΢ÈíÐû²¼2Ô·Ý9¸öÇ徲ͨ¸æ ÐÞ¸´ÁË56¸öÇå¾²Îó²î (Alert2015-02)
2015-02-11
ÐÎò£º
΢ÈíÐû²¼ÁË2Ô·Ý9¸öÇ徲ͨ¸æ£ºMS15-009µ½MS15-017£¬ÐÞ¸´ÁËMicrosoft Windows¡¢Internet Explorer¡¢Office¡¢Graphics¡¢GP¡¢VMM¡¢KMDÖеÄÇå¾²Îó²î¡£
ÎÒÃÇÇ¿ÁÒ½¨ÒéʹÓÃWindows²Ù×÷ϵͳµÄÓû§Á¬Ã¦¼ì²éÒ»ÏÂÄúµÄϵͳÊÇ·ñÊÜ´ËÎó²îÓ°Ï죬
²¢Æ¾Ö¤ÎÒÃÇÌṩµÄ½â¾öÒªÁìÓèÒÔ½â¾ö¡£
ÆÊÎö£º
======
1¡¢MS15-009
´Ë¸üнâ¾öÁËInternet ExplorerÄÚ1¸ö¹ûÕæ±¨¸æµÄÎó²îºÍ40¸öÉñÃØ±¨¸æµÄÎó²î¡£ÈôÊÇ
Óû§ÓÃIEÉó²éÌØÖÆµÄÍøÒ³£¬×îÑÏÖØµÄÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
ÊÜÓ°ÏìÈí¼þ:
Internet Explorer 6
Internet Explorer 7
Internet Explorer 8
Internet Explorer 9
Internet Explorer 10
Internet Explorer 11
Îó²îÐÎò£º
1£©¶à¸öȨÏÞÌáÉýÎó²î - CVE-2015-0054¡¢CVE-2015-0055IEÔÚijЩÇéÐÎÏÂûÓÐ׼ȷÑé֤ȨÏÞ±£´æÈ¨ÏÞÌáÉýÎó²î£¬¿Éµ¼ÖÂÒÔÌáÉýµÄȨÏÞÖ´Ðо籾¡£
2£©IEÄÚ¶à¸öÄÚ´æÆÆËðÎó²î
Internet Explorer ûÓÐ׼ȷ»á¼ûÄڴ湤¾ß£¬ÔÚʵÏÖÉϱ£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÀÖ³É
ʹÓúó¿ÉÆÆËðÄڴ棬ÔÚÄ¿½ñÓû§È¨ÏÞÏÂÖ´ÐÐí§Òâ´úÂë¡£ÕâЩÎó²î°üÀ¨£º
IEÄÚ´æÆÆËðÎó²î CVE-2014-8967
IEÄÚ´æÆÆËðÎó²î CVE-2015-0017
IEÄÚ´æÆÆËðÎó²î CVE-2015-0018
IEÄÚ´æÆÆËðÎó²î CVE-2015-0019
IEÄÚ´æÆÆËðÎó²î CVE-2015-0020
IEÄÚ´æÆÆËðÎó²î CVE-2015-0021
IEÄÚ´æÆÆËðÎó²î CVE-2015-0022
IEÄÚ´æÆÆËðÎó²î CVE-2015-0023
IEÄÚ´æÆÆËðÎó²î CVE-2015-0025
IEÄÚ´æÆÆËðÎó²î CVE-2015-0026
IEÄÚ´æÆÆËðÎó²î CVE-2015-0027
IEÄÚ´æÆÆËðÎó²î CVE-2015-0028
IEÄÚ´æÆÆËðÎó²î CVE-2015-0029
IEÄÚ´æÆÆËðÎó²î CVE-2015-0030
IEÄÚ´æÆÆËðÎó²î CVE-2015-0031
IEÄÚ´æÆÆËðÎó²î CVE-2015-0035
IEÄÚ´æÆÆËðÎó²î CVE-2015-0036
IEÄÚ´æÆÆËðÎó²î CVE-2015-0037
IEÄÚ´æÆÆËðÎó²î CVE-2015-0038
IEÄÚ´æÆÆËðÎó²î CVE-2015-0039
IEÄÚ´æÆÆËðÎó²î CVE-2015-0040
IEÄÚ´æÆÆËðÎó²î CVE-2015-0041
IEÄÚ´æÆÆËðÎó²î CVE-2015-0042
IEÄÚ´æÆÆËðÎó²î CVE-2015-0043
IEÄÚ´æÆÆËðÎó²î CVE-2015-0044
IEÄÚ´æÆÆËðÎó²î CVE-2015-0045
IEÄÚ´æÆÆËðÎó²î CVE-2015-0046
IEÄÚ´æÆÆËðÎó²î CVE-2015-0048
IEÄÚ´æÆÆËðÎó²î CVE-2015-0049
IEÄÚ´æÆÆËðÎó²î CVE-2015-0050
IEÄÚ´æÆÆËðÎó²î CVE-2015-0052
IEÄÚ´æÆÆËðÎó²î CVE-2015-0053
IEÄÚ´æÆÆËðÎó²î CVE-2015-0066
IEÄÚ´æÆÆËðÎó²î CVE-2015-0067
IEÄÚ´æÆÆËðÎó²î CVE-2015-0068
ÔÝʱ½â¾ö¼Æ»®£º
* ÉèÖû¥ÁªÍøºÍÄÚÁªÍøÇå¾²ÇøÓòÉèÖÃΪ¡°¸ß¡±
* ÉèÖÃIEÔÚÔËÐÐÔ˶¯¾ç±¾Ö®Ìõ¼þʾ»òÖ±½Ó½ûÓá£
3£©IE ASLRÈÆ¹ýÎó²î CVE-2015-0051¡¢CVE-2015-0069¡¢CVE-2015-0071
µ±IEûÓÐʹÓÃASLRÇå¾²¹¦Ð§Ê±±£´æÇå¾²ÏÞÖÆÈÆ¹ýÎó²î£¬¿Éʹ¹¥»÷ÕßÕ¹ÍûÌØ¶¨Å²ÓÃÕ»
ÄÚijЩָÁîµÄÆ«ÒÆ¡£
4£©IE¿çÓòÐÅϢй¶Îó²î CVE-2015-0070
IEûÓÐ׼ȷʵÏÖ¿çÕ¾Õ½ÂÔ£¬±£´æÐÅϢй¶Îó²î£¬¹¥»÷Õß¿ÉʹÓôËÎó²î»ñÈ¡ÆäËûÓòµÄÐÅÏ¢¡£
2¡¢MS15-010
´Ë¸üнâ¾öÁËMicrosoft WindowsÄÚ1¸ö¹ûÕæ±¨¸æ¼°5¸öÉñÃØ±¨¸æµÄÎó²î¡£ÈôÊÇÓû§´ò
¿ªÈ«ÐĽṹµÄÎļþ»òä¯ÀÀ°üÀ¨Ç¶ÈëʽTrueType×ÖÌåµÄ¿ÉÒÉÍøÕ¾£¬¸ÃÎó²î¿Éµ¼ÖÂÔ¶³Ì
´úÂëÖ´ÐС£
ÊÜÓ°ÏìÈí¼þ£º
Windows Server 2003
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 8
Windows 8.1
Windows Server 2012
Windows Server 2012 R2
Windows RT
Windows RT 8.1
Îó²îÐÎò£º
1£©Win32kȨÏÞÌáÉýÎó²î - CVE-2015-0003
Win32k.sysûÓÐ׼ȷ´¦Öóͷ£Äڴ湤¾ßʱ±£´æÈ¨ÏÞÌáÉýÎó²î£¬ÀÖ³ÉʹÓúó¿Éµ¼ÖÂȨÏÞÌáÉý¡£
ÔÝʱ½â¾ö¼Æ»®£º
* ÉèÖÃ×¢²á±íÏî½ûÓÿÕÒ³Ó³É䣨½öWindows 7£©
2£©CNGÇå¾²¹¦Ð§ÈƹýÎó²î - CVE-2015-0010
CNGÄÚºËģʽÇý¶¯³ÌÐò(cng.sys)ûÓÐ׼ȷÑéÖ¤²¢Ö´ÐÐÄ£Äâ¼¶±ðʱ±£´æÇå¾²ÏÞÖÆÈÆ¹ý
Îó²î£¬¿Éµ¼ÖÂÐÅϢй¶¸ø¹¥»÷Õß¡£
3£©Win32kȨÏÞÌáÉýÎó²î - CVE-2015-0057
Win32k.sysûÓÐ׼ȷ´¦Öóͷ£Äڴ湤¾ßʱ±£´æÈ¨ÏÞÌáÉýÎó²î£¬ÀÖ³ÉʹÓúó¿Éµ¼ÖÂȨÏÞÌáÉý¡£
4£©Windows¹â±ê¹¤¾ßË«ÖØÊÍ·ÅÎó²î - CVE-2015-0058
Win32k.sysÓÉÓÚË«ÖØÊÍ·ÅÎÊÌ⣬±£´æÈ¨ÏÞÌáÉýÎó²î£¬ÀÖ³ÉʹÓúó¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐС£
5£©TrueType×ÖÌåÆÊÎöÔ¶³Ì´úÂëÖ´ÐÐÎó²î - CVE-2015-0059
Win32k.sysûÓÐ׼ȷ´¦Öóͷ£TrueType×ÖÌ壬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÀÖ³ÉʹÓúó¿Éµ¼ÖÂ
ÔÚÄÚºËģʽí§Òâ´úÂëÖ´ÐС£
ÔÝʱ½â¾ö¼Æ»®£º
* եȡ»á¼û T2EMBED.DLL
6£©Window×ÖÌåÇý¶¯¾Ü¾ø·þÎñÎó²î - CVE-2015-0060
Win32k.sysÔÚWindow×ÖÌåÇý¶¯ÊµÑéËõ·Å×ÖÌåʱ±£´æ¾Ü¾ø·þÎñÎó²î£¬ÀÖ³ÉʹÓúó¿Éµ¼ÖÂ
ÊÜÓ°ÏìÅÌËã»ú×èÖ¹ÏìÓ¦¡£
ÔÝʱ½â¾ö¼Æ»®£º
* եȡ»á¼û T2EMBED.DLL
3¡¢MS15-011
´Ë¸üнâ¾öÁËMicrosoft WindowsÄÚ1¸öÉñÃØ±¨¸æµÄÎó²î¡£ÈôÊǹ¥»÷ÕßÓÕʹÓòÉèÖÃϵͳ
Óû§ÅþÁ¬µ½¶ñÒâÍøÕ¾£¬Ôò¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐС£
ÊÜÓ°ÏìÈí¼þ£º
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 8
Windows 8.1
Windows Server 2012
Windows Server 2012 R2
Windows RT
Windows RT 8.1
Îó²îÐÎò£º
×éÕ½ÂÔÔ¶³Ì´úÂëÖ´ÐÐÎó²î - CVE-2015-0008
µ±ÓòÅþÁ¬Ï½µµÍ¬½Óµ½Óò¿ØÖÆÆ÷ʱ£¬×éÕ½ÂÔÎüÊÕ¼°Ó¦ÓÃÕ½ÂÔÊý¾Ýʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐ
Îó²î¡£
4¡¢MS15-012
´Ë¸üнâ¾öÁËMicrosoft OfficeÄÚ3¸öÉñÃØ±¨¸æµÄÎó²î¡£ÈôÊÇÓû§·¿ªÈ«ÐĽṹµÄ
OfficeÎļþ£¬´ËÎó²î¿ÉÔÊÐíÔ¶³Ì´úÂëÖ´ÐС£
ÊÜÓ°ÏìÈí¼þ£º
Microsoft Office 2007
Microsoft Office 2010
Microsoft Office 2013
Îó²îÐÎò£º
1£©ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î - CVE-2015-0063
Microsoft ExcelÆÊÎöÈ«ÐĽṹµÄOfficeÎļþʱûÓÐ׼ȷ´¦Öóͷ£Äڴ湤¾ß£¬±£´æÔ¶³Ì
´úÂëÖ´ÐÐÎó²î£¬¿Éµ¼ÖÂÄÚ´æÆÆËð£¬Ö´ÐÐí§Òâ´úÂë¡£
2£©OfficeÔ¶³Ì´úÂëÖ´ÐÐÎó²î - CVE-2015-0064
WordÆÊÎöÈ«ÐĽṹµÄOfficeÎļþʱûÓÐ׼ȷ´¦Öóͷ£Äڴ湤¾ß£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬
¿Éµ¼ÖÂÄÚ´æÆÆËð£¬Ö´ÐÐí§Òâ´úÂë¡£
3£©OneTableDocumentStreamÔ¶³Ì´úÂëÖ´ÐÐÎó²î - CVE-2015-0065
WordÆÊÎöÈ«ÐĽṹµÄOfficeÎļþʱûÓÐ׼ȷ´¦Öóͷ£Äڴ湤¾ß£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬
¿Éµ¼ÖÂÄÚ´æÆÆËð£¬Ö´ÐÐí§Òâ´úÂë¡£
5¡¢MS15-013
´Ë¸üнâ¾öÁËMicrosoft OfficeÄÚ1¸ö¹ûÕæ±¨¸æµÄÎó²î¡£ÈôÊÇÓû§·¿ªÈ«ÐĽṹµÄ
OfficeÎļþ£¬´ËÎó²î¿ÉÔÊÐíÈÆ¹ýÇå¾²¹¦Ð§¡£
ÊÜÓ°ÏìÈí¼þ£º
Microsoft Office 2007
Microsoft Office 2010
Microsoft Office 2013
Îó²îÐÎò£º
Office×é¼þÊͷźóÖØÊ¹ÓÃÎó²î - CVE-2014-6362
Microsoft OfficeûÓÐ׼ȷʹÓÃASLRÇå¾²¹¦Ð§Ê±±£´æÇå¾²¹¦Ð§ÈƹýÎó²î£¬¿Éʹ¹¥»÷Õß
Äܹ»Õ¹ÍûÌØ¶¨Å²ÓÃջijЩָÁîµÄÆ«ÒÆ¡£
ÔÝʱ½â¾ö¼Æ»®£º
* ʹÓÃEMETÄÚµÄMandatory ASLR mitigation¡£
6¡¢MS15-014
´Ë¸üнâ¾öÁËMicrosoft WindowsÄÚ1¸öÉñÃØ±¨¸æµÄÎó²î¡£ÈôÊǹ¥»÷ÕßʹÓÃÖÐÐÄÈ˹¥»÷
Ôì³ÉGroup Policy Security Configuration EngineÕ½ÂÔÎļþË𻵣¬Ôò¿Éµ¼ÖÂÇå¾²
¹¦Ð§Èƹý¡£
ÊÜÓ°ÏìÈí¼þ£º
Windows Server 2003
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 8
Windows 8.1
Windows Server 2012
Windows Server 2012 R2
Windows RT
Windows RT 8.1
Îó²îÐÎò£º
×éÕ½ÂÔÇå¾²¹¦Ð§ÈƹýÎó²î - CVE-2015-0009
×éÕ½ÂÔÓ¦ÓÃÖб£´æÇå¾²¹¦Ð§ÈƹýÎó²î£¬¿ÉʹÖÐÐÄÈ˹¥»÷ÕßÐÞ¸ÄÓò¿ØÖÆÆ÷¶Ô¿Í»§¶ËµÄ
ÏìÓ¦¡£
7¡¢MS15-015
´Ë¸üнâ¾öÁËMicrosoft WindowsÄÚ1¸öÉñÃØ±¨¸æµÄÎó²î¡£´ËÎó²î¿Éʹ¹¥»÷ÕßʹÓÃȱÉÙ
Ä£Äâ²ãÇå¾²¼ì²éÌáÉýÀú³Ì½¨ÉèÖеÄȨÏÞ¡£
ÊÜÓ°ÏìÈí¼þ£º
Windows 7
Windows Server 2008 R2
Windows 8
Windows 8.1
Windows Server 2012
Windows Server 2012 R2
Windows RT
Windows RT 8.1
Îó²îÐÎò£º
Windows½¨ÉèÀú³ÌȨÏÞÌáÉýÎó²î - CVE-2015-0062
WindowsûÓÐ׼ȷÑéÖ¤²¢Ö´ÐÐÄ£Äâ²ã£¬±£´æÈ¨ÏÞÌáÉýÎó²î£¬¿Éµ¼ÖÂÈÆ¹ýÄ£Äâ²ãÇå¾²¼ì²é
»ñÈ¡ÌáÉýµÄȨÏÞ¡£
8¡¢MS15-016
´Ë¸üнâ¾öÁËMicrosoft WindowsÄÚ1¸öÉñÃØ±¨¸æµÄÎó²î¡£ÈôÊÇÓû§Éó²é°üÀ¨ÌØÖÆTIFF
ͼÐεÄÍøÕ¾£¬´ËÎó²î¿Éµ¼ÖÂÐÅϢй¶¡£
ÊÜÓ°ÏìÈí¼þ£º
Windows Server 2003
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 8
Windows 8.1
Windows Server 2012
Windows Server 2012 R2
Windows RT
Windows RT 8.1
Îó²îÐÎò£º
TIFFÀú³ÌÐÅϢй¶Îó²î - CVE-2015-0061
WindowsÔÚÆÊÎöijЩTIFFͼÐÎÃûÌÃÎļþʱ£¬Ã»ÓÐ׼ȷ´¦Öóͷ£Î´³õʼ»¯Äڴ棬±£´æÐÅϢй¶
Îó²î£¬¿Éµ¼Ö¹¥»÷Õß»ñÈ¡Ãô¸ÐÐÅÏ¢¡£
9¡¢MS15-017
´Ë¸üнâ¾öÁËVirtual Machine ManagerÄÚ1¸öÉñÃØ±¨¸æµÄÎó²î¡£ÈôÊÇÓû§µÇ¼µ½ÊÜ
Ó°Ïìϵͳ£¬´ËÎó²î¿ÉÔÊÐíȨÏÞÌáÉý¡£
ÊÜÓ°ÏìÈí¼þ£º
Microsoft System Center Virtual Machine Manager
Îó²îÐÎò£º
Virtual Machine ManagerȨÏÞÌáÉýÎó²î - CVE-2015-0012
µ±VMMûÓÐ׼ȷÑéÖ¤Óû§½Çɫʱ±£´æÇå¾²Îó²î£¬¿Éµ¼ÖÂȨÏÞÌáÉý¡£
³§ÉÌ״̬£º
==========
³§ÉÌÒѾÐû²¼ÁËÏà¹Ø²¹¶¡£¬ÇëʵʱʹÓÃWindowsµÄ×Ô¶¯¸üлú֯װÖÃ×îв¹¶¡¡£
¸½¼ÓÐÅÏ¢£º
==========
1. http://technet.microsoft.com/security/bulletin/MS15-009
2. http://technet.microsoft.com/security/bulletin/MS15-010
3. http://technet.microsoft.com/security/bulletin/MS15-011
4. http://technet.microsoft.com/security/bulletin/MS15-012
5. http://technet.microsoft.com/security/bulletin/MS15-013
6. http://technet.microsoft.com/security/bulletin/MS15-014
7. http://technet.microsoft.com/security/bulletin/MS15-015
8. http://technet.microsoft.com/security/bulletin/MS15-016
9. http://technet.microsoft.com/security/bulletin/MS15-017

AG¹«Ë¾ÔÆ





