本月补丁星期二活动共计修复108处漏洞 其中19处为关键漏洞

2021年04月14日 08:09 次阅读 稿源:Win10s.COM 条评论

对于普通用户来说,本月补丁星期二活动发布的 Windows 10 累积更新并没有什么新的内容,主要是对系统安全性进行优化。不过对于 Windows 和 Microsoft Exchange 管理员来说,最近几个月一直非常忙碌,4 月累积更新修复了 5 个零日漏洞和更多的 Exchange 漏洞

patch-tuesday-large.jpg

在今天的更新中,微软共计修复了 108 处漏洞,其中 19 个标记为“关键漏洞”(Critial),89 个标记为“重要漏洞”(Important)。而且这些漏洞并不包含本月初发布的 6 个 Chromium Edge 漏洞。

此外,今天微软还修复了 5 个公开披露的零日漏洞,其中 1 个已知用于网络攻击。更糟糕的是,微软修复了 NSA 发现的 4 个关键的 Microsoft Exchange 漏洞。作为今天补丁星期二的一部分,微软已经修复了 4 个公开披露的漏洞和一个主动利用的漏洞。

以下 4 个漏洞微软表示已经公开暴露,但没有证据表明被黑客利用。

CVE-2021-27091 - RPC端点映射器服务权限提升的漏洞

CVE-2021-28312 - Windows NTFS 拒绝服务漏洞

CVE-2021-28437 - Windows 安装程序信息泄露漏洞 - PolarBear

CVE-2021-28458 - Azure ms-rest-nodeauth 库的权限提升漏洞

卡巴斯基研究人员 Boris Larin 发现的以下漏洞已经被黑客组织 BITTER APT 利用。

CVE-2021-28310 - Win32k 提升权限漏洞

卡巴斯基在博文中解释道:“不幸的是,我们无法捕捉到一个完整的链条,所以我们不知道该漏洞是否与另一个浏览器零日配合使用,或者与已知的、打过补丁的漏洞结合在一起使用”。

微软 Exchange 的管理员们并没有得到任何休息,因为今天又有 4 个 NSA 发现的关键远程代码执行漏洞在微软 Exchange 中得到了修复。其中两个漏洞是预认证,这意味着它们不需要攻击者先登录服务器。

CVE-2021-28480--微软Exchange服务器远程代码执行漏洞

CVE-2021-28481 - 微软Exchange服务器远程代码执行漏洞

CVE-2021-28482 - 微软Exchange服务器远程代码执行漏洞

CVE-2021-28483 - 微软Exchange服务器远程代码执行漏洞

完整报告如下

TagCVE IDCVE TitleSeverity
Azure AD Web Sign-inAzure AD Web Sign-in Security Feature Bypass VulnerabilityImportant
Azure DevOpsAzure DevOps Server Spoofing VulnerabilityImportant
Azure DevOpsAzure DevOps Server and Team Foundation Server Information Disclosure VulnerabilityImportant
Azure SphereAzure Sphere Unsigned Code Execution VulnerabilityCritical
Microsoft Edge (Chromium-based)Chromium: CVE-2021-21199 Use Use after free in AuraUnknown
Microsoft Edge (Chromium-based)Chromium: CVE-2021-21194 Use after free in screen captureUnknown
Microsoft Edge (Chromium-based)Chromium: CVE-2021-21197 Heap buffer overflow in TabStripUnknown
Microsoft Edge (Chromium-based)Chromium: CVE-2021-21198 Out of bounds read in IPCUnknown
Microsoft Edge (Chromium-based)Chromium: CVE-2021-21195 Use after free in V8Unknown
Microsoft Edge (Chromium-based)Chromium: CVE-2021-21196 Heap buffer overflow in TabStripUnknown
Microsoft Exchange ServerMicrosoft Exchange Server Remote Code Execution VulnerabilityCritical
Microsoft Exchange ServerMicrosoft Exchange Server Remote Code Execution VulnerabilityCritical
Microsoft Exchange ServerMicrosoft Exchange Server Remote Code Execution VulnerabilityCritical
Microsoft Exchange ServerMicrosoft Exchange Server Remote Code Execution VulnerabilityCritical
Microsoft Graphics ComponentWindows GDI+ Remote Code Execution VulnerabilityImportant
Microsoft Graphics ComponentWindows GDI+ Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentWindows GDI+ Remote Code Execution VulnerabilityImportant
Microsoft Graphics ComponentWindows GDI+ Remote Code Execution VulnerabilityImportant
Microsoft Internet Messaging APIMicrosoft Internet Messaging API Remote Code Execution VulnerabilityImportant
Microsoft NTFSWindows NTFS Denial of Service VulnerabilityModerate
Microsoft NTFSNTFS Elevation of Privilege VulnerabilityImportant
Microsoft Office ExcelMicrosoft Excel Information Disclosure VulnerabilityImportant
Microsoft Office ExcelMicrosoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelMicrosoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelMicrosoft Office Remote Code Execution VulnerabilityImportant
Microsoft Office OutlookMicrosoft Outlook Memory Corruption VulnerabilityImportant
Microsoft Office SharePointMicrosoft SharePoint Denial of Service UpdateImportant
Microsoft Office WordMicrosoft Word Remote Code Execution VulnerabilityImportant
Microsoft Windows Codecs LibraryVP9 Video Extensions Remote Code Execution VulnerabilityImportant
Microsoft Windows Codecs LibraryRaw Image Extension Remote Code Execution VulnerabilityImportant
Microsoft Windows Codecs LibraryWindows Media Photo Codec Information Disclosure VulnerabilityImportant
Microsoft Windows Codecs LibraryRaw Image Extension Remote Code Execution VulnerabilityImportant
Microsoft Windows Codecs LibraryMicrosoft Windows Codecs Library Information Disclosure VulnerabilityImportant
Microsoft Windows DNSWindows DNS Information Disclosure VulnerabilityImportant
Microsoft Windows DNSWindows DNS Information Disclosure VulnerabilityImportant
Microsoft Windows SpeechWindows Speech Runtime Elevation of Privilege VulnerabilityImportant
Microsoft Windows SpeechWindows Speech Runtime Elevation of Privilege VulnerabilityImportant
Microsoft Windows SpeechWindows Speech Runtime Elevation of Privilege VulnerabilityImportant
Open Source SoftwareAzure ms-rest-nodeauth Library Elevation of Privilege VulnerabilityImportant
Role: Hyper-VWindows Hyper-V Information Disclosure VulnerabilityImportant
Role: Hyper-VWindows Hyper-V Elevation of Privilege VulnerabilityImportant
Role: Hyper-VWindows Hyper-V Security Feature Bypass VulnerabilityImportant
Role: Hyper-VWindows Hyper-V Denial of Service VulnerabilityImportant
Visual StudioVisual Studio Installer Elevation of Privilege VulnerabilityImportant
Visual Studio CodeVisual Studio Code Remote Code Execution VulnerabilityImportant
Visual Studio CodeRemote Development Extension for Visual Studio Code Remote Code Execution VulnerabilityImportant
Visual Studio CodeVisual Studio Code Remote Code Execution VulnerabilityImportant
Visual Studio CodeVisual Studio Code Remote Code Execution VulnerabilityImportant
Visual Studio CodeVisual Studio Code Remote Code Execution VulnerabilityImportant
Visual Studio CodeVisual Studio Code Remote Code Execution VulnerabilityImportant
Visual Studio Code - GitHub Pull Requests and Issues ExtensionVisual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution VulnerabilityImportant
Visual Studio Code - Kubernetes ToolsVisual Studio Code Kubernetes Tools Remote Code Execution VulnerabilityImportant
Visual Studio Code - Maven for Java ExtensionVisual Studio Code Maven for Java Extension Remote Code Execution VulnerabilityImportant
Windows Application Compatibility CacheWindows Application Compatibility Cache Denial of Service VulnerabilityImportant
Windows AppX Deployment ExtensionsWindows AppX Deployment Server Denial of Service VulnerabilityImportant
Windows Console DriverWindows Console Driver Denial of Service VulnerabilityImportant
Windows Console DriverWindows Console Driver Denial of Service VulnerabilityImportant
Windows Diagnostic HubDiagnostics Hub Standard Collector Service Elevation of Privilege VulnerabilityImportant
Windows Diagnostic HubDiagnostics Hub Standard Collector Service Elevation of Privilege VulnerabilityImportant
Windows Diagnostic HubDiagnostics Hub Standard Collector Service Elevation of Privilege VulnerabilityImportant
Windows Early Launch Antimalware DriverWindows Early Launch Antimalware Driver Security Feature Bypass VulnerabilityImportant
Windows ELAMWindows Early Launch Antimalware Driver Security Feature Bypass VulnerabilityImportant
Windows Event TracingWindows Event Tracing Elevation of Privilege VulnerabilityImportant
Windows Event TracingWindows Event Tracing Information Disclosure VulnerabilityImportant
Windows InstallerWindows Installer Spoofing VulnerabilityImportant
Windows InstallerWindows Installer Elevation of Privilege VulnerabilityImportant
Windows InstallerWindows Installer Information Disclosure VulnerabilityImportant
Windows InstallerWindows Installer Elevation of Privilege VulnerabilityImportant
Windows KernelWindows Kernel Information Disclosure VulnerabilityImportant
Windows KernelWindows Kernel Information Disclosure VulnerabilityImportant
Windows Media PlayerWindows Media Video Decoder Remote Code Execution VulnerabilityCritical
Windows Media PlayerWindows Media Video Decoder Remote Code Execution VulnerabilityCritical
Windows Network File SystemWindows Network File System Remote Code Execution VulnerabilityImportant
Windows Overlay FilterWindows Overlay Filter Information Disclosure VulnerabilityImportant
Windows PortmappingWindows Portmapping Information Disclosure VulnerabilityImportant
Windows RegistryRPC Endpoint Mapper Service Elevation of Privilege VulnerabilityImportant
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityCritical
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityCritical
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityCritical
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityCritical
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityCritical
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityCritical
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityCritical
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityCritical
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityCritical
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityCritical
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityCritical
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeRemote Procedure Call Runtime Remote Code Execution VulnerabilityCritical
Windows Resource ManagerWindows Resource Manager PSM Service Extension Elevation of Privilege VulnerabilityImportant
Windows Secure Kernel ModeWindows Secure Kernel Mode Elevation of Privilege VulnerabilityImportant
Windows Services and Controller AppWindows Services and Controller App Elevation of Privilege VulnerabilityImportant
Windows SMB ServerWindows SMB Information Disclosure VulnerabilityImportant
Windows SMB ServerWindows SMB Information Disclosure VulnerabilityImportant
Windows TCP/IPWindows TCP/IP Driver Denial of Service VulnerabilityImportant
Windows TCP/IPWindows TCP/IP Information Disclosure VulnerabilityImportant
Windows TCP/IPWindows TCP/IP Driver Denial of Service VulnerabilityImportant
Windows Win32KWin32k Elevation of Privilege VulnerabilityImportant
Windows Win32KWin32k Elevation of Privilege VulnerabilityImportant
Windows WLAN Auto Config ServiceWindows WLAN AutoConfig Service Security Feature Bypass VulnerabilityImportant

对文章打分

本月补丁星期二活动共计修复108处漏洞 其中19处为关键漏洞

1 (8%)
已有 条意见

    最新资讯

    加载中...

    编辑精选

    加载中...

    热门评论

      Top 10

      招聘