Microsoft | 12Ô¶à¸ö²úÆ··ì϶¹«¸æ

°ä²¼¹¦·ò 2020-12-09

0x00 ·ì϶¸ÅÊö

2020Äê12ÔÂ08ÈÕ£¬£¬£¬£¬£¬£¬Microsoft°ä²¼ÁË12Ô·ݵݲȫ¸üУ¬£¬£¬£¬£¬£¬±¾´Î°ä²¼µÄ°²È«·ì϶¹²¼Æ58¸ö£¬£¬£¬£¬£¬£¬Ïà½ÏÓÚÉÏÔÂÏ÷¼õÁË54¸ö¡£¡£¡£¡£¡£¡£ÆäÖÐÓÐ9¸ö·ì϶ÆÀ¼¶ÎªÑϳÁ£¬£¬£¬£¬£¬£¬46¸ö·ì϶ÆÀ¼¶Îª¸ßΣ¡£¡£¡£¡£¡£¡£ÔÚÕâ´Î°ä²¼µÄ°²È«·ì϶ÖУ¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ23¸ö·ì϶ΪԶ³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬14¸ö·ì϶ΪȨÏÞÌáÉý·ì϶£¬£¬£¬£¬£¬£¬9¸ö·ì϶ΪÐÅϢй¶·ì϶¡£¡£¡£¡£¡£¡£

 

0x01 ·ì϶ÏêÇé

 

image.png

΢Èí±¾´Î°ä²¼µÄ°²È«¸üÐÂÖУ¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·ºÍ×é¼þÔ̺¬£ºMicrosoft Windows¡¢Microsoft Edge (EdgeHTML-based)¡¢Microsoft Edge for Android¡¢ChakraCore¡¢Microsoft Office and Microsoft Office Services and Web Apps¡¢Microsoft Exchange Server¡¢Azure DevOps¡¢Microsoft Dynamics¡¢Visual Studio¡¢Azure SDKºÍAzure Sphere¡£¡£¡£¡£¡£¡£

±¾´Î°ä²¼µÄÆëÈ«·ì϶ÁбíÈçÏ£º

CVE-ID

·ìϼûû³Æ

ÑϳÁˮƽ

CVE-2020-17131

Chakra¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶

ÑϳÁ

CVE-2020-17095

Hyper-VÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2020-17152

Microsoft Dynamics 365 for Finance and Operations´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2020-17158

Microsoft Dynamics 365 for Finance and Operations´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2020-17117

Microsoft ExchangeÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2020-17132

Microsoft ExchangeÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2020-17142

Microsoft ExchangeÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2020-17118

Microsoft SharePointÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2020-17121

Microsoft SharePointÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

CVE-2020-17145

Azure DevOps·þÎñÆ÷ºÍTeam   Foundation ServicesºýŪ·ì϶

¸ßΣ

CVE-2020-17135

Azure DevOps·þÎñÆ÷ºýŪ·ì϶

¸ßΣ

CVE-2020-17002

ÓÃÓÚC°²È«Ö°ÄÜÈÆ¹ýµÄAzure SDK

¸ßΣ

CVE-2020-17160

Azure Sphere°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2020-17137

DirectXͼÐÎÄÚºËȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-17147

Dynamics CRM Webclient¿çÕ¾µã¾ç±¾·ì϶

¸ßΣ

CVE-2020-16996

Kerberos°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2020-17133

Microsoft Dynamics Business Central / NAVÐÅÏ¢Åû¶

¸ßΣ

CVE-2020-17126

Microsoft ExcelÐÅϢй¶·ì϶

¸ßΣ

CVE-2020-17122

Microsoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17123

Microsoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17125

Microsoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17127

Microsoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17128

Microsoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17129

Microsoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17130

Microsoft Excel°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2020-17143

Microsoft ExchangeÐÅϢй¶·ì϶

¸ßΣ

CVE-2020-17141

Microsoft ExchangeÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17144

Microsoft ExchangeÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17119

Microsoft OutlookÐÅϢй¶·ì϶

¸ßΣ

CVE-2020-17124

Microsoft PowerPointÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17089

Microsoft SharePointȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-17120

Microsoft SharePointÐÅϢй¶·ì϶

¸ßΣ

CVE-2020-17159

Visual Studio Code JavaÀ©´ó°üÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17150

Visual Studio´úÂëÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17148

Visual Studio CodeÔ¶³Ì¿ª·¢À©´óÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17156

Visual StudioÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-16958

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-16959

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-16960

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-16961

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-16962

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-16963

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-16964

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-17103

WindowsÔÆÎļþÓ×ÐÍɸѡÆ÷Çý¶¯·¨Ê½È¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-17134

WindowsÔÆÎļþÓ×ÐÍɸѡÆ÷Çý¶¯·¨Ê½È¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-17136

WindowsÔÆÎļþÓ×ÐÍɸѡÆ÷Çý¶¯·¨Ê½È¨ÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-17097

Windows Digital Media ReceiverȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-17094

WindowsÃýÎó»ã±¨ÐÅϢй¶·ì϶

¸ßΣ

CVE-2020-17138

WindowsÃýÎó»ã±¨ÐÅϢй¶·ì϶

¸ßΣ

CVE-2020-17098

Windows GDI +ÐÅϢй¶·ì϶

¸ßΣ

CVE-2020-17099

WindowsËø¶¨ÆÁÄ»°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2020-17092

WindowsÍøÂçÏνӷþÎñȨÏÞÌáÉý·ì϶

¸ßΣ

CVE-2020-17096

Windows NTFSÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

CVE-2020-17139

Windows¸²¸ÇɸѡÆ÷°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

CVE-2020-17140

Windows SMBÐÅϢй¶·ì϶

¸ßΣ

CVE-2020-16971

ºÏÓÃÓÚJavaµÄAzure SDK°²È«Ö°ÄÜÈÆ¹ý·ì϶

ÖÐΣ

CVE-2020-17153

Android EdgeµÄMicrosoft   Edge·ì϶

ÖÐΣ

CVE-2020-17115

Microsoft SharePointºýŪ·ì϶

ÖÐΣ

 

²¿ÃÅÑϳÁ·ì϶ÈçÏ£º

Hyper-VÔ¶³Ì´úÂëÖ´Ðзì϶

Hyper-VÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-17095£©£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö8.5¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ý´Ë·ì϶½«Hyper-V Guest OSȨÏÞÌáÉýµ½Hyper-V HostȨÏÞ£¬£¬£¬£¬£¬£¬×îÖÕÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£

Windows NTFSÔ¶³Ì´úÂëÖ´Ðзì϶

Windows NTFSÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-17096£©£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.5¡£¡£¡£¡£¡£¡£ÓµÓÐSMBv2½Ó¼ûȨÏ޵Ĺ¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâÒªÇóÀ´ÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬×îÖÕÄܹ»ÔÚÖ¸±êϵͳÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£

Microsoft SharePoint Ô¶³Ì´úÂëÖ´Ðзì϶

MicrosoftÔÚSharePointÖн¨¸´ÁË2¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-17121ºÍCVE-2020-17118£©¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬CVE-2020-17118 CVSSÆÀ·Ö8.1£¬£¬£¬£¬£¬£¬CVE-2020-17121 CVSSÆÀ·Ö8.8¡£¡£¡£¡£¡£¡£

¹¥»÷Õß¿ÉÄÜÀûÓÃCVE-2020-17121»ñµÃ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬ÒÔ´´½¨Õ¾µã²¢ÔÚkernelÄÚÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£

Microsoft ExchangeÔ¶³Ì´úÂëÖ´Ðзì϶

Microsoft½¨¸´ÁËExchangeÖеÄ5¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-17141¡¢CVE-2020-17142¡¢CVE-2020-17144¡¢ CVE-2020-17117¡¢CVE-2020-17132£©¡£¡£¡£¡£¡£¡£

ÆäÖУ¬£¬£¬£¬£¬£¬CVE-2020-17132ÊǶÔcmdlet²ÎÊýµÄÑéÖ¤²»ÕýÈ·Ôì³ÉµÄ£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.1¡£¡£¡£¡£¡£¡£Microsoft²¢Î´ÔÚ´Ë´¦Ìṩ¹¥»÷³¡¾°£¬£¬£¬£¬£¬£¬µ«Ö¸³ö¹¥»÷Õß±ØÒª½øÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬ÇҸ÷ì϶µÄÀûÓø´ÔÓÐԵ͡£¡£¡£¡£¡£¡£ÈôÊǹ¥»÷ÕßÈëÇÖÁËijÈ˵ÄÓÊÏ䣬£¬£¬£¬£¬£¬ÔòÄܹ»½ÚÔìÕû¸öExchange·þÎñÆ÷¡£¡£¡£¡£¡£¡£

 

0x02 ´ëÖý¨Òé

ĿǰMicrosoftÒѾ­°ä²¼Á˰²È«¸üУ¬£¬£¬£¬£¬£¬½¨ÒéʵʱװÖÃÓйز¹¶¡¡£¡£¡£¡£¡£¡£

 

£¨Ò»£© Windows update¸üÐÂ

 

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£¡£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС±£¬£¬£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£¡£

4¡¢³ÁÆôÍÆËã»ú£¬£¬£¬£¬£¬£¬×°ÖøüÐÂϵͳ³ÁÐÂÆô¶¯ºó£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¡£¡£¡£¡£¡£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬£¬£¬£¬£¬£¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£¡£

 

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

΢Èí¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£¡£¡£¡£¡£¡£

ÏÂÔØµØÖ·£º

https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec

https://threatpost.com/microsoft-patch-tuesday-holidays/162041/

https://www.darkreading.com/threat-intelligence/microsoft-fixes-58-cves-for-december-patch-tuesday/d/d-id/1339651?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple

 

0x04 ¹¦·òÏß

2020-12-08  Microsoft°ä²¼°²È«¸üÐÂ

2020-12-09  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

 

 

 

image.png