CVE±àºÅ | ͨ¸æÎÊÌâºÍÕªÒª | ×î¸ßÑÏÖØÆ·¼¶ºÍÎó²îÓ°Ïì | ÊÜÓ°ÏìµÄÈí¼þ |
CVE-2020-1350 | Windows DNS ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î Windows Domain Name System serversδÄÜ׼ȷ´¦ÀíÇëÇóʱ£¬£¬£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÍâµØÏµÍ³ÕÊ»§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂë¡£ÉèÖÃΪDNS·þÎñÆ÷µÄWindows·þÎñÆ÷±£´æ´ËÎó²îµÄ·çÏÕ¡£ ҪʹÓôËÎó²î¾ÙÐй¥»÷£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÏòWindows DNS server·¢ËͶñÒâÇëÇó¡£ ´Ë¸üÐÂͨ¹ýÐÞ¸ÄWindows DNS servers´¦ÀíÇëÇóµÄ·½Ê½À´½â¾ö¸ÃÎó²î¡£ | ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë | Server 2016 Server 2019 Server, version 1903 Server, version 1909 Server, version 2004 Server 2012 Server 2012 R2 |
CVE-2020-1032 | Hyper-V RemoteFX vGPUÔ¶³Ì´úÂëÖ´ÐÐÎó²î µ±Ö÷»ú·þÎñÆ÷ÉϵÄHyper-V RemoteFX vGPUδÄÜ׼ȷÑéÖ¤Guest²Ù×÷ϵͳÉϾÉí·ÝÑéÖ¤µÄÓû§µÄÊäÈëʱ£¬£¬£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£ÒªÊ¹ÓôËÎó²î£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÔÚGuest²Ù×÷ϵͳÉÏÔËÐÐÌØÖÆ³ÌÐò£¬£¬£¬¹¥»÷ÔËÐÐÔÚHyper-V host²Ù×÷ϵͳÉϵĵÚÈý·½ÊÓÆµÇý¶¯À´Ê¹ÓôËÎó²î£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÔÚHost²Ù×÷ϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£ | ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë | Server 2016 Server 2012 Server 2012 R2 |
CVE-2020-1463 | Windows SharedStream LibraryȨÏÞÌáÉýÎó²îSharedStream Library´¦ÀíÄÚ´æÖй¤¾ßµÄ·½Ê½±£´æÈ¨ÏÞÌáÉýÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÌáÉýµÄȨÏÞÖ´ÐдúÂ롣ҪʹÓôËÎó²î¾ÙÐй¥»÷£¬£¬£¬ÍâµØÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÔËÐй¹½¨µÄÓ¦ÓóÌÐò¡£ Çå¾²¸üÐÂͨ¹ýÈ·±£SharedStream Library׼ȷ´¦ÀíÄÚ´æÖеŤ¾ßÀ´½â¾ö¸ÃÎó²î¡£ | Ö÷Òª ÌØÈ¨ÌáÉý | Windows 10 Server 2016 Server 2019 Server, version 1903 Server, version 1909 Server, version 2004 |
CVE-2020-1374 | Windows Remote Desktop ClientÔ¶³Ì´úÂëÖ´ÐÐÎó²î µ±Óû§ÅþÁ¬µ½¶ñÒâ·þÎñÆ÷ʱ£¬£¬£¬Windows Remote Desktop ClientÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÅþÁ¬¿Í»§¶ËµÄÅÌËã»úÉÏÖ´ÐÐí§Òâ´úÂ롣Ȼºó£¬£¬£¬¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»£»£»Éó²é¡¢¡¢¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»£»£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ҪʹÓôËÎó²î£¬£¬£¬¹¥»÷ÕßÐèÒª¿ØÖÆ·þÎñÆ÷£¬£¬£¬È»ºó˵·þÓû§ÅþÁ¬µ½·þÎñÆ÷¡£¹¥»÷ÕßÎÞ·¨Ç¿ÆÈÓû§ÅþÁ¬µ½¶ñÒâ·þÎñÆ÷£¬£¬£¬ÐèҪͨ¹ýÉç»á¹¤³Ì¡¢¡¢¡¢DNSÖж¾»òʹÓÃÖÐÐÄÈË£¨MITM£©ÊÖÒÕÓÕÆÓû§ÅþÁ¬¡£¹¥»÷Õß»¹¿ÉÒÔΣº£º¦Õýµ±·þÎñÆ÷£¬£¬£¬ÔÚÆäÉÏÍйܶñÒâ´úÂ룬£¬£¬²¢ÆÚ´ýÓû§ÅþÁ¬¡£ ´Ë¸üÐÂͨ¹ý¸üÕýWindows Remote Desktop Client´¦ÀíÅþÁ¬ÇëÇóµÄ·½Ê½À´½â¾ö¸ÃÎó²î¡£ | ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë | Windows 10 Server 2016 Server 2019 Server, version 1903 Server, version 1909 Server, version 2004 Windows 8.1 Server 2012 Server 2012 R2 |
CVE-2020-1410 | Windows Address BookÔ¶³Ì´úÂëÖ´ÐÐÎó²î µ±Windows Address Book (WAB)δÄÜ׼ȷµØ´¦ÀívcardÎļþʱ£¬£¬£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£ÒªÊ¹ÓôËÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËͶñÒâvcard£¬£¬£¬Êܺ¦Õß¿ÉÒÔʹÓÃWindows Address Book (WAB)·¿ª¸Ãvcard¡£ÀÖ³ÉʹÓøÃÎó²îºó£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÊܺ¦ÕßϵͳÉÏÖ´ÐС£ Çå¾²¸üÐÂͨ¹ý¸üÕýWWindows Address Book´¦Àí°ó¶¨¼ì²éµÄ·½Ê½À´½â¾ö¸ÃÎó²î¡£ | ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë | Windows 10 Server 2016 Server 2019 Server, version 1903 Server, version 1909 Server, version 2004 Windows 8.1 Server 2012 Server 2012 R2 |
CVE-2020-1435 | Windows Graphics Device Interface (GDI)Ô¶³Ì´úÂëÖ´ÐÐÎó²î Windows Graphics Device Interface (GDI) ´¦ÀíÄÚ´æÖеŤ¾ßʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£È»ºó£¬£¬£¬¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»£»£»Éó²é¡¢¡¢¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»£»£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ÓëʹÓÃÖÎÀíÓû§È¨ÏÞ²Ù×÷µÄÓû§Ïà±È£¬£¬£¬ÕÊ»§ÉèÖÃΪÔÚϵͳÉϾßÓнÏÉÙÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì½ÏС¡£ | ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë | Windows 10 Server 2016 Server 2019 Server, version 1903 Server, version 1909 Server, version 2004 Windows 8.1 Server 2012 Server 2012 R2 |
CVE-2020-1436 | Windows Font LibraryÔ¶³Ì´úÂëÖ´ÐÐÎó²î µ±Windows×ÖÌå¿âδÄÜ׼ȷ´¦Àí¹¹½¨µÄ×ÖÌåʱ£¬£¬£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¹ØÓÚ³ýWindows 10ÒÔÍâµÄËùÓÐϵͳ£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔ¶³ÌÖ´ÐдúÂë¡£¹ØÓÚÔËÐÐWindows 10µÄϵͳ£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚAppContainerɳºÐÉÏÏÂÎÄÖÐÒÔÓÐÏÞµÄȨÏ޺͹¦Ð§Ö´ÐдúÂ롣Ȼºó£¬£¬£¬¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»£»£»Éó²é¡¢¡¢¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»£»£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ | ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë | Windows 10 Server 2016 Server 2019 Server, version 1903 Server, version 1909 Server, version 2004 Windows 8.1 Server 2012 Server 2012 R2 |
CVE-2020-1403 | VBScriptÔ¶³Ì´úÂëÖ´ÐÐÎó²î VBScript engine´¦ÀíÄÚ´æÖй¤¾ßµÄ·½Ê½±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¸ÃÎó²î¿ÉÄÜ»áËð»µÄڴ棬£¬£¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»ÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£È»ºó£¬£¬£¬¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»£»£»Éó²é¡¢¡¢¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»£»£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ | ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë | Internet Explorer 11 Internet Explorer 9 |
CVE-2020-1439 | PerformancePoint ServicesÔ¶³Ì´úÂëÖ´ÐÐÎó²îµ±PerformancePoint Services for SharePoint ServerÎÞ·¨¼ì²éXMLÎļþÊäÈëµÄÔ´±ê¼Çʱ£¬£¬£¬¸ÃÈí¼þÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÈÏÕæXMLÄÚÈÝ·´ÐòÁл¯µÄÀú³ÌÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂ롣ҪʹÓôËÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÊÜÓ°ÏìµÄ²úÆ·½«ÌåÀýµÄÎĵµÉÏ´«µ½·þÎñÆ÷ÒÔ´¦ÀíÄÚÈÝ¡£ Çå¾²¸üÐÂͨ¹ý¸üÕýPerformancePoint ServicesÔõÑùÑéÖ¤XMLÄÚÈݵÄÔ´±ê¼ÇÀ´½â¾ö´ËÎó²î¡£ | ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë | SharePoint Enterprise Server 2013 SharePoint Server 2019 SharePoint Foundation 2013 SharePoint Enterprise Server 2016 Business Productivity Servers 2010 |
CVE-2020-1025 | Microsoft OfficeȨÏÞÌáÉýÎó²î µ±Microsoft SharePoint ServerºÍSkype for Business Server²»×¼È·µØ´¦ÀíOAuthÁîÅÆÑé֤ʱ£¬£¬£¬±£´æÈ¨ÏÞÌáÉýÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÈÆ¹ýÉí·ÝÑéÖ¤²¢ÊµÏÖ²»×¼È·µÄ»á¼û¡£ÒªÊ¹ÓôËÎó²î¾ÙÐй¥»÷£¬£¬£¬¹¥»÷ÕßÐèÒªÐÞ¸ÄÁîÅÆ¡£ ´Ë¸üÐÂͨ¹ýÐÞ¸ÄMicrosoft SharePoint ServerºÍSkype for Business ServerÑéÖ¤ÁîÅÆµÄ·½Ê½À´½â¾ö´ËÎó²î¡£ | ÑÏÖØ ÌØÈ¨ÌáÉý | Skype Business Server 2019 CU2 Skype Business Server 2015 CU 8 Lync Server 2013 SharePoint Enterprise Server 2016 SharePoint Server 2019 SharePoint Foundation 2013 |
CVE-2020-1349 | Microsoft OutlookÔ¶³Ì´úÂëÖ´ÐÐÎó²î Microsoft OutlookÈí¼þδÄÜ׼ȷ´¦ÀíÄÚ´æÖеŤ¾ßʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÇÉÈ«ÐÄ˼¹¹½¨µÄÎļþÔÚÄ¿½ñÓû§µÄÇå¾²ÉÏÏÂÎÄÖÐÖ´ÐвÙ×÷¡£ÀýÈ磬£¬£¬¸ÃÎļþËæºó¿ÉÒÔ´ú±í¾ßÓÐÓëÄ¿½ñÓû§ÏàͬȨÏ޵ĵÇÈÎÃü»§Ö´ÐвÙ×÷¡£ | ÑÏÖØ Ô¶³ÌÖ´ÐдúÂë | 365 Apps Enterprise Office 2019 Outlook 2016 Outlook 2013 Outlook 2010 |
CVE-2020-1446 | Microsoft WordÔ¶³Ì´úÂëÖ´ÐÐÎó²î Microsoft WordÈí¼þδÄÜ׼ȷ´¦ÀíÄÚ´æÖеŤ¾ßʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÇÉÈ«ÐÄ˼¹¹½¨µÄÎļþÔÚÄ¿½ñÓû§µÄÇå¾²ÉÏÏÂÎÄÖÐÖ´ÐвÙ×÷¡£ÀýÈ磬£¬£¬¸ÃÎļþËæºó¿ÉÒÔ´ú±í¾ßÓÐÓëÄ¿½ñÓû§ÏàͬȨÏ޵ĵÇÈÎÃü»§Ö´ÐвÙ×÷¡£ | Ö÷Òª Ô¶³ÌÖ´ÐдúÂë | SharePoint Server 2010 SharePoint Enterprise Server 2013/2016 SharePoint Server 2019 Office Online Server 365 Apps Enterprise Office 2010/2019 Office Web Apps 2010/2013 Word 2010/2013/2016 Office 2016/2019 for Mac |