Microsoft 3Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-03-10

0x00 ·ì϶¸ÅÊö

2021Äê03ÔÂ09ÈÕ£¬Microsoft°ä²¼ÁË3Ô·ݵݲȫ¸üУ¬¹²¼Æ½¨¸´ÁË122¸ö°²È«·ì϶£¬ÆäÖÐÓÐ14¸ö·ì϶ÆÀ¼¶ÎªÑϳÁ£¬75¸ö·ì϶ÆÀ¼¶Îª¸ßΣ£¬ÆäÖÐÔ̺¬2¸ö0 day·ì϶¡£

 

0x01 ·ì϶ÏêÇé

image.png 

±¾´Î°ä²¼µÄ²¹¶¡º­¸ÇÁËWindowsϵͳ¡¢Azure¡¢Exchange Server¡¢Office¡¢SharePoint Server¡¢Visual Studio¡¢Hyper-V¡¢IEºÍEdge£¬3ÔÂÆëÈ«·ì϶ÁбíÈçÏ£º

±êÇ©

CVE   ID

CVE±êÌâ

ÑϳÁˮƽ

Application   Virtualization

CVE-2021-26890

ÀûÓ÷¨Ê½Ðé¹¹»¯Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Azure

CVE-2021-27075

AzureÐé¹¹»úÐÅϢй¶·ì϶

¸ßΣ

Azure   Sphere

CVE-2021-27074

Azure   SphereδÊðÃû´úÂëÖ´Ðзì϶

ÑϳÁ

Azure   Sphere

CVE-2021-27080

Azure   SphereδÊðÃû´úÂëÖ´Ðзì϶

ÑϳÁ

Internet   Explorer

CVE-2021-27085

Internet   ExplorerÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Internet   Explorer

CVE-2021-26411

Internet   ExplorerÄÚ´æ°Ü»µ·ì϶

ÑϳÁ

Microsoft   ActiveX

CVE-2021-26869

Windows   ActiveX×°Ö÷¨Ê½·þÎñÐÅϢй¶·ì϶

¸ßΣ

Microsoft   Edge on Chromium

CVE-2021-21173

Chromium   CVE-2021-21173£ºÍøÂçÄÚ²¿µÄ²àͨ·ÐÅϢй©

δ֪

Microsoft   Edge on Chromium

CVE-2021-21172

Chromium   CVE-2021-21172£ºÎļþϵͳAPIÖеÄÕ½ÊõÖ´Ðв»¼°

δ֪

Microsoft   Edge on Chromium

CVE-2021-21169

Chromium   CVE-2021-21169£ºV8ÖеÄÔ½½çÄÚ´æ½Ó¼û

δ֪

Microsoft   Edge on Chromium

CVE-2021-21170

Chromium   CVE-2021-21170£º¼ÓÔØ·¨Ê½ÖеݲȫÐÔUI²»ÕýÈ·

δ֪

Microsoft   Edge on Chromium

CVE-2021-21171

Chromium   CVE-2021-21171£ºTabStripºÍµ¼º½ÖеݲȫÐÔUI²»ÕýÈ·

δ֪

Microsoft   Edge on Chromium

CVE-2021-21175

Chromium   CVE-2021-21175£ºÕ¾µã¸ôÀëÖеÄÖ´Ðв»µ±

δ֪

Microsoft   Edge on Chromium

CVE-2021-21176

Chromium   CVE-2021-21176£ºÔÚÈ«ÆÁģʽÏÂÖ´Ðв»µ±

δ֪

Microsoft   Edge on Chromium

CVE-2021-21177

Chromium   CVE-2021-21177£º×Ô¶¯Ìî³äÖеÄÕ½ÊõÖ´Ðв»¼°

δ֪

Microsoft   Edge on Chromium

CVE-2021-21174

Chromium   CVE-2021-21174£ºÔÚReferrerÖÐÖ´Ðв»µ±

δ֪

Microsoft   Edge on Chromium

CVE-2021-21178

Chromium   CVE-2021-21178£ºÔںϳÉÖÐÖ´Ðв»µ±

δ֪

Microsoft   Edge on Chromium

CVE-2021-21161

Chromium   CVE-2021-21161£ºTabStripÖеĶѻº³åÇøÒç³ö

δ֪

Microsoft   Edge on Chromium

CVE-2021-21162

Chromium   CVE-2021-21162£ºÔÚWebRTCÖÐUse-after-free

δ֪

Microsoft   Edge on Chromium

CVE-2021-21160

Chromium   CVE-2021-21160£ºWebAudioÖеĶѻº³åÇøÒç³ö

δ֪

Microsoft   Edge on Chromium

CVE-2020-27844

Chromium   CVE-2020-27844£ºOpenJPEGÖеĶѻº³åÇøÒç³ö

δ֪

Microsoft   Edge on Chromium

CVE-2021-21159

Chromium   CVE-2021-21159£ºTabStripÖеĶѻº³åÇøÒç³ö

δ֪

Microsoft   Edge on Chromium

CVE-2021-21163

Chromium   CVE-2021-21163£ºÔÚÔĶÁÆ÷ģʽÏÂÊý¾ÝÑéÖ¤²»¼°

δ֪

Microsoft   Edge on Chromium

CVE-2021-21167

Chromium   CVE-2021-21167£ºÔÚÊéÇ©ÖÐUse-after-free

δ֪

Microsoft   Edge on Chromium

CVE-2021-21168

Chromium   CVE-2021-21168£ºappcacheÖеÄÕ½ÊõÖ´Ðв»¼°

δ֪

Microsoft   Edge on Chromium

CVE-2021-21166

Chromium   CVE-2021-21166£ºÒôƵÖеĶÔÏóÐÔÃüÖÜÆÚÎÊÌâ

δ֪

Microsoft   Edge on Chromium

CVE-2021-21164

Chromium   CVE-2021-21164£ºChromeÖеÄiOSÊý¾ÝÑéÖ¤²»¼°

δ֪

Microsoft   Edge on Chromium

CVE-2021-21165

Chromium   CVE-2021-21165£ºÒôƵÖеĶÔÏóÐÔÃüÖÜÆÚÎÊÌâ

δ֪

Microsoft   Edge on Chromium

CVE-2021-21189

Chromium   CVE-2021-21189£º¸¶¿îÖеÄÕþ²ßÖ´Ðв»¼°

δ֪

Microsoft   Edge on Chromium

CVE-2021-21181

Chromium   CVE-2021-21181£º×Ô¶¯Ìî³äÖеIJàͨ·ÐÅϢй©

δ֪

Microsoft   Edge on Chromium

CVE-2021-21186

Chromium   CVE-2021-21186£ºQRɨÃèÖеÄÕ½ÊõÖ´Ðв»¼°

δ֪

Microsoft   Edge on Chromium

CVE-2021-21190

Chromium   CVE-2021-21190£ºÔÚPDFiumÖÐδ³õʼ»¯Ê¹ÓÃ

δ֪

Microsoft   Edge on Chromium

CVE-2021-21183

Chromium   CVE-2021-21183£º»úÄÜAPIÖеÄʵÏÖ²»µ±

δ֪

Microsoft   Edge on Chromium

CVE-2021-21185

Chromium   CVE-2021-21185£ºÀ©´óÖеÄÕ½ÊõÖ´Ðв»¼°

δ֪

Microsoft   Edge on Chromium

CVE-2021-21187

Chromium   CVE-2021-21187£ºURLÌåʽÖеÄÊý¾ÝÑéÖ¤²»¼°

δ֪

Microsoft   Edge on Chromium

CVE-2021-21182

Chromium   CVE-2021-21182£ºµ¼º½ÖеÄÕ½ÊõÖ´Ðв»¼°

δ֪

Microsoft   Edge on Chromium

CVE-2021-21180

Chromium   CVE-2021-21180£ºÔÚ±êÇ©ËÑË÷ÖÐUse-after-free

δ֪

Microsoft   Edge on Chromium

CVE-2021-21184

Chromium   CVE-2021-21184£º»úÄÜAPIÖеÄʵÏÖ²»µ±

δ֪

Microsoft   Edge on Chromium

CVE-2021-21179

Chromium   CVE-2021-21179£ºÔÚÍøÂçÄÚ²¿Use-after-free

δ֪

Microsoft   Edge on Chromium

CVE-2021-21188

Chromium   CVE-2021-21188£ºÔÚBlinkÖÐUse-after-free

δ֪

Microsoft   Exchange Server

CVE-2021-26412

Microsoft   Exchange ServerÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

Microsoft   Exchange Server

CVE-2021-27065

Microsoft   Exchange ServerÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

Microsoft   Exchange Server

CVE-2021-27078

Microsoft   Exchange ServerÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Exchange Server

CVE-2021-26854

Microsoft   Exchange ServerÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Exchange Server

CVE-2021-26857

Microsoft   Exchange ServerÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

Microsoft   Exchange Server

CVE-2021-26855

Microsoft   Exchange ServerÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

Microsoft   Exchange Server

CVE-2021-26858

Microsoft   Exchange ServerÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Graphics Component

CVE-2021-26863

Windows   Win32kȨÏÞÌáÉý·ì϶

¸ßΣ

Microsoft   Graphics Component

CVE-2021-27077

Windows   Win32kȨÏÞÌáÉý·ì϶

¸ßΣ

Microsoft   Graphics Component

CVE-2021-26861

WindowsͼÐÎ×é¼þÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Graphics Component

CVE-2021-26876

OpenType×ÖÌå½âÎöÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

Microsoft   Graphics Component

CVE-2021-26875

Windows   Win32kȨÏÞÌáÉý·ì϶

¸ßΣ

Microsoft   Graphics Component

CVE-2021-26868

WindowsͼÐÎ×é¼þȨÏÞÌáÉý·ì϶

¸ßΣ

Microsoft   Office

CVE-2021-24108

Microsoft   OfficeÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Office

CVE-2021-27058

Microsoft   Office ClickToRunÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Office

CVE-2021-27059

Microsoft   OfficeÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Office Excel

CVE-2021-27053

Microsoft   ExcelÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Office Excel

CVE-2021-27054

Microsoft   ExcelÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Office Excel

CVE-2021-27057

Microsoft   OfficeÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Office PowerPoint

CVE-2021-27056

Microsoft   PowerPointÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Office SharePoint

CVE-2021-27052

Microsoft   SharePoint ServerÐÅϢй¶·ì϶

¸ßΣ

Microsoft   Office SharePoint

CVE-2021-24104

Microsoft   SharePointºýŪ·ì϶

¸ßΣ

Microsoft   Office SharePoint

CVE-2021-27076

Microsoft   SharePoint ServerÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Office Visio

CVE-2021-27055

Microsoft   Visio°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

Microsoft   Windows Codecs Library

CVE-2021-27050

HEVCÊÓÆÂ·©Õ¹Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Windows Codecs Library

CVE-2021-27049

HEVCÊÓÆÂ·©Õ¹Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Windows Codecs Library

CVE-2021-26884

Windows   MediaÕÕÆ¬±à½âÂëÆ÷ÐÅϢй¶·ì϶

¸ßΣ

Microsoft   Windows Codecs Library

CVE-2021-27051

HEVCÊÓÆÂ·©Õ¹Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Windows Codecs Library

CVE-2021-27062

HEVCÊÓÆÂ·©Õ¹Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Windows Codecs Library

CVE-2021-24110

HEVCÊÓÆÂ·©Õ¹Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Windows Codecs Library

CVE-2021-24089

HEVCÊÓÆÂ·©Õ¹Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

Microsoft   Windows Codecs Library

CVE-2021-27061

HEVCÊÓÆÂ·©Õ¹Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

Microsoft   Windows Codecs Library

CVE-2021-27048

HEVCÊÓÆÂ·©Õ¹Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Windows Codecs Library

CVE-2021-27047

HEVCÊÓÆÂ·©Õ¹Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Windows Codecs Library

CVE-2021-26902

HEVCÊÓÆÂ·©Õ¹Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

Power   BI

CVE-2021-26859

Microsoft   Power BIÐÅϢй¶·ì϶

¸ßΣ

Role:   DNS Server

CVE-2021-27063

Windows   DNS·þÎñÆ÷»Ø¾ø·þÎñ·ì϶

¸ßΣ

Role:   DNS Server

CVE-2021-26893

Windows   DNS·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Role:   DNS Server

CVE-2021-26897

Windows   DNS·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

Role:   DNS Server

CVE-2021-26894

Windows   DNS·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Role:   DNS Server

CVE-2021-26895

Windows   DNS·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Role:   DNS Server

CVE-2021-26896

Windows   DNS·þÎñÆ÷»Ø¾ø·þÎñ·ì϶

¸ßΣ

Role:   DNS Server

CVE-2021-26877

Windows   DNS·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Role:   Hyper-V

CVE-2021-26867

Windows   Hyper-VÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

Role:   Hyper-V

CVE-2021-26879

Windows   NAT»Ø¾ø·þÎñ·ì϶

¸ßΣ

Visual   Studio

CVE-2021-27084

Visual   Studio Code JavaÀ©´ó°üÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Visual   Studio

CVE-2021-21300

Git   for Visual StudioÔ¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

Visual   Studio Code

CVE-2021-27060

Visual   Studio´úÂëÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Visual   Studio Code

CVE-2021-27081

Visual   Studio Code ESLintÀ©´óÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Visual   Studio Code

CVE-2021-27083

Visual   Studio CodeÔ¶³Ì´úÂëÖ´ÐеÄÔ¶³Ì¿ª·¢À©´ó·ì϶

¸ßΣ

Visual   Studio Code

CVE-2021-27082

ÓÃÓÚVisual Studio´úÂëÔ¶³Ì´úÂëÖ´Ðзì϶µÄQuantum¿ª·¢Ì×¼þ

¸ßΣ

Windows   Admin Center

CVE-2021-27066

WindowsÖÎÀíÖÐÐݲȫְÄÜÈÆ¹ý·ì϶

¸ßΣ

Windows   Container Execution Agent

CVE-2021-26891

WindowsÈÝÆ÷Ö´ÐдúÀíȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Container Execution Agent

CVE-2021-26865

WindowsÈÝÆ÷Ö´ÐдúÀíȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   DirectX

CVE-2021-24095

DirectXȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Error Reporting

CVE-2021-24090

WindowsÃýÎó»ã±¨È¨ÏÞÌáÉý·ì϶

¸ßΣ

Windows   Event Tracing

CVE-2021-24107

WindowsÊÂÎñ¸ú×ÙÐÅϢй¶·ì϶

¸ßΣ

Windows   Event Tracing

CVE-2021-26872

WindowsÊÂÎñ¸ú×ÙȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Event Tracing

CVE-2021-26901

WindowsÊÂÎñ¸ú×ÙȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Event Tracing

CVE-2021-26898

WindowsÊÂÎñ¸ú×ÙȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Extensible Firmware Interface

CVE-2021-26892

Windows¿ÉÀ©´ó¹Ì¼þ½Ó¿Ú°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

Windows   Folder Redirection

CVE-2021-26887

Microsoft   WindowsÎļþ¼Ð³Á¶¨ÏòȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Installer

CVE-2021-26862

Windows   InstallerȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Media

CVE-2021-26881

Microsoft   Windows Media FoundationÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Windows   Overlay Filter

CVE-2021-26874

Windows¸²¸ÇɸѡÆ÷ȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Overlay Filter

CVE-2021-26860

Windows   App-V¸²¸ÇɸѡÆ÷ȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Print Spooler Components

CVE-2021-1640

Windows   Print SpoolerȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Print Spooler Components

CVE-2021-26878

Windows   Print SpoolerȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Projected File System Filter Driver

CVE-2021-26870

Windows   ProjectedÎļþϵͳȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Registry

CVE-2021-26864

WindowsÐé¹¹×¢²á±íÌṩ·¨Ê½È¨ÏÞÌáÉý·ì϶

¸ßΣ

Windows   Remote Access API

CVE-2021-26882

Ô¶³Ì½Ó¼ûAPIȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Storage Spaces Controller

CVE-2021-26880

´æ´¢¿Õ¼ä½ÚÔìÆ÷ȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Update Assistant

CVE-2021-27070

Windows   10 Update AssistantȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Update Stack

CVE-2021-1729

Windows   Update²Ö¿â×°ÖÃȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Update Stack

CVE-2021-26889

Windows   Update²Ö¿âȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Update Stack

CVE-2021-26866

Windows   Update ServiceȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   UPnP Device Host

CVE-2021-26899

Windows   UPnPÉ豸Ö÷»úȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   User Profile Service

CVE-2021-26873

WindowsÓû§ÅäÖÃÎļþ·þÎñȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   User Profile Service

CVE-2021-26886

Óû§ÅäÖÃÎļþ·þÎñ»Ø¾ø·þÎñ·ì϶

¸ßΣ

Windows   WalletService

CVE-2021-26871

Windows   WalletServiceȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   WalletService

CVE-2021-26885

Windows   WalletServiceȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Win32K

CVE-2021-26900

Windows   Win32kȨÏÞÌáÉý·ì϶

¸ßΣ

 

 

0x02 ´ëÖý¨Òé

ĿǰMicrosoftÒѰ䲼Óйذ²È«¸üУ¬½¨Ò龡¿ì½¨¸´¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС±£¬ÆÚ´ýϵͳ½«×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüС£

4¡¢³ÁÆôÍÆËã»ú£¬×°ÖøüÐÂϵͳ³ÁÐÂÆô¶¯ºó£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£

 

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

΢Èí¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/releaseNote/2021-Mar

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/releaseNote/2021-Mar

https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2021-patch-tuesday-fixes-82-flaws-2-zero-days/

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-27076

https://www.zerodayinitiative.com/blog/2021/1/27/zdi-can-12671-windows-kernel-dosprivilege-escalation-via-a-null-pointer-deref

 

0x04 ¹¦·òÏß

2021-03-09  ΢Èí°ä²¼°²È«¸üÐÂ

2021-03-10  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png