃÎļþ£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´Ðзì϶ ¡£


Microsoft WindowsÊÇÃÀ¹ú΢Èí¹«Ë¾Ñз¢µÄÒ»Ì×ѡȡÁËͼÐλ¯Ä£Ê½µÄ²Ù×÷ϵͳ ¡£WindowsÖеÄHTTPºÍ̸ÊÇÒ»ÖÖͨѶºÍ̸£¬¼´³¬Îı¾´«ÊäºÍ̸ ¡£Microsoft Windows HTTPºÍ̸´æÔÚ²Ö¿âÔ¶³Ì´úÂëÖ´Ðзì϶ ¡£¸Ã·ì϶ԴÓÚHTTP ºÍ̸²Ö¿âδÄÜÕýÈ·´¦ÖÃÄÚ´æÖеĶÔÏ󣬹¥»÷ÕßÄܹ»ÏòÖ¸±êhttp.sys·þÎñÆ÷·¢Ë;­¹ýÌØÊâ»ú¹ØµÄÊý¾Ý°ü£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´Ðзì϶ ¡£


ÔÚ΢Èí±¾Ô½¨¸´µÄËùÓзì϶ÖУ¬±»ÒÔΪ×îÑϳÁµÄ·ì϶ÊÇCVE-2018-8225 ¡£Ëü±»ÃèÊöΪһ¸öWindows DNSAPIÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶ÊÇÓÉÓÚWindows ÓòÃûϵͳ£¨DNS£© DNSAPI.dllÎÞ·¨ÕýÈ·´¦ÖÃDNSÏìÓ¦µ¼ÖµÄ ¡£¹¥»÷ÕßÄܹ»ÔÚ±¾µØÏµÍ³ÕÊ»§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂ룬¶ø¹¥»÷ÕßËùÒª×öµÄ¾ÍÊǽ«Ê¹ÓöñÒâDNS·þÎñÆ÷ÏòÖ¸±ê·¢ËͰܻµµÄDNSÏìÓ¦ ¡£


½öÓÐÒ»¸ö·ì϶Ôڰ䲼ʱ±»ÁÐΪ¹«¿ª£¬ÕâÊÇÒ»¸ö¾ç±¾ÒýÇæÄÚ´æ·ÛËé·ì϶£¬·ì϶±àºÅΪCVE-2018-8267£¬¾ç±¾ÒýÇæÔÚInternet ExplorerÖд¦ÖÃÄÚ´æÖеĶÔÏóµÄ·½Ê½ÖдæÔÚµÄÔ¶³ÌÖ´ÐдúÂë·ì϶ ¡£ÔÚ»ùÓÚWebµÄ¹¥»÷Çé¾°ÖУ¬¹¥»÷Õß¿ÉÄÜÍйܾ­¹ýÌØÔìµÄÍøÕ¾£¬¸ÃÍøÕ¾Ö¼ÔÚͨ¹ýInternet ExplorerÀûÓô˷ì϶£¬¶øºóÓÕʹÓû§²é¿´¸ÃÍøÕ¾ ¡£¹¥»÷Õß»¹Äܹ»ÔÚÍйÜIE³öÏÖÒýÇæµÄÀûÓ÷¨Ê½»òMicrosoft OfficeÎĵµÖÐǶÈëÏóÕ÷Ϊ¡®°²È«³õʼ»¯¡¯µÄActiveX¿Ø¼þ ¡£¹¥»÷Õß»¹Äܹ»ÀûÓÃÊܵ½ÍþвµÄÍøÕ¾ºÍ½ÓÊÜ»òÍйÜÓû§ÌṩµÄÄÚÈÝ»ò¸æ°×µÄÍøÕ¾ ¡£ÕâÐ©ÍøÕ¾¿ÉÄÜÔ̺¬¿ÉÀûÓô˷ì϶µÄÌØÔìÄÚÈÝ ¡£


½¨¸´½¨Ò飺


Ŀǰ£¬Î¢Èí¹Ù·½ÒѾ­°ä²¼²¹¶¡½¨¸´ÁËÉÏÊö·ì϶£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½·ì϶ӰÏ죬¾¡¿ì²ÉÈ¡½¨²¹´ëÊ©£¬ÒÔÔ¤·ÀDZÔڵݲȫÍþв ¡£ÏëÒª½øÐиüУ¬Ö»Ðèתµ½ÉèÖáú¸üкͰ²È«¡úWindows¸üСú²é³­¸üУ¬»òÕßÒ²Äܹ»Í¨¹ýÊÖ¶¯½øÐиüР¡£

ĿǰÒѾ­·¢ÏÖÓÐÀûÓÃCVE-2018-8248·ì϶µÄľÂí£¬ÓйØÁ´½Ó£ºhttps://www.symantec.com/security-center/writeup/2018-061314-3210-99 ¡£


²Î¿¼Á´½Ó£º


https://portal.msrc.microsoft.com/en-us/security-guidance/acknowledgments