ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ35ÖÜ

°ä²¼¹¦·ò 2021-08-30

>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö

2021Äê08ÔÂ23ÈÕÖÁ08ÔÂ29ÈÕ¹²ÊÕ¼°²È«·ì϶60¸ö £¬£¬£¬£¬ £¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇFlatCore-CMS upload addon²å¼þ´úÂëÖ´ÐЩ£»£»£»£»£»£»NASCENT RemKon Device Manager assets/index.phpËÁÒâ´úÂëÉÏ´«·ì϶£»£»£»£»£»£»Teamviewer TVS½âÎöÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶£»£»£»£»£»£»RaspAP raspap-webguiÌØÈ¨ÌáÉý·ì϶£»£»£»£»£»£»SolarWinds Web Help Desk referrerαÔì½Ó¼ûÏÞ¶ÈÈÆ¹ý·ì϶¡£¡£¡£¡£¡£ ¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÐÂ¼ÓÆÂ·¿µØ²ú¹«Ë¾OrangeTeeÔâµ½ALTDOSµÄÀÕË÷¹¥»÷£»£»£»£»£»£»HuntressÔÚ1900̨Exchange¼ì²âµ½140¶àÖÖWeb shell£»£»£»£»£»£»Razer SynapseÖеı¾µØÌáȨ0dayÓ°Ï쳬¹ý1ÒÚÓû§£»£»£»£»£»£»SAM·¢ÏÖMiraiÀûÓÃRealtek SDKÖзì϶µÄ¹¥»÷»î¶¯£»£»£»£»£»£»OpenSSL°ä²¼°²È«¸üР£¬£¬£¬£¬ £¬£¬£¬£¬½¨¸´²úÆ·ÖеÄ2¸ö°²È«·ì϶¡£¡£¡£¡£¡£ ¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬£¬£¬£¬ £¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£ ¡£¡£¡£


>³ÁÒª°²È«·ì϶Áбí


1.Google chrome V8 CVE-2021-30598ÀàÐÍ»ìºÏ´úÂëÖ´Ðзì϶


FlatCore-CMS upload addon²å¼þ´æÔÚ°²È«·ì϶ £¬£¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬£¬£¬£¬ £¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£¡£


https://github.com/flatCore/flatCore-CMS/issues/52


2.NASCENT RemKon Device Manager assets/index.phpËÁÒâ´úÂëÉÏ´«·ì϶


NASCENT RemKon Device Manager assets/index.phpͼÏñÉÏ´«Ö°ÄÜ´æÔÚ°²È«·ì϶ £¬£¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬£¬£¬£¬ £¬£¬£¬£¬¿ÉÉÏ´«ËÁÒâÎļþ²¢ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£¡£


https://www.blacklanternsecurity.com/2021-08-23-Nascent-RemKon-CVEs/


3.Teamviewer TVS½âÎöÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶


Teamviewer TVS½âÎö´æÔÚÄÚ´æ·ÛËé·ì϶ £¬£¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó £¬£¬£¬£¬ £¬£¬£¬£¬ÓÕʹÓû§½âÎö £¬£¬£¬£¬ £¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£¡£


https://www.zerodayinitiative.com/advisories/ZDI-21-1003/


4.RaspAP raspap-webguiÌØÈ¨ÌáÉý·ì϶


RaspAP raspap-webgui´æÔÚ²»°²È«µÄsudoersȨÏÞ·ì϶ £¬£¬£¬£¬ £¬£¬£¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬£¬£¬£¬ £¬£¬£¬£¬»ñµÃROOTȨÏÞ¡£¡£¡£¡£¡£ ¡£¡£¡£


https://github.com/RaspAP/raspap-webgui/blob/fabc48c7daae4013b9888f266332e510b196a062/installers/raspap.sudoers


5.SolarWinds Web Help Desk referrerαÔì½Ó¼ûÏÞ¶ÈÈÆ¹ý·ì϶


SolarWinds Web Help Desk referrerαÔì´æÔÚ°²È«·ì϶ £¬£¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬£¬£¬£¬ £¬£¬£¬£¬¿ÉÈÆ¹ýÏÞ¶ÈδÊÚȨ½Ó¼û¡£¡£¡£¡£¡£ ¡£¡£¡£


https://www.solarwinds.com/trust-center/security-advisories/cve-2021-32076


 >³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢ÐÂ¼ÓÆÂ·¿µØ²ú¹«Ë¾OrangeTeeÔâµ½ALTDOSµÄÀÕË÷¹¥»÷


ÐÂ¼ÓÆÂ·¿µØ²ú¹«Ë¾OrangeTeeÔâµ½ALTDOSµÄÀÕË÷¹¥»÷.jpg


8ÔÂ6ÈÕ £¬£¬£¬£¬ £¬£¬£¬£¬ÐÂ¼ÓÆÂ·¿µØ²ú¹«Ë¾OrangeTee GroupÔÚÆä¹ÙÍøÉϰ䲼ÉêÃ÷³ÆÆäÔâµ½Á˹¥»÷¡£¡£¡£¡£¡£ ¡£¡£¡£8ÔÂ12ÈÕ £¬£¬£¬£¬ £¬£¬£¬£¬ºÚ¿ÍÍÅ»ïALTDOSÐû³ÆËüÃÇ×Ô2021Äê6ÔÂÒÔÀ´ £¬£¬£¬£¬ £¬£¬£¬£¬Ò»ÏòÔÚÇÔÈ¡¸Ã¹«Ë¾µÄÊý¾Ý £¬£¬£¬£¬ £¬£¬£¬£¬ÏÖÒÑ»ñµÃÁËÀ´×ÔACSystem¡¢NewOrangeTee¡¢OT_Analytics¡¢OT_LeaveºÍProjInfoListingµÄ969¸öÊý¾Ý¿â¡£¡£¡£¡£¡£ ¡£¡£¡£Í¬ÈÕ £¬£¬£¬£¬ £¬£¬£¬£¬OrangeTee¹«Ë¾°µÊ¾Æä²»»áÖ§¸¶Êê½ð¡£¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/singapore-real-estate-firm-breached-by-altdos/


2¡¢HuntressÔÚ1900̨Exchange¼ì²âµ½140¶àÖÖWeb shell


HuntressÔÚ1900̨Exchange¼ì²âµ½140¶àÖÖWeb shell.jpg


ÉÏÖÜÎå £¬£¬£¬£¬ £¬£¬£¬£¬°²È«¹«Ë¾Huntress Labs³Æ½ü2000̨Microsoft ExchangeÓʼþ·þÎñÆ÷ÔÚ´Óǰ¼¸ÌìÄÚÔâµ½ºÚ¿Í¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£¡£ProxyShellÊÇ3¸ö·ì϶CVE-2021-34473¡¢CVE-2021-34523ºÍCVE-2021-31207µÄͳ³Æ¡£¡£¡£¡£¡£ ¡£¡£¡£×êÑÐÈËÔ±°µÊ¾ £¬£¬£¬£¬ £¬£¬£¬£¬ÔÚProxyShell¸ÅÏëÑéÖ¤´úÂë°ä²¼ºó²»¾Ã³öÏÖÁËÓйØÉ¨Ãè»î¶¯ £¬£¬£¬£¬ £¬£¬£¬£¬Ö±µ½ÉÏÖÜÄ©Ôì³ÉÁËÏÖʵ¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£¡£´Ë±í £¬£¬£¬£¬ £¬£¬£¬£¬Òѱ»ÈëÇÖµÄ1900¶ą̀Exchange·þÎñÆ÷Éæ¼°µ½µÄ×éÖ¯Ô̺¬¹¹ÖþÔì×÷ÉÌ¡¢º£Ïʼӹ¤³§¡¢¹¤Òµ»úе¹«Ë¾¡¢Æû³µÎ¬½¨µêºÍÓ×ÐÍ»ú³¡µÈ¡£¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/almost-2000-exchange-servers-hacked-using-proxyshell-exploit/


3¡¢Razer SynapseÖеı¾µØÌáȨ0dayÓ°Ï쳬¹ý1ÒÚÓû§


Razer SynapseÖеı¾µØÌáȨ0dayÓ°Ï쳬¹ý1ÒÚÓû§.jpg


×êÑÐÈËÔ±jonhatÓÚ2021Äê8ÔÂ21ÈÕÔÚTwitterÉÏÅû¶ÁËRazer SynapseÖеı¾µØÌáȨ0dayµÄϸ½Ú¡£¡£¡£¡£¡£ ¡£¡£¡£RazerÊÇÒ»¼ÒÍÆËã»ú±íÉèÔì×÷ÉÌ £¬£¬£¬£¬ £¬£¬£¬£¬Ðû³ÆÆäRazer SynapseÒѱ»È«Çò³¬¹ý1ÒÚÓû§Ê¹Óᣡ£¡£¡£¡£ ¡£¡£¡£ÕâÊÇÒ»¸ö±¾µØÌáȨ£¨LPE£©·ì϶ £¬£¬£¬£¬ £¬£¬£¬£¬½«RazerÉ豸²åÈëWindows 10ʱ £¬£¬£¬£¬ £¬£¬£¬£¬ÏµÍ³»á×Ô¶¯ÏÂÔØ²¢×°ÖÃÇý¶¯·¨Ê½ºÍRazer Synapse £¬£¬£¬£¬ £¬£¬£¬£¬ÓÉÓÚRazerInstaller.exeÊÇͨ¹ýSYSTEMȨÏÞµÄWindows¹ý³ÌÆô¶¯µÄ £¬£¬£¬£¬ £¬£¬£¬£¬Òò¶øÆäÒ²»ñµÃÁËSYSTEMȨÏÞ¡£¡£¡£¡£¡£ ¡£¡£¡£Ö®ºóÔÚÑ¡Ôñ×°ÖÃÎļþ¼Ðʱ £¬£¬£¬£¬ £¬£¬£¬£¬°´ÏÂShift²¢ÓÒ¼üµ¥»÷¶Ô»°¿ò £¬£¬£¬£¬ £¬£¬£¬£¬¾ÍÄܹ»´ò¿ªSYSTEMȨÏÞµÄPowerShell´°¿Ú¡£¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/razer-bug-lets-you-become-a-windows-10-admin-by-plugging-in-a-mouse/


4¡¢SAM·¢ÏÖMiraiÀûÓÃRealtek SDKÖзì϶µÄ¹¥»÷»î¶¯


SAM·¢ÏÖMiraiÀûÓÃRealtek SDKÖзì϶µÄ¹¥»÷»î¶¯.jpg


°²È«¹«Ë¾SAM SeamlessÓÚ8ÔÂ19ÈÕ³ÆÆä·¢ÏÖÁ˽©Ê¬ÍøÂçMiraiÀûÓÃRealtek SDKÖзì϶µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£ ¡£¡£¡£¸Ã·ì϶ΪÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶ £¬£¬£¬£¬ £¬£¬£¬£¬×·×ÙΪCVE-2021-20090 £¬£¬£¬£¬ £¬£¬£¬£¬ÆÀ·ÖΪ9.8·Ö £¬£¬£¬£¬ £¬£¬£¬£¬RealtekÒÑÓÚ8ÔÂ13ÈÕ°ä²¼¸Ã·ì϶µÄ²¹¶¡·¨Ê½¡£¡£¡£¡£¡£ ¡£¡£¡£SAM°µÊ¾ £¬£¬£¬£¬ £¬£¬£¬£¬ËûÃÇÓÚ8ÔÂ18ÈÕÔÚÒ°·¢ÏÖÁËÕâ´Î·ì϶ÀûÓû £¬£¬£¬£¬ £¬£¬£¬£¬¹¥»÷Ô´ÓÚ31.210.20[.]100 £¬£¬£¬£¬ £¬£¬£¬£¬µ«¹¥»÷ÕßµÄIPµØÖ·¿ÉÄÜ»áËæ×Ź¦·ò¶øÅ¤×ª¡£¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securingsam.com/realtek-vulnerabilities-weaponized/


5¡¢OpenSSL°ä²¼°²È«¸üР£¬£¬£¬£¬ £¬£¬£¬£¬½¨¸´²úÆ·ÖеÄ2¸ö°²È«·ì϶


OpenSSL.png


OpenSSLÓÚ8ÔÂ24ÈÕ°ä²¼°²È«¸üР£¬£¬£¬£¬ £¬£¬£¬£¬½¨¸´Æä²úÆ·ÖеÄ2¸ö°²È«·ì϶¡£¡£¡£¡£¡£ ¡£¡£¡£ÆäÖÐ×îΪÑϳÁµÄÊÇ»º³åÇøÒç¶Âí½Å £¬£¬£¬£¬ £¬£¬£¬£¬×·×ÙΪCVE-2021-3711 £¬£¬£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÆä¿Éµ¼ÖÂÀûÓ÷¨Ê½±ÀÀ£¡£¡£¡£¡£¡£ ¡£¡£¡£¸Ã·ì϶ÓëSM2¼ÓÃÜÊý¾ÝµÄ½âÃܹý³ÌÓÐ¹Ø £¬£¬£¬£¬ £¬£¬£¬£¬¿ÉÓÃÀ´¸ü¸Ä¶ÑÖеÄÊý¾Ý£¨¼´Í´´¦£©¡£¡£¡£¡£¡£ ¡£¡£¡£Õâ´Î½¨¸´µÄÁíÒ»¸ö·ì϶׷×ÙΪCVE-2021-3712 £¬£¬£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶´¥·¢»Ø¾ø·þÎñ(DoS) £¬£¬£¬£¬ £¬£¬£¬£¬»¹¿ÉÄܵ¼Ö»úÃÜÐÅϢй¶ £¬£¬£¬£¬ £¬£¬£¬£¬ÀýÈç˽Կ»òÃô¸ÐÃ÷ÎÄ¡£¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/121426/hacking/cve-2021-3711-openssl-flaws.html