ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ9ÖÜ

Ðû²¼Ê±¼ä 2021-03-01

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2021Äê02ÔÂ22ÈÕÖÁ02ÔÂ28ÈÕ¹²ÊÕ¼Çå¾²Îó²î53¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇNETGEAR Nighthawk R7800Ó²±àÂëÑéÖ¤ÈÆ¹ýÎó²î£»£»£»Siemens SINEC NMS FirmwareFileUtils extractToFolderĿ¼±éÀú´úÂëÖ´ÐÐÎó²î£»£»£»TP-Link AC1750 sync-serverÕ»Òç³öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»On Netshield NANO CVE-2021-3149ÏÂÁî×¢ÈëÎó²î£»£»£»Adobe Bridge CVE-2021-21065Ô½½çд´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ΢Èí·¢Ã÷Windows Win32kÌáȨ0dayÒѱ»ÔÚҰʹÓ㻣»£»Ð¶ñÒâÈí¼þSilver SparrowÒÑѬȾ½ü3Íǫ̀Mac×°±¸£»£»£»FireEye³ÆÕë¶ÔAccellion FTAµÄ¹¥»÷ÓëFIN11Óйأ»£»£»·É»úÖÆÔìÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹûÕæ£»£»£»·ÒÀ¼TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬¿Í»§Ð§ÀÍÔÝʱÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£


> Ö÷ÒªÇå¾²Îó²îÁбí


1.NETGEAR Nighthawk R7800Ó²±àÂëÑéÖ¤ÈÆ¹ýÎó²î


NETGEAR Nighthawk R7800 apply_save.cgiʹÓÃÓ²±àÂëÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔROOTȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-252/


2.Siemens SINEC NMS FirmwareFileUtils extractToFolderĿ¼±éÀú´úÂëÖ´ÐÐÎó²î


Siemens SINEC NMS FirmwareFileUtils extractToFolder±£´æÄ¿Â¼±éÀúÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔWEBÓ¦ÓóÌÐòÉÏÏÂÎĶÁÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-253/


3.TP-Link AC1750 sync-serverÕ»Òç³öÔ¶³Ì´úÂëÖ´ÐÐÎó²î


TP-Link AC1750 sync-server MACµØµã´¦Öóͷ£±£´æÕ»Òç³öÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔROOTȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-215/


4.On Netshield NANO CVE-2021-3149ÏÂÁî×¢ÈëÎó²î


On Netshield NANO /usr/local/webmin/System/manual_ping.cgi±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔWEBÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://www.digitaldefense.com/resources/vulnerability-research/netshield-corporation-nano-25/


5.Adobe Bridge CVE-2021-21065Ô½½çд´úÂëÖ´ÐÐÎó²î


Adobe Bridge´¦Öóͷ£Îļþ±£´æÔ½½çдÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»ò¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://helpx.adobe.com/security/products/bridge/apsb21-07.html


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Î¢Èí·¢Ã÷Windows Win32kÌáȨ0dayÒѱ»ÔÚҰʹÓÃ


1.jpg


΢Èí·¢Ã÷Windows Win32kÖеÄÌáȨ0day£¨CVE-2021-1732£©Òѱ»ÔÚҰʹÓᣡ£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚwin32k.sys½¹µãÄÚºË×é¼þÖУ¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý´¥·¢ÊͷźóʹÓÃÎó²î½«ÆäȨÏÞÌáÉýµ½admin¼¶±ð£¬£¬£¬£¬£¬¾ßÓлù±¾Óû§È¨Ï޵Ĺ¥»÷Õß²»ÐèÒªÓëÓû§½»»¥¼´¿ÉʹÓøÃÎó²î¡£¡£¡£¡£¡£¡£¡£¾ÝÊӲ죬£¬£¬£¬£¬¸ÃÎó²îÒѱ»APT×éÖ¯BitterºÍT-APT-17ʹÓ㬣¬£¬£¬£¬DBAPPSecurityÔò³ÆÆäÓÚ12Ô·¢Ã÷ÁË¿ª·¢ÈÕÆÚΪ2020Äê5ÔµÄÑù±¾¡£¡£¡£¡£¡£¡£¡£¶ø×Ô2021Äê2ÔÂ×îÏÈ£¬£¬£¬£¬£¬ºÚ¿ÍÖ»ÔÚÉÙÊýÕë¶ÔÖж«µÄ¹¥»÷ÖÐʹÓÃÁËCVE-2021-1732Îó²î¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/recently-fixed-windows-zero-day-actively-exploited-since-mid-2020/


2¡¢Ð¶ñÒâÈí¼þSilver SparrowÒÑѬȾ½ü3Íǫ̀Mac×°±¸


2.jpg


Red CanaryÑо¿Ö°Ô±·¢Ã÷Õë¶ÔMac×°±¸µÄжñÒâÈí¼þSilver Sparrow¡£¡£¡£¡£¡£¡£¡£×èÖ¹2ÔÂ17ÈÕ£¬£¬£¬£¬£¬Silver SparrowÒÑÔÚ153¸ö¹ú¼ÒºÍµØÇøÑ¬È¾ÁË29139¸ömacOSÖÕ¶Ë£¬£¬£¬£¬£¬²¢ÔÚÃÀ¹ú¡¢Ó¢¹ú¡¢¼ÓÄô󡢷¨¹úºÍµÂ¹ú´ó×ÚÈö²¥¡£¡£¡£¡£¡£¡£¡£Óë´ó´ó¶¼Ê¹ÓÃ'preinstall'ºÍ'postinstall'¾ç±¾µÄ¶ñÒâÈí¼þ²î±ð£¬£¬£¬£¬£¬Silver SparrowʹÓÃJavaScriptÖ´ÐÐÏÂÁ£¬£¬£¬£¬´Ó¶øºÜÄÑÆ¾Ö¤ÏÂÁîÐвÎÊý¼ì²â¶ñÒâ»î¶¯¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þµÄÕæÕýÄ¿µÄÏÖÔÚÈÔÈ»ÊǸöÃÕ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/30000-macs-infected-with-new-silver-sparrow-malware/


3¡¢FireEye³ÆÕë¶ÔAccellion FTAµÄ¹¥»÷ÓëFIN11ÓйØ


3.jpg


Çå¾²¹«Ë¾FireEye³Æ£¬£¬£¬£¬£¬2020Äê12Ôµ½2021Äê1ÔÂÖ®¼äʹÓÃAccellion FTAЧÀÍÆ÷ÖÐ0dayµÄ¹¥»÷»î¶¯ÓëFIN11Óйأ¬£¬£¬£¬£¬²¨¼°ÁËÈ«ÇòÔ¼100¼Ò¹«Ë¾¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÖ÷ҪʹÓÃÁËËĸöÎó²îÀ´¹¥»÷FTAЧÀÍÆ÷£¬£¬£¬£¬£¬²¢×°ÖÃÁËÒ»¸öÃûΪDEWMODEµÄWeb Shell£¬£¬£¬£¬£¬À´ÏÂÔØÊܺ¦ÕßFTA×°±¸ÉÏ´æ´¢µÄÎļþ¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¹«Ë¾ºÍ×éÖ¯°üÀ¨Fugro¡¢Danaher¡¢Singtel¡¢Jones¡¢ÐÂÎ÷À¼´¢±¸ÒøÐкͰĴóÀûÑÇ֤ȯºÍͶ×ÊίԱ»á£¨ASIC£©µÈ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ºÚ¿ÍÔÚClopµÄÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏÁгöÁ˲¿·Ö¹«Ë¾£¬£¬£¬£¬£¬ÒÔڲƭÀÕË÷¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/attacks-targeting-accellion-product-linked-fin11-cybercrime-group


4¡¢·É»úÖÆÔìÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹûÕæ


4.jpg


¼ÓÄôó·É»úÖÆÔìÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹûÕæ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚͨ¸æÖÐÌåÏÖ£¬£¬£¬£¬£¬¾­³õ³ÌÐò²é£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃÁ˵ÚÈý·½Îļþ´«ÊäÓ¦ÓÃÖеÄÎó²îÀ´»á¼ûºÍÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü²¢Ã»ÓÐÏêϸָ³ö¸Ã×°±¸µÄÃû³Æ£¬£¬£¬£¬£¬µ«¾ÝÍÆ²âºÜ¿ÉÄÜÊÇÖ¸µÄAccellion FTA¡£¡£¡£¡£¡£¡£¡£±»µÁÊý¾ÝÒÑÔÚÀÕË÷ÍÅ»ïClopµÄÊý¾ÝÐ¹Â¶ÍøÕ¾¹ûÕæ£¬£¬£¬£¬£¬°üÀ¨BombardierÖÖÖÖ·É»úºÍ·É»úÁã¼þµÄÉè¼ÆÎļþ£¬£¬£¬£¬£¬²¢Ã»ÓÐÈκÎСÎÒ˽¼ÒÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/airplane-maker-bombardier-data-posted-on-ransomware-leak-site-following-fta-hack/


5¡¢·ÒÀ¼TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬¿Í»§Ð§ÀÍÔÝʱÖÐÖ¹


5.jpg


·ÒÀ¼ITЧÀ͹«Ë¾TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬¿Í»§Ð§ÀÍÔÝʱÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£TietoEVRYÊÇÒ»¼ÒÈí¼þ¿ª·¢ºÍITЧÀ͹«Ë¾£¬£¬£¬£¬£¬ÔÚ80¸ö¹ú¼ÒºÍµØÇøÓµÓÐ24000ÃûÔ±¹¤£¬£¬£¬£¬£¬2019ÄêµÄÊÕÈëΪ29.5ÒÚÅ·Ôª¡£¡£¡£¡£¡£¡£¡£±¾ÖÜÒ»£¬£¬£¬£¬£¬TietoEVRYµÄÁãÊÛ¡¢ÖÆÔìºÍЧÀÍÏà¹ØÐÐÒµµÄ25¸ö¿Í»§ÌåÏÖÆäÓöµ½ÁËÊÖÒÕÎÊÌ⣬£¬£¬£¬£¬ØÊºóµÃÖªÕâЩÎÊÌâÊÇÓÉÀÕË÷Èí¼þ¹¥»÷ÒýÆðµÄ¡£¡£¡£¡£¡£¡£¡£TietoEVRY·¢Ã÷¹¥»÷ºóÁ¬Ã¦¹Ø±ÕÁËÊÜÓ°ÏìµÄϵͳºÍЧÀÍ£¬£¬£¬£¬£¬²¢ÓëµØ·½Õþ¸®¶Ô´ËÊÂÕö¿ªÊӲ졣¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/finnish-it-services-giant-tietoevry-discloses-ransomware-attack/