近日,微软官方发布了多个安全漏洞的公告,包括MicrosoftWindows Active Directory 权限许可和访问控制问题漏洞(CNNVD-202111-788、CVE-2021-42291)、Microsoft Windows ActiveDirectory 权限许可和访问控制问题漏洞(CNNVD-202111-789、CVE-2021-42287)等多个漏洞。成功利用上述漏洞的攻击者可以在目标系统上执行任意代码、获取用户数据,提升权限等。微软多个产品和系统受漏洞影响。目前,微软官方已经发布了漏洞修复补丁,建议用户及时确认是否受到漏洞影响,尽快采取修补措施。
一、漏洞介绍
2021年11月9日,微软发布了2021年11月份安全更新,共51个漏洞的补丁程序,CNNVD对这些漏洞进行了收录。本次更新主要涵盖了Microsoft Windows 和Windows 组件、Microsoft Windows CodecsLibrary、Microsoft Azure、Microsoft3D Viewer、Microsoft Windows Feedback Hub、Microsoft Azure Sphere等。CNNVD对其危害等级进行了评价,其中高危漏洞25个,中危漏洞22个,低危漏洞4个。微软多个产品和系统版本受漏洞影响,具体影响范围可访问https://portal.msrc.microsoft.com/zh-cn/security-guidance查询。
二、漏洞详情
此次更新共包括51个漏洞的补丁程序,其中高危漏洞25个,中危漏洞22个,低危漏洞4个。
序号 | 漏洞名称 | CNNVD编号 | CVE编号 | 危害等级 | 官方链接 |
1 | Microsoft Windows Active Directory权限许可和访问控制问题漏洞 | CNNVD-202111-788 | CVE-2021-42291 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42291 |
2 | Microsoft Windows Active Directory权限许可和访问控制问题漏洞 | CNNVD-202111-789 | CVE-2021-42287 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287 |
3 | Microsoft Windows Kernel权限许可和访问控制问题漏洞 | CNNVD-202111-791 | CVE-2021-42285 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42285 |
4 | Microsoft Windows权限许可和访问控制问题漏洞 | CNNVD-202111-792 | CVE-2021-42286 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42286 |
5 | Microsoft Windows NTFS权限许可和访问控制问题漏洞 | CNNVD-202111-795 | CVE-2021-42283 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42283 |
6 | Microsoft Windows Active Directory权限许可和访问控制问题漏洞 | CNNVD-202111-796 | CVE-2021-42282 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42282 |
7 | Microsoft Windows Active Directory权限许可和访问控制问题漏洞 | CNNVD-202111-797 | CVE-2021-42278 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278 |
8 | Microsoft Windows NTFS代码注入漏洞 | CNNVD-202111-803 | CVE-2021-41378 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41378 |
9 | Microsoft Windows Codecs Library代码注入漏洞 | CNNVD-202111-804 | CVE-2021-42276 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42276 |
10 | Microsoft Windows Fastfat Driver权限许可和访问控制问题漏洞 | CNNVD-202111-805 | CVE-2021-41377 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41377 |
11 | Microsoft Windows COM代码注入漏洞 | CNNVD-202111-806 | CVE-2021-42275 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42275 |
12 | Microsoft Windows NTFS权限许可和访问控制问题漏洞 | CNNVD-202111-808 | CVE-2021-4137 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4137 |
13 | Microsoft Windows NTFS权限许可和访问控制问题漏洞 | CNNVD-202111-809 | CVE-2021-41367 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41367 |
14 | Microsoft Windows权限许可和访问控制问题漏洞 | CNNVD-202111-81 | CVE-2021-41366 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41366 |
15 | Microsoft Windows输入验证错误漏洞 | CNNVD-202111-811 | CVE-2021-41356 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41356 |
16 | Microsoft 3D Viewer代码注入漏洞 | CNNVD-202111-812 | CVE-2021-43208 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43208 |
17 | Microsoft 3D Viewer代码注入漏洞 | CNNVD-202111-813 | CVE-2021-43209 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43209 |
18 | Microsoft Windows rdp代码注入漏洞 | CNNVD-202111-815 | CVE-2021-38666 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38666 |
19 | Microsoft Windows Virtual Machine代码注入漏洞 | CNNVD-202111-827 | CVE-2021-26443 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26443 |
20 | Microsoft Dynamics代码注入漏洞 | CNNVD-202111-835 | CVE-2021-42316 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42316 |
21 | Microsoft Visual Studio权限许可和访问控制问题漏洞 | CNNVD-202111-839 | CVE-2021-42322 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42322 |
22 | Microsoft Exchange Server输入验证错误漏洞 | CNNVD-202111-842 | CVE-2021-42321 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42321 |
23 | Microsoft Office代码注入漏洞 | CNNVD-202111-848 | CVE-2021-40442 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40442 |
24 | Microsoft Office输入验证错误漏洞 | CNNVD-202111-857 | CVE-2021-42292 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42292 |
25 | Microsoft Office代码注入漏洞 | CNNVD-202111-858 | CVE-2021-42296 | 高危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42296 |
26 | Microsoft Windows Hello安全特征问题特征问题漏洞 | CNNVD-202111-786 | CVE-2021-42288 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42288 |
27 | Microsoft Hyper-V输入验证错误漏洞 | CNNVD-202111-794 | CVE-2021-42284 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42284 |
28 | Microsoft Windows Feedback Hub权限许可和访问控制问题漏洞 | CNNVD-202111-798 | CVE-2021-4228 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4228 |
29 | Microsoft Windows Scripting缓冲区错误漏洞 | CNNVD-202111-799 | CVE-2021-42279 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42279 |
30 | Microsoft Hyper-V输入验证错误漏洞 | CNNVD-202111-8 | CVE-2021-42274 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42274 |
31 | Microsoft Windows Installer权限许可和访问控制问题漏洞 | CNNVD-202111-802 | CVE-2021-41379 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41379 |
32 | Microsoft Windows rdp信息泄露漏洞 | CNNVD-202111-807 | CVE-2021-41371 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41371 |
33 | Microsoft Windows Desktop Bridge权限许可和访问控制问题漏洞 | CNNVD-202111-814 | CVE-2021-36957 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36957 |
34 | Microsoft Exchange Server安全漏洞 | CNNVD-202111-816 | CVE-2021-41349 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41349 |
35 | Microsoft Windows rdp信息泄露漏洞 | CNNVD-202111-817 | CVE-2021-38631 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38631 |
36 | Microsoft Windows rdp信息泄露漏洞 | CNNVD-202111-818 | CVE-2021-38665 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38665 |
37 | Microsoft Azure Sphere数据伪造问题漏洞 | CNNVD-202111-819 | CVE-2021-423 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-423 |
38 | Microsoft Power BI Report Server安全漏洞 | CNNVD-202111-821 | CVE-2021-41372 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41372 |
39 | Microsoft Office代码注入漏洞 | CNNVD-202111-822 | CVE-2021-41368 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41368 |
40 | Microsoft Azure Sphere安全漏洞 | CNNVD-202111-823 | CVE-2021-41375 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41375 |
41 | Microsoft Azure Sphere输入验证错误漏洞 | CNNVD-202111-824 | CVE-2021-41374 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41374 |
42 | Microsoft Azure权限许可和访问控制问题漏洞 | CNNVD-202111-826 | CVE-2021-42304 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42304 |
43 | Microsoft Azure权限许可和访问控制问题漏洞 | CNNVD-202111-83 | CVE-2021-42302 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42302 |
44 | Microsoft Azure权限许可和访问控制问题漏洞 | CNNVD-202111-831 | CVE-2021-42303 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42303 |
45 | Microsoft Edge安全漏洞 | CNNVD-202111-838 | CVE-2021-41351 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41351 |
46 | Microsoft Azure信息泄露漏洞 | CNNVD-202111-84 | CVE-2021-41373 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41373 |
47 | Microsoft Exchange Server安全漏洞 | CNNVD-202111-852 | CVE-2021-42305 | 中危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42305 |
48 | Microsoft Azure Sphere缓冲区错误漏洞 | CNNVD-202111-82 | CVE-2021-41376 | 低危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41376 |
49 | Microsoft Azure信息泄露漏洞 | CNNVD-202111-828 | CVE-2021-42323 | 低危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42323 |
50 | Microsoft Azure信息泄露漏洞 | CNNVD-202111-829 | CVE-2021-26444 | 低危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26444 |
51 | Microsoft Azure信息泄露漏洞 | CNNVD-202111-832 | CVE-2021-42301 | 低危 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42301 |
三、修复建议
目前,微软官方已经发布补丁修复了上述漏洞,建议用户及时确认漏洞影响,尽快采取修补措施。微软官方补丁下载地址:
https://msrc.microsoft.com/update-guide/en-us
CNNVD将继续跟踪上述漏洞的相关情况,及时发布相关信息。如有需要,可与CNNVD联系。联系方式: cnnvdvul@itsec.gov.cn
声明:本文来自CNNVD安全动态,版权归作者所有。文章内容仅代表作者独立观点,不代表安全内参立场,转载目的在于传递更多信息。如有侵权,请联系 anquanneican@163.com。