五月婷婷丁香性爱|j久久一级免费片|久久美女福利视频|中文观看在线观看|加勒比四区三区二|亚洲裸女视频网站|超碰97AV在线69网站免费观看|有码在线免费视频|久久青青日本视频|亚洲国产AAAA

服務(wù)公告

全部公告 > 安全公告 > 微軟Type 1字體解析遠(yuǎn)程代碼執(zhí)行漏洞預(yù)警

微軟Type 1字體解析遠(yuǎn)程代碼執(zhí)行漏洞預(yù)警

2020-03-24

一、概要

近日,華為云關(guān)注到微軟官方緊急發(fā)布編號(hào)為ADV200006的安全通告,當(dāng)中披露由于Windows Adobe Type Manager Library不恰當(dāng)?shù)奶幚硖厥鈽?gòu)造的多重母版字體 - Adobe Type1 PostScript格式,導(dǎo)致存在兩個(gè)遠(yuǎn)程代碼0day漏洞。漏洞影響多個(gè)windows操作系統(tǒng)版本,目前已發(fā)現(xiàn)有在野攻擊利用,官方暫僅提供緩解措施來(lái)降低安全風(fēng)險(xiǎn),補(bǔ)丁程序?qū)⒃谙聜€(gè)月的補(bǔ)丁日發(fā)布。

華為云提醒使用windows用戶及時(shí)安排自檢并做好安全加固。

參考鏈接:

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/adv200006

二、威脅級(jí)別

威脅級(jí)別:【嚴(yán)重】

(說(shuō)明:威脅級(jí)別共四級(jí):一般、重要、嚴(yán)重、緊急) 

三、漏洞影響范圍

影響版本:

Windows 10 for 32-bit Systems

Windows 10 for x64-based Systems Windows 10 Version 1607 for 32-bit Systems

Windows 10 Version 1607 for x64-based Systems

Windows 10 Version 1709 for 32-bit Systems

Windows 10 Version 1709 for ARM64-based Systems

Windows 10 Version 1709 for x64-based Systems

Windows 10 Version 1803 for 32-bit Systems

Windows 10 Version 1803 for ARM64-based Systems

Windows 10 Version 1803 for x64-based Systems

Windows 10 Version 1809 for 32-bit Systems

Windows 10 Version 1809 for ARM64-based Systems

Windows 10 Version 1809 for x64-based Systems

Windows 10 Version 1903 for 32-bit Systems

Windows 10 Version 1903 for ARM64-based Systems

Windows 10 Version 1903 for x64-based Systems

Windows 10 Version 1909 for 32-bit Systems

Windows 10 Version 1909 for ARM64-based Systems

Windows 10 Version 1909 for x64-based Systems

Windows 7 for 32-bit Systems Service Pack 1

Windows 7 for x64-based Systems Service Pack 1

Windows 8.1 for 32-bit systems

Windows 8.1 for x64-based systems

Windows RT 8.1

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for Itanium-Based Systems Service Pack 2

Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Windows Server 2012

Windows Server 2012 (Server Core installation)

Windows Server 2012 R2

Windows Server 2012 R2 (Server Core installation)

Windows Server 2016

Windows Server 2016 (Server Core installation)

Windows Server 2019

Windows Server 2019 (Server Core installation)

Windows Server, version 1803 (Server Core Installation)

Windows Server, version 1903 (Server Core installation)

Windows Server, version 1909 (Server Core installation) 

四、漏洞處置

目前,官方已在通告內(nèi)容中提供了多種緩解措施,請(qǐng)受影響的用戶參考官方指導(dǎo)進(jìn)行操作,主要有以下幾種方式:

措施1、在Windows資源管理器中禁用預(yù)覽窗格和詳細(xì)信息窗格;

措施2、禁用WebClient服務(wù);

措施3、重命名ATMFD.DLL。

注:修復(fù)漏洞前請(qǐng)將資料備份,并進(jìn)行充分測(cè)試。