Microsoft 2Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-02-100x00 ·ì϶¸ÅÊö
2021Äê02ÔÂ09ÈÕÐÇÆÚ¶þ£¬Microsoft°ä²¼ÁË2Ô·ݵݲȫ¸üС£±¾´Î°ä²¼µÄ°²È«¸üй²½¨¸´ÁË56¸ö·ì϶£¬ÆäÖÐ11¸öÆÀ¼¶ÎªÑϳÁ£¬43¸öÆÀ¼¶Îª¸ßΣ£¬2¸öÆÀ¼¶ÎªÖÐΣ¡£
0x01 ·ì϶ÏêÇé

Microsoft±¾´Î°ä²¼µÄ°²È«¸üн¨¸´ÁËWindows Win32kȨÏÞÌáÉý0 day·ì϶£¨CVE-2021-1732£©¡¢6¸öÒÔǰÅû¶µÄ·ì϶£¨CVE-2021-1721¡¢CVE-2021-1727¡¢CVE-2021-1733¡¢CVE-2021-24098¡¢CVE-2021-24106ºÍCVE-2021-26701£©ÒÔ¼°¿ÉÒý·¢¹©¸øÁ´¹¥»÷µÄ·¨Ê½°üÖÎÀíÆ÷ÅäÖÃÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-24105£©£¬¸Ã·ì϶½«Ó°ÏìMicrosoft¡¢Apple¡¢ PayPal¡¢Shopify¡¢Netflix¡¢Tesla¡¢Yelp¡¢TeslaºÍUberµÈ¶à¸ö¹«Ë¾¡£
ÔÚ±¾´Î½¨¸´µÄ·ì϶ÖУ¬ÖµÍ×ÌùÐĵÄÊÇWindows TCP/IPÖеÄ2¸öRCE·ì϶£¨CVE-2021-24074ºÍCVE-2021-24094£¬ÆäCVSSÆÀ·Ö¾ùΪ9.8£©ºÍ1¸ö»Ø¾ø·þÎñ·ì϶£¨CVE-2021-24086£¬ÆäCVSSÆÀ·Ö7.5£©£¬¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâIPÊý¾Ý°üÀ´´¥·¢ÕâЩ·ì϶£¬×îÖÕÔÚÖ¸±êÖ÷»ú»ò·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë»òµ¼ÖÂÀ¶ÆÁ¡£Microsoft°²È«ÏìÓ¦ÖÐÐÄMSRC°µÊ¾£¬Õâ3¸ö·ì϶»áÓ°ÏìËùÓеÄWindowsϵͳ£¬µ«ÓÉÓÚRCE·ì϶ÀûÓýÏΪ¸´ÔÓ£¬Òò¶ø¶ÌÆÚÄÚ²»Ì«¿ÉÄܱ»ÀûÓ㬵«¹¥»÷ÕߺÜÈÝÒ×ÌáÒéDos¹¥»÷¡£Ä¿Ç°ÕâЩ·ì϶ÒѾ½¨¸´£¬½¨Ò龡¿ìÀûÓÃWindows¸üС£
ÆëÈ«·ì϶ÁбíÈçÏ£º
²úÆ·/×é¼þ | CVE ID | CVE±êÌâ | ÑϳÁˮƽ |
.NET Core | CVE-2021-26701 | .NET CoreÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
.NET Core | CVE-2021-24112 | .NET CoreÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
.NET Core & Visual Studio | CVE-2021-1721 | .NET CoreºÍVisual Studio»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
.NET Framework | CVE-2021-24111 | .NET Framework»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
Azure IoT | CVE-2021-24087 | Azure IoT CLIÀ©´óȨÏÞÌáÉý·ì϶ | ¸ßΣ |
Developer Tools | CVE-2021-24105 | ·¨Ê½°üÖÎÀíÆ÷ÅäÖÃÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
Microsoft Azure Kubernetes Service | CVE-2021-24109 | Microsoft Azure Kubernetes·þÎñȨÏÞÌáÉý·ì϶ | ÖÐΣ |
Microsoft Dynamics | CVE-2021-24101 | Microsoft DataverseÐÅϢй¶·ì϶ | ¸ßΣ |
Microsoft Dynamics | CVE-2021-1724 | Microsoft Dynamics Business Central¿çÕ¾µã¾ç±¾·ì϶ | ¸ßΣ |
Microsoft Edge for Android | CVE-2021-24100 | Microsoft Edge for AndroidÐÅϢй¶·ì϶ | ¸ßΣ |
Microsoft Exchange Server | CVE-2021-24085 | Microsoft Exchange ServerºýŪ·ì϶ | ¸ßΣ |
Microsoft Exchange Server | CVE-2021-1730 | Microsoft Exchange ServerºýŪ·ì϶ | ¸ßΣ |
Microsoft Graphics Component | CVE-2021-24093 | WindowsͼÐÎ×é¼þÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
Microsoft Office Excel | CVE-2021-24067 | Microsoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
Microsoft Office Excel | CVE-2021-24068 | Microsoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
Microsoft Office Excel | CVE-2021-24069 | Microsoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
Microsoft Office Excel | CVE-2021-24070 | Microsoft ExcelÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
Microsoft Office SharePoint | CVE-2021-24071 | Microsoft SharePointÐÅϢй¶·ì϶ | ¸ßΣ |
Microsoft Office SharePoint | CVE-2021-1726 | Microsoft SharePointºýŪ·ì϶ | ¸ßΣ |
Microsoft Office SharePoint | CVE-2021-24066 | Microsoft SharePointÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
Microsoft Office SharePoint | CVE-2021-24072 | Microsoft SharePoint ServerÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
Microsoft Teams | CVE-2021-24114 | Microsoft Teams iOSÐÅϢй¶·ì϶ | ¸ßΣ |
Microsoft Windows Codecs Library | CVE-2021-24081 | Microsoft Windows±à½âÂëÆ÷¿âÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
Microsoft Windows Codecs Library | CVE-2021-24091 | Windows Camera Codec PackÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
Role: DNS Server | CVE-2021-24078 | Windows DNS·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
Role: Hyper-V | CVE-2021-24076 | Microsoft Windows VMSwitchÐÅϢй¶·ì϶ | ¸ßΣ |
Role: Windows Fax Service | CVE-2021-24077 | Windows´«Õæ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
Role: Windows Fax Service | CVE-2021-1722 | Windows´«Õæ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
Skype for Business | CVE-2021-24073 | Skype for BusinessºÍLyncºýŪ·ì϶ | ¸ßΣ |
Skype for Business | CVE-2021-24099 | Skype for BusinessºÍLync»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
SysInternals | CVE-2021-1733 | Sysinternals PsExecȨÏÞÌáÉý·ì϶ | ¸ßΣ |
System Center | CVE-2021-1728 | System Center Operations ManagerȨÏÞÌáÉý·ì϶ | ¸ßΣ |
Visual Studio | CVE-2021-1639 | Visual Studio´úÂëÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
Visual Studio Code | CVE-2021-26700 | Visual Studio Code npm-script ExtensionÔ¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
Windows Address Book | CVE-2021-24083 | WindowsͨѶ²¾Ô¶³Ì´úÂëÖ´Ðзì϶ | ¸ßΣ |
Windows Backup Engine | CVE-2021-24079 | Windows±¸·ÝÒýÇæÐÅϢй¶·ì϶ | ¸ßΣ |
Windows Console Driver | CVE-2021-24098 | Windows½ÚÔį̀Çý¶¯·¨Ê½»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
Windows Defender | CVE-2021-24092 | Microsoft DefenderȨÏÞÌáÉý·ì϶ | ¸ßΣ |
Windows DirectX | CVE-2021-24106 | Windows DirectXÐÅϢй¶·ì϶ | ¸ßΣ |
Windows Event Tracing | CVE-2021-24102 | WindowsÊÂÎñ¸ú×ÙȨÏÞÌáÉý·ì϶ | ¸ßΣ |
Windows Event Tracing | CVE-2021-24103 | WindowsÊÂÎñ¸ú×ÙȨÏÞÌáÉý·ì϶ | ¸ßΣ |
Windows Installer | CVE-2021-1727 | Windows InstallerȨÏÞÌáÉý·ì϶ | ¸ßΣ |
Windows Kernel | CVE-2021-24096 | WindowsÄÚºËȨÏÞÌáÉý·ì϶ | ¸ßΣ |
Windows Kernel | CVE-2021-1732 | Windows Win32kȨÏÞÌáÉý·ì϶ | ¸ßΣ |
Windows Kernel | CVE-2021-1698 | Windows Win32kȨÏÞÌáÉý·ì϶ | ¸ßΣ |
Windows Mobile Device Management | CVE-2021-24084 | Windows MobileÉ豸ÖÎÀíÐÅϢй¶·ì϶ | ¸ßΣ |
Windows Network File System | CVE-2021-24075 | WindowsÍøÂçÎļþϵͳ»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
Windows PFX Encryption | CVE-2021-1731 | PFX¼ÓÃܰ²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
Windows PKU2U | CVE-2021-25195 | Windows PKU2UȨÏÞÌáÉý·ì϶ | ¸ßΣ |
Windows PowerShell | CVE-2021-24082 | Microsoft.PowerShell.UtilityÄ£¿éWDAC°²È«Ö°ÄÜÈÆ¹ý·ì϶ | ¸ßΣ |
Windows Print Spooler Components | CVE-2021-24088 | Windows±¾µØºó¶Ü´¦Ö÷¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
Windows Remote Procedure Call | CVE-2021-1734 | WindowsÔ¶³Ì¹ý³ÌŲÓÃÐÅϢй¶·ì϶ | ¸ßΣ |
Windows TCP/IP | CVE-2021-24086 | Windows TCP/IP»Ø¾ø·þÎñ·ì϶ | ¸ßΣ |
Windows TCP/IP | CVE-2021-24074 | Windows TCP/IPÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
Windows TCP/IP | CVE-2021-24094 | Windows TCP/IPÔ¶³Ì´úÂëÖ´Ðзì϶ | ÑϳÁ |
Windows Trust Verification API | CVE-2021-24080 | WindowsÐÅÀµÑéÖ¤API»Ø¾ø·þÎñ·ì϶ | ÖÐΣ |
0x02 ´ëÖý¨Òé
ĿǰMicrosoftÒѰ䲼°²È«¸üУ¬½¨ÒéʵʱװÖÃÓйز¹¶¡¡£
£¨Ò»£© Windows update¸üÐÂ
×Ô¶¯¸üУº
Microsoft UpdateĬÈÏÆôÓ㬵±ÏµÍ³¼ì²âµ½¿ÉÓøüÐÂʱ£¬½«»á×Ô¶¯ÏÂÔØ¸üв¢±ÉÈËÒ»´ÎÆô¶¯Ê±×°Öá£
ÊÖ¶¯¸üУº
1¡¢µã»÷¡°ÆðÍ·²Ëµ¥¡±»ò°´Windows¿ì½Ý¼ü£¬µã»÷½øÈë¡°ÉèÖá±
2¡¢Ñ¡Ôñ¡°¸üкͰ²È«¡±£¬½øÈë¡°Windows¸üС±£¨Windows 8¡¢Windows 8.1¡¢Windows Server 2012ÒÔ¼°Windows Server 2012 R2¿Éͨ¹ý½ÚÔìÃæ°å½øÈë¡°Windows¸üС±£¬¾ßÌå²½ÖèΪ¡°½ÚÔìÃæ°å¡±->¡°ÏµÍ³ºÍ°²È«¡±->¡°Windows¸üС±£©
3¡¢Ñ¡Ôñ¡°²é³¸üС±£¬ÆÚ´ýϵͳ½«×Ô¶¯²é³²¢ÏÂÔØ¿ÉÓøüС£
4¡¢³ÁÆôÍÆËã»ú£¬×°ÖøüÐÂϵͳ³ÁÐÂÆô¶¯ºó£¬¿Éͨ¹ý½øÈë¡°Windows¸üС±->¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´ÊÇ·ñ³É¹¦×°ÖÃÁ˸üС£¶ÔÓÚûÓгɹ¦×°ÖõĸüУ¬Äܹ»µã»÷¸Ã¸üÐÂÃû³Æ½øÈëMicrosoft¹Ù·½¸üÐÂÃèÊöÁ´½Ó£¬µã»÷×îеÄSSUÃû³Æ²¢ÔÚÐÂÁ´½ÓÖеã»÷¡°Microsoft ¸üÐÂĿ¼¡±£¬¶øºóÔÚÐÂÁ´½Óµ±Ñ¡ÔñºÏÓÃÓÚÖ¸±êϵͳµÄ²¹¶¡½øÐÐÏÂÔØ²¢×°Öá£
£¨¶þ£© ÊÖ¶¯×°ÖøüÐÂ
Microsoft¹Ù·½ÏÂÔØÏàÓ¦²¹¶¡½øÐиüС£
ÏÂÔØÁ´½Ó£º
https://msrc.microsoft.com/update-guide
»º½â´ëÊ©
Õë¶ÔCVE-2021-24074£º
1.Äܹ»Í¨¹ýʹÓúÅÁÖÎÀíԱȨÏÞ£©½«sourceroutingbehavior ÉèÖÃΪ
"drop"£º
netsh int ipv4 set global sourceroutingbehavior=drop
¿ÉʹÓÃÒÔϺÅÁÔĬÈÏÉèÖãº
netsh int ipv4 set global sourceroutingbehavior=dontforward
2.ÅäÖ÷À»ðǽ»ò¸ºÔØÆ½ºâÆ÷ÒÔ²»ÈÝԴ·ÓÉÒªÇó¡£
Õë¶ÔCVE-2021-24094ºÍCVE-2021-24086£º
1.¿Éͨ¹ýÒÔϺÅÁÖÎÀíԱȨÏÞ£©½«global reassemblylimit ÉèÖÃΪ0£º
Netsh int ipv6 set global reassemblylimit=0
°ÑÎÈ£¬¸ÃºÅÁ½ûÓÃÊý¾Ý°ü³Á×飬ÂÒÐòÊý¾Ý°ü½«»á±»Åׯú£¬½¨ÒéÔÚ²âÊÔÖ®ºóÔÙ¸üгö²úϵͳ¡£
¿ÉʹÓÃÒÔϺÅÁÔĬÈÏÉèÖãº
Netsh int ipv6 set global reassemblylimit=267748640
2.ÅäÖ÷À»ðǽ»ò¸ºÔØÆ½ºâÆ÷ÒÔ²»ÈÝIPv6 UDP·Ö¶Î¡£
0x03 ²Î¿¼Á´½Ó
https://msrc.microsoft.com/update-guide/releaseNote/2021-Feb
https://msrc-blog.microsoft.com/2021/02/09/multiple-security-updates-affecting-tcp-ip/
https://www.bleepingcomputer.com/news/security/microsoft-february-2021-patch-tuesday-fixes-56-flaws-1-zero-day/
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-24094
0x04 ¹¦·òÏß
2021-02-09 Microsoft°ä²¼°²È«¸üÐÂ
2021-02-10 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ