΢Èí7Ô²¹¶¡ÈÕÐè¹Ø×¢µÄ¸ßΣÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-07-11

Îó²î±àºÅºÍ¼¶±ð

CVE-2018-8304  Ö÷Òª  ³§ÉÌ×ÔÆÀ£º5.9

CVE-2018-8279  ÑÏÖØ  ³§ÉÌ×ÔÆÀ£º4.2

CVE-2018-8281  Ö÷Òª  

CVE-2018-8311  Ö÷Òª  

CVE-2018-8300  Ö÷Òª

 

Îó²î¸ÅÊö

7ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬Î¢ÈíÐû²¼ÁË2018Äê7Ô·ݵÄÔ¶ÈÀýÐÐÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÆä¶à¿î²úÆ·±£´æµÄ87¸öÇå¾²Îó²î¡£¡£¡£ ¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨Windows 10 v1803 and Server 2016£¨7¸ö£©¡¢Windows 10 v1709£¨8¸ö£©¡¢Windows 10 v1703£¨8¸ö£©¡¢Windows 8.1 and Windows Server2012 R2£¨9¸ö£©¡¢Windows Server 2012£¨8¸ö£©¡¢Windows 7 and Windows Server 2008R2£¨8¸ö£©¡¢Windows Server 2008£¨7¸ö£©¡¢Internet Explorer£¨6¸ö£©¡¢Microsoft Edge£¨19¸ö£©ºÍMicrosoft Office£¨7¸ö£©¡£¡£¡£ ¡£¡£¡£

 

ʹÓÃÉÏÊöÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ»ñÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬ÌáÉýȨÏÞ£¬£¬£¬£¬£¬£¬ÓÕÆ­£¬£¬£¬£¬£¬£¬ÈƹýÇå¾²¹¦Ð§ÏÞÖÆ£¬£¬£¬£¬£¬£¬Ö´ÐÐÔ¶³Ì´úÂ룬£¬£¬£¬£¬£¬»ò¾ÙÐоܾøÐ§À͹¥»÷µÈ¡£¡£¡£ ¡£¡£¡£ÌáÐÑ¿í´óMicrosoftÓû§¾¡¿ìÏÂÔØ²¹¶¡¸üУ¬£¬£¬£¬£¬£¬×èÖ¹Òý·¢Îó²îÏà¹ØµÄÍøÂçÇå¾²ÊÂÎñ¡£¡£¡£ ¡£¡£¡£

 

CVE-2018-8304 Microsoft Windows DNSAPI¾Ü¾øÐ§ÀÍÎó²î

Windows Domain Name System (DNS) DNSAPI.dllδÄÜ׼ȷ´¦Öóͷ£DNSÏìӦʱ£¬£¬£¬£¬£¬£¬±£´æ¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£ ¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÄܵ¼ÖÂϵͳ×èÖ¹ÏìÓ¦¡£¡£¡£ ¡£¡£¡£ÒªÊ¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß½«Ê¹ÓöñÒâDNSЧÀÍÆ÷ÏòÄ¿µÄ·¢ËÍË𻵵ÄDNSÏìÓ¦¡£¡£¡£ ¡£¡£¡£

 

ÊÜÓ°ÏìµÄÈí¼þ£º

Windows 10

Windows 7

Windows 8.1

Windows RT 8.1

Server 2008

Server 2008 R2

Server 2012

Server 2012 R2

Server 2016

 

CVE-2018-8279 Microsoft EdgeÔ¶³ÌÖ´ÐдúÂëÎó²î

µ±Microsoft EdgeδÄÜ׼ȷ»á¼ûÄÚ´æÖеŤ¾ßʱ£¬£¬£¬£¬£¬£¬±£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¡£¡£ ¡£¡£¡£¸ÃÎó²î¿ÉÄÜÒÔÒ»ÖÖʹ¹¥»÷ÕßÄܹ»ÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂëµÄ·½·¨À´ÆÆËðÄÚ´æ¡£¡£¡£ ¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£¡£¡£ ¡£¡£¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬£¬£¬£¬£¬£¬Ôò¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¡£¡£ ¡£¡£¡£È»ºó¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»£»£» Éó²é£¬£¬£¬£¬£¬£¬¸ü¸Ä»òɾ³ýÊý¾Ý£»£»£» »ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£ ¡£¡£¡£

 

ÊÜÓ°ÏìµÄÈí¼þ£º

Microsoft  ChakraCore

Microsoft Edge

 

CVE-2018-8281 Microsoft  OfficeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

µ±Èí¼þδÄÜ׼ȷ´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ£¬£¬£¬£¬£¬£¬Microsoft OfficeÈí¼þ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£ ¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬£¬£¬£¬£¬£¬Ôò¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¡£¡£ ¡£¡£¡£È»ºó¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»£»£»Éó²é£¬£¬£¬£¬£¬£¬¸ü¸Ä»òɾ³ýÊý¾Ý£»£»£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£ ¡£¡£¡£ÕÊ»§±»ÉèÖÃΪӵÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§¿ÉÄܱÈʹÓÃÖÎÀíÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°ÏìҪС¡£¡£¡£ ¡£¡£¡£

 

ÊÜÓ°ÏìµÄÈí¼þ£º

Office 2016 for Mac

PowerPoint Viewer

Office 2016 C2R

Office Compat Pack

Word Viewer

Excel Viewer

 

CVE-2018-8311 Microsoft Skype for Business and LyncÔ¶³Ì´úÂëÖ´ÐÐÎó²î

µ±Skype for BusinessºÍMicrosoft Lync¿Í»§¶ËδÄÜ׼ȷ¹ýÂËÌØÖÆÄÚÈÝʱ£¬£¬£¬£¬£¬£¬±£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¡£¡£ ¡£¡£¡£¸ÃÎó²î¿ÉÄÜÒÔÒ»ÖÖÔÊÐí¹¥»÷ÕßÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂëµÄ·½·¨À´ÆÆËðÄÚ´æ¡£¡£¡£ ¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëÄ¿½ñÓû§ÏàͬµÄÓû§È¨ÏÞ¡£¡£¡£ ¡£¡£¡£ÈôÊÇÄ¿½ñÓû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬£¬£¬£¬£¬£¬Ôò¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¡£¡£ ¡£¡£¡£È»ºó¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò£»£»£»Éó²é£¬£¬£¬£¬£¬£¬¸ü¸Ä»òɾ³ýÊý¾Ý£»£»£»»ò½¨Éè¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£ ¡£¡£¡£

 

ÊÜÓ°ÏìµÄÈí¼þ£º

Skype for Business 2016

Lync 2013

 

CVE-2018-8300 Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐÐÎó²î

µ±Èí¼þδÄܼì²éÓ¦ÓóÌÐò°üµÄÔ´±ê¼Çʱ£¬£¬£¬£¬£¬£¬Microsoft SharePointÖб£´æÒ»¸öÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¡£¡£ ¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚSharePointÓ¦ÓóÌÐò³ØºÍSharePointЧÀÍÆ÷³¡ÕÊ»§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£¡£

ʹÓôËÎó²îÐèÒªÓû§½«ÌØÖƵÄSharePointÓ¦ÓóÌÐò°üÉÏÔØµ½ÊÜÓ°ÏìµÄSharePoint°æ±¾¡£¡£¡£ ¡£¡£¡£

 

ÊÜÓ°ÏìµÄÈí¼þ£º

SharePoint  Enterprise 2016

SharePoint  Foundation 2013

 

ÐÞ¸´½¨Ò飺

ÏÖÔÚ£¬£¬£¬£¬£¬£¬Î¢Èí¹Ù·½ÒѾ­Ðû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬£¬£¬£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ï죬£¬£¬£¬£¬£¬¾¡¿ì½ÓÄÉÐÞ²¹²½·¥£¬£¬£¬£¬£¬£¬ÒÔ×èֹDZÔÚµÄÇå¾²Íþв¡£¡£¡£ ¡£¡£¡£ÏëÒª¾ÙÐиüУ¬£¬£¬£¬£¬£¬Ö»Ðèתµ½ÉèÖáú¸üкÍÇå¾²¡úWindows¸üСú¼ì²é¸üУ¬£¬£¬£¬£¬£¬»òÕßÒ²¿ÉÒÔͨ¹ýÊÖ¶¯¾ÙÐиüС£¡£¡£ ¡£¡£¡£

 

²Î¿¼Á´½Ó£º

https://portal.msrc.microsoft.com/en-us/security-guidance/acknowledgments