
10月13日,亞信安全應(yīng)急響應(yīng)中心(CERT)監(jiān)測發(fā)現(xiàn),微軟9月份補丁日至10月份補丁日共修復(fù)漏洞107個,涉及Windows Kernel、Windows exFAT File System、Windows TCP/IP、Windows Win32K、HTTP.sys、Microsoft Dynamics、Microsoft Exchange Server、Microsoft Edge (Chromium-based)等產(chǎn)品。經(jīng)亞信安全CERT研判發(fā)現(xiàn),其中共有13個漏洞危害較大,建議客戶及時做好資產(chǎn)自查以及漏洞修復(fù)工作。
目前微軟官方已發(fā)布相關(guān)安全更新:
https://msrc.microsoft.com/update-guide/releaseNote/2021-Oct
經(jīng)亞信安全CERT研判,需重點關(guān)注以下漏洞:
其中,Win32k特權(quán)提升漏洞(CVE-2021-40449)被發(fā)現(xiàn)在野使用,建議客戶及時做好資產(chǎn)自查以及漏洞修復(fù)工作。
通過Windows安全更新自動安裝補丁或手動“檢查更新”。
對于不能自動更新的系統(tǒng)版本,可下載對應(yīng)版本的補丁進行安裝:
https://msrc.microsoft.com/update-guide/releaseNote/2021-Oct
NET Core & Visual Studio
Active Directory Federation Services
Console Window Host
HTTP.sys
Microsoft DWM Core Library
Microsoft Dynamics
Microsoft Edge (Chromium-based)
Microsoft Exchange Server
Microsoft Graphics Component
Microsoft Intune
Microsoft Office Excel
Microsoft Office SharePoint
Microsoft Office Visio
Microsoft Office Word
Microsoft Windows Codecs Library
Rich Text Edit Control
DNS Server
Windows Active Directory Server
Windows AD FS Server
Windows Hyper-V
System Center
Visual Studio
Windows AppContainer
Windows AppX Deployment Service
Windows Bind Filter Driver
Windows Cloud Files Mini Filter Driver
Windows Common Log File System Driver
Windows Desktop Bridge
Windows DirectX
Windows Event Tracing
Windows exFAT File System
Windows Fastfat Driver
Windows Installer
Windows Kernel
Windows MSHTML Platform
Windows Nearby Sharing
Windows Network Address Translation (NAT)
Windows Print Spooler Components
Windows Remote Procedure Call Runtime
Windows Storage Spaces Controller
Windows TCP/IP
Windows Text Shaping
https://msrc.microsoft.com/update-guide/releaseNote/2021-Oct