ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ48ÖÜ
°ä²¼¹¦·ò 2020-11-30> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê11ÔÂ23ÈÕÖÁ11ÔÂ29ÈÕ¹²ÊÕ¼°²È«·ì϶48¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇVmware Workspace One CVE-2020-4006ºÅÁî×¢Èë·ì϶£»£»£»£»£»£»Shenzhen C-Data 72408AĬÈÏtelnet·þÎñ·ì϶£»£»£»£»£»£»Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤·ì϶£»£»£»£»£»£»Barco wePresent WiPG-1600W¹Ì¼þÐÅϢй¶·ì϶£»£»£»£»£»£»Mongodb Server RoleName::parseFromBSON()»Ø¾ø·þÎñ·ì϶¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÁù¸öÔÂÒÔÀ´Î¢ÈíÈÔ佨¸´Windows10ÖÐÒÑÖª·ì϶£»£»£»£»£»£»ºÚ¿Í¹«¿ª5Íò¸ö´æÔÚ·ì϶µÄFortinet VPNÉ豸ÁÐ±í£»£»£»£»£»£»VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬£¬£¬£¬£¬£¬£¬ÉÐδ°ä²¼²¹¶¡£¡£¡£¡£¡£»£»£»£»£»£»×êÑÐÈËÔ±·¢ÏÖWin7ºÍServer2008Öеı¾µØÌáȨ0day£»£»£»£»£»£»Group-IB°ä²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÔ¤²â·ÖÎö»ã±¨¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£
> ³ÁÒª°²È«·ì϶Áбí
1.Vmware Workspace One CVE-2020-4006ºÅÁî×¢Èë·ì϶
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿É×¢ÈëËÁÒâºÅÁî²¢Ö´ÐÓ×£¡£¡£¡£¡£
https://docs.opsmanager.mongodb.com/current/release-notes/application/#onprem-server-4-4-3
2.Shenzhen C-Data 72408AĬÈÏtelnet·þÎñ·ì϶
Shenzhen C-Data 72408A Telnet·þÎñ´æÔÚ¶à¸öĬÈÏÍ´´¦·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉδÊÚȨ½Ó¼ûÉ豸¡£¡£¡£¡£¡£
https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html
3.Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤·ì϶
Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿É×°Öý¨»Ú¸ÄµÄ/¶ñÒâµÄÓ³Ïñ¡£¡£¡£¡£¡£
https://korelogic.com/Resources/Advisories/KL-001-2020-009.txt
4.Barco wePresent WiPG-1600W¹Ì¼þÐÅϢй¶·ì϶
Barco wePresent WiPG-1600W¹Ì¼þÓ³ÏñÖÐÔ̺¬Ó²±àÂëµÄ¸ùÃÜÂëÉ¢ÁУ¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿Éͨ¹ý´ËÐÅϢδÊÚȨ½Ó¼û¡£¡£¡£¡£¡£
https://korelogic.com/Resources/Advisories/KL-001-2020-008.txt
5.Mongodb Server RoleName::parseFromBSON()»Ø¾ø·þÎñ·ì϶
Mongodb Server RoleName::parseFromBSON()´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿É½øÐлؾø·þÎñ¹¥»÷¡£¡£¡£¡£¡£
https://jira.mongodb.org/browse/SERVER-49142
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Áù¸öÔÂÒÔÀ´Î¢ÈíÈÔ佨¸´Windows10ÖÐÒÑÖª·ì϶

×Ô2020Äê5Ô£¬£¬£¬£¬£¬£¬£¬Microsoft°ä²¼ÁËWindows 10 2004°²È«¸üк󣬣¬£¬£¬£¬£¬£¬³öÏÖÁËÁ½¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂSSDÇý¶¯Æ÷µÄ´ÅÅÌË鯬Õû¶Ù¹ýÓÚÆµÈÔ£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ·ÇSSDÇý¶¯Æ÷Éϳ¢ÊÔTRIM²Ù×÷¡£¡£¡£¡£¡£µÚÒ»¸ö·ì϶ʹWin10×Ô¶¯ÊØ»¤Ö°ÄÜÎÞ·¨¼Çס³ÁÆôϵͳʱÇý¶¯Æ÷µÄ×îºóÓÅ»¯¹¦·ò£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÇý¶¯Æ÷ÔÚÿ´Î³ÁÆôÍÆËã»úʱ¶¼½øÐÐË鯬Õû¶Ù¡£¡£¡£¡£¡£µÚ¶þ¸ö·ì϶µ¼ÖÂWin10µÄÓÅ»¯Çý¶¯Æ÷Ö°ÄÜ»á¶Ô·ÇSSDÇý¶¯Æ÷½øÐÐTRIM£¬£¬£¬£¬£¬£¬£¬Õâ»áµ¼ÖÂÊÂÎñÈÕÖ¾ÖÐÃýÎ󡣡£¡£¡£¡£Èç½ñ£¬£¬£¬£¬£¬£¬£¬ÔÚ½üÁù¸öÔÂÖ®ºó£¬£¬£¬£¬£¬£¬£¬MicrosoftÈÔ佨¸´¸Ã·ì϶¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/windows-10-defrag-trim-bug-still-not-fixed-after-six-months/
2¡¢ºÚ¿Í¹«¿ª5Íò¸ö´æÔÚ·ì϶µÄFortinet VPNÉ豸Áбí

ºÚ¿Í¹«¿ª5Íò¸ö´æÔÚ·ì϶µÄFortinet VPNÉ豸ÁÐ±í£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬À´×ÔÊÀ½ç¸÷µØµÄ´óÐÍÒøÐк͵±¾Ö×éÖ¯¡£¡£¡£¡£¡£ÕâЩÉ豸Öоù´æÔÚõè¾¶±éÀú·ì϶£¬£¬£¬£¬£¬£¬£¬±»×·×ÙΪCVE-2018-13379£¬£¬£¬£¬£¬£¬£¬ËüÓ°ÏìÁË´óÁ¿Î´½¨²¹µÄFortinet FortiOS SSL VPNÉ豸¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬£¬´ÓFortinet VPN½Ó¼ûsslvpn_websessionÎļþÀ´ÇÔÈ¡µÇ¼ʹ´¦£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäÓÃÓÚ·ÛËéÍøÂç²¢²¿ÊðÀÕË÷Èí¼þ¡£¡£¡£¡£¡£Ö»¹Ü¸Ã·ì϶ÔÚÒ»Äêǰ¾Í±»¹«¿ªÅû¶£¬£¬£¬£¬£¬£¬£¬µ«ºÚ¿ÍÈÔ·¢ÏÖ²¢¹«¿ªÁËÁË49577¸ö´æÔÚ´ËÀà·ì϶µÄ´óÐÍÉ豸µÄÁÐ±í¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-posts-exploits-for-over-49-000-vulnerable-fortinet-vpns/
3¡¢VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬£¬£¬£¬£¬£¬£¬ÉÐδ°ä²¼²¹¶¡

VMwareÅû¶ÁËÓ°ÏìÆäWorkspace One¶à¸ö×é¼þÖеÄÌáȨ0day£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÌáȨÒÔÔÚLinuxºÍWindows²Ù×÷ϵͳÉÏÖ´ÐкÅÁ£¬£¬£¬£¬£¬£¬Ä¿Ç°ÉÐδ°ä²¼Óйز¹¶¡·¨Ê½¡£¡£¡£¡£¡£¸Ã·ì϶±»¸ú×ÙΪCVE-2020-4006£¬£¬£¬£¬£¬£¬£¬CVSSµÈ¼¶Îª9.1£¬£¬£¬£¬£¬£¬£¬ÆäÓ°ÏìÁËVMware Workspace ONE Access¡¢½Ó¼ûÏÎ½ÓÆ÷¡¢Éí·ÝÖÎÀíÆ÷¡¢Éí·ÝÖÎÀíÆ÷ÏÎ½ÓÆ÷¡¢VMwareÔÆ»ù½ð»áºÍvRealize SuiteÐÔÃüÖÜÆÚÖÎÀíÆ÷¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬VMwareÒѰ䲼һʱ½â¾ö·¨×ÓÒÔ½â³ý¹¥»÷ý½é²¢Ô¤·À·ì϶µÄÀûÓᣡ£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/vmware-zero-day-patch-pending/161523/
4¡¢×êÑÐÈËÔ±·¢ÏÖWin7ºÍServer2008Öеı¾µØÌáȨ0day

·¨¹ú×êÑÐÈËÔ±·¢ÏÖWindows 7ºÍServer 2008´æÔÚ±¾µØÌáȨ£¨LPE£©0day£¬£¬£¬£¬£¬£¬£¬µ±Windows°²È«¹¤¾ß¸üÐÂʱ»áÓ°ÏìÆä²Ù×÷ϵͳ¡£¡£¡£¡£¡£¸Ã·ì϶λÓÚËùÓÐWindows×°ÖÃÖеÄRPC¶ËµãÓ³ÉäÆ÷ºÍDNSCache·þÎñµÄÁ½¸öÃýÎóÅäÖõÄ×¢²á±íÏîÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýÅú¸ÄÕâЩע²á±íÀ´¼¤»îWindows»úÄܼල»úÔìËùʹÓõÄ×ÓÃÜÔ¿¡£¡£¡£¡£¡£Ä¿Ç°0patchƽ̨ÒѰ䲼һʱ΢²¹¶¡£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ΢Èí°ä²¼Õýʽ²¹¶¡Ç°¶ÔËùÓÐÈËÃâ·ÑÌṩ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/windows-7-and-server-2008-zero-day-bug-gets-a-free-patch/
5¡¢Group-IB°ä²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÔ¤²â·ÖÎö»ã±¨

Group-IB°ä²¼Á˶ÔÀ´ÄêÍøÂçÍþвµÄÔ¤²â·ÖÎö»ã±¨£¬£¬£¬£¬£¬£¬£¬×êÑÐÁË2019ÄêϰëÄêÖÁ2020ÄêÉϰëÄêÖ®¼ä¹ú¼ÊÍøÂç·¸×ï״ΪµÄÖØÒª±ä¶¯£¬£¬£¬£¬£¬£¬£¬²¢¶ÔÀ´Äê×ö³öÁËÔ¤²â¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þ»î¶¯Ôì³ÉÁËÑϳÁµÄ¾¼ÃËðʧ£¬£¬£¬£¬£¬£¬£¬Ë½Óª¹«Ë¾ºÍµ±¾Ö»ú¹¹¶¼Î´ÄÜÐÒÃâ¡£¡£¡£¡£¡£ÔÚ´ËÆÚ¼ä£¬£¬£¬£¬£¬£¬£¬×ܹ²ÓÐÕë¶Ô³¬¹ý45¸ö¹ú¶ÈµÄ500ÂÅ´ÎÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£Æ¾¾ÝGroup-IBµÄÊØ¾É¹À¼Æ£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þÍÅ»ïÔì³ÉµÄ×ܲÆÕþËðʧ³¬¹ý10ÒÚÃÀÔª£¨1005186000ÃÀÔª£©¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬MazeºÍREvilµÄÓ°Ïì×î´ó£¬£¬£¬£¬£¬£¬£¬Õ¼ËùÓй¥»÷µÄ°ëÊýÒÔÉÏ£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇRyuk¡¢NetWalkerºÍDoppelPaymer¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.group-ib.com/media/gib-report-2020/


¾©¹«Íø°²±¸11010802024551ºÅ