一远程就蓝屏,报错码KMODE_EXCEPTION_NOT_HANDLED ,dmp文件有关键词cdd.dll
KMODE_EXCEPTION_NOT_HANDLED
cdd.dll
cdd是Canonical Display Driver(标准显示驱动)的缩写
不远程没事,一远程就蓝屏,报错码KMODE_EXCEPTION_NOT_HANDLED ,从dmp文件分析,跟cdd.dll ( Canonical Display Driver)有关
云镜显示了漏洞CVE-2021-40449
网上查找到2021年最早的Canonical Display Driver漏洞修复是在7月微软发布的CVE中有体现
https://www.systemtek.co.uk/2021/07/microsoft-windows-canonical-display-driver-privilege-escalation-vulnerability-cve-2021-34516/
https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=CVE-2021-34516
微软在7月月度累计更新中明确写明修复Windows Graphics漏洞(Graphics跟Display脱不了干系)
10月发布的CVE已经包含7月发布的CVE:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40449
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34516
KB5006714跟KB5004298的渊源可以从下面看出:KB5004298 → KB5005076 → KB5005613 → KB5006714
https://www.catalog.update.microsoft.com/Search.aspx?q=KB5004298
https://www.catalog.update.microsoft.com/Search.aspx?q=KB5005076
https://www.catalog.update.microsoft.com/Search.aspx?q=KB5005613
https://www.catalog.update.microsoft.com/Search.aspx?q=KB5006714