ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ48ÖÜ

°ä²¼¹¦·ò 2020-11-30

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê11ÔÂ23ÈÕÖÁ11ÔÂ29ÈÕ¹²ÊÕ¼°²È«·ì϶48¸ö£¬ £¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇVmware Workspace One CVE-2020-4006ºÅÁî×¢Èë·ì϶£»£» £» £» £» £»Shenzhen C-Data 72408AĬÈÏtelnet·þÎñ·ì϶£»£» £» £» £» £»Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤·ì϶£»£» £» £» £» £»Barco wePresent WiPG-1600W¹Ì¼þÐÅϢй¶·ì϶£»£» £» £» £» £»Mongodb Server RoleName::parseFromBSON()»Ø¾ø·þÎñ·ì϶¡£¡£ ¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÁù¸öÔÂÒÔÀ´Î¢ÈíÈÔ佨¸´Windows10ÖÐÒÑÖª·ì϶£»£» £» £» £» £»ºÚ¿Í¹«¿ª5Íò¸ö´æÔÚ·ì϶µÄFortinet VPNÉ豸Áбí£»£» £» £» £» £»VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬ £¬£¬£¬£¬£¬£¬ÉÐδ°ä²¼²¹¶¡£¡£ ¡£¡£¡£»£» £» £» £» £»×êÑÐÈËÔ±·¢ÏÖWin7ºÍServer2008Öеı¾µØÌáȨ0day£»£» £» £» £» £»Group-IB°ä²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÔ¤²â·ÖÎö»ã±¨¡£¡£ ¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬ £¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£ ¡£¡£¡£


³ÁÒª°²È«·ì϶Áбí


1.Vmware Workspace One CVE-2020-4006ºÅÁî×¢Èë·ì϶


VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address´æÔÚ°²È«·ì϶£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬£¬£¬£¬¿É×¢ÈëËÁÒâºÅÁî²¢Ö´ÐÓ×£¡£ ¡£¡£¡£

https://docs.opsmanager.mongodb.com/current/release-notes/application/#onprem-server-4-4-3


2.Shenzhen C-Data 72408AĬÈÏtelnet·þÎñ·ì϶


Shenzhen C-Data 72408A Telnet·þÎñ´æÔÚ¶à¸öĬÈÏÍ´´¦·ì϶£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬£¬£¬£¬¿ÉδÊÚȨ½Ó¼ûÉ豸¡£¡£ ¡£¡£¡£

https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html


3.Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤·ì϶


Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤´æÔÚ°²È«·ì϶£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬£¬£¬£¬¿É×°Öý¨»Ú¸ÄµÄ/¶ñÒâµÄÓ³Ïñ¡£¡£ ¡£¡£¡£

https://korelogic.com/Resources/Advisories/KL-001-2020-009.txt


4.Barco wePresent WiPG-1600W¹Ì¼þÐÅϢй¶·ì϶


Barco wePresent WiPG-1600W¹Ì¼þÓ³ÏñÖÐÔ̺¬Ó²±àÂëµÄ¸ùÃÜÂëÉ¢ÁУ¬ £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬£¬£¬£¬¿Éͨ¹ý´ËÐÅϢδÊÚȨ½Ó¼û¡£¡£ ¡£¡£¡£

https://korelogic.com/Resources/Advisories/KL-001-2020-008.txt


5.Mongodb Server RoleName::parseFromBSON()»Ø¾ø·þÎñ·ì϶


Mongodb Server RoleName::parseFromBSON()´æÔÚ°²È«·ì϶£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬£¬£¬£¬¿É½øÐлؾø·þÎñ¹¥»÷¡£¡£ ¡£¡£¡£

https://jira.mongodb.org/browse/SERVER-49142


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Áù¸öÔÂÒÔÀ´Î¢ÈíÈÔ佨¸´Windows10ÖÐÒÑÖª·ì϶


1.jpg


×Ô2020Äê5Ô£¬ £¬£¬£¬£¬£¬£¬Microsoft°ä²¼ÁËWindows 10 2004°²È«¸üкó£¬ £¬£¬£¬£¬£¬£¬³öÏÖÁËÁ½¸ö·ì϶£¬ £¬£¬£¬£¬£¬£¬µ¼ÖÂSSDÇý¶¯Æ÷µÄ´ÅÅÌË鯬Õû¶Ù¹ýÓÚÆµÈÔ£¬ £¬£¬£¬£¬£¬£¬²¢ÔÚ·ÇSSDÇý¶¯Æ÷Éϳ¢ÊÔTRIM²Ù×÷¡£¡£ ¡£¡£¡£µÚÒ»¸ö·ì϶ʹWin10×Ô¶¯ÊØ»¤Ö°ÄÜÎÞ·¨¼Çס³ÁÆôϵͳʱÇý¶¯Æ÷µÄ×îºóÓÅ»¯¹¦·ò£¬ £¬£¬£¬£¬£¬£¬µ¼ÖÂÇý¶¯Æ÷ÔÚÿ´Î³ÁÆôÍÆËã»úʱ¶¼½øÐÐË鯬Õû¶Ù¡£¡£ ¡£¡£¡£µÚ¶þ¸ö·ì϶µ¼ÖÂWin10µÄÓÅ»¯Çý¶¯Æ÷Ö°ÄÜ»á¶Ô·ÇSSDÇý¶¯Æ÷½øÐÐTRIM£¬ £¬£¬£¬£¬£¬£¬Õâ»áµ¼ÖÂÊÂÎñÈÕÖ¾ÖÐÃýÎ󡣡£ ¡£¡£¡£Èç½ñ£¬ £¬£¬£¬£¬£¬£¬ÔÚ½üÁù¸öÔÂÖ®ºó£¬ £¬£¬£¬£¬£¬£¬MicrosoftÈÔ佨¸´¸Ã·ì϶¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/windows-10-defrag-trim-bug-still-not-fixed-after-six-months/


2¡¢ºÚ¿Í¹«¿ª5Íò¸ö´æÔÚ·ì϶µÄFortinet VPNÉ豸Áбí


2.jpg


ºÚ¿Í¹«¿ª5Íò¸ö´æÔÚ·ì϶µÄFortinet VPNÉ豸Áбí£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬À´×ÔÊÀ½ç¸÷µØµÄ´óÐÍÒøÐк͵±¾Ö×éÖ¯¡£¡£ ¡£¡£¡£ÕâЩÉ豸Öоù´æÔÚõè¾¶±éÀú·ì϶£¬ £¬£¬£¬£¬£¬£¬±»×·×ÙΪCVE-2018-13379£¬ £¬£¬£¬£¬£¬£¬ËüÓ°ÏìÁË´óÁ¿Î´½¨²¹µÄFortinet FortiOS SSL VPNÉ豸¡£¡£ ¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶£¬ £¬£¬£¬£¬£¬£¬´ÓFortinet VPN½Ó¼ûsslvpn_websessionÎļþÀ´ÇÔÈ¡µÇ¼ʹ´¦£¬ £¬£¬£¬£¬£¬£¬²¢½«ÆäÓÃÓÚ·ÛËéÍøÂç²¢²¿ÊðÀÕË÷Èí¼þ¡£¡£ ¡£¡£¡£Ö»¹Ü¸Ã·ì϶ÔÚÒ»Äêǰ¾Í±»¹«¿ªÅû¶£¬ £¬£¬£¬£¬£¬£¬µ«ºÚ¿ÍÈÔ·¢ÏÖ²¢¹«¿ªÁËÁË49577¸ö´æÔÚ´ËÀà·ì϶µÄ´óÐÍÉ豸µÄÁÐ±í¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-posts-exploits-for-over-49-000-vulnerable-fortinet-vpns/


3¡¢VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬ £¬£¬£¬£¬£¬£¬ÉÐδ°ä²¼²¹¶¡


3.jpg


VMwareÅû¶ÁËÓ°ÏìÆäWorkspace One¶à¸ö×é¼þÖеÄÌáȨ0day£¬ £¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÌáȨÒÔÔÚLinuxºÍWindows²Ù×÷ϵͳÉÏÖ´ÐкÅÁ £¬£¬£¬£¬£¬£¬Ä¿Ç°ÉÐδ°ä²¼Óйز¹¶¡·¨Ê½¡£¡£ ¡£¡£¡£¸Ã·ì϶±»¸ú×ÙΪCVE-2020-4006£¬ £¬£¬£¬£¬£¬£¬CVSSµÈ¼¶Îª9.1£¬ £¬£¬£¬£¬£¬£¬ÆäÓ°ÏìÁËVMware Workspace ONE Access¡¢½Ó¼ûÏÎ½ÓÆ÷¡¢Éí·ÝÖÎÀíÆ÷¡¢Éí·ÝÖÎÀíÆ÷ÏÎ½ÓÆ÷¡¢VMwareÔÆ»ù½ð»áºÍvRealize SuiteÐÔÃüÖÜÆÚÖÎÀíÆ÷¡£¡£ ¡£¡£¡£Ä¿Ç°£¬ £¬£¬£¬£¬£¬£¬VMwareÒѰ䲼һʱ½â¾ö·¨×ÓÒÔ½â³ý¹¥»÷ý½é²¢Ô¤·À·ì϶µÄÀûÓᣡ£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/vmware-zero-day-patch-pending/161523/


4¡¢×êÑÐÈËÔ±·¢ÏÖWin7ºÍServer2008Öеı¾µØÌáȨ0day


4.jpg


·¨¹ú×êÑÐÈËÔ±·¢ÏÖWindows 7ºÍServer 2008´æÔÚ±¾µØÌáȨ£¨LPE£©0day£¬ £¬£¬£¬£¬£¬£¬µ±Windows°²È«¹¤¾ß¸üÐÂʱ»áÓ°ÏìÆä²Ù×÷ϵͳ¡£¡£ ¡£¡£¡£¸Ã·ì϶λÓÚËùÓÐWindows×°ÖÃÖеÄRPC¶ËµãÓ³ÉäÆ÷ºÍDNSCache·þÎñµÄÁ½¸öÃýÎóÅäÖõÄ×¢²á±íÏîÖУ¬ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýÅú¸ÄÕâЩע²á±íÀ´¼¤»îWindows»úÄܼල»úÔìËùʹÓõÄ×ÓÃÜÔ¿¡£¡£ ¡£¡£¡£Ä¿Ç°0patchƽ̨ÒѰ䲼һʱ΢²¹¶¡£¬ £¬£¬£¬£¬£¬£¬²¢ÔÚ΢Èí°ä²¼Õýʽ²¹¶¡Ç°¶ÔËùÓÐÈËÃâ·ÑÌṩ¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/windows-7-and-server-2008-zero-day-bug-gets-a-free-patch/


5¡¢Group-IB°ä²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÔ¤²â·ÖÎö»ã±¨


5.jpg


Group-IB°ä²¼Á˶ÔÀ´ÄêÍøÂçÍþвµÄÔ¤²â·ÖÎö»ã±¨£¬ £¬£¬£¬£¬£¬£¬×êÑÐÁË2019ÄêϰëÄêÖÁ2020ÄêÉϰëÄêÖ®¼ä¹ú¼ÊÍøÂç·¸×ï״ΪµÄÖØÒª±ä¶¯£¬ £¬£¬£¬£¬£¬£¬²¢¶ÔÀ´Äê×ö³öÁËÔ¤²â¡£¡£ ¡£¡£¡£»ã±¨Ö¸³ö£¬ £¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þ»î¶¯Ôì³ÉÁËÑϳÁµÄ¾­¼ÃËðʧ£¬ £¬£¬£¬£¬£¬£¬Ë½Óª¹«Ë¾ºÍµ±¾Ö»ú¹¹¶¼Î´ÄÜÐÒÃâ¡£¡£ ¡£¡£¡£ÔÚ´ËÆÚ¼ä£¬ £¬£¬£¬£¬£¬£¬×ܹ²ÓÐÕë¶Ô³¬¹ý45¸ö¹ú¶ÈµÄ500ÂÅ´ÎÀÕË÷Èí¼þ¹¥»÷¡£¡£ ¡£¡£¡£Æ¾¾ÝGroup-IBµÄÊØ¾É¹À¼Æ£¬ £¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þÍÅ»ïÔì³ÉµÄ×ܲÆÕþËðʧ³¬¹ý10ÒÚÃÀÔª£¨1005186000ÃÀÔª£©¡£¡£ ¡£¡£¡£ÆäÖУ¬ £¬£¬£¬£¬£¬£¬MazeºÍREvilµÄÓ°Ïì×î´ó£¬ £¬£¬£¬£¬£¬£¬Õ¼ËùÓй¥»÷µÄ°ëÊýÒÔÉÏ£¬ £¬£¬£¬£¬£¬£¬Æä´ÎÊÇRyuk¡¢NetWalkerºÍDoppelPaymer¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.group-ib.com/media/gib-report-2020/