΢Èí6Ô¶à¸ö°²È«·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-06-14·ì϶¸ÅÊö
2019Äê6ÔÂ11ÈÕ£¬Microsoft°ä²¼ÁËÁùÔ·ݰ²È«²¹¶¡¸üС£ÔÚ¹Ù·½µÄ°²È«¸üв¼¸æÖÐÒ»¹²Åû¶ÁË88¸ö·ì϶µÄÓйØÐÅÏ¢£¬ÆäÖÐ21¸ö»ñµÃÁË¡°ÑϳÁ¡±ÆÀ¼¶£¬ÕâÊÇ΢ÈíÓÐÊ·ÒÔÀ´·ì϶ÑϳÁˮƽ×î¸ßµÄÒ»´ÎÅÅÃû¡£½ØÖÁĿǰΪֹ£¬ÉÐδ·¢ÏÖÕâ88¸ö·ì϶µÄÔÚÒ°ÀûÓá£
³É¹¦ÀûÓÃÉÏÊö·ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡¢»ñÈ¡Óû§Êý¾Ý¡£Î¢Èí¶à¸ö²úÆ·ºÍϵͳÊÜ·ì϶ӰÏ졣Ŀǰ£¬Î¢Èí¹Ù·½ÒѾ°ä²¼·ì϶½¨¸´²¹¶¡£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½·ì϶ӰÏ죬²ÉÈ¡½¨²¹´ëÊ©¡£
1¡¢Windows Hyper-VÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0620£©£¨CVE-2019-0709£©£¨CVE-2019-0722£©
·ì϶¼ò½é£ºµ±Ö÷»ú·þÎñÆ÷É쵀 Windows Hyper-V ÎÞ·¨ÕýÈ·ÑéÖ¤À´±öϵͳÉϾÉí·ÝÑéÖ¤µÄÓû§ÊäÈëʱ£¬´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷ÕßÄܹ»ÔÚÀ´±ö²Ù×÷ϵͳÉÏÔËÐÐ¾ÌØÊâÉè¼ÆµÄ¶ñÒⷨʽ£¬×îÖÕÔÚÖ÷»ú·þÎñÆ÷ϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0709
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0722
2¡¢Jet Êý¾Ý¿âÒýÇæÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0904£©£¨CVE-2019-0905£©£¨CVE-2019-0906£©£¨CVE-2019-0907£©£¨CVE-2019-0908£©£¨CVE-2019-0909£©
·ì϶¼ò½é£ºµ± Windows Jet Êý¾Ý¿âÒýÇæ²»ÕýÈ·µØ´¦ÖÃÄÚ´æÖеĶÔÏóʱ£¬»á´¥·¢Ô¶³Ì´úÂëÖ´Ðзì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÊܺ¦ÕßϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0905
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0906
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0907
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0908
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0909
3¡¢ActiveX Data Objects (ADO)Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0888£©
·ì϶¼ò½é£ºActiveX Data Objects (ADO)´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£ ¹¥»÷Õ߿ɴ´½¨º¬ÓжñÒâ´úÂëµÄÍøÕ¾£¬²¢ÓÕʹÓû§½øÐнӼû£¬×îÖÕʵÏÖÔ¶³Ì´úÂëÖ´ÐС£
¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0888
4¡¢Microsoft Word Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-1034£©£¨CVE-2019-1035£©
·ì϶¼ò½é£ºµ± Microsoft WordÎÞ·¨ÕýÈ·´¦ÖÃÄÚ´æÖеĶÔÏóʱ£¬»á´¥·¢Ô¶³Ì´úÂëÖ´Ðзì϶¡£¹¥»÷Õß¿Éͨ¹ýÏòÓû§·¢ËÍ¾ÌØÊâÉè¼ÆµÄÎļþ²¢ÓÕʹÓû§´ò¿ª¸ÃÎļþÒÔÀûÓô˷ì϶¡£³É¹¦ÀûÓ÷ì϶µÄ¹¥»÷Õß¿ÉÔÚÓû§ÏµÍ³ÉÏÖ´ÐÐËÁÒâ´úÂë¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1035
5¡¢Chakra ¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶£¨CVE-2019-1002£©£¨CVE-2019-1003£©£¨CVE-2019-0989£©£¨CVE-2019-0991£©£¨CVE-2019-0992£©£¨CVE-2019-0993£©
·ì϶¼ò½é£ºChakra ¾ç±¾ÒýÇæÔÚ Microsoft Edge Öд¦ÖÃÄÚ´æÖеĶÔÏóʱ¿ÉÄÜ´¥·¢¸Ã·ì϶¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíԱȨÏ޵Ǽ£¬¹¥»÷Õß±ãÄܹ»ËÁÒâ×°Ö÷¨Ê½¡¢²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£¬»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1003
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0989
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0991
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0992
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0993
6¡¢Microsoft Speech API Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0985£©
·ì϶¼ò½é£ºµ±Microsoft Speech API²»ÕýÈ·µØ´¦ÖÃÎı¾µ½ÓïÒô£¨TTS£©ÊäÈëʱ£¬´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£ ¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖʹ¹¥»÷Õß¿ÉÄÜÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½À´·ÛËéÄÚ´æ¡£
¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0985
7¡¢Microsoft Windows°²È«ÌصãÈÆ¹ý·ì϶£¨CVE-2019-1019£©
·ì϶¼ò½é£º WindowsÖÐNetlogonÐÂÎÅ¿ÉÄÜ»ñÈ¡»á»°ÃÜÔ¿²¢¶ÔÐÂÎŽøÐÐÊðÃû£¬¸ÃÐÂÎÅ´æÔÚÒ»¸ö°²È«ÌصãÈÆ¹ý·ì϶¡£ÎªÁËÀûÓô˷ì϶£¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄÉè¼ÆµÄÉí·ÝÑéÖ¤ÒªÇ󡣳ɹ¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ê¹ÓÃÔʼÓû§È¨ÏÞ½Ó¼ûÁíÒ»Ì¨ÍÆËã»ú¡£
¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1019
8¡¢Microsoft IIS·þÎñÆ÷»Ø¾ø·þÎñ·ì϶£¨CVE-2019-0941£©
·ì϶¼ò½é£ºMicrosoft IIS ServerÖдæÔÚÒ»¸ö»Ø¾ø·þÎñ·ì϶£¨CVE-2019-0941£©£¬µ±¿ÉѡҪÇóɸѡְÄÜÎÞ·¨ÕýÈ·´¦ÖÃÒªÇóʱ£¬¸Ã·ì϶½«»áÆô³Ì¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜ»á¶ÔÅäÖÃΪʹÓÃÒªÇóɸѡµÄÒ³ÃæÔì³Éһʱ»Ø¾ø·þÎñ¡£
¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0941
9¡¢Windows NTLM´Û¸Ä·ì϶£¨CVE-2019-1040£©
·ì϶¼ò½é£ºMicrosoft WindowsµÄNTLMÖдæÔڴ۸ķì϶£¬¹¥»÷ÕßÄܹ»Í¨¹ýÖÐÑëÈ˹¥»÷³É¹¦ÈƹýNTLM MIC£¨ÐÂÎÅÆëÈ«ÐԲ鳣©µÄ±£»¤£¬ÊµÏÖNTLM°²È«Ö°ÄܵĽµ¼¶¡£¸Ã·ì϶Äܹ»Ôì³É·ÖÆçˮƽµÄ·çÏÕ£¬×îΪÑϳÁʱ¿ÉÔÚʹÓÃͨ³£ÓòÕ˺ŵÄÇé¿öϽÚÔìÓòÄÚµÄËùÓлúе¡£¹¥»÷ÕßÏëÒª³É¹¦ÀûÓô˷ì϶£¬±ØÒª´Û¸ÄNTLM»¥»»ÐÅÏ¢£¬¶øºóÔÚ±£ÕÏÊðÃûÒÀÈ»ÓÐЧµÄǰÌáÏÂÅú¸ÄNTLMÊý¾Ý°üµÄ±êÖ¾¡£
¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1040
10¡¢Windows»Ø¾ø·þÎñ·ì϶£¨CVE-2019-1025£©
·ì϶¼ò½é£ºWindowsµÄÄÚ´æ´¦Ö÷½Ê½ÖдæÔڻؾø·þÎñ·ì϶£¬µ±ÃýÎ󵨴¦ÖÃÄÚ´æ¶ÔÏóʱ½«»á´¥·¢¸Ã·ì϶¡£ÒªÀûÓô˷ì϶£¬¹¥»÷Õß±ØÐëµÇ¼µ½ÊÜÓ°ÏìµÄϵͳ²¢ÔËÐÐ¾ÌØÊâÉè¼ÆµÄÀûÓ÷¨Ê½»òÓÕÆÓû§´ò¿ªÍøÂç¹²ÏíÉϵÄÌØ¶¨Îļþ¡£¸Ã·ì϶²»ÔÊÐí¹¥»÷ÕßÖ±½ÓÖ´ÐдúÂë»òÌáÉýÓû§È¨ÏÞ£¬µ«¿ÉÄܻᵼÖÂÖ¸±êϵͳÖÕ³¡ÏìÓ¦¡£
¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1025
½¨¸´½¨Òé
Ŀǰ£¬Î¢Èí¹Ù·½ÒѾ°ä²¼²¹¶¡½¨¸´ÁËÉÏÊö·ì϶£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½·ì϶ӰÏ죬¾¡¿ì²ÉÈ¡½¨²¹´ëÊ©£¬ÒÔÔ¤·ÀDZÔڵݲȫÍþв¡£ÏëÒª½øÐиüУ¬Ö»Ðèתµ½ÉèÖáú¸üкͰ²È«¡úWindows ¸üСú²é³¸üУ¬»òÕßÒ²Äܹ»Í¨¹ýÊÖ¶¯½øÐиüС£
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ