Microsoft | 12Ô¶à¸ö²úÆ··ì϶¹«¸æ

°ä²¼¹¦·ò 2020-12-09

0x00 ·ì϶¸ÅÊö

2020Äê12ÔÂ08ÈÕ£¬Microsoft°ä²¼ÁË12Ô·ݵݲȫ¸üУ¬±¾´Î°ä²¼µÄ°²È«·ì϶¹²¼Æ58¸ö£¬Ïà½ÏÓÚÉÏÔÂÏ÷¼õÁË54¸ö¡£ÆäÖÐÓÐ9¸ö·ì϶ÆÀ¼¶ÎªÑϳÁ£¬46¸ö·ì϶ÆÀ¼¶Îª¸ßΣ¡£ÔÚÕâ´Î°ä²¼µÄ°²È«·ì϶ÖУ¬ÆäÖÐÓÐ23¸ö·ì϶ΪԶ³Ì´úÂëÖ´Ðзì϶£¬14¸ö·ì϶ΪȨÏÞÌáÉý·ì϶£¬9¸ö·ì϶ΪÐÅϢй¶·ì϶¡£

 

0x01 ·ì϶ÏêÇé

 

image.png

΢Èí±¾´Î°ä²¼µÄ°²È«¸üÐÂÖУ¬ÊÜÓ°ÏìµÄ²úÆ·ºÍ×é¼þÔ̺¬£ºMicrosoft Windows¡¢Microsoft Edge (EdgeHTML-based)¡¢Microsoft Edge for Android¡¢ChakraCore¡¢Microsoft Office and Microsoft Office Services and Web Apps¡¢Microsoft Exchange Server¡¢Azure DevOps¡¢Microsoft Dynamics¡¢Visual Studio¡¢Azure SDKºÍAzure Sphere¡£

±¾´Î°ä²¼µÄÆëÈ«·ì϶ÁбíÈçÏ£º

CVE-ID

·ìϼûû³Æ

ÑϳÁˮƽ

CVE-2020-17131

Chakra¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶

ÑϳÁ

CVE-2020-17095

Hyper-VÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2020-17152

Microsoft Dynamics 365 for Finance and Operations´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2020-17158

Microsoft Dynamics 365 for Finance and Operations´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2020-17117

Microsoft ExchangeÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2020-17132

Microsoft ExchangeÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2020-17142

Microsoft ExchangeÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2020-17118

Microsoft SharePointÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2020-17121

Microsoft SharePointÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2020-17145

Azure DevOps·þÎñÆ÷ºÍTeam   Foundation ServicesºýŪ·ì϶

¸ßΣ

CVE-2020-17135

Azure DevOps·þÎñÆ÷ºýŪ·ì϶

¸ßΣ

CVE-2020-17002

ÓÃÓÚC°²È«Ö°ÄÜÈÆ¹ýµÄAzure SDK

¸ßΣ

CVE-2020-17160

Azure Sphere°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2020-17137

DirectXͼÐÎÄÚºËȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-17147

Dynamics CRM Webclient¿çÕ¾µã¾ç±¾·ì϶

¸ßΣ

CVE-2020-16996

Kerberos°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2020-17133

Microsoft Dynamics Business Central / NAVÐÅÏ¢Åû¶

¸ßΣ

CVE-2020-17126

Microsoft ExcelÐÅϢй¶·ì϶

¸ßΣ

CVE-2020-17122

Microsoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17123

Microsoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17125

Microsoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17127

Microsoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17128

Microsoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17129

Microsoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17130

Microsoft Excel°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2020-17143

Microsoft ExchangeÐÅϢй¶·ì϶

¸ßΣ

CVE-2020-17141

Microsoft ExchangeÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17144

Microsoft ExchangeÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17119

Microsoft OutlookÐÅϢй¶·ì϶

¸ßΣ

CVE-2020-17124

Microsoft PowerPointÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17089

Microsoft SharePointȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-17120

Microsoft SharePointÐÅϢй¶·ì϶

¸ßΣ

CVE-2020-17159

Visual Studio Code JavaÀ©´ó°üÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17150

Visual Studio´úÂëÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17148

Visual Studio CodeÔ¶³Ì¿ª·¢À©´óÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17156

Visual StudioÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-16958

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-16959

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-16960

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-16961

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-16962

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-16963

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-16964

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-17103

WindowsÔÆÎļþÓ×ÐÍɸѡÆ÷Çý¶¯·¨Ê½È¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-17134

WindowsÔÆÎļþÓ×ÐÍɸѡÆ÷Çý¶¯·¨Ê½È¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-17136

WindowsÔÆÎļþÓ×ÐÍɸѡÆ÷Çý¶¯·¨Ê½È¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-17097

Windows Digital Media ReceiverȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-17094

WindowsÃýÎó»ã±¨ÐÅϢй¶·ì϶

¸ßΣ

CVE-2020-17138

WindowsÃýÎó»ã±¨ÐÅϢй¶·ì϶

¸ßΣ

CVE-2020-17098

Windows GDI +ÐÅϢй¶·ì϶

¸ßΣ

CVE-2020-17099

WindowsËø¶¨ÆÁÄ»°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2020-17092

WindowsÍøÂçÏνӷþÎñȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-17096

Windows NTFSÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17139

Windows¸²¸ÇɸѡÆ÷°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2020-17140

Windows SMBÐÅϢй¶·ì϶

¸ßΣ

CVE-2020-16971

ºÏÓÃÓÚJavaµÄAzure SDK°²È«Ö°ÄÜÈÆ¹ý·ì϶

ÖÐΣ

CVE-2020-17153

Android EdgeµÄMicrosoft   Edge·ì϶

ÖÐΣ

CVE-2020-17115

Microsoft SharePointºýŪ·ì϶

ÖÐΣ

 

²¿ÃÅÑϳÁ·ì϶ÈçÏ£º

Hyper-VÔ¶³Ì´úÂëÖ´Ðзì϶

Hyper-VÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-17095£©£¬ÆäCVSSÆÀ·Ö8.5¡£¹¥»÷ÕßÄܹ»Í¨¹ý´Ë·ì϶½«Hyper-V Guest OSȨÏÞÌáÉýµ½Hyper-V HostȨÏÞ£¬×îÖÕÔ¶³ÌÖ´ÐдúÂë¡£

Windows NTFSÔ¶³Ì´úÂëÖ´Ðзì϶

Windows NTFSÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-17096£©£¬ÆäCVSSÆÀ·Ö7.5¡£ÓµÓÐSMBv2½Ó¼ûȨÏ޵Ĺ¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâÒªÇóÀ´ÀûÓô˷ì϶£¬×îÖÕÄܹ»ÔÚÖ¸±êϵͳÉÏÔ¶³ÌÖ´ÐдúÂë¡£

Microsoft SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶

MicrosoftÔÚSharePointÖн¨¸´ÁË2¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-17121ºÍCVE-2020-17118£©¡£ÆäÖУ¬CVE-2020-17118 CVSSÆÀ·Ö8.1£¬CVE-2020-17121 CVSSÆÀ·Ö8.8¡£

¹¥»÷Õß¿ÉÄÜÀûÓÃCVE-2020-17121»ñµÃ½Ó¼ûȨÏÞ£¬ÒÔ´´½¨Õ¾µã²¢ÔÚkernelÄÚÔ¶³ÌÖ´ÐдúÂë¡£

Microsoft ExchangeÔ¶³Ì´úÂëÖ´Ðзì϶

Microsoft½¨¸´ÁËExchangeÖеÄ5¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-17141¡¢CVE-2020-17142¡¢CVE-2020-17144¡¢ CVE-2020-17117¡¢CVE-2020-17132£©¡£

ÆäÖУ¬CVE-2020-17132ÊǶÔcmdlet²ÎÊýµÄÑéÖ¤²»ÕýÈ·Ôì³ÉµÄ£¬ÆäCVSSÆÀ·Ö9.1¡£Microsoft²¢Î´ÔÚ´Ë´¦Ìṩ¹¥»÷³¡¾°£¬µ«Ö¸³ö¹¥»÷Õß±ØÒª½øÐÐÉí·ÝÑéÖ¤£¬ÇҸ÷ì϶µÄÀûÓø´ÔÓÐԵ͡£ÈôÊǹ¥»÷ÕßÈëÇÖÁËijÈ˵ÄÓÊÏ䣬ÔòÄܹ»½ÚÔìÕû¸öExchange·þÎñÆ÷¡£

 

0x02 ´ëÖý¨Òé

ĿǰMicrosoftÒѾ­°ä²¼Á˰²È«¸üУ¬½¨ÒéʵʱװÖÃÓйز¹¶¡¡£

 

£¨Ò»£© Windows update¸üÐÂ

 

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС±£¬ÆÚ´ýϵͳ½«×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüС£

4¡¢³ÁÆôÍÆËã»ú£¬×°ÖøüÐÂϵͳ³ÁÐÂÆô¶¯ºó£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£

 

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

΢Èí¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

ÏÂÔØµØÖ·£º

https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec

https://threatpost.com/microsoft-patch-tuesday-holidays/162041/

https://www.darkreading.com/threat-intelligence/microsoft-fixes-58-cves-for-december-patch-tuesday/d/d-id/1339651?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple

 

0x04 ¹¦·òÏß

2020-12-08  Microsoft°ä²¼°²È«¸üÐÂ

2020-12-09  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

 

 

 

image.png