btiÌåÓý

Microsoft 2020Äê7ÔÂÇ徲ͨ¸æ

Ðû²¼Ê±¼ä£º£º2020-08-14 00:00:00 ×÷Õߣº£ºadmin


7ÔÂ14ÈÕ£¬£¬£¬Î¢ÈíÐû²¼ÁË2020Äê7Ô·ݵÄÔ¶ÈÀýÐÐÇ徲ͨ¸æ£¬£¬£¬ÐÞ¸´ÁËÆä¶à¿î²úÆ·±£´æµÄ123¸öÇå¾²Îó²î ¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨£º£ºWindows 10 2004 & WindowsServer v2004£¨86¸ö£©¡¢¡¢¡¢Windows 10 1909 & WindowsServer v1909£¨86¸ö£©¡¢¡¢¡¢Windows 10 1903 & WindowsServer v1903£¨86¸ö£©¡¢¡¢¡¢Windows Server 2012£¨48¸ö£©¡¢¡¢¡¢Windows 8.1 & Server 2012 R2£¨48¸ö£©¡¢¡¢¡¢Windows RT 8.1£¨42¸ö£©¡¢¡¢¡¢Microsoft Edge (EdgeHTML-based)£¨2¸ö£©¡¢¡¢¡¢Internet Explorer£¨2¸ö£©ºÍMicrosoft Office-related software£¨14¸ö£© ¡£

ʹÓÃÉÏÊöÎó²î£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÎó²î¾ÙÐÐÓÕÆ­£¬£¬£¬ÈƹýÇå¾²¹¦Ð§ÏÞÖÆ£¬£¬£¬»ñÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬ÌáÉýȨÏÞ£¬£¬£¬Ö´ÐÐÔ¶³Ì´úÂ룬£¬£¬»òÌᳫ¾Ü¾ø·þÎñ¹¥»÷µÈ ¡£ÌáÐÑ¿í´óMicrosoftÓû§¾¡¿ìÏÂÔØ²¹¶¡¸üУ¬£¬£¬×èÖ¹Òý·¢Îó²îÏà¹ØµÄÍøÂçÇå¾²ÊÂÎñ ¡£

CVE񅧏

ͨ¸æÎÊÌâºÍÕªÒª

×î¸ßÑÏÖØÆ·¼¶ºÍÎó²îÓ°Ïì

ÊÜÓ°ÏìµÄÈí¼þ

CVE-2020-1350

Windows DNS ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Windows Domain Name System serversδÄÜ׼ȷ´¦ÀíÇëÇóʱ£¬£¬£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î ¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÍâµØÏµÍ³ÕÊ»§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂë ¡£ÉèÖÃΪDNS·þÎñÆ÷µÄWindows·þÎñÆ÷±£´æ´ËÎó²îµÄ·çÏÕ ¡£
ҪʹÓôËÎó²î¾ÙÐй¥»÷£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÏò
Windows DNS server·¢ËͶñÒâÇëÇó ¡£
´Ë¸üÐÂͨ¹ýÐÞ¸Ä
Windows DNS servers´¦ÀíÇëÇóµÄ·½Ê½À´½â¾ö¸ÃÎó²î ¡£

ÑÏÖØ
Ô¶³ÌÖ´ÐдúÂë

Server 2016
Server 2019
Server, version 1903
Server, version 1909
Server, version 2004
Server 2012
Server 2012 R2

CVE-2020-1032

Hyper-V RemoteFX vGPUÔ¶³Ì´úÂëÖ´ÐÐÎó²î
µ±Ö÷»ú·þÎñÆ÷ÉϵÄHyper-V RemoteFX vGPUδÄÜ׼ȷÑéÖ¤Guest²Ù×÷ϵͳÉϾ­Éí·ÝÑéÖ¤µÄÓû§µÄÊäÈëʱ£¬£¬£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î ¡£ÒªÊ¹ÓôËÎó²î£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÔÚGuest²Ù×÷ϵͳÉÏÔËÐÐÌØÖÆ³ÌÐò£¬£¬£¬¹¥»÷ÔËÐÐÔÚHyper-V host²Ù×÷ϵͳÉϵĵÚÈý·½ÊÓÆµÇý¶¯À´Ê¹ÓôËÎó²î£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÔÚHost²Ù×÷ϵͳÉÏÖ´ÐÐí§Òâ´úÂë ¡£

ÑÏÖØ
Ô¶³ÌÖ´ÐдúÂë

Server 2016
Server 2012
Server 2012 R2

CVE-2020-1463

Windows SharedStream LibraryȨÏÞÌáÉýÎó²îSharedStream Library´¦ÀíÄÚ´æÖй¤¾ßµÄ·½Ê½±£´æÈ¨ÏÞÌáÉýÎó²î ¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÌáÉýµÄȨÏÞÖ´ÐдúÂë ¡£ÒªÊ¹ÓôËÎó²î¾ÙÐй¥»÷£¬£¬£¬ÍâµØÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÔËÐй¹½¨µÄÓ¦ÓóÌÐò ¡£
Çå¾²¸üÐÂͨ¹ýÈ·±£
SharedStream Library׼ȷ´¦ÀíÄÚ´æÖеŤ¾ßÀ´½â¾ö¸ÃÎó²î ¡£

Ö÷Òª
ÌØÈ¨ÌáÉý

Windows 10
Server 2016
Server 2019
Server, version 1903
Server, version 1909
Server, version 2004

CVE-2020-1374

Windows Remote Desktop ClientÔ¶³Ì´úÂëÖ´ÐÐÎó²î
µ±Óû§ÅþÁ¬µ½¶ñÒâ·þÎñÆ÷ʱ£¬£¬£¬Windows Remote Desktop ClientÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î ¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÅþÁ¬¿Í»§¶ËµÄÅÌËã»úÉÏÖ´ÐÐí§Òâ´úÂë ¡£È»ºó£¬£¬£¬¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»£»£»Éó²é¡¢¡¢¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»£»£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§ ¡£
ҪʹÓôËÎó²î£¬£¬£¬¹¥»÷ÕßÐèÒª¿ØÖÆ·þÎñÆ÷£¬£¬£¬È»ºó˵·þÓû§ÅþÁ¬µ½·þÎñÆ÷ ¡£¹¥»÷ÕßÎÞ·¨Ç¿ÆÈÓû§ÅþÁ¬µ½¶ñÒâ·þÎñÆ÷£¬£¬£¬ÐèҪͨ¹ýÉç»á¹¤³Ì¡¢¡¢¡¢
DNSÖж¾»òʹÓÃÖÐÐÄÈË£¨MITM£©ÊÖÒÕÓÕÆ­Óû§ÅþÁ¬ ¡£¹¥»÷Õß»¹¿ÉÒÔΣº£º¦Õýµ±·þÎñÆ÷£¬£¬£¬ÔÚÆäÉÏÍйܶñÒâ´úÂ룬£¬£¬²¢ÆÚ´ýÓû§ÅþÁ¬ ¡£
´Ë¸üÐÂͨ¹ý¸üÕý
Windows Remote Desktop Client´¦ÀíÅþÁ¬ÇëÇóµÄ·½Ê½À´½â¾ö¸ÃÎó²î ¡£

ÑÏÖØ
Ô¶³ÌÖ´ÐдúÂë

Windows 10
Server 2016
Server 2019
Server, version 1903
Server, version 1909
Server, version 2004
Windows 8.1
Server 2012
Server 2012 R2

CVE-2020-1410

Windows Address BookÔ¶³Ì´úÂëÖ´ÐÐÎó²î
µ±Windows Address Book (WAB)δÄÜ׼ȷµØ´¦ÀívcardÎļþʱ£¬£¬£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î ¡£ÒªÊ¹ÓôËÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËͶñÒâvcard£¬£¬£¬Êܺ¦Õß¿ÉÒÔʹÓÃWindows Address Book (WAB)·­¿ª¸Ãvcard ¡£ÀÖ³ÉʹÓøÃÎó²îºó£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÊܺ¦ÕßϵͳÉÏÖ´ÐÐ ¡£
Çå¾²¸üÐÂͨ¹ý¸üÕý
WWindows Address Book´¦Àí°ó¶¨¼ì²éµÄ·½Ê½À´½â¾ö¸ÃÎó²î ¡£

ÑÏÖØ
Ô¶³ÌÖ´ÐдúÂë

Windows 10
Server 2016
Server 2019
Server, version 1903
Server, version 1909
Server, version 2004
Windows 8.1
Server 2012
Server 2012 R2

CVE-2020-1435

Windows Graphics Device Interface (GDI)Ô¶³Ì´úÂëÖ´ÐÐÎó²î
Windows Graphics Device Interface (GDI) ´¦ÀíÄÚ´æÖеŤ¾ßʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î ¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ ¡£È»ºó£¬£¬£¬¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»£»£»Éó²é¡¢¡¢¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»£»£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§ ¡£ÓëʹÓÃÖÎÀíÓû§È¨ÏÞ²Ù×÷µÄÓû§Ïà±È£¬£¬£¬ÕÊ»§ÉèÖÃΪÔÚϵͳÉϾßÓнÏÉÙÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì½ÏС ¡£

ÑÏÖØ
Ô¶³ÌÖ´ÐдúÂë

Windows 10
Server 2016
Server 2019
Server, version 1903
Server, version 1909
Server, version 2004
Windows 8.1
Server 2012
Server 2012 R2

CVE-2020-1436

Windows Font LibraryÔ¶³Ì´úÂëÖ´ÐÐÎó²î
µ±Windows×ÖÌå¿âδÄÜ׼ȷ´¦Àí¹¹½¨µÄ×ÖÌåʱ£¬£¬£¬±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î ¡£¹ØÓÚ³ýWindows 10ÒÔÍâµÄËùÓÐϵͳ£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔ¶³ÌÖ´ÐдúÂë ¡£¹ØÓÚÔËÐÐWindows 10µÄϵͳ£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚAppContainerɳºÐÉÏÏÂÎÄÖÐÒÔÓÐÏÞµÄȨÏ޺͹¦Ð§Ö´ÐдúÂë ¡£È»ºó£¬£¬£¬¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»£»£»Éó²é¡¢¡¢¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»£»£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§ ¡£

ÑÏÖØ
Ô¶³ÌÖ´ÐдúÂë

Windows 10
Server 2016
Server 2019
Server, version 1903
Server, version 1909
Server, version 2004
Windows 8.1
Server 2012
Server 2012 R2

CVE-2020-1403

VBScriptÔ¶³Ì´úÂëÖ´ÐÐÎó²î
VBScript engine´¦ÀíÄÚ´æÖй¤¾ßµÄ·½Ê½±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î ¡£¸ÃÎó²î¿ÉÄÜ»áËð»µÄڴ棬£¬£¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»ÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë ¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ ¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ ¡£È»ºó£¬£¬£¬¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»£»£»Éó²é¡¢¡¢¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»£»£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§ ¡£

ÑÏÖØ
Ô¶³ÌÖ´ÐдúÂë

Internet Explorer 11
Internet Explorer 9

CVE-2020-1439

PerformancePoint ServicesÔ¶³Ì´úÂëÖ´ÐÐÎó²îµ±PerformancePoint Services for SharePoint ServerÎÞ·¨¼ì²éXMLÎļþÊäÈëµÄÔ´±ê¼Çʱ£¬£¬£¬¸ÃÈí¼þÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î ¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÈÏÕæXMLÄÚÈÝ·´ÐòÁл¯µÄÀú³ÌÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂë ¡£ÒªÊ¹ÓôËÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÊÜÓ°ÏìµÄ²úÆ·½«ÌåÀýµÄÎĵµÉÏ´«µ½·þÎñÆ÷ÒÔ´¦ÀíÄÚÈÝ ¡£
Çå¾²¸üÐÂͨ¹ý¸üÕý
PerformancePoint ServicesÔõÑùÑéÖ¤XMLÄÚÈݵÄÔ´±ê¼ÇÀ´½â¾ö´ËÎó²î ¡£

ÑÏÖØ
Ô¶³ÌÖ´ÐдúÂë

SharePoint Enterprise Server 2013
SharePoint Server 2019
SharePoint Foundation 2013
SharePoint Enterprise Server 2016
Business Productivity Servers 2010

CVE-2020-1025

Microsoft OfficeȨÏÞÌáÉýÎó²î
µ±Microsoft SharePoint ServerºÍSkype for Business Server²»×¼È·µØ´¦ÀíOAuthÁîÅÆÑé֤ʱ£¬£¬£¬±£´æÈ¨ÏÞÌáÉýÎó²î ¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÈÆ¹ýÉí·ÝÑéÖ¤²¢ÊµÏÖ²»×¼È·µÄ»á¼û ¡£ÒªÊ¹ÓôËÎó²î¾ÙÐй¥»÷£¬£¬£¬¹¥»÷ÕßÐèÒªÐÞ¸ÄÁîÅÆ ¡£
´Ë¸üÐÂͨ¹ýÐÞ¸Ä
Microsoft SharePoint ServerºÍSkype for Business ServerÑéÖ¤ÁîÅÆµÄ·½Ê½À´½â¾ö´ËÎó²î ¡£

ÑÏÖØ
ÌØÈ¨ÌáÉý

Skype Business Server 2019 CU2
Skype Business Server 2015 CU 8
Lync Server 2013
SharePoint Enterprise Server 2016
SharePoint Server 2019
SharePoint Foundation 2013

CVE-2020-1349

Microsoft OutlookÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Microsoft OutlookÈí¼þδÄÜ׼ȷ´¦ÀíÄÚ´æÖеŤ¾ßʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î ¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÇÉÈ«ÐÄ˼¹¹½¨µÄÎļþÔÚÄ¿½ñÓû§µÄÇå¾²ÉÏÏÂÎÄÖÐÖ´ÐвÙ×÷ ¡£ÀýÈ磬£¬£¬¸ÃÎļþËæºó¿ÉÒÔ´ú±í¾ßÓÐÓëÄ¿½ñÓû§ÏàͬȨÏ޵ĵÇÈÎÃü»§Ö´ÐвÙ×÷ ¡£

ÑÏÖØ
Ô¶³ÌÖ´ÐдúÂë

365 Apps Enterprise
Office 2019
Outlook 2016
Outlook 2013
Outlook 2010

CVE-2020-1446

Microsoft WordÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Microsoft WordÈí¼þδÄÜ׼ȷ´¦ÀíÄÚ´æÖеŤ¾ßʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î ¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÇÉÈ«ÐÄ˼¹¹½¨µÄÎļþÔÚÄ¿½ñÓû§µÄÇå¾²ÉÏÏÂÎÄÖÐÖ´ÐвÙ×÷ ¡£ÀýÈ磬£¬£¬¸ÃÎļþËæºó¿ÉÒÔ´ú±í¾ßÓÐÓëÄ¿½ñÓû§ÏàͬȨÏ޵ĵÇÈÎÃü»§Ö´ÐвÙ×÷ ¡£

Ö÷Òª
Ô¶³ÌÖ´ÐдúÂë

SharePoint Server 2010
SharePoint Enterprise
Server 2013/2016
SharePoint Server 2019
Office Online Server
365 Apps Enterprise
Office 2010/2019
Office Web Apps 2010/2013
Word 2010/2013/2016
Office 2016/2019 for Mac

²Î¿¼ÐÅÏ¢£º£º

https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/2020-Jul

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200008



¡¾ÍøÕ¾µØÍ¼¡¿
_visitcount?siteId=156&type=3&articleId=143011