ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ33ÖÜ

Ðû²¼Ê±¼ä 2021-08-23

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê08ÔÂ09ÈÕÖÁ08ÔÂ15ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´58¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Dynamics CVE-2021-36946¿çÕ¾½Å±¾Â©¶´ £»SAP Business OneÈÎÒâÎļþÉÏ´«´úÂëÖ´ÐЩ¶´ £»SapphireIMSÃüÁî×¢È멶´ £»Adobe Connect CVE-2021-36061Äþ¾²Èƹý©¶´ £»Apache ServiceComb Service-Center CVE-2021-21501·¾¶±éÀú©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÑо¿ÈËÔ±·¢ÏÖÀûÓÃExchangeÖЩ¶´ProxyShellµÄ¹¥»÷»î¶¯ £»Ñо¿ÍŶӷ¢ÏÖÀûÓÃArcadyan¹Ì¼þÖЩ¶´°²×°MiraiµÄ»î¶¯ £»RansomEXXÍÅ»ïÉù³ÆÒÑÇÔÈ¡ÉݳÞÆ·ÅÆZegnaÁè¼Ý20GBÊý¾Ý £»Î¢ÈíÖܶþÄþ¾²¸üУ¬ÐÞ¸´°üÂÞ3¸ö0dayÔÚÄÚµÄ44¸ö©¶´ £»KasperskyÐû²¼2021ÄêQ2À¬»øÓʼþºÍµöÓã»î¶¯µÄ³ÂËß¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£



>ÖØÒªÄþ¾²Â©¶´Áбí


1.Microsoft Dynamics CVE-2021-36946¿çÕ¾½Å±¾Â©¶´


Microsoft Dynamics´æÔÚ¿çÕ¾½Å±¾Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴עÈë¶ñÒâ½Å±¾»òHTML´úÂ룬µ±¶ñÒâÊý¾Ý±»¼ì²ìʱ£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»ò½Ù³ÖÓû§»á»°¡£


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36946



2.SAP Business OneÈÎÒâÎļþÉÏ´«´úÂëÖ´ÐЩ¶´


SAP Business One´æÔÚÈÎÒâÎļþÉÏ´«Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806


3.SapphireIMSÃüÁî×¢È멶´


SapphireIMS´æÔÚÓ²±àÂëºÍÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÈƹýÄþ¾²ÏÞÖÆ£¬Ö´ÐÐÈÎÒâÃüÁî¡£


https://www.sapphireims.com/patches/


4.Adobe Connect CVE-2021-36061Äþ¾²Èƹý©¶´


Adobe Connect´æÔÚÄþ¾²Èƹý©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎÊÓ¦Óá£


https://helpx.adobe.com/security/products/connect/apsb21-66.html


5.Apache ServiceComb Service-Center CVE-2021-21501·¾¶±éÀú©¶´


Apache ServiceComb Service-Center´æÔÚÅäÖôíÎ󩶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɽøÐÐĿ¼±éÀú¹¥»÷£¬»ñÈ¡Ãô¸ÐÐÅÏ¢¡£


https://lists.apache.org/thread.html/r337be65e504eac52a12e89d7de40345e5d335deee9dd7288f7f59b81%40%3Cdev.servicecomb.apache.org%3E


 >ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Ñо¿ÈËÔ±·¢ÏÖÀûÓÃExchangeÖЩ¶´ProxyShellµÄ¹¥»÷»î¶¯


Ñо¿ÈËÔ±·¢ÏÖÀûÓÃExchangeÖЩ¶´ProxyShellµÄ¹¥»÷»î¶¯.jpg


2021 Black Hat´ó»áÉÏͳ³ÆΪProxyShellµÄ3¸ö©¶´µÄϸ½Ú¹ûÈ»ºó£¬Ñо¿ÈËÔ±·¢ÏÖÁË»ý¼«ÀûÓø鶴µÄ»î¶¯¡£ProxyShell°üÂÞACLÈƹý©¶´£¨CVE-2021-34473£©¡¢ Exchange PowerShellºó¶ËµÄÌáȨ©¶´£¨CVE-2021-34523£©ºÍÈÎÒâÎļþдÈëµ¼ÖµÄRCE©¶´£¨CVE-2021-31207£©¡£ÕâЩ©¶´¿ÉÒÔͨ¹ýIISÖеĶ˿Ú443ÉÏÔËÐеÄMicrosoft Exchange¿Í»§¶Ë·ÃÎÊ·þÎñ(CAS)Ô¶³ÌÀûÓ㬽áºÏʹÓÿɽøÐÐδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-servers-scanned-for-proxyshell-vulnerability-patch-now/


2¡¢Ñо¿ÍŶӷ¢ÏÖÀûÓÃArcadyan¹Ì¼þÖЩ¶´°²×°MiraiµÄ»î¶¯


Ñо¿ÍŶӷ¢ÏÖÀûÓÃArcadyan¹Ì¼þÖЩ¶´°²×°MiraiµÄ»î¶¯.jpg


Õ°²©ÍøÂçµÄÑо¿ÍŶÓÔÚ½üÆÚ·¢ÏÖÁËÀûÓÃArcadyan¹Ì¼þÖЩ¶´µÄ¹¥»÷»î¶¯¡£¸Ã©¶´ÊÇ·¾¶±éÀú©¶´£¬×·×ÙΪCVE-2021-20090£¬ÆÀ·ÖΪ9.9¡£´æÔÚÓÚʹÓÃArcadyan¹Ì¼þµÄ·ÓÉÆ÷µÄweb½çÃæÉÏ£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈƹýÉí·ÝÑéÖ¤£¬Ó°ÏìÁËÊýÊ®ÖÖÐͺŵÄÊý°ÙÍǫ̀·ÓÉÆ÷¡£×ÔÉÏÖÜËÄÒÔÀ´£¬Ñо¿ÈËÔ±ÔÚÒ°·¢ÏÖÁËÀûÓôË©¶´µÄ¹¥»÷»î¶¯,Ö¼ÔÚ½Ó¹ÜÄ¿±êÉ豸²¢°²×°½©Ê¬ÍøÂçMiraiµÄpayload¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/actively-exploited-bug-bypasses-authentication-on-millions-of-routers/


3¡¢RansomEXXÍÅ»ïÉù³ÆÒÑÇÔÈ¡ÉݳÞÆ·ÅÆZegnaÁè¼Ý20GBÊý¾Ý


RansomEXXÍÅ»ïÉù³ÆÒÑÇÔÈ¡ÉݳÞÆ·ÅÆZegnaÁè¼Ý20GBÊý¾Ý.jpg


ÀÕË÷ÍÅ»ïRansomEXX½üÆÚÉù³ÆÒÑÇÔÈ¡ÉݳÞÆ·ÅÆZegnaÁè¼Ý20GBÊý¾Ý¡£ZegnaÊÇÒâ´óÀû×îÖøÃûµÄÉݳÞʱװƷÅÆÖ®Ò»£¬ÊÇÈ«ÇòÊÕÈë×î¸ßµÄÄÐ×°Æ·ÅÆ¡£RansomEXX³ÆÒѴӸù«Ë¾ÇÔÈ¡ÁË20.74GBµÄÊý¾Ý£¬²¢Ðû²¼ÁË43¸öÎļþ£¨42¸ö500MBµÄÎļþºÍ1¸ö239.54MBµÄÎļþ£©×÷ΪÑù±¾¡£½üÆÚ£¬RansomEXXÍÅ»ïÔøѬȾÁËÒâ´óÀûÀ­Æë°Â´óÇøµÄϵͳ£¬²¢¹¥»÷ÁËÖйų́ÍåµÄ¼ÆËã»úÓ²¼þÖÆÔìÉ̼¼¼Î£¨GIGABYTE£©¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120898/data-breach/ransomexx-ransomware-zegna.html


4¡¢Î¢ÈíÖܶþÄþ¾²¸üУ¬ÐÞ¸´°üÂÞ3¸ö0dayÔÚÄÚµÄ44¸ö©¶´


΢ÈíÖܶþÄþ¾²¸üУ¬ÐÞ¸´°üÂÞ3¸ö0dayÔÚÄÚµÄ44¸ö©¶´.jpg


΢ÈíÐû²¼2021Äê8ÔµÄÖܶþÄþ¾²¸üУ¬×ܼÆÐÞ¸´ÁË44¸ö©¶´¡£ÆäÖаüÂÞ13¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´¡¢8¸öÐÅϢ鶩¶´¡¢2¸ö¾Ü¾ø·þÎñ©¶´ºÍ4¸öÆÛƭ©¶´¡£´Ë´ÎÐÞ¸´µÄ3¸ö0dayΪWindows Print SpoolerÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-36936£©¡¢ Windows LSAÖеÄÆÛƭ©¶´£¨CVE-2021-36942£©ÒÔ¼°Windows Update Medic·þÎñÖеÄÌáȨ©¶´£¨CVE-2021-36948£©¡£´ËÍ⣬Ñо¿ÈËÔ±ÒѾ­·¢ÏÖÖ÷¶¯ÀûÓÃCVE-2021-36948µÄ¹¥»÷»î¶¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2021-patch-tuesday-fixes-3-zero-days-44-flaws/


5¡¢KasperskyÐû²¼2021ÄêQ2À¬»øÓʼþºÍµöÓã»î¶¯µÄ³ÂËß


KasperskyÐû²¼2021ÄêQ2À¬»øÓʼþºÍµöÓã»î¶¯µÄ³ÂËß.jpg


KasperskyÐû²¼ÁËÓйØ2021ÄêQ2À¬»øÓʼþºÍµöÓã»î¶¯µÄ·ÖÎö³ÂËß¡£2021ÄêQ2£¬ÆóÒµÕË»§ÈÔÈ»Êǹ¥»÷ÕßµÄÖ÷ҪĿ±êÖ®Ò»¡£ÎªÁËÔö¼ÓµöÓãÓʼþÖÐÁ´½ÓµÄ¿ÉÐŶÈ£¬¹¥»÷Õßαװ³ÆÀ´×ÔÔÆ·þÎñµÄÓʼþ£¬ÀýÈçMicrosoft Teams»áÒéµÄ֪ͨµÈ¡£À¬»øÓʼþÊýÁ¿µÄÕ¼±ÈÔÚ3Ô·ݴ¥µ×£¨45.10%£©ºó£¬ÔÚ4Ô·ÝС·ùÉÏÉý£¨45.29%£©£¬µ½6Ô£¨48.03%£©Óë2020ÄêQ4Ï൱¡£À¬»øÓʼþÀ´Ô´×î¶àµÄ¹ú¼ÒΪ¶íÂÞ˹£¨26.07%£©£¬Æä´ÎÊǵ¹ú£¨13.97%£©ºÍÃÀ¹ú£¨11.24%£©¡£×î³£¼ûµÄ¶ñÒ⸽¼þÊÇBadun¼Ò×壨7.09%£©¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/spam-and-phishing-in-q2-2021/103548/