¡¾·ì϶¹«¸æ¡¿Trend Micro Apex One 7Ô¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-07-30

0x00 ·ì϶¸ÅÊö

Apex OneÊÇTrend Micro¿ª·¢µÄÒ»Ì׿ÉÄÜÌṩ×Ô¶¯Íþв¼ì²âºÍÏìÓ¦Ö°ÄܵĶ˵㰲ȫ·À»¤Èí¼þ ¡£¡£¡£¡£¡£

2021Äê7ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬Trend Micro£¨Ç÷Ïò¿Æ¼¼£©°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬¹«¿ªÁËÆäApex One ºÍApex One as a Service£¨Apex One SaaS£©ÖеĶà¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓÃÕâЩ·ìÏ¶ÈÆ¹ýÉí·ÝÈÏÖ¤¡¢ÉÏ´«ËÁÒâÎļþ¡¢ÌáÉýȨÏÞ»òÖ´ÐÐÆäËüδÊÚȨ²Ù×÷ ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬ÆäÖв¿ÃÅ·ì϶ÒѾ­¼ì²âµ½ÔÚÒ°ÀûÓà ¡£¡£¡£¡£¡£

 

0x01 ·ì϶ÏêÇé

image.png

±¾´Î¹«¿ªµÄ4¸ö·ì϶ÖУ¬£¬£¬£¬£¬£¬CVE-2021-32464ºÍCVE-2021-36742¿É±¾µØÀûÓ㬣¬£¬£¬£¬£¬CVE-2021-32465ºÍCVE-2021-36741¿ÉÔ¶³ÌÀûÓ㬣¬£¬£¬£¬£¬ËüÃǵķì϶ÆÀ¼¶¾ùΪ¸ßΣ ¡£¡£¡£¡£¡£ÆäÏêÇéÈçÏ£º

Apex OneȨÏÞÌáÉý·ì϶£¨CVE-2021-32464£©

ÓÉÓÚȨÏÞ·ÖÅä²»ÕýÈ·£¬£¬£¬£¬£¬£¬Apex One ºÍApex One as a ServiceÖдæÔÚȨÏÞÌáÉý·ì϶£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚÖ´ÐÐÌØ¶¨¾ç±¾Ö®Ç°¶ÔÆä½øÐÐÅú¸Ä£¬£¬£¬£¬£¬£¬µ«¹¥»÷Õß±ØÐëÊ×ÏÈ»ñµÃÔÚÖ¸±êϵͳÉϽϵÍȨÏ޵ĴúÂëÖ´ÐÐÄÜÁ¦ ¡£¡£¡£¡£¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.8 ¡£¡£¡£¡£¡£

 

Apex OneÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2021-32465£©

ÓÉÓÚApex OneºÍApex One as a ServiceÖдæÔÚÒ»¸ö²»ÕýÈ·µÄȨÏÞ±£Áô·ì϶£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚÖ¸±êϵͳÉÏÖ´Ðй¥»÷²¢ÈƹýÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬µ«¹¥»÷Õß±ØÐëÊ×ÏÈ»ñµÃÔÚÖ¸±êϵͳÉϽϵÍȨÏ޵ĴúÂëÖ´ÐÐÄÜÁ¦ ¡£¡£¡£¡£¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.5 ¡£¡£¡£¡£¡£

 

Apex OneËÁÒâÎļþÉÏ´«·ì϶£¨CVE-2021-36741£©

ÓÉÓÚApex OneºÍApex One as a ServiceÖдæÔÚÒ»¸ö²»ÕýÈ·µÄÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚÖ¸±êϵÍÓð»¯Ï´«ËÁÒâÎļþ£¬£¬£¬£¬£¬£¬µ«¹¥»÷Õß±ØÐëÊ×ÏÈ»ñµÃµÇ¼¸Ã²úÆ·ÖÎÀí½ÚÔį̀µÄÄÜÁ¦ ¡£¡£¡£¡£¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.1£¬£¬£¬£¬£¬£¬Ä¿Ç°ÒѾ­¼ì²âµ½ÔÚÒ°ÀûÓà ¡£¡£¡£¡£¡£

 

Apex One±¾µØÌáȨ·ì϶£¨CVE-2021-36742£©

ÓÉÓÚApex OneºÍApex One as a ServiceÖдæÔÚÒ»¸ö²»ÕýÈ·µÄÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚÖ¸±êϵͳÉÏʵÏÖ±¾µØÌáÉýȨÏÞ£¬£¬£¬£¬£¬£¬µ«¹¥»÷Õß±ØÐëÊ×ÏÈ»ñµÃÔÚÖ¸±êϵͳÉϽϵÍȨÏ޵ĴúÂëÖ´ÐÐÄÜÁ¦ ¡£¡£¡£¡£¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬Ä¿Ç°ÒѾ­¼ì²âµ½ÔÚÒ°ÀûÓà ¡£¡£¡£¡£¡£

 

Ó°ÏìÁìÓò

Trend Micro Apex One 2019 (On-prem)£¨Windows£©

Trend Micro Apex One SaaS£¨Windows£©

 

0x02 ´ëÖý¨Òé

ĿǰÕâЩ·ì϶ÒѾ­½¨¸´ ¡£¡£¡£¡£¡£¼øÓÚ²¿ÃÅ·ì϶ÒѾ­³Ê´Ë¿ÌÒ°ÀûÓ㬣¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄ¿Í»§ÊµÊ±×°ÖÃÒÔϲ¹¶ ¡£¡£¡£¡£¡£º

Apex One (on-prem)  CP 9601²¹¶¡

Apex One as a Service (SaaS)  2021 Äê 7 ÔÂÔ¶Ȳ¹¶¡

ÏÂÔØÁ´½Ó£º

https://success.trendmicro.com/solution/000287819

 

0x03 ²Î¿¼Á´½Ó

https://success.trendmicro.com/solution/000287819

https://www.trendmicro.com/en_ca/business/products/downloads.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32464

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2021-07-30

³õ´Î°ä²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ8827Ì«Ñô¼¯ÍÅ

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png   image.png