¡¾·ì϶¹«¸æ¡¿Microsoft 1Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-01-13

0x00 ·ì϶¸ÅÊö

2021Äê01ÔÂ12ÈÕÐÇÆÚ¶þ£¬Microsoft°ä²¼ÁË1Ô·ݵݲȫ¸üУ¬±¾´Î°²È«¸üй²¼Æ½¨¸´ÁË83¸ö·ì϶£¬ÆäÖÐÓÐ10¸ö·ì϶ÆÀ¼¶ÎªÑϳÁ£¬73¸ö·ì϶ÆÀ¼¶Îª¸ßΣ£¬ÒÔ¼°Ò»¸ö0day·ì϶¡£

0x01 ·ì϶ÏêÇé

image.png

 

±¾´Î½¨¸´µÄÆëÈ«·ì϶ÁбíÈçÏ£º

CVE ID

CVE±êÌâ

±êÇ©

ÑϳÁˮƽ

CVE-2021-1725

Bot   Framework SDKÐÅϢй¶·ì϶

.NET´æ´¢¿â

¸ßΣ

CVE-2021-1723

ASP.NET   CoreºÍVisual Studio»Ø¾ø·þÎñ·ì϶

ASP.NETÖ÷ÌâºÍ.NETÖ÷Ìâ

¸ßΣ

CVE-2021-1677

Azure   Active Directory PodÉí·ÝºýŪ·ì϶

Azure   Active Directory PodÉí·Ý

¸ßΣ

CVE-2021-1683

WindowsÀ¶ÑÀ°²È«Ö°ÄÜÈÆ¹ý·ì϶

MicrosoftÀ¶ÑÀÇý¶¯·¨Ê½

¸ßΣ

CVE-2021-1638

WindowsÀ¶ÑÀ°²È«Ö°ÄÜÈÆ¹ý·ì϶

MicrosoftÀ¶ÑÀÇý¶¯·¨Ê½

¸ßΣ

CVE-2021-1684

WindowsÀ¶ÑÀ°²È«Ö°ÄÜÈÆ¹ý·ì϶

MicrosoftÀ¶ÑÀÇý¶¯·¨Ê½

¸ßΣ

CVE-2021-1668

Microsoft   DTV-DVDÊÓÆµ½âÂëÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft   DTV-DVDÊÓÆµ½âÂëÆ÷

ÑϳÁ

CVE-2021-1705

Microsoft   Edge£¨»ùÓÚHTML£©µÄÄÚ´æ°Ü»µ·ì϶

Microsoft   Edge£¨»ùÓÚHTML£©

ÑϳÁ

CVE-2021-1709

Windows   Win32kȨÏÞÌáÉý·ì϶

MicrosoftͼÐÎ×é¼þ

¸ßΣ

CVE-2021-1696

WindowsͼÐÎ×é¼þÐÅϢй¶·ì϶

MicrosoftͼÐÎ×é¼þ

¸ßΣ

CVE-2021-1665

GDI   +Ô¶³Ì´úÂëÖ´Ðзì϶

MicrosoftͼÐÎ×é¼þ

ÑϳÁ

CVE-2021-1708

Windows   GDI +ÐÅϢй¶·ì϶

MicrosoftͼÐÎ×é¼þ

¸ßΣ

CVE-2021-1647

Microsoft   DefenderÔ¶³Ì´úÂëÖ´Ðзì϶

Microsoft¶ñÒâÈí¼þ±£»¤ÒýÇæ

ÑϳÁ

CVE-2021-1713

Microsoft   ExcelÔ¶³Ì´úÂëÖ´Ðзì϶

΢Èí°ì¹«Èí¼þ

¸ßΣ

CVE-2021-1714

Microsoft   ExcelÔ¶³Ì´úÂëÖ´Ðзì϶

΢Èí°ì¹«Èí¼þ

¸ßΣ

CVE-2021-1711

Microsoft   OfficeÔ¶³Ì´úÂëÖ´Ðзì϶

΢Èí°ì¹«Èí¼þ

¸ßΣ

CVE-2021-1715

Microsoft   WordÔ¶³Ì´úÂëÖ´Ðзì϶

΢Èí°ì¹«Èí¼þ

¸ßΣ

CVE-2021-1716

Microsoft   WordÔ¶³Ì´úÂëÖ´Ðзì϶

΢Èí°ì¹«Èí¼þ

¸ßΣ

CVE-2021-1712

Microsoft   SharePointȨÏÞÌáÉý·ì϶

Microsoft   Office SharePoint

¸ßΣ

CVE-2021-1707

Microsoft   SharePoint ServerÔ¶³Ì´úÂëÖ´Ðзì϶

Microsoft   Office SharePoint

¸ßΣ

CVE-2021-1718

Microsoft   SharePoint Server´Û¸Ä·ì϶

Microsoft   Office SharePoint

¸ßΣ

CVE-2021-1717

Microsoft   SharePointºýŪ·ì϶

Microsoft   Office SharePoint

¸ßΣ

CVE-2021-1719

Microsoft   SharePointȨÏÞÌáÉý·ì϶

Microsoft   Office SharePoint

¸ßΣ

CVE-2021-1641

Microsoft   SharePointºýŪ·ì϶

Microsoft   Office SharePoint

¸ßΣ

CVE-2021-1702

WindowsÔ¶³Ì¹ý³ÌŲÓÃÔËÐÐʱȨÏÞÌáÉý·ì϶

Microsoft   RPC

¸ßΣ

CVE-2021-1649

»î¶¯Ä£°å¿âȨÏÞÌáÉý·ì϶

΢ÈíWindows

¸ßΣ

CVE-2021-1676

Windows   NT Lan ManagerÊý¾Ý±¨½Ó¹ÜÆ÷Çý¶¯·¨Ê½ÐÅϢй©·ì϶

΢ÈíWindows

¸ßΣ

CVE-2021-1689

Windows¶àµãÖÎÀíȨÏÞÌáÉý·ì϶

΢ÈíWindows

¸ßΣ

CVE-2021-1657

Windows´«Õæ×«Ð´±íµ¥Ô¶³Ì´úÂëÖ´Ðзì϶

΢ÈíWindows

¸ßΣ

CVE-2021-1646

Windows   WLAN·þÎñȨÏÞÌáÉý·ì϶

΢ÈíWindows

¸ßΣ

CVE-2021-1650

Windows   Runtime C ++Ä£°å¿âȨÏÞÌáÉý·ì϶

΢ÈíWindows

¸ßΣ

CVE-2021-1706

Windows   LUAFVȨÏÞÌáÉý·ì϶

΢ÈíWindows

¸ßΣ

CVE-2021-1699

Windows£¨modem.sys£©ÐÅϢй¶·ì϶

΢ÈíWindows

¸ßΣ

CVE-2021-1644

HEVCÊÓÆÂ·©Õ¹Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft   Windows±à½âÂëÆ÷¿â

¸ßΣ

CVE-2021-1643

HEVCÊÓÆÂ·©Õ¹Ô¶³Ì´úÂëÖ´Ðзì϶

Microsoft   Windows±à½âÂëÆ÷¿â

ÑϳÁ

CVE-2021-1637

Windows   DNS²éÎÊÐÅϢй¶·ì϶

Microsoft   Windows DNS

¸ßΣ

CVE-2021-1636

Microsoft   SQLȨÏÞÌáÉý·ì϶

SQL·þÎñÆ÷

¸ßΣ

CVE-2020-26870

Visual   StudioÔ¶³Ì´úÂëÖ´Ðзì϶

ÊÓ¾õ¹¤×÷ÊÒ

¸ßΣ

CVE-2021-1642

Windows   AppX²¿ÊðÀ©´óȨÏÞÌáÉý·ì϶

Windows   AppX²¿ÊðÀ©´ó

¸ßΣ

CVE-2021-1685

Windows   AppX²¿ÊðÀ©´óȨÏÞÌáÉý·ì϶

Windows   AppX²¿ÊðÀ©´ó

¸ßΣ

CVE-2021-1679

Windows   CryptoAPI»Ø¾ø·þÎñ·ì϶

Windows   CryptoAPI

¸ßΣ

CVE-2021-1652

Windows   CSC·þÎñȨÏÞÌáÉý·ì϶

Windows   CSC·þÎñ

¸ßΣ

CVE-2021-1654

Windows   CSC·þÎñȨÏÞÌáÉý·ì϶

Windows   CSC·þÎñ

¸ßΣ

CVE-2021-1659

Windows   CSC·þÎñȨÏÞÌáÉý·ì϶

Windows   CSC·þÎñ

¸ßΣ

CVE-2021-1653

Windows   CSC·þÎñȨÏÞÌáÉý·ì϶

Windows   CSC·þÎñ

¸ßΣ

CVE-2021-1655

Windows   CSC·þÎñȨÏÞÌáÉý·ì϶

Windows   CSC·þÎñ

¸ßΣ

CVE-2021-1693

Windows   CSC·þÎñȨÏÞÌáÉý·ì϶

Windows   CSC·þÎñ

¸ßΣ

CVE-2021-1688

Windows   CSC·þÎñȨÏÞÌáÉý·ì϶

Windows   CSC·þÎñ

¸ßΣ

CVE-2021-1680

Õï¶ÏÖÐÐij߶ÈÍøÂçÆ÷ȨÏÞÌáÉý·ì϶

WindowsÕï¶ÏÖÐÐÄ

¸ßΣ

CVE-2021-1651

Õï¶ÏÖÐÐij߶ÈÍøÂçÆ÷ȨÏÞÌáÉý·ì϶

WindowsÕï¶ÏÖÐÐÄ

¸ßΣ

CVE-2021-1645

Windows   DockerÐÅϢй¶·ì϶

Windows   DP API

¸ßΣ

CVE-2021-1703

WindowsÊÂÎñÈÕÖ¾¼Í¼·þÎñȨÏÞÌáÉý·ì϶

WindowsÊÂÎñ¼Í¼·þÎñ

¸ßΣ

CVE-2021-1662

WindowsÊÂÎñ¸ú×ÙȨÏÞÌáÉý·ì϶

WindowsÊÂÎñ¸ú×Ù

¸ßΣ

CVE-2021-1691

Hyper-V»Ø¾ø·þÎñ·ì϶

Windows   Hyper-V

¸ßΣ

CVE-2021-1704

Windows   Hyper-VȨÏÞÌáÉý·ì϶

Windows   Hyper-V

¸ßΣ

CVE-2021-1692

Hyper-V»Ø¾ø·þÎñ·ì϶

Windows   Hyper-V

¸ßΣ

CVE-2021-1661

Windows   InstallerȨÏÞÌáÉý·ì϶

Windows×°Ö÷¨Ê½

¸ßΣ

CVE-2021-1697

Windows   InstallServiceȨÏÞÌáÉý·ì϶

Windows×°Ö÷¨Ê½

¸ßΣ

CVE-2021-1682

WindowsÄÚºËȨÏÞÌáÉý·ì϶

WindowsÄÚºË

¸ßΣ

CVE-2021-1710

Microsoft   Windows Media FoundationÔ¶³Ì´úÂëÖ´Ðзì϶

WindowsýÌå

¸ßΣ

CVE-2021-1678

NTLM°²È«Ö°ÄÜÈÆ¹ý·ì϶

Windows   NTLM

¸ßΣ

CVE-2021-1695

Windows   Print SpoolerȨÏÞÌáÉý·ì϶

Windows´òÓ¡ºó¶Ü´¦Ö÷¨Ê½×é¼þ

¸ßΣ

CVE-2021-1663

Windows   Projected File System FSɸѡÆ÷Çý¶¯·¨Ê½ÐÅϢй¶·ì϶

WindowsͶӰÎļþϵͳɸѡÆ÷Çý¶¯·¨Ê½

¸ßΣ

CVE-2021-1672

Windows   Projected File System FSɸѡÆ÷Çý¶¯·¨Ê½ÐÅϢй¶·ì϶

WindowsͶӰÎļþϵͳɸѡÆ÷Çý¶¯·¨Ê½

¸ßΣ

CVE-2021-1670

Windows   Projected File System FSɸѡÆ÷Çý¶¯·¨Ê½ÐÅϢй¶·ì϶

WindowsͶӰÎļþϵͳɸѡÆ÷Çý¶¯·¨Ê½

¸ßΣ

CVE-2021-1674

WindowsÔ¶³Ì×ÀÃæºÍ̸Ö÷ÌⰲȫְÄÜÈÆ¹ý·ì϶

WindowsÔ¶³Ì×ÀÃæ

¸ßΣ

CVE-2021-1669

WindowsÔ¶³Ì×ÀÃæ°²È«Ö°ÄÜÈÆ¹ý·ì϶

WindowsÔ¶³Ì×ÀÃæ

¸ßΣ

CVE-2021-1701

Ô¶³Ì¹ý³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´Ðзì϶

WindowsÔ¶³Ì¹ý³ÌŲÓÃÔËÐÐʱ

¸ßΣ

CVE-2021-1700

Ô¶³Ì¹ý³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´Ðзì϶

WindowsÔ¶³Ì¹ý³ÌŲÓÃÔËÐÐʱ

¸ßΣ

CVE-2021-1666

Ô¶³Ì¹ý³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´Ðзì϶

WindowsÔ¶³Ì¹ý³ÌŲÓÃÔËÐÐʱ

ÑϳÁ

CVE-2021-1664

Ô¶³Ì¹ý³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´Ðзì϶

WindowsÔ¶³Ì¹ý³ÌŲÓÃÔËÐÐʱ

¸ßΣ

CVE-2021-1671

Ô¶³Ì¹ý³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´Ðзì϶

WindowsÔ¶³Ì¹ý³ÌŲÓÃÔËÐÐʱ

¸ßΣ

CVE-2021-1673

Ô¶³Ì¹ý³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´Ðзì϶

WindowsÔ¶³Ì¹ý³ÌŲÓÃÔËÐÐʱ

ÑϳÁ

CVE-2021-1658

Ô¶³Ì¹ý³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´Ðзì϶

WindowsÔ¶³Ì¹ý³ÌŲÓÃÔËÐÐʱ

ÑϳÁ

CVE-2021-1667

Ô¶³Ì¹ý³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´Ðзì϶

WindowsÔ¶³Ì¹ý³ÌŲÓÃÔËÐÐʱ

ÑϳÁ

CVE-2021-1660

Ô¶³Ì¹ý³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´Ðзì϶

WindowsÔ¶³Ì¹ý³ÌŲÓÃÔËÐÐʱ

ÑϳÁ

CVE-2021-1648

Microsoft   splwow64ȨÏÞÌáÉý·ì϶

Windows   splwow64

¸ßΣ

CVE-2021-1656

TPMÉ豸Çý¶¯·¨Ê½ÐÅϢй¶·ì϶

Windows   TPMÉ豸Çý¶¯·¨Ê½

¸ßΣ

CVE-2021-1694

Windows   Update²Ö¿âȨÏÞÌáÉý·ì϶

Windows¸üвֿâ

¸ßΣ

CVE-2021-1686

Windows   WalletServiceȨÏÞÌáÉý·ì϶

Windows   WalletService

¸ßΣ

CVE-2021-1681

Windows   WalletServiceȨÏÞÌáÉý·ì϶

Windows   WalletService

¸ßΣ

CVE-2021-1690

Windows   WalletServiceȨÏÞÌáÉý·ì϶

Windows   WalletService

¸ßΣ

CVE-2021-1687

Windows   WalletServiceȨÏÞÌáÉý·ì϶

Windows   WalletService

¸ßΣ

 

²¿ÃÅ·ì϶ÏêÇéÈçÏ£º

Microsoft DefenderÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-1647£©

¸Ã·ì϶ÊÇMicrosoft Defender·À²¡¶¾Èí¼þÖеÄ0day·ì϶£¬´æÔÚÓÚ¶ñÒâÈí¼þ±£»¤ÒýÇæ×é¼þ£¨mpengine.dll£©ÖУ¬ÆäCVSSÆÀ·Ö7.8¡£¸Ã·ì϶ÔÚ²¹¶¡°ä²¼Ö®Ç°¾Í±»¹¥»÷Õß¿í·ºÀûÓá£

Ó°ÏìÁìÓò

1.1.17600.5

½¨¸´°æ±¾

1.1.17700.4

×¢£º¸Ã·ì϶µÄ°²È«¸üн«ÔÚÏνӻ¥ÁªÍøµÄÇé¿öÏÂ×Ô¶¯×°ÖÃÔÚÔËÐÐÊÜÓ°ÏìMicrosoft DefenderµÄϵͳÉÏ£¬ÎÞÐèÊÖ¶¯Ö´ÐС£

 

Microsoft splwow64ȨÏÞÌáÉý·ì϶£¨CVE-2021-1648£©

¸Ã·ì϶ÊÇWindows´òÓ¡Çý¶¯·¨Ê½¹ý³ÌSPLWOW64.exeÖеÄȨÏÞÌáÉý·ì϶£¬ÆäCVSSÆÀ·Ö7.8¡£¸Ã·ì϶×îÔçÓÉGoogle·¢ÏÖ²¢½¨¸´£¬µ«ÓÉÓÚ²¹¶¡·¨Ê½²»ÆëÈ«£¬Òò¶øÎª½øÒ»²½µ¼ÖÂÁ˸÷ì϶¡£

SPLWOW64.exeÊÇÔÚ64λWindows²Ù×÷ϵͳÉÏʹÓÃ32λ´òÓ¡»úÇý¶¯·¨Ê½Ê±ÔËÐеÄWindows¹ý³Ì¡£·¢ËÍ´òÓ¡×÷ҵʱ»áÖ´Ðд˹ý³Ì£¬²¢ÇÒÓÐʱÔÚʵÏÖ×÷Òµºó¸Ã¹ý³Ì»áÎÞ·¨ÕýÈ·¹Ø¹Ø¡£

µ±SPLWOW64.exe¹ý³ÌûÓÐÕýÈ·ÖÕֹʱ£¬»á²úÉúÄÚ´æÐ¹Â¶£¬½«ÑϳÁÓ°Ïì·þÎñÆ÷»ò×ÀÃæ×ÊÔ´µÄ»úÄܺͿÉÓÃÐÔ¡£

image.png

Ó°ÏìÁìÓò

Windows 10 Version 20H2 for ARM64-based Systems

Windows 10 Version 20H2 for 32-bit Systems

Windows Server, version 20H2 (Server Core Installation)

Windows 10 Version 20H2 for x64-based Systems

Windows Server 2012 R2 (Server Core installation)

Windows Server 2012 R2

Windows Server 2012 (Server Core installation)

Windows Server 2012

Windows RT 8.1

Windows 8.1 for x64-based systems

Windows 8.1 for 32-bit systems

Windows Server 2016 (Server Core installation)

Windows Server 2016

Windows 10 Version 1607 for x64-based Systems

Windows 10 Version 1607 for 32-bit Systems

Windows 10 for x64-based Systems

Windows 10 for 32-bit Systems

Windows Server, version 2004 (Server Core installation)

Windows 10 Version 2004 for x64-based Systems

Windows 10 Version 2004 for ARM64-based Systems

Windows 10 Version 2004 for 32-bit Systems

Windows Server, version 1909 (Server Core installation)

Windows 10 Version 1909 for ARM64-based Systems

Windows 10 Version 1909 for x64-based Systems

Windows 10 Version 1909 for 32-bit Systems

Windows Server 2019 (Server Core installation)

Windows Server 2019

Windows 10 Version 1809 for ARM64-based Systems

Windows 10 Version 1809 for x64-based Systems

Windows 10 Version 1809 for 32-bit Systems

Windows 10 Version 1803 for ARM64-based Systems

Windows 10 Version 1803 for x64-based Systems

Windows 10 Version 1803 for 32-bit Systems

 

0x02 ´ëÖý¨Òé

ĿǰMicrosoftÒѰ䲼Óйذ²È«¸üУ¬½¨ÒéʵʱװÖò¹¶¡¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС±£¬ÆÚ´ýϵͳ½«×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüС£

4¡¢³ÁÆôÍÆËã»ú£¬×°ÖøüÐÂϵͳ³ÁÐÂÆô¶¯ºó£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£

 

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

΢Èí¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-1647

https://goliathtechnologies.com/troubleshoot-resolve-citrix-splwow64-exe-issues-p/

https://threatpost.com/critical-microsoft-defender-bug-exploited/162992/

https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2021-patch-tuesday-fixes-83-flaws-1-zero-day/

https://www.bleepingcomputer.com/news/security/microsoft-patches-defender-antivirus-zero-day-exploited-in-the-wild/

 

0x04 ¹¦·òÏß

2021-01-12  Microsoft°ä²¼°²È«¸üÐÂ

2021-01-13  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png