΢Èí6Ô¶à¸öÇå¾²Îó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-06-14Îó²î¸ÅÊö
2019Äê6ÔÂ11ÈÕ£¬£¬£¬MicrosoftÐû²¼ÁËÁùÔ·ÝÇå¾²²¹¶¡¸üС£¡£¡£¡£¡£¡£ÔÚ¹Ù·½µÄÇå¾²¸üÐÂͨ¸æÖÐÒ»¹²Åû¶ÁË88¸öÎó²îµÄÏà¹ØÐÅÏ¢£¬£¬£¬ÆäÖÐ21¸ö»ñµÃÁË¡°ÑÏÖØ¡±ÆÀ¼¶£¬£¬£¬ÕâÊÇ΢ÈíÓÐÊ·ÒÔÀ´Îó²îÑÏÖØË®Æ½×î¸ßµÄÒ»´ÎÅÅÃû¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚΪֹ£¬£¬£¬ÉÐδ·¢Ã÷Õâ88¸öÎó²îµÄÔÚҰʹÓᣡ£¡£¡£¡£¡£
ÀÖ³ÉʹÓÃÉÏÊöÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡¢»ñÈ¡Óû§Êý¾Ý¡£¡£¡£¡£¡£¡£Î¢Èí¶à¸ö²úÆ·ºÍϵͳÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬Î¢Èí¹Ù·½ÒѾÐû²¼Îó²îÐÞ¸´²¹¶¡£¬£¬£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ï죬£¬£¬½ÓÄÉÐÞ²¹²½·¥¡£¡£¡£¡£¡£¡£
1¡¢Windows Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0620£©£¨CVE-2019-0709£©£¨CVE-2019-0722£©
Îó²î¼ò½é£ºµ±Ö÷»úЧÀÍÆ÷É쵀 Windows Hyper-V ÎÞ·¨×¼È·ÑéÖ¤À´±öϵͳÉϾÉí·ÝÑéÖ¤µÄÓû§ÊäÈëʱ£¬£¬£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÔÚÀ´±ö²Ù×÷ϵͳÉÏÔËÐÐ¾ÌØÊâÉè¼ÆµÄ¶ñÒâ³ÌÐò£¬£¬£¬×îÖÕÔÚÖ÷»úЧÀÍÆ÷ϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0709
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0722
2¡¢Jet Êý¾Ý¿âÒýÇæÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0904£©£¨CVE-2019-0905£©£¨CVE-2019-0906£©£¨CVE-2019-0907£©£¨CVE-2019-0908£©£¨CVE-2019-0909£©
Îó²î¼ò½é£ºµ± Windows Jet Êý¾Ý¿âÒýÇæ²»×¼È·µØ´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ£¬£¬£¬»á´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÊܺ¦ÕßϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0905
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0906
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0907
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0908
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0909
3¡¢ActiveX Data Objects (ADO)Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0888£©
Îó²î¼ò½é£ºActiveX Data Objects (ADO)´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨Öб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£ ¹¥»÷Õ߿ɽ¨É躬ÓжñÒâ´úÂëµÄÍøÕ¾£¬£¬£¬²¢ÓÕʹÓû§¾ÙÐлá¼û£¬£¬£¬×îÖÕʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£
¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0888
4¡¢Microsoft Word Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-1034£©£¨CVE-2019-1035£©
Îó²î¼ò½é£ºµ± Microsoft WordÎÞ·¨×¼È·´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ£¬£¬£¬»á´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÏòÓû§·¢ËÍ¾ÌØÊâÉè¼ÆµÄÎļþ²¢ÓÕʹÓû§·¿ª¸ÃÎļþÒÔʹÓôËÎó²î¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓÃÎó²îµÄ¹¥»÷Õß¿ÉÔÚÓû§ÏµÍ³ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1035
5¡¢Chakra ¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î£¨CVE-2019-1002£©£¨CVE-2019-1003£©£¨CVE-2019-0989£©£¨CVE-2019-0991£©£¨CVE-2019-0992£©£¨CVE-2019-0993£©
Îó²î¼ò½é£ºChakra ¾ç±¾ÒýÇæÔÚ Microsoft Edge Öд¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ¿ÉÄÜ´¥·¢¸ÃÎó²î¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£¡£¡£¡£¡£¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíԱȨÏ޵Ǽ£¬£¬£¬¹¥»÷Õß±ã¿ÉÒÔí§Òâ×°ÖóÌÐò¡¢Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£¬£¬£¬»òÕß½¨ÉèÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£¡£¡£¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1003
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0989
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0991
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0992
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0993
6¡¢Microsoft Speech API Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0985£©
Îó²î¼ò½é£ºµ±Microsoft Speech API²»×¼È·µØ´¦Öóͷ£Îı¾µ½ÓïÒô£¨TTS£©ÊäÈëʱ£¬£¬£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£ ¸ÃÎó²î¿ÉÄÜÒÔÒ»ÖÖʹ¹¥»÷ÕßÄܹ»ÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂëµÄ·½·¨À´ÆÆËðÄÚ´æ¡£¡£¡£¡£¡£¡£
¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0985
7¡¢Microsoft WindowsÇå¾²ÌØÕ÷ÈÆ¹ýÎó²î£¨CVE-2019-1019£©
Îó²î¼ò½é£º WindowsÖÐNetlogonÐÂÎÅÄܹ»»ñÈ¡»á»°ÃÜÔ¿²¢¶ÔÐÂΞÙÐÐÊðÃû£¬£¬£¬¸ÃÐÂÎű£´æÒ»¸öÇå¾²ÌØÕ÷ÈÆ¹ýÎó²î¡£¡£¡£¡£¡£¡£ÎªÁËʹÓôËÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐÄÉè¼ÆµÄÉí·ÝÑéÖ¤ÇëÇ󡣡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÔʼÓû§È¨ÏÞ»á¼ûÁíһ̨ÅÌËã»ú¡£¡£¡£¡£¡£¡£
¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1019
8¡¢Microsoft IISЧÀÍÆ÷¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2019-0941£©
Îó²î¼ò½é£ºMicrosoft IIS ServerÖб£´æÒ»¸ö¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2019-0941£©£¬£¬£¬µ±¿ÉÑ¡ÇëÇóɸѡ¹¦Ð§ÎÞ·¨×¼È·´¦Öóͷ£ÇëÇóʱ£¬£¬£¬¸ÃÎó²î½«»á³ö·¢¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÄÜ»á¶ÔÉèÖÃΪʹÓÃÇëÇóɸѡµÄÒ³ÃæÔì³ÉÔÝʱ¾Ü¾øÐ§ÀÍ¡£¡£¡£¡£¡£¡£
¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0941
9¡¢Windows NTLM¸Ä¶¯Îó²î£¨CVE-2019-1040£©
Îó²î¼ò½é£ºMicrosoft WindowsµÄNTLMÖб£´æ¸Ä¶¯Îó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÖÐÐÄÈ˹¥»÷ÀÖ³ÉÈÆ¹ýNTLM MIC£¨ÐÂÎÅÍêÕûÐÔ¼ì²é£©µÄ±£»£»£»£»£»¤£¬£¬£¬ÊµÏÖNTLMÇå¾²¹¦Ð§µÄ½µ¼¶¡£¡£¡£¡£¡£¡£¸ÃÎó²î¿ÉÒÔÔì³É²î±ðˮƽµÄΣº¦£¬£¬£¬×îΪÑÏÖØÊ±¿ÉÔÚʹÓÃͨË×ÓòÕ˺ŵÄÇéÐÎÏ¿ØÖÆÓòÄÚµÄËùÓлúе¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÏëÒªÀÖ³ÉʹÓôËÎó²î£¬£¬£¬ÐèÒª¸Ä¶¯NTLM½»Á÷ÐÅÏ¢£¬£¬£¬È»ºóÔÚ°ü¹ÜÊðÃûÈÔÈ»ÓÐÓõÄÌõ¼þÏÂÐÞ¸ÄNTLMÊý¾Ý°üµÄ±ê¼Ç¡£¡£¡£¡£¡£¡£
¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1040
10¡¢Windows¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2019-1025£©
Îó²î¼ò½é£ºWindowsµÄÄÚ´æ´¦Öóͷ£·½·¨Öб£´æ¾Ü¾øÐ§ÀÍÎó²î£¬£¬£¬µ±¹ýʧµØ´¦Öóͷ£Äڴ湤¾ßʱ½«»á´¥·¢¸ÃÎó²î¡£¡£¡£¡£¡£¡£ÒªÊ¹ÓôËÎó²î£¬£¬£¬¹¥»÷Õß±ØÐèµÇ¼µ½ÊÜÓ°ÏìµÄϵͳ²¢ÔËÐÐ¾ÌØÊâÉè¼ÆµÄÓ¦ÓóÌÐò»òÓÕÆÓû§·¿ªÍøÂç¹²ÏíÉϵÄÌØ¶¨Îļþ¡£¡£¡£¡£¡£¡£¸ÃÎó²î²»ÔÊÐí¹¥»÷ÕßÖ±½ÓÖ´ÐдúÂë»òÌáÉýÓû§È¨ÏÞ£¬£¬£¬µ«¿ÉÄܻᵼÖÂÄ¿µÄϵͳ×èÖ¹ÏìÓ¦¡£¡£¡£¡£¡£¡£
¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1025
ÐÞ¸´½¨Òé
ÏÖÔÚ£¬£¬£¬Î¢Èí¹Ù·½ÒѾÐû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ï죬£¬£¬¾¡¿ì½ÓÄÉÐÞ²¹²½·¥£¬£¬£¬ÒÔ×èֹDZÔÚµÄÇå¾²Íþв¡£¡£¡£¡£¡£¡£ÏëÒª¾ÙÐиüУ¬£¬£¬Ö»Ðèתµ½ÉèÖáú¸üкÍÇå¾²¡úWindows ¸üСú¼ì²é¸üУ¬£¬£¬»òÕßÒ²¿ÉÒÔͨ¹ýÊÖ¶¯¾ÙÐиüС£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó