¡¾Îó²îͨ¸æ¡¿Microsoft 12Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-12-150x00 Îó²î¸ÅÊö
2021Äê12ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬MicrosoftÐû²¼ÁË12Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÐÞ¸´Á˰üÀ¨6¸ö0 dayÎó²îÔÚÄÚµÄ67¸öÇå¾²Îó²î£¨°üÀ¨ Microsoft EdgeΪ83¸öÎó²î£©£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ7¸öÎó²îÆÀ¼¶ÎªÑÏÖØ£¬£¬£¬£¬£¬£¬£¬£¬60¸öÎó²îÆÀ¼¶Îª¸ßΣ¡£¡£¡£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé

±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÉæ¼°Internet Storage Name Service¡¢Microsoft Defender for IoT¡¢Microsoft Devices¡¢Microsoft Office¡¢Remote Desktop Client¡¢Visual Studio Code - WSL Extension¡¢Windows EFS¡¢Windows Installer¡¢Windows TCP/IP¡¢Windows Update Stack¡¢Windows NTFSºÍWindows KernelµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÚ67¸öÎó²î£¨²»°üÀ¨ Microsoft Edge£©ÖУ¬£¬£¬£¬£¬£¬£¬£¬21¸öΪȨÏÞÌáÉýÎó²î£¬£¬£¬£¬£¬£¬£¬£¬26¸öΪԶ³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬£¬10¸öΪÐÅϢй¶Îó²î£¬£¬£¬£¬£¬£¬£¬£¬3¸öΪ¾Ü¾øÐ§ÀÍÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°7¸öÓÕÆÎó²î¡£¡£¡£¡£¡£¡£¡£¡£
Microsoft±¾´ÎÐÞ¸´ÁË6¸ö0 dayÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ1¸ö±»Æð¾¢Ê¹Óãº
Windows AppX InstallerÓÕÆÎó²î£¨CVE-2021-43890£©
¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.1£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÖØÆ¯ºó¸ß£¬£¬£¬£¬£¬£¬£¬£¬ËùÐèȨÏ޵ͣ¬£¬£¬£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥¼´¿É±»Ô¶³ÌʹÓᣡ£¡£¡£¡£¡£¡£¡£´ËÎó²îÏÖÔÚÒѹûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬£¬ÇÒÒѼì²âµ½Îó²îʹÓ㨰üÀ¨Emotet/Trickbot/Bazaloader¶ñÒâÈí¼þ¼Ò×壩£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÆ¾Ö¤Î¢Èí¹Ù·½Í¨¸æÊµÊ±ÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬£¬²¢Ìá·ÀÕë¶Ô¸ÃÎó²îµÄÍøÂç´¹Âڻ£º
ÔËÐÐWindows 10°æ±¾1809¼°¸ü¸ß°æ±¾µÄ¿Í»§¿ÉÒÔÏÂÔØ²¢×°ÖãºMicrosoft Desktop Installer 1.16£»£»£»£»£»£»£»£»ÔËÐÐWindows 10 1709°æ±¾»òWindows 10 1803°æ±¾µÄ¿Í»§¿ÉÒÔÏÂÔØ²¢×°ÖãºMicrosoft Desktop Installer 1.11¡£¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-43890
ÆäËü5¸ö¹ûÕæÅû¶µÄ0 dayÎó²îÈçÏ£º
l CVE-2021-43240 £ºNTFS ÉèÖöÌÃû³ÆÌØÈ¨ÌáÉýÎó²î£¨CVSSÆÀ·Ö7.8£¬£¬£¬£¬£¬£¬£¬£¬ÍâµØ£©£¬£¬£¬£¬£¬£¬£¬£¬ÒѹûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óᱡ£¡£¡£¡£¡£¡£¡£¡£
l CVE-2021-41333 £ºWindows ´òÓ¡ºǫ́´¦Öóͷ£³ÌÐòÌØÈ¨ÌáÉýÎó²î£¨CVSSÆÀ·Ö7.8£¬£¬£¬£¬£¬£¬£¬£¬ÍâµØ£©£¬£¬£¬£¬£¬£¬£¬£¬ÒѹûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°ÓпÉÄܱ»Ê¹Óᱡ£¡£¡£¡£¡£¡£¡£¡£
l CVE-2021-43880 £ºWindows Mobile ×°±¸ÖÎÀíÌØÈ¨ÌáÉýÎó²î£¨CVSSÆÀ·Ö5.5£¬£¬£¬£¬£¬£¬£¬£¬ÍâµØ£©£¬£¬£¬£¬£¬£¬£¬£¬ÒѹûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°ÓпÉÄܱ»Ê¹Óᱡ£¡£¡£¡£¡£¡£¡£¡£
l CVE-2021-43883£ºWindows InstallerÌØÈ¨ÌáÉýÎó²î£¨CVSSÆÀ·Ö7.8£¬£¬£¬£¬£¬£¬£¬£¬ÍâµØ£©£¬£¬£¬£¬£¬£¬£¬£¬ÒѹûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°ÓпÉÄܱ»Ê¹Óᱡ£¡£¡£¡£¡£¡£¡£¡£
l CVE-2021-43893£º Windows ¼ÓÃÜÎļþϵͳ (EFS) ÌØÈ¨ÌáÉýÎó²î£¨CVSSÆÀ·Ö7.5£¬£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì£©£¬£¬£¬£¬£¬£¬£¬£¬ÒѹûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óᱡ£¡£¡£¡£¡£¡£¡£¡£
7¸öÆÀ¼¶ÎªÑÏÖØµÄÎó²î°üÀ¨£º
l CVE-2021-43215£ºiSNS ЧÀÍÆ÷ÄÚ´æËð»µÎó²î¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¨CVSSÆÀ·Ö9.8£¬£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì£©£¬£¬£¬£¬£¬£¬£¬£¬ÔÝδ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°ÓпÉÄܱ»Ê¹Óᱡ£¡£¡£¡£¡£¡£¡£¡£Windows iSNSЧÀÍ·ÇĬÈÏ×°Öᣡ£¡£¡£¡£¡£¡£¡£
l CVE-2021-42310£ºMicrosoft Defender for IoT Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVSSÆÀ·Ö8.1£¬£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì£©£¬£¬£¬£¬£¬£¬£¬£¬ÔÝδ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óᱡ£¡£¡£¡£¡£¡£¡£¡£Microsoft Defender for IoT 10.5.2 ¼°ÒÔÉϰ汾¾ßÓбÜÃâ´ËÎó²îµÄÇå¾²¸üС£¡£¡£¡£¡£¡£¡£¡£
l CVE-2021-43899 £ºMicrosoft 4K Wireless Display AdapterÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVSSÆÀ·Ö9.8£¬£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì£©£¬£¬£¬£¬£¬£¬£¬£¬ÔÝδ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óᱡ£¡£¡£¡£¡£¡£¡£¡£Microsoft 4K Wireless Display AdapterµÄËùÓй̼þ°æ±¾ 3.9520.47 ¼°¸ü¸ß°æ±¾¾ù²»ÊÜ´ËÎó²îµÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£
l CVE-2021-43905£ºMicrosoft Office Ó¦ÓóÌÐòÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVSSÆÀ·Ö9.6£¬£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì£©£¬£¬£¬£¬£¬£¬£¬£¬ÔÝδ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°ÓпÉÄܱ»Ê¹Óᱡ£¡£¡£¡£¡£¡£¡£¡£Microsoft Store ½«×Ô¶¯¸üУ¨Î´½ûÓÃÇéÐÎÏ£©£¬£¬£¬£¬£¬£¬£¬£¬Ó¦ÓóÌÐò°æ±¾18.2110.13110.0¼°¸ü¸ß°æ±¾°üÀ¨´Ë¸üС£¡£¡£¡£¡£¡£¡£¡£
l CVE-2021-43233£ºRemote Desktop ClientÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVSSÆÀ·Ö7.5£¬£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì£©£¬£¬£¬£¬£¬£¬£¬£¬ÔÝδ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°ÓпÉÄܱ»Ê¹Óᱡ£¡£¡£¡£¡£¡£¡£¡£
l CVE-2021-43907£ºVisual Studio Code WSL ExtensionÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVSSÆÀ·Ö9.8£¬£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì£©£¬£¬£¬£¬£¬£¬£¬£¬ÔÝδ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óᱡ£¡£¡£¡£¡£¡£¡£¡£
l CVE-2021-43217£ºWindows Encrypting File System (EFS) Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVSSÆÀ·Ö8.1£¬£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì£©£¬£¬£¬£¬£¬£¬£¬£¬ÔÝδ¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíµÄ¿ÉʹÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»Ê¹Óᱡ£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÄܻᵼÖ»º³åÇøÒç³öдÈ룬£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄ·ÇɳºÐ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î²¢·ÇÐèҪʹÓà EFS ²Å»ªÊ¹Ó㬣¬£¬£¬£¬£¬£¬£¬ÈôÊÇ EFS ЧÀÍÉÐδÔËÐУ¬£¬£¬£¬£¬£¬£¬£¬EFS ½Ó¿Ú»á´¥·¢ËüµÄÆô¶¯¡£¡£¡£¡£¡£¡£¡£¡£Microsoft ÕýÔÚ·Ö2¸ö½×¶ÎÀ´ÐÞ¸´¸ÃÎó²î£ºµÚÒ»½×¶Î´Ó2021Äê12ÔÂ14ÈÕÐû²¼µÄWindows¸üУ¨KB5009763£©×îÏÈ£»£»£»£»£»£»£»£»µÚ¶þ½×¶ÎÓ¦ÔÚ 2022 ÄêµÚÒ»¼¾¶Èʱ¿ÉÓᣡ£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚMicrosoftÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬¼øÓÚÎó²îµÄÑÏÖØÐÔ£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£¡£¡£¡£¡£¡£¡£¡£
£¨Ò»£© Windows update¸üÐÂ
×Ô¶¯¸üУº
Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£¡£¡£¡£
ÊÖ¶¯¸üУº
1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£¡£¡£¡£
4¡¢ÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬£¬£¬£¬×°ÖøüÐÂÏµÍ³ÖØÐÂÆô¶¯ºó£¬£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£¡£¡£¡£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability
0x03 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/vulnerability
https://www.bleepingcomputer.com/news/microsoft/microsoft-december-2021-patch-tuesday-fixes-6-zero-days-67-flaws/
https://blog.qualys.com/vulnerabilities-threat-research/2021/12/14/microsoft-adobe-patch-tuesday-december-2021-microsoft-83-vulnerabilities-with-7-critical-1-actively-exploited-adobe-60-vulnerabilities-28-critical
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-12-15 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
ÍòÀû¹ú¼Ê¹ÙÍø¼ò½é
ÍòÀû¹ú¼Ê¹ÙÍø¹«Ë¾½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬£¬£¬£¬£¬£¬£¬£¬ÊǺ£ÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÇå¾²²úÆ·¡¢¿ÉÐÅÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄ×ÛºÏÌṩÉÌ¡£¡£¡£¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÇþµÀϵͳºÍÊÖÒÕÖ§³ÖÖÐÐÄ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£¡£¡£¡£¡£¡£¡£¡£
¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£¡£¡£
¹ØÓÚÍòÀû¹ú¼Ê¹ÙÍø
ÍòÀû¹ú¼Ê¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ