ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ16ÖÜ

Ðû²¼Ê±¼ä 2021-04-19

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê04ÔÂ12ÈÕÖÁ04ÔÂ18ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´56¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Photoshop CVE-2021-28549»º³åÇøÒç³ö´úÂëÖ´ÐЩ¶´£»Google Chrome BlinkÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´£»Apache TapestryÔ¶³Ì´úÂëÖ´ÐЩ¶´£»Microsoft Exchange Server CVE-2021-28483Ô¶³Ì´úÂëÖ´ÐЩ¶´£»SolarWinds Orion PlatformÌØȨÌáÉý©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ°ÍÎ÷½ðÈÚ¹«Ë¾IuguÊý¾Ý¿âÅäÖôíÎóй¶1.7 TBÊý¾Ý£»Ñо¿ÈËÔ±³ÆÁè¼Ý53Íò¸ö»ªÎªÊÖ»úѬȾJoker¶ñÒâÈí¼þ£»BitdefenderÐû²¼2020ÄêÍþв̬Êƺͷ¸×ïÇ÷ÊƵĻع˳ÂËߣ»ForescoutÅû¶ӰÏìÉÏÒŲ́É豸µÄDNS©¶´NAME£ºWRECK£»MicrosoftÐû²¼4Ô²¹¶¡£¬ÐÞ¸´5¸ö0dayÔÚÄÚµÄ108¸ö©¶´¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


> ÖØÒªÄþ¾²Â©¶´Áбí


1.Adobe Photoshop CVE-2021-28549»º³åÇøÒç³ö´úÂëÖ´ÐЩ¶´


Adobe Photoshop´¦ÖÃÎļþ´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://helpx.adobe.com/security/products/photoshop/apsb21-28.html


2.Google Chrome BlinkÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´


Google Chrome Blink´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÒ³ÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»ò¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-411/


3.Apache TapestryÔ¶³Ì´úÂëÖ´ÐЩ¶´


Apache Tapestry´æÔÚÄþ¾²Èƹý©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

http://www.openwall.com/lists/oss-security/2021/04/15/1


4.Microsoft Exchange Server CVE-2021-28483Ô¶³Ì´úÂëÖ´ÐЩ¶´


Microsoft Exchange Server´æÔÚδÃ÷Äþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-28483


5.SolarWinds Orion PlatformÌØȨÌáÉý©¶´


SolarWinds Orion Platform SaveUserSetting´æÔÚȱÏÝ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɰÑguestÓû§ÌáÉýΪ¹ÜÀíÔ±¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-192/


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢°ÍÎ÷½ðÈÚ¹«Ë¾IuguÊý¾Ý¿âÅäÖôíÎóй¶1.7 TBÊý¾Ý


1.jpg


Ñо¿ÈËÔ±Bob DiachenkoÓÚÉÏÖÜÈý·¢ÏÖ£¬°ÍÎ÷½ðÈڿƼ¼IuguÒòÊý¾Ý¿â·þÎñÆ÷ÅäÖôíÎóй¶1.7 TBÊý¾Ý¡£´Ë´Îʼþй¶ÁË´Ó2013Äêµ½2021ÄêµÄÃô¸ÐÊý¾Ý£¬°üÂÞ¿Í»§µç×ÓÓʼþ¡¢Óû§Ãû¡¢µç»°ºÅÂëºÍµØÖ·¡¢½»Ò׼Ǽ¡¢ÎĵµºÍÆäËû²ÆÕþÏêϸÐÅÏ¢µÈ¡£IuguÈ·ÈϸÃÊý¾Ý¿â̻¶ÁËԼĪÁ½¸öСʱ£¬½öй¶Á˱¸·ÝÊý¾ÝÖÐԼĪ1£¥µÄ¿ÉÓÃÐÅÏ¢£¬Ä¿Ç°Ð¹Â¶µÄÊý¾ÝÒѱ»±£»¤ÆðÀ´¡£


Ô­ÎÄÁ´½Ó£º

https://canaltech.com.br/seguranca/vazamento-expoe-17-tb-de-dados-dos-clientes-da-fintech-brasileira-iugu-na-web-182312/


2¡¢Ñо¿ÈËÔ±³ÆÁè¼Ý53Íò¸ö»ªÎªÊÖ»úѬȾJoker¶ñÒâÈí¼þ


2.jpg


Äþ¾²¹«Ë¾Doctor Web³ÆÁè¼Ý53Íò¸ö»ªÎªÊÖ»úÔÚÆä¹Ù·½É̵êAppGalleryÏÂÔØÁËÊÜJoker£¨ÓÖÃûBread£©¶ñÒâÈí¼þѬȾµÄÓ¦Óá£Joker¿É±»ÓÃÀ´Ö´Ðй㷺µÄ¶ñÒâ²Ù×÷£¬°üÂÞ½ûÓÃGoogle Play±£»¤·þÎñ¡¢°²×°¶ñÒâÓ¦Ó÷¨Ê½¡¢Éú³ÉÐé¼ÙÆÀÂÛºÍÏÔʾ¹ã¸æµÈ¡£Éæ¼°µÄÓ¦ÓðüÂÞ°üÂÞÐéÄâ¼üÅÌ¡¢Ïà»ú¡¢Æô¶¯Æ÷¡¢ÔÚÏßMessenger¡¢ÌùÖ½ÊÕ¼¯¡¢×ÅÉ«·¨Ê½ºÍÓÎÏ·µÈ£¬ÆäÖдó¶àÊýÓ¦ÓÃÀ´×ÔÓÚͬһλ¿ª·¢ÈËÔ±£¨É½Î÷¿ìÀ´ÅÄÍøÂç¼¼ÊõÓÐÏÞ¹«Ë¾£©¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116643/malware/huawei-store-joker-malware.html


3¡¢BitdefenderÐû²¼2020ÄêÍþв̬Êƺͷ¸×ïÇ÷ÊƵĻع˳ÂËß


3.jpg


BitdefenderÐû²¼ÁË2020ÄêÍøÂçÍþв̬Êƺͷ¸×ïÇ÷ÊƵĻع˳ÂËß¡£³ÂËßÖ¸³ö£¬ÀÕË÷Èí¼þ¹¥»÷ÔÚÈ«Çò·¶Î§ÄÚ¼¤Ôö485£¥£¬ÔÚ2020ÄêQ1ºÍQ2Õ¼ËùÓй¥»÷µÄ64£¥£»ÖÇÄܵçÊӵĩ¶´ÊýÁ¿Ôö¼ÓÁË338£¥£»NASÉ豸ÖеÄ©¶´ÊýÁ¿Í¬±ÈÔö³¤198£¥¡£´ËÍ⣬ÔÚ¼ì²âµ½µÄËùÓÐAndroid¶ñÒâÈí¼þÖУ¬ÓÐ35£¥À´×ÔAndroid.Trojan.AgentϵÁУ¬Æä´ÎÊÇAndroid.Trojan.Downloader£¨Õ¼10£¥£©ºÍAndroid.Trojan.Banker£¨Õ¼7£¥£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bitdefender.com/files/News/CaseStudies/study/395/Bitdefender-2020-Consumer-Threat-Landscape-Report.pdf


4¡¢ForescoutÅû¶ӰÏìÉÏÒŲ́É豸µÄDNS©¶´NAME£ºWRECK


4.jpg


Äþ¾²¹«Ë¾ForescoutºÍÒÔÉ«ÁÐÄþ¾²ÍŶÓJSOFÁªºÏÅû¶ÁËTCP/IP¶ÑÕ»ÖÐDNSЭÒéÖеÄ9¸öÄþ¾²Â©¶´£¬Í³³ÆΪNAME£ºWRECK£¬Ó°ÏìÁË1ÒÚ¸öÔÚInternetÉÏÔËÐеÄÉ豸¡£¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ©¶´Ê¹É豸ÍÑ»ú»òÕßÍêÈ«¿ØÖÆÉ豸¡£ÕâЩ©¶´ÖÐ×îÑÏÖصÄΪIPnetÖеÄRCE©¶´£¨CVE-2016-20009£©£¬ÑÏÖØÐԵ÷ÖΪ9.8¡£Æä´ÎΪRCE£¨CVE-2020-7461¡¢CVE-2020-15795ºÍCVE-2020-27009£©ºÍDoS£¨CVE-2020-27736ºÍCVE-2020-27737£©µÈ©¶´¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/name-wreck-dns-vulnerabilities-affect-over-100-million-devices/


5¡¢MicrosoftÐû²¼4Ô²¹¶¡£¬ÐÞ¸´5¸ö0dayÔÚÄÚµÄ108¸ö©¶´


5.jpg


MicrosoftÐû²¼ÁË4Ô·ݵÄÖܶþ²¹¶¡£¬×ܼÆÐÞ¸´ÁË°üÂÞ5¸ö0dayÔÚÄÚµÄ108¸ö©¶´¡£´Ë´ÎÐÞ¸´µÄ0day°üÂÞRPC¶ËµãÓ³ÉäÆ÷µÄÌáȨ©¶´£¨CVE-2021-27091£©¡¢NTFS¾Ü¾ø·þÎñ©¶´£¨CVE-2021-28312£©¡¢Windows°²×°·¨Ê½ÖеÄÐÅϢ鶩¶´£¨CVE-2021-28437£©¡¢Azure ms-rest-nodeauth¿âµÄÌáȨ©¶´£¨CVE-2021-28458£©ÒÔ¼°Win32kÖеÄÌáȨ©¶´£¨CVE-2021-28310£©¡£ÆäÖУ¬CVE-2021-28310©¶´ÊÇKasperskyÔÚÒ°·¢Ïֵģ¬Òѱ»APT×éÖ¯BITTERÀûÓá£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2021-patch-tuesday-fixes-108-flaws-5-zero-days/