大家好,我是 Richard Chen。
在此提前通知各位:微软计划于北京时间2012年2月14日清晨发布9个安全补丁,共修复 Microsoft Windows, Office, Internet Explorer 和 .NET/Silverlight 中的21个安全漏洞。补丁的最高严重等级详见下表:
Bulletin ID Maximum Severity Rating and Vulnerability Impact Restart Requirement Affected SoftwareBulletin 1 | Critical Remote Code Execution |
Requires restart | Microsoft Windows |
Bulletin 2 | Critical Remote Code Execution |
Requires restart | Microsoft Windows, Internet Explorer |
Bulletin 3 | Critical Remote Code Execution |
Requires restart | Microsoft Windows |
Bulletin 4 | Critical Remote Code Execution |
May require restart | Microsoft .NET Framework, Microsoft Silverlight |
Bulletin 5 | Important Elevation of Privilege |
Requires restart | Microsoft Windows |
Bulletin 6 | Important Elevation of Privilege |
May require restart | Microsoft Office, Microsoft Server Software |
Bulletin 7 | Important Remote Code Execution |
May require restart | Microsoft Windows |
Bulletin 8 | Important Remote Code Execution |
May require restart | Microsoft Windows |
Bulletin 9 | Important Remote Code Execution |
May require restart | Microsoft Office |
按照受影响的操作系统分类如下:
Windows XP Windows Server 2003 Windows Vista Windows Server 2008 Windows 7 Windows Server 2008 R2Bulletin Identifier | Bulletin 1 | Bulletin 2 | Bulletin 3 | Bulletin 4 | Bulletin 5 | Bulletin 7 | Bulletin 8 |
Aggregate Severity Rating | Critical | Critical | None | Critical | Important | None | Important |
Windows XP Service Pack 3 | Windows XP Service Pack 3 (Critical) |
Internet Explorer 6 (Moderate) Internet Explorer 7 (Critical) Internet Explorer 8 (Critical) |
Not applicable | Windows XP Service Pack 3 (Critical) |
Not applicable | Not applicable | Windows XP Service Pack 3 (Important) |
Windows XP Professional x64 Edition Service Pack 2 | Windows XP Professional x64 Edition Service Pack 2 (Critical) |
Internet Explorer 6 (Moderate) Internet Explorer 7 (Critical) Internet Explorer 8 (Critical) |
Not applicable | Windows XP Professional x64 Edition Service Pack 2 (Critical) |
Windows XP Professional x64 Edition Service Pack 2 (Important) |
Not applicable | Not applicable |
Bulletin Identifier | Bulletin 1 | Bulletin 2 | Bulletin 3 | Bulletin 4 | Bulletin 5 | Bulletin 7 | Bulletin 8 |
Aggregate Severity Rating | Critical | Moderate | None | Critical | Important | None | None |
Windows Server 2003 Service Pack 2 | Windows Server 2003 Service Pack 2 (Critical) |
Internet Explorer 6 (No severity rating[1]) Internet Explorer 7 (Moderate) Internet Explorer 8 (Moderate) |
Not applicable | Windows Server 2003 Service Pack 2 (Critical) |
Windows Server 2003 Service Pack 2 (Important) |
Not applicable | Not applicable |
Windows Server 2003 x64 Edition Service Pack 2 | Windows Server 2003 x64 Edition Service Pack 2 (Critical) |
Internet Explorer 6 (No severity rating[1]) Internet Explorer 7 (Moderate) Internet Explorer 8 (Moderate) |
Not applicable | Windows Server 2003 x64 Edition Service Pack 2 (Critical) |
Windows Server 2003 x64 Edition Service Pack 2 (Important) |
Not applicable | Not applicable |
Windows Server 2003 with SP2 for Itanium-based Systems | Windows Server 2003 with SP2 for Itanium-based Systems (Critical) |
Internet Explorer 6 (No severity rating[1]) Internet Explorer 7 (Moderate) |
Not applicable | Windows Server 2003 with SP2 for Itanium-based Systems (Critical) |
Windows Server 2003 with SP2 for Itanium-based Systems (Important) |
Not applicable | Not applicable |
Bulletin Identifier | Bulletin 1 | Bulletin 2 | Bulletin 3 | Bulletin 4 | Bulletin 5 | Bulletin 7 | Bulletin 8 |
Aggregate Severity Rating | Critical | Critical | Critical | Critical | Important | None | None |
Windows Vista Service Pack 2 | Windows Vista Service Pack 2 (Critical) |
Internet Explorer 7 (Critical) Internet Explorer 8 (Critical) Internet Explorer 9 (Critical) |
Windows Vista Service Pack 2 (Critical) |
Windows Vista Service Pack 2 (Critical) |
Not applicable | Not applicable | Not applicable |
Windows Vista x64 Edition Service Pack 2 | Windows Vista x64 Edition Service Pack 2 (Critical) |
Internet Explorer 7 (Critical) Internet Explorer 8 (Critical) Internet Explorer 9 (Critical) |
Windows Vista x64 Edition Service Pack 2 (Critical) |
Windows Vista x64 Edition Service Pack 2 (Critical) |
Windows Vista x64 Edition Service Pack 2 (Important) |
Not applicable | Not applicable |
Bulletin Identifier | Bulletin 1 | Bulletin 2 | Bulletin 3 | Bulletin 4 | Bulletin 5 | Bulletin 7 | Bulletin 8 |
Aggregate Severity Rating | Critical | Moderate | Critical | Critical | Important | Important | None |
Windows Server 2008 for 32-bit Systems Service Pack 2 | Windows Server 2008 for 32-bit Systems Service Pack 2**** (Critical) |
Internet Explorer 7** (Moderate) Internet Explorer 8** (Moderate) Internet Explorer 9** (Moderate) |
Windows Server 2008 for 32-bit Systems Service Pack 2* (Critical) |
Windows Server 2008 for 32-bit Systems Service Pack 2 (Critical) |
Not applicable | Windows Server 2008 for 32-bit Systems Service Pack 2** (Important) |
Not applicable |
Windows Server 2008 for x64-based Systems Service Pack 2 | Windows Server 2008 for x64-based Systems Service Pack 2**** (Critical) |
Internet Explorer 7** (Moderate) Internet Explorer 8** (Moderate) Internet Explorer 9** (Moderate) |
Windows Server 2008 for x64-based Systems Service Pack 2* (Critical) |
Windows Server 2008 for x64-based Systems Service Pack 2 (Critical) |
Windows Server 2008 for x64-based Systems Service Pack 2* (Important) |
Windows Server 2008 for x64-based Systems Service Pack 2** (Important) |
Not applicable |
Windows Server 2008 for Itanium-based Systems Service Pack 2 | Windows Server 2008 for Itanium-based Systems Service Pack 2 (Critical) |
Internet Explorer 7 (Moderate) |
Windows Server 2008 for Itanium-based Systems Service Pack 2 (Critical) |
Windows Server 2008 for Itanium-based Systems Service Pack 2 (Critical) |
Windows Server 2008 for Itanium-based Systems Service Pack 2 (Important) |
Windows Server 2008 for Itanium-based Systems Service Pack 2 (Important) |
Not applicable |
Bulletin Identifier | Bulletin 1 | Bulletin 2 | Bulletin 3 | Bulletin 4 | Bulletin 5 | Bulletin 7 | Bulletin 8 |
Aggregate Severity Rating | Critical | Critical | Critical | Critical | Important | None | None |
Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1 | Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1 (Critical) |
Internet Explorer 8 (Critical) Internet Explorer 9 (Critical) |
Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1 (Critical) |
Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1 (Critical) |
Not applicable | Not applicable | Not applicable |
Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1 | Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1 (Critical) |
Internet Explorer 8 (Critical) Internet Explorer 9 (Critical) |
Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1 (Critical) |
Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1 (Critical) |
Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1 (Important) |
Not applicable | Not applicable |
Bulletin Identifier | Bulletin 1 | Bulletin 2 | Bulletin 3 | Bulletin 4 | Bulletin 5 | Bulletin 7 | Bulletin 8 |
Aggregate Severity Rating | Critical | Moderate | Critical | Critical | Important | Important | None |
Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1**** (Critical) |
Internet Explorer 8** (Moderate) Internet Explorer 9** (Moderate) |
Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1* (Critical) |
Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1* (Critical) |
Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1* (Important) |
Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1** (Important) |
Not applicable |
Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 | Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 (Critical) |
Internet Explorer 8 (Moderate) |
Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 (Critical) |
Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 (Critical) |
Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 (Important) |
Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 (Important) |
Not applicable |
Windows Server 2008和 Windows Server 2008 R2注意事项:
*Server Core 安装受影响
**Server Core 安装不受影响
****Server Core 安装受影响,严重等级较低
Bulletin 2 的注释:
[1]由于软件默认设置屏蔽此类漏洞攻击,综合严重等级不适用于该补丁涉及的具体软件。
Bulletin 4 的注释 : 本补丁影响多类软件。
微软 Office 补丁相关信息:
Microsoft Office Software
Bulletin Identifier | Bulletin 9 |
Aggregate Severity Rating | Important |
Microsoft Visio Viewer 2010 and Microsoft Visio Viewer 2010 Service Pack 1 (32-bit Edition) | Microsoft Visio Viewer 2010 and Microsoft Visio Viewer 2010 Service Pack 1 (32-bit Edition) (Important) |
Microsoft Visio Viewer 2010 and Microsoft Visio Viewer 2010 Service Pack 1 (64-bit Edition) | Microsoft Visio Viewer 2010 and Microsoft Visio Viewer 2010 Service Pack 1 (64-bit Edition) (Important) |
微软服务器软件补丁相关信息:
Bulletin Identifier | Bulletin 6 |
Aggregate Severity Rating | Important |
Microsoft SharePoint Server 2010 and Microsoft SharePoint Server 2010 Service Pack 1 | Microsoft SharePoint Server 2010 and Microsoft SharePoint Server 2010 Service Pack 1 (Important) |
Bulletin Identifier | Bulletin 6 |
Aggregate Severity Rating | Important |
Microsoft SharePoint Foundation 2010 and Microsoft SharePoint Foundation 2010 Service Pack 1 | Microsoft SharePoint Foundation 2010 and Microsoft SharePoint Foundation 2010 Service Pack 1 (Important) |
微软开发者工具与软件补丁相关信息:
Bulletin Identifier | Bulletin 4 |
Aggregate Severity Rating | Critical |
Microsoft Silverlight 4 | Microsoft Silverlight 4 (Critical) |
Bulletin 4 的注释 : 本补丁影响多类软件。
以下为提前通知的文章全文(英文),请各位先行评估了解受影响的系统。
Microsoft Security Bulletin Advance Notification for February 2012:
http://technet.microsoft.com/en-us/security/bulletin/ms12-feb
谢谢!
Richard Chen
大中华区软件安全项目经理