5GÐÂÎó²î¿É¸ú×ٵ绰λÖü°¹ã²¥Ðéα¾¯±¨£»£»£»£»£»£»£»McAfeeɱ¶¾Èí¼þ´úÂëÖ´ÐÐÎó²î(CVE-2019-3648)

Ðû²¼Ê±¼ä 2019-11-14

1¡¢5GÐÂÎó²î¿É¸ú×ٵ绰λÖü°¹ã²¥Ðéα¾¯±¨


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÆÕ¶É´óѧ£¨Purdue University£©ºÍ°®ºÉ»ª´óѧ£¨University of Iowa£©µÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷¿ìÒª12¸ö5GÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÌåÏÖÕâЩÎó²î¿ÉÔÊÐí¹¥»÷Õß»ñȡĿµÄÓû§µç»°µÄÐÂ/¾ÉÔÝÊ±ÍøÂç±êʶ·û£¬£¬£¬£¬£¬£¬£¬´Ó¶ø¸ú×ٵ绰µÄλÖ㬣¬£¬£¬£¬£¬£¬ÉõÖÁÐ®ÖÆÑ°ºôÐŵÀ¾ÙÐÐÐéαµÄ½ôÆÈ¾¯±¨¹ã²¥ ¡£¡£¡£ÔÚijЩÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ÕâЩÎó²î¿ÉÄܱ»ÓÃÀ´½«·äÎÑÅþÁ¬½µ¼¶Îª²»Ì«Çå¾²µÄ±ê×¼ ¡£¡£¡£Ò»Ð©ÐµĹ¥»÷Ò²¿ÉÄÜÔÚÏÖÓеÄ4GÍøÂçÉϱ»Ê¹Óà ¡£¡£¡£¼øÓÚÎó²îµÄÐÔ×Ó£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÌåÏÖËûÃDz»ÍýÏë¹ûÕæÆäPoC´úÂ룬£¬£¬£¬£¬£¬£¬µ«ËûÃǽ«ÕâЩ·¢Ã÷֪ͨÁËÈ«Çò·äÎÑÍøÂçGSMЭ»á£¨GSMA£© ¡£¡£¡£GSMAûÓÐ͸¶ÊÇ·ñ¿ÉÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬£¬Ò²Ã»ÓÐ͸¶ÐÞ¸´Ê±¼ä ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://finance.yahoo.com/news/5g-flaws-track-phone-locations-163014364.html


2¡¢Intel cpuÊÜÐÂÍÆ²âÖ´ÐÐÎó²îZombieload v2Ó°Ïì


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Intel CPUÔÙÆØÐµIJàÐŵÀ¹¥»÷ZombieLoad 2£¨ÓÖ±»³ÆÎªTSXÒì²½ÖÐÖ¹£©£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÉõÖÁÓ°ÏìÁË×îеÄCascade Lake¼Ü¹¹ ¡£¡£¡£Zombiload v2£¨CVE-2019-11135£©ÊÇZombieload v1Îó²îµÄÒ»ÖÖ±äÌ壬£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷ʹÓÃÁËIntelÊÂÎñͬ²½À©Õ¹£¨TSX£©Òì²½ÖÐÖ¹²Ù×÷£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚCPUÄÚ²¿µÄ¶ÁÈ¡²Ù×÷Ôì³É³åͻʱй¶Êý¾Ý ¡£¡£¡£IntelÔÚÒ»·Ý±¨¸æÖÐÌåÏÖÖ§³ÖIntel TSX ÊÖÒÕµÄWhiskey Lake¡¢Cascade LakeÒÔ¼°Coffee Lake R´¦Öóͷ£Æ÷¾ù»áÊܵ½²î±ðˮƽµÄÓ°Ïì ¡£¡£¡£IntelÒѾ­Îª´ËÐû²¼ÁËCPU΢´úÂë¸üР¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/latest-intel-cpus-affected-by-new-tsx-speculative-attack/


3¡¢McAfeeɱ¶¾Èí¼þ´úÂëÖ´ÐÐÎó²î(CVE-2019-3648)


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


SafeBreach Labs·¢Ã÷McAfee·À²¡¶¾Èí¼þÊÜ´úÂëÖ´ÐÐÎó²î£¨CVE-2019-3648£©µÄÓ°Ï죬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÈÆ¹ýMcAfeeµÄ×ÔÎÀ»úÖÆ£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö¶ÔÊÜѬȾϵͳµÄ½øÒ»²½¹¥»÷ ¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚδÑéÖ¤¼ÓÔØDLLµÄÊðÃûµ¼ÖµÄ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽ«í§ÒâδÊðÃûµÄDLL¼ÓÔØµ½ÒÔNT AUTHORITY\SYSTEMȨÏÞÔËÐеĶà¸öЧÀÍÖÐ ¡£¡£¡£¸Ã¹¥»÷»¹¿ÉÒÔÈÆ¹ýÓ¦ÓóÌÐò°×Ãûµ¥±£»£»£»£»£»£»£»¤²¢×èÖ¹±»Çå¾²Èí¼þ¼ì²âµ½ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/mcafee-antivirus-software-impacted-by-code-execution-vulnerability/


4¡¢AdobeÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Æä²úÆ·ÖеĶà¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


AdobeÔÚ11ÔÂÇå¾²¸üÐÂÖÐÐÞ¸´ÁËIllustrator¡¢Ã½Ìå±àÂëÆ÷µÈ²úÆ·ÖеĶà¸öÎó²î ¡£¡£¡£ÆäÖÐIllustrator 2019ÖÐÐÞ¸´ÁËÑÏÖØ¼¶±ðµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-8247ºÍCVE-2019-8248£©£¬£¬£¬£¬£¬£¬£¬Windowsƽ̨°æ±¾23.1ºÍ¸üÔç°æ±¾Êܵ½Ó°Ïì ¡£¡£¡£Ã½Ìå±àÂëÆ÷ÖÐÒ²ÐÞ¸´ÁËÒ»¸öÑÏÖØµÄRCEÎó²î£¨CVE-2019-8246£©£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁ˰汾13.1 ¡£¡£¡£ÆäËüÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/adobe-critical-bugs-illustrator-media-encoder/150114/


5¡¢ÃÀ¹úÁãÊÛÉÌOrvisÄÚ²¿Æ¾Ö¤ÔÚPastebinÉÏй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹úÁãÊÛÉÌOrvisµÄÄÚ²¿Æ¾Ö¤ÔÚPastebin.comÍøÕ¾ÉÏй¶ ¡£¡£¡£Æ¾Ö¤ÊÓ²ì¼ÇÕß²¼À³¶÷¡¤¿ËÀײ¼Ë¹£¨Brian Krebs£©µÄ±¨µÀ£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÎļþ°üÀ¨¸Ã¹«Ë¾µÄ°²·ÀÉãÏñͷƾ֤¡¢ÃÅ¿ØÖÆÆ÷ƾ֤¼°±¨¾¯´úÂë¡¢FTPƾ֤ÉõÖÁÓë·À»ðǽ¡¢Â·ÓÉÆ÷¡¢Êý¾Ý¿âЧÀÍÆ÷µÄÖÎÀíÔ±ÕË»§ÓйصĴ¿Îı¾Óû§ÃûºÍÃÜÂëµÈ ¡£¡£¡£ÕâЩÊý¾Ý»®·ÖÓÚ10ÔÂ4ÈÕºÍ22ÈÕÁ½´Î±»Ðû²¼µ½PastebinÉϲ¢Ì»Â¶ÁËÊýÖܵÄʱ¼ä ¡£¡£¡£Orvis½²»°È˳ÆÕâЩÎļþÖÐµÄÆ¾Ö¤Ö»ÊÇ¾ÉÆ¾Ö¤£¬£¬£¬£¬£¬£¬£¬¹ØÁªµÄÐí¶à×°±¸¶¼ÒÑÍ£Ó㬣¬£¬£¬£¬£¬£¬²¢ÌåÏÖÕýÔÚÊÓ²ìÊÂÎñÔõÑù±¬·¢ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/orvis-passwords-leaked-twice-on/


6¡¢ÀÕË÷Èí¼þPureLocker¿ÉÕë¶ÔËùÓÐÖ÷Á÷²Ù×÷ϵͳ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ñо¿Ö°Ô±·¢Ã÷Ò»¸öеÄÀÕË÷Èí¼þPureLocker£¬£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔÕë¶ÔËùÓÐÖ÷Á÷²Ù×÷ϵͳ£¬£¬£¬£¬£¬£¬£¬°üÀ¨Windows¡¢LinuxºÍmacOS ¡£¡£¡£¸Ã¶ñÒâÈí¼þ¾­ÓÉÈ«ÐÄÉè¼Æ£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚɳºÐÇéÐÎÖÐÒþ²Ø¶ñÒâÐÐΪ£¬£¬£¬£¬£¬£¬£¬Ã°³ä¼ÓÃÜ¿âCrypto++²¢Ê¹ÓÿâÖг£¼ûµÄ¹¦Ð§À´²¥·ÅÒôÀÖ ¡£¡£¡£ÔÚÒÑÍùµÄÈý¸öÐÇÆÚÖУ¬£¬£¬£¬£¬£¬£¬PureLockerÏÕЩÍêÈ«ÌÓ±ÜÁËVirusTotalÉÏ·À²¡¶¾ÒýÇæµÄ¼ì²â ¡£¡£¡£¸ÃÀÕË÷Èí¼þµÄ±à³ÌÓïÑÔÊÇPureBasic£¬£¬£¬£¬£¬£¬£¬ÆäÔÚ¼ÓÃÜÎļþºó¸½¼ÓµÄÀ©Õ¹ÃûΪ.CR1 ¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ËüÖØ¸´Ê¹ÓÃÁËMore_EggsºóÃÅÖеĴúÂë ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/purelocker-ransomware-can-lock-files-on-windows-linux-and-macos/