Microsoft | 12Ô¶à¸ö²úÆ·Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-12-09

0x00 Îó²î¸ÅÊö

2020Äê12ÔÂ08ÈÕ£¬£¬£¬£¬MicrosoftÐû²¼ÁË12Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²Îó²î¹²¼Æ58¸ö£¬£¬£¬£¬Ïà½ÏÓÚÉÏÔÂïÔÌ­ÁË54¸ö¡£¡£¡£¡£¡£ÆäÖÐÓÐ9¸öÎó²îÆÀ¼¶ÎªÑÏÖØ£¬£¬£¬£¬46¸öÎó²îÆÀ¼¶Îª¸ßΣ¡£¡£¡£¡£¡£ÔÚ´Ë´ÎÐû²¼µÄÇå¾²Îó²îÖУ¬£¬£¬£¬ÆäÖÐÓÐ23¸öÎó²îΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬14¸öÎó²îΪȨÏÞÌáÉýÎó²î£¬£¬£¬£¬9¸öÎó²îΪÐÅϢй¶Îó²î¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

 

image.png

΢Èí±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÖУ¬£¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·ºÍ×é¼þ°üÀ¨£ºMicrosoft Windows¡¢Microsoft Edge (EdgeHTML-based)¡¢Microsoft Edge for Android¡¢ChakraCore¡¢Microsoft Office and Microsoft Office Services and Web Apps¡¢Microsoft Exchange Server¡¢Azure DevOps¡¢Microsoft Dynamics¡¢Visual Studio¡¢Azure SDKºÍAzure Sphere¡£¡£¡£¡£¡£

±¾´ÎÐû²¼µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE-ID

Îó²îÃû³Æ

ÑÏÖØË®Æ½

CVE-2020-17131

Chakra¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î

ÑÏÖØ

CVE-2020-17095

Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17152

Microsoft Dynamics 365 for Finance and Operations´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17158

Microsoft Dynamics 365 for Finance and Operations´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17117

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17132

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17142

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17118

Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17121

Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17145

Azure DevOpsЧÀÍÆ÷ºÍTeam   Foundation ServicesÓÕÆ­Îó²î

¸ßΣ

CVE-2020-17135

Azure DevOpsЧÀÍÆ÷ÓÕÆ­Îó²î

¸ßΣ

CVE-2020-17002

ÓÃÓÚCÇå¾²¹¦Ð§ÈƹýµÄAzure SDK

¸ßΣ

CVE-2020-17160

Azure SphereÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17137

DirectXͼÐÎÄÚºËȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17147

Dynamics CRM Webclient¿çÕ¾µã¾ç±¾Îó²î

¸ßΣ

CVE-2020-16996

KerberosÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17133

Microsoft Dynamics Business Central / NAVÐÅÏ¢Åû¶

¸ßΣ

CVE-2020-17126

Microsoft ExcelÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17122

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17123

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17125

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17127

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17128

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17129

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17130

Microsoft ExcelÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17143

Microsoft ExchangeÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17141

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17144

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17119

Microsoft OutlookÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17124

Microsoft PowerPointÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17089

Microsoft SharePointȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17120

Microsoft SharePointÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17159

Visual Studio Code JavaÀ©Õ¹°üÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17150

Visual Studio´úÂëÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17148

Visual Studio CodeÔ¶³Ì¿ª·¢À©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17156

Visual StudioÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-16958

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16959

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16960

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16961

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16962

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16963

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16964

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17103

WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17134

WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17136

WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17097

Windows Digital Media ReceiverȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17094

Windows¹ýʧ±¨¸æÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17138

Windows¹ýʧ±¨¸æÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17098

Windows GDI +ÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17099

WindowsËø¶¨ÆÁÄ»Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17092

WindowsÍøÂçÅþÁ¬Ð§ÀÍȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17096

Windows NTFSÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17139

WindowsÁýÕÖɸѡÆ÷Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17140

Windows SMBÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-16971

ÊÊÓÃÓÚJavaµÄAzure SDKÇå¾²¹¦Ð§ÈƹýÎó²î

ÖÐΣ

CVE-2020-17153

Android EdgeµÄMicrosoft   EdgeÎó²î

ÖÐΣ

CVE-2020-17115

Microsoft SharePointÓÕÆ­Îó²î

ÖÐΣ

 

²¿·ÖÑÏÖØÎó²îÈçÏ£º

Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Hyper-VÖб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17095£©£¬£¬£¬£¬ÆäCVSSÆÀ·Ö8.5¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý´ËÎó²î½«Hyper-V Guest OSȨÏÞÌáÉýµ½Hyper-V HostȨÏÞ£¬£¬£¬£¬×îÖÕÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£

Windows NTFSÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Windows NTFSÖб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17096£©£¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.5¡£¡£¡£¡£¡£¾ßÓÐSMBv2»á¼ûȨÏ޵Ĺ¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâÇëÇóÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬×îÖÕ¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£

Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î

MicrosoftÔÚSharePointÖÐÐÞ¸´ÁË2¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17121ºÍCVE-2020-17118£©¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬CVE-2020-17118 CVSSÆÀ·Ö8.1£¬£¬£¬£¬CVE-2020-17121 CVSSÆÀ·Ö8.8¡£¡£¡£¡£¡£

¹¥»÷ÕßÄܹ»Ê¹ÓÃCVE-2020-17121»ñµÃ»á¼ûȨÏÞ£¬£¬£¬£¬ÒÔ½¨ÉèÕ¾µã²¢ÔÚkernelÄÚÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

MicrosoftÐÞ¸´ÁËExchangeÖеÄ5¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17141¡¢CVE-2020-17142¡¢CVE-2020-17144¡¢ CVE-2020-17117¡¢CVE-2020-17132£©¡£¡£¡£¡£¡£

ÆäÖУ¬£¬£¬£¬CVE-2020-17132ÊǶÔcmdlet²ÎÊýµÄÑéÖ¤²»×¼È·Ôì³ÉµÄ£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.1¡£¡£¡£¡£¡£Microsoft²¢Î´ÔÚ´Ë´¦Ìṩ¹¥»÷³¡¾°£¬£¬£¬£¬µ«Ö¸³ö¹¥»÷ÕßÐèÒª¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬ÇÒ¸ÃÎó²îµÄʹÓÃÖØ´óÐԵ͡£¡£¡£¡£¡£ÈôÊǹ¥»÷ÕßÈëÇÖÁËijÈ˵ÄÓÊÏ䣬£¬£¬£¬Ôò¿ÉÒÔ¿ØÖÆÕû¸öExchangeЧÀÍÆ÷¡£¡£¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚMicrosoftÒѾ­Ðû²¼ÁËÇå¾²¸üУ¬£¬£¬£¬½¨ÒéʵʱװÖÃÏà¹Ø²¹¶¡¡£¡£¡£¡£¡£

 

£¨Ò»£© Windows update¸üÐÂ

 

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£

4¡¢ÖØÆôÅÌËã»ú£¬£¬£¬£¬×°ÖøüÐÂÏµÍ³ÖØÐÂÆô¶¯ºó£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£

 

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

΢Èí¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£

ÏÂÔØµØµã£º

https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec

https://threatpost.com/microsoft-patch-tuesday-holidays/162041/

https://www.darkreading.com/threat-intelligence/microsoft-fixes-58-cves-for-december-patch-tuesday/d/d-id/1339651?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple

 

0x04 ʱ¼äÏß

2020-12-08  MicrosoftÐû²¼Çå¾²¸üÐÂ

2020-12-09  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

 

 

 

image.png