ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ48ÖÜ
Ðû²¼Ê±¼ä 2020-11-30> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2020Äê11ÔÂ23ÈÕÖÁ11ÔÂ29ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´48¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇVmware Workspace One CVE-2020-4006ÃüÁî×¢È멶´£»Shenzhen C-Data 72408AĬÈÏtelnet·þÎñ©¶´£»Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑé֤©¶´£»Barco wePresent WiPG-1600W¹Ì¼þÐÅϢ鶩¶´£»Mongodb Server RoleName::parseFromBSON()¾Ü¾ø·þÎñ©¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÁù¸öÔÂÒÔÀ´Î¢ÈíÈÔδÐÞ¸´Windows10ÖÐÒÑ֪©¶´£»ºÚ¿Í¹ûÈ»5Íò¸ö´æÔÚ©¶´µÄFortinet VPNÉ豸ÁÐ±í£»VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬ÉÐδÐû²¼²¹¶¡£»Ñо¿ÈËÔ±·¢ÏÖWin7ºÍServer2008Öеĵ±µØÌáȨ0day£»Group-IBÐû²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÔ¤²â·ÖÎö³ÂËß¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
> ÖØÒªÄþ¾²Â©¶´Áбí
1.Vmware Workspace One CVE-2020-4006ÃüÁî×¢È멶´
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿É×¢ÈëÈÎÒâÃüÁî²¢Ö´ÐС£
https://docs.opsmanager.mongodb.com/current/release-notes/application/#onprem-server-4-4-3
2.Shenzhen C-Data 72408AĬÈÏtelnet·þÎñ©¶´
Shenzhen C-Data 72408A Telnet·þÎñ´æÔÚ¶à¸öĬÈÏƾ¾Ý©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎÊÉ豸¡£
https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html
3.Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑé֤©¶´
Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɰ²×°Ð޸ĹýµÄ/¶ñÒâµÄÓ³Ïñ¡£
https://korelogic.com/Resources/Advisories/KL-001-2020-009.txt
4.Barco wePresent WiPG-1600W¹Ì¼þÐÅϢ鶩¶´
Barco wePresent WiPG-1600W¹Ì¼þÓ³ÏñÖаüÂÞÓ²±àÂëµÄ¸ùÃÜÂëÉ¢ÁУ¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éͨ¹ý´ËÐÅϢδÊÚȨ·ÃÎÊ¡£
https://korelogic.com/Resources/Advisories/KL-001-2020-008.txt
5.Mongodb Server RoleName::parseFromBSON()¾Ü¾ø·þÎñ©¶´
Mongodb Server RoleName::parseFromBSON()´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɽøÐоܾø·þÎñ¹¥»÷¡£
https://jira.mongodb.org/browse/SERVER-49142
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢Áù¸öÔÂÒÔÀ´Î¢ÈíÈÔδÐÞ¸´Windows10ÖÐÒÑ֪©¶´
×Ô2020Äê5Ô£¬MicrosoftÐû²¼ÁËWindows 10 2004Äþ¾²¸üк󣬷ºÆðÁËÁ½¸ö©¶´£¬µ¼ÖÂSSDÇý¶¯Æ÷µÄ´ÅÅÌËéƬÕûÀí¹ýÓÚƵ·±£¬²¢ÔÚ·ÇSSDÇý¶¯Æ÷ÉÏʵÑéTRIM²Ù×÷¡£µÚÒ»¸ö©¶´Ê¹Win10×Ô¶¯Î¬»¤¹¦Ð§ÎÞ·¨¼ÇסÖØÆôϵͳʱÇý¶¯Æ÷µÄ×îºóÓÅ»¯Ê±¼ä£¬µ¼ÖÂÇý¶¯Æ÷ÔÚÿ´ÎÖØÆô¼ÆËã»úʱ¶¼½øÐÐËéƬÕûÀí¡£µÚ¶þ¸ö©¶´µ¼ÖÂWin10µÄÓÅ»¯Çý¶¯Æ÷¹¦Ð§»á¶Ô·ÇSSDÇý¶¯Æ÷½øÐÐTRIM£¬Õâ»áµ¼ÖÂʼþÈÕÖ¾ÖдíÎó¡£Èç½ñ£¬ÔÚ½üÁù¸öÔÂÖ®ºó£¬MicrosoftÈÔδÐÞ¸´¸Ã©¶´¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/windows-10-defrag-trim-bug-still-not-fixed-after-six-months/
2¡¢ºÚ¿Í¹ûÈ»5Íò¸ö´æÔÚ©¶´µÄFortinet VPNÉ豸Áбí
ºÚ¿Í¹ûÈ»5Íò¸ö´æÔÚ©¶´µÄFortinet VPNÉ豸ÁÐ±í£¬ÆäÖаüÂÞÀ´×ÔÊÀ½ç¸÷µØµÄ´óÐÍÒøÐкÍÕþ¸®×éÖ¯¡£ÕâЩÉ豸Öоù´æÔÚ·¾¶±éÀú©¶´£¬±»×·×ÙΪCVE-2018-13379£¬ËüÓ°ÏìÁË´óÁ¿Î´ÐÞ²¹µÄFortinet FortiOS SSL VPNÉ豸¡£¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´£¬´ÓFortinet VPN·ÃÎÊsslvpn_websessionÎļþÀ´ÇÔÈ¡µÇ¼ƾ¾Ý£¬²¢½«ÆäÓÃÓÚÆÆ»µÍøÂç²¢²¿ÊðÀÕË÷Èí¼þ¡£¾¡¹Ü¸Ã©¶´ÔÚÒ»ÄêÇ°¾Í±»¹ûÈ»Åû¶£¬µ«ºÚ¿ÍÈÔ·¢ÏÖ²¢¹ûÈ»ÁËÁË49577¸ö´æÔÚ´ËÀ੶´µÄ´óÐÍÉ豸µÄÁÐ±í¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-posts-exploits-for-over-49-000-vulnerable-fortinet-vpns/
3¡¢VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬ÉÐδÐû²¼²¹¶¡
VMwareÅû¶ÁËÓ°ÏìÆäWorkspace One¶à¸ö×é¼þÖеÄÌáȨ0day£¬¹¥»÷Õß¿ÉÀûÓø鶴ÌáȨÒÔÔÚLinuxºÍWindows²Ù×÷ϵͳÉÏÖ´ÐÐÃüÁĿǰÉÐδÐû²¼Ïà¹Ø²¹¶¡·¨Ê½¡£¸Ã©¶´±»¸ú×ÙΪCVE-2020-4006£¬CVSSÆ·¼¶Îª9.1£¬ÆäÓ°ÏìÁËVMware Workspace ONE Access¡¢·ÃÎÊÁ¬½ÓÆ÷¡¢Éí·Ý¹ÜÀíÆ÷¡¢Éí·Ý¹ÜÀíÆ÷Á¬½ÓÆ÷¡¢VMwareÔÆ»ù½ð»áºÍvRealize SuiteÉúÃüÖÜÆÚ¹ÜÀíÆ÷¡£Ä¿Ç°£¬VMwareÒÑÐû²¼ÁÙʱ½â¾ö´ëÊ©ÒÔÏû³ý¹¥»÷ý½é²¢·Àֹ©¶´µÄÀûÓá£
ÔÎÄÁ´½Ó£º
https://threatpost.com/vmware-zero-day-patch-pending/161523/
4¡¢Ñо¿ÈËÔ±·¢ÏÖWin7ºÍServer2008Öеĵ±µØÌáȨ0day
·¨¹úÑо¿ÈËÔ±·¢ÏÖWindows 7ºÍServer 2008´æÔÚµ±µØÌáȨ£¨LPE£©0day£¬µ±WindowsÄþ¾²¹¤¾ß¸üÐÂʱ»áÓ°ÏìÆä²Ù×÷ϵͳ¡£¸Ã©¶´Î»ÓÚËùÓÐWindows°²×°ÖеÄRPC¶ËµãÓ³ÉäÆ÷ºÍDNSCache·þÎñµÄÁ½¸ö´íÎóÅäÖõÄ×¢²á±íÏîÖУ¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄÕâЩע²á±íÀ´¼¤»îWindowsÐÔÄܼàÊÓ»úÖÆËùʹÓõÄ×ÓÃÜÔ¿¡£Ä¿Ç°0patchƽ̨ÒÑÐû²¼ÁÙʱ΢²¹¶¡£¬²¢ÔÚ΢ÈíÐû²¼Õýʽ²¹¶¡Ç°¶ÔËùÓÐÈËÃâ·ÑÌṩ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/windows-7-and-server-2008-zero-day-bug-gets-a-free-patch/
5¡¢Group-IBÐû²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÔ¤²â·ÖÎö³ÂËß
Group-IBÐû²¼Á˶ÔÀ´ÄêÍøÂçÍþвµÄÔ¤²â·ÖÎö³ÂËߣ¬Ñо¿ÁË2019ÄêÏ°ëÄêÖÁ2020ÄêÉÏ°ëÄêÖ®¼ä¹ú¼ÊÍøÂç·¸×ïÐÐΪµÄÖ÷Òª±ä»¯£¬²¢¶ÔÀ´Äê×ö³öÁËÔ¤²â¡£³ÂËßÖ¸³ö£¬ÀÕË÷Èí¼þ»î¶¯Ôì³ÉÁËÑÏÖصľ¼ÃËðʧ£¬Ë½Óª¹«Ë¾ºÍÕþ¸®»ú¹¹¶¼Î´ÄÜÐÒÃâ¡£ÔÚ´ËÆڼ䣬×ܹ²ÓÐÕë¶ÔÁè¼Ý45¸ö¹ú¼ÒµÄ500¶à´ÎÀÕË÷Èí¼þ¹¥»÷¡£Æ¾¾ÝGroup-IBµÄÊؾÉÔ¤¼Æ£¬ÀÕË÷Èí¼þÍÅ»ïÔì³ÉµÄ×ܲÆÕþËðʧÁè¼Ý10ÒÚÃÀÔª£¨1005186000ÃÀÔª£©¡£ÆäÖУ¬MazeºÍREvilµÄÓ°Ïì×î´ó£¬Õ¼ËùÓй¥»÷µÄ°ëÊýÒÔÉÏ£¬Æä´ÎÊÇRyuk¡¢NetWalkerºÍDoppelPaymer¡£
ÔÎÄÁ´½Ó£º
https://www.group-ib.com/media/gib-report-2020/