【漏洞通告】2021年11月关于微软多个产品高危漏洞通告

2021.12.03

摘要

近日,微软官方发布了多个安全漏洞的公告,包括MicrosoftWindows Active Directory 权限许可和访问控制问题漏洞(CNNVD-202111-788、CVE-2021-42291)、Microsoft Windows ActiveDirectory 权限许可和访问控制问题漏洞(CNNVD-202111-789、CVE-2021-42287)等多个漏洞,建议用户及时确认是否受到漏洞影响,尽快采取修补措施。

近日,微软官方发布了多个安全漏洞的公告,包括MicrosoftWindows Active Directory 权限许可和访问控制问题漏洞(CNNVD-202111-788、CVE-2021-42291)、Microsoft Windows ActiveDirectory 权限许可和访问控制问题漏洞(CNNVD-202111-789、CVE-2021-42287)等多个漏洞。成功利用上述漏洞的攻击者可以在目标系统上执行任意代码、获取用户数据,提升权限等。微软多个产品和系统受漏洞影响。目前,微软官方已经发布了漏洞修复补丁,建议用户及时确认是否受到漏洞影响,尽快采取修补措施。

一、漏洞介绍

2021年11月9日,微软发布了2021年11月份安全更新,共51个漏洞的补丁程序,CNNVD对这些漏洞进行了收录。本次更新主要涵盖了Microsoft Windows 和Windows 组件、Microsoft Windows CodecsLibrary、Microsoft Azure、Microsoft3D Viewer、Microsoft Windows Feedback Hub、Microsoft Azure Sphere等。CNNVD对其危害等级进行了评价,其中高危漏洞25个,中危漏洞22个,低危漏洞4个。微软多个产品和系统版本受漏洞影响,具体影响范围可访问https://portal.msrc.microsoft.com/zh-cn/security-guidance查询。

二、重点漏洞概述

根据产品流行度和漏洞重要性筛选出此次更新中包含影响较大的漏洞,请相关用户重点进行关注:

IE Chakra 脚本内存引擎损坏漏洞(CVE-2021-42279):

由于Chakra脚本引擎边界存在错误,导致远程攻击者可以通过触发内存损坏,最终实现在目标系统上执行任意代码。
官方通告链接:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42279

Microsoft Exchange Server 远程代码执行漏洞(CVE-2021-42321):

由于Microsoft Exchange Server对cmdlet参数的验证不足,通过身份验证的远程攻击者可以在目标系统上运行恶意的cmdlet,最终导致任意代码执行。该漏洞似乎在天府杯中被利用。
官方通告链接:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42321

Microsoft Dynamics 365远程代码执行漏洞(CVE-2021-42316):

由于Microsoft Dynamics 365(本地部署)中的输入验证错误,经过身份验证的远程攻击者通过恶意请求,导致在目标系统上执行任意代码。
官方通告链接:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42316

Microsoft Excel 安全功能绕过漏洞(CVE-2021-42292):

Microsoft Excel中存在安全功能绕过漏洞,该漏洞允许本地用户打开特制文件时执行任意代码,且被检测到存在在野利用。
官方通告链接:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42292

Microsoft Defender 远程代码执行漏洞(CVE-2021-42298):

Defender 在扫描文件时会以最高权限在系统中运行。无需进行身份验证的远程攻击者通过诱导受害者打开发送的恶意文件,甚至受害者在无需打开或运行任何文件的情况下,会导致在目标系统上执行任意代码。
官方通告链接:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42298

Remote Desktop Client 远程代码执行漏洞(CVE-2021-38666):

在远程桌面连接的情况下,当受害者的远程桌面客户端与攻击服务器连接时,控制远程桌面服务器的攻击者可以在 RDP 客户端计算机上触发该漏洞,从而在目标系统上以用户权限执行任意代码。
官方通告链接:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38666

Microsoft RDP 信息泄露漏洞(CVE-2021-38631/CVE-2021-41371):

成功利用该漏洞的攻击者可以查看易受攻击系统的RDP密码,造成安全隐患。
官方通告链接:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38631
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41371

以下为重点关注漏洞的受影响产品版本,其他漏洞影响产品范围请参阅官方通告链接。

漏洞编号受影响产品版本
CVE-2021-42279Windows Server, version 20H2   (Server Core Installation)
Windows Server, version 2004   (Server Core installation)
Windows Server 2022
Windows Server 2019
Windows Server 2016
Windows 11 for x64-based   Systems
Windows 11 for ARM64-based   Systems
Windows 10 for x64-based   Systems
Windows 10 for 32-bit Systems
Windows 10 Version 21H1 for   x64-based Systems
Windows 10 Version 21H1 for   ARM64-based Systems
Windows 10 Version 21H1 for   32-bit Systems
Windows 10 Version 20H2 for   x64-based Systems
Windows 10 Version 20H2 for   ARM64-based Systems
Windows 10 Version 20H2 for   32-bit Systems
Windows 10 Version 2004 for   x64-based Systems
Windows 10 Version 2004 for   ARM64-based Systems
Windows 10 Version 2004 for   32-bit Systems
Windows 10 Version 1909 for   x64-based Systems
Windows 10 Version 1909 for   ARM64-based Systems
Windows 10 Version 1909 for   32-bit Systems
Windows 10 Version 1809 for   x64-based Systems
Windows 10 Version 1809 for   ARM64-based Systems
Windows 10 Version 1809 for   32-bit Systems
Windows 10 Version 1607 for   x64-based Systems
Windows 10 Version 1607 for   32-bit Systems
CVE-2021-42321Microsoft Exchange Server 2019   Cumulative Update 11
Microsoft Exchange Server 2019   Cumulative Update 10
Microsoft Exchange Server 2016   Cumulative Update 22
Microsoft Exchange Server 2016   Cumulative Update 21
CVE-2021-42316Microsoft Dynamics 365   (on-premises) version 9.1
Microsoft Dynamics 365   (on-premises) version 9.0
CVE-2021-42292Microsoft Office LTSC for Mac 2021
Microsoft Office LTSC 2021 for   64-bit editions
Microsoft Office LTSC 2021 for   32-bit editions
Microsoft Office 2019 for Mac
Microsoft Office 2019 for   64-bit editions
Microsoft Office 2019 for   32-bit editions
Microsoft Office 2016 (64-bit   edition)
Microsoft Office 2016 (32-bit   edition)
Microsoft Office 2013 Service   Pack 1 (64-bit editions)
Microsoft Office 2013 Service   Pack 1 (32-bit editions)
Microsoft Office 2013 RT   Service Pack 1
Microsoft Excel 2016 (64-bit edition)
Microsoft Excel 2016 (32-bit edition)
Microsoft Excel 2013 Service   Pack 1 (64-bit editions)
Microsoft Excel 2013 Service   Pack 1 (32-bit editions)
Microsoft Excel 2013 RT Service Pack 1
Microsoft 365 Apps for   Enterprise for 64-bit Systems
Microsoft 365 Apps for   Enterprise for 32-bit Systems
CVE-2021-42298Microsoft Malware Protection   Engine
CVE-2021-38666Windows Server, version 20H2   (Server Core Installation)
Windows Server, version 2004   (Server Core installation)
Windows Server 2022 (Server   Core installation)
Windows Server 2022
Windows Server 2019 (Server   Core installation)
Windows Server 2019
Windows Server 2016 (Server   Core installation)
Windows Server 2016
Windows Server 2012 R2 (Server   Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server   Core installation)
Windows Server 2012
Windows Server 2008 for   x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for   x64-based Systems Service Pack 2
Windows Server 2008 for 32-bit   Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for 32-bit   Systems Service Pack 2
Windows Server 2008 R2 for   x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows RT 8.1
Windows 8.1 for x64-based   systems
Windows 8.1 for 32-bit systems
Windows 7 for x64-based Systems   Service Pack 1
Windows 7 for 32-bit Systems   Service Pack 1
Windows 11 for x64-based Systems
Windows 11 for ARM64-based   Systems
Windows 10 for x64-based   Systems
Windows 10 for 32-bit Systems
Windows 10 Version 21H1 for   x64-based Systems
Windows 10 Version 21H1 for   ARM64-based Systems
Windows 10 Version 21H1 for 32-bit Systems
Windows 10 Version 20H2 for   x64-based Systems
Windows 10 Version 20H2 for   ARM64-based Systems
Windows 10 Version 20H2 for   32-bit Systems
Windows 10 Version 2004 for   x64-based Systems
Windows 10 Version 2004 for   ARM64-based Systems
Windows 10 Version 2004 for   32-bit Systems
Windows 10 Version 1909 for   x64-based Systems
Windows 10 Version 1909 for   ARM64-based Systems
Windows 10 Version 1909 for 32-bit Systems
Windows 10 Version 1809 for   x64-based Systems
Windows 10 Version 1809 for   ARM64-based Systems
Windows 10 Version 1809 for   32-bit Systems
Windows 10 Version 1607 for   x64-based Systems
Windows 10 Version 1607 for   32-bit Systems
Remote Desktop client for   Windows Desktop
Windows Server, version 2004   (Server Core installation)
Windows Server 2022 (Server   Core installation)
Windows Server 2022
Windows Server, version 20H2   (Server Core Installation)
Windows Server 2019 (Server   Core installation)
Windows Server 2019
Windows Server 2012 R2 (Server   Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server   Core installation)
Windows Server 2012
Windows Server 2008 R2 for   x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for   x64-based Systems Service Pack 1
Windows Server 2008 for   x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for   x64-based Systems Service Pack 2
Windows Server 2008 for 32-bit   Systems Service Pack 2 (ServerCore installation)
Windows Server 2008 for 32-bit   Systems Service Pack 2
Windows Server 2016 (Server   Core installation)
Windows Server 2016
CVE-2021-38631
CVE-2021-41371
Windows Server, version 20H2   (Server Core Installation)
Windows Server, version 2004 (Server   Core installation)
Windows Server 2022 (Server   Core installation)
Windows Server 2022
Windows Server 2019 (Server   Core installation)
Windows Server 2019
Windows Server 2016 (Server   Core installation)
Windows Server 2016
Windows Server 2012 R2 (Server   Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server   Core installation)
Windows Server 2012
Windows Server 2008 for   x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for   x64-based Systems Service Pack 2
Windows Server 2008 for 32-bit   Systems Service Pack 2 (ServerCore installation)
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 R2 for   x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based   Systems Service Pack 1
Windows RT 8.1
Windows 8.1 for x64-based   systems
Windows 8.1 for 32-bit systems
Windows 7 for x64-based Systems   Service Pack 1
Windows 7 for 32-bit Systems   Service Pack 1
Windows 11 for x64-based   Systems
Windows 11 for ARM64-based   Systems
Windows 10 for x64-based   Systems
Windows 10 for 32-bit Systems
Windows 10 Version 21H1 for   x64-based Systems
Windows 10 Version 21H1 for   ARM64-based Systems
Windows 10 Version 21H1 for   32-bit Systems
Windows 10 Version 20H2 for   x64-based Systems
Windows 10 Version 20H2 for   ARM64-based Systems
Windows 10 Version 20H2 for 32-bit Systems
Windows 10 Version 2004 for   x64-based Systems
Windows 10 Version 2004 for ARM64-based Systems
Windows 10 Version 2004 for   32-bit Systems
Windows 10 Version 1909 for   x64-based Systems
Windows 10 Version 1909 for   ARM64-based Systems
Windows 10 Version 1909 for   32-bit Systems
Windows 10 Version 1809 for   x64-based Systems
Windows 10 Version 1809 for   ARM64-based Systems
Windows 10 Version 1809 for   32-bit Systems
Windows 10 Version 1607 for   x64-based Systems
Windows 10 Version 1607 for   32-bit Systems


三、漏洞详情

此次更新共包括51个漏洞的补丁程序,其中高危漏洞25个,中危漏洞22个,低危漏洞4个。

序号漏洞名称

CNNVD编号

CVE编号

危害等级

官方链接

1

Microsoft  Windows Active   Directory 权限许可和访问控制问题漏洞

CNNVD-202111-788

CVE-2021-42291

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42291

2

Microsoft  Windows Active   Directory 权限许可和访问控制问题漏洞

CNNVD-202111-789

CVE-2021-42287

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42287

3

Microsoft  Windows Kernel 权限许可和访问控制问题漏洞

CNNVD-202111-791

CVE-2021-42285

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42285

4

Microsoft  Windows 权限许可和访问控制问题漏洞

CNNVD-202111-792

CVE-2021-42286

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42286

5

Microsoft  Windows NTFS 权限许可和访问控制问题漏洞

CNNVD-202111-795

CVE-2021-42283

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42283

6

Microsoft  Windows Active Directory 权限许可和访问控制问题漏洞

CNNVD-202111-796

CVE-2021-42282

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42282

7

Microsoft  Windows Active   Directory 权限许可和访问控制问题漏洞

CNNVD-202111-797

CVE-2021-42278

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278

8

Microsoft  Windows NTFS 代码注入漏洞

CNNVD-202111-803

CVE-2021-41378

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41378

9

Microsoft  Windows Codecs   Library 代码注入漏洞

CNNVD-202111-804

CVE-2021-42276

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42276

10

Microsoft  Windows Fastfat   Driver 权限许可和访问控制问题漏洞

CNNVD-202111-805

CVE-2021-41377

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41377

11

Microsoft  Windows COM 代码注入漏洞

CNNVD-202111-806

CVE-2021-42275

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42275

12

Microsoft  Windows NTFS 权限许可和访问控制问题漏洞

CNNVD-202111-808

CVE-2021-4137

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4137

13

Microsoft  Windows NTFS 权限许可和访问控制问题漏洞

CNNVD-202111-809

CVE-2021-41367

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41367

14

Microsoft  Windows 权限许可和访问控制问题漏洞

CNNVD-202111-81

CVE-2021-41366

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41366

15

Microsoft  Windows 输入验证错误漏洞

CNNVD-202111-811

CVE-2021-41356

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41356

16

Microsoft 3D  Viewer 代码注入漏洞

CNNVD-202111-812

CVE-2021-43208

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43208

17

Microsoft 3D  Viewer 代码注入漏洞

CNNVD-202111-813

CVE-2021-43209

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43209

18

Microsoft  Windows rdp 代码注入漏洞

CNNVD-202111-815

CVE-2021-38666

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38666

19

Microsoft  Windows Virtual Machine 代码注入漏洞

CNNVD-202111-827

CVE-2021-26443

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26443

20

Microsoft  Dynamics 代码注入漏洞

CNNVD-202111-835

CVE-2021-42316

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42316

21

Microsoft  Visual Studio 权限许可和访问控制问题漏洞

CNNVD-202111-839

CVE-2021-42322

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42322

22

Microsoft  Exchange   Server 输入验证错误漏洞

CNNVD-202111-842

CVE-2021-42321

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42321

23

Microsoft  Office 代码注入漏洞

CNNVD-202111-848

CVE-2021-40442

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40442

24

Microsoft  Office 输入验证错误漏洞

CNNVD-202111-857

CVE-2021-42292

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42292

25

Microsoft  Office 代码注入漏洞

CNNVD-202111-858

CVE-2021-42296

高危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42296

26

Microsoft  Windows Hello 安全特征问题特征问题漏洞

CNNVD-202111-786

CVE-2021-42288

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42288

27

Microsoft  Hyper-V 输入验证错误漏洞

CNNVD-202111-794

CVE-2021-42284

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42284

28

Microsoft  Windows Feedback   Hub 权限许可和访问控制问题漏洞

CNNVD-202111-798

CVE-2021-4228

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-4228

29

Microsoft  Windows   Scripting 缓冲区错误漏洞

CNNVD-202111-799

CVE-2021-42279

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42279

30

Microsoft  Hyper-V 输入验证错误漏洞

CNNVD-202111-8

CVE-2021-42274

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42274

31

Microsoft  Windows   Installer 权限许可和访问控制问题漏洞

CNNVD-202111-802

CVE-2021-41379

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41379

32

Microsoft  Windows rdp 信息泄露漏洞

CNNVD-202111-807

CVE-2021-41371

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41371

33

Microsoft  Windows Desktop   Bridge 权限许可和访问控制问题漏洞

CNNVD-202111-814

CVE-2021-36957

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36957

34

Microsoft  Exchange   Server 安全漏洞

CNNVD-202111-816

CVE-2021-41349

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41349

35

Microsoft  Windows rdp 信息泄露漏洞

CNNVD-202111-817

CVE-2021-38631

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38631

36

Microsoft  Windows rdp 信息泄露漏洞

CNNVD-202111-818

CVE-2021-38665

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38665

37

Microsoft  Azure Sphere 数据伪造问题漏洞

CNNVD-202111-819

CVE-2021-423

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-423

38

Microsoft  Power BI Report   Server 安全漏洞

CNNVD-202111-821

CVE-2021-41372

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41372

39

Microsoft  Office 代码注入漏洞

CNNVD-202111-822

CVE-2021-41368

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41368

40

Microsoft  Azure Sphere 安全漏洞

CNNVD-202111-823

CVE-2021-41375

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41375

41

Microsoft  Azure Sphere 输入验证错误漏洞

CNNVD-202111-824

CVE-2021-41374

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41374

42

Microsoft  Azure 权限许可和访问控制问题漏洞

CNNVD-202111-826

CVE-2021-42304

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42304

43

Microsoft  Azure 权限许可和访问控制问题漏洞

CNNVD-202111-83

CVE-2021-42302

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42302

44

Microsoft  Azure 权限许可和访问控制问题漏洞

CNNVD-202111-831

CVE-2021-42303

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42303

45

Microsoft  Edge 安全漏洞

CNNVD-202111-838

CVE-2021-41351

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41351

46

Microsoft  Azure 信息泄露漏洞

CNNVD-202111-84

CVE-2021-41373

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41373

47

Microsoft  Exchange   Server 安全漏洞

CNNVD-202111-852

CVE-2021-42305

中危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42305

48

Microsoft  Azure Sphere 缓冲区错误漏洞

CNNVD-202111-82

CVE-2021-41376

低危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41376

49

Microsoft  Azure 信息泄露漏洞

CNNVD-202111-828

CVE-2021-42323

低危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42323

50

Microsoft  Azure 信息泄露漏洞

CNNVD-202111-829

CVE-2021-26444

低危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26444

51

Microsoft  Azure 信息泄露漏洞

CNNVD-202111-832

CVE-2021-42301

低危

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42301


四、修复建议

目前微软官方已针对受支持的产品版本发布了修复以上漏洞的安全补丁,强烈建议受影响用户尽快安装补丁进行防护,官方下载链接:https://msrc.microsoft.com/update-guide/en-us/releaseNote/2021-Nov

注:由于网络问题、计算机环境问题等原因,Windows Update的补丁更新可能出现失败。用户在安装补丁后,应及时检查补丁是否成功更新。右键点击Windows图标,选择“设置(N)”,选择“更新和安全”-“Windows更新”,查看该页面上的提示信息,也可点击“查看更新历史记录”查看历史更新情况。针对未成功安装的更新,可点击更新名称跳转到微软官方下载页面,建议用户点击该页面上的链接,转到“Microsoft更新目录”网站下载独立程序包并安装。