Microsoft 6Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-06-09

0x00 ·ì϶¸ÅÊö

2021Äê06ÔÂ08ÈÕ£¬Microsoft°ä²¼ÁË6Ô·ݵݲȫ¸üУ¬±¾´Î°ä²¼µÄ°²È«¸üй²¼Æ½¨¸´ÁË50¸ö°²È«·ì϶£¬ÆäÖÐÓÐ5¸ö·ì϶ÆÀ¼¶ÎªÑϳÁ£¬45¸ö·ì϶ÆÀ¼¶Îª¸ßΣ£¬ÆäÖÐÔ̺¬7¸ö0 day·ì϶ ¡£

 

0x01 ·ì϶ÏêÇé

image.png

 

±¾´Î°ä²¼µÄ°²È«¸üÐÂÉæ¼°.NET Core & Visual Studio¡¢Microsoft Office¡¢Excel¡¢SharePoint¡¢Outlook¡¢Microsoft Windows Codecs Library¡¢Microsoft Scripting Engine¡¢Windows TCP/IP¡¢Windows Remote Desktop¡¢Windows Kernel ºÍWindows DefenderµÈ¶à¸ö²úÆ·ºÍ×é¼þ ¡£ÆäÖУ¬5¸öÆÀ¼¶ÎªÑϳÁµÄ·ì϶ÈçÏÂ:

Microsoft Defender Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2021-31985)

¸Ã·ì϶ÊÇMicrosoft DefenderÖеÄRCE·ì϶£¬ÆäCVSSv3ÆÀ·ÖΪ7.8 ¡£¸Ã·ì϶ÀûÓø´ÔӶȵÍ£¬²»±ØÒªÌØÊâȨÏÞ¼´¿É±¾µØÀûÓ㬵«±ØÒªÓû§½»»¥£¬MicrosoftµÄ¿ÉÀûÓÃÐÔÆÀ¹ÀΪ¡°¿ÉÄܱ»ÀûÓá± ¡£

 

Scripting EngineÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-31959£©

¸Ã·ì϶ÊÇChakra JScript ¾ç±¾ÒýÇæÖеÄÄÚ´æ°Ü»µ·ì϶£¬ÆäCVSSv3ÆÀ·ÖΪ6.4 ¡£´Ë·ì϶ӰÏì Windows 7¡¢Windows 8¡¢Windows 10¡¢Windows Server 2008 R2¡¢Windows Server 2012 (R2) ºÍ Windows Server 2016µÈËùÓÐÊÜÖ§³ÖµÄMicrosoft Windows °æ±¾ ¡£¸Ã·ì϶ÀûÓø´ÔӶȽϸߣ¬²»±ØÒªÌØÊâȨÏÞ¼´¿ÉÔ¶³ÌÀûÓ㬵«±ØÒªÓû§½»»¥ ¡£

 

Microsoft SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-31963£©

¸Ã·ì϶ÊÇMicrosoft SharePoint Server ÖеÄRCE·ì϶£¬ÆäCVSSv3ÆÀ·ÖΪ7.1 ¡£¸Ã·ì϶ÎÞÐèÓû§½»»¥¼´¿ÉÔ¶³ÌÀûÓ㬵«·ì϶ÀûÓø´ÔÓ¶È½Ï¸ß ¡£

 

VP9 Video ExtensionsÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-31967£©

¸Ã·ì϶ÊÇVP9 ÊÓÆÂ·©Õ¹ÖеÄRCE·ì϶£¬ÆäCVSSv3ÆÀ·ÖΪ7.8 ¡£¸Ã·ì϶ÀûÓø´ÔӶȵÍ£¬²»±ØÒªÌØÊâȨÏÞ¼´¿É±¾µØÀûÓ㬵«±ØÒªÓû§½»»¥ ¡£Ä¿Ç°´Ë·ì϶ÒÑÔÚÀûÓ÷¨Ê½°ü°æ±¾1.0.41182.0¼°¸ü¸ß°æ±¾Öн¨¸´£¬Óû§Äܹ»ÔÚ PowerShell Öв鳭Èí¼þ°ü°æ±¾£º

Get-AppxPackage -Name Microsoft.VP9VideoExtensions

 

Windows MSHTML ƽ̨Զ³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-33742£©

¸Ã·ì϶ÊÇWindows MSHTML ƽ̨ÖеÄRCE·ì϶£¬ÆäCVSSv3ÆÀ·ÖΪ7.5 ¡£¸Ã·ì϶ÎÞÐèÌØÊâȨÏÞ¼´¿ÉÔ¶³ÌÀûÓ㬵«·ì϶ÀûÓø´ÔӶȽϸߣ¬ÇÒÐèÓëÓû§½»»¥£¬Ä¿Ç°´Ë·ì϶ÒÑ·¢´Ë¿ÌÒ°ÀûÓà ¡£

 

Microsoft½¨¸´µÄ7¸ö0 day·ì϶ÖУ¬6¸öÒѱ»ÔÚÒ°ÀûÓõķì϶ÈçÏ£º

CVE-2021-31955 - Windows KernelÐÅϢй¶·ì϶

CVE-2021-31956 - Windows NTFS ȨÏÞÌáÉý·ì϶

CVE-2021-33739 - Microsoft DWM Ö÷Ìâ¿âȨÏÞÌáÉý·ì϶

CVE-2021-33742 - Windows MSHTML ƽ̨Զ³Ì´úÂëÖ´Ðзì϶

CVE-2021-31199 - Microsoft ¼ÓÇ¿ÐͼÓÃÜÌṩ·¨Ê½È¨ÏÞÌáÉý·ì϶

CVE-2021-31201 - Microsoft ¼ÓÇ¿ÐͼÓÃÜÌṩ·¨Ê½È¨ÏÞÌáÉý·ì϶

´Ë±í£¬ CVE-2021-31968 (Windows Ô¶³Ì×ÀÃæ·þÎñ»Ø¾ø·þÎñ·ì϶)ÒѾ­¹«¿ªÅû¶£¬µ«ÉÐδ·¢´Ë¿ÌÒ°ÀûÓà ¡£


Microsoft 6Ô²¹¶¡½¨¸´µÄÆëÈ«·ì϶ÁбíÈçÏ£º

±êÇ©

CVE ID

CVE   ±êÌâ

ÑϳÁÐÔ

.NET   Core & Visual Studio

CVE-2021-31957

.NET   Core ºÍ Visual Studio »Ø¾ø·þÎñ·ì϶

¸ßΣ

3D   Viewer

CVE-2021-31942

3D   ViewerÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

3D   Viewer

CVE-2021-31943

3D   ViewerÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

3D   Viewer

CVE-2021-31944

3D   ViewerÐÅϢй¶·ì϶

¸ßΣ

Microsoft   DWM Core Library

CVE-2021-33739

Microsoft   DWM Ö÷Ìâ¿âȨÏÞÌáÉý·ì϶

¸ßΣ

Microsoft   Edge (Chromium-based)

CVE-2021-33741

Microsoft   Edge£¨»ùÓÚ Chromium£©È¨ÏÞÌáÉý·ì϶

¸ßΣ

Microsoft   Intune

CVE-2021-31980

Microsoft   Intune ÖÎÀíÀ©´óÔ¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Office

CVE-2021-31940

Microsoft   Office Graphics Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Office

CVE-2021-31941

Microsoft   Office Graphics Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Office Excel

CVE-2021-31939

Microsoft   Excel Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Office Outlook

CVE-2021-31949

Microsoft   Outlook Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Office SharePoint

CVE-2021-31964

Microsoft   SharePoint Server ºýŪ·ì϶

¸ßΣ

Microsoft   Office SharePoint

CVE-2021-31963

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

Microsoft   Office SharePoint

CVE-2021-31950

Microsoft   SharePoint Server ºýŪ·ì϶

¸ßΣ

Microsoft   Office SharePoint

CVE-2021-31948

Microsoft   SharePoint Server ºýŪ·ì϶

¸ßΣ

Microsoft   Office SharePoint

CVE-2021-31966

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Office SharePoint

CVE-2021-31965

Microsoft   SharePoint Server ÐÅϢй¶·ì϶

¸ßΣ

Microsoft   Office SharePoint

CVE-2021-26420

Microsoft   SharePoint Server Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Microsoft   Scripting Engine

CVE-2021-31959

¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶

ÑϳÁ

Microsoft   Windows Codecs Library

CVE-2021-31967

VP9   ÊÓÆÂ·©Õ¹Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

Paint   3D

CVE-2021-31946

Paint   3D Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Paint   3D

CVE-2021-31983

Paint   3D Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Paint   3D

CVE-2021-31945

Paint   3D Ô¶³Ì´úÂëÖ´Ðзì϶

¸ßΣ

Role:   Hyper-V

CVE-2021-31977

Windows   Hyper-V »Ø¾ø·þÎñ·ì϶

¸ßΣ

Visual   Studio Code - Kubernetes Tools

CVE-2021-31938

Microsoft   VsCode Kubernetes ¹¤¾ßÀ©´óȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Bind Filter Driver

CVE-2021-31960

Windows   °ó¶¨É¸Ñ¡Æ÷Çý¶¯·¨Ê½ÐÅϢй¶·ì϶

¸ßΣ

Windows   Common Log File System Driver

CVE-2021-31954

Windows   ͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½È¨ÏÞÌáÉý·ì϶

¸ßΣ

Windows   Cryptographic Services

CVE-2021-31201

 Microsoft ¼ÓÇ¿ÐͼÓÃÜÌṩ·¨Ê½È¨ÏÞÌáÉý·ì϶

¸ßΣ

Windows   Cryptographic Services

CVE-2021-31199

  Microsoft ¼ÓÇ¿ÐͼÓÃÜÌṩ·¨Ê½È¨ÏÞÌáÉý·ì϶

¸ßΣ

Windows   DCOM Server

CVE-2021-26414

Windows   DCOM ·þÎñÆ÷°²È«Ö°ÄÜÈÆ¹ý

¸ßΣ

Windows   Defender

CVE-2021-31978

Microsoft   Defender »Ø¾ø·þÎñ·ì϶

¸ßΣ

Windows   Defender

CVE-2021-31985

Microsoft   Defender Ô¶³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

Windows   Drivers

CVE-2021-31969

Windows   ÔÆÎļþÃÔÄã¹ýÂËÆ÷Çý¶¯È¨ÏÞÌáÉý·ì϶

¸ßΣ

Windows   Event Logging Service

CVE-2021-31972

Windows   ÐÅϢй¶·ì϶µÄÊÂÎñ¸ú×Ù

¸ßΣ

Windows   Filter Manager

CVE-2021-31953

Windows   ¹ýÂËÆ÷ÖÎÀíÆ÷ȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   HTML Platform

CVE-2021-31971

Windows   HTML ƽ̨°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

Windows   Installer

CVE-2021-31973

Windows   GPSVC ȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Kerberos

CVE-2021-31962

Kerberos   AppContainer °²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

Windows   Kernel

CVE-2021-31951

Windows   ÄÚºËȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Kernel

CVE-2021-31955

Windows   ÄÚºËÐÅϢй¶·ì϶

¸ßΣ

Windows   Kernel-Mode Drivers

CVE-2021-31952

Windows   ÄÚºËģʽÇý¶¯·¨Ê½È¨ÏÞÌáÉý·ì϶

¸ßΣ

Windows   MSHTML Platform

CVE-2021-33742

Windows   MSHTML ƽ̨Զ³Ì´úÂëÖ´Ðзì϶

ÑϳÁ

Windows   Network File System

CVE-2021-31975

NFS   ÐÅϢй¶·ì϶·þÎñÆ÷

¸ßΣ

Windows   Network File System

CVE-2021-31974

NFS   »Ø¾ø·þÎñ·ì϶·þÎñÆ÷

¸ßΣ

Windows   Network File System

CVE-2021-31976

NFS   ÐÅϢй¶·ì϶·þÎñÆ÷

¸ßΣ

Windows   NTFS

CVE-2021-31956

Windows   NTFS ȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   NTLM

CVE-2021-31958

Windows   NTLM ȨÏÞÌáÉý·ì϶

¸ßΣ

Windows   Print Spooler Components

CVE-2021-1675

Windows   ´òÓ¡ºó¶Ü´¦Ö÷¨Ê½È¨ÏÞÌáÉý·ì϶

¸ßΣ

Windows   Remote Desktop

CVE-2021-31968

Windows   Ô¶³Ì×ÀÃæ·þÎñ»Ø¾ø·þÎñ·ì϶

¸ßΣ

Windows   TCP/IP

CVE-2021-31970

Windows   TCP/IP Çý¶¯·¨Ê½°²È«Ö°ÄÜÈÆ¹ý·ì϶

¸ßΣ

 

 

0x02 ´ëÖý¨Òé

ĿǰMicrosoftÒѰ䲼Óйذ²È«¸üУ¬½¨Ò龡¿ì½¨¸´ ¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öà ¡£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°²é³­¸üС±£¬ÆÚ´ýϵͳ½«×Ô¶¯²é³­²¢ÏÂÔØ¿ÉÓøüР¡£

4¡¢³ÁÆôÍÆËã»ú£¬×°ÖøüÐÂϵͳ³ÁÐÂÆô¶¯ºó£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üР¡£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öà ¡£

 

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüР¡£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide/

 

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/vulnerability

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-31963

https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2021-patch-tuesday-fixes-6-exploited-zero-days-50-flaws/

 

0x04 ¹¦·òÏß

2021-06-08  Microsoft°ä²¼°²È«¸üÐÂ

2021-06-09  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png