近日,微软官方发布了多个安全漏洞的公告,包括Microsoft Exchange Server 权限许可和访问控制问题漏洞(CNNVD-202110-795、CVE-2021-26427)、Microsoft Office 代码注入漏洞(CNNVD-202110-856、CVE-2021-40479)等多个漏洞。成功利用上述漏洞的攻击者可以在目标系统上执行任意代码、获取用户数据,提升权限等。微软多个产品和系统受漏洞影响。目前,微软官方已经发布了漏洞修复补丁,建议用户及时确认是否受到漏洞影响,尽快采取修补措施。

一、漏洞介绍

2021年10月13日,微软发布了2021年10月份安全更新,共69个漏洞的补丁程序,CNNVD对这些漏洞进行了收录。本次更新主要涵盖了Microsoft Windows 和 Windows 组件、Microsoft Edge、Exchange Server、.NET Core 和 Visual Studio、Microsoft Office、SharePoint Server、Microsoft Dynamics、InTune、System Center Operations Manager等。CNNVD对其危害等级进行了评价,其中超危漏洞1个,高危漏洞41个,中危漏洞26个,低危漏洞1个。微软多个产品和系统版本受漏洞影响,具体影响范围可访问https://portal.msrc.microsoft.com/zh-cn/security-guidance查询。

二、漏洞详情

此次更新共包括69个漏洞的补丁程序,其中超危漏洞1个,高危漏洞41个,中危漏洞26个,低危漏洞1个。

序号

漏洞名称

CNNVD编号

CVE编号

危害等级

官方链接

1

Microsoft Exchange Server 权限许可和访问控制问题漏洞

CNNVD-202110-795

CVE-2021-26427

超危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26427

2

Microsoft Windows AppX Deployment Extensions权限许可和访问控制问题漏洞

CNNVD-202110-788

CVE-2021-41347

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41347

3

Microsoft Win32k 权限许可和访问控制问题漏洞

CNNVD-202110-789

CVE-2021-41357

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41357

4

Microsoft Windows Storage Spaces Controller 权限许可和访问控制问题漏洞

CNNVD-202110-793

CVE-2021-41345

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41345

5

Microsoft Exchange Server 权限许可和访问控制问题漏洞

CNNVD-202110-794

CVE-2021-41348

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41348

6

Microsoft Exchange Server 输入验证错误漏洞

CNNVD-202110-797

CVE-2021-34453

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34453

7

Microsoft Graphics Components 代码注入漏洞

CNNVD-202110-801

CVE-2021-41340

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41340

8

Microsoft Windows Desktop Bridge 权限许可和访问控制问题漏洞

CNNVD-202110-804

CVE-2021-41334

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41334

9

Microsoft Windows Kernel 权限许可和访问控制问题漏洞

CNNVD-202110-806

CVE-2021-41335

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41335

10

Microsoft Windows Codecs 代码注入漏洞

CNNVD-202110-808

CVE-2021-41331

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41331

11

Microsoft Windows Codecs 代码注入漏洞

CNNVD-202110-809

CVE-2021-41330

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41330

12

Microsoft Windows Storage Spaces Controller 权限许可和访问控制问题漏洞

CNNVD-202110-811

CVE-2021-40489

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40489

13

Microsoft Windows Event Tracing权限许可和访问控制问题漏洞

CNNVD-202110-812

CVE-2021-40477

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40477

14

Microsoft Windows Storage Spaces Controller 权限许可和访问控制问题漏洞

CNNVD-202110-813

CVE-2021-40478

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40478

15

Microsoft Windows 代码注入漏洞

CNNVD-202110-814

CVE-2021-40469

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40469

16

Microsoft Windows Common Log File System Driver 权限许可和访问控制问题漏洞

CNNVD-202110-815

CVE-2021-40467

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40467

17

Microsoft Windows Common Log File System Driver 权限许可和访问控制问题漏洞

CNNVD-202110-817

CVE-2021-40466

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40466

18

Microsoft Windows 权限许可和访问控制问题漏洞

CNNVD-202110-819

CVE-2021-40464

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40464

19

Microsoft Windows 输入验证错误漏洞

CNNVD-202110-820

CVE-2021-40463

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40463

20

Microsoft Windows AppContainer 权限许可和访问控制问题漏洞

CNNVD-202110-821

CVE-2021-40476

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40476

21

Microsoft Windows Codecs Library 代码注入漏洞

CNNVD-202110-822

CVE-2021-40462

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40462

22

Microsoft Windows 代码注入漏洞

CNNVD-202110-823

CVE-2021-40465

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40465

23

Microsoft Hyper-V 代码注入漏洞

CNNVD-202110-824

CVE-2021-40461

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40461

24

Microsoft Win32k 缓冲区错误漏洞

CNNVD-202110-828

CVE-2021-40449

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40449

25

Microsoft Hyper-V 代码注入漏洞

CNNVD-202110-830

CVE-2021-38672

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38672

26

Microsoft Windows Print Spooler Components 安全漏洞

CNNVD-202110-833

CVE-2021-36970

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-36970

27

Microsoft Windows 输入验证错误漏洞

CNNVD-202110-836

CVE-2021-36953

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-36953

28

Microsoft Windows Storage Spaces Controller 权限许可和访问控制问题漏洞

CNNVD-202110-840

CVE-2021-26441

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26441

29

Microsoft Office和Microsoft SharePoint 代码注入漏洞

CNNVD-202110-842

CVE-2021-41344

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41344

30

Microsoft Office和Microsoft SharePoint 代码注入漏洞

CNNVD-202110-846

CVE-2021-40487

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40487

31

Microsoft Office和Microsoft SharePoint 安全漏洞

CNNVD-202110-849

CVE-2021-40484

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40484

32

Microsoft Office 安全漏洞

CNNVD-202110-851

CVE-2021-40483

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40483

33

Microsoft Office 代码注入漏洞

CNNVD-202110-856

CVE-2021-40479

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40479

34

Microsoft Office 代码注入漏洞

CNNVD-202110-858

CVE-2021-40474

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40474

35

Microsoft Office 代码注入漏洞

CNNVD-202110-859

CVE-2021-40473

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40473

36

Microsoft Office 代码注入漏洞

CNNVD-202110-860

CVE-2021-40471

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40471

37

Microsoft Office 代码注入漏洞

CNNVD-202110-863

CVE-2021-40485

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40485

38

Microsoft Office 代码注入漏洞

CNNVD-202110-865

CVE-2021-40486

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40486

39

Microsoft Office 代码注入漏洞

CNNVD-202110-866

CVE-2021-40480

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40480

40

Microsoft Windows 权限许可和访问控制问题漏洞

CNNVD-202110-869

CVE-2021-40470

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40470

41

Microsoft Office 代码注入漏洞

CNNVD-202110-870

CVE-2021-40481

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40481

42

Microsoft System Center Operations Manager 信息泄露漏洞

CNNVD-202110-874

CVE-2021-41352

高危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41352

43

Microsoft Active Directory Federation Services 安全漏洞

CNNVD-202110-787

CVE-2021-41361

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41361

44

Microsoft Windows 安全特征问题特征问题漏洞

CNNVD-202110-791

CVE-2021-41346

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41346

45

Microsoft Exchange Server 跨站脚本漏洞

CNNVD-202110-792

CVE-2021-41350

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41350

46

Microsoft Windows 信息泄露漏洞

CNNVD-202110-796

CVE-2021-41343

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41343

47

Microsoft Windows MSHTML Platform 代码注入漏洞

CNNVD-202110-798

CVE-2021-41342

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41342

48

Microsoft DWM Core Library权限许可和访问控制问题漏洞

CNNVD-202110-800

CVE-2021-41339

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41339

49

Microsoft Windows AppContainer 安全特征问题特征问题漏洞

CNNVD-202110-802

CVE-2021-41338

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41338

50

Microsoft Windows Kernel 信息泄露漏洞

CNNVD-202110-803

CVE-2021-41336

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41336

51

Microsoft Windows 安全特征问题特征问题漏洞

CNNVD-202110-805

CVE-2021-41337

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41337

52

Microsoft Windows Print Spooler Components 信息泄露漏洞

CNNVD-202110-807

CVE-2021-41332

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41332

53

Microsoft Windows Storage Spaces Controller 权限许可和访问控制问题漏洞

CNNVD-202110-810

CVE-2021-40488

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40488

54

Microsoft Windows 信息泄露漏洞

CNNVD-202110-816

CVE-2021-40468

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40468

55

Microsoft Windows Cloud Files Mini Filter Driver 信息泄露漏洞

CNNVD-202110-818

CVE-2021-40475

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40475

56

Microsoft Windows Remote Procedure Call Runtime安全特征问题特征问题漏洞

CNNVD-202110-825

CVE-2021-40460

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40460

57

Microsoft Windows Server 安全特征问题特征问题漏洞

CNNVD-202110-826

CVE-2021-40456

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40456

58

Microsoft Windows Installer 安全漏洞

CNNVD-202110-827

CVE-2021-40455

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40455

59

Microsoft Win32k 权限许可和访问控制问题漏洞

CNNVD-202110-829

CVE-2021-40450

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40450

60

Microsoft Windows exFAT File System 信息泄露漏洞

CNNVD-202110-831

CVE-2021-38663

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38663

61

Microsoft Windows信息泄露漏洞

CNNVD-202110-832

CVE-2021-38662

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38662

62

Microsoft Windows Common Log File System Driver 权限许可和访问控制问题漏洞

CNNVD-202110-834

CVE-2021-40443

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40443

63

Microsoft HTTP.sys 权限许可和访问控制问题漏洞

CNNVD-202110-835

CVE-2021-26442

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26442

64

Microsoft Office 信息泄露漏洞

CNNVD-202110-853

CVE-2021-40482

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40482

65

Microsoft Dynamics 365和Microsoft Dynamics 跨站脚本漏洞

CNNVD-202110-857

CVE-2021-40457

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40457

66

Microsoft Office 信息泄露漏洞

CNNVD-202110-861

CVE-2021-40472

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40472

67

Microsoft Dynamics 365和Microsoft Dynamics 跨站脚本漏洞

CNNVD-202110-871

CVE-2021-41354

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41354

68

Microsoft Dynamics 365和Microsoft Dynamics 安全漏洞

CNNVD-202110-873

CVE-2021-41353

中危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41353

69

Microsoft Intune 安全特征问题特征问题漏洞

CNNVD-202110-896

CVE-2021-41363

低危

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41363

三、修复建议

目前,微软官方已经发布补丁修复了上述漏洞,建议用户及时确认漏洞影响,尽快采取修补措施。微软官方补丁下载地址:

https://msrc.microsoft.com/update-guide/en-us

CNNVD将继续跟踪上述漏洞的相关情况,及时发布相关信息。如有需要,可与CNNVD联系。联系方式: cnnvdvul@itsec.gov.cn

声明:本文来自CNNVD安全动态,版权归作者所有。文章内容仅代表作者独立观点,不代表安全内参立场,转载目的在于传递更多信息。如有侵权,请联系 anquanneican@163.com。