Microsoft 4Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-04-14

0x00 Îó²î¸ÅÊö

2021Äê04ÔÂ13ÈÕ£¬£¬£¬ £¬£¬£¬£¬MicrosoftÐû²¼ÁË4Ô·ݵÄÇå¾²¸üУ¬£¬£¬ £¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²¸üй²¼ÆÐÞ¸´ÁË108¸öÇå¾²Îó²î£¬£¬£¬ £¬£¬£¬£¬ÆäÖÐÓÐ19¸öÎó²îÆÀ¼¶ÎªÑÏÖØ£¬£¬£¬ £¬£¬£¬£¬89¸öÎó²îÆÀ¼¶Îª¸ßΣ£¬£¬£¬ £¬£¬£¬£¬ÆäÖаüÀ¨5¸ö0 dayÎó²îºÍ4¸öMicrosoft ExchangeÎó²î¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

 

±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÉæ¼°Azure¡¢Microsoft Edge (Chromium-based)¡¢Exchange Server¡¢Microsoft Office¡¢Windows DNS¡¢Windows Kernel¡¢Windows SMB ServerºÍWindows TCP/IPµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬ £¬£¬£¬£¬MicrosoftÒѾ­ÐÞ¸´ÁËÒÔÏÂ5¸ö0 dayÎó²î£¬£¬£¬ £¬£¬£¬£¬ÆäÖÐCVE-2021-28310Òѱ»ÔÚҰʹÓᣡ£¡£¡£¡£

RPC¶ËµãÓ³ÉäÆ÷ЧÀÍȨÏÞÌáÉýÎó²î£¨CVE-2021-27091£©

¸ÃÎó²îÊÇWindows×¢²á±íÖеÄRPCȨÏÞÌáÉýÎó²î£¬£¬£¬ £¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.8£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓᣡ£¡£¡£¡£

 

Windows NTFS¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2021-28312£©

¸ÃÎó²îÊÇWindows NTFSϵͳÖеľܾøÐ§ÀÍÎó²î£¬£¬£¬ £¬£¬£¬£¬ÆäCVSSÆÀ·Ö3.3£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÐèÓëÓû§½»»¥²Å¿ÉʹÓᣡ£¡£¡£¡£

 

Windows InstallerÐÅϢй¶Îó²î£¨CVE-2021-28437£©

¸ÃÎó²îÊÇWindows Installer¹¤¾ßÖеÄÐÅϢй¶Îó²î£¬£¬£¬ £¬£¬£¬£¬ÆäCVSSÆÀ·Ö5.5£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓᣡ£¡£¡£¡£

 

Azure ms-rest-nodeauth¿âȨÏÞÌáÉýÎó²î£¨CVE-2021-28458£©

¸ÃÎó²îÊÇAzure ms-rest-nodeauth¿âÖеÄȨÏÞÌáÉýÎó²î£¬£¬£¬ £¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.8£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓᣡ£¡£¡£¡£

 

Win32kȨÏÞÌáÉýÎó²î£¨CVE-2021-28310£©

¸ÃÎó²îÊÇWindowsÇý¶¯ÎļþÖеÄȨÏÞÌáÉýÎó²î£¬£¬£¬ £¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.8£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓᣡ£¡£¡£¡£

 

±ðµÄ£¬£¬£¬ £¬£¬£¬£¬MicrosoftÒѾ­Ðû²¼ÁË2021Äê4ÔµÄExchange ServerÇå¾²¸üУ¨ÀÛ»ý¸üУ¬£¬£¬ £¬£¬£¬£¬°üÀ¨Exchange Server 2021Äê3ÔµÄÇå¾²¸üУ©£¬£¬£¬ £¬£¬£¬£¬ÒÔÐÞ¸´NSA·¢Ã÷µÄ4¸öÑÏÖØµÄMicrosoft ExchangeÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬ £¬£¬£¬£¬ÕâЩÎó²îÏÖÔÚÉÐδ±»ÔÚҰʹÓᣡ£¡£¡£¡£ÆäÖУ¬£¬£¬ £¬£¬£¬£¬CVE-2021-28480ºÍCVE-2021-28481ΪԤÉí·ÝÑéÖ¤Îó²î£¬£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßÎÞÐè¾ÙÐÐÉí·ÝÑéÖ¤¼´¿ÉʹÓᣡ£¡£¡£¡£

CVE   ID

ÆÀ·Ö

Ãû³Æ

ÊÇ·ñ½»»¥

Ó°Ïì¹æÄ£

Ó°Ïì°æ±¾

CVE-2021-28480

9.8

Microsoft   Exchange ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î

 

 

ÎÞÐèÓû§½»»¥

Exchange   Server 2013

Exchange   Server 2016

Exchange   Server 2019

Exchange   Server 2013 CU23

Exchange   Server 2016 CU19ºÍCU20

Exchange   Server 2019 CU8ºÍCU9

CVE-2021-28481

9.8

CVE-2021-28482

8.8

CVE-2021-28483

9.0

 

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚMicrosoftÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬ £¬£¬£¬£¬½¨Ò龡¿ìÐÞ¸´¡£¡£¡£¡£¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬣¬£¬ £¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬ £¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£¡£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬ £¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬ £¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬ £¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬ £¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£¡£

4¡¢ÖØÆôÅÌËã»ú£¬£¬£¬ £¬£¬£¬£¬×°ÖøüÐÂÏµÍ³ÖØÐÂÆô¶¯ºó£¬£¬£¬ £¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬ £¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬ £¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬ £¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£¡£

 

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/vulnerability

 

0x03 ²Î¿¼Á´½Ó

https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2021-patch-tuesday-fixes-108-flaws-5-zero-days/

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28480

https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2021-exchange-server-security-updates/ba-p/2254617

 

0x04 ʱ¼äÏß

2021-04-13  MicrosoftÐû²¼Çå¾²¸üÐÂ

2021-04-14  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png