¡¾Íþвͨ¸æ¡¿Î¢ÈíÐû²¼Çå¾²¸üÐÂÐÞ¸´¶à¸ö¸ßΣÎó²î
2020-01-15
Ò». Îó²î¸ÅÊö
ÍâµØÊ±¼ä1ÔÂ14ÈÕ£¬Î¢ÈíÐû²¼ÁË×îеÄÔ¶Ȳ¹¶¡¸üУ¬ÐÞ¸´ÁË49¸ö´ÓÐÅϢй¶µ½Ô¶³Ì´úÂëÖ´ÐеÄÇå¾²ÎÊÌ⣬²úÆ·Éæ¼°Microsoft Windows¡¢Internet Explorer¡¢Microsoft Office¡¢Microsoft Office ServicesºÍWebÓ¦Óá¢ASP.NET Core¡¢.NET Core¡¢.NET Framework¡¢OneDrive for Android¡¢Microsoft Dynamics¡£
ÆäÖÐÓÐÈçÏÂÒªº¦ÎÊÌâÇëÏà¹ØÓû§×ÅÖØ¾ÙÐйØ×¢£º
CVE-2020-0601£ºWindows CryptoAPI ÓÕÆÎó²î
CVE-2020-0609/0610£ºWindowsÔ¶³Ì×ÀÃæÐÒ飨RDP£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î
CVE-2020-0611£ºÔ¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³ÌÖ´ÐдúÂëÎó²î
CVE-2020-0620£ºMicrosoft Cryptographic Services ÌØÈ¨ÌáÉýÎó²î
×¢£º
΢ÈíÐû²¼¶Ô Windows 7¡¢Windows Server 2008 R2 ºÍ Windows Server 2008 µÄÖ§³Ö½«ÓÚ 2020 Äê 1 Ô 14 ÈÕÖÕÖ¹£¬²¿·ÖÎó²îδÌṩ²¹¶¡£¬½¨ÒéÓû§Éý¼¶µ½×îа汾ϵͳ£¬¹Ø×¢Î¢Èí¹Ù·½Ç徲ͨ¸æ¡£

²Î¿¼Á´½Ó£º
https://portal.msrc.microsoft.com/zh-cn/security-guidance/releasenotedetail/2020-Jan
¶þ. Ó°Ïì¹æÄ£
CVE-2020-0601£º
ÊÜÓ°ÏìÇÒÔÚÖ§³Ö¹æÄ£°æ±¾
- Windows 10
- Windows Server 2016
- Windows Server 2019
¸üÏêϸ°æ±¾ÐÅÏ¢Çë²Î¿¼¹Ù·½Í¨¸æ¡£
https://portal.msrc.microsoft.com/zh-cn/security-guidance/advisory/CVE-2020-0601
CVE-2020-0609/0610£º
ÊÜÓ°ÏìÇÒÔÚÖ§³Ö¹æÄ£°æ±¾
- Windows Server 2012
- Windows Server 2012 R2
- Windows Server 2016
- Windows Server 2019
¹Ù·½Í¨¸æ£º
https://portal.msrc.microsoft.com/zh-cn/security-guidance/advisory/CVE-2020-0609
CVE-2020-0611£º
ÊÜÓ°ÏìÇÒÔÚÖ§³Ö¹æÄ£°æ±¾
- Windows 10
- Windows 7
- Windows 8.1
- Windows RT 8.1
- Windows Server 2008
- Windows Server 2012
- Windows Server 2016
- Windows Server 2019
¸üÏêϸ°æ±¾ÐÅÏ¢Çë²Î¿¼¹Ù·½Í¨¸æ¡£
https://portal.msrc.microsoft.com/zh-cn/security-guidance/advisory/CVE-2020-0611
CVE-2020-0620£º
ÊÜÓ°ÏìÇÒÔÚÖ§³Ö¹æÄ£°æ±¾
- Windows 10
- Windows 7
- Windows 8.1
- Windows RT 8.1
- Windows Server 2008
- Windows Server 2012
- Windows Server 2012 R2
- Windows Server 2016
- Windows Server 2019
¸üÏêϸ°æ±¾ÐÅÏ¢Çë²Î¿¼¹Ù·½Í¨¸æ¡£
https://portal.msrc.microsoft.com/zh-cn/security-guidance/advisory/CVE-2020-0620
ÆäËûÇå¾²ÎÊÌâÊÜÓ°Ïìϵͳ°æ±¾Çë²éÔĹٷ½Í¨¸æ¡£
Èý. Îó²î·À»¤
3.1 ²¹¶¡¸üÐÂ
ÏÖÔÚ΢Èí¹Ù·½ÒÑÕë¶ÔÊÜÖ§³ÖµÄϵͳ°æ±¾Ðû²¼ÐÞ¸´ÁËÒÔÉÏÎó²îµÄÇå¾²²¹¶¡£¬Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì×°Öò¹¶¡¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£º
https://portal.msrc.microsoft.com/zh-cn/security-guidance/releasenotedetail/2020-Jan
×¢£ºÓÉÓÚÍøÂçÎÊÌâ¡¢ÅÌËã»úÇéÐÎÎÊÌâµÈÔµ¹ÊÔÓÉ£¬Windows UpdateµÄ²¹¶¡¸üпÉÄÜ·ºÆðʧ°Ü¡£Óû§ÔÚ×°Öò¹¶¡ºó£¬Ó¦ÊµÊ±¼ì²é²¹¶¡ÊÇ·ñÀֳɸüС£
ÓÒ¼üµã»÷Windows»Õ±ê£¬Ñ¡Ôñ“ÉèÖÃ(N)”£¬Ñ¡Ôñ“¸üкÍÇå¾²”-“Windows¸üД£¬Éó²é¸ÃÒ³ÃæÉϵÄÌáÐÑÐÅÏ¢£¬Ò²¿Éµã»÷“Éó²é¸üÐÂÀúÊ·¼Í¼”Éó²éÀúÊ·¸üÐÂÇéÐΡ£
Õë¶ÔδÀÖ³É×°ÖõĸüУ¬¿Éµã»÷¸üÐÂÃû³ÆÌø×ªµ½Î¢Èí¹Ù·½ÏÂÔØÒ³Ãæ£¬½¨ÒéÓû§µã»÷¸ÃÒ³ÃæÉϵÄÁ´½Ó£¬×ªµ½“Microsoft¸üÐÂĿ¼”ÍøÕ¾ÏÂÔØ×ÔÁ¦³ÌÐò°ü²¢×°Öá£
3.2 Windows 7 ϵͳÉý¼¶
ÇëÈÔÔÚʹÓÃWindows 7ϵͳµÄÓû§¾¡¿ì¸üÐÂϵͳ£¬ÒÔ»ñµÃ΢Èí¹Ù·½ÌṩµÄÊÖÒÕÖ§³Ö¡£
ÏÖÔÚ£¬Í¨¹ý΢Èí¹Ù·½ÌṩµÄ“ýÌ彨É蹤¾ß”¿ÉÒÔʵÏÖWindows 7µ½Windows 10µÄÖ±½ÓÉý¼¶£¬¸Ã²Ù×÷¿ÉÒÔÖ±½ÓÔÚWin7ϵͳÉÏÍê³É£¬¿ÉÒÔ±£´æÔ²Ù×÷ϵͳÖеÄСÎÒ˽¼ÒÎļþ¼°Ó¦ÓóÌÐò¡£Ïêϸ·½·¨ÈçÏ£º
1¡¢ÉúÑIJ¢¹Ø±ÕÄ¿½ñ´¦Öóͷ£µÄËùÓÐÎļþ£¬¶Ô²Ù×÷ϵͳÖеÄÖ÷ÒªÎļþ¾ÙÐб¸·Ý¡£
2¡¢»á¼û£º https://www.microsoft.com/en-us/software-download/windows10 £¬µã»÷“Download Tool Now”°´Å¥£¬ÏÂÔØMedia Creation Tool¹¤¾ß¡£
3¡¢ÔËÐÐMedia Creation Tool¹¤¾ß£¬ÔÚͨ¹ýÓû§ÐÒé²¢ÆÚ´ýÒ»¶Îʱ¼äºó£¬Ñ¡Ôñ“Á¬Ã¦Éý¼¶Õą̂µçÄÔ”£¬²¢µã»÷ÏÂÒ»²½¡£
4¡¢¹¤¾ß½«×Ô¶¯ÏÂÔØWindows 10£¬ÔÚÏÂÔØÍê³Éºó£¬Ñ¡Ôñ“±£´æËùÓÐÓ¦ÓúÍÎļþ”£¨Ö÷Òª£¡£©£¬µã»÷“×°ÖÔ¡£
5¡¢ÔÚ×°ÖÃÀú³ÌÖУ¬½«»á×Ô¶¯ÖØÆô¶à´Î£¬ÇëÄÍÐÄÆÚ´ý×°ÖÃÍê³É¡£
ËÄ. Îó²î¼òÊö
CVE-2020-0601£ºWindows CryptoAPI ÓÕÆÎó²î
Windows CryptoAPI (Crypt32.dll) ÑéÖ¤ÍÖÔ²ÇúÏß¼ÓÃÜ (ECC) Ö¤ÊéµÄ·½·¨Öб£´æÓÕÆÎó²î¡£¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÓÕÆÐԵĴúÂëÊðÃûÖ¤Êé¶Ô¶ñÒâ¿ÉÖ´ÐÐÎļþ¾ÙÐÐÊðÃûÀ´Ê¹ÓôËÎó²î£¬´Ó¶øÊ¹¸ÃÎļþ¿´ËÆÀ´×ÔÊÜÐÅÍеÄÕýµ±ÈªÔ´¡£Óû§½«ÎÞ·¨ÖªµÀ¸ÃÎļþÊǶñÒâÎļþ£¬ÓÉÓÚÊý×ÖÊðÃû¿´ËÆÀ´×ÔÊÜÐÅÍеÄÌṩ³ÌÐò¡£ÀֳɵÄʹÓû¹¿ÉÒÔʹ¹¥»÷Õß¾ÙÐÐÖÐÐÄÈ˹¥»÷£¬²¢¶ÔÓйØÓû§ÓëÊÜÓ°ÏìÈí¼þµÄÅþÁ¬µÄÉñÃØÐÅÏ¢¾ÙÐнâÃÜ¡£´ËÇå¾²¸üÐÂͨ¹ýÈ·±£ Windows CryptoAPI ÖÜÈ«ÑéÖ¤ ECC Ö¤ÊéÀ´ÐÞ¸´´ËÎó²î¡£
CVE-2020-0609/0610£ºWindowsÔ¶³Ì×ÀÃæÐÒ飨RDP£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î
Óû§¿ªÆôÔ¶³Ì×ÀÃæ¹¦Ð§£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýRDPÏòÓû§·¢ËÍÈ«ÐÄÖÆ×÷µÄ¶ñÒâÇëÇ󣬼´¿ÉÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ룬¸ÃÀú³Ì²»ÐèÒªÓû§½»»¥¡£´Ë¸üÐÂͨ¹ý¸üÕý RDP Íø¹Ø´¦Öóͷ£ÅþÁ¬ÇëÇóµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£
CVE-2020-0611£ºÔ¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³ÌÖ´ÐдúÂëÎó²î
¹¥»÷ÕßʹÓÿØÖƵĶñÒâ·þÎñÆ÷£¬ÓÕµ¼Óû§ÅþÁ¬µ½¶ñÒâ·þÎñÆ÷£¬¿ÉÒÔÔÚÅþÁ¬¿Í»§¶ËµÄÅÌËã»úÉÏÖ´ÐÐí§Òâ´úÂë¡£¹¥»÷Õß»¹¿ÉÄÜΣº¦Õýµ±·þÎñÆ÷£¬ÔÚÆäÉÏÍйܶñÒâ´úÂ룬²¢ÆÚ´ýÓû§ÅþÁ¬¡£´ËÇå¾²¸üÐÂͨ¹ý¸üÕý Windows Ô¶³Ì×ÀÃæ¿Í»§¶Ë´¦Öóͷ£ÅþÁ¬ÇëÇóµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£
CVE-2020-0620£ºMicrosoft Cryptographic Services ÌØÈ¨ÌáÉýÎó²î
µ±Microsoft Cryptographic Services²»×¼È·µØ´¦Öóͷ£Îļþʱ£¬±£´æÌØÈ¨ÌáÉýÎó²î¡£¹¥»÷Õß¿ÉÄÜʹÓôËÎó²îÁýÕÖ»òÐÞ¸ÄÊܱ£»¤µÄÎļþ£¬´Ó¶øµ¼ÖÂÌØÈ¨ÌáÉý¡£ÈôҪʹÓôËÎó²î£¬¹¥»÷ÕßÐèÒªÔÚÊܺ¦ÕßϵͳÉÏ»ñµÃÖ´ÐÐȨ¡£´ËÇå¾²¸üÐÂͨ¹ý½â¾öMicrosoft Cryptographic ServicesÈçÄÇÀïÖÃÎļþÀ´ÐÞ¸´´ËÎó²î¡£
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
±±¾©ÉñÖÝAG¹«Ë¾ÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
±±¾©ÉñÖÝAG¹«Ë¾ÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ







