΢ÈíÖÒÑÔAdob??e Type Manager¿âÖеÄÁ½¸öRCE 0day£»£»£»£»LenovoÐÞ¸´Ô¤×°ÖÃÈí¼þVantageÖеÄÌáȨÎó²î

Ðû²¼Ê±¼ä 2020-03-24

1.΢ÈíÖÒÑÔAdobe Type Manager¿âÖеÄÁ½¸öRCE 0day


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



΢ÈíÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬ÖÒÑÔWindows Adobe Type Manager¿âÖеÄÁ½¸öRCE 0day£¬£¬£¬£¬ÕâÁ½¸öÎó²îÓ°ÏìÁËÄ¿½ñËùÓÐÊÜÖ§³ÖµÄWindowsºÍWindows Server°æ±¾¡£¡£ ¡£¡£¡£Îó²î±£´æÓÚAdobe Type Manager¿â´¦Öóͷ£Adobe Type 1 PostScript×ÖÌåÃûÌõķ½·¨ÖУ¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¶àÖÖ·½·¨Ê¹ÓôËÎó²î£¬£¬£¬£¬ÀýÈç˵·þÓû§·­¿ª¶ñÒâÎĵµ»òÔÚWindowsÔ¤ÀÀ´°¸ñÖÐÉó²éËü¡£¡£ ¡£¡£¡£Î¢ÈíÒѾ­·¢Ã÷ʹÓôËÎó²îµÄÓÐÏÞÕë¶ÔÐÔ¹¥»÷¡£¡£ ¡£¡£¡£½¨ÒéÔÚWindows×ÊÔ´ÖÎÀíÆ÷ÖнûÓá°Ô¤ÀÀ´°¸ñ¡±ºÍ¡°ÏêϸÐÅÏ¢´°¸ñ¡±£¬£¬£¬£¬ÒÔ¼õÇáʹÓÃΣº¦£¬£¬£¬£¬ÁíÍâÁ½¸ö»º½â²½·¥ÊǽûÓÃWebClientЧÀͺÍÖØÃüÃû¡°ATMFD.DLL¡±¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200006


2.¼¸ÄÚÑÇÒé»áÑ¡¾Ùǰ»¥ÁªÍøÖÐÖ¹£¬£¬£¬£¬ÁªÍøÂʽöΪ12%


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤NetBlocks»¥ÁªÍøÊÓ²ìÕ¾µÄÍøÂçÊý¾Ý£¬£¬£¬£¬3ÔÂ20ÈÕ¼¸ÄÚÑǹ²ºÍ¹úµÄ»¥ÁªÍø±»Çжϣ¬£¬£¬£¬¸Ã¹ú¼ÒÔ­¶¨ÓÚ3ÔÂ22ÈÕ£¨ÐÇÆÚÈÕ£©¾ÙÐÐÒé»áÑ¡¾ÙºÍÏÜ·¨¹«Í¶¡£¡£ ¡£¡£¡£ÊÖÒÕÖ¸±êÏÔʾ£¬£¬£¬£¬¸Ã¹ú¼ÒËùÓÐ6¸öÍøÂç¾ùÒѹرգ¨°üÀ¨Ö÷ÒªÔËÓªÉÌOrangeÔÚÄÚ£©£¬£¬£¬£¬»¥ÁªÍøÅþÁ¬Ë®Æ½½öΪͨ³£µÄ12%£¬£¬£¬£¬·äÎÑÍøÂçºÍ¹ÌÍøÒ²Êܵ½ÀàËÆµÄÓ°Ïì¡£¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬£¬¼¸ÄÚÑÇÓÚ3ÔÂ21ÈÕ£¨ÐÇÆÚÁù£©ÍíÉÏ8:00×îÏÈ·â±ÕÉ罻ýÌ壬£¬£¬£¬°üÀ¨Twitter¡¢FacebookºÍInstagram¾ù±»·â±Õ£¬£¬£¬£¬WhatAppЧÀÍÆ÷Ò²Êܵ½²¿·ÖÏÞÖÆ¡£¡£ ¡£¡£¡£·â±ÕÒ»Ö±Ò»Á¬ÁË36¸öСʱ£¬£¬£¬£¬Ö±µ½3ÔÂ23ÈÕ£¨ÐÇÆÚÒ»£©ÉÏÎç8:00²Å½â½û¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://netblocks.org/reports/internet-cut-across-guinea-ahead-of-elections-xAGoQxAz


3.Ameren SiouxºÍLabadieµç³§µÄ¹©Ó¦ÉÌÔâÀÕË÷Èí¼þ¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹úÃÜËÕÀïÖÝAmeren SiouxºÍLabadieµç³§µÄ×°±¸¹©Ó¦ÉÌ£¨LTI Power Systems£©ÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬²¿·ÖÊý¾ÝÎļþ±»ÇÔ¡£¡£ ¡£¡£¡£ÕâЩÎļþ°üÀ¨Á½¼Òµç³§µÄ×°±¸Í¼ºÍʾÒâͼ£¬£¬£¬£¬ÀýÈç²»ÖÐÖ¹µçÔ´×°±¸µÄÏêϸԭÀíͼ£¬£¬£¬£¬¸Ã×°±¸ÓÃÓÚÔÚÖÐֹʱ´úÌṩÔÝʱ±¸ÓõçÔ´¡£¡£ ¡£¡£¡£Ê¥Â·Ò×˹¹«¹²¹ã²¥µç̨³ÆÕâЩÊý¾ÝÎļþµÄʱ¼äÔÚ1996ÄêÖÁ2017ÄêÖ®¼ä¡£¡£ ¡£¡£¡£ÎļþÖÐËÆºõ²»Éæ¼°¿Í»§ÐÅÏ¢¡£¡£ ¡£¡£¡£»£»£»£»ªÊ¢¶Ù´óÑ§ÍøÂçÇå¾²Õ½ÂÔÍýÏëµÄÈÏÕæÈËÇÇ¡¤ÉáÀÕ£¨Joe Scherrer£©ÌåÏÖ£¬£¬£¬£¬¸Ã¹¥»÷µÄÄ¿µÄÖ÷ÒªÊÇΪÁËÇÔȡ֪ʶ²úȨ¡£¡£ ¡£¡£¡£Ameren½²»°ÈËÌåÏָù«Ë¾ÕýÔÚ¶Ô´ËÊÂÎñ¾ÙÐÐÊӲ죬£¬£¬£¬²¢Ôö²¹³ÆÃ»ÓÐÀíÓÉÒÔΪй¶µÄÊý¾ÝÉæ¼°ÉñÃØ»ò¶ÔÆäÔËÓªÖÁ¹ØÖ÷Òª¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://news.stlpublicradio.org/post/ameren-missouri-equipment-supplier-targeted-ransomware-attack#stream/0


4.ÑÀÂò¼Ó¹ú¼ÒÒøÐÐÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬²¿·ÖЧÀÍÖÐÖ¹


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÑÀÂò¼Ó¹ú¼ÒÒøÐÐÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬¾¯ÆÓÖ±ÔÚ¾ÙÐÐÊӲ졣¡£ ¡£¡£¡£¸ÃÒøÐÐÌåÏÖ¹¥»÷±¬·¢ÔÚ3ÔÂ14ÈÕÐÇÆÚÁù£¬£¬£¬£¬¶ÔÆäЧÀÍÔì³ÉÁËһЩÖÐÖ¹£¬£¬£¬£¬µ«ÓÉÓÚÕË»§ÊÇÓɵ¥¶ÀµÄϵͳÉúÑĺͱ£»£»£»£»¤µÄ£¬£¬£¬£¬Òò´ËûÓпͻ§ÕÊ»§Êܵ½Ó°Ïì¡£¡£ ¡£¡£¡£ÆäÐÅÏ¢ÊÖÒÕºÍÍøÂçÇå¾²ÍŶÓÁ¬Ã¦½ÓÄÉÐж¯×èÖ¹Á˶ñÒâÈí¼þ£¬£¬£¬£¬²¢ÊÔͼȷ¶¨¹¥»÷Ô´¡£¡£ ¡£¡£¡£ÏÖÔÚÆäЧÀÍ»ù±¾ÉÏÒѻָ´ÔÚÏߣ¬£¬£¬£¬µ«¸ÃÒøÐÐÈ·ÈϹ¥»÷ÕßÇÔÈ¡Á˲¿·Ö»áÔ±ºÍ¿Í»§µÄÊý¾Ý£¬£¬£¬£¬¸ÃÒøÐÐÕýÔÚ½ÓÄɲ½·¥Í¨ÖªÊܲ¨¼°µÄÓû§¡£¡£ ¡£¡£¡£ÓÉÓÚ¾¯·½ÊӲ컹ÔÚ¾ÙÐÐÖУ¬£¬£¬£¬¸ÃÒøÐÐûÓÐ͸¶¸ü¶àÐÅÏ¢¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.jamaicaobserver.com/latestnews/Police_investigate_ransomware_attack_at_Jamaica_National


5.¹¥»÷ÕßʹÓÃEnigmaSparkÕë¶ÔÖж«£¬£¬£¬£¬ÓëµØÔµÕþÖÎÓйØ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


IBM X-ForceÍŶӷ¢Ã÷·Ö·¢EnigmaSparkºóÃŵÄй¥»÷»î¶¯£¬£¬£¬£¬¸Ã»î¶¯¿ÉÄܳöÓÚÕþÖÎÄîÍ·£¬£¬£¬£¬ËƺõÓë×èµ²×î½üµÄÖж«Çå¾²ÍýÏëÓйØ¡£¡£ ¡£¡£¡£¹¥»÷ÕßÊÔͼÃé×¼¶ÔÖж«Çå¾²ÍýÏëÓÐÖØ´óÐËȤ»òÌṩ֧³ÖµÄ×éÖ¯/»ú¹¹µÄÍøÂçÇéÐΣ¬£¬£¬£¬Í¨¹ýÈ«ÐÄÖÆ×÷µÄ¡¢ÏêϸµÄ¡¢¾ßÓÐÕþÖÎÖ¸¿ØµÄÓÕ¶üÎļþ£¬£¬£¬£¬ÉøÍ¸ÊÕ¼þÈ˵ÄÇéÐβ¢¾ÙÐÐÊý¾ÝÇÔÈ¡µÈ¶ñÒâ»î¶¯¡£¡£ ¡£¡£¡£EnigmaSparkµÄÓÕ¶üÎĵµÓëÒÔǰ·Ö·¢JhoneRATµÄÓÕ¶üÎĵµ¾ßÓÐÍêÈ«ÏàͬµÄ±àÒëÈÕÆÚ/ʱ¼ä£¨2020-01-14 07:54:00£©£¬£¬£¬£¬²¢ÇÒÔÚTTP¡¢Õë¶ÔÐÔÉ϶¼¾ßÓÐÏàËÆÖ®´¦£¬£¬£¬£¬Òò´ËEnigmaSpark»î¶¯¿ÉÄÜÓëJhoneRATÓйأ¬£¬£¬£¬²¢ÇÒ¶¼¿ÉÄÜÊôÓÚ·¸·¨ÍÅ»ïMolerats¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityintelligence.com/posts/EnigmaSpark-Politically-Themed-Cyber-Activity-Highlights-Regional-Opposition-to-Middle-East-Peace-Plan/


6.LenovoÐÞ¸´Ô¤×°ÖÃÈí¼þVantageÖеÄÌáȨÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


LenovoÐÞ¸´ÆäPCԤװÖÃÈí¼þVantageÖеÄÁ½¸öÌáȨÎó²î£¨CVE-2020-8319ºÍCVE-2020-8324£©¡£¡£ ¡£¡£¡£Vantage×Ô2016Äê×óÓÒÐû²¼ÒÔÀ´£¬£¬£¬£¬È¡´úÁËLenovo Solutions Center£¨LSC£©³ÉΪLenovo×°±¸µÄÍÆ¼öƽ̨ÖÎÀíºÍϵͳ¸üй¤¾ß¡£¡£ ¡£¡£¡£VantageÒÀÀµÓÚϵͳ½Ó¿Ú»ù´¡Ð§ÀÍ£¬£¬£¬£¬¸ÃЧÀÍͨ¹ýÖØ´óµÄ²å¼þϵͳִÐÐÖÖÖÖåÚÏëÌØ¶¨µÄÐÐΪ¡£¡£ ¡£¡£¡£ÓÉÓÚûÓжԲå¼þ×Ô¼º¼ÓÔØµÄDLLÖ´ÐÐÖ¤Êé¼ì²é£¬£¬£¬£¬Òò´Ë¿ÉÒÔͨ¹ýÌæ»»TouchScreenContronlDLL.dll»ñµÃSYSTEMȨÏÞ¡£¡£ ¡£¡£¡£½¨ÒéÓû§½«Vantage¸üÐÂÖÁ×îа汾¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.pentestpartners.com/security-blog/privesc-in-lenovo-vantage-two-minutes-later/