ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ52ÖÜ
Ðû²¼Ê±¼ä 2019-01-02
2018Äê12ÔÂ24ÈÕ30ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe AcrobatºÍReader TIFFͼÏñ½âÎö»º³åÇøÒç³ö©¶´£»IBM NotesºÍDomino NSD·þÎñȨÏÞÌáÉý©¶´£»Discuz! DiscuzX CVE-2018-20422Äþ¾²ÏÞÖÆÈƹý©¶´£»TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSÃüÁî×¢È멶´£»Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç³ö©¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÊ¥µØÑǸçѧÇøÔâºÚ¿ÍÈëÇÖ£¬Áè¼Ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶;ά»ù½âÃÜÅû¶ÃÀ¹ú´óʹ¹Ý¹ºÎïÇåµ¥£¬ÎļþÊýÁ¿Áè¼Ý1.6Íò·Ý;IBM X-ForceÐû²¼2019ÄêÍøÂç·¸×ïÍþвǰ¾°µÄÔ¤²â³ÂËß;Exchange ServerºáÏòÉø͸ºÍÌáȨ£¬EXPÒÑÐû²¼;ÍøÐŰ쿪չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬Ï¼Ü3469¿îAPP¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
ÖØÒªÄþ¾²Â©¶´Áбí
Adobe AcrobatºÍReader´¦ÖÃTIFFͼÏñ´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://helpx.adobe.com/security/products/acrobat/apsb18-34.html
2. IBM NotesºÍDomino NSD·þÎñȨÏÞÌáÉý©¶´
IBM NotesºÍDomino NSD·þÎñ´¦ÖÃIPC´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÃüÁîÐУ¬ÌáÉýȨÏÞ¡£
https://www.ibm.com/support/docview.wss?uid=ibm10743405
3. Discuz! DiscuzX CVE-2018-20422Äþ¾²ÏÞÖÆÈƹý©¶´
Discuz! DiscuzXÆôÓÃWeChatʱ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ïòplugin.php ac=wxregister·¢ËÍ¿Õ#wechat#common_member_wechatmpµÄÇëÇ󣬿ÉÈƹýÄþ¾²ÏÞÖÆ£¬Î´ÊÚȨ·ÃÎÊ¡£
https://gitee.com/ComsenzDiscuz/DiscuzX/issues/IPRUI4. TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSÃüÁî×¢È멶´
TOSHIBA Home Gateway HEM-GW26AºÍTOSHIBA Home Gateway HEM-GW16A´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâOSÃüÁî¡£
http://www.tlt.co.jp/tlt/information/seihin/notice/defect/20181219/20181219.htm5. Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç³ö©¶´
Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴¹¹½¨¶ñÒâÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.foxitsoftware.com/support/security-bulletins.phpÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢Ê¥µØÑǸçѧÇøÔâºÚ¿ÍÈëÇÖ£¬Áè¼Ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶
Ê¥µØÑǸçѧÇø£¨SDUSD£©Ôâµ½ÍøÂçµöÓã¹¥»÷£¬¹¥»÷Õßͨ¹ýÊÕ¼¯µ½µÄÊÂÇéÈËԱƾ¾Ý·ÃÎÊÁ˸ÃѧÇøµÄÍøÂç·þÎñ£¬Áè¼Ý50ÍòѧÉú¡¢âïÊÑÒÔ¼°ÊÂÇéÈËÔ±µÄÐÅϢй¶¡£SDUSD³Æ¸ÃδÊÚȨ·ÃÎÊÁ¬ÐøÁ˽«½üÒ»ÄêµÄʱ¼ä£¨2018Äê1Ôµ½11Ô£©£¬ÊÜÓ°ÏìµÄÊý¾Ý×îÔç¿É×·ËÝÖÁ2008ÖÁ2009ѧÄ꣬°üÂÞѧÉúºÍÔ±¹¤µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢Éç±£ºÅÂë/ѧÉúID¡¢Ñ§ÉúµÄ×¢²áÐÅÏ¢¡¢Ñ§Éú¼Ò³¤¼°Ô±¹¤µÄ½ô¼±ÁªÏµÈËÐÅÏ¢¡¢Ô±¹¤µÄÈËΪÒÔ¼°¸£ÀûÐÅÏ¢µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/
ÔÎÄÁ´½Ó£º
https://shoppinglist.wikileaks.org/
3¡¢IBM X-ForceÐû²¼2019ÄêÍøÂç·¸×ïÍþвǰ¾°µÄÔ¤²â³ÂËß
ÔÎÄÁ´½Ó£º
https://securityintelligence.com/ibm-x-force-security-predictions-for-the-2019-cybercrime-threat-landscape/
4¡¢Exchange ServerºáÏòÉø͸ºÍÌáȨ£¬EXPÒÑÐû²¼

ZDIÅû¶Exchange ServerÖеÄÒ»¸öÄþ¾²Â©¶´£¨CVE-2018-8581£©µÄ¼¼Êõϸ½Ú¡£¸Ã©¶´ÔÊÐíÈκξ¹ýÉí·ÝÑéÖ¤µÄÓû§Ã°³äExchange ServerÉϵÄÆäËüÓû§£¬¿ÉÓÃÓÚµöÓã»î¶¯¡¢Êý¾Ýй¶µÈ¹¥»÷»î¶¯ÖС£¸Ã©¶´ÊÇÒ»¸ö·þÎñÆ÷¶ËÇëÇóαÔ죨SSRF£©Â©¶´£¬Ñо¿ÈËÔ±ÑÝʾÁËÈçºÎÀûÓø鶴ÐÞ¸ÄÊܺ¦ÕßÓÊÏäµÄÈëÕ¾¹æÔò£¬²¢½«ËùÓеÄÈëÕ¾µç×ÓÓʼþ¶¼×ª·¢¸ø¹¥»÷Õߣ¬Æäexp½Å±¾¿ÉÒÔ´ÓgithubÉÏÏÂÔØ¡£Î¢ÈíÔÚ11Ô·ݵÄÐÞ¸´²¹¶¡ÖÐͨ¹ýɾ³ýÒ»¸ö×¢²á±íÏîÀ´»º½â¸Ã©¶´¡£
ÔÎÄÁ´½Ó£º
https://www.zerodayinitiative.com/blog/2018/12/19/an-insincere-form-of-flattery-impersonating-users-on-microsoft-exchange
5¡¢ÍøÐŰ쿪չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬Ï¼Ü3469¿îAPP

½üÆÚ£¬¹ú¼ÒÍøÐÅ°ì»áͬÓйز¿ÃÅÕë¶ÔÍøÃñ·´Ó³Ç¿ÁÒµÄÎ¥·¨Î¥¹æ¡¢µÍËײ»Á¼Òƶ¯Ó¦Ó÷¨Ê½£¨APP£©ÂÒÏ󣬼¯ÖпªÕ¹ÇåÀíÕûÖÎרÏîÐж¯£¬ÒÀ·¨¹Øͣϼܡ°³ÉÈËÔ¼ÁÄ¡±¡°Á½ÐÔ˽ÃÜȦ¡±¡°°ÄÃŽðɳ¡±¡°Ò¹É«µÄ¼Åį¡±¡°È«ÃñÉäË®¹û¡±µÈ3469¿îÉæ»ÆÉæ¶Ä¡¢¶ñÒâ¿Û·Ñ¡¢ÇÔÈ¡Òþ˽¡¢ÓÕÆÕ©Æ¡¢Î¥¹æÓÎÏ·¡¢²»Á¼Ñ§Ï°ÀàAPP¡£¾Ýͳ¼Æ£¬Ä¿Ç°ÔÚ¹úÄÚÓ¦ÓÃÉ̵êÉϼܵÄAPPÒѾÁè¼Ý480Íò¿î£¬º¸ÇÁËÈËÃñÉú»îµÄ¸÷¸ö·½Ãæ¡£½üÈÕ£¬¹ú¼ÒÍøÐŰ켯ÌåԼ̸28¼ÒÓ¦ÓÃÉ̵ꡢÉ罻ƽ̨ºÍÔÆ·þÎñÆóÒµ£¬¶ÔÆäÂÄÐÐÖ÷ÌåÔðÈβ»Á¦¡¢¿Í¹ÛÉÏΪΥ·¨Î¥¹æAPPÌṩ½ÓÈëͨµÀ¡¢À©É¢ÇþµÀÌá³ö¾¯¸æ£¬ÒªÇóÁ¢¼´¶Ô¸÷×Ôƽ̨½øÐÐÈ«ÃæÅŲ飬ÈÏÕ濪չ×Ô²é×Ô¾À£¬»ý¼«Ö÷¶¯¼ÓÈëÎ¥·¨Î¥¹æAPPÂÒÏóרÏîÕûÖÎÐж¯£¬ÇåÀíÓ¦ÓÃÉ̵꣬ÆÁ±Î¶ñÒâÁ´½Ó£¬Çå²é½ÓÈë·þÎñ¡£
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2018-12/28/c_1123919199.htm
ÉùÃ÷£º±¾×ÊѶÓɶ«Éƽ̨άËûÃüÄþ¾²Ð¡×é·ÒëºÍÕûÀí