Microsoft 6Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-06-09

0x00 Îó²î¸ÅÊö

2021Äê06ÔÂ08ÈÕ£¬£¬£¬£¬£¬MicrosoftÐû²¼ÁË6Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²¸üй²¼ÆÐÞ¸´ÁË50¸öÇå¾²Îó²î£¬£¬£¬£¬£¬ÆäÖÐÓÐ5¸öÎó²îÆÀ¼¶ÎªÑÏÖØ£¬£¬£¬£¬£¬45¸öÎó²îÆÀ¼¶Îª¸ßΣ£¬£¬£¬£¬£¬ÆäÖаüÀ¨7¸ö0 dayÎó²î¡£¡£¡£¡£ ¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

 

±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÉæ¼°.NET Core & Visual Studio¡¢Microsoft Office¡¢Excel¡¢SharePoint¡¢Outlook¡¢Microsoft Windows Codecs Library¡¢Microsoft Scripting Engine¡¢Windows TCP/IP¡¢Windows Remote Desktop¡¢Windows Kernel ºÍWindows DefenderµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£ ¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬5¸öÆÀ¼¶ÎªÑÏÖØµÄÎó²îÈçÏÂ:

Microsoft Defender Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2021-31985)

¸ÃÎó²îÊÇMicrosoft DefenderÖеÄRCEÎó²î£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ7.8¡£¡£¡£¡£ ¡£¡£¡£¸ÃÎó²îʹÓÃÖØÆ¯ºóµÍ£¬£¬£¬£¬£¬²»ÐèÒªÌØÊâȨÏÞ¼´¿ÉÍâµØÊ¹Ó㬣¬£¬£¬£¬µ«ÐèÒªÓû§½»»¥£¬£¬£¬£¬£¬MicrosoftµÄ¿ÉʹÓÃÐÔÆÀ¹ÀΪ¡°¿ÉÄܱ»Ê¹Óᱡ£¡£¡£¡£ ¡£¡£¡£

 

Scripting EngineÄÚ´æËð»µÎó²î£¨CVE-2021-31959£©

¸ÃÎó²îÊÇChakra JScript ¾ç±¾ÒýÇæÖеÄÄÚ´æËð»µÎó²î£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ6.4¡£¡£¡£¡£ ¡£¡£¡£´ËÎó²îÓ°Ïì Windows 7¡¢Windows 8¡¢Windows 10¡¢Windows Server 2008 R2¡¢Windows Server 2012 (R2) ºÍ Windows Server 2016µÈËùÓÐÊÜÖ§³ÖµÄMicrosoft Windows °æ±¾¡£¡£¡£¡£ ¡£¡£¡£¸ÃÎó²îʹÓÃÖØÆ¯ºó½Ï¸ß£¬£¬£¬£¬£¬²»ÐèÒªÌØÊâȨÏÞ¼´¿ÉÔ¶³ÌʹÓ㬣¬£¬£¬£¬µ«ÐèÒªÓû§½»»¥¡£¡£¡£¡£ ¡£¡£¡£

 

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31963£©

¸ÃÎó²îÊÇMicrosoft SharePoint Server ÖеÄRCEÎó²î£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ7.1¡£¡£¡£¡£ ¡£¡£¡£¸ÃÎó²îÎÞÐèÓû§½»»¥¼´¿ÉÔ¶³ÌʹÓ㬣¬£¬£¬£¬µ«Îó²îʹÓÃÖØÆ¯ºó½Ï¸ß¡£¡£¡£¡£ ¡£¡£¡£

 

VP9 Video ExtensionsÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31967£©

¸ÃÎó²îÊÇVP9 ÊÓÆµÀ©Õ¹ÖеÄRCEÎó²î£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ7.8¡£¡£¡£¡£ ¡£¡£¡£¸ÃÎó²îʹÓÃÖØÆ¯ºóµÍ£¬£¬£¬£¬£¬²»ÐèÒªÌØÊâȨÏÞ¼´¿ÉÍâµØÊ¹Ó㬣¬£¬£¬£¬µ«ÐèÒªÓû§½»»¥¡£¡£¡£¡£ ¡£¡£¡£ÏÖÔÚ´ËÎó²îÒÑÔÚÓ¦ÓóÌÐò°ü°æ±¾1.0.41182.0¼°¸ü¸ß°æ±¾ÖÐÐÞ¸´£¬£¬£¬£¬£¬Óû§¿ÉÒÔÔÚ PowerShell Öмì²éÈí¼þ°ü°æ±¾£º

Get-AppxPackage -Name Microsoft.VP9VideoExtensions

 

Windows MSHTML ƽ̨Զ³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-33742£©

¸ÃÎó²îÊÇWindows MSHTML ƽ̨ÖеÄRCEÎó²î£¬£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ7.5¡£¡£¡£¡£ ¡£¡£¡£¸ÃÎó²îÎÞÐèÌØÊâȨÏÞ¼´¿ÉÔ¶³ÌʹÓ㬣¬£¬£¬£¬µ«Îó²îʹÓÃÖØÆ¯ºó½Ï¸ß£¬£¬£¬£¬£¬ÇÒÐèÓëÓû§½»»¥£¬£¬£¬£¬£¬ÏÖÔÚ´ËÎó²îÒÑ·¢Ã÷ÔÚҰʹÓᣡ£¡£¡£ ¡£¡£¡£

 

MicrosoftÐÞ¸´µÄ7¸ö0 dayÎó²îÖУ¬£¬£¬£¬£¬6¸öÒѱ»ÔÚҰʹÓõÄÎó²îÈçÏ£º

CVE-2021-31955 - Windows KernelÐÅϢй¶Îó²î

CVE-2021-31956 - Windows NTFS ȨÏÞÌáÉýÎó²î

CVE-2021-33739 - Microsoft DWM ½¹µã¿âȨÏÞÌáÉýÎó²î

CVE-2021-33742 - Windows MSHTML ƽ̨Զ³Ì´úÂëÖ´ÐÐÎó²î

CVE-2021-31199 - Microsoft ÔöÇ¿ÐͼÓÃÜÌṩ³ÌÐòȨÏÞÌáÉýÎó²î

CVE-2021-31201 - Microsoft ÔöÇ¿ÐͼÓÃÜÌṩ³ÌÐòȨÏÞÌáÉýÎó²î

±ðµÄ£¬£¬£¬£¬£¬ CVE-2021-31968 (Windows Ô¶³Ì×ÀÃæÐ§À;ܾøÐ§ÀÍÎó²î)ÒѾ­¹ûÕæÅû¶£¬£¬£¬£¬£¬µ«ÉÐδ·¢Ã÷ÔÚҰʹÓᣡ£¡£¡£ ¡£¡£¡£


Microsoft 6Ô²¹¶¡ÐÞ¸´µÄÍêÕûÎó²îÁбíÈçÏ£º

±êÇ©

CVE ID

CVE   ÎÊÌâ

ÑÏÖØÐÔ

.NET   Core & Visual Studio

CVE-2021-31957

.NET   Core ºÍ Visual Studio ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

3D   Viewer

CVE-2021-31942

3D   ViewerÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

3D   Viewer

CVE-2021-31943

3D   ViewerÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

3D   Viewer

CVE-2021-31944

3D   ViewerÐÅϢй¶Îó²î

¸ßΣ

Microsoft   DWM Core Library

CVE-2021-33739

Microsoft   DWM ½¹µã¿âȨÏÞÌáÉýÎó²î

¸ßΣ

Microsoft   Edge (Chromium-based)

CVE-2021-33741

Microsoft   Edge£¨»ùÓÚ Chromium£©È¨ÏÞÌáÉýÎó²î

¸ßΣ

Microsoft   Intune

CVE-2021-31980

Microsoft   Intune ÖÎÀíÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

Microsoft   Office

CVE-2021-31940

Microsoft   Office Graphics Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

Microsoft   Office

CVE-2021-31941

Microsoft   Office Graphics Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

Microsoft   Office Excel

CVE-2021-31939

Microsoft   Excel Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

Microsoft   Office Outlook

CVE-2021-31949

Microsoft   Outlook Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

Microsoft   Office SharePoint

CVE-2021-31964

Microsoft   SharePoint Server ÓÕÆ­Îó²î

¸ßΣ

Microsoft   Office SharePoint

CVE-2021-31963

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

Microsoft   Office SharePoint

CVE-2021-31950

Microsoft   SharePoint Server ÓÕÆ­Îó²î

¸ßΣ

Microsoft   Office SharePoint

CVE-2021-31948

Microsoft   SharePoint Server ÓÕÆ­Îó²î

¸ßΣ

Microsoft   Office SharePoint

CVE-2021-31966

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

Microsoft   Office SharePoint

CVE-2021-31965

Microsoft   SharePoint Server ÐÅϢй¶Îó²î

¸ßΣ

Microsoft   Office SharePoint

CVE-2021-26420

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

Microsoft   Scripting Engine

CVE-2021-31959

¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î

ÑÏÖØ

Microsoft   Windows Codecs Library

CVE-2021-31967

VP9   ÊÓÆµÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

Paint   3D

CVE-2021-31946

Paint   3D Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

Paint   3D

CVE-2021-31983

Paint   3D Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

Paint   3D

CVE-2021-31945

Paint   3D Ô¶³Ì´úÂëÖ´ÐÐÎó²î

¸ßΣ

Role:   Hyper-V

CVE-2021-31977

Windows   Hyper-V ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

Visual   Studio Code - Kubernetes Tools

CVE-2021-31938

Microsoft   VsCode Kubernetes ¹¤¾ßÀ©Õ¹È¨ÏÞÌáÉýÎó²î

¸ßΣ

Windows   Bind Filter Driver

CVE-2021-31960

Windows   °ó¶¨É¸Ñ¡Æ÷Çý¶¯³ÌÐòÐÅϢй¶Îó²î

¸ßΣ

Windows   Common Log File System Driver

CVE-2021-31954

Windows   ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòȨÏÞÌáÉýÎó²î

¸ßΣ

Windows   Cryptographic Services

CVE-2021-31201

 Microsoft ÔöÇ¿ÐͼÓÃÜÌṩ³ÌÐòȨÏÞÌáÉýÎó²î

¸ßΣ

Windows   Cryptographic Services

CVE-2021-31199

  Microsoft ÔöÇ¿ÐͼÓÃÜÌṩ³ÌÐòȨÏÞÌáÉýÎó²î

¸ßΣ

Windows   DCOM Server

CVE-2021-26414

Windows   DCOM ЧÀÍÆ÷Çå¾²¹¦Ð§Èƹý

¸ßΣ

Windows   Defender

CVE-2021-31978

Microsoft   Defender ¾Ü¾øÐ§ÀÍÎó²î

¸ßΣ

Windows   Defender

CVE-2021-31985

Microsoft   Defender Ô¶³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

Windows   Drivers

CVE-2021-31969

Windows   ÔÆÎļþÃÔÄã¹ýÂËÆ÷Çý¶¯È¨ÏÞÌáÉýÎó²î

¸ßΣ

Windows   Event Logging Service

CVE-2021-31972

Windows   ÐÅϢй¶Îó²îµÄÊÂÎñ¸ú×Ù

¸ßΣ

Windows   Filter Manager

CVE-2021-31953

Windows   ¹ýÂËÆ÷ÖÎÀíÆ÷ȨÏÞÌáÉýÎó²î

¸ßΣ

Windows   HTML Platform

CVE-2021-31971

Windows   HTML ƽ̨Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

Windows   Installer

CVE-2021-31973

Windows   GPSVC ȨÏÞÌáÉýÎó²î

¸ßΣ

Windows   Kerberos

CVE-2021-31962

Kerberos   AppContainer Çå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

Windows   Kernel

CVE-2021-31951

Windows   ÄÚºËȨÏÞÌáÉýÎó²î

¸ßΣ

Windows   Kernel

CVE-2021-31955

Windows   ÄÚºËÐÅϢй¶Îó²î

¸ßΣ

Windows   Kernel-Mode Drivers

CVE-2021-31952

Windows   ÄÚºËģʽÇý¶¯³ÌÐòȨÏÞÌáÉýÎó²î

¸ßΣ

Windows   MSHTML Platform

CVE-2021-33742

Windows   MSHTML ƽ̨Զ³Ì´úÂëÖ´ÐÐÎó²î

ÑÏÖØ

Windows   Network File System

CVE-2021-31975

NFS   ÐÅϢй¶Îó²îЧÀÍÆ÷

¸ßΣ

Windows   Network File System

CVE-2021-31974

NFS   ¾Ü¾øÐ§ÀÍÎó²îЧÀÍÆ÷

¸ßΣ

Windows   Network File System

CVE-2021-31976

NFS   ÐÅϢй¶Îó²îЧÀÍÆ÷

¸ßΣ

Windows   NTFS

CVE-2021-31956

Windows   NTFS ȨÏÞÌáÉýÎó²î

¸ßΣ

Windows   NTLM

CVE-2021-31958

Windows   NTLM ȨÏÞÌáÉýÎó²î

¸ßΣ

Windows   Print Spooler Components

CVE-2021-1675

Windows   ´òÓ¡ºǫ́´¦Öóͷ£³ÌÐòȨÏÞÌáÉýÎó²î

¸ßΣ

Windows   Remote Desktop

CVE-2021-31968

Windows   Ô¶³Ì×ÀÃæÐ§À;ܾøÐ§ÀÍÎó²î

¸ßΣ

Windows   TCP/IP

CVE-2021-31970

Windows   TCP/IP Çý¶¯³ÌÐòÇå¾²¹¦Ð§ÈƹýÎó²î

¸ßΣ

 

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚMicrosoftÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬½¨Ò龡¿ìÐÞ¸´¡£¡£¡£¡£ ¡£¡£¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£ ¡£¡£¡£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£ ¡£¡£¡£

4¡¢ÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬×°ÖøüÐÂÏµÍ³ÖØÐÂÆô¶¯ºó£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£ ¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£ ¡£¡£¡£

 

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£ ¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/

 

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/vulnerability

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-31963

https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2021-patch-tuesday-fixes-6-exploited-zero-days-50-flaws/

 

0x04 ʱ¼äÏß

2021-06-08  MicrosoftÐû²¼Çå¾²¸üÐÂ

2021-06-09  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png