×êÑÐÈËÔ±·¢ÏÖWin7ºÍServer2008Öеı¾µØÌáȨ0day£»£»£»£»£»£»£»Google³Æ°Ù¶ÈµØÍ¼ºÍ°Ù¶ÈËÑË÷ÍøÂçÓû§Ãô¸ÐÊý¾Ý
°ä²¼¹¦·ò 2020-11-26
·¨¹ú×êÑÐÈËÔ±·¢ÏÖWindows 7ºÍServer 2008´æÔÚ±¾µØÌáȨ£¨LPE£©0day£¬£¬£¬£¬£¬£¬£¬£¬µ±Windows°²È«¹¤¾ß¸üÐÂʱ»áÓ°ÏìÆä²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¸Ã·ì϶λÓÚËùÓÐWindows×°ÖÃÖеÄRPC¶ËµãÓ³ÉäÆ÷ºÍDNSCache·þÎñµÄÁ½¸öÃýÎóÅäÖõÄ×¢²á±íÏîÖУ¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýÅú¸ÄÕâЩע²á±íÀ´¼¤»îWindows»úÄܼල»úÔìËùʹÓõÄ×ÓÃÜÔ¿¡£¡£¡£¡£¡£¡£Ä¿Ç°0patchƽ̨ÒѰ䲼һʱ΢²¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ΢Èí°ä²¼Õýʽ²¹¶¡Ç°¶ÔËùÓÐÈËÃâ·ÑÌṩ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/windows-7-and-server-2008-zero-day-bug-gets-a-free-patch/
2.Google³Æ°Ù¶ÈµØÍ¼ºÍ°Ù¶ÈËÑË÷ÍøÂçÓû§Ãô¸ÐÊý¾Ý

Google·¢ÏְٶȵÄÁ½¸öAndroidÀûÓðٶȵØÍ¼ºÍ°Ù¶ÈËÑË÷ÔÚÍøÂçÓû§Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬²¢ÓÚ10Ô½«Æä´ÓPlayÉ̵êÖÐɾ³ý¡£¡£¡£¡£¡£¡£°²È«¹«Ë¾Palo Alto Networks·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÁ½¸öÀûÓÃÄܹ»ÔÚÓû§²»ÖªÇéµÄÇé¿öÏÂÍøÂçÉ豸±êʶ·û£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈç¹ú¼ÊÒÆ¶¯¶©»§Éí·Ý£¨IMSI£©ºÅÂë»òMACµØÖ·£¬£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂÓû§±»¸ú×Ù¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬£¬GoogleÓÚ10ÔÂ28ÈÕÒÔδָ¶¨µÄÇÖȨÐÐΪΪÓɲó·ÁËÕâЩÀûÓᣡ£¡£¡£¡£¡£°Ù¶ÈËÑË÷ÒÑÓÚ11ÔÂ19ÈÕ¸´Ôµ½PlayÉ̵꣬£¬£¬£¬£¬£¬£¬£¬¶ø°Ù¶ÈµØÍ¼Ä¿Ç°ÈÔ²»³ÉÓᣡ£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2020/11/baidus-android-apps-caught-collecting.html
3.×êÑÐÍŶӷ¢ÏÖcPanel 2FA¿É±»Èƹý£¬£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÁ¿³¬¹ý7000Íò

°²È«ÈËÔ±·¢ÏÖcPanel´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¿É±»ÓÃÀ´ÈƹýË«³ÁÉí·ÝÑéÖ¤£¨2FA£©¡£¡£¡£¡£¡£¡£cPanelÊÇÍøÂçÍйܹ«Ë¾ÓÃÀ´ÎªÆä¿Í»§ÖÎÀíÍøÕ¾µÄÈí¼þÌ×¼þ£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÖÎÀí×ų¬¹ý7000Íò¸öÕ¾µã¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄ´æÔÚÔÓÉÓÚcPanel°²È«Õ½Êõ²¢Î´×èÖ¹¹¥»÷Õß³Á¸´Ìá½»2FA´úÂ룬£¬£¬£¬£¬£¬£¬£¬ÕâʹµÃ¹¥»÷ÕßÄܹ»Ê¹Óñ©Á¦¹¥»÷ÈÆ¹ý2FAÑéÖ¤¡£¡£¡£¡£¡£¡£ÔÚ½ÏÔçʱ³½¹¥»÷ÕßÒ²Äܹ»Í¨¹ý²Â²âURL²ÎÊý²¢Èƹý2FA£¬£¬£¬£¬£¬£¬£¬£¬µ«Í¨³£±ØÒªÊýÓ×ʱ»òÊýÌìÄÜÁ¦³É¹¦£¬£¬£¬£¬£¬£¬£¬£¬¶øÔÚÕâÖÖÇé¿öÏµĹ¥»÷Ö»±ØÒª¼¸·ÖÖÓ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶Òѱ»½¨¸´¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/2fa-bypass-discovered-in-web-hosting-software-cpanel/
4.Õë¶ÔLinux·þÎñÆ÷µÄÐÂStantinko¼Ù×°³ÉhttpdµÄ¹ý³Ì

×êÑÐÈËÔ±·¢ÏÖÁ˽©Ê¬ÍøÂçStantinkoµÄбäÖÖÄܹ»¼Ù×°³ÉApache Web·þÎñÆ÷httpdµÄ¹ý³Ì£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔLinux·þÎñÆ÷¡£¡£¡£¡£¡£¡£StantinkoÓÚ2017Äê³õ´Î±»·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬°æ±¾ºÅΪ1.2£¬£¬£¬£¬£¬£¬£¬£¬¶øÈç½ñµÄ°æ±¾ºÅΪ2.17£¬£¬£¬£¬£¬£¬£¬£¬Óë֮ǰ°æ±¾Ïà±Å×кܴóµÄÌá¸ß¡£¡£¡£¡£¡£¡£Ð°汾Խ·¢¾«¼ò²¢ÇÒÔ̺¬µÄÖ°ÄܸüÉÙ£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±²Â²â¸ÃÍÅ»ïÊÔͼÏ÷¼õ¶ñÒâÈí¼þÖ¸ÎÆÒÔÔ¤·À±»É±¶¾Èí¼þ¼ì²â¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Æä»¹Åú¸ÄÁËLinux¶ñÒâÈí¼þʹÓõĹý³ÌÃû³Æ£¬£¬£¬£¬£¬£¬£¬£¬¸ÄÃûΪhttpd£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/111393/malware/stantinkos-linux-variant.html
5.ºÚ¿Í¹«¿ªÊÂÎñÖÎÀíµ±ÓÃPeatixµÄ420Íò¸öÓû§µÄÐÅÏ¢

ºÚ¿Í¹«¿ªÊÂÎñÖÎÀíµ±ÓÃPeatixÖеÄ420Íò¸öÓû§µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£Õâ´Îй©µÄÐÅÏ¢Ô̺¬Óû§ÐÕÃû¡¢Óû§Ãû¡¢µç×ÓÓʼþÒÔ¼°¼ÓÑκ͹þÏ£ÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬ÆäÖдó²¿ÃÅÓû§ÎªÑÇÖÞÈË¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒѾȷÈÏÆäÔâµ½Á˹¥»÷µ¼ÖÂÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬²¢ÒÑ×èÖ¹ÈëÇÖÕßÔٴνӼûÆäϵͳ¡£¡£¡£¡£¡£¡£Peatix»¹ÏòÓû§±£ÕÏ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËùÓи¶¿î¶¼ÊÇͨ¹ýµÚÈý·½Æ½Ì¨´¦Öõ쬣¬£¬£¬£¬£¬£¬£¬Òò¶ø²¢ÎÞ²ÆÕþÓйØÊý¾Ýй¶¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hacker-leaks-the-user-data-of-event-management-app-peatix/
6.Ó¢¹úNCSC½¨ÒéÓйØ×éÖ¯½¨¸´CVE-2020-15505·ì϶

Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©·¢³ö¾¯±¨£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓйØ×éÖ¯½¨¸´MobileIronÒÆ¶¯É豸ÖÎÀí£¨MDM£©ÏµÍ³ÖеÄCVE-2020-15505·ì϶¡£¡£¡£¡£¡£¡£MDMÊÇÒ»¸öÈí¼þƽ̨£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÖÎÀíÔ±Ô¶³ÌÖÎÀíÆä×éÖ¯ÖеÄÒÆ¶¯É豸¡£¡£¡£¡£¡£¡£¸Ã·ì϶ΪԶ³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚMDM·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐкÅÁî²¢ÎÞÐèÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬£¬£¬MobileIronÒÑÓÚ6Ô°䲼Á˲¹¶¡·¨Ê½¡£¡£¡£¡£¡£¡£NCSC³Æ£¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇ·¢ÏÖºÚ¿ÍÍÅ»ïÔÚÀûÓø÷ì϶À´·ÛËéÒ½ÁƱ£½¡ÐÐÒµ¡¢´¦Ëùµ±¾Ö¡¢ÎïÁ÷ºÍ˾·¨²¿ÃŵÄÍøÂç¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/uk-urges-orgs-to-patch-critical-mobileiron-cve-2020-15505-rce-bug/


¾©¹«Íø°²±¸11010802024551ºÅ