΢Èí6Ô²¹¶¡ÈÕÐè¹Ø×¢µÄ¸ßΣ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-06-15

·ì϶±àºÅºÍ¼¶±ð


CVE-2018-8248  ³ÁÒª


CVE-2018-8231  ÑϳÁ  ³§ÉÌ×ÔÆÀ£º8.1


CVE-2018-8225  ÑϳÁ  ³§ÉÌ×ÔÆÀ£º8.1


CVE-2018-8267  ÑϳÁ  ³§ÉÌ×ÔÆÀ£º6.4


·ì϶¸ÅÊö


6ÔÂ12ÈÕ£¬£¬£¬£¬£¬Î¢Èí°ä²¼ÁË2018Äê6Ô·ݵÄÔ¶ÈÀýÐа²È«²¼¸æ£¬£¬£¬£¬£¬½¨¸´ÁËÆä¶à¿î²úÆ·´æÔÚµÄ122¸ö°²È«·ì϶¡£ ¡£¡£¡£¡£¡£¡£²¼¸æÖÐÔ̺¬ÁËMicrosoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-8248£©£¬£¬£¬£¬£¬Microsoft Windows HTTPºÍ̸²Ö¿âÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-8231£©£¬£¬£¬£¬£¬Windows DNSAPIÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-8225£©¼°Microsoft  Internet Explorer¾ç±¾ÒýÇæÄÚ´æ·ÛËé·ì϶£¨CVE-2018-8267£©¡£ ¡£¡£¡£¡£¡£¡£


³É¹¦ÀûÓÃMicrosoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶µÄ¹¥»÷Õߣ¬£¬£¬£¬£¬ÄÜÔÚµ±Ç°Óû§»·¾³ÏÂÖ´ÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíԱȨÏ޵Ǽ£¬£¬£¬£¬£¬¹¥»÷ÕßÉõÖÁÄܹ»ÆëÈ«½ÚÔì¸ÃÓû§µÄϵͳ¡£ ¡£¡£¡£¡£¡£¡£Microsoft Office 2010 Service Pack 2¡¢Microsoft Office 2013 RT Service Pack 1¡¢Microsoft Office 2013 Service Pack 1¡¢Microsoft Office 2016¡¢Microsoft Office 2016 Click-to-Run (C2R)µÈ°æ±¾¾ùÊÜ·ì϶ӰÏì¡£ ¡£¡£¡£¡£¡£¡£

 

³É¹¦ÀûÓÃMicrosoft Windows HTTP 2.0ºÍ̸²Ö¿âÔ¶³Ì´úÂëÖ´Ðзì϶µÄ¹¥»÷Õߣ¬£¬£¬£¬£¬¿ÉÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬²¢½ÚÔì¸ÃÓû§µÄϵͳ¡£ ¡£¡£¡£¡£¡£¡£Windows 10¡¢Windows 10 Version 1607¡¢Windows 10 Version 1703¡¢Windows 10 Version 1709¡¢Windows 10 Version 1803¡¢Windows Server 2016¡¢Windows Server 2016 (Server Core installation)¡¢Windows Server version 1709 (Server Core Installation)¡¢Windows Server version 1803 (Server Core Installation)µÈ°æ±¾¾ùÊÜ·ì϶ӰÏì¡£ ¡£¡£¡£¡£¡£¡£

 

³É¹¦ÀûÓÃWindows DNSAPIÔ¶³Ì´úÂëÖ´Ðзì϶µÄ¹¥»÷Õߣ¬£¬£¬£¬£¬Äܹ»ÔÚ±¾µØÏµÍ³ÕÊ»§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬¶ø¹¥»÷ÕßËùÒª×öµÄ¾ÍÊǽ«Ê¹ÓöñÒâDNS·þÎñÆ÷ÏòÖ¸±ê·¢ËͰܻµµÄDNSÏìÓ¦¡£ ¡£¡£¡£¡£¡£¡£Windows 7¡¢Windows 8.1¡¢Windows RT 8.1ºÍWindows 10ÒÔ¼°Windows Server 2008¡¢Windows Server 2008 R2¡¢Windows Server 2012¡¢Windows Server 2012 R2¡¢Windows Server 2016¡¢Windows Server°æ±¾1709ºÍ°æ±¾1803µÈ°æ±¾¾ùÊÜ·ì϶ӰÏì¡£ ¡£¡£¡£¡£¡£¡£


³É¹¦ÀûÓÃMicrosoft  Internet Explorer¾ç±¾ÒýÇæÄÚ´æ·ÛËé·ì϶µÄ¹¥»÷Õߣ¬£¬£¬£¬£¬Äܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£ ¡£¡£¡£¡£¡£¡£ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬£¬£¬£¬£¬Ôò³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£ ¡£¡£¡£¡£¡£¡£¶øºó¹¥»÷ÕßÄܹ»×°Ö÷¨Ê½£¬£¬£¬£¬£¬²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£¬£¬£¬£¬£¬»ò´´½¨ÓµÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ¡£¡£¡£¡£¡£¡£Windows Server 2012¡¢Windows Server 2016¡¢Windows 10¡¢Windows 7¡¢Windows 8.1¡¢Windows RT 8.1¡¢Windows Server 2008 R2¡¢Windows Server 2012 R2ÒÔ¼°Windows Server 2008µÄInternet Explorer 9 ¡¢Internet Explorer 10ºÍInternet Explorer 11µÈ°æ±¾¾ùÊÜ·ì϶ӰÏì¡£ ¡£¡£¡£¡£¡£¡£


·ì϶½éÉÜ


Microsoft ExcelÊÇÃÀ¹ú΢Èí¹«Ë¾ÎªÊ¹ÓÃWindowsºÍApple Macintosh²Ù×÷ϵͳµÄµçÄÔ±àдµÄÒ»¿îµç×Ó±í¸ñÈí¼þ¡£ ¡£¡£¡£¡£¡£¡£Microsoft Excel´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬¸Ã·ì϶ԴÓÚ¸ÃÈí¼þδÄÜÕýÈ·´¦ÖÃÄÚ´æÖеĶÔÏ󣬣¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÏòÓû§·¢Ë;­¹ýÌØÊâ»ú¹ØµÄÎļþ²¢ÓÕʹÓû§´ò¿ª¸ÃÎļþ£¬£¬£¬£¬£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´Ðзì϶¡£ ¡£¡£¡£¡£¡£¡£


Microsoft WindowsÊÇÃÀ¹ú΢Èí¹«Ë¾Ñз¢µÄÒ»Ì×ѡȡÁËͼÐλ¯Ä£Ê½µÄ²Ù×÷ϵͳ¡£ ¡£¡£¡£¡£¡£¡£WindowsÖеÄHTTPºÍ̸ÊÇÒ»ÖÖͨѶºÍ̸£¬£¬£¬£¬£¬¼´³¬Îı¾´«ÊäºÍ̸¡£ ¡£¡£¡£¡£¡£¡£Microsoft Windows HTTPºÍ̸´æÔÚ²Ö¿âÔ¶³Ì´úÂëÖ´Ðзì϶¡£ ¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚHTTP ºÍ̸²Ö¿âδÄÜÕýÈ·´¦ÖÃÄÚ´æÖеĶÔÏ󣬣¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÏòÖ¸±êhttp.sys·þÎñÆ÷·¢Ë;­¹ýÌØÊâ»ú¹ØµÄÊý¾Ý°ü£¬£¬£¬£¬£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´Ðзì϶¡£ ¡£¡£¡£¡£¡£¡£


ÔÚ΢Èí±¾Ô½¨¸´µÄËùÓзì϶ÖУ¬£¬£¬£¬£¬±»ÒÔΪ×îÑϳÁµÄ·ì϶ÊÇCVE-2018-8225¡£ ¡£¡£¡£¡£¡£¡£Ëü±»ÃèÊöΪһ¸öWindows DNSAPIÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬¸Ã·ì϶ÊÇÓÉÓÚWindows ÓòÃûϵͳ£¨DNS£© DNSAPI.dllÎÞ·¨ÕýÈ·´¦ÖÃDNSÏìÓ¦µ¼ÖµÄ¡£ ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÔÚ±¾µØÏµÍ³ÕÊ»§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬¶ø¹¥»÷ÕßËùÒª×öµÄ¾ÍÊǽ«Ê¹ÓöñÒâDNS·þÎñÆ÷ÏòÖ¸±ê·¢ËͰܻµµÄDNSÏìÓ¦¡£ ¡£¡£¡£¡£¡£¡£


½öÓÐÒ»¸ö·ì϶Ôڰ䲼ʱ±»ÁÐΪ¹«¿ª£¬£¬£¬£¬£¬ÕâÊÇÒ»¸ö¾ç±¾ÒýÇæÄÚ´æ·ÛËé·ì϶£¬£¬£¬£¬£¬·ì϶±àºÅΪCVE-2018-8267£¬£¬£¬£¬£¬¾ç±¾ÒýÇæÔÚInternet ExplorerÖд¦ÖÃÄÚ´æÖеĶÔÏóµÄ·½Ê½ÖдæÔÚµÄÔ¶³ÌÖ´ÐдúÂë·ì϶¡£ ¡£¡£¡£¡£¡£¡£ÔÚ»ùÓÚWebµÄ¹¥»÷Çé¾°ÖУ¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÍйܾ­¹ýÌØÔìµÄÍøÕ¾£¬£¬£¬£¬£¬¸ÃÍøÕ¾Ö¼ÔÚͨ¹ýInternet ExplorerÀûÓô˷ì϶£¬£¬£¬£¬£¬¶øºóÓÕʹÓû§²é¿´¸ÃÍøÕ¾¡£ ¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹Äܹ»ÔÚÍйÜIE³öÏÖÒýÇæµÄÀûÓ÷¨Ê½»òMicrosoft OfficeÎĵµÖÐǶÈëÏóÕ÷Ϊ¡®°²È«³õʼ»¯¡¯µÄActiveX¿Ø¼þ¡£ ¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹Äܹ»ÀûÓÃÊܵ½ÍþвµÄÍøÕ¾ºÍ½ÓÊÜ»òÍйÜÓû§ÌṩµÄÄÚÈÝ»ò¸æ°×µÄÍøÕ¾¡£ ¡£¡£¡£¡£¡£¡£ÕâÐ©ÍøÕ¾¿ÉÄÜÔ̺¬¿ÉÀûÓô˷ì϶µÄÌØÔìÄÚÈÝ¡£ ¡£¡£¡£¡£¡£¡£


½¨¸´½¨Ò飺


Ŀǰ£¬£¬£¬£¬£¬Î¢Èí¹Ù·½ÒѾ­°ä²¼²¹¶¡½¨¸´ÁËÉÏÊö·ì϶£¬£¬£¬£¬£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½·ì϶ӰÏ죬£¬£¬£¬£¬¾¡¿ì²ÉÈ¡½¨²¹´ëÊ©£¬£¬£¬£¬£¬ÒÔÔ¤·ÀDZÔڵݲȫÍþв¡£ ¡£¡£¡£¡£¡£¡£ÏëÒª½øÐиüУ¬£¬£¬£¬£¬Ö»Ðèתµ½ÉèÖáú¸üкͰ²È«¡úWindows¸üСú²é³­¸üУ¬£¬£¬£¬£¬»òÕßÒ²Äܹ»Í¨¹ýÊÖ¶¯½øÐиüС£ ¡£¡£¡£¡£¡£¡£

ĿǰÒѾ­·¢ÏÖÓÐÀûÓÃCVE-2018-8248·ì϶µÄľÂí£¬£¬£¬£¬£¬ÓйØÁ´½Ó£ºhttps://www.symantec.com/security-center/writeup/2018-061314-3210-99¡£ ¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó£º


https://portal.msrc.microsoft.com/en-us/security-guidance/acknowledgments