Microsoft | 12Ô¶à¸ö²úÆ·Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-12-09

0x00 Îó²î¸ÅÊö

2020Äê12ÔÂ08ÈÕ£¬£¬£¬£¬£¬MicrosoftÐû²¼ÁË12Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²Îó²î¹²¼Æ58¸ö£¬£¬£¬£¬£¬Ïà½ÏÓÚÉÏÔÂïÔÌ­ÁË54¸ö¡£¡£¡£¡£¡£¡£ÆäÖÐÓÐ9¸öÎó²îÆÀ¼¶ÎªÑÏÖØ£¬£¬£¬£¬£¬46¸öÎó²îÆÀ¼¶Îª¸ßΣ¡£¡£¡£¡£¡£¡£ÔÚ´Ë´ÎÐû²¼µÄÇå¾²Îó²îÖУ¬£¬£¬£¬£¬ÆäÖÐÓÐ23¸öÎó²îΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬14¸öÎó²îΪȨÏÞÌáÉýÎó²î£¬£¬£¬£¬£¬9¸öÎó²îΪÐÅϢй¶Îó²î¡£¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

 

image.png

΢Èí±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÖУ¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·ºÍ×é¼þ°üÀ¨£ºMicrosoft Windows¡¢Microsoft Edge (EdgeHTML-based)¡¢Microsoft Edge for Android¡¢ChakraCore¡¢Microsoft Office and Microsoft Office Services and Web Apps¡¢Microsoft Exchange Server¡¢Azure DevOps¡¢Microsoft Dynamics¡¢Visual Studio¡¢Azure SDKºÍAzure Sphere¡£¡£¡£¡£¡£¡£

±¾´ÎÐû²¼µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE-ID

Îó²îÃû³Æ

ÑÏÖØË®Æ½

CVE-2020-17131

Chakra¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î

ÑÏÖØ

CVE-2020-17095

Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17152

Microsoft Dynamics 365 for Finance and Operations´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17158

Microsoft Dynamics 365 for Finance and Operations´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17117

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17132

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17142

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17118

Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17121

Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17145

Azure DevOpsЧÀÍÆ÷ºÍTeam   Foundation ServicesÓÕÆ­Îó²î

¸ßΣ

CVE-2020-17135

Azure DevOpsЧÀÍÆ÷ÓÕÆ­Îó²î

¸ßΣ

CVE-2020-17002

ÓÃÓÚCÇå¾²¹¦Ð§ÈƹýµÄAzure SDK

¸ßΣ

CVE-2020-17160

Azure SphereÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17137

DirectXͼÐÎÄÚºËȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17147

Dynamics CRM Webclient¿çÕ¾µã¾ç±¾Îó²î

¸ßΣ

CVE-2020-16996

KerberosÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17133

Microsoft Dynamics Business Central / NAVÐÅÏ¢Åû¶

¸ßΣ

CVE-2020-17126

Microsoft ExcelÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17122

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17123

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17125

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17127

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17128

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17129

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17130

Microsoft ExcelÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17143

Microsoft ExchangeÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17141

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17144

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17119

Microsoft OutlookÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17124

Microsoft PowerPointÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17089

Microsoft SharePointȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17120

Microsoft SharePointÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17159

Visual Studio Code JavaÀ©Õ¹°üÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17150

Visual Studio´úÂëÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17148

Visual Studio CodeÔ¶³Ì¿ª·¢À©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17156

Visual StudioÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-16958

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16959

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16960

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16961

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16962

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16963

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16964

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17103

WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17134

WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17136

WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17097

Windows Digital Media ReceiverȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17094

Windows¹ýʧ±¨¸æÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17138

Windows¹ýʧ±¨¸æÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17098

Windows GDI +ÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17099

WindowsËø¶¨ÆÁÄ»Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17092

WindowsÍøÂçÅþÁ¬Ð§ÀÍȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17096

Windows NTFSÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17139

WindowsÁýÕÖɸѡÆ÷Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17140

Windows SMBÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-16971

ÊÊÓÃÓÚJavaµÄAzure SDKÇå¾²¹¦Ð§ÈƹýÎó²î

ÖÐΣ

CVE-2020-17153

Android EdgeµÄMicrosoft   EdgeÎó²î

ÖÐΣ

CVE-2020-17115

Microsoft SharePointÓÕÆ­Îó²î

ÖÐΣ

 

²¿·ÖÑÏÖØÎó²îÈçÏ£º

Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Hyper-VÖб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17095£©£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö8.5¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý´ËÎó²î½«Hyper-V Guest OSȨÏÞÌáÉýµ½Hyper-V HostȨÏÞ£¬£¬£¬£¬£¬×îÖÕÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£

Windows NTFSÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Windows NTFSÖб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17096£©£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.5¡£¡£¡£¡£¡£¡£¾ßÓÐSMBv2»á¼ûȨÏ޵Ĺ¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâÇëÇóÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬×îÖÕ¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£

Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î

MicrosoftÔÚSharePointÖÐÐÞ¸´ÁË2¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17121ºÍCVE-2020-17118£©¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬CVE-2020-17118 CVSSÆÀ·Ö8.1£¬£¬£¬£¬£¬CVE-2020-17121 CVSSÆÀ·Ö8.8¡£¡£¡£¡£¡£¡£

¹¥»÷ÕßÄܹ»Ê¹ÓÃCVE-2020-17121»ñµÃ»á¼ûȨÏÞ£¬£¬£¬£¬£¬ÒÔ½¨ÉèÕ¾µã²¢ÔÚkernelÄÚÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

MicrosoftÐÞ¸´ÁËExchangeÖеÄ5¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17141¡¢CVE-2020-17142¡¢CVE-2020-17144¡¢ CVE-2020-17117¡¢CVE-2020-17132£©¡£¡£¡£¡£¡£¡£

ÆäÖУ¬£¬£¬£¬£¬CVE-2020-17132ÊǶÔcmdlet²ÎÊýµÄÑéÖ¤²»×¼È·Ôì³ÉµÄ£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.1¡£¡£¡£¡£¡£¡£Microsoft²¢Î´ÔÚ´Ë´¦Ìṩ¹¥»÷³¡¾°£¬£¬£¬£¬£¬µ«Ö¸³ö¹¥»÷ÕßÐèÒª¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬ÇÒ¸ÃÎó²îµÄʹÓÃÖØ´óÐԵ͡£¡£¡£¡£¡£¡£ÈôÊǹ¥»÷ÕßÈëÇÖÁËijÈ˵ÄÓÊÏ䣬£¬£¬£¬£¬Ôò¿ÉÒÔ¿ØÖÆÕû¸öExchangeЧÀÍÆ÷¡£¡£¡£¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚMicrosoftÒѾ­Ðû²¼ÁËÇå¾²¸üУ¬£¬£¬£¬£¬½¨ÒéʵʱװÖÃÏà¹Ø²¹¶¡¡£¡£¡£¡£¡£¡£

 

£¨Ò»£© Windows update¸üÐÂ

 

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£¡£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£¡£

4¡¢ÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬×°ÖøüÐÂÏµÍ³ÖØÐÂÆô¶¯ºó£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£¡£

 

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

΢Èí¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£¡£

ÏÂÔØµØµã£º

https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec

https://threatpost.com/microsoft-patch-tuesday-holidays/162041/

https://www.darkreading.com/threat-intelligence/microsoft-fixes-58-cves-for-december-patch-tuesday/d/d-id/1339651?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple

 

0x04 ʱ¼äÏß

2020-12-08  MicrosoftÐû²¼Çå¾²¸üÐÂ

2020-12-09  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

 

 

 

image.png