΢Èí6Ô¶à¸öÇå¾²Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-14

Îó²î¸ÅÊö



2019Äê6ÔÂ11ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬MicrosoftÐû²¼ÁËÁùÔ·ÝÇå¾²²¹¶¡¸üС£¡£¡£¡£¡£ÔÚ¹Ù·½µÄÇå¾²¸üÐÂͨ¸æÖÐÒ»¹²Åû¶ÁË88¸öÎó²îµÄÏà¹ØÐÅÏ¢ £¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ21¸ö»ñµÃÁË¡°ÑÏÖØ¡±ÆÀ¼¶ £¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇ΢ÈíÓÐÊ·ÒÔÀ´Îó²îÑÏÖØË®Æ½×î¸ßµÄÒ»´ÎÅÅÃû¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚΪֹ £¬£¬£¬£¬£¬£¬£¬£¬ÉÐδ·¢Ã÷Õâ88¸öÎó²îµÄÔÚҰʹÓᣡ£¡£¡£¡£


ÀÖ³ÉʹÓÃÉÏÊöÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡¢»ñÈ¡Óû§Êý¾Ý¡£¡£¡£¡£¡£Î¢Èí¶à¸ö²úÆ·ºÍϵͳÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬£¬£¬£¬£¬£¬Î¢Èí¹Ù·½ÒѾ­Ðû²¼Îó²îÐÞ¸´²¹¶¡ £¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ïì £¬£¬£¬£¬£¬£¬£¬£¬½ÓÄÉÐÞ²¹²½·¥¡£¡£¡£¡£¡£


1¡¢Windows Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0620£©£¨CVE-2019-0709£©£¨CVE-2019-0722£©


Îó²î¼ò½é£ºµ±Ö÷»úЧÀÍÆ÷É쵀 Windows Hyper-V ÎÞ·¨×¼È·ÑéÖ¤À´±öϵͳÉϾ­Éí·ÝÑéÖ¤µÄÓû§ÊäÈëʱ £¬£¬£¬£¬£¬£¬£¬£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÔÚÀ´±ö²Ù×÷ϵͳÉÏÔËÐо­ÌØÊâÉè¼ÆµÄ¶ñÒâ³ÌÐò £¬£¬£¬£¬£¬£¬£¬£¬×îÖÕÔÚÖ÷»úЧÀÍÆ÷ϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0620
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0709

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0722


2¡¢Jet Êý¾Ý¿âÒýÇæÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0904£©£¨CVE-2019-0905£©£¨CVE-2019-0906£©£¨CVE-2019-0907£©£¨CVE-2019-0908£©£¨CVE-2019-0909£©


Îó²î¼ò½é£ºµ± Windows Jet Êý¾Ý¿âÒýÇæ²»×¼È·µØ´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ £¬£¬£¬£¬£¬£¬£¬£¬»á´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÊܺ¦ÕßϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0904
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0905
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0906
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0907
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0908

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0909


3¡¢ActiveX Data Objects (ADO)Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0888£©


Îó²î¼ò½é£ºActiveX Data Objects (ADO)´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨Öб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£ ¹¥»÷Õ߿ɽ¨É躬ÓжñÒâ´úÂëµÄÍøÕ¾ £¬£¬£¬£¬£¬£¬£¬£¬²¢ÓÕʹÓû§¾ÙÐлá¼û £¬£¬£¬£¬£¬£¬£¬£¬×îÖÕʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0888


4¡¢Microsoft Word Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-1034£©£¨CVE-2019-1035£©


Îó²î¼ò½é£ºµ± Microsoft WordÎÞ·¨×¼È·´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ £¬£¬£¬£¬£¬£¬£¬£¬»á´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÏòÓû§·¢Ë;­ÌØÊâÉè¼ÆµÄÎļþ²¢ÓÕʹÓû§·­¿ª¸ÃÎļþÒÔʹÓôËÎó²î¡£¡£¡£¡£¡£ÀÖ³ÉʹÓÃÎó²îµÄ¹¥»÷Õß¿ÉÔÚÓû§ÏµÍ³ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1034

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1035


5¡¢Chakra ¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î£¨CVE-2019-1002£©£¨CVE-2019-1003£©£¨CVE-2019-0989£©£¨CVE-2019-0991£©£¨CVE-2019-0992£©£¨CVE-2019-0993£©


Îó²î¼ò½é£ºChakra ¾ç±¾ÒýÇæÔÚ Microsoft Edge Öд¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ¿ÉÄÜ´¥·¢¸ÃÎó²î¡£¡£¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£¡£¡£¡£¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíԱȨÏ޵Ǽ £¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß±ã¿ÉÒÔí§Òâ×°ÖóÌÐò¡¢Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý £¬£¬£¬£¬£¬£¬£¬£¬»òÕß½¨ÉèÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1002
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1003
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0989
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0991
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0992

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0993


6¡¢Microsoft Speech API Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0985£©


Îó²î¼ò½é£ºµ±Microsoft Speech API²»×¼È·µØ´¦Öóͷ£Îı¾µ½ÓïÒô£¨TTS£©ÊäÈëʱ £¬£¬£¬£¬£¬£¬£¬£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£ ¸ÃÎó²î¿ÉÄÜÒÔÒ»ÖÖʹ¹¥»÷ÕßÄܹ»ÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂëµÄ·½·¨À´ÆÆËðÄÚ´æ¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0985


7¡¢Microsoft WindowsÇå¾²ÌØÕ÷ÈÆ¹ýÎó²î£¨CVE-2019-1019£©


Îó²î¼ò½é£º WindowsÖÐNetlogonÐÂÎÅÄܹ»»ñÈ¡»á»°ÃÜÔ¿²¢¶ÔÐÂΞÙÐÐÊðÃû £¬£¬£¬£¬£¬£¬£¬£¬¸ÃÐÂÎű£´æÒ»¸öÇå¾²ÌØÕ÷ÈÆ¹ýÎó²î¡£¡£¡£¡£¡£ÎªÁËʹÓôËÎó²î £¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐÄÉè¼ÆµÄÉí·ÝÑéÖ¤ÇëÇ󡣡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃԭʼÓû§È¨ÏÞ»á¼ûÁíһ̨ÅÌËã»ú¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1019


8¡¢Microsoft IISЧÀÍÆ÷¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2019-0941£©


Îó²î¼ò½é£ºMicrosoft IIS ServerÖб£´æÒ»¸ö¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2019-0941£© £¬£¬£¬£¬£¬£¬£¬£¬µ±¿ÉÑ¡ÇëÇóɸѡ¹¦Ð§ÎÞ·¨×¼È·´¦Öóͷ£ÇëÇóʱ £¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î½«»á³ö·¢¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÄÜ»á¶ÔÉèÖÃΪʹÓÃÇëÇóɸѡµÄÒ³ÃæÔì³ÉÔÝʱ¾Ü¾øÐ§ÀÍ¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0941


9¡¢Windows NTLM¸Ä¶¯Îó²î£¨CVE-2019-1040£©


Îó²î¼ò½é£ºMicrosoft WindowsµÄNTLMÖб£´æ¸Ä¶¯Îó²î £¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÖÐÐÄÈ˹¥»÷ÀÖ³ÉÈÆ¹ýNTLM MIC£¨ÐÂÎÅÍêÕûÐÔ¼ì²é£©µÄ±£»£»£»£»£» £»¤ £¬£¬£¬£¬£¬£¬£¬£¬ÊµÏÖNTLMÇå¾²¹¦Ð§µÄ½µ¼¶¡£¡£¡£¡£¡£¸ÃÎó²î¿ÉÒÔÔì³É²î±ðˮƽµÄΣº¦ £¬£¬£¬£¬£¬£¬£¬£¬×îΪÑÏÖØÊ±¿ÉÔÚʹÓÃͨË×ÓòÕ˺ŵÄÇéÐÎÏ¿ØÖÆÓòÄÚµÄËùÓлúе¡£¡£¡£¡£¡£¹¥»÷ÕßÏëÒªÀÖ³ÉʹÓôËÎó²î £¬£¬£¬£¬£¬£¬£¬£¬ÐèÒª¸Ä¶¯NTLM½»Á÷ÐÅÏ¢ £¬£¬£¬£¬£¬£¬£¬£¬È»ºóÔÚ°ü¹ÜÊðÃûÈÔÈ»ÓÐÓõÄÌõ¼þÏÂÐÞ¸ÄNTLMÊý¾Ý°üµÄ±ê¼Ç¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1040


10¡¢Windows¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2019-1025£©


Îó²î¼ò½é£ºWindowsµÄÄÚ´æ´¦Öóͷ£·½·¨Öб£´æ¾Ü¾øÐ§ÀÍÎó²î £¬£¬£¬£¬£¬£¬£¬£¬µ±¹ýʧµØ´¦Öóͷ£Äڴ湤¾ßʱ½«»á´¥·¢¸ÃÎó²î¡£¡£¡£¡£¡£ÒªÊ¹ÓôËÎó²î £¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß±ØÐèµÇ¼µ½ÊÜÓ°ÏìµÄϵͳ²¢ÔËÐо­ÌØÊâÉè¼ÆµÄÓ¦ÓóÌÐò»òÓÕÆ­Óû§·­¿ªÍøÂç¹²ÏíÉϵÄÌØ¶¨Îļþ¡£¡£¡£¡£¡£¸ÃÎó²î²»ÔÊÐí¹¥»÷ÕßÖ±½ÓÖ´ÐдúÂë»òÌáÉýÓû§È¨ÏÞ £¬£¬£¬£¬£¬£¬£¬£¬µ«¿ÉÄܻᵼÖÂÄ¿µÄϵͳ×èÖ¹ÏìÓ¦¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1025



ÐÞ¸´½¨Òé



ÏÖÔÚ £¬£¬£¬£¬£¬£¬£¬£¬Î¢Èí¹Ù·½ÒѾ­Ðû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î £¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ïì £¬£¬£¬£¬£¬£¬£¬£¬¾¡¿ì½ÓÄÉÐÞ²¹²½·¥ £¬£¬£¬£¬£¬£¬£¬£¬ÒÔ×èֹDZÔÚµÄÇå¾²Íþв¡£¡£¡£¡£¡£ÏëÒª¾ÙÐиüР£¬£¬£¬£¬£¬£¬£¬£¬Ö»Ðèתµ½ÉèÖáú¸üкÍÇå¾²¡úWindows ¸üСú¼ì²é¸üР£¬£¬£¬£¬£¬£¬£¬£¬»òÕßÒ²¿ÉÒÔͨ¹ýÊÖ¶¯¾ÙÐиüС£¡£¡£¡£¡£



²Î¿¼Á´½Ó



https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/253dc509-9a5b-e911-a98e-000d3a33c573