Microsoft | 12Ô¶à¸ö²úÆ·Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-12-090x00 Îó²î¸ÅÊö
2020Äê12ÔÂ08ÈÕ£¬£¬£¬MicrosoftÐû²¼ÁË12Ô·ݵÄÇå¾²¸üУ¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²Îó²î¹²¼Æ58¸ö£¬£¬£¬Ïà½ÏÓÚÉÏÔÂïÔÌÁË54¸ö¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÓÐ9¸öÎó²îÆÀ¼¶ÎªÑÏÖØ£¬£¬£¬46¸öÎó²îÆÀ¼¶Îª¸ßΣ¡£¡£¡£¡£¡£¡£¡£ÔÚ´Ë´ÎÐû²¼µÄÇå¾²Îó²îÖУ¬£¬£¬ÆäÖÐÓÐ23¸öÎó²îΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬14¸öÎó²îΪȨÏÞÌáÉýÎó²î£¬£¬£¬9¸öÎó²îΪÐÅϢй¶Îó²î¡£¡£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé

΢Èí±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÖУ¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·ºÍ×é¼þ°üÀ¨£ºMicrosoft Windows¡¢Microsoft Edge (EdgeHTML-based)¡¢Microsoft Edge for Android¡¢ChakraCore¡¢Microsoft Office and Microsoft Office Services and Web Apps¡¢Microsoft Exchange Server¡¢Azure DevOps¡¢Microsoft Dynamics¡¢Visual Studio¡¢Azure SDKºÍAzure Sphere¡£¡£¡£¡£¡£¡£¡£
±¾´ÎÐû²¼µÄÍêÕûÎó²îÁбíÈçÏ£º
CVE-ID | Îó²îÃû³Æ | ÑÏÖØË®Æ½ |
CVE-2020-17131 | Chakra¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î | ÑÏÖØ |
CVE-2020-17095 | Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2020-17152 | Microsoft Dynamics 365 for Finance and Operations´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2020-17158 | Microsoft Dynamics 365 for Finance and Operations´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2020-17117 | Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2020-17132 | Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2020-17142 | Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2020-17118 | Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2020-17121 | Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ÑÏÖØ |
CVE-2020-17145 | Azure DevOpsЧÀÍÆ÷ºÍTeam Foundation ServicesÓÕÆÎó²î | ¸ßΣ |
CVE-2020-17135 | Azure DevOpsЧÀÍÆ÷ÓÕÆÎó²î | ¸ßΣ |
CVE-2020-17002 | ÓÃÓÚCÇå¾²¹¦Ð§ÈƹýµÄAzure SDK | ¸ßΣ |
CVE-2020-17160 | Azure SphereÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2020-17137 | DirectXͼÐÎÄÚºËȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-17147 | Dynamics CRM Webclient¿çÕ¾µã¾ç±¾Îó²î | ¸ßΣ |
CVE-2020-16996 | KerberosÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2020-17133 | Microsoft Dynamics Business Central / NAVÐÅÏ¢Åû¶ | ¸ßΣ |
CVE-2020-17126 | Microsoft ExcelÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2020-17122 | Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17123 | Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17125 | Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17127 | Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17128 | Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17129 | Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17130 | Microsoft ExcelÇå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2020-17143 | Microsoft ExchangeÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2020-17141 | Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17144 | Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17119 | Microsoft OutlookÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2020-17124 | Microsoft PowerPointÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17089 | Microsoft SharePointȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-17120 | Microsoft SharePointÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2020-17159 | Visual Studio Code JavaÀ©Õ¹°üÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17150 | Visual Studio´úÂëÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17148 | Visual Studio CodeÔ¶³Ì¿ª·¢À©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17156 | Visual StudioÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-16958 | Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-16959 | Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-16960 | Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-16961 | Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-16962 | Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-16963 | Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-16964 | Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-17103 | WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-17134 | WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-17136 | WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-17097 | Windows Digital Media ReceiverȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-17094 | Windows¹ýʧ±¨¸æÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2020-17138 | Windows¹ýʧ±¨¸æÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2020-17098 | Windows GDI +ÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2020-17099 | WindowsËø¶¨ÆÁÄ»Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2020-17092 | WindowsÍøÂçÅþÁ¬Ð§ÀÍȨÏÞÌáÉýÎó²î | ¸ßΣ |
CVE-2020-17096 | Windows NTFSÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ¸ßΣ |
CVE-2020-17139 | WindowsÁýÕÖɸѡÆ÷Çå¾²¹¦Ð§ÈƹýÎó²î | ¸ßΣ |
CVE-2020-17140 | Windows SMBÐÅϢй¶Îó²î | ¸ßΣ |
CVE-2020-16971 | ÊÊÓÃÓÚJavaµÄAzure SDKÇå¾²¹¦Ð§ÈƹýÎó²î | ÖÐΣ |
CVE-2020-17153 | Android EdgeµÄMicrosoft EdgeÎó²î | ÖÐΣ |
CVE-2020-17115 | Microsoft SharePointÓÕÆÎó²î | ÖÐΣ |
²¿·ÖÑÏÖØÎó²îÈçÏ£º
Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Hyper-VÖб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17095£©£¬£¬£¬ÆäCVSSÆÀ·Ö8.5¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý´ËÎó²î½«Hyper-V Guest OSȨÏÞÌáÉýµ½Hyper-V HostȨÏÞ£¬£¬£¬×îÖÕÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£
Windows NTFSÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Windows NTFSÖб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17096£©£¬£¬£¬ÆäCVSSÆÀ·Ö7.5¡£¡£¡£¡£¡£¡£¡£¾ßÓÐSMBv2»á¼ûȨÏ޵Ĺ¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâÇëÇóÀ´Ê¹ÓôËÎó²î£¬£¬£¬×îÖÕ¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£
Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î
MicrosoftÔÚSharePointÖÐÐÞ¸´ÁË2¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17121ºÍCVE-2020-17118£©¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬CVE-2020-17118 CVSSÆÀ·Ö8.1£¬£¬£¬CVE-2020-17121 CVSSÆÀ·Ö8.8¡£¡£¡£¡£¡£¡£¡£
¹¥»÷ÕßÄܹ»Ê¹ÓÃCVE-2020-17121»ñµÃ»á¼ûȨÏÞ£¬£¬£¬ÒÔ½¨ÉèÕ¾µã²¢ÔÚkernelÄÚÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£
Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î
MicrosoftÐÞ¸´ÁËExchangeÖеÄ5¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17141¡¢CVE-2020-17142¡¢CVE-2020-17144¡¢ CVE-2020-17117¡¢CVE-2020-17132£©¡£¡£¡£¡£¡£¡£¡£
ÆäÖУ¬£¬£¬CVE-2020-17132ÊǶÔcmdlet²ÎÊýµÄÑéÖ¤²»×¼È·Ôì³ÉµÄ£¬£¬£¬ÆäCVSSÆÀ·Ö9.1¡£¡£¡£¡£¡£¡£¡£Microsoft²¢Î´ÔÚ´Ë´¦Ìṩ¹¥»÷³¡¾°£¬£¬£¬µ«Ö¸³ö¹¥»÷ÕßÐèÒª¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬ÇÒ¸ÃÎó²îµÄʹÓÃÖØ´óÐԵ͡£¡£¡£¡£¡£¡£¡£ÈôÊǹ¥»÷ÕßÈëÇÖÁËijÈ˵ÄÓÊÏ䣬£¬£¬Ôò¿ÉÒÔ¿ØÖÆÕû¸öExchangeЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚMicrosoftÒѾÐû²¼ÁËÇå¾²¸üУ¬£¬£¬½¨ÒéʵʱװÖÃÏà¹Ø²¹¶¡¡£¡£¡£¡£¡£¡£¡£
£¨Ò»£© Windows update¸üÐÂ
×Ô¶¯¸üУº
Microsoft UpdateĬÈÏÆôÓ㬣¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£¡£¡£
ÊÖ¶¯¸üУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£¡£¡£
4¡¢ÖØÆôÅÌËã»ú£¬£¬£¬×°ÖøüÐÂÏµÍ³ÖØÐÂÆô¶¯ºó£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£¡£¡£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
΢Èí¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£¡£¡£
ÏÂÔØµØµã£º
https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec
0x03 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec
https://threatpost.com/microsoft-patch-tuesday-holidays/162041/
https://www.darkreading.com/threat-intelligence/microsoft-fixes-58-cves-for-december-patch-tuesday/d/d-id/1339651?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple
0x04 ʱ¼äÏß
2020-12-08 MicrosoftÐû²¼Çå¾²¸üÐÂ
2020-12-09 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ