΢Èí6Ô²¹¶¡ÈÕÐè¹Ø×¢µÄ¸ßΣÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-06-15Îó²î±àºÅºÍ¼¶±ð
CVE-2018-8248 Ö÷Òª
CVE-2018-8231 ÑÏÖØ ³§ÉÌ×ÔÆÀ£º8.1
CVE-2018-8225 ÑÏÖØ ³§ÉÌ×ÔÆÀ£º8.1
CVE-2018-8267 ÑÏÖØ ³§ÉÌ×ÔÆÀ£º6.4
Îó²î¸ÅÊö
6ÔÂ12ÈÕ£¬£¬£¬£¬£¬Î¢ÈíÐû²¼ÁË2018Äê6Ô·ݵÄÔ¶ÈÀýÐÐÇ徲ͨ¸æ£¬£¬£¬£¬£¬ÐÞ¸´ÁËÆä¶à¿î²úÆ·±£´æµÄ122¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£Í¨¸æÖаüÀ¨ÁËMicrosoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8248£©£¬£¬£¬£¬£¬Microsoft Windows HTTPÐÒé¿ÍÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8231£©£¬£¬£¬£¬£¬Windows DNSAPIÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-8225£©¼°Microsoft Internet Explorer¾ç±¾ÒýÇæÄÚ´æÆÆËðÎó²î£¨CVE-2018-8267£©¡£¡£¡£¡£¡£¡£
ÀÖ³ÉʹÓÃMicrosoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²îµÄ¹¥»÷Õߣ¬£¬£¬£¬£¬ÄÜÔÚÄ¿½ñÓû§ÇéÐÎÏÂÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíԱȨÏ޵Ǽ£¬£¬£¬£¬£¬¹¥»÷ÕßÉõÖÁ¿ÉÒÔÍêÈ«¿ØÖƸÃÓû§µÄϵͳ¡£¡£¡£¡£¡£¡£Microsoft Office 2010 Service Pack 2¡¢Microsoft Office 2013 RT Service Pack 1¡¢Microsoft Office 2013 Service Pack 1¡¢Microsoft Office 2016¡¢Microsoft Office 2016 Click-to-Run (C2R)µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£
ÀÖ³ÉʹÓÃMicrosoft Windows HTTP 2.0ÐÒé¿ÍÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²îµÄ¹¥»÷Õߣ¬£¬£¬£¬£¬¿ÉÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬²¢¿ØÖƸÃÓû§µÄϵͳ¡£¡£¡£¡£¡£¡£Windows 10¡¢Windows 10 Version 1607¡¢Windows 10 Version 1703¡¢Windows 10 Version 1709¡¢Windows 10 Version 1803¡¢Windows Server 2016¡¢Windows Server 2016 (Server Core installation)¡¢Windows Server version 1709 (Server Core Installation)¡¢Windows Server version 1803 (Server Core Installation)µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£
ÀÖ³ÉʹÓÃWindows DNSAPIÔ¶³Ì´úÂëÖ´ÐÐÎó²îµÄ¹¥»÷Õߣ¬£¬£¬£¬£¬¿ÉÒÔÔÚÍâµØÏµÍ³ÕÊ»§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂ룬£¬£¬£¬£¬¶ø¹¥»÷ÕßËùÒª×öµÄ¾ÍÊǽ«Ê¹ÓöñÒâDNSЧÀÍÆ÷ÏòÄ¿µÄ·¢ËÍË𻵵ÄDNSÏìÓ¦¡£¡£¡£¡£¡£¡£Windows 7¡¢Windows 8.1¡¢Windows RT 8.1ºÍWindows 10ÒÔ¼°Windows Server 2008¡¢Windows Server 2008 R2¡¢Windows Server 2012¡¢Windows Server 2012 R2¡¢Windows Server 2016¡¢Windows Server°æ±¾1709ºÍ°æ±¾1803µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£
ÀÖ³ÉʹÓÃMicrosoft Internet Explorer¾ç±¾ÒýÇæÄÚ´æÆÆËðÎó²îµÄ¹¥»÷Õߣ¬£¬£¬£¬£¬¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£¡£¡£¡£¡£¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬£¬£¬£¬£¬ÔòÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£¡£È»ºó¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£¬£¬£¬£¬£¬Éó²é¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£¬£¬£¬£¬£¬»ò½¨Éè¾ßÓÐÍêÕûÓû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£¡£¡£¡£Windows Server 2012¡¢Windows Server 2016¡¢Windows 10¡¢Windows 7¡¢Windows 8.1¡¢Windows RT 8.1¡¢Windows Server 2008 R2¡¢Windows Server 2012 R2ÒÔ¼°Windows Server 2008µÄInternet Explorer 9 ¡¢Internet Explorer 10ºÍInternet Explorer 11µÈ°æ±¾¾ùÊÜÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£
Îó²îÏÈÈÝ
Microsoft ExcelÊÇÃÀ¹ú΢Èí¹«Ë¾ÎªÊ¹ÓÃWindowsºÍApple Macintosh²Ù×÷ϵͳµÄµçÄÔ±àдµÄÒ»¿îµç×Ó±í¸ñÈí¼þ¡£¡£¡£¡£¡£¡£Microsoft Excel±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ¸ÃÈí¼þδÄÜ׼ȷ´¦Öóͷ£ÄÚ´æÖеŤ¾ß£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÏòÓû§·¢Ë;ÓÉÌØÊâ½á¹¹µÄÎļþ²¢ÓÕʹÓû§·¿ª¸ÃÎļþ£¬£¬£¬£¬£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£
Microsoft WindowsÊÇÃÀ¹ú΢Èí¹«Ë¾Ñз¢µÄÒ»Ì×½ÓÄÉÁËͼÐλ¯Ä£Ê½µÄ²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£WindowsÖеÄHTTPÐÒéÊÇÒ»ÖÖͨѶÐÒ飬£¬£¬£¬£¬¼´³¬Îı¾´«ÊäÐÒé¡£¡£¡£¡£¡£¡£Microsoft Windows HTTPÐÒé±£´æ¿ÍÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚHTTP ÐÒé¿ÍջδÄÜ׼ȷ´¦Öóͷ£ÄÚ´æÖеŤ¾ß£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÏòÄ¿µÄhttp.sysЧÀÍÆ÷·¢Ë;ÓÉÌØÊâ½á¹¹µÄÊý¾Ý°ü£¬£¬£¬£¬£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£
ÔÚ΢Èí±¾ÔÂÐÞ¸´µÄËùÓÐÎó²îÖУ¬£¬£¬£¬£¬±»ÒÔΪ×îÑÏÖØµÄÎó²îÊÇCVE-2018-8225¡£¡£¡£¡£¡£¡£Ëü±»ÐÎòΪһ¸öWindows DNSAPIÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îÊÇÓÉÓÚWindows ÓòÃûϵͳ£¨DNS£© DNSAPI.dllÎÞ·¨×¼È·´¦Öóͷ£DNSÏìÓ¦µ¼Öµġ£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÔÚÍâµØÏµÍ³ÕÊ»§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂ룬£¬£¬£¬£¬¶ø¹¥»÷ÕßËùÒª×öµÄ¾ÍÊǽ«Ê¹ÓöñÒâDNSЧÀÍÆ÷ÏòÄ¿µÄ·¢ËÍË𻵵ÄDNSÏìÓ¦¡£¡£¡£¡£¡£¡£
½öÓÐÒ»¸öÎó²îÔÚÐû²¼Ê±±»ÁÐΪ¹ûÕæ£¬£¬£¬£¬£¬ÕâÊÇÒ»¸ö¾ç±¾ÒýÇæÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬Îó²î±àºÅΪCVE-2018-8267£¬£¬£¬£¬£¬¾ç±¾ÒýÇæÔÚInternet ExplorerÖд¦Öóͷ£ÄÚ´æÖеŤ¾ßµÄ·½·¨Öб£´æµÄÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¡£¡£¡£¡£¡£ÔÚ»ùÓÚWebµÄ¹¥»÷ÇéÐÎÖУ¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÍйܾÓÉÌØÖÆµÄÍøÕ¾£¬£¬£¬£¬£¬¸ÃÍøÕ¾Ö¼ÔÚͨ¹ýInternet ExplorerʹÓôËÎó²î£¬£¬£¬£¬£¬È»ºóÓÕʹÓû§Éó²é¸ÃÍøÕ¾¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔÔÚÍйÜIE·ºÆðÒýÇæµÄÓ¦ÓóÌÐò»òMicrosoft OfficeÎĵµÖÐǶÈë±ê¼ÇΪ¡®Çå¾²³õʼ»¯¡¯µÄActiveX¿Ø¼þ¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔʹÓÃÊܵ½ÍþвµÄÍøÕ¾ºÍ½ÓÊÜ»òÍйÜÓû§ÌṩµÄÄÚÈÝ»ò¹ã¸æµÄÍøÕ¾¡£¡£¡£¡£¡£¡£ÕâÐ©ÍøÕ¾¿ÉÄܰüÀ¨¿ÉʹÓôËÎó²îµÄÌØÖÆÄÚÈÝ¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Ò飺
ÏÖÔÚ£¬£¬£¬£¬£¬Î¢Èí¹Ù·½ÒѾÐû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬£¬£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ï죬£¬£¬£¬£¬¾¡¿ì½ÓÄÉÐÞ²¹²½·¥£¬£¬£¬£¬£¬ÒÔ×èֹDZÔÚµÄÇå¾²Íþв¡£¡£¡£¡£¡£¡£ÏëÒª¾ÙÐиüУ¬£¬£¬£¬£¬Ö»Ðèתµ½ÉèÖáú¸üкÍÇå¾²¡úWindows¸üСú¼ì²é¸üУ¬£¬£¬£¬£¬»òÕßÒ²¿ÉÒÔͨ¹ýÊÖ¶¯¾ÙÐиüС£¡£¡£¡£¡£¡£
ÏÖÔÚÒѾ·¢Ã÷ÓÐʹÓÃCVE-2018-8248Îó²îµÄľÂí£¬£¬£¬£¬£¬Ïà¹ØÁ´½Ó£ºhttps://www.symantec.com/security-center/writeup/2018-061314-3210-99¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó£º
https://portal.msrc.microsoft.com/en-us/security-guidance/acknowledgments


¾©¹«Íø°²±¸11010802024551ºÅ