¡¾Â©¶´Í¨¸æ¡¿Microsoft 10Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2021-10-13

0x00 ©¶´¸ÅÊö

2021Äê10ÔÂ12ÈÕ £¬MicrosoftÐû²¼ÁË10Ô·ݵÄÄþ¾²¸üР£¬±¾´ÎÐû²¼µÄÄþ¾²¸üÐÂÐÞ¸´Á˰üÂÞ4¸ö0 day©¶´ÔÚÄÚµÄ74¸öÄþ¾²Â©¶´£¨°üÂÞMicrosoft Edge Ϊ81¸ö©¶´£© £¬ÆäÖÐÓÐ3¸ö©¶´ÆÀ¼¶ÎªÑÏÖØ £¬70¸ö©¶´ÆÀ¼¶Îª¸ßΣ £¬1¸ö©¶´ÆÀ¼¶ÎªÖÐΣ¡£


0x01 ©¶´ÏêÇé

image.png

±¾´ÎÐû²¼µÄÄþ¾²¸üÐÂÉæ¼°Microsoft Exchange Serve¡¢Microsoft OfficeÌ×¼þ¡¢Visual Studio¡¢Windows Win32K¡¢Windows TCP/IP¡¢Windows InstallerºÍWindows KernelµÈ¶à¸ö²úÎïºÍ×é¼þ¡£

ÔÚ81¸ö©¶´ÖУ¨°üÂÞMicrosoft Edge£© £¬21¸öΪȨÏÞÌáÉý©¶´ £¬6¸öΪÄþ¾²¹¦Ð§Èƹý©¶´ £¬20¸öΪԶ³Ì´úÂëÖ´ÐЩ¶´ £¬13¸öΪÐÅϢй¶©¶´ £¬5¸öΪ¾Ü¾ø·þÎñ©¶´ £¬ÒÔ¼°9¸öÆÛƭ©¶´¡£

 

Microsoft±¾´ÎÐÞ¸´µÄ4¸ö0 day©¶´ÈçÏ £¬ÆäÖÐWin32k ȨÏÞÌáÉý©¶´Òѱ»»ý¼«ÀûÓãº

l  Win32k ȨÏÞÌáÉý©¶´£¨CVE-2021-40449£©

¸Ã©¶´ÎªWindows Win32k ÄÚºËÇý¶¯·¨Ê½ÖеÄȨÏÞÌáÉý©¶´ £¬ÆäCVSSÆÀ·ÖΪ7.8 £¬¹¥»÷ÅÓ´ó¶ÈºÍËùÐèȨÏÞµÍ £¬ÎÞÐèÓû§½»»¥¼´¿É±»µ±µØÀûÓá£Ä¿Ç°´Ë©¶´Òѱ»¹ûÈ»Åû¶ £¬¾Ý¿¨°Í˹»ùÌåÏÖ £¬¸Ã©¶´Õý±»ÍþвÐÐΪÕßÓÃÓÚÕë¶Ô IT ¹«Ë¾¡¢¾üÊÂ/¹ú·À³Ð°üÉ̺ÍÍ⽻ʵÌåµÄ¹ã·º¼äµý»î¶¯ £¬²¢ÓÃÓÚÌáÉýMysterySnailÔ¶³Ì·ÃÎÊľÂí (RAT)µÄȨÏÞ £¬¿¨°Í˹»ù½«Æä¹éÒòÓÚIronHusky APT»î¶¯¡£

l  Windows DNS serverÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-40469£©

¸Ã©¶´ÒѾ­¹ûÈ»Åû¶ £¬ÆäCVSSÆÀ·ÖΪ7.2 £¬Ä¿Ç°ÔÝδ·¢ÏÖ±»ÀûÓ᣸é¶´ÎÞÐèÓû§½»»¥¼´¿ÉÔ¶³ÌÀûÓà £¬¹¥»÷ÅÓ´ó¶ÈµÍ £¬µ«ËùÐèȨÏÞ¸ß £¬¶øÇÒ½öÔÚ·þÎñÆ÷ÅäÖÃΪ DNS ·þÎñÆ÷ʱ²Å¿É±»ÀûÓá£Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»ÀûÓá°¡£

l  Windows KernelȨÏÞÌáÉý©¶´£¨CVE-2021-41335£©

¸Ã©¶´ÒѾ­¹ûÈ»Åû¶ £¬ÆäCVSSÆÀ·ÖΪ7.8 £¬Ä¿Ç°ÔÝδ·¢ÏÖ±»ÀûÓ᣸é¶´µÄ¹¥»÷ÅÓ´ó¶ÈºÍËùÐèȨÏÞµÍ £¬ÎÞÐèÓû§½»»¥¼´¿É±»µ±µØÀûÓà £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»ÀûÓá°¡£

l  Windows AppContainer ·À»ðǽ¹æÔòÄþ¾²¹¦Ð§Èƹý©¶´£¨CVE-2021-41338£©

¸Ã©¶´ÒѾ­¹ûÈ»Åû¶ £¬ÆäCVSSÆÀ·ÖΪ5.5 £¬Ä¿Ç°ÔÝδ·¢ÏÖ±»ÀûÓ᣸é¶´µÄ¹¥»÷ÅÓ´ó¶ÈºÍËùÐèȨÏÞµÍ £¬ÎÞÐèÓû§½»»¥¼´¿É±»µ±µØÀûÓà £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»ÀûÓá°¡£

 

3¸öÆÀ¼¶ÎªÑÏÖØµÄ©¶´°üÂÞ£º

l  Microsoft WordÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-40486£©

¸Ã©¶´ÉÐδ¹ûÈ»Åû¶ £¬ÆäCVSSÆÀ·ÖΪ7.8 £¬Ä¿Ç°ÔÝδ·¢ÏÖ±»ÀûÓ᣸é¶´µÄ¹¥»÷ÅÓ´ó¶ÈµÍÇÒÎÞÐèÌØÊâȨÏÞ¼´¿É±»µ±µØÀûÓà £¬µ«ÐèÓëÓû§½»»¥ £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»ÀûÓá°¡£´ËÍâ £¬ÐèҪעÒâµÄÊÇ £¬Ô¤ÀÀ´°¸ñÊÇ´Ë©¶´µÄÒ»ÖÖ¹¥»÷ý½é¡£

l  Windows Hyper-V Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-40461£©

¸Ã©¶´ÉÐδ¹ûÈ»Åû¶ £¬ÆäCVSSÆÀ·ÖΪ8.0 £¬Ä¿Ç°ÔÝδ·¢ÏÖ±»ÀûÓá£ÀûÓøÃ©¶´ËùÐèȨÏÞµÍÇÒÎÞÐèÓû§½»»¥ £¬µ«¹¥»÷ÅÓ´ó¶È¸ß £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»ÀûÓá°¡£

l  Windows Hyper-V Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-38672£©

¸Ã©¶´ÉÐδ¹ûÈ»Åû¶ £¬ÆäCVSSÆÀ·ÖΪ8.0 £¬Ä¿Ç°ÔÝδ·¢ÏÖ±»ÀûÓá£ÀûÓøÃ©¶´ËùÐèȨÏÞµÍÇÒÎÞÐèÓû§½»»¥ £¬µ«¹¥»÷ÅÓ´ó¶È¸ß £¬Î¢ÈíµÄ¿ÉÀûÓÃÐÔÆÀ¹À½«ÆäÆÀΪ¡°²»Ì«¿ÉÄܱ»ÀûÓá°¡£

ΪÁËÀûÓôË©¶´ £¬¶ñÒâÀ´±öVM¿ÉÄÜ»á¶ÁÈ¡Ö÷»úÖеÄÄÚºËÄÚ´æ¡£µ«Òª´¥·¢´Ë©¶´ £¬À´±öVMÐèÒªÊ×ÏÈÔÚÀ´±öVMÉÏ·¢ÉúÄÚ´æ·ÖÅä´íÎó £¬´Ë´íÎó¿Éµ¼Ö´ÓÀ´±öµ½Ö÷»úµÄVMÌÓÒÝ¡£

 

´ËÍâ £¬ÐèÒªÓÅÏÈÐÞ¸´µÄ©¶´»¹°üÂÞµ«²»ÏÞÓÚÒÔÏ£º

l  CVE-2021-33781£ºAzure AD Äþ¾²¹¦Ð§Èƹý©¶´

l  CVE-2021-38624£ºWindows ÃÜÔ¿´æ´¢Ìṩ·¨Ê½Äþ¾²¹¦Ð§Èƹý©¶´

l  CVE-2021-26427£ºExchange Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

l  CVE-2021-40454£ºPower Apps Öеĸ»Îı¾±à¼­¿ØÖÆÐÅϢй¶©¶´

l  CVE-2021-40487£ºMicrosoft SharePoint Server Ô¶³Ì´úÂëÖ´ÐЩ¶´

 

0x02 ´¦Öý¨Òé

ĿǰMicrosoftÒÑÐû²¼Ïà¹ØÄþ¾²¸üР£¬¼øÓÚ©¶´µÄÑÏÖØÐÔ £¬½¨ÒéÊÜÓ°ÏìµÄÓû§¾¡¿ìÐÞ¸´¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓà £¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ £¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü £¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡± £¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС± £¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС± £¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢ÖØÆô¼ÆËã»ú £¬°²×°¸üÐÂÏµÍ³ÖØÐÂÆô¶¯ºó £¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üР£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó £¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡± £¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£

 

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/vulnerability

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/vulnerability

https://www.bleepingcomputer.com/news/microsoft/microsoft-october-2021-patch-tuesday-fixes-4-zero-days-71-flaws/

https://www.theregister.com/2021/10/12/microsoft_patch_tuesday/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-10-13

Ê×´ÎÐû²¼

 

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

CVSS£ºwww.first.org

NVD£ºnvd.nist.gov

 

0x06 ¹ØÓÚ¶«É­Æ½Ì¨

¹Ø×¢ÒÔϹ«ÖںŠ£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png