Microsoft | 12Ô¶à¸ö²úÆ·Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-12-09

0x00 Îó²î¸ÅÊö

2020Äê12ÔÂ08ÈÕ£¬£¬£¬MicrosoftÐû²¼ÁË12Ô·ݵÄÇå¾²¸üУ¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²Îó²î¹²¼Æ58¸ö£¬£¬£¬Ïà½ÏÓÚÉÏÔÂïÔÌ­ÁË54¸ö¡£¡£¡£¡£¡£ ¡£¡£ÆäÖÐÓÐ9¸öÎó²îÆÀ¼¶ÎªÑÏÖØ£¬£¬£¬46¸öÎó²îÆÀ¼¶Îª¸ßΣ¡£¡£¡£¡£¡£ ¡£¡£ÔÚ´Ë´ÎÐû²¼µÄÇå¾²Îó²îÖУ¬£¬£¬ÆäÖÐÓÐ23¸öÎó²îΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬14¸öÎó²îΪȨÏÞÌáÉýÎó²î£¬£¬£¬9¸öÎó²îΪÐÅϢй¶Îó²î¡£¡£¡£¡£¡£ ¡£¡£

 

0x01 Îó²îÏêÇé

 

image.png

΢Èí±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÖУ¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·ºÍ×é¼þ°üÀ¨£ºMicrosoft Windows¡¢Microsoft Edge (EdgeHTML-based)¡¢Microsoft Edge for Android¡¢ChakraCore¡¢Microsoft Office and Microsoft Office Services and Web Apps¡¢Microsoft Exchange Server¡¢Azure DevOps¡¢Microsoft Dynamics¡¢Visual Studio¡¢Azure SDKºÍAzure Sphere¡£¡£¡£¡£¡£ ¡£¡£

±¾´ÎÐû²¼µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE-ID

Îó²îÃû³Æ

ÑÏÖØË®Æ½

CVE-2020-17131

Chakra¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î

ÑÏÖØ

CVE-2020-17095

Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17152

Microsoft Dynamics 365 for Finance and Operations´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17158

Microsoft Dynamics 365 for Finance and Operations´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17117

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17132

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17142

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17118

Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17121

Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17145

Azure DevOpsЧÀÍÆ÷ºÍTeam   Foundation ServicesÓÕÆ­Îó²î

¸ßΣ

CVE-2020-17135

Azure DevOpsЧÀÍÆ÷ÓÕÆ­Îó²î

¸ßΣ

CVE-2020-17002

ÓÃÓÚCÇå¾²¹¦Ð§ÈƹýµÄAzure SDK

¸ßΣ

CVE-2020-17160

Azure SphereÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17137

DirectXͼÐÎÄÚºËȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17147

Dynamics CRM Webclient¿çÕ¾µã¾ç±¾Îó²î

¸ßΣ

CVE-2020-16996

KerberosÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17133

Microsoft Dynamics Business Central / NAVÐÅÏ¢Åû¶

¸ßΣ

CVE-2020-17126

Microsoft ExcelÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17122

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17123

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17125

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17127

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17128

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17129

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17130

Microsoft ExcelÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17143

Microsoft ExchangeÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17141

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17144

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17119

Microsoft OutlookÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17124

Microsoft PowerPointÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17089

Microsoft SharePointȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17120

Microsoft SharePointÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17159

Visual Studio Code JavaÀ©Õ¹°üÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17150

Visual Studio´úÂëÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17148

Visual Studio CodeÔ¶³Ì¿ª·¢À©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17156

Visual StudioÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-16958

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16959

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16960

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16961

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16962

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16963

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16964

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17103

WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17134

WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17136

WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17097

Windows Digital Media ReceiverȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17094

Windows¹ýʧ±¨¸æÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17138

Windows¹ýʧ±¨¸æÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17098

Windows GDI +ÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17099

WindowsËø¶¨ÆÁÄ»Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17092

WindowsÍøÂçÅþÁ¬Ð§ÀÍȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17096

Windows NTFSÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17139

WindowsÁýÕÖɸѡÆ÷Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17140

Windows SMBÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-16971

ÊÊÓÃÓÚJavaµÄAzure SDKÇå¾²¹¦Ð§ÈƹýÎó²î

ÖÐΣ

CVE-2020-17153

Android EdgeµÄMicrosoft   EdgeÎó²î

ÖÐΣ

CVE-2020-17115

Microsoft SharePointÓÕÆ­Îó²î

ÖÐΣ

 

²¿·ÖÑÏÖØÎó²îÈçÏ£º

Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Hyper-VÖб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17095£©£¬£¬£¬ÆäCVSSÆÀ·Ö8.5¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý´ËÎó²î½«Hyper-V Guest OSȨÏÞÌáÉýµ½Hyper-V HostȨÏÞ£¬£¬£¬×îÖÕÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£ ¡£¡£

Windows NTFSÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Windows NTFSÖб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17096£©£¬£¬£¬ÆäCVSSÆÀ·Ö7.5¡£¡£¡£¡£¡£ ¡£¡£¾ßÓÐSMBv2»á¼ûȨÏ޵Ĺ¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâÇëÇóÀ´Ê¹ÓôËÎó²î£¬£¬£¬×îÖÕ¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£ ¡£¡£

Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î

MicrosoftÔÚSharePointÖÐÐÞ¸´ÁË2¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17121ºÍCVE-2020-17118£©¡£¡£¡£¡£¡£ ¡£¡£ÆäÖУ¬£¬£¬CVE-2020-17118 CVSSÆÀ·Ö8.1£¬£¬£¬CVE-2020-17121 CVSSÆÀ·Ö8.8¡£¡£¡£¡£¡£ ¡£¡£

¹¥»÷ÕßÄܹ»Ê¹ÓÃCVE-2020-17121»ñµÃ»á¼ûȨÏÞ£¬£¬£¬ÒÔ½¨ÉèÕ¾µã²¢ÔÚkernelÄÚÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£ ¡£¡£

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

MicrosoftÐÞ¸´ÁËExchangeÖеÄ5¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17141¡¢CVE-2020-17142¡¢CVE-2020-17144¡¢ CVE-2020-17117¡¢CVE-2020-17132£©¡£¡£¡£¡£¡£ ¡£¡£

ÆäÖУ¬£¬£¬CVE-2020-17132ÊǶÔcmdlet²ÎÊýµÄÑéÖ¤²»×¼È·Ôì³ÉµÄ£¬£¬£¬ÆäCVSSÆÀ·Ö9.1¡£¡£¡£¡£¡£ ¡£¡£Microsoft²¢Î´ÔÚ´Ë´¦Ìṩ¹¥»÷³¡¾°£¬£¬£¬µ«Ö¸³ö¹¥»÷ÕßÐèÒª¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬ÇÒ¸ÃÎó²îµÄʹÓÃÖØ´óÐԵ͡£¡£¡£¡£¡£ ¡£¡£ÈôÊǹ¥»÷ÕßÈëÇÖÁËijÈ˵ÄÓÊÏ䣬£¬£¬Ôò¿ÉÒÔ¿ØÖÆÕû¸öExchangeЧÀÍÆ÷¡£¡£¡£¡£¡£ ¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚMicrosoftÒѾ­Ðû²¼ÁËÇå¾²¸üУ¬£¬£¬½¨ÒéʵʱװÖÃÏà¹Ø²¹¶¡¡£¡£¡£¡£¡£ ¡£¡£

 

£¨Ò»£© Windows update¸üÐÂ

 

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬣¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£ ¡£¡£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£ ¡£¡£

4¡¢ÖØÆôÅÌËã»ú£¬£¬£¬×°ÖøüÐÂÏµÍ³ÖØÐÂÆô¶¯ºó£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£ ¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£ ¡£¡£

 

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

΢Èí¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£ ¡£¡£

ÏÂÔØµØµã£º

https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec

https://threatpost.com/microsoft-patch-tuesday-holidays/162041/

https://www.darkreading.com/threat-intelligence/microsoft-fixes-58-cves-for-december-patch-tuesday/d/d-id/1339651?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple

 

0x04 ʱ¼äÏß

2020-12-08  MicrosoftÐû²¼Çå¾²¸üÐÂ

2020-12-09  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

 

 

 

image.png