• 产品与解决方案
  • 行业解决方案
  • 服务
  • 支持
  • 合作伙伴
  • 新华三人才研学中心
  • 关于我们
docurl=/cn/Products___Technology/Products/IP_Security/Security_Research/Home/Notice/Notice/202112/1519562_30003_0.htm

Windows Print Spooler远程代码执行漏洞通告(CVE-2021-1675)

【发布时间:2021-12-30】

威胁预警团队

2021/06/30


1. 漏洞综述

1.1 漏洞背景

Print Spooler是打印后台处理服务,管理所有本地和网络打印队列及控制所有打印工作, 其进程名为spoolsv.exe。近日,新华三攻防实验室威胁预警团队监测到微软官方6月发布的安全更新中修复的一处Windows Print Spooler远程代码执行漏洞(CVE-2021-1675)利用代码在网络中公开,攻击者可远程触发漏洞,成功利用这些漏洞可导致在目标机器上执行任意代码或实现权限提升。

1.2 漏洞原理

漏洞根源在于Windows Print Spooler未能正确地实施安全限制,攻击者可绕过RpcAddPrinterDriver的安全验证,在打印服务器上安装恶意驱动程序。若攻击者获取到域用户权限,可连接到域控中的Spooler服务,并在域控制器中安装恶意驱动程序,从而完全控制整个域环境。

目前该漏洞利用细节已在互联网公开,建议受影响用户及时排查并修复。

2. 影响范围

Windows Server 2019 (Server Core installation)

Windows Server 2019

Windows Server 2016 (Server Core installation)

Windows Server 2016

Windows Server 2012 R2 (Server Core installation)

Windows Server 2012 R2

Windows Server 2012 (Server Core installation)

Windows Server 2012

Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server, version 2004 (Server Core installation)

Windows RT 8.1

Windows 8.1 for x64-based systems

Windows 8.1 for 32-bit systems

Windows 7 for x64-based Systems Service Pack 1

Windows 7 for 32-bit Systems Service Pack 1

Windows 10 Version 1607 for x64-based Systems

Windows 10 Version 1607 for 32-bit Systems

Windows 10 for x64-based Systems

Windows 10 for 32-bit Systems

Windows Server, version 20H2 (Server Core Installation)

Windows 10 Version 20H2 for ARM64-based Systems

Windows 10 Version 20H2 for 32-bit Systems

Windows 10 Version 20H2 for x64-based Systems

Windows 10 Version 2004 for x64-based Systems

Windows 10 Version 2004 for ARM64-based Systems

Windows 10 Version 2004 for 32-bit Systems

Windows 10 Version 21H1 for 32-bit Systems

Windows 10 Version 21H1 for ARM64-based Systems

Windows 10 Version 21H1 for x64-based Systems

Windows 10 Version 1909 for ARM64-based Systems

Windows 10 Version 1909 for x64-based Systems

Windows 10 Version 1909 for 32-bit Systems

Windows 10 Version 1809 for ARM64-based Systems

Windows 10 Version 1809 for x64-based Systems

Windows 10 Version 1809 for 32-bit Systems

3. 处置方法

3.1官方补丁

1、目前官方已经发布对应漏洞修复程序,请下载安装对应的安全更新,下载链接: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-1675

4. 参考链接

1、 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-1675

新华三官网
联系我们