¡¾Îó²îͨ¸æ¡¿Microsoft 10Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-10-13

0x00 Îó²î¸ÅÊö

2021Äê10ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬MicrosoftÐû²¼ÁË10Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÐÞ¸´Á˰üÀ¨4¸ö0 dayÎó²îÔÚÄÚµÄ74¸öÇå¾²Îó²î£¨°üÀ¨Microsoft Edge Ϊ81¸öÎó²î£©£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ3¸öÎó²îÆÀ¼¶ÎªÑÏÖØ£¬£¬£¬£¬£¬£¬70¸öÎó²îÆÀ¼¶Îª¸ßΣ£¬£¬£¬£¬£¬£¬1¸öÎó²îÆÀ¼¶ÎªÖÐΣ¡£¡£¡£¡£


0x01 Îó²îÏêÇé

image.png

±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÉæ¼°Microsoft Exchange Serve¡¢Microsoft OfficeÌ×¼þ¡¢Visual Studio¡¢Windows Win32K¡¢Windows TCP/IP¡¢Windows InstallerºÍWindows KernelµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£

ÔÚ81¸öÎó²îÖУ¨°üÀ¨Microsoft Edge£©£¬£¬£¬£¬£¬£¬21¸öΪȨÏÞÌáÉýÎó²î£¬£¬£¬£¬£¬£¬6¸öΪÇå¾²¹¦Ð§ÈƹýÎó²î£¬£¬£¬£¬£¬£¬20¸öΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬13¸öΪÐÅϢй¶Îó²î£¬£¬£¬£¬£¬£¬5¸öΪ¾Ü¾øÐ§ÀÍÎó²î£¬£¬£¬£¬£¬£¬ÒÔ¼°9¸öÓÕÆ­Îó²î¡£¡£¡£¡£

 

Microsoft±¾´ÎÐÞ¸´µÄ4¸ö0 dayÎó²îÈçÏ£¬£¬£¬£¬£¬£¬ÆäÖÐWin32k ȨÏÞÌáÉýÎó²îÒѱ»Æð¾¢Ê¹Óãº

l  Win32k ȨÏÞÌáÉýÎó²î£¨CVE-2021-40449£©

¸ÃÎó²îΪWindows Win32k ÄÚºËÇý¶¯³ÌÐòÖеÄȨÏÞÌáÉýÎó²î£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬¹¥»÷ÖØÆ¯ºóºÍËùÐèȨÏ޵ͣ¬£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥¼´¿É±»ÍâµØÊ¹Óᣡ£¡£¡£ÏÖÔÚ´ËÎó²îÒѱ»¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬¾Ý¿¨°Í˹»ùÌåÏÖ£¬£¬£¬£¬£¬£¬¸ÃÎó²îÕý±»ÍþвÐÐΪÕßÓÃÓÚÕë¶Ô IT ¹«Ë¾¡¢¾üÊÂ/¹ú·À³Ð°üÉ̺ÍÍ⽻ʵÌåµÄÆÕ±éÌØ¹¤»î¶¯£¬£¬£¬£¬£¬£¬²¢ÓÃÓÚÌáÉýMysterySnailÔ¶³Ì»á¼ûľÂí (RAT)µÄȨÏÞ£¬£¬£¬£¬£¬£¬¿¨°Í˹»ù½«Æä¹éÒòÓÚIronHusky APT»î¶¯¡£¡£¡£¡£

l  Windows DNS serverÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40469£©

¸ÃÎó²îÒѾ­¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.2£¬£¬£¬£¬£¬£¬ÏÖÔÚÔÝδ·¢Ã÷±»Ê¹Óᣡ£¡£¡£¸ÃÎó²îÎÞÐèÓû§½»»¥¼´¿ÉÔ¶³ÌʹÓ㬣¬£¬£¬£¬£¬¹¥»÷ÖØÆ¯ºóµÍ£¬£¬£¬£¬£¬£¬µ«ËùÐèȨÏ޸ߣ¬£¬£¬£¬£¬£¬²¢ÇÒ½öÔÚЧÀÍÆ÷ÉèÖÃΪ DNS ЧÀÍÆ÷ʱ²Å¿É±»Ê¹Óᣡ£¡£¡£Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óá°¡£¡£¡£¡£

l  Windows KernelȨÏÞÌáÉýÎó²î£¨CVE-2021-41335£©

¸ÃÎó²îÒѾ­¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬ÏÖÔÚÔÝδ·¢Ã÷±»Ê¹Óᣡ£¡£¡£¸ÃÎó²îµÄ¹¥»÷ÖØÆ¯ºóºÍËùÐèȨÏ޵ͣ¬£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥¼´¿É±»ÍâµØÊ¹Ó㬣¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óá°¡£¡£¡£¡£

l  Windows AppContainer ·À»ðǽ¹æÔòÇå¾²¹¦Ð§ÈƹýÎó²î£¨CVE-2021-41338£©

¸ÃÎó²îÒѾ­¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ5.5£¬£¬£¬£¬£¬£¬ÏÖÔÚÔÝδ·¢Ã÷±»Ê¹Óᣡ£¡£¡£¸ÃÎó²îµÄ¹¥»÷ÖØÆ¯ºóºÍËùÐèȨÏ޵ͣ¬£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥¼´¿É±»ÍâµØÊ¹Ó㬣¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óá°¡£¡£¡£¡£

 

3¸öÆÀ¼¶ÎªÑÏÖØµÄÎó²î°üÀ¨£º

l  Microsoft WordÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40486£©

¸ÃÎó²îÉÐδ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬ÏÖÔÚÔÝδ·¢Ã÷±»Ê¹Óᣡ£¡£¡£¸ÃÎó²îµÄ¹¥»÷ÖØÆ¯ºóµÍÇÒÎÞÐèÌØÊâȨÏÞ¼´¿É±»ÍâµØÊ¹Ó㬣¬£¬£¬£¬£¬µ«ÐèÓëÓû§½»»¥£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óá°¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÐèÒª×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬Ô¤ÀÀ´°¸ñÊÇ´ËÎó²îµÄÒ»ÖÖ¹¥»÷ǰÑÔ¡£¡£¡£¡£

l  Windows Hyper-V Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40461£©

¸ÃÎó²îÉÐδ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ8.0£¬£¬£¬£¬£¬£¬ÏÖÔÚÔÝδ·¢Ã÷±»Ê¹Óᣡ£¡£¡£Ê¹ÓøÃÎó²îËùÐèȨÏÞµÍÇÒÎÞÐèÓû§½»»¥£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÖØÆ¯ºó¸ß£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óá°¡£¡£¡£¡£

l  Windows Hyper-V Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-38672£©

¸ÃÎó²îÉÐδ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ8.0£¬£¬£¬£¬£¬£¬ÏÖÔÚÔÝδ·¢Ã÷±»Ê¹Óᣡ£¡£¡£Ê¹ÓøÃÎó²îËùÐèȨÏÞµÍÇÒÎÞÐèÓû§½»»¥£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÖØÆ¯ºó¸ß£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óá°¡£¡£¡£¡£

ΪÁËʹÓôËÎó²î£¬£¬£¬£¬£¬£¬¶ñÒâÀ´±öVM¿ÉÄÜ»á¶ÁÈ¡Ö÷»úÖеÄÄÚºËÄÚ´æ¡£¡£¡£¡£µ«Òª´¥·¢´ËÎó²î£¬£¬£¬£¬£¬£¬À´±öVMÐèÒªÊ×ÏÈÔÚÀ´±öVMÉϱ¬·¢ÄÚ´æ·ÖÅɹýʧ£¬£¬£¬£¬£¬£¬´Ë¹ýʧ¿Éµ¼ÖÂÀúÀ´±öµ½Ö÷»úµÄVMÌÓÒÝ¡£¡£¡£¡£

 

±ðµÄ£¬£¬£¬£¬£¬£¬ÐèÒªÓÅÏÈÐÞ¸´µÄÎó²î»¹°üÀ¨µ«²»ÏÞÓÚÒÔÏ£º

l  CVE-2021-33781£ºAzure AD Çå¾²¹¦Ð§ÈƹýÎó²î

l  CVE-2021-38624£ºWindows ÃÜÔ¿´æ´¢Ìṩ³ÌÐòÇå¾²¹¦Ð§ÈƹýÎó²î

l  CVE-2021-26427£ºExchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

l  CVE-2021-40454£ºPower Apps Öеĸ»Îı¾±à¼­¿ØÖÆÐÅϢй¶Îó²î

l  CVE-2021-40487£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚMicrosoftÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬£¬¼øÓÚÎó²îµÄÑÏÖØÐÔ£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£

4¡¢ÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬£¬×°ÖøüÐÂÏµÍ³ÖØÐÂÆô¶¯ºó£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£

 

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/vulnerability

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/vulnerability

https://www.bleepingcomputer.com/news/microsoft/microsoft-october-2021-patch-tuesday-fixes-4-zero-days-71-flaws/

https://www.theregister.com/2021/10/12/microsoft_patch_tuesday/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-10-13

Ê×´ÎÐû²¼

 

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

CVSS£ºwww.first.org

NVD£ºnvd.nist.gov

 

0x06 ¹ØÓÚÍòÀû¹ú¼Ê¹ÙÍø

¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png