ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ48ÖÜ

Ðû²¼Ê±¼ä 2020-11-30

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê11ÔÂ23ÈÕÖÁ11ÔÂ29ÈÕ¹²ÊÕ¼Çå¾²Îó²î48¸ö£¬ £¬£¬ £¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇVmware Workspace One CVE-2020-4006ÏÂÁî×¢ÈëÎó²î£»£»£»£»£»Shenzhen C-Data 72408AĬÈÏtelnetЧÀÍÎó²î£»£»£»£»£»Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤Îó²î£»£»£»£»£»Barco wePresent WiPG-1600W¹Ì¼þÐÅϢй¶Îó²î£»£»£»£»£»Mongodb Server RoleName::parseFromBSON()¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÁù¸öÔÂÒÔÀ´Î¢ÈíÈÔδÐÞ¸´Windows10ÖÐÒÑÖªÎó²î£»£»£»£»£»ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸ÁÐ±í£»£»£»£»£»VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬ £¬£¬ £¬£¬£¬ÉÐδÐû²¼²¹¶¡£¡£¡£¡£»£»£»£»£»Ñо¿Ö°Ô±·¢Ã÷Win7ºÍServer2008ÖеÄÍâµØÌáȨ0day£»£»£»£»£»Group-IBÐû²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÕ¹ÍûÆÊÎö±¨¸æ¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬ £¬£¬ £¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£


Ö÷ÒªÇå¾²Îó²îÁбí


1.Vmware Workspace One CVE-2020-4006ÏÂÁî×¢ÈëÎó²î


VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address±£´æÇå¾²Îó²î£¬ £¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬ £¬£¬£¬¿É×¢Èëí§ÒâÏÂÁî²¢Ö´ÐС£¡£¡£¡£

https://docs.opsmanager.mongodb.com/current/release-notes/application/#onprem-server-4-4-3


2.Shenzhen C-Data 72408AĬÈÏtelnetЧÀÍÎó²î


Shenzhen C-Data 72408A TelnetЧÀͱ£´æ¶à¸öĬÈÏÆ¾Ö¤Îó²î£¬ £¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬ £¬£¬£¬¿ÉδÊÚȨ»á¼û×°±¸¡£¡£¡£¡£

https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html


3.Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤Îó²î


Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤±£´æÇå¾²Îó²î£¬ £¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬ £¬£¬£¬¿É×°ÖÃÐ޻ڸĵÄ/¶ñÒâµÄÓ³Ïñ¡£¡£¡£¡£

https://korelogic.com/Resources/Advisories/KL-001-2020-009.txt


4.Barco wePresent WiPG-1600W¹Ì¼þÐÅϢй¶Îó²î


Barco wePresent WiPG-1600W¹Ì¼þÓ³ÏñÖаüÀ¨Ó²±àÂëµÄ¸ùÃÜÂëÉ¢ÁУ¬ £¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬ £¬£¬£¬¿Éͨ¹ý´ËÐÅϢδÊÚȨ»á¼û¡£¡£¡£¡£

https://korelogic.com/Resources/Advisories/KL-001-2020-008.txt


5.Mongodb Server RoleName::parseFromBSON()¾Ü¾øÐ§ÀÍÎó²î


Mongodb Server RoleName::parseFromBSON()±£´æÇå¾²Îó²î£¬ £¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬ £¬£¬£¬¿É¾ÙÐоܾøÐ§À͹¥»÷¡£¡£¡£¡£

https://jira.mongodb.org/browse/SERVER-49142


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Áù¸öÔÂÒÔÀ´Î¢ÈíÈÔδÐÞ¸´Windows10ÖÐÒÑÖªÎó²î


1.jpg


×Ô2020Äê5Ô£¬ £¬£¬ £¬£¬£¬MicrosoftÐû²¼ÁËWindows 10 2004Çå¾²¸üкó£¬ £¬£¬ £¬£¬£¬·ºÆðÁËÁ½¸öÎó²î£¬ £¬£¬ £¬£¬£¬µ¼ÖÂSSDÇý¶¯Æ÷µÄ´ÅÅÌË鯬ÕûÀí¹ýÓÚÆµÈÔ£¬ £¬£¬ £¬£¬£¬²¢ÔÚ·ÇSSDÇý¶¯Æ÷ÉÏʵÑéTRIM²Ù×÷¡£¡£¡£¡£µÚÒ»¸öÎó²îʹWin10×Ô¶¯Î¬»¤¹¦Ð§ÎÞ·¨¼Ç×ÅÖØÆôϵͳʱÇý¶¯Æ÷µÄ×îºóÓÅ»¯Ê±¼ä£¬ £¬£¬ £¬£¬£¬µ¼ÖÂÇý¶¯Æ÷ÔÚÿ´ÎÖØÆôÅÌËã»úʱ¶¼¾ÙÐÐË鯬ÕûÀí¡£¡£¡£¡£µÚ¶þ¸öÎó²îµ¼ÖÂWin10µÄÓÅ»¯Çý¶¯Æ÷¹¦Ð§»á¶Ô·ÇSSDÇý¶¯Æ÷¾ÙÐÐTRIM£¬ £¬£¬ £¬£¬£¬Õâ»áµ¼ÖÂÊÂÎñÈÕÖ¾Öйýʧ¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬ £¬£¬£¬ÔÚ½üÁù¸öÔÂÖ®ºó£¬ £¬£¬ £¬£¬£¬MicrosoftÈÔδÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/windows-10-defrag-trim-bug-still-not-fixed-after-six-months/


2¡¢ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸Áбí


2.jpg


ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸Áбí£¬ £¬£¬ £¬£¬£¬ÆäÖаüÀ¨À´×ÔÌìϸ÷µØµÄ´óÐÍÒøÐкÍÕþ¸®×éÖ¯¡£¡£¡£¡£ÕâЩװ±¸Öоù±£´æÂ·¾¶±éÀúÎó²î£¬ £¬£¬ £¬£¬£¬±»×·×ÙΪCVE-2018-13379£¬ £¬£¬ £¬£¬£¬ËüÓ°ÏìÁË´ó×ÚδÐÞ²¹µÄFortinet FortiOS SSL VPN×°±¸¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î£¬ £¬£¬ £¬£¬£¬´ÓFortinet VPN»á¼ûsslvpn_websessionÎļþÀ´ÇÔÈ¡µÇ¼ƾ֤£¬ £¬£¬ £¬£¬£¬²¢½«ÆäÓÃÓÚÆÆËðÍøÂç²¢°²ÅÅÀÕË÷Èí¼þ¡£¡£¡£¡£Ö»¹Ü¸ÃÎó²îÔÚÒ»Äêǰ¾Í±»¹ûÕæÅû¶£¬ £¬£¬ £¬£¬£¬µ«ºÚ¿ÍÈÔ·¢Ã÷²¢¹ûÕæÁËÁË49577¸ö±£´æ´ËÀàÎó²îµÄ´óÐÍ×°±¸µÄÁбí¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-posts-exploits-for-over-49-000-vulnerable-fortinet-vpns/


3¡¢VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬ £¬£¬ £¬£¬£¬ÉÐδÐû²¼²¹¶¡


3.jpg


VMwareÅû¶ÁËÓ°ÏìÆäWorkspace One¶à¸ö×é¼þÖеÄÌáȨ0day£¬ £¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÌáȨÒÔÔÚLinuxºÍWindows²Ù×÷ϵͳÉÏÖ´ÐÐÏÂÁ £¬£¬ £¬£¬£¬ÏÖÔÚÉÐδÐû²¼Ïà¹Ø²¹¶¡³ÌÐò¡£¡£¡£¡£¸ÃÎó²î±»¸ú×ÙΪCVE-2020-4006£¬ £¬£¬ £¬£¬£¬CVSSÆ·¼¶Îª9.1£¬ £¬£¬ £¬£¬£¬ÆäÓ°ÏìÁËVMware Workspace ONE Access¡¢»á¼ûÅþÁ¬Æ÷¡¢Éí·ÝÖÎÀíÆ÷¡¢Éí·ÝÖÎÀíÆ÷ÅþÁ¬Æ÷¡¢VMwareÔÆ»ù½ð»áºÍvRealize SuiteÉúÃüÖÜÆÚÖÎÀíÆ÷¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬ £¬£¬£¬VMwareÒÑÐû²¼ÔÝʱ½â¾ö²½·¥ÒÔÏû³ý¹¥»÷ǰÑÔ²¢±ÜÃâÎó²îµÄʹÓᣡ£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/vmware-zero-day-patch-pending/161523/


4¡¢Ñо¿Ö°Ô±·¢Ã÷Win7ºÍServer2008ÖеÄÍâµØÌáȨ0day


4.jpg


·¨¹úÑо¿Ö°Ô±·¢Ã÷Windows 7ºÍServer 2008±£´æÍâµØÌáȨ£¨LPE£©0day£¬ £¬£¬ £¬£¬£¬µ±WindowsÇå¾²¹¤¾ß¸üÐÂʱ»áÓ°ÏìÆä²Ù×÷ϵͳ¡£¡£¡£¡£¸ÃÎó²îλÓÚËùÓÐWindows×°ÖÃÖеÄRPC¶ËµãÓ³ÉäÆ÷ºÍDNSCacheЧÀ͵ÄÁ½¸ö¹ýʧÉèÖõÄ×¢²á±íÏîÖУ¬ £¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄÕâЩע²á±íÀ´¼¤»îWindowsÐÔÄܼàÊÓ»úÖÆËùʹÓõÄ×ÓÃÜÔ¿¡£¡£¡£¡£ÏÖÔÚ0patchƽ̨ÒÑÐû²¼ÔÝʱ΢²¹¶¡£¬ £¬£¬ £¬£¬£¬²¢ÔÚ΢ÈíÐû²¼Õýʽ²¹¶¡Ç°¶ÔËùÓÐÈËÃâ·ÑÌṩ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/windows-7-and-server-2008-zero-day-bug-gets-a-free-patch/


5¡¢Group-IBÐû²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÕ¹ÍûÆÊÎö±¨¸æ


5.jpg


Group-IBÐû²¼Á˶ÔÀ´ÄêÍøÂçÍþвµÄÕ¹ÍûÆÊÎö±¨¸æ£¬ £¬£¬ £¬£¬£¬Ñо¿ÁË2019ÄêϰëÄêÖÁ2020ÄêÉϰëÄêÖ®¼ä¹ú¼ÊÍøÂç·¸·¨ÐÐΪµÄÖ÷Ҫת±ä£¬ £¬£¬ £¬£¬£¬²¢¶ÔÀ´Äê×ö³öÁËÕ¹Íû¡£¡£¡£¡£±¨¸æÖ¸³ö£¬ £¬£¬ £¬£¬£¬ÀÕË÷Èí¼þ»î¶¯Ôì³ÉÁËÑÏÖØµÄ¾­¼ÃËðʧ£¬ £¬£¬ £¬£¬£¬Ë½Óª¹«Ë¾ºÍÕþ¸®»ú¹¹¶¼Î´ÄÜÐÒÃâ¡£¡£¡£¡£ÔÚ´Ëʱ´ú£¬ £¬£¬ £¬£¬£¬×ܹ²ÓÐÕë¶ÔÁè¼Ý45¸ö¹ú¼ÒµÄ500¶à´ÎÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£Æ¾Ö¤Group-IBµÄÊØ¾ÉÔ¤¼Æ£¬ £¬£¬ £¬£¬£¬ÀÕË÷Èí¼þÍÅ»ïÔì³ÉµÄ×ܲÆÎñËðʧÁè¼Ý10ÒÚÃÀÔª£¨1005186000ÃÀÔª£©¡£¡£¡£¡£ÆäÖУ¬ £¬£¬ £¬£¬£¬MazeºÍREvilµÄÓ°Ïì×î´ó£¬ £¬£¬ £¬£¬£¬Õ¼ËùÓй¥»÷µÄ°ëÊýÒÔÉÏ£¬ £¬£¬ £¬£¬£¬Æä´ÎÊÇRyuk¡¢NetWalkerºÍDoppelPaymer¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.group-ib.com/media/gib-report-2020/