近日,微软官方发布了多个安全漏洞的公告,包括MicrosoftWindows TCP/IP component 缓冲区错误漏洞(CNNVD-202108-856、CVE-2021-26424)、MicrosoftWindows代码注入漏洞(CNNVD-202108-863、CVE-2021-26432)等多个漏洞。成功利用上述漏洞的攻击者可以在目标系统上执行任意代码、获取用户数据,提升权限等。微软多个产品和系统受漏洞影响。目前,微软官方已经发布漏洞修复补丁,建议用户及时确认是否受到漏洞影响,尽快采取修补措施。
一、漏洞介绍
2021年8月11日,微软发布了2021年8月份安全更新,共44个漏洞的补丁程序,CNNVD对这些漏洞进行了收录。本次更新主要涵盖了Windows操作系统、MicrosoftGraphics Component、Remote Desktop Client、Windows NTLM、Windows TCP/IP、Windows UpdateAssistant等。CNNVD对其危害等级进行了评价,其中超危漏洞2个、高危漏洞有26个,中危漏洞16个。微软多个产品和系统版本受漏洞影响,具体影响范围可访问https://portal.msrc.microsoft.com/zh-cn/security-guidance查询。
二、漏洞详情
此次更新共包括44个漏洞的补丁程序,其中超危漏洞2个、高危漏洞有26个,中危漏洞16个。
序号 | 漏洞名称 | CNNVD编号 | CVE编号 | 危害等级 | 官方链接 |
1 | Microsoft Windows TCP/IP component 缓冲区错误漏洞 | CNNVD-202108-856 | CVE-2021-26424 | 超危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26424 |
2 | Microsoft Windows代码注入漏洞 | CNNVD-202108-863 | CVE-2021-26432 | 超危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26432 |
3 | Microsoft Windows Update Assistant 缓冲区错误漏洞 | CNNVD-202108-834 | CVE-2021-36948 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36948 |
4 | Microsoft Windows Print Spooler Components 代码注入漏洞 | CNNVD-202108-835 | CVE-2021-36947 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36947 |
5 | Microsoft Windows 安全漏洞 | CNNVD-202108-836 | CVE-2021-36942 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36942 |
6 | Microsoft Windows Print Spooler Components 代码注入漏洞 | CNNVD-202108-837 | CVE-2021-36936 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36936 |
7 | Microsoft Windows Codecs 代码注入漏洞 | CNNVD-202108-838 | CVE-2021-36937 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36937 |
8 | Microsoft Windows 信息泄露漏洞 | CNNVD-202108-840 | CVE-2021-36933 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36933 |
9 | Microsoft Windows Media Foundation权限许可和访问控制问题漏洞 | CNNVD-202108-841 | CVE-2021-36927 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36927 |
10 | Microsoft Windows Bluetooth Service 权限许可和访问控制问题漏洞 | CNNVD-202108-842 | CVE-2021-34537 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34537 |
11 | Microsoft Windows 信息泄露漏洞 | CNNVD-202108-843 | CVE-2021-36932 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36932 |
12 | Microsoft Dynamics 代码注入漏洞 | CNNVD-202108-844 | CVE-2021-34524 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34524 |
13 | Microsoft Windows 信息泄露漏洞 | CNNVD-202108-845 | CVE-2021-36926 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36926 |
14 | Microsoft Windows Storage Spaces Controller 权限许可和访问控制问题漏洞 | CNNVD-202108-850 | CVE-2021-34536 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34536 |
15 | Microsoft Remote Desktop Protocol Client 代码注入漏洞 | CNNVD-202108-851 | CVE-2021-34535 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34535 |
16 | Microsoft Windows Print Spooler Components 权限许可和访问控制问题漏洞 | CNNVD-202108-853 | CVE-2021-34483 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34483 |
17 | Microsoft Graphics Components 代码注入漏洞 | CNNVD-202108-854 | CVE-2021-34530 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34530 |
18 | Microsoft Windows 产品权限许可和访问控制问题漏洞 | CNNVD-202108-855 | CVE-2021-34484 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34484 |
19 | Microsoft Graphics Components 代码注入漏洞 | CNNVD-202108-857 | CVE-2021-34533 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34533 |
20 | Microsoft Office 代码注入漏洞 | CNNVD-202108-859 | CVE-2021-34478 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34478 |
21 | Microsoft Windows Event Tracing 权限许可和访问控制问题漏洞 | CNNVD-202108-864 | CVE-2021-34487 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34487 |
22 | Microsoft Windows Update Assistant 权限许可和访问控制问题漏洞 | CNNVD-202108-866 | CVE-2021-26431 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26431 |
23 | Microsoft Office和Microsoft SharePoint 安全漏洞 | CNNVD-202108-868 | CVE-2021-36940 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36940 |
24 | Microsoft Office 代码注入漏洞 | CNNVD-202108-870 | CVE-2021-36941 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36941 |
25 | Microsoft Azure Sphere 权限许可和访问控制问题漏洞 | CNNVD-202108-871 | CVE-2021-26429 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26429 |
26 | Microsoft Windows 权限许可和访问控制问题漏洞 | CNNVD-202108-873 | CVE-2021-26426 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26426 |
27 | Microsoft Windows Event Tracing权限许可和访问控制问题漏洞 | CNNVD-202108-874 | CVE-2021-26425 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26425 |
28 | Microsoft Azure和Microsoft Azure Active Directory Connect 授权问题漏洞 | CNNVD-202108-877 | CVE-2021-36949 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36949 |
29 | Microsoft Windows Cryptographic Services 信息泄露漏洞 | CNNVD-202108-839 | CVE-2021-36938 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36938 |
30 | Microsoft Dynamics 跨站脚本漏洞 | CNNVD-202108-846 | CVE-2021-36950 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36950 |
31 | Microsoft .NET Core和Microsoft Visual Studio 输入验证错误漏洞 | CNNVD-202108-847 | CVE-2021-26423 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26423 |
32 | Microsoft .NET Core和Microsoft Visual Studio 信息泄露漏洞 | CNNVD-202108-848 | CVE-2021-34485 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34485 |
33 | Microsoft .NET Core和Microsoft Visual Studio 信息泄露漏洞 | CNNVD-202108-849 | CVE-2021-34532 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34532 |
34 | Microsoft Windows Update Assistant 权限许可和访问控制问题漏洞 | CNNVD-202108-852 | CVE-2021-36945 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36945 |
35 | Microsoft Azure 权限许可和访问控制问题漏洞 | CNNVD-202108-858 | CVE-2021-36943 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36943 |
36 | Microsoft Windows MSHTML Platform 代码注入漏洞 | CNNVD-202108-860 | CVE-2021-34534 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34534 |
37 | Microsoft Azure 权限许可和访问控制问题漏洞 | CNNVD-202108-861 | CVE-2021-33762 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-33762 |
38 | Microsoft Windows 信息泄露漏洞 | CNNVD-202108-862 | CVE-2021-26433 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26433 |
39 | Microsoft Windows Defender 权限许可和访问控制问题漏洞 | CNNVD-202108-865 | CVE-2021-34471 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34471 |
40 | Microsoft Windows Event Tracing 权限许可和访问控制问题漏洞 | CNNVD-202108-867 | CVE-2021-34486 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34486 |
41 | Microsoft Azure Sphere 输入验证错误漏洞 | CNNVD-202108-869 | CVE-2021-26428 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26428 |
42 | Microsoft Azure Sphere 输入验证错误漏洞 | CNNVD-202108-872 | CVE-2021-26430 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26430 |
43 | 多款Microsoft产品缓冲区错误漏洞 | CNNVD-202108-875 | CVE-2021-34480 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34480 |
44 | Microsoft Dynamics 跨站脚本漏洞 | CNNVD-202108-876 | CVE-2021-36946 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36946 |
三、修复建议
目前,微软官方已经发布补丁修复了上述漏洞,建议用户及时确认漏洞影响,尽快采取修补措施。微软官方补丁下载地址:
https://msrc.microsoft.com/update-guide/en-us
CNNVD将继续跟踪上述漏洞的相关情况,及时发布相关信息。如有需要,可与CNNVD联系。联系方式:cnnvd@itsec.gov.cn
声明:本文来自CNNVD安全动态,版权归作者所有。文章内容仅代表作者独立观点,不代表安全内参立场,转载目的在于传递更多信息。如有侵权,请联系 anquanneican@163.com。