»ù´¡ÉèÊ©Çå¾²
Êý¾ÝÇå¾²
ÔÆÅÌËãÇå¾²
¹¤Òµ»¥ÁªÍøÇå¾²
ÎïÁªÍøÇå¾²
ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
ËùÓвúÆ·
ËùÓнâ¾ö¼Æ»®
2021-05-12
Ò». Îó²î¸ÅÊö
5ÔÂ12ÈÕ£¬Î¢ÈíÐû²¼5ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË55¸öÇå¾²Îó²î£¬Éæ¼°Windows¡¢Microsoft Office¡¢Exchange Server¡¢Visual Studio Code¡¢Internet ExplorerµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨Ô¶³Ì´úÂëÖ´ÐкÍȨÏÞÌáÉýµÈ¸ßΣÎó²îÀàÐÍ¡£
±¾ÔÂ΢ÈíÔ¶ȸüÐÂÐÞ¸´µÄÎó²îÖУ¬ÑÏÖØË®Æ½ÎªÒªº¦£¨Critical£©µÄÎó²îÓÐ4¸ö£¬Ö÷Òª£¨Important£©Îó²îÓÐ50¸ö¡£ÇëÏà¹ØÓû§¾¡¿ì¸üв¹¶¡¾ÙÐзÀ»¤¡£ÏêϸÎó²îÁбíÇë²Î¿¼¸½Â¼¡£
AG¹«Ë¾Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS£©ÒѾ߱¸Î¢Èí´Ë´Î²¹¶¡¸üÐÂÖдó´ó¶¼Îó²îµÄ¼ì²âÄÜÁ¦£¨°üÀ¨CVE-2021-26419¡¢CVE-2021-31166¡¢CVE-2021-31194¡¢CVE-2021-28476µÈ¸ßΣÎó²î£©£¬ÇëÏà¹ØÓû§¹Ø×¢AG¹«Ë¾Ô¶³ÌÇå¾²ÆÀ¹Àϵͳϵͳ²å¼þÉý¼¶°üµÄ¸üУ¬ÊµÊ±Éý¼¶ÖÁV6.0R02F01.2301£¬¹ÙÍøÁ´½Ó£ºhttp://update.nsfocus.com/update/listRsasDetail/v/vulsys¡£
²Î¿¼Á´½Ó£º
https://msrc.microsoft.com/update-guide/en-us/releaseNote/2021-May
¶þ. ÖØµãÎó²î¼òÊö
ƾ֤²úÆ·Ê¢ÐжȺÍÎó²îÖ÷ÒªÐÔɸѡ³ö´Ë´Î¸üÐÂÖаüÀ¨Ó°Ïì½Ï´óµÄÎó²î£¬ÇëÏà¹ØÓû§Öصã¾ÙÐйØ×¢£º
HTTPÐÒéÕ»Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31166£©£º
HTTPÐÒéÕ»£¨http.sys£©±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòÄ¿µÄÖ÷»ú·¢ËÍÌØÖÆÊý¾Ý°üÀ´Ê¹ÓôËÎó²î£¬´Ó¶øÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£CVSSÆÀ·ÖΪ9.8£¬Î¢ÈíÌåÏÖ´ËÎó²î¿ÉÓÃÓÚÈä³æÊ½Èö²¥¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-31166
Hyper-V Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-28476£©£º
ÐéÄâ»úÖÎÀí³ÌÐòWindows Hyper-V±£´æÔ¶³ÌÖ´ÐдúÂëÎó²î£¬CVSSÆÀ·ÖΪ9.9 ¡£´ËÎó²îʹguest VM ¿ÉÒÔÇ¿ÖÆHyper-V hostµÄÄں˶ÁÈ¡í§Òâ¿ÉÄÜÎÞЧµÄµØµã£¬ÔÚijЩÇéÐÎÏÂÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚ Hyper-V µÄ·þÎñÆ÷ÉÏÔËÐжþ½øÖÆÎļþ»òÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-28476
Microsoft SharePointÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-28474/CVE-2021-31181£©£º
¾ÓÉÉí·ÝÈÏÖ¤µÄ¹¥»÷Õß¿Éͨ¹ý»á¼û½¨ÉèSharePointÕ¾µãʹÓÃÒÔÉÏÎó²î£¬ÊµÏÖÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-28474
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-31181
OLE Automation Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31194£©£º
´ËÎó²î±£´æÓÚWindows OLEÖУ¬¹¥»÷Õߴһ¸ö¶ñÒâµÄÍøÕ¾ÓÕµ¼Óû§»á¼û£¬Í¨¹ýWebä¯ÀÀÆ÷ŲÓÃOLE×Ô¶¯»¯Ê¹ÓôËÎó²î£¬´Ó¶øÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-31194
Exchange Server Çå¾²¹¦Ð§ÈƹýÎó²î£¨CVE-2021-31207£©£º
´ËÎó²îΪ2021 Pwn2Own ¾ºÈüÉÏ·¢Ã÷µÄExchange ServerÎó²îÖ®Ò»£¬ÏÖÔÚÒѹûÕæÅû¶£¬¹¥»÷ÕßÀÖ³ÉʹÓøÃÎó²î¿É»ñȡһ¶¨µÄ·þÎñÆ÷¿ØÖÆÈ¨ÏÞ¡£
¹Ù·½Í¨¸æÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-31207
Èý. Ó°Ïì¹æÄ£
ÒÔÏÂÎªÖØµã¹Ø×¢Îó²îµÄÊÜÓ°Ïì²úÆ·°æ±¾£¬ÆäËûÎó²îÓ°Ïì²úÆ·¹æÄ£Çë²ÎÔĹٷ½Í¨¸æÁ´½Ó¡£
|
Îó²î±àºÅ |
ÊÜÓ°Ïì²úÆ·°æ±¾ |
|
CVE-2021-31166 |
Windows Server, version 20H2 (Server Core Installation) Windows 10 Version 20H2 for ARM64-based Systems Windows 10 Version 20H2 for 32-bit Systems Windows 10 Version 20H2 for x64-based Systems Windows Server, version 2004 (Server Core installation) Windows 10 Version 2004 for x64-based Systems Windows 10 Version 2004 for ARM64-based Systems Windows 10 Version 2004 for 32-bit Systems |
|
CVE-2021-28476 |
Windows Server 2012 R2 (Server Core installation) Windows Server 2012 R2 Windows Server 2012 (Server Core installation) Windows Server 2012 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) Windows Server 2008 R2 for x64-based Systems Service Pack 1 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) Windows Server 2008 for x64-based Systems Service Pack 2 Windows 8.1 for x64-based systems Windows 7 for x64-based Systems Service Pack 1 Windows Server 2016 (Server Core installation) Windows Server 2016 Windows 10 Version 1607 for x64-based Systems Windows 10 for x64-based Systems Windows Server, version 20H2 (Server Core Installation) Windows 10 Version 20H2 for x64-based Systems Windows Server, version 2004 (Server Core installation) Windows 10 Version 2004 for x64-based Systems Windows Server, version 1909 (Server Core installation) Windows 10 Version 1909 for x64-based Systems Windows Server 2019 (Server Core installation) Windows Server 2019 Windows 10 Version 1809 for x64-based Systems Windows 10 Version 1803 for x64-based Systems |
|
CVE-2021-28474 CVE-2021-31181 |
Microsoft SharePoint Foundation 2013 Service Pack 1 Microsoft SharePoint Server 2019 Microsoft SharePoint Enterprise Server 2016 |
|
CVE-2021-31194 |
Windows 10 Version 2004 for x64-based Systems Windows 10 Version 2004 for ARM64-based Systems Windows 10 Version 2004 for 32-bit Systems Windows Server, version 1909 (Server Core installation) Windows 10 Version 1909 for ARM64-based Systems Windows 10 Version 20H2 for x64-based Systems Windows Server, version 2004 (Server Core installation) Windows 10 Version 1909 for x64-based Systems Windows 10 Version 1909 for 32-bit Systems Windows Server 2019 (Server Core installation) Windows Server 2019 Windows 10 Version 1809 for ARM64-based Systems Windows 10 Version 1809 for x64-based Systems Windows 10 Version 1809 for 32-bit Systems Windows 10 Version 1803 for ARM64-based Systems Windows 10 Version 1803 for x64-based Systems Windows 10 Version 1803 for 32-bit Systems Windows Server 2012 R2 (Server Core installation) Windows Server 2012 R2 Windows Server 2012 (Server Core installation) Windows Server 2012 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) Windows Server 2008 R2 for x64-based Systems Service Pack 1 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) Windows Server 2008 for x64-based Systems Service Pack 2 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) Windows Server 2008 for 32-bit Systems Service Pack 2 Windows RT 8.1 Windows 8.1 for x64-based systems Windows 8.1 for 32-bit systems Windows 7 for x64-based Systems Service Pack 1 Windows 7 for 32-bit Systems Service Pack 1 Windows Server 2016 (Server Core installation) Windows Server 2016 Windows 10 Version 1607 for x64-based Systems Windows 10 Version 1607 for 32-bit Systems Windows 10 for x64-based Systems Windows 10 for 32-bit Systems Windows Server, version 20H2 (Server Core Installation) Windows 10 Version 20H2 for ARM64-based Systems Windows 10 Version 20H2 for 32-bit Systems |
|
CVE-2021-31207 |
Microsoft Exchange Server 2019 Cumulative Update 8 Microsoft Exchange Server 2016 Cumulative Update 19 Microsoft Exchange Server 2016 Cumulative Update 20 Microsoft Exchange Server 2019 Cumulative Update 9 Microsoft Exchange Server 2013 Cumulative Update 23 |
ËÄ. Îó²î·À»¤
4.1 ²¹¶¡¸üÐÂ
ÏÖÔÚ΢Èí¹Ù·½ÒÑÕë¶ÔÊÜÖ§³ÖµÄ²úÆ·°æ±¾Ðû²¼ÁËÐÞ¸´ÒÔÉÏÎó²îµÄÇå¾²²¹¶¡£¬Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì×°Öò¹¶¡¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide/en-us/releaseNote/2021-May
×¢£ºÓÉÓÚÍøÂçÎÊÌâ¡¢ÅÌËã»úÇéÐÎÎÊÌâµÈÔµ¹ÊÔÓÉ£¬Windows UpdateµÄ²¹¶¡¸üпÉÄÜ·ºÆðʧ°Ü¡£Óû§ÔÚ×°Öò¹¶¡ºó£¬Ó¦ÊµÊ±¼ì²é²¹¶¡ÊÇ·ñÀֳɸüС£
ÓÒ¼üµã»÷Windowsͼ±ê£¬Ñ¡Ôñ“ÉèÖÃ(N)”£¬Ñ¡Ôñ“¸üкÍÇå¾²”-“Windows¸üД£¬Éó²é¸ÃÒ³ÃæÉϵÄÌáÐÑÐÅÏ¢£¬Ò²¿Éµã»÷“Éó²é¸üÐÂÀúÊ·¼Í¼”Éó²éÀúÊ·¸üÐÂÇéÐΡ£
Õë¶ÔδÀÖ³É×°ÖõĸüУ¬¿Éµã»÷¸üÐÂÃû³ÆÌø×ªµ½Î¢Èí¹Ù·½ÏÂÔØÒ³Ãæ£¬½¨ÒéÓû§µã»÷¸ÃÒ³ÃæÉϵÄÁ´½Ó£¬×ªµ½“Microsoft¸üÐÂĿ¼”ÍøÕ¾ÏÂÔØ×ÔÁ¦³ÌÐò°ü²¢×°Öá£
? 2025 NSFOCUS AG¹«Ë¾¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ