΢Èí11Ô·ݵÄÖܶþ²¹¶¡µ¼ÖÂODBCÊý¾Ý¿âÏνӴæÔÚBug

°ä²¼¹¦·ò 2022-12-09
1¡¢Î¢Èí11Ô·ݵÄÖܶþ²¹¶¡µ¼ÖÂODBCÊý¾Ý¿âÏνӴæÔÚBug

¾ÝýÌå12ÔÂ7ÈÕ±¨Â· £¬ £¬£¬ £¬£¬£¬Î¢ÈíÔÚÖÂÁ¦½â¾ö2022Äê11ÔÂÖܶþ²¹¶¡µ¼ÖµÄODBCÊý¾Ý¿âÏνÓÎÊÌâ¡£¡£ ¡£¡£¡£¡£×°Öô˸üÐÂºó £¬ £¬£¬ £¬£¬£¬Í¨¹ý΢ÈíODBC SQL ServerÇý¶¯·¨Ê½£¨sqlsrv32.dll£©Ê¹ÓÃODBCÏνÓÀ´½Ó¼ûÊý¾Ý¿âµÄÀûÓÿÉÄÜ»áÎÞ·¨Ïνӡ£¡£ ¡£¡£¡£¡£´Ë±í £¬ £¬£¬ £¬£¬£¬Óû§¿ÉÄÜÔÚÀûÓÃÖÐÊÕµ½Ò»¸öÃýÎó £¬ £¬£¬ £¬£¬£¬»òÕßÔÚSQL·þÎñÆ÷ÊÕµ½Ò»¸öÃýÎ󡣡£ ¡£¡£¡£¡£Î¢Èí°µÊ¾ £¬ £¬£¬ £¬£¬£¬ÆäĿǰÔÚÔì¶©½â¾ö¹æ»® £¬ £¬£¬ £¬£¬£¬ÓйشËÎÊÌâµÄ¸ü¶à¾ßÌåÐÅÏ¢½«ÔÚ½«À´µÄ¸üÐÂÖа䲼¡£¡£ ¡£¡£¡£¡£  

https://www.bleepingcomputer.com/news/microsoft/microsoft-november-updates-break-odbc-database-connections/

2¡¢ÐÂÎ÷À¼¶à¸öµ±¾Ö»ú¹¹µÄMSP Mercury ITÔâµ½ÀÕË÷¹¥»÷

¾ÝýÌå12ÔÂ7ÈÕ³Æ £¬ £¬£¬ £¬£¬£¬ÍйܷþÎñÌṩÉÌ(MSP)Mercury ITÔâµ½¹¥»÷ £¬ £¬£¬ £¬£¬£¬Ó°ÏìÁ˸ùúµÄÊýÊ®¸ö¹«Ë¾ºÍµ±¾Ö»ú¹¹¡£¡£ ¡£¡£¡£¡£Ë¾·¨²¿ºÍÐÂÎ÷À¼ÎÀÉú²¿Ð¹Â©ÓÉÓÚÕâ´Î¹¥»÷ £¬ £¬£¬ £¬£¬£¬ËûÃǵIJ¿ÃÅÎļþÎÞ·¨½Ó¼û¡£¡£ ¡£¡£¡£¡£ÎÀÉú²¿»¹³ÆÏÖ½×¶ÎÕâЩÎļþ²¢Î´Êܵ½Î´¾­ÊÚȨµÄ½Ó¼û»òÏÂÔØ £¬ £¬£¬ £¬£¬£¬ÇÒÎÀÉú·þÎñҲûÓÐÖжϡ£¡£ ¡£¡£¡£¡£·ÇͶ»úÐÔ½¡È«±£ÏÕÌṩÉÌBusinessNZÒ²°ä·¢ÆäÈÕ³£ÔËÓªºÍ¿Í»§·þÎñÊܵ½Ó°Ïì¡£¡£ ¡£¡£¡£¡£Ä¿Ç° £¬ £¬£¬ £¬£¬£¬ÐÂÎ÷À¼Óйز¿ÃÅÔÚ·¢Õ¹´¹Î£¹¤×÷ £¬ £¬£¬ £¬£¬£¬ÒÔÏàʶÊÜÓ°ÏìµÄ×éÖ¯ÊýÁ¿¡¢ËùÉæ¼°ÐÅÏ¢µÄÐÔÖÊÒÔ¼°ÐÅϢй¶ˮƽ¡£¡£ ¡£¡£¡£¡£

https://therecord.media/multiple-government-departments-in-new-zealand-affected-by-ransomware-attack-on-it-provider/

3¡¢Sophos°ä²¼¸üР£¬ £¬£¬ £¬£¬£¬½¨¸´ÆäFirewall 19.5ÖеÄ7¸ö·ì϶

¾Ý12ÔÂ7ÈÕ±¨Â· £¬ £¬£¬ £¬£¬£¬Sophos°ä²¼Á˰²È«¸üÐÂÒÔ½¨¸´ÆäFirewall°æ±¾19.5ÖеÄ7¸ö·ì϶¡£¡£ ¡£¡£¡£¡£ÆäÖÐ £¬ £¬£¬ £¬£¬£¬×îÑϳÁµÄÊÇÓû§ÃÅ»§ºÍWebadminÖеĴúÂë×¢Èë·ì϶£¨CVE-2022-3236£© £¬ £¬£¬ £¬£¬£¬¿ÉÓÃÀ´Ô¶³ÌÖ´ÐдúÂë¡£¡£ ¡£¡£¡£¡£SophosÒѹ۲쵽´Ë·ì϶ÔÚÒ°±í±»ÀûÓõÄÇé¿ö £¬ £¬£¬ £¬£¬£¬ÖØÒªÎ»ÓÚÄÏÑǵØÓò¡£¡£ ¡£¡£¡£¡£Æä´ÎΪºÅÁî×¢Èë·ì϶£¨CVE-2022-3226£©¡¢´úÂë×¢Èë·ì϶£¨CVE-2022-3713£©ÒÔ¼°´úÂë×¢Èë·ì϶£¨CVE-2022-3696£©µÈ¡£¡£ ¡£¡£¡£¡£

https://securityaffairs.co/wordpress/139362/security/sophos-firewall-critical-flaw.html

4¡¢APT 37ÀûÓÃIEÖеÄÁãÈÕ·ì϶CVE-2022-41128¹¥»÷º«¹ú

GoogleÓÚ12ÔÂ7ÈÕÅû¶Á˳¯ÏÊÍÅ»ïAPT 37Õë¶Ôº«¹úµÄ¹¥»÷»î¶¯¡£¡£ ¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈÒÔÊ×¶ûÀæÌ©Ôº±äÂÒΪµö¶ü £¬ £¬£¬ £¬£¬£¬·Ö·¢Ô̺¬¶ñÒâÈí¼þµÄMicrosoft OfficeÎĵµ £¬ £¬£¬ £¬£¬£¬¸ÃÎĵµ»áÏÂÔØÒ»¸ö¸»Îı¾Îļþ(RTF)Ô¶³ÌÄ£°å £¬ £¬£¬ £¬£¬£¬¶øºó»ñȡԶ³ÌHTMLÄÚÈÝ¡£¡£ ¡£¡£¡£¡£¼ÓÔØÔ¶³ÌHTMLÄÚÈÝÔÊÐí¹¥»÷ÕßÀûÓÃIEÁãÈÕ·ì϶£¨CVE-2022-41128£© £¬ £¬£¬ £¬£¬£¬¼´±ãÖ¸±êûÓн«Æä×÷ΪĬÈÏä¯ÀÀÆ÷¡£¡£ ¡£¡£¡£¡£ÕâÊÇIEµÄJavaScriptÒýÇæµÄÒ»¸ö·ì϶ £¬ £¬£¬ £¬£¬£¬³É¹¦ÀûÓÃËüµÄ¹¥»÷ÕßÔÚ³öÏÖ¶ñÒâÍøÕ¾Ê±¿ÉÖ´ÐÐËÁÒâ´úÂë £¬ £¬£¬ £¬£¬£¬ÒÑÓÚ11ÔÂ8ÈÕÔÚ΢Èí°ä²¼µÄÖܶþ²¹¶¡Öн¨¸´¡£¡£ ¡£¡£¡£¡£

https://blog.google/threat-analysis-group/internet-explorer-0-day-exploited-by-north-korean-actor-apt37/

5¡¢ÔÚÏßÁãÊÛÆ½Ì¨Vevor·þÎñÆ÷ÅäÖÃÃýÎóй¶³¬¹ý1Òڱʼͼ

ýÌå12ÔÂ8ÈÕй© £¬ £¬£¬ £¬£¬£¬×êÑÐÍŶӷ¢ÏÖÁËÒ»¸öÎÞÃÜÂë±£»£»£»£»£»¤µÄÊý¾Ý¿â £¬ £¬£¬ £¬£¬£¬ÆäÖÐÊý¾Ý¼¯×Ü´óÓ×Ϊ601.84 GB £¬ £¬£¬ £¬£¬£¬Îĵµ×ÜÊý³¬¹ý1.16ÒÚ¡£¡£ ¡£¡£¡£¡£¾­µ÷²é £¬ £¬£¬ £¬£¬£¬ÕâЩÊý¾ÝÊôÓÚ¼ÓÀû¸£ÄáÑǵÄÔÚÏßÁãÊÛÉÌVevor £¬ £¬£¬ £¬£¬£¬Ò»¸öרһÓÚÉ豸ºÍ¹¤¾ßµÄÆ·ÅÆ¡£¡£ ¡£¡£¡£¡£¸Ã·þÎñÆ÷ÊÇÔÚ2022Äê4Ô³õ´Î±»·¢ÏÖ £¬ £¬£¬ £¬£¬£¬¶øºó×êÑÐÈËÔ±ÔÚ2022Äê7ÔÂÔٴη¢ÏÖ²»°²È«µÄAWS·þÎñÆ÷ £¬ £¬£¬ £¬£¬£¬±»ÍйÜÔÚ·ÖÆçµÄIPµØÖ·ÉÏ¡£¡£ ¡£¡£¡£¡£2022Äê4ÔµÄÊÂÎñй¶ÁË406.79 GBÊý¾Ý £¬ £¬£¬ £¬£¬£¬Ô̺¬706206770¸öÎļþ£»£»£»£»£»2022Äê7ÔÂй¶ÁË601.84 GBÊý¾Ý £¬ £¬£¬ £¬£¬£¬1166293742¸öÎĵµ¡£¡£ ¡£¡£¡£¡£¾ÝϤ £¬ £¬£¬ £¬£¬£¬ÕâÊÇÓÉÓÚ·þÎñÆ÷ËùÓÐÕßÅäÖÃÃýÎóµ¼Öµġ£¡£ ¡£¡£¡£¡£

https://www.websiteplanet.com/blog/vevor-breach-report/

6¡¢ESET·¢ÏÖÒÁÀÊAgriusʹÓÃÐÂFantasyµÄ¹©¸øÁ´¹¥»÷»î¶¯¡£¡£ ¡£¡£¡£¡£

12ÔÂ7ÈÕ £¬ £¬£¬ £¬£¬£¬ESET³ÆÆä·¢ÏÖÁËÒÁÀÊAgriusµÄ¹©¸øÁ´¹¥»÷»î¶¯¡£¡£ ¡£¡£¡£¡£¸Ã»î¶¯ÓÚ½ñÄê2ÔÂÆðÍ· £¬ £¬£¬ £¬£¬£¬ÓÚ3ÔÂÈ«Ãæ·¢Õ¹ £¬ £¬£¬ £¬£¬£¬ÒÑÈëÇÖÒ»¼ÒITÖ§³Ö·þÎñ¹«Ë¾¡¢Ò»¼Ò×êʯÅú·¢ÉÌ¡¢Ò»¼ÒÖ鱦É̺ÍÒ»¼ÒÈËÁ¦×ÊÔ´Õ÷ѯ¹«Ë¾¡£¡£ ¡£¡£¡£¡£¸Ã»î¶¯ÀûÓÃÁËÒ»¸öеÄFantasy Wiper £¬ £¬£¬ £¬£¬£¬ËüµÄ´ó²¿ÃÅ´úÂë¿âÀ´×ÔAgriusÔÚ֮ǰµÄ¹¥»÷ÖÐʹÓõÄApostle Wiper¡£¡£ ¡£¡£¡£¡£Fantasy»áÓÃËæ»úÊý¾Ý¸²¸Çÿ¸öÎļþµÄÄÚÈÝ £¬ £¬£¬ £¬£¬£¬½«¹¦·ò´ÁÉèÖÃΪ2037ÄêÎçÒ¹²¢É¾³ý £¬ £¬£¬ £¬£¬£¬´Ë¾ÙÊÇΪÁËÔ¤·ÀÎļþ±»Êý¾Ý¸´Ô­¹¤¾ß¸´Ô­¡£¡£ ¡£¡£¡£¡£³ýÁËFantasy £¬ £¬£¬ £¬£¬£¬Agrius»¹·Ö·¢ÁËÒ»ÖÖеÄÓÃÓÚºáÏòÒÆ¶¯ºÍÖ´ÐÐFantasyµÄ¹¤¾ßSandals¡£¡£ ¡£¡£¡£¡£

https://www.welivesecurity.com/2022/12/07/fantasy-new-agrius-wiper-supply-chain-attack/