Microsoft випустила оновлення безпеки за лютий 2019 року
Microsoft випустила оновлення безпеки за лютий 2019
Microsoft випустила оновлення безпеки для таких продуктів: Windows, Windows Server, Microsoft Edge, Internet Explorer, Office, SharePoint, Exchange Server, Visual Studio, Team Foundation Server, .NET Framework, .NET Core, ChakraCore та Java SDK for Azure IoT.
| Product Family | Maximum Severity | Maximum Impact | Associated KB Articles and/or Support Webpages |
| Windows 10 v1809, v1803, v1709, v1703, v1607, Windows 10 для 32-бітних систем, і Windows 10 для x64-базованих систем (не включає Edge) | Critical | Remote Code Execution | Windows 10 v1809 Security Update: 4487044;
Windows 10 v1803 Security Update: 4487017; Windows 10 v1709 Security Update: 4486996; Windows 10 v1703 Security Update: 4487020; Windows 10 v1607 Security Update: 4487026; Windows 10 Security Update: 4487018; |
| Windows Server 2019, Windows Server 2016, and Server Core installations (2019, 2016, v1803, and v1709) | Critical | Remote Code Execution | Windows Server 2019 Security Update: 4487044;
Windows Server 2016 Security Update: 4487026; Windows Server, version 1803 Security Update: 4487017; Windows Server, version 1709 Security Update: 4486996; |
| Windows 8.1, Windows Server 2012 R2, Windows Server 2012, Windows 7, Windows Server 2008 R2 та Windows Server 2008 | Critical | Remote Code Execution | Windows 8.1 та Windows Server 2012 R2 та Windows RT 8.1 Monthly Rollup: 4487000; Windows 8.1 та Windows Server 2012 R2 Security Only: 4487028;
Windows Server 2012 Security Only: 4486993; Windows Server 2012 Monthly Rollup: 4487025; Windows 7 та Windows Server 2008 R2 Monthly Rollup: 4486563; Windows 7 та Windows Server 2008 R2 Security Only: 4486564; Windows Server 2008 Security Only: 4487019; Windows Server 2008 Monthly Rollup: 4487023; |
| Microsoft Edge | Critical | Remote Code Execution | Microsoft Edge on Windows 10 v1809 and Microsoft Edge на Windows Server 2019 Security Update: 4487044;
Microsoft Edge on Windows 10 v1803 Security Update: 4487017; Microsoft Edge on Windows 10 v1709 Security Update: 4486996; Microsoft Edge on Windows 10 v1703 Security Update: 4487020; Microsoft Edge на Windows Server 2016 та Microsoft Edge на Windows 10 v1607 Security Update: 4487026; Microsoft Edge on Windows 10 Security Update: 4487018; |
| Internet Explorer | Critical | Remote Code Execution | Internet Explorer 11 на Windows 10 v1809 та Internet Explorer 11 на Windows Server 2019 Security Update: 4487044;
Internet Explorer 11 on Windows 10 v1803 Security Update: 4487017; Internet Explorer 11 on Windows 10 v1709 Security Update: 4486996; Internet Explorer 11 на Windows 10 v1703 Security Update: 4487020; Internet Explorer 11 на Windows Server 2016 та Internet Explorer 11 на Windows 10 v1607 Зображення Update: 4487026; Internet Explorer 11 на Windows 10 Security Update: 4487018; Internet Explorer 11 on Windows 7 and Internet Explorer 11 on Windows Server 2008 R2 and Internet Explorer 11 on Windows 8.1 and Internet Explorer 11 on Windows Server 2012 R2 and Internet Explorer 10 on Windows Server 2012 IE Cumulative: 4486474; >Internet Explorer 10 on Windows Server 2012 Monthly Rollup: 4487025; Internet Explorer 11 на Windows 7 та Internet Explorer 11 на Windows Server 2008 R2 Monthly Rollup: 4486563; |
| Microsoft Office-related software | Important | Remote Code Execution | Через число KB статей, пов'язаних з Microsoft Office-related software для кожного місяця надійного оновлення варіації, в залежності від числа CVEs і числа помітних компонентів. Цей місяць є більше ніж 20 KB Articles related to Microsoft Office-related software updates – це багато для цього, щоб отримати всі суми. Review the content in the Security Update Guide for article details. |
| Microsoft SharePoint-related software | Critical | Remote Code Execution | Microsoft SharePoint Server 2019 : 4462171 Microsoft SharePoint Enterprise Server 2016 : 4462155 Microsoft SharePoint Enterprise Server 2013 : 4462139 Microsoft SharePoint Foundation : 4462143 Microsoft SharePoint Server 2010 : 4461630 |
| .NET Framework | Important | Remote Code Execution | Кількість KB елементів, що володіють .NET Framework для кожного місяця безпеки, оновлення варіації, що лежать в номері CVEs і в ряді компонентів. Цей місяць буде більше 20 KB Articles related to. Review the content in the Security Update Guide for article details. |
| Visual Studio | Important | Remote Code Execution | https://code.visualstudio.com/Download |
| Microsoft Exchange Server | Important | Elevation of Privilege | Microsoft Exchange Server 2019: 4471391
Microsoft Exchange Server 2016: 4471392 |
| Adobe Flash Player | Critical | Remote Code Execution | Adobe Flash Security Update: 4487038 Adobe Flash Player Advisory: ADV190003 |
| Team Foundation Server | Important | Spoofing | https://aka.ms/tfs2018.3.2patch |
| Java SDK for Azure IoT | Important | Elevation of Privilege | https://github.com/Azure/azure-iot-sdk-java/releases |
| ChakraCore | Critical | Remote Code Execution | ChakraCore is core part of Chakra, high-performance JavaScript engine that powers Microsoft Edge and Windows applications written in HTML/CSS/JS. More information is available at https://github.com/Microsoft/ChakraCore/wiki. |
На наступні вразливості та оновлення безпеки слід звернути особливу увагу:
Windows/Windows Server
CVE-2019-0626 – Windows DHCP Client Remote Code Execution Vulnerability
CVE-2019-0625 – Jet Database Engine Remote Code Execution Vulnerability
CVE-2019-0662 – GDI+ Remote Code Execution Vulnerability
CVE-2019-0630 – Windows SMB Remote Code Execution Vulnerability
CVE-2019-0636 – Windows Information Disclosure Vulnerability
Microsoft Edge/Internet Explorer
CVE-2019-0606 – Internet Explorer Memory Corruption Vulnerability
CVE-2019-0607 – Scripting Engine Memory Corruption Vulnerability
Microsoft Office
CVE-2019-0671 – Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
CVE-2019-0594 – Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft Exchange
ADV190007 – Guidance for “PrivExchange” Elevation of Privilege Vulnerability
CVE-2019-0686 – Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2019-0724 – Microsoft Exchange Server Elevation of Privilege Vulnerability
KB4490059 – Reducing permissions required to run Exchange Server використовує Shared Permissions Model
Рекомендації з безпеки
У січні було випущено такі рекомендаційні документи:
ADV190003 – February 2019 Adobe Flash Security Update
ADV190004 – February 2019 Oracle Outside In Library Security Update
ADV190006 – Guidance to mitigate unconstrained delegation vulnerabilities
ADV190007 – Guidance for “PrivExchange” Elevation of Privilege Vulnerability
Були доповнені та оновлені такі рекомендаційні документи:
ADV990001 – Latest Servicing Stack Updates
