Microsoft 5Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-05-12

0x00 Îó²î¸ÅÊö

2021Äê05ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬£¬MicrosoftÐû²¼ÁË5Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²¸üй²¼ÆÐÞ¸´ÁË55¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ4¸öÎó²îÆÀ¼¶ÎªÑÏÖØ£¬£¬£¬£¬£¬£¬£¬50¸öÎó²îÆÀ¼¶Îª¸ßΣ£¬£¬£¬£¬£¬£¬£¬1¸öÎó²îÆÀ¼¶ÎªÖÐΣ£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨3¸ö0 dayÎó²î¡£¡£¡£¡£ ¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

 

±¾´ÎÐû²¼µÄÇå¾²¸üÐÂÉæ¼°.NET Core & Visual Studio¡¢Internet Explorer¡¢Microsoft Exchange Server¡¢Microsoft Office¡¢Excel¡¢SharePoint¡¢Windows OLE¡¢Windows SMBµÈ¶à¸ö²úÆ·ºÍ×é¼þ¡£¡£¡£¡£ ¡£¡£¡£MicrosoftÒѾ­ÐÞ¸´ÁËÒÔÏÂ3¸ö0 dayÎó²î£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÕâЩÎó²îÉÐδ±»ÔÚҰʹÓᣡ£¡£¡£ ¡£¡£¡£

.NET & Visual StudioȨÏÞÌáÉýÎó²î£¨CVE-2021-31204£©

´ËÎó²îÊÇ.NET ºÍ Visual StudioÖеÄȨÏÞÌáÉýÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.3£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚ´ËÎó²îÒѾ­¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬µ«ÐèÓû§½»»¥²Å¿ÉʹÓᣡ£¡£¡£ ¡£¡£¡£

 

Microsoft Exchange ServerÇå¾²¹¦Ð§ÈƹýÎó²î£¨CVE-2021-31207£©

´ËÎó²îÊÇ2021ÄêPwn2Own¾ºÈüÖз¢Ã÷µÄExchange ServerÎó²îÖ®Ò»£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö6.6£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÒѾ­¹ûÕæÅû¶¡£¡£¡£¡£ ¡£¡£¡£´ËÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓ㬣¬£¬£¬£¬£¬£¬µ«Ê¹ÓÃÖØÆ¯ºóºÍËùÐèȨÏ޽ϸß¡£¡£¡£¡£ ¡£¡£¡£

 

Common UtilitiesÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31200£©

´ËÎó²îÊÇ¿ªÔ´Èí¼þÖÐͨÓÃÊÊÓóÌÐò£¨Neural Network Intelligence¹¤¾ß°ü£©ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.2£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÒѾ­¹ûÕæÅû¶¡£¡£¡£¡£ ¡£¡£¡£´ËÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓ㬣¬£¬£¬£¬£¬£¬µ«ËùÐèȨÏ޽ϸß¡£¡£¡£¡£ ¡£¡£¡£

 

 

±¾´ÎÇå¾²¸üÐÂÐÞ¸´µÄ4¸öÑÏÖØÎó²îΪ£º

HTTPЭÒéÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31166£©

´ËÎó²îÊÇHTTP.sysÖеÄRCEÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.8,δ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓÃHTTPЭÒéÕ»£¨HTTP.sys£©ÏòÄ¿µÄЧÀÍÆ÷·¢ËͶñÒâ¹¹½¨µÄÊý¾Ý°üÀ´´¦Öóͷ£Êý¾Ý°ü¡£¡£¡£¡£ ¡£¡£¡£´ËÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓ㬣¬£¬£¬£¬£¬£¬ÇÒ¹¥»÷ÖØÆ¯ºóºÍËùÐèȨÏ޽ϵÍ¡£¡£¡£¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬´ËÎó²î»¹¿Éµ¼ÖÂÈ䳿²¡¶¾¡£¡£¡£¡£ ¡£¡£¡£

 

¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î£¨CVE-2021-26419£©

´ËÎó²îÊÇInternet ExplorerÖеľ籾ÒýÇæÄÚ´æËð»µÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.5¡£¡£¡£¡£ ¡£¡£¡£´ËÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓ㬣¬£¬£¬£¬£¬£¬µ«¹¥»÷ÖØ´ó½Ï¸ß£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÉÐδ±»Ê¹Óᣡ£¡£¡£ ¡£¡£¡£

 

Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-28476£©

´ËÎó²îÊÇHyper-VÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ9.9£¬£¬£¬£¬£¬£¬£¬´ËÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓ㬣¬£¬£¬£¬£¬£¬ÇÒ¹¥»÷ÖØÆ¯ºóºÍËùÐèȨÏ޽ϵÍ£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÉÐδ±»Ê¹Óᣡ£¡£¡£ ¡£¡£¡£

 

OLE AutomationÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31194£©

´ËÎó²î±£´æÓÚWindows OLEÖУ¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ8.8, ´ËÎó²îÎÞÐèÓû§½»»¥¼´¿ÉʹÓ㬣¬£¬£¬£¬£¬£¬ÇÒ¹¥»÷ÖØÆ¯ºóºÍËùÐèȨÏ޽ϵÍ£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÉÐδ±»Ê¹Óᣡ£¡£¡£ ¡£¡£¡£

 

±ðµÄ£¬£¬£¬£¬£¬£¬£¬±¾´ÎÐû²¼µÄÇå¾²¸üл¹ÐÞ¸´ÁË4¸öMicrosoft Exchange ServerÎó²î£º

CVE-2021-31195£ºMicrosoft Exchange ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©

CVE-2021-31209£ºMicrosoft Exchange ServerÓÕÆ­Îó²î£¨¸ßΣ£©

CVE-2021-31207£ºMicrosoft Exchange ServerÇå¾²¹¦Ð§ÈƹýÎó²î£¨ÖÐΣ£©

CVE-2021-31198£ºMicrosoft Exchange ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨¸ßΣ£©

 

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚMicrosoftÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬½¨Ò龡¿ìÐÞ¸´¡£¡£¡£¡£ ¡£¡£¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£ ¡£¡£¡£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£ ¡£¡£¡£

4¡¢ÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬£¬£¬×°ÖøüÐÂÏµÍ³ÖØÐÂÆô¶¯ºó£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£ ¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£ ¡£¡£¡£

 

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£ ¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/vulnerability

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/vulnerability

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-28476

https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2021-patch-tuesday-fixes-55-flaws-3-zero-days/

 

0x04 ʱ¼äÏß

2021-05-11  MicrosoftÐû²¼Çå¾²¸üÐÂ

2021-05-12  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png