ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ48ÖÜ

Ðû²¼Ê±¼ä 2020-11-30

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê11ÔÂ23ÈÕÖÁ11ÔÂ29ÈÕ¹²ÊÕ¼Çå¾²Îó²î48¸ö£¬£¬£¬£¬ £¬ £¬£¬ÖµµÃ¹Ø×¢µÄÊÇVmware Workspace One CVE-2020-4006ÏÂÁî×¢ÈëÎó²î£»£»£» £»£»£» £»Shenzhen C-Data 72408AĬÈÏtelnetЧÀÍÎó²î£»£»£» £»£»£» £»Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤Îó²î£»£»£» £»£»£» £»Barco wePresent WiPG-1600W¹Ì¼þÐÅϢй¶Îó²î£»£»£» £»£»£» £»Mongodb Server RoleName::parseFromBSON()¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÁù¸öÔÂÒÔÀ´Î¢ÈíÈÔδÐÞ¸´Windows10ÖÐÒÑÖªÎó²î£»£»£» £»£»£» £»ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸Áбí£»£»£» £»£»£» £»VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬£¬£¬£¬ £¬ £¬£¬ÉÐδÐû²¼²¹¶¡£¡£¡£¡£»£»£» £»£»£» £»Ñо¿Ö°Ô±·¢Ã÷Win7ºÍServer2008ÖеÄÍâµØÌáȨ0day£»£»£» £»£»£» £»Group-IBÐû²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÕ¹ÍûÆÊÎö±¨¸æ¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬ £¬ £¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£


Ö÷ÒªÇå¾²Îó²îÁбí


1.Vmware Workspace One CVE-2020-4006ÏÂÁî×¢ÈëÎó²î


VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address±£´æÇå¾²Îó²î£¬£¬£¬£¬ £¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬ £¬£¬¿É×¢Èëí§ÒâÏÂÁî²¢Ö´ÐС£¡£¡£¡£

https://docs.opsmanager.mongodb.com/current/release-notes/application/#onprem-server-4-4-3


2.Shenzhen C-Data 72408AĬÈÏtelnetЧÀÍÎó²î


Shenzhen C-Data 72408A TelnetЧÀͱ£´æ¶à¸öĬÈÏÆ¾Ö¤Îó²î£¬£¬£¬£¬ £¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬ £¬£¬¿ÉδÊÚȨ»á¼û×°±¸¡£¡£¡£¡£

https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html


3.Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤Îó²î


Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤±£´æÇå¾²Îó²î£¬£¬£¬£¬ £¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬ £¬£¬¿É×°ÖÃÐ޻ڸĵÄ/¶ñÒâµÄÓ³Ïñ¡£¡£¡£¡£

https://korelogic.com/Resources/Advisories/KL-001-2020-009.txt


4.Barco wePresent WiPG-1600W¹Ì¼þÐÅϢй¶Îó²î


Barco wePresent WiPG-1600W¹Ì¼þÓ³ÏñÖаüÀ¨Ó²±àÂëµÄ¸ùÃÜÂëÉ¢ÁУ¬£¬£¬£¬ £¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬ £¬£¬¿Éͨ¹ý´ËÐÅϢδÊÚȨ»á¼û¡£¡£¡£¡£

https://korelogic.com/Resources/Advisories/KL-001-2020-008.txt


5.Mongodb Server RoleName::parseFromBSON()¾Ü¾øÐ§ÀÍÎó²î


Mongodb Server RoleName::parseFromBSON()±£´æÇå¾²Îó²î£¬£¬£¬£¬ £¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬ £¬£¬¿É¾ÙÐоܾøÐ§À͹¥»÷¡£¡£¡£¡£

https://jira.mongodb.org/browse/SERVER-49142


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Áù¸öÔÂÒÔÀ´Î¢ÈíÈÔδÐÞ¸´Windows10ÖÐÒÑÖªÎó²î


1.jpg


×Ô2020Äê5Ô£¬£¬£¬£¬ £¬ £¬£¬MicrosoftÐû²¼ÁËWindows 10 2004Çå¾²¸üк󣬣¬£¬£¬ £¬ £¬£¬·ºÆðÁËÁ½¸öÎó²î£¬£¬£¬£¬ £¬ £¬£¬µ¼ÖÂSSDÇý¶¯Æ÷µÄ´ÅÅÌË鯬ÕûÀí¹ýÓÚÆµÈÔ£¬£¬£¬£¬ £¬ £¬£¬²¢ÔÚ·ÇSSDÇý¶¯Æ÷ÉÏʵÑéTRIM²Ù×÷¡£¡£¡£¡£µÚÒ»¸öÎó²îʹWin10×Ô¶¯Î¬»¤¹¦Ð§ÎÞ·¨¼Ç×ÅÖØÆôϵͳʱÇý¶¯Æ÷µÄ×îºóÓÅ»¯Ê±¼ä£¬£¬£¬£¬ £¬ £¬£¬µ¼ÖÂÇý¶¯Æ÷ÔÚÿ´ÎÖØÆôÅÌËã»úʱ¶¼¾ÙÐÐË鯬ÕûÀí¡£¡£¡£¡£µÚ¶þ¸öÎó²îµ¼ÖÂWin10µÄÓÅ»¯Çý¶¯Æ÷¹¦Ð§»á¶Ô·ÇSSDÇý¶¯Æ÷¾ÙÐÐTRIM£¬£¬£¬£¬ £¬ £¬£¬Õâ»áµ¼ÖÂÊÂÎñÈÕÖ¾Öйýʧ¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬ £¬ £¬£¬ÔÚ½üÁù¸öÔÂÖ®ºó£¬£¬£¬£¬ £¬ £¬£¬MicrosoftÈÔδÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/windows-10-defrag-trim-bug-still-not-fixed-after-six-months/


2¡¢ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸Áбí


2.jpg


ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸Áбí£¬£¬£¬£¬ £¬ £¬£¬ÆäÖаüÀ¨À´×ÔÌìϸ÷µØµÄ´óÐÍÒøÐкÍÕþ¸®×éÖ¯¡£¡£¡£¡£ÕâЩװ±¸Öоù±£´æÂ·¾¶±éÀúÎó²î£¬£¬£¬£¬ £¬ £¬£¬±»×·×ÙΪCVE-2018-13379£¬£¬£¬£¬ £¬ £¬£¬ËüÓ°ÏìÁË´ó×ÚδÐÞ²¹µÄFortinet FortiOS SSL VPN×°±¸¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î£¬£¬£¬£¬ £¬ £¬£¬´ÓFortinet VPN»á¼ûsslvpn_websessionÎļþÀ´ÇÔÈ¡µÇ¼ƾ֤£¬£¬£¬£¬ £¬ £¬£¬²¢½«ÆäÓÃÓÚÆÆËðÍøÂç²¢°²ÅÅÀÕË÷Èí¼þ¡£¡£¡£¡£Ö»¹Ü¸ÃÎó²îÔÚÒ»Äêǰ¾Í±»¹ûÕæÅû¶£¬£¬£¬£¬ £¬ £¬£¬µ«ºÚ¿ÍÈÔ·¢Ã÷²¢¹ûÕæÁËÁË49577¸ö±£´æ´ËÀàÎó²îµÄ´óÐÍ×°±¸µÄÁбí¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-posts-exploits-for-over-49-000-vulnerable-fortinet-vpns/


3¡¢VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬£¬£¬£¬ £¬ £¬£¬ÉÐδÐû²¼²¹¶¡


3.jpg


VMwareÅû¶ÁËÓ°ÏìÆäWorkspace One¶à¸ö×é¼þÖеÄÌáȨ0day£¬£¬£¬£¬ £¬ £¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÌáȨÒÔÔÚLinuxºÍWindows²Ù×÷ϵͳÉÏÖ´ÐÐÏÂÁ£¬£¬£¬ £¬ £¬£¬ÏÖÔÚÉÐδÐû²¼Ïà¹Ø²¹¶¡³ÌÐò¡£¡£¡£¡£¸ÃÎó²î±»¸ú×ÙΪCVE-2020-4006£¬£¬£¬£¬ £¬ £¬£¬CVSSÆ·¼¶Îª9.1£¬£¬£¬£¬ £¬ £¬£¬ÆäÓ°ÏìÁËVMware Workspace ONE Access¡¢»á¼ûÅþÁ¬Æ÷¡¢Éí·ÝÖÎÀíÆ÷¡¢Éí·ÝÖÎÀíÆ÷ÅþÁ¬Æ÷¡¢VMwareÔÆ»ù½ð»áºÍvRealize SuiteÉúÃüÖÜÆÚÖÎÀíÆ÷¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬ £¬ £¬£¬VMwareÒÑÐû²¼ÔÝʱ½â¾ö²½·¥ÒÔÏû³ý¹¥»÷ǰÑÔ²¢±ÜÃâÎó²îµÄʹÓᣡ£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/vmware-zero-day-patch-pending/161523/


4¡¢Ñо¿Ö°Ô±·¢Ã÷Win7ºÍServer2008ÖеÄÍâµØÌáȨ0day


4.jpg


·¨¹úÑо¿Ö°Ô±·¢Ã÷Windows 7ºÍServer 2008±£´æÍâµØÌáȨ£¨LPE£©0day£¬£¬£¬£¬ £¬ £¬£¬µ±WindowsÇå¾²¹¤¾ß¸üÐÂʱ»áÓ°ÏìÆä²Ù×÷ϵͳ¡£¡£¡£¡£¸ÃÎó²îλÓÚËùÓÐWindows×°ÖÃÖеÄRPC¶ËµãÓ³ÉäÆ÷ºÍDNSCacheЧÀ͵ÄÁ½¸ö¹ýʧÉèÖõÄ×¢²á±íÏîÖУ¬£¬£¬£¬ £¬ £¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄÕâЩע²á±íÀ´¼¤»îWindowsÐÔÄܼàÊÓ»úÖÆËùʹÓõÄ×ÓÃÜÔ¿¡£¡£¡£¡£ÏÖÔÚ0patchƽ̨ÒÑÐû²¼ÔÝʱ΢²¹¶¡£¬£¬£¬£¬ £¬ £¬£¬²¢ÔÚ΢ÈíÐû²¼Õýʽ²¹¶¡Ç°¶ÔËùÓÐÈËÃâ·ÑÌṩ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/windows-7-and-server-2008-zero-day-bug-gets-a-free-patch/


5¡¢Group-IBÐû²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÕ¹ÍûÆÊÎö±¨¸æ


5.jpg


Group-IBÐû²¼Á˶ÔÀ´ÄêÍøÂçÍþвµÄÕ¹ÍûÆÊÎö±¨¸æ£¬£¬£¬£¬ £¬ £¬£¬Ñо¿ÁË2019ÄêϰëÄêÖÁ2020ÄêÉϰëÄêÖ®¼ä¹ú¼ÊÍøÂç·¸·¨ÐÐΪµÄÖ÷Ҫת±ä£¬£¬£¬£¬ £¬ £¬£¬²¢¶ÔÀ´Äê×ö³öÁËÕ¹Íû¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬ £¬ £¬£¬ÀÕË÷Èí¼þ»î¶¯Ôì³ÉÁËÑÏÖØµÄ¾­¼ÃËðʧ£¬£¬£¬£¬ £¬ £¬£¬Ë½Óª¹«Ë¾ºÍÕþ¸®»ú¹¹¶¼Î´ÄÜÐÒÃâ¡£¡£¡£¡£ÔÚ´Ëʱ´ú£¬£¬£¬£¬ £¬ £¬£¬×ܹ²ÓÐÕë¶ÔÁè¼Ý45¸ö¹ú¼ÒµÄ500¶à´ÎÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£Æ¾Ö¤Group-IBµÄÊØ¾ÉÔ¤¼Æ£¬£¬£¬£¬ £¬ £¬£¬ÀÕË÷Èí¼þÍÅ»ïÔì³ÉµÄ×ܲÆÎñËðʧÁè¼Ý10ÒÚÃÀÔª£¨1005186000ÃÀÔª£©¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬ £¬ £¬£¬MazeºÍREvilµÄÓ°Ïì×î´ó£¬£¬£¬£¬ £¬ £¬£¬Õ¼ËùÓй¥»÷µÄ°ëÊýÒÔÉÏ£¬£¬£¬£¬ £¬ £¬£¬Æä´ÎÊÇRyuk¡¢NetWalkerºÍDoppelPaymer¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.group-ib.com/media/gib-report-2020/