ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ33ÖÜ

Ðû²¼Ê±¼ä 2019-08-26

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö



2019Äê8ÔÂ19ÈÕÖÁ25ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´46¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇForcepoint Next Generation FirewallÃÜÂëÑéÖ¤Èƹý©¶´£»Aspose Aspose.Cells LabelSst´úÂëÖ´ÐЩ¶´£»Cisco Small Business 220ϵÁÐÖÇÄܽ»»»»úÔ¶³Ì´úÂëÖ´ÐЩ¶´£»IBM DB2 High Performance UnloadȨÏÞÌáÉý©¶´£»Google Nest Cam IQ Indoor Weave PASE½âÎö¹¦Ð§ÐÅϢ鶩¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ΢ÈíÈ·ÈÏWindows10 1903¸üдæÔÚ´íÎó0x80073701£»ÏµÍ³¹ÜÀíÔ±¹¤¾ßWebmin´æÔÚ0day©¶´¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ»ÃÀ¹úµÂ¿ËÈø˹ÖÝ23¸öÕþ¸®»ú¹¹ÔâÀÕË÷Èí¼þ¹¥»÷£»¹È¸è¡¢Mozilla¼°Æ»¹û½ûÓùþÈø¿Ë˹̹Õþ¸®·¢±íµÄ¸ùÖ¤Ê飻¿¨°Í˹»ùÐû²¼2019Ä깤ҵÍøÂçÄþ¾²×´¿ö³ÂËß¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


> ÖØÒªÄþ¾²Â©¶´Áбí



1. Forcepoint Next Generation FirewallÃÜÂëÑéÖ¤Èƹý©¶´


Forcepoint Next Generation Firewall LDAPÑéÖ¤ÒªÁì´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÈƹýÃÜÂëÑéÖ¤£¬·ÃÎÊÊܱ£»¤·þÎñ¡£
https://support.forcepoint.com/KBArticle?id=000017474

2. Aspose Aspose.Cells LabelSst´úÂëÖ´ÐЩ¶´


Aspose Cells labelSst record parser´æÔÚÔ½½ç¶Á©¶´£¬ÔÊÐíδÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄXLSÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÒÔÓû§ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0794

3. Cisco Small Business 220ϵÁÐÖÇÄܽ»»»»úÔ¶³Ì´úÂëÖ´ÐЩ¶´


Cisco Small Business 220ϵÁÐÖÇÄܽ»»»»ú¶ÁÈ¡Êý¾Ýµ½ÄÚ²¿»º³åÇøʱ´æÔÚ»º³åÇøÒç³ö¹¥»÷£¬ÔÊÐíδÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔROOTȨÏÞÖ´ÐÐÈÎÒâÃüÁî¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190806-sb220-rce

4. IBM DB2 High Performance UnloadȨÏÞÌáÉý©¶´


IBM DB2 High Performance Unload´¦ÖÃPATH´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíµ±µØ¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɼÓÔضñÒâ¹²Ïí¿â£¬ÌáÉýȨÏÞ¡£
https://www-01.ibm.com/support/docview.wss?uid=ibm10964592

5. Google Nest Cam IQ Indoor Weave PASE½âÎö¹¦Ð§ÐÅϢ鶩¶´


Google Nest Cam IQ Indoor Weave PASE½âÎö¹¦Ð§´æÔÚÐÅϢ鶩¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄweave±¨ÎÄÇëÇ󣬿ɿØÖÆÉ豸¡£
https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0798


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö



1¡¢Î¢ÈíÈ·ÈÏWindows10 1903¸üдæÔÚ´íÎó0x80073701


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


MicrosoftÒÑÈ·ÈÏËûÃÇÕýÔÚÐÞ¸´Óû§ÔÚ°²×°ÐµÄv1903¸üÐÂʱÊÕµ½µÄ0x80073701´íÎó¡£ÔÚ2019Äê8Ô²¹¶¡ÐÇÆÚ¶þ¸üÐÂÐû²¼ºó£¬Óû§¿ªÊ¼³ÂËßËûÃÇÔÚʵÑé°²×°Windows 10°æ±¾1903ÀÛ»ý¸üÐÂʱÊÕµ½´íÎó¡£ËäÈ»´ó¶àÊýÓû§³ÂËß±íÃ÷ÎÊÌâʼÓÚ8ÔÂ13ÈÕ£¬µ«Î¢ÈíÌåÏÖ£¬ÔÚÐû²¼2019Äê5ÔÂ29ÈÕKB4497935  ÀÛ»ý¸üÐÂʱ£¬ÎÊÌâʵ¼ÊÉÏÒѾ­·ºÆð¡£Ä¿Ç°Éв»Çå³þÈκÎδÀ´µÄÐÞ¸´·¨Ê½ÊÇ·ñÒ²½«½âÎöÓû§ÕýÔÚ½ÓÊÕµÄÆäËû´íÎó´úÂë¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-windows-10-1903-update-error-0x80073701-working-on-fix/

2¡¢ÏµÍ³¹ÜÀíÔ±¹¤¾ßWebmin´æÔÚ0day©¶´¿ÉÖÂÔ¶³Ì´úÂëÖ´ÐÐ


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Á÷ÐеÄϵͳ¹ÜÀíÔ±¹¤¾ßWebminÔÚÖØÖÃÃÜÂ빦ЧÖз¢ÏÖÁËÒ»¸ö´íÎ󣬸ôíÎóÔÊÐí¶ñÒâµÚÈý·½ÓÉÓÚȱÉÙÊäÈëÑéÖ¤¶øÖ´ÐжñÒâ´úÂë¡££¬ÒÑÖªÔڶ˿Ú10000ÉÏÔËÐУ¬¶øÇÒÓ°Ïì×îа汾1.920£¬WebminÉÐδÐû²¼¹ûÈ»ÉùÃ÷»ò²¹¶¡£¬Ä¿Ç°»¥ÁªÍøÉϹûÈ»µÄWebminÖÁÉÙÁè¼Ý13Íò¸ö¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.firosolutions.com/exploits/webmin/

3¡¢ÃÀ¹úµÂ¿ËÈø˹ÖÝ23¸öÕþ¸®»ú¹¹ÔâÀÕË÷Èí¼þ¹¥»÷


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÉÏÖÜÎåµÂ¿ËÈø˹Öݶà´ï23¼ÒʵÌå»ú¹¹-ÆäÖдó¶àÊýÊǵط½Õþ¸®-Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µÂ¿ËÈø˹ÖݹÙÔ±³ÆÕâÊÇÒ»¸öµ¥Ò»¹¥»÷ÕßÌᳫµÄÕë¶ÔÐÔ¹¥»÷µÄÒ»²¿ÃÅ¡£½ØÖÁÖÜÁùÍí£¬µÂ¿ËÈø˹ÖÝÐÅÏ¢×ÊÔ´²¿£¨DIR£©ÌåÏÖÓ¦¼±ÏìÓ¦ÍŶÓÕý»ý¼«ÓëËùÓÐ23¸öʵÌåºÏ×÷£¬Ê¹ÆäϵͳÖØÐÂÉÏÏߣ¬¶øÇҵ¿ËÈø˹ÖݵÄϵͳºÍÍøÂç²»»áÊܵ½Ó°Ï졣Ŀǰ¾ßÌå¹¥»÷ϸ½ÚÈÔÈ»²»×㣬DIRҲûÓÐÆÀÂÛÄÄЩϵͳ·ºÆð¹ÊÕÏ¡¢ÏµÍ³ÈçºÎ±»Ñ¬È¾ÒÔ¼°¾ßÌåµÄÊê½ðÊý¶î¡£


Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/coordinated-ransomware-attack-hits-23-texas-government-agencies/147457/

4¡¢¹È¸è¡¢Mozilla¼°Æ»¹û½ûÓùþÈø¿Ë˹̹Õþ¸®·¢±íµÄ¸ùÖ¤Êé


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹È¸è¡¢Mozilla¼°Æ»¹û½ûÓùþÈø¿Ë˹̹Õþ¸®ÓÚÉϸöÔ·¢±íµÄ¸ùÖ¤Ê飬¸ÃÖ¤ÊéÓÃÓÚ¼à¿Ø¹«ÃñµÄÉÏÍøÁ÷Á¿¡£Æäʱ¹þÈø¿Ë˹̹Õþ¸®ÒªÇó¸Ã¹úISPºÏ×÷£¬Ç¿ÖÆÔÚËùÓÐÍøÂçÓû§Öа²×°¸Ã¸ùÖ¤Êé¡£ÏÖÔÚµ±Chrome¡¢Firefox¼°Safari¼ì²âµ½¸Ã¸ùÖ¤Êéʱ£¬½«×èÖ¹Á¬½Ó²¢ÏÔʾ´íÎóÐÅÏ¢¡£¹þÈø¿Ë˹̹Õþ¸®ÒѾ­ÔÚ8Ô³õÍ£Ö¹ÁËÕâÒ»¼Æ»®£¬Ò»Ãû¹ÙÔ±ÌåÏÖÕû¸ö¼Æ»®Ö»ÊÇÕþ¸®µÄÒ»¸ö²âÊÔ¡£µ«ÈÔÓÐÊý°ÙÍòÉ豸ÈÔÔÚʹÓøÃÖ¤Êé¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/kazakhstan-root-certificate.html

5¡¢¿¨°Í˹»ùÐû²¼2019Ä깤ҵÍøÂçÄþ¾²×´¿ö³ÂËß


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù¶Ô282¼ÒÔËÐÐOT/ICSϵͳµÄÆóÒµ½øÐе÷ÑУ¬ÕûÀí²¢Ðû²¼ÁË¡¶2019Ä깤ҵÍøÂçÄþ¾²×´¿ö¡·³ÂËß¡£Æ¾¾Ý¸Ã³ÂËߣ¬È¥ÄêÁè¼ÝÒ»°ë£¨52%£©µÄ¹¤¿ØÄþ¾²Ê¼þÊÇÓÉÈËΪʧÎóµ¼ÖµÄ¡£ËäÈ»¾ø´ó¶àÊý¹«Ë¾£¨81£¥£©¼Æ»®½øÐÐÍøÂçÊý×Ö»¯ÔËÓªÒÔÍƶ¯¹¤Òµ4.0£¬µ«·ÖÅäÁËÍøÂçÄþ¾²Ô¤ËãµÄÈ´Éٵöࣨ57£¥£©¡£³ý´ËÖ®Í⣬ÕâЩ¹«Ë¾µÄÍøÂçÄþ¾²¼¼ÄÜÈÔÈ»ÁîÈ˵£ÓÇ£ºÊÜ·ÃÕßµÄÁ½´óµ£ÓǼ¯ÖÐÔÚûÓÐ×ã¹»µÄÍøÂçÄþ¾²×¨¼ÒÀ´¹ÜÀí¹¤ÒµÍøÂ磬ÒÔ¼°OT/ICS²Ù×÷Ô±ÆÕ±éȱ·¦Äþ¾²Òâʶ¡£

Ô­ÎÄÁ´½Ó£ºhttps://ics.kaspersky.com/the-state-of-industrial-cybersecurity-2019/