΢Èí2Ô¶à¸ö°²È«·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-02-12

·ì϶¸ÅÊö


΢ÈíÓÚÖܶþ°ä²¼ÁË2Ô°²È«¸üв¹¶¡ £¬°ä²¼ÁËÕë¶Ô99¸ö·ì϶µÄ½¨¸´·¨Ê½¡£ÔÚÕâЩ·ì϶ÖÐ £¬ÓÐ10¸ö±»·ÖÀàΪÑϳÁ £¬87¸ö±»·ÖÀàΪ³ÁÒª £¬2¸ö±»·ÖÀàΪÖеÈ¡£


Õâ´Î¸üÐÂÖÐÔ̺¬Ò»¸öÕë¶ÔCVE-2020-0674 Internet ExplorerÁãÈÕ·ì϶µÄ°²È«¸üР£¬¸Ã·ì϶ÔÚÒ°±í±»»ý¼«ÀûÓá£2020Äê1ÔÂ17ÈÕ £¬Microsoft°ä²¼ÁËÓйØInternet ExplorerÁãÈÕÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶£¨CVE-2020-0674£©µÄ²¼¸æ£ºhttps://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV200001 £¬¸Ã²¼¸æÒѹ«¿ªÅû¶²¢±»¹¥»÷Õß»ý¼«ÀûÓá£


¡°ÕâÊÇÒ»¸öÔ¶³ÌÖ´ÐдúÂë·ì϶ £¬¸Ã¾ç±¾ÒýÇæ´¦ÖÃÔÚInternet ExplorerÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚ £¬¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½À´·ÛËéÄÚ´æ¡£¡±³É¹¦ÀûÓô˰²È«·ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓëµÇ¼ÊÜËðWindowsÉ豸µÄÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ÈôÊÇÓû§Ê¹ÓÃÖÎÀíȨÏ޵Ǽ £¬Ôò¹¥»÷ÕßÄܹ»ÆëÈ«½ÚÔìϵͳ £¬´Ó¶øÔÊÐí·¨Ê½×°Öà £¬Êý¾Ý²Ù×÷»ò´´½¨ÓµÓÐÆëÈ«Óû§È¨ÏÞµÄÕÊ»§µÄ¿ÉÄÜÐÔ¡£


΢Èí²¹³ä˵£º¡°ÔÚ»ùÓÚWebµÄ¹¥»÷Çé¾°ÖÐ £¬¹¥»÷Õß¿ÉÄÜÕ¼ÓÐÒ»¸öÖ¼ÔÚͨ¹ýInternet ExplorerÀûÓô˷ì϶µÄÌØÔìÍøÕ¾ £¬¶øºóÓÕʹÓû§²é¿´¸ÃÍøÕ¾ £¬ÀýÈç £¬Í¨¹ý·¢Ë͵ç×ÓÓʼþ¡£¡±


´Ë±í £¬Microsoft»¹ÉêÃ÷ÆäËûÈý¸ö·ì϶Òѹ«¿ªÅû¶ £¬µ«²¢Î´ÔÚÒ°±í±»ÀûÓá£Ô̺¬£ºCVE-2020-0683 -Windows InstallerÌØÈ¨ÌáÉý·ì϶ £¬CVE-2020-0686 -Windows InstallerÌØÈ¨ÌáÉý·ì϶ £¬CVE-2020-0706 -Microsoftä¯ÀÀÆ÷ÐÅϢй¶·ì϶¡£


ÒÔÏÂÊÇÒѽâ¾öµÄÑϳÁ·ì϶µÄÆëÈ«ÁбíÒÔ¼°2020Äê2Ô²¹¶¡ÐÇÆÚ¶þ¸üÐÂÖеĽ¨Òé¡£



CVE±àºÅ ÑϳÁˮƽ CVE±êÌâ ·ìϼûèÊö ±êÇ©
CVE-2020-0713 ÑϳÁ ¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶ ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½°Ü»µÄÚ´æ¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ £¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß±ã¿É½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ´Ë°²È«¸üз¨Ê½Í¨¹ýÅú¸Ä ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£ Microsoft¾ç±¾ÒýÇæ
CVE-2020-0711 ÑϳÁ ¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶ ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½°Ü»µÄÚ´æ¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ £¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß±ã¿É½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ´Ë°²È«¸üз¨Ê½Í¨¹ýÅú¸Ä ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£ Microsoft¾ç±¾ÒýÇæ
CVE-2020-0710 ÑϳÁ ¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶ ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½°Ü»µÄÚ´æ¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ £¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß±ã¿É½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ´Ë°²È«¸üз¨Ê½Í¨¹ýÅú¸Ä ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£ Microsoft¾ç±¾ÒýÇæ
CVE-2020-0712 ÑϳÁ ¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶ ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½°Ü»µÄÚ´æ¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ £¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß±ã¿É½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ´Ë°²È«¸üз¨Ê½Í¨¹ýÅú¸Ä ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£ Microsoft¾ç±¾ÒýÇæ
CVE-2020-0767 ÑϳÁ ¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶ ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½°Ü»µÄÚ´æ¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ £¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß±ã¿É½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ´Ë°²È«¸üз¨Ê½Í¨¹ýÅú¸Ä ChakraCore ¾ç±¾ÒýÇæ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£ Microsoft¾ç±¾ÒýÇæ
CVE-2020-0681 ÑϳÁ Ô¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³ÌÖ´ÐдúÂë·ì϶ µ±Óû§Ïνӵ½¶ñÒâ·þÎñÆ÷ʱ £¬Windows Ô¶³Ì×ÀÃæ¿Í»§¶ËÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÏνӿͻ§¶ËµÄÍÆËã»úÖÐÖ´ÐÐËÁÒâ´úÂë¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ÈôÒªÀûÓô˷ì϶ £¬¹¥»÷Õß±ØÒª½ÚÔì·þÎñÆ÷ £¬¶øºóÓÕµ¼Óû§Ïνӵ½¸Ã·þÎñÆ÷¡£¹¥»÷ÕßÎÞ·¨Ç¿ÆÅ×û§Ïνӵ½¶ñÒâ·þÎñÆ÷ £¬ËûÃDZØÒªÍ¨¹ýÉç»á¹¤³Ì¡¢DNS ²¡¶¾»òʹÓÃÖÐÑëÈË (MITM) ¼¼ÊõÓÕµ¼Óû§ÏνÓ¡£¹¥»÷Õß»¹¿ÉÄÜ·çÏպϷ¨·þÎñÆ÷ £¬ÔÚÆäÉÏÍйܶñÒâ´úÂë £¬²¢ÆÚ´ýÓû§ÏνÓ¡£ ´Ë°²È«¸üÐÂͨ¹ý¸üÕý Windows Ô¶³Ì×ÀÃæ¿Í»§¶Ë´¦ÖÃÏνÓÒªÇóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£ ΢ÈíWindows
CVE-2020-0734 ÑϳÁ Ô¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³ÌÖ´ÐдúÂë·ì϶ µ±Óû§Ïνӵ½¶ñÒâ·þÎñÆ÷ʱ £¬Windows Ô¶³Ì×ÀÃæ¿Í»§¶ËÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÏνӿͻ§¶ËµÄÍÆËã»úÖÐÖ´ÐÐËÁÒâ´úÂë¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ÈôÒªÀûÓô˷ì϶ £¬¹¥»÷Õß±ØÒª½ÚÔì·þÎñÆ÷ £¬¶øºóÓÕµ¼Óû§Ïνӵ½¸Ã·þÎñÆ÷¡£¹¥»÷ÕßÎÞ·¨Ç¿ÆÅ×û§Ïνӵ½¶ñÒâ·þÎñÆ÷ £¬ËûÃDZØÒªÍ¨¹ýÉç»á¹¤³Ì¡¢DNS ²¡¶¾»òʹÓÃÖÐÑëÈË (MITM) ¼¼ÊõÓÕµ¼Óû§ÏνÓ¡£¹¥»÷Õß»¹¿ÉÄÜ·çÏպϷ¨·þÎñÆ÷ £¬ÔÚÆäÉÏÍйܶñÒâ´úÂë £¬²¢ÆÚ´ýÓû§ÏνÓ¡£ ´Ë°²È«¸üÐÂͨ¹ý¸üÕý Windows Ô¶³Ì×ÀÃæ¿Í»§¶Ë´¦ÖÃÏνÓÒªÇóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£ Ô¶³Ì×ÀÃæ¿Í»§¶Ë
CVE-2020-0662 ÑϳÁ WindowsÔ¶³ÌÖ´ÐдúÂë·ì϶ Windows ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ê¹ÓÃÌáÉýµÄÌØÈ¨ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£ ÈôÒªÀûÓô˷ì϶ £¬ÓµÓÐÓòÓû§ÕÊ»§µÄ¹¥»÷ÕßÄܹ»´´½¨¾­ÌØÊâÉè¼ÆµÄÒªÇó £¬´Ó¶øÊ¹ Windows ÀûÓÃÌáÉýµÄÌØÈ¨Ö´ÐÐËÁÒâ´úÂë¡£ ´Ë°²È«¸üз¨Ê½Í¨¹ý¸üÕý Windows ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´Õâ¸ö·ì϶¡£ Windows Hyper-V
CVE-2020-0738 ÑϳÁ Media FoundationÄÚ´æ°Ü»µ·ì϶ µ± Windows ýÌå»ù´¡²»ÕýÈ·µØ´¦ÖÃÄÚ´æÖжÔÏóʱ £¬´æÔÚÄÚ´æ°Ü»µ·ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»×°Ö÷¨Ê½£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ¹¥»÷Õß¿ÉÄÜͨ¹ý¶àÖÖ·½Ê½ÀûÓô˷ì϶ £¬Ô̺¬ÓÕʹÓû§´ò¿ª¾­ÌØÊâÉè¼ÆµÄÎĵµ»òÓÕʹÓû§½Ó¼û¶ñÒâÍøÒ³¡£ ´Ë°²È«¸üÐÂͨ¹ý¸üÕý Windows ýÌå»ù´¡´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½À´½¨¸´´Ë·ì϶¡£ WindowsýÌå
CVE-2020-0729 ÑϳÁ LNKÔ¶³ÌÖ´ÐдúÂë·ì϶ ÈôÊÇ´¦ÖÃÁË .LNK Îļþ £¬Ôò Microsoft Windows ÖдæÔÚÒ»¸öÔ¶³ÌÖ´ÐдúÂë·ì϶ £¬¿ÉÄÜÔÊÐíÔ¶³ÌÖ´ÐдúÂë¡£ ³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜ»á»ñµÃÓë±¾µØÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ÓëÕ¼ÓÐÖÎÀíÓû§È¨ÏÞµÄÓû§Ïà±È £¬ÕÊ»§±»ÅäÖÃΪռÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì¸üÓס£ ¹¥»÷Õß¿ÉÄÜ»áÏòÓû§ÏÔʾÔ̺¬¶ñÒâ .LNK ÎļþºÍ¹ØÁªµÄ¶ñÒâ¶þ½øÔìÎļþµÄ¿ÉÒÆ³ýÇý¶¯Æ÷»òÔ¶³Ì¹²Ïí¡£µ±Óû§ÔÚ Windows ×ÊÔ´ÖÎÀíÆ÷Öдò¿ª´ËÇý¶¯Æ÷£¨»òÔ¶³Ì¹²Ïí£© £¬»ò´ò¿ª¿É·ÖÎö .LNK ÎļþµÄÆäËûÈκÎÀûÓ÷¨Ê½Ê± £¬¶ñÒâ¶þ½øÔìÎļþ»áÔÚÖ¸±êϵͳÉÏÖ´Ðй¥»÷ÕßÑ¡ÔñµÄ´úÂë¡£ ´Ë°²È«¸üз¨Ê½Í¨¹ý¸üÕý´¦Öÿì½Ý·½Ê½ LNK ÒýÓõķ½Ê½À´½¨¸´´Ë·ì϶¡£ Windows Shell



½¨¸´½¨Òé



Ŀǰ £¬Î¢Èí¹Ù·½ÒѾ­°ä²¼²¹¶¡½¨¸´ÁËÉÏÊö·ì϶ £¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½·ì϶ӰÏì £¬ ¾¡¿ì²ÉÈ¡½¨²¹´ëÊ© £¬ÒÔÔ¤·ÀDZÔڵݲȫÍþв¡£ÏëÒª½øÐиüР£¬Ö»Ðèתµ½ÉèÖáú¸üкͰ²È«¡úWindows ¸üСú²é³­¸üР£¬»òÕßÒ²Äܹ»Í¨¹ýÊÖ¶¯½øÐиüС£


²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/zh-cn/security-guidance