漏洞描述
9月15日,亚信安(ān)全应急响应中(zhōng)心(CERT)监测发现,微软8月份补丁日至9月份补丁日共修复漏洞137个,涉及Windows MSHTML Platform、Windows Win32K、Windows Common Log File System Driver、Windows WLAN Auto Config Service等产(chǎn)品。经亚信安(ān)全CERT研判发现,其中(zhōng)共有(yǒu)10个漏洞(包括3个紧急漏洞和7个重要漏洞)危害较大,建议客户及时进行修复。
重点关注漏洞
目前微软官方已发布相关安(ān)全更新(xīn):
https://msrc.microsoft.com/update-guide/releaseNote/2021-Sep
经亚信安(ān)全CERT研判,需重点关注以下漏洞:

其中(zhōng),Windows MSHTML遠(yuǎn)程代码执行漏洞(CVE-2021-40444)已监测到被攻击利用(yòng),EXP已对外公(gōng)开。
修复建议
请选择以下方式进行更新(xīn):
通过Windows安(ān)全更新(xīn)自动安(ān)装(zhuāng)补丁或手动“检查更新(xīn)”。
对于不能(néng)自动更新(xīn)的系统版本,可(kě)下载对应版本的补丁进行安(ān)装(zhuāng):https://msrc.microsoft.com/update-guide/releaseNote/2021-Sep
受影响的版本
此次安(ān)全更新(xīn)发布的漏洞影响以下组件:
Azure Open Management Infrastructure
Azure Sphere
Dynamics Business Central Control
Microsoft Accessibility Insights for Android
Microsoft Edge (Chromium-based)
Microsoft Edge for Android
Microsoft MPEG-2 Video Extension
Microsoft Office
Microsoft Office Access
Microsoft Office Excel
Microsoft Office SharePoint
Microsoft Office Visio
Microsoft Office Word
Microsoft Windows Codecs Library
Microsoft Windows DNS
Visual Studio
Windows Ancillary Function Driver for WinSock
Windows Authenticode
Windows Bind Filter Driver
Windows BitLocker
Windows Common Log File System Driver
Windows Event Tracing
Windows Installer
Windows Kernel
Windows Key Storage Provider
Windows MSHTML Platform
Windows Print Spooler Components
Windows Redirected Drive Buffering
Windows Scripting
Windows SMB
Windows Storage
Windows Subsystem for Linux
Windows TDX.sys
Windows Update
Windows Win32K
Windows WLAN Auto Config Service
Windows WLAN Service
参考链接
https://msrc.microsoft.com/update-guide/releaseNote/2021-Sep
https://mp.weixin.qq.com/s/tBA6BUtyjqr2-bLhG0_H5Q