ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ37ÖÜ

°ä²¼¹¦·ò 2020-09-14

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê09ÔÂ07ÈÕÖÁ09ÔÂ13ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö  £¬ÖµµÃ¹Ø×¢µÄÊÇSAP Solution ManagerÑéÖ¤²é³­È±Ê§·ì϶ £»Tenda AC18 Router´úÂëÖ´Ðзì϶ £»Android mediaframework CVE-2020-0245´úÂëÖ´Ðзì϶ £»Microsoft ChakraCore CVE-2020-1172ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶ £»Project Worlds Car Rental Management SystemËÁÒâÎļþÉÏ´«·ì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇWhatsAppÅû¶ÆäÀûÓÃÖеÄ6¸ö·ì϶  £¬ÏÖÒѽ¨¸´ £»ÆôÓÃHyper-VµÄWin10ϵͳÖдæÔÚ0day  £¬¿É´´½¨Îļþ £»Î¢Èí°ä²¼9Ô·ݰ²È«¸üР £¬×ܼƽ¨¸´129¸ö·ì϶ £»Adobe°ä²¼°²È«¸üР £¬½¨¸´¶à¿î²úÆ·ÖеÄ12¸ö·ì϶ £»CodeMeterÖдæÔÚÑϳÁ·ì϶  £¬¿Éµ¼ÖÂOT¹©¸øÁ´¹¥»÷¡£


ƾ¾ÝÒÔÉÏ×ÛÊö  £¬±¾Öܰ²È«ÍþвΪÖС£


³ÁÒª°²È«·ì϶Áбí


1.SAP Solution ManagerÑéÖ¤²é³­È±Ê§·ì϶


SAP Solution Manager´æÔÚÑéÖ¤²é³­È±Ê§·ì϶  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó  £¬Î´ÊÚȨ½ÚÔì½Ó¼ûÀûÓá£

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700


2. Tenda AC18 Router´úÂëÖ´Ðзì϶


Tenda AC18 Router /usr/lib/lua/lua/ngx_authserver/ngx_wdasÖеÄlogincheck£¨£©º¯ÊýµÄÉí·ÝÑéÖ¤´¦ÖôæÔÚ·ì϶  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó  £¬Î´ÊÚȨִÐÐËÁÒâ´úÂë¡£

https://www.tendacn.com/en/product/AC18.html


3.Android mediaframework CVE-2020-0245´úÂëÖ´Ðзì϶


Android mediaframework´æÔÚ°²È«·ì϶  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó  £¬ÓÕʹÓû§½âÎö  £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ £»òÕßÒÔϵͳ¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://source.android.com/security/bulletin/2020-09-01


4. Microsoft ChakraCore CVE-2020-1172ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶


Microsoft ChakraCore´æÔÚÄÚ´æ·ÛËé·ì϶  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó  £¬ÓÕʹÓû§½âÎö  £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ £»òÕßÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2020-1172


5. Project Worlds Car Rental Management SystemËÁÒâÎļþÉÏ´«·ì϶


Project Worlds Car Rental Management System³µÍ¼ÏñÉÏ´«×é¼þ´æÔÚ°²È«·ì϶  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó  £¬¿ÉÉÏ´«ËÁÒâÎļþ  £¬²¢Ö´ÐÐËÁÒâ´úÂë¡£


https://github.com/hyd3sec/CarRentalManagement-Unauth-RCE-WebApp


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢WhatsAppÅû¶ÆäÀûÓÃÖеÄ6¸ö·ì϶  £¬ÏÖÒѽ¨¸´


1.jpg


WhatsAppÅû¶ÆäÀûÓÃÖдæÔÚµÄ6¸ö·ì϶  £¬ÏÖÒѽ¨¸´¡£Õâ´Î½¨¸´µÄ·ì϶ÖнÏΪÑϳÁµÄΪ²Ö¿âдÈëÒç¶Âí½Å£¨CVE-2020-1894£©  £¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐÐ  £¬32λÉ豸´æÔÚµÄдÒç¶Âí½Å£¨CVE-2020-1891£©ºÍURLÑéÖ¤ÎÊÌ⣨CVE-2020-1890£©  £¬¿Éµ¼ÖºڿÍÔÚûÓÐÓëÓû§½»»¥µÄÇé¿öÏ´ӷ¢¼þÈ˵ÄURL¼ÓÔØÍ¼Ïñ¡£ÆäËû·ì϶Ϊ°²È«¼ì²âÈÆ¹ýÎÊÌ⣨CVE-2020-1889µÄ£©¡¢»º³åÇøÒç¶Âí½Å£¨CVE-2020-1886£©ºÍÊäÈëÑéÖ¤ÎÊÌ⣨CVE-2019-11928£©¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/107950/security/whatsapp-undisclosed-flaws.html


2¡¢ÆôÓÃHyper-VµÄWin10ϵͳÖдæÔÚ0day  £¬¿É´´½¨Îļþ


2.jpg


ÄæÏò¹¤³ÌʦJonas LykkegaardÔÚÆôÓÃÁËHyper-VµÄWindows 10ϵͳÖз¢ÏÖÁËÒ»¸öеÄ0day  £¬¸Ã·ì϶¿É±»ÀûÓÃÔÚÊÜÓ°ÏìµÄ²Ù×÷ϵͳÖд´½¨Îļþ¡£ÔÚHyper-V´¦Óڻ״̬ʱ  £¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚ\ system32Öд´½¨Îļþ  £¬²¢ÇÒ²»±ØÒª½øÐÐÌáȨ¡£ÓÉÓÚÎļþµÄ´´½¨ÕßÒ²ÊÇËùÓÐÕß  £¬Òò¶ø¹¥»÷ÕßÄܹ»Ê¹ÓøÃÎļþ½«¶ñÒâ´úÂë×¢ÈëϵͳÄÚ²¿  £¬²¢ÔÚ±ØÒªÊ±Ê¹ÓÃÌáÉýµÄȨÏÞÖ´ÐиöñÒâ´úÂë¡£CERT/CC·ì϶·ÖÎöʦWill Dormann  °µÊ¾  £¬¹¥»÷ÕßÏÕЩ²»±ØÒª×öÈκÎÖÂÁ¦±ãÄܹ»ÀûÓø÷ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/windows-10-sandbox-activation-enables-zero-day-vulnerability/


3¡¢Î¢Èí°ä²¼9Ô·ݰ²È«¸üР £¬×ܼƽ¨¸´129¸ö·ì϶


3.jpg


΢Èí°ä²¼ÁË9Ô·ݰ²È«¸üР £¬×ܼƽ¨¸´129¸ö·ì϶  £¬ÆäÖÐÔ̺¬23¸öÑϳÁ·ì϶¡£Ö»¹ÜÕâ´Î¸üÐÂÖв¢Ã»ÓÐ0day  £¬µ«ÈÔÓкܶà·ì϶¿É±»Ô¶³ÌÀûÓá£Õâ´Î½¨¸´µÄ¾ÍΪÑϳÁµÄÈý¸ö·ì϶±ðÀëΪMicrosoft ExchangeÄÚ´æ°Ü»µ·ì϶£¨CVE-2020-16875£©  £¬Ô¶³Ì¹¥»÷ÕßÀûÓø÷ì϶Äܹ»½öͨ¹ýÏòExchange·þÎñÆ÷·¢ËÍÌØÔìµç×ÓÓʼþÔ¶³ÌÖ´ÐдúÂë  £¬WindowsÔ¶³ÌÖ´ÐдúÂëµÄMicrosoft COM·ì϶£¨CVE-2020-0922£©  £¬Äܹ»Í¨¹ýÓÕʹÓû§½Ó¼û´øÓжñÒâJavaScriptµÄÕ¾µãÀ´¼ÓÒÔÀûÓà  £¬ÒÔ¼°WindowsÎı¾·þÎñÄ£¿éÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-0908£©  £¬Äܹ»Í¨¹ýÓÕʹÓû§½Ó¼ûÔ̺¬¶ñÒâ¸æ°×µÄÍøÕ¾À´¼ÓÒÔÀûÓá£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2020-patch-tuesday-fixes-129-vulnerabilities/


4¡¢Adobe°ä²¼°²È«¸üР £¬½¨¸´¶à¿î²úÆ·ÖеÄ12¸ö·ì϶


4.jpg


Adobe°ä²¼°²È«¸üР £¬Òѽ¨¸´Ó°ÏìÆäAdobe InDesign¡¢Adobe FramemakerºÍAdobe Experience Manager²úÆ·ÖеÄ12¸ö´úÂëÖ´Ðзì϶¡£Õâ´Î¸üн¨¸´ÁËAdobe InDesignÖÐÒòÄÚ´æ°Ü»µµ¼ÖµÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-9727¡¢CVE-2020-9728¡¢CVE-2020-9729¡¢CVE-2020-9730ºÍCVE-2020-9731£©  £¬FramemakerÖÐÔ½½ç¶ÁÈ¡µ¼ÖµĴúÂëÖ´Ðзì϶£¨CVE-2020-9726£©ºÍ»ùÓÚ²Ö¿âµÄ»º³åÇøÒç³öµÄ´úÂëÖ´Ðзì϶£¨CVE-2020-9725 £©  £¬ÒÔ¼°Experience ManagerÖеĶà¸öXSS·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-vulnerabilities-in-indesign-and-framemaker/


5¡¢CodeMeterÖдæÔÚÑϳÁ·ì϶  £¬¿Éµ¼ÖÂOT¹©¸øÁ´¹¥»÷


5.jpg


Claroty·¢ÏÖÎ÷ÃÅ×ӵȶ¥¼¶ICS¹©¸øÉÌʹÓõĵÚÈý·½¹¤Òµ×é¼þCodeMeterÖдæÔÚ6¸öÑϳÁµÄ·ì϶  £¬»ò½«µ¼ÖÂOT¹©¸øÁ´¹¥»÷  £¬ÕâЩ·ì϶µÄCVSSÆÀ·Ö¾ùΪ10.0¡£CISA°µÊ¾  £¬¹¥»÷Õ߳ɹ¦ÀûÓÃÕâЩ·ì϶ºó¿É¸ü¸ÄºÍαÔìÐí¿ÉÖ¤Îļþ  £¬µ¼Ö»ؾø·þÎñÇé¿ö  £¬Ç±ÔÚµØÊµÏÖÔ¶³ÌÖ´ÐдúÂë¡¢¶ÁÈ¡¶ÑÊý¾Ý²¢×èÖ¹ÒÀÀµCodeMeterµÄµÚÈý·½Èí¼þµÄÕý³£ÔËÐС£ÆäÖÐ×îÑϳÁµÄ·ì϶¿Éͨ¹ý·ÛËéCodeMeterͨѶºÍ̸ºÍÄÚ²¿APÒÔIÔ¶³ÌÖ´ÐдúÂë  £¬ÊµÏÖICSϵͳµÄÆëÈ«ÊÕÊÜ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/critical-bugs-enable-ot-supply/