Microsoft 5Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-05-12

0x00 ·ì϶¸ÅÊö

2021Äê05ÔÂ11ÈÕ £¬Microsoft°ä²¼ÁË5Ô·ݵݲȫ¸üР£¬±¾´Î°ä²¼µÄ°²È«¸üй²¼Æ½¨¸´ÁË55¸ö°²È«·ì϶ £¬ÆäÖÐÓÐ4¸ö·ì϶ÆÀ¼¶ÎªÑϳÁ £¬50¸ö·ì϶ÆÀ¼¶Îª¸ßΣ £¬1¸ö·ì϶ÆÀ¼¶ÎªÖÐΣ £¬ÆäÖÐÔ̺¬3¸ö0 day·ì϶¡£

 

0x01 ·ì϶ÏêÇé

image.png

 

±¾´Î°ä²¼µÄ°²È«¸üÐÂÉæ¼°.NET Core & Visual Studio¡¢Internet Explorer¡¢Microsoft Exchange Server¡¢Microsoft Office¡¢Excel¡¢SharePoint¡¢Windows OLE¡¢Windows SMBµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£MicrosoftÒѾ­½¨¸´ÁËÒÔÏÂ3¸ö0 day·ì϶ £¬Ä¿Ç°ÕâЩ·ì϶ÉÐδ±»ÔÚÒ°ÀûÓá£

.NET & Visual StudioȨÏÞÌáÉý·ì϶£¨CVE-2021-31204£©

´Ë·ì϶ÊÇ.NET ºÍ Visual StudioÖеÄȨÏÞÌáÉý·ì϶ £¬ÆäCVSSÆÀ·Ö7.3 £¬Ä¿Ç°´Ë·ì϶ÒѾ­¹«¿ªÅû¶ £¬µ«ÐèÓû§½»»¥²Å¿ÉÀûÓá£

 

Microsoft Exchange Server°²È«Ö°ÄÜÈÆ¹ý·ì϶£¨CVE-2021-31207£©

´Ë·ì϶ÊÇ2021ÄêPwn2Own½ÏÁ¿Öз¢ÏÖµÄExchange Server·ì϶֮һ £¬ÆäCVSSÆÀ·Ö6.6 £¬Ä¿Ç°ÒѾ­¹«¿ªÅû¶¡£´Ë·ì϶ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓà £¬µ«ÀûÓø´ÔӶȺÍËùÐèȨÏ޽ϸß¡£

 

Common UtilitiesÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-31200£©

´Ë·ì϶ÊÇ¿ªÔ´Èí¼þÖÐͨÓÃʵÓ÷¨Ê½£¨Neural Network Intelligence¹¤¾ß°ü£©ÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶ £¬ÆäCVSSÆÀ·Ö7.2 £¬Ä¿Ç°ÒѾ­¹«¿ªÅû¶¡£´Ë·ì϶ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓà £¬µ«ËùÐèȨÏ޽ϸß¡£

 

 

±¾´Î°²È«¸üн¨¸´µÄ4¸öÑϳÁ·ì϶Ϊ£º

HTTPºÍ̸ջԶ³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-31166£©

´Ë·ì϶ÊÇHTTP.sysÖеÄRCE·ì϶ £¬ÆäCVSSÆÀ·ÖΪ9.8,δ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓÃHTTPºÍ̸ջ£¨HTTP.sys£©ÏòÖ¸±ê·þÎñÆ÷·¢ËͶñÒâ¹¹½¨µÄÊý¾Ý°üÀ´´¦ÖÃÊý¾Ý°ü¡£´Ë·ì϶ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓà £¬ÇÒ¹¥»÷¸´ÔӶȺÍËùÐèȨÏ޽ϵÍ¡£´Ë±í £¬´Ë·ì϶»¹¿Éµ¼ÖÂÈ䳿²¡¶¾¡£

 

¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-26419£©

´Ë·ì϶ÊÇInternet ExplorerÖеľ籾ÒýÇæÄÚ´æ°Ü»µ·ì϶ £¬ÆäCVSSÆÀ·ÖΪ7.5¡£´Ë·ì϶ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓà £¬µ«¹¥»÷¸´Ôӽϸß £¬Ä¿Ç°ÉÐδ±»ÀûÓá£

 

Hyper-VÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-28476£©

´Ë·ì϶ÊÇHyper-VÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶ £¬ÆäCVSSÆÀ·ÖΪ9.9 £¬´Ë·ì϶ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓà £¬ÇÒ¹¥»÷¸´ÔӶȺÍËùÐèȨÏ޽ϵÍ £¬Ä¿Ç°ÉÐδ±»ÀûÓá£

 

OLE AutomationÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-31194£©

´Ë·ì϶´æÔÚÓÚWindows OLEÖÐ £¬ÆäCVSSÆÀ·ÖΪ8.8, ´Ë·ì϶ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓà £¬ÇÒ¹¥»÷¸´ÔӶȺÍËùÐèȨÏ޽ϵÍ £¬Ä¿Ç°ÉÐδ±»ÀûÓá£

 

´Ë±í £¬±¾´Î°ä²¼µÄ°²È«¸üл¹½¨¸´ÁË4¸öMicrosoft Exchange Server·ì϶£º

CVE-2021-31195£ºMicrosoft Exchange ServerÔ¶³Ì´úÂëÖ´Ðзì϶£¨¸ßΣ£©

CVE-2021-31209£ºMicrosoft Exchange ServerºýŪ·ì϶£¨¸ßΣ£©

CVE-2021-31207£ºMicrosoft Exchange Server°²È«Ö°ÄÜÈÆ¹ý·ì϶£¨ÖÐΣ£©

CVE-2021-31198£ºMicrosoft Exchange ServerÔ¶³Ì´úÂëÖ´Ðзì϶£¨¸ßΣ£©

 

 

0x02 ´ëÖý¨Òé

ĿǰMicrosoftÒѰ䲼Óйذ²È«¸üР£¬½¨Ò龡¿ì½¨¸´¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓà £¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ £¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü £¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡± £¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС± £¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС± £¬ÆÚ´ýϵͳ½«×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüС£

4¡¢³ÁÆôÍÆËã»ú £¬×°ÖøüÐÂϵͳ³ÁÐÂÆô¶¯ºó £¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüР£¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó £¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡± £¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£

 

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/vulnerability

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/vulnerability

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-28476

https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2021-patch-tuesday-fixes-55-flaws-3-zero-days/

 

0x04 ¹¦·òÏß

2021-05-11  Microsoft°ä²¼°²È«¸üÐÂ

2021-05-12  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png