ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ20ÖÜ
Ðû²¼Ê±¼ä 2019-05-20±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2019Äê5ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´74¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Remote Desktop Services CVE-2019-0708Ô¶³Ì´úÂëÖ´ÐЩ¶´£»Adobe Media Encoder CVE-2019-7842ÊͷźóʹÓÃÔ¶³Ì´úÂëÖ´ÐЩ¶´£» Facebook WhatsApp CVE-2019-3568»º³åÇøÒç³ö©¶´£»Apple Safari¶à¸öÄÚ´æÆÆ»µÈÎÒâ´úÂëÖ´ÐЩ¶´£»Adobe AcrobatºÍReader¶à¸öÊͷźóʹÓôúÂëÖ´ÐЩ¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ΢ÈíÐÞ¸´79¸ö©¶´£¬°üÂÞRDPÖеÄRCE©¶´£¨CVE-2019-0708£©£»¹¥»÷ÕßÀûÓûªË¶ÖмäÈ˹¥»÷·Ö·¢PleadºóÃÅ£»Stack OverflowÐû²¼Í¨¸æ³ÆÆäÔâºÚ¿ÍÈëÇÖ£»Î´ÉèÃÜÂëµÄÊý¾Ý¿âй¶½ü90%°ÍÄÃÂí¹«ÃñÐÅÏ¢£»¶íÂÞ˹ºÚ¿Í×éÖ¯³öÊÛÃÀ¹ú3´ó·´²¡¶¾¹«Ë¾Ô´Âë¡£
ÖØÒªÄþ¾²Â©¶´Áбí
1. Microsoft Windows Remote Desktop Services CVE-2019-0708Ô¶³Ì´úÂëÖ´ÐЩ¶´
Microsoft Windows Remote Desktop Services´¦ÖÃÄڴ湤¾ß´æÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄRDPÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
2. Adobe Media Encoder CVE-2019-7842ÊͷźóʹÓÃÔ¶³Ì´úÂëÖ´ÐЩ¶´
Adobe Media Encoder´¦ÖÃÎļþ´æÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://helpx.adobe.com/security/products/media-encoder/apsb19-29.html
3. Facebook WhatsApp CVE-2019-3568»º³åÇøÒç³ö©¶´
Facebook WhatsApp´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.facebook.com/security/advisories/cve-2019-3568
4. Apple Safari¶à¸öÄÚ´æÆÆ»µÈÎÒâ´úÂëÖ´ÐЩ¶´
Apple Safari WebKit´æÔÚ¶à¸öÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÒ³ÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://support.apple.com/zh-cn/HT210123
5. Adobe AcrobatºÍReader¶à¸öÊͷźóʹÓôúÂëÖ´ÐЩ¶´
Adobe AcrobatºÍReader´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÒ³ÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://helpx.adobe.com/security/products/acrobat/apsb19-18.html
ÖØÒªÄþ¾²Ê¼þ×ÛÊö

Öܶþ΢ÈíÐû²¼5ÔÂWindowsÄþ¾²¸üУ¬ÐÞ¸´79¸ö©¶´¡£ÆäÖаüÂÞRDP·þÎñÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2019-0708£©£¬´Ë©¶´ÊÇÔ¤Éí·ÝÑéÖ¤£¬ÎÞÐèÓû§½»»¥£¬ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿±êϵͳÉÏÖ´ÐÐÈÎÒâ´úÂ룻ÌáȨ0day£¨CVE-2019-0863£©£¬¸Ã©¶´¿ÉÔÊÐí¹¥»÷ÕßÌáÉýÖÁ¹ÜÀíԱȨÏÞ£»Õë¶ÔIntel CPU MDS¹¥»÷µÄ©¶´ÐÞ¸´£¬ÕâЩ©¶´Ó°ÏìÁË2011ÄêÒÔÀ´¼¸ºõËùÓеÄIntel CPU¡£ÍêÕû©¶´ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-may-2019-patch-tuesday-arrives-with-fix-for-windows-zero-day-mds-attacks/
2¡¢¹¥»÷ÕßÀûÓûªË¶ÖмäÈ˹¥»÷·Ö·¢PleadºóÃÅ
4Ôµ×ESETÑо¿ÈËÔ±ÊӲ쵽ÀûÓá°AsusWSPanel.exe¡±·Ö·¢PleadºóÃŵĹ¥»÷»î¶¯¡£AsusWSPanel.exeÊÇ»ªË¶ÔÆ´æ´¢·þÎñWebStorageµÄWindows¿Í»§¶Ë¡£Ñо¿ÈËÔ±¸ø³öÁËÁ½ÖÖ¿ÉÄܵĹ¥»÷³¡¾°£¬Ò»ÖÖÊÇ»ªË¶Ôâµ½¹©Ó¦Á´¹¥»÷£¬ÁíÒ»ÖÖÊǹ¥»÷ÕßÀûÓÃÖмäÈ˹¥»÷ºÍÒ×Êܹ¥»÷µÄ·ÓÉÆ÷À´Á÷´«¶ñÒâÈí¼þ¡£½øÒ»²½µÄ·ÖÎöºóÑо¿ÈËÔ±ÈÏΪºóÒ»ÖÖ¹¥»÷³¡¾°µÄ¿ÉÄÜÐÔ¸ü´ó¡£
ÔÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/bad-actors-using-mitm-attacks-against-asus-to-distribute-plead-backdoor/
3¡¢Stack OverflowÐû²¼Í¨¸æ³ÆÆäÔâºÚ¿ÍÈëÇÖ
5ÔÂ16ÈÕStack OverflowÐû²¼ÁËÒ»Ìõ¼ò¶ÌµÄͨ¸æ£¬³Æ5ÔÂ11ÈÕºÚ¿ÍÈëÇÖÁËÆäÉú²úϵͳ¡£Æ¾¾ÝStack Overflow¹¤³Ì¸±×ܲÃMary FergusonµÄ˵·¨£¬ºÚ¿Í»ñµÃÁËÒ»¶¨Ë®Æ½µÄÉú²úϵͳ·ÃÎÊȨÏÞ£¬Stack Overflow·¢ÏÖ²¢ÊÓ²ìÁË·ÃÎʵķ¶Î§£¬¶øÇÒÐÞ¸´ÁËËùÓеÄÒÑ֪©¶´¡£ÊÓ²ìûÓз¢ÏÖºÚ¿Í»ñµÃÓû§Êý¾ÝµÄÈκÎÖ¤¾Ý¡£Ä¿Ç°ÊÓ²ìÕýÔÚ½øÐÐÖУ¬Òò´ËStack Overflow²¢Î´Åû¶¸ü¶àϸ½Ú¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/stack-overflow-says-hackers-breached-production-systems/
4¡¢Î´ÉèÃÜÂëµÄÊý¾Ý¿âй¶½ü90%°ÍÄÃÂí¹«ÃñÐÅÏ¢
Äþ¾²Ñо¿Ô±Bob DiachenkoʹÓÃShodanÔÚAWSÉÏ·¢ÏÖÒ»¸öδÊܱ£»¤µÄElasticsearchÊý¾Ý¿â£¬¸ÃÊý¾Ý¿âй¶ÁËÊý°ÙÍò°ÍÄÃÂí¹«ÃñµÄÃô¸ÐÐÅÏ¢¡£Æ¾¾ÝÑо¿ÈËÔ±µÄ±íÊö£¬¸ÃÊý¾Ý¿â°üÂÞ3427396Ìõ±êǩΪ¡°»¼Õß¡±µÄ¼Ç¼ÒÔ¼°468086Ìõ±êǩΪ¡°²âÊÔ»¼Õß¡±µÄ¼Ç¼¡£ÕâЩÐÅÏ¢°üÂÞÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éí·ÝÖ¤ºÅÂë¡¢µØÖ·¡¢ÓÊÏäºÍµç»°ºÅÂëµÈ¡£Èç¹ûÊý¾ÝûÓÐÖظ´£¬ÕâЩ¼Ç¼Լռ¸Ã¹ú×ÜÈË¿ÚµÄ90%¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/sensitive-information-of-millions-of-panama-citizens-leaked/
5¡¢¶íÂÞ˹ºÚ¿Í×éÖ¯³öÊÛÃÀ¹ú3´ó·´²¡¶¾¹«Ë¾Ô´Âë
×Ô3Ô·ÝÒÔÀ´£¬¶íÂÞ˹ºÚ¿ÍÍÅ»ïFxmspÔÚµØÏÂÂÛ̳ÉÏÐû³Æ³öÊÛÈý¼ÒÃÀ¹ú·´²¡¶¾¹«Ë¾µÄÈí¼þ²úÎïÔ´ÂëºÍ¹«Ë¾ÍøÂç·ÃÎÊȨÏÞ¡£¿ª¶ËµÄ¼Û¸ñÊÇ·ÃÎÊȨÏÞ25ÍòÃÀÔª£¬Ô´´úÂë15ÍòÃÀÔª£¬µ«±¨¼Û²¢²»Àι̡£Fxmsp²¢Î´Ö¸³ö¾ßÌåµÄ¹«Ë¾Ãû³Æ£¬µ«ÌṩÁË°üÂÞ30TBÊý¾ÝµÄÎļþ¼Ð½ØÆÁ£¬¾Ý³ÆÕâЩÊý¾Ý°üÂÞ¿ª·¢Îĵµ¡¢È˹¤ÖÇÄÜÄ£ÐÍ¡¢WebÄþ¾²Èí¼þºÍ·´²¡¶¾Èí¼þµÄ´úÂëµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-selling-access-and-source-code-from-antivirus-companies/