ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ38ÖÜ
Ðû²¼Ê±¼ä 2019-09-30±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2019Äê9ÔÂ23ÈÕÖÁ29ÈÕ¹²ÊÕ¼Çå¾²Îó²î43¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇRIOT MQTT-SN CVE-2019-16754¿ÕÖ¸Õë¼ä½ÓÒýÓÃÎó²î; vBulletin widgetConfig[code]Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»Adobe ColdFusioní§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»Microsoft Internet ExplorerÄڴ湤¾ß´¦Öóͷ£Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»phpstudyºóÃÅÖ²ÈëÎó²î¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇTescoÍ£³µÓ¦Óñ£´æÎó²îµ¼ÖÂÊýÍòÍò³µÅÆÍ¼Ïñй¶£»£»£»£»Î¢Èí½ôÆÈÐÞ¸´IEÖеÄRCE 0day¼°DefenderÖеÄDoSÎó²î£»£»£»£»¾Ýͳ¼Æ2019ÄêÃÀ¹úÒÑÓжà´ï500ËùѧУÔâÀÕË÷Èí¼þ¹¥»÷£»£»£»£»iOS 13ºÍiPadOSÎó²î¿Éµ¼ÖµÚÈý·½¼üÅÌ»ñÈ¡ÍêÈ«»á¼ûȨÏÞ£»£»£»£»iOSÎó²îCheckm8¿Éµ¼ÖÂiPhone4µ½XÓÀÊÀÔ½Óü¡£¡£¡£¡£¡£
Ö÷ÒªÇå¾²Îó²îÁбí
RIOT MQTT-SNʵÏÖ±£´æ¿ÕÖ¸ÕëÒýÓÃÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉʹϵͳÍ߽⡣¡£¡£¡£¡£
https://github.com/RIOT-OS/RIOT/pull/12293
2. vBulletin widgetConfig[code]Ô¶³Ì´úÂëÖ´ÐÐÎó²î
vBulletin ajax/render/widget_php routestring´¦Öóͷ£widgetConfig[code]±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£
https://seclists.org/fulldisclosure/2019/Sep/31
3. Adobe ColdFusioní§Òâ´úÂëÖ´ÐÐÎó²î
Adobe ColdFusionij×é¼þ±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿É×¢Èëí§ÒâÏÂÁî²¢Ö´ÐС£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/coldfusion/apsb19-47.html
4. Microsoft Internet ExplorerÄڴ湤¾ß´¦Öóͷ£Ô¶³Ì´úÂëÖ´ÐÐÎó²î
Microsoft Internet Explorer´¦Öóͷ£Äڴ湤¾ß±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://support.microsoft.com/zh-cn/help/4522007/cumulative-security-update-for-internet-explorer
5. phpstudyºóÃÅÖ²ÈëÎó²î
phpstudy±»×¢ÈëºóÃÅ£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ØÖÆÄ¿µÄÓ¦ÓÃϵͳ¡£¡£¡£¡£¡£
https://www.xp.cn/
Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2019/09/20/tesco_parking_app_10s_millions_anpr_photos_exposed/
2¡¢Î¢Èí½ôÆÈÐÞ¸´IEÖеÄRCE 0day¼°DefenderÖеÄDoSÎó²î
΢ÈíÐû²¼½ôÆÈÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´IEÖеÄRCE 0day¼°Windows DefenderÖеÄDoSÎó²î¡£¡£¡£¡£¡£ÆäÖÐIE 0dayΪ¹È¸èÑо¿Ö°Ô±Cl¨¦mentLecigne·¢Ã÷µÄ¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î£¨CVE-2019-1367£©£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¸ÃÎó²î¿ÉÒÔͨ¹ý½«Ä¿µÄÓû§Öض¨ÏòÖÁ¶ñÒâÍøÕ¾À´Ê¹Ó㬣¬£¬£¬ÊÜÓ°ÏìµÄ°æ±¾°üÀ¨IE9¡¢10ºÍ11¡£¡£¡£¡£¡£ÁíÒ»¸öÎó²îÊÇWindows DefenderÖеľܾøÐ§ÀÍÎó²î£¨CVE-2019-1255£©£¬£¬£¬£¬¸ÃÎó²îÓëDefender´¦Öóͷ£ÎļþµÄ·½·¨Óйأ¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î×èÖ¹Õýµ±ÕË»§Ö´ÐÐÕýµ±µÄϵͳÎļþ¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄDefender°æ±¾Îª1.1.16300.1£¬£¬£¬£¬²¢ÒÑÔÚ1.1.16400.2ÖÐÐÞ¸´¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-releases-out-of-band-security-update-to-fix-ie-zero-day-defender-bug/
3¡¢¾Ýͳ¼Æ2019ÄêÃÀ¹úÒÑÓжà´ï500ËùѧУÔâÀÕË÷Èí¼þ¹¥»÷
Æ¾Ö¤ÔÆÇå¾²¹«Ë¾ArmorµÄµ÷ÑУ¬£¬£¬£¬ÃÀ¹úÒÑÓÐ49¸öÑ§ÇøµÄ½ÌÓý»ú¹¹Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬Ê¹µÃ½ÌÓýÐÐÒµ³ÉΪ½ö´ÎÓڵط½Õþ¸®µÄµÚ¶þ´óÒ×Êܹ¥»÷Ä¿µÄ¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÆÊÎöÁË×Ô2019Äê1ÔÂÒÔÀ´¹ûÕæ±¨µÀµÄ¹¥»÷£¬£¬£¬£¬·¢Ã÷ÔÚ2019Äêǰ9¸öÔÂÒÑÓжà´ï500ËùK-12ѧУÔâµ½¹¥»÷£¬£¬£¬£¬¶øÈ¥ÄêÖ»ÓÐ11ËùѧУ¡£¡£¡£¡£¡£½öÔÚ9ÔÂÖÐÑ®µÄÒ»Öܶàʱ¼äÀï¾ÍÓÐ9¸öÐÂÑ§ÇøºÍ1Ëù´óѧÊܵ½¹¥»÷£¬£¬£¬£¬²¨¼°Ô¼100ËùK-12ѧУ¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿µÄùµÒ¸ñÖݵÄÑ§ÇøÊܵ½µÄÍþв×îΪÑÏÖØ£¬£¬£¬£¬¸ÃÖݹ²ÔâÓöÁË7´Î¹¥»÷£¬£¬£¬£¬º¸Ç104ËùѧУ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/hundreds-of-us-schools-hit-by/4¡¢iOS 13ºÍiPadOSÎó²î¿Éµ¼ÖµÚÈý·½¼üÅÌ»ñÈ¡ÍêÈ«»á¼ûȨÏÞ
ÔÎÄÁ´½Ó£º
https://threatpost.com/bug-granting-full-access-keyboards/148638/5¡¢iOSÎó²îCheckm8¿Éµ¼ÖÂiPhone4µ½XÓÀÊÀÔ½Óü
Çå¾²Ñо¿Ô±axi0mXÅû¶iOSÖеÄÇå¾²Îó²îcheckm8£¬£¬£¬£¬¸ÃÎó²î¿ÉÒÔʹiPhone4S£¨A5оƬ£©µ½iPhone8¡¢iPhoneX£¨A11оƬ£©µÄËùÓÐÆ»¹ûÊÖ»ú¼°Í¬¿îAϵÁд¦Öóͷ£Æ÷µÄiPad¡¢iPod touchµÈiOS×°±¸ÓÀÊÀÔ½Óü¡£¡£¡£¡£¡£Ã»ÓÐÌáµ½×îеÄA12ºÍA13ÊÇ·ñÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¸Ã¹¥»÷ʹÓÃÁËbootromÎó²î£¬£¬£¬£¬¼´´æ´¢ÁËiPhoneÆô¶¯Ö¸ÁîµÄÖ»¶Á´æ´¢Æ÷£¨ROM£©Îó²î£¬£¬£¬£¬ÓÉÓڸò¿·ÖÄÚ´æÊÇÖ»¶ÁµÄ£¬£¬£¬£¬Òò´ËÎÞ·¨Í¨¹ýÇå¾²¸üÐÂÀ´ÐÞ¸´Îó²î¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚGithubÉÏÐû²¼ÁËÏà¹ØÎó²îʹÓ㬣¬£¬£¬µ«ÉÐÎÞ¹ûÕæ¿ÉÓõÄÔ½Óü³ÌÐò¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/ios-exploit-checkm8-could-allow-permanent-iphone-jailbreaks/148762/