΢Èí6Ô²¹¶¡ÈÕÐè¹Ø×¢µÄ¸ßΣÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-06-15Îó²î±àºÅºÍ¼¶±ð
CVE-2018-8248 Ö÷Òª
CVE-2018-8231 ÑÏÖØ ³§ÉÌ×ÔÆÀ£º8.1
CVE-2018-8225 ÑÏÖØ ³§ÉÌ×ÔÆÀ£º8.1
CVE-2018-8267 ÑÏÖØ ³§ÉÌ×ÔÆÀ£º6.4
Îó²î¸ÅÊö
6ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬£¬Î¢ÈíÐû²¼ÁË2018Äê6Ô·ݵÄÔ¶ÈÀýÐÐÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÆä¶à¿î²úÆ·±£´æµÄ122¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£Í¨¸æÖаüÀ¨ÁËMicrosoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8248£©£¬£¬£¬£¬£¬£¬£¬Microsoft Windows HTTPÐÒé¿ÍÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8231£©£¬£¬£¬£¬£¬£¬£¬Windows DNSAPIÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8225£©¼°Microsoft Internet Explorer¾ç±¾ÒýÇæÄÚ´æÆÆËðÎó²î£¨CVE-2018-8267£©¡£¡£¡£¡£¡£¡£¡£
ÀÖ³ÉʹÓÃMicrosoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²îµÄ¹¥»÷Õߣ¬£¬£¬£¬£¬£¬£¬ÄÜÔÚÄ¿½ñÓû§ÇéÐÎÏÂÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬£¬ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíԱȨÏ޵Ǽ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÉõÖÁ¿ÉÒÔÍêÈ«¿ØÖƸÃÓû§µÄϵͳ¡£¡£¡£¡£¡£¡£¡£Microsoft Office 2010 Service Pack 2¡¢Microsoft Office 2013 RT Service Pack 1¡¢Microsoft Office 2013 Service Pack 1¡¢Microsoft Office 2016¡¢Microsoft Office 2016 Click-to-Run (C2R)µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£¡£
ÀÖ³ÉʹÓÃMicrosoft Windows HTTP 2.0ÐÒé¿ÍÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²îµÄ¹¥»÷Õߣ¬£¬£¬£¬£¬£¬£¬¿ÉÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬£¬²¢¿ØÖƸÃÓû§µÄϵͳ¡£¡£¡£¡£¡£¡£¡£Windows 10¡¢Windows 10 Version 1607¡¢Windows 10 Version 1703¡¢Windows 10 Version 1709¡¢Windows 10 Version 1803¡¢Windows Server 2016¡¢Windows Server 2016 (Server Core installation)¡¢Windows Server version 1709 (Server Core Installation)¡¢Windows Server version 1803 (Server Core Installation)µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£¡£
ÀÖ³ÉʹÓÃWindows DNSAPIÔ¶³Ì´úÂëÖ´ÐÐÎó²îµÄ¹¥»÷Õߣ¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÍâµØÏµÍ³ÕÊ»§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬£¬¶ø¹¥»÷ÕßËùÒª×öµÄ¾ÍÊǽ«Ê¹ÓöñÒâDNSЧÀÍÆ÷ÏòÄ¿µÄ·¢ËÍË𻵵ÄDNSÏìÓ¦¡£¡£¡£¡£¡£¡£¡£Windows 7¡¢Windows 8.1¡¢Windows RT 8.1ºÍWindows 10ÒÔ¼°Windows Server 2008¡¢Windows Server 2008 R2¡¢Windows Server 2012¡¢Windows Server 2012 R2¡¢Windows Server 2016¡¢Windows Server°æ±¾1709ºÍ°æ±¾1803µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£¡£
ÀÖ³ÉʹÓÃMicrosoft Internet Explorer¾ç±¾ÒýÇæÄÚ´æÆÆËðÎó²îµÄ¹¥»÷Õߣ¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬£¬£¬£¬£¬£¬£¬ÔòÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£¡£¡£È»ºó¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£¬£¬£¬£¬£¬£¬£¬Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£¬£¬£¬£¬£¬£¬£¬»ò½¨Éè¾ßÓÐÍêÕûÓû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£¡£¡£¡£¡£Windows Server 2012¡¢Windows Server 2016¡¢Windows 10¡¢Windows 7¡¢Windows 8.1¡¢Windows RT 8.1¡¢Windows Server 2008 R2¡¢Windows Server 2012 R2ÒÔ¼°Windows Server 2008µÄInternet Explorer 9 ¡¢Internet Explorer 10ºÍInternet Explorer 11µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£¡£
Îó²îÏÈÈÝ
Microsoft ExcelÊÇÃÀ¹ú΢Èí¹«Ë¾ÎªÊ¹ÓÃWindowsºÍApple Macintosh²Ù×÷ϵͳµÄµçÄÔ±àдµÄÒ»¿îµç×Ó±í¸ñÈí¼þ¡£¡£¡£¡£¡£¡£¡£Microsoft Excel±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ¸ÃÈí¼þδÄÜ׼ȷ´¦Öóͷ£ÄÚ´æÖеŤ¾ß£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÏòÓû§·¢Ë;ÓÉÌØÊâ½á¹¹µÄÎļþ²¢ÓÕʹÓû§·¿ª¸ÃÎļþ£¬£¬£¬£¬£¬£¬£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£
Microsoft WindowsÊÇÃÀ¹ú΢Èí¹«Ë¾Ñз¢µÄÒ»Ì×½ÓÄÉÁËͼÐλ¯Ä£Ê½µÄ²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£WindowsÖеÄHTTPÐÒéÊÇÒ»ÖÖͨѶÐÒ飬£¬£¬£¬£¬£¬£¬¼´³¬Îı¾´«ÊäÐÒé¡£¡£¡£¡£¡£¡£¡£Microsoft Windows HTTPÐÒé±£´æ¿ÍÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚHTTP ÐÒé¿ÍջδÄÜ׼ȷ´¦Öóͷ£ÄÚ´æÖеŤ¾ß£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÏòÄ¿µÄhttp.sysЧÀÍÆ÷·¢Ë;ÓÉÌØÊâ½á¹¹µÄÊý¾Ý°ü£¬£¬£¬£¬£¬£¬£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£
ÔÚ΢Èí±¾ÔÂÐÞ¸´µÄËùÓÐÎó²îÖУ¬£¬£¬£¬£¬£¬£¬±»ÒÔΪ×îÑÏÖØµÄÎó²îÊÇCVE-2018-8225¡£¡£¡£¡£¡£¡£¡£Ëü±»ÐÎòΪһ¸öWindows DNSAPIÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÊÇÓÉÓÚWindows ÓòÃûϵͳ£¨DNS£© DNSAPI.dllÎÞ·¨×¼È·´¦Öóͷ£DNSÏìÓ¦µ¼Öµġ£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÔÚÍâµØÏµÍ³ÕÊ»§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬£¬¶ø¹¥»÷ÕßËùÒª×öµÄ¾ÍÊǽ«Ê¹ÓöñÒâDNSЧÀÍÆ÷ÏòÄ¿µÄ·¢ËÍË𻵵ÄDNSÏìÓ¦¡£¡£¡£¡£¡£¡£¡£
½öÓÐÒ»¸öÎó²îÔÚÐû²¼Ê±±»ÁÐΪ¹ûÕæ£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸ö¾ç±¾ÒýÇæÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬£¬£¬Îó²î±àºÅΪCVE-2018-8267£¬£¬£¬£¬£¬£¬£¬¾ç±¾ÒýÇæÔÚInternet ExplorerÖд¦Öóͷ£ÄÚ´æÖеŤ¾ßµÄ·½·¨Öб£´æµÄÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¡£¡£¡£¡£¡£¡£ÔÚ»ùÓÚWebµÄ¹¥»÷ÇéÐÎÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÍйܾÓÉÌØÖÆµÄÍøÕ¾£¬£¬£¬£¬£¬£¬£¬¸ÃÍøÕ¾Ö¼ÔÚͨ¹ýInternet ExplorerʹÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬È»ºóÓÕʹÓû§Éó²é¸ÃÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔÔÚÍйÜIE·ºÆðÒýÇæµÄÓ¦ÓóÌÐò»òMicrosoft OfficeÎĵµÖÐǶÈë±ê¼ÇΪ¡®Çå¾²³õʼ»¯¡¯µÄActiveX¿Ø¼þ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔʹÓÃÊܵ½ÍþвµÄÍøÕ¾ºÍ½ÓÊÜ»òÍйÜÓû§ÌṩµÄÄÚÈÝ»ò¹ã¸æµÄÍøÕ¾¡£¡£¡£¡£¡£¡£¡£ÕâÐ©ÍøÕ¾¿ÉÄܰüÀ¨¿ÉʹÓôËÎó²îµÄÌØÖÆÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺
ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬Î¢Èí¹Ù·½ÒѾÐû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ï죬£¬£¬£¬£¬£¬£¬¾¡¿ì½ÓÄÉÐÞ²¹²½·¥£¬£¬£¬£¬£¬£¬£¬ÒÔ×èֹDZÔÚµÄÇå¾²Íþв¡£¡£¡£¡£¡£¡£¡£ÏëÒª¾ÙÐиüУ¬£¬£¬£¬£¬£¬£¬Ö»Ðèתµ½ÉèÖáú¸üкÍÇå¾²¡úWindows¸üСú¼ì²é¸üУ¬£¬£¬£¬£¬£¬£¬»òÕßÒ²¿ÉÒÔͨ¹ýÊÖ¶¯¾ÙÐиüС£¡£¡£¡£¡£¡£¡£
ÏÖÔÚÒѾ·¢Ã÷ÓÐʹÓÃCVE-2018-8248Îó²îµÄľÂí£¬£¬£¬£¬£¬£¬£¬Ïà¹ØÁ´½Ó£ºhttps://www.symantec.com/security-center/writeup/2018-061314-3210-99¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó£º
https://portal.msrc.microsoft.com/en-us/security-guidance/acknowledgments