ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ16ÖÜ

°ä²¼¹¦·ò 2021-04-19

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê04ÔÂ12ÈÕÖÁ04ÔÂ18ÈÕ¹²ÊÕ¼°²È«·ì϶56¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Photoshop CVE-2021-28549»º³åÇøÒç³ö´úÂëÖ´Ðзì϶£»£»£» £»£» £»£»Google Chrome BlinkÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»£»£» £»£» £»£»Apache TapestryÔ¶³Ì´úÂëÖ´Ðзì϶£»£»£» £»£» £»£»Microsoft Exchange Server CVE-2021-28483Ô¶³Ì´úÂëÖ´Ðзì϶£»£»£» £»£» £»£»SolarWinds Orion PlatformÌØÈ¨ÌáÉý·ì϶¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǰÍÎ÷½ðÈÚ¹«Ë¾IuguÊý¾Ý¿âÅäÖÃÃýÎóй¶1.7 TBÊý¾Ý£»£»£» £»£» £»£»×êÑÐÈËÔ±³Æ³¬¹ý53Íò¸ö»ªÎªÊÖ»úϰȾJoker¶ñÒâÈí¼þ£»£»£» £»£» £»£»Bitdefender°ä²¼2020ÄêÍþÐ²Ì¬ÊÆºÍ·¸×ïÇ÷ÏòµÄ»ØÊ׻㱨£»£»£» £»£» £»£»ForescoutÅû¶ӰÏìÉÏÒŲ́É豸µÄDNS·ì϶NAME£ºWRECK£»£»£» £»£» £»£»Microsoft°ä²¼4Ô²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬½¨¸´5¸ö0dayÔÚÄÚµÄ108¸ö·ì϶¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£


> ³ÁÒª°²È«·ì϶Áбí


1.Adobe Photoshop CVE-2021-28549»º³åÇøÒç³ö´úÂëÖ´Ðзì϶


Adobe Photoshop´¦ÖÃÎļþ´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£» £»£» £»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://helpx.adobe.com/security/products/photoshop/apsb21-28.html


2.Google Chrome BlinkÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


Google Chrome Blink´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³ÒªÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£» £»£» £»£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-411/


3.Apache TapestryÔ¶³Ì´úÂëÖ´Ðзì϶


Apache Tapestry´æÔÚ°²È«Èƹý·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

http://www.openwall.com/lists/oss-security/2021/04/15/1


4.Microsoft Exchange Server CVE-2021-28483Ô¶³Ì´úÂëÖ´Ðзì϶


Microsoft Exchange Server´æÔÚδÃ÷°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-28483


5.SolarWinds Orion PlatformÌØÈ¨ÌáÉý·ì϶


SolarWinds Orion Platform SaveUserSetting´æÔÚȱµã·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿É°ÑguestÓû§ÌáÉýΪÖÎÀíÔ±¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-192/


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢°ÍÎ÷½ðÈÚ¹«Ë¾IuguÊý¾Ý¿âÅäÖÃÃýÎóй¶1.7 TBÊý¾Ý


1.jpg


×êÑÐÈËÔ±Bob DiachenkoÓÚÉÏÖÜÈý·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬°ÍÎ÷½ðÈڿƼ¼IuguÒòÊý¾Ý¿â·þÎñÆ÷ÅäÖÃÃýÎóй¶1.7 TBÊý¾Ý¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñй¶ÁË´Ó2013Äêµ½2021ÄêµÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Ô̺¬¿Í»§µç×ÓÓʼþ¡¢Óû§Ãû¡¢µç»°ºÅÂëºÍµØÖ·¡¢ÂòÂô¼Í¼¡¢ÎĵµºÍÆäËû²ÆÕþ¾ßÌåÐÅÏ¢µÈ¡£¡£¡£¡£¡£IuguÈ·ÈϸÃÊý¾Ý¿â¶³öÁËԼĪÁ½¸öÓ×ʱ£¬£¬£¬£¬£¬£¬£¬½öй¶Á˱¸·ÝÊý¾ÝÖÐԼĪ1£¥µÄ¿ÉÓÃÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°Ð¹Â¶µÄÊý¾ÝÒѱ»±£»£»£» £»£» £»£»¤ÆðÀ´¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://canaltech.com.br/seguranca/vazamento-expoe-17-tb-de-dados-dos-clientes-da-fintech-brasileira-iugu-na-web-182312/


2¡¢×êÑÐÈËÔ±³Æ³¬¹ý53Íò¸ö»ªÎªÊÖ»úϰȾJoker¶ñÒâÈí¼þ


2.jpg


°²È«¹«Ë¾Doctor Web³Æ³¬¹ý53Íò¸ö»ªÎªÊÖ»úÔÚÆä¹Ù·½É̵êAppGalleryÏÂÔØÁËÊÜJoker£¨±ðÃûBread£©¶ñÒâÈí¼þϰȾµÄÀûÓᣡ£¡£¡£¡£Joker¿É±»ÓÃÀ´Ö´ÐÐ¿í·ºµÄ¶ñÒâ²Ù×÷£¬£¬£¬£¬£¬£¬£¬Ô̺¬½ûÓÃGoogle Play±£»£»£» £»£» £»£»¤·þÎñ¡¢×°ÖöñÒâÀûÓ÷¨Ê½¡¢ÌìÉúÐéαÆÀÂÛºÍÏÔʾ¸æ°×µÈ¡£¡£¡£¡£¡£Éæ¼°µÄÀûÓÃÔ̺¬Ô̺¬Ðé¹¹¼üÅÌ¡¢Ïà»ú¡¢Æô¶¯Æ÷¡¢ÔÚÏßMessenger¡¢ÌùÖ½ÍøÂç¡¢×ÅÉ«·¨Ê½ºÍÓÎÏ·µÈ£¬£¬£¬£¬£¬£¬£¬ÆäÖдóÎÞÊýÀûÓÃÀ´×ÔÓÚͳһλ¿ª·¢ÈËÔ±£¨É½Î÷¿ìÀ´ÅÄÍøÂç¼¼ÊõÓÐÏÞ¹«Ë¾£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116643/malware/huawei-store-joker-malware.html


3¡¢Bitdefender°ä²¼2020ÄêÍþÐ²Ì¬ÊÆºÍ·¸×ïÇ÷ÏòµÄ»ØÊ׻㱨


3.jpg


Bitdefender°ä²¼ÁË2020ÄêÍøÂçÍþÐ²Ì¬ÊÆºÍ·¸×ïÇ÷ÏòµÄ»ØÊ׻㱨¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þ¹¥»÷ÔÚÈ«ÇòÁìÓòÄÚ¼¤Ôö485£¥£¬£¬£¬£¬£¬£¬£¬ÔÚ2020ÄêQ1ºÍQ2Õ¼ËùÓй¥»÷µÄ64£¥£»£»£» £»£» £»£»ÖÇÄܵçÊӵķì϶ÊýÁ¿Ôö³¤ÁË338£¥£»£»£» £»£» £»£»NASÉ豸Öеķì϶ÊýÁ¿Í¬±ÈÔö³¤198£¥¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬ÔÚ¼ì²âµ½µÄËùÓÐAndroid¶ñÒâÈí¼þÖУ¬£¬£¬£¬£¬£¬£¬ÓÐ35£¥À´×ÔAndroid.Trojan.AgentϵÁУ¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇAndroid.Trojan.Downloader£¨Õ¼10£¥£©ºÍAndroid.Trojan.Banker£¨Õ¼7£¥£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bitdefender.com/files/News/CaseStudies/study/395/Bitdefender-2020-Consumer-Threat-Landscape-Report.pdf


4¡¢ForescoutÅû¶ӰÏìÉÏÒŲ́É豸µÄDNS·ì϶NAME£ºWRECK


4.jpg


°²È«¹«Ë¾ForescoutºÍÒÔÉ«Áа²È«ÍŶÓJSOF½áºÏÅû¶ÁËTCP/IP²Ö¿âÖÐDNSºÍ̸ÖеÄ9¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬Í³³ÆÎªNAME£ºWRECK£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË1ÒÚ¸öÔÚInternetÉÏÔËÐеÄÉ豸¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶ʹÉ豸ÍÑ»ú»òÕ߯ëÈ«½ÚÔìÉ豸¡£¡£¡£¡£¡£ÕâЩ·ì϶ÖÐ×îÑϳÁµÄΪIPnetÖеÄRCE·ì϶£¨CVE-2016-20009£©£¬£¬£¬£¬£¬£¬£¬ÑϳÁÐԵ÷ÖΪ9.8¡£¡£¡£¡£¡£Æä´ÎΪRCE£¨CVE-2020-7461¡¢CVE-2020-15795ºÍCVE-2020-27009£©ºÍDoS£¨CVE-2020-27736ºÍCVE-2020-27737£©µÈ·ì϶¡£¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/name-wreck-dns-vulnerabilities-affect-over-100-million-devices/


5¡¢Microsoft°ä²¼4Ô²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬½¨¸´5¸ö0dayÔÚÄÚµÄ108¸ö·ì϶


5.jpg


Microsoft°ä²¼ÁË4Ô·ݵÄÖܶþ²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬×ܼƽ¨¸´ÁËÔ̺¬5¸ö0dayÔÚÄÚµÄ108¸ö·ì϶¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ0dayÔ̺¬RPC¶ËµãÓ³ÉäÆ÷µÄÌáȨ·ì϶£¨CVE-2021-27091£©¡¢NTFS»Ø¾ø·þÎñ·ì϶£¨CVE-2021-28312£©¡¢Windows×°Ö÷¨Ê½ÖеÄÐÅϢй¶·ì϶£¨CVE-2021-28437£©¡¢Azure ms-rest-nodeauth¿âµÄÌáȨ·ì϶£¨CVE-2021-28458£©ÒÔ¼°Win32kÖеÄÌáȨ·ì϶£¨CVE-2021-28310£©¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬CVE-2021-28310·ì϶ÊÇKasperskyÔÚÒ°·¢Ïֵ쬣¬£¬£¬£¬£¬£¬Òѱ»APT×éÖ¯BITTERÀûÓᣡ£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2021-patch-tuesday-fixes-108-flaws-5-zero-days/