五月婷婷丁香性爱|j久久一级免费片|久久美女福利视频|中文观看在线观看|加勒比四区三区二|亚洲裸女视频网站|超碰97AV在线69网站免费观看|有码在线免费视频|久久青青日本视频|亚洲国产AAAA

服務(wù)公告

全部公告 > 安全公告 > Windows Print Spooler遠(yuǎn)程代碼執(zhí)行漏洞預(yù)警 (CVE-2021-1675)

Windows Print Spooler遠(yuǎn)程代碼執(zhí)行漏洞預(yù)警 (CVE-2021-1675)

2021-06-30

一、概要

近日,華為云關(guān)注到業(yè)界安全研究人員披露了Windows Print Spooler遠(yuǎn)程代碼執(zhí)行漏洞(CVE-2021-1675)POC,攻擊者利用漏洞可繞過(guò)PfcAddPrinterDriver的安全驗(yàn)證,并在打印服務(wù)器中安裝惡意的驅(qū)動(dòng)程序,如果攻擊者所控制的用戶在域中,則攻擊者可以連接到DC中的Spooler服務(wù),并利用該漏洞在DC中安裝惡意的驅(qū)動(dòng)程序,完全的控制整個(gè)域環(huán)境,目前漏洞POC已公開,風(fēng)險(xiǎn)較高。

Windows Print Spooler是Windows的打印機(jī)后臺(tái)處理程序,廣泛運(yùn)用于各種內(nèi)網(wǎng)中。華為云提醒使用Windows Print Spooler的用戶及時(shí)安排自檢并做好安全加固以降低安全風(fēng)險(xiǎn)。

參考鏈接:https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-1675

二、威脅級(jí)別

威脅級(jí)別:【嚴(yán)重】

(說(shuō)明:威脅級(jí)別共四級(jí):一般、重要、嚴(yán)重、緊急)

三、漏洞影響范圍

影響版本:

Windows Server 2019 (Server Core installation)

Windows Server 2019

Windows Server 2016 (Server Core installation)

Windows Server 2016

Windows Server 2012 R2 (Server Core installation)

Windows Server 2012 R2

Windows Server 2012 (Server Core installation)

Windows Server 2012

Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server, version 2004 (Server Core installation)

Windows RT 8.1

Windows 8.1 for x64-based systems

Windows 8.1 for 32-bit systems

Windows 7 for x64-based Systems Service Pack 1

Windows 7 for 32-bit Systems Service Pack 1

Windows 10 Version 1607 for x64-based Systems

Windows 10 Version 1607 for 32-bit Systems

Windows 10 for x64-based Systems

Windows 10 for 32-bit Systems

Windows Server, version 20H2 (Server Core Installation)

Windows 10 Version 20H2 for ARM64-based Systems

Windows 10 Version 20H2 for 32-bit Systems

Windows 10 Version 20H2 for x64-based Systems

Windows 10 Version 2004 for x64-based Systems

Windows 10 Version 2004 for ARM64-based Systems

Windows 10 Version 2004 for 32-bit Systems

Windows 10 Version 21H1 for 32-bit Systems

Windows 10 Version 21H1 for ARM64-based Systems

Windows 10 Version 21H1 for x64-based Systems

Windows 10 Version 1909 for ARM64-based Systems

Windows 10 Version 1909 for x64-based Systems

Windows 10 Version 1909 for 32-bit Systems

Windows 10 Version 1809 for ARM64-based Systems

Windows 10 Version 1809 for x64-based Systems

Windows 10 Version 1809 for 32-bit Systems

四、安全建議

1、微軟已在6月初的月度更新中發(fā)布了補(bǔ)丁,受影響用戶可通過(guò)Windows Update自動(dòng)更新微軟補(bǔ)丁修復(fù)漏洞,也可以手動(dòng)下載補(bǔ)丁,補(bǔ)丁下載地址:

https://msrc.microsoft.com/update-guide

2、若無(wú)法及時(shí)安裝補(bǔ)丁,可通過(guò)禁用Print Spooler服務(wù)來(lái)進(jìn)行臨時(shí)風(fēng)險(xiǎn)規(guī)避

在服務(wù)應(yīng)用(services.msc)中找到Print Spooler服務(wù),停止運(yùn)行服務(wù)并將“啟動(dòng)類型”修改為“禁用”。

3、為確保數(shù)據(jù)安全,建議重要業(yè)務(wù)數(shù)據(jù)進(jìn)行異地備份。

注:修復(fù)漏洞前請(qǐng)將資料備份,并進(jìn)行充分測(cè)試。