Windows OLEÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2014-4114) (Alert2014-09)
2014-10-15
ÐÎò£º
CVE ID£ºCVE-2014-4114ÊÜÓ°ÏìµÄÈí¼þ¼°ÏµÍ³£º
====================
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows 7
Microsoft Windows Server 2008 R2
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows RT
Microsoft Windows RT 8.1
δÊÜÓ°ÏìµÄÈí¼þ¼°ÏµÍ³£º
======================
Microsoft Windows XP
×ÛÊö£º
======
Windows OLE×é¼þ¹¦Ð§Öб£´æÒ»¸öÎó²î£¬ÈôÊÇÓû§·¿ª°üÀ¨ÌØÖÆ OLE ¹¤¾ßµÄÎļþ£¬¸ÃÎó²î¿ÉÄÜÔÊÐíÔ¶³ÌÖ´ÐдúÂë¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓëµÇÈÎÃü»§ÏàͬµÄÓû§È¨ÏÞ¡£´ËÎó²îÒѾÔÚijЩAPT¹¥»÷Öб»Ê¹Óá£
΢ÈíÒѾÔÚMS14-060ÖÐÐÞ¸´ÁË´ËÇå¾²Îó²î£¬Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìµÄÓû§ÊµÊ±Éý¼¶×îеÄÇå¾²²¹¶¡¡£
ÆÊÎö£º
======
OLE£¨¹¤¾ßÁ´½ÓÓëǶÈ룩ÊÇÒ»ÖÖÔÊÐíÓ¦ÓóÌÐò¹²ÏíÊý¾ÝºÍ¹¦Ð§µÄÊÖÒÕ£¬Microsoft OfficeÎĵµ¿ÉÒÔʹÓÃOLE¹¤¾ß¡£
INFÎļþÊÇWindowsµÄ×°ÖÃÐÅÏ¢Îļþ£¬ÄÚÀï°üÀ¨ÐèÒªÏÂÔØ²¢×°ÖõÄÈí¼þÐÅÏ¢¡£
OfficeÎĵµ£¨ÀýÈçPowerPointÎļþ£¬ºó׺Ϊ.pptx/.ppt/.pps/.ppsx£©±»·¿ªÊ±£¬ÆäÖеÄÄ³Ð©ÌØÖÆµÄOLE¹¤¾ß¿É¼ÓÔØ²¢Ö´ÐÐÔ¶³ÌINFÎļþ£¬Õâµ¼ÖÂINFÎļþÖÐÉ趨µÄÔ¶³Ì¶ñÒâ¿ÉÖ´ÐгÌÐò±»ÏÂÔØ£¬È»ºóͨ¹ý²Ù×÷×¢²á±í£¬´Ó¶ø½øÒ»²½Ö´ÐиöñÒâÎļþ¡£
Ô¶³Ì¹¥»÷Õß¿ÉÄÜʹÓôËÎó²îͨ¹ýÓÕʹÓû§·¿ª¶ñÒâµÄOfficeÎĵµ£¬²¢¿ØÖÆÓû§ÏµÍ³¡£
´ËÎó²î¿ÉÄÜͨ¹ýÖÖÖÖʹÓÃOLE×é¼þµÄÎĵµ¾ÙÐÐʹÓá£ÏÖÔÚÒÑÖªµÄʹÓ÷½·¨ÊÇͨ¹ýPowerPointÎļþ£¬ÌØÊâÊÇ.ppsºÍ.ppsxÕâЩ¿ÉÒÔ×Ô¶¯²¥·ÅµÄÎļþ¡£
ÏÖÔÚÒÔΪWindows XP²Ù×÷ϵͳ²»ÊÜ´ËÎó²îÓ°Ïì¡£
½â¾öÒªÁ죺
ÈôÊDz»¿ÉʵʱװÖò¹¶¡£¬½¨Òé½ÓÄÉÈçÏ·À»¤²½·¥:* ½ûÓÃWebclient·þÎñ¡£
ÓÉÓÚ¼ÓÔØÍⲿINFµÄ·½·¨ÊÇͨ¹ýWEBDAV·½·¨¾ÙÐУ¬ÒÔÊǽûÓÃWEBDAV»á¼û¿ÉÒÔ±ÜÃâ¹¥»÷¡£
µ«Õâ»áµ¼ÖÂËùÓÐÒÀÀµWEBDAVµÄ¹¦Ð§Ê§Ð§¡£
½ûÓÃÒªÁ죺
µ¥»÷¡°×îÏÈ¡±£¬µ¥»÷¡°ÔËÐС±£¨ÔÚWindows 8 ºÍ 8.1Éϰ´ Windows »Õ±ê¼ü + S ·¿ªËÑË÷£©£¬
¼üÈë¡°Services.msc¡±£¬È»ºóµ¥»÷¡°È·¶¨¡±¡£
ÓÒ¼üµ¥»÷¡°WebClient¡±£¬È»ºóÑ¡Ôñ¡°ÊôÐÔ¡±¡£
½«¡°Æô¶¯ÀàÐÍ¡±¸ü¸ÄΪ¡°ÒѽûÓᱡ£ÈôÊÇ·þÎñÕýÔÚÔËÐУ¬Çëµ¥»÷¡°×èÖ¹¡±¡£
µ¥»÷¡°È·¶¨¡±£¬È»ÍËÈ´³ö·þÎñÖÎÀí¿ØÖÆÌ¨¡£
* ÔÚ½çÏßÍø¹ØÉÏ×èÖ¹¶Ô TCP ¶Ë¿Ú 139 ºÍ 445µÄ»á¼û
³§ÉÌ״̬£º
==========
³§ÉÌÒÑÔÚÇ徲ͨ¸æMS14-060ÖÐÐÞ¸´ÁË´ËÇå¾²Îó²î¡£ÎÒÃǽ¨ÒéÓû§¿ªÆô×Ô¶¯¸üзþÎñÒÔʵʱװÖÃ×îв¹¶¡¡£
³§ÉÌÇ徲ͨ¸æ£º
http://technet.microsoft.com/security/bulletin/MS14-060
¸½¼ÓÐÅÏ¢£º
==========
1. http://technet.microsoft.com/security/bulletin/MS14-060
2. http://www.nsfocus.net/index.php?act=alert&do=view&aid=151

¾ÅÓÎÀϸçÔÆ





