大家好,我是 Richard Chen。
在此提前通知各位:微软计划于北京时间8月15日清晨发布9个安全补丁,共修复 Microsoft Windows, Internet Explorer, Exchange, SQL Server, Server Software 和 Developer Tools 中的10个安全漏洞。9个补丁的最高严重等级详见下图:
Bulletin ID | Maximum Severity Rating and Vulnerability Impact | Restart Requirement | Affected Software |
---|---|---|---|
Bulletin 1 | Critical Remote Code Execution | Requires restart | Microsoft Windows, Internet Explorer |
Bulletin 2 | Critical Remote Code Execution | Requires restart | Microsoft Windows |
Bulletin 3 | Critical Remote Code Execution | Requires restart | Microsoft Windows |
Bulletin 4 | Critical Remote Code Execution | May require restart | Microsoft Office, Microsoft SQL Server, Microsoft Server Software, Microsoft Developer Tools |
Bulletin 5 | Critical Remote Code Execution | Does not require restart | Microsoft Exchange |
Bulletin 6 | Important Elevation of Privilege | Requires restart | Microsoft Windows |
Bulletin 7 | Important Remote Code Execution | May require restart | Microsoft Windows |
Bulletin 8 | Important Remote Code Execution | May require restart | Microsoft Office |
Bulletin 9 | Important Remote Code Execution | May require restart | Microsoft Office |
按照受影响的操作系统分类如下:
Windows XP | |||||
---|---|---|---|---|---|
Bulletin Identifier | Bulletin 1 | Bulletin 2 | Bulletin 3 | Bulletin 6 | Bulletin 7 |
Aggregate Severity Rating | Critical | Critical | Critical | Important | Important |
Windows XP Service Pack 3 | Internet Explorer 6 (Critical) Internet Explorer 7 (Critical) Internet Explorer 8 (Critical) | Windows XP Service Pack 3 (Critical) | Windows XP Service Pack 3 (Critical) | Windows XP Service Pack 3 (Important) | Not applicable |
Windows XP Professional x64 Edition Service Pack 2 | Internet Explorer 6 (Critical) Internet Explorer 7 (Critical) Internet Explorer 8 (Critical) | Not applicable | Windows XP Professional x64 Edition Service Pack 2 (Critical) | Windows XP Professional x64 Edition Service Pack 2 (Important) | Windows XP Professional x64 Edition Service Pack 2 (Important) |
Windows Server 2003 | |||||
Bulletin Identifier | Bulletin 1 | Bulletin 2 | Bulletin 3 | Bulletin 6 | Bulletin 7 |
Aggregate Severity Rating | Moderate | None | Critical | Important | Low |
Windows Server 2003 Service Pack 2 | Internet Explorer 6 (Moderate) Internet Explorer 7 (Moderate) Internet Explorer 8 (Moderate) | Not applicable | Windows Server 2003 Service Pack 2 (Critical) | Windows Server 2003 Service Pack 2 (Important) | Not applicable |
Windows Server 2003 x64 Edition Service Pack 2 | Internet Explorer 6 (Moderate) Internet Explorer 7 (Moderate) Internet Explorer 8 (Moderate) | Not applicable | Windows Server 2003 x64 Edition Service Pack 2 (Critical) | Windows Server 2003 x64 Edition Service Pack 2 (Important) | Windows Server 2003 x64 Edition Service Pack 2 (Low) |
Windows Server 2003 with SP2 for Itanium-based Systems | Internet Explorer 6 (Moderate) Internet Explorer 7 (Moderate) | Not applicable | Windows Server 2003 with SP2 for Itanium-based Systems (Critical) | Windows Server 2003 with SP2 for Itanium-based Systems (Important) | Not applicable |
Windows Vista | |||||
Bulletin Identifier | Bulletin 1 | Bulletin 2 | Bulletin 3 | Bulletin 6 | Bulletin 7 |
Aggregate Severity Rating | Critical | None | Important | Important | Important |
Windows Vista Service Pack 2 | Internet Explorer 7 (Critical) Internet Explorer 8 (Critical) Internet Explorer 9 (Critical) | Not applicable | Windows Vista Service Pack 2 (Important) | Windows Vista Service Pack 2 (Important) | Not applicable |
Windows Vista x64 Edition Service Pack 2 | Internet Explorer 7 (Critical) Internet Explorer 8 (Critical) Internet Explorer 9 (Critical) | Not applicable | Windows Vista x64 Edition Service Pack 2 (Important) | Windows Vista x64 Edition Service Pack 2 (Important) | Windows Vista x64 Edition Service Pack 2 (Important) |
Windows Server 2008 | |||||
Bulletin Identifier | Bulletin 1 | Bulletin 2 | Bulletin 3 | Bulletin 6 | Bulletin 7 |
Aggregate Severity Rating | Moderate | None | Moderate | Important | Low |
Windows Server 2008 for 32-bit Systems Service Pack 2 | Internet Explorer 7 (Moderate) Internet Explorer 8 (Moderate) Internet Explorer 9 (Moderate) | Not applicable | Windows Server 2008 for 32-bit Systems Service Pack 2 (Moderate) | Windows Server 2008 for 32-bit Systems Service Pack 2 (Important) | Not applicable |
Windows Server 2008 for x64-based Systems Service Pack 2 | Internet Explorer 7 (Moderate) Internet Explorer 8 (Moderate) Internet Explorer 9 (Moderate) | Not applicable | Windows Server 2008 for x64-based Systems Service Pack 2 (Moderate) | Windows Server 2008 for x64-based Systems Service Pack 2 (Important) | Windows Server 2008 for x64-based Systems Service Pack 2 (Low) |
Windows Server 2008 for Itanium-based Systems Service Pack 2 | Internet Explorer 7 (Moderate) | Not applicable | Windows Server 2008 for Itanium-based Systems Service Pack 2 (Moderate) | Windows Server 2008 for Itanium-based Systems Service Pack 2 (Important) | Not applicable |
Windows 7 | |||||
Bulletin Identifier | Bulletin 1 | Bulletin 2 | Bulletin 3 | Bulletin 6 | Bulletin 7 |
Aggregate Severity Rating | Critical | None | Moderate | Important | Important |
Windows 7 for 32-bit Systems | Internet Explorer 8 (Critical) Internet Explorer 9 (Critical) | Not applicable | Windows 7 for 32-bit Systems (Moderate) | Windows 7 for 32-bit Systems (Important) | Not applicable |
Windows 7 for 32-bit Systems Service Pack 1 | Internet Explorer 8 (Critical) Internet Explorer 9 (Critical) | Not applicable | Windows 7 for 32-bit Systems Service Pack 1 (Moderate) | Windows 7 for 32-bit Systems Service Pack 1 (Important) | Not applicable |
Windows 7 for x64-based Systems | Internet Explorer 8 (Critical) Internet Explorer 9 (Critical) | Not applicable | Windows 7 for x64-based Systems (Moderate) | Windows 7 for x64-based Systems (Important) | Windows 7 for x64-based Systems (Important) |
Windows 7 for x64-based Systems Service Pack 1 | Internet Explorer 8 (Critical) Internet Explorer 9 (Critical) | Not applicable | Windows 7 for x64-based Systems Service Pack 1 (Moderate) | Windows 7 for x64-based Systems Service Pack 1 (Important) | Windows 7 for x64-based Systems Service Pack 1 (Important) |
Windows Server 2008 R2 | |||||
Bulletin Identifier | Bulletin 1 | Bulletin 2 | Bulletin 3 | Bulletin 6 | Bulletin 7 |
Aggregate Severity Rating | Moderate | None | Moderate | Important | Low |
Windows Server 2008 R2 for x64-based Systems | Internet Explorer 8 (Moderate) Internet Explorer 9 (Moderate) | Not applicable | Windows Server 2008 R2 for x64-based Systems (Moderate) | Windows Server 2008 R2 for x64-based Systems (Important) | Windows Server 2008 R2 for x64-based Systems (Low) |
Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Internet Explorer 8 (Moderate) Internet Explorer 9 (Moderate) | Not applicable | Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Moderate) | Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Important) | Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Low) |
Windows Server 2008 R2 for Itanium-based Systems | Internet Explorer 8 (Moderate) | Not applicable | Windows Server 2008 R2 for Itanium-based Systems (Moderate) | Windows Server 2008 R2 for Itanium-based Systems (Important) | Windows Server 2008 R2 for Itanium-based Systems (Low) |
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 | Internet Explorer 8 (Moderate) | Not applicable | Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 (Moderate) | Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 (Important) | Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 (Low) |
Server Core installation option | |||||
Bulletin Identifier | Bulletin 1 | Bulletin 2 | Bulletin 3 | Bulletin 6 | Bulletin 7 |
Aggregate Severity Rating | None | None | Moderate | Important | None |
Windows Server 2008 for 32-bit Systems Service Pack 2 | Not applicable | Not applicable | Windows Server 2008 for 32-bit Systems Service Pack 2 (Moderate) | Windows Server 2008 for 32-bit Systems Service Pack 2 (Important) | Not applicable |
Windows Server 2008 for x64-based Systems Service Pack 2 | Not applicable | Not applicable | Windows Server 2008 for x64-based Systems Service Pack 2 (Moderate) | Windows Server 2008 for x64-based Systems Service Pack 2 (Important) | Not applicable |
Windows Server 2008 R2 for x64-based Systems | Not applicable | Not applicable | Windows Server 2008 R2 for x64-based Systems (Moderate) | Windows Server 2008 R2 for x64-based Systems (Important) | Not applicable |
Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Not applicable | Not applicable | Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Moderate) | Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Important) | Not applicable |
微软 Office 补丁相关信息:
Microsoft Office Suites and Software | |||
---|---|---|---|
Bulletin Identifier | Bulletin 4 | Bulletin 8 | Bulletin 9 |
Aggregate Severity Rating | Critical | Important | Important |
Microsoft Office 2003 Service Pack 3 | Microsoft Office 2003 Service Pack 3 (Critical) | Not applicable | Not applicable |
Microsoft Office 2007 Service Pack 2 | Microsoft Office 2007 Service Pack 2 (Critical) | Microsoft Office 2007 Service Pack 2 (Important) | Not applicable |
Microsoft Office 2007 Service Pack 3 | Microsoft Office 2007 Service Pack 3 (Critical) | Microsoft Office 2007 Service Pack 3 (Important) | Not applicable |
Microsoft Office 2010 Service Pack 1 (32-bit editions) | Microsoft Office 2010 Service Pack 1 (32-bit editions) (Critical) | Microsoft Office 2010 Service Pack 1 (32-bit editions) (Important) | Microsoft Visio 2010 Service Pack 1 (32-bit editions) (Important) |
Microsoft Office 2010 Service Pack 1 (64-bit editions) | Not applicable | Microsoft Office 2010 Service Pack 1 (64-bit editions) (Important) | Microsoft Visio 2010 Service Pack 1 (64-bit editions) (Important) |
Microsoft Office Web Components | |||
Bulletin Identifier | Bulletin 4 | Bulletin 8 | Bulletin 9 |
Aggregate Severity Rating | Critical | None | None |
Microsoft Office 2003 Web Components Service Pack 3 | Microsoft Office 2003 Web Components Service Pack 3 (Critical) | Not applicable | Not applicable |
Other Microsoft Office Software | |||
Bulletin Identifier | Bulletin 4 | Bulletin 8 | Bulletin 9 |
Aggregate Severity Rating | None | None | Important |
Microsoft Visio Viewer 2010 Service Pack 1 (32-bit Edition) | Not applicable | Not applicable | Microsoft Visio Viewer 2010 Service Pack 1 (32-bit Edition) (Important) |
Microsoft Visio Viewer 2010 Service Pack 1 (64-bit Edition) | Not applicable | Not applicable | Microsoft Visio Viewer 2010 Service Pack 1 (64-bit Edition) (Important) |
Bulletin 4 的注释 : 本补丁影响多类软件。
微软服务器软件补丁相关信息:
Microsoft SQL Server | |||
---|---|---|---|
Bulletin Identifier | Bulletin 4 | Bulletin 5 | |
Aggregate Severity Rating | Critical | None | |
Microsoft SQL Server 2000 Service Pack 4 | Microsoft SQL Server 2000 Service Pack 4 (Critical) | Not applicable | |
Microsoft SQL Server 2000 Analysis Services Service Pack 4 | Microsoft SQL Server 2000 Analysis Services Service Pack 4 (Critical) | Not applicable | |
Microsoft SQL Server 2005 Express Edition with Advanced Services Service Pack 4 | Microsoft SQL Server 2005 Express Edition with Advanced Services Service Pack 4 (Critical) | Not applicable | |
Microsoft SQL Server 2005 for 32-bit Systems Service Pack 4 | Microsoft SQL Server 2005 for 32-bit Systems Service Pack 4 (Critical) | Not applicable | |
Microsoft SQL Server 2005 for Itanium-based Systems Service Pack 4 | Microsoft SQL Server 2005 for Itanium-based Systems Service Pack 4 (Critical) | Not applicable | |
Microsoft SQL Server 2005 for x64-based Systems Service Pack 4 | Microsoft SQL Server 2005 for x64-based Systems Service Pack 4 (Critical) | Not applicable | |
Microsoft SQL Server 2008 for 32-bit Systems Service Pack 2 | Microsoft SQL Server 2008 for 32-bit Systems Service Pack 2 (Critical) | Not applicable | |
Microsoft SQL Server 2008 for 32-bit Systems Service Pack 3 | Microsoft SQL Server 2008 for 32-bit Systems Service Pack 3 (Critical) | Not applicable | |
Microsoft SQL Server 2008 for x64-based Systems Service Pack 2 | Microsoft SQL Server 2008 for x64-based Systems Service Pack 2 (Critical) | Not applicable | |
Microsoft SQL Server 2008 for x64-based Systems Service Pack 3 | Microsoft SQL Server 2008 for x64-based Systems Service Pack 3 (Critical) | Not applicable | |
Microsoft SQL Server 2008 for Itanium-based Systems Service Pack 2 | Microsoft SQL Server 2008 for Itanium-based Systems Service Pack 2 (Critical) | Not applicable | |
Microsoft SQL Server 2008 for Itanium-based Systems Service Pack 3 | Microsoft SQL Server 2008 for Itanium-based Systems Service Pack 3 (Critical) | Not applicable | |
Microsoft SQL Server 2008 R2 for 32-bit Systems | Microsoft SQL Server 2008 R2 for 32-bit Systems (Critical) | Not applicable | |
Microsoft SQL Server 2008 R2 for 32-bit Systems Service Pack 1 | Microsoft SQL Server 2008 R2 for 32-bit Systems Service Pack 1 (Critical) | Not applicable | |
Microsoft SQL Server 2008 R2 for 32-bit Systems Service Pack 2 | Microsoft SQL Server 2008 R2 for 32-bit Systems Service Pack 2 (Critical) | Not applicable | |
Microsoft SQL Server 2008 R2 for x64-based Systems | Microsoft SQL Server 2008 R2 for x64-based Systems (Critical) | Not applicable | |
Microsoft SQL Server 2008 R2 for x64-based Systems Service Pack 1 | Microsoft SQL Server 2008 R2 for x64-based Systems Service Pack 1 (Critical) | Not applicable | |
Microsoft SQL Server 2008 R2 for x64-based Systems Service Pack 2 | Microsoft SQL Server 2008 R2 for x64-based Systems Service Pack 2 (Critical) | Not applicable | |
Microsoft SQL Server 2008 R2 for Itanium-based Systems | Microsoft SQL Server 2008 R2 for Itanium-based Systems (Critical) | Not applicable | |
Microsoft SQL Server 2008 R2 for Itanium-based Systems Service Pack 1 | Microsoft SQL Server 2008 R2 for Itanium-based Systems Service Pack 1 (Critical) | Not applicable | |
Microsoft SQL Server 2008 R2 for Itanium-based Systems Service Pack 2 | Microsoft SQL Server 2008 R2 for Itanium-based Systems Service Pack 2 (Critical) | Not applicable | |
Microsoft Commerce Server | |||
Bulletin Identifier | Bulletin 4 | Bulletin 5 | |
Aggregate Severity Rating | Critical | None | |
Microsoft Commerce Server 2002 Service Pack 4 | Microsoft Commerce Server 2002 Service Pack 4 (Critical) | Not applicable | |
Microsoft Commerce Server 2007 Service Pack 2 | Microsoft Commerce Server 2007 Service Pack 2 (Critical) | Not applicable | |
Microsoft Commerce Server 2009 | Microsoft Commerce Server 2009 (Critical) | Not applicable | |
Microsoft Commerce Server 2009 R2 | Microsoft Commerce Server 2009 R2 (Critical) | Not applicable | |
Microsoft Host Integration Server | |||
Bulletin Identifier | Bulletin 4 | Bulletin 5 | |
Aggregate Severity Rating | Critical | None | |
Microsoft Host Integration Server 2004 Service Pack 1 | Microsoft Host Integration Server 2004 Service Pack 1 (Critical) | Not applicable | |
Microsoft Exchange Server | |||
Bulletin Identifier | Bulletin 4 | Bulletin 5 | |
Aggregate Severity Rating | None | Critical | |
Microsoft Exchange Server 2007 Service Pack 3 | Not applicable | Microsoft Exchange Server 2007 Service Pack 3 (Critical) | |
Microsoft Exchange Server 2010 Service Pack 1 | Not applicable | Microsoft Exchange Server 2010 Service Pack 1 (Critical) | |
Microsoft Exchange Server 2010 Service Pack 2 | Not applicable | Microsoft Exchange Server 2010 Service Pack 2 (Critical) |
Bulletin 4 的注释 : 本补丁影响多类软件。
微软开发者工具与软件补丁相关信息:
Microsoft Visual FoxPro | |
---|---|
Bulletin Identifier | Bulletin 4 |
Aggregate Severity Rating | Critical |
Microsoft Visual FoxPro 8.0 Service Pack 1 | Microsoft Visual FoxPro 8.0 Service Pack 1 (Critical) |
Microsoft Visual FoxPro 9.0 Service Pack 2 | Microsoft Visual FoxPro 9.0 Service Pack 2 (Critical) |
Visual Basic | |
Bulletin Identifier | Bulletin 4 |
Aggregate Severity Rating | Critical |
Visual Basic 6.0 Runtime | Visual Basic 6.0 Runtime (Critical) |
Bulletin 4 的注释 : 本补丁影响多类软件。
以下为提前通知的文章全文(英文),请各位先行评估了解受影响的系统。
Microsoft Security Bulletin Advance Notification for Aug 2012:
http://technet.microsoft.com/en-us/security/bulletin/ms12-aug
谢谢!
Richard Chen
大中华区软件安全项目经理