΢ÈíÐû²¼2Ô·Ý7¸öÇ徲ͨ¸æ ÐÞ¸´ÁË31¸öÇå¾²Îó²î (Alert2014-01)
2014-02-12
ÐÎò£º
΢ÈíÐû²¼ÁË2Ô·Ý7¸öÇ徲ͨ¸æ£ºMS14-005µ½MS14-011£¬ÐÞ¸´ÁËMSXML¡¢IPv6¡¢Direct2D¡¢Microsoft ForeFront Protection 2010 for Exchange¡¢.NET¡¢IE¡¢vb
ÎÒÃÇÇ¿ÁÒ½¨ÒéʹÓÃWindows²Ù×÷ϵͳµÄÓû§Á¬Ã¦¼ì²éÒ»ÏÂÄúµÄϵͳÊÇ·ñÊÜ´ËÎó²îÓ°Ï죬
²¢Æ¾Ö¤ÎÒÃÇÌṩµÄ½â¾öÒªÁìÓèÒÔ½â¾ö¡£
ÆÊÎö£º
1¡¢ MS14-005 - Microsoft XML Core ServicesÐÅϢй¶Îó²î´Ë¸üнâ¾öÁËMicrosoft XML Core ServicesÄÚ1¸ö¹ûÕæ±¨¸æµÄÎó²î¡£ÈôÊÇÓû§ÓÃIE
Éó²éÌØÖÆÍøÒ³£¬´ËÎó²î¿Éµ¼ÖÂÐÅϢй¶¡£
ÊÜÓ°ÏìÈí¼þ:
Windows XP
Windows Server 2003
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 8
Windows 8.1
Windows Server 2012
Windows Server 2012 R2
Windows RT
Windows RT 8.1
Îó²îÐÎò£º
MSXMLÐÅϢй¶Îó²î - CVE-2014-0266
¸ÃÐÅϢй¶Îó²î¿Éʹ¹¥»÷Õß¶ÁÈ¡Óû§ÍâµØÎļþϵͳÉϵÄÎļþ£¬»òÕß¾ÓÉÉí·ÝÑéÖ¤µÄ
WebÓòÄÚÈÝ¡£µ±Óû§Éó²éÌØÖÆµÄWebÄÚÈÝʱ»áͨ¹ýIE´¥·¢MSXML£¬´Ëʱ¹¥»÷Õß¼´¿ÉÒÔÀû
ÓôËÎó²î¡£
ÔÝʱ½â¾ö¼Æ»®£º
* ×èÖ¹ÔÚIEÖÐʹÓÃMSXML 3.0¶þ½øÖÆÐÐΪ
* ½«»¥ÁªÍøºÍÍâµØÍøÂçÇå¾²ÇøÓòÉèÖÃΪ¡°¸ß¡±ÒÔ×èÖ¹ActiveX¿Ø¼þ¼°Ô˶¯¾ç±¾
* ½«IEÉèÖÃΪÔËÐÐÔ˶¯¾ç±¾Ö®Ìõ¼þʾ»òÕßÖ±½Ó½ûÓÃ
2¡¢ MS14-006 - IPv6¾Ü¾ø·þÎñÎó²î
´Ë¸üнâ¾öÁËMicrosoft WindowsÄÚ1¸ö¹ûÕæ±¨¸æµÄÎó²î¡£ÈôÊÇÓû§·¢ËÍ´ó×ÚµÄÌØÖÆ
IPv6Êý¾Ý°üµ½ÊÜÓ°Ïìϵͳ£¬¸ÃÎó²î¿ÉÔì³É¾Ü¾ø·þÎñ¡£ÒªÊ¹ÓôËÎó²î£¬¹¥»÷ÕßµÄϵͳ
±ØÐèºÍÄ¿µÄϵͳÊôÓÚͳһ¸ö×ÓÍø¡£
ÊÜÓ°ÏìÈí¼þ:
Windows 8
Windows Server 2012
Windows RT
Îó²îÐÎò£º
TCP/IP°æ±¾6(IPv6)¾Ü¾ø·þÎñÎó²î - CVE-2014-0254
WindowsÄÚTCP/IP IPv6ʵÏÖ±£´æ¾Ü¾ø·þÎñÎó²î£¬ÀÖ³ÉʹÓúó¿ÉÔì³ÉÊÜÓ°Ïìϵͳ×èÖ¹
ÏìÓ¦¡£
ÔÝʱ½â¾ö¼Æ»®£º
* ½ûÓ÷ÓÉÆ÷·¢Ã÷ÐÒé¡£
* ½ûÓû¥ÁªÍøÐÒé°æ±¾6(IPv6)
* ½ûÓà "Core Networking ¨C Router Advertisement (ICMPv6-In)" ½øÕ¾·À»ðǽ¹æÔò
3¡¢MS14-007 - Direct2DÔ¶³Ì´úÂëÖ´ÐÐÎó²î
´Ë¸üнâ¾öÁËMicrosoft WindowsÖÐ1¸öÉñÃØ±¨¸æµÄÎó²î£¬ÈôÊÇÓû§ÓÃIEÉó²éÌØÖÆÍøÒ³£¬
´ËÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
ÊÜÓ°ÏìÈí¼þ£º
Windows 7
Windows Server 2008 R2
Windows 8
Windows 8.1
Windows Server 2012
Windows Server 2012 R2
Windows RT
Windows RT 8.1
Îó²îÐÎò£º
WindowͼÐÎ×é¼þÄÚ´æÆÆËðÎó²î - CVE-2014-0263
ÊÜÓ°ÏìWindows×é¼þ´¦Öóͷ£ÌØÖƵÄ2D¼¸ºÎͼÐÎʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÈôÊÇÓû§ÓÃIE
Éó²é°üÀ¨ÁËÌØÖÆÍ¼ÐεÄÎļþ£¬¸ÃÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
4¡¢ MS14-008 - Microsoft Forefront Protection for ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î
´Ë¸üнâ¾öÁËMicrosoft ForefrontÖÐ1¸öÉñÃØ±¨¸æµÄÎó²î£¬ÈôÊÇɨÃèÁËÌØÖÆµÄµç×Ó
Óʼþ£¬¸ÃÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
ÊÜÓ°ÏìÈí¼þ£º
Microsoft Forefront Protection 2010 for Exchange Server
Îó²îÐÎò:
RCEÎó²î ¨C CVE-2014-0294
Forefront Protection for Exchange±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÀÖ³ÉʹÓúó¿ÉÔÚÉèÖÃ
ÁË·þÎñÕʺŵÄÇå¾²ÉÏÏÂÎÄÖÐÔËÐÐÔ¶³Ì´úÂë¡£
5¡¢MS14-009 - .NET FrameworkȨÏÞÌáÉýÎó²î
´Ë¸üнâ¾öÁËMicrosoft .NET FrameworkÖÐÁ½¸ö¹ûÕæÐû²¼µÄÎó²îºÍÒ»¸öÉñÃØ±¨¸æµÄ
Îó²î¡£ÈôÊÇÓû§ä¯ÀÀÁËÌØÖÆµÄÍøÕ¾£¬ºÜÊÇÑÏÖØµÄÎó²î¿Éµ¼ÖÂȨÏÞÌáÉý¡£
ÊÜÓ°ÏìÈí¼þ£º
Windows XP
Windows Server 2003
Windows Vista
Windows Server 2008
Windows 7
Windows 8¡¢8.1
Windows Server 2008 R2
Windows Server 2012¡¢2012 R2
Windows RT¡¢RT 8.1
Îó²îÐÎò:
1£©POSTÇëÇó¾Ü¾ø·þÎñÎó²î - CVE-2014-0253
Microsoft ASP.NETÖб£´æ¾Ü¾ø·þÎñÎó²î£¬¿Éʹ¹¥»÷ÕßÔì³ÉASP.NET·þÎñÆ÷²»ÏìÓ¦¡£
ÔÝʱ½â¾ö¼Æ»®£º
* ÉèÖÃ
Îó²îµÄÇëÇó¡£
2£©ÀàÐͱéÀúÎó²î - CVE-2014-0257
Microsoft.NET FrameworkÄÚ±£´æÈ¨ÏÞÌáÉýÎó²î£¬¿Éʹ¹¥»÷ÕßÌáÉýÆäÔÚÊÜÓ°ÏìϵͳÉÏ
µÄȨÏÞ¡£
3£©VSAVB7RT ASLRÎó²î - CVE-2014-0295
Microsoft.NET FrameworkûÓÐ׼ȷʵÏֵصã¿Õ¼ä½á¹¹Ëæ»ú»¯£¬±£´æÇå¾²ÏÞÖÆÈÆ¹ý©
¶´¡£´ËÎó²î¿Éʹ¹¥»÷ÕßÈÆ¹ýASLRÇå¾²¹¦Ð§£¬È»ºó¼´¿É¼ÓÔØ¶ñÒâ´úÂ룬ʹÓÃÆäËüÎó²î¡£
ÔÝʱ½â¾ö¼Æ»®£º
* ×°ÖÃForce ASLR¹¦Ð§ÐÞ¸´£¬²¢ÆôÓÃIFEO×¢²á±íÏî¡£
6¡¢MS14-010 - Internet ExplorerÀÛ»ýÇå¾²¸üÐÂ
´Ë¸üнâ¾öÁËInternet ExplorerÄÚ1¸ö¹ûÕæ±¨¸æµÄÎó²îºÍ23¸öÉñÃØ±¨¸æµÄÎó²î¡£Èç
¹ûÓû§ÓÃIEÉó²éÌØÖÆµÄÍøÒ³£¬×îÑÏÖØµÄÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
ÊÜÓ°ÏìÈí¼þ:
Internet Explorer 6
Internet Explorer 7
Internet Explorer 8
Internet Explorer 9
Internet Explorer 10
Internet Explorer 11
Îó²îÐÎò:
1£©IEȨÏÞÌáÉýÎó²î - CVE-2014-0268
ÔÚÑéÖ¤ÍâµØÎļþ×°ÖÃʱ¼°Çå¾²½¨Éè×¢²á±íÏîʱ£¬IE±£´æÈ¨ÏÞÌáÉýÎó²î¡£
2£©vb
vb
¿ÉÒÔÔÚÄ¿½ñÓû§ÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£
ÔÝʱ½â¾ö¼Æ»®£º
* ÉèÖû¥ÁªÍøºÍÄÚÁªÍøÇå¾²ÇøÓòÉèÖÃΪ¡°¸ß¡±
* ÉèÖÃIEÔÚÔËÐÐÔ˶¯¾ç±¾Ö®Ìõ¼þʾ»òÖ±½Ó½ûÓá£
3£©IE¿çÓòÐÅϢй¶Îó²î - CVE-2014-0293
IEÄÚ±£´æÐÅϢй¶Îó²î£¬¿Éʹ¹¥»÷Õß»á¼ûÁíÒ»¸öÓò»òIEÓòÄÚµÄÐÅÏ¢¡£¹¥»÷Õßͨ¹ý¹¹½¨
ÌØÖÆµÄÍøÒ³Ê¹ÓôËÎó²î¡£
ÔÝʱ½â¾ö¼Æ»®£º
* ÉèÖû¥ÁªÍøºÍÄÚÁªÍøÇå¾²ÇøÓòÉèÖÃΪ¡°¸ß¡±
* ÉèÖÃIEÔÚÔËÐÐÔ˶¯¾ç±¾Ö®Ìõ¼þʾ»òÖ±½Ó½ûÓá£
4£©IEÄÚ¶à¸öÄÚ´æÆÆËðÎó²î
Internet Explorer ûÓÐ׼ȷ»á¼ûÄڴ湤¾ß£¬ÔÚʵÏÖÉϱ£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÀÖ³É
ʹÓúó¿ÉÆÆËðÄڴ棬ÔÚÄ¿½ñÓû§È¨ÏÞÏÂÖ´ÐÐí§Òâ´úÂë¡£ÕâЩÎó²î°üÀ¨£º
IEÄÚ´æÆÆËðÎó²î CVE-2014-0267
IEÄÚ´æÆÆËðÎó²î CVE-2014-0269
IEÄÚ´æÆÆËðÎó²î CVE-2014-0270
IEÄÚ´æÆÆËðÎó²î CVE-2014-0272
IEÄÚ´æÆÆËðÎó²î CVE-2014-0273
IEÄÚ´æÆÆËðÎó²î CVE-2014-0274
IEÄÚ´æÆÆËðÎó²î CVE-2014-0275
IEÄÚ´æÆÆËðÎó²î CVE-2014-0276
IEÄÚ´æÆÆËðÎó²î CVE-2014-0277
IEÄÚ´æÆÆËðÎó²î CVE-2014-0278
IEÄÚ´æÆÆËðÎó²î CVE-2014-0279
IEÄÚ´æÆÆËðÎó²î CVE-2014-0280
IEÄÚ´æÆÆËðÎó²î CVE-2014-0281
IEÄÚ´æÆÆËðÎó²î CVE-2014-0283
IEÄÚ´æÆÆËðÎó²î CVE-2014-0284
IEÄÚ´æÆÆËðÎó²î CVE-2014-0285
IEÄÚ´æÆÆËðÎó²î CVE-2014-0286
IEÄÚ´æÆÆËðÎó²î CVE-2014-0287
IEÄÚ´æÆÆËðÎó²î CVE-2014-0288
IEÄÚ´æÆÆËðÎó²î CVE-2014-0289
IEÄÚ´æÆÆËðÎó²î CVE-2014-0290
ÔÝʱ½â¾ö¼Æ»®£º
* ÉèÖû¥ÁªÍøºÍÄÚÁªÍøÇå¾²ÇøÓòÉèÖÃΪ¡°¸ß¡±
* ÉèÖÃIEÔÚÔËÐÐÔ˶¯¾ç±¾Ö®Ìõ¼þʾ»òÖ±½Ó½ûÓá£
7¡¢MS14-011 - vb
´Ë¸üнâ¾öÁËMicrosoft WindowsÄÚvb
Óû§Éó²éÌØÖÆµÄÍøÕ¾£¬¸ÃÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£
ÊÜÓ°ÏìÈí¼þ£º
vb
vb
vb
vb
vb
vb
ÔÝʱ½â¾ö¼Æ»®£º
* ÉèÖû¥ÁªÍøºÍÄÚÁªÍøÇå¾²ÇøÓòÉèÖÃΪ¡°¸ß¡±
* ÉèÖÃIEÔÚÔËÐÐÔ˶¯¾ç±¾Ö®Ìõ¼þʾ»òÖ±½Ó½ûÓá£
¸½¼ÓÐÅÏ¢£º
==========
1. http://technet.microsoft.com/security/bulletin/MS14-005
2. http://technet.microsoft.com/security/bulletin/MS14-006
3. http://technet.microsoft.com/security/bulletin/MS14-007
4. http://technet.microsoft.com/security/bulletin/MS14-008
5. http://technet.microsoft.com/security/bulletin/MS14-009
6. http://technet.microsoft.com/security/bulletin/MS14-010
7. http://technet.microsoft.com/security/bulletin/MS14-011

¾ÅÓÎÀϸçÔÆ





