ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ40ÖÜ
°ä²¼¹¦·ò 2020-10-09> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê09ÔÂ28ÈÕÖÁ10ÔÂ04ÈÕ¹²ÊÕ¼°²È«·ì϶56¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇFoxit Reader Field::ClearItems/Field::DeleteOptionsÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»£»£»£»£»£»Secudos DOMOS conf_datetimeËÁÒâºÅÁîÖ´Ðзì϶£»£»£»£»£»£»WAVLINK WN530H4 /cgi-bin/live_api.cgiºÅÁî×¢Èë·ì϶£»£»£»£»£»£»WAVLINK WN530H4 /cgi-bin/makeRequest.cgi»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»WAVLINK WN530H4 /cgi-bin/¶à¸öÑéÖ¤ÈÆ¹ý·ì϶¡£¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ£ºCNCERT°ä²¼¡¶2020ÄêÉϰëÄêÎÒ¹ú»¥ÁªÍøÍøÂ簲ȫ¼à²âÊý¾Ý·ÖÎö»ã±¨¡·£»£»£»£»£»£»×êÑÐÈËÔ±·¢ÏÖжñÒâÈí¼þTaurusͨ¹ý¶ñÒâ¸æ°×»î¶¯´«²¼£»£»£»£»£»£»ÃÀ¹úºÍ°Ä´óÀûÑÇOffice 365·þÎñ³öÏÖAADSTS90033ÃýÎ󣻣»£»£»£»£»ÃÀ¹ú14¸öÖݻ㱨Æä911·þÎñÖжϣ¬£¬£¬£¬£¬£¬ÊÂÎñÔÒò»¹ÔÚµ÷²éÖУ»£»£»£»£»£»ºÚ¿ÍÒÔWin7Éý¼¶Îªµö¶üÌáÒé´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬ÇÔÈ¡OutlookÍ´´¦¡£¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£¡£¡£
> ³ÁÒª°²È«·ì϶Áбí
1.Foxit Reader Field::ClearItems/Field::DeleteOptionsÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶
Foxit Reader Field::ClearItems/Field::DeleteOptions´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»òÕßÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://www.foxitsoftware.com/support/security-bulletins.html
2.Secudos DOMOS conf_datetimeËÁÒâºÅÁîÖ´Ðзì϶
Secudos DOMOS conf_datetime´¦ÖÃzone²ÎÊý´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Äܹ»root¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£
https://www.secudos.de/en/news-en/domos-release-5-9
3.WAVLINK WN530H4 /cgi-bin/live_api.cgiºÅÁî×¢Èë·ì϶
WAVLINK WN530H4 /cgi-bin/live_api.cgi´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Äܹ»ROOTȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£
https://cerne.xyz/bugs/CVE-2020-12124
4.WAVLINK WN530H4 /cgi-bin/makeRequest.cgi»º³åÇøÒç¶Âí½Å
WAVLINK WN530H4 /cgi-bin/makeRequest.cgi´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Äܹ»ROOTȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£
https://cerne.xyz/bugs/CVE-2020-12125
5.WAVLINK WN530H4 /cgi-bin/¶à¸öÑéÖ¤ÈÆ¹ý·ì϶
WAVLINK WN530H4 /cgi-bin/´æÔÚ¶à¸öÑéÖ¤ÈÆ¹ý·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉÅú¸ÄÅäÖ㬣¬£¬£¬£¬£¬½øÐлؾø·þÎñµÈ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
https://cerne.xyz/bugs/CVE-2020-12126
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢CNCERT°ä²¼¡¶2020ÄêÉϰëÄêÎÒ¹ú»¥ÁªÍøÍøÂ簲ȫ¼à²âÊý¾Ý·ÖÎö»ã±¨¡·

ÎªÈ«Ãæ·´Ó³2020ÄêÉϰëÄêÎÒ¹ú»¥ÁªÍøÔÚ¶ñÒⷨʽ´«²¼¡¢·ì϶·çÏÕ¡¢DDoS¹¥»÷¡¢ÍøÕ¾°²È«µÈ·½ÃæµÄÇé¿ö£¬£¬£¬£¬£¬£¬CNCERT¶ÔÉϰëÄê¼à²âÊý¾Ý½øÐÐÁËÊáÀí£¬£¬£¬£¬£¬£¬²¢Ðγɼà²âÊý¾Ý·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬£¬2020ÄêÉϰëÄ꣬£¬£¬£¬£¬£¬²¶»ñÍÆËã»ú¶ñÒⷨ״ò±¾ÊýÁ¿Ô¼1815Íò¸ö£¬£¬£¬£¬£¬£¬ÈÕ¾ù´«²¼´ÎÊý´ï483ÍòÓà´Î£¬£¬£¬£¬£¬£¬Éæ¼°ÍÆËã»ú¶ñÒⷨʽ¼Ò×åÔ¼1.1ÍòÓà¸ö¡£¡£¡£¡£¡£¡£¡£¡£ÒÀÕÕ´«²¼ÆðԴͳ¼Æ£¬£¬£¬£¬£¬£¬¾³±í¶ñÒâ·¨Ê½ÖØÒªÀ´×ÔÃÀ¹ú¡¢ÈûÉà¶ûºÍ¼ÓÄôóµÈ£¬£¬£¬£¬£¬£¬¾³ÄڵĶñÒâ·¨Ê½ÖØÒªÀ´×ÔÕã½Ê¡¡¢¹ã¶«Ê¡ºÍ±±¾©Êеȡ£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cert.org.cn/publish/main/46/2020/20200926085042652505447/20200926085042652505447_.html
2¡¢×êÑÐÈËÔ±·¢ÏÖжñÒâÈí¼þTaurusͨ¹ý¶ñÒâ¸æ°×»î¶¯´«²¼

×êÑÐÈËÔ±·¢ÏÖеÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þTaurusͨ¹ý¶ñÒâ¸æ°×»î¶¯´«²¼¡£¡£¡£¡£¡£¡£¡£¡£TaurusÊÇÒ»ÖÖÏà¶Ô½ÏеĶñÒâÈí¼þ£¬£¬£¬£¬£¬£¬ÓÚ2020Äê´º¼¾³öÏÖ£¬£¬£¬£¬£¬£¬Í¨¹ýÕë¶ÔÃÀ¹úÓû§µÄ¶ñÒâ¸æ°×»î¶¯½øÐд«²¼¡£¡£¡£¡£¡£¡£¡£¡£Æä×î³õÊÇÓÉPredatorµÄ´´½¨ÕßËù¿ª·¢£¬£¬£¬£¬£¬£¬Òò¶ø¶þÕßÓµÓÐÒ»ÑùµÄÖ°ÄÜ£¬£¬£¬£¬£¬£¬¼´´Óä¯ÀÀÆ÷¡¢FTP¡¢VPN¡¢µç×ÓÓʼþ¿Í»§¶ËÒÔ¼°¼ÓÃÜÇ®±ÒÇ®°üÇÔȡʹ´¦¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î×îз¢ÏֵĶñÒâ»î¶¯ÖØÒªÕë¶Ô³ÉÈËÍøÕ¾µÄ½Ó¼ûÕߣ¬£¬£¬£¬£¬£¬Êܺ¦Õß´ó¶àÀ´×ÔÃÀ¹ú£¬£¬£¬£¬£¬£¬Ò²ÓÐÀ´×Ô°Ä´óÀûÑǺÍÓ¢¹ú¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/malwarebytes-news/2020/09/taurus-project-stealer-now-spreading-via-malvertising-campaign/
3¡¢ÃÀ¹úºÍ°Ä´óÀûÑÇOffice 365·þÎñ³öÏÖAADSTS90033ÃýÎó

´Ó9ÔÂ28ÈÕÃÀ¹ú¶«²¿¹¦·òÏÂÎç5:15ÆðÍ·£¬£¬£¬£¬£¬£¬ÃÀ¹úºÍ°Ä´óÀûÑǵÄOffice 365Óû§ÆðÍ·ÄÑÒԵǼÆäµç×ÓÓʼþÕÊ»§»ò½Ó¼ûµç×ÓÓʼþ£¬£¬£¬£¬£¬£¬²¢»á³öÏÖAADSTS90033ÃýÎóÌáÐÑ¡£¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÖжÏÓ°ÏìÁ˵ç×ÓÓʼþ·þÎñ¡¢Microsoft Teams¡¢Office.com¡¢Power PlatformºÍDynamics365¡£¡£¡£¡£¡£¡£¡£¡£Microsoft×î³õ°µÊ¾£¬£¬£¬£¬£¬£¬ËûÃÇÈ·¶¨Á˵¼ÖÂÖжϵÄÔÒò£¬£¬£¬£¬£¬£¬µ«ÊÇÔڻعöÖ®ºóÖжÏÒÀȻûÓеõ½½â¾ö¡£¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬MicrosoftÆðÍ·³¢ÊÔͨ¹ý·ÖÆçµÄ·þÎñÆ÷³ÁзÓÉÁ÷Á¿£¬£¬£¬£¬£¬£¬²¢ÇÒһЩÓû§»ã±¨ËµÄܹ»ÔٴεǼ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-office-365-is-down-in-the-usa-shows-transient-error/
4¡¢ÃÀ¹ú14¸öÖݻ㱨Æä911·þÎñÖжϣ¬£¬£¬£¬£¬£¬ÊÂÎñÔÒò»¹ÔÚµ÷²éÖÐ

±¾ÖÜÒ»£¬£¬£¬£¬£¬£¬ÃÀ¹ú»ªÊ¢¶ÙÖÝ¡¢±öϦ·¨ÄáÑÇÖÝºÍ¶íº¥¶íÖݵÈ14¸öÖݻ㱨Æä911·þÎñÖжϣ¬£¬£¬£¬£¬£¬Ä¿Ç°ÊÂÎñÔÒò»¹ÔÚµ÷²éÖÓ×£¡£¡£¡£¡£¡£¡£¡£Õâ´Î·þÎñÖжÏÓ°ÏìÁËËùÓд¹Î£·þÎñ£¬£¬£¬£¬£¬£¬µ«´óÎÞÊýÊÜÓ°ÏìµØÓòµÄ911·þÎñÔÚ30·ÖÖÓºÍ60·ÖÖÓÄÚ¸´Ô¡£¡£¡£¡£¡£¡£¡£¡£ÓÐÐÂÎÅÆðÔ´³ÆÕâ´ÎÖжϻòÓë΢ÈíµÄ´ó¹æÄ£Í£»£»£»£»£»£»úÓйء£¡£¡£¡£¡£¡£¡£¡£µ«ÆäËûÆðÔ´Åú×¢£¬£¬£¬£¬£¬£¬Î¢ÈíÖжϽöÓ°ÏìÁËOfficeºÍÓëµç×ÓÓʼþÓйصķþÎñ£¬£¬£¬£¬£¬£¬911·þÎñÖжϿÉÄܵ××ÓÓë΢ÈíÎ޹أ¬£¬£¬£¬£¬£¬²¢ÇҺܿÉÄÜ·¢Ô´ÓÚPSAP£¨¹«¹²°²È«Ó¦´ðµã£©ÌṩÉÌ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/911-services-down-in-multiple-us-states/
5¡¢ºÚ¿ÍÒÔWin7Éý¼¶Îªµö¶üÌáÒé´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬ÇÔÈ¡OutlookÍ´´¦

×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬ºÚ¿ÍÒÔWin7Éý¼¶Îªµö¶üÌáÒé´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡OutlookÓû§Í´´¦¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯Í¨¹ý·¢ËÍÒÔ¡°Re£ºMicrosoft Windows Upgrade¡±ÎªÌâµÄ´¹µöÓʼþ£¬£¬£¬£¬£¬£¬ÓÕʹÊܺ¦Õßµã¿ªÍøÂç´¹µöµÇÂ¼Ò³Ãæ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÒ³ÃæÊÇαÔìµÄOutlook Web App£¨OWA£©µÇÂ¼Ò³Ãæ£¬£¬£¬£¬£¬£¬ÒªÇóÓû§ÊäÈëµç×ÓÓʼþµØÖ·¡¢Óò/Óû§ÃûºÍÃÜÂ룬£¬£¬£¬£¬£¬ÒÔ´ËÀ´ÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¸Ã´¹µöÓʼþ»¹Ô̺¬ÆäËû¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬ÀýÈçÉý¼¶¹ý³ÌÖпÉÄÜ»áÓöµ½µÄÎÊÌ⣬£¬£¬£¬£¬£¬ÒÔÔö³¤ÆäÕæÊµÐÔ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/windows-7-outlook/159621/


¾©¹«Íø°²±¸11010802024551ºÅ