ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ35ÖÜ
°ä²¼¹¦·ò 2021-08-30>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê08ÔÂ23ÈÕÖÁ08ÔÂ29ÈÕ¹²ÊÕ¼°²È«·ì϶60¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇFlatCore-CMS upload addon²å¼þ´úÂëÖ´ÐЩ£»£»£»£»£»£»NASCENT RemKon Device Manager assets/index.phpËÁÒâ´úÂëÉÏ´«·ì϶£»£»£»£»£»£»Teamviewer TVS½âÎöÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶£»£»£»£»£»£»RaspAP raspap-webguiÌØÈ¨ÌáÉý·ì϶£»£»£»£»£»£»SolarWinds Web Help Desk referrerαÔì½Ó¼ûÏÞ¶ÈÈÆ¹ý·ì϶¡£¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÐÂ¼ÓÆÂ·¿µØ²ú¹«Ë¾OrangeTeeÔâµ½ALTDOSµÄÀÕË÷¹¥»÷£»£»£»£»£»£»HuntressÔÚ1900̨Exchange¼ì²âµ½140¶àÖÖWeb shell£»£»£»£»£»£»Razer SynapseÖеı¾µØÌáȨ0dayÓ°Ï쳬¹ý1ÒÚÓû§£»£»£»£»£»£»SAM·¢ÏÖMiraiÀûÓÃRealtek SDKÖзì϶µÄ¹¥»÷»î¶¯£»£»£»£»£»£»OpenSSL°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´²úÆ·ÖеÄ2¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£¡£¡£
>³ÁÒª°²È«·ì϶Áбí
1.Google chrome V8 CVE-2021-30598ÀàÐÍ»ìºÏ´úÂëÖ´Ðзì϶
FlatCore-CMS upload addon²å¼þ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://github.com/flatCore/flatCore-CMS/issues/52
2.NASCENT RemKon Device Manager assets/index.phpËÁÒâ´úÂëÉÏ´«·ì϶
NASCENT RemKon Device Manager assets/index.phpͼÏñÉÏ´«Ö°ÄÜ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÉÏ´«ËÁÒâÎļþ²¢ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://www.blacklanternsecurity.com/2021-08-23-Nascent-RemKon-CVEs/
3.Teamviewer TVS½âÎöÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶
Teamviewer TVS½âÎö´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-1003/
4.RaspAP raspap-webguiÌØÈ¨ÌáÉý·ì϶
RaspAP raspap-webgui´æÔÚ²»°²È«µÄsudoersȨÏÞ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬»ñµÃROOTȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£
https://github.com/RaspAP/raspap-webgui/blob/fabc48c7daae4013b9888f266332e510b196a062/installers/raspap.sudoers
5.SolarWinds Web Help Desk referrerαÔì½Ó¼ûÏÞ¶ÈÈÆ¹ý·ì϶
SolarWinds Web Help Desk referrerαÔì´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÈÆ¹ýÏÞ¶ÈδÊÚȨ½Ó¼û¡£¡£¡£¡£¡£¡£¡£¡£
https://www.solarwinds.com/trust-center/security-advisories/cve-2021-32076
>³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÐÂ¼ÓÆÂ·¿µØ²ú¹«Ë¾OrangeTeeÔâµ½ALTDOSµÄÀÕË÷¹¥»÷

8ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÐÂ¼ÓÆÂ·¿µØ²ú¹«Ë¾OrangeTee GroupÔÚÆä¹ÙÍøÉϰ䲼ÉêÃ÷³ÆÆäÔâµ½Á˹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£8ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ïALTDOSÐû³ÆËüÃÇ×Ô2021Äê6ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬Ò»ÏòÔÚÇÔÈ¡¸Ã¹«Ë¾µÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÒÑ»ñµÃÁËÀ´×ÔACSystem¡¢NewOrangeTee¡¢OT_Analytics¡¢OT_LeaveºÍProjInfoListingµÄ969¸öÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£¡£Í¬ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬OrangeTee¹«Ë¾°µÊ¾Æä²»»áÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/singapore-real-estate-firm-breached-by-altdos/
2¡¢HuntressÔÚ1900̨Exchange¼ì²âµ½140¶àÖÖWeb shell

ÉÏÖÜÎ壬£¬£¬£¬£¬£¬£¬£¬°²È«¹«Ë¾Huntress Labs³Æ½ü2000̨Microsoft ExchangeÓʼþ·þÎñÆ÷ÔÚ´Óǰ¼¸ÌìÄÚÔâµ½ºÚ¿Í¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ProxyShellÊÇ3¸ö·ì϶CVE-2021-34473¡¢CVE-2021-34523ºÍCVE-2021-31207µÄͳ³Æ¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ÔÚProxyShell¸ÅÏëÑéÖ¤´úÂë°ä²¼ºó²»¾Ã³öÏÖÁËÓйØÉ¨Ãè»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬Ö±µ½ÉÏÖÜÄ©Ôì³ÉÁËÏÖʵ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Òѱ»ÈëÇÖµÄ1900¶ą̀Exchange·þÎñÆ÷Éæ¼°µ½µÄ×éÖ¯Ô̺¬¹¹ÖþÔì×÷ÉÌ¡¢º£Ïʼӹ¤³§¡¢¹¤Òµ»úе¹«Ë¾¡¢Æû³µÎ¬½¨µêºÍÓ×ÐÍ»ú³¡µÈ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/almost-2000-exchange-servers-hacked-using-proxyshell-exploit/
3¡¢Razer SynapseÖеı¾µØÌáȨ0dayÓ°Ï쳬¹ý1ÒÚÓû§

×êÑÐÈËÔ±jonhatÓÚ2021Äê8ÔÂ21ÈÕÔÚTwitterÉÏÅû¶ÁËRazer SynapseÖеı¾µØÌáȨ0dayµÄϸ½Ú¡£¡£¡£¡£¡£¡£¡£¡£RazerÊÇÒ»¼ÒÍÆËã»ú±íÉèÔì×÷ÉÌ£¬£¬£¬£¬£¬£¬£¬£¬Ðû³ÆÆäRazer SynapseÒѱ»È«Çò³¬¹ý1ÒÚÓû§Ê¹Óᣡ£¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸ö±¾µØÌáȨ£¨LPE£©·ì϶£¬£¬£¬£¬£¬£¬£¬£¬½«RazerÉ豸²åÈëWindows 10ʱ£¬£¬£¬£¬£¬£¬£¬£¬ÏµÍ³»á×Ô¶¯ÏÂÔØ²¢×°ÖÃÇý¶¯·¨Ê½ºÍRazer Synapse£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚRazerInstaller.exeÊÇͨ¹ýSYSTEMȨÏÞµÄWindows¹ý³ÌÆô¶¯µÄ£¬£¬£¬£¬£¬£¬£¬£¬Òò¶øÆäÒ²»ñµÃÁËSYSTEMȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£Ö®ºóÔÚÑ¡Ôñ×°ÖÃÎļþ¼Ðʱ£¬£¬£¬£¬£¬£¬£¬£¬°´ÏÂShift²¢ÓÒ¼üµ¥»÷¶Ô»°¿ò£¬£¬£¬£¬£¬£¬£¬£¬¾ÍÄܹ»´ò¿ªSYSTEMȨÏÞµÄPowerShell´°¿Ú¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/razer-bug-lets-you-become-a-windows-10-admin-by-plugging-in-a-mouse/
4¡¢SAM·¢ÏÖMiraiÀûÓÃRealtek SDKÖзì϶µÄ¹¥»÷»î¶¯

°²È«¹«Ë¾SAM SeamlessÓÚ8ÔÂ19ÈÕ³ÆÆä·¢ÏÖÁ˽©Ê¬ÍøÂçMiraiÀûÓÃRealtek SDKÖзì϶µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ΪÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¬£¬£¬£¬£¬£¬£¬£¬×·×ÙΪCVE-2021-20090£¬£¬£¬£¬£¬£¬£¬£¬ÆÀ·ÖΪ9.8·Ö£¬£¬£¬£¬£¬£¬£¬£¬RealtekÒÑÓÚ8ÔÂ13ÈÕ°ä²¼¸Ã·ì϶µÄ²¹¶¡·¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£SAM°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇÓÚ8ÔÂ18ÈÕÔÚÒ°·¢ÏÖÁËÕâ´Î·ì϶ÀûÓû£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Ô´ÓÚ31.210.20[.]100£¬£¬£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÕßµÄIPµØÖ·¿ÉÄÜ»áËæ×Ź¦·ò¶øÅ¤×ª¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securingsam.com/realtek-vulnerabilities-weaponized/
5¡¢OpenSSL°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´²úÆ·ÖеÄ2¸ö°²È«·ì϶

OpenSSLÓÚ8ÔÂ24ÈÕ°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´Æä²úÆ·ÖеÄ2¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ×îΪÑϳÁµÄÊÇ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬×·×ÙΪCVE-2021-3711£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÆä¿Éµ¼ÖÂÀûÓ÷¨Ê½±ÀÀ£¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÓëSM2¼ÓÃÜÊý¾ÝµÄ½âÃܹý³ÌÓйأ¬£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´¸ü¸Ä¶ÑÖеÄÊý¾Ý£¨¼´Í´´¦£©¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄÁíÒ»¸ö·ì϶׷×ÙΪCVE-2021-3712£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶´¥·¢»Ø¾ø·þÎñ(DoS)£¬£¬£¬£¬£¬£¬£¬£¬»¹¿ÉÄܵ¼Ö»úÃÜÐÅϢй¶£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈç˽Կ»òÃô¸ÐÃ÷ÎÄ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/121426/hacking/cve-2021-3711-openssl-flaws.html


¾©¹«Íø°²±¸11010802024551ºÅ