Microsoft 5Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-05-120x00 Îó²î¸ÅÊö
2021Äê05ÔÂ11ÈÕ£¬£¬£¬£¬£¬MicrosoftÐû²¼ÁË5Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²¸üй²¼ÆÐÞ¸´ÁË55¸öÇå¾²Îó²î£¬£¬£¬£¬£¬ÆäÖÐÓÐ4¸öÎó²îÆÀ¼¶ÎªÑÏÖØ£¬£¬£¬£¬£¬50¸öÎó²îÆÀ¼¶Îª¸ßΣ£¬£¬£¬£¬£¬1¸öÎó²îÆÀ¼¶ÎªÖÐΣ£¬£¬£¬£¬£¬ÆäÖаüÀ¨3¸ö0 dayÎó²î¡£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé
±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÉæ¼°.NET Core & Visual Studio¡¢Internet Explorer¡¢Microsoft Exchange Server¡¢Microsoft Office¡¢Excel¡¢SharePoint¡¢Windows OLE¡¢Windows SMBµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£¡£¡£MicrosoftÒѾÐÞ¸´ÁËÒÔÏÂ3¸ö0 dayÎó²î£¬£¬£¬£¬£¬ÏÖÔÚÕâЩÎó²îÉÐδ±»ÔÚҰʹÓᣡ£¡£¡£¡£¡£
.NET & Visual StudioȨÏÞÌáÉýÎó²î£¨CVE-2021-31204£©
´ËÎó²îÊÇ.NET ºÍ Visual StudioÖеÄȨÏÞÌáÉýÎó²î£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.3£¬£¬£¬£¬£¬ÏÖÔÚ´ËÎó²îÒѾ¹ûÕæÅû¶£¬£¬£¬£¬£¬µ«ÐèÓû§½»»¥²Å¿ÉʹÓᣡ£¡£¡£¡£¡£
Microsoft Exchange ServerÇå¾²¹¦Ð§ÈƹýÎó²î£¨CVE-2021-31207£©
´ËÎó²îÊÇ2021ÄêPwn2Own¾ºÈüÖз¢Ã÷µÄExchange ServerÎó²îÖ®Ò»£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö6.6£¬£¬£¬£¬£¬ÏÖÔÚÒѾ¹ûÕæÅû¶¡£¡£¡£¡£¡£¡£´ËÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓ㬣¬£¬£¬£¬µ«Ê¹ÓÃÖØÆ¯ºóºÍËùÐèȨÏ޽ϸߡ£¡£¡£¡£¡£¡£
Common UtilitiesÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31200£©
´ËÎó²îÊÇ¿ªÔ´Èí¼þÖÐͨÓÃÊÊÓóÌÐò£¨Neural Network Intelligence¹¤¾ß°ü£©ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.2£¬£¬£¬£¬£¬ÏÖÔÚÒѾ¹ûÕæÅû¶¡£¡£¡£¡£¡£¡£´ËÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓ㬣¬£¬£¬£¬µ«ËùÐèȨÏ޽ϸߡ£¡£¡£¡£¡£¡£
±¾´ÎÇå¾²¸üÐÂÐÞ¸´µÄ4¸öÑÏÖØÎó²îΪ£º
HTTPÐÒéÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31166£©
´ËÎó²îÊÇHTTP.sysÖеÄRCEÎó²î£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8,δ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓÃHTTPÐÒéÕ»£¨HTTP.sys£©ÏòÄ¿µÄЧÀÍÆ÷·¢ËͶñÒâ¹¹½¨µÄÊý¾Ý°üÀ´´¦Öóͷ£Êý¾Ý°ü¡£¡£¡£¡£¡£¡£´ËÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓ㬣¬£¬£¬£¬ÇÒ¹¥»÷ÖØÆ¯ºóºÍËùÐèȨÏ޽ϵ͡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬´ËÎó²î»¹¿Éµ¼ÖÂÈ䳿²¡¶¾¡£¡£¡£¡£¡£¡£
¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î£¨CVE-2021-26419£©
´ËÎó²îÊÇInternet ExplorerÖеľ籾ÒýÇæÄÚ´æËð»µÎó²î£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.5¡£¡£¡£¡£¡£¡£´ËÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓ㬣¬£¬£¬£¬µ«¹¥»÷ÖØ´ó½Ï¸ß£¬£¬£¬£¬£¬ÏÖÔÚÉÐδ±»Ê¹Óᣡ£¡£¡£¡£¡£
Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-28476£©
´ËÎó²îÊÇHyper-VÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.9£¬£¬£¬£¬£¬´ËÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓ㬣¬£¬£¬£¬ÇÒ¹¥»÷ÖØÆ¯ºóºÍËùÐèȨÏ޽ϵͣ¬£¬£¬£¬£¬ÏÖÔÚÉÐδ±»Ê¹Óᣡ£¡£¡£¡£¡£
OLE AutomationÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31194£©
´ËÎó²î±£´æÓÚWindows OLEÖУ¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ8.8, ´ËÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓ㬣¬£¬£¬£¬ÇÒ¹¥»÷ÖØÆ¯ºóºÍËùÐèȨÏ޽ϵͣ¬£¬£¬£¬£¬ÏÖÔÚÉÐδ±»Ê¹Óᣡ£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²¸üл¹ÐÞ¸´ÁË4¸öMicrosoft Exchange ServerÎó²î£º
CVE-2021-31195£ºMicrosoft Exchange ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©
CVE-2021-31209£ºMicrosoft Exchange ServerÓÕÆÎó²î£¨¸ßΣ£©
CVE-2021-31207£ºMicrosoft Exchange ServerÇå¾²¹¦Ð§ÈƹýÎó²î£¨ÖÐΣ£©
CVE-2021-31198£ºMicrosoft Exchange ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚMicrosoftÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬½¨Ò龡¿ìÐÞ¸´¡£¡£¡£¡£¡£¡£
£¨Ò»£© Windows update¸üÐÂ
×Ô¶¯¸üУº
Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£¡£
ÊÖ¶¯¸üУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£¡£
4¡¢ÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬×°ÖøüÐÂÏµÍ³ÖØÐÂÆô¶¯ºó£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£¡£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability
0x03 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/vulnerability
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-28476
https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2021-patch-tuesday-fixes-55-flaws-3-zero-days/
0x04 ʱ¼äÏß
2021-05-11 MicrosoftÐû²¼Çå¾²¸üÐÂ
2021-05-12 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/