Microsoft 5Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2021-05-12

0x00 ©¶´¸ÅÊö

2021Äê05ÔÂ11ÈÕ£¬MicrosoftÐû²¼ÁË5Ô·ݵÄÄþ¾²¸üУ¬±¾´ÎÐû²¼µÄÄþ¾²¸üй²¼ÆÐÞ¸´ÁË55¸öÄþ¾²Â©¶´£¬ÆäÖÐÓÐ4¸ö©¶´ÆÀ¼¶ÎªÑÏÖØ£¬50¸ö©¶´ÆÀ¼¶Îª¸ßΣ£¬1¸ö©¶´ÆÀ¼¶ÎªÖÐΣ£¬ÆäÖаüÂÞ3¸ö0 day©¶´¡£

 

0x01 ©¶´ÏêÇé

image.png

 

±¾´ÎÐû²¼µÄÄþ¾²¸üÐÂÉæ¼°.NET Core & Visual Studio¡¢Internet Explorer¡¢Microsoft Exchange Server¡¢Microsoft Office¡¢Excel¡¢SharePoint¡¢Windows OLE¡¢Windows SMBµÈ¶à¸ö²úÎïºÍ×é¼þ¡£MicrosoftÒѾ­ÐÞ¸´ÁËÒÔÏÂ3¸ö0 day©¶´£¬Ä¿Ç°ÕâЩ©¶´ÉÐδ±»ÔÚÒ°ÀûÓá£

.NET & Visual StudioȨÏÞÌáÉý©¶´£¨CVE-2021-31204£©

´Ë©¶´ÊÇ.NET ºÍ Visual StudioÖеÄȨÏÞÌáÉý©¶´£¬ÆäCVSSÆÀ·Ö7.3£¬Ä¿Ç°´Ë©¶´ÒѾ­¹ûÈ»Åû¶£¬µ«ÐèÓû§½»»¥²Å¿ÉÀûÓá£

 

Microsoft Exchange ServerÄþ¾²¹¦Ð§Èƹý©¶´£¨CVE-2021-31207£©

´Ë©¶´ÊÇ2021ÄêPwn2Own¾ºÈüÖз¢ÏÖµÄExchange Server©¶´Ö®Ò»£¬ÆäCVSSÆÀ·Ö6.6£¬Ä¿Ç°ÒѾ­¹ûÈ»Åû¶¡£´Ë©¶´ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓ㬵«ÀûÓÃÅÓ´ó¶ÈºÍËùÐèȨÏ޽ϸß¡£

 

Common UtilitiesÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-31200£©

´Ë©¶´ÊÇ¿ªÔ´Èí¼þÖÐͨÓÃʵÓ÷¨Ê½£¨Neural Network Intelligence¹¤¾ß°ü£©ÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬ÆäCVSSÆÀ·Ö7.2£¬Ä¿Ç°ÒѾ­¹ûÈ»Åû¶¡£´Ë©¶´ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓ㬵«ËùÐèȨÏ޽ϸß¡£

 

 

±¾´ÎÄþ¾²¸üÐÂÐÞ¸´µÄ4¸öÑÏÖØÂ©¶´Îª£º

HTTPЭÒéÕ»Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-31166£©

´Ë©¶´ÊÇHTTP.sysÖеÄRCE©¶´£¬ÆäCVSSÆÀ·ÖΪ9.8,δ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÀûÓÃHTTPЭÒéÕ»£¨HTTP.sys£©ÏòÄ¿±ê·þÎñÆ÷·¢ËͶñÒâ¹¹½¨µÄÊý¾Ý°üÀ´´¦ÖÃÊý¾Ý°ü¡£´Ë©¶´ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓã¬ÇÒ¹¥»÷ÅÓ´ó¶ÈºÍËùÐèȨÏ޽ϵÍ¡£´ËÍ⣬´Ë©¶´»¹¿Éµ¼ÖÂÈ䳿²¡¶¾¡£

 

½Å±¾ÒýÇæÄÚ´æËð»µÂ©¶´£¨CVE-2021-26419£©

´Ë©¶´ÊÇInternet ExplorerÖеĽű¾ÒýÇæÄÚ´æËð»µÂ©¶´£¬ÆäCVSSÆÀ·ÖΪ7.5¡£´Ë©¶´ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓ㬵«¹¥»÷ÅÓ´ó½Ï¸ß£¬Ä¿Ç°ÉÐδ±»ÀûÓá£

 

Hyper-VÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-28476£©

´Ë©¶´ÊÇHyper-VÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬ÆäCVSSÆÀ·ÖΪ9.9£¬´Ë©¶´ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓã¬ÇÒ¹¥»÷ÅÓ´ó¶ÈºÍËùÐèȨÏ޽ϵÍ£¬Ä¿Ç°ÉÐδ±»ÀûÓá£

 

OLE AutomationÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-31194£©

´Ë©¶´´æÔÚÓÚWindows OLEÖУ¬ÆäCVSSÆÀ·ÖΪ8.8, ´Ë©¶´ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓã¬ÇÒ¹¥»÷ÅÓ´ó¶ÈºÍËùÐèȨÏ޽ϵÍ£¬Ä¿Ç°ÉÐδ±»ÀûÓá£

 

´ËÍ⣬±¾´ÎÐû²¼µÄÄþ¾²¸üл¹ÐÞ¸´ÁË4¸öMicrosoft Exchange Server©¶´£º

CVE-2021-31195£ºMicrosoft Exchange ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨¸ßΣ£©

CVE-2021-31209£ºMicrosoft Exchange ServerÆÛƭ©¶´£¨¸ßΣ£©

CVE-2021-31207£ºMicrosoft Exchange ServerÄþ¾²¹¦Ð§Èƹý©¶´£¨ÖÐΣ£©

CVE-2021-31198£ºMicrosoft Exchange ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨¸ßΣ£©

 

 

0x02 ´¦Öý¨Òé

ĿǰMicrosoftÒÑÐû²¼Ïà¹ØÄþ¾²¸üУ¬½¨Ò龡¿ìÐÞ¸´¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±°²×°¡£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°¿ªÊ¼²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÄþ¾²¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÄþ¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£

4¡¢ÖØÆô¼ÆËã»ú£¬°²×°¸üÐÂÏµÍ³ÖØÐÂÆô¶¯ºó£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°¼ì²ì¸üÐÂÀúÊ·¼Ç¼¡±¼ì²ìÊÇ·ñÀֳɰ²×°Á˸üС£¶ÔÓÚûÓÐÀֳɰ²×°µÄ¸üУ¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢°²×°¡£

 

£¨¶þ£© ÊÖ¶¯°²×°¸üÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/vulnerability

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/vulnerability

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-28476

https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2021-patch-tuesday-fixes-55-flaws-3-zero-days/

 

0x04 ʱ¼äÏß

2021-05-11  MicrosoftÐû²¼Äþ¾²¸üÐÂ

2021-05-12  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png