¡¾Ç徲ͨ¸æ¡¿Î¢ÈíÐû²¼10Ô²¹¶¡ÐÞ¸´87¸öÇå¾²ÎÊÌâ
2020-10-14
×ÛÊö
΢ÈíÓÚÖܶþÐû²¼ÁË10ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË87¸ö´Ó¼òÆÓµÄÓÕÆ¹¥»÷µ½Ô¶³ÌÖ´ÐдúÂëµÄÇå¾²ÎÊÌ⣬²úÆ·Éæ¼°.NET Framework¡¢Azure¡¢Group Policy¡¢Microsoft Dynamics¡¢Microsoft Exchange Server¡¢Microsoft Graphics Component¡¢Microsoft NTFS¡¢Microsoft Office¡¢Microsoft Office SharePoint¡¢Microsoft Windows¡¢Microsoft Windows Codecs Library¡¢PowerShellGet¡¢Visual Studio¡¢Windows COM¡¢Windows Error Reporting¡¢Windows Hyper-V¡¢Windows Installer¡¢Windows Kernel¡¢Windows Media Player¡¢Windows RDPÒÔ¼°Windows Secure Kernel Mode¡£
Critical & ImportantÎó²î¸ÅÊö
±¾´Î΢Èí¹²ÐÞ¸´ÁË11¸öCritical¼¶±ðÎó²î£¬75 ¸ö Important ¼¶±ðÎó²î£¬1¸öModerate ¼¶±ðÎó²î¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£
²¿·Ö Critical ¼°Important Îó²îÐÎòÈçÏ£º
Windows TCP / IPÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-16898£¬´úºÅ Bad Neighbor£©
ÓÉÓÚWindows TCP/IP¿Íջδ׼ȷ´¦Öóͷ£OptionÀàÐÍΪ 25£¨µÝ¹éDNS·þÎñÆ÷£©ÇÒLength×Ö¶ÎֵΪżÊýµÄ?ICMPv6 Router AdvertisementÊý¾Ý°ü£¬µ¼Ö¹¥»÷Õßͨ¹ý·¢ËͶñÒâÖÆ×÷µÄICMPv6 Router AdvertisementÊý¾Ý°ü£¬ÓпÉÄÜÔÚÔ¶³ÌϵͳÉÏÖ´ÐÐí§Òâ´úÂ롣΢ÈíÔÚͨ¸æÖÐÌåÏÖ´ËÎó²îºÜÓпÉÄܱ»Ê¹Óá£
¹Ù·½ÆÀ¼¶ Critical£¬CVSSÆÀ·Ö 9.8 £º
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16898
Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-16951£¬CVE-2020-16952£©
Îó²îÔ´ÓÚ³ÌÐòδ׼ȷÑéÖ¤Ó¦ÓóÌÐò°üµÄÔ´±ê¼Ç¡£ÒªÊ¹ÓÃÕâÁ½¸öÎó²î£¬¹¥»÷ÕßÐèÒª½«ÌØÖƵÄSharePointÓ¦ÓóÌÐò°üÉÏ´«µ½ÊÜÓ°Ïì°æ±¾µÄSharePoint£¬ÒÔÖ´ÐÐí§Òâ´úÂë¡£ÈôÊÇ·þÎñÆ÷µÄÉèÖÃÔÊÐí£¬»¹¿ÉÒÔÓÉûÓÐÌØÈ¨µÄSharePointÓû§Íê³É´Ë²Ù×÷¡£
¹Ù·½ÆÀ¼¶ Critical£¬CVSSÆÀ·Ö 8.6 £º
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L/E:P/RL:O/RC:C
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16951
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16952
Base3DÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17003£©
µ±Base3DäÖȾÒýÇæÎ´×¼È·´¦Öóͷ£ÄÚ´æÊ±£¬±£´æÒ»¸öÔ¶³ÌÖ´ÐдúÂëÎó²î¡£
ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß½«ÔÚÊÜÓ°ÏìϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£
¹Ù·½ÆÀ¼¶ Critical£¬CVSSÆÀ·Ö 7.8 £º
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-17003
Microsoft OutlookÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-16947£©
Îó²î±£´æÓÚÆÊÎöµç×ÓÓʼþÀïHTMLÄÚÈݵÄÀú³ÌÖУ¬³ÌÐòÔÚ½«Óû§ÌṩµÄÊý¾Ý¸´ÖƵ½Àο¿³¤¶ÈµÄ»º³åÇøÖ®Ç°£¬Ã»ÓÐÑéÖ¤Æä³¤¶È¡£¹¥»÷Õß¿ÉÄÜ»áͨ¹ý·¢ËÍÌØÖÆµÄµç×ÓÓʼþÀ´Ê¹ÓøÃÎó²î£¬ÓÉÓÚÔ¤ÀÀ´°¸ñÒ²¿É±»×÷Ϊ¹¥»÷ǰÑÔ£¬Òò´ËÖ»ÒªÊÕ¼þÈËÔÚOutlookÓʼþ¿Í»§¶ËÖÐÉó²é¸ÃÓʼþ£¨°üÀ¨ÔÚÔ¤ÀÀ´°¸ñÖÐÔ¤ÀÀÓʼþ£©¾Í¿ÉÄÜÊܵ½Ó°Ïì¡£
ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚϵͳÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£Ö»¹Ü΢ÈíÔÚͨ¸æÖÐÌåÏÖ¸ÃÎó²î²»Ì«¿ÉÄܱ»Ê¹Ó㬵«¾ÝZDI ÌåÏÖ£¬ÒÑÕÆÎÕÓÐÓÃµÄ PoC£¬¹ÊÐ뾡¿ìÐÞ²¹¡£
¹Ù·½ÆÀ¼¶ Critical£¬CVSSÆÀ·Ö 8.1 £º
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16947
Windows Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-16891£©
Îó²îÔµÓÚËÞÖ÷»ú·þÎñÆ÷ÉϵÄWindows Hyper-VÎÞ·¨×¼È·ÑéÖ¤¿Í»§»ú²Ù×÷ϵͳÉϾÓÉÉí·ÝÑéÖ¤µÄÓû§ÊäÈë¡£¹¥»÷Õß¿ÉÄÜ»áͨ¹ýÔÚ¿Í»§»ú²Ù×÷ϵͳÉÏÔËÐÐÌØÖÆµÄÓ¦ÓóÌÐòÀ´Ê¹ÓøÃÎó²î£¬×îÖÕʵÏÖÔÚHyper-VËÞÖ÷»ú²Ù×÷ϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£
¹Ù·½ÆÀ¼¶ Critical£¬CVSSÆÀ·Ö 8.8 £º
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16891
MicrosoftͼÐÎ×é¼þÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-16923£©
Îó²î±£´æÓÚMicrosoftͼÐÎ×é¼þ´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄÀú³ÌÖС£ÈôҪʹÓøÃÎó²î£¬¹¥»÷ÕßÐ뽨ÉèÒ»¸öÌØÖÆÎļþ²¢Ëµ·þÄ¿µÄ·¿ª¸ÃÎļþ£¬Õâ¿ÉÒÔͨ¹ýÓÐÕë¶ÔÐÔµÄÉç»á¹¤³ÌѧÀ´ÊµÏÖ¡£ÀֳɵÄʹÓý«Ê¹¹¥»÷Õß¿ÉÒÔÔÚÊÜÎó²îÓ°ÏìµÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£
¹Ù·½ÆÀ¼¶ Critical£¬CVSSÆÀ·Ö 7.8 £º
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16923
Windows TCP / IP¾Ü¾ø·þÎñÎó²î£¨CVE-2020-16899£©
ÓëCVE-2020-16898ÏàËÆ£¬CVE-2020-16899Ò²ÊÇWindows TCP/IP¿ÍÕ»ÖеÄÎó²î¡£¸ÃÎó²îÒ²ÊÇÓÉÓÚ¶ÔICMPv6 Router AdvertisementÊý¾Ý°ü´¦Öóͷ£²»µ±¶øµ¼Öµġ£ÒªÊ¹ÓôËÎó²î£¬¹¥»÷ÕßÐèÒª·¢ËÍÈ«ÐÄÖÆ×÷µÄICMPv6Router AdvertisementÊý¾Ý°ü£¬×îÖÕ¿ÉÄܵ¼ÖÂϵͳ×èÖ¹ÏìÓ¦¡£
¹Ù·½ÆÀ¼¶ Important£¬CVSSÆÀ·Ö 7.5 £º
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16899
Windows¹ýʧ±¨¸æÌáȨÎó²î£¨CVE-2020-16909£©
Windows¹ýʧ±¨¸æ£¨WER£©×é¼þÖеÄÌØÈ¨ÌáÉý£¨EoP£©Îó²îÔÊÐí¹¥»÷Õß»ñµÃ¶ÔÃô¸ÐÐÅÏ¢ºÍϵͳ¹¦Ð§µÄ¸ü´ó»á¼ûȨÏÞ¡£¸ÃÎó²îÊÇÔÚÔ¶ȸüÐÂÐû²¼Ç°¾ÍÒѱ»¹ûÕæÁ˵ÄÎó²îÖ®Ò»¡£
Ö»¹Ü΢ÈíÌåÏÖ´ËCVEδ±£´æ¹ûÕæÊ¹Ó㬵«ÔÚ´ËǰµÄһƪ±¨µÀÖÐÏÔʾ£¬WER ×é¼þÖеÄȱÏÝÒÑÔÚÎÞÎļþ¹¥»÷Öб»ÆÕ±éÓ¦Óá£
¹Ù·½ÆÀ¼¶ Important£¬CVSSÆÀ·Ö 7.8 £º
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16909

AG¹«Ë¾ÔÆ







