¡¾Íþвͨ¸æ¡¿Î¢Èí10ÔÂÇå¾²¸üжà¸ö²úÆ·¸ßΣÎó²îͨ¸æ
2021-10-14
Ò». Îó²î¸ÅÊö
10ÔÂ13ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Î¢ÈíÐû²¼10ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË81¸öÇå¾²ÎÊÌâ£¬Éæ¼°Windows¡¢Microsoft Office¡¢Microsoft Visual Studio¡¢Exchange ServerµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨È¨ÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐеȸßΣÎó²îÀàÐÍ¡£
±¾ÔÂ΢ÈíÔ¶ȸüÐÂÐÞ¸´µÄÎó²îÖУ¬ÑÏÖØË®Æ½ÎªÒªº¦£¨Critical£©µÄÎó²îÓÐ3¸ö£¬Ö÷Òª£¨Important£©Îó²îÓÐ70¸ö£¬ÆäÖаüÀ¨4¸ö0dayÎó²î£º
Win32k ȨÏÞÌáÉýÎó²î£¨CVE-2021-40449£©
Windows DNS Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40469£©
Windows Kernel ȨÏÞÌáÉýÎó²î£¨CVE-2021-41335£©
Windows AppContainer ·À»ðǽ¹æÔòÇå¾²¹¦Ð§ÈƹýÎó²î£¨CVE-2021-41338£©
ÇëÏà¹ØÓû§¾¡¿ì¸üв¹¶¡¾ÙÐзÀ»¤£¬ÍêÕûÎó²îÁбíÇë²Î¿¼¸½Â¼¡£
AG¹«Ë¾Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS£©ÒѾ߱¸Î¢Èí´Ë´Î²¹¶¡¸üÐÂÖд󲿷ÖÎó²îµÄ¼ì²âÄÜÁ¦£¨°üÀ¨CVE-2021-38672¡¢CVE-2021-40461¡¢CVE-2021-40486¡¢CVE-2021-40469¡¢CVE-2021-40449µÈ¸ßΣÎó²î£©£¬ÇëÏà¹ØÓû§¹Ø×¢AG¹«Ë¾Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ²å¼þÉý¼¶°üµÄ¸üУ¬ÊµÊ±Éý¼¶ÖÁV6.0R02F01.2501£¬¹ÙÍøÁ´½Ó£ºhttp://update.nsfocus.com/update/listRsasDetail/v/vulsys
²Î¿¼Á´½Ó£º
https://msrc.microsoft.com/update-guide/en-us/releaseNote/2021-Oct
¶þ. ÖØµãÎó²î¼òÊö
ƾ֤²úÆ·Ê¢ÐжȺÍÎó²îÖ÷ÒªÐÔɸѡ³ö´Ë´Î¸üÐÂÖаüÀ¨Ó°Ïì½Ï´óµÄÎó²î£¬ÇëÏà¹ØÓû§Öصã¾ÙÐйØ×¢£º
Windows Hyper-V Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-38672/ CVE-2021-40461£©£º
Windows Hyper-VÊÇMicrosoftµÄÍâµØÐéÄâ»úÖÎÀí³ÌÐò£¬guest VM¿É¶ÁÈ¡Ö÷»úÖеÄÄÚºËÄÚ´æÓëÔÚ×ÔÉíVMÉϱ¬·¢µÄÄÚ´æ·ÖÅɹýʧ£¬µÍȨÏ޵Ĺ¥»÷Õ߿ɷ¢ËÍÌØÖÆµÄÇëÇóÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-38672
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-40461
Win32k ȨÏÞÌáÉýÎó²î£¨CVE-2021-40449£©£º
Win32kÖб£´æÒ»¸öNtGdiResetDC º¯Êý£¬¹¥»÷ÕßÔڸú¯ÊýÊÍ·ÅÖ®ºó¿ÉÒÔÉèÖÃÓû§Ä£Ê½»Øµ÷£»ÓµÓеÍȨÏ޵Ĺ¥»÷Õßͨ¹ýÖ´ÐÐÒâÍâµÄ API º¯Êý¿ÉʵÏÖȨÏÞÌáÉý£¬ÏÖÔÚÒѼì²âµ½¸ÃÎó²î±»ÔÚҰʹÓá£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40449
Windows Print Spooler ÓÕÆÎó²î£¨CVE-2021-36970£©£º
Windows´òÓ¡ºǫ́·þÎñÖб£´æÎó²î£¬ÔÚÓû§½»»¥µÄÇéÐÎÏ£¬Î´¾Éí·ÝÑéÖ¤¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÔÚÄ¿µÄÖ÷»úÉÏÔ¶³ÌÖ´ÐдúÂë¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36970
Microsoft Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-26427£©£º
¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÏàÁÚÍøÂç¶ÔÊÜÓ°ÏìµÄExchange·þÎñÆ÷¾ÙÐй¥»÷£¬¿ÉÔÚÄ¿µÄ·þÎñÆ÷¶ËʵÏÖÔ¶³Ì´úÂëÖ´ÐÐ
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26427
Microsoft Word Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40486£©£º
¹¥»÷Õß¿Éͨ¹ýÖÆ×÷¶ñÒâµÄWordÎĵµ£¬µ±ÀÖ³ÉÓÕµ¼Óû§ÔÚÊÜÓ°ÏìµÄϵͳÉÏ·¿ª¶ñÒâÎĵµºó£¬¿ÉÔÚÄ¿µÄϵͳÉÏÒÔ¸ÃÓû§È¨ÏÞÖ´ÐÐí§Òâ´úÂ룬ԤÀÀ´°¸ñÒ²±»ÁÐΪ¹¥»÷ǰÑÔ¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-40486
WindowsDNS serverÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40469£©£º
ÔÚ·þÎñÆ÷ÉèÖÃΪDNS·þÎñÆ÷µÄÇéÐÎÏ£¬¹¥»÷Õß¿ÉʹÓôËÎó²îʵÏÖÔÚÄ¿µÄϵͳÉÏÒÔ SYSTEM ȨÏÞÔ¶³Ì´úÂëÖ´ÐУ¬ÇÒ²»ÐèÒªÓû§½»»¥£¬ÏÖÔÚÎó²îϸ½ÚÒѹûÕæ¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40469
Èý. Ó°Ïì¹æÄ£
ÒÔÏÂÎªÖØµã¹Ø×¢Îó²îµÄÊÜÓ°Ïì²úÆ·°æ±¾£¬ÆäËûÎó²îÓ°Ïì²úÆ·¹æÄ£Çë²ÎÔĹٷ½Í¨¸æÁ´½Ó¡£
|
Îó²î±àºÅ |
ÊÜÓ°Ïì²úÆ·°æ±¾ |
|
CVE-2021-38672
|
Windows Server 2022 (Server Core installation) Windows Server 2022 Windows 11 for x64-based Systems |
|
CVE-2021-40461 |
Windows Server, version 20H2 (Server Core Installation) Windows Server, version 2004 (Server Core installation) Windows Server 2022 (Server Core installation) Windows Server 2022 Windows Server 2019 (Server Core installation) Windows Server 2019 Windows 11 for x64-based Systems Windows 10 Version 21H1 for x64-based Systems Windows 10 Version 20H2 for x64-based Systems Windows 10 Version 2004 for x64-based Systems Windows 10 Version 1909 for x64-based Systems Windows 10 Version 1809 for x64-based Systems |
|
CVE-2021-40449 CVE-2021-36970 |
Windows Server, version 20H2 (Server Core Installation) Windows Server, version 2004 (Server Core installation) Windows Server 2022 (Server Core installation) Windows Server 2022 Windows Server 2019 (Server Core installation) Windows Server 2019 Windows Server 2016 (Server Core installation) Windows Server 2016 Windows Server 2012 R2 (Server Core installation) Windows Server 2012 R2 Windows Server 2012 (Server Core installation) Windows Server 2012 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) Windows Server 2008 for x64-based Systems Service Pack 2 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) Windows Server 2008 for 32-bit Systems Service Pack 2 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) Windows Server 2008 R2 for x64-based Systems Service Pack 1 Windows RT 8.1 Windows 8.1 for x64-based systems Windows 8.1 for 32-bit systems Windows 7 for x64-based Systems Service Pack 1 Windows 7 for 32-bit Systems Service Pack 1 Windows 11 for x64-based Systems Windows 11 for ARM64-based Systems Windows 10 for x64-based Systems Windows 10 for 32-bit Systems Windows 10 Version 21H1 for x64-based Systems Windows 10 Version 21H1 for ARM64-based Systems Windows 10 Version 21H1 for 32-bit Systems Windows 10 Version 20H2 for x64-based Systems Windows 10 Version 20H2 for ARM64-based Systems Windows 10 Version 20H2 for 32-bit Systems Windows 10 Version 2004 for x64-based Systems Windows 10 Version 2004 for ARM64-based Systems Windows 10 Version 2004 for 32-bit Systems Windows 10 Version 1909 for x64-based Systems Windows 10 Version 1909 for ARM64-based Systems Windows 10 Version 1909 for 32-bit Systems Windows 10 Version 1809 for x64-based Systems Windows 10 Version 1809 for ARM64-based Systems Windows 10 Version 1809 for 32-bit Systems Windows 10 Version 1607 for x64-based Systems Windows 10 Version 1607 for 32-bit Systems |
|
CVE-2021-26427 |
Microsoft Exchange Server 2019 Cumulative Update 11 Microsoft Exchange Server 2019 Cumulative Update 10 Microsoft Exchange Server 2016 Cumulative Update 22 Microsoft Exchange Server 2016 Cumulative Update 21 Microsoft Exchange Server 2013 Cumulative Update 23 |
|
CVE-2021-40486 |
Microsoft Word 2016 (64-bit edition) Microsoft Word 2016 (32-bit edition) Microsoft Word 2013 Service Pack 1 (32-bit editions) Microsoft Word 2013 RT Service Pack 1 Microsoft SharePoint Enterprise Server 2016 Microsoft SharePoint Enterprise Server 2013 Service Pack 1 Microsoft Office Web Apps Server 2013 Service Pack 1 Microsoft Office Online Server Microsoft Office 2019 for 64-bit editions Microsoft Office 2019 for 32-bit editions |
|
CVE-2021-40469 |
Windows Server, version 2004 (Server Core installation) Windows Server 2022 (Server Core installation) Windows Server 2022 Windows Server, version 20H2 (Server Core Installation) Windows Server 2019 (Server Core installation) Windows Server 2012 R2 (Server Core installation) Windows Server 2012 R2 Windows Server 2012 (Server Core installation) Windows Server 2012 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) Windows Server 2008 R2 for x64-based Systems Service Pack 1 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) Windows Server 2008 for x64-based Systems Service Pack 2 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) Windows Server 2008 for 32-bit Systems Service Pack 2 Windows Server 2016 (Server Core installation) Windows Server 2016 |
ËÄ. Îó²î·À»¤
4.1 ²¹¶¡¸üÐÂ
ÏÖÔÚ΢Èí¹Ù·½ÒÑÕë¶ÔÊÜÖ§³ÖµÄ²úÆ·°æ±¾Ðû²¼ÁËÐÞ¸´ÒÔÉÏÎó²îµÄÇå¾²²¹¶¡£¬Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì×°Öò¹¶¡¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-us/releaseNote/2021-Oct
×¢£ºÓÉÓÚÍøÂçÎÊÌâ¡¢ÅÌËã»úÇéÐÎÎÊÌâµÈÔµ¹ÊÔÓÉ£¬Windows UpdateµÄ²¹¶¡¸üпÉÄÜ·ºÆðʧ°Ü¡£Óû§ÔÚ×°Öò¹¶¡ºó£¬Ó¦ÊµÊ±¼ì²é²¹¶¡ÊÇ·ñÀֳɸüС£
ÓÒ¼üµã»÷Windowsͼ±ê£¬Ñ¡Ôñ“ÉèÖÃ(N)”£¬Ñ¡Ôñ“¸üкÍÇå¾²”-“Windows¸üД£¬Éó²é¸ÃÒ³ÃæÉϵÄÌáÐÑÐÅÏ¢£¬Ò²¿Éµã»÷“Éó²é¸üÐÂÀúÊ·¼Í¼”Éó²éÀúÊ·¸üÐÂÇéÐΡ£
Õë¶ÔδÀÖ³É×°ÖõĸüУ¬¿Éµã»÷¸üÐÂÃû³ÆÌø×ªµ½Î¢Èí¹Ù·½ÏÂÔØÒ³Ãæ£¬½¨ÒéÓû§µã»÷¸ÃÒ³ÃæÉϵÄÁ´½Ó£¬×ªµ½“Microsoft¸üÐÂĿ¼”ÍøÕ¾ÏÂÔØ×ÔÁ¦³ÌÐò°ü²¢×°Öá£

AG¹«Ë¾ÔÆ







