΢Èí7Ô²¹¶¡ÈÕÐè¹Ø×¢µÄ¸ßΣÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-07-11

Îó²î±àºÅºÍ¼¶±ð

CVE-2018-8304  Ö÷Òª  ³§ÉÌ×ÔÆÀ£º5.9

CVE-2018-8279  ÑÏÖØ  ³§ÉÌ×ÔÆÀ£º4.2

CVE-2018-8281  Ö÷Òª  

CVE-2018-8311  Ö÷Òª  

CVE-2018-8300  Ö÷Òª

 

Îó²î¸ÅÊö

7ÔÂ10ÈÕ £¬Î¢ÈíÐû²¼ÁË2018Äê7Ô·ݵÄÔ¶ÈÀýÐÐÇ徲ͨ¸æ £¬ÐÞ¸´ÁËÆä¶à¿î²úÆ·±£´æµÄ87¸öÇå¾²Îó²î¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨Windows 10 v1803 and Server 2016£¨7¸ö£©¡¢Windows 10 v1709£¨8¸ö£©¡¢Windows 10 v1703£¨8¸ö£©¡¢Windows 8.1 and Windows Server2012 R2£¨9¸ö£©¡¢Windows Server 2012£¨8¸ö£©¡¢Windows 7 and Windows Server 2008R2£¨8¸ö£©¡¢Windows Server 2008£¨7¸ö£©¡¢Internet Explorer£¨6¸ö£©¡¢Microsoft Edge£¨19¸ö£©ºÍMicrosoft Office£¨7¸ö£©¡£

 

ʹÓÃÉÏÊöÎó²î £¬¹¥»÷Õß¿ÉÒÔ»ñÈ¡Ãô¸ÐÐÅÏ¢ £¬ÌáÉýȨÏÞ £¬ÓÕÆ­ £¬ÈƹýÇå¾²¹¦Ð§ÏÞÖÆ £¬Ö´ÐÐÔ¶³Ì´úÂë £¬»ò¾ÙÐоܾø·þÎñ¹¥»÷µÈ¡£ÌáÐÑ¿í´óMicrosoftÓû§¾¡¿ìÏÂÔØ²¹¶¡¸üР£¬×èÖ¹Òý·¢Îó²îÏà¹ØµÄÍøÂçÇå¾²ÊÂÎñ¡£

 

CVE-2018-8304 Microsoft Windows DNSAPI¾Ü¾ø·þÎñÎó²î

Windows Domain Name System (DNS) DNSAPI.dllδÄÜ׼ȷ´¦Öóͷ£DNSÏìӦʱ £¬±£´æ¾Ü¾ø·þÎñÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÄܵ¼ÖÂϵͳ×èÖ¹ÏìÓ¦¡£ÒªÊ¹ÓôËÎó²î £¬¹¥»÷Õß½«Ê¹ÓöñÒâDNS·þÎñÆ÷ÏòÄ¿µÄ·¢ËÍË𻵵ÄDNSÏìÓ¦¡£

 

ÊÜÓ°ÏìµÄÈí¼þ£º

Windows 10

Windows 7

Windows 8.1

Windows RT 8.1

Server 2008

Server 2008 R2

Server 2012

Server 2012 R2

Server 2016

 

CVE-2018-8279 Microsoft EdgeÔ¶³ÌÖ´ÐдúÂëÎó²î

µ±Microsoft EdgeδÄÜ׼ȷ»á¼ûÄÚ´æÖеŤ¾ßʱ £¬±£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¸ÃÎó²î¿ÉÄÜÒÔÒ»ÖÖʹ¹¥»÷ÕßÄܹ»ÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂëµÄ·½·¨À´ÆÆËðÄÚ´æ¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓùÜÀíÓû§È¨Ï޵Ǽ £¬Ôò¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£È»ºó¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£» Éó²é £¬¸ü¸Ä»òɾ³ýÊý¾Ý£» »ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£

 

ÊÜÓ°ÏìµÄÈí¼þ£º

Microsoft  ChakraCore

Microsoft Edge

 

CVE-2018-8281 Microsoft  OfficeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

µ±Èí¼þδÄÜ׼ȷ´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ £¬Microsoft OfficeÈí¼þ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂë¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓùÜÀíÓû§È¨Ï޵Ǽ £¬Ôò¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£È»ºó¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»Éó²é £¬¸ü¸Ä»òɾ³ýÊý¾Ý£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ÕÊ»§±»ÉèÖÃΪӵÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§¿ÉÄܱÈʹÓùÜÀíÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°ÏìҪС¡£

 

ÊÜÓ°ÏìµÄÈí¼þ£º

Office 2016 for Mac

PowerPoint Viewer

Office 2016 C2R

Office Compat Pack

Word Viewer

Excel Viewer

 

CVE-2018-8311 Microsoft Skype for Business and LyncÔ¶³Ì´úÂëÖ´ÐÐÎó²î

µ±Skype for BusinessºÍMicrosoft Lync¿Í»§¶ËδÄÜ׼ȷ¹ýÂËÌØÖÆÄÚÈÝʱ £¬±£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¸ÃÎó²î¿ÉÄÜÒÔÒ»ÖÖÔÊÐí¹¥»÷ÕßÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂëµÄ·½·¨À´ÆÆËðÄÚ´æ¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓùÜÀíÓû§È¨Ï޵Ǽ £¬Ôò¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£È»ºó¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»Éó²é £¬¸ü¸Ä»òɾ³ýÊý¾Ý£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£

 

ÊÜÓ°ÏìµÄÈí¼þ£º

Skype for Business 2016

Lync 2013

 

CVE-2018-8300 Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐÐÎó²î

µ±Èí¼þδÄܼì²éÓ¦ÓóÌÐò°üµÄÔ´±ê¼Çʱ £¬Microsoft SharePointÖб£´æÒ»¸öÔ¶³ÌÖ´ÐдúÂëÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚSharePointÓ¦ÓóÌÐò³ØºÍSharePoint·þÎñÆ÷³¡ÕÊ»§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂë¡£

ʹÓôËÎó²îÐèÒªÓû§½«ÌØÖƵÄSharePointÓ¦ÓóÌÐò°üÉÏÔØµ½ÊÜÓ°ÏìµÄSharePoint°æ±¾¡£

 

ÊÜÓ°ÏìµÄÈí¼þ£º

SharePoint  Enterprise 2016

SharePoint  Foundation 2013

 

ÐÞ¸´½¨Ò飺

ÏÖÔÚ £¬Î¢Èí¹Ù·½ÒѾ­Ðû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î £¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ïì £¬¾¡¿ì½ÓÄÉÐÞ²¹²½·¥ £¬ÒÔ×èֹDZÔÚµÄÇå¾²Íþв¡£ÏëÒª¾ÙÐиüР£¬Ö»Ðèתµ½ÉèÖáú¸üкÍÇå¾²¡úWindows¸üСú¼ì²é¸üР£¬»òÕßÒ²¿ÉÒÔͨ¹ýÊÖ¶¯¾ÙÐиüС£

 

²Î¿¼Á´½Ó£º

https://portal.msrc.microsoft.com/en-us/security-guidance/acknowledgments