ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ9ÖÜ

Ðû²¼Ê±¼ä 2021-03-01

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê02ÔÂ22ÈÕÖÁ02ÔÂ28ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´53¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇNETGEAR Nighthawk R7800Ó²±àÂëÑéÖ¤Èƹý©¶´£»Siemens SINEC NMS FirmwareFileUtils extractToFolderĿ¼±éÀú´úÂëÖ´ÐЩ¶´£»TP-Link AC1750 sync-serverÕ»Òç³öÔ¶³Ì´úÂëÖ´ÐЩ¶´£»On Netshield NANO CVE-2021-3149ÃüÁî×¢È멶´£»Adobe Bridge CVE-2021-21065Ô½½çд´úÂëÖ´ÐЩ¶´ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ΢Èí·¢ÏÖWindows Win32kÌáȨ0dayÒѱ»ÔÚÒ°ÀûÓã»Ð¶ñÒâÈí¼þSilver SparrowÒÑѬȾ½ü3Íǫ̀MacÉ豸£»FireEye³ÆÕë¶ÔAccellion FTAµÄ¹¥»÷ÓëFIN11ÓйØ£»·É»úÖÆÔìÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹûÈ»£»·ÒÀ¼TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬¿Í»§·þÎñÔÝʱÖжÏ ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£


> ÖØÒªÄþ¾²Â©¶´Áбí


1.NETGEAR Nighthawk R7800Ó²±àÂëÑéÖ¤Èƹý©¶´


NETGEAR Nighthawk R7800 apply_save.cgiʹÓÃÓ²±àÂ멶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔROOTȨÏÞÖ´ÐÐÈÎÒâ´úÂë ¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-252/


2.Siemens SINEC NMS FirmwareFileUtils extractToFolderĿ¼±éÀú´úÂëÖ´ÐЩ¶´


Siemens SINEC NMS FirmwareFileUtils extractToFolder´æÔÚĿ¼±éÀú©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔWEBÓ¦Ó÷¨Ê½ÉÏÏÂÎĶÁÈ¡Ãô¸ÐÐÅÏ¢ ¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-253/


3.TP-Link AC1750 sync-serverÕ»Òç³öÔ¶³Ì´úÂëÖ´ÐЩ¶´


TP-Link AC1750 sync-server MACµØÖ·´¦ÖôæÔÚÕ»Òç³ö©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔROOTȨÏÞÖ´ÐÐÈÎÒâ´úÂë ¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-215/


4.On Netshield NANO CVE-2021-3149ÃüÁî×¢È멶´


On Netshield NANO /usr/local/webmin/System/manual_ping.cgi´æÔÚÊäÈëÑé֤©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔWEBÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://www.digitaldefense.com/resources/vulnerability-research/netshield-corporation-nano-25/


5.Adobe Bridge CVE-2021-21065Ô½½çд´úÂëÖ´ÐЩ¶´


Adobe Bridge´¦ÖÃÎļþ´æÔÚÔ½½ç䩶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»ò¿ÉÖ´ÐÐÈÎÒâ´úÂë ¡£

https://helpx.adobe.com/security/products/bridge/apsb21-07.html


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Î¢Èí·¢ÏÖWindows Win32kÌáȨ0dayÒѱ»ÔÚÒ°ÀûÓÃ


1.jpg


΢Èí·¢ÏÖWindows Win32kÖеÄÌáȨ0day£¨CVE-2021-1732£©Òѱ»ÔÚÒ°ÀûÓà ¡£¸Ã©¶´´æÔÚÓÚwin32k.sysºËÐÄÄÚºË×é¼þÖÐ £¬¹¥»÷Õß¿Éͨ¹ý´¥·¢ÊͷźóʹÓ鶴½«ÆäȨÏÞÌáÉýµ½admin¼¶±ð £¬¾ßÓлù±¾Óû§È¨Ï޵Ĺ¥»÷Õß²»ÐèÒªÓëÓû§½»»¥¼´¿ÉÀûÓø鶴 ¡£¾ÝÊÓ²ì £¬¸Ã©¶´Òѱ»APT×éÖ¯BitterºÍT-APT-17ÀûÓà £¬DBAPPSecurityÔò³ÆÆäÓÚ12Ô·¢ÏÖÁË¿ª·¢ÈÕÆÚΪ2020Äê5ÔµÄÑù±¾ ¡£¶ø×Ô2021Äê2Ô¿ªÊ¼ £¬ºÚ¿ÍÖ»ÔÚÉÙÊýÕë¶ÔÖж«µÄ¹¥»÷ÖÐʹÓÃÁËCVE-2021-1732©¶´ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/recently-fixed-windows-zero-day-actively-exploited-since-mid-2020/


2¡¢Ð¶ñÒâÈí¼þSilver SparrowÒÑѬȾ½ü3Íǫ̀MacÉ豸


2.jpg


Red CanaryÑо¿ÈËÔ±·¢ÏÖÕë¶ÔMacÉ豸µÄжñÒâÈí¼þSilver Sparrow ¡£½ØÖÁ2ÔÂ17ÈÕ £¬Silver SparrowÒÑÔÚ153¸ö¹ú¼ÒºÍµØÓòѬȾÁË29139¸ömacOSÖÕ¶Ë £¬²¢ÔÚÃÀ¹ú¡¢Ó¢¹ú¡¢¼ÓÄô󡢷¨¹úºÍµÂ¹ú´óÁ¿Á÷´« ¡£Óë´ó¶àÊýʹÓÃ'preinstall'ºÍ'postinstall'½Å±¾µÄ¶ñÒâÈí¼þ²îÒì £¬Silver SparrowÀûÓÃJavaScriptÖ´ÐÐÃüÁî £¬´Ó¶øºÜÄÑƾ¾ÝÃüÁîÐвÎÊý¼ì²â¶ñÒâ»î¶¯ ¡£´ËÍâ £¬¸Ã¶ñÒâÈí¼þµÄÕæÕýÄ¿µÄÏÖÔÚÈÔÈ»ÊǸöÃÕ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/30000-macs-infected-with-new-silver-sparrow-malware/


3¡¢FireEye³ÆÕë¶ÔAccellion FTAµÄ¹¥»÷ÓëFIN11ÓйØ


3.jpg


Äþ¾²¹«Ë¾FireEye³Æ £¬2020Äê12Ôµ½2021Äê1ÔÂÖ®¼äÀûÓÃAccellion FTA·þÎñÆ÷ÖÐ0dayµÄ¹¥»÷»î¶¯ÓëFIN11ÓÐ¹Ø £¬²¨¼°ÁËÈ«ÇòÔ¼100¼Ò¹«Ë¾ ¡£ºÚ¿ÍÖ÷ÒªÀûÓÃÁËËĸö©¶´À´¹¥»÷FTA·þÎñÆ÷ £¬²¢°²×°ÁËÒ»¸öÃûΪDEWMODEµÄWeb Shell £¬À´ÏÂÔØÊܺ¦ÕßFTAÉ豸ÉÏ´æ´¢µÄÎļþ ¡£ÊÜÓ°ÏìµÄ¹«Ë¾ºÍ×éÖ¯°üÂÞFugro¡¢Danaher¡¢Singtel¡¢Jones¡¢ÐÂÎ÷À¼´¢ÐîÒøÐкͰĴóÀûÑÇ֤ȯºÍͶ×ÊίԱ»á£¨ASIC£©µÈ ¡£´ËÍâ £¬ºÚ¿ÍÔÚClopµÄÊý¾Ýй¶ÍøÕ¾ÉÏÁгöÁ˲¿ÃŹ«Ë¾ £¬ÒÔÇÃÕ©ÀÕË÷ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/attacks-targeting-accellion-product-linked-fin11-cybercrime-group


4¡¢·É»úÖÆÔìÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹûÈ»


4.jpg


¼ÓÄôó·É»úÖÆÔìÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹûÈ» ¡£¸Ã¹«Ë¾ÔÚͨ¸æÖÐÌåÏÖ £¬¾­³õ·¨Ê½²é £¬ºÚ¿ÍÀûÓÃÁ˵ÚÈý·½Îļþ´«ÊäÓ¦ÓÃÖеÄ©¶´À´·ÃÎʺÍÇÔÈ¡Êý¾Ý ¡£¾¡¹Ü²¢Ã»ÓоßÌåÖ¸³ö¸ÃÉ豸µÄÃû³Æ £¬µ«¾ÝÍƲâºÜ¿ÉÄÜÊÇÖ¸µÄAccellion FTA ¡£±»µÁÊý¾ÝÒÑÔÚÀÕË÷ÍÅ»ïClopµÄÊý¾Ýй¶ÍøÕ¾¹ûÈ» £¬°üÂÞBombardierÖÖÖÖ·É»úºÍ·É»úÁã¼þµÄÉè¼ÆÎļþ £¬²¢Ã»ÓÐÈκθöÈËÊý¾Ýй¶ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/airplane-maker-bombardier-data-posted-on-ransomware-leak-site-following-fta-hack/


5¡¢·ÒÀ¼TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬¿Í»§·þÎñÔÝʱÖжÏ


5.jpg


·ÒÀ¼IT·þÎñ¹«Ë¾TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬¿Í»§·þÎñÔÝʱÖжÏ ¡£TietoEVRYÊÇÒ»¼ÒÈí¼þ¿ª·¢ºÍIT·þÎñ¹«Ë¾ £¬ÔÚ80¸ö¹ú¼ÒºÍµØÓòÓµÓÐ24000ÃûÔ±¹¤ £¬2019ÄêµÄÊÕÈëΪ29.5ÒÚÅ·Ôª ¡£±¾ÖÜÒ» £¬TietoEVRYµÄÁãÊÛ¡¢ÖÆÔìºÍ·þÎñÏà¹ØÐÐÒµµÄ25¸ö¿Í»§ÌåÏÖÆäÓöµ½Á˼¼ÊõÎÊÌâ £¬ºóÀ´µÃÖªÕâЩÎÊÌâÊÇÓÉÀÕË÷Èí¼þ¹¥»÷ÒýÆðµÄ ¡£TietoEVRY·¢ÏÖ¹¥»÷ºóÁ¢¼´¹Ø±ÕÁËÊÜÓ°ÏìµÄϵͳºÍ·þÎñ £¬²¢ÓëµØ·½Õþ¸®¶Ô´ËÊÂÕ¹¿ªÊÓ²ì ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/finnish-it-services-giant-tietoevry-discloses-ransomware-attack/