
经亚信安(ān)全CERT研判,本周期共有(yǒu):
6个被标记為(wèi)紧急的漏洞,其中(zhōng)4个漏洞评分(fēn)超过7.5
2个被标记為(wèi)重要且在野利用(yòng)的漏洞
1个被标记為(wèi)重要且易被利用(yòng)的漏洞
其中(zhōng),被发现在野利用(yòng)的漏洞為(wèi):
Microsoft Excel安(ān)全功能(néng)绕过漏洞(CVE-2021-42292)
Microsoft Exchange Server遠(yuǎn)程代码执行漏洞(CVE-2021-42321)
本期需重点关注的漏洞:

此次安(ān)全更新(xīn)发布的漏洞影响以下组件:
3D Viewer
Microsoft Dynamics
Microsoft Edge (Chromium-based)
Microsoft Edge (Chromium-based) in IE Mode
Microsoft Exchange Server
Microsoft Office
Microsoft Office Access
Microsoft Office Excel
Microsoft Office SharePoint
Microsoft Office Word
Microsoft Windows
Microsoft Windows Codecs Library
Power BI
Role: Windows Hyper-V
Visual Studio
Visual Studio Code
Windows Active Directory
Windows COM
Windows Core Shell
Windows Cred SSProvider Protocol
Windows Defender
Windows Desktop Bridge
Windows Diagnostic Hub
Windows Fastfat Driver
Windows Feedback Hub
Windows Hello
Windows Installer
Windows Kernel
Windows NTFS
Windows RDP
Windows Scripting
Windows Virtual Machine Bus
请选择以下方式进行更新(xīn):
1.通过Windows安(ān)全更新(xīn)自动安(ān)装(zhuāng)补丁或手动“检查更新(xīn)”。
2.对于不能(néng)自动更新(xīn)的系统版本,可(kě)下载对应版本的补丁进行安(ān)装(zhuāng):
https://msrc.microsoft.com/update-guide/releaseNote/2021-Nov
https://msrc.microsoft.com/update-guide/releaseNote/2021-Nov