1ÔÂ14ÈÕ£¬£¬Î¢ÈíÐû²¼ÁË2020Äê1Ô·ݵÄÔ¶ÈÀýÐÐÇ徲ͨ¸æ£¬£¬ÐÞ¸´ÁËÆä¶à¿î²úÆ·±£´æµÄ204¸öÇå¾²Îó²î¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨£ºWindows 10 1909 & WindowsServer v1909£¨29¸ö£©¡¢¡¢Windows 10 1903 & WindowsServer v1903£¨29¸ö£©¡¢¡¢Windows 10 1809 & WindowsServer 2019£¨33¸ö£©¡¢¡¢Windows 8.1 & Server 2012 R2£¨26¸ö£©¡¢¡¢Windows Server 2012£¨23¸ö£©¡¢¡¢Windows RT 8.1£¨22¸ö£©¡¢¡¢Windows 7 and Windows Server 2008R2£¨19¸ö£©¡¢¡¢Windows Server 2008£¨16¸ö£©¡¢¡¢Internet Explorer£¨6¸ö£©ºÍMicrosoft Office-related software£¨6¸ö£©¡£¡£¡£
ʹÓÃÉÏÊöÎó²î£¬£¬¹¥»÷Õß¿ÉÒÔÌáÉýȨÏÞ£¬£¬ÓÕÆ£¬£¬ÈƹýÇå¾²¹¦Ð§ÏÞÖÆ£¬£¬»ñÈ¡Ãô¸ÐÐÅÏ¢£¬£¬Ö´ÐÐÔ¶³Ì´úÂë»òÌᳫ¾Ü¾ø·þÎñ¹¥»÷µÈ¡£¡£¡£CNVDÌáÐÑ¿í´óMicrosoftÓû§¾¡¿ìÏÂÔØ²¹¶¡¸üУ¬£¬×èÖ¹Òý·¢Îó²îÏà¹ØµÄÍøÂçÇå¾²ÊÂÎñ¡£¡£¡£
CVE±àºÅ | ͨ¸æÎÊÌâºÍÕªÒª | ×î¸ßÑÏÖØÆ·¼¶ºÍÎó²îÓ°Ïì | ÊÜÓ°ÏìµÄÈí¼þ |
CVE-2020-0609 | Windows Remote Desktop Gateway (RD Gateway) Ô¶³Ì´úÂëÖ´ÐÐÎó²î µ±Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßʹÓÃRDPÅþÁ¬µ½Ä¿µÄϵͳ²¢·¢ËÍרÃÅÖÆ×÷µÄÇëÇóʱ£¬£¬Windows Remote Desktop Gateway (RD Gateway)Öб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£´ËÎó²îÊÇÔ¤ÈÏÖ¤£¬£¬²»ÐèÒªÓû§½»»¥¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£È»ºó£¬£¬¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»£»Éó²é¡¢¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£ÒªÊ¹ÓôËÎó²î£¬£¬¹¥»÷ÕßÐèҪͨ¹ýRDPÏòÄ¿µÄϵͳRDÍø¹Ø·¢ËÍÈ«ÐÄÌåÀýµÄÇëÇ󡣡£¡£ ´Ë¸üÐÂͨ¹ý¸üÕýRDÍø¹Ø´¦ÀíÅþÁ¬ÇëÇóµÄ·½Ê½À´½â¾ö´ËÎó²î¡£¡£¡£ | ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë | Server 2019 Server 2016 Server 2012 Mitigations Server 2012 R2 |
CVE-2020-0601 | Windows CryptoAPIÓÕÆÎó²î ÔÚWindows CryptoAPI£¨Curt32.dll£©ÑéÖ¤Elliptic Curve Cryptography (ECC)Ö¤ÊéµÄ·½Ê½Öб£´æÓÕÆÎó²î¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îʹÓÃαÔìµÄ´úÂëÊðÃûÖ¤Êé¶Ô¶ñÒâ¿ÉÖ´ÐÐÎļþ¾ÙÐÐÊðÃû£¬£¬Ê¹Æä¿´ÆðÀ´ÎļþÀ´×ÔÊÜÐÅÈεÄÕýµ±Ô´¡£¡£¡£Óû§½«ÎÞ·¨ÖªµÀ¸ÃÎļþÊǶñÒâµÄ£¬£¬ÓÉÓÚÊý×ÖÊðÃûËÆºõÀ´×ÔÊÜÐÅÈεÄÌṩ³ÌÐò¡£¡£¡£ÀÖ³ÉʹÓôËÎó²î»¹¿ÉÒÔÈù¥»÷Õß¾ÙÐÐÖÐÐÄÈ˹¥»÷£¬£¬²¢½âÃÜÓëÊÜÓ°ÏìÈí¼þµÄÓû§ÅþÁ¬µÄÉñÃØÐÅÏ¢¡£¡£¡£ Çå¾²¸üÐÂͨ¹ýÈ·±£Windows CryptoAPIÍêÈ«ÑéÖ¤ECCÖ¤ÊéÀ´½â¾ö¸ÃÎó²î¡£¡£¡£ | Ö÷Òª ÓÕÆ | Windows 10 Server 2016 Server 2019 Server, version 1803 Server, version 1903 Server, version 1909 |
CVE-2020-0625 | Windows Search IndexerȨÏÞÌáÉýÎó²î ÒÔWindows Search Indexer´¦ÀíÄÚ´æÖй¤¾ßµÄ·½Ê½±£´æÈ¨ÏÞÌáÉýÎó²î¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÌáÉýµÄȨÏÞÖ´ÐдúÂë¡£¡£¡£ÒªÊ¹ÓôËÎó²î£¬£¬¾ÓÉÍâµØÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÔËÐй¹½¨µÄÓ¦ÓóÌÐò¡£¡£¡£ Çå¾²¸üÐÂͨ¹ýÈ·±£Windows Search Indexer׼ȷ´¦ÀíÄÚ´æÖеŤ¾ßÀ´½â¾ö´ËÎó²î¡£¡£¡£ | Ö÷Òª ÌØÈ¨ÌáÉý | Windows 10 Server 2016 Server 2019 Server, version 1803 Server, version 1903 Server, version 1909 Windows 7 Windows 8.1 Server 2008 Server 2008 R2 Server 2012 Server 2012 R2 |
CVE-2020-0611 | Remote Desktop ClientÔ¶³Ì´úÂëÖ´ÐÐÎó²î µ±Óû§ÅþÁ¬µ½¶ñÒâ·þÎñÆ÷ʱ£¬£¬Windows Remote Desktop ClientÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÅþÁ¬¿Í»§¶ËµÄÅÌËã»úÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£È»ºó£¬£¬¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»£»Éó²é¡¢¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£ ҪʹÓôËÎó²î£¬£¬¹¥»÷ÕßÐèÒª¿ØÖÆ·þÎñÆ÷£¬£¬È»ºó˵·þÓû§ÅþÁ¬µ½¸Ã·þÎñÆ÷¡£¡£¡£¹¥»÷ÕßÎÞ·¨Ç¿ÆÈÓû§ÅþÁ¬µ½¶ñÒâ·þÎñÆ÷£¬£¬ÐèҪͨ¹ýÉç»á¹¤³Ì¡¢¡¢DNSÖж¾»òʹÓÃÖÐÐÄÈË£¨MITM£©ÊÖÒÕÓÕÆÓû§ÅþÁ¬¡£¡£¡£¹¥»÷Õß»¹¿ÉÄÜΣº¦Õýµ±·þÎñÆ÷£¬£¬ÔÚÆäÉÏÍйܶñÒâ´úÂ룬£¬²¢ÆÚ´ýÓû§ÅþÁ¬¡£¡£¡£ ´Ë¸üÐÂͨ¹ý¸üÕýWindows Remote Desktop Client´¦ÀíÅþÁ¬ÇëÇóµÄ·½Ê½À´½â¾ö´ËÎó²î¡£¡£¡£ | ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë | Windows 10 Server, version 1803 Server 2019 Server, version 1903 Server, version 1909 Server 2016 Windows 7 Windows 8.1 Server 2008 R2 Server 2012 Server 2012 R2 |
CVE-2020-0640 | Internet ExplorerÄÚ´æÆÆËðÎó²î µ±Internet ExplorerδÄÜ׼ȷ»á¼ûÄÚ´æÖеŤ¾ßʱ£¬£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¸ÃÎó²î¿ÉÄÜ»áÆÆËðÄڴ棬£¬Ê¹µÃ¹¥»÷Õß¿ÉÒÔÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£¡£¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬£¬Ôò¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¡£¡£È»ºó£¬£¬¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»£»Éó²é¡¢¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£ Çå¾²¸üÐÂͨ¹ýÐÞ¸ÄInternet Explorer´¦ÀíÄÚ´æÖй¤¾ßµÄ·½Ê½À´½â¾ö¸ÃÎó²î¡£¡£¡£ | ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë | Internet Explorer 10 Internet Explorer 9 Internet Explorer 11 |
CVE-2020-0650 | Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î µ±Èí¼þδÄÜ׼ȷ´¦ÀíÄÚ´æÖеŤ¾ßʱ£¬£¬Microsoft ExcelÈí¼þÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂë¡£¡£¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬£¬Ôò¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¡£¡£È»ºó£¬£¬¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»£»Éó²é¡¢¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£½«ÕÊ»§ÉèÖÃΪÔÚϵͳÉÏÓµÓнÏÉÙÓû§È¨ÏÞµÄÓû§¿ÉÄܱÈʹÓÃÖÎÀíÓû§È¨ÏÞ²Ù×÷µÄÓû§ÊÜÓ°Ïì¸üС¡£¡£¡£ Çå¾²¸üÐÂͨ¹ý¸üÕýMicrosoft ExcelÈçÄÇÀïÖÃÄÚ´æÖеŤ¾ßÀ´½â¾ö´ËÎó²î¡£¡£¡£ | Ö÷Òª Ô¶³ÌÖ´ÐдúÂë | Office 2019 Office 2019 for Mac Office 365 ProPlus Excel 2016 Office 2016 for Mac Excel 2010 Excel 2013 |
²Î¿¼ÐÅÏ¢£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/adv990001
https://docs.microsoft.com/en-us/windows/deployment/update/servicing-stackupdates#why-should-servicing-stack-updates-be-installed-and-kept-up-to-date
https://techcommunity.microsoft.com/t5/Windows-IT-Pro-Blog/Windows-7-servicingstack-updates-managing-change-and/ba-p/260434