΢ÈíÖÒ¸æAdob??e Type Manager¿âÖеÄÁ½¸öRCE 0day£»Lenovo½¨¸´Ô¤×°ÖÃÈí¼þVantageÖеÄÌáȨ·ì϶

°ä²¼¹¦·ò 2020-03-24

1.΢ÈíÖÒ¸æAdobe Type Manager¿âÖеÄÁ½¸öRCE 0day


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



΢Èí°ä²¼°²È«²¼¸æ£¬ÖÒ¸æWindows Adobe Type Manager¿âÖеÄÁ½¸öRCE 0day£¬ÕâÁ½¸ö·ì϶ӰÏìÁ˵±Ç°ËùÓÐÊÜÖ§³ÖµÄWindowsºÍWindows Server°æ±¾ ¡£·ì϶´æÔÚÓÚAdobe Type Manager¿â´¦ÖÃAdobe Type 1 PostScript×ÖÌåÌåʽµÄ·½Ê½ÖУ¬¹¥»÷ÕßÄܹ»Í¨¹ý¶àÖÖ·½Ê½ÀûÓô˷ì϶£¬ÀýÈç˵·þÓû§´ò¿ª¶ñÒâÎĵµ»òÔÚWindowsÔ¤ÀÀ´°¸ñÖв鿴Ëü ¡£Î¢ÈíÒѾ­·¢ÏÖÀûÓô˷ì϶µÄÓÐÏÞÕë¶ÔÐÔ¹¥»÷ ¡£½¨ÒéÔÚWindows×ÊÔ´ÖÎÀíÆ÷ÖнûÓá°Ô¤ÀÀ´°¸ñ¡±ºÍ¡°¾ßÌåÐÅÏ¢´°¸ñ¡±£¬ÒÔ¼õÇáÀûÓ÷çÏÕ£¬Áí±íÁ½¸ö»º½â´ëÊ©ÊǽûÓÃWebClient·þÎñºÍ³Á¶¨Ãû¡°ATMFD.DLL¡± ¡£


Ô­ÎÄÁ´½Ó£º

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200006


2.¼¸ÄÚÑÇÒé»áÑ¡¾Ùǰ»¥ÁªÍøÖжÏ£¬ÁªÍøÂʽöΪ12%


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝNetBlocks»¥ÁªÍø¹Û²âÕ¾µÄÍøÂçÊý¾Ý£¬3ÔÂ20ÈÕ¼¸ÄÚÑǹ²ºÍ¹úµÄ»¥ÁªÍø±»¶Â½Ø£¬¸Ã¹ú¶ÈÔ­¶¨ÓÚ3ÔÂ22ÈÕ£¨ÐÇÆÚÈÕ£©½øÐÐÒé»áÑ¡¾ÙºÍÏÜ·¨¹«Í¶ ¡£¼¼ÊõÖ¸±êÏÔʾ£¬¸Ã¹ú¶ÈËùÓÐ6¸öÍøÂç¾ùÒѹعأ¨Ô̺¬ÖØÒªÔËÓªÉÌOrangeÔÚÄÚ£©£¬»¥ÁªÍøÏνÓˮƽ½öΪƽÈÕµÄ12%£¬·äÎÑÍøÂçºÍ¹ÌÍøÒ²Êܵ½ÀàËÆµÄÓ°Ïì ¡£´Ë±í£¬¼¸ÄÚÑÇÓÚ3ÔÂ21ÈÕ£¨ÐÇÆÚÁù£©ÍíÉÏ8:00ÆðÍ·¹Ø±ÕÉ罻ýÌ壬Ô̺¬Twitter¡¢FacebookºÍInstagram¾ù±»¹Ø±Õ£¬WhatApp·þÎñÆ÷Ò²Êܵ½²¿ÃÅÏÞ¶È ¡£¹Ø±ÕÒ»Ïò³ÖÐøÁË36¸öÓ×ʱ£¬Ö±µ½3ÔÂ23ÈÕ£¨ÐÇÆÚÒ»£©ÉÏÎç8:00²Å½â½û ¡£


Ô­ÎÄÁ´½Ó£º

https://netblocks.org/reports/internet-cut-across-guinea-ahead-of-elections-xAGoQxAz


3.Ameren SiouxºÍLabadieµç³§µÄ¹©¸øÉÌÔâÀÕË÷Èí¼þ¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úÃÜËÕÀïÖÝAmeren SiouxºÍLabadieµç³§µÄÉ豸¹©¸øÉÌ£¨LTI Power Systems£©ÔâÀÕË÷Èí¼þ¹¥»÷£¬²¿ÃÅÊý¾ÝÎļþ±»ÇÔ ¡£ÕâЩÎļþÔ̺¬Á½¼Òµç³§µÄÉ豸ͼºÍʾÒâͼ£¬ÀýÈç²»¼ä¶ÏµçÔ´É豸µÄ¾ßÌåµÀÀíͼ£¬¸ÃÉ豸ÓÃÓÚÔÚÖÐ¶ÏÆÚ¼äÌṩһʱ±¸ÓõçÔ´ ¡£Ê¥Â·Ò×˹¹«¹²¹ã²¥µç̨³ÆÕâЩÊý¾ÝÎļþµÄ¹¦·òÔÚ1996ÄêÖÁ2017ÄêÖ®¼ä ¡£ÎļþÖÐËÆºõ²»Éæ¼°¿Í»§ÐÅÏ¢ ¡£»ªÊ¢¶Ù´óÑ§ÍøÂ簲ȫսÊõ´òËãµÄÕÆ¹ÜÈËÇÇ¡¤ÉáÀÕ£¨Joe Scherrer£©°µÊ¾£¬¸Ã¹¥»÷µÄÖ÷ÕÅÖØÒªÊÇΪÁËÇÔȡ֪ʶ²úȨ ¡£Ameren½²»°È˰µÊ¾¸Ã¹«Ë¾ÔÚ¶Ô´ËÊÂÎñ½øÐе÷²é£¬²¢²¹³ä³ÆÃ»ÓÐÀíÓÉÒÔΪй¶µÄÊý¾ÝÉæ¼°»úÃÜ»ò¶ÔÆäÔËÓªÖÁ¹Ø³ÁÒª ¡£


Ô­ÎÄÁ´½Ó£º

https://news.stlpublicradio.org/post/ameren-missouri-equipment-supplier-targeted-ransomware-attack#stream/0


4.ÑÀÂò¼Ó¹ú¶ÈÒøÐÐÔâÀÕË÷Èí¼þ¹¥»÷£¬²¿ÃÅ·þÎñÖжÏ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÑÀÂò¼Ó¹ú¶ÈÒøÐÐÔâÀÕË÷Èí¼þ¹¥»÷£¬¾¯·½ÔÚ½øÐе÷²é ¡£¸ÃÒøÐаµÊ¾¹¥»÷²úÉúÔÚ3ÔÂ14ÈÕÐÇÆÚÁù£¬¶ÔÆä·þÎñÔì³ÉÁËһЩÖжÏ£¬µ«ÓÉÓÚÕË»§ÊÇÓɵ¥¶ÀµÄϵͳ±£ÁôºÍ±£»¤µÄ£¬Òò¶øÃ»Óпͻ§ÕÊ»§Êܵ½Ó°Ïì ¡£ÆäÐÅÏ¢¼¼ÊõºÍÍøÂ簲ȫÍŶӵ±¼´²ÉÈ¡Ðж¯¶ôÔìÁ˶ñÒâÈí¼þ£¬²¢ÊÔͼȷ¶¨¹¥»÷Ô´ ¡£Ä¿Ç°Æä·þÎñ¸ù»ùÉÏÒѸ´Ô­ÔÚÏߣ¬µ«¸ÃÒøÐÐÈ·ÈϹ¥»÷ÕßÇÔÈ¡Á˲¿ÃÅ»áÔ±ºÍ¿Í»§µÄÊý¾Ý£¬¸ÃÒøÐÐÔÚ²ÉÈ¡´ëʩ֪ͨÊܲ¨¼°µÄÓû§ ¡£ÓÉÓÚ¾¯·½µ÷²é»¹ÔÚ½øÐÐÖУ¬¸ÃÒøÐÐûÓÐй©¸ü¶àÐÅÏ¢ ¡£


Ô­ÎÄÁ´½Ó£º

http://www.jamaicaobserver.com/latestnews/Police_investigate_ransomware_attack_at_Jamaica_National


5.¹¥»÷ÕßÀûÓÃEnigmaSparkÕë¶ÔÖж«£¬ÓëµØÔµÕþÖÎÓйØ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


IBM X-ForceÍŶӷ¢ÏÖ·Ö·¢EnigmaSparkºóÃŵÄй¥»÷»î¶¯£¬¸Ã»î¶¯¿ÉÄܳöÓÚÕþÖζ¯»ú£¬ËƺõÓë·ñ¾ö×î½üµÄÖж«ºÍƽ´òËãÓйØ ¡£¹¥»÷ÕßÊÔͼ¶Ô×¼¶ÔÖж«ºÍƽ´òËãÓгÁ´óÐËÖ»òÌṩ֧³ÖµÄ×éÖ¯/»ú¹¹µÄÍøÂç»·¾³£¬Í¨¹ý¾«ÐÄÔì×÷µÄ¡¢¾ßÌåµÄ¡¢ÓµÓÐÕþÖÎÖ¸¿ØµÄµö¶üÎļþ£¬ÉøÈëÊÕ¼þÈ˵Ļ·¾³²¢½øÐÐÊý¾ÝÇÔÈ¡µÈ¶ñÒâ»î¶¯ ¡£EnigmaSparkµÄµö¶üÎĵµÓëÒÔǰ·Ö·¢JhoneRATµÄµö¶üÎĵµÓµÓÐÆëȫһÑùµÄ±àÒëÈÕÆÚ/¹¦·ò£¨2020-01-14 07:54:00£©£¬²¢ÇÒÔÚTTP¡¢Õë¶ÔÐÔÉ϶¼ÓµÓÐÀàËÆÖ®´¦£¬Òò¶øEnigmaSpark»î¶¯¿ÉÄÜÓëJhoneRATÓйØ£¬²¢ÇÒ¶¼¿ÉÄÜÊôÓÚ·¸×ïÍÅ»ïMolerats ¡£


Ô­ÎÄÁ´½Ó£º

https://securityintelligence.com/posts/EnigmaSpark-Politically-Themed-Cyber-Activity-Highlights-Regional-Opposition-to-Middle-East-Peace-Plan/


6.Lenovo½¨¸´Ô¤×°ÖÃÈí¼þVantageÖеÄÌáȨ·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Lenovo½¨¸´ÆäPCԤװÖÃÈí¼þVantageÖеÄÁ½¸öÌáȨ·ì϶£¨CVE-2020-8319ºÍCVE-2020-8324£© ¡£Vantage×Ô2016Äê×óÓÒ°ä²¼ÒÔÀ´£¬È¡´úÁËLenovo Solutions Center£¨LSC£©³ÉΪLenovoÉ豸µÄÍÆ¼öƽ̨ÖÎÀíºÍϵͳ¸üй¤¾ß ¡£VantageÒÀÀµÓÚϵͳ½Ó¿Ú»ù´¡·þÎñ£¬¸Ã·þÎñͨ¹ý¸´ÔӵIJå¼þϵͳִÐи÷ÀàåÚÏëÌØ¶¨µÄÐÐΪ ¡£ÓÉÓÚûÓжԲå¼þ×ÔÉí¼ÓÔØµÄDLLÖ´ÐÐÖ¤Êé²é³­£¬Òò¶øÄܹ»Í¨¹ý´úÌæTouchScreenContronlDLL.dll»ñµÃSYSTEMȨÏÞ ¡£½¨ÒéÓû§½«Vantage¸üÐÂÖÁ×îа汾 ¡£


Ô­ÎÄÁ´½Ó£º

https://www.pentestpartners.com/security-blog/privesc-in-lenovo-vantage-two-minutes-later/