¡¾Îó²îͨ¸æ¡¿Microsoft 1Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-01-13

0x00 Îó²î¸ÅÊö

2021Äê01ÔÂ12ÈÕÐÇÆÚ¶þ£¬£¬£¬£¬£¬£¬MicrosoftÐû²¼ÁË1Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬±¾´ÎÇå¾²¸üй²¼ÆÐÞ¸´ÁË83¸öÎó²î£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐ10¸öÎó²îÆÀ¼¶ÎªÑÏÖØ£¬£¬£¬£¬£¬£¬73¸öÎó²îÆÀ¼¶Îª¸ßΣ£¬£¬£¬£¬£¬£¬ÒÔ¼°Ò»¸ö0dayÎó²î¡£¡£¡£¡£

0x01 Îó²îÏêÇé

image.png

 

±¾´ÎÐÞ¸´µÄÍêÕûÎó²îÁбíÈçÏ£º

CVE ID

CVEÎÊÌâ

±êÇ©

ÑÏÖØË®Æ½

CVE-2021-1725

Bot   Framework SDKÐÅϢй¶Îó²î

.NET´æ´¢¿â

¸ßΣ

CVE-2021-1723

ASP.NET   CoreºÍVisual Studio¾Ü¾øÐ§ÀÍÎó²î

ASP.NET½¹µãºÍ.NET½¹µã

¸ßΣ

CVE-2021-1677

Azure   Active Directory PodÉí·ÝÓÕÆ­Îó²î

Azure   Active Directory PodÉí·Ý

¸ßΣ

CVE-2021-1683

WindowsÀ¶ÑÀÇå¾²¹¦Ð§ÈƹýÎó²î

MicrosoftÀ¶ÑÀÇý¶¯³ÌÐò

¸ßΣ

CVE-2021-1638

WindowsÀ¶ÑÀÇå¾²¹¦Ð§ÈƹýÎó²î

MicrosoftÀ¶ÑÀÇý¶¯³ÌÐò

¸ßΣ

CVE-2021-1684

WindowsÀ¶ÑÀÇå¾²¹¦Ð§ÈƹýÎó²î

MicrosoftÀ¶ÑÀÇý¶¯³ÌÐò

¸ßΣ

CVE-2021-1668

Microsoft   DTV-DVDÊÓÆµ½âÂëÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft   DTV-DVDÊÓÆµ½âÂëÆ÷

ÑÏÖØ

CVE-2021-1705

Microsoft   Edge£¨»ùÓÚHTML£©µÄÄÚ´æËð»µÎó²î

Microsoft   Edge£¨»ùÓÚHTML£©

ÑÏÖØ

CVE-2021-1709

Windows   Win32kȨÏÞÌáÉýÎó²î

MicrosoftͼÐÎ×é¼þ

¸ßΣ

CVE-2021-1696

WindowsͼÐÎ×é¼þÐÅϢй¶Îó²î

MicrosoftͼÐÎ×é¼þ

¸ßΣ

CVE-2021-1665

GDI   +Ô¶³Ì´úÂëÖ´ÐÐÎó²î

MicrosoftͼÐÎ×é¼þ

ÑÏÖØ

CVE-2021-1708

Windows   GDI +ÐÅϢй¶Îó²î

MicrosoftͼÐÎ×é¼þ

¸ßΣ

CVE-2021-1647

Microsoft   DefenderÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft¶ñÒâÈí¼þ±£»£»£»£»¤ÒýÇæ

ÑÏÖØ

CVE-2021-1713

Microsoft   ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

΢Èí°ì¹«Èí¼þ

¸ßΣ

CVE-2021-1714

Microsoft   ExcelÔ¶³Ì´úÂëÖ´ÐÐÎó²î

΢Èí°ì¹«Èí¼þ

¸ßΣ

CVE-2021-1711

Microsoft   OfficeÔ¶³Ì´úÂëÖ´ÐÐÎó²î

΢Èí°ì¹«Èí¼þ

¸ßΣ

CVE-2021-1715

Microsoft   WordÔ¶³Ì´úÂëÖ´ÐÐÎó²î

΢Èí°ì¹«Èí¼þ

¸ßΣ

CVE-2021-1716

Microsoft   WordÔ¶³Ì´úÂëÖ´ÐÐÎó²î

΢Èí°ì¹«Èí¼þ

¸ßΣ

CVE-2021-1712

Microsoft   SharePointȨÏÞÌáÉýÎó²î

Microsoft   Office SharePoint

¸ßΣ

CVE-2021-1707

Microsoft   SharePoint ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft   Office SharePoint

¸ßΣ

CVE-2021-1718

Microsoft   SharePoint Server¸Ä¶¯Îó²î

Microsoft   Office SharePoint

¸ßΣ

CVE-2021-1717

Microsoft   SharePointÓÕÆ­Îó²î

Microsoft   Office SharePoint

¸ßΣ

CVE-2021-1719

Microsoft   SharePointȨÏÞÌáÉýÎó²î

Microsoft   Office SharePoint

¸ßΣ

CVE-2021-1641

Microsoft   SharePointÓÕÆ­Îó²î

Microsoft   Office SharePoint

¸ßΣ

CVE-2021-1702

WindowsÔ¶³ÌÀú³ÌŲÓÃÔËÐÐʱȨÏÞÌáÉýÎó²î

Microsoft   RPC

¸ßΣ

CVE-2021-1649

»î¶¯Ä£°å¿âȨÏÞÌáÉýÎó²î

΢ÈíWindows

¸ßΣ

CVE-2021-1676

Windows   NT Lan ManagerÊý¾Ý±¨ÎüÊÕÆ÷Çý¶¯³ÌÐòÐÅÏ¢×ß©Îó²î

΢ÈíWindows

¸ßΣ

CVE-2021-1689

Windows¶àµãÖÎÀíȨÏÞÌáÉýÎó²î

΢ÈíWindows

¸ßΣ

CVE-2021-1657

Windows´«Õæ×«Ð´±íµ¥Ô¶³Ì´úÂëÖ´ÐÐÎó²î

΢ÈíWindows

¸ßΣ

CVE-2021-1646

Windows   WLANЧÀÍȨÏÞÌáÉýÎó²î

΢ÈíWindows

¸ßΣ

CVE-2021-1650

Windows   Runtime C ++Ä£°å¿âȨÏÞÌáÉýÎó²î

΢ÈíWindows

¸ßΣ

CVE-2021-1706

Windows   LUAFVȨÏÞÌáÉýÎó²î

΢ÈíWindows

¸ßΣ

CVE-2021-1699

Windows£¨modem.sys£©ÐÅϢй¶Îó²î

΢ÈíWindows

¸ßΣ

CVE-2021-1644

HEVCÊÓÆµÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft   Windows±à½âÂëÆ÷¿â

¸ßΣ

CVE-2021-1643

HEVCÊÓÆµÀ©Õ¹Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft   Windows±à½âÂëÆ÷¿â

ÑÏÖØ

CVE-2021-1637

Windows   DNSÅÌÎÊÐÅϢй¶Îó²î

Microsoft   Windows DNS

¸ßΣ

CVE-2021-1636

Microsoft   SQLȨÏÞÌáÉýÎó²î

SQLЧÀÍÆ÷

¸ßΣ

CVE-2020-26870

Visual   StudioÔ¶³Ì´úÂëÖ´ÐÐÎó²î

ÊÓ¾õÊÂÇéÊÒ

¸ßΣ

CVE-2021-1642

Windows   AppX°²ÅÅÀ©Õ¹È¨ÏÞÌáÉýÎó²î

Windows   AppX°²ÅÅÀ©Õ¹

¸ßΣ

CVE-2021-1685

Windows   AppX°²ÅÅÀ©Õ¹È¨ÏÞÌáÉýÎó²î

Windows   AppX°²ÅÅÀ©Õ¹

¸ßΣ

CVE-2021-1679

Windows   CryptoAPI¾Ü¾øÐ§ÀÍÎó²î

Windows   CryptoAPI

¸ßΣ

CVE-2021-1652

Windows   CSCЧÀÍȨÏÞÌáÉýÎó²î

Windows   CSCЧÀÍ

¸ßΣ

CVE-2021-1654

Windows   CSCЧÀÍȨÏÞÌáÉýÎó²î

Windows   CSCЧÀÍ

¸ßΣ

CVE-2021-1659

Windows   CSCЧÀÍȨÏÞÌáÉýÎó²î

Windows   CSCЧÀÍ

¸ßΣ

CVE-2021-1653

Windows   CSCЧÀÍȨÏÞÌáÉýÎó²î

Windows   CSCЧÀÍ

¸ßΣ

CVE-2021-1655

Windows   CSCЧÀÍȨÏÞÌáÉýÎó²î

Windows   CSCЧÀÍ

¸ßΣ

CVE-2021-1693

Windows   CSCЧÀÍȨÏÞÌáÉýÎó²î

Windows   CSCЧÀÍ

¸ßΣ

CVE-2021-1688

Windows   CSCЧÀÍȨÏÞÌáÉýÎó²î

Windows   CSCЧÀÍ

¸ßΣ

CVE-2021-1680

Õï¶ÏÖÐÐıê×¼ÍøÂçÆ÷ȨÏÞÌáÉýÎó²î

WindowsÕï¶ÏÖÐÐÄ

¸ßΣ

CVE-2021-1651

Õï¶ÏÖÐÐıê×¼ÍøÂçÆ÷ȨÏÞÌáÉýÎó²î

WindowsÕï¶ÏÖÐÐÄ

¸ßΣ

CVE-2021-1645

Windows   DockerÐÅϢй¶Îó²î

Windows   DP API

¸ßΣ

CVE-2021-1703

WindowsÊÂÎñÈÕÖ¾¼Í¼ЧÀÍȨÏÞÌáÉýÎó²î

WindowsÊÂÎñ¼Í¼ЧÀÍ

¸ßΣ

CVE-2021-1662

WindowsÊÂÎñ¸ú×ÙȨÏÞÌáÉýÎó²î

WindowsÊÂÎñ¸ú×Ù

¸ßΣ

CVE-2021-1691

Hyper-V¾Ü¾øÐ§ÀÍÎó²î

Windows   Hyper-V

¸ßΣ

CVE-2021-1704

Windows   Hyper-VȨÏÞÌáÉýÎó²î

Windows   Hyper-V

¸ßΣ

CVE-2021-1692

Hyper-V¾Ü¾øÐ§ÀÍÎó²î

Windows   Hyper-V

¸ßΣ

CVE-2021-1661

Windows   InstallerȨÏÞÌáÉýÎó²î

Windows×°ÖóÌÐò

¸ßΣ

CVE-2021-1697

Windows   InstallServiceȨÏÞÌáÉýÎó²î

Windows×°ÖóÌÐò

¸ßΣ

CVE-2021-1682

WindowsÄÚºËȨÏÞÌáÉýÎó²î

WindowsÄÚºË

¸ßΣ

CVE-2021-1710

Microsoft   Windows Media FoundationÔ¶³Ì´úÂëÖ´ÐÐÎó²î

WindowsýÌå

¸ßΣ

CVE-2021-1678

NTLMÇå¾²¹¦Ð§ÈƹýÎó²î

Windows   NTLM

¸ßΣ

CVE-2021-1695

Windows   Print SpoolerȨÏÞÌáÉýÎó²î

Windows´òÓ¡ºǫ́´¦Öóͷ£³ÌÐò×é¼þ

¸ßΣ

CVE-2021-1663

Windows   Projected File System FSɸѡÆ÷Çý¶¯³ÌÐòÐÅϢй¶Îó²î

WindowsͶӰÎļþϵͳɸѡÆ÷Çý¶¯³ÌÐò

¸ßΣ

CVE-2021-1672

Windows   Projected File System FSɸѡÆ÷Çý¶¯³ÌÐòÐÅϢй¶Îó²î

WindowsͶӰÎļþϵͳɸѡÆ÷Çý¶¯³ÌÐò

¸ßΣ

CVE-2021-1670

Windows   Projected File System FSɸѡÆ÷Çý¶¯³ÌÐòÐÅϢй¶Îó²î

WindowsͶӰÎļþϵͳɸѡÆ÷Çý¶¯³ÌÐò

¸ßΣ

CVE-2021-1674

WindowsÔ¶³Ì×ÀÃæÐ­Òé½¹µãÇå¾²¹¦Ð§ÈƹýÎó²î

WindowsÔ¶³Ì×ÀÃæ

¸ßΣ

CVE-2021-1669

WindowsÔ¶³Ì×ÀÃæÇå¾²¹¦Ð§ÈƹýÎó²î

WindowsÔ¶³Ì×ÀÃæ

¸ßΣ

CVE-2021-1701

Ô¶³ÌÀú³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´ÐÐÎó²î

WindowsÔ¶³ÌÀú³ÌŲÓÃÔËÐÐʱ

¸ßΣ

CVE-2021-1700

Ô¶³ÌÀú³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´ÐÐÎó²î

WindowsÔ¶³ÌÀú³ÌŲÓÃÔËÐÐʱ

¸ßΣ

CVE-2021-1666

Ô¶³ÌÀú³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´ÐÐÎó²î

WindowsÔ¶³ÌÀú³ÌŲÓÃÔËÐÐʱ

ÑÏÖØ

CVE-2021-1664

Ô¶³ÌÀú³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´ÐÐÎó²î

WindowsÔ¶³ÌÀú³ÌŲÓÃÔËÐÐʱ

¸ßΣ

CVE-2021-1671

Ô¶³ÌÀú³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´ÐÐÎó²î

WindowsÔ¶³ÌÀú³ÌŲÓÃÔËÐÐʱ

¸ßΣ

CVE-2021-1673

Ô¶³ÌÀú³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´ÐÐÎó²î

WindowsÔ¶³ÌÀú³ÌŲÓÃÔËÐÐʱ

ÑÏÖØ

CVE-2021-1658

Ô¶³ÌÀú³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´ÐÐÎó²î

WindowsÔ¶³ÌÀú³ÌŲÓÃÔËÐÐʱ

ÑÏÖØ

CVE-2021-1667

Ô¶³ÌÀú³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´ÐÐÎó²î

WindowsÔ¶³ÌÀú³ÌŲÓÃÔËÐÐʱ

ÑÏÖØ

CVE-2021-1660

Ô¶³ÌÀú³ÌŲÓÃÔËÐÐʱԶ³Ì´úÂëÖ´ÐÐÎó²î

WindowsÔ¶³ÌÀú³ÌŲÓÃÔËÐÐʱ

ÑÏÖØ

CVE-2021-1648

Microsoft   splwow64ȨÏÞÌáÉýÎó²î

Windows   splwow64

¸ßΣ

CVE-2021-1656

TPM×°±¸Çý¶¯³ÌÐòÐÅϢй¶Îó²î

Windows   TPM×°±¸Çý¶¯³ÌÐò

¸ßΣ

CVE-2021-1694

Windows   Update¿ÍջȨÏÞÌáÉýÎó²î

Windows¸üпÍÕ»

¸ßΣ

CVE-2021-1686

Windows   WalletServiceȨÏÞÌáÉýÎó²î

Windows   WalletService

¸ßΣ

CVE-2021-1681

Windows   WalletServiceȨÏÞÌáÉýÎó²î

Windows   WalletService

¸ßΣ

CVE-2021-1690

Windows   WalletServiceȨÏÞÌáÉýÎó²î

Windows   WalletService

¸ßΣ

CVE-2021-1687

Windows   WalletServiceȨÏÞÌáÉýÎó²î

Windows   WalletService

¸ßΣ

 

²¿·ÖÎó²îÏêÇéÈçÏ£º

Microsoft DefenderÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-1647£©

¸ÃÎó²îÊÇMicrosoft Defender·À²¡¶¾Èí¼þÖеÄ0dayÎó²î£¬£¬£¬£¬£¬£¬±£´æÓÚ¶ñÒâÈí¼þ±£»£»£»£»¤ÒýÇæ×é¼þ£¨mpengine.dll£©ÖУ¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¸ÃÎó²îÔÚ²¹¶¡Ðû²¼Ö®Ç°¾Í±»¹¥»÷Õ߯ձéʹÓᣡ£¡£¡£

Ó°Ïì¹æÄ£

1.1.17600.5

ÐÞ¸´°æ±¾

1.1.17700.4

×¢£º¸ÃÎó²îµÄÇå¾²¸üн«ÔÚÅþÁ¬»¥ÁªÍøµÄÇéÐÎÏÂ×Ô¶¯×°ÖÃÔÚÔËÐÐÊÜÓ°ÏìMicrosoft DefenderµÄϵͳÉÏ£¬£¬£¬£¬£¬£¬ÎÞÐèÊÖ¶¯Ö´ÐС£¡£¡£¡£

 

Microsoft splwow64ȨÏÞÌáÉýÎó²î£¨CVE-2021-1648£©

¸ÃÎó²îÊÇWindows´òÓ¡Çý¶¯³ÌÐòÀú³ÌSPLWOW64.exeÖеÄȨÏÞÌáÉýÎó²î£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö7.8¡£¡£¡£¡£¸ÃÎó²î×îÔçÓÉGoogle·¢Ã÷²¢ÐÞ¸´£¬£¬£¬£¬£¬£¬µ«ÓÉÓÚ²¹¶¡³ÌÐò²»ÍêÕû£¬£¬£¬£¬£¬£¬Òò´ËΪ½øÒ»²½µ¼ÖÂÁ˸ÃÎó²î¡£¡£¡£¡£

SPLWOW64.exeÊÇÔÚ64λWindows²Ù×÷ϵͳÉÏʹÓÃ32λ´òÓ¡»úÇý¶¯³ÌÐòʱÔËÐеÄWindowsÀú³Ì¡£¡£¡£¡£·¢ËÍ´òÓ¡×÷ҵʱ»áÖ´ÐдËÀú³Ì£¬£¬£¬£¬£¬£¬²¢ÇÒÓÐʱÔÚÍê³É×÷Òµºó¸ÃÀú³Ì»áÎÞ·¨×¼È·¹Ø±Õ¡£¡£¡£¡£

µ±SPLWOW64.exeÀú³ÌûÓÐ׼ȷÖÕֹʱ£¬£¬£¬£¬£¬£¬»á±¬·¢ÄÚ´æÐ¹Â¶£¬£¬£¬£¬£¬£¬½«ÑÏÖØÓ°ÏìЧÀÍÆ÷»ò×ÀÃæ×ÊÔ´µÄÐÔÄܺͿÉÓÃÐÔ¡£¡£¡£¡£

image.png

Ó°Ïì¹æÄ£

Windows 10 Version 20H2 for ARM64-based Systems

Windows 10 Version 20H2 for 32-bit Systems

Windows Server, version 20H2 (Server Core Installation)

Windows 10 Version 20H2 for x64-based Systems

Windows Server 2012 R2 (Server Core installation)

Windows Server 2012 R2

Windows Server 2012 (Server Core installation)

Windows Server 2012

Windows RT 8.1

Windows 8.1 for x64-based systems

Windows 8.1 for 32-bit systems

Windows Server 2016 (Server Core installation)

Windows Server 2016

Windows 10 Version 1607 for x64-based Systems

Windows 10 Version 1607 for 32-bit Systems

Windows 10 for x64-based Systems

Windows 10 for 32-bit Systems

Windows Server, version 2004 (Server Core installation)

Windows 10 Version 2004 for x64-based Systems

Windows 10 Version 2004 for ARM64-based Systems

Windows 10 Version 2004 for 32-bit Systems

Windows Server, version 1909 (Server Core installation)

Windows 10 Version 1909 for ARM64-based Systems

Windows 10 Version 1909 for x64-based Systems

Windows 10 Version 1909 for 32-bit Systems

Windows Server 2019 (Server Core installation)

Windows Server 2019

Windows 10 Version 1809 for ARM64-based Systems

Windows 10 Version 1809 for x64-based Systems

Windows 10 Version 1809 for 32-bit Systems

Windows 10 Version 1803 for ARM64-based Systems

Windows 10 Version 1803 for x64-based Systems

Windows 10 Version 1803 for 32-bit Systems

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚMicrosoftÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬£¬½¨ÒéʵʱװÖò¹¶¡¡£¡£¡£¡£

£¨Ò»£© Windows update¸üÐÂ

×Ô¶¯¸üУº

Microsoft UpdateĬÈÏÆôÓ㬣¬£¬£¬£¬£¬µ±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬£¬£¬£¬£¬£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢ÔÚÏÂÒ»´ÎÆô¶¯Ê±×°Öᣡ£¡£¡£

 

ÊÖ¶¯¸üУº

1¡¢µã»÷¡°×îÏȲ˵¥¡±»ò°´Windows¿ì½Ý¼ü£¬£¬£¬£¬£¬£¬µã»÷½øÈë¡°ÉèÖá±

2¡¢Ñ¡Ôñ¡°¸üкÍÇå¾²¡±£¬£¬£¬£¬£¬£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý¿ØÖÆÃæ°å½øÈë¡°Windows¸üС±£¬£¬£¬£¬£¬£¬Ïêϸ°ì·¨Îª¡°¿ØÖÆÃæ°å¡±->¡°ÏµÍ³ºÍÇå¾²¡±->¡°Windows¸üС±£©

3¡¢Ñ¡Ôñ¡°¼ì²é¸üС±£¬£¬£¬£¬£¬£¬ÆÚ´ýϵͳ½«×Ô¶¯¼ì²é²¢ÏÂÔØ¿ÉÓøüС£¡£¡£¡£

4¡¢ÖØÆôÅÌËã»ú£¬£¬£¬£¬£¬£¬×°ÖøüÐÂÏµÍ³ÖØÐÂÆô¶¯ºó£¬£¬£¬£¬£¬£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÊÇ·ñÀÖ³É×°ÖÃÁ˸üС£¡£¡£¡£¹ØÓÚûÓÐÀÖ³É×°ÖõĸüУ¬£¬£¬£¬£¬£¬¿ÉÒÔµã»÷¸Ã¸üÐÂÃû³Æ½øÈë΢Èí¹Ù·½¸üÐÂÐÎòÁ´½Ó£¬£¬£¬£¬£¬£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬£¬£¬£¬£¬£¬È»ºóÔÚÐÂÁ´½ÓÖÐÑ¡ÔñÊÊÓÃÓÚÄ¿µÄϵͳµÄ²¹¶¡¾ÙÐÐÏÂÔØ²¢×°Öᣡ£¡£¡£

 

£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ

΢Èí¹Ù·½ÏÂÔØÏìÓ¦²¹¶¡¾ÙÐиüС£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://msrc.microsoft.com/update-guide

 

0x03 ²Î¿¼Á´½Ó

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-1647

https://goliathtechnologies.com/troubleshoot-resolve-citrix-splwow64-exe-issues-p/

https://threatpost.com/critical-microsoft-defender-bug-exploited/162992/

https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2021-patch-tuesday-fixes-83-flaws-1-zero-day/

https://www.bleepingcomputer.com/news/security/microsoft-patches-defender-antivirus-zero-day-exploited-in-the-wild/

 

0x04 ʱ¼äÏß

2021-01-12  MicrosoftÐû²¼Çå¾²¸üÐÂ

2021-01-13  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png