Microsoft 4Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2021-04-14

0x00 ©¶´¸ÅÊö

2021Äê04ÔÂ13ÈÕ£¬MicrosoftÐû²¼ÁË4Ô·ݵÄÄþ¾²¸üУ¬±¾´ÎÐû²¼µÄÄþ¾²¸üй²¼ÆÐÞ¸´ÁË108¸öÄþ¾²Â©¶´£¬ÆäÖÐÓÐ19¸ö©¶´ÆÀ¼¶ÎªÑÏÖØ£¬89¸ö©¶´ÆÀ¼¶Îª¸ßΣ£¬ÆäÖаüÂÞ5¸ö0 day©¶´ºÍ4¸öMicrosoft Exchange©¶´¡£

 

0x01 ©¶´ÏêÇé

image.png

 

±¾´ÎÐû²¼µÄÄþ¾²¸üÐÂÉæ¼°Azure¡¢Microsoft Edge (Chromium-based)¡¢Exchange Server¡¢Microsoft Office¡¢Windows DNS¡¢Windows Kernel¡¢Windows SMB ServerºÍWindows TCP/IPµÈ¶à¸ö²úÎïºÍ×é¼þ¡£Ä¿Ç°£¬MicrosoftÒѾ­ÐÞ¸´ÁËÒÔÏÂ5¸ö0 day©¶´£¬ÆäÖÐCVE-2021-28310Òѱ»ÔÚÒ°ÀûÓá£

RPC¶ËµãÓ³ÉäÆ÷·þÎñȨÏÞÌáÉý©¶´£¨CVE-2021-27091£©

¸Ã©¶´ÊÇWindows×¢²á±íÖеÄRPCȨÏÞÌáÉý©¶´£¬ÆäCVSSÆÀ·Ö7.8£¬¸Ã©¶´ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓá£

 

Windows NTFS¾Ü¾ø·þÎñ©¶´£¨CVE-2021-28312£©

¸Ã©¶´ÊÇWindows NTFSϵͳÖеľܾø·þÎñ©¶´£¬ÆäCVSSÆÀ·Ö3.3£¬¸Ã©¶´ÐèÓëÓû§½»»¥²Å¿ÉÀûÓá£

 

Windows InstallerÐÅϢй¶©¶´£¨CVE-2021-28437£©

¸Ã©¶´ÊÇWindows Installer¹¤¾ßÖеÄÐÅϢй¶©¶´£¬ÆäCVSSÆÀ·Ö5.5£¬¸Ã©¶´ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓá£

 

Azure ms-rest-nodeauth¿âȨÏÞÌáÉý©¶´£¨CVE-2021-28458£©

¸Ã©¶´ÊÇAzure ms-rest-nodeauth¿âÖеÄȨÏÞÌáÉý©¶´£¬ÆäCVSSÆÀ·Ö7.8£¬¸Ã©¶´ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓá£

 

Win32kȨÏÞÌáÉý©¶´£¨CVE-2021-28310£©

¸Ã©¶´ÊÇWindowsÇý¶¯ÎļþÖеÄȨÏÞÌáÉý©¶´£¬ÆäCVSSÆÀ·Ö7.8£¬¸Ã©¶´ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓá£

 

´ËÍ⣬MicrosoftÒѾ­Ðû²¼ÁË2021Äê4ÔµÄExchange ServerÄþ¾²¸üУ¨ÀÛ»ý¸üУ¬°üÂÞExchange Server 2021Äê3ÔµÄÄþ¾²¸üУ©£¬ÒÔÐÞ¸´NSA·¢ÏÖµÄ4¸öÑÏÖØµÄMicrosoft ExchangeÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬ÕâЩ©¶´Ä¿Ç°ÉÐδ±»ÔÚÒ°ÀûÓá£ÆäÖУ¬CVE-2021-28480ºÍCVE-2021-28481ΪԤÉí·ÝÑé֤©¶´£¬¹¥»÷ÕßÎÞÐè½øÐÐÉí·ÝÑéÖ¤¼´¿ÉÀûÓá£

CVE   ID

ÆÀ·Ö

Ãû³Æ

ÊÇ·ñ½»»¥

Ó°Ï췶Χ

Ó°Ïì°æ±¾

CVE-2021-28480

9.8

Microsoft   Exchange ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´

 

 

ÎÞÐèÓû§½»»¥

Exchange   Server 2013

Exchange   Server 2016

Exchange   Server 2019

Exchange   Server 2013 CU23

Exchange   Server 2016 CU19ºÍCU20

Exchange   Server 2019 CU8ºÍCU9

CVE-2021-28481

9.8

CVE-2021-28482

8.8

CVE-2021-28483

9.0

 

 

0x02 ´¦Öý¨Òé

ĿǰMicrosoftÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨Ò龡¿ìÐÞ¸´¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢ÖØÆô¼ÆËã»ú£¬°²×°¸üÐÂÏµÍ³ÖØÐÂÆô¶¯ºó£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£

 

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/vulnerability

 

0x03 ²Î¿¼Á´½Ó

https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2021-patch-tuesday-fixes-108-flaws-5-zero-days/

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28480

https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2021-exchange-server-security-updates/ba-p/2254617

 

0x04 ʱ¼äÏß

2021-04-13  MicrosoftÐû²¼Äþ¾²¸üÐÂ

2021-04-14  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png