ûÓй«¸æ

ÍÆ¼öÎÄÕÂ
 
ÈÈÃÅÎÄÕÂ
¸ü¶à
 
 
΢Èí·¢²¼2007Äê2Ô·ݰ²È«¹«¸æ
×÷ÕߣºCCERT    ÎÄÕÂÀ´Ô´£ºCCERT    µã»÷Êý£º    ¸üÐÂʱ¼ä£º2007-2-14

 

΢Èí¸Õ¸Õ·¢²¼Á˽ñÄê2Ô·ݵÄ12¸ö°²È«¹«¸æ£¬¹«¸æÖÐÓÐ6¸öÊôÓÚÑÏÖØ¼¶±ð£¬ËüÃÇ·Ö±ðÊÇ£º

 

HTML °ïÖú ActiveX ¿Ø¼þÔ¶³ÌÖ´ÐдúÂë©¶´ (928843)

΢Èí°²È«¹«¸æ MS07-008

 

·¢²¼ÈÕÆÚ:2007-02-13

 

Ó°Ïìϵͳ:

Microsoft Windows 2000 Service Pack 4

Microsoft Windows XP Service Pack 2

Microsoft Windows XP Professional x64 Edition

Microsoft Windows Server 2003

Microsoft Windows Server 2003 Service Pack 1

Microsoft Windows Server 2003£¨ÓÃÓÚ»ùÓÚ Itanium µÄϵͳ£©

Microsoft Windows Server 2003 SP1£¨ÓÃÓÚ»ùÓÚ Itanium µÄϵͳ£©

Microsoft Windows Server 2003 x64 Edition

 

CVE񅧏:CVE-2007-0214

 

·çÏյȼ¶:ÑÏÖØ

 

ÏêϸÐÅÏ¢:

windowsϵͳÖеÄHTML °ïÖú ActiveX ¿Ø¼þÖдæÔÚÔ¶³ÌÖ´ÐдúÂë©¶´¡£ ¹¥»÷Õß¿ÉÒÔͨ¹ý¹¹

½¨ÌØÖÆÍøÒ³À´ÀûÓôË©¶´£¬Èç¹ûÓû§·ÃÎʸÃÍøÒ³£¬ÔòÓпÉÄÜÔÊÐíÔ¶³ÌÖ´ÐдúÂë¡£³É¹¦ÀûÓôË

©¶´µÄ¹¥»÷Õß¿ÉÒÔÍêÈ«¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£

 

½â¾ö°ì·¨

 

ÁÙʱ°ì·¨:

ÔÝʱ×èÖ¹ HTML °ïÖú ActiveX ¿Ø¼þÔÚ Internet Explorer ÖÐÔËÐÐ.

ActiveX ¿Ø¼þµÄ CLSID ÊǸÿؼþµÄ GUID¡£ Äú¿ÉÒÔͨ¹ýÉèÖà kill bit ʹ Internet Explorer´Ó²»µ÷Óÿؼþ£¬´Ó¶ø×èÖ¹ ActiveX ¿Ø¼þÔÚ Internet Explorer ÖÐÔËÐС£ kill bit ÊÇ×¢²á±íÖÐ ActiveX ¿Ø¼þµÄ Compatibility Flags DWORD ÖµµÄÒ»¸öÌØ¶¨Öµ¡£

HTML °ïÖú ActiveX ¿Ø¼þµÄ CLSID Ϊ {52a2aaae-085d-4187-97ea-8c30db990436}

 

²¹¶¡ÏÂÔØ:

³§ÉÌÒѾ­Õë¶Ô¸Ã©¶´·¢²¼ÁËÏàÓ¦µÄ°²È«¹«¸æºÍ²¹¶¡³ÌÐò£¬ÓÉÓÚ²¹¶¡°²×°Ñ¡Ôñ±È½Ï¸´ÔÓ£¬ÎÒÃDz»½¨ÒéÄúʹÓÃÊÖ¹¤°²×°µÄ·½Ê½£¬Äã¿ÉÒÔʹÓÃwindows×Ô´øµÄupdate¹¦ÄܽøÐиüУ¬Í¬Ê±ÄãÒ²¿ÉÒÔʹÓÃÎÒÃÇÌṩµÄsus·þÎñ£¨http://sus.ccert.edu.cn)½øÐиüÐÂ.

²Î¿¼Á´½Ó£ºhttp://www.microsoft.com/technet/security/bulletin/ms07-008.mspx

 

Microsoft Data Access Components ÖпÉÄÜÔÊÐíÔ¶³ÌÖ´ÐдúÂë©¶´ (927779)

΢Èí°²È«¹«¸æ MS07-009

 

·¢²¼ÈÕÆÚ:2007-02-13

 

Ó°Ïìϵͳ:

Microsoft Windows 2000 Service Pack 4

Microsoft Windows XP Service Pack 2 

Microsoft Windows Server 2003 

Microsoft Windows Server 2003£¨ÓÃÓÚ»ùÓÚ Itanium µÄϵͳ£©

 

CVE񅧏:CVE-2006-5559

 

·çÏյȼ¶:ÑÏÖØ

 

ÏêϸÐÅÏ¢:

×÷Ϊ ActiveX Êý¾Ý¶ÔÏó (ADO) µÄÒ»²¿·ÖÌṩ²¢ÔÚ MDAC Öзַ¢µÄ ADODB.Connection ActiveX

¿Ø¼þÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£MDAC ÖÐµÄ ADODB.Connection ActiveX ¿Ø¼þÈç¹û´«µÝÌØ

¶¨¸ñʽµÄÊý¾Ý£¬»áµ¼ÖÂIEä¯ÀÀÆ÷ÔËÐÐʧ°Ü£¬Í¬Ê±¿ÉÄÜÔÊÐíÖ´ÐдúÂë¡£

 

½â¾ö°ì·¨

 

ÁÙʱ½â¾ö°ì·¨:

 

·½·¨Ò»£º½ûÖ¹ ADODB.Connection ActiveX ¿Ø¼þÔÚ Internet Explorer ÖÐÔËÐÐ,·½·¨ÈçÏÂ:

 

1.½«ÏÂÁÐÎı¾±£´æµ½Ò»¸ö.reg ÎļþÖС£

 

Windows ×¢²á±í±à¼­Æ÷ 5.00 °æ

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\

{00000514-0000-0010-8000-00AA006D2EA4}]

Compatibility Flags=dword:00000400

 

2.ͨ¹ýË«»÷´Ë .reg Îļþ½«ÆäÓ¦Óõ½¸÷¸öϵͳ¡£

·½·¨¶þ£º½« Internet Explorer ÅäÖÃΪÔÚ Internet ºÍ±¾µØ Intranet °²È«ÇøÓòÖÐÔËÐÐ ActiveX¿Ø¼þ֮ǰ½øÐÐÌáʾ£¬²½ÖèÈçÏ£º

1. ÔÚ Internet Explorer ÖУ¬µ¥»÷¡°¹¤¾ß¡±²Ëµ¥Éϵġ°Internet Ñ¡Ï¡£

2. µ¥»÷¡°°²È«¡±Ñ¡Ï¡£

3. µ¥»÷¡°Internet¡±£¬È»ºóµ¥»÷¡°×Ô¶¨Òå¼¶±ð¡±¡£

4. ÔÚ¡°ÉèÖá±Ï£¬ÔÚ¡°ActiveX ¿Ø¼þºÍ²å¼þ¡±²¿·ÖÖеġ°ÔËÐÐ ActiveX ¿Ø¼þºÍ²å¼þ¡±Ï£¬µ¥»÷¡°Ìáʾ¡±»ò¡°½ûÖ¹¡±£¬È»ºóµ¥»÷¡°È·¶¨¡±¡£

5. µ¥»÷¡°±¾µØ Intranet¡±£¬È»ºóµ¥»÷¡°×Ô¶¨Òå¼¶±ð¡±¡£

6. ÔÚ¡°ÉèÖá±Ï£¬ÔÚ¡°ActiveX ¿Ø¼þºÍ²å¼þ¡±²¿·ÖÖеġ°ÔËÐÐ ActiveX ¿Ø¼þºÍ²å¼þ¡±Ï£¬µ¥»÷¡°Ìáʾ¡±»ò¡°½ûÖ¹¡±£¬È»ºóµ¥»÷¡°È·¶¨¡±¡£

7. µ¥»÷¡°È·¶¨¡±Á½´Î·µ»Øµ½ Internet Explorer¡£

²¹¶¡ÏÂÔØ:

³§ÉÌÒѾ­Õë¶Ô¸Ã©¶´·¢²¼ÁËÏàÓ¦µÄ°²È«¹«¸æºÍ²¹¶¡³ÌÐò£¬ÓÉÓÚ²¹¶¡°²×°Ñ¡Ôñ±È½Ï¸´ÔÓ£¬ÎÒÃDz»½¨ÒéÄúʹÓÃÊÖ¹¤°²×°µÄ·½Ê½£¬Äã¿ÉÒÔʹÓÃwindows×Ô´øµÄupdate¹¦ÄܽøÐиüУ¬Í¬Ê±ÄãÒ²¿ÉÒÔʹÓÃÎÒÃÇÌṩµÄsus·þÎñ£¨http://sus.ccert.edu.cn)½øÐиüÐÂ.

²Î¿¼Á´½Ó£ºhttp://www.microsoft.com/technet/security/bulletin/ms07-009.mspx

 

windows¶ñÒâÈí¼þ±£»¤ÒýÇæÖпÉÄÜÔÊÐíÔ¶³ÌÖ´ÐдúÂë©¶´ (932135)

΢Èí°²È«¹«¸æ MS07-010

 

·¢²¼ÈÕÆÚ:2007-02-13

 

Ó°Ïìϵͳ:

Windows Live OneCare

Microsoft Antigen for Exchange Server 9.x

Microsoft Antigen for SMTP Server 9.x

Microsoft Windows Defender

Microsoft Windows Defender x64 Edition

Microsoft Forefront Security Server for Exchange Server 10

Microsoft Forefront Security for SharePoint Server 10

 

CVE񅧏:CVE-2006-5270

 

·çÏյȼ¶:ÑÏÖØ

 

ÏêϸÐÅÏ¢:

Microsoft ¶ñÒâÈí¼þ±£»¤ÒýÇæ (mpengine.dll) ¿ÉΪÒÔÏ·À²¡¶¾ºÍ·´¼äµýÈí¼þ¿Í»§¶ËÌṩɨÃè¡¢¼à²âºÍÇå³ý¹¦ÄÜ¡£ÓÉÓÚ¸ÃÒýÇæ´¦ÀíÌØÖÆ PDF Îļþʱ´æÔÚÕûÊýÒç³ö´íÎóµ¼Ö¿ÉÄÜ´æÔÚÔ¶³ÌÖ´ÐдúÂë©¶´.Ä¿±ê¼ÆËã»úϵͳÊÕµ½ PDF Îļþ»ò Microsoft ¶ñÒâÈí¼þ±£»¤ÒýÇæÉ¨Ãè PDF Îļþʱ£¬¹¥»÷Õß¿ÉÄÜ»áͨ¹ý¹¹½¨ÌØÖÆµÄ PDF ÎļþÀ´ÀûÓôË©¶´£¬³É¹¦ÀûÓôË©¶´¹¥»÷Õß¿ÉÒÔÍêÈ«¿ØÖÆÓû§µÄ¼ÆËã»ú¡£

½â¾ö°ì·¨

 

ÁÙʱ½â¾ö°ì·¨:

ÔÝʱûÓлº½â¹¥»÷ÍþвµÄ°ì·¨

 

²¹¶¡ÏÂÔØ:

³§ÉÌÒѾ­Õë¶Ô¸Ã©¶´·¢²¼ÁËÏàÓ¦µÄ°²È«¹«¸æºÍ²¹¶¡³ÌÐò£¬ÓÉÓÚ²¹¶¡°²×°Ñ¡Ôñ±È½Ï¸´ÔÓ£¬ÎÒÃDz»½¨ÒéÄúʹÓÃÊÖ¹¤°²×°µÄ·½Ê½£¬Äã¿ÉÒÔʹÓÃwindows×Ô´øµÄupdate¹¦ÄܽøÐиüУ¬Í¬Ê±ÄãÒ²¿ÉÒÔʹÓÃÎÒÃÇÌṩµÄsus·þÎñ£¨http://sus.ccert.edu.cn)½øÐиüÐÂ.

²Î¿¼Á´½Ó£ºhttp://www.microsoft.com/technet/security/bulletin/ms07-010.mspx

 

 

Word ÖпÉÄÜÔÊÐíÔ¶³ÌÖ´ÐдúÂë©¶´ (929434)

΢Èí°²È«¹«¸æ MS07-014

 

·¢²¼ÈÕÆÚ:2007-02-13

 

Ó°Ïìϵͳ:

Microsoft Office 2000 Service Pack 3

 -Microsoft Word 2000  

Microsoft Office XP Service Pack 3

 -Microsoft Word 2002  

Microsoft Office 2003 Service Pack 2

 -Microsoft Word 2003

 -Microsoft Word Viewer 2003  

Microsoft Works Suite£º

 -Microsoft Works Suite 2004

 -Microsoft Works Suite 2005

 -Microsoft Works Suite 2006

Microsoft Office 2004 for Mac

 

CVE񅧏:

CVE-2006-5994

CVE-2006-6456

CVE-2006-6561

CVE-2007-0208

CVE-2007-0209

CVE-2007-0515

 

·çÏյȼ¶:ÑÏÖØ

 

ÏêϸÐÅÏ¢:

1¡¢Word ¸ñʽ´íÎóµÄ×Ö·û´®Â©¶´

Word ´¦ÀíÎļþµÄÄÚÈÝʱûÓÐÖ´ÐÐ×ã¹»µÄÊý¾ÝÑéÖ¤¡£ µ± Word ´ò¿ªÌØÖƵÄWord Îļþ²¢·ÖÎö

¸ñʽ´íÎóµÄ×Ö·û´®Ê±£¬Ëü¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷Õß¿ÉÒÔÖ´ÐÐÈÎÒâ´úÂëµÄ·½Ê½À´ÆÆ»µÏµÍ³ÄÚ´æ¡£´ËÀà

ÌØÖÆÎļþ¿ÉÄܰüÀ¨ÔÚµç×ÓÓʼþ¸½¼þÖлòËÞÖ÷ÔÚ¶ñÒâÍøÕ¾ÉÏ¡£

 

2¡¢Word ¸ñʽ´íÎóµÄÊý¾Ý½á¹¹Â©¶´

Word ´¦ÀíÎļþµÄÄÚÈÝʱûÓÐÖ´ÐÐ×ã¹»µÄÊý¾ÝÑéÖ¤¡£ µ± Word ´ò¿ªÌØÖÆµÄ Word Îļþ²¢·ÖÎö

¸ñʽ´íÎóµÄÊý¾Ý½á¹¹Ê±£¬Ëü¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷Õß¿ÉÒÔÖ´ÐÐÈÎÒâ´úÂëµÄ·½Ê½À´ÆÆ»µÏµÍ³ÄÚ´æ¡£´Ë

ÀàÌØÖÆÎļþ¿ÉÄܰüÀ¨ÔÚµç×ÓÓʼþ¸½¼þÖлòËÞÖ÷ÔÚ¶ñÒâÍøÕ¾ÉÏ¡£

 

3¡¢word×ÖÊýͳ¼ÆÂ©¶´

Microsoft Word ÖдæÔÚÒ»¸öÔ¶³ÌÖ´ÐдúÂë©¶´¡£ÔÚ Word ·ÖÎöÎļþºÍ´¦Àíδ¾­¼ì²éµÄ¼ÆÊýʱ¹¥»÷Õß¿ÉÀûÓôË©¶´¡£´ËÀàÌØÖÆÎļþ¿ÉÄܰüÀ¨ÔÚµç×ÓÓʼþ¸½¼þÖлòËÞÖ÷ÔÚ¶ñÒâÍøÕ¾ÉÏ¡£¹¥»÷Õß¿ÉÒÔͨ¹ý¹¹½¨ÌØÖÆµÄ Word ÎļþÀ´ÀûÓôË©¶´£¬´ËÎļþ¿ÉÄÜÔÊÐíÔ¶³ÌÖ´ÐдúÂë¡£ ÔÚÊÜÓ°ÏìµÄ Outlook °æ±¾Öв鿴»òÔ¤ÀÀ¸ñʽ´íÎóµÄµç×ÓÓʼþ²»»áµ¼ÖÂÀûÓôË©¶´¡£

 

4¡¢Word ºê©¶´

ºêÊÇÖ¸²Ù×÷ϵͳ»ò³ÌÐòÄÚ×Ô¶¯Ö´Ðг£¼ûÈÎÎñµÄС³ÌÐò¡£ Office ²úƷϵÁеÄËùÓгÉÔ±¾ùÖ§³Ö

ʹÓúꡣWord ¶Ô¾­¹ýÐ޸ĵÄÎĵµ½øÐдíÎóµÄÊôÐÔ¼ì²é£¬µ¼ÖÂÎĵµÖгöÏÖºêʱ£¬ËüûÓÐͨ¹ýºê°²È«¾¯¸æÌáʾÓû§¡£

 

5¡¢Word¸ñʽ´íÎóµÄ»æÍ¼¶ÔÏó©¶´

Word ´¦ÀíÎļþµÄÄÚÈÝʱûÓÐÖ´ÐÐ×ã¹»µÄÊý¾ÝÑéÖ¤¡£ µ± Word ´ò¿ªÌØÖÆµÄ Word Îļþ²¢·ÖÎö¸ñʽ´íÎóµÄ»æÍ¼¶ÔÏóʱ£¬Ëü¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷Õß¿ÉÒÔÖ´ÐÐÈÎÒâ´úÂëµÄ·½Ê½À´ÆÆ»µÏµÍ³ÄÚ´æ¡£

 

6¡¢Word ¸ñʽ´íÎóµÄ¹¦ÄÜ©¶´

Word ´¦ÀíÎļþµÄÄÚÈÝʱûÓÐÖ´ÐÐ×ã¹»µÄÊý¾ÝÑéÖ¤¡£ µ± Word ´ò¿ªÌØÖÆµÄ Word Îļþ²¢·ÖÎö¸ñʽ´íÎóµÄ¹¦ÄÜʱ£¬Ëü¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷Õß¿ÉÒÔÖ´ÐÐÈÎÒâ´úÂëµÄ·½Ê½À´ÆÆ»µÏµÍ³ÄÚ´æ¡£

 

½â¾ö°ì·¨

 

ÁÙʱ½â¾ö°ì·¨:

²»ÒªËæ±ã´ò¿ª²»ÊÜÐÅÈεÄwordÎĵµ

 

²¹¶¡ÏÂÔØ:

³§ÉÌÒѾ­Õë¶Ô¸Ã©¶´·¢²¼ÁËÏàÓ¦µÄ°²È«¹«¸æºÍ²¹¶¡³ÌÐò£¬ÓÉÓÚ²¹¶¡°²×°Ñ¡Ôñ±È½Ï¸´ÔÓ£¬ÎÒÃDz»½¨ÒéÄúʹÓÃÊÖ¹¤°²×°µÄ·½Ê½£¬Äã¿ÉÒÔʹÓÃwindows×Ô´øµÄupdate¹¦ÄܽøÐиüУ¬Í¬Ê±ÄãÒ²¿ÉÒÔʹÓÃÎÒÃÇÌṩµÄsus·þÎñ£¨http://sus.ccert.edu.cn)½øÐиüÐÂ.

 

²Î¿¼Á´½Ó£ºhttp://www.microsoft.com/technet/security/bulletin/ms07-014.mspx

 

 

OfficeÖпÉÄÜÔÊÐíÔ¶³ÌÖ´ÐдúÂë©¶´ (932554)

΢Èí°²È«¹«¸æ MS07-015

 

·¢²¼ÈÕÆÚ£º2007-02-13

 

Ó°Ïìϵͳ£º

Microsoft Office 2000 Service Pack 3

Microsoft Office XP Service Pack 3

Microsoft Office 2003 Service Pack 2

Microsoft Project 2000 Service Release 1

Microsoft Project 2002 Service Pack 1

Microsoft Visio 2002 Service Pack 2

Microsoft Office 2004 for Mac

 

CVE񅧏:

CVE-2006-3877

CVE-2007-0671

 

·çÏյȼ¶:ÑÏÖØ

 

ÏêϸÐÅÏ¢:

1¡¢PowerPoint ¸ñʽ´íÎóµÄ¼Ç¼ÄÚ´æËð»µÂ©¶´

PowerPoint ÖдæÔÚÒ»¸öÔ¶³ÌÖ´ÐдúÂë©¶´£¬µ± PowerPoint ´ò¿ªÌØÖÆÎļþʱ£¬¸Ã©¶´¿ÉÄܱ»ÀûÓᣴËÀàÎļþ¿ÉÄܰüÀ¨ÔÚµç×ÓÓʼþ¸½¼þÖлòËÞÖ÷ÔÚ¶ñÒâÍøÕ¾ÉÏ¡£¹¥»÷Õß¿ÉÒÔͨ¹ý¹¹½¨ÌØÖÆµÄ PowerPointÎļþÀ´ÀûÓôË©¶´£¬´ËÎļþ¿ÉÄÜÔÊÐíÔ¶³ÌÖ´ÐдúÂë¡£Èç¹ûÓû§Ê¹ÓùÜÀíÓû§È¨Ï޵Ǽ£¬³É¹¦ÀûÓôË©¶´µÄ¹¥»÷Õß±ã¿ÉÍêÈ«¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó°²×°³ÌÐò£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨ÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ ÄÇЩÕÊ»§±»ÅäÖÃΪӵÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§±È¾ßÓйÜÀíÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°ÏìҪС¡£

2¡¢Excel ¸ñʽ´íÎóµÄ¼Ç¼©¶´

Excel ÖдæÔÚÒ»¸öÔ¶³ÌÖ´ÐдúÂë©¶´£¬µ± Excel ´ò¿ªÌØÖÆÎļþʱ£¬¸Ã©¶´¿ÉÄܱ»ÀûÓᣴËÀàÎļþ¿ÉÄܰüÀ¨ÔÚµç×ÓÓʼþ¸½¼þÖлòËÞÖ÷ÔÚ¶ñÒâÍøÕ¾ÉÏ¡£¹¥»÷Õß¿ÉÒÔͨ¹ý¹¹½¨ÌØÖÆµÄ Excel ÎļþÀ´ÀûÓôË©¶´£¬´ËÎļþ¿ÉÄÜÔÊÐíÔ¶³ÌÖ´ÐдúÂë¡£Èç¹ûÓû§Ê¹ÓùÜÀíÓû§È¨Ï޵Ǽ£¬³É¹¦ÀûÓôË©¶´µÄ¹¥»÷Õß±ã¿ÉÍêÈ«¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£¹¥»÷Õß¿ÉËæºó°²×°³ÌÐò£»²é¿´¡¢¸ü¸Ä»òɾ³ýÊý¾Ý£»»òÕß´´½¨ÓµÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£ÄÇЩÕÊ»§±»ÅäÖÃΪӵÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§±È¾ßÓйÜÀíÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°ÏìҪС¡£

 

½â¾ö°ì·¨

 

ÁÙʱ½â¾ö°ì·¨:

²»ÒªËæ±ã´ò¿ª²»ÊÜÐÅÈεÄpptºÍexcelÎĵµ

 

²¹¶¡ÏÂÔØ:

³§ÉÌÒѾ­Õë¶Ô¸Ã©¶´·¢²¼ÁËÏàÓ¦µÄ°²È«¹«¸æºÍ²¹¶¡³ÌÐò£¬ÓÉÓÚ²¹¶¡°²×°Ñ¡Ôñ±È½Ï¸´ÔÓ£¬ÎÒÃDz»½¨ÒéÄúʹÓÃÊÖ¹¤°²×°µÄ·½Ê½£¬Äã¿ÉÒÔʹÓÃwindows×Ô´øµÄupdate¹¦ÄܽøÐиüУ¬Í¬Ê±ÄãÒ²¿ÉÒÔʹÓÃÎÒÃÇÌṩµÄsus·þÎñ£¨http://sus.ccert.edu.cn)½øÐиüÐÂ.

 

²Î¿¼Á´½Ó£ºhttp://www.microsoft.com/technet/security/bulletin/ms07-015.mspx

 

 

Internet Explorer µÄÀÛ»ýÐÔ°²È«¸üР(928090)

΢Èí°²È«¹«¸æ MS07-016

 

·¢²¼ÈÕÆÚ£º2007-02-13

 

Ó°Ïìϵͳ£º

Microsoft Windows 2000 Service Pack 4

Microsoft Windows XP Service Pack 2

Microsoft Windows XP Professional x64 Edition

Microsoft Windows Server 2003 ºÍ Microsoft Windows Server 2003 Service Pack 1

Microsoft Windows Server 2003£¨ÓÃÓÚ»ùÓÚ Itanium µÄϵͳ£©

Microsoft Windows Server 2003 SP1£¨ÓÃÓÚ»ùÓÚ Itanium µÄϵͳ£©

Microsoft Windows Server 2003 x64 Edition

 

CVE񅧏:

CVE-2006-4697

CVE-2007-0219

CVE-2007-0217

 

·çÏյȼ¶:ÑÏÖØ

 

ÏêϸÐÅÏ¢£º

1¡¢COM ¶ÔÏóʵÀý»¯ÄÚ´æËð»µÂ©¶´

IEä¯ÀÀÆ÷ÊÇÎÒÃÇ×î³£ÓõÄÍøÒ³ä¯ÀÀÆ÷Ö®Ò»£¬×î½ü·¢ÏÖµ±Internet Explorer³¢ÊÔ½«Ä³Ð©

COM ¶ÔÏóʵÀý»¯Îª ActiveX ¿Ø¼þʱ£¬COM ¶ÔÏó¿ÉÄÜÒÔÒ»ÖÖ¹¥»÷Õß¿ÉÒÔÖ´ÐÐÈÎÒâ´úÂëµÄ·½Ê½À´ÆÆ»µÏµÍ³×´Ì¬¡£¹¥»÷Õß¿ÉÄÜͨ¹ý¹¹½¨ÌØÖÆÍøÒ³À´ÀûÓôË©¶´£¬Èç¹ûÓû§²é¿´Á˸ÃÍøÒ³£¬Ôò¿ÉÄÜÔÊÐíÔ¶³ÌÖ´ÐдúÂë¡£³É¹¦ÀûÓôË©¶´µÄ¹¥»÷Õß¿ÉÒÔÍêÈ«¿ØÖÆÊÜÓ°ÏìµÄϵͳ¡£

2¡¢FTP ·þÎñÆ÷ÏìӦ©¶´

Internet Explorer ½âÊÍÀ´×Ô FTP ·þÎñÆ÷µÄÏìÓ¦µÄ·½Ê½ÖдæÔÚÒ»¸öÔ¶³ÌÖ´ÐдúÂë©¶´¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚ FTP »á»°Öз¢ËÍÌØÖÆµÄ FTP ÏìÓ¦ÖÁ°üÀ¨ÔÚ Internet Explorer ÖÐµÄ FTP ¿Í»§¶ËÀ´ÀûÓøÃ©¶´¡£³É¹¦ÀûÓôË©¶´µÄ¹¥»÷Õß¿ÉÒÔ»ñµÃÓë±¾µØÓû§ÏàͬµÄÓû§È¨ÏÞ¡£ÄÇЩÕÊ»§±»ÅäÖÃΪӵÓнÏÉÙϵͳÓû§È¨ÏÞµÄÓû§±È¾ßÓйÜÀíÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°ÏìҪС¡£

 

½â¾ö°ì·¨

 

ÁÙʱ½â¾ö°ì·¨£º

·½·¨Ò»£º½« Internet Explorer ÅäÖÃΪÔÚ Internet ºÍ±¾µØ Intranet °²È«ÇøÓòÖÐÔËÐÐ ActiveX ¿Ø¼þ

֮ǰ½øÐÐÌáʾ£¬·½·¨ÈçÏ£º

1.ÔÚ Internet Explorer ÖУ¬µ¥»÷¡°¹¤¾ß¡±²Ëµ¥Éϵġ°Internet Ñ¡Ï¡£

 2.µ¥»÷¡°°²È«¡±Ñ¡Ï¡£

3.µ¥»÷¡°Internet¡±£¬È»ºóµ¥»÷¡°×Ô¶¨Òå¼¶±ð¡±¡£

 4.ÔÚ¡°ÉèÖá±Ï£¬ÔÚ¡°ActiveX ¿Ø¼þºÍ²å¼þ¡±²¿·ÖÖеġ°ÔËÐÐ ActiveX ¿Ø¼þºÍ²å¼þ¡±Ï£¬µ¥»÷¡°Ìáʾ¡±»ò¡°½ûÖ¹¡±£¬È»ºóµ¥»÷¡°È·¶¨¡±¡£

 5.µ¥»÷¡°±¾µØ Intranet¡±£¬È»ºóµ¥»÷¡°×Ô¶¨Òå¼¶±ð¡±¡£

 6.ÔÚ¡°ÉèÖá±Ï£¬ÔÚ¡°ActiveX ¿Ø¼þºÍ²å¼þ¡±²¿·ÖÖеġ°ÔËÐÐ ActiveX ¿Ø¼þºÍ²å¼þ¡±Ï£¬µ¥»÷¡°Ìáʾ¡±»ò¡°½ûÖ¹¡±£¬È»ºóµ¥»÷¡°È·¶¨¡±¡£

7.µ¥»÷¡°È·¶¨¡±Á½´Î·µ»Øµ½ Internet Explorer¡£

 

·½·¨¶þ£ºÊ¹Óô¿Îı¾¸ñʽ²é¿´µç×ÓÓʼþ

 

²¹¶¡ÏÂÔØ:

³§ÉÌÒѾ­Õë¶Ô¸Ã©¶´·¢²¼ÁËÏàÓ¦µÄ°²È«¹«¸æºÍ²¹¶¡³ÌÐò£¬ÓÉÓÚ²¹¶¡°²×°Ñ¡Ôñ±È½Ï¸´ÔÓ£¬ÎÒÃDz»½¨ÒéÄúʹÓÃÊÖ¹¤°²×°µÄ·½Ê½£¬Äã¿ÉÒÔʹÓÃwindows×Ô´øµÄupdate¹¦ÄܽøÐиüУ¬Í¬Ê±ÄãÒ²¿ÉÒÔʹÓÃÎÒÃÇÌṩµÄsus·þÎñ£¨http://sus.ccert.edu.cn)½øÐиüÐÂ.

 

²Î¿¼Á´½Ó£ºhttp://www.microsoft.com/technet/security/bulletin/ms07-016.mspx

 

¼øÓڴ˴ι«²¼Â©¶´µÄΣº¦ÐÔ£¬ÎÒÃǽ¨ÒéÓû§¾¡¿ì°²×°ÏàÓ¦µÄ²¹¶¡³ÌÐò¡£

Äú¿ÉÒÔͨ¹ýÒÔÏ·½Ê½°²×°²¹¶¡³ÌÐò£º

1¡¢Ê¹ÓÃwindows×Ô´øµÄupdate¹¦ÄÜ

2¡¢Ê¹ÓÃwsus·þÎñÆ÷Éý¼¶²¹¶¡³ÌÐò£¬CCERTµÄwsus·þÎñÆ÷µØÖ·Îªhttp://sus.ccert.edu.cn

ÎÄÕ¼È룺¶àÁ¦À¤    ÔðÈα༭£º¶àÁ¦À¤ 
  • ÉÏһƪÎÄÕ£º