¡¾Ç徲ͨ¸æ¡¿Î¢ÈíÐû²¼11Ô²¹¶¡ÐÞ¸´112¸öÇå¾²ÎÊÌâ
2020-11-11
×ÛÊö
΢ÈíÓÚ±¾ÖܶþÐû²¼ÁË11ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË112¸ö´Ó¼òÆÓµÄÓÕÆ¹¥»÷µ½Ô¶³ÌÖ´ÐдúÂëµÄÇå¾²ÎÊÌâ¡£ÆäÖÐCritical¼¶±ðÎó²î17¸ö£¬Important ¼¶±ðÎó²î93 ¸ö£¬Low¼¶±ðÎó²î2¸ö¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£
ÊÜÓ°Ïì²úÆ·Éæ¼°Azure DevOps¡¢Azure Sphere¡¢Common Log File System Driver¡¢Microsoft Browsers¡¢Microsoft Dynamics¡¢Microsoft Exchange Server¡¢Microsoft Graphics Component¡¢Microsoft Office¡¢Microsoft Office SharePoint¡¢Microsoft Scripting Engine¡¢Microsoft Teams¡¢Microsoft Windows¡¢Microsoft Windows Codecs Library¡¢Visual Studio¡¢Windows Defender¡¢Windows Kernel¡¢Windows NDIS¡¢Windows Update StackÒÔ¼°Windows WalletService¡£
Critical & ImportantÎó²î¸ÅÊö
²¿·Ö Critical ¼°Important Îó²îÐÎòÈçÏ£º
WindowsÄÚºËÍâµØÌØÈ¨ÌáÉýÎó²î£¨CVE-2020-17087£©
±¾ÔÂ2ºÅ£¬Google Project ZeroÍŶÓÐû²¼ÁËһƪ¹ØÓÚWindows cng.sysÌáȨÎó²î£¨CVE-2020-17087£©µÄÎÄÕ¡£¸ÃÎó²îÔÊÐí¹¥»÷ÕßÔÚδÊÚȨµÄÇéÐÎÏ£¬Í¨¹ýÓÕʹÓû§ÔËÐÐÈ«ÐÄÖÆ×÷µÄ¶ñÒâ³ÌÐò£¬µÖ´ïȨÏÞÌáÉýµÄЧ¹û¡£ÆäʱCVE-2020-17087ÒѾÓÐÔÚҰʹÓõÄÐÐΪ·ºÆð£¬²¢ÇÒ΢Èí¹Ù·½Ã»ÓÐÐû²¼Ïà¹Ø²¹¶¡¡£
ÔÚ±¾´Î¸üÐÂÖУ¬¸ÃÎó²î±»ÐÞ¸´¡£ÇëÊÜÓ°ÏìÓû§¾¡¿ì×°Öò¹¶¡¾ÙÐзÀ»¤¡£
¹Ù·½ÆÀ¼¶ Important£¬CVSS:3.0 7.8/7.2
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17087
WindowsÍøÂçÎļþϵͳ£¨NFS£©Îó²î£¨CVE-2020-17051/ 17056£©
CVE-2020-17051ÊÇÒ»¸ö±£´æÓÚnfssvr.sysÇý¶¯ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¿Éµ¼ÖÂÀ¶ÆÁËÀ»ú£¨BSOD£©¡£
CVE-2020-17056ÊÇÒ»¸ö±£´æÓÚnfssvr.sysÇý¶¯ÖеÄÔ¶³ÌÄÚºËÊý¾Ý¶ÁÈ¡Îó²î£¬¿Éµ¼ÖÂASLR£¨µØµã¿Õ¼ä½á¹¹Ëæ»ú»¯£©±»Èƹý¡£
µ±ÕâÁ½¸öÎó²î±»×éºÏʹÓÃʱ£¬ÔÚWindows·þÎñÆ÷ÉÏÈÆ¹ýÎó²î»º½â²½·¥²¢ÊµÏÖÔ¶³ÌʹÓõĿÉÄÜÐÔ´ó´óÔöÌí¡£
NFSÓÃÓÚÔÚWindowsºÍUnix/LinuxÇéÐÎÖÐ×öÎļþ¹²Ïí¡£
CVE-2020-17051¹Ù·½ÆÀ¼¶ Critical£¬CVSS:3.0 9.8/8.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CVE-2020-17056¹Ù·½ÆÀ¼¶ Important£¬CVSS:3.0 5.5/4.8
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17051
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17056
Microsoft Exchange·þÎñÆ÷Îó²î£¨CVE-2020-17083/17084/17085£©
CVE-2020-17083ºÍCVE-2020-17084ÊDZ£´æÓÚMicrosoft Exchange·þÎñÆ÷ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£ CVE-2020-17085ÊÇһö¾Ü¾ø·þÎñÎó²î¡£
Èý¸öÎó²î¹Ù·½ÆÀ¼¶¾ùΪ Important¡£
CVE-2020-17083 CVSS:3.0 5.5/4.8
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L/E:U/RL:O/RC:C
CVE-2020-17084 CVSS:3.0 8.5/7.4
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
CVE-2020-17085 CVSS:3.0 6.2/5.4
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17083
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17084
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17085
Windows Hyper-V Çå¾²¹¦Ð§ÈƹýÎó²î£¨CVE-2020-17040£©
Hyper-V Öб£´æÒ»¸öʹÓÃÖØÆ¯ºóµÍ¡¢ÎÞÐèÌØÈ¨¡¢ÎÞÐèÓû§½»»¥µÄÇå¾²¹¦Ð§ÈƹýÎó²î¡£
¹Ù·½ÆÀ¼¶ Important£¬CVSS:3.0 6.5/5.7
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17040

AG¹«Ë¾ÔÆ







