΢ÈíÐû²¼6Ô·Ý7¸öÇ徲ͨ¸æ ÐÞ¸´ÁË66¸öÇå¾²Îó²î (Alert2014-07)
2014-06-11
ÐÎò£º
΢ÈíÐû²¼ÁË6Ô·Ý7¸öÇ徲ͨ¸æ£ºMS14-030µ½MS14-036£¬ÐÞ¸´ÁËMicrosoft RDP, TCPÐÒé, MS Lync, MSXML, MS Word, Internet Explorer, MS GDI+ÖеÄÇå¾²Îó²î¹²¼Æ66¸ö£¬ÆäÖаüÀ¨59¸öIEä¯ÀÀÆ÷µÄÇå¾²Îó²î¡£ÎÒÃÇÇ¿ÁÒ½¨ÒéʹÓÃWindows²Ù×÷ϵͳµÄÓû§Á¬Ã¦¼ì²éÒ»ÏÂÄúµÄϵͳÊÇ·ñÊÜÕâЩÎó²îÓ°Ï죬²¢ÊµÊ±×°Öò¹¶¡¡£
ÆÊÎö£º
1¡¢MS14-030´Ë¸üнâ¾öÁËMicrosoft WindowsÄÚÒ»¸öÉñÃØ±¨¸æµÄÎó²î¡£ÈôÊǹ¥»÷ÕßÔÚÔ˶¯RDP»á»°Ê±¿ÉÒÔ»á¼ûÄ¿µÄϵͳÏàͬµÄÍøÂç·Ö¶Î£¬È»ºó·¢ËÍÌØÖÆµÄRDPÊý¾Ý°üµ½Ä¿µÄϵͳ£¬Ôò¸ÃÎó²î¿Éµ¼Ö¸Ķ¯¡£
ÊÜÓ°ÏìÈí¼þ£º
Windows 7
Windows 8
Windows 8.1
Windows Server 2012
Windows Server 2012 R2
Îó²îÐÎò£º
RDP MACÎó²î - CVE-2014-0296
Ô¶³Ì×ÀÃæÐÒé±£´æ¸Ä¶¯Îó²î£¬¿Éʹ¹¥»÷ÕßÐÞ¸ÄÔ˶¯RDP»á»°µÄͨѶÄÚÈÝ¡£
ÔÝʱ½â¾ö¼Æ»®£º
* È·±£ÔÚÔËÐÐWindows 7, Windows 8, Windows 8.1, Windows Server 2012, Windows Server 2012 R2µÄϵͳÉÏÆôÓÃÁË¡°ÍøÂç¼¶±ðÉí·ÝÑéÖ¤¡±
2¡¢MS14-031
´Ë¸üнâ¾öÁËMicrosoft WindowsÄÚ1¸öÉñÃØ±¨¸æµÄÎó²î¡£ÈôÊǹ¥»÷Õß·¢ËÍһϵÁÐÌØÖÆµÄÊý¾Ý°üµ½Ä¿µÄϵͳ£¬¸ÃÎó²î¿Éµ¼Ö¾ܾø·þÎñ¡£
ÊÜÓ°ÏìÈí¼þ£º
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 8
Windows 8.1
Windows Server 2012
Windows Server 2012 R2
Windows RT
Windows RT 8.1
Îó²îÐÎò£º
TCP¾Ü¾ø·þÎñÎó²î - CVE-2014-1811
Windows TCP/IPÍøÂçÐÒé±£´æ¾Ü¾ø·þÎñÎó²î£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÔì³ÉÊÜÓ°Ïìϵͳ×èÖ¹ÏìÓ¦¡£
3¡¢MS14-032
´Ë¸üнâ¾öÁËMicrosoft Lync ServerÄÚ1¸öÉñÃØ±¨¸æµÄÎó²î¡£ÈôÊÇÓû§µ¥»÷È«ÐĽṹµÄ¾Û»áURLÒÔ±ã¼ÓÈëLync¾Û»á£¬´ËÎó²î¿Éµ¼ÖÂÐÅϢй¶¡£
ÊÜÓ°ÏìÈí¼þ£º
Microsoft Lync Server 2010
Microsoft Lync Server 2013
Îó²îÐÎò£º
Lync ServerÄÚÈݹýÂËÎó²î - CVE-2014-1823
Lync Server¹ýÂËÈ«ÐĽṹµÄÄÚÈÝʧ°Üºó±£´æÐÅϢй¶Îó²î£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÔì³ÉÔÚÓû§ä¯ÀÀÆ÷ÄÚÖ´Ðо籾ÒÔ»ñÈ¡Web»á»°µÄÐÅÏ¢¡£
4¡¢MS14-033
´Ë¸üнâ¾öÁËMicrosoft WindowsÄÚ1¸öÉñÃØ±¨¸æµÄÎó²î¡£ÈôÊÇÒѵÇÈÎÃü»§µÇ¼ÁËÈ«ÐĽṹµÄÍøÕ¾£¬¸ÃÍøÕ¾µÄÄ¿µÄ¾ÍÊÇͨ¹ýIEŲÓÃMSXML£¬Ôò¸ÃÎó²î¿Éµ¼ÖÂÐÅϢй¶¡£
ÊÜÓ°ÏìÈí¼þ£º
Windows Server 2003 Service Pack 2
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 8
Windows 8.1
Windows Server 2012
Windows Server 2012 R2
Windows RT
Windows RT 8.1
Îó²îÐÎò£º
MSXMLʵÌåURIÎó²î - CVE-2014-1816
Microsoft WindowsÆÊÎöXMLÄÚÈÝʱ±£´æÐÅϢй¶Îó²î£¬¿Éʹ¹¥»÷ÕßδÊÚȨ»á¼ûÃô¸ÐÐÅÏ¢¡£
ÔÝʱ½â¾ö¼Æ»®£º
* ÔÚIEÖÐեȡʹÓÃMSXML 3.0¶þ½øÖÆÐÐΪ¡£
* ÉèÖÃIEÔÚÔËÐÐASÌõ¼þʾ»òÔÚ»¥ÁªÍø¼°ÄÚÁªÍøÇå¾²ÇøÓòÄÚ½ûÓÃAS¡£
* ½«»¥ÁªÍø¼°ÄÚÁªÍøÇå¾²ÇøÓòÉèÖÃΪ¡°¸ß¡±ÒÔ×èÖ¹ActiveX¿Ø¼þ¼°AS¡£
5¡¢MS14-034
´Ë¸üнâ¾öÁËMicrosoft OfficeÄÚÒ»¸öÉñÃØ±¨¸æµÄÎó²î¡£ÈôÊÇÔÚÊÜÓ°ÏìWord°æ±¾Öз¿ªÈ«ÐĽṹµÄÎļþ£¬´ËÎó²î¿ÉÔÊÐíÔ¶³Ì´úÂëÖ´ÐС£
ÊÜÓ°ÏìÈí¼þ£º
Microsoft Office 2007
Microsoft Office Compatibility Pack Service Pack 3
Îó²îÐÎò£º
ǶÈë×ÖÌåÎó²î ¨C CVE-2014-2778
Microsoft OfficeÆÊÎöijЩȫÐĽṹµÄÎļþʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÀÖ³ÉʹÓúó¿Éµ¼ÖÂÍêÈ«¿ØÖÆÊÜÓ°Ïìϵͳ¡£
ÔÝʱ½â¾ö¼Æ»®£º
* ²»Òª·¿ª´Ó¿ÉÒÉÔ´ÊÕµ½µÄOfficeÎļþ»òÕß´ÓÐÅÍÐÔ´ÒâÍâÊÕµ½µÄÎļþ¡£
6¡¢MS14-035
´Ë¸üнâ¾öÁËInternet ExplorerÄÚÁ½¸ö¹ûÕæ±¨¸æµÄÎó²îºÍ57¸öÉñÃØ±¨¸æµÄÎó²î¡£ÈôÊÇÓû§ÓÃIEÉó²éÌØÖÆµÄÍøÒ³£¬×îÑÏÖØµÄÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
ÊÜÓ°ÏìÈí¼þ:
Internet Explorer 6
Internet Explorer 7
Internet Explorer 8
Internet Explorer 9
Internet Explorer 10
Internet Explorer 11
Îó²îÐÎò:
1£©TLS·þÎñÆ÷Ö¤ÊéÖØÐÂ̸ÅÐÎó²î - CVE-2014-1771
IE´¦Öóͷ£TLS»á»°ÖеÄÖ¤Êé̸Åз½·¨±£´æÐÅϢй¶Îó²î£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÐ®ÖÆIEºÍÄ¿µÄ·þÎñÆ÷Ö®¼ä¾ÓÉÉí·ÝÑéÖ¤µÄTLSÅþÁ¬¡£
2£©IEÐÅϢй¶Îó²î - CVE-2014-1777
IEÔÚÑéÖ¤ÍâµØÎļþ×°ÖÃʱ±£´æÐÅϢй¶Îó²î¡£
3£©IE¶à¸öȨÏÞÌáÉýÎó²î£ºÎó²î
IE±£´æ¶à¸öȨÏÞÌáÉýÎó²î£¬ÀÖ³ÉʹÓúó¿ÉÌáÉý¹¥»÷ÕßÔÚÊÜÓ°ÏìIE°æ±¾ÄÚµÄȨÏÞ¡£ÕâЩÎó²î°üÀ¨£º
Internet ExplorerȨÏÞÌáÉýÎó²î£ºCVE-2014-1764
Internet ExplorerȨÏÞÌáÉýÎó²î£º CVE-2014-1778
Internet ExplorerȨÏÞÌáÉýÎó²î£º CVE-2014-2777
4£©IEÄÚ¶à¸öÄÚ´æÆÆËðÎó²î
Internet Explorer ûÓÐ׼ȷ»á¼ûÄڴ湤¾ß£¬ÔÚʵÏÖÉϱ£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÀÖ³ÉʹÓúó¿ÉÆÆËðÄڴ棬ÔÚÄ¿½ñÓû§È¨ÏÞÏÂÖ´ÐÐí§Òâ´úÂë¡£ÕâЩÎó²î°üÀ¨£º
IEÄÚ´æÆÆËðÎó²î CVE-2014-0282
IEÄÚ´æÆÆËðÎó²î CVE-2014-1762
IEÄÚ´æÆÆËðÎó²î CVE-2014-1769
IEÄÚ´æÆÆËðÎó²î CVE-2014-1770
IEÄÚ´æÆÆËðÎó²î CVE-2014-1772
IEÄÚ´æÆÆËðÎó²î CVE-2014-1773
IEÄÚ´æÆÆËðÎó²î CVE-2014-1774
IEÄÚ´æÆÆËðÎó²î CVE-2014-1775
IEÄÚ´æÆÆËðÎó²î CVE-2014-1766
IEÄÚ´æÆÆËðÎó²î CVE-2014-1779
IEÄÚ´æÆÆËðÎó²î CVE-2014-1780
IEÄÚ´æÆÆËðÎó²î CVE-2014-1781
IEÄÚ´æÆÆËðÎó²î CVE-2014-1782
IEÄÚ´æÆÆËðÎó²î CVE-2014-1783
IEÄÚ´æÆÆËðÎó²î CVE-2014-1784
IEÄÚ´æÆÆËðÎó²î CVE-2014-1785
IEÄÚ´æÆÆËðÎó²î CVE-2014-1786
IEÄÚ´æÆÆËðÎó²î CVE-2014-1788
IEÄÚ´æÆÆËðÎó²î CVE-2014-1789
IEÄÚ´æÆÆËðÎó²î CVE-2014-1790
IEÄÚ´æÆÆËðÎó²î CVE-2014-1791
IEÄÚ´æÆÆËðÎó²î CVE-2014-1792
IEÄÚ´æÆÆËðÎó²î CVE-2014-1794
IEÄÚ´æÆÆËðÎó²î CVE-2014-1795
IEÄÚ´æÆÆËðÎó²î CVE-2014-1796
IEÄÚ´æÆÆËðÎó²î CVE-2014-1797
IEÄÚ´æÆÆËðÎó²î CVE-2014-1799
IEÄÚ´æÆÆËðÎó²î CVE-2014-1800
IEÄÚ´æÆÆËðÎó²î CVE-2014-1802
IEÄÚ´æÆÆËðÎó²î CVE-2014-1803
IEÄÚ´æÆÆËðÎó²î CVE-2014-1804
IEÄÚ´æÆÆËðÎó²î CVE-2014-1805
IEÄÚ´æÆÆËðÎó²î CVE-2014-2753
IEÄÚ´æÆÆËðÎó²î CVE-2014-2754
IEÄÚ´æÆÆËðÎó²î CVE-2014-2755
IEÄÚ´æÆÆËðÎó²î CVE-2014-2756
IEÄÚ´æÆÆËðÎó²î CVE-2014-2757
IEÄÚ´æÆÆËðÎó²î CVE-2014-2758
IEÄÚ´æÆÆËðÎó²î CVE-2014-2759
IEÄÚ´æÆÆËðÎó²î CVE-2014-2760
IEÄÚ´æÆÆËðÎó²î CVE-2014-2761
IEÄÚ´æÆÆËðÎó²î CVE-2014-2763
IEÄÚ´æÆÆËðÎó²î CVE-2014-2764
IEÄÚ´æÆÆËðÎó²î CVE-2014-2765
IEÄÚ´æÆÆËðÎó²î CVE-2014-2766
IEÄÚ´æÆÆËðÎó²î CVE-2014-2767
IEÄÚ´æÆÆËðÎó²î CVE-2014-2768
IEÄÚ´æÆÆËðÎó²î CVE-2014-2769
IEÄÚ´æÆÆËðÎó²î CVE-2014-2770
IEÄÚ´æÆÆËðÎó²î CVE-2014-2771
IEÄÚ´æÆÆËðÎó²î CVE-2014-2772
IEÄÚ´æÆÆËðÎó²î CVE-2014-2773
IEÄÚ´æÆÆËðÎó²î CVE-2014-2775
IEÄÚ´æÆÆËðÎó²î CVE-2014-2776
ÔÝʱ½â¾ö¼Æ»®£º
* ÉèÖÃIEÔÚÔËÐÐASÌõ¼þʾ»òÔÚ»¥ÁªÍø¼°ÄÚÁªÍøÇå¾²ÇøÓòÄÚ½ûÓÃAS¡£
* ½«»¥ÁªÍø¼°ÄÚÁªÍøÇå¾²ÇøÓòÉèÖÃΪ¡°¸ß¡±ÒÔ×èÖ¹ActiveX¿Ø¼þ¼°AS¡£
7¡¢MS14-036
´Ë¸üнâ¾öÁËMicrosoft Windows, Microsoft Office, Microsoft LyncÄÚ2¸öÉñÃØ±¨¸æµÄÎó²î¡£ÈôÊÇÓû§·¿ªÈ«ÐĽṹµÄÎļþ»òÍøÒ³£¬´ËÎó²î¿ÉÔÊÐíÔ¶³Ì´úÂëÖ´ÐС£
ÊÜÓ°ÏìÈí¼þ:
Windows Server 2003
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 8
Windows 8.1
Windows Server 2012
Windows Server 2012 R2
Windows RT
Windows RT 8.1
Îó²îÐÎò£º
1) Unicode¾ç±¾´¦Öóͷ£Æ÷Îó²î - CVE-2014-1817
ÊÜÓ°Ïì×é¼þ´¦Öóͷ£È«ÐĽṹµÄ×ÖÌåÎļþʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÀÖ³ÉʹÓúó¿ÉÔÊÐíÔ¶³Ì´úÂëÖ´ÐС£
ÔÝʱ½â¾ö¼Æ»®£º
* ½ûÓÃWebClient·þÎñ¡£
* ÔÚ·À»ðǽ×èÖ¹TCP¶Ë¿Ú139ºÍ445
* ÔÚWindows ExplorerÄÚ½ûÓÃÔ¤ÀÀ´°¸ñºÍÏêϸÐÅÏ¢´°¸ñ¡£
2) GDI+ͼÐÎÆÊÎöÎó²î - CVE-2014-1818
GDI+Ñé֤ȫÐĽṹµÄͼÐÎʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÈôÊÇÓû§·¿ªÌØÖƵÄͼÐΣ¬¸ÃÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
ÔÝʱ½â¾ö¼Æ»®£º
* ÐÞ¸Ä×¢²á±í¹Ø±ÕÔ´Îļþ´¦Öóͷ£
* ÔÚLyncÖнûÓÃÊý¾ÝÐ×÷
* ÒÔ´¿Îı¾¶ÁÈ¡µç×ÓÓʼþ
³§ÉÌ״̬£º
==========
³§ÉÌÒѾÐû²¼ÁËÏà¹Ø²¹¶¡£¬ÇëʵʱʹÓÃWindows update×°ÖÃ×îв¹¶¡¡£
¸½¼ÓÐÅÏ¢£º
==========
1. http://technet.microsoft.com/security/bulletin/MS14-030
2. http://technet.microsoft.com/security/bulletin/MS14-031
3. http://technet.microsoft.com/security/bulletin/MS14-032
4. http://technet.microsoft.com/security/bulletin/MS14-033
5. http://technet.microsoft.com/security/bulletin/MS14-034
6. http://technet.microsoft.com/security/bulletin/MS14-035
7. http://technet.microsoft.com/security/bulletin/MS14-036

AG¹«Ë¾ÔÆ





