΢Èí8Ô²¹¶¡ÈÕ¸ßΣ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-08-15

·ì϶±àºÅºÍ¼¶±ð


CVE-2018-8350µÈ£¨Ïê¼ûÏÂÎÄ£©£¬ £¬ £¬£¬£¬£¬£¬ £¬ÑϳÁ£¬ £¬ £¬£¬£¬£¬£¬ £¬CVSS·ÖÖµ¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


²úÆ·Éæ¼°.NET Framework¡¢Adobe Flash Player¡¢Device Guard¡¢Internet Explorer¡¢Microsoft Browsers¡¢Microsoft Edge¡¢Microsoft Exchange Server¡¢Microsoft Graphics Component¡¢Microsoft Office¡¢Microsoft Scripting Engine¡¢Microsoft Windows¡¢Microsoft Windows PDF¡¢SQL Server¡¢Windows Authentication Methods¡¢Windows COM¡¢Windows Diagnostic Hub¡¢Windows Installer¡¢Windows Kernel¡¢Windows NDIS¡¢Windows RNDISÒÔ¼°Windows Shell¡£¡£¡£¡£¡£¡£¡£


·ì϶¸ÅÊö


΢ÈíÓÚÖܶþ°ä²¼ÁË8Ô°²È«¸üв¹¶¡£¬ £¬ £¬£¬£¬£¬£¬ £¬½¨¸´ÁË63¸ö´Óµ¥Ò»µÄºýŪ¹¥»÷µ½Ô¶³ÌÖ´ÐдúÂëµÄ°²È«ÎÊÌ⣬ £¬ £¬£¬£¬£¬£¬ £¬ÆäÖÐ11¸öÑϳÁ·ì϶£¬ £¬ £¬£¬£¬£¬£¬ £¬±ØÒª¸ß¶È¹Ø×¢¡£¡£¡£¡£¡£¡£¡£


1£®Windows PDFÔ¶³ÌÖ´ÐдúÂë·ì϶CVE-2018-8350
Windows PDF´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓø÷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓ뵱ǰÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£¡£¡£¡£¡£¡£¡£ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬ £¬ £¬£¬£¬£¬£¬ £¬ÄÇô¹¥»÷Õß±ã¿É½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½ £»£»£»£»£»£»£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý £»£»£»£»£»£»£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£¡£¡£¡£¡£


 

2£®Microsoft ExcelÔ¶³ÌÖ´ÐдúÂë·ì϶CVE-2018-8375


Microsoft Excel´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬ £¬ £¬£¬£¬£¬£¬ £¬ÄÇô¹¥»÷Õß¾ÍÄܹ»½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½ £»£»£»£»£»£»£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý £»£»£»£»£»£»£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£¡£¡£¡£¡£ÓëÕ¼ÓÐÖÎÀíÓû§È¨ÏÞµÄÓû§Ïà±È£¬ £¬ £¬£¬£¬£¬£¬ £¬ÕÊ»§±»ÅäÖÃΪռÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì¸üÓס£¡£¡£¡£¡£¡£¡£


3£®Microsoft PowerPointÔ¶³ÌÖ´ÐдúÂë·ì϶CVE-2018-8376


Microsoft PowerPoint´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬ £¬ £¬£¬£¬£¬£¬ £¬ÄÇô¹¥»÷Õß¾ÍÄܹ»½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½ £»£»£»£»£»£»£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý £»£»£»£»£»£»£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£¡£¡£¡£¡£ÓëÕ¼ÓÐÖÎÀíÓû§È¨ÏÞµÄÓû§Ïà±È£¬ £¬ £¬£¬£¬£¬£¬ £¬ÕÊ»§±»ÅäÖÃΪռÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì¸üÓס£¡£¡£¡£¡£¡£¡£


4£®Microsoft ExcelÔ¶³ÌÖ´ÐдúÂë·ì϶CVE-2018-8379


Microsoft Excel Èí¼þ´¦ÖÃÄÚ´æÖеĶÔÏóµÄ·½Ê½´æÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬ £¬ £¬£¬£¬£¬£¬ £¬ÄÇô¹¥»÷Õß¾ÍÄܹ»½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½ £»£»£»£»£»£»£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý £»£»£»£»£»£»£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£¡£¡£¡£¡£ÓëÕ¼ÓÐÖÎÀíÓû§È¨ÏÞµÄÓû§Ïà±È£¬ £¬ £¬£¬£¬£¬£¬ £¬ÕÊ»§±»ÅäÖÃΪռÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì¸üÓ×.


5£®Microsoft SQL ServerÔ¶³ÌÖ´ÐдúÂë·ì϶CVE-2018-8273


Microsoft SQL Server ÖдæÔÚ»º³åÇøÒç¶Âí½Å£¬ £¬ £¬£¬£¬£¬£¬ £¬Õ⽫ÔÊÐí¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄϵͳÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚ SQL Server Êý¾Ý¿âÒýÇæ·þÎñÕÊ»§µÄ¸ßµÍÎÄÖÐÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£


6 £®MicrosoftͼÐÎÔ¶³ÌÖ´ÐдúÂë·ì϶CVE-2018-8344


Windows ×ÖÌå¿â´¦ÖÃǶÈë×ÖÌåµÄ·½Ê½´æÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½ £»£»£»£»£»£»£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý £»£»£»£»£»£»£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£¡£¡£¡£¡£ÓëÕ¼ÓÐÖÎÀíÓû§È¨ÏÞµÄÓû§Ïà±È£¬ £¬ £¬£¬£¬£¬£¬ £¬ÕÊ»§±»ÅäÖÃΪռÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì¸üÓס£¡£¡£¡£¡£¡£¡£


7£®LNKÔ¶³ÌÖ´ÐдúÂë·ì϶CVE-2018-8345


Microsoft Windows´¦ÖÃ.LNK  ÎļþµÄ·½Ê½´æÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜ»á»ñµÃÓë±¾µØÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£¡£¡£¡£¡£¡£¡£ÓëÕ¼ÓÐÖÎÀíÓû§È¨ÏÞµÄÓû§Ïà±È£¬ £¬ £¬£¬£¬£¬£¬ £¬ÕÊ»§±»ÅäÖÃΪռÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì¸üÓס£¡£¡£¡£¡£¡£¡£


8£®GDI Ô¶³ÌÖ´ÐдúÂë·ì϶CVE-2018-8397


Windows ͼÐÎÉ豸½Ó¿Ú (GDI) ´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜ»á½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½ £»£»£»£»£»£»£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý £»£»£»£»£»£»£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£¡£¡£¡£¡£ÓëÕ¼ÓÐÖÎÀíÓû§È¨ÏÞµÄÓû§Ïà±È£¬ £¬ £¬£¬£¬£¬£¬ £¬ÕÊ»§±»ÅäÖÃΪռÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì¸üÓס£¡£¡£¡£¡£¡£¡£


9£®LNKÔ¶³ÌÖ´ÐдúÂë·ì϶CVE-2018-8346


Microsoft Windows´¦ÖÃ.LNK  ÎļþµÄ·½Ê½´æÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜ»á»ñµÃÓë±¾µØÓû§Ò»ÑùµÄÓû§È¨ÏÞ¡£¡£¡£¡£¡£¡£¡£ÓëÕ¼ÓÐÖÎÀíÓû§È¨ÏÞµÄÓû§Ïà±È£¬ £¬ £¬£¬£¬£¬£¬ £¬ÕÊ»§±»ÅäÖÃΪռÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì¸üÓס£¡£¡£¡£¡£¡£¡£


10£®Microsoft COM for WindowsÔ¶³ÌÖ´ÐдúÂë·ì϶CVE-2018-8349


Windows for Microsoft COM ×é¼þ´¦ÖÃÐòÁл¯×Ö·û´®Ê±´æÔÚÐòÁл¯·ì϶¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»Ê¹Óþ­ÌØÊâÉè¼ÆµÄÎļþ»ò¾ç±¾Ö´ÐвÙ×÷¡£¡£¡£¡£¡£¡£¡£ÔÚµç×ÓÓʼþ¹¥»÷Çé¾°ÖУ¬ £¬ £¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÄÜͨ¹ýÏòÓû§·¢Ë;­ÌØÊâÉè¼ÆµÄÎļþ²¢ÓÕµ¼Óû§´ò¿ª¸ÃÎļþÒÔ¹¥»÷·ì϶¡£¡£¡£¡£¡£¡£¡£ÔÚ»ùÓÚ Web µÄ¹¥»÷Çé¾°ÖУ¬ £¬ £¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÄÜÍйÜÍøÕ¾£¨»òÀûÓýÓÊÜ»òÍйÜÓû§ÌṩµÄÄÚÈݵÄÔâµ½ÈëÇÖµÄÍøÕ¾£©£¬ £¬ £¬£¬£¬£¬£¬ £¬ÆäÖÐÔ̺¬¾­ÌØÊâÉè¼ÆµÄÎļþÒÔ¹¥»÷·ì϶¡£¡£¡£¡£¡£¡£¡£µ«ÊÇ£¬ £¬ £¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÎÞ·¨Ç¿ÆÅ×û§½Ó¼û´ËÀàÍøÕ¾¡£¡£¡£¡£¡£¡£¡£Ïà·´£¬ £¬ £¬£¬£¬£¬£¬ £¬¹¥»÷Õß±ØÐëÓÕµ¼Óû§µ¥»÷Á´½Ó£¬ £¬ £¬£¬£¬£¬£¬ £¬²½Öèͨ³£ÊÇͨ¹ýµç×ÓÓʼþ»ò¼´Ê±ÐÂÎŽøÐÐÓÕÆ­£¬ £¬ £¬£¬£¬£¬£¬ £¬¶øºóÓÕµ¼Óû§´ò¿ª¾­ÌØÊâÉè¼ÆµÄÎļþ¡£¡£¡£¡£¡£¡£¡£


11£®Microsoft PowerPointÔ¶³ÌÖ´ÐдúÂë·ì϶CVE-2018-8376


Microsoft PowerPoint´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÖдæÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÔËÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£ÈôÊǵ±Ç°Óû§Ê¹ÓÃÖÎÀíÓû§È¨Ï޵Ǽ£¬ £¬ £¬£¬£¬£¬£¬ £¬ÄÇô¹¥»÷Õß¾ÍÄܹ»½ÚÔìÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉËæºó×°Ö÷¨Ê½ £»£»£»£»£»£»£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý £»£»£»£»£»£»£»»òÕß´´½¨Õ¼ÓÐÆëÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£¡£¡£¡£¡£¡£¡£ÓëÕ¼ÓÐÖÎÀíÓû§È¨ÏÞµÄÓû§Ïà±È£¬ £¬ £¬£¬£¬£¬£¬ £¬ÕÊ»§±»ÅäÖÃΪռÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì¸üÓס£¡£¡£¡£¡£¡£¡£ 


½¨¸´½¨Òé


΢Èí¹Ù·½ÒѾ­°ä²¼¸üв¹¶¡£¬ £¬ £¬£¬£¬£¬£¬ £¬Çëʵʱ½øÐв¹¶¡¸üС£¡£¡£¡£¡£¡£¡£


¹Ù·½Á´½Ó


1£®Windows PDFÔ¶³ÌÖ´ÐдúÂë·ì϶

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2018-8350


2£®Microsoft ExcelÔ¶³ÌÖ´ÐдúÂë·ì϶

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2018-8375


3£®Microsoft PowerPointÔ¶³ÌÖ´ÐдúÂë·ì϶

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2018-8376


4£®Microsoft ExcelÔ¶³ÌÖ´ÐдúÂë·ì϶

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2018-8379


5£®Microsoft SQL ServerÔ¶³ÌÖ´ÐдúÂë·ì϶

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2018-8273


6£®MicrosoftͼÐÎÔ¶³ÌÖ´ÐдúÂë·ì϶

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2018-8344


7£®LNKÔ¶³ÌÖ´ÐдúÂë·ì϶

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2018-8345


8£®GDI Ô¶³ÌÖ´ÐдúÂë·ì϶

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2018-8397


9£®LNKÔ¶³ÌÖ´ÐдúÂë·ì϶

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2018-8346


10£®Microsoft COM for WindowsÔ¶³ÌÖ´ÐдúÂë·ì϶

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2018-8349


11£®Windows ShellÔ¶³ÌÖ´ÐдúÂë·ì϶

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2018-8414


²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/ecb26425-583f-e811-a96f-000d3a33c573