ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ42ÖÜ

Ðû²¼Ê±¼ä 2021-10-19

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼Äþ¾²Â©¶´62¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft SharePoint Server CVE-2021-40487Ô¶³Ì´úÂëÖ´ÐЩ¶´£»SAP Environmental Compliance XMLÍⲿʵÌå×¢È멶´£»JP1/IT Desktop Management 2 31016·þÎñ´úÂëÖ´ÐЩ¶´£»Schneider Electric IGSS³¤¶È¼ì²é´úÂëÖ´ÐЩ¶´£»ZOHO ManageEngine ADManager PlusÎļþÉÏ´«´úÂëÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÑо¿ÍŶӷ¢ÏÖSky.com·þÎñÆ÷ÒòÅäÖôíÎóй¶´óÁ¿Êý¾Ý£»AppleÐû²¼½ô¼±¸üÐÂÐÞ¸´iOSºÍiPadOSÖÐÄÚ´æËð»µ0day£»MicrosoftÐû²¼10Ô¸üУ¬ÐÞ¸´4¸ö0dayÔÚÄÚµÄ74¸ö©¶´£»Microsoft³ÆÆäÀֳɵÖÓù¸ß´ï2.4 TbpsµÄDDoS¹¥»÷£»Ñо¿ÍŶӷ¢ÏÖLinux¶ñÒâÍÚ¿óÈí¼þµÄбäÌåÃé×¼»ªÎªÔÆ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. Microsoft SharePoint Server CVE-2021-40487Ô¶³Ì´úÂëÖ´ÐЩ¶´


Microsoft SharePoint Server´æÔÚδÃ÷Äþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-40487



2. SAP Environmental Compliance XMLÍⲿʵÌå×¢È멶´


SAP Environmental Compliance½âÎöXML´æÔÚÍⲿʵÌå×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɻñÈ¡Ãô¸ÐÐÅÏ¢»òʹ·þÎñ·¨Ê½Í߽⡣


https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=587169983



3. JP1/IT Desktop Management 2 31016·þÎñ´úÂëÖ´ÐЩ¶´


JP1/IT Desktop Management 2 31016·þÎñ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.hitachi.com/hirt/security/index.html



4. Schneider Electric IGSS³¤¶È¼ì²é´úÂëÖ´ÐЩ¶´


Schneider Electric IGSS´¦Öñ¨ÎÄ´æÔÚ³¤¶È¼ì²é©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://us-cert.cisa.gov/ics/advisories/icsa-21-285-03



5. ZOHO ManageEngine ADManager PlusÎļþÉÏ´«´úÂëÖ´ÐЩ¶´


ZOHO ManageEngine ADManager Plus /RestAPI/WC/Personalize´æÔÚÈÎÒâÎļþÉÏ´«Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://zh-cn.tenable.com/security/research/tra-2021-43?tns_redirect=true


 >ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Ñо¿ÍŶӷ¢ÏÖSky.com·þÎñÆ÷ÒòÅäÖôíÎóй¶´óÁ¿Êý¾Ý


CyberNewsÑо¿ÍŶÓÔÚ10ÔÂ8ÈÕÅû¶£¬Sky.com·þÎñÆ÷ÒòÅäÖôíÎóй¶´óÁ¿Êý¾Ý¡£SkyÊÇÅ·ÖÞ×î´óµÄýÌ幫˾£¬ÓµÓÐ12%µÄÊг¡·Ý¶î£¬2020ÄêµÄÊÕÈëԼΪ134ÒÚÓ¢°÷¡£Ñо¿ÍŶÓÔÚ10ÔÂ7ÈÕ·¢ÏÖÒ»¸öÍйÜÔÚSky.comµÄ¡°upliftmedia¡±×ÓÓòÉϵÄÓ¦Ó÷¨Ê½µÄÖ÷ÅäÖÃÎļþ£¬ÆäÖаüÂÞÁ˶ÔÍйÜÔÚSky.comÓòÃûÉϵÄÊý¾Ý¿âµÄ·ÃÎÊƾ֤¡£CyberNewsÔÚ10ÔÂ8ÈÕ½«´ËÎÊÌâ³ÂË߸øSky£¬¸Ã¹«Ë¾ÏÖÒѽûÓöÔÅäÖÃÎļþµÄ·ÃÎÊ¡£


Ô­ÎÄÁ´½Ó£º

https://cybernews.com/news/sky-com-servers-exposed-via-misconfiguration/


2¡¢AppleÐû²¼½ô¼±¸üÐÂÐÞ¸´iOSºÍiPadOSÖÐÄÚ´æËð»µ0day


AppleÔÚ10ÔÂ11ÈÕÐû²¼½ô¼±¸üУ¬ÐÞ¸´ÁËiOS 15.0.2ºÍiPadOS 15.0.2ÖеÄÄÚ´æËð»µ0day¡£¸Ã©¶´×·×ÙΪCVE-2021-30883£¬ÊÇIOMobileFrameBufferÖеÄÒ»¸öÄÚ´æËð»µÂ©¶´£¬¿ÉÓÃÀ´ÔÚÄ¿±êÉ豸ִÐÐÃüÁî¡£AppleÔÚÄþ¾²Í¨¸æÖгƸ鶴ÒÑÔÚÕë¶ÔÊÖ»úºÍiPadµÄ¹¥»÷Öб»¹ã·ºÀûÓᣴËÍ⣬ÔÚ©¶´¹ûÈ»²»¾Ã£¬Ñо¿ÈËÔ±Saar Amar¾ÍÐû²¼Á˹ØÓڸ鶴µÄ¼¼ÊõÎÄÕºÍÀûÓ鶴µÄPoC¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/emergency-apple-ios-1502-update-fixes-zero-day-used-in-attacks/


3¡¢MicrosoftÐû²¼10Ô¸üУ¬ÐÞ¸´4¸ö0dayÔÚÄÚµÄ74¸ö©¶´


MicrosoftÔÚ10ÔÂ12ÈÕÐû²¼Á˱¾ÔµÄÖܶþ²¹¶¡£¬×ܼÆÐÞ¸´ÁË74¸ö©¶´£¨°üÂÞMicrosoft EdgeÔÚÄÚÊÇ81¸ö£©¡£´Ë´Î¸üÐÂ×ܹ²ÐÞ¸´ÁË4¸ö0day£¬°üÂÞWin32kÖеÄÌáȨ©¶´CVE-2021-40449£¬Windows DNS·þÎñÆ÷ÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´CVE-2021-40469£¬WindowsÄÚºËÌáȨ©¶´CVE-2021-41335£¬ÒÔ¼°Windows AppContainer ·À»ðǽ¹æÔòÄþ¾²¹¦Ð§Èƹý©¶´CVE-2021-41338¡£´ËÍ⣬KasperskyÑо¿ÈËÔ±ÒѾ­ÔÚÒ°·¢ÏÖÀûÓÃCVE-2021-40449µÄ¹¥»÷»î¶¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-october-2021-patch-tuesday-fixes-4-zero-days-71-flaws/


4¡¢Microsoft³ÆÆäÀֳɵÖÓù¸ß´ï2.4 TbpsµÄDDoS¹¥»÷


MicrosoftÑо¿ÈËÔ±Amir DahanÔÚ10ÔÂ11Èճƣ¬ËûÃÇÔÚ8ÔµÄ×îºóÒ»ÖÜÀֳɵÖÓùÁËÊ·ÉÏ×î¸ßµÄDDoS¹¥»÷¡£Amir DahanÌåÏÖ£¬ÕâÊÇÕë¶ÔÆäÅ·ÖÞAzure¿Í»§µÄ¹¥»÷£¬ÓÉÖ÷ÒªÂþÑÜÔÚÑÇÌ«µØÓòºÍÃÀ¹úµÄÔ¼70000̨É豸ÌᳫµÄ¡£´Ë´ÎµÄ¹¥»÷ÏòÁ¿ÎªUDP·´É䣬Á¬Ðøʱ¼äÁè¼Ý10·ÖÖÓ£¬·¢×÷ʱ¼ä·Ç³£¶Ì£¬Ã¿´Î·¢×÷¶¼ÊÐÔÚ¼¸ÃëÖÓÄÚÉÏÉýµ½TBÁ¿¼¶£¬×ܹ²·ºÆðÁËÁËÈý¸öÖ÷Òª·åÖµ£¬·Ö±ðΪ2.4 Tbps¡¢0.55 TbpsºÍ1.7 Tbps¡£


Ô­ÎÄÁ´½Ó£º

https://azure.microsoft.com/en-us/blog/business-as-usual-for-azure-customers-despite-24-tbps-ddos-attack/


5¡¢Ñо¿ÍŶӷ¢ÏÖLinux¶ñÒâÍÚ¿óÈí¼þµÄбäÌåÃé×¼»ªÎªÔÆ


TrendMicroµÄÑо¿ÈËÔ±·¢ÏÖÒÔÇ°ÓÃÓÚÕë¶ÔDockerÈÝÆ÷µÄLinux¶ñÒâÍÚ¿óÈí¼þµÄбäÌ壬¿ªÊ¼Õë¶ÔÏñ»ªÎªÔÆÕâÑùµÄÐÂÔÆ·þÎñÌṩÉÌ¡£¾ßÌåµØ˵£¬ÐÂÑù±¾ÒѾ­×¢Ê͵ôÁË·À»ðǽ¹æÔò´´½¨¹¦Ð§£¬²¢¼ÌÐøʹÓÃÍøÂçɨÃèÆ÷À´Ñ°ÕÒÆäËû¾ßÓÐapiÏà¹Ø¶Ë¿ÚµÄÖ÷»ú¡£»ªÎªÔÆÊǽÏеÄÔÆÌṩÉÌ£¬Éù³ÆËüÒѾ­ÎªÁè¼Ý300Íò¿Í»§Ìṩ·þÎñ¡£Ñо¿ÈËÔ±Òѽ«´Ë´Î¹¥»÷֪ͨ¸Ã¹«Ë¾£¬µ«ÉÐδÊÕµ½»Ø¸´¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/huawei-cloud-targeted-by-updated-cryptomining-malware/