΢ÈíÐû²¼11Ô·Ý8¸öÇ徲ͨ¸æ ÐÞ¸´ÁË19¸öÇå¾²Îó²î (Alert2013-12)
2013-11-13
ÐÎò£º
΢ÈíÐû²¼ÁË11Ô·Ý8¸öÇå¾²²¹¶¡£ºMS13-088µ½MS13-095¡£ÆäÖÐ3¸öΪÑÏÖØÆ·¼¶²¹¶¡£¬ÁíÍâ5¸öΪÖ÷ҪƷ¼¶²¹¶¡¡£ÕâЩ²¹¶¡ÐÞ¸´ÁËMicrosoft Internet Explorer, Office, WindowsÖеÄÇå¾²Îó²î¡£ÎÒÃÇÇ¿ÁÒ½¨ÒéʹÓÃWindows²Ù×÷ϵͳµÄÓû§Á¬Ã¦¼ì²éÒ»ÏÂÄúµÄϵͳÊÇ·ñÊÜ´ËÎó²îÓ°Ï죬 ²¢ÊµÊ±×°ÖÃ×îв¹¶¡¡£
ÆÊÎö£º
1¡¢ MS13-088 -Internet ExplorerÀÛ»ýÇå¾²¸üд˸üнâ¾öÁËInternet ExplorerÄÚ10¸öÉñÃØ±¨¸æµÄÎó²î¡£ÈôÊÇÓû§ÓÃIEÉó²éÌØÖÆµÄÍøÒ³£¬×îÑÏÖØµÄÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ÕâЩÎó²î°üÀ¨£º
1) Internet ExplorerÐÅϢй¶Îó²î - CVE-2013-3908
Internet ExplorerÌìÉú´òÓ¡Ô¤ÀÀʱ´¦Öóͷ£ÌØÖƵÄWebÄÚÈݻᵼÖÂÐÅÏ¢Îó²î¡£
ÔÝʱ½â¾ö¼Æ»®£º
* ²»±ØÔÚIEÖÐʹÓôòÓ¡Ô¤ÀÀ¹¦Ð§¡£
* ÉèÖû¥ÁªÍøºÍÄÚÁªÍøÇå¾²ÇøÓòÉèÖÃΪ¡°¸ß¡±
* ½«ÐÅÍеÄÍøÕ¾Ìí¼Óµ½IE¿ÉÐÅÕ¾µãÇøÓò¡£
* ÉèÖÃIEÔÚÔËÐÐÔ˶¯¾ç±¾Ö®Ìõ¼þʾ»òÖ±½Ó½ûÓá£
* ²»ÒªÔÚ²»ÊÜÐÅÍеÄÍøÕ¾»ò²»ÊÜ¿ØÖƵÄÍøÒ³Éϵ÷ÊԾ籾¡£
2) Internet ExplorerÐÅϢй¶Îó²î - CVE-2013-3909
Internet Explorer´¦Öóͷ£CSSÌØÊâ×Ö·ûʱ±£´æÐÅϢй¶Îó²î£¬¹¥»÷Õßͨ¹ý¹¹½¨ÌØÖƵÄÍøÒ³Ê¹ÓôËÎó²î¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£
3£©¶à¸öÄÚ´æÆÆËðÎó²î£¬°üÀ¨£º
Internet ExplorerÄÚ´æÆÆËðÎó²î - CVE-2013-3871
Internet ExplorerÄÚ´æÆÆËðÎó²î - CVE-2013-3910
Internet ExplorerÄÚ´æÆÆËðÎó²î - CVE-2013-3911
Internet ExplorerÄÚ´æÆÆËðÎó²î - CVE-2013-3912
Internet ExplorerÄÚ´æÆÆËðÎó²î - CVE-2013-3914
Internet ExplorerÄÚ´æÆÆËðÎó²î - CVE-2013-3915
Internet ExplorerÄÚ´æÆÆËðÎó²î - CVE-2013-3916
Internet ExplorerÄÚ´æÆÆËðÎó²î - CVE-2013-3917
ÊÜÓ°ÏìÈí¼þ:
Internet Explorer 6
Internet Explorer 7
Internet Explorer 8
Internet Explorer 9
Internet Explorer 10
Internet Explorer 11
ÔÝʱ½â¾ö¼Æ»®£º
* ÉèÖû¥ÁªÍøºÍÄÚÁªÍøÇå¾²ÇøÓòÉèÖÃΪ¡°¸ß¡±
* ÉèÖÃIEÔÚÔËÐÐÔ˶¯¾ç±¾Ö®Ìõ¼þʾ»òÖ±½Ó½ûÓá£
* ²»ÒªÔÚ²»ÊÜÐÅÍеÄÍøÕ¾»ò²»ÊÜ¿ØÖƵÄÍøÒ³Éϵ÷ÊԾ籾¡£
2¡¢MS13-089 - WindowsͼÐÎ×°±¸½Ó¿ÚÔ¶³Ì´úÂëÖ´ÐÐÎó²î
´Ë¸üнâ¾öÁËMicrosoft WindowsÖÐ1¸öÉñÃØ±¨¸æµÄÎó²î£¬ÈôÊÇÓû§Éó²é»ò·¿ªWorPadÄÚµÄÌØÖÆWindows WriteÎļþ£¬´ËÎó²î¿ÉÔÊÐíÔ¶³Ì´úÂëÖ´ÐС£
ÊÜÓ°ÏìÈí¼þ£º
Windows XP
Windows Server 2003
Windows Vista
Windows Server 2008
Windows 7
Windows 8¡¢8.1
Windows Server 2008 R2
Windows Server 2012¡¢2012 R2
Windows RT¡¢RT 8.1
Îó²îÐÎò£º
ͼÐÎ×°±¸½Ó¿ÚÕûÊýÒç³öÎó²î - CVE-2013-3940
Windows GDIÔÚWordPadÄÚ´¦Öóͷ£ÌØÖƵÄWriteÎļþʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¹¥»÷Õß¿ÉʹÓôËÎó²îÍêÈ«¿ØÖÆÊÜÓ°Ïìϵͳ¡£
ÔÝʱ½â¾ö¼Æ»®£º
* ÏÖÔÚ»á¼ûmswrd8.wpc½ûÓÃWord 6ת»»Æ÷¡£
* ²»Òª·¿ª´Ó²»ÊÜÐÅÍÐÔ´ÎüÊÕµ½µÄ»òÒâÍâ´ÓÊÜÐÅÍÐÔ´ÎüÊÕµ½µÄWindows WriteÎĵµ¡£
3¡¢ MS13-090 - ActiveX Kill BitsÇå¾²¸üР(2878890)
´Ë¸üнâ¾öÁËWindowsµÄInformationCardSigninHelper Class ActiveX¿Ø¼þÖÐ1¸öÉñÃØ±¨¸æµÄÎó²î£¬ÈôÊÇÓû§ÓÃʵÀý»¯ÁËActiveX¿Ø¼þµÄIEä¯ÀÀÌØÖÆÍøÒ³£¬´ËÎó²î¿ÉÔÊÐíÔ¶³Ì´úÂëÖ´ÐС£
ÊÜÓ°ÏìÈí¼þ£º
Windows XP
Windows Vista
Windows 7
Windows 8
Windows RT
Windows 8.1
Windows RT 8.1
Windows Server 2003
Windows Server 2008
Windows Server 2008 R2
Windows Server 2012
Windows Server 2012 R2
Îó²îÐÎò:
InformationCardSigninHelperÎó²î ¨C CVE-2013-3918
InformationCardSigninHelper Class ActiveX¿Ø¼þicardie.dll±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÈôÊÇÓû§¹¹½¨ÁËÌØÖÆµÄÍøÒ³Ê¹ÓôËÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
ÔÝʱ½â¾ö¼Æ»®£º
* ×èÖ¹ÔÚIEÄÚʹÓöþ½øÖƲÙ×÷¡£
4¡¢MS13-091 - Microsoft OfficeÔ¶³Ì´úÂëÖ´ÐÐÎó²î(2885093)
Microsoft Office±£´æ3¸öÉñÃØ±¨¸æµÄÎó²î£¬ÈôÊÇÔÚÊÜÓ°Ïì°æ±¾µÄMicrosoft OfficeÈí¼þÖз¿ªÌØÖƵÄWordPerfectÎĵµÎļþ£¬´ËÎó²î¿ÉÔÊÐíÔ¶³Ì´úÂëÖ´ÐС£
ÊÜÓ°ÏìÈí¼þ£º
Microsoft Office 2003
Microsoft Office 2007
Microsoft Office 2010
Microsoft Office 2013
Microsoft Office 2013 RT
Îó²îÐÎò:
1) WPDÎļþÃûÌÃÄÚ´æÆÆËðÎó²î - CVE-2013-0082
ÊÜÓ°ÏìMicrosoft OfficeÈí¼þÆÊÎöÌØÖÆµÄ.wpdÎļþʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÀÖ³ÉʹÓúó¿Éµ¼ÖÂÍêÈ«¿ØÖÆÊÜÓ°Ïìϵͳ¡£
ÔÝʱ½â¾ö¼Æ»®£º
* ÏÞÖÆ»á¼ûÊÜÓ°ÏìWordPerfectÎļþת»»Æ÷ (wpft632.cnv)
* ²»Òª·¿ª´Ó²»ÊÜÐÅÍÐÔ´ÎüÊÕµ½µÄ»òÒâÍâ´ÓÊÜÐÅÍÐÔ´ÎüÊÕµ½µÄWordPerfectÎĵµ¡£
2) WordÕ»»º³åÇøÁýÕÖÎó²î - CVE-2013-1324
ÊÜÓ°ÏìMicrosoft OfficeÈí¼þÆÊÎöÌØÖÆµÄ.wpdÎļþʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÀÖ³ÉʹÓúó¿Éµ¼ÖÂÍêÈ«¿ØÖÆÊÜÓ°Ïìϵͳ¡£
ÔÝʱ½â¾ö¼Æ»®£º
* ÏÞÖÆ»á¼ûÊÜÓ°ÏìWordPerfectÎļþת»»Æ÷ (wpft532.cnv)
* ²»Òª·¿ª´Ó²»ÊÜÐÅÍÐÔ´ÎüÊÕµ½µÄ»òÒâÍâ´ÓÊÜÐÅÍÐÔ´ÎüÊÕµ½µÄWordPerfectÎĵµ¡£
3£©Word¶ÑÁýÕÖÎó²î - CVE-2013-1325
ÊÜÓ°ÏìMicrosoft OfficeÈí¼þÆÊÎöÌØÖÆµÄ.wpdÎļþʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÀÖ³ÉʹÓúó¿Éµ¼ÖÂÍêÈ«¿ØÖÆÊÜÓ°Ïìϵͳ¡£
ÔÝʱ½â¾ö¼Æ»®£º
* ÏÞÖÆ»á¼ûÊÜÓ°ÏìWordPerfectÎļþת»»Æ÷ (wpft532.cnv)
* ²»Òª·¿ª´Ó²»ÊÜÐÅÍÐÔ´ÎüÊÕµ½µÄ»òÒâÍâ´ÓÊÜÐÅÍÐÔ´ÎüÊÕµ½µÄWordPerfectÎĵµ¡£
5¡¢MS13-092 - Hyper-VȨÏÞÌáÉýÎó²î (2885089)
´ËÇå¾²¸üнâ¾öÁË Microsoft WindowsÖеÄ1¸öÉñÃØ±¨¸æµÄÎó²î¡£ÈôÊǹ¥»÷Õß´ÓÏÖÔÚÔËÐеÄÐéÄâ»úת´ïhypercallµÄÌØÖÆº¯Êý²ÎÊýµ½ÖÎÀí³ÌÐò£¬´ËÎó²î¿ÉÔÊÐíȨÏÞÌáÉý¡£Ò²¿Éµ¼ÖÂHyper-VÖ÷»ú¾Ü¾ø·þÎñ¡£
ÊÜÓ°ÏìÈí¼þ:
Windows Server 2012
Windows 8
Îó²îÐÎò:
µØµãÆÆËðÎó²î - CVE-2013-3898
Windows 8¡¢Windows Server 2012ÉϵÄHyper-V±£´æÈ¨ÏÞÌáÉýÎó²î£¬ÀÖ³ÉʹÓúó¿Éµ¼ÖÂÔÚ¹²ÏíHyper-VÖ÷»úµÄÁíÒ»¸öVMÉÏÒÔϵͳ¼¶±ðȨÏÞÖ´ÐÐí§Òâ´úÂ룬Ҳ¿Éµ¼ÖÂͳһƽ̨ÉϵÄHyper-V¾Ü¾ø·þÎñ¡£
6¡¢MS13-093 - Windows¸¨Öú¹¦Ð§Çý¶¯³ÌÐòÐÅϢй¶Îó²î
´Ë¸üнâ¾öÁËMicrosoft WindowsÄÚ1¸öÉñÃØ±¨¸æµÄÎó²î¡£ÈôÊǹ¥»÷Õß×÷ΪÍâµØÓû§µÇ¼ÊÜÓ°Ïìϵͳ²¢ÔËÐÐÌØÖÆµÄÓ¦Ó㬴ËÎó²î¿Éµ¼ÖÂÐÅϢй¶¡£
ÊÜÓ°ÏìÈí¼þ£º
Windows XP
Windows Server 2003
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 8
Windows Server 2012
Îó²îÐÎò£º
¸¨Öú¹¦Ð§Çý¶¯³ÌÐòÐÅϢй¶Îó²î - CVE-2013-3887
WindowsÄÚºËģʽÇý¶¯³ÌÐò²»×¼È·´¦Öóͷ£ÁËÄں˺ÍÓû§ÄÚ´æÖ®¼äµÄÊý¾Ý¸´ÖÆ£¬±£´æÐÅϢй¶Îó²î¡£
ÔÝʱ½â¾ö¼Æ»®£º
* ²»Òª·¿ª¿ÉÒÉÔ´µÄ¿ÉÖ´ÐÐÎļþ¡£
7¡¢MS13-094 Microsoft OutlookÐÅϢй¶Îó²î(2894514)
´Ë¸üнâ¾öÁËMicrosoft OutlookÄÚ1¸ö¹ûÕæ±¨¸æµÄÎó²î¡£ÈôÊÇÓû§ÓÃÊÜÓ°Ïì°æ±¾Outlook ·¿ª»òÔ¤ÀÀÌØÖÆµÄµç×ÓÓʼþ£¬´ËÎó²î¿Éµ¼ÖÂÖîÈçIPµØµã¡¢¿ª·ÅµÄTCP¶Ë¿ÚµÈϵͳÃô¸ÐÐÅϢй¶¡£
ÊÜÓ°ÏìÈí¼þ£º
Microsoft Outlook 2007
Microsoft Outlook 2010
Microsoft Outlook 2013
Microsoft Outlook 2013 RT
Îó²îÐÎò£º
S/MIME AIA Îó²î - CVE-2013-3905
Microsoft OutlookûÓÐ׼ȷ´¦Öóͷ£S/MIMEÖ¤ÊéÔ´Êý¾ÝµÄÀ©Õ¹£¬ÔÚʵÏÖÉϱ£´æÐÅϢй¶Îó²î¡£´ËÎó²î¿Éµ¼ÖÂÖîÈçIPµØµã¡¢¿ª·ÅµÄTCP¶Ë¿ÚµÈÄ¿µÄϵͳ¼°ÆäËûϵͳµÄÃô¸ÐÐÅϢй¶¡£
ÔÝʱ½â¾ö¼Æ»®£º
* ÔÚOutlookÄÚեȡÔĶÁÃæ°å¡£
8¡¢MS13-095 Êý×ÖÊðÃû¾Ü¾ø·þÎñÎó²î (2890788)
´Ë¸üнâ¾öÁËMicrosoft WindowsÄÚ1¸öÉñÃØ±¨¸æµÄÎó²î¡£ÊÜÓ°ÏìWeb·þÎñÈôÊÇ´¦Öóͷ£ÌØÖƵÄX.509Ö¤Ê飬´ËÎó²î¿Éµ¼Ö¾ܾø·þÎñ¡£
ÊÜÓ°ÏìÈí¼þ£º
Windows XP
Windows Server 2003
Windows Vista
Windows Server 2008
Windows 7
Windows 8¡¢8.1
Windows Server 2008 R2
Windows Server 2012¡¢2012 R2
Windows RT¡¢RT 8.1
Îó²îÐÎò£º
Êý×ÖÊðÃûÎó²î - CVE-2013-3869
X.509Ö¤ÊéÑéÖ¤ÆÊÎöÖб£´æ¾Ü¾ø·þÎñÎó²î£¬¿Éµ¼ÖÂÊÜÓ°ÏìWeb·þÎñ×èÖ¹ÏìÓ¦¡£
³§ÉÌ״̬£º
==========
³§ÉÌÒѾÐû²¼ÁËÏà¹Ø²¹¶¡£¬ÇëʵʱʹÓÃWindows update×°ÖÃ×îв¹¶¡¡£
¸½¼ÓÐÅÏ¢£º
==========
1. http://technet.microsoft.com/security/bulletin/MS13-088
2. http://technet.microsoft.com/security/bulletin/MS13-089
3. http://technet.microsoft.com/security/bulletin/MS13-090
4. http://technet.microsoft.com/security/bulletin/MS13-091
5. http://technet.microsoft.com/security/bulletin/MS13-092
6. http://technet.microsoft.com/security/bulletin/MS13-093
7. http://technet.microsoft.com/security/bulletin/MS13-094
8. http://technet.microsoft.com/security/bulletin/MS13-095

AG¹«Ë¾ÔÆ





