΢Èí9Ô¶à¸öÇå¾²Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-16

¡ñÎó²î¸ÅÊö


΢ÈíÓÚÖܶþÐû²¼ÁË9ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË81¸ö´Ó¼òÆÓµÄÓÕÆ­¹¥»÷µ½Ô¶³ÌÖ´ÐдúÂëµÄÇå¾²ÎÊÌ⣬²úÆ·Éæ¼°.NET Core¡¢.NET Framework¡¢Active Directory¡¢Adobe Flash Player¡¢ASP.NET¡¢Common Log File System Driver¡¢Microsoft Browsers¡¢Microsoft Edge¡¢Microsoft Exchange Server¡¢Microsoft Graphics Component¡¢Microsoft JET Database Engine¡¢Microsoft Office¡¢Microsoft Office SharePoint¡¢Microsoft Scripting Engine¡¢Microsoft Windows¡¢Microsoft Yammer¡¢Project Rome¡¢Servicing Stack Updates¡¢Skype for Business and Microsoft Lync¡¢Team Foundation Server¡¢Visual Studio¡¢Windows Hyper-V¡¢Windows KernelÒÔ¼°Windows RDP¡£


ʹÓÃÉÏÊöÎó²î£¬¹¥»÷Õß¿ÉÒÔÌáÉýȨÏÞ£¬ÓÕÆ­£¬ÈƹýÇå¾²¹¦Ð§ÏÞÖÆ£¬»ñÈ¡Ãô¸ÐÐÅÏ¢£¬Ö´ÐÐÔ¶³Ì´úÂë»òÌᳫ¾Ü¾ø·þÎñ¹¥»÷µÈ¡£ÌáÐÑ¿í´óMicrosoftÓû§¾¡¿ìÏÂÔØ²¹¶¡¸üУ¬×èÖ¹Òý·¢Îó²îÏà¹ØµÄÍøÂçÇå¾²ÊÂÎñ¡£


CVE 񅧏

ÑÏÖØË®Æ½

CVE ÎÊÌâ

Îó²îÐÎò

²úÆ·

CVE-2019-1257

ÑÏÖØ

Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft SharePointÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄÒ»ÌׯóҵӪҵЭ×÷ƽ̨¡£¸Ãƽ̨ÓÃÓÚ¶ÔÓªÒµÐÅÏ¢¾ÙÐÐÕûºÏ£¬²¢Äܹ»¹²ÏíÊÂÇé¡¢ÓëËûÈËЭͬÊÂÇé¡¢×éÖ¯ÏîÄ¿ºÍÊÂÇé×é¡¢ËÑË÷Ö°Ô±ºÍÐÅÏ¢¡£ Microsoft SharePointÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòÎÞ·¨¼ì²éÓ¦ÓóÌÐò°üµÄÔ´±ê¼Ç¡£¹¥»÷Õ߿ɽèÖúÌØÖÆµÄSharePointÓ¦ÓóÌÐò°üʹÓøÃÎó²îÔÚSharePointÓ¦ÓóÌÐò³ØºÍSharePoint·þÎñÆ÷³¡ÕÊ»§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂë¡£

Microsoft Office SharePoint

CVE-2019-1295

ÑÏÖØ

Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft SharePointÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄÒ»ÌׯóҵӪҵЭ×÷ƽ̨¡£¸Ãƽ̨ÓÃÓÚ¶ÔÓªÒµÐÅÏ¢¾ÙÐÐÕûºÏ£¬²¢Äܹ»¹²ÏíÊÂÇé¡¢ÓëËûÈËЭͬÊÂÇé¡¢×éÖ¯ÏîÄ¿ºÍÊÂÇé×é¡¢ËÑË÷Ö°Ô±ºÍÐÅÏ¢¡£ Microsoft SharePointÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¸ÃÎó²îÔ´ÓÚAPIδÊÊÍâµØ±ÜÃâ²»Çå¾²µÄÊý¾ÝÊäÈë¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚSharePointÓ¦ÓóÌÐò³ØºÍSharePoint·þÎñÆ÷³¡ÕÊ»§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂë¡£

Microsoft Office SharePoint

CVE-2019-1296

ÑÏÖØ

Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft SharePointÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄÒ»ÌׯóҵӪҵЭ×÷ƽ̨¡£¸Ãƽ̨ÓÃÓÚ¶ÔÓªÒµÐÅÏ¢¾ÙÐÐÕûºÏ£¬²¢Äܹ»¹²ÏíÊÂÇé¡¢ÓëËûÈËЭͬÊÂÇé¡¢×éÖ¯ÏîÄ¿ºÍÊÂÇé×é¡¢ËÑË÷Ö°Ô±ºÍÐÅÏ¢¡£ Microsoft SharePointÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¸ÃÎó²îÔ´ÓÚÆäÖÐAPI׼ȷ±ÜÃâ²»Çå¾²µÄÊý¾ÝÊäÈë¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚSharePointÓ¦ÓóÌÐò³ØºÍSharePoint·þÎñÆ÷³¡ÕÊ»§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂë¡£

Microsoft Office SharePoint

CVE-2019-1208

ÑÏÖØ

VBScript Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft Internet Explorer£¨IE£©ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄÒ»¿îWindows²Ù×÷ϵͳ¸½´øµÄWebä¯ÀÀÆ÷¡£VBScript EngineÊÇÆäÖеÄÒ»¸öVBScript¾ç±¾ÓïÑÔÒýÇæ¡£ Microsoft IE 9¡¢10ºÍ11ÖÐVBScriptÒýÇæ´¦Öóͷ£Äڴ湤¾ßµÄ·½·¨±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룬Ëð»µÄÚ´æ¡£

Microsoft Scripting Engine

CVE-2019-1217

ÑÏÖØ

Chakra Scripting Engine ÄÚ´æÆÆËðÎó²î

Microsoft ChakraCoreºÍMicrosoft Edge¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£ChakraCoreÊÇʹÓÃÔÚEdgeä¯ÀÀÆ÷ÖеÄÒ»¸ö¿ªÔ´µÄChakraJavaScript¾ç±¾ÒýÇæµÄ½¹µã²¿·Ö£¬Ò²¿É×÷Ϊµ¥¶ÀµÄJavaScriptÒýÇæÊ¹Óá£Microsoft EdgeÊÇÒ»¿îWindows 10Ö®ºó°æ±¾ÏµÍ³¸½´øµÄWebä¯ÀÀÆ÷¡£ Microsoft EdgeºÍChakraCoreÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룬Ëð»µÄÚ´æ¡£

Microsoft Scripting Engine

CVE-2019-1221

ÑÏÖØ

Scripting Engine ÄÚ´æÆÆËðÎó²î

¾ç±¾ÒýÇæÔÚ Internet Explorer Öд¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨Öб£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¸ÃÎó²î¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷Õß¿ÉÒÔÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂëµÄ·½·¨Ëð»µÄÚ´æ¡£ÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß±ã¿É¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó×°ÖóÌÐò£»Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß½¨ÉèÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£

ÔÚ»ùÓÚ Web µÄ¹¥»÷ÇéÐÎÖУ¬¹¥»÷Õß¿ÉÄÜÓµÓÐÒ»¸öÖ¼ÔÚͨ¹ý Internet Explorer ʹÓôËÎó²îµÄ¾­ÌØÊâÉè¼ÆµÄÍøÕ¾£¬È»ºóÓÕʹÓû§Éó²é¸ÃÍøÕ¾¡£¹¥»÷ÕßÒ²¿ÉÄÜÔÚÍÐ¹Ü IE ·ºÆðÒýÇæµÄÓ¦ÓóÌÐò»ò Microsoft Office ÎĵµÖÐǶÈë±êÓС°Çå¾²³õʼ»¯¡±µÄ ActiveX ¿Ø¼þ¡£¹¥»÷Õß»¹¿ÉÄÜʹÓÃÔâµ½ÈëÇÖµÄÍøÕ¾ÒÔ¼°½ÓÊÜ»òÍйÜÓû§ÌṩµÄÄÚÈÝ»ò¹ã¸æµÄÍøÕ¾¡£ÕâÐ©ÍøÕ¾¿ÉÄܰüÀ¨¿ÉÒÔʹÓôËÎó²îµÄ¾­ÌØÊâÉè¼ÆµÄÄÚÈÝ¡£

Microsoft Scripting Engine

CVE-2019-1236

ÑÏÖØ

VBScript Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft Internet Explorer£¨IE£©ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄÒ»¿îWindows²Ù×÷ϵͳ¸½´øµÄWebä¯ÀÀÆ÷¡£VBScript EngineÊÇÆäÖеÄÒ»¸öVBScript¾ç±¾ÓïÑÔÒýÇæ¡£ Microsoft IE 9¡¢10ºÍ11ÖÐVBScriptÒýÇæ´¦Öóͷ£Äڴ湤¾ßµÄ·½·¨±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룬Ëð»µÄÚ´æ¡£

Microsoft Scripting Engine

CVE-2019-1237

ÑÏÖØ

Chakra Scripting Engine ÄÚ´æÆÆËðÎó²î

Microsoft ChakraCoreºÍMicrosoft Edge¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£ChakraCoreÊÇʹÓÃÔÚEdgeä¯ÀÀÆ÷ÖеÄÒ»¸ö¿ªÔ´µÄChakraJavaScript¾ç±¾ÒýÇæµÄ½¹µã²¿·Ö£¬Ò²¿É×÷Ϊµ¥¶ÀµÄJavaScriptÒýÇæÊ¹Óá£Microsoft EdgeÊÇÒ»¿îWindows 10Ö®ºó°æ±¾ÏµÍ³¸½´øµÄWebä¯ÀÀÆ÷¡£ Microsoft ChakraCoreºÍMicrosoft EdgeÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룬Ëð»µÄÚ´æ¡£

Microsoft Scripting Engine

CVE-2019-1300

ÑÏÖØ

Chakra Scripting Engine ÄÚ´æÆÆËðÎó²î

Microsoft ChakraCoreºÍMicrosoft Edge¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£ChakraCoreÊÇʹÓÃÔÚEdgeä¯ÀÀÆ÷ÖеÄÒ»¸ö¿ªÔ´µÄChakraJavaScript¾ç±¾ÒýÇæµÄ½¹µã²¿·Ö£¬Ò²¿É×÷Ϊµ¥¶ÀµÄJavaScriptÒýÇæÊ¹Óá£Microsoft EdgeÊÇÒ»¿îWindows 10Ö®ºó°æ±¾ÏµÍ³¸½´øµÄWebä¯ÀÀÆ÷¡£ Microsoft ChakraCoreºÍMicrosoft EdgeÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룬Ëð»µÄÚ´æ¡£

Microsoft Scripting Engine

CVE-2019-1280

ÑÏÖØ

LNK Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft WindowsºÍMicrosoft Windows Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft WindowsÊÇÒ»Ì×СÎÒ˽¼Ò×°±¸Ê¹ÓõIJÙ×÷ϵͳ¡£Microsoft Windows ServerÊÇÒ»Ì×·þÎñÆ÷²Ù×÷ϵͳ¡£ Microsoft WindowsºÍMicrosoft Windows ServerÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õ߿ɽèÖú´øÓжñÒâ.LNKÎļþºÍ¹ØÁªµÄ¶ñÒâ¶þ½øÖÆÎļþµÄÒÆ³ýÇý¶¯Æ÷»òÔ¶³Ì¹²ÏíʹÓøÃÎó²îÖ´ÐдúÂë¡£

Microsoft Windows

CVE-2019-1306

ÑÏÖØ

Azure DevOps and Team Foundation Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft Team Foundation ServerºÍMicrosoft Azure DevOps Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft Team Foundation ServerÊÇÒ»Ì×Ó¦ÓóÌÐòÉúÃüÖÜÆÚÖÎÀí£¨ALM£©¹¤¾ßÌ×¼þÖеÄÍŶÓЭ×÷ƽ̨¡£¸Ãƽ̨°üÀ¨µÄ´úÂëÖÎÀí¡¢ÏîÄ¿ÖÎÀíµÈ¹¦Ð§¡£Microsoft Azure DevOps ServerÊÇÒ»Ì×Èí¼þ¿ª·¢Ð­×÷¹¤¾ß¡£¸Ã²úÆ·°üÀ¨¹²Ïí´úÂë¡¢ÊÂÇé¸ú×ÙºÍÈí¼þÐû²¼µÈ¹¦Ð§¡£ Microsoft Team Foundation Server 2018 Update 3.2°æ±¾¡¢Azure DevOps Server 2019 Update 1°æ±¾ºÍ2019.0.1°æ±¾Öб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓÐ׼ȷÑéÖ¤ÊäÈë¡£¹¥»÷Õß¿Éͨ¹ýÉÏ´«ÌØÖƵÄÎļþʹÓøÃÎó²îÔÚTFS»òADO·þÎñÕË»§µÄÉÏÏÂÎÄÖÐÔÚ·þÎñÆ÷ÉÏÖ´ÐдúÂë¡£

Team Foundation Server

CVE-2019-0787

ÑÏÖØ

Remote Desktop Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft WindowsºÍMicrosoft Windows Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft WindowsÊÇÒ»Ì×СÎÒ˽¼Ò×°±¸Ê¹ÓõIJÙ×÷ϵͳ¡£Microsoft Windows ServerÊÇÒ»Ì×·þÎñÆ÷²Ù×÷ϵͳ¡£Windows Remote Desktop ClientÊÇÆäÖеÄÒ»¸öWindowsÔ¶³Ì×ÀÃæ¿Í»§¶Ë³ÌÐò¡£ Microsoft Windows Remote Desktop ClientÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õß¿Éͨ¹ýÔÚÉç»á¹¤³Ì¡¢DNS²¡¶¾»òʹÓÃÖÐÐÄÈË(MITM)ÊÖÒÕÓÕµ¼Óû§ÅþÁ¬¶ñÒâµÄ·þÎñÆ÷ʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£

Windows RDP

CVE-2019-0788

ÑÏÖØ

Remote Desktop Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft WindowsºÍMicrosoft Windows Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft WindowsÊÇÒ»Ì×СÎÒ˽¼Ò×°±¸Ê¹ÓõIJÙ×÷ϵͳ¡£Microsoft Windows ServerÊÇÒ»Ì×·þÎñÆ÷²Ù×÷ϵͳ¡£Windows Remote Desktop ClientÊÇÆäÖеÄÒ»¸öWindowsÔ¶³Ì×ÀÃæ¿Í»§¶Ë³ÌÐò¡£ Microsoft Windows Remote Desktop ClientÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õß¿Éͨ¹ýÔÚÉç»á¹¤³Ì¡¢DNS ²¡¶¾»òʹÓÃÖÐÐÄÈË (MITM) ÊÖÒÕÓÕµ¼Óû§ÅþÁ¬¶ñÒâµÄ·þÎñÆ÷ʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£

Windows RDP

CVE-2019-1290

ÑÏÖØ

Remote Desktop Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft WindowsºÍMicrosoft Windows Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft WindowsÊÇÒ»Ì×СÎÒ˽¼Ò×°±¸Ê¹ÓõIJÙ×÷ϵͳ¡£Microsoft Windows ServerÊÇÒ»Ì×·þÎñÆ÷²Ù×÷ϵͳ¡£Windows Remote Desktop ClientÊÇÆäÖеÄÒ»¸öWindowsÔ¶³Ì×ÀÃæ¿Í»§¶Ë³ÌÐò¡£Microsoft Windows Remote Desktop ClientÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õß¿Éͨ¹ýÔÚÉç»á¹¤³Ì¡¢DNS ²¡¶¾»òʹÓÃÖÐÐÄÈË (MITM) ÊÖÒÕÓÕµ¼Óû§ÅþÁ¬¶ñÒâµÄ·þÎñÆ÷ʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£

Windows RDP

CVE-2019-1291

ÑÏÖØ

Remote Desktop Client Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft WindowsºÍMicrosoft Windows Server¶¼ÊÇÃÀ¹ú΢Èí£¨Microsoft£©¹«Ë¾µÄ²úÆ·¡£Microsoft WindowsÊÇÒ»Ì×СÎÒ˽¼Ò×°±¸Ê¹ÓõIJÙ×÷ϵͳ¡£Microsoft Windows ServerÊÇÒ»Ì×·þÎñÆ÷²Ù×÷ϵͳ¡£Windows Remote Desktop ClientÊÇÆäÖеÄÒ»¸öWindowsÔ¶³Ì×ÀÃæ¿Í»§¶Ë³ÌÐò¡£ Microsoft Windows Remote Desktop ClientÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚÅþÁ¬¿Í»§¶ËµÄÅÌËã»úÉÏÖ´ÐÐí§Òâ´úÂë¡£

Windows RDP


¡ñÐÞ¸´½¨Òé


ÏÖÔÚ£¬Î¢Èí¹Ù·½ÒѾ­Ðû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ïì¡£


¾¡¿ì½ÓÄÉÐÞ²¹²½·¥£¬ÒÔ×èֹDZÔÚµÄÇå¾²Íþв¡£ÏëÒª¾ÙÐиüУ¬Ö»Ðèתµ½ÉèÖáú¸üкÍÇå¾²¡úWindows ¸üСú¼ì²é¸üУ¬»òÕßÒ²¿ÉÒÔͨ¹ýÊÖ¶¯¾ÙÐиüС£


¡ñ²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/releasenotedetail/24f46f0a-489c-e911-a994-000d3a33c573