΢Èí1Ô¶à¸öÇå¾²Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-01-16

Îó²î¸ÅÊö


΢ÈíÓÚÖܶþÐû²¼ÁË1ÔÂÇå¾²¸üв¹¶¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬£¬Ðû²¼ÁËÕë¶Ô49¸öÎó²îµÄÐÞ¸´³ÌÐò¡£¡£¡£¡£ÔÚÕâЩÎó²îÖУ¬£¬£¬£¬£¬£¬£¬£¬ÓÐ7¸ö±»·ÖÀàΪÑÏÖØ£¬£¬£¬£¬£¬£¬£¬£¬41¸ö±»·ÖÀàΪÖ÷Òª£¬£¬£¬£¬£¬£¬£¬£¬1¸ö±»·ÖÀàΪÖеÈ¡£¡£¡£¡£²úÆ·Éæ¼°Microsoft Windows¡¢Internet Explorer¡¢Microsoft Office¡¢Microsoft Office ServicesºÍWebÓ¦Óá¢ASP.NET Core¡¢.NET Core¡¢.NET Framework¡¢OneDrive for Android¡¢Microsoft Dynamics¡£¡£¡£¡£


ÒÔÏÂÊÇÒѽâ¾öµÄÑÏÖØÎó²îµÄÍêÕûÁбíÒÔ¼°2020Äê1Ô²¹¶¡ÐÇÆÚ¶þ¸üÐÂÖеĽ¨Òé¡£¡£¡£¡£


CVE񅧏

ÑÏÖØË®Æ½

CVEÎÊÌâ

Îó²îÐÎò

²úÆ·

CVE-2020-0606

ÑÏÖØ

.NET FrameworkÔ¶³ÌÖ´ÐдúÂëÎó²î

ÕâÊÇASP.NET ÓëÆäËû¿ò¼Ü£¨ÈçEntity Framework£©Ò»Æð×÷Ϊģ¿£¿£¿ £¿é»¯Web¿ò¼ÜµÄÖØÐÂʵÏÖ¡£¡£¡£¡£Ð¿ò¼ÜʹÓÃеĿªÔ´.NET±àÒëÆ÷ƽ̨£¨´úºÅ¡° Roslyn¡±£©¡£¡£¡£¡£

.NET FrameworkÊÇMicrosoft¿ª·¢µÄÒ»ÖÖÈí¼þ¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÔÚ WindowsÉÏÔËÐС£¡£¡£¡£Ëü°üÀ¨Ò»¸ö³ÆÎª¿ò¼ÜÀà¿â£¨FCL£©µÄ´óÐÍÀà¿â£¬£¬£¬£¬£¬£¬£¬£¬²¢ÌṩÁ˼¸ÖÖ±à³ÌÓïÑÔÖ®¼äµÄÓïÑÔ»¥²Ù×÷ÐÔ£¨Ã¿ÖÖÓïÑÔ¶¼¿ÉÒÔʹÓÃÒÔÆäËûÓïÑÔ±àдµÄ´úÂ룩¡£¡£¡£¡£Îª.NET Framework±àдµÄ³ÌÐòÔÚ³ÆÎª¹«¹²ÓïÑÔÔËÐÐʱ£¨CLR£©µÄÈí¼þÇéÐΣ¨ÓëÓ²¼þÇéÐÎÏà·´£©ÖÐÖ´ÐС£¡£¡£¡£FCLºÍCLRÅäºÏ×é³É.NET Framework¡£¡£¡£¡£

.NET FrameworkÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔ­ÓÉÖ÷ÒªÊÇ.NET FrameworkÔÚ¶ÔÎļþÔ´±ê¼Ç¾ÙÐмì²éʱ±£´æÎÊÌâ¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÓÕµ¼Óû§Ê¹ÓÃÊÜÓ°ÏìµÄ.NET Framework·­¿ªÌØÖƵÄÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

.NET Framework

CVE-2020-0605

ÑÏÖØ

.NET FrameworkÔ¶³ÌÖ´ÐдúÂëÎó²î

ÕâÊÇASP.NET ÓëÆäËû¿ò¼Ü£¨ÈçEntity Framework£©Ò»Æð×÷Ϊģ¿£¿£¿ £¿é»¯Web¿ò¼ÜµÄÖØÐÂʵÏÖ¡£¡£¡£¡£Ð¿ò¼ÜʹÓÃеĿªÔ´.NET±àÒëÆ÷ƽ̨£¨´úºÅ¡° Roslyn¡±£©¡£¡£¡£¡£

.NET FrameworkÊÇMicrosoft¿ª·¢µÄÒ»ÖÖÈí¼þ¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÔÚ WindowsÉÏÔËÐС£¡£¡£¡£Ëü°üÀ¨Ò»¸ö³ÆÎª¿ò¼ÜÀà¿â£¨FCL£©µÄ´óÐÍÀà¿â£¬£¬£¬£¬£¬£¬£¬£¬²¢ÌṩÁ˼¸ÖÖ±à³ÌÓïÑÔÖ®¼äµÄÓïÑÔ»¥²Ù×÷ÐÔ£¨Ã¿ÖÖÓïÑÔ¶¼¿ÉÒÔʹÓÃÒÔÆäËûÓïÑÔ±àдµÄ´úÂ룩¡£¡£¡£¡£Îª.NET Framework±àдµÄ³ÌÐòÔÚ³ÆÎª¹«¹²ÓïÑÔÔËÐÐʱ£¨CLR£©µÄÈí¼þÇéÐΣ¨ÓëÓ²¼þÇéÐÎÏà·´£©ÖÐÖ´ÐС£¡£¡£¡£FCLºÍCLRÅäºÏ×é³É.NET Framework¡£¡£¡£¡£

¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔ­ÓÉÖ÷ÒªÊÇ.NET FrameworkÔÚ¶ÔÎļþÔ´±ê¼Ç¾ÙÐмì²éʱ±£´æÎÊÌâ¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÓÕµ¼Óû§Ê¹ÓÃÊÜÓ°ÏìµÄ.NET Framework·­¿ªÌØÖƵÄÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

.NET Framework

CVE-2020-0646

ÑÏÖØ

.NET FrameworkÔ¶³ÌÖ´ÐдúÂë×¢ÈëÎó²î

ASP.NETÊÇ¿ª·ÅÔ´´úÂëЧÀÍÆ÷¶Ë WebÓ¦ÓóÌÐò¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÓÃÓÚWeb¿ª·¢ÒÔÌìÉúMicrosoft¿ª·¢µÄ¶¯Ì¬ÍøÒ³£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÔÊÐí³ÌÐòÔ±¹¹½¨¶¯Ì¬ÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬Ó¦ÓóÌÐòºÍЧÀÍ¡£¡£¡£¡£ASP.NETµÄºó¼ÌÕßÊÇASP.NET Core¡£¡£¡£¡£ËüÊÇASP.NET ÓëÆäËû¿ò¼Ü£¨ÈçEntity Framework£©Ò»Æð×÷Ϊģ¿£¿£¿ £¿é»¯Web¿ò¼ÜµÄÖØÐÂʵÏÖ¡£¡£¡£¡£Ð¿ò¼ÜʹÓÃеĿªÔ´.NET±àÒëÆ÷ƽ̨£¨´úºÅ¡° Roslyn¡±£©¡£¡£¡£¡£

¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔ­ÓÉÖ÷ÒªÊÇ.NET FrameworkÎÞ·¨×¼È·ÑéÖ¤ÊäÈ룬£¬£¬£¬£¬£¬£¬£¬ÔÚÓû§ÊäÈëÖпÉÒÔ²åÈë¿ÉÖ´ÐеÄÏÂÁî¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃÌØ¶¨µÄ.NETÒªÁì½«ÌØ¶¨ÊäÈë´«ÈëÓ¦ÓóÌÐò£¬£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£

.NET Framework

CVE-2020-0603

ÑÏÖØ

ASP.NET CoreÔ¶³ÌÖ´ÐдúÂëÎó²î

ASP.NETÊÇ¿ª·ÅÔ´´úÂëЧÀÍÆ÷¶Ë WebÓ¦ÓóÌÐò¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÓÃÓÚWeb¿ª·¢ÒÔÌìÉúMicrosoft¿ª·¢µÄ¶¯Ì¬ÍøÒ³£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÔÊÐí³ÌÐòÔ±¹¹½¨¶¯Ì¬ÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬Ó¦ÓóÌÐòºÍЧÀÍ¡£¡£¡£¡£ASP.NETµÄºó¼ÌÕßÊÇASP.NET Core¡£¡£¡£¡£

¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔ­ÓÉÖ÷ÒªÊÇASP.NET CoreÔÚ´¦Öóͷ£Äڴ湤¾ßʱ±£´æÎÊÌâ¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÓÕµ¼Óû§Ê¹ÓÃÊÜÓ°ÏìµÄASP.NET Core·­¿ªÌØÖƵÄÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

ASP.NET

CVE-2020-0610

ÑÏÖØ

WindowsÔ¶³Ì×ÀÃæÍø¹Ø£¨RDÍø¹Ø£©Ô¶³ÌÖ´ÐдúÂëÎó²î

Óû§¿ªÆôÔ¶³Ì×ÀÃæ¹¦Ð§£¬£¬£¬£¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýRDPÏòÓû§·¢ËÍÈ«ÐÄÖÆ×÷µÄ¶ñÒâÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¼´¿ÉÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬£¬£¬¸ÃÀú³Ì²»ÐèÒªÓû§½»»¥¡£¡£¡£¡£´Ë¸üÐÂͨ¹ý¸üÕý RDP Íø¹Ø´¦Öóͷ£ÅþÁ¬ÇëÇóµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£¡£¡£¡£

Windows RDP

CVE-2020-0609

ÑÏÖØ

WindowsÔ¶³Ì×ÀÃæÍø¹Ø£¨RDÍø¹Ø£©Ô¶³ÌÖ´ÐдúÂëÎó²î

Óû§¿ªÆôÔ¶³Ì×ÀÃæ¹¦Ð§£¬£¬£¬£¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýRDPÏòÓû§·¢ËÍÈ«ÐÄÖÆ×÷µÄ¶ñÒâÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¼´¿ÉÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬£¬£¬¸ÃÀú³Ì²»ÐèÒªÓû§½»»¥¡£¡£¡£¡£´Ë¸üÐÂͨ¹ý¸üÕý RDP Íø¹Ø´¦Öóͷ£ÅþÁ¬ÇëÇóµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£¡£¡£¡£

Windows RDP

CVE-2020-0611

ÑÏÖØ

Ô¶³Ì×ÀÃæ¿Í»§¶ËÔ¶³ÌÖ´ÐдúÂëÎó²î

¹¥»÷ÕßʹÓÿØÖƵĶñÒâЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬£¬ÓÕµ¼Óû§ÅþÁ¬µ½¶ñÒâЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÅþÁ¬¿Í»§¶ËµÄÅÌËã»úÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÄÜΣº¦Õýµ±Ð§ÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÆäÉÏÍйܶñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬£¬²¢ÆÚ´ýÓû§ÅþÁ¬¡£¡£¡£¡£´ËÇå¾²¸üÐÂͨ¹ý¸üÕý Windows Ô¶³Ì×ÀÃæ¿Í»§¶Ë´¦Öóͷ£ÅþÁ¬ÇëÇóµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£¡£¡£¡£

Windows RDP


ÐÞ¸´½¨Òé


ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬Î¢Èí¹Ù·½ÒѾ­Ðû²¼²¹¶¡ÐÞ¸´ÁËÉÏÊöÎó²î£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§ÊµÊ±È·ÈÏÊÇ·ñÊܵ½Îó²îÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬¾¡¿ì½ÓÄÉÐÞ²¹²½·¥£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ×èֹDZÔÚµÄÇå¾²Íþв¡£¡£¡£¡£ÏëÒª¾ÙÐиüУ¬£¬£¬£¬£¬£¬£¬£¬Ö»Ðèתµ½ÉèÖáú¸üкÍÇå¾²¡úWindows ¸üСú¼ì²é¸üУ¬£¬£¬£¬£¬£¬£¬£¬»òÕßÒ²¿ÉÒÔͨ¹ýÊÖ¶¯¾ÙÐиüС£¡£¡£¡£


²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/zh-cn/security-guidance