Microsoft | 12Ô¶à¸ö²úÆ·Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-12-090x00 Îó²î¸ÅÊö
2020Äê12ÔÂ08ÈÕ£¬£¬£¬£¬MicrosoftÐû²¼ÁË12Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²Îó²î¹²¼Æ58¸ö£¬£¬£¬£¬Ïà½ÏÓÚÉÏÔÂïÔÌÁË54¸ö¡£¡£¡£¡£¡£ÆäÖÐÓÐ9¸öÎó²îÆÀ¼¶ÎªÑÏÖØ£¬£¬£¬£¬46¸öÎó²îÆÀ¼¶Îª¸ßΣ¡£¡£¡£¡£¡£ÔÚ´Ë´ÎÐû²¼µÄÇå¾²Îó²îÖУ¬£¬£¬£¬ÆäÖÐÓÐ23¸öÎó²îΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬14¸öÎó²îΪȨÏÞÌáÉýÎó²î£¬£¬£¬£¬9¸öÎó²îΪÐÅϢй¶Îó²î¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé
΢Èí±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÖУ¬£¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·ºÍ×é¼þ°üÀ¨£ºMicrosoft Windows¡¢Microsoft Edge (EdgeHTML-based)¡¢Microsoft Edge for Android¡¢ChakraCore¡¢Microsoft Office and Microsoft Office Services and Web Apps¡¢Microsoft Exchange Server¡¢Azure DevOps¡¢Microsoft Dynamics¡¢Visual Studio¡¢Azure SDKºÍAzure Sphere¡£¡£¡£¡£¡£
±¾´ÎÐû²¼µÄÍêÕûÎó²îÁбíÈçÏ£º
CVE-ID | Îó²îÃû³Æ | ÑÏÖØË®Æ½ |
CVE-2020-17131 | Chakra¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î | ÑÏÖØ |
CVE-2020-17095 | Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2020-17152 | Microsoft Dynamics 365 for Finance and Operations´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2020-17158 | Microsoft Dynamics 365 for Finance and Operations´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2020-17117 | Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2020-17132 | Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2020-17142 | Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2020-17118 | Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2020-17121 | Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2020-17145 | Azure DevOpsЧÀÍÆ÷ºÍTeam Foundation ServicesÓÕÆÎó²î | ¸ßΣ |
CVE-2020-17135 | Azure DevOpsЧÀÍÆ÷ÓÕÆÎó²î | ¸ßΣ |
CVE-2020-17002 | ÓÃÓÚCÇå¾²¹¦Ð§ÈƹýµÄAzure SDK | ¸ßΣ |
CVE-2020-17160 | Azure SphereÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2020-17137 | DirectXͼÐÎÄÚºËȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-17147 | Dynamics CRM Webclient¿çÕ¾µã¾ç±¾Îó²î | ¸ßΣ |
CVE-2020-16996 | KerberosÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2020-17133 | Microsoft Dynamics Business Central / NAVÐÅÏ¢Åû¶ | ¸ßΣ |
CVE-2020-17126 | Microsoft ExcelÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2020-17122 | Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17123 | Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17125 | Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17127 | Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17128 | Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17129 | Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17130 | Microsoft ExcelÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2020-17143 | Microsoft ExchangeÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2020-17141 | Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17144 | Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17119 | Microsoft OutlookÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2020-17124 | Microsoft PowerPointÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17089 | Microsoft SharePointȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-17120 | Microsoft SharePointÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2020-17159 | Visual Studio Code JavaÀ©Õ¹°üÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17150 | Visual Studio´úÂëÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17148 | Visual Studio CodeÔ¶³Ì¿ª·¢À©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17156 | Visual StudioÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-16958 | Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-16959 | Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-16960 | Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-16961 | Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-16962 | Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-16963 | Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-16964 | Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-17103 | WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-17134 | WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-17136 | WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-17097 | Windows Digital Media ReceiverȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-17094 | Windows¹ýʧ±¨¸æÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2020-17138 | Windows¹ýʧ±¨¸æÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2020-17098 | Windows GDI +ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2020-17099 | WindowsËø¶¨ÆÁÄ»Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2020-17092 | WindowsÍøÂçÅþÁ¬Ð§ÀÍȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-17096 | Windows NTFSÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17139 | WindowsÁýÕÖɸѡÆ÷Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2020-17140 | Windows SMBÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2020-16971 | ÊÊÓÃÓÚJavaµÄAzure SDKÇå¾²¹¦Ð§ÈƹýÎó²î | ÖÐΣ |
CVE-2020-17153 | Android EdgeµÄMicrosoft EdgeÎó²î | ÖÐΣ |
CVE-2020-17115 | Microsoft SharePointÓÕÆÎó²î | ÖÐΣ |
²¿·ÖÑÏÖØÎó²îÈçÏ£º
Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Hyper-VÖб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17095£©£¬£¬£¬£¬ÆäCVSSÆÀ·Ö8.5¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý´ËÎó²î½«Hyper-V Guest OSȨÏÞÌáÉýµ½Hyper-V HostȨÏÞ£¬£¬£¬£¬×îÖÕÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£
Windows NTFSÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Windows NTFSÖб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17096£©£¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.5¡£¡£¡£¡£¡£¾ßÓÐSMBv2»á¼ûȨÏ޵Ĺ¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâÇëÇóÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬×îÖÕ¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£
Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î
MicrosoftÔÚSharePointÖÐÐÞ¸´ÁË2¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17121ºÍCVE-2020-17118£©¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬CVE-2020-17118 CVSSÆÀ·Ö8.1£¬£¬£¬£¬CVE-2020-17121 CVSSÆÀ·Ö8.8¡£¡£¡£¡£¡£
¹¥»÷ÕßÄܹ»Ê¹ÓÃCVE-2020-17121»ñµÃ»á¼ûȨÏÞ£¬£¬£¬£¬ÒÔ½¨ÉèÕ¾µã²¢ÔÚkernelÄÚÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£
Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î
MicrosoftÐÞ¸´ÁËExchangeÖеÄ5¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17141¡¢CVE-2020-17142¡¢CVE-2020-17144¡¢ CVE-2020-17117¡¢CVE-2020-17132£©¡£¡£¡£¡£¡£
ÆäÖУ¬£¬£¬£¬CVE-2020-17132ÊǶÔcmdlet²ÎÊýµÄÑéÖ¤²»×¼È·Ôì³ÉµÄ£¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.1¡£¡£¡£¡£¡£Microsoft²¢Î´ÔÚ´Ë´¦Ìṩ¹¥»÷³¡¾°£¬£¬£¬£¬µ«Ö¸³ö¹¥»÷ÕßÐèÒª¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬ÇÒ¸ÃÎó²îµÄʹÓÃÖØ´óÐԵ͡£¡£¡£¡£¡£ÈôÊǹ¥»÷ÕßÈëÇÖÁËijÈ˵ÄÓÊÏ䣬£¬£¬£¬Ôò¿ÉÒÔ¿ØÖÆÕû¸öExchangeЧÀÍÆ÷¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚMicrosoftÒѾÐû²¼ÁËÇå¾²¸üУ¬£¬£¬£¬½¨ÒéʵʱװÖÃÏà¹Ø²¹¶¡¡£¡£¡£¡£¡£
£¨Ò»£© Windows update¸üÐÂ
×Ô¶¯¸üУº
Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£
ÊÖ¶¯¸üУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£
4¡¢ÖØÆôÅÌËã»ú£¬£¬£¬£¬×°ÖøüÐÂÏµÍ³ÖØÐÂÆô¶¯ºó£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
΢Èí¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£
ÏÂÔØµØµã£º
https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec
0x03 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec
https://threatpost.com/microsoft-patch-tuesday-holidays/162041/
https://www.darkreading.com/threat-intelligence/microsoft-fixes-58-cves-for-december-patch-tuesday/d/d-id/1339651?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple
0x04 ʱ¼äÏß
2020-12-08 MicrosoftÐû²¼Çå¾²¸üÐÂ
2020-12-09 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/