¡¾Îó²îͨ¸æ¡¿Î¢Èí1ÔÂÇå¾²¸üжà¸ö²úÆ·¸ßΣÎó²îͨ¸æ
2021-01-13
Ò». Îó²î¸ÅÊö
±±¾©Ê±¼ä1ÔÂ13ÈÕ£¬Î¢ÈíÐû²¼1ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË83¸öÇå¾²ÎÊÌâ£¬Éæ¼°Microsoft Windows¡¢Microsoft Office¡¢Microsoft SQL Server¡¢Visual Studio¡¢Microsoft DefenderµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨Ô¶³Ì´úÂëÖ´ÐкÍȨÏÞÌáÉýµÈ¸ßΣÎó²îÀàÐÍ¡£
±¾ÔÂ΢ÈíÔ¶ȸüÐÂÐÞ¸´µÄÎó²îÖУ¬ÑÏÖØË®Æ½ÎªÒªº¦£¨Critical£©µÄÎó²îÓÐ9¸ö£¬Ö÷Òª£¨Important£©Îó²îÓÐ73¸ö£¬1¸ö ÖÐΣ£¨Moderate£©¼¶±ðÎó²î¡£ÇëÏà¹ØÓû§ÊµÊ±¸üв¹¶¡¾ÙÐзÀ»¤£¬ÏêϸÎó²îÁбíÇë²Î¿¼¸½Â¼¡£
AG¹«Ë¾Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS£©ÒѾ߱¸Î¢Èí´Ë´Î²¹¶¡¸üÐÂÖдó´ó¶¼Îó²îµÄ¼ì²âÄÜÁ¦£¨°üÀ¨CVE-2021-1705£¬CVE-2021-1673£¬CVE-2021-1668£¬CVE-2021-1667£¬CVE-2021-1666£¬CVE-2021-1665£¬CVE-2021-1660£¬CVE-2021-1658µÈ¸ßΣÎó²î£©£¬ÇëÏà¹ØÓû§¹Ø×¢AG¹«Ë¾Ô¶³ÌÇå¾²ÆÀ¹Àϵͳϵͳ²å¼þÉý¼¶°üµÄ¸üУ¬ÊµÊ±Éý¼¶ÖÁV6.0R02F01.2101£¬¹ÙÍøÁ´½Ó£ºhttp://update.nsfocus.com/update/listRsasDetail/v/vulsys
²Î¿¼Á´½Ó£º
https://msrc.microsoft.com/update-guide/en-us/releaseNote/2021-Jan
¶þ. ÖØµãÎó²î¼òÊö
ƾ֤²úÆ·Ê¢ÐжȺÍÎó²îÖ÷ÒªÐÔɸѡ³ö´Ë´Î¸üÐÂÖаüÀ¨Ó°Ïì½Ï´óµÄÎó²î£¬ÇëÏà¹ØÓû§Öصã¾ÙÐйØ×¢£º
Microsoft DefenderÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-1647£©£º
Microsoft DefenderÔÚɨÃèÎļþµÄÀú³ÌÖб£´æÄÚ´æËð»µÎó²î£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâPEÎļþ£¬Í¨¹ý´¹ÂÚÓʼþ/Á´½ÓµÈ·½·¨Ê¹Êܺ¦Õß»ñÈ¡µ½¸Ã¶ñÒâÎļþ£¬²¢Ê¹Microsoft DefenderɨÃè¸Ã¶ñÒâÎļþ£¬±¬·¢»º³åÇøÒç³ö£¬×îÖÕÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£Î¢Èí¹Ù·½ÏÖÔÚÒÑ·¢Ã÷¸ÃÎó²î±£´æÔÚҰʹÓá£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-1647
Microsoft splwow64ȨÏÞÌáÉýÎó²î£¨CVE-2021-1648£©£º
Windows´òÓ¡Çý¶¯³ÌÐòÀú³ÌSPLWOW64.exeÖб£´æÈ¨ÏÞÌáÉýÎó²î£¬ÓÉÓÚȱÉÙ¶ÔÓû§ÌṩµÄÊý¾Ý¾ÙÐÐÊʵ±ÑéÖ¤£¬µ¼Ö¿ÉÄÜ·ºÆðÔ½½ç¶ÁÈ¡£¬¹¥»÷Õß¿ÉʹÓôËÎó²î¾ÙÐÐȨÏÞÌáÉý£¬ÏÖÔÚÒÑÓÐPoC¹ûÕæ¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-1648
SharePoint Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-1707£©£º
Microsoft SharePoint±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÌØÖÆÇëÇó°ü£¬¿ÉÔÚ SharePointÓ¦ÓóÌÐò³ØºÍSharePoint·þÎñÆ÷ÕË»§ÉÏÖ´ÐÐí§Òâ´úÂë¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-1707
Windows Win32kȨÏÞÌáÉýÎó²î £¨CVE-2021-1709£©£º
Win32kϵͳÀú³ÌÖб£´æÒ»¸öȨÏÞÌáÉýÎó²î£¬¾ÓÉÉí·ÝÑéÖ¤µÄÍâµØ¹¥»÷Õß¿ÉʹÓôËÎó²îÔÚÄ¿µÄϵͳÉÏÌáÉýÆäȨÏÞÒÔÖ´ÐÐí§Òâ´úÂë¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-1709
GDI +Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-1665£©£º
Windows ͼÐÎ×°±¸½Ó¿Ú (GDI) ÔÚ´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õß¿Éͨ¹ý¶àÖÖ·½·¨Ê¹ÓôËÎó²î£¬ÔÚ»ùÓÚWebµÄ¹¥»÷ÇéÐÎÖУ¬¹¥»÷Õß¿ÉÓÕµ¼Óû§·¿ªµç×ÓÓʼþ¸½¼þ»òµ¥»÷µç×ÓÓʼþ»ò¼´Ê±ÐÂÎÅÖеÄÁ´½ÓÀ´»á¼ûʹÓôËÎó²îµÄ¶ñÒâÍøÕ¾£»ÔÚÎļþ¹²Ïí¹¥»÷ÇéÐÎÖУ¬¹¥»÷Õß¿ÉÓÕµ¼Óû§·¿ªÊ¹ÓôËÎó²îµÄÌØÖÆÎļþ¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÔÚÄ¿µÄϵͳÉÏÒÔÄ¿½ñÓû§È¨ÏÞÖ´ÐÐí§Òâ´úÂë¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1665
WindowsÔ¶³Ì×ÀÃæÐÒé½¹µãÇå¾²¹¦Ð§ÈƹýÎó²î£¨CVE-2021-1674£©£º
Kerberos ÑéÖ¤Á÷³ÌÖб£´æÒ»´¦Çå¾²ÌØÕ÷ÈÆ¹ýÎó²î¡£Ó°ÏìKerberos»ùÓÚ×ÊÔ´µÄÔ¼ÊøÎ¯ÅÉ£¨RBCD£©£¬Ïêϸϸ½ÚÉÐδ¹ûÕæ¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-1674
Èý. Ó°Ïì¹æÄ£
ÒÔÏÂÎªÖØµã¹Ø×¢Îó²îµÄÊÜÓ°Ïì²úÆ·°æ±¾£¬ÆäËûÎó²îÓ°Ïì²úÆ·¹æÄ£Çë²ÎÔĹٷ½Í¨¸æÁ´½Ó¡£
ËÄ. Îó²î·À»¤
4.1 ²¹¶¡¸üÐÂ
ÏÖÔÚ΢Èí¹Ù·½ÒÑÕë¶ÔÊÜÖ§³ÖµÄ²úÆ·°æ±¾Ðû²¼ÁËÐÞ¸´ÒÔÉÏÎó²îµÄÇå¾²²¹¶¡£¬Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì×°Öò¹¶¡¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-us/releaseNote/2021-Jan
×¢£ºÓÉÓÚÍøÂçÎÊÌâ¡¢ÅÌËã»úÇéÐÎÎÊÌâµÈÔµ¹ÊÔÓÉ£¬Windows UpdateµÄ²¹¶¡¸üпÉÄÜ·ºÆðʧ°Ü¡£Óû§ÔÚ×°Öò¹¶¡ºó£¬Ó¦ÊµÊ±¼ì²é²¹¶¡ÊÇ·ñÀֳɸüС£
ÓÒ¼üµã»÷Windowsͼ±ê£¬Ñ¡Ôñ“ÉèÖÃ(N)”£¬Ñ¡Ôñ“¸üкÍÇå¾²”-“Windows¸üД£¬Éó²é¸ÃÒ³ÃæÉϵÄÌáÐÑÐÅÏ¢£¬Ò²¿Éµã»÷“Éó²é¸üÐÂÀúÊ·¼Í¼”Éó²éÀúÊ·¸üÐÂÇéÐΡ£
Õë¶ÔδÀÖ³É×°ÖõĸüУ¬¿Éµã»÷¸üÐÂÃû³ÆÌø×ªµ½Î¢Èí¹Ù·½ÏÂÔØÒ³Ãæ£¬½¨ÒéÓû§µã»÷¸ÃÒ³ÃæÉϵÄÁ´½Ó£¬×ªµ½“Microsoft¸üÐÂĿ¼”ÍøÕ¾ÏÂÔØ×ÔÁ¦³ÌÐò°ü²¢×°Öá£

AG¹«Ë¾ÔÆ







