ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ19ÖÜ

°ä²¼¹¦·ò 2021-05-10

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê05ÔÂ03ÈÕÖÁ05ÔÂ09ÈÕ¹²ÊÕ¼°²È«·ì϶54¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇTenda AC11 /goform/setVLAN»º³åÇøÒç¶Âí½Å£»£» £»£»£»£»Pulse Secure Pulse Connect SecureÖ¤Êé·þÎñWEB·þÎñÄÚ´æÃýÎóÀûÓôúÂëÖ´Ðзì϶£»£» £»£»£»£»Linux Kernel eBPFȨÏÞÌáÉý·ì϶£»£» £»£»£»£»Trend Micro IM SecurityÈõÁîÅÆÑéÖ¤ÈÆ¹ý·ì϶£»£» £»£»£»£»Foxit Reader CVE-2021-31468ÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊDZÈÀûʱBelnetÔâµ½DDoS¹¥»÷£¬£¬£¬£¬£¬£¬¶à¸ö¹Ù·½ÍøÕ¾ÎÞ·¨½Ó¼û£»£» £»£»£»£»QualysÅû¶EximÖÐÓ°ÏìÊý°ÙÍǫ̀·þÎñÆ÷µÄ·ì϶21Nails£»£» £»£»£»£»FireEye°ä²¼ÓйØUNC2529´¹µö»î¶¯µÄ·ÖÎö»ã±¨£»£» £»£»£»£»Win10 DefenderÖдæÔÚbug£¬£¬£¬£¬£¬£¬¿ÉÔÚCÅÌ´´½¨´óÁ¿Îļþ£»£» £»£»£»£»¸ßͨоƬ´æÔÚ´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬Ó°Ïì30£¥µÄAndroidϵͳ¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£


> ³ÁÒª°²È«·ì϶Áбí


1.Tenda AC11 /goform/setVLAN»º³åÇøÒç¶Âí½Å


Tenda AC11 /goform/setVLAN´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£» £»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://github.com/Yu3H0/IoT_CVE/tree/main/Tenda/CVE_4


2.Pulse Secure Pulse Connect SecureÖ¤Êé·þÎñWEB·þÎñÄÚ´æÃýÎóÀûÓôúÂëÖ´Ðзì϶


Pulse Secure Pulse Connect SecureÖ¤Êé·þÎñWEB·þÎñ´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784/p?pubstatus=o


3.Linux Kernel eBPFȨÏÞÌáÉý·ì϶


Linux Kernel eBPF´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉÌáÉýȨÏÞ¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-503/


4.Trend Micro IM SecurityÈõÁîÅÆÑéÖ¤ÈÆ¹ý·ì϶


Trend Micro IM Security¼àÌý16373¶Ë¿ÚµÄWEB½ÚÔį̀´æÔÚÈõ»á»°·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉÈÆ¹ý°²È«ÏÞ¶È£¬£¬£¬£¬£¬£¬Î´ÊÚȨ½Ó¼û¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-525/


5.Foxit Reader CVE-2021-31468ÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


Foxit Reader U3DÔ½½ç¶Á·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£» £»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-557/


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢±ÈÀûʱBelnetÔâµ½DDoS¹¥»÷£¬£¬£¬£¬£¬£¬¶à¸ö¹Ù·½ÍøÕ¾ÎÞ·¨½Ó¼û


1.jpg


±ÈÀûʱBelnetÓÚÖܶþÔâµ½´ó¹æÄ£DDoS¹¥»÷£¬£¬£¬£¬£¬£¬¶à¸ö¹Ù·½ÍøÕ¾ÎÞ·¨½Ó¼û¡£¡£¡£¡£¡£Belnet£¨±ÈÀûʱ ¹ú¶È×êÑкͽÌÓýÍøÂ磩ÊÇΪ±ÈÀûʱ½ÌÓý»ú¹¹¡¢×êÑÐÖÐÐÄ¡¢¿ÆÑ§×êÑÐËùºÍµ±¾Ö·þÎñÌṩ·þÎñµÄ»¥ÁªÍøÌṩÉÌ¡£¡£¡£¡£¡£¾Ý¹À¼Æ£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷Ó°ÏìÁ˱ÈÀûʱµÄ200¶à¸ö×éÖ¯£¬£¬£¬£¬£¬£¬Ô̺¬µ±¾Ö¡¢¾¯Ô±¾ÖºÍCOVID-19ÒßÃçÔ¤Ô¼µÈÍøÕ¾¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬±ÈÀûʱµ±¾ÖÔÚµ÷²é´ËÊÂÎñ£¬£¬£¬£¬£¬£¬Éв»Ã÷ÏÔ·¢ÆðÕâ´Î¹¥»÷µÄ¹¥»÷Õß¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/belgium-was-hit-by-a-massive-cyberattack-532812.shtml


2¡¢QualysÅû¶EximÖÐÓ°ÏìÊý°ÙÍǫ̀·þÎñÆ÷µÄ·ì϶21Nails


2.jpg


QualysÅû¶EximÓʼþ´«Êä´úÀí£¨MTA£©Èí¼þÓ°ÏìÊý°ÙÍǫ̀·þÎñÆ÷µÄ21¸ö·ì϶£¬£¬£¬£¬£¬£¬Í³³ÆÎª21Nails¡£¡£¡£¡£¡£ÕâЩ·ì϶ÓÐ10¸ö¿É±»Ô¶³ÌÀûÓ㬣¬£¬£¬£¬£¬Áí±í11¸öΪ±¾µØ·ì϶£¬£¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿É×éºÏʹÓÃÕâЩ·ì϶£¬£¬£¬£¬£¬£¬À´Ô¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬£¬²¢ÔÚExim ServerÉÏ»ñµÃrootȨÏÞ¡£¡£¡£¡£¡£ÕâЩ·ì϶±ðÀëΪqueue_run£¨£©ÖеĶѻº³åÇøÒç¶Âí½Å£¨CVE-2020-28011£©¡¢tls-openssl.cÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2020-28018£©µÈ¡£¡£¡£¡£¡£×êÑÐÈËÔ±½¨ÒéÓû§Á¢¼´Éý¼¶µ½×îеĿÉÓÃExim°æ±¾¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-21nails-exim-bugs-expose-millions-of-servers-to-attacks/


3¡¢FireEye°ä²¼ÓйØUNC2529´¹µö»î¶¯µÄ·ÖÎö»ã±¨


3.jpg


FireEye°ä²¼ÁËÓйØUNC2529´¹µö»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£FireEyeµÄMandiantÍŶӷ¢ÏÖ2020Äê12ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬ºÍ2020Äê12ÔÂ11ÈÕÖÁ12ÔÂ18ÈÕÖ®¼ä²úÉúµÄÁ½ÂÖ´¹µö»î¶¯£¬£¬£¬£¬£¬£¬ÖØÒªÒÔÃÀ¹ú¡¢Å·ÖÞ¡¢Öж«¡¢·ÇÖÞ¡¢ÑÇÖ޺ͰĴóÀûÑǵĹ«Ë¾ÎªÖ¸±ê¡£¡£¡£¡£¡£¹¥»÷Õß×ܹ²Ê¹ÓÃÁ˳¬¹ý50¸öÓò£¬£¬£¬£¬£¬£¬ÀûÓö¨ÔìµÄ´¹µöÓʼþ£¬£¬£¬£¬£¬£¬Õë¶ÔÔ̺¬¹ú·À¡¢Ò½Ò©¡¢ÔËÊä¡¢¾üʺ͵ç×ÓµÈ·ÖÆçµÄÐÐÒµ¡£¡£¡£¡£¡£ÔÚÒ»´Î¹¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬£¬UNC2529³É¹¦ÈëÇÖÁËÃÀ¹úÒ»¼Ò¹©ÎÂůÔìÀä·þÎñ¹«Ë¾µÄÓò²¢´Û¸ÄÁËÆäDNS¼Í¼¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2021/05/unc2529-triple-double-trifecta-phishing-campaign.html


4¡¢Win10 DefenderÖдæÔÚbug£¬£¬£¬£¬£¬£¬¿ÉÔÚCÅÌ´´½¨´óÁ¿Îļþ


4.jpg


Windows Defender´æÔÚbug£¬£¬£¬£¬£¬£¬¿ÉÔÚC£º\ProgramData\Microsoft\Windows Defender\Scans\History\StoreÎļþ¼ÐÄÚ´´½¨´óÁ¿MD5¹þÏ£Îļþ¡£¡£¡£¡£¡£ÕâЩÎļþµÄ´óÓ×Ϊ600×Ö½Úµ½1KB£¬£¬£¬£¬£¬£¬ÓеÄϵͳÖÐÖ»ÓÐԼĪ1MBµÄÎļþ£¬£¬£¬£¬£¬£¬¶øÓеÄÓû§Ôò³ÆÆäϵͳ´æÔÚ´óÁ¿µÄÎļþ£¬£¬£¬£¬£¬£¬Õ¼ÓÃÁË30GBµÄ´æ´¢¿Õ¼ä¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬¸ÃÎÊÌâÒÑÔÚWindows Defender 1.1.18100.6°æ±¾Öн¨¸´¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/windows-defender-bug-fills-windows-10-boot-drive-with-thousands-of-files/


5¡¢¸ßͨоƬ´æÔÚ´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬Ó°Ïì30£¥µÄAndroidϵͳ


5.jpg


Check Point·¢ÏÖ¸ßͨ£¨Qualcomm£©µ÷Ôì½âµ÷Æ÷£¨MSM£©½Ó¿Ú£¨¼ò³ÆÎªQMI£©ÖдæÔÚ´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¾Ýͳ¼Æ£¬£¬£¬£¬£¬£¬È«ÇòÔ¼30£¥µÄÊÖ»ú¶¼ÔÚʹÓÃQMI£¬£¬£¬£¬£¬£¬Ô̺¬Google Pixels¡¢LG¡¢OnePlus¡¢ÈýÐÇGalaxyϵÁкÍÓ×Ã×ÊÖ»ú¡£¡£¡£¡£¡£¸Ã·ì϶׷×ÙΪCVE-2020-11292£¬£¬£¬£¬£¬£¬ÊÇqmi_voicei_srvcc_call_config_req´¦Ö÷¨Ê½£¨0x64£©ÖеĶÑÒç¶Âí½Å£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶Զ³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬£¬À´½Ó¼ûÓû§µÄͨ»°¼Í¼ºÍ¶ÌÐÅ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/qualcomm-chip-bug-android-eavesdropping/165934/