΢Èí6Ô¶à¸öÇå¾²Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-14

Îó²î¸ÅÊö



2019Äê6ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬MicrosoftÐû²¼ÁËÁùÔ·ÝÇå¾²²¹¶¡¸üС£¡£¡£ÔÚ¹Ù·½µÄÇå¾²¸üÐÂͨ¸æÖÐÒ»¹²Åû¶ÁË88¸öÎó²îµÄÏà¹ØÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ21¸ö»ñµÃÁË¡°ÑÏÖØ¡±ÆÀ¼¶£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇ΢ÈíÓÐÊ·ÒÔÀ´Îó²îÑÏÖØË®Æ½×î¸ßµÄÒ»´ÎÅÅÃû¡£¡£¡£×èÖ¹ÏÖÔÚΪֹ£¬£¬£¬£¬£¬£¬£¬£¬ÉÐδ·¢Ã÷Õâ88¸öÎó²îµÄÔÚҰʹÓᣡ£¡£


ÀÖ³ÉʹÓÃÉÏÊöÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡¢»ñÈ¡Óû§Êý¾Ý¡£¡£¡£Î¢Èí¶à¸ö²úÆ·ºÍϵͳÊÜÎó²îÓ°Ïì¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬Î¢Èí¹Ù·½ÒѾ­Ðû²¼Îó²îÐÞ¸´²¹¶¡£¡£¡£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬½ÓÄÉÐÞ²¹²½·¥¡£¡£¡£


1¡¢Windows Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0620£©£¨CVE-2019-0709£©£¨CVE-2019-0722£©


Îó²î¼ò½é£ºµ±Ö÷»úЧÀÍÆ÷É쵀 Windows Hyper-V ÎÞ·¨×¼È·ÑéÖ¤À´±öϵͳÉϾ­Éí·ÝÑéÖ¤µÄÓû§ÊäÈëʱ£¬£¬£¬£¬£¬£¬£¬£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¹¥»÷Õß¿ÉÒÔÔÚÀ´±ö²Ù×÷ϵͳÉÏÔËÐо­ÌØÊâÉè¼ÆµÄ¶ñÒâ³ÌÐò£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕÔÚÖ÷»úЧÀÍÆ÷ϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0620
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0709

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0722


2¡¢Jet Êý¾Ý¿âÒýÇæÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0904£©£¨CVE-2019-0905£©£¨CVE-2019-0906£©£¨CVE-2019-0907£©£¨CVE-2019-0908£©£¨CVE-2019-0909£©


Îó²î¼ò½é£ºµ± Windows Jet Êý¾Ý¿âÒýÇæ²»×¼È·µØ´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ£¬£¬£¬£¬£¬£¬£¬£¬»á´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÊܺ¦ÕßϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0904
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0905
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0906
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0907
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0908

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0909


3¡¢ActiveX Data Objects (ADO)Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0888£©


Îó²î¼ò½é£ºActiveX Data Objects (ADO)´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨Öб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£ ¹¥»÷Õ߿ɽ¨É躬ÓжñÒâ´úÂëµÄÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬²¢ÓÕʹÓû§¾ÙÐлá¼û£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0888


4¡¢Microsoft Word Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-1034£©£¨CVE-2019-1035£©


Îó²î¼ò½é£ºµ± Microsoft WordÎÞ·¨×¼È·´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ£¬£¬£¬£¬£¬£¬£¬£¬»á´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÏòÓû§·¢Ë;­ÌØÊâÉè¼ÆµÄÎļþ²¢ÓÕʹÓû§·­¿ª¸ÃÎļþÒÔʹÓôËÎó²î¡£¡£¡£ÀÖ³ÉʹÓÃÎó²îµÄ¹¥»÷Õß¿ÉÔÚÓû§ÏµÍ³ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1034

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1035


5¡¢Chakra ¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î£¨CVE-2019-1002£©£¨CVE-2019-1003£©£¨CVE-2019-0989£©£¨CVE-2019-0991£©£¨CVE-2019-0992£©£¨CVE-2019-0993£©


Îó²î¼ò½é£ºChakra ¾ç±¾ÒýÇæÔÚ Microsoft Edge Öд¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ¿ÉÄÜ´¥·¢¸ÃÎó²î¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£¡£¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíԱȨÏ޵Ǽ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß±ã¿ÉÒÔí§Òâ×°ÖóÌÐò¡¢Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬»òÕß½¨ÉèÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1002
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1003
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0989
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0991
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0992

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0993


6¡¢Microsoft Speech API Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0985£©


Îó²î¼ò½é£ºµ±Microsoft Speech API²»×¼È·µØ´¦Öóͷ£Îı¾µ½ÓïÒô£¨TTS£©ÊäÈëʱ£¬£¬£¬£¬£¬£¬£¬£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£ ¸ÃÎó²î¿ÉÄÜÒÔÒ»ÖÖʹ¹¥»÷ÕßÄܹ»ÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂëµÄ·½·¨À´ÆÆËðÄÚ´æ¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0985


7¡¢Microsoft WindowsÇå¾²ÌØÕ÷ÈÆ¹ýÎó²î£¨CVE-2019-1019£©


Îó²î¼ò½é£º WindowsÖÐNetlogonÐÂÎÅÄܹ»»ñÈ¡»á»°ÃÜÔ¿²¢¶ÔÐÂΞÙÐÐÊðÃû£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÐÂÎű£´æÒ»¸öÇå¾²ÌØÕ÷ÈÆ¹ýÎó²î¡£¡£¡£ÎªÁËʹÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐÄÉè¼ÆµÄÉí·ÝÑéÖ¤ÇëÇ󡣡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃԭʼÓû§È¨ÏÞ»á¼ûÁíһ̨ÅÌËã»ú¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1019


8¡¢Microsoft IISЧÀÍÆ÷¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2019-0941£©


Îó²î¼ò½é£ºMicrosoft IIS ServerÖб£´æÒ»¸ö¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2019-0941£©£¬£¬£¬£¬£¬£¬£¬£¬µ±¿ÉÑ¡ÇëÇóɸѡ¹¦Ð§ÎÞ·¨×¼È·´¦Öóͷ£ÇëÇóʱ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î½«»á³ö·¢¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÄÜ»á¶ÔÉèÖÃΪʹÓÃÇëÇóɸѡµÄÒ³ÃæÔì³ÉÔÝʱ¾Ü¾øÐ§ÀÍ¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0941


9¡¢Windows NTLM¸Ä¶¯Îó²î£¨CVE-2019-1040£©


Îó²î¼ò½é£ºMicrosoft WindowsµÄNTLMÖб£´æ¸Ä¶¯Îó²î£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÖÐÐÄÈ˹¥»÷ÀÖ³ÉÈÆ¹ýNTLM MIC£¨ÐÂÎÅÍêÕûÐÔ¼ì²é£©µÄ±£»£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬£¬£¬ÊµÏÖNTLMÇå¾²¹¦Ð§µÄ½µ¼¶¡£¡£¡£¸ÃÎó²î¿ÉÒÔÔì³É²î±ðˮƽµÄΣº¦£¬£¬£¬£¬£¬£¬£¬£¬×îΪÑÏÖØÊ±¿ÉÔÚʹÓÃͨË×ÓòÕ˺ŵÄÇéÐÎÏ¿ØÖÆÓòÄÚµÄËùÓлúе¡£¡£¡£¹¥»÷ÕßÏëÒªÀÖ³ÉʹÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÐèÒª¸Ä¶¯NTLM½»Á÷ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬È»ºóÔÚ°ü¹ÜÊðÃûÈÔÈ»ÓÐÓõÄÌõ¼þÏÂÐÞ¸ÄNTLMÊý¾Ý°üµÄ±ê¼Ç¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1040


10¡¢Windows¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2019-1025£©


Îó²î¼ò½é£ºWindowsµÄÄÚ´æ´¦Öóͷ£·½·¨Öб£´æ¾Ü¾øÐ§ÀÍÎó²î£¬£¬£¬£¬£¬£¬£¬£¬µ±¹ýʧµØ´¦Öóͷ£Äڴ湤¾ßʱ½«»á´¥·¢¸ÃÎó²î¡£¡£¡£ÒªÊ¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß±ØÐèµÇ¼µ½ÊÜÓ°ÏìµÄϵͳ²¢ÔËÐо­ÌØÊâÉè¼ÆµÄÓ¦ÓóÌÐò»òÓÕÆ­Óû§·­¿ªÍøÂç¹²ÏíÉϵÄÌØ¶¨Îļþ¡£¡£¡£¸ÃÎó²î²»ÔÊÐí¹¥»÷ÕßÖ±½ÓÖ´ÐдúÂë»òÌáÉýÓû§È¨ÏÞ£¬£¬£¬£¬£¬£¬£¬£¬µ«¿ÉÄܻᵼÖÂÄ¿µÄϵͳ×èÖ¹ÏìÓ¦¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1025



ÐÞ¸´½¨Òé



ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬Î¢Èí¹Ù·½ÒѾ­Ðû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬¾¡¿ì½ÓÄÉÐÞ²¹²½·¥£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ×èֹDZÔÚµÄÇå¾²Íþв¡£¡£¡£ÏëÒª¾ÙÐиüУ¬£¬£¬£¬£¬£¬£¬£¬Ö»Ðèתµ½ÉèÖáú¸üкÍÇå¾²¡úWindows ¸üСú¼ì²é¸üУ¬£¬£¬£¬£¬£¬£¬£¬»òÕßÒ²¿ÉÒÔͨ¹ýÊÖ¶¯¾ÙÐиüС£¡£¡£



²Î¿¼Á´½Ó



https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/253dc509-9a5b-e911-a98e-000d3a33c573