一、漏洞詳情
Print Spooler是Windows系統(tǒng)中用于管理打印相關(guān)事務(wù)的服務(wù)。
該漏洞在域環(huán)境中合適的條件下,無(wú)需任何用戶交互,未經(jīng)身份驗(yàn)證的遠(yuǎn)程攻擊者就可以利用該漏洞以SYSTEM權(quán)限在域控制器上執(zhí)行任意代碼,從而獲得整個(gè)域的控制權(quán)。
建議受影響用戶及時(shí)更新漏洞補(bǔ)丁進(jìn)行防護(hù),做好資產(chǎn)自查以及預(yù)防工作,以免遭受黑客攻擊。
二、影響范圍
Windows Server 2012 R2 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server Core installation)
Windows Server 2012
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows RT 8.1
Windows 8.1 for x64-based systems
Windows 8.1 for 32-bit systems
Windows 7 for x64-based Systems Service Pack 1
Windows 7 for 32-bit Systems Service Pack 1
Windows Server 2016 (Server Core installation)
Windows Server 2016
Windows 10 Version 1607 for x64-based Systems
Windows 10 Version 1607 for 32-bit Systems
Windows 10 for x64-based Systems
Windows 10 for 32-bit Systems
Windows Server, version 20H2 (Server Core Installation)
Windows 10 Version 20H2 for ARM64-based Systems
Windows 10 Version 20H2 for 32-bit Systems
Windows 10 Version 20H2 for x64-based Systems
Windows Server, version 2004 (Server Core installation)
Windows 10 Version 2004 for x64-based Systems
Windows 10 Version 2004 for ARM64-based Systems
Windows 10 Version 2004 for 32-bit Systems
Windows 10 Version 21H1 for 32-bit Systems
Windows 10 Version 21H1 for ARM64-based Systems
Windows 10 Version 21H1 for x64-based Systems
Windows 10 Version 1909 for ARM64-based Systems
Windows 10 Version 1909 for x64-based Systems
Windows 10 Version 1909 for 32-bit Systems
Windows Server 2019 (Server Core installation)
Windows Server 2019
Windows 10 Version 1809 for ARM64-based Systems
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems
三、修復(fù)建議
1.官方建議:
目前官方已發(fā)布漏洞修復(fù)補(bǔ)丁,建議受影響用戶盡快更新漏洞補(bǔ)丁。
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-1675
2. 臨時(shí)防護(hù)措施:
若相關(guān)用戶暫時(shí)無(wú)法進(jìn)行補(bǔ)丁更新,可通過(guò)禁用Print Spooler服務(wù)來(lái)進(jìn)行緩解:
1)在服務(wù)應(yīng)用(services.msc)中找到Print Spooler服務(wù)。
2)停止運(yùn)行服務(wù),同時(shí)將“啟動(dòng)類(lèi)型”修改為“禁用”。