內容說明:
微軟釋出產品十二月份安全性更新,修補遠端執行任意程式碼等漏洞。
影響平台:
Windows Media
Microsoft Windows Codecs Library
Microsoft Defender for IoT
Internet Storage Name Service
Microsoft Local Security Authority Server (lsasrv)
Windows Encrypting File System (EFS)
Windows DirectX
Microsoft Message Queuing
Windows Remote Access Connection Manager
Windows Common Log File System Driver
Azure Bot Framework SDK
Windows Storage Spaces Controller
Windows SymCrypt
Windows NTFS
Windows Event Tracing
Remote Desktop Client
Role: Windows Fax Service
Windows Storage
Windows Update Stack
Windows Kernel
Windows Digital TV Tuner
Role: Windows Hyper-V
Windows TCP/IP
Office Developer Platform
Microsoft Office
ASP.NET Core & Visual Studio
Visual Studio Code
Microsoft Devices
Windows Print Spooler Components
Windows Mobile Device Management
Windows Installer
Microsoft PowerShell
處置建議:
目前微軟官方已針對弱點釋出修復版本,請各機關可聯絡系統維護廠商或參考以下連結:
https://msrc.microsoft.com/update-guide/releaseNote/2021-Dec
CVE編號:
CVE-2021-40452
CVE-2021-40453
CVE-2021-41360
CVE-2021-41365
CVE-2021-42293
CVE-2021-42294
CVE-2021-42295
CVE-2021-42309
CVE-2021-42310
CVE-2021-42311
CVE-2021-42312
CVE-2021-42313
CVE-2021-42314
CVE-2021-42315
CVE-2021-42320
CVE-2021-43214
CVE-2021-43215
CVE-2021-43216
CVE-2021-43217
CVE-2021-43222
CVE-2021-43224
CVE-2021-43227
CVE-2021-43235
CVE-2021-43236
CVE-2021-43243
CVE-2021-43244
CVE-2021-43255
CVE-2021-43256
CVE-2021-43875
CVE-2021-43880
CVE-2021-43882
CVE-2021-43888
CVE-2021-43889
CVE-2021-43899
CVE-2021-43905
參考資料:
1. https://msrc.microsoft.com/update-guide/releaseNote/2021-Dec