¡¾Îó²îͨ¸æ¡¿Microsoft 10Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-10-130x00 Îó²î¸ÅÊö
2021Äê10ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬£¬MicrosoftÐû²¼ÁË10Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÐÞ¸´Á˰üÀ¨4¸ö0 dayÎó²îÔÚÄÚµÄ74¸öÇå¾²Îó²î£¨°üÀ¨Microsoft Edge Ϊ81¸öÎó²î£©£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ3¸öÎó²îÆÀ¼¶ÎªÑÏÖØ£¬£¬£¬£¬£¬£¬£¬70¸öÎó²îÆÀ¼¶Îª¸ßΣ£¬£¬£¬£¬£¬£¬£¬1¸öÎó²îÆÀ¼¶ÎªÖÐΣ¡£¡£¡£
0x01 Îó²îÏêÇé
±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÉæ¼°Microsoft Exchange Serve¡¢Microsoft OfficeÌ×¼þ¡¢Visual Studio¡¢Windows Win32K¡¢Windows TCP/IP¡¢Windows InstallerºÍWindows KernelµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£
ÔÚ81¸öÎó²îÖУ¨°üÀ¨Microsoft Edge£©£¬£¬£¬£¬£¬£¬£¬21¸öΪȨÏÞÌáÉýÎó²î£¬£¬£¬£¬£¬£¬£¬6¸öΪÇå¾²¹¦Ð§ÈƹýÎó²î£¬£¬£¬£¬£¬£¬£¬20¸öΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬13¸öΪÐÅϢй¶Îó²î£¬£¬£¬£¬£¬£¬£¬5¸öΪ¾Ü¾øÐ§ÀÍÎó²î£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°9¸öÓÕÆÎó²î¡£¡£¡£
Microsoft±¾´ÎÐÞ¸´µÄ4¸ö0 dayÎó²îÈçÏ£¬£¬£¬£¬£¬£¬£¬ÆäÖÐWin32k ȨÏÞÌáÉýÎó²îÒѱ»Æð¾¢Ê¹Óãº
l Win32k ȨÏÞÌáÉýÎó²î£¨CVE-2021-40449£©
¸ÃÎó²îΪWindows Win32k ÄÚºËÇý¶¯³ÌÐòÖеÄȨÏÞÌáÉýÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÖØÆ¯ºóºÍËùÐèȨÏ޵ͣ¬£¬£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥¼´¿É±»ÍâµØÊ¹Óᣡ£¡£ÏÖÔÚ´ËÎó²îÒѱ»¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬¾Ý¿¨°Í˹»ùÌåÏÖ£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÕý±»ÍþвÐÐΪÕßÓÃÓÚÕë¶Ô IT ¹«Ë¾¡¢¾üÊÂ/¹ú·À³Ð°üÉ̺ÍÍ⽻ʵÌåµÄÆÕ±éÌØ¹¤»î¶¯£¬£¬£¬£¬£¬£¬£¬²¢ÓÃÓÚÌáÉýMysterySnailÔ¶³Ì»á¼ûľÂí (RAT)µÄȨÏÞ£¬£¬£¬£¬£¬£¬£¬¿¨°Í˹»ù½«Æä¹éÒòÓÚIronHusky APT»î¶¯¡£¡£¡£
l Windows DNS serverÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40469£©
¸ÃÎó²îÒѾ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.2£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÔÝδ·¢Ã÷±»Ê¹Óᣡ£¡£¸ÃÎó²îÎÞÐèÓû§½»»¥¼´¿ÉÔ¶³ÌʹÓ㬣¬£¬£¬£¬£¬£¬¹¥»÷ÖØÆ¯ºóµÍ£¬£¬£¬£¬£¬£¬£¬µ«ËùÐèȨÏ޸ߣ¬£¬£¬£¬£¬£¬£¬²¢ÇÒ½öÔÚЧÀÍÆ÷ÉèÖÃΪ DNS ЧÀÍÆ÷ʱ²Å¿É±»Ê¹Óᣡ£¡£Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óá°¡£¡£¡£
l Windows KernelȨÏÞÌáÉýÎó²î£¨CVE-2021-41335£©
¸ÃÎó²îÒѾ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÔÝδ·¢Ã÷±»Ê¹Óᣡ£¡£¸ÃÎó²îµÄ¹¥»÷ÖØÆ¯ºóºÍËùÐèȨÏ޵ͣ¬£¬£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥¼´¿É±»ÍâµØÊ¹Ó㬣¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óá°¡£¡£¡£
l Windows AppContainer ·À»ðǽ¹æÔòÇå¾²¹¦Ð§ÈƹýÎó²î£¨CVE-2021-41338£©
¸ÃÎó²îÒѾ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ5.5£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÔÝδ·¢Ã÷±»Ê¹Óᣡ£¡£¸ÃÎó²îµÄ¹¥»÷ÖØÆ¯ºóºÍËùÐèȨÏ޵ͣ¬£¬£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥¼´¿É±»ÍâµØÊ¹Ó㬣¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óá°¡£¡£¡£
3¸öÆÀ¼¶ÎªÑÏÖØµÄÎó²î°üÀ¨£º
l Microsoft WordÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40486£©
¸ÃÎó²îÉÐδ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÔÝδ·¢Ã÷±»Ê¹Óᣡ£¡£¸ÃÎó²îµÄ¹¥»÷ÖØÆ¯ºóµÍÇÒÎÞÐèÌØÊâȨÏÞ¼´¿É±»ÍâµØÊ¹Ó㬣¬£¬£¬£¬£¬£¬µ«ÐèÓëÓû§½»»¥£¬£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óá°¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÐèÒª×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬£¬Ô¤ÀÀ´°¸ñÊÇ´ËÎó²îµÄÒ»ÖÖ¹¥»÷ǰÑÔ¡£¡£¡£
l Windows Hyper-V Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40461£©
¸ÃÎó²îÉÐδ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ8.0£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÔÝδ·¢Ã÷±»Ê¹Óᣡ£¡£Ê¹ÓøÃÎó²îËùÐèȨÏÞµÍÇÒÎÞÐèÓû§½»»¥£¬£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÖØÆ¯ºó¸ß£¬£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óá°¡£¡£¡£
l Windows Hyper-V Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-38672£©
¸ÃÎó²îÉÐδ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ8.0£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÔÝδ·¢Ã÷±»Ê¹Óᣡ£¡£Ê¹ÓøÃÎó²îËùÐèȨÏÞµÍÇÒÎÞÐèÓû§½»»¥£¬£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÖØÆ¯ºó¸ß£¬£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óá°¡£¡£¡£
ΪÁËʹÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬¶ñÒâÀ´±öVM¿ÉÄÜ»á¶ÁÈ¡Ö÷»úÖеÄÄÚºËÄÚ´æ¡£¡£¡£µ«Òª´¥·¢´ËÎó²î£¬£¬£¬£¬£¬£¬£¬À´±öVMÐèÒªÊ×ÏÈÔÚÀ´±öVMÉϱ¬·¢ÄÚ´æ·ÖÅɹýʧ£¬£¬£¬£¬£¬£¬£¬´Ë¹ýʧ¿Éµ¼ÖÂÀúÀ´±öµ½Ö÷»úµÄVMÌÓÒÝ¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÐèÒªÓÅÏÈÐÞ¸´µÄÎó²î»¹°üÀ¨µ«²»ÏÞÓÚÒÔÏ£º
l CVE-2021-33781£ºAzure AD Çå¾²¹¦Ð§ÈƹýÎó²î
l CVE-2021-38624£ºWindows ÃÜÔ¿´æ´¢Ìṩ³ÌÐòÇå¾²¹¦Ð§ÈƹýÎó²î
l CVE-2021-26427£ºExchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î
l CVE-2021-40454£ºPower Apps Öеĸ»Îı¾±à¼¿ØÖÆÐÅϢй¶Îó²î
l CVE-2021-40487£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚMicrosoftÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬¼øÓÚÎó²îµÄÑÏÖØÐÔ£¬£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£
£¨Ò»£© Windows update¸üÐÂ
×Ô¶¯¸üУº
Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£
ÊÖ¶¯¸üУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£
4¡¢ÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬£¬£¬×°ÖøüÐÂÏµÍ³ÖØÐÂÆô¶¯ºó£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£
ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability
0x03 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/vulnerability
https://www.bleepingcomputer.com/news/microsoft/microsoft-october-2021-patch-tuesday-fixes-4-zero-days-71-flaws/
https://www.theregister.com/2021/10/12/microsoft_patch_tuesday/
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-10-13 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
CVSS£ºwww.first.org
NVD£ºnvd.nist.gov
0x06 ¹ØÓÚ¼øºÚµ£±£Íø
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º