ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ48ÖÜ
°ä²¼¹¦·ò 2020-11-30> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê11ÔÂ23ÈÕÖÁ11ÔÂ29ÈÕ¹²ÊÕ¼°²È«·ì϶48¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇVmware Workspace One CVE-2020-4006ºÅÁî×¢Èë·ì϶£»Shenzhen C-Data 72408AĬÈÏtelnet·þÎñ·ì϶£»Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤·ì϶£»Barco wePresent WiPG-1600W¹Ì¼þÐÅϢй¶·ì϶£»Mongodb Server RoleName::parseFromBSON()»Ø¾ø·þÎñ·ì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÁù¸öÔÂÒÔÀ´Î¢ÈíÈÔ佨¸´Windows10ÖÐÒÑÖª·ì϶£»ºÚ¿Í¹«¿ª5Íò¸ö´æÔÚ·ì϶µÄFortinet VPNÉ豸ÁÐ±í£»VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬ÉÐδ°ä²¼²¹¶¡£»×êÑÐÈËÔ±·¢ÏÖWin7ºÍServer2008Öеı¾µØÌáȨ0day£»Group-IB°ä²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÔ¤²â·ÖÎö»ã±¨¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
> ³ÁÒª°²È«·ì϶Áбí
1.Vmware Workspace One CVE-2020-4006ºÅÁî×¢Èë·ì϶
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿É×¢ÈëËÁÒâºÅÁî²¢Ö´ÐС£
https://docs.opsmanager.mongodb.com/current/release-notes/application/#onprem-server-4-4-3
2.Shenzhen C-Data 72408AĬÈÏtelnet·þÎñ·ì϶
Shenzhen C-Data 72408A Telnet·þÎñ´æÔÚ¶à¸öĬÈÏÍ´´¦·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉδÊÚȨ½Ó¼ûÉ豸¡£
https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html
3.Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤·ì϶
Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿É×°Öý¨»Ú¸ÄµÄ/¶ñÒâµÄÓ³Ïñ¡£
https://korelogic.com/Resources/Advisories/KL-001-2020-009.txt
4.Barco wePresent WiPG-1600W¹Ì¼þÐÅϢй¶·ì϶
Barco wePresent WiPG-1600W¹Ì¼þÓ³ÏñÖÐÔ̺¬Ó²±àÂëµÄ¸ùÃÜÂëÉ¢ÁУ¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿Éͨ¹ý´ËÐÅϢδÊÚȨ½Ó¼û¡£
https://korelogic.com/Resources/Advisories/KL-001-2020-008.txt
5.Mongodb Server RoleName::parseFromBSON()»Ø¾ø·þÎñ·ì϶
Mongodb Server RoleName::parseFromBSON()´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ɽøÐлؾø·þÎñ¹¥»÷¡£
https://jira.mongodb.org/browse/SERVER-49142
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Áù¸öÔÂÒÔÀ´Î¢ÈíÈÔ佨¸´Windows10ÖÐÒÑÖª·ì϶

×Ô2020Äê5Ô£¬Microsoft°ä²¼ÁËWindows 10 2004°²È«¸üк󣬳öÏÖÁËÁ½¸ö·ì϶£¬µ¼ÖÂSSDÇý¶¯Æ÷µÄ´ÅÅÌË鯬Õû¶Ù¹ýÓÚÆµÈÔ£¬²¢ÔÚ·ÇSSDÇý¶¯Æ÷Éϳ¢ÊÔTRIM²Ù×÷¡£µÚÒ»¸ö·ì϶ʹWin10×Ô¶¯ÊØ»¤Ö°ÄÜÎÞ·¨¼Çס³ÁÆôϵͳʱÇý¶¯Æ÷µÄ×îºóÓÅ»¯¹¦·ò£¬µ¼ÖÂÇý¶¯Æ÷ÔÚÿ´Î³ÁÆôÍÆËã»úʱ¶¼½øÐÐË鯬Õû¶Ù¡£µÚ¶þ¸ö·ì϶µ¼ÖÂWin10µÄÓÅ»¯Çý¶¯Æ÷Ö°ÄÜ»á¶Ô·ÇSSDÇý¶¯Æ÷½øÐÐTRIM£¬Õâ»áµ¼ÖÂÊÂÎñÈÕÖ¾ÖÐÃýÎó¡£Èç½ñ£¬ÔÚ½üÁù¸öÔÂÖ®ºó£¬MicrosoftÈÔ佨¸´¸Ã·ì϶¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/windows-10-defrag-trim-bug-still-not-fixed-after-six-months/
2¡¢ºÚ¿Í¹«¿ª5Íò¸ö´æÔÚ·ì϶µÄFortinet VPNÉ豸Áбí

ºÚ¿Í¹«¿ª5Íò¸ö´æÔÚ·ì϶µÄFortinet VPNÉ豸ÁÐ±í£¬ÆäÖÐÔ̺¬À´×ÔÊÀ½ç¸÷µØµÄ´óÐÍÒøÐк͵±¾Ö×éÖ¯¡£ÕâЩÉ豸Öоù´æÔÚõè¾¶±éÀú·ì϶£¬±»×·×ÙΪCVE-2018-13379£¬ËüÓ°ÏìÁË´óÁ¿Î´½¨²¹µÄFortinet FortiOS SSL VPNÉ豸¡£¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶£¬´ÓFortinet VPN½Ó¼ûsslvpn_websessionÎļþÀ´ÇÔÈ¡µÇ¼ʹ´¦£¬²¢½«ÆäÓÃÓÚ·ÛËéÍøÂç²¢²¿ÊðÀÕË÷Èí¼þ¡£Ö»¹Ü¸Ã·ì϶ÔÚÒ»Äêǰ¾Í±»¹«¿ªÅû¶£¬µ«ºÚ¿ÍÈÔ·¢ÏÖ²¢¹«¿ªÁËÁË49577¸ö´æÔÚ´ËÀà·ì϶µÄ´óÐÍÉ豸µÄÁÐ±í¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-posts-exploits-for-over-49-000-vulnerable-fortinet-vpns/
3¡¢VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬ÉÐδ°ä²¼²¹¶¡

VMwareÅû¶ÁËÓ°ÏìÆäWorkspace One¶à¸ö×é¼þÖеÄÌáȨ0day£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÌáȨÒÔÔÚLinuxºÍWindows²Ù×÷ϵͳÉÏÖ´ÐкÅÁĿǰÉÐδ°ä²¼Óйز¹¶¡·¨Ê½¡£¸Ã·ì϶±»¸ú×ÙΪCVE-2020-4006£¬CVSSµÈ¼¶Îª9.1£¬ÆäÓ°ÏìÁËVMware Workspace ONE Access¡¢½Ó¼ûÏÎ½ÓÆ÷¡¢Éí·ÝÖÎÀíÆ÷¡¢Éí·ÝÖÎÀíÆ÷ÏÎ½ÓÆ÷¡¢VMwareÔÆ»ù½ð»áºÍvRealize SuiteÐÔÃüÖÜÆÚÖÎÀíÆ÷¡£Ä¿Ç°£¬VMwareÒѰ䲼һʱ½â¾ö·¨×ÓÒÔ½â³ý¹¥»÷ý½é²¢Ô¤·À·ì϶µÄÀûÓá£
ÔÎÄÁ´½Ó£º
https://threatpost.com/vmware-zero-day-patch-pending/161523/
4¡¢×êÑÐÈËÔ±·¢ÏÖWin7ºÍServer2008Öеı¾µØÌáȨ0day

·¨¹ú×êÑÐÈËÔ±·¢ÏÖWindows 7ºÍServer 2008´æÔÚ±¾µØÌáȨ£¨LPE£©0day£¬µ±Windows°²È«¹¤¾ß¸üÐÂʱ»áÓ°ÏìÆä²Ù×÷ϵͳ¡£¸Ã·ì϶λÓÚËùÓÐWindows×°ÖÃÖеÄRPC¶ËµãÓ³ÉäÆ÷ºÍDNSCache·þÎñµÄÁ½¸öÃýÎóÅäÖõÄ×¢²á±íÏîÖУ¬¹¥»÷ÕßÄܹ»Í¨¹ýÅú¸ÄÕâЩע²á±íÀ´¼¤»îWindows»úÄܼල»úÔìËùʹÓõÄ×ÓÃÜÔ¿¡£Ä¿Ç°0patchƽ̨ÒѰ䲼һʱ΢²¹¶¡£¬²¢ÔÚ΢Èí°ä²¼Õýʽ²¹¶¡Ç°¶ÔËùÓÐÈËÃâ·ÑÌṩ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/windows-7-and-server-2008-zero-day-bug-gets-a-free-patch/
5¡¢Group-IB°ä²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÔ¤²â·ÖÎö»ã±¨

Group-IB°ä²¼Á˶ÔÀ´ÄêÍøÂçÍþвµÄÔ¤²â·ÖÎö»ã±¨£¬×êÑÐÁË2019ÄêϰëÄêÖÁ2020ÄêÉϰëÄêÖ®¼ä¹ú¼ÊÍøÂç·¸×ï״ΪµÄÖØÒª±ä¶¯£¬²¢¶ÔÀ´Äê×ö³öÁËÔ¤²â¡£»ã±¨Ö¸³ö£¬ÀÕË÷Èí¼þ»î¶¯Ôì³ÉÁËÑϳÁµÄ¾¼ÃËðʧ£¬Ë½Óª¹«Ë¾ºÍµ±¾Ö»ú¹¹¶¼Î´ÄÜÐÒÃâ¡£ÔÚ´ËÆÚ¼ä£¬×ܹ²ÓÐÕë¶Ô³¬¹ý45¸ö¹ú¶ÈµÄ500ÂÅ´ÎÀÕË÷Èí¼þ¹¥»÷¡£Æ¾¾ÝGroup-IBµÄÊØ¾É¹À¼Æ£¬ÀÕË÷Èí¼þÍÅ»ïÔì³ÉµÄ×ܲÆÕþËðʧ³¬¹ý10ÒÚÃÀÔª£¨1005186000ÃÀÔª£©¡£ÆäÖУ¬MazeºÍREvilµÄÓ°Ïì×î´ó£¬Õ¼ËùÓй¥»÷µÄ°ëÊýÒÔÉÏ£¬Æä´ÎÊÇRyuk¡¢NetWalkerºÍDoppelPaymer¡£
ÔÎÄÁ´½Ó£º
https://www.group-ib.com/media/gib-report-2020/


¾©¹«Íø°²±¸11010802024551ºÅ