΢Èí6Ô²¹¶¡ÈÕÐè¹Ø×¢µÄ¸ßΣÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-06-15

Îó²î±àºÅºÍ¼¶±ð


CVE-2018-8248  Ö÷Òª


CVE-2018-8231  ÑÏÖØ  ³§ÉÌ×ÔÆÀ£º8.1


CVE-2018-8225  ÑÏÖØ  ³§ÉÌ×ÔÆÀ£º8.1


CVE-2018-8267  ÑÏÖØ  ³§ÉÌ×ÔÆÀ£º6.4


Îó²î¸ÅÊö


6ÔÂ12ÈÕ£¬£¬£¬£¬£¬ £¬£¬Î¢ÈíÐû²¼ÁË2018Äê6Ô·ݵÄÔ¶ÈÀýÐÐÇ徲ͨ¸æ£¬£¬£¬£¬£¬ £¬£¬ÐÞ¸´ÁËÆä¶à¿î²úÆ·±£´æµÄ122¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£Í¨¸æÖаüÀ¨ÁËMicrosoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8248£©£¬£¬£¬£¬£¬ £¬£¬Microsoft Windows HTTPЭÒé¿ÍÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8231£©£¬£¬£¬£¬£¬ £¬£¬Windows DNSAPIÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8225£©¼°Microsoft  Internet Explorer¾ç±¾ÒýÇæÄÚ´æÆÆËðÎó²î£¨CVE-2018-8267£©¡£¡£¡£¡£¡£¡£¡£


ÀÖ³ÉʹÓÃMicrosoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²îµÄ¹¥»÷Õߣ¬£¬£¬£¬£¬ £¬£¬ÄÜÔÚÄ¿½ñÓû§ÇéÐÎÏÂÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬ £¬£¬ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíԱȨÏ޵Ǽ£¬£¬£¬£¬£¬ £¬£¬¹¥»÷ÕßÉõÖÁ¿ÉÒÔÍêÈ«¿ØÖƸÃÓû§µÄϵͳ¡£¡£¡£¡£¡£¡£¡£Microsoft Office 2010 Service Pack 2¡¢Microsoft Office 2013 RT Service Pack 1¡¢Microsoft Office 2013 Service Pack 1¡¢Microsoft Office 2016¡¢Microsoft Office 2016 Click-to-Run (C2R)µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£¡£

 

ÀÖ³ÉʹÓÃMicrosoft Windows HTTP 2.0ЭÒé¿ÍÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²îµÄ¹¥»÷Õߣ¬£¬£¬£¬£¬ £¬£¬¿ÉÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬ £¬£¬²¢¿ØÖƸÃÓû§µÄϵͳ¡£¡£¡£¡£¡£¡£¡£Windows 10¡¢Windows 10 Version 1607¡¢Windows 10 Version 1703¡¢Windows 10 Version 1709¡¢Windows 10 Version 1803¡¢Windows Server 2016¡¢Windows Server 2016 (Server Core installation)¡¢Windows Server version 1709 (Server Core Installation)¡¢Windows Server version 1803 (Server Core Installation)µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£¡£

 

ÀÖ³ÉʹÓÃWindows DNSAPIÔ¶³Ì´úÂëÖ´ÐÐÎó²îµÄ¹¥»÷Õߣ¬£¬£¬£¬£¬ £¬£¬¿ÉÒÔÔÚÍâµØÏµÍ³ÕÊ»§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂ룬£¬£¬£¬£¬ £¬£¬¶ø¹¥»÷ÕßËùÒª×öµÄ¾ÍÊǽ«Ê¹ÓöñÒâDNSЧÀÍÆ÷ÏòÄ¿µÄ·¢ËÍË𻵵ÄDNSÏìÓ¦¡£¡£¡£¡£¡£¡£¡£Windows 7¡¢Windows 8.1¡¢Windows RT 8.1ºÍWindows 10ÒÔ¼°Windows Server 2008¡¢Windows Server 2008 R2¡¢Windows Server 2012¡¢Windows Server 2012 R2¡¢Windows Server 2016¡¢Windows Server°æ±¾1709ºÍ°æ±¾1803µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£¡£


ÀÖ³ÉʹÓÃMicrosoft  Internet Explorer¾ç±¾ÒýÇæÄÚ´æÆÆËðÎó²îµÄ¹¥»÷Õߣ¬£¬£¬£¬£¬ £¬£¬¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬£¬£¬£¬£¬ £¬£¬ÔòÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£¡£¡£È»ºó¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£¬£¬£¬£¬£¬ £¬£¬Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£¬£¬£¬£¬£¬ £¬£¬»ò½¨Éè¾ßÓÐÍêÕûÓû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£¡£¡£¡£¡£Windows Server 2012¡¢Windows Server 2016¡¢Windows 10¡¢Windows 7¡¢Windows 8.1¡¢Windows RT 8.1¡¢Windows Server 2008 R2¡¢Windows Server 2012 R2ÒÔ¼°Windows Server 2008µÄInternet Explorer 9 ¡¢Internet Explorer 10ºÍInternet Explorer 11µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£¡£


Îó²îÏÈÈÝ


Microsoft ExcelÊÇÃÀ¹ú΢Èí¹«Ë¾ÎªÊ¹ÓÃWindowsºÍApple Macintosh²Ù×÷ϵͳµÄµçÄÔ±àдµÄÒ»¿îµç×Ó±í¸ñÈí¼þ¡£¡£¡£¡£¡£¡£¡£Microsoft Excel±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬ £¬£¬¸ÃÎó²îÔ´ÓÚ¸ÃÈí¼þδÄÜ׼ȷ´¦Öóͷ£ÄÚ´æÖеŤ¾ß£¬£¬£¬£¬£¬ £¬£¬¹¥»÷Õß¿Éͨ¹ýÏòÓû§·¢Ë;­ÓÉÌØÊâ½á¹¹µÄÎļþ²¢ÓÕʹÓû§·­¿ª¸ÃÎļþ£¬£¬£¬£¬£¬ £¬£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£


Microsoft WindowsÊÇÃÀ¹ú΢Èí¹«Ë¾Ñз¢µÄÒ»Ì×½ÓÄÉÁËͼÐλ¯Ä£Ê½µÄ²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£WindowsÖеÄHTTPЭÒéÊÇÒ»ÖÖͨѶЭÒ飬£¬£¬£¬£¬ £¬£¬¼´³¬Îı¾´«ÊäЭÒé¡£¡£¡£¡£¡£¡£¡£Microsoft Windows HTTPЭÒé±£´æ¿ÍÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚHTTP ЭÒé¿ÍջδÄÜ׼ȷ´¦Öóͷ£ÄÚ´æÖеŤ¾ß£¬£¬£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔÏòÄ¿µÄhttp.sysЧÀÍÆ÷·¢Ë;­ÓÉÌØÊâ½á¹¹µÄÊý¾Ý°ü£¬£¬£¬£¬£¬ £¬£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£


ÔÚ΢Èí±¾ÔÂÐÞ¸´µÄËùÓÐÎó²îÖУ¬£¬£¬£¬£¬ £¬£¬±»ÒÔΪ×îÑÏÖØµÄÎó²îÊÇCVE-2018-8225¡£¡£¡£¡£¡£¡£¡£Ëü±»ÐÎòΪһ¸öWindows DNSAPIÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬ £¬£¬¸ÃÎó²îÊÇÓÉÓÚWindows ÓòÃûϵͳ£¨DNS£© DNSAPI.dllÎÞ·¨×¼È·´¦Öóͷ£DNSÏìÓ¦µ¼Öµġ£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÔÚÍâµØÏµÍ³ÕÊ»§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂ룬£¬£¬£¬£¬ £¬£¬¶ø¹¥»÷ÕßËùÒª×öµÄ¾ÍÊǽ«Ê¹ÓöñÒâDNSЧÀÍÆ÷ÏòÄ¿µÄ·¢ËÍË𻵵ÄDNSÏìÓ¦¡£¡£¡£¡£¡£¡£¡£


½öÓÐÒ»¸öÎó²îÔÚÐû²¼Ê±±»ÁÐΪ¹ûÕæ£¬£¬£¬£¬£¬ £¬£¬ÕâÊÇÒ»¸ö¾ç±¾ÒýÇæÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬ £¬£¬Îó²î±àºÅΪCVE-2018-8267£¬£¬£¬£¬£¬ £¬£¬¾ç±¾ÒýÇæÔÚInternet ExplorerÖд¦Öóͷ£ÄÚ´æÖеŤ¾ßµÄ·½·¨Öб£´æµÄÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¡£¡£¡£¡£¡£¡£ÔÚ»ùÓÚWebµÄ¹¥»÷ÇéÐÎÖУ¬£¬£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÄÜÍйܾ­ÓÉÌØÖÆµÄÍøÕ¾£¬£¬£¬£¬£¬ £¬£¬¸ÃÍøÕ¾Ö¼ÔÚͨ¹ýInternet ExplorerʹÓôËÎó²î£¬£¬£¬£¬£¬ £¬£¬È»ºóÓÕʹÓû§Éó²é¸ÃÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔÔÚÍйÜIE·ºÆðÒýÇæµÄÓ¦ÓóÌÐò»òMicrosoft OfficeÎĵµÖÐǶÈë±ê¼ÇΪ¡®Çå¾²³õʼ»¯¡¯µÄActiveX¿Ø¼þ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔʹÓÃÊܵ½ÍþвµÄÍøÕ¾ºÍ½ÓÊÜ»òÍйÜÓû§ÌṩµÄÄÚÈÝ»ò¹ã¸æµÄÍøÕ¾¡£¡£¡£¡£¡£¡£¡£ÕâÐ©ÍøÕ¾¿ÉÄܰüÀ¨¿ÉʹÓôËÎó²îµÄÌØÖÆÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Ò飺


ÏÖÔÚ£¬£¬£¬£¬£¬ £¬£¬Î¢Èí¹Ù·½ÒѾ­Ðû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬£¬£¬ £¬£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ï죬£¬£¬£¬£¬ £¬£¬¾¡¿ì½ÓÄÉÐÞ²¹²½·¥£¬£¬£¬£¬£¬ £¬£¬ÒÔ×èֹDZÔÚµÄÇå¾²Íþв¡£¡£¡£¡£¡£¡£¡£ÏëÒª¾ÙÐиüУ¬£¬£¬£¬£¬ £¬£¬Ö»Ðèתµ½ÉèÖáú¸üкÍÇå¾²¡úWindows¸üСú¼ì²é¸üУ¬£¬£¬£¬£¬ £¬£¬»òÕßÒ²¿ÉÒÔͨ¹ýÊÖ¶¯¾ÙÐиüС£¡£¡£¡£¡£¡£¡£

ÏÖÔÚÒѾ­·¢Ã÷ÓÐʹÓÃCVE-2018-8248Îó²îµÄľÂí£¬£¬£¬£¬£¬ £¬£¬Ïà¹ØÁ´½Ó£ºhttps://www.symantec.com/security-center/writeup/2018-061314-3210-99¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó£º


https://portal.msrc.microsoft.com/en-us/security-guidance/acknowledgments