΢Èí6Ô¶à¸ö°²È«·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-06-14

·ì϶¸ÅÊö



2019Äê6ÔÂ11ÈÕ £¬£¬£¬£¬£¬£¬Microsoft°ä²¼ÁËÁùÔ·ݰ²È«²¹¶¡¸üР¡£¡£¡£¡£¡£¡£ÔÚ¹Ù·½µÄ°²È«¸üв¼¸æÖÐÒ»¹²Åû¶ÁË88¸ö·ì϶µÄÓйØÐÅÏ¢ £¬£¬£¬£¬£¬£¬ÆäÖÐ21¸ö»ñµÃÁË¡°ÑϳÁ¡±ÆÀ¼¶ £¬£¬£¬£¬£¬£¬ÕâÊÇ΢ÈíÓÐÊ·ÒÔÀ´·ì϶ÑϳÁˮƽ×î¸ßµÄÒ»´ÎÅÅÃû ¡£¡£¡£¡£¡£¡£½ØÖÁĿǰΪֹ £¬£¬£¬£¬£¬£¬ÉÐδ·¢ÏÖÕâ88¸ö·ì϶µÄÔÚÒ°ÀûÓà ¡£¡£¡£¡£¡£¡£


³É¹¦ÀûÓÃÉÏÊö·ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡¢»ñÈ¡Óû§Êý¾Ý ¡£¡£¡£¡£¡£¡£Î¢Èí¶à¸ö²úÆ·ºÍϵͳÊÜ·ì϶ӰÏì ¡£¡£¡£¡£¡£¡£Ä¿Ç° £¬£¬£¬£¬£¬£¬Î¢Èí¹Ù·½ÒѾ­°ä²¼·ì϶½¨¸´²¹¶¡ £¬£¬£¬£¬£¬£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½·ì϶ӰÏì £¬£¬£¬£¬£¬£¬²ÉÈ¡½¨²¹´ëÊ© ¡£¡£¡£¡£¡£¡£


1¡¢Windows Hyper-VÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0620£©£¨CVE-2019-0709£©£¨CVE-2019-0722£©


·ì϶¼ò½é£ºµ±Ö÷»ú·þÎñÆ÷É쵀 Windows Hyper-V ÎÞ·¨ÕýÈ·ÑéÖ¤º£¶«ÏµÍ³ÉϾ­Éí·ÝÑéÖ¤µÄÓû§ÊäÈëʱ £¬£¬£¬£¬£¬£¬´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶ ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÔÚº£¶«²Ù×÷ϵͳÉÏÔËÐо­ÌØÊâÉè¼ÆµÄ¶ñÒⷨʽ £¬£¬£¬£¬£¬£¬×îÖÕÔÚÖ÷»ú·þÎñÆ÷ϵͳÉÏÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0620
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0709

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0722


2¡¢Jet Êý¾Ý¿âÒýÇæÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0904£©£¨CVE-2019-0905£©£¨CVE-2019-0906£©£¨CVE-2019-0907£©£¨CVE-2019-0908£©£¨CVE-2019-0909£©


·ì϶¼ò½é£ºµ± Windows Jet Êý¾Ý¿âÒýÇæ²»ÕýÈ·µØ´¦ÖÃÄÚ´æÖеĶÔÏóʱ £¬£¬£¬£¬£¬£¬»á´¥·¢Ô¶³Ì´úÂëÖ´Ðзì϶ ¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÊܺ¦ÕßϵͳÉÏÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0904
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0905
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0906
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0907
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0908

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0909


3¡¢ActiveX Data Objects (ADO)Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0888£©


·ì϶¼ò½é£ºActiveX Data Objects (ADO)´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶ ¡£¡£¡£¡£¡£¡£ ¹¥»÷Õ߿ɴ´½¨º¬ÓжñÒâ´úÂëµÄÍøÕ¾ £¬£¬£¬£¬£¬£¬²¢ÓÕʹÓû§½øÐнӼû £¬£¬£¬£¬£¬£¬×îÖÕʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ ¡£¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0888


4¡¢Microsoft Word Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-1034£©£¨CVE-2019-1035£©


·ì϶¼ò½é£ºµ± Microsoft WordÎÞ·¨ÕýÈ·´¦ÖÃÄÚ´æÖеĶÔÏóʱ £¬£¬£¬£¬£¬£¬»á´¥·¢Ô¶³Ì´úÂëÖ´Ðзì϶ ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÏòÓû§·¢Ë;­ÌØÊâÉè¼ÆµÄÎļþ²¢ÓÕʹÓû§´ò¿ª¸ÃÎļþÒÔÀûÓô˷ì϶ ¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓ÷ì϶µÄ¹¥»÷Õß¿ÉÔÚÓû§ÏµÍ³ÉÏÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1034

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1035


5¡¢Chakra ¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶£¨CVE-2019-1002£©£¨CVE-2019-1003£©£¨CVE-2019-0989£©£¨CVE-2019-0991£©£¨CVE-2019-0992£©£¨CVE-2019-0993£©


·ì϶¼ò½é£ºChakra ¾ç±¾ÒýÇæÔÚ Microsoft Edge Öд¦ÖÃÄÚ´æÖеĶÔÏóʱ¿ÉÄÜ´¥·¢¸Ã·ì϶ ¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ ¡£¡£¡£¡£¡£¡£ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíԱȨÏ޵Ǽ £¬£¬£¬£¬£¬£¬¹¥»÷Õß±ãÄܹ»ËÁÒâ×°Ö÷¨Ê½¡¢²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý £¬£¬£¬£¬£¬£¬»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§ ¡£¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1002
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1003
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0989
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0991
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0992

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0993


6¡¢Microsoft Speech API Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0985£©


·ì϶¼ò½é£ºµ±Microsoft Speech API²»ÕýÈ·µØ´¦ÖÃÎı¾µ½ÓïÒô£¨TTS£©ÊäÈëʱ £¬£¬£¬£¬£¬£¬´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶ ¡£¡£¡£¡£¡£¡£ ¸Ã·ì϶¿ÉÄÜÒÔÒ»ÖÖʹ¹¥»÷Õß¿ÉÄÜÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂëµÄ·½Ê½À´·ÛËéÄÚ´æ ¡£¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0985


7¡¢Microsoft Windows°²È«ÌصãÈÆ¹ý·ì϶£¨CVE-2019-1019£©


·ì϶¼ò½é£º WindowsÖÐNetlogonÐÂÎÅ¿ÉÄÜ»ñÈ¡»á»°ÃÜÔ¿²¢¶ÔÐÂÎŽøÐÐÊðÃû £¬£¬£¬£¬£¬£¬¸ÃÐÂÎÅ´æÔÚÒ»¸ö°²È«ÌصãÈÆ¹ý·ì϶ ¡£¡£¡£¡£¡£¡£ÎªÁËÀûÓô˷ì϶ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄÉè¼ÆµÄÉí·ÝÑéÖ¤ÒªÇó ¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ê¹ÓÃԭʼÓû§È¨ÏÞ½Ó¼ûÁíÒ»Ì¨ÍÆËã»ú ¡£¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1019


8¡¢Microsoft IIS·þÎñÆ÷»Ø¾ø·þÎñ·ì϶£¨CVE-2019-0941£©


·ì϶¼ò½é£ºMicrosoft IIS ServerÖдæÔÚÒ»¸ö»Ø¾ø·þÎñ·ì϶£¨CVE-2019-0941£© £¬£¬£¬£¬£¬£¬µ±¿ÉѡҪÇóɸѡְÄÜÎÞ·¨ÕýÈ·´¦ÖÃÒªÇóʱ £¬£¬£¬£¬£¬£¬¸Ã·ì϶½«»áÆô³Ì ¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜ»á¶ÔÅäÖÃΪʹÓÃÒªÇóɸѡµÄÒ³ÃæÔì³Éһʱ»Ø¾ø·þÎñ ¡£¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0941


9¡¢Windows NTLM´Û¸Ä·ì϶£¨CVE-2019-1040£©


·ì϶¼ò½é£ºMicrosoft WindowsµÄNTLMÖдæÔڴ۸ķì϶ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýÖÐÑëÈ˹¥»÷³É¹¦ÈƹýNTLM MIC£¨ÐÂÎÅÆëÈ«ÐԲ鳭£©µÄ±£»£» £»£»£»£» £»£»¤ £¬£¬£¬£¬£¬£¬ÊµÏÖNTLM°²È«Ö°ÄܵĽµ¼¶ ¡£¡£¡£¡£¡£¡£¸Ã·ì϶Äܹ»Ôì³É·ÖÆçˮƽµÄ·çÏÕ £¬£¬£¬£¬£¬£¬×îΪÑϳÁʱ¿ÉÔÚʹÓÃͨ³£ÓòÕ˺ŵÄÇé¿öϽÚÔìÓòÄÚµÄËùÓлúе ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÏëÒª³É¹¦ÀûÓô˷ì϶ £¬£¬£¬£¬£¬£¬±ØÒª´Û¸ÄNTLM»¥»»ÐÅÏ¢ £¬£¬£¬£¬£¬£¬¶øºóÔÚ±£ÕÏÊðÃûÒÀÈ»ÓÐЧµÄǰÌáÏÂÅú¸ÄNTLMÊý¾Ý°üµÄ±êÖ¾ ¡£¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1040


10¡¢Windows»Ø¾ø·þÎñ·ì϶£¨CVE-2019-1025£©


·ì϶¼ò½é£ºWindowsµÄÄÚ´æ´¦Ö÷½Ê½ÖдæÔڻؾø·þÎñ·ì϶ £¬£¬£¬£¬£¬£¬µ±ÃýÎ󵨴¦ÖÃÄÚ´æ¶ÔÏóʱ½«»á´¥·¢¸Ã·ì϶ ¡£¡£¡£¡£¡£¡£ÒªÀûÓô˷ì϶ £¬£¬£¬£¬£¬£¬¹¥»÷Õß±ØÐëµÇ¼µ½ÊÜÓ°ÏìµÄϵͳ²¢ÔËÐо­ÌØÊâÉè¼ÆµÄÀûÓ÷¨Ê½»òÓÕÆ­Óû§´ò¿ªÍøÂç¹²ÏíÉϵÄÌØ¶¨Îļþ ¡£¡£¡£¡£¡£¡£¸Ã·ì϶²»ÔÊÐí¹¥»÷ÕßÖ±½ÓÖ´ÐдúÂë»òÌáÉýÓû§È¨ÏÞ £¬£¬£¬£¬£¬£¬µ«¿ÉÄܻᵼÖÂÖ¸±êϵͳÖÕ³¡ÏìÓ¦ ¡£¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1025



½¨¸´½¨Òé



Ŀǰ £¬£¬£¬£¬£¬£¬Î¢Èí¹Ù·½ÒѾ­°ä²¼²¹¶¡½¨¸´ÁËÉÏÊö·ì϶ £¬£¬£¬£¬£¬£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½·ì϶ӰÏì £¬£¬£¬£¬£¬£¬¾¡¿ì²ÉÈ¡½¨²¹´ëÊ© £¬£¬£¬£¬£¬£¬ÒÔÔ¤·ÀDZÔڵݲȫÍþв ¡£¡£¡£¡£¡£¡£ÏëÒª½øÐиüР£¬£¬£¬£¬£¬£¬Ö»Ðèתµ½ÉèÖáú¸üкͰ²È«¡úWindows ¸üСú²é³­¸üР£¬£¬£¬£¬£¬£¬»òÕßÒ²Äܹ»Í¨¹ýÊÖ¶¯½øÐиüР¡£¡£¡£¡£¡£¡£



²Î¿¼Á´½Ó



https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/253dc509-9a5b-e911-a98e-000d3a33c573