΢Èí12Ô¶à¸öÇå¾²Îó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2019-12-11Îó²î¸ÅÊö
΢ÈíÓÚÖܶþÐû²¼ÁË12ÔÂÇå¾²¸üв¹¶¡£¬£¬£¬Ðû²¼ÁË36¸öÎó²îµÄ2¸öͨ¸æºÍ¸üС£¡£¡£¡£ÔÚÕâЩÎó²îÖУ¬£¬£¬ÓÐ7¸ö±»·ÖÀàΪÑÏÖØ£¬£¬£¬27¸ö±»·ÖÀàΪÖ÷Òª£¬£¬£¬1¸ö±»·ÖÀàΪÖУ¬£¬£¬1¸ö±»·ÖÀàΪµÍ¡£¡£¡£¡£Éæ¼°µ½Windows Hyper-V£¬£¬£¬Graphics£¬£¬£¬GDI, RDP, OLE£¬£¬£¬Microsoft PowerPoint£¬£¬£¬Word£¬£¬£¬Excel£¬£¬£¬Git for Visual StudioµÈ×é¼þºÍÈí¼þ¡£¡£¡£¡£
ÐèÒª¹Ø×¢µÄÎó²îÊÇWin32k×é¼þÖеÄÌØÈ¨ÌáÉý0day£¬£¬£¬¸ÃÎó²î£¨CVE-2019-1458£©ÊÇÓÉ¿¨°Í˹»ùÑо¿Ö°Ô±·¢Ã÷µÄ£¬£¬£¬²¢ÒÑÔÚÒ°Íâ±»Æð¾¢Ê¹Óᣡ£¡£¡£Æ¾Ö¤Î¢ÈíµÄÇ徲ͨ¸æ£¬£¬£¬¸ÃÎó²î±¬·¢ÔÚWin32k×é¼þÎÞ·¨×¼È·´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄÚºËģʽÏÂÔËÐÐí§Òâ´úÂë¡£¡£¡£¡£ÒªÊ¹ÓôËÎó²î£¬£¬£¬¹¥»÷Õß±ØÐèÊ×ÏȵǼϵͳ£¬£¬£¬È»ºó¿Éͨ¹ýÔËÐÐʹÓôËÎó²îµÄ¶ñÒâÈí¼þÀ´½ÓÊÜϵͳ¡£¡£¡£¡£
³ýÁËÇå¾²¸üÐÂÍ⣬£¬£¬Microsoft½ñÌ컹Ðû²¼ÁËÁ½¸öͨ¸æ¡£¡£¡£¡£Ò»¸öÊÇЧÀÍ¿ÍÕ»¸üУ¬£¬£¬ÁíÒ»¸öÊÇÓйØÔõÑùɾ³ýÓÉÒ×Êܹ¥»÷µÄTPM×°±¸½¨ÉèµÄÁæØêWindows Hello for Business£¨WHfB£©¹«Ô¿µÄÖ¸ÄÏ¡£¡£¡£¡£
ADV190026-MicrosoftÖ¸ÄÏ£¬£¬£¬ÓÃÓÚÕûÀíÔÚÒ×Êܹ¥»÷µÄTPMÉÏÌìÉú²¢ÓÃÓÚWindows HelloÆóÒµ°æµÄÁæØêÃÜÔ¿
ADV990001-×îÐÂЧÀÍ¿ÍÕ»¸üÐÂ
ÒÔÏÂÊÇÒѽâ¾öµÄÑÏÖØÎó²îµÄÍêÕûÁбíÒÔ¼°2019Äê12Ô²¹¶¡ÐÇÆÚ¶þ¸üÐÂÖеĽ¨Òé¡£¡£¡£¡£
|
CVE񅧏 |
ÑÏÖØË®Æ½ |
CVEÎÊÌâ |
Îó²îÐÎò |
²úÆ· |
|
CVE-2019-1468 |
ÑÏÖØ |
Win32kͼÐÎÔ¶³ÌÖ´ÐдúÂëÎó²î |
Microsoft WindowsÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾Ðû²¼µÄһϵÁвÙ×÷ϵͳ¡£¡£¡£¡£GraphicsÊÇÆäÖеÄÒ»¸öͼÐÎÇý¶¯Æ÷×é¼þ¡£¡£¡£¡£ Win32k Graphics±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-1468£©£¬£¬£¬¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔÓÉÊÇWindows×ÖÌå¿âÔÚ´¦Öóͷ£ÌØÖƵÄǶÈëʽ×ÖÌåʱ±¬·¢Òì³£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î£¬£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£ |
MicrosoftͼÐÎ×é¼þ |
|
CVE-2019-1350 |
ÑÏÖØ |
Git for Visual StudioÔ¶³ÌÖ´ÐдúÂëÎó²î |
Microsoft Visual Studio£¨¼ò³ÆVS»òMSVS£©ÊÇ΢Èí¹«Ë¾µÄ¿ª·¢¹¤¾ß°üϵÁвúÆ·£¬£¬£¬ÊÇÒ»¸öÍêÕûµÄ¿ª·¢¹¤¾ß¼¯£¬£¬£¬°üÀ¨ÁËÕû¸öÈí¼þÉúÃüÖÜÆÚÖÐËùÐèÒªµÄ´ó²¿·Ö¹¤¾ß£¨UML¹¤¾ß¡¢´úÂë¹Ü¿Ø¹¤¾ß¡¢¼¯³É¿ª·¢ÇéÐΣ¨IDE£©µÈµÈ£©¡£¡£¡£¡£GitÊÇÏÖÔÚ×îÏȽøµÄ°æ±¾¿ØÖÆÏµÍ³£¬£¬£¬ÓµÓÐ×î¶àµÄÓû§ÊýÄ¿²¢ÖÎÀí×ÅÊýÄ¿ÖØ´óµÄÈí¼þÏîÄ¿¡£¡£¡£¡£VS2013×îÏÈ£¬£¬£¬ÄÚÖÃÁËGit×é¼þ£¬£¬£¬Àû±ã¿ª·¢Ö°Ô±¾ÙÐа汾¿ØÖÆ¡£¡£¡£¡£ Visual StudioµÄGit²å¼þ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔÓÉÊÇGit²å¼þÎÞ·¨×¼È·µØÕûÀíÌØ¶¨ÊäÈë¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î£¬£¬£¬ÒÔÄ¿½ñÓû§Éí·ÝÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ |
Microsoft Visual Studio |
|
CVE-2019-1349 |
ÑÏÖØ |
Git for Visual StudioÔ¶³ÌÖ´ÐдúÂëÎó²î |
Microsoft Visual Studio£¨¼ò³ÆVS»òMSVS£©ÊÇ΢Èí¹«Ë¾µÄ¿ª·¢¹¤¾ß°üϵÁвúÆ·£¬£¬£¬ÊÇÒ»¸öÍêÕûµÄ¿ª·¢¹¤¾ß¼¯£¬£¬£¬°üÀ¨ÁËÕû¸öÈí¼þÉúÃüÖÜÆÚÖÐËùÐèÒªµÄ´ó²¿·Ö¹¤¾ß£¨UML¹¤¾ß¡¢´úÂë¹Ü¿Ø¹¤¾ß¡¢¼¯³É¿ª·¢ÇéÐΣ¨IDE£©µÈµÈ£©¡£¡£¡£¡£GitÊÇÏÖÔÚ×îÏȽøµÄ°æ±¾¿ØÖÆÏµÍ³£¬£¬£¬ÓµÓÐ×î¶àµÄÓû§ÊýÄ¿²¢ÖÎÀí×ÅÊýÄ¿ÖØ´óµÄÈí¼þÏîÄ¿¡£¡£¡£¡£VS2013×îÏÈ£¬£¬£¬ÄÚÖÃÁËGit×é¼þ£¬£¬£¬Àû±ã¿ª·¢Ö°Ô±¾ÙÐа汾¿ØÖÆ¡£¡£¡£¡£ Visual StudioµÄGit²å¼þ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔÓÉÊÇGit²å¼þÎÞ·¨×¼È·µØÕûÀíÌØ¶¨ÊäÈë¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î£¬£¬£¬ÒÔÄ¿½ñÓû§Éí·ÝÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ |
Microsoft Visual Studio |
|
CVE-2019-1387 |
ÑÏÖØ |
Git for Visual StudioÔ¶³ÌÖ´ÐдúÂëÎó²î |
µ± Git for Visual Studio ²»×¼È·µØÕûÀíÊäÈëʱ£¬£¬£¬±£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¹¥»÷Õß¿ÉËæºó×°ÖóÌÐò£»£»£»£»£»£»Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»£»£»£»£»£»»òÕß½¨ÉèÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£¡£ÓëÓµÓÐÖÎÀíÓû§È¨ÏÞµÄÓû§Ïà±È£¬£¬£¬ÕÊ»§±»ÉèÖÃΪӵÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì¸üС¡£¡£¡£¡£ ÈôҪʹÓôËÎó²î£¬£¬£¬¹¥»÷ÕßÊ×ÏȱØÐèÓÕʹÓû§¿Ë¡¶ñÒâ´æ´¢¿â¡£¡£¡£¡£ |
Microsoft Visual Studio |
|
CVE-2019-1354 |
ÑÏÖØ |
Git for Visual StudioÔ¶³ÌÖ´ÐдúÂëÎó²î |
Microsoft Visual Studio£¨¼ò³ÆVS»òMSVS£©ÊÇ΢Èí¹«Ë¾µÄ¿ª·¢¹¤¾ß°üϵÁвúÆ·£¬£¬£¬ÊÇÒ»¸öÍêÕûµÄ¿ª·¢¹¤¾ß¼¯£¬£¬£¬°üÀ¨ÁËÕû¸öÈí¼þÉúÃüÖÜÆÚÖÐËùÐèÒªµÄ´ó²¿·Ö¹¤¾ß£¨UML¹¤¾ß¡¢´úÂë¹Ü¿Ø¹¤¾ß¡¢¼¯³É¿ª·¢ÇéÐΣ¨IDE£©µÈµÈ£©¡£¡£¡£¡£GitÊÇÏÖÔÚ×îÏȽøµÄ°æ±¾¿ØÖÆÏµÍ³£¬£¬£¬ÓµÓÐ×î¶àµÄÓû§ÊýÄ¿²¢ÖÎÀí×ÅÊýÄ¿ÖØ´óµÄÈí¼þÏîÄ¿¡£¡£¡£¡£VS2013×îÏÈ£¬£¬£¬ÄÚÖÃÁËGit×é¼þ£¬£¬£¬Àû±ã¿ª·¢Ö°Ô±¾ÙÐа汾¿ØÖÆ¡£¡£¡£¡£ Visual StudioµÄGit²å¼þ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔÓÉÊÇGit²å¼þÎÞ·¨×¼È·µØÕûÀíÌØ¶¨ÊäÈë¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î£¬£¬£¬ÒÔÄ¿½ñÓû§Éí·ÝÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ |
Microsoft Visual Studio |
|
CVE-2019-1352 |
ÑÏÖØ |
Git for Visual StudioÔ¶³ÌÖ´ÐдúÂëÎó²î |
Microsoft Visual Studio£¨¼ò³ÆVS»òMSVS£©ÊÇ΢Èí¹«Ë¾µÄ¿ª·¢¹¤¾ß°üϵÁвúÆ·£¬£¬£¬ÊÇÒ»¸öÍêÕûµÄ¿ª·¢¹¤¾ß¼¯£¬£¬£¬°üÀ¨ÁËÕû¸öÈí¼þÉúÃüÖÜÆÚÖÐËùÐèÒªµÄ´ó²¿·Ö¹¤¾ß£¨UML¹¤¾ß¡¢´úÂë¹Ü¿Ø¹¤¾ß¡¢¼¯³É¿ª·¢ÇéÐΣ¨IDE£©µÈµÈ£©¡£¡£¡£¡£GitÊÇÏÖÔÚ×îÏȽøµÄ°æ±¾¿ØÖÆÏµÍ³£¬£¬£¬ÓµÓÐ×î¶àµÄÓû§ÊýÄ¿²¢ÖÎÀí×ÅÊýÄ¿ÖØ´óµÄÈí¼þÏîÄ¿¡£¡£¡£¡£VS2013×îÏÈ£¬£¬£¬ÄÚÖÃÁËGit×é¼þ£¬£¬£¬Àû±ã¿ª·¢Ö°Ô±¾ÙÐа汾¿ØÖÆ¡£¡£¡£¡£ Visual StudioµÄGit²å¼þ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔÓÉÊÇGit²å¼þÎÞ·¨×¼È·µØÕûÀíÌØ¶¨ÊäÈë¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î£¬£¬£¬ÒÔÄ¿½ñÓû§Éí·ÝÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ |
Microsoft Visual Studio |
|
CVE-2019-1471 |
ÑÏÖØ |
Windows Hyper-VÔ¶³ÌÖ´ÐдúÂëÎó²î |
µ±Ö÷»úЧÀÍÆ÷É쵀 Windows Hyper-V ÎÞ·¨×¼È·ÑéÖ¤À´±ö²Ù×÷ϵͳÉϾÉí·ÝÑéÖ¤µÄÓû§µÄÊäÈëʱ£¬£¬£¬±£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¡£¡£¡£ÈôҪʹÓôËÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÀ´±ö²Ù×÷ϵͳÉÏÔËÐÐ¾ÌØÊâÉè¼ÆµÄ¿Éʹ Hyper-V Ö÷»ú²Ù×÷ϵͳִÐÐí§Òâ´úÂëµÄÓ¦ÓóÌÐò¡£¡£¡£¡£ ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÖ÷»ú²Ù×÷ϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ |
Windows Hyper-V |
ÐÞ¸´½¨Òé
ÏÖÔÚ£¬£¬£¬Î¢Èí¹Ù·½ÒѾÐû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ï죬£¬£¬
¾¡¿ì½ÓÄÉÐÞ²¹²½·¥£¬£¬£¬ÒÔ×èֹDZÔÚµÄÇå¾²Íþв¡£¡£¡£¡£ÏëÒª¾ÙÐиüУ¬£¬£¬Ö»Ðèתµ½ÉèÖáú¸üкÍÇå¾²¡úWindows ¸üСú¼ì²é¸üУ¬£¬£¬»òÕßÒ²¿ÉÒÔͨ¹ýÊÖ¶¯¾ÙÐиüС£¡£¡£¡£
²Î¿¼Á´½Ó
https://portal.msrc.microsoft.com/zh-cn/security-guidance


¾©¹«Íø°²±¸11010802024551ºÅ