Microsoft 4Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-04-14

0x00 ·ì϶¸ÅÊö

2021Äê04ÔÂ13ÈÕ £¬Microsoft°ä²¼ÁË4Ô·ݵݲȫ¸üР£¬±¾´Î°ä²¼µÄ°²È«¸üй²¼Æ½¨¸´ÁË108¸ö°²È«·ì϶ £¬ÆäÖÐÓÐ19¸ö·ì϶ÆÀ¼¶ÎªÑϳÁ £¬89¸ö·ì϶ÆÀ¼¶Îª¸ßΣ £¬ÆäÖÐÔ̺¬5¸ö0 day·ì϶ºÍ4¸öMicrosoft Exchange·ì϶ ¡£

 

0x01 ·ì϶ÏêÇé

image.png

 

±¾´Î°ä²¼µÄ°²È«¸üÐÂÉæ¼°Azure¡¢Microsoft Edge (Chromium-based)¡¢Exchange Server¡¢Microsoft Office¡¢Windows DNS¡¢Windows Kernel¡¢Windows SMB ServerºÍWindows TCP/IPµÈ¶à¸ö²úÆ·ºÍ×é¼þ ¡£Ä¿Ç° £¬MicrosoftÒѾ­½¨¸´ÁËÒÔÏÂ5¸ö0 day·ì϶ £¬ÆäÖÐCVE-2021-28310Òѱ»ÔÚÒ°ÀûÓà ¡£

RPC¶ËµãÓ³ÉäÆ÷·þÎñȨÏÞÌáÉý·ì϶£¨CVE-2021-27091£©

¸Ã·ì϶ÊÇWindows×¢²á±íÖеÄRPCȨÏÞÌáÉý·ì϶ £¬ÆäCVSSÆÀ·Ö7.8 £¬¸Ã·ì϶ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓà ¡£

 

Windows NTFS»Ø¾ø·þÎñ·ì϶£¨CVE-2021-28312£©

¸Ã·ì϶ÊÇWindows NTFSϵͳÖеĻؾø·þÎñ·ì϶ £¬ÆäCVSSÆÀ·Ö3.3 £¬¸Ã·ì϶ÐèÓëÓû§½»»¥²Å¿ÉÀûÓà ¡£

 

Windows InstallerÐÅϢй¶·ì϶£¨CVE-2021-28437£©

¸Ã·ì϶ÊÇWindows Installer¹¤¾ßÖеÄÐÅϢй¶·ì϶ £¬ÆäCVSSÆÀ·Ö5.5 £¬¸Ã·ì϶ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓà ¡£

 

Azure ms-rest-nodeauth¿âȨÏÞÌáÉý·ì϶£¨CVE-2021-28458£©

¸Ã·ì϶ÊÇAzure ms-rest-nodeauth¿âÖеÄȨÏÞÌáÉý·ì϶ £¬ÆäCVSSÆÀ·Ö7.8 £¬¸Ã·ì϶ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓà ¡£

 

Win32kȨÏÞÌáÉý·ì϶£¨CVE-2021-28310£©

¸Ã·ì϶ÊÇWindowsÇý¶¯ÎļþÖеÄȨÏÞÌáÉý·ì϶ £¬ÆäCVSSÆÀ·Ö7.8 £¬¸Ã·ì϶ÎÞÐèÓû§½»»¥¼´¿ÉÀûÓà ¡£

 

´Ë±í £¬MicrosoftÒѾ­°ä²¼ÁË2021Äê4ÔµÄExchange Server°²È«¸üУ¨ÀÛ»ý¸üР£¬Ô̺¬Exchange Server 2021Äê3Եݲȫ¸üУ© £¬ÒÔ½¨¸´NSA·¢ÏÖµÄ4¸öÑϳÁµÄMicrosoft ExchangeÔ¶³Ì´úÂëÖ´Ðзì϶ £¬ÕâЩ·ì϶ĿǰÉÐδ±»ÔÚÒ°ÀûÓà ¡£ÆäÖÐ £¬CVE-2021-28480ºÍCVE-2021-28481ΪԤÉí·ÝÑéÖ¤·ì϶ £¬¹¥»÷ÕßÎÞÐè½øÐÐÉí·ÝÑéÖ¤¼´¿ÉÀûÓà ¡£

CVE   ID

ÆÀ·Ö

Ãû³Æ

ÊÇ·ñ½»»¥

Ó°ÏìÁìÓò

Ó°Ïì°æ±¾

CVE-2021-28480

9.8

Microsoft   Exchange ServerÔ¶³Ì´úÂëÖ´Ðзì϶

 

 

ÎÞÐèÓû§½»»¥

Exchange   Server 2013

Exchange   Server 2016

Exchange   Server 2019

Exchange   Server 2013 CU23

Exchange   Server 2016 CU19ºÍCU20

Exchange   Server 2019 CU8ºÍCU9

CVE-2021-28481

9.8

CVE-2021-28482

8.8

CVE-2021-28483

9.0

 

 

0x02 ´ëÖý¨Òé

ĿǰMicrosoftÒѰ䲼Óйذ²È«¸üР£¬½¨Ò龡¿ì½¨¸´ ¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓà £¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ £¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öà ¡£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü £¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡± £¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС± £¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС± £¬ÆÚ´ýϵͳ½«×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüР¡£

4¡¢³ÁÆôÍÆËã»ú £¬×°ÖøüÐÂϵͳ³ÁÐÂÆô¶¯ºó £¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üР¡£¶ÔÓÚûÓгɹ¦×°ÖõĸüР£¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó £¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡± £¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öà ¡£

 

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüР¡£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/vulnerability

 

0x03 ²Î¿¼Á´½Ó

https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2021-patch-tuesday-fixes-108-flaws-5-zero-days/

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28480

https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2021-exchange-server-security-updates/ba-p/2254617

 

0x04 ¹¦·òÏß

2021-04-13  Microsoft°ä²¼°²È«¸üÐÂ

2021-04-14  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png