【漏洞详情】 严重漏洞(9个):
CVE-2018-8583 - Chakra scripting engine memory corruption vulnerability
CVE-2018-8617 - Chakra scripting engine memory corruption vulnerability
CVE-2018-8618 - Chakra scripting engine memory corruption vulnerability
CVE-2018-8624 - Chakra scripting engine memory corruption vulnerability
CVE-2018-8629 - Chakra scripting engine memory corruption vulnerability
CVE-2018-8540 - Microsoft .NET framework remote code injection vulnerability
CVE-2018-8626 - Windows DNS servers remote code execution vulnerability
CVE-2018-8631 - Internet Explorer remote code execution vulnerability
CVE-2018-8634 - Microsoft Edge memory corruption vulnerability
重要漏洞(29个):
CVE-2018-8597 - Microsoft Excel remote code execution vulnerability
CVE-2018-8636 - Microsoft Excel remote code execution vulnerability
CVE-2018-8587 - Microsoft Outlook remote code execution vulnerability
CVE-2018-8590 - Microsoft Word remote code execution vulnerability
CVE-2018-8619 - Internet Explorer VBScript remote code execution vulnerability
CVE-2018-8625 - VBScript engine remote code execution vulnerability
CVE-2018-8628 - Microsoft PowerPoint remote code execution vulnerability
CVE-2018-8643 - Internet Explorer remote code execution vulnerability
CVE-2018-8477 - Windows kernel information disclosure vulnerability
CVE-2018-8514 - Remote Procedure Call information disclosure vulnerability
CVE-2018-8517 - .NET Framework denial of service vulnerability
CVE-2018-8580 - Microsoft SharePoint Server information disclosure vulnerability
CVE-2018-8595 - Windows GDI information disclosure vulnerability
CVE-2018-8596 - Windows GDI information disclosure vulnerability
CVE-2018-8598 - Microsoft Excel information disclosure vulnerability
CVE-2018-8599 - Diagnostics Hub Standard Collector Service elevation of privilege vulnerability
CVE-2018-8604 - Microsoft Exchange Server tampering vulnerability
CVE-2018-8611 - Windows kernel elevation of privilege vulnerability
CVE-2018-8612 - User Experiences and Telemetry Service Denial Of Service vulnerability
CVE-2018-8621 - Windows kernel information disclosure vulnerability
CVE-2018-8622 - Windows kernel information disclosure vulnerability
CVE-2018-8627 - Microsoft Excel information disclosure vulnerability
CVE-2018-8635 - Microsoft SharePoint Server elevation of privilege vulnerability
CVE-2018-8637 - Windows kernel information disclosure vulnerability
CVE-2018-8638 - DirectX information disclosure vulnerability
CVE-2018-8639 - Win32k elevation of privilege vulnerability
CVE-2018-8614 - 暂未披露详细信息
CVE-2018-8616 - 暂未披露详细信息
CVE-2018-8630 - 暂未披露详细信息
【风险等级】 高风险
【漏洞风险】
代码执行、权限提升、安全绕过以及信息泄露;
【影响版本】
目前已知受影响产品如下:
Microsoft Edge
Internet Explorer
Chakra Scripting Engine
Windows DNSAPI
Microsoft Office
Windows Kernel