漏洞描述
9月15日,亞信安全應(yīng)急響應(yīng)中心(CERT)監(jiān)測發(fā)現(xiàn),微軟8月份補(bǔ)丁日至9月份補(bǔ)丁日共修復(fù)漏洞137個,涉及Windows MSHTML Platform、Windows Win32K、Windows Common Log File System Driver、Windows WLAN Auto Config Service等產(chǎn)品。經(jīng)亞信安全CERT研判發(fā)現(xiàn),其中共有10個漏洞(包括3個緊急漏洞和7個重要漏洞)危害較大,建議客戶及時進(jìn)行修復(fù)。
重點關(guān)注漏洞
目前微軟官方已發(fā)布相關(guān)安全更新:
https://msrc.microsoft.com/update-guide/releaseNote/2021-Sep
經(jīng)亞信安全CERT研判,需重點關(guān)注以下漏洞:

其中,Windows MSHTML遠(yuǎn)程代碼執(zhí)行漏洞(CVE-2021-40444)已監(jiān)測到被攻擊利用,EXP已對外公開。
修復(fù)建議
請選擇以下方式進(jìn)行更新:
通過Windows安全更新自動安裝補(bǔ)丁或手動“檢查更新”。
對于不能自動更新的系統(tǒng)版本,可下載對應(yīng)版本的補(bǔ)丁進(jìn)行安裝:https://msrc.microsoft.com/update-guide/releaseNote/2021-Sep
受影響的版本
此次安全更新發(fā)布的漏洞影響以下組件:
Azure Open Management Infrastructure
Azure Sphere
Dynamics Business Central Control
Microsoft Accessibility Insights for Android
Microsoft Edge (Chromium-based)
Microsoft Edge for Android
Microsoft MPEG-2 Video Extension
Microsoft Office
Microsoft Office Access
Microsoft Office Excel
Microsoft Office SharePoint
Microsoft Office Visio
Microsoft Office Word
Microsoft Windows Codecs Library
Microsoft Windows DNS
Visual Studio
Windows Ancillary Function Driver for WinSock
Windows Authenticode
Windows Bind Filter Driver
Windows BitLocker
Windows Common Log File System Driver
Windows Event Tracing
Windows Installer
Windows Kernel
Windows Key Storage Provider
Windows MSHTML Platform
Windows Print Spooler Components
Windows Redirected Drive Buffering
Windows Scripting
Windows SMB
Windows Storage
Windows Subsystem for Linux
Windows TDX.sys
Windows Update
Windows Win32K
Windows WLAN Auto Config Service
Windows WLAN Service
參考鏈接
https://msrc.microsoft.com/update-guide/releaseNote/2021-Sep
https://mp.weixin.qq.com/s/tBA6BUtyjqr2-bLhG0_H5Q