΢Èí12Ô¶à¸ö°²È«·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2019-12-11

·ì϶¸ÅÊö


΢ÈíÓÚÖܶþ°ä²¼ÁË12Ô°²È«¸üв¹¶¡ £¬°ä²¼ÁË36¸ö·ì϶µÄ2¸ö²¼¸æºÍ¸üС£ÔÚÕâЩ·ì϶ÖÐ £¬ÓÐ7¸ö±»·ÖÀàΪÑϳÁ £¬27¸ö±»·ÖÀàΪ³ÁÒª £¬1¸ö±»·ÖÀàΪÖÐ £¬1¸ö±»·ÖÀàΪµÍ¡£Éæ¼°µ½Windows Hyper-V £¬Graphics £¬GDI, RDP, OLE £¬Microsoft PowerPoint £¬Word £¬Excel £¬Git for Visual StudioµÈ×é¼þºÍÈí¼þ¡£


±ØÒª¹Ø×¢µÄ·ì϶ÊÇWin32k×é¼þÖеÄÌØÈ¨ÌáÉý0day £¬¸Ã·ì϶£¨CVE-2019-1458£©ÊÇÓÉ¿¨°Í˹»ù×êÑÐÈËÔ±·¢ÏÖµÄ £¬²¢ÒÑÔÚÒ°±í±»»ý¼«ÀûÓá£Æ¾¾Ý΢ÈíµÄ°²È«²¼¸æ £¬¸Ã·ì϶²úÉúÔÚWin32k×é¼þÎÞ·¨ÕýÈ·´¦ÖÃÄÚ´æÖеĶÔÏóʱ £¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÄÚºËģʽÏÂÔËÐÐËÁÒâ´úÂë¡£ÒªÀûÓô˷ì϶ £¬¹¥»÷Õß±ØÐëÊ×ÏȵǼϵͳ £¬¶øºó¿Éͨ¹ýÔËÐÐÀûÓô˷ì϶µÄ¶ñÒâÈí¼þÀ´ÊÕÊÜϵͳ¡£


³ýÁ˰²È«¸üбí £¬Microsoft½ñÌ컹°ä²¼ÁËÁ½¸ö²¼¸æ¡£Ò»¸öÊÇ·þÎñ²Ö¿â¸üР£¬ÁíÒ»¸öÊÇÓйØÈôºÎɾ³ýÓÉÒ×Êܹ¥»÷µÄTPMÉ豸´´½¨µÄ¹ÂÁ¢Windows Hello for Business£¨WHfB£©¹«Ô¿µÄÖ¸ÄÏ¡£


ADV190026-MicrosoftÖ¸ÄÏ £¬ÓÃÓÚËãÕÊÔÚÒ×Êܹ¥»÷µÄTPMÉÏÌìÉú²¢ÓÃÓÚWindows HelloÆóÒµ°æµÄ¹ÂÁ¢ÃÜÔ¿

ADV990001-×îзþÎñ²Ö¿â¸üÐÂ


ÒÔÏÂÊÇÒѽâ¾öµÄÑϳÁ·ì϶µÄÆëÈ«ÁбíÒÔ¼°2019Äê12Ô²¹¶¡ÐÇÆÚ¶þ¸üÐÂÖеĽ¨Òé¡£


CVE񅧏

ÑϳÁˮƽ

CVE±êÌâ

·ìϼûèÊö

²úÆ·

CVE-2019-1468

ÑϳÁ

Win32kͼÐÎÔ¶³ÌÖ´ÐдúÂë·ì϶

Microsoft WindowsÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾°ä²¼µÄһϵÁвÙ×÷ϵͳ¡£GraphicsÊÇÆäÖеÄÒ»¸öͼÐÎÇý¶¯Æ÷×é¼þ¡£

Win32k Graphics´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-1468£© £¬¸Ã·ì϶²úÉúµÄÔ­ÒòÊÇWindows×ÖÌå¿âÔÚ´¦ÖÃÌØÔìµÄǶÈëʽ×ÖÌåʱ²úÉúÒì³£¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ £¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£

MicrosoftͼÐÎ×é¼þ

CVE-2019-1350

ÑϳÁ

Git for Visual StudioÔ¶³ÌÖ´ÐдúÂë·ì϶

Microsoft Visual Studio£¨¼ò³ÆVS»òMSVS£©ÊÇ΢Èí¹«Ë¾µÄ¿ª·¢¹¤¾ß°üϵÁвúÆ· £¬ÊÇÒ»¸öÆëÈ«µÄ¿ª·¢¹¤¾ß¼¯ £¬Ô̺¬ÁËÕû¸öÈí¼þÐÔÃüÖÜÆÚÖÐËù±ØÒªµÄ´ó²¿Ãʤ¾ß£¨UML¹¤¾ß¡¢´úÂë¹Ü¿Ø¹¤¾ß¡¢¼¯³É¿ª·¢»·¾³£¨IDE£©µÈµÈ£©¡£GitÊÇĿǰ×îÏȽøµÄ°æ±¾½ÚÔìϵͳ £¬Õ¼ÓÐ×î¶àµÄÓû§ÊýÁ¿²¢ÖÎÀí×ÅÊýÁ¿ÖØ´óµÄÈí¼þÏîÄ¿¡£VS2013ÆðÍ· £¬ÄÚÖÃÁËGit×é¼þ £¬·½±ã¿ª·¢ÈËÔ±½øÐа汾½ÚÔì¡£

Visual StudioµÄGit²å¼þ´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶ £¬¸Ã·ì϶²úÉúµÄÔ­ÒòÊÇGit²å¼þÎÞ·¨ÕýÈ·µØËãÕÊÌØ¶¨ÊäÈë¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ £¬ÒÔµ±Ç°Óû§Éí·ÝÖ´ÐÐËÁÒâ´úÂë¡£

Microsoft Visual Studio

CVE-2019-1349

ÑϳÁ

Git for Visual StudioÔ¶³ÌÖ´ÐдúÂë·ì϶

Microsoft Visual Studio£¨¼ò³ÆVS»òMSVS£©ÊÇ΢Èí¹«Ë¾µÄ¿ª·¢¹¤¾ß°üϵÁвúÆ· £¬ÊÇÒ»¸öÆëÈ«µÄ¿ª·¢¹¤¾ß¼¯ £¬Ô̺¬ÁËÕû¸öÈí¼þÐÔÃüÖÜÆÚÖÐËù±ØÒªµÄ´ó²¿Ãʤ¾ß£¨UML¹¤¾ß¡¢´úÂë¹Ü¿Ø¹¤¾ß¡¢¼¯³É¿ª·¢»·¾³£¨IDE£©µÈµÈ£©¡£GitÊÇĿǰ×îÏȽøµÄ°æ±¾½ÚÔìϵͳ £¬Õ¼ÓÐ×î¶àµÄÓû§ÊýÁ¿²¢ÖÎÀí×ÅÊýÁ¿ÖØ´óµÄÈí¼þÏîÄ¿¡£VS2013ÆðÍ· £¬ÄÚÖÃÁËGit×é¼þ £¬·½±ã¿ª·¢ÈËÔ±½øÐа汾½ÚÔì¡£

Visual StudioµÄGit²å¼þ´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶ £¬¸Ã·ì϶²úÉúµÄÔ­ÒòÊÇGit²å¼þÎÞ·¨ÕýÈ·µØËãÕÊÌØ¶¨ÊäÈë¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ £¬ÒÔµ±Ç°Óû§Éí·ÝÖ´ÐÐËÁÒâ´úÂë¡£

Microsoft Visual Studio

CVE-2019-1387

ÑϳÁ

Git for Visual StudioÔ¶³ÌÖ´ÐдúÂë·ì϶

µ± Git for Visual Studio ²»ÕýÈ·µØËãÕÊÊäÈëʱ £¬´æÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ÓëÕ¼ÓÐÖÎÀíÓû§È¨ÏÞµÄÓû§Ïà±È £¬ÕÊ»§±»ÅäÖÃΪռÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì¸üÓס£

ÈôÒªÀûÓô˷ì϶ £¬¹¥»÷ÕßÊ×ÏȱØÐëÓÕʹÓû§¿Ë¡¶ñÒâ´æ´¢¿â¡£

Microsoft Visual Studio

CVE-2019-1354

ÑϳÁ

Git for Visual StudioÔ¶³ÌÖ´ÐдúÂë·ì϶

Microsoft Visual Studio£¨¼ò³ÆVS»òMSVS£©ÊÇ΢Èí¹«Ë¾µÄ¿ª·¢¹¤¾ß°üϵÁвúÆ· £¬ÊÇÒ»¸öÆëÈ«µÄ¿ª·¢¹¤¾ß¼¯ £¬Ô̺¬ÁËÕû¸öÈí¼þÐÔÃüÖÜÆÚÖÐËù±ØÒªµÄ´ó²¿Ãʤ¾ß£¨UML¹¤¾ß¡¢´úÂë¹Ü¿Ø¹¤¾ß¡¢¼¯³É¿ª·¢»·¾³£¨IDE£©µÈµÈ£©¡£GitÊÇĿǰ×îÏȽøµÄ°æ±¾½ÚÔìϵͳ £¬Õ¼ÓÐ×î¶àµÄÓû§ÊýÁ¿²¢ÖÎÀí×ÅÊýÁ¿ÖØ´óµÄÈí¼þÏîÄ¿¡£VS2013ÆðÍ· £¬ÄÚÖÃÁËGit×é¼þ £¬·½±ã¿ª·¢ÈËÔ±½øÐа汾½ÚÔì¡£

Visual StudioµÄGit²å¼þ´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶ £¬¸Ã·ì϶²úÉúµÄÔ­ÒòÊÇGit²å¼þÎÞ·¨ÕýÈ·µØËãÕÊÌØ¶¨ÊäÈë¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ £¬ÒÔµ±Ç°Óû§Éí·ÝÖ´ÐÐËÁÒâ´úÂë¡£

Microsoft Visual Studio

CVE-2019-1352

ÑϳÁ

Git for Visual StudioÔ¶³ÌÖ´ÐдúÂë·ì϶

Microsoft Visual Studio£¨¼ò³ÆVS»òMSVS£©ÊÇ΢Èí¹«Ë¾µÄ¿ª·¢¹¤¾ß°üϵÁвúÆ· £¬ÊÇÒ»¸öÆëÈ«µÄ¿ª·¢¹¤¾ß¼¯ £¬Ô̺¬ÁËÕû¸öÈí¼þÐÔÃüÖÜÆÚÖÐËù±ØÒªµÄ´ó²¿Ãʤ¾ß£¨UML¹¤¾ß¡¢´úÂë¹Ü¿Ø¹¤¾ß¡¢¼¯³É¿ª·¢»·¾³£¨IDE£©µÈµÈ£©¡£GitÊÇĿǰ×îÏȽøµÄ°æ±¾½ÚÔìϵͳ £¬Õ¼ÓÐ×î¶àµÄÓû§ÊýÁ¿²¢ÖÎÀí×ÅÊýÁ¿ÖØ´óµÄÈí¼þÏîÄ¿¡£VS2013ÆðÍ· £¬ÄÚÖÃÁËGit×é¼þ £¬·½±ã¿ª·¢ÈËÔ±½øÐа汾½ÚÔì¡£

Visual StudioµÄGit²å¼þ´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶ £¬¸Ã·ì϶²úÉúµÄÔ­ÒòÊÇGit²å¼þÎÞ·¨ÕýÈ·µØËãÕÊÌØ¶¨ÊäÈë¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ £¬ÒÔµ±Ç°Óû§Éí·ÝÖ´ÐÐËÁÒâ´úÂë¡£

Microsoft Visual Studio

CVE-2019-1471

ÑϳÁ

Windows Hyper-VÔ¶³ÌÖ´ÐдúÂë·ì϶

µ±Ö÷»ú·þÎñÆ÷É쵀 Windows Hyper-V ÎÞ·¨ÕýÈ·ÑéÖ¤À´±ö²Ù×÷ϵͳÉϾ­Éí·ÝÑéÖ¤µÄÓû§µÄÊäÈëʱ £¬´æÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£ÈôÒªÀûÓô˷ì϶ £¬¹¥»÷ÕßÄܹ»ÔÚÀ´±ö²Ù×÷ϵͳÉÏÔËÐо­ÌØÊâÉè¼ÆµÄ¿Éʹ Hyper-V Ö÷»ú²Ù×÷ϵͳִÐÐËÁÒâ´úÂëµÄÀûÓ÷¨Ê½¡£

³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÖ÷»ú²Ù×÷ϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£

Windows Hyper-V

½¨¸´½¨Òé


Ŀǰ £¬Î¢Èí¹Ù·½ÒѾ­°ä²¼²¹¶¡½¨¸´ÁËÉÏÊö·ì϶ £¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½·ì϶ӰÏì £¬

¾¡¿ì²ÉÈ¡½¨²¹´ëÊ© £¬ÒÔÔ¤·ÀDZÔڵݲȫÍþв¡£ÏëÒª½øÐиüР£¬Ö»Ðèתµ½ÉèÖáú¸üкͰ²È«¡úWindows ¸üСú²é³­¸üР£¬»òÕßÒ²Äܹ»Í¨¹ýÊÖ¶¯½øÐиüС£


²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/zh-cn/security-guidance