΢Èí¶à¸öÇå¾²Îó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-02-14Îó²î¸ÅÊö
2ÔÂ12ÈÕ£¬£¬£¬£¬Î¢ÈíÐû²¼ÁË2019Äê2Ô·ݵÄÔ¶ÈÀýÐÐÇ徲ͨ¸æ£¬£¬£¬£¬ÐÞ¸´ÁËÆä¶à¿î²úÆ·±£´æµÄ242¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨£ºWindows 10 1809 & Windows Server2019£¨28¸ö£©¡¢Windows 10 1803 & WindowsServer v1803£¨29¸ö£©¡¢Windows 10 1709 & WindowsServer v1709£¨30¸ö£©¡¢Windows RT 8.1£¨24¸ö£©¡¢Windows Server 2012£¨25¸ö£©¡¢Windows 8.1 & Server 2012 R2£¨25¸ö£©¡¢Windows Server 2008£¨24¸ö£©¡¢Windows 7 and Windows Server 2008R2£¨24¸ö£©¡¢Internet Explorer£¨3¸ö£©¡¢Microsoft Edge£¨21¸ö£©ºÍOffice£¨9¸ö£©¡£¡£¡£¡£¡£¡£¡£
ʹÓÃÉÏÊöÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ»ñÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬ÌáÉýȨÏÞ£¬£¬£¬£¬ÓÕÆ£¬£¬£¬£¬ÈƹýÇå¾²¹¦Ð§ÏÞÖÆ£¬£¬£¬£¬Ö´ÐÐÔ¶³Ì´úÂ룬£¬£¬£¬»ò¾ÙÐоܾøÐ§À͹¥»÷µÈ¡£¡£¡£¡£¡£¡£¡£ÌáÐÑ¿í´óMicrosoftÓû§¾¡¿ìÏÂÔØ²¹¶¡¸üУ¬£¬£¬£¬×èÖ¹Òý·¢Îó²îÏà¹ØµÄÍøÂçÇå¾²ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£
CVE񅧏 |
ͨ¸æÎÊÌâºÍÕªÒª |
×î¸ßÑÏÖØÆ·¼¶ºÍÎó²îÓ°Ïì |
ÊÜÓ°ÏìµÄÈí¼þ |
CVE-2019-0630 |
Microsoft Windows SMB ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î Microsoft Server Message Block 2.0£¨smbv2£©Ð§ÀÍÆ÷´¦Öóͷ£Ä³Ð©ÇëÇóʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£ÎªÁËʹÓøÃÎó²î£¬£¬£¬£¬¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÏòÄ¿µÄsmbv2ЧÀÍÆ÷·¢ËÍÈ«ÐÄÉè¼ÆµÄÊý¾Ý°ü¡£¡£¡£¡£¡£¡£¡£ |
Ö÷Òª Ô¶³ÌÖ´ÐдúÂë |
Windows Server 2008 R2 Windows Server 2012 R2 Windows Server 2008 Windows Server 2012 Windows Server 2016 Windows Server 2019 Server, version 1709 Server, version 1803 Windows 8.1 Windows 10 Windows 7 |
CVE-2019-0626 |
Microsoft Windows DHCP ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î µ±¹¥»÷ÕßÏòDHCPЧÀÍÆ÷·¢ËÍÈ«ÐÄÉè¼ÆµÄÊý¾Ý°üʱ£¬£¬£¬£¬Windows Server DHCPЧÀÍÖб£´æÄÚ´æÆÆËðÎó²î¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚDHCPЧÀÍÆ÷ÉÏÔËÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£ |
ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë |
Windows Server 2008 R2 Windows Server 2012 R2 Windows Server 2008 Windows Server 2012 Windows Server 2016 Windows Server 2019 Server, version 1709 Server, version 1803 Windows 8.1 Windows 10 Windows 7 |
CVE-2019-0662 |
Microsoft Windows GDI+ ×é¼þÔ¶³Ì´úÂëÖ´ÐÐÎó²î ¹¥»÷Õß¿ÉÒÔͨ¹ý¶àÖÖ·½·¨Ê¹ÓøÃÎó²î£ºÔÚ»ùÓÚWebµÄ¹¥»÷³¡¾°ÖУ¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÍйÜÒ»¸öרÃÅÉè¼ÆÓÃÓÚʹÓøÃÎó²îµÄÍøÕ¾£¬£¬£¬£¬È»ºó˵·þÓû§Éó²é¸ÃÍøÕ¾¡£¡£¡£¡£¡£¡£¡£ÔÚÎļþ¹²Ïí¹¥»÷³¡¾°ÖУ¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÌṩרÃÅÉè¼ÆµÄÎĵµÎļþ£¬£¬£¬£¬¸ÃÎļþÖ¼ÔÚʹÓÃÎó²î£¬£¬£¬£¬È»ºó˵·þÓû§·¿ªÎĵµÎļþ¡£¡£¡£¡£¡£¡£¡£ |
ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë |
Windows Server 2008 R2 Windows Server 2012 R2 Windows Server 2008 Windows Server 2012 Windows Server 2016 Windows Server 2019 Server, version 1709 Server, version 1803 Windows 8.1 Windows 10 Windows 7 |
CVE-2019-0625 |
Microsoft Windows JetÊý¾Ý¿âÒýÇæÔ¶³Ì´úÂëÖ´ÐÐÎó²î µ±Windows JetÊý¾Ý¿âÒýÇæÎ´ÄÜ׼ȷµØ´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ£¬£¬£¬£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÊܺ¦ÕßϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÓÕʹÊܺ¦Õß·¿ªÈ«ÐÄÌåÀýµÄÎļþÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£ |
Ö÷Òª Ô¶³ÌÖ´ÐдúÂë |
Windows Server 2008 R2 Windows Server 2012 R2 Windows Server 2008 Windows Server 2012 Windows Server 2016 Windows Server 2019 Server, version 1709 Server, version 1803 Windows 8.1 Windows 10 Windows 7 |
CVE-2019-0636 |
Microsoft WindowsÍâµØÐÅϢй¶Îó²î µ±Windows²»×¼È·µØ¹ûÕæÎļþÐÅϢʱ£¬£¬£¬£¬±£´æÐÅÏ¢Îó²î¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²î¿Éʹ¹¥»÷Õß¶ÁÈ¡´ÅÅÌÉÏÎļþµÄÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£ÒªÊ¹ÓøÃÎó²î£¬£¬£¬£¬¹¥»÷Õß±ØÐèµÇ¼ÊÜÓ°ÏìµÄϵͳ²¢ÔËÐÐרÃÅÉè¼ÆµÄÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¡£¡£¸üÐÂͨ¹ý¸ü¸ÄWindows¹ûÕæÎļþÐÅÏ¢µÄ·½·¨À´½â¾ö¸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£ |
Ö÷Òª ÐÅϢй¶ |
Windows Server 2008 R2 Windows Server 2012 R2 Windows Server 2008 Windows Server 2012 Windows Server 2016 Windows Server 2019 Server, version 1709 Server, version 1803 Windows 8.1 Windows 10 Windows 7 |
CVE-2019-0606 |
Microsoft Internet ExplorerÔ¶³ÌÄÚ´æÆÆËðÎó²î ¹¥»÷Õß¿ÉÒÔÍйÜÒ»¸öÈ«ÐÄÉè¼ÆµÄÍøÕ¾£¬£¬£¬£¬¸ÃÍøÕ¾Ö¼ÔÚͨ¹ýÊÜÓ°ÏìµÄMicrosoftä¯ÀÀÆ÷ʹÓøÃÎó²î£¬£¬£¬£¬È»ºó˵·þÓû§Éó²é¸ÃÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔͨ¹ýÌí¼Ó¿ÉʹÓøÃÎó²îµÄÈ«ÐÄÉè¼ÆµÄÄÚÈÝ£¬£¬£¬£¬Ê¹ÓÃÊܵ½¹¥»÷µÄÍøÕ¾»ò½ÓÊÜ»òËÞÖ÷Óû§ÌṩµÄÄÚÈÝ»ò¹ã¸æµÄÍøÕ¾¡£¡£¡£¡£¡£¡£¡£ |
ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë |
Internet Explorer 11 |
CVE-2019-0607 |
Microsoft Edge Chakra Scripting EngineÔ¶³ÌÄÚ´æÆÆËðÎó²î ¹¥»÷Õß¿ÉÒÔÍйÜÒ»¸öÈ«ÐÄÉè¼ÆµÄÍøÕ¾£¬£¬£¬£¬¸ÃÍøÕ¾Ö¼ÔÚͨ¹ýÊÜÓ°ÏìµÄMicrosoftä¯ÀÀÆ÷ʹÓøÃÎó²î£¬£¬£¬£¬È»ºó˵·þÓû§Éó²é¸ÃÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔͨ¹ýÌí¼Ó¿ÉʹÓøÃÎó²îµÄÈ«ÐÄÉè¼ÆµÄÄÚÈÝ£¬£¬£¬£¬Ê¹ÓÃÊܵ½¹¥»÷µÄÍøÕ¾»ò½ÓÊÜ»òËÞÖ÷Óû§ÌṩµÄÄÚÈÝ»ò¹ã¸æµÄÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔÔÚ³ÐÔØä¯ÀÀÆ÷·ºÆðÒýÇæµÄÓ¦ÓóÌÐò»òOfficeÎĵµÖÐǶÈë±ê¼ÇΪ¡°³õʼ»¯Çå¾²¡±µÄActiveX¿Ø¼þ¡£¡£¡£¡£¡£¡£¡£ |
ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë |
Microsoft Edge ChakraCore |
CVE-2019-0594 |
Microsoft SharePoint ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î µ±Èí¼þÎÞ·¨¼ì²éÓ¦ÓóÌÐò°üµÄÔ´±ê¼Çʱ£¬£¬£¬£¬Microsoft SharePointÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔËÐÐSharePointÓ¦ÓóÌÐò³ØºÍSharePointЧÀÍÆ÷³¡ÕÊ»§ÉÏÏÂÎÄÖеÄí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£Ê¹ÓôËÎó²îÐèÒªÓû§½«È«ÐÄÉè¼ÆµÄSharePointÓ¦ÓóÌÐò°üÉÏÔØµ½ÊÜÓ°ÏìµÄSharePoint°æ±¾¡£¡£¡£¡£¡£¡£¡£ |
ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë |
SharePoint Server 2010 SharePoint Foundation 2013 SharePoint Enterprise Server 2016 SharePoint Server 2019 |
CVE-2019-0671 |
Microsoft Office Access Connectivity EngineÔ¶³Ì´úÂëÖ´ÐÐÎó²î µ±Microsoft Office AccessÅþÁ¬ÒýÇæÎ´ÄÜ׼ȷµØ´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ£¬£¬£¬£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÊܺ¦ÕßϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÓÕʹÊܺ¦Õß·¿ªÈ«ÐÄÌåÀýµÄÎļþÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£ |
Ö÷Òª Ô¶³ÌÖ´ÐдúÂë |
Office 2010/2013/2016/2019 Office 365 ProPlus |
CVE-2019-0676 |
Internet Explorer ÐÅÏ¢×ß©Îó²îµ± Internet Explorer ²»×¼È·µØ´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ£¬£¬£¬£¬±£´æÐÅÏ¢×ß©Îó²î¡£¡£¡£¡£¡£¡£¡£ ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ²âÊÔÅÌÉÏÊÇ·ñ±£´æÎļþ¡£¡£¡£¡£¡£¡£¡£ÈôÒªÈù¥»÷Àֳɣ¬£¬£¬£¬¹¥»÷Õß±ØÐèÓÕʹÓû§·¿ª¶ñÒâÍøÕ¾¡£¡£¡£¡£¡£¡£¡£ ´ËÇå¾²¸üÐÂͨ¹ý¸ü¸Ä Internet Explorer ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£¡£¡£¡£¡£¡£¡£ |
Ö÷Òª ÐÅϢй¶ |
Internet Explorer 11 |
CVE-2019-0686 |
Microsoft Exchange Server ÌØÈ¨ÌáÉýÎó²îMicrosoft Exchange Server Öб£´æÌØÈ¨ÌáÉýÎó²î¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʵÑéÄ£Äâ Exchange ЧÀÍÆ÷µÄÆäËûÈκÎÓû§¡£¡£¡£¡£¡£¡£¡£ ΪÁËʹÓôËÎó²î£¬£¬£¬£¬¹¥»÷ÕßÐèÒªÖ´ÐÐÖÐÐÄÈ˹¥»÷£¬£¬£¬£¬ÒÔ½«Éí·ÝÑéÖ¤ÇëÇóת·¢µ½ Microsoft Exchange Server£¬£¬£¬£¬½ø¶øÔÊÐíÄ£ÄâÆäËû Exchange Óû§¡£¡£¡£¡£¡£¡£¡£ ΪÐÞ¸´Õâ¸öÎó²î£¬£¬£¬£¬Ó¦½ç˵ EWSMaxSubscriptions µÄ Throttling Policy ²¢ÔÚÊýֵΪ 0 µÄÌõ¼þÏÂÓ¦ÓÃÓڽṹ¡£¡£¡£¡£¡£¡£¡£ÕâÑù»á±ÜÃâ Exchange ЧÀÍÆ÷·¢ËÍ EWSÐÂÎÅ£¬£¬£¬£¬²¢±ÜÃâÒÀÀµ EWS ֪ͨµÄÓû§¶ËÓ¦ÓóÌÐòµÄÕý³£ÔËÐС£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìÓ¦ÓõÄʾÀý°üÀ¨ Mac °æ Outlook¡¢ÉÌÎñ°æ Skype¡¢ÒÀÀµÍ¨ÖªµÄ LOB Ó¦Ó㬣¬£¬£¬ÒÔ¼°Ò»Ð© iOS ±¾»úµÄÓʼþÓû§¶Ë¡£¡£¡£¡£¡£¡£¡£ |
Ö÷Òª ÌØÈ¨ÌáÉý |
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 26 Microsoft Exchange Server 2013 Cumulative Update 22 Microsoft Exchange Server 2016 Cumulative Update 12 Microsoft Exchange Server 2019 Cumulative Update 1 |
CVE-2019-0540 |
Microsoft Office Çå¾²¹¦Ð§ÈƹýÎó²îµ± Microsoft Office ²»ÑéÖ¤ URL ʱ£¬£¬£¬£¬±£´æÇå¾²¹¦Ð§ÈƹýÎó²î¡£¡£¡£¡£¡£¡£¡£ ¹¥»÷Õß¿ÉÒÔ·¢ËÍÕë¶ÔÊܺ¦ÕßÌØÊâÉè¼ÆµÄÎļþ£¬£¬£¬£¬Õâ¸öÎļþÄܹ»ÓÕʹÊܺ¦ÕßÊäÈëÆ¾Ö¤¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÄÜÖ´Ðд¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£¡£ ´Ë¸üÐÂͨ¹ýÈ·±£ Microsoft Office ׼ȷÑéÖ¤ URL À´ÐÞ¸´´ËÎó²î¡£¡£¡£¡£¡£¡£¡£ |
Ö÷Òª ÐÅϢй¶ |
Internet Explorer 11 |
CVE-2019-0591 |
¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î¾ç±¾ÒýÇæÔÚ Microsoft Edge Öд¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨Öб£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷Õß¿ÉÒÔÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂëµÄ·½·¨Ëð»µÄÚ´æ¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß±ã¿É¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉËæºó×°ÖóÌÐò£»£»£»Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»£»£»»òÕß½¨ÉèÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£¡£¡£¡£¡£ ÔÚ»ùÓÚ Web µÄ¹¥»÷ÇéÐÎÖУ¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÓµÓÐÒ»¸öÖ¼ÔÚͨ¹ý Microsoft Edge ʹÓôËÎó²îµÄ¾ÌØÊâÉè¼ÆµÄÍøÕ¾£¬£¬£¬£¬È»ºóÓÕʹÓû§Éó²é¸ÃÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÄÜʹÓÃÔâµ½ÈëÇÖµÄÍøÕ¾ÒÔ¼°½ÓÊÜ»òÍйÜÓû§ÌṩµÄÄÚÈÝ»ò¹ã¸æµÄÍøÕ¾¡£¡£¡£¡£¡£¡£¡£ÕâÐ©ÍøÕ¾¿ÉÄܰüÀ¨¿ÉÒÔʹÓôËÎó²îµÄ¾ÌØÊâÉè¼ÆµÄÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£ ´ËÇå¾²¸üгÌÐòͨ¹ýÐ޸ľ籾ÒýÇæ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£¡£¡£¡£¡£¡£¡£ |
ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë |
Microsoft Edge |
ÐÞ¸´½¨Òé
ÏÖÔÚ£¬£¬£¬£¬Î¢Èí¹Ù·½ÒѾÐû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ï죬£¬£¬£¬¾¡¿ì½ÓÄÉÐÞ²¹²½·¥£¬£¬£¬£¬ÒÔ×èֹDZÔÚµÄÇå¾²Íþв¡£¡£¡£¡£¡£¡£¡£ÏëÒª¾ÙÐиüУ¬£¬£¬£¬Ö»Ðèתµ½ÉèÖáú¸üкÍÇå¾²¡úWindows ¸üСú¼ì²é¸üУ¬£¬£¬£¬»òÕßÒ²¿ÉÒÔͨ¹ýÊÖ¶¯¾ÙÐиüС£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/51503ac5-e6d2-e811-a983-000d3a33c57