΢Èí¸üжà¸ö²úÆ·¸ßΣÎó²îÍþвͨ¸æ
2020-02-13
Îó²î¸ÅÊö
±±¾©Ê±¼ä2ÔÂ12ÈÕ£¬Î¢ÈíÐû²¼2ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË100¸öÇå¾²ÎÊÌâ£¬Éæ¼°Internet Explorer¡¢Microsoft Edge¡¢Microsoft Exchange Server¡¢Microsoft OfficeµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨ÌáȨºÍÔ¶³Ì´úÂëÖ´ÐеȸßΣÎó²î¡£
´Ë´ÎÇå¾²¸üÐÂÐÞ¸´µÄÎó²îÖУ¬Windows installerÍâµØÌáȨÎó²î£¨CVE-2020-0683£©µÄPoCÒѹûÕæ£¬ÇÒ¹Ù·½ÆÀ¼¶Îª¸ßΣ£¬²¢ÇÒ£¬Î¢ÈíÓÚ1ÔÂ17ÈÕÐû²¼µÄ IE ´úÂëÖ´ÐÐ0dayÎó²î£¨CVE-2020-0674£©Ò²ÔÚ´Ë´ÎÇå¾²¸üÐÂÖлñµÃÁËÐÞ¸´£¬´ËÎó²îÒѱ»·¢Ã÷ÔÚҰʹÓá£ÇëÏà¹ØÓû§ÊµÊ±¸üв¹¶¡¾ÙÐзÀ»¤£¬ÏêϸÎó²îÁбíÇë²Î¿¼¸½Â¼¡£
²Î¿¼Á´½Ó £º https://portal.msrc.microsoft.com/zh-cn/security-guidance/releasenotedetail/2020-Feb
ÖØµãÎó²î¼òÊö
±¾ÔÂ΢ÈíÔ¶ȸüÐÂÐÞ¸´µÄÎó²îÖУ¬ÑÏÖØË®Æ½ÎªÒªº¦£¨Critical£©µÄÎó²î¹²ÓÐ 12¸ö£¬Ö÷Òª£¨Important£©Îó²îÓÐ 88¸ö¡£ÒÔÏÂΪ´Ë´Î¸üÐÂÖаüÀ¨Ó°Ïì½Ï´óµÄÎó²î£¬ÇëÏà¹ØÓû§×ÅÖØ¾ÙÐйØ×¢£º
Windows
CVE-2020-0683
µ± MSI °ü´¦Öóͷ£·ûºÅÁ´½Óʱ£¬Windows Installer Öб£´æÌØÈ¨ÌáÉýÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÈÆ¹ý»á¼ûÏÞÖÆÀ´Ìí¼Ó»òɾ³ýÎļþ¡£
ΪÁËʹÓôËÎó²î£¬¹¥»÷ÕßÊ×ÏȱØÐèµÇ¼ϵͳ¡£È»ºó£¬¹¥»÷Õß¿ÉÒÔÔËÐÐÒ»¸ö¾ÌØÊâÉè¼ÆµÄÓ¦ÓóÌÐò£¬¸ÃÓ¦ÓóÌÐò¿ÉÒÔʹÓôËÎó²î²¢Ìí¼Ó»òɾ³ýÎļþ¡£
´ËÇå¾²¸üÐÂͨ¹ýÐÞ¸Ä Windows Installer ´¦Öóͷ£ÖØÆÊÎöµãµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£ ÏÖÔÚpocÒѾ¹ûÕæ£¬Ê¹ÓÃÀֳɵĽØÍ¼ÈçÏ£º

CVE-2020-0662
Windows ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨Öб£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÌáÉýµÄÌØÈ¨ÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£
ÈôҪʹÓôËÎó²î£¬¾ßÓÐÓòÓû§ÕÊ»§µÄ¹¥»÷Õß¿ÉÒÔ½¨Éè¾ÌØÊâÉè¼ÆµÄÇëÇ󣬴ӶøÊ¹ Windows ʹÓÃÌáÉýµÄÌØÈ¨Ö´ÐÐí§Òâ´úÂë¡£
¹ØÓÚÎó²îµÄ¸ü¶àÏêÇé¼°¸üÐÂÏÂÔØ£¬Çë²Î¿¼Î¢Èí¹Ù·½Ç徲ͨ¸æ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0662
Microsoft Scripting Engine
CVE-2020-0673¡¢CVE-2020-0674
΢ÈíÔøÓÚ1ÔÂ17ÈÕÐû²¼¹ýÒ»¸öÓйØInternet ExplorerÎó²î£¨CVE-2020-0674£©µÄÇ徲ͨ¸æ£¬ÌåÏÖ¸ÃÎó²î·¢Ã÷ÔÚÒ°ÍⱻʹÓõÄÇéÐΣ¬Æäʱͨ¸æ½ö°üÀ¨¿ÉÓ¦Óõıäͨ²½·¥»ººÍ½â²½·¥£¬±¾´Î¸üÐÂÖÐÐÂÔöÁËÕë¶Ô¸ÃÎó²îµÄ²¹¶¡¡£
¾ç±¾ÒýÇæÔÚ´¦Öóͷ£Internet ExplorerÖÐÄڴ湤¾ßµÄ·½·¨Öб£´æÒÔÉÏÔ¶³ÌÖ´ÐдúÂëÎó²î¡£
ÀÖ³ÉʹÓÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬Ôò¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£È»ºó£¬¿ÉÄÜ»á×°ÖóÌÐò¡£Éó²é£¬¸ü¸Ä»òɾ³ýÊý¾Ý»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£
ÔÚ»ùÓÚWebµÄ¹¥»÷³¡¾°ÖУ¬¹¥»÷Õß¿ÉÄÜ»á´î½¨Ò»¸öÌØÖÆµÄÍøÕ¾£¬È»ºóÓÕʹÓû§»á¼û¸ÃÕ¾µã¡£²»¹ý¹¥»÷ÕßÎÞ·¨Ç¿ÆÈÓû§Éó²é¶ñÒâÄÚÈÝ¡£ÒÔÊÇͨ³£»áͨ¹ýµç×ÓÓʼþ»ò¼´Ê±ÐÂÎŵķ½·¨À´ÓÕµ¼Óû§¡£±ðµÄ£¬¹¥»÷Õß»¹¿ÉÄÜÔÚ³ÐÔØIEäÖȾÒýÇæµÄÓ¦ÓóÌÐò»òMicrosoft OfficeÎĵµÖÐǶÈë±ê¼ÇΪ“³õʼ»¯Çå¾²”µÄActiveX¿Ø¼þ¡£
Internet Explorer 9¡¢10¡¢11 ¾ùÊÜÓ°Ïì¡£
¹ØÓÚÎó²îµÄ¸ü¶àÏêÇé¼°¸üÐÂÏÂÔØ£¬Çë²Î¿¼Î¢Èí¹Ù·½Ç徲ͨ¸æ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0673
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0674
CVE-2020-0710¡¢CVE-2020-0711¡¢CVE-2020-0712¡¢CVE-2020-0713¡¢CVE-2020-0767
ChakraCore¾ç±¾ÒýÇæÔÚ´¦Öóͷ£Äڴ湤¾ßµÄ·½·¨Öб£´æÒÔÉÏÔ¶³ÌÖ´ÐдúÂëÎó²î¡£ÀÖ³ÉʹÓÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£
¹ØÓÚÎó²îµÄ¸ü¶àÏêÇé¼°¸üÐÂÏÂÔØ£¬Çë²Î¿¼Î¢Èí¹Ù·½Ç徲ͨ¸æ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0710
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0711
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0712
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0713 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0767
RDP
CVE-2020-0681¡¢CVE-2020-0734
ÕâÊÇ WindowsÔ¶³Ì×ÀÃæ¿Í»§¶ËÖеÄÁ½¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£
ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÅþÁ¬µ½¶ñÒâ·þÎñÆ÷µÄÓû§ÅÌËã»úÉÏÖ´ÐÐí§Òâ´úÂ롣Ȼºó£¬¹¥»÷Õß¿ÉÄÜ»á×°ÖóÌÐò¡£Éó²é£¬¸ü¸Ä»òɾ³ýÊý¾Ý»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£
ҪʹÓôËÎó²î£¬¹¥»÷ÕßÐèÒª¿ØÖÆ·þÎñÆ÷£¬È»ºóÓÕʹÓû§ÅþÁ¬µ½¸Ã·þÎñÆ÷¡£ÈôÊÇÓû§»á¼ûÁ˶ñÒâµÄ·þÎñÆ÷£¬Ôò¿ÉÒÔ´¥·¢´ËÎó²î¡£ËäÈ»¹¥»÷ÕßÎÞ·¨Ç¿ÆÈÓû§ÅþÁ¬µ½¶ñÒâ·þÎñÆ÷£¬µ«ËûÃÇ¿ÉÄÜ»áͨ¹ýÉ繤£¬DNSÖж¾»òÖÐÐÄÈË£¨MITM£©ÊÖÒÕÓÕʹÓû§¾ÙÐÐÅþÁ¬¡£¹¥»÷Õß»¹¿ÉÄÜÆÆËðÕýµ±·þÎñÆ÷£¬ÔÚÆäÉÏÍйܶñÒâ´úÂ룬ȻºóÆÚ´ýÓû§ÅþÁ¬¡£
¹ØÓÚÎó²îµÄ¸ü¶àÏêÇé¼°¸üÐÂÏÂÔØ£¬Çë²Î¿¼Î¢Èí¹Ù·½Ç徲ͨ¸æ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0681https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0734
LNK
CVE-2020-0729
Microsoft WindowsÖб£´æÒ»¸öÔ¶³ÌÖ´ÐдúÂëÎó²î£¬ÈôÊÇ´¦Öóͷ£ÁË.LNKÎļþ£¬¸ÃÎó²î¿ÉÄÜÔÊÐíÔ¶³ÌÖ´ÐдúÂë¡£
ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÍâµØÓû§ÏàͬµÄȨÏÞ¡£
¹¥»÷Õß¿ÉÄÜÏòÓû§Ìṩ¿ÉÒÆ¶¯Çý¶¯Æ÷»òÔ¶³Ì¹²Ïí£¬ÆäÖаüÀ¨¶ñÒâµÄ.LNKÎļþºÍ¹ØÁªµÄ¶ñÒâ¶þ½øÖÆÎļþ¡£µ±Óû§ÔÚWindows×ÊÔ´ÖÎÀíÆ÷»òÈÎºÎÆäËûÆÊÎö.LNKÎļþµÄÓ¦ÓóÌÐòÖз¿ª´ËÇý¶¯Æ÷£¨»òÔ¶³Ì¹²Ïí£©Ê±£¬¶ñÒâ¶þ½øÖÆÎļþ½«ÔÚÄ¿µÄϵͳÉÏÖ´Ðй¥»÷ÕßÑ¡ÔñµÄ´úÂë¡£
¹ØÓÚÎó²îµÄ¸ü¶àÏêÇé¼°¸üÐÂÏÂÔØ£¬Çë²Î¿¼Î¢Èí¹Ù·½Ç徲ͨ¸æ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0729
Media Foundation
CVE-2020-0738
Windows Media Foundation²»×¼È·µØ´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ£¬±£´æÄÚ´æËð»µÎó²î¡£
ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£¬Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£
¹¥»÷Õß¿ÉÒÔ½ÓÄɶàÖÖ·½·¨Ê¹ÓôËÎó²î£¬ÀýÈ磬˵·þÓû§·¿ªÌØÖÆÎĵµ£¬»ò˵·þÓû§»á¼û¶ñÒâÍøÒ³¡£
¹ØÓÚÎó²îµÄ¸ü¶àÏêÇé¼°¸üÐÂÏÂÔØ£¬Çë²Î¿¼Î¢Èí¹Ù·½Ç徲ͨ¸æ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0738
Îó²î·À»¤
²¹¶¡¸üÐÂ
ÏÖÔÚ΢Èí¹Ù·½ÒÑÕë¶ÔÊÜÖ§³ÖµÄϵͳ°æ±¾Ðû²¼ÐÞ¸´ÁËÒÔÉÏÎó²îµÄÇå¾²²¹¶¡£¬Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì×°Öò¹¶¡¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£º
https://portal.msrc.microsoft.com/zh-cn/security-guidance
×¢£ºÓÉÓÚÍøÂçÎÊÌâ¡¢ÅÌËã»úÇéÐÎÎÊÌâµÈÔµ¹ÊÔÓÉ£¬Windows UpdateµÄ²¹¶¡¸üпÉÄÜ·ºÆðʧ°Ü¡£Óû§ÔÚ×°Öò¹¶¡ºó£¬Ó¦ÊµÊ±¼ì²é²¹¶¡ÊÇ·ñÀֳɸüС£
ÓÒ¼üµã»÷Windows»Õ±ê£¬Ñ¡Ôñ“ÉèÖÃ(N)”£¬Ñ¡Ôñ“¸üкÍÇå¾²”-“Windows¸üД£¬Éó²é¸ÃÒ³ÃæÉϵÄÌáÐÑÐÅÏ¢£¬Ò²¿Éµã»÷“Éó²é¸üÐÂÀúÊ·¼Í¼”Éó²éÀúÊ·¸üÐÂÇéÐΡ£ Õë¶ÔδÀÖ³É×°ÖõĸüУ¬¿Éµã»÷¸üÐÂÃû³ÆÌø×ªµ½Î¢Èí¹Ù·½ÏÂÔØÒ³Ãæ£¬½¨ÒéÓû§µã»÷¸ÃÒ³ÃæÉϵÄÁ´½Ó£¬×ªµ½“Microsoft¸üÐÂĿ¼”ÍøÕ¾ÏÂÔØ×ÔÁ¦³ÌÐò°ü²¢×°Öá£
¸½Â¼£º²úÆ·Îó²îÁбí
| Ó°Ïì²úÆ· | CVE ±àºÅ | Îó²îÎÊÌâ | ÑÏÖØË®Æ½ |
| Adobe Flash Player | ADV200003 | February 2020 Adobe Flash Çå¾²¸üР| Important |
| Internet Explorer | CVE-2020-0673 | Scripting Engine ÄÚ´æÆÆËðÎó²î | Critical |
| Internet Explorer | CVE-2020-0674 | Scripting Engine ÄÚ´æÆÆËðÎó²î | Critical |
| Microsoft Edge | CVE-2020-0663 | Microsoft Edge ÌØÈ¨ÌáÉýÎó²î | Important |
| Microsoft Edge | CVE-2020-0706 | Microsoft Browser ÐÅϢй¶Îó²î | Important |
| Microsoft Exchange Server | CVE-2020-0688 | Microsoft Exchange ÄÚ´æÆÆËðÎó²î | Important |
| Microsoft Exchange Server | CVE-2020-0696 | Microsoft Outlook Çå¾²¹¦Ð§ÈƹýÎó²î | Important |
| Microsoft Exchange Server | CVE-2020-0692 | Microsoft Exchange Server ÌØÈ¨ÌáÉýÎó²î | Important |
| Microsoft Graphics Component | CVE-2020-0745 | Windows Graphics Component ÌØÈ¨ÌáÉýÎó²î | Important |
| Microsoft Graphics Component | CVE-2020-0746 | Microsoft Graphics Components ÐÅϢй¶Îó²î | Important |
| Microsoft Graphics Component | CVE-2020-0792 | Windows Graphics Component ÌØÈ¨ÌáÉýÎó²î | Important |
| Microsoft Graphics Component | CVE-2020-0709 | DirectX ÌØÈ¨ÌáÉýÎó²î | Important |
| Microsoft Graphics Component | CVE-2020-0714 | DirectX ÐÅϢй¶Îó²î | Important |
| Microsoft Graphics Component | CVE-2020-0715 | Windows Graphics Component ÌØÈ¨ÌáÉýÎó²î | Important |
| Microsoft Graphics Component | CVE-2020-0744 | Windows GDI ÐÅϢй¶Îó²î | Important |
| Microsoft Malware Protection Engine | CVE-2020-0733 | Windows Malicious Software Removal Tool ÌØÈ¨ÌáÉýÎó²î | Important |
| Microsoft Office | CVE-2020-0695 | Microsoft Office Online Server ÓÕÆÎó²î | Important |
| Microsoft Office | CVE-2020-0697 | Microsoft Office Tampering Vulnerability | Important |
| Microsoft Office | CVE-2020-0759 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î | Important |
| Microsoft Office SharePoint | CVE-2020-0693 | Microsoft Office SharePoint XSS Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2020-0694 | Microsoft Office SharePoint XSS Vulnerability | Important |
| Microsoft Scripting Engine | CVE-2020-0767 | Scripting Engine ÄÚ´æÆÆËðÎó²î | Critical |
| Microsoft Scripting Engine | CVE-2020-0710 | Scripting Engine ÄÚ´æÆÆËðÎó²î | Critical |
| Microsoft Scripting Engine | CVE-2020-0711 | Scripting Engine ÄÚ´æÆÆËðÎó²î | Critical |
| Microsoft Scripting Engine | CVE-2020-0712 | Scripting Engine ÄÚ´æÆÆËðÎó²î | Critical |
| Microsoft Scripting Engine | CVE-2020-0713 | Scripting Engine ÄÚ´æÆÆËðÎó²î | Critical |
| Microsoft Windows | CVE-2020-0666 | Windows Search Indexer ÌØÈ¨ÌáÉýÎó²î | Important |
| Microsoft Windows | CVE-2020-0667 | Windows Search Indexer ÌØÈ¨ÌáÉýÎó²î | Important |
| Microsoft Windows |
$(".info_chag img").each(function () {
$(this).css({ "max-width": "100%","height": "auto","display":"inline-block" }).parent().css({"text-align":"center"});
});
?
ÄúµÄÁªÏµ·½·¨? 2026 NSFOCUS AG¹«Ë¾¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ |

AG¹«Ë¾ÔÆ





