ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ48ÖÜ
Ðû²¼Ê±¼ä 2020-11-30> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2020Äê11ÔÂ23ÈÕÖÁ11ÔÂ29ÈÕ¹²ÊÕ¼Çå¾²Îó²î48¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇVmware Workspace One CVE-2020-4006ÏÂÁî×¢ÈëÎó²î£»Shenzhen C-Data 72408AĬÈÏtelnet·þÎñÎó²î£»Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤Îó²î£»Barco wePresent WiPG-1600W¹Ì¼þÐÅϢй¶Îó²î£»Mongodb Server RoleName::parseFromBSON()¾Ü¾ø·þÎñÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÁù¸öÔÂÒÔÀ´Î¢ÈíÈÔδÐÞ¸´Windows10ÖÐÒÑÖªÎó²î£»ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸ÁÐ±í£»VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬ÉÐδÐû²¼²¹¶¡£»Ñо¿Ö°Ô±·¢Ã÷Win7ºÍServer2008ÖеÄÍâµØÌáȨ0day£»Group-IBÐû²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÕ¹ÍûÆÊÎö±¨¸æ¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Vmware Workspace One CVE-2020-4006ÏÂÁî×¢ÈëÎó²î
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿É×¢Èëí§ÒâÏÂÁî²¢Ö´ÐС£
https://docs.opsmanager.mongodb.com/current/release-notes/application/#onprem-server-4-4-3
2.Shenzhen C-Data 72408AĬÈÏtelnet·þÎñÎó²î
Shenzhen C-Data 72408A Telnet·þÎñ±£´æ¶à¸öĬÈÏƾ֤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ»á¼û×°±¸¡£
https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html
3.Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤Îó²î
Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿É×°ÖÃÐ޻ڸĵÄ/¶ñÒâµÄÓ³Ïñ¡£
https://korelogic.com/Resources/Advisories/KL-001-2020-009.txt
4.Barco wePresent WiPG-1600W¹Ì¼þÐÅϢй¶Îó²î
Barco wePresent WiPG-1600W¹Ì¼þÓ³ÏñÖаüÀ¨Ó²±àÂëµÄ¸ùÃÜÂëÉ¢ÁУ¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿Éͨ¹ý´ËÐÅϢδÊÚȨ»á¼û¡£
https://korelogic.com/Resources/Advisories/KL-001-2020-008.txt
5.Mongodb Server RoleName::parseFromBSON()¾Ü¾ø·þÎñÎó²î
Mongodb Server RoleName::parseFromBSON()±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ɾÙÐоܾø·þÎñ¹¥»÷¡£
https://jira.mongodb.org/browse/SERVER-49142
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢Áù¸öÔÂÒÔÀ´Î¢ÈíÈÔδÐÞ¸´Windows10ÖÐÒÑÖªÎó²î
×Ô2020Äê5Ô£¬MicrosoftÐû²¼ÁËWindows 10 2004Çå¾²¸üк󣬷ºÆðÁËÁ½¸öÎó²î£¬µ¼ÖÂSSDÇý¶¯Æ÷µÄ´ÅÅÌËéƬÕûÀí¹ýÓÚƵÈÔ£¬²¢ÔÚ·ÇSSDÇý¶¯Æ÷ÉÏʵÑéTRIM²Ù×÷¡£µÚÒ»¸öÎó²îʹWin10×Ô¶¯Î¬»¤¹¦Ð§ÎÞ·¨¼Ç×ÅÖØÆôϵͳʱÇý¶¯Æ÷µÄ×îºóÓÅ»¯Ê±¼ä£¬µ¼ÖÂÇý¶¯Æ÷ÔÚÿ´ÎÖØÆôÅÌËã»úʱ¶¼¾ÙÐÐËéƬÕûÀí¡£µÚ¶þ¸öÎó²îµ¼ÖÂWin10µÄÓÅ»¯Çý¶¯Æ÷¹¦Ð§»á¶Ô·ÇSSDÇý¶¯Æ÷¾ÙÐÐTRIM£¬Õâ»áµ¼ÖÂÊÂÎñÈÕÖ¾Öйýʧ¡£ÏÖÔÚ£¬ÔÚ½üÁù¸öÔÂÖ®ºó£¬MicrosoftÈÔδÐÞ¸´¸ÃÎó²î¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/windows-10-defrag-trim-bug-still-not-fixed-after-six-months/
2¡¢ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸Áбí
ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸ÁÐ±í£¬ÆäÖаüÀ¨À´×ÔÌìϸ÷µØµÄ´óÐÍÒøÐкÍÕþ¸®×éÖ¯¡£ÕâЩװ±¸Öоù±£´æ·¾¶±éÀúÎó²î£¬±»×·×ÙΪCVE-2018-13379£¬ËüÓ°ÏìÁË´ó×ÚδÐÞ²¹µÄFortinet FortiOS SSL VPN×°±¸¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î£¬´ÓFortinet VPN»á¼ûsslvpn_websessionÎļþÀ´ÇÔÈ¡µÇ¼ƾ֤£¬²¢½«ÆäÓÃÓÚÆÆËðÍøÂç²¢°²ÅÅÀÕË÷Èí¼þ¡£Ö»¹Ü¸ÃÎó²îÔÚÒ»ÄêÇ°¾Í±»¹ûÕæÅû¶£¬µ«ºÚ¿ÍÈÔ·¢Ã÷²¢¹ûÕæÁËÁË49577¸ö±£´æ´ËÀàÎó²îµÄ´óÐÍ×°±¸µÄÁÐ±í¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-posts-exploits-for-over-49-000-vulnerable-fortinet-vpns/
3¡¢VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬ÉÐδÐû²¼²¹¶¡
VMwareÅû¶ÁËÓ°ÏìÆäWorkspace One¶à¸ö×é¼þÖеÄÌáȨ0day£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÌáȨÒÔÔÚLinuxºÍWindows²Ù×÷ϵͳÉÏÖ´ÐÐÏÂÁÏÖÔÚÉÐδÐû²¼Ïà¹Ø²¹¶¡³ÌÐò¡£¸ÃÎó²î±»¸ú×ÙΪCVE-2020-4006£¬CVSSÆ·¼¶Îª9.1£¬ÆäÓ°ÏìÁËVMware Workspace ONE Access¡¢»á¼ûÅþÁ¬Æ÷¡¢Éí·ÝÖÎÀíÆ÷¡¢Éí·ÝÖÎÀíÆ÷ÅþÁ¬Æ÷¡¢VMwareÔÆ»ù½ð»áºÍvRealize SuiteÉúÃüÖÜÆÚÖÎÀíÆ÷¡£ÏÖÔÚ£¬VMwareÒÑÐû²¼ÔÝʱ½â¾ö²½·¥ÒÔÏû³ý¹¥»÷Ç°ÑÔ²¢±ÜÃâÎó²îµÄʹÓá£
ÔÎÄÁ´½Ó£º
https://threatpost.com/vmware-zero-day-patch-pending/161523/
4¡¢Ñо¿Ö°Ô±·¢Ã÷Win7ºÍServer2008ÖеÄÍâµØÌáȨ0day
·¨¹úÑо¿Ö°Ô±·¢Ã÷Windows 7ºÍServer 2008±£´æÍâµØÌáȨ£¨LPE£©0day£¬µ±WindowsÇå¾²¹¤¾ß¸üÐÂʱ»áÓ°ÏìÆä²Ù×÷ϵͳ¡£¸ÃÎó²îλÓÚËùÓÐWindows×°ÖÃÖеÄRPC¶ËµãÓ³ÉäÆ÷ºÍDNSCache·þÎñµÄÁ½¸ö¹ýʧÉèÖõÄ×¢²á±íÏîÖУ¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄÕâЩע²á±íÀ´¼¤»îWindowsÐÔÄܼàÊÓ»úÖÆËùʹÓõÄ×ÓÃÜÔ¿¡£ÏÖÔÚ0patchƽ̨ÒÑÐû²¼ÔÝʱ΢²¹¶¡£¬²¢ÔÚ΢ÈíÐû²¼Õýʽ²¹¶¡Ç°¶ÔËùÓÐÈËÃâ·ÑÌṩ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/windows-7-and-server-2008-zero-day-bug-gets-a-free-patch/
5¡¢Group-IBÐû²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÕ¹ÍûÆÊÎö±¨¸æ
Group-IBÐû²¼Á˶ÔÀ´ÄêÍøÂçÍþвµÄÕ¹ÍûÆÊÎö±¨¸æ£¬Ñо¿ÁË2019ÄêÏ°ëÄêÖÁ2020ÄêÉÏ°ëÄêÖ®¼ä¹ú¼ÊÍøÂç·¸·¨ÐÐΪµÄÖ÷Ҫת±ä£¬²¢¶ÔÀ´Äê×ö³öÁËÕ¹Íû¡£±¨¸æÖ¸³ö£¬ÀÕË÷Èí¼þÔ˶¯Ôì³ÉÁËÑÏÖصľ¼ÃËðʧ£¬Ë½Óª¹«Ë¾ºÍÕþ¸®»ú¹¹¶¼Î´ÄÜÐÒÃâ¡£ÔÚ´Ëʱ´ú£¬×ܹ²ÓÐÕë¶ÔÁè¼Ý45¸ö¹ú¼ÒµÄ500¶à´ÎÀÕË÷Èí¼þ¹¥»÷¡£Æ¾Ö¤Group-IBµÄÊؾÉÔ¤¼Æ£¬ÀÕË÷Èí¼þÍÅ»ïÔì³ÉµÄ×ܲÆÎñËðʧÁè¼Ý10ÒÚÃÀÔª£¨1005186000ÃÀÔª£©¡£ÆäÖУ¬MazeºÍREvilµÄÓ°Ïì×î´ó£¬Õ¼ËùÓй¥»÷µÄ°ëÊýÒÔÉÏ£¬Æä´ÎÊÇRyuk¡¢NetWalkerºÍDoppelPaymer¡£
ÔÎÄÁ´½Ó£º
https://www.group-ib.com/media/gib-report-2020/