΢Èí6Ô²¹¶¡ÈÕÐè¹Ø×¢µÄ¸ßΣÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-06-15

Îó²î±àºÅºÍ¼¶±ð


CVE-2018-8248  Ö÷Òª


CVE-2018-8231  ÑÏÖØ  ³§ÉÌ×ÔÆÀ£º8.1


CVE-2018-8225  ÑÏÖØ  ³§ÉÌ×ÔÆÀ£º8.1


CVE-2018-8267  ÑÏÖØ  ³§ÉÌ×ÔÆÀ£º6.4


Îó²î¸ÅÊö


6ÔÂ12ÈÕ£¬£¬£¬ £¬Î¢ÈíÐû²¼ÁË2018Äê6Ô·ݵÄÔ¶ÈÀýÐÐÇ徲ͨ¸æ£¬£¬£¬ £¬ÐÞ¸´ÁËÆä¶à¿î²úÆ·±£´æµÄ122¸öÇå¾²Îó²î¡£¡£¡£¡£¡£Í¨¸æÖаüÀ¨ÁËMicrosoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8248£©£¬£¬£¬ £¬Microsoft Windows HTTPЭÒé¿ÍÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8231£©£¬£¬£¬ £¬Windows DNSAPIÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8225£©¼°Microsoft  Internet Explorer¾ç±¾ÒýÇæÄÚ´æÆÆËðÎó²î£¨CVE-2018-8267£©¡£¡£¡£¡£¡£


ÀÖ³ÉʹÓÃMicrosoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²îµÄ¹¥»÷Õߣ¬£¬£¬ £¬ÄÜÔÚÄ¿½ñÓû§ÇéÐÎÏÂÖ´ÐÐí§Òâ´úÂ룬£¬£¬ £¬ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíԱȨÏ޵Ǽ£¬£¬£¬ £¬¹¥»÷ÕßÉõÖÁ¿ÉÒÔÍêÈ«¿ØÖƸÃÓû§µÄϵͳ¡£¡£¡£¡£¡£Microsoft Office 2010 Service Pack 2¡¢Microsoft Office 2013 RT Service Pack 1¡¢Microsoft Office 2013 Service Pack 1¡¢Microsoft Office 2016¡¢Microsoft Office 2016 Click-to-Run (C2R)µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£

 

ÀÖ³ÉʹÓÃMicrosoft Windows HTTP 2.0ЭÒé¿ÍÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²îµÄ¹¥»÷Õߣ¬£¬£¬ £¬¿ÉÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ룬£¬£¬ £¬²¢¿ØÖƸÃÓû§µÄϵͳ¡£¡£¡£¡£¡£Windows 10¡¢Windows 10 Version 1607¡¢Windows 10 Version 1703¡¢Windows 10 Version 1709¡¢Windows 10 Version 1803¡¢Windows Server 2016¡¢Windows Server 2016 (Server Core installation)¡¢Windows Server version 1709 (Server Core Installation)¡¢Windows Server version 1803 (Server Core Installation)µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£

 

ÀÖ³ÉʹÓÃWindows DNSAPIÔ¶³Ì´úÂëÖ´ÐÐÎó²îµÄ¹¥»÷Õߣ¬£¬£¬ £¬¿ÉÒÔÔÚÍâµØÏµÍ³ÕÊ»§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂ룬£¬£¬ £¬¶ø¹¥»÷ÕßËùÒª×öµÄ¾ÍÊǽ«Ê¹ÓöñÒâDNSЧÀÍÆ÷ÏòÄ¿µÄ·¢ËÍË𻵵ÄDNSÏìÓ¦¡£¡£¡£¡£¡£Windows 7¡¢Windows 8.1¡¢Windows RT 8.1ºÍWindows 10ÒÔ¼°Windows Server 2008¡¢Windows Server 2008 R2¡¢Windows Server 2012¡¢Windows Server 2012 R2¡¢Windows Server 2016¡¢Windows Server°æ±¾1709ºÍ°æ±¾1803µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£


ÀÖ³ÉʹÓÃMicrosoft  Internet Explorer¾ç±¾ÒýÇæÄÚ´æÆÆËðÎó²îµÄ¹¥»÷Õߣ¬£¬£¬ £¬¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£¡£¡£¡£¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬£¬£¬ £¬ÔòÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£È»ºó¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£¬£¬£¬ £¬Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£¬£¬£¬ £¬»ò½¨Éè¾ßÓÐÍêÕûÓû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£¡£¡£Windows Server 2012¡¢Windows Server 2016¡¢Windows 10¡¢Windows 7¡¢Windows 8.1¡¢Windows RT 8.1¡¢Windows Server 2008 R2¡¢Windows Server 2012 R2ÒÔ¼°Windows Server 2008µÄInternet Explorer 9 ¡¢Internet Explorer 10ºÍInternet Explorer 11µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£


Îó²îÏÈÈÝ


Microsoft ExcelÊÇÃÀ¹ú΢Èí¹«Ë¾ÎªÊ¹ÓÃWindowsºÍApple Macintosh²Ù×÷ϵͳµÄµçÄÔ±àдµÄÒ»¿îµç×Ó±í¸ñÈí¼þ¡£¡£¡£¡£¡£Microsoft Excel±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬ £¬¸ÃÎó²îÔ´ÓÚ¸ÃÈí¼þδÄÜ׼ȷ´¦Öóͷ£ÄÚ´æÖеŤ¾ß£¬£¬£¬ £¬¹¥»÷Õß¿Éͨ¹ýÏòÓû§·¢Ë;­ÓÉÌØÊâ½á¹¹µÄÎļþ²¢ÓÕʹÓû§·­¿ª¸ÃÎļþ£¬£¬£¬ £¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£


Microsoft WindowsÊÇÃÀ¹ú΢Èí¹«Ë¾Ñз¢µÄÒ»Ì×½ÓÄÉÁËͼÐλ¯Ä£Ê½µÄ²Ù×÷ϵͳ¡£¡£¡£¡£¡£WindowsÖеÄHTTPЭÒéÊÇÒ»ÖÖͨѶЭÒ飬£¬£¬ £¬¼´³¬Îı¾´«ÊäЭÒé¡£¡£¡£¡£¡£Microsoft Windows HTTPЭÒé±£´æ¿ÍÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚHTTP ЭÒé¿ÍջδÄÜ׼ȷ´¦Öóͷ£ÄÚ´æÖеŤ¾ß£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔÏòÄ¿µÄhttp.sysЧÀÍÆ÷·¢Ë;­ÓÉÌØÊâ½á¹¹µÄÊý¾Ý°ü£¬£¬£¬ £¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£


ÔÚ΢Èí±¾ÔÂÐÞ¸´µÄËùÓÐÎó²îÖУ¬£¬£¬ £¬±»ÒÔΪ×îÑÏÖØµÄÎó²îÊÇCVE-2018-8225¡£¡£¡£¡£¡£Ëü±»ÐÎòΪһ¸öWindows DNSAPIÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬ £¬¸ÃÎó²îÊÇÓÉÓÚWindows ÓòÃûϵͳ£¨DNS£© DNSAPI.dllÎÞ·¨×¼È·´¦Öóͷ£DNSÏìÓ¦µ¼ÖµÄ¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÔÚÍâµØÏµÍ³ÕÊ»§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂ룬£¬£¬ £¬¶ø¹¥»÷ÕßËùÒª×öµÄ¾ÍÊǽ«Ê¹ÓöñÒâDNSЧÀÍÆ÷ÏòÄ¿µÄ·¢ËÍË𻵵ÄDNSÏìÓ¦¡£¡£¡£¡£¡£


½öÓÐÒ»¸öÎó²îÔÚÐû²¼Ê±±»ÁÐΪ¹ûÕæ£¬£¬£¬ £¬ÕâÊÇÒ»¸ö¾ç±¾ÒýÇæÄÚ´æÆÆËðÎó²î£¬£¬£¬ £¬Îó²î±àºÅΪCVE-2018-8267£¬£¬£¬ £¬¾ç±¾ÒýÇæÔÚInternet ExplorerÖд¦Öóͷ£ÄÚ´æÖеŤ¾ßµÄ·½·¨Öб£´æµÄÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¡£¡£¡£¡£ÔÚ»ùÓÚWebµÄ¹¥»÷ÇéÐÎÖУ¬£¬£¬ £¬¹¥»÷Õß¿ÉÄÜÍйܾ­ÓÉÌØÖÆµÄÍøÕ¾£¬£¬£¬ £¬¸ÃÍøÕ¾Ö¼ÔÚͨ¹ýInternet ExplorerʹÓôËÎó²î£¬£¬£¬ £¬È»ºóÓÕʹÓû§Éó²é¸ÃÍøÕ¾¡£¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔÔÚÍйÜIE·ºÆðÒýÇæµÄÓ¦ÓóÌÐò»òMicrosoft OfficeÎĵµÖÐǶÈë±ê¼ÇΪ¡®Çå¾²³õʼ»¯¡¯µÄActiveX¿Ø¼þ¡£¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔʹÓÃÊܵ½ÍþвµÄÍøÕ¾ºÍ½ÓÊÜ»òÍйÜÓû§ÌṩµÄÄÚÈÝ»ò¹ã¸æµÄÍøÕ¾¡£¡£¡£¡£¡£ÕâÐ©ÍøÕ¾¿ÉÄܰüÀ¨¿ÉʹÓôËÎó²îµÄÌØÖÆÄÚÈÝ¡£¡£¡£¡£¡£


ÐÞ¸´½¨Ò飺


ÏÖÔÚ£¬£¬£¬ £¬Î¢Èí¹Ù·½ÒѾ­Ðû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬ £¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ï죬£¬£¬ £¬¾¡¿ì½ÓÄÉÐÞ²¹²½·¥£¬£¬£¬ £¬ÒÔ×èֹDZÔÚµÄÇå¾²Íþв¡£¡£¡£¡£¡£ÏëÒª¾ÙÐиüУ¬£¬£¬ £¬Ö»Ðèתµ½ÉèÖáú¸üкÍÇå¾²¡úWindows¸üСú¼ì²é¸üУ¬£¬£¬ £¬»òÕßÒ²¿ÉÒÔͨ¹ýÊÖ¶¯¾ÙÐиüС£¡£¡£¡£¡£

ÏÖÔÚÒѾ­·¢Ã÷ÓÐʹÓÃCVE-2018-8248Îó²îµÄľÂí£¬£¬£¬ £¬Ïà¹ØÁ´½Ó£ºhttps://www.symantec.com/security-center/writeup/2018-061314-3210-99¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó£º


https://portal.msrc.microsoft.com/en-us/security-guidance/acknowledgments