¡¾Íþвͨ¸æ¡¿Î¢ÈíÐû²¼1Ô²¹¶¡ÐÞ¸´49¸öÇå¾²ÎÊÌâ
2020-01-14
×ÛÊö
΢ÈíÓÚÖܶþÐû²¼ÁË1ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË49¸ö´Ó¼òÆÓµÄÓÕÆ¹¥»÷µ½Ô¶³ÌÖ´ÐдúÂëµÄÇå¾²ÎÊÌ⣬²úÆ·Éæ¼°.NET Framework¡¢Apps¡¢ASP.NET¡¢Common Log File System Driver¡¢Microsoft Dynamics¡¢Microsoft Graphics Component¡¢Microsoft Office¡¢Microsoft Scripting Engine¡¢Microsoft Windows¡¢Microsoft Windows Search Component¡¢Windows Hyper-V¡¢Windows Media¡¢Windows RDP¡¢Windows Subsystem for LinuxÒÔ¼°Windows Update Stack¡£
±¾ÔÂ΢ÈíÔ¶ȸüÐÂÐÞ¸´µÄÎó²îÖУ¬ÑÏÖØË®Æ½ÎªÒªº¦£¨Critical£©µÄÎó²î¹²ÓÐ 8 ¸ö£¬»®·Ö±£´æÓÚ .NET Framework¡¢ASP.NET¡¢Microsoft Scripting EngineÒÔ¼°Windows RDPÖС£³ý´ËÖ®Í⣬»¹°üÀ¨41¸öÖ÷Òª£¨Important£©Îó²î¡£
CriticalÎó²î¸ÅÊö
ÒÔÏÂΪ´Ë´Î¸üÐÂÖаüÀ¨µÄ8¸öCritical¼¶±ðÎó²î¡£
Windows RDP
- CVE-2020-0609¡¢CVE-2020-0610
ÕâÁ½¸öWindowsÔ¶³Ì×ÀÃæÍø¹Ø£¨RDÍø¹Ø£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î¿É±»Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßʹÓá£
ÈôÊÇʹÓÃÀֳɣ¬Ôò¿ÉÄÜÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ롣Ȼºó£¬¹¥»÷Õß¿ÉÄÜ»á×°ÖóÌÐò¡£Éó²é£¬¸ü¸Ä»òɾ³ýÊý¾Ý£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£
ҪʹÓôËÎó²î£¬¹¥»÷Õß½«ÐèҪͨ¹ýRDPÏòÄ¿µÄϵͳRDÍø¹Ø·¢ËÍÌØÖÆÇëÇó¡£
±¾´Î¸üÐÂͨ¹ý¸üÕýRDÍø¹Ø´¦Öóͷ£ÅþÁ¬ÇëÇóµÄ·½·¨À´½â¾ö¸ÃÎÊÌâ¡£
¹ØÓÚÎó²îµÄ¸ü¶àÏêÇé¼°¸üÐÂÏÂÔØ£¬Çë²Î¿¼Î¢Èí¹Ù·½Ç徲ͨ¸æ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0609
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0610
- CVE-2020-0611
ÕâÊÇ WindowsÔ¶³Ì×ÀÃæ¿Í»§¶ËÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£
ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÅþÁ¬µ½¶ñÒâ·þÎñÆ÷µÄÓû§ÅÌËã»úÉÏÖ´ÐÐí§Òâ´úÂ롣Ȼºó£¬¹¥»÷Õß¿ÉÄÜ»á×°ÖóÌÐò¡£Éó²é£¬¸ü¸Ä»òɾ³ýÊý¾Ý£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£
ҪʹÓôËÎó²î£¬¹¥»÷ÕßÐèÒª¿ØÖÆ·þÎñÆ÷£¬È»ºóÓÕʹÓû§ÅþÁ¬µ½¸Ã·þÎñÆ÷¡£ÈôÊÇÓû§»á¼ûÁ˶ñÒâµÄ·þÎñÆ÷£¬Ôò¿ÉÒÔ´¥·¢´ËÎó²î¡£ËäÈ»¹¥»÷ÕßÎÞ·¨Ç¿ÆÈÓû§ÅþÁ¬µ½¶ñÒâ·þÎñÆ÷£¬µ«ËûÃÇ¿ÉÄÜ»áͨ¹ýÉ繤£¬DNSÖж¾»òÖÐÐÄÈË£¨MITM£©ÊÖÒÕÓÕʹÓû§¾ÙÐÐÅþÁ¬¡£¹¥»÷Õß»¹¿ÉÄÜÆÆËðÕýµ±·þÎñÆ÷£¬ÔÚÆäÉÏÍйܶñÒâ´úÂ룬ȻºóÆÚ´ýÓû§ÅþÁ¬¡£
¹ØÓÚÎó²îµÄ¸ü¶àÏêÇé¼°¸üÐÂÏÂÔØ£¬Çë²Î¿¼Î¢Èí¹Ù·½Ç徲ͨ¸æ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0611
Microsoft Scripting Engine
- CVE-2020-0640
ÕâÊÇ Internet Explorer ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨Öб£´æµÄÒ»¸öÄÚ´æËð»µÎó²î¡£¸ÃÎó²îʹ¹¥»÷Õß¿ÉÒÔÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£
ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬Ôò¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£È»ºó£¬¿ÉÄÜ»á×°ÖóÌÐò¡£Éó²é£¬¸ü¸Ä»òɾ³ýÊý¾Ý£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£
¹¥»÷Õß¿ÉÄÜ»á´î½¨Ò»¸öÌØÖÆµÄÍøÕ¾£¬È»ºóÓÕʹÓû§Éó²é¸ÃÍøÕ¾¡£²»¹ý¹¥»÷ÕßÎÞ·¨Ç¿ÆÈÓû§Éó²é¶ñÒâÄÚÈÝ¡£ÒÔÊÇͨ³£»áͨ¹ýµç×ÓÓʼþ»ò¼´Ê±ÐÂÎŵķ½·¨À´ÓÕµ¼Óû§¡£
Internet Explorer 9¡¢10¡¢11 ¾ùÊÜÓ°Ïì¡£
¹ØÓÚÎó²îµÄ¸ü¶àÏêÇé¼°¸üÐÂÏÂÔØ£¬Çë²Î¿¼Î¢Èí¹Ù·½Ç徲ͨ¸æ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0640
ASP.NET ºÍ.NET Framework
- CVE-2020-0603 ¡¢CVE-2020-0605¡¢CVE-2020-0606¡¢CVE-2020-0646
ÒÔÉÏÎó²îÊÇ.NETºÍASP.NET½¹µãÈí¼þÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£ÈôÊÇÓû§ÔÚʹÓÃÊÜÓ°ÏìµÄ.NET»òASP.NET Core°æ±¾Ê±·¿ª¶ñÒâµÄÌØÖÆÎļþ£¬Ôò¿ÉÒÔ´¥·¢ÕâЩÎó²î¡£ÈôÊÇʹÓÃÀֳɣ¬¹¥»÷Õß±ã¿ÉÒÔÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£ÕâЩ¹ýʧ±£´æÓÚÈí¼þ´¦Öóͷ£Äڴ湤¾ßµÄ·½·¨ÖС£
¹ØÓÚÎó²îµÄ¸ü¶àÏêÇé¼°¸üÐÂÏÂÔØ£¬Çë²Î¿¼Î¢Èí¹Ù·½Ç徲ͨ¸æ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0603
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0605
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0606
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0646
ImportantÎó²î¸ÅÊö
³ýÁËCriticalÎó²îÍ⣬´Ë´Î¸üл¹°üÀ¨ÁË41¸öimportant ¼¶±ðÎó²î£¬ÆäÖÐ3½ÏÐè¹Ø×¢µÄÎó²îÈçÏ¡£
CVE-2020-0601
ÕâÊÇWindows CryptoAPIÖеÄÒ»¸öÓÕÆÎó²î¡£ÓÉÓÚcrypt32.dll²»×¼È·µØÑéÖ¤ÁËÍÖÔ²ÇúÏßÃÜÂëÖ¤Êé¡£¹¥»÷Õß¿ÉÄÜʹÓô˹ýʧÀ´ÓÕÆ´úÂëÊðÃûÖ¤Êé²¢ÉñÃØÊðÃûÎļþ£¬´Ó¶øÊ¹¸ÃÎļþ¿´ÆðÀ´ËƺõÀ´×ÔÊÜÐÅÍеÄÔ´¡£¹¥»÷ÕßÒ²¿ÉÄÜʹÓôËÎó²î¾ÙÐÐÖÐÐÄÈ˹¥»÷²¢½âÃÜÉñÃØÐÅÏ¢¡£
¹ØÓÚÎó²îµÄ¸ü¶àÏêÇé¼°¸üÐÂÏÂÔØ£¬Çë²Î¿¼Î¢Èí¹Ù·½Ç徲ͨ¸æ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601
CVE-2020-0616
ÕâÊÇÒ»¸öMicrosoft Windows¾Ü¾ø·þÎñÎó²î¡£µ±WindowsÎÞ·¨×¼È·´¦Öóͷ£Ó²Á´½Óʱ£¬±£´æ¸ÃÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÄܵ¼ÖÂÄ¿µÄϵͳ×èÖ¹ÏìÓ¦¡£
¹¥»÷Õß±ØÐèµÇ¼Êܺ¦ÕßÅÌËã»úÒÔʹÓôËÎó²î£¬È»ºóÔËÐÐ¾ÌØÊâÉè¼ÆµÄÓ¦ÓóÌÐò£¬¸ÃÎó²î½«Ê¹¹¥»÷Õß¿ÉÒÔÁýÕÖϵͳÎļþ¡£
¹ØÓÚÎó²îµÄ¸ü¶àÏêÇé¼°¸üÐÂÏÂÔØ£¬Çë²Î¿¼Î¢Èí¹Ù·½Ç徲ͨ¸æ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0616
CVE-2020-0654
AndroidµÄMicrosoft OneDriveÓ¦ÓóÌÐòÖб£´æÒ»¸öÇå¾²¹¦Ð§ÈƹýÎó²î¡£Õâ¿ÉÄÜʹ¹¥»÷Õß¿ÉÒÔÈÆ¹ýÓ¦ÓóÌÐòµÄÃÜÂë»òÖ¸ÎÆ¡£
¹ØÓÚÎó²îµÄ¸ü¶àÏêÇé¼°¸üÐÂÏÂÔØ£¬Çë²Î¿¼Î¢Èí¹Ù·½Ç徲ͨ¸æ£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0654
ÐÞ¸´¸Å¿ö
±¾´Î¸üеÄÎó²îÐÞ¸´ÇéÐμûÏÂ±í£º
| ²úÆ· | CVE ±àºÅ | CVE ÎÊÌâ | ÑÏÖØË®Æ½ |
| .NET Framework | CVE-2020-0605 | .NET Framework Ô¶³Ì´úÂëÖ´ÐÐÎó²î | Critical |
| .NET Framework | CVE-2020-0606 | .NET Framework Ô¶³Ì´úÂëÖ´ÐÐÎó²î | Critical |
| .NET Framework | CVE-2020-0646 | .NET Framework Remote Code Execution Injection Vulnerability | Critical |
| Apps | CVE-2020-0654 | Microsoft OneDrive for Android Çå¾²¹¦Ð§ÈƹýÎó²î | Important |
| ASP.NET | CVE-2020-0602 | ASP.NET Core ¾Ü¾ø·þÎñÎó²î | Important |
| ASP.NET | CVE-2020-0603 | ASP.NET Core Ô¶³Ì´úÂëÖ´ÐÐÎó²î | Critical |
| Common Log File System Driver | CVE-2020-0615 | Windows Common Log File System Driver ÐÅϢй¶Îó²î | Important |
| Common Log File System Driver | CVE-2020-0639 | Windows Common Log File System Driver ÐÅϢй¶Îó²î | Important |
| Common Log File System Driver | CVE-2020-0634 | Windows Common Log File System Driver ÌØÈ¨ÌáÉýÎó²î | Important |
| Microsoft Dynamics | CVE-2020-0656 | Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability | Important |
| Microsoft Graphics Component | CVE-2020-0607 | Microsoft Graphics Components ÐÅϢй¶Îó²î | Important |
| Microsoft Graphics Component | CVE-2020-0622 | Microsoft Graphics Component ÐÅϢй¶Îó²î | Important |
| Microsoft Graphics Component | CVE-2020-0642 | Win32k ÌØÈ¨ÌáÉýÎó²î | Important |
| Microsoft Graphics Component | CVE-2020-0643 | Windows GDI+ ÐÅϢй¶Îó²î | Important |
| Microsoft Office | CVE-2020-0647 | Microsoft Office Online ÓÕÆÎó²î | Important |
| Microsoft Office | CVE-2020-0650 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î | Important |
| Microsoft Office | CVE-2020-0651 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î | Important |
| Microsoft Office | CVE-2020-0652 | Microsoft Office ÄÚ´æÆÆËðÎó²î | Important |
| Microsoft Office | CVE-2020-0653 | Microsoft Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î | Important |
| Microsoft Scripting Engine | CVE-2020-0640 | Internet Explorer ÄÚ´æÆÆËðÎó²î | Critical |
| Microsoft Windows | CVE-2020-0601 | Windows CryptoAPI ÓÕÆÎó²î | Important |
| Microsoft Windows | CVE-2020-0608 | Win32k ÐÅϢй¶Îó²î | Important |
| Microsoft Windows | CVE-2020-0616 | Microsoft Windows ¾Ü¾ø·þÎñÎó²î | Important |
| Microsoft Windows | CVE-2020-0620 | Microsoft Cryptographic Services ÌØÈ¨ÌáÉýÎó²î | Important |
| Microsoft Windows | CVE-2020-0621 | Windows Çå¾²¹¦Ð§ÈƹýÎó²î | Important |
| Microsoft Windows | CVE-2020-0624 | Win32k ÌØÈ¨ÌáÉýÎó²î | Important |
| Microsoft Windows | CVE-2020-0635 | Windows ÌØÈ¨ÌáÉýÎó²î | Important |
| Microsoft Windows | CVE-2020-0644 | Windows ÌØÈ¨ÌáÉýÎó²î |
$(".info_chag img").each(function () {
$(this).css({ "max-width": "100%","height": "auto","display":"inline-block" }).parent().css({"text-align":"center"});
});
?
ÄúµÄÁªÏµ·½·¨? 2026 NSFOCUS AG¹«Ë¾¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ |

AG¹«Ë¾ÔÆ





