ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ33ÖÜ

°ä²¼¹¦·ò 2021-08-23

>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê08ÔÂ09ÈÕÖÁ08ÔÂ15ÈÕ¹²ÊÕ¼°²È«·ì϶58¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Dynamics CVE-2021-36946¿çÕ¾¾ç±¾·ì϶£»£»£»£»£»£»£»SAP Business OneËÁÒâÎļþÉÏ´«´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»SapphireIMSºÅÁî×¢Èë·ì϶£»£»£»£»£»£»£»Adobe Connect CVE-2021-36061°²È«Èƹý·ì϶£»£»£»£»£»£»£»Apache ServiceComb Service-Center CVE-2021-21501õè¾¶±éÀú·ì϶¡£¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑÐÈËÔ±·¢ÏÖÀûÓÃExchangeÖзì϶ProxyShellµÄ¹¥»÷»î¶¯£»£»£»£»£»£»£»×êÑÐÍŶӷ¢ÏÖÀûÓÃArcadyan¹Ì¼þÖзì϶װÖÃMiraiµÄ»î¶¯£»£»£»£»£»£»£»RansomEXXÍÅ»ïÐû³ÆÒÑÇÔÈ¡ÉÝ³ÞÆ·ÅÆZegna³¬¹ý20GBÊý¾Ý£»£»£»£»£»£»£»Î¢ÈíÖܶþ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´Ô̺¬3¸ö0dayÔÚÄÚµÄ44¸ö·ì϶£»£»£»£»£»£»£»Kaspersky°ä²¼2021ÄêQ2À¬»øÓʼþºÍ´¹µö»î¶¯µÄ»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£¡£¡£



>³ÁÒª°²È«·ì϶Áбí


1.Microsoft Dynamics CVE-2021-36946¿çÕ¾¾ç±¾·ì϶


Microsoft Dynamics´æÔÚ¿çÕ¾¾ç±¾·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶עÈë¶ñÒâ¾ç±¾»òHTML´úÂ룬£¬£¬£¬£¬£¬£¬µ±¶ñÒâÊý¾Ý±»²é¿´Ê±£¬£¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»ò½Ù³ÖÓû§»á»°¡£¡£¡£¡£¡£¡£¡£¡£


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36946



2.SAP Business OneËÁÒâÎļþÉÏ´«´úÂëÖ´Ðзì϶


SAP Business One´æÔÚËÁÒâÎļþÉÏ´«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£


https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806


3.SapphireIMSºÅÁî×¢Èë·ì϶


SapphireIMS´æÔÚÓ²±àÂëºÍÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÈÆ¹ý°²È«ÏÞ¶È£¬£¬£¬£¬£¬£¬£¬Ö´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£


https://www.sapphireims.com/patches/


4.Adobe Connect CVE-2021-36061°²È«Èƹý·ì϶


Adobe Connect´æÔÚ°²È«Èƹý·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉδÊÚȨ½Ó¼ûÀûÓᣡ£¡£¡£¡£¡£¡£¡£


https://helpx.adobe.com/security/products/connect/apsb21-66.html


5.Apache ServiceComb Service-Center CVE-2021-21501õè¾¶±éÀú·ì϶


Apache ServiceComb Service-Center´æÔÚÅäÖÃÃýÎó·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿É½øÐÐĿ¼±éÀú¹¥»÷£¬£¬£¬£¬£¬£¬£¬»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£


https://lists.apache.org/thread.html/r337be65e504eac52a12e89d7de40345e5d335deee9dd7288f7f59b81%40%3Cdev.servicecomb.apache.org%3E


 >³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢×êÑÐÈËÔ±·¢ÏÖÀûÓÃExchangeÖзì϶ProxyShellµÄ¹¥»÷»î¶¯


×êÑÐÈËÔ±·¢ÏÖÀûÓÃExchangeÖзì϶ProxyShellµÄ¹¥»÷»î¶¯.jpg


2021 Black Hat´ó»áÉÏͳ³ÆÎªProxyShellµÄ3¸ö·ì϶µÄϸ½Ú¹«¿ªºó£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁË»ý¼«ÀûÓø÷ì϶µÄ»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£ProxyShellÔ̺¬ACLÈÆ¹ý·ì϶£¨CVE-2021-34473£©¡¢ Exchange PowerShellºó¶ËµÄÌáȨ·ì϶£¨CVE-2021-34523£©ºÍËÁÒâÎļþдÈëµ¼ÖµÄRCE·ì϶£¨CVE-2021-31207£©¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶Äܹ»Í¨¹ýIISÖеĶ˿Ú443ÉÏÔËÐеÄMicrosoft Exchange¿Í»§¶Ë½Ó¼û·þÎñ(CAS)Ô¶³ÌÀûÓ㬣¬£¬£¬£¬£¬£¬½áºÏʹÓÿɽøÐÐδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-servers-scanned-for-proxyshell-vulnerability-patch-now/


2¡¢×êÑÐÍŶӷ¢ÏÖÀûÓÃArcadyan¹Ì¼þÖзì϶װÖÃMiraiµÄ»î¶¯


×êÑÐÍŶӷ¢ÏÖÀûÓÃArcadyan¹Ì¼þÖзì϶װÖÃMiraiµÄ»î¶¯.jpg


Õ°²©ÍøÂçµÄ×êÑÐÍŶÓÔÚ½üÆÚ·¢ÏÖÁËÀûÓÃArcadyan¹Ì¼þÖзì϶µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇõè¾¶±éÀú·ì϶£¬£¬£¬£¬£¬£¬£¬×·×ÙΪCVE-2021-20090£¬£¬£¬£¬£¬£¬£¬ÆÀ·ÖΪ9.9¡£¡£¡£¡£¡£¡£¡£¡£´æÔÚÓÚʹÓÃArcadyan¹Ì¼þµÄ·ÓÉÆ÷µÄweb½çÃæÉÏ£¬£¬£¬£¬£¬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËÊýÊ®ÖÖÐͺŵÄÊý°ÙÍǫ̀·ÓÉÆ÷¡£¡£¡£¡£¡£¡£¡£¡£×ÔÉÏÖÜËÄÒÔÀ´£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÔÚÒ°·¢ÏÖÁËÀûÓô˷ì϶µÄ¹¥»÷»î¶¯,Ö¼ÔÚÊÕÊÜÖ¸±êÉ豸²¢×°Öý©Ê¬ÍøÂçMiraiµÄpayload¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/actively-exploited-bug-bypasses-authentication-on-millions-of-routers/


3¡¢RansomEXXÍÅ»ïÐû³ÆÒÑÇÔÈ¡ÉÝ³ÞÆ·ÅÆZegna³¬¹ý20GBÊý¾Ý


RansomEXXÍÅ»ïÐû³ÆÒÑÇÔÈ¡ÉÝ³ÞÆ·ÅÆZegna³¬¹ý20GBÊý¾Ý.jpg


ÀÕË÷ÍÅ»ïRansomEXX½üÆÚÐû³ÆÒÑÇÔÈ¡ÉÝ³ÞÆ·ÅÆZegna³¬¹ý20GBÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£ZegnaÊÇÒâ´óÀû×î³ÛÃûµÄÉݳÞÊ±×°Æ·ÅÆÖ®Ò»£¬£¬£¬£¬£¬£¬£¬ÊÇÈ«ÇòÊÕÈë×î¸ßµÄÄÐ×°Æ·ÅÆ¡£¡£¡£¡£¡£¡£¡£¡£RansomEXX³ÆÒѴӸù«Ë¾ÇÔÈ¡ÁË20.74GBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢°ä²¼ÁË43¸öÎļþ£¨42¸ö500MBµÄÎļþºÍ1¸ö239.54MBµÄÎļþ£©×÷ΪÑù±¾¡£¡£¡£¡£¡£¡£¡£¡£½üÆÚ£¬£¬£¬£¬£¬£¬£¬RansomEXXÍÅ»ïÔøÏ°È¾ÁËÒâ´óÀûÀ­Æë°Â´óÇøµÄϵͳ£¬£¬£¬£¬£¬£¬£¬²¢¹¥»÷ÁËÖйų́ÍåµÄÍÆËã»úÓ²¼þÔì×÷É̼¼¼Î£¨GIGABYTE£©¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120898/data-breach/ransomexx-ransomware-zegna.html


4¡¢Î¢ÈíÖܶþ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´Ô̺¬3¸ö0dayÔÚÄÚµÄ44¸ö·ì϶


΢ÈíÖܶþ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´Ô̺¬3¸ö0dayÔÚÄÚµÄ44¸ö·ì϶.jpg


΢Èí°ä²¼2021Äê8ÔµÄÖܶþ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬×ܼƽ¨¸´ÁË44¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬13¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡¢8¸öÐÅϢй¶·ì϶¡¢2¸ö»Ø¾ø·þÎñ·ì϶ºÍ4¸öºýŪ·ì϶¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ3¸ö0dayΪWindows Print SpoolerÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-36936£©¡¢ Windows LSAÖеĺýŪ·ì϶£¨CVE-2021-36942£©ÒÔ¼°Windows Update Medic·þÎñÖеÄÌáȨ·ì϶£¨CVE-2021-36948£©¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÒѾ­·¢ÏÖ×Ô¶¯ÀûÓÃCVE-2021-36948µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2021-patch-tuesday-fixes-3-zero-days-44-flaws/


5¡¢Kaspersky°ä²¼2021ÄêQ2À¬»øÓʼþºÍ´¹µö»î¶¯µÄ»ã±¨


Kaspersky°ä²¼2021ÄêQ2À¬»øÓʼþºÍ´¹µö»î¶¯µÄ»ã±¨.jpg


Kaspersky°ä²¼ÁËÓйØ2021ÄêQ2À¬»øÓʼþºÍ´¹µö»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£2021ÄêQ2£¬£¬£¬£¬£¬£¬£¬ÆóÒµÕË»§ÒÀÈ»Êǹ¥»÷ÕßµÄÖØÒªÖ¸±êÖ®Ò»¡£¡£¡£¡£¡£¡£¡£¡£ÎªÁËÔö³¤´¹µöÓʼþÖÐÁ´½ÓµÄ¿ÉÐŶÈ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¼Ù×°³ÆÀ´×ÔÔÆ·þÎñµÄÓʼþ£¬£¬£¬£¬£¬£¬£¬ÀýÈçMicrosoft Teams»áÒéµÄ֪ͨµÈ¡£¡£¡£¡£¡£¡£¡£¡£À¬»øÓʼþÊýÁ¿µÄÕ¼±ÈÔÚ3Ô·ݴ¥µ×£¨45.10%£©ºó£¬£¬£¬£¬£¬£¬£¬ÔÚ4Ô·ÝÓ×·ùÉÏÉý£¨45.29%£©£¬£¬£¬£¬£¬£¬£¬µ½6Ô£¨48.03%£©Óë2020ÄêQ4Ï൱¡£¡£¡£¡£¡£¡£¡£¡£À¬»øÓʼþÆðÔ´×î¶àµÄ¹ú¶ÈΪ¶íÂÞ˹£¨26.07%£©£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊǵ¹ú£¨13.97%£©ºÍÃÀ¹ú£¨11.24%£©¡£¡£¡£¡£¡£¡£¡£¡£×î³£¼ûµÄ¶ñÒ⸽¼þÊÇBadun¼Ò×壨7.09%£©¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/spam-and-phishing-in-q2-2021/103548/