ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ16ÖÜ
Ðû²¼Ê±¼ä 2021-04-19> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2021Äê04ÔÂ12ÈÕÖÁ04ÔÂ18ÈÕ¹²ÊÕ¼Çå¾²Îó²î56¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Photoshop CVE-2021-28549»º³åÇøÒç³ö´úÂëÖ´ÐÐÎó²î£»£»£»£»Google Chrome BlinkÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»£»Apache TapestryÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»Microsoft Exchange Server CVE-2021-28483Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»SolarWinds Orion PlatformÌØÈ¨ÌáÉýÎó²î¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǰÍÎ÷½ðÈÚ¹«Ë¾IuguÊý¾Ý¿âÉèÖùýʧй¶1.7 TBÊý¾Ý£»£»£»£»Ñо¿Ö°Ô±³ÆÁè¼Ý53Íò¸ö»ªÎªÊÖ»úѬȾJoker¶ñÒâÈí¼þ£»£»£»£»BitdefenderÐû²¼2020ÄêÍþÐ²Ì¬ÊÆºÍ·¸·¨Ç÷ÊÆµÄ»ØÊ×±¨¸æ£»£»£»£»ForescoutÅû¶ӰÏìÉÏÒŲ́װ±¸µÄDNSÎó²îNAME£ºWRECK£»£»£»£»MicrosoftÐû²¼4Ô²¹¶¡£¬£¬£¬£¬£¬ÐÞ¸´5¸ö0dayÔÚÄÚµÄ108¸öÎó²î¡£¡£¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Adobe Photoshop CVE-2021-28549»º³åÇøÒç³ö´úÂëÖ´ÐÐÎó²î
Adobe Photoshop´¦Öóͷ£Îļþ±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/photoshop/apsb21-28.html
2.Google Chrome BlinkÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Google Chrome Blink±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³ÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»ò¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-411/
3.Apache TapestryÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Apache Tapestry±£´æÇå¾²ÈÆ¹ýÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
http://www.openwall.com/lists/oss-security/2021/04/15/1
4.Microsoft Exchange Server CVE-2021-28483Ô¶³Ì´úÂëÖ´ÐÐÎó²î
Microsoft Exchange Server±£´æÎ´Ã÷Çå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-28483
5.SolarWinds Orion PlatformÌØÈ¨ÌáÉýÎó²î
SolarWinds Orion Platform SaveUserSetting±£´æÈ±ÏÝÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿É°ÑguestÓû§ÌáÉýΪÖÎÀíÔ±¡£¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-192/
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢°ÍÎ÷½ðÈÚ¹«Ë¾IuguÊý¾Ý¿âÉèÖùýʧй¶1.7 TBÊý¾Ý

Ñо¿Ö°Ô±Bob DiachenkoÓÚÉÏÖÜÈý·¢Ã÷£¬£¬£¬£¬£¬°ÍÎ÷½ðÈڿƼ¼IuguÒòÊý¾Ý¿âЧÀÍÆ÷ÉèÖùýʧй¶1.7 TBÊý¾Ý¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñй¶ÁË´Ó2013Äêµ½2021ÄêµÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬°üÀ¨¿Í»§µç×ÓÓʼþ¡¢Óû§Ãû¡¢µç»°ºÅÂëºÍµØµã¡¢ÉúÒâ¼Í¼¡¢ÎĵµºÍÆäËû²ÆÎñÏêϸÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£IuguÈ·ÈϸÃÊý¾Ý¿â̻¶ÁËԼĪÁ½¸öСʱ£¬£¬£¬£¬£¬½öй¶Á˱¸·ÝÊý¾ÝÖÐԼĪ1£¥µÄ¿ÉÓÃÐÅÏ¢£¬£¬£¬£¬£¬ÏÖÔÚй¶µÄÊý¾ÝÒѱ»±£»£»£»£»¤ÆðÀ´¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://canaltech.com.br/seguranca/vazamento-expoe-17-tb-de-dados-dos-clientes-da-fintech-brasileira-iugu-na-web-182312/
2¡¢Ñо¿Ö°Ô±³ÆÁè¼Ý53Íò¸ö»ªÎªÊÖ»úѬȾJoker¶ñÒâÈí¼þ

Çå¾²¹«Ë¾Doctor Web³ÆÁè¼Ý53Íò¸ö»ªÎªÊÖ»úÔÚÆä¹Ù·½ÊÐËÁAppGalleryÏÂÔØÁËÊÜJoker£¨ÓÖÃûBread£©¶ñÒâÈí¼þѬȾµÄÓ¦Óᣡ£¡£¡£¡£¡£¡£Joker¿É±»ÓÃÀ´Ö´ÐÐÆÕ±éµÄ¶ñÒâ²Ù×÷£¬£¬£¬£¬£¬°üÀ¨½ûÓÃGoogle Play±£»£»£»£»¤Ð§ÀÍ¡¢×°ÖöñÒâÓ¦ÓóÌÐò¡¢ÌìÉúÐéα̸ÂÛºÍÏÔʾ¹ã¸æµÈ¡£¡£¡£¡£¡£¡£¡£Éæ¼°µÄÓ¦ÓðüÀ¨°üÀ¨ÐéÄâ¼üÅÌ¡¢Ïà»ú¡¢Æô¶¯Æ÷¡¢ÔÚÏßMessenger¡¢ÌùÖ½ÍøÂç¡¢×ÅÉ«³ÌÐòºÍÓÎÏ·µÈ£¬£¬£¬£¬£¬ÆäÖдó´ó¶¼Ó¦ÓÃÀ´×ÔÓÚͳһλ¿ª·¢Ö°Ô±£¨É½Î÷¿ìÀ´ÅÄÍøÂçÊÖÒÕÓÐÏÞ¹«Ë¾£©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/116643/malware/huawei-store-joker-malware.html
3¡¢BitdefenderÐû²¼2020ÄêÍþÐ²Ì¬ÊÆºÍ·¸·¨Ç÷ÊÆµÄ»ØÊ×±¨¸æ

BitdefenderÐû²¼ÁË2020ÄêÍøÂçÍþÐ²Ì¬ÊÆºÍ·¸·¨Ç÷ÊÆµÄ»ØÊ×±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬ÀÕË÷Èí¼þ¹¥»÷ÔÚÈ«Çò¹æÄ£ÄÚ¼¤Ôö485£¥£¬£¬£¬£¬£¬ÔÚ2020ÄêQ1ºÍQ2Õ¼ËùÓй¥»÷µÄ64£¥£»£»£»£»ÖÇÄܵçÊÓµÄÎó²îÊýÄ¿ÔöÌíÁË338£¥£»£»£»£»NAS×°±¸ÖеÄÎó²îÊýĿͬ±ÈÔöÌí198£¥¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ÔÚ¼ì²âµ½µÄËùÓÐAndroid¶ñÒâÈí¼þÖУ¬£¬£¬£¬£¬ÓÐ35£¥À´×ÔAndroid.Trojan.AgentϵÁУ¬£¬£¬£¬£¬Æä´ÎÊÇAndroid.Trojan.Downloader£¨Õ¼10£¥£©ºÍAndroid.Trojan.Banker£¨Õ¼7£¥£©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bitdefender.com/files/News/CaseStudies/study/395/Bitdefender-2020-Consumer-Threat-Landscape-Report.pdf
4¡¢ForescoutÅû¶ӰÏìÉÏÒŲ́װ±¸µÄDNSÎó²îNAME£ºWRECK

Çå¾²¹«Ë¾ForescoutºÍÒÔÉ«ÁÐÇå¾²ÍŶÓJSOFÁªºÏÅû¶ÁËTCP/IP¿ÍÕ»ÖÐDNSÐÒéÖеÄ9¸öÇå¾²Îó²î£¬£¬£¬£¬£¬Í³³ÆÎªNAME£ºWRECK£¬£¬£¬£¬£¬Ó°ÏìÁË1ÒÚ¸öÔÚInternetÉÏÔËÐеÄ×°±¸¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îʹװ±¸ÍÑ»ú»òÕßÍêÈ«¿ØÖÆ×°±¸¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÖÐ×îÑÏÖØµÄΪIPnetÖеÄRCEÎó²î£¨CVE-2016-20009£©£¬£¬£¬£¬£¬ÑÏÖØÐԵ÷ÖΪ9.8¡£¡£¡£¡£¡£¡£¡£Æä´ÎΪRCE£¨CVE-2020-7461¡¢CVE-2020-15795ºÍCVE-2020-27009£©ºÍDoS£¨CVE-2020-27736ºÍCVE-2020-27737£©µÈÎó²î¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/name-wreck-dns-vulnerabilities-affect-over-100-million-devices/
5¡¢MicrosoftÐû²¼4Ô²¹¶¡£¬£¬£¬£¬£¬ÐÞ¸´5¸ö0dayÔÚÄÚµÄ108¸öÎó²î

MicrosoftÐû²¼ÁË4Ô·ݵÄÖܶþ²¹¶¡£¬£¬£¬£¬£¬×ܼÆÐÞ¸´Á˰üÀ¨5¸ö0dayÔÚÄÚµÄ108¸öÎó²î¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ0day°üÀ¨RPC¶ËµãÓ³ÉäÆ÷µÄÌáȨÎó²î£¨CVE-2021-27091£©¡¢NTFS¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2021-28312£©¡¢Windows×°ÖóÌÐòÖеÄÐÅϢй¶Îó²î£¨CVE-2021-28437£©¡¢Azure ms-rest-nodeauth¿âµÄÌáȨÎó²î£¨CVE-2021-28458£©ÒÔ¼°Win32kÖеÄÌáȨÎó²î£¨CVE-2021-28310£©¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬CVE-2021-28310Îó²îÊÇKasperskyÔÚÒ°·¢Ã÷µÄ£¬£¬£¬£¬£¬Òѱ»APT×éÖ¯BITTERʹÓᣡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2021-patch-tuesday-fixes-108-flaws-5-zero-days/


¾©¹«Íø°²±¸11010802024551ºÅ