內容說明:
微軟釋出產品四月份安全性更新,修補遠端執行任意程式碼等漏洞。
影響平台:
Azure AD Web Sign-in
Azure DevOps
Azure Sphere
Microsoft Edge (Chromium-based)
Microsoft Exchange Server
Microsoft Graphics Component
Microsoft Internet Messaging API
Microsoft NTFS
Microsoft Office Excel
Microsoft Office Outlook
Microsoft Office SharePoint
Microsoft Office Word
Microsoft Windows Codecs Library
Microsoft Windows Speech
Open Source Software
Role: DNS Server
Role: Hyper-V
Visual Studio
Visual Studio Code
Visual Studio Code - GitHub Pull Requests and Issues Extension
Visual Studio Code - Kubernetes Tools
Visual Studio Code - Maven for Java Extension
Windows Application Compatibility Cache
Windows AppX Deployment Extensions
Windows Console Driver
Windows Diagnostic Hub
Windows Early Launch Antimalware Driver
Windows ELAM
Windows Event Tracing
Windows Installer
Windows Kernel
Windows Media Player
Windows Network File System
Windows Overlay Filter
Windows Portmapping
Windows Registry
Windows Remote Procedure Call Runtime
Windows Resource Manager
Windows Secure Kernel Mode
Windows Services and Controller App
Windows SMB Server
Windows TCP/IP
Windows Win32K
Windows WLAN Auto Config Service
處置建議:
目前微軟官方已針對弱點釋出修復版本,請各機關可聯絡系統維護廠商或參考以下連結:
https://msrc.microsoft.com/update-guide/releaseNote/2021-Apr
CVE編號:
CVE-2021-21194
CVE-2021-21195
CVE-2021-21196
CVE-2021-21197
CVE-2021-21198
CVE-2021-21199
CVE-2021-26416
CVE-2021-26417
CVE-2021-27067
CVE-2021-27079
CVE-2021-27093
CVE-2021-27095
CVE-2021-28309
CVE-2021-28315
CVE-2021-28317
CVE-2021-28318
CVE-2021-28323
CVE-2021-28324
CVE-2021-28325
CVE-2021-28328
CVE-2021-28435
CVE-2021-28437
CVE-2021-28441
CVE-2021-28442
CVE-2021-28444
CVE-2021-28446
CVE-2021-28449
CVE-2021-28451
CVE-2021-28452
CVE-2021-28453
CVE-2021-28454
CVE-2021-28456
CVE-2021-28460
CVE-2021-28464
CVE-2021-28466
CVE-2021-28468
CVE-2021-28480
CVE-2021-28481
CVE-2021-28482
CVE-2021-28483
參考資料:
1. https://msrc.microsoft.com/update-guide/releaseNote/2021-Apr