MS16-146:Microsoft图形组件的安全更新:2016 年 12 月 13 日

应用对象
Windows Server 2016 Windows Server 2016 Essentials Windows Server 2016 Standard Windows 10 Windows 10, version 1511, all editions Windows 10, version 1607, all editions Windows Server 2012 R2 Datacenter Windows Server 2012 R2 Standard Windows Server 2012 R2 Essentials Windows Server 2012 R2 Foundation Windows 8.1 Enterprise Windows 8.1 Pro Windows 8.1 Windows RT 8.1 Windows Server 2012 Datacenter Windows Server 2012 Datacenter Windows Server 2012 Standard Windows Server 2012 Standard Windows Server 2012 Essentials Windows Server 2012 Foundation Windows Server 2012 Foundation Windows Server 2008 R2 Service Pack 1 Windows Server 2008 R2 Datacenter Windows Server 2008 R2 Enterprise Windows Server 2008 R2 Standard Windows Server 2008 R2 Web Edition Windows Server 2008 R2 Foundation Windows 7 Service Pack 1 Windows 7 Ultimate Windows 7 Enterprise Windows 7 Professional Windows 7 Home Premium Windows 7 Home Basic Windows 7 Starter Windows Server 2008 Service Pack 2 Windows Server 2008 Datacenter Windows Server 2008 Enterprise Windows Server 2008 Standard Windows Server 2008 Web Edition Windows Server 2008 Foundation Windows Server 2008 for Itanium-Based Systems Windows Vista Service Pack 2 Windows Vista Ultimate Windows Vista Enterprise Windows Vista Business Windows Vista Home Premium Windows Vista Home Basic Windows Vista Starter

摘要

此安全更新修复了 Microsoft Windows 中的漏洞。 如果用户访问特制网站或打开特制文档,则最严重的漏洞可能允许远程执行代码。 与使用管理用户权限操作的用户相比,其帐户在系统上具有较少用户权限的用户受到影响。

若要了解有关漏洞的详细信息,请参阅 Microsoft安全公告 MS16-146

详细信息

重要

  • Windows RT 8.1、Windows 8.1 和 Windows Server 2012 R2 的所有未来安全和非安全更新都需要安装更新2919355。 我们建议在基于 Windows RT 8.1、Windows 8.1 或 Windows Server 2012 R2 的计算机上安装更新 2919355,以便今后持续接收更新。
  • 若在安装此更新后安装语言包,则必须重新安装此更新。 因此,我们建议先安装所需的全部语言包,然后再安装此更新。 有关更多信息,请参阅添加语言包至 Windows

有关此安全更新的其他信息

下列文章包含此安全更新针对具体产品版本的其他信息。 文章可能包含已知问题信息。

  • 3205638 MS16-146:Microsoft图形组件的安全更新说明:2016 年 12 月 13 日
  • 3204724 MS16-146:Microsoft图形组件的安全更新说明:2016 年 12 月 13 日
  • 3205400 2016 年 12 月 Windows 8.1 和 Windows Server 2012 R2 仅安全质量更新
  • 3205401 2016 年 12 月 Windows 8.1 和 Windows Server 2012 R2 的安全质量月度汇总
  • 3205408 2016 年 12 月 Windows Server 2012 仅安全质量更新
  • 3205409 2016 年 12 月 Windows Server 2012 安全质量月度汇总
  • 3205394 2016 年 12 月 Windows 7 SP1 和 Windows Server 2008 R2 SP1 仅安全质量更新
  • 3207752 2016 年 12 月 Windows 7 SP1 和 Windows Server 2008 R2 SP1 的安全质量月度汇总

此外,有关Windows 10、Windows 10版本 1511、Windows 10版本 1607 和 Windows Server 2016 的详细信息,请参阅以下文章:

详细信息

安全更新部署信息

Windows Vista (所有版本) 参考表

下表包含此软件的安全更新信息。

安全更新文件名 对于所有受支持的 32 位版本的 Windows Vista:
Windows6.0-KB3205638-x86.msu
Windows6.0-KB3204724-x86.msu
对于所有受支持的基于 x64 的 Windows Vista 版本:
Windows6.0-KB3205638-x64.msu
Windows6.0-KB3204724-x64.msu
安装开关 请参阅 Microsoft 知识库文章 934307
重启要求 应用此安全更新后,必须重启系统。
删除信息 WUSA.exe 不支持卸载更新程序。 若要卸载 WUSA 安装的更新,请单击“控制面板”,然后单击“安全性”。 在“Windows 更新”下,单击“查看已安装的更新”,然后从更新列表中选择。
文件信息 请参阅 Microsoft知识库文章3205638

请参阅 Microsoft知识库文章3204724
注册表项验证 注意 此更新不会添加注册表项来验证其安装。

Windows Server 2008 (所有版本) 参考表

下表包含此软件的安全更新信息。

安全更新文件名 对于所有受支持的 32 位版本的 Windows Server 2008:
Windows6.0-KB3205638-x86.msu
Windows6.0-KB3204724-x86.msu
对于所有受支持的基于 x64 的 Windows Server 2008 版本:
Windows6.0-KB3205638-x64.msu
Windows6.0-KB3204724-x64.msu
对于 2008 Windows Server支持的所有基于 Itanium 的版本:
Windows6.0-KB3205638-ia64.msu
Windows6.0-KB3204724-ia64.msu
安装开关 请参阅 Microsoft 知识库文章 934307
重启要求 应用此安全更新后,必须重启系统。
删除信息 WUSA.exe 不支持卸载更新程序。 若要卸载 WUSA 安装的更新,请单击“控制面板”,然后单击“安全性”。 在“Windows 更新”下,单击“查看已安装的更新”,然后从更新列表中选择。
文件信息 请参阅 Microsoft知识库文章3205638
请参阅 Microsoft知识库文章3204724
注册表项验证 注意 此更新不会添加注册表项来验证其安装。

Windows 7 (所有版本) 参考表

下表包含此软件的安全更新信息。

安全更新文件名 对于所有受支持的 32 位版本的 Windows 7:
Windows6.1-KB3205394-x86.msu
仅安全相关
对于所有受支持的 32 位版本的 Windows 7
Windows6.1-KB3207752-x86.msu
月度汇总
对于所有受支持的基于 x64 的 Windows 7 版本:
Windows6.1-KB3205394-x64.msu
仅安全相关
对于所有受支持的基于 x64 的 Windows 7 版本:
Windows6.1-KB3207752-x64.msu
月度汇总
安装开关 请参阅 Microsoft 知识库文章 934307
重启要求 应用此安全更新后,必须重启系统。
删除信息 若要卸载 WUSA 安装的更新,请使用 /Uninstall 安装程序开关,或单击“控制面板”,然后单击“系统和安全”。 在“Windows 更新”下,单击“查看已安装的更新”并从更新列表中选择。
文件信息 请参阅 Microsoft知识库文章3205394
请参阅 Microsoft知识库文章3207752
注册表项验证 注意 此更新不会添加注册表项来验证其安装。

Windows Server 2008 R2 (所有版本) 参考表

下表包含此软件的安全更新信息。

安全更新文件名 对于所有受支持的基于 x64 的 Windows Server 2008 R2 版本:
Windows6.1-KB3205394-x64.msu
仅安全相关
对于所有受支持的基于 x64 的 Windows Server 2008 R2 版本:
Windows6.1-KB3207752-x64.msu
月度汇总
对于所有受支持的基于 Itanium 的 Windows Server 2008 R2 版本:
Windows6.1-KB3205394-ia64.msu
仅安全相关
对于所有受支持的基于 Itanium 的 Windows Server 2008 R2 版本:
Windows6.1-KB3207752-ia64.msu
月度汇总
安装开关 请参阅 Microsoft 知识库文章 934307
重启要求 应用此安全更新后,必须重启系统。
删除信息 若要卸载 WUSA 安装的更新,请使用 /Uninstall 安装程序开关,或单击“控制面板”,然后单击“系统和安全”。 在“Windows 更新”下,单击“查看已安装的更新”并从更新列表中选择。
文件信息 请参阅 Microsoft知识库文章3205394
请参阅 Microsoft知识库文章3207752
注册表项验证 注意 此更新不会添加注册表项来验证其安装。

Windows 8.1 (引用表) 所有版本

下表包含此软件的安全更新信息。

安全更新文件名 对于所有受支持的 32 位版本的 Windows 8.1:
Windows8.1-KB3205400-x86.msu
仅安全相关
对于所有受支持的 32 位版本的 Windows 8.1:
Windows8.1-KB3205401-x86.msu
月度汇总
对于所有受支持的基于 x64 的 Windows 8.1版本:
Windows8.1-KB3205400-x64.msu
仅安全相关
对于所有受支持的基于 x64 的 Windows 8.1版本:
Windows8.1-KB3205401-x64.msu
月度汇总
安装开关 请参阅 Microsoft 知识库文章 934307
重启要求 应用此安全更新后,必须重启系统。
删除信息 若要卸载 WUSA 安装的更新,请使用 /Uninstall 安装程序开关或单击控制面板,单击“系统和安全”,然后单击“Windows 更新”。 在“另请参阅”下,单击“已安装的更新”,然后从更新列表中选择。
文件信息 请参阅 Microsoft知识库文章 3205400
请参阅 Microsoft知识库文章3205401
注册表项验证 注意 此更新不会添加注册表项来验证其安装。

Windows Server 2012和Windows Server 2012 R2 (所有版本) 参考表

下表包含此软件的安全更新信息。

安全更新文件名 对于所有受支持的Windows Server 2012版本:
Windows8-RT-KB3205408-x64.msu
仅安全相关
对于所有受支持的Windows Server 2012版本:
Windows8-RT-KB3205409-x64.msu
月度汇总
对于所有受支持的 Windows Server 2012 R2 版本:
Windows8.1-KB3205400-x64.msu
仅安全相关
对于所有受支持的 Windows Server 2012 R2 版本:
Windows8.1-KB3205401-x64.msu
月度汇总
安装开关 请参阅 Microsoft 知识库文章 934307
重启要求 应用此安全更新后,必须重启系统。
删除信息 若要卸载 WUSA 安装的更新,请使用 /Uninstall 安装程序开关或单击控制面板,单击“系统和安全”,然后单击“Windows 更新”。 在“另请参阅”下,单击“已安装的更新”,然后从更新列表中选择。
文件信息 请参阅 Microsoft知识库文章3205408
请参阅 Microsoft知识库文章3205409
请参阅 Microsoft知识库文章 3205400
请参阅 Microsoft知识库文章3205401
注册表项验证 注意 此更新不会添加注册表项来验证其安装。

Windows RT 8.1 (所有版本) 参考表

下表包含此软件的安全更新信息。

部署 3205401仅每月更新仅通过 Windows 更新 提供。
重启要求 应用此安全更新后,必须重启系统。
删除信息 依次单击“控制面板”、“系统和安全”,然后单击“Windows 更新”。 在“另请参阅”下,单击“已安装的更新”,然后从更新列表中选择。
文件信息 请参阅 Microsoft知识库文章3205401

Windows 10 (引用表) 所有版本

下表包含此软件的安全更新信息。

安全更新文件名 对于所有受支持的 32 位版本的 Windows 10:
Windows10.0-KB3205383-x86.msu
对于所有受支持的基于 x64 的Windows 10版本:
Windows10.0-KB3205383-x64.msu
对于所有受支持的 32 位版本的 Windows 10 版本 1511:
Windows10.0-KB3205386-x86.msu
对于所有受支持的基于 x64 的版本Windows 10版本 1511:
Windows10.0-KB3205386-x64.msu
对于所有受支持的 32 位版本的 Windows 10 版本 1607:
Windows10.0-KB3206632-x86.msu
对于所有受支持的基于 x64 的 Windows 10 版本 1607 版本:
Windows10.0-KB3206632-x64.msu
安装开关 请参阅 Microsoft 知识库文章 934307
重启要求 应用此安全更新后,必须重启系统。
删除信息 若要卸载 WUSA 安装的更新,请使用 /Uninstall 安装程序开关或单击控制面板,单击“系统和安全”,然后单击“Windows 更新”。 在“另请参阅”下,单击“已安装的更新”,然后从更新列表中选择。
文件信息 Windows 10 RTM 发行说明 (KB3205383)
Windows 10版本 1511 发行说明 (KB3205386)
Windows 10版本 1607 和Windows Server 2016发行说明 (KB3206632)
注册表项验证 注意 此更新不会添加注册表项来验证其安装。

Windows Server 2016 (引用表) 所有版本

下表包含此软件的安全更新信息。

安全更新文件名 对于所有受支持的基于 x64 的Windows Server 2016版本:
Windows10.0-KB3206632-x64.msu
安装开关 请参阅 Microsoft 知识库文章 934307
重启要求 应用此安全更新后,必须重启系统。
删除信息 若要卸载 WUSA 安装的更新,请使用 /Uninstall 安装程序开关或单击控制面板,单击“系统和安全”,然后单击“Windows 更新”。 在“另请参阅”下,单击“已安装的更新”,然后从更新列表中选择。
文件信息 Windows 10版本 1607 和Windows Server 2016发行说明 (KB3206632)
注册表项验证 注意 此更新不会添加注册表项来验证其安装。

      

如何获取此安全更新的帮助和支持

有关安装更新的帮助: 支持Microsoft更新

面向 IT 专业人员的安全解决方案: TechNet 安全故障排除和支持

有关保护基于 Windows 的计算机免受病毒和恶意软件的帮助: 病毒解决方案和安全中心

根据你的国家/地区提供本地 支持:国际支持