Microsoft Word RTFÎļþÆÊÎö¹ýʧ´úÂëÖ´ÐÐ0dayÎó²î (Alert2014-03)
2014-03-25
ÐÎò£º
CVE ID£ºCVE-2014-1761ÊÜÓ°ÏìµÄÈí¼þ¼°ÏµÍ³£º
====================
Microsoft Word 2003 Service Pack 3
Microsoft Word 2007 Service Pack 3
Microsoft Word 2010 Service Pack 1 (32-bit editions)
Microsoft Word 2010 Service Pack 2 (32-bit editions)
Microsoft Word 2010 Service Pack 1 (64-bit editions)
Microsoft Word 2010 Service Pack 2 (64-bit editions)
Microsoft Word 2013 (32-bit editions)
Microsoft Word 2013 (64-bit editions)
Microsoft Word 2013 RT
Microsoft Word Viewer
Microsoft Office Compatibility Pack Service Pack 3
Microsoft Office for Mac 2011
Word Automation Services on Microsoft SharePoint Server 2010 Service Pack 1
Word Automation Services on Microsoft SharePoint Server 2010 Service Pack 2
Word Automation Services on Microsoft SharePoint Server 2013
Microsoft Office Web Apps 2010 Service Pack 1
Microsoft Office Web Apps 2010 Service Pack 2
Microsoft Office Web Apps Server 2013
======
Microsoft Word ÊÇ΢Èí¹«Ë¾µÄÒ»¸öÎÄ×Ö´¦Öóͷ£Èí¼þ¡£
Microsoft Word±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐ0dayÎó²î£¬Î¢ÈíÒѾ·¢Ã÷Óй¥»÷ÕßÔÚʹÓôËÎó²î¾ÙÐй¥»÷£¬ÏÖÔÚ΢Èí»¹Ã»ÓÐÌṩÕýʽ²¹¶¡¡£
Ç¿ÁÒ½¨ÒéWordÓû§²ÎÕÕ½â¾öÒªÁ첿·ÖµÄ²½·¥¾ÙÐÐÐëÒªµÄ·À»¤£¬²¢ÔÚ΢ÈíÕýʽ²¹¶¡Ðû²¼ºóʵʱÉý¼¶¡£
======
Microsoft WordÔÚÆÊÎö»ûÐεÄRTFÃûÌÃÊý¾Ýʱ±£´æ¹ýʧµ¼ÖÂÄÚ´æÆÆËð£¬Ê¹µÃ¹¥»÷ÕßÄܹ»Ö´ÐÐí§Òâ´úÂë¡£µ±Óû§Ê¹ÓÃMicrosoft WordÊÜÓ°ÏìµÄ°æ±¾·¿ª¶ñÒâRTFÎļþ£¬»òÕßMicrosoft WordÊÇMicrosoft OutlookµÄEmail Viewerʱ£¬Óû§Ô¤ÀÀ»ò·¿ª¶ñÒâµÄRTFÓʼþÐÅÏ¢£¬¹¥»÷Õß¶¼¿ÉÄÜÀÖ³ÉʹÓôËÎó²î£¬´Ó¶ø»ñÊÊÄ¿½ñÓû§µÄȨÏÞ¡£ÖµµÃ×¢ÖØµÄÊÇ£¬Microsoft Outlook 2007/2010/2013ĬÈϵÄEmail Viewer¶¼ÊÇMicrosoft Word¡£
½â¾öÒªÁ죺
ÔÚ³§É̲¹¶¡Ðû²¼Ö®Ç°£¬ÎÒÃǽ¨ÒéÓû§¿ÉÒÔ½ÓÄÉÈçÏ·À»¤²½·¥:* եȡMircosoft Word·¿ªRTFÎļþ¡£½¨ÒéʹÓÃ΢ÈíÌṩµÄFixIt¹¤¾ß: https://support.microsoft.com/kb/2953095
* ÔÚMircosoft WordÐÅÍÐÖÐÐÄÉèÖÃ×ÜÊÇÔÚ±£»¤ÊÓͼ(Protected View)·¿ªRTFÎļþ¡£
* ½ÓÄɳ§ÉÌÌṩµÄEnhanced Mitigation Experience Toolkit (EMET)¹¤¾ß¡£
ÔöÇ¿»º½âÌåÑ鹤¾ß°ü£¨EMET£©ÊÇÒ»¸öÊÊÓù¤¾ß£¬ÓÃÓÚ±ÜÃâÈí¼þÖеÄÎó²î±»ÀÖ³ÉʹÓá£
´ÓÈçÏÂÍøÖ·ÏÂÔØÔöÇ¿»º½âÌåÑ鹤¾ß°ü£º
http://go.microsoft.com/fwlink/?LinkID=200220&clcid=0x409
×°ÖÃÒÔºóÔËÐУ¬ÔÚ"Quick Profile Name"ÖÐÑ¡ÔñRecommended security settings£¬¼´¿É»ñµÃÏìÓ¦µÄ·À»¤¡£
==========
³§ÉÌÒÑÐû²¼Ç徲ͨ¸æºÍÔÝʱ½â¾ö¼Æ»®£¬ÏÖÔÚ»¹Ã»ÓÐÐû²¼²¹¶¡¡£
³§ÉÌÇ徲ͨ¸æ£º
http://technet.microsoft.com/en-us/security/advisory/2953095
FixIt Tool:
https://support.microsoft.com/kb/2953095
==========
1. http://blogs.technet.com/b/srd/archive/2014/03/24/security-advisory-2953095-recommendation-to-stay-protected-and-for-detections.aspx
2. http://technet.microsoft.com/en-us/security/advisory/2953095

¾ÅÓÎÀϸçÔÆ





