Windows Server ¸üе¼ÖÂÓò½ÚÔìÆ÷±ÀÀ£²¢³ÁÐÂÆô¶¯

°ä²¼¹¦·ò 2024-03-22

1. Windows Server ¸üе¼ÖÂÓò½ÚÔìÆ÷±ÀÀ£²¢³ÁÐÂÆô¶¯


3ÔÂ21ÈÕ£¬ £¬£¬£¬£¬ £¬£¬£¬ÓÉÓÚ Windows Server 2016 ºÍ Windows Server 2022 µÄ 2024 Äê 3 ÔÂÀÛ»ý¸üÐÂÖÐÒýÈëÁ˱¾µØ°²È«»ú¹¹×Óϵͳ·þÎñ (LSASS) £¬ £¬£¬£¬£¬ £¬£¬£¬ÊÜÓ°ÏìµÄ·þÎñÆ÷ÔÚ¶³½á²¢³ÁÐÂÆô¶¯¡£¡£¡£¡£¡£LSASS ÊÇÒ»Ïî Windows ·þÎñ£¬ £¬£¬£¬£¬ £¬£¬£¬ÓÃÓÚÖ´Ðа²È«Õ½Êõ²¢´¦ÖÃÓû§µÇ¼¡¢½Ó¼ûÁîÅÆ´´½¨ºÍÃÜÂë¸ü¸Ä¡£¡£¡£¡£¡£ÕýÈçºÜ¶àÖÎÀíÔ±ÖÒ¸æµÄÄÇÑù£¬ £¬£¬£¬£¬ £¬£¬£¬ÔÚ×°ÖÃÖܶþ°ä²¼µÄ KB5035855 ºÍ KB5035857 Windows Server ¸üкó£¬ £¬£¬£¬£¬ £¬£¬£¬ÓµÓÐ×îиüеÄÓò½ÚÔìÆ÷½«ÓÉÓÚ LSASS ÄÚ´æÊ¹ÓÃÁ¿Ôö³¤¶ø±ÀÀ£²¢³ÁÐÂÆô¶¯¡£¡£¡£¡£¡£ÔÚ Microsoft ÕýʽÈϿɴËÄÚ´æÐ¹Â¶ÎÊÌâ֮ǰ£¬ £¬£¬£¬£¬ £¬£¬£¬½¨ÒéÖÎÀíÔ±´ÓÆäÓò½ÚÔìÆ÷Ð¶ÔØÓÐÎÊÌâµÄ Windows Server ¸üС£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/new-windows-server-updates-cause-domain-controller-crashes-reboots/


2. ³¯ÏÊ Kimsuky ÍøÂç·¸×ïÍÅ»ïÒÑÆðͷʹÓÃÐÂÕ½Êõ·¢Õ¹»î¶¯


3ÔÂ21ÈÕ£¬ £¬£¬£¬£¬ £¬£¬£¬¾ÝÐÅÏ¢°²È«¹©¸øÉÌ Rapid7 ³Æ£¬ £¬£¬£¬£¬ £¬£¬£¬³¯ÏʳôÃûÔ¶ÑïµÄ Kimsuky ÍøÂç·¸×ïÍÅ»ïÒÑÆðͷʹÓÃÐÂÕ½Êõ·¢Õ¹»î¶¯¡£¡£¡£¡£¡£¸ÃÍÅ»ïÒ²±»³ÆÎª Black Banshee¡¢Thallium¡¢APT 43 ºÍ Velvet Chollima¡ª¡ª³Ö¾ÃÒÔÀ´Ò»ÏòÊÔͼ´Óµ±¾Ö»ú¹¹ºÍÖÇ¿âµÈ»ú¹¹»ñÊØÐÅÏ¢£¬ £¬£¬£¬£¬ £¬£¬£¬Rapid7 ²»È·¶¨¸ÃÍÅ»ïÈôºÎ·Ö·¢Æä×îй¥»÷£¬ £¬£¬£¬£¬ £¬£¬£¬µ«È·ÐÅÓÐЧ¸ºÔØÔ̺¬Óж¾µÄ Microsoft ±àÒë HTML Ô®ÊÖ (CHM) ÎļþÒÔ¼° ISO¡¢VHD¡¢ZIP ºÍ RAR Îļþ¡£¡£¡£¡£¡£CHM ÎļþÄܹ»Ô̺¬Îı¾¡¢Í¼ÏñºÍ³¬Á´½Ó¡£¡£¡£¡£¡£Kimsuky ¿ÉÄܶÔËüÃǸü¸ÐÐËÖ£¬ £¬£¬£¬£¬ £¬£¬£¬ÓÉÓÚËüÃÇÄܹ»Ö´ÐÐ JavaScript¡£¡£¡£¡£¡£Rapid7 µÄ×êÑÐÈËÔ±ÆÆ½âÁËÆäÖÐÒ»¸ö CHM Îļþ£¬ £¬£¬£¬£¬ £¬£¬£¬ËûÃÇÒÔΪÕâÊÇ Kimsuky µÄÎÄÕ£¬ £¬£¬£¬£¬ £¬£¬£¬²¢·¢ÏÖÁË¡°Ò»¸öʹÓà HTML ºÍ ActiveX ÔÚ Windows ÍÆËã»úÉÏÖ´ÐÐËÁÒâºÅÁîµÄʾÀý£¬ £¬£¬£¬£¬ £¬£¬£¬Í¨³£ÓÃÓÚ¶ñÒâÖ÷ÕÅ¡±¡£¡£¡£¡£¡£


https://www.theregister.com/2024/03/21/kimsuky_chm_file_campaign/


3. ÍþвÐÐΪÕßÀûÓà JETBRAINS TEAMCITY ·ì϶´«²¼¶ñÒâÈí¼þ


3ÔÂ20ÈÕ£¬ £¬£¬£¬£¬ £¬£¬£¬Ç÷Ïò¿Æ¼¼×êÑÐÈËÔ±·¢ÏÖÀûÓà JetBrains TeamCity ÖÐ×î½üÅû¶µÄ·ì϶CVE-2024-27198  £¨CVSS ÆÀ·Ö£º9.8£©ºÍCVE-2024-27199£¨CVSS ÆÀ·Ö 7.3£©°²È«·ì϶À´²¿Êð¶à¸ö¶ñÒâÈí¼þµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£CVE-2024-27198 ÊÇ TeamCity Web ×é¼þÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¬ £¬£¬£¬£¬ £¬£¬£¬ÓÉ´úÌæõè¾¶ÎÊÌâ ( CWE-288 ) ÒýÆð£¬ £¬£¬£¬£¬ £¬£¬£¬CVSS ¸ù»ùÆÀ·ÖΪ 9.8£¨ÑϳÁ£©¡£¡£¡£¡£¡£CVE-2024-27199ÊÇ TeamCity Web ×é¼þÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¬ £¬£¬£¬£¬ £¬£¬£¬ÓÉõè¾¶±éÀúÎÊÌâ ( CWE-22 ) ÒýÆð£¬ £¬£¬£¬£¬ £¬£¬£¬CVSS ¸ù»ùÆÀ·ÖΪ 7.3£¨¸ß£©¡£¡£¡£¡£¡£ÕâЩ·ì϶¿ÉÄÜʹδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÄÜͨ¹ý HTTP(S) ½Ó¼û TeamCity ·þÎñÆ÷À´ÈƹýÉí·ÝÑéÖ¤²é³­²¢»ñµÃ¶Ô¸Ã TeamCity ·þÎñÆ÷µÄÖÎÀí½ÚÔì¡£¡£¡£¡£¡£


https://securityaffairs.com/160823/breaking-news/jetbrains-teamcity-flaws-actively-exploited.html


4. еÄÑ­»· DoS ¹¥»÷¿ÉÄÜ»áÓ°Ïì¶à´ï 30Íò¸öϵͳ


3ÔÂ20ÈÕ£¬ £¬£¬£¬£¬ £¬£¬£¬Ò»ÖÖÃûΪ¡°Ñ­»· DoS¡±µÄлؾø·þÎñ¹¥»÷Õë¶ÔÀûÓòãºÍ̸£¬ £¬£¬£¬£¬ £¬£¬£¬Äܹ»½«ÍøÂç·þÎñÅä¶Ôµ½ÎÞÏÞͨѶѭ»·ÖУ¬ £¬£¬£¬£¬ £¬£¬£¬´Ó¶ø²úÉú´óÁ¿Á÷Á¿¡£¡£¡£¡£¡£¸Ã¹¥»÷ÓÉCISPA º¥Ä·»ô×ÈÐÅÏ¢°²È«ÖÐÐĵÄ×êÑÐÈËÔ±Éè¼Æ£¬ £¬£¬£¬£¬ £¬£¬£¬Ê¹ÓÃÓû§Êý¾Ý±¨ºÍ̸ (UDP)£¬ £¬£¬£¬£¬ £¬£¬£¬Ó°Ïì¹À¼Æ 300,000 ̨Ö÷»ú¼°ÆäÍøÂç¡£¡£¡£¡£¡£Õâ´Î¹¥»÷¿ÉÄÜÊÇÓÉÓÚ UDP ºÍ̸ʵÏÖÖеÄÒ»¸ö·ì϶£¨Ä¿Ç°¸ú×ÙΪCVE-2024-2169 £©Ôì³ÉµÄ£¬ £¬£¬£¬£¬ £¬£¬£¬¸Ã·ì϶ÈÝÒ×Êܵ½ IP ºýŪ£¬ £¬£¬£¬£¬ £¬£¬£¬²¢ÇÒ²»Ìṩ×ã¹»µÄÊý¾Ý°üÑéÖ¤¡£¡£¡£¡£¡£ÀûÓø÷ì϶µÄ¹¥»÷Õ߻ᴴ½¨Ò»ÖÖ×ÔÎÒÒ»Á¬µÄ»úÔ죬 £¬£¬£¬£¬ £¬£¬£¬¸Ã»úÔì»áÎÞÏ޶ȵزúÉú¹ý¶àµÄÁ÷Á¿£¬ £¬£¬£¬£¬ £¬£¬£¬²¢ÇÒÎÞ·¨×èÖ¹Ëü£¬ £¬£¬£¬£¬ £¬£¬£¬´Ó¶øµ¼ÖÂÖ¸±êϵͳÉõÖÁÕû¸öÍøÂç³öÏֻؾø·þÎñ (DoS) Çé¿ö¡£¡£¡£¡£¡£Ñ­»· DoS ÒÀÀµÓÚ IP ºýŪ£¬ £¬£¬£¬£¬ £¬£¬£¬²¢ÇÒÄܹ»´Ó·¢ËÍÒ»ÌõÐÂÎÅÒÔÆô¶¯Í¨Ñ¶µÄµ¥¸öÖ÷»ú´¥·¢¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-loop-dos-attack-may-impact-up-to-300-000-online-systems/


5. ÒÁÀʺڿÍÐû³ÆÒÑÈëÇÖÒÔÉ«ÁеĺËÉèÊ©


3ÔÂ21ÈÕ£¬ £¬£¬£¬£¬ £¬£¬£¬ Ò»¸öÓëÒÁÀÊÓйصĺڿÍ×éÖ¯Ðû³ÆÔÚ¡°ÄäÃû¡±ºÚ¿Í°ä·¢µÄһ·ÊÂÎñÖзÛËéÁËÒÔÉ«ÁÐÃô¸ÐºËÉèÊ©µÄÍÆËã»úÍøÂ磬 £¬£¬£¬£¬ £¬£¬£¬ÒÔ¿¹Òé¼ÓɳսÕù¡£¡£¡£¡£¡£ºÚ¿ÍÐû³Æ´ÓÎ÷ÃÉ¡¤ÅåÀ×˹¡¤ÄڸǷòºË×êÑÐÖÐÐÄÇÔÈ¡²¢°ä²¼ÁËÊýǧ·ÝÎļþ£¬ £¬£¬£¬£¬ £¬£¬£¬Ô̺¬ PDF¡¢µç×ÓÓʼþºÍ PowerPoint »ÃµÆÆ¬¡£¡£¡£¡£¡£Õâ¸ö°ÂÃØÉèÊ©ÄÚÓÐÒ»¸öÓëÒÔÉ«ÁÐδ¹«¿ªµÄºË±øÆ÷´òËãÓйصĺ˷´Ó³¶Ñ£¬ £¬£¬£¬£¬ £¬£¬£¬º¹ÇàÉÏÒ»ÏòÊǹþÂí˹»ð¼ýµÄÖ¸±ê¡£¡£¡£¡£¡£¸Ã×éÖ¯ÔÚÉ罻ýÌåÐÂÎÅÖÐÚ¹ÊÏçËËûÃǵÄÒâͼ£¬ £¬£¬£¬£¬ £¬£¬£¬Ðû³Æ¡°ÎÒÃDz»ÏñÊÈѪµÄÄÚËþÄáÑǺúºÍËûµÄ¿Ö²À¾ü¶ÓÄÇÑù£¬ £¬£¬£¬£¬ £¬£¬£¬ÎÒÃÇÒÔûÓв¼ÒÂÊܵ½ÖÐÉ˵ķ½Ê½½øÐÐÕâ´ÎÐж¯¡£¡£¡£¡£¡£¡± Ö»¹ÜÓÐÕâÒ»ÉêÃ÷£¬ £¬£¬£¬£¬ £¬£¬£¬¸Ã×éÖ¯ÔÚÁíÒ»ÌõÉ罻ýÌåÐÂÎÅÖаµÊ¾£¬ £¬£¬£¬£¬ £¬£¬£¬Ëü¡°ÎÞÒâ½øÐк˱¬Õ¨£¬ £¬£¬£¬£¬ £¬£¬£¬µ«Õâ´ÎÐж¯ºÜΣÏÕ£¬ £¬£¬£¬£¬ £¬£¬£¬ÈκÎʼþ¶¼¿ÉÄܲúÉú¡±£¬ £¬£¬£¬£¬ £¬£¬£¬Í¬Ê±»¹°ä²¼ÁËÒ»¶ÎÃèÊöºË±¬Õ¨ºÍºôÓõ³·ÀëÈËÔ±µÄ¶¯»­ÊÓÆµ¡£¡£¡£¡£¡£


https://news.hitb.org/content/iranian-hackers-claim-have-breached-israeli-nuclear-facility


6. ×êÑÐÈËÔ±³Æ AceCryptor ¶ñÒâÈí¼þÔÚÅ·ÖÞ¼¤Ôö


3ÔÂ21ÈÕ£¬ £¬£¬£¬£¬ £¬£¬£¬×÷ΪÕë¶ÔÅ·ÖÞ¸÷µØ×éÖ¯µÄ»î¶¯µÄÒ»²¿ÃÅ£¬ £¬£¬£¬£¬ £¬£¬£¬ÒѾ­·¢ÏÖÁËÉæ¼° AceCryptor ¹¤¾ßµÄÊýǧ¸öÐÂϰȾ£¬ £¬£¬£¬£¬ £¬£¬£¬ºÚ¿Í»ìºÏ¶ñÒâÈí¼þ²¢½«ÆäÖ²Èëϵͳ¶ø²»±»·À²¡¶¾Èí¼þ¼ì²âµ½¡£¡£¡£¡£¡£ESET µÄ×êÑÐÈËÔ±»¨ÁËÊýÄ깦·ò¸ú×Ù AceCryptor£¬ £¬£¬£¬£¬ £¬£¬£¬ËûÃÇÖÜÈý°µÊ¾£¬ £¬£¬£¬£¬ £¬£¬£¬×î½üµÄ¹¥»÷»î¶¯Óë֮ǰµÄµü´ú·ÖÆç£¬ £¬£¬£¬£¬ £¬£¬£¬ÓÉÓÚ¹¥»÷ÕßÀ©´óÁËÄÚ²¿´ò°üµÄ¶ñÒâ´úÂëÀàÐÍ¡£¡£¡£¡£¡£AceCryptor ͨ³£ÓëÃûΪ Remcos»ò Rescoms µÄ¶ñÒâÈí¼þһ·ʹÓ㬠£¬£¬£¬£¬ £¬£¬£¬ÕâÊÇÒ»ÖÖ׳´óµÄÔ¶³Ì¼à¶½¹¤¾ß£¬ £¬£¬£¬£¬ £¬£¬£¬×êÑÐÈËÔ±ÒÑ·¢Ïָù¤¾ßÂÅ´ÎÓÃÓÚÕë¶ÔÎÚ¿ËÀ¼µÄ×éÖ¯¡£¡£¡£¡£¡£³ýÁË Remcos ºÍÁíÒ»¸öÊìϤµÄ¹¤¾ß SmokeLoader Ö®±í£¬ £¬£¬£¬£¬ £¬£¬£¬ESET °µÊ¾£¬ £¬£¬£¬£¬ £¬£¬£¬´Ë¿Ì»¹·¢ÏÖ AceCryptor ·Ö·¢ STOP ÀÕË÷Èí¼þºÍ Vidar ÇÔÈ¡·¨Ê½µÈ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£ESET ƾ¾ÝÖ¸±ê¹ú¶È/µØÓò·¢ÏÖÁËһЩ²î¾à¡£¡£¡£¡£¡£ÎÚ¿ËÀ¼µÄ¹¥»÷ʹÓÃÁËSmokeLoader£¬ £¬£¬£¬£¬ £¬£¬£¬¶ø²¨À¼¡¢Ë¹Âå·¥¿Ë¡¢±£¼ÓÀûÑǺÍÈû¶ûάÑǵĹ¥»÷ÔòʹÓÃÁËRemcos¡£¡£¡£¡£¡£ 


https://therecord.media/acecryptor-malware-surge-europe-remcos