΢Èí¶à¸ö°²È«·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-02-14

·ì϶¸ÅÊö


2ÔÂ12ÈÕ£¬Î¢Èí°ä²¼ÁË2019Äê2Ô·ݵÄÔ¶ÈÀýÐа²È«²¼¸æ£¬½¨¸´ÁËÆä¶à¿î²úÆ·´æÔÚµÄ242¸ö°²È«·ì϶¡£ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬£ºWindows 10 1809 & Windows Server2019£¨28¸ö£©¡¢Windows 10 1803 & WindowsServer v1803£¨29¸ö£©¡¢Windows 10 1709 & WindowsServer v1709£¨30¸ö£©¡¢Windows RT 8.1£¨24¸ö£©¡¢Windows Server 2012£¨25¸ö£©¡¢Windows 8.1 & Server 2012 R2£¨25¸ö£©¡¢Windows Server 2008£¨24¸ö£©¡¢Windows 7 and Windows Server 2008R2£¨24¸ö£©¡¢Internet Explorer£¨3¸ö£©¡¢Microsoft Edge£¨21¸ö£©ºÍOffice£¨9¸ö£©¡£


ÀûÓÃÉÏÊö·ì϶£¬¹¥»÷ÕßÄܹ»»ñÈ¡Ãô¸ÐÐÅÏ¢£¬ÌáÉýȨÏÞ£¬ºýŪ£¬Èƹý°²È«Ö°ÄÜÏÞ¶È£¬Ö´ÐÐÔ¶³Ì´úÂ룬»ò½øÐлؾø·þÎñ¹¥»÷µÈ¡£ÌáÐÑ¿í´óMicrosoftÓû§¾¡¿ìÏÂÔØ²¹¶¡¸üУ¬Ô¤·ÀÒý·¢·ì϶ÓйصÄÍøÂ簲ȫÊÂÎñ¡£

CVE񅧏

²¼¸æ±êÌâºÍÌáÒª

×î¸ßÑϳÁµÈ¼¶ºÍ·ì϶ӰÏì

ÊÜÓ°ÏìµÄÈí¼þ

CVE-2019-0630

Microsoft Windows SMB  ServerÔ¶³Ì´úÂëÖ´Ðзì϶

Microsoft Server Message Block 2.0£¨smbv2£©·þÎñÆ÷´¦ÖÃijЩҪÇóʱ´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£ÎªÁËÀûÓø÷ì϶£¬¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÏòÖ¸±êsmbv2·þÎñÆ÷·¢Ë;«ÐÄÉè¼ÆµÄÊý¾Ý°ü¡£

³ÁÒª

Ô¶³ÌÖ´ÐдúÂë

Windows Server 2008  R2

Windows Server 2012  R2

Windows Server 2008

Windows Server 2012

Windows Server 2016

Windows Server 2019

Server, version  1709

Server, version  1803

Windows 8.1

Windows 10

Windows 7

CVE-2019-0626

Microsoft Windows DHCP ServerÔ¶³Ì´úÂëÖ´Ðзì϶

µ±¹¥»÷ÕßÏòDHCP·þÎñÆ÷·¢Ë;«ÐÄÉè¼ÆµÄÊý¾Ý°üʱ£¬Windows Server DHCP·þÎñÖдæÔÚÄÚ´æ·ÛËé·ì϶¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚDHCP·þÎñÆ÷ÉÏÔËÐÐËÁÒâ´úÂë¡£

ÑϳÁ

Ô¶³ÌÖ´ÐдúÂë

Windows Server 2008  R2

Windows Server 2012  R2

Windows Server 2008

Windows Server 2012

Windows Server 2016

Windows Server 2019

Server, version  1709

Server, version  1803

Windows 8.1

Windows 10

Windows 7

CVE-2019-0662

Microsoft  Windows GDI+ ×é¼þÔ¶³Ì´úÂëÖ´Ðзì϶

¹¥»÷ÕßÄܹ»Í¨¹ý¶àÖÖ·½Ê½ÀûÓø÷ì϶£ºÔÚ»ùÓÚWebµÄ¹¥»÷³¡¾°ÖУ¬¹¥»÷ÕßÄܹ»ÍйÜÒ»¸öרÃÅÉè¼ÆÓÃÓÚÀûÓø÷ì϶µÄÍøÕ¾£¬¶øºó˵·þÓû§²é¿´¸ÃÍøÕ¾¡£ÔÚÎļþ¹²Ïí¹¥»÷³¡¾°ÖУ¬¹¥»÷ÕßÄܹ»ÌṩרÃÅÉè¼ÆµÄÎĵµÎļþ£¬¸ÃÎļþÖ¼ÔÚÀûÓ÷ì϶£¬¶øºó˵·þÓû§´ò¿ªÎĵµÎļþ¡£

ÑϳÁ

Ô¶³ÌÖ´ÐдúÂë

Windows Server 2008 R2

Windows Server 2012 R2

Windows Server 2008

Windows Server 2012

Windows Server 2016

Windows Server 2019

Server, version 1709

Server, version 1803

Windows 8.1

Windows 10

Windows 7

CVE-2019-0625

Microsoft Windows JetÊý¾Ý¿âÒýÇæÔ¶³Ì´úÂëÖ´Ðзì϶

µ±Windows JetÊý¾Ý¿âÒýÇæÎ´ÄÜÕýÈ·µØ´¦ÖÃÄÚ´æÖеĶÔÏóʱ£¬´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÊܺ¦ÕßϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£¹¥»÷ÕßÄܹ»Í¨¹ýÓÕʹÊܺ¦Õß´ò¿ª¾«ÐļÙÔìµÄÎļþÀ´ÀûÓô˷ì϶¡£

³ÁÒª

Ô¶³ÌÖ´ÐдúÂë

Windows Server 2008  R2

Windows Server 2012  R2

Windows Server 2008

Windows Server 2012

Windows Server 2016

Windows Server 2019

Server, version  1709

Server, version 1803

Windows 8.1

Windows 10

Windows 7

CVE-2019-0636

Microsoft Windows±¾µØÐÅϢй¶·ì϶

µ±Windows²»ÕýÈ·µØ¹«¿ªÎļþÐÅϢʱ£¬´æÔÚÐÅÏ¢·ì϶¡£³É¹¦ÀûÓø÷ì϶¿Éʹ¹¥»÷Õß¶ÁÈ¡´ÅÅÌÉÏÎļþµÄÄÚÈÝ¡£ÒªÀûÓø÷ì϶£¬¹¥»÷Õß±ØÐëµÇ¼ÊÜÓ°ÏìµÄϵͳ²¢ÔËÐÐרÃÅÉè¼ÆµÄÀûÓ÷¨Ê½¡£¸üÐÂͨ¹ý¸ü¸ÄWindows¹«¿ªÎļþÐÅÏ¢µÄ·½Ê½À´½â¾ö¸Ã·ì϶¡£

³ÁÒª

ÐÅϢй¶

Windows Server 2008  R2

Windows Server 2012  R2

Windows Server 2008

Windows Server 2012

Windows Server 2016

Windows Server 2019

Server, version  1709

Server, version  1803

Windows 8.1

Windows 10

Windows 7

CVE-2019-0606

Microsoft Internet ExplorerÔ¶³ÌÄÚ´æ·ÛËé·ì϶

¹¥»÷ÕßÄܹ»ÍйÜÒ»¸ö¾«ÐÄÉè¼ÆµÄÍøÕ¾£¬¸ÃÍøÕ¾Ö¼ÔÚͨ¹ýÊÜÓ°ÏìµÄMicrosoftä¯ÀÀÆ÷ÀûÓø÷ì϶£¬¶øºó˵·þÓû§²é¿´¸ÃÍøÕ¾¡£¹¥»÷Õß»¹Äܹ»Í¨¹ýÔö³¤¿ÉÀûÓø÷ì϶µÄ¾«ÐÄÉè¼ÆµÄÄÚÈÝ£¬ÀûÓÃÊܵ½¹¥»÷µÄÍøÕ¾»ò½ÓÊÜ»òËÞÖ÷Óû§ÌṩµÄÄÚÈÝ»ò¸æ°×µÄÍøÕ¾¡£

ÑϳÁ

Ô¶³ÌÖ´ÐдúÂë

Internet Explorer  11

CVE-2019-0607

Microsoft Edge Chakra Scripting EngineÔ¶³ÌÄÚ´æ·ÛËé·ì϶

¹¥»÷ÕßÄܹ»ÍйÜÒ»¸ö¾«ÐÄÉè¼ÆµÄÍøÕ¾£¬¸ÃÍøÕ¾Ö¼ÔÚͨ¹ýÊÜÓ°ÏìµÄMicrosoftä¯ÀÀÆ÷ÀûÓø÷ì϶£¬¶øºó˵·þÓû§²é¿´¸ÃÍøÕ¾¡£¹¥»÷Õß»¹Äܹ»Í¨¹ýÔö³¤¿ÉÀûÓø÷ì϶µÄ¾«ÐÄÉè¼ÆµÄÄÚÈÝ£¬ÀûÓÃÊܵ½¹¥»÷µÄÍøÕ¾»ò½ÓÊÜ»òËÞÖ÷Óû§ÌṩµÄÄÚÈÝ»ò¸æ°×µÄÍøÕ¾¡£¹¥»÷Õß»¹Äܹ»ÔÚ³ÐÔØä¯ÀÀÆ÷³öÏÖÒýÇæµÄÀûÓ÷¨Ê½»òOfficeÎĵµÖÐǶÈëÏóÕ÷Ϊ¡°³õʼ»¯°²È«¡±µÄActiveX¿Ø¼þ¡£

ÑϳÁ

Ô¶³ÌÖ´ÐдúÂë

Microsoft Edge

ChakraCore

CVE-2019-0594

Microsoft SharePoint ServerÔ¶³Ì´úÂëÖ´Ðзì϶

µ±Èí¼þÎÞ·¨²é³­ÀûÓ÷¨Ê½°üµÄÔ´ÏóÕ÷ʱ£¬Microsoft SharePointÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£³É¹¦ÀûÓ÷ì϶µÄ¹¥»÷ÕßÄܹ»ÔËÐÐSharePointÀûÓ÷¨Ê½³ØºÍSharePoint·þÎñÆ÷³¡ÕÊ»§¸ßµÍÎÄÖеÄËÁÒâ´úÂë¡£ÀûÓô˷ì϶±ØÒªÓû§½«¾«ÐÄÉè¼ÆµÄSharePointÀûÓ÷¨Ê½°üÉÏÔØµ½ÊÜÓ°ÏìµÄSharePoint°æ±¾¡£

ÑϳÁ

Ô¶³ÌÖ´ÐдúÂë

SharePoint Server  2010

SharePoint Foundation  2013

SharePoint  Enterprise Server 2016

SharePoint Server  2019

CVE-2019-0671

Microsoft Office Access Connectivity  EngineÔ¶³Ì´úÂëÖ´Ðзì϶

µ±Microsoft Office AccessÏνÓÒýÇæÎ´ÄÜÕýÈ·µØ´¦ÖÃÄÚ´æÖеĶÔÏóʱ£¬´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÊܺ¦ÕßϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£¹¥»÷ÕßÄܹ»Í¨¹ýÓÕʹÊܺ¦Õß´ò¿ª¾«ÐļÙÔìµÄÎļþÀ´ÀûÓô˷ì϶¡£

³ÁÒª

Ô¶³ÌÖ´ÐдúÂë

Office  2010/2013/2016/2019

Office 365 ProPlus

CVE-2019-0676

Internet Explorer ÐÅϢй©·ì϶

µ± Internet Explorer ²»ÕýÈ·µØ´¦ÖÃÄÚ´æÖеĶÔÏóʱ£¬´æÔÚÐÅϢй©·ì϶¡£

³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»²âÊÔÅÌÉÏÊÇ·ñ´æÔÚÎļþ¡£ÈôÒªÈù¥»÷³É¹¦£¬¹¥»÷Õß±ØÐëÓÕʹÓû§´ò¿ª¶ñÒâÍøÕ¾¡£

´Ë°²È«¸üÐÂͨ¹ý¸ü¸Ä Internet Explorer ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£

³ÁÒª

ÐÅϢй¶

Internet Explorer  11

CVE-2019-0686

Microsoft Exchange Server ÌØÈ¨ÌáÉý·ì϶

Microsoft Exchange Server ÖдæÔÚÌØÈ¨ÌáÉý·ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»³¢ÊÔ·ÂÕÕ Exchange ·þÎñÆ÷µÄÆäËûÈκÎÓû§¡£

ΪÁËÀûÓô˷ì϶£¬¹¥»÷Õß±ØÒªÖ´ÐÐÖÐÑëÈ˹¥»÷£¬ÒÔ½«Éí·ÝÑéÖ¤ÒªÇóת·¢µ½ Microsoft Exchange Server£¬½ø¶øÔÊÐí·ÂÕÕÆäËû Exchange Óû§¡£

Ϊ½¨¸´Õâ¸ö·ì϶£¬Ó¦½ç˵ EWSMaxSubscriptions µÄ Throttling Policy ²¢ÔÚÊýֵΪ 0 µÄǰÌáÏÂÀûÓÃÓڽṹ¡£ÕâÑù»áÔ¤·À Exchange ·þÎñÆ÷·¢ËÍ EWSÐÂÎÅ£¬²¢Ô¤·ÀÒÀÀµ EWS ֪ͨµÄÓû§¶ËÀûÓ÷¨Ê½µÄÕý³£ÔËÐС£ÊÜÓ°ÏìÀûÓõÄʾÀýÔ̺¬ Mac °æ Outlook¡¢ÉÌÎñ°æ Skype¡¢ÒÀÀµÍ¨ÖªµÄ LOB ÀûÓã¬ÒÔ¼°Ò»Ð© iOS ±¾»úµÄÓʼþÓû§¶Ë¡£

³ÁÒª

ÌØÈ¨ÌáÉý

Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 26

Microsoft Exchange Server 2013 Cumulative Update 22

Microsoft Exchange Server 2016 Cumulative Update 12

Microsoft Exchange Server 2019 Cumulative Update 1

CVE-2019-0540

Microsoft Office °²È«Ö°ÄÜÈÆ¹ý·ì϶

µ± Microsoft Office ²»ÑéÖ¤ URL ʱ£¬´æÔÚ°²È«Ö°ÄÜÈÆ¹ý·ì϶¡£

¹¥»÷ÕßÄܹ»·¢ËÍÕë¶ÔÊܺ¦ÕßÌØÊâÉè¼ÆµÄÎļþ£¬Õâ¸öÎļþ¿ÉÄÜÓÕʹÊܺ¦ÕßÊäÈëÆ¾Ö¤¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÖ´Ðд¹µö¹¥»÷¡£

´Ë¸üÐÂͨ¹ýÈ·±£ Microsoft Office ÕýÈ·ÑéÖ¤ URL À´½¨¸´´Ë·ì϶¡£

³ÁÒª

ÐÅϢй¶

Internet Explorer  11

CVE-2019-0591

¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶

¾ç±¾ÒýÇæÔÚ Microsoft Edge Öд¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½°Ü»µÄÚ´æ¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß±ã¿É½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£

ÔÚ»ùÓÚ Web µÄ¹¥»÷Çé¾°ÖУ¬¹¥»÷Õß¿ÉÄÜÕ¼ÓÐÒ»¸öÖ¼ÔÚͨ¹ý Microsoft Edge ÀûÓô˷ì϶µÄ¾­ÌØÊâÉè¼ÆµÄÍøÕ¾£¬¶øºóÓÕʹÓû§²é¿´¸ÃÍøÕ¾¡£¹¥»÷Õß»¹¿ÉÄÜÀûÓÃÔâµ½ÈëÇÖµÄÍøÕ¾ÒÔ¼°½ÓÊÜ»òÍйÜÓû§ÌṩµÄÄÚÈÝ»ò¸æ°×µÄÍøÕ¾¡£ÕâÐ©ÍøÕ¾¿ÉÄÜÔ̺¬Äܹ»ÀûÓô˷ì϶µÄ¾­ÌØÊâÉè¼ÆµÄÄÚÈÝ¡£

´Ë°²È«¸üз¨Ê½Í¨¹ýÅú¸Ä¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£

ÑϳÁ

Ô¶³ÌÖ´ÐдúÂë

Microsoft Edge


½¨¸´½¨Òé

Ŀǰ£¬Î¢Èí¹Ù·½ÒѾ­°ä²¼²¹¶¡½¨¸´ÁËÉÏÊö·ì϶£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½·ì϶ӰÏ죬¾¡¿ì²ÉÈ¡½¨²¹´ëÊ©£¬ÒÔÔ¤·ÀDZÔڵݲȫÍþв¡£ÏëÒª½øÐиüУ¬Ö»Ðèתµ½ÉèÖáú¸üкͰ²È«¡úWindows ¸üСú²é³­¸üУ¬»òÕßÒ²Äܹ»Í¨¹ýÊÖ¶¯½øÐиüС£


²Î¿¼Á´½Ó

https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/51503ac5-e6d2-e811-a983-000d3a33c57