¡¾Îó²îͨ¸æ¡¿Trend Micro Apex One 7Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-07-30

0x00 Îó²î¸ÅÊö

Apex OneÊÇTrend Micro¿ª·¢µÄÒ»Ì×Äܹ»Ìṩ×Ô¶¯Íþв¼ì²âºÍÏìÓ¦¹¦Ð§µÄ¶ËµãÇå¾²·À»¤Èí¼þ¡£¡£ ¡£¡£¡£¡£¡£

2021Äê7ÔÂ28ÈÕ£¬£¬ £¬£¬ £¬Trend Micro£¨Ç÷ÊÆ¿Æ¼¼£©Ðû²¼Ç徲ͨ¸æ£¬£¬ £¬£¬ £¬¹ûÕæÁËÆäApex One ºÍApex One as a Service£¨Apex One SaaS£©ÖеĶà¸öÇå¾²Îó²î£¬£¬ £¬£¬ £¬¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÕâЩÎó²îÈÆ¹ýÉí·ÝÈÏÖ¤¡¢ÉÏ´«í§ÒâÎļþ¡¢ÌáÉýȨÏÞ»òÖ´ÐÐÆäËüδÊÚȨ²Ù×÷¡£¡£ ¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬ £¬£¬ £¬ÆäÖв¿·ÖÎó²îÒѾ­¼ì²âµ½ÔÚҰʹÓᣡ£ ¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

±¾´Î¹ûÕæµÄ4¸öÎó²îÖУ¬£¬ £¬£¬ £¬CVE-2021-32464ºÍCVE-2021-36742¿ÉÍâµØÊ¹Ó㬣¬ £¬£¬ £¬CVE-2021-32465ºÍCVE-2021-36741¿ÉÔ¶³ÌʹÓ㬣¬ £¬£¬ £¬ËüÃǵÄÎó²îÆÀ¼¶¾ùΪ¸ßΣ¡£¡£ ¡£¡£¡£¡£¡£ÆäÏêÇéÈçÏ£º

Apex OneȨÏÞÌáÉýÎó²î£¨CVE-2021-32464£©

ÓÉÓÚȨÏÞ·ÖÅɲ»×¼È·£¬£¬ £¬£¬ £¬Apex One ºÍApex One as a ServiceÖб£´æÈ¨ÏÞÌáÉýÎó²î£¬£¬ £¬£¬ £¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚÖ´ÐÐÌØ¶¨¾ç±¾Ö®Ç°¶ÔÆä¾ÙÐÐÐ޸쬣¬ £¬£¬ £¬µ«¹¥»÷Õß±ØÐèÊ×ÏÈ»ñµÃÔÚÄ¿µÄϵͳÉϽϵÍȨÏ޵ĴúÂëÖ´ÐÐÄÜÁ¦¡£¡£ ¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.8¡£¡£ ¡£¡£¡£¡£¡£

 

Apex OneÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2021-32465£©

ÓÉÓÚApex OneºÍApex One as a ServiceÖб£´æÒ»¸ö²»×¼È·µÄȨÏÞ±£´æÎó²î£¬£¬ £¬£¬ £¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚÄ¿µÄϵͳÉÏÖ´Ðй¥»÷²¢ÈƹýÉí·ÝÑéÖ¤£¬£¬ £¬£¬ £¬µ«¹¥»÷Õß±ØÐèÊ×ÏÈ»ñµÃÔÚÄ¿µÄϵͳÉϽϵÍȨÏ޵ĴúÂëÖ´ÐÐÄÜÁ¦¡£¡£ ¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.5¡£¡£ ¡£¡£¡£¡£¡£

 

Apex Oneí§ÒâÎļþÉÏ´«Îó²î£¨CVE-2021-36741£©

ÓÉÓÚApex OneºÍApex One as a ServiceÖб£´æÒ»¸ö²»×¼È·µÄÊäÈëÑéÖ¤Îó²î£¬£¬ £¬£¬ £¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚÄ¿µÄϵͳÉÏÉÏ´«í§ÒâÎļþ£¬£¬ £¬£¬ £¬µ«¹¥»÷Õß±ØÐèÊ×ÏÈ»ñµÃµÇ¼¸Ã²úÆ·ÖÎÀí¿ØÖÆÌ¨µÄÄÜÁ¦¡£¡£ ¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.1£¬£¬ £¬£¬ £¬ÏÖÔÚÒѾ­¼ì²âµ½ÔÚҰʹÓᣡ£ ¡£¡£¡£¡£¡£

 

Apex OneÍâµØÌáȨÎó²î£¨CVE-2021-36742£©

ÓÉÓÚApex OneºÍApex One as a ServiceÖб£´æÒ»¸ö²»×¼È·µÄÊäÈëÑéÖ¤Îó²î£¬£¬ £¬£¬ £¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚÄ¿µÄϵͳÉÏʵÏÖÍâµØÌáÉýȨÏÞ£¬£¬ £¬£¬ £¬µ«¹¥»÷Õß±ØÐèÊ×ÏÈ»ñµÃÔÚÄ¿µÄϵͳÉϽϵÍȨÏ޵ĴúÂëÖ´ÐÐÄÜÁ¦¡£¡£ ¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.8£¬£¬ £¬£¬ £¬ÏÖÔÚÒѾ­¼ì²âµ½ÔÚҰʹÓᣡ£ ¡£¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

Trend Micro Apex One 2019 (On-prem)£¨Windows£©

Trend Micro Apex One SaaS£¨Windows£©

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÕâЩÎó²îÒѾ­ÐÞ¸´¡£¡£ ¡£¡£¡£¡£¡£¼øÓÚ²¿·ÖÎó²îÒѾ­·ºÆðÔÚҰʹÓ㬣¬ £¬£¬ £¬½¨ÒéÊÜÓ°ÏìµÄ¿Í»§ÊµÊ±×°ÖÃÒÔϲ¹¶¡£¡£ ¡£¡£¡£¡£¡£º

Apex One (on-prem)  CP 9601²¹¶¡

Apex One as a Service (SaaS)  2021 Äê 7 ÔÂÔ¶Ȳ¹¶¡

ÏÂÔØÁ´½Ó£º

https://success.trendmicro.com/solution/000287819

 

0x03 ²Î¿¼Á´½Ó

https://success.trendmicro.com/solution/000287819

https://www.trendmicro.com/en_ca/business/products/downloads.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32464

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-07-30

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ¼øºÚµ£±£Íø

¹Ø×¢ÒÔϹ«Öںţ¬£¬ £¬£¬ £¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png   image.png