ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ10ÖÜ
Ðû²¼Ê±¼ä 2021-03-08> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2021Äê03ÔÂ01ÈÕÖÁ03ÔÂ07ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´60¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Exchange Server CVE-2021-27078Ô¶³Ì´úÂëÖ´ÐЩ¶´£»Google Chrome TabStrip¶ÑÒç³ö´úÂëÖ´ÐЩ¶´£»CGAL libcgal CGAL PM_io_parser::read_vertex()Ô½½ç¶Á¾Ü¾ø·þÎñ©¶´£»Courier Management System MULTIPART street×¢È멶´£»Rockwell Automation WEB½Ó¿Ú¿çÕ¾½Å±¾Â©¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇRockwell AutomationµÄPLC´æÔÚÉí·ÝÑéÖ¤Èƹý©¶´£»ºÚ¿ÍÔÚ°µÍø³öÊÛ3¿îVPNÈí¼þµÄ2100ÍòµÄÓû§Êý¾Ý£»UHSÉù³ÆÈ¥ÄêµÄRyukÀÕË÷¹¥»÷Ôì³É6700ÍòÃÀÔªµÄËðʧ£»SolarWinds¸ß¹Ü³ÆÆäÔâµ½µÄ¹©Ó¦Á´¹¥»÷Ô´ÓÚÈõ¿ÚÁîй¶£»ÂíÀ´Î÷ÑǺ½¿Õ¹«Ë¾³ÆÆä»áÔ±ÐÅÏ¢ÒÑй¶³¤´ï¾ÅÄêÖ®¾Ã¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
> ÖØÒªÄþ¾²Â©¶´Áбí
1.Microsoft Exchange Server CVE-2021-27078Ô¶³Ì´úÂëÖ´ÐЩ¶´
Microsoft Exchange Server´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-27078
2.Google Chrome TabStrip¶ÑÒç³ö´úÂëÖ´ÐЩ¶´
Google Chrome TabStrip´æÔÚ¶ÑÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄWEBÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://chromereleases.googleblog.com/2021/03/stable-channel-update-for-desktop.html
3.CGAL libcgal CGAL PM_io_parser::read_vertex()Ô½½ç¶Á¾Ü¾ø·þÎñ©¶´
Laurent Rineau CGAL PM_io_parser::read_vertex()´æÔÚÔ½½ç¶Á©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½Í߽⡣
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1225
4.Courier Management System MULTIPART street×¢È멶´
SourceCodester Courier Management System MULTIPART street×ֶδ¦ÖôæÔÚSQL×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄSQLÇëÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.exploit-db.com/exploits/49242
5.Rockwell Automation WEB½Ó¿Ú¿çÕ¾½Å±¾Â©¶´
Rockwell Automation WEB½Ó¿Ú´æÔÚ¿çÕ¾½Å±¾Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴עÈë¶ñÒâ½Å±¾»òHTML´úÂ룬µ±¶ñÒâÊý¾Ý±»¼ì²ìʱ£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»ò½Ù³ÖÓû§»á»°¡£
https://www.suse.com/support/update/announcement/2020/suse-su-202014502-1/
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢Rockwell AutomationµÄPLC´æÔÚÉí·ÝÑéÖ¤Èƹý©¶´
Ñо¿ÈËÔ±·¢ÏÖRockwell AutomationµÄ¿É±à³ÌÂß¼¿ØÖÆÆ÷£¨PLC£©ÖдæÔÚÉí·ÝÑéÖ¤Èƹý©¶´¡£¸Ã©¶´±»×·×ÙΪCVE-2021-22681£¬CVSSÆÀ·ÖΪ10£¬Æä´æÔÚÓÚLogix DesignerÈí¼þÖУ¬ÊÇÓÉÓÚÑéÖ¤¿ØÖÆÆ÷ͨÐŵÄ˽ÓÐÃÜÔ¿±£»¤²»×ãµ¼Öµġ£Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÀûÓø鶴ÈƹýÑéÖ¤»úÖÆÀ´Á¬½ÓLogix¿ØÖÆÆ÷¡£´ËÍ⣬ÀûÓôË©¶´ºÍµÚÈý·½¹¤¾ß»¹Äܸü¸Ä¿ØÖÆÆ÷µÄÅäÖúÍÓ¦Ó÷¨Ê½´úÂë¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/115085/ics-scada/rockwell-automation-software-flaw.html
2¡¢ºÚ¿ÍÔÚ°µÍø³öÊÛ3¿îVPNÈí¼þµÄ2100ÍòµÄÓû§Êý¾Ý
ºÚ¿ÍÔÚ°µÍø³öÊÛ3¿îAndroid VPN·þÎñ£¨SuperVPN¡¢GeckoVPNºÍChatVPN£©µÄÓû§Æ¾¾ÝºÍÉ豸Êý¾Ý£¬×ܹ²Éæ¼°2100ÍòÓû§¡£Ð¹Â¶µÄÓû§ÐÅÏ¢°üÂÞµç×ÓÓʼþµØÖ·¡¢Óû§Ãû¡¢ÐÕÃû¡¢¹úÃû¡¢Ëæ»úÉú³ÉµÄÃÜÂë×Ö·û´®¡¢¸¶¿îÏà¹Ø×ÊÁϺ͸߼¶»áÔ±Éí·Ý¼°ÆäÓÐЧÆڵȣ¬É豸Êý¾Ý°üÂÞÉ豸ÐòÁкš¢ÊÖ»úÀàÐͺÍÖÆÔìÉÌ¡¢É豸IDºÍÉ豸IMSI±àºÅµÈ¡£´ËÍ⣬¹¥»÷ÕßÉù³ÆÒÑ»ñµÃ¶ÔVPN·þÎñÆ÷µÄÔ¶³Ì·ÃÎÊȨÏÞ£¬Ä¿Ç°³öÊÛ¼Û¸ñδ֪¡£
ÔÎÄÁ´½Ó£º
https://cybernews.com/security/one-of-the-biggest-android-vpns-hacked-data-of-21-million-users-from-3-android-vpns-put-for-sale-online/
3¡¢UHSÉù³ÆÈ¥ÄêµÄRyukÀÕË÷¹¥»÷Ôì³É6700ÍòÃÀÔªµÄËðʧ
Universal Health Services£¨UHS£©Éù³ÆÈ¥Äê9ÔµÄRyukÀÕË÷¹¥»÷¸øÆäÔì³ÉÁË6700ÍòÃÀÔªµÄËðʧ¡£UHSµÄ×Ó¹«Ë¾±é¼°ÃÀ¹ú38¸öÖÝ£¬ÓµÓÐ26¼Ò¼±ÕïÒ½ÔºÒÔ¼°42¼ÒÃÅÕïÉèÊ©ºÍÃÅÕï·þÎñÖÐÐÄ£¬Òò´ËÍøÂç¹¥»÷µÄÓ°ÏìÉîÔ¶¡£¸Ã¹«Ë¾ÌåÏÖ£¬´ó²¿ÃÅÓ°ÏìÓëÆä¼±Õï·þÎñÓйأ¬ÀýÈçÒò»¼Õ߻¼õÉÙÒÔ¼°Ïà¹ØµÄÕʵ¥ÑÓ³Ù¶øµ¼ÖµÄÓªÒµÊÕÈëµÄËðʧ¡£´ËÍ⣬IT·þÎñÌṩÉÌCognizantºÍÂÁÉú²úÉÌNorsk HydroÈ¥ÄêÒ²Åû¶ÁËÀàËƵÄʼþ£¬Ëðʧ·Ö±ð¸ß´ï7000ÍòÃÀÔªºÍ4000ÍòÃÀÔª¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/universal-health-services-lost-67-million-due-to-ryuk-ransomware-attack/
4¡¢SolarWinds¸ß¹Ü³ÆÆäÔâµ½µÄ¹©Ó¦Á´¹¥»÷Ô´ÓÚÈõ¿ÚÁîй¶
Èí¼þ¹«Ë¾SolarWindsµÄÒ»Ãû¸ß¹Ü³ÆÆäÔâµ½¹©Ó¦Á´¹¥»÷µÄ»ù´¡ÔÒòÊÇÒ»ÃûʵϰÉúʹÓÃÁËÈõÃÜÂë¡£³õ·¨Ê½²éÏÔʾ£¬×Ô2018Äê6ÔÂ17ÈÕÒÔÀ´£¬ÅäÖôíÎóµÄGitHub´æ´¢¿âй¶ÁËÃÜÂësolarwinds123£¬¸ÃÎÊÌâÒÑÔÚ2019Äê11ÔÂ22ÈÕ½â¾ö£¬¶ø×î³õµÄ¹¥»÷¿ÉÄÜ·¢ÉúÓÚ2019Äê9ÔÂ4ÈÕ¡£¸Ã¹«Ë¾µÄCEOÌåÏÖ£¬Õâ¿ÉÄÜÊÇÒ»ÃûʵϰÉúÓÚ2017ÄêÔÚËûµÄһ̨·þÎñÆ÷ÉÏʹÓõÄÃÜÂ룬²¢Ë½×Ô½«ÃÜÂëÐû²¼µ½ÁËÆäÄÚ²¿Github˽ÈËÕÊ»§ÉÏ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/115134/security/solarwinds-intern-solarwinds123-password-leak.html
5¡¢ÂíÀ´Î÷ÑǺ½¿Õ¹«Ë¾³ÆÆä»áÔ±ÐÅÏ¢ÒÑй¶³¤´ï¾ÅÄêÖ®¾Ã
ÂíÀ´Î÷ÑǺ½¿Õ¹«Ë¾³ÆÆäEnrich³£Âÿͼƻ®ÖлáÔ±µÄ¸öÈËÐÅÏ¢ÒÑй¶³¤´ï¾ÅÄêÖ®¾Ã¡£¸Ã¹«Ë¾ÌåÏÖÆäÊÕµ½À´×ÔµÚÈý·½IT·þÎñÌṩÉ̵Ä֪ͨ£¬Ö¸³ö¸Ã¹«Ë¾ÔÚ2010Äê3ÔÂÖÁ2019Äê6ÔÂÆڼ䷢ÉúÁËÊý¾Ýй¶£¬Ð¹Â¶µÄÊý¾Ý°üÂÞ»áÔ±µÄÃû³Æ¡¢ÁªÏµÐÅÏ¢¡¢³öÉúÈÕÆÚ¡¢ÐԱ𡢳£ÂÿͺÅÂ롢״̬ºÍ½±ÀøÆ·¼¶¡£Ä¿Ç°Éв»Çå³þÊÜÓ°Ïì»áÔ±µÄ·¶Î§£¬¸Ã¹«Ë¾Ò²Î´Ðû²¼¸ü¶àÓйش˴ÎʼþµÄÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/malaysia-airlines-discloses-a-nine-year-long-data-breach/