Microsoft | 12Ô¶à¸ö²úÆ·Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-12-09

0x00 Îó²î¸ÅÊö

2020Äê12ÔÂ08ÈÕ £¬ £¬£¬£¬£¬MicrosoftÐû²¼ÁË12Ô·ݵÄÇå¾²¸üР£¬ £¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²Îó²î¹²¼Æ58¸ö £¬ £¬£¬£¬£¬Ïà½ÏÓÚÉÏÔÂïÔÌ­ÁË54¸ö¡£¡£¡£¡£ ¡£¡£ÆäÖÐÓÐ9¸öÎó²îÆÀ¼¶ÎªÑÏÖØ £¬ £¬£¬£¬£¬46¸öÎó²îÆÀ¼¶Îª¸ßΣ¡£¡£¡£¡£ ¡£¡£ÔÚ´Ë´ÎÐû²¼µÄÇå¾²Îó²îÖÐ £¬ £¬£¬£¬£¬ÆäÖÐÓÐ23¸öÎó²îΪԶ³Ì´úÂëÖ´ÐÐÎó²î £¬ £¬£¬£¬£¬14¸öÎó²îΪȨÏÞÌáÉýÎó²î £¬ £¬£¬£¬£¬9¸öÎó²îΪÐÅϢй¶Îó²î¡£¡£¡£¡£ ¡£¡£

 

0x01 Îó²îÏêÇé

 

image.png

΢Èí±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÖÐ £¬ £¬£¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·ºÍ×é¼þ°üÀ¨£ºMicrosoft Windows¡¢Microsoft Edge (EdgeHTML-based)¡¢Microsoft Edge for Android¡¢ChakraCore¡¢Microsoft Office and Microsoft Office Services and Web Apps¡¢Microsoft Exchange Server¡¢Azure DevOps¡¢Microsoft Dynamics¡¢Visual Studio¡¢Azure SDKºÍAzure Sphere¡£¡£¡£¡£ ¡£¡£

±¾´ÎÐû²¼µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE-ID

Îó²îÃû³Æ

ÑÏÖØË®Æ½

CVE-2020-17131

Chakra¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î

ÑÏÖØ

CVE-2020-17095

Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17152

Microsoft Dynamics 365 for Finance and Operations´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17158

Microsoft Dynamics 365 for Finance and Operations´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17117

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17132

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17142

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17118

Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17121

Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

CVE-2020-17145

Azure DevOpsЧÀÍÆ÷ºÍTeam   Foundation ServicesÓÕÆ­Îó²î

¸ßΣ

CVE-2020-17135

Azure DevOpsЧÀÍÆ÷ÓÕÆ­Îó²î

¸ßΣ

CVE-2020-17002

ÓÃÓÚCÇå¾²¹¦Ð§ÈƹýµÄAzure SDK

¸ßΣ

CVE-2020-17160

Azure SphereÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17137

DirectXͼÐÎÄÚºËȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17147

Dynamics CRM Webclient¿çÕ¾µã¾ç±¾Îó²î

¸ßΣ

CVE-2020-16996

KerberosÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17133

Microsoft Dynamics Business Central / NAVÐÅÏ¢Åû¶

¸ßΣ

CVE-2020-17126

Microsoft ExcelÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17122

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17123

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17125

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17127

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17128

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17129

Microsoft ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17130

Microsoft ExcelÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17143

Microsoft ExchangeÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17141

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17144

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17119

Microsoft OutlookÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17124

Microsoft PowerPointÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17089

Microsoft SharePointȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17120

Microsoft SharePointÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17159

Visual Studio Code JavaÀ©Õ¹°üÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17150

Visual Studio´úÂëÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17148

Visual Studio CodeÔ¶³Ì¿ª·¢À©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17156

Visual StudioÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-16958

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16959

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16960

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16961

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16962

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16963

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-16964

Windows±¸·ÝÒýÇæÈ¨ÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17103

WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17134

WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17136

WindowsÔÆÎļþСÐÍɸѡÆ÷Çý¶¯³ÌÐòȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17097

Windows Digital Media ReceiverȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17094

Windows¹ýʧ±¨¸æÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17138

Windows¹ýʧ±¨¸æÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17098

Windows GDI +ÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-17099

WindowsËø¶¨ÆÁÄ»Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17092

WindowsÍøÂçÅþÁ¬Ð§ÀÍȨÏÞÌáÉýÎó²î

¸ßΣ

CVE-2020-17096

Windows NTFSÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

CVE-2020-17139

WindowsÁýÕÖɸѡÆ÷Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

CVE-2020-17140

Windows SMBÐÅϢй¶Îó²î

¸ßΣ

CVE-2020-16971

ÊÊÓÃÓÚJavaµÄAzure SDKÇå¾²¹¦Ð§ÈƹýÎó²î

ÖÐΣ

CVE-2020-17153

Android EdgeµÄMicrosoft   EdgeÎó²î

ÖÐΣ

CVE-2020-17115

Microsoft SharePointÓÕÆ­Îó²î

ÖÐΣ

 

²¿·ÖÑÏÖØÎó²îÈçÏ£º

Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Hyper-VÖб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17095£© £¬ £¬£¬£¬£¬ÆäCVSSÆÀ·Ö8.5¡£¡£¡£¡£ ¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý´ËÎó²î½«Hyper-V Guest OSȨÏÞÌáÉýµ½Hyper-V HostȨÏÞ £¬ £¬£¬£¬£¬×îÖÕÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£ ¡£¡£

Windows NTFSÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Windows NTFSÖб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17096£© £¬ £¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.5¡£¡£¡£¡£ ¡£¡£¾ßÓÐSMBv2»á¼ûȨÏ޵Ĺ¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâÇëÇóÀ´Ê¹ÓôËÎó²î £¬ £¬£¬£¬£¬×îÖÕ¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£ ¡£¡£

Microsoft SharePoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î

MicrosoftÔÚSharePointÖÐÐÞ¸´ÁË2¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17121ºÍCVE-2020-17118£©¡£¡£¡£¡£ ¡£¡£ÆäÖÐ £¬ £¬£¬£¬£¬CVE-2020-17118 CVSSÆÀ·Ö8.1 £¬ £¬£¬£¬£¬CVE-2020-17121 CVSSÆÀ·Ö8.8¡£¡£¡£¡£ ¡£¡£

¹¥»÷ÕßÄܹ»Ê¹ÓÃCVE-2020-17121»ñµÃ»á¼ûȨÏÞ £¬ £¬£¬£¬£¬ÒÔ½¨ÉèÕ¾µã²¢ÔÚkernelÄÚÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£ ¡£¡£

Microsoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

MicrosoftÐÞ¸´ÁËExchangeÖеÄ5¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-17141¡¢CVE-2020-17142¡¢CVE-2020-17144¡¢ CVE-2020-17117¡¢CVE-2020-17132£©¡£¡£¡£¡£ ¡£¡£

ÆäÖÐ £¬ £¬£¬£¬£¬CVE-2020-17132ÊǶÔcmdlet²ÎÊýµÄÑéÖ¤²»×¼È·Ôì³ÉµÄ £¬ £¬£¬£¬£¬ÆäCVSSÆÀ·Ö9.1¡£¡£¡£¡£ ¡£¡£Microsoft²¢Î´ÔÚ´Ë´¦Ìṩ¹¥»÷³¡¾° £¬ £¬£¬£¬£¬µ«Ö¸³ö¹¥»÷ÕßÐèÒª¾ÙÐÐÉí·ÝÑéÖ¤ £¬ £¬£¬£¬£¬ÇÒ¸ÃÎó²îµÄʹÓÃÖØ´óÐԵ͡£¡£¡£¡£ ¡£¡£ÈôÊǹ¥»÷ÕßÈëÇÖÁËijÈ˵ÄÓÊÏä £¬ £¬£¬£¬£¬Ôò¿ÉÒÔ¿ØÖÆÕû¸öExchangeЧÀÍÆ÷¡£¡£¡£¡£ ¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚMicrosoftÒѾ­Ðû²¼ÁËÇå¾²¸üР£¬ £¬£¬£¬£¬½¨ÒéʵʱװÖÃÏà¹Ø²¹¶¡¡£¡£¡£¡£ ¡£¡£

 

£¨Ò»£© Windows update¸üÐÂ

 

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓà £¬ £¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ £¬ £¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£ ¡£¡£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü £¬ £¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡± £¬ £¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС± £¬ £¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС± £¬ £¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£ ¡£¡£

4¡¢ÖØÆôÅÌËã»ú £¬ £¬£¬£¬£¬×°ÖøüÐÂÏµÍ³ÖØÐÂÆô¶¯ºó £¬ £¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£ ¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüР£¬ £¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó £¬ £¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡± £¬ £¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£ ¡£¡£

 

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

΢Èí¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£ ¡£¡£

ÏÂÔØµØµã£º

https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec

https://threatpost.com/microsoft-patch-tuesday-holidays/162041/

https://www.darkreading.com/threat-intelligence/microsoft-fixes-58-cves-for-december-patch-tuesday/d/d-id/1339651?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple

 

0x04 ʱ¼äÏß

2020-12-08  MicrosoftÐû²¼Çå¾²¸üÐÂ

2020-12-09  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

 

 

 

image.png