ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ35ÖÜ

Ðû²¼Ê±¼ä 2021-08-30

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö

2021Äê08ÔÂ23ÈÕÖÁ08ÔÂ29ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´60¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇFlatCore-CMS upload addon²å¼þ´úÂëÖ´ÐЩ£»NASCENT RemKon Device Manager assets/index.phpÈÎÒâ´úÂëÉÏ´«Â©¶´£»Teamviewer TVS½âÎöÄÚ´æÆÆ»µ´úÂëÖ´ÐЩ¶´£»RaspAP raspap-webguiÌØȨÌáÉý©¶´£»SolarWinds Web Help Desk referrerαÔì·ÃÎÊÏÞÖÆÈƹý©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇмÓÆ·¿µØ²ú¹«Ë¾OrangeTeeÔâµ½ALTDOSµÄÀÕË÷¹¥»÷£»HuntressÔÚ1900̨Exchange¼ì²âµ½140¶àÖÖWeb shell£»Razer SynapseÖеĵ±µØÌáȨ0dayÓ°ÏìÁè¼Ý1ÒÚÓû§£»SAM·¢ÏÖMiraiÀûÓÃRealtek SDKÖЩ¶´µÄ¹¥»÷»î¶¯£»OpenSSLÐû²¼Äþ¾²¸üР£¬ÐÞ¸´²úÎïÖеÄ2¸öÄþ¾²Â©¶´¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1.Google chrome V8 CVE-2021-30598ÀàÐÍ»ìÏý´úÂëÖ´ÐЩ¶´


FlatCore-CMS upload addon²å¼þ´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://github.com/flatCore/flatCore-CMS/issues/52


2.NASCENT RemKon Device Manager assets/index.phpÈÎÒâ´úÂëÉÏ´«Â©¶´


NASCENT RemKon Device Manager assets/index.phpͼÏñÉÏ´«¹¦Ð§´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÉÏ´«ÈÎÒâÎļþ²¢ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.blacklanternsecurity.com/2021-08-23-Nascent-RemKon-CVEs/


3.Teamviewer TVS½âÎöÄÚ´æÆÆ»µ´úÂëÖ´ÐЩ¶´


Teamviewer TVS½âÎö´æÔÚÄÚ´æÆÆ»µÂ©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.zerodayinitiative.com/advisories/ZDI-21-1003/


4.RaspAP raspap-webguiÌØȨÌáÉý©¶´


RaspAP raspap-webgui´æÔÚ²»Äþ¾²µÄsudoersȨÏÞ©¶´ £¬ÔÊÐíµ±µØ¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬»ñµÃROOTȨÏÞ¡£


https://github.com/RaspAP/raspap-webgui/blob/fabc48c7daae4013b9888f266332e510b196a062/installers/raspap.sudoers


5.SolarWinds Web Help Desk referrerαÔì·ÃÎÊÏÞÖÆÈƹý©¶´


SolarWinds Web Help Desk referrerαÔì´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÈƹýÏÞÖÆδÊÚȨ·ÃÎÊ¡£


https://www.solarwinds.com/trust-center/security-advisories/cve-2021-32076


 >ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Ð¼ÓÆ·¿µØ²ú¹«Ë¾OrangeTeeÔâµ½ALTDOSµÄÀÕË÷¹¥»÷


мÓÆ·¿µØ²ú¹«Ë¾OrangeTeeÔâµ½ALTDOSµÄÀÕË÷¹¥»÷.jpg


8ÔÂ6ÈÕ £¬Ð¼ÓÆ·¿µØ²ú¹«Ë¾OrangeTee GroupÔÚÆä¹ÙÍøÉÏÐû²¼ÉùÃ÷³ÆÆäÔâµ½Á˹¥»÷¡£8ÔÂ12ÈÕ £¬ºÚ¿ÍÍÅ»ïALTDOSÉù³ÆËüÃÇ×Ô2021Äê6ÔÂÒÔÀ´ £¬Ò»Ö±ÔÚÇÔÈ¡¸Ã¹«Ë¾µÄÊý¾Ý £¬ÏÖÒÑ»ñµÃÁËÀ´×ÔACSystem¡¢NewOrangeTee¡¢OT_Analytics¡¢OT_LeaveºÍProjInfoListingµÄ969¸öÊý¾Ý¿â¡£Í¬ÈÕ £¬OrangeTee¹«Ë¾ÌåÏÖÆä²»»áÖ§¸¶Êê½ð¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/singapore-real-estate-firm-breached-by-altdos/


2¡¢HuntressÔÚ1900̨Exchange¼ì²âµ½140¶àÖÖWeb shell


HuntressÔÚ1900̨Exchange¼ì²âµ½140¶àÖÖWeb shell.jpg


ÉÏÖÜÎå £¬Äþ¾²¹«Ë¾Huntress Labs³Æ½ü2000̨Microsoft ExchangeÓʼþ·þÎñÆ÷ÔÚ¹ýÈ¥¼¸ÌìÄÚÔâµ½ºÚ¿Í¹¥»÷¡£ProxyShellÊÇ3¸ö©¶´CVE-2021-34473¡¢CVE-2021-34523ºÍCVE-2021-31207µÄͳ³Æ¡£Ñо¿ÈËÔ±ÌåÏÖ £¬ÔÚProxyShell¿´·¨ÑéÖ¤´úÂëÐû²¼ºó²»¾Ã·ºÆðÁËÏà¹ØɨÃè»î¶¯ £¬Ö±µ½ÉÏÖÜÄ©Äð³ÉÁËʵ¼Ê¹¥»÷¡£´ËÍâ £¬Òѱ»ÈëÇÖµÄ1900¶ą̀Exchange·þÎñÆ÷Éæ¼°µ½µÄ×éÖ¯°üÂÞ½¨ÖþÖÆÔìÉÌ¡¢º£Ïʼӹ¤³§¡¢¹¤Òµ»úе¹«Ë¾¡¢Æû³µÎ¬ÐÞµêºÍСÐÍ»ú³¡µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/almost-2000-exchange-servers-hacked-using-proxyshell-exploit/


3¡¢Razer SynapseÖеĵ±µØÌáȨ0dayÓ°ÏìÁè¼Ý1ÒÚÓû§


Razer SynapseÖеĵ±µØÌáȨ0dayÓ°ÏìÁè¼Ý1ÒÚÓû§.jpg


Ñо¿ÈËÔ±jonhatÓÚ2021Äê8ÔÂ21ÈÕÔÚTwitterÉÏÅû¶ÁËRazer SynapseÖеĵ±µØÌáȨ0dayµÄϸ½Ú¡£RazerÊÇÒ»¼Ò¼ÆËã»úÍâÉèÖÆÔìÉÌ £¬Éù³ÆÆäRazer SynapseÒѱ»È«ÇòÁè¼Ý1ÒÚÓû§Ê¹Óá£ÕâÊÇÒ»¸öµ±µØÌáȨ£¨LPE£©Â©¶´ £¬½«RazerÉ豸²åÈëWindows 10ʱ £¬ÏµÍ³»á×Ô¶¯ÏÂÔز¢°²×°Çý¶¯·¨Ê½ºÍRazer Synapse £¬ÓÉÓÚRazerInstaller.exeÊÇͨ¹ýSYSTEMȨÏÞµÄWindows½ø³ÌÆô¶¯µÄ £¬Òò´ËÆäÒ²»ñµÃÁËSYSTEMȨÏÞ¡£Ö®ºóÔÚÑ¡Ôñ°²×°Îļþ¼Ðʱ £¬°´ÏÂShift²¢ÓÒ¼üµ¥»÷¶Ô»°¿ò £¬¾Í¿ÉÒÔ´ò¿ªSYSTEMȨÏÞµÄPowerShell´°¿Ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/razer-bug-lets-you-become-a-windows-10-admin-by-plugging-in-a-mouse/


4¡¢SAM·¢ÏÖMiraiÀûÓÃRealtek SDKÖЩ¶´µÄ¹¥»÷»î¶¯


SAM·¢ÏÖMiraiÀûÓÃRealtek SDKÖЩ¶´µÄ¹¥»÷»î¶¯.jpg


Äþ¾²¹«Ë¾SAM SeamlessÓÚ8ÔÂ19ÈÕ³ÆÆä·¢ÏÖÁ˽©Ê¬ÍøÂçMiraiÀûÓÃRealtek SDKÖЩ¶´µÄ¹¥»÷»î¶¯¡£¸Ã©¶´ÎªÉí·ÝÑéÖ¤Èƹý©¶´ £¬×·×ÙΪCVE-2021-20090 £¬ÆÀ·ÖΪ9.8·Ö £¬RealtekÒÑÓÚ8ÔÂ13ÈÕÐû²¼¸Ã©¶´µÄ²¹¶¡·¨Ê½¡£SAMÌåÏÖ £¬ËûÃÇÓÚ8ÔÂ18ÈÕÔÚÒ°·¢ÏÖÁ˴˴Ω¶´ÀûÓû £¬¹¥»÷Ô´ÓÚ31.210.20[.]100 £¬µ«¹¥»÷ÕßµÄIPµØÖ·¿ÉÄÜ»áËæ×Åʱ¼ä¶ø¸Ä±ä¡£


Ô­ÎÄÁ´½Ó£º

https://securingsam.com/realtek-vulnerabilities-weaponized/


5¡¢OpenSSLÐû²¼Äþ¾²¸üР£¬ÐÞ¸´²úÎïÖеÄ2¸öÄþ¾²Â©¶´


OpenSSL.png


OpenSSLÓÚ8ÔÂ24ÈÕÐû²¼Äþ¾²¸üР£¬ÐÞ¸´Æä²úÎïÖеÄ2¸öÄþ¾²Â©¶´¡£ÆäÖÐ×îΪÑÏÖصÄÊÇ»º³åÇøÒç³ö©¶´ £¬×·×ÙΪCVE-2021-3711 £¬¹¥»÷ÕßÀûÓÃÆä¿Éµ¼ÖÂÓ¦Ó÷¨Ê½Í߽⡣¸Ã©¶´ÓëSM2¼ÓÃÜÊý¾ÝµÄ½âÃܹý³ÌÏà¹Ø £¬¿ÉÓÃÀ´¸ü¸Ä¶ÑÖеÄÊý¾Ý£¨¼´Æ¾¾Ý£©¡£´Ë´ÎÐÞ¸´µÄÁíÒ»¸ö©¶´×·×ÙΪCVE-2021-3712 £¬¹¥»÷Õß¿ÉÒÔÀûÓø鶴´¥·¢¾Ü¾ø·þÎñ(DoS) £¬»¹¿ÉÄܵ¼Ö»úÃÜÐÅϢй¶ £¬ÀýÈç˽Կ»òÃô¸ÐÃ÷ÎÄ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/121426/hacking/cve-2021-3711-openssl-flaws.html