ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ33ÖÜ

°ä²¼¹¦·ò 2019-08-26

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö



2019Äê8ÔÂ19ÈÕÖÁ25ÈÕ¹²ÊÕ¼°²È«·ì϶46¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇForcepoint Next Generation FirewallÃÜÂëÑéÖ¤ÈÆ¹ý·ì϶ £»Aspose Aspose.Cells LabelSst´úÂëÖ´Ðзì϶ £»Cisco Small Business 220ϵÁÐÖÇÄÜ»¥»»»úÔ¶³Ì´úÂëÖ´Ðзì϶ £»IBM DB2 High Performance UnloadȨÏÞÌáÉý·ì϶ £»Google Nest Cam IQ Indoor Weave PASE½âÎöÖ°ÄÜÐÅϢй¶·ì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ΢ÈíÈ·ÈÏWindows10 1903¸üдæÔÚÃýÎó0x80073701 £»ÏµÍ³ÖÎÀíÔ±¹¤¾ßWebmin´æÔÚ0day·ì϶¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ £»ÃÀ¹úµÂ¿ËÈøË¹ÖÝ23¸öµ±¾Ö»ú¹¹ÔâÀÕË÷Èí¼þ¹¥»÷ £»¹È¸è¡¢Mozilla¼°Æ»¹û½ûÓùþÈø¿Ë˹̹µ±¾ÖÐû¸æµÄ¸ùÖ¤Êé £»¿¨°Í˹»ù°ä²¼2019Äê¹¤ÒµÍøÂ簲ȫÇé¿ö»ã±¨¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


> ³ÁÒª°²È«·ì϶Áбí



1. Forcepoint Next Generation FirewallÃÜÂëÑéÖ¤ÈÆ¹ý·ì϶


Forcepoint Next Generation Firewall LDAPÑéÖ¤²½Öè´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÈÆ¹ýÃÜÂëÑéÖ¤£¬½Ó¼ûÊܱ £»¤·þÎñ¡£
https://support.forcepoint.com/KBArticle?id=000017474

2. Aspose Aspose.Cells LabelSst´úÂëÖ´Ðзì϶


Aspose Cells labelSst record parser´æÔÚÔ½½ç¶Á·ì϶£¬ÔÊÐíδÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄXLSÒªÇó£¬ÓÕʹÓû§½âÎö£¬Äܹ»Óû§¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0794

3. Cisco Small Business 220ϵÁÐÖÇÄÜ»¥»»»úÔ¶³Ì´úÂëÖ´Ðзì϶


Cisco Small Business 220ϵÁÐÖÇÄÜ»¥»»»ú¶ÁÈ¡Êý¾Ýµ½ÄÚ²¿»º³åÇøÊ±´æÔÚ»º³åÇøÒç³ö¹¥»÷£¬ÔÊÐíδÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ROOTȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190806-sb220-rce

4. IBM DB2 High Performance UnloadȨÏÞÌáÉý·ì϶


IBM DB2 High Performance Unload´¦ÖÃPATH´æÔÚ°²È«·ì϶£¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ɼÓÔØ¶ñÒâ¹²Ïí¿â£¬ÌáÉýȨÏÞ¡£
https://www-01.ibm.com/support/docview.wss?uid=ibm10964592

5. Google Nest Cam IQ Indoor Weave PASE½âÎöÖ°ÄÜÐÅϢй¶·ì϶


Google Nest Cam IQ Indoor Weave PASE½âÎöÖ°ÄÜ´æÔÚÐÅϢй¶·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄweave±¨ÎÄÒªÇ󣬿ɽÚÔìÉ豸¡£
https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0798


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö



1¡¢Î¢ÈíÈ·ÈÏWindows10 1903¸üдæÔÚÃýÎó0x80073701


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


MicrosoftÒÑÈ·ÈÏËûÃÇÔÚ½¨¸´Óû§ÔÚ×°ÖÃеÄv1903¸üÐÂʱÊÕµ½µÄ0x80073701ÃýÎó¡£ÔÚ2019Äê8Ô²¹¶¡ÐÇÆÚ¶þ¸üа䲼ºó£¬Óû§ÆðÍ·»ã±¨ËûÃÇÔÚ³¢ÊÔ×°ÖÃWindows 10°æ±¾1903ÀÛ»ý¸üÐÂʱÊÕµ½ÃýÎó¡£¹ÌÈ»´óÎÞÊýÓû§»ã±¨Åú×¢ÎÊÌâʼÓÚ8ÔÂ13ÈÕ£¬µ«Î¢Èí°µÊ¾£¬ÔÚ°ä²¼2019Äê5ÔÂ29ÈÕKB4497935  ÀÛ»ý¸üÐÂʱ£¬ÎÊÌâÏÖʵÉÏÒѾ­³öÏÖ¡£Ä¿Ç°Éв»Ã÷ÏÔÈκν«À´µÄ½¨¸´·¨Ê½ÊÇ·ñÒ²½«½âÎöÓû§ÔÚ½Ó¹ÜµÄÆäËûÃýÎó´úÂë¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-windows-10-1903-update-error-0x80073701-working-on-fix/

2¡¢ÏµÍ³ÖÎÀíÔ±¹¤¾ßWebmin´æÔÚ0day·ì϶¿ÉÖÂÔ¶³Ì´úÂëÖ´ÐÐ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ê¢ÐеÄϵͳÖÎÀíÔ±¹¤¾ßWebminÔÚ³ÁÖÃÃÜÂëÖ°ÄÜÖз¢ÏÖÁËÒ»¸öÃýÎ󣬸ÃÃýÎóÔÊÐí¶ñÒâµÚÈý·½ÓÉÓÚ¶ÌȱÊäÈëÑéÖ¤¶øÖ´ÐжñÒâ´úÂë¡££¬ÒÑÖªÔÚ¶Ë¿Ú10000ÉÏÔËÐУ¬²¢ÇÒÓ°Ïì×îа汾1.920£¬WebminÉÐδ°ä²¼¹«¿ªÉêÃ÷»ò²¹¶¡£¬Ä¿Ç°»¥ÁªÍøÉϹ«¿ªµÄWebminÖÁÉÙ³¬¹ý13Íò¸ö¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.firosolutions.com/exploits/webmin/

3¡¢ÃÀ¹úµÂ¿ËÈøË¹ÖÝ23¸öµ±¾Ö»ú¹¹ÔâÀÕË÷Èí¼þ¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÉÏÖÜÎåµÂ¿ËÈøË¹Öݶà´ï23¼ÒʵÌå»ú¹¹-ÆäÖдóÎÞÊýÊÇ´¦Ëùµ±¾Ö-Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µÂ¿ËÈøË¹ÖݹÙÔ±³ÆÕâÊÇÒ»¸öµ¥Ò»¹¥»÷ÕßÌáÒéµÄÕë¶ÔÐÔ¹¥»÷µÄÒ»²¿ÃÅ¡£½ØÖÁÖÜÁùÍí£¬µÂ¿ËÈøË¹ÖÝÐÅÏ¢×ÊÔ´²¿£¨DIR£©°µÊ¾Ó¦¼±ÏìÓ¦ÍŶÓÕý»ý¼«ÓëËùÓÐ23¸öʵÌåºÏ×÷£¬Ê¹Æäϵͳ³ÁÐÂÉÏÏߣ¬²¢Çҵ¿ËÈøË¹ÖݵÄϵͳºÍÍøÂç²»»áÊܵ½Ó°Ï졣Ŀǰ¾ßÌå¹¥»÷ϸ½ÚÒÀÈ»²»¼°£¬DIRҲûÓÐÆÀÂÛÄÄЩϵͳ³öÏÖ¹ÊÕÏ¡¢ÏµÍ³ÈôºÎ±»Ï°È¾ÒÔ¼°¾ßÌåµÄÊê½ðÊý¶î¡£


Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/coordinated-ransomware-attack-hits-23-texas-government-agencies/147457/

4¡¢¹È¸è¡¢Mozilla¼°Æ»¹û½ûÓùþÈø¿Ë˹̹µ±¾ÖÐû¸æµÄ¸ùÖ¤Êé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹È¸è¡¢Mozilla¼°Æ»¹û½ûÓùþÈø¿Ë˹̹µ±¾ÖÓÚÉϸöÔÂÐû¸æµÄ¸ùÖ¤Ê飬¸ÃÖ¤ÊéÓÃÓÚ¼à¿Ø¹«ÃñµÄÉÏÍøÁ÷Á¿¡£Æäʱ¹þÈø¿Ë˹̹µ±¾ÖÒªÇó¸Ã¹úISPºÏ×÷£¬Ç¿ÔìÔÚËùÓÐÍøÂçÓû§ÖÐ×°ÖøøùÖ¤Êé¡£´Ë¿Ìµ±Chrome¡¢Firefox¼°Safari¼ì²âµ½¸Ã¸ùÖ¤Êéʱ£¬½«×èÖ¹ÏνӲ¢ÏÔʾÃýÎóÐÅÏ¢¡£¹þÈø¿Ë˹̹µ±¾ÖÒѾ­ÔÚ8Ô³õÖÕ³¡ÁËÕâÒ»´òË㣬һÃû¹ÙÔ±°µÊ¾Õû¸ö´òËãÖ»Êǵ±¾ÖµÄÒ»¸ö²âÊÔ¡£µ«ÈÔº±¼û°ÙÍòÉ豸ÈÔÔÚʹÓøÃÖ¤Êé¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/kazakhstan-root-certificate.html

5¡¢¿¨°Í˹»ù°ä²¼2019Äê¹¤ÒµÍøÂ簲ȫÇé¿ö»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù¶Ô282¼ÒÔËÐÐOT/ICSϵͳµÄÆóÒµ½øÐе÷ÑУ¬Õû¶Ù²¢°ä²¼ÁË¡¶2019Äê¹¤ÒµÍøÂ簲ȫÇé¿ö¡·»ã±¨¡£Æ¾¾Ý¸Ã»ã±¨£¬È¥Ä곬¹ýÒ»°ë£¨52%£©µÄ¹¤¿Ø°²È«ÊÂÎñÊÇÓɱ¨´ðʧÎóµ¼ÖµÄ¡£¹ÌÈ»¾ø´óÎÞÊý¹«Ë¾£¨81£¥£©´òËã½øÐÐÍøÂçÊý×Ö»¯ÔËÓªÒÔÍÆ¶¯¹¤Òµ4.0£¬µ«·ÖÅäÁËÍøÂ簲ȫԤËãµÄÈ´Éٵöࣨ57£¥£©¡£³ý´ËÖ®±í£¬ÕâЩ¹«Ë¾µÄÍøÂ簲ȫ¼¼ÊõÒÀÈ»ÁîÈËÓÇÓô£ºÊÜ·ÃÕßµÄÁ½´óÓÇÓô¼¯ÖÐÔÚûÓÐ×ã¹»µÄÍøÂ簲ȫר¼ÒÀ´ÖÎÀí¹¤ÒµÍøÂ磬ÒÔ¼°OT/ICS²Ù×÷Ô±ÆÕ±é²»×㰲ȫÒâʶ¡£

Ô­ÎÄÁ´½Ó£ºhttps://ics.kaspersky.com/the-state-of-industrial-cybersecurity-2019/