ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ48ÖÜ

Ðû²¼Ê±¼ä 2020-11-30

> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö


2020Äê11ÔÂ23ÈÕÖÁ11ÔÂ29ÈÕ¹²ÊÕ¼Çå¾²Îó²î48¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇVmware Workspace One CVE-2020-4006ÏÂÁî×¢ÈëÎó²î£»Shenzhen C-Data 72408AĬÈÏtelnet·þÎñÎó²î£»Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤Îó²î£»Barco wePresent WiPG-1600W¹Ì¼þÐÅϢй¶Îó²î£»Mongodb Server RoleName::parseFromBSON()¾Ü¾ø·þÎñÎó²î¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÁù¸öÔÂÒÔÀ´Î¢ÈíÈÔδÐÞ¸´Windows10ÖÐÒÑÖªÎó²î£»ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸Áбí£»VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬ÉÐδÐû²¼²¹¶¡£»Ñо¿Ö°Ô±·¢Ã÷Win7ºÍServer2008ÖеÄÍâµØÌáȨ0day£»Group-IBÐû²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÕ¹ÍûÆÊÎö±¨¸æ¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£


Ö÷ÒªÇå¾²Îó²îÁбí


1.Vmware Workspace One CVE-2020-4006ÏÂÁî×¢ÈëÎó²î


VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿É×¢Èëí§ÒâÏÂÁî²¢Ö´ÐС£

https://docs.opsmanager.mongodb.com/current/release-notes/application/#onprem-server-4-4-3


2.Shenzhen C-Data 72408AĬÈÏtelnet·þÎñÎó²î


Shenzhen C-Data 72408A Telnet·þÎñ±£´æ¶à¸öĬÈÏƾ֤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ»á¼û×°±¸¡£

https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html


3.Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤Îó²î


Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿É×°ÖÃÐ޻ڸĵÄ/¶ñÒâµÄÓ³Ïñ¡£

https://korelogic.com/Resources/Advisories/KL-001-2020-009.txt


4.Barco wePresent WiPG-1600W¹Ì¼þÐÅϢй¶Îó²î


Barco wePresent WiPG-1600W¹Ì¼þÓ³ÏñÖаüÀ¨Ó²±àÂëµÄ¸ùÃÜÂëÉ¢ÁУ¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿Éͨ¹ý´ËÐÅϢδÊÚȨ»á¼û¡£

https://korelogic.com/Resources/Advisories/KL-001-2020-008.txt


5.Mongodb Server RoleName::parseFromBSON()¾Ü¾ø·þÎñÎó²î


Mongodb Server RoleName::parseFromBSON()±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ɾÙÐоܾø·þÎñ¹¥»÷¡£

https://jira.mongodb.org/browse/SERVER-49142


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Áù¸öÔÂÒÔÀ´Î¢ÈíÈÔδÐÞ¸´Windows10ÖÐÒÑÖªÎó²î


1.jpg


×Ô2020Äê5Ô£¬MicrosoftÐû²¼ÁËWindows 10 2004Çå¾²¸üк󣬷ºÆðÁËÁ½¸öÎó²î£¬µ¼ÖÂSSDÇý¶¯Æ÷µÄ´ÅÅÌËéƬÕûÀí¹ýÓÚƵÈÔ£¬²¢ÔÚ·ÇSSDÇý¶¯Æ÷ÉÏʵÑéTRIM²Ù×÷¡£µÚÒ»¸öÎó²îʹWin10×Ô¶¯Î¬»¤¹¦Ð§ÎÞ·¨¼Ç×ÅÖØÆôϵͳʱÇý¶¯Æ÷µÄ×îºóÓÅ»¯Ê±¼ä£¬µ¼ÖÂÇý¶¯Æ÷ÔÚÿ´ÎÖØÆôÅÌËã»úʱ¶¼¾ÙÐÐËéƬÕûÀí¡£µÚ¶þ¸öÎó²îµ¼ÖÂWin10µÄÓÅ»¯Çý¶¯Æ÷¹¦Ð§»á¶Ô·ÇSSDÇý¶¯Æ÷¾ÙÐÐTRIM£¬Õâ»áµ¼ÖÂÊÂÎñÈÕÖ¾Öйýʧ¡£ÏÖÔÚ£¬ÔÚ½üÁù¸öÔÂÖ®ºó£¬MicrosoftÈÔδÐÞ¸´¸ÃÎó²î¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/windows-10-defrag-trim-bug-still-not-fixed-after-six-months/


2¡¢ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸Áбí


2.jpg


ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸Áбí£¬ÆäÖаüÀ¨À´×ÔÌìϸ÷µØµÄ´óÐÍÒøÐкÍÕþ¸®×éÖ¯¡£ÕâЩװ±¸Öоù±£´æ·¾¶±éÀúÎó²î£¬±»×·×ÙΪCVE-2018-13379£¬ËüÓ°ÏìÁË´ó×ÚδÐÞ²¹µÄFortinet FortiOS SSL VPN×°±¸¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î£¬´ÓFortinet VPN»á¼ûsslvpn_websessionÎļþÀ´ÇÔÈ¡µÇ¼ƾ֤£¬²¢½«ÆäÓÃÓÚÆÆËðÍøÂç²¢°²ÅÅÀÕË÷Èí¼þ¡£Ö»¹Ü¸ÃÎó²îÔÚÒ»ÄêÇ°¾Í±»¹ûÕæÅû¶£¬µ«ºÚ¿ÍÈÔ·¢Ã÷²¢¹ûÕæÁËÁË49577¸ö±£´æ´ËÀàÎó²îµÄ´óÐÍ×°±¸µÄÁбí¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-posts-exploits-for-over-49-000-vulnerable-fortinet-vpns/


3¡¢VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬ÉÐδÐû²¼²¹¶¡


3.jpg


VMwareÅû¶ÁËÓ°ÏìÆäWorkspace One¶à¸ö×é¼þÖеÄÌáȨ0day£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÌáȨÒÔÔÚLinuxºÍWindows²Ù×÷ϵͳÉÏÖ´ÐÐÏÂÁÏÖÔÚÉÐδÐû²¼Ïà¹Ø²¹¶¡³ÌÐò¡£¸ÃÎó²î±»¸ú×ÙΪCVE-2020-4006£¬CVSSÆ·¼¶Îª9.1£¬ÆäÓ°ÏìÁËVMware Workspace ONE Access¡¢»á¼ûÅþÁ¬Æ÷¡¢Éí·ÝÖÎÀíÆ÷¡¢Éí·ÝÖÎÀíÆ÷ÅþÁ¬Æ÷¡¢VMwareÔÆ»ù½ð»áºÍvRealize SuiteÉúÃüÖÜÆÚÖÎÀíÆ÷¡£ÏÖÔÚ£¬VMwareÒÑÐû²¼ÔÝʱ½â¾ö²½·¥ÒÔÏû³ý¹¥»÷Ç°ÑÔ²¢±ÜÃâÎó²îµÄʹÓá£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/vmware-zero-day-patch-pending/161523/


4¡¢Ñо¿Ö°Ô±·¢Ã÷Win7ºÍServer2008ÖеÄÍâµØÌáȨ0day


4.jpg


·¨¹úÑо¿Ö°Ô±·¢Ã÷Windows 7ºÍServer 2008±£´æÍâµØÌáȨ£¨LPE£©0day£¬µ±WindowsÇå¾²¹¤¾ß¸üÐÂʱ»áÓ°ÏìÆä²Ù×÷ϵͳ¡£¸ÃÎó²îλÓÚËùÓÐWindows×°ÖÃÖеÄRPC¶ËµãÓ³ÉäÆ÷ºÍDNSCache·þÎñµÄÁ½¸ö¹ýʧÉèÖõÄ×¢²á±íÏîÖУ¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄÕâЩע²á±íÀ´¼¤»îWindowsÐÔÄܼàÊÓ»úÖÆËùʹÓõÄ×ÓÃÜÔ¿¡£ÏÖÔÚ0patchƽ̨ÒÑÐû²¼ÔÝʱ΢²¹¶¡£¬²¢ÔÚ΢ÈíÐû²¼Õýʽ²¹¶¡Ç°¶ÔËùÓÐÈËÃâ·ÑÌṩ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/windows-7-and-server-2008-zero-day-bug-gets-a-free-patch/


5¡¢Group-IBÐû²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÕ¹ÍûÆÊÎö±¨¸æ


5.jpg


Group-IBÐû²¼Á˶ÔÀ´ÄêÍøÂçÍþвµÄÕ¹ÍûÆÊÎö±¨¸æ£¬Ñо¿ÁË2019ÄêÏ°ëÄêÖÁ2020ÄêÉÏ°ëÄêÖ®¼ä¹ú¼ÊÍøÂç·¸·¨ÐÐΪµÄÖ÷Ҫת±ä£¬²¢¶ÔÀ´Äê×ö³öÁËÕ¹Íû¡£±¨¸æÖ¸³ö£¬ÀÕË÷Èí¼þÔ˶¯Ôì³ÉÁËÑÏÖصľ­¼ÃËðʧ£¬Ë½Óª¹«Ë¾ºÍÕþ¸®»ú¹¹¶¼Î´ÄÜÐÒÃâ¡£ÔÚ´Ëʱ´ú£¬×ܹ²ÓÐÕë¶ÔÁè¼Ý45¸ö¹ú¼ÒµÄ500¶à´ÎÀÕË÷Èí¼þ¹¥»÷¡£Æ¾Ö¤Group-IBµÄÊؾÉÔ¤¼Æ£¬ÀÕË÷Èí¼þÍÅ»ïÔì³ÉµÄ×ܲÆÎñËðʧÁè¼Ý10ÒÚÃÀÔª£¨1005186000ÃÀÔª£©¡£ÆäÖУ¬MazeºÍREvilµÄÓ°Ïì×î´ó£¬Õ¼ËùÓй¥»÷µÄ°ëÊýÒÔÉÏ£¬Æä´ÎÊÇRyuk¡¢NetWalkerºÍDoppelPaymer¡£


Ô­ÎÄÁ´½Ó£º

https://www.group-ib.com/media/gib-report-2020/