¡¾Ç徲ͨ¸æ¡¿Î¢ÈíÐû²¼12Ô²¹¶¡ÐÞ¸´58¸öÇå¾²ÎÊÌâ
2020-12-09
×ÛÊö
΢ÈíÓÚÖܶþÐû²¼ÁË12ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË58¸ö´Ó¼òÆÓµÄÓÕÆ¹¥»÷µ½Ô¶³ÌÖ´ÐдúÂëµÄÇå¾²ÎÊÌ⣬ÆäÖÐCritical¼¶±ðÎó²î9¸ö£¬Important ¼¶±ðÎó²î47 ¸ö£¬Moderate¼¶±ðÎó²î2¸ö¡£Ç¿ÁÒ½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖøüС£
ÊÜÓ°Ïì²úÆ·Éæ¼°Azure DevOps¡¢Azure SDK¡¢Azure Sphere¡¢Microsoft Dynamics¡¢Microsoft Edge¡¢Microsoft Exchange Server¡¢Microsoft Graphics Component¡¢Microsoft Office¡¢Microsoft Office SharePoint¡¢Microsoft Windows¡¢Microsoft Windows DNS¡¢Visual Studio¡¢Windows Backup Engine¡¢Windows Error Reporting¡¢Windows Hyper-V¡¢Windows Lock Screen¡¢Windows MediaÒÔ¼°Windows SMB¡£
Critical & ImportantÎó²î¸ÅÊö
²¿·Ö Critical ¼°Important Îó²îÐÎòÈçÏ£º
Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17132¡¢CVE-2020-17142£©
ÕâÁ½¸öÎó²îÊÇÓɳÌÐò¶Ôcmdlet²ÎÊýµÄÑéÖ¤²»×¼È·Ôì³É£¬¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßʹÓøÃÎó²î¿ÉÔÚÎÞÐèÓû§½»»¥µÄÇéÐÎÏÂʵÏÖÔ¶³Ì´úÂëÖ´ÐС£
¹Ù·½ÆÀ¼¶ Critical£¬CVSS:3.0 9.1/8.2
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17132
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17142
Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17121£©
¸ÃÎó²îÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚ SharePoint WebÓ¦ÓóÌÐò·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ .NET ´úÂë¡£ÔÚÆäĬÈÏÉèÖÃÖУ¬¾ÓÉÉí·ÝÑéÖ¤µÄSharePointÓû§Äܹ»½¨ÉèÌṩÐëҪȨÏÞµÄÕ¾µã£¬¶øÕâЩȨÏÞǡǡÊÇÌᳫ¹¥»÷µÄÏȾöÌõ¼þ¡£
¹Ù·½ÆÀ¼¶ Critical£¬CVSS:3.0 8.8/7.7
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17121
Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17095£©
Äܹ»ÔÚHyper-V¿Í»§»úÉÏÖ´ÐÐÌØÖÆÈí¼þµÄ¹¥»÷Õߣ¬Í¨¹ýÏòHyper-VËÞÖ÷»ú·¢ËÍvSMBÊý¾Ý°ü£¬¿ÉÄÜÔÚHyper-VËÞÖ÷»úÉÏÖ´ÐÐí§Òâ´úÂë¡£
¹Ù·½ÆÀ¼¶ Critical£¬CVSS:3.0 8.5/7.4
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17095
Microsoft Exchange 2010Ô¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-17144£©
Îó²îÓɳÌÐò¶Ôcmdlet²ÎÊýµÄÑéÖ¤²»×¼È·Ôì³É£¬¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßʹÓøÃÎó²î¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐС£
¹Ù·½ÆÀ¼¶ Important£¬CVSS:3.0 8.4/7.6
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17144
Windows NTFSÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17096£©
ʹÓøÃÎó²î£¬ÍâµØ¹¥»÷ÕßÔËÐÐÌØÖÆµÄÓ¦ÓóÌÐò¿ÉʵÏÖÌØÈ¨ÌáÉý¡£Äܹ»Í¨¹ýSMBv2»á¼ûųÈõϵͳµÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÍøÂç·¢ËÍÌØÊâÉè¼ÆµÄÇëÇó£¬Ê¹ÓÃÎó²îÔÚÄ¿µÄϵͳÉÏÖ´ÐдúÂë¡£
¹Ù·½ÆÀ¼¶ Important£¬CVSS:3.0 7.5/6.5
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17096

AG¹«Ë¾ÔÆ







