ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ40ÖÜ

Ðû²¼Ê±¼ä 2020-10-09

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê09ÔÂ28ÈÕÖÁ10ÔÂ04ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´56¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇFoxit Reader Field::ClearItems/Field::DeleteOptionsÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´£»Secudos DOMOS conf_datetimeÈÎÒâÃüÁîÖ´ÐЩ¶´£»WAVLINK WN530H4 /cgi-bin/live_api.cgiÃüÁî×¢È멶´£»WAVLINK WN530H4 /cgi-bin/makeRequest.cgi»º³åÇøÒç³ö©¶´£»WAVLINK WN530H4 /cgi-bin/¶à¸öÑéÖ¤Èƹý©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ£ºCNCERTÐû²¼¡¶2020ÄêÉÏ°ëÄêÎÒ¹ú»¥ÁªÍøÍøÂçÄþ¾²¼à²âÊý¾Ý·ÖÎö³ÂËß¡·£»Ñо¿ÈËÔ±·¢ÏÖжñÒâÈí¼þTaurusͨ¹ý¶ñÒâ¹ã¸æ»î¶¯Á÷´«£»ÃÀ¹úºÍ°Ä´óÀûÑÇOffice 365·þÎñ·ºÆðAADSTS90033´íÎó£»ÃÀ¹ú14¸öÖݳÂËßÆä911·þÎñÖÐ¶Ï £¬Ê¼þÔ­Òò»¹ÔÚÊÓ²ìÖУ»ºÚ¿ÍÒÔWin7Éý¼¶ÎªÓÕ¶üÌᳫµöÓã¹¥»÷ £¬ÇÔÈ¡Outlookƾ¾Ý¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí


1.Foxit Reader Field::ClearItems/Field::DeleteOptionsÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´


Foxit Reader Field::ClearItems/Field::DeleteOptions´æÔÚÊͷźóʹÓ鶴 £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.foxitsoftware.com/support/security-bulletins.html


2.Secudos DOMOS conf_datetimeÈÎÒâÃüÁîÖ´ÐЩ¶´


Secudos DOMOS conf_datetime´¦ÖÃzone²ÎÊý´æÔÚÊäÈëÑé֤©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔrootÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî¡£

https://www.secudos.de/en/news-en/domos-release-5-9


3.WAVLINK WN530H4 /cgi-bin/live_api.cgiÃüÁî×¢È멶´


WAVLINK WN530H4 /cgi-bin/live_api.cgi´æÔÚÊäÈëÑé֤©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔROOTȨÏÞÖ´ÐÐÈÎÒâÃüÁî¡£

https://cerne.xyz/bugs/CVE-2020-12124


4.WAVLINK WN530H4 /cgi-bin/makeRequest.cgi»º³åÇøÒç³ö©¶´


WAVLINK WN530H4 /cgi-bin/makeRequest.cgi´æÔÚ»º³åÇøÒç³ö©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔROOTȨÏÞÖ´ÐÐÈÎÒâÃüÁî¡£

https://cerne.xyz/bugs/CVE-2020-12125


5.WAVLINK WN530H4 /cgi-bin/¶à¸öÑéÖ¤Èƹý©¶´


WAVLINK WN530H4 /cgi-bin/´æÔÚ¶à¸öÑéÖ¤Èƹý©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÐÞ¸ÄÅäÖà £¬½øÐоܾø·þÎñµÈ¹¥»÷¡£

https://cerne.xyz/bugs/CVE-2020-12126


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢CNCERTÐû²¼¡¶2020ÄêÉÏ°ëÄêÎÒ¹ú»¥ÁªÍøÍøÂçÄþ¾²¼à²âÊý¾Ý·ÖÎö³ÂËß¡·


1.jpg


ΪȫÃæ·´Ó³2020ÄêÉÏ°ëÄêÎÒ¹ú»¥ÁªÍøÔÚ¶ñÒⷨʽÁ÷´«¡¢Â©¶´·çÏÕ¡¢DDoS¹¥»÷¡¢ÍøÕ¾Äþ¾²µÈ·½ÃæµÄÇé¿ö £¬CNCERT¶ÔÉÏ°ëÄê¼à²âÊý¾Ý½øÐÐÁËÊáÀí £¬²¢Ðγɼà²âÊý¾Ý·ÖÎö³ÂËß¡£³ÂËßÏÔʾ £¬2020ÄêÉÏ°ëÄê £¬²¶×½¼ÆËã»ú¶ñÒⷨʽÑù±¾ÊýÁ¿Ô¼1815Íò¸ö £¬ÈÕ¾ùÁ÷´«´ÎÊý´ï483ÍòÓà´Î £¬Éæ¼°¼ÆËã»ú¶ñÒⷨʽ¼Ò×åÔ¼1.1ÍòÓà¸ö¡£Æ¾¾ÝÁ÷´«À´Ô´Í³¼Æ £¬¾³Íâ¶ñÒⷨʽÖ÷ÒªÀ´×ÔÃÀ¹ú¡¢ÈûÉà¶ûºÍ¼ÓÄôóµÈ £¬¾³ÄڵĶñÒⷨʽÖ÷ÒªÀ´×ÔÕã½­Ê¡¡¢¹ã¶«Ê¡ºÍ±±¾©ÊеÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.cert.org.cn/publish/main/46/2020/20200926085042652505447/20200926085042652505447_.html


2¡¢Ñо¿ÈËÔ±·¢ÏÖжñÒâÈí¼þTaurusͨ¹ý¶ñÒâ¹ã¸æ»î¶¯Á÷´«


2.jpg


Ñо¿ÈËÔ±·¢ÏÖеÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þTaurusͨ¹ý¶ñÒâ¹ã¸æ»î¶¯Á÷´«¡£TaurusÊÇÒ»ÖÖÏà¶Ô½ÏеĶñÒâÈí¼þ £¬ÓÚ2020Äê´º¼¾·ºÆ𠣬ͨ¹ýÕë¶ÔÃÀ¹úÓû§µÄ¶ñÒâ¹ã¸æ»î¶¯½øÐÐÁ÷´«¡£Æä×î³õÊÇÓÉPredatorµÄ´´½¨ÕßËù¿ª·¢ £¬Òò´Ë¶þÕß¾ßÓÐÏàͬµÄ¹¦Ð§ £¬¼´´Óä¯ÀÀÆ÷¡¢FTP¡¢VPN¡¢µç×ÓÓʼþ¿Í»§¶ËÒÔ¼°¼ÓÃÜ»õ±ÒÇ®°üÇÔȡƾ¾Ý¡£´Ë´Î×îз¢ÏֵĶñÒâ»î¶¯Ö÷ÒªÕë¶Ô³ÉÈËÍøÕ¾µÄ·ÃÎÊÕß £¬Êܺ¦Õß´ó¶àÀ´×ÔÃÀ¹ú £¬Ò²ÓÐÀ´×Ô°Ä´óÀûÑǺÍÓ¢¹ú¡£


Ô­ÎÄÁ´½Ó£º

https://blog.malwarebytes.com/malwarebytes-news/2020/09/taurus-project-stealer-now-spreading-via-malvertising-campaign/


3¡¢ÃÀ¹úºÍ°Ä´óÀûÑÇOffice 365·þÎñ·ºÆðAADSTS90033´íÎó


3.jpg


´Ó9ÔÂ28ÈÕÃÀ¹ú¶«²¿Ê±¼äÏÂÎç5:15¿ªÊ¼ £¬ÃÀ¹úºÍ°Ä´óÀûÑǵÄOffice 365Óû§¿ªÊ¼ÄÑÒԵǼÆäµç×ÓÓʼþÕÊ»§»ò·ÃÎʵç×ÓÓʼþ £¬²¢»á·ºÆðAADSTS90033´íÎóÌáʾ¡£´Ë´ÎÖжÏÓ°ÏìÁ˵ç×ÓÓʼþ·þÎñ¡¢Microsoft Teams¡¢Office.com¡¢Power PlatformºÍDynamics365¡£Microsoft×î³õÌåÏÖ £¬ËûÃÇÈ·¶¨Á˵¼ÖÂÖжϵÄÔ­Òò £¬µ«ÊÇÔڻعöÖ®ºóÖжÏÒÀȻûÓеõ½½â¾ö¡£Ö®ºó £¬Microsoft¿ªÊ¼ÊµÑéͨ¹ý²îÒìµÄ·þÎñÆ÷ÖØзÓÉÁ÷Á¿ £¬¶øÇÒһЩÓû§³ÂËß˵¿ÉÒÔÔٴεǼ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-office-365-is-down-in-the-usa-shows-transient-error/


4¡¢ÃÀ¹ú14¸öÖݳÂËßÆä911·þÎñÖÐ¶Ï £¬Ê¼þÔ­Òò»¹ÔÚÊÓ²ìÖÐ


4.jpg


±¾ÖÜÒ» £¬ÃÀ¹ú»ªÊ¢¶ÙÖÝ¡¢±öϦ·¨ÄáÑÇÖÝºÍ¶íº¥¶íÖݵÈ14¸öÖݳÂËßÆä911·þÎñÖÐ¶Ï £¬Ä¿Ç°Ê¼þÔ­Òò»¹ÔÚÊÓ²ìÖС£´Ë´Î·þÎñÖжÏÓ°ÏìÁËËùÓнô¼±·þÎñ £¬µ«´ó¶àÊýÊÜÓ°ÏìµØÓòµÄ911·þÎñÔÚ30·ÖÖÓºÍ60·ÖÖÓÄÚ»Ö¸´¡£ÓÐÏûÏ¢À´Ô´³Æ´Ë´ÎÖжϻòÓë΢ÈíµÄ´ó¹æģͣ»úÓйØ¡£µ«ÆäËûÀ´Ô´±íÃ÷ £¬Î¢ÈíÖжϽöÓ°ÏìÁËOfficeºÍÓëµç×ÓÓʼþÏà¹ØµÄ·þÎñ £¬911·þÎñÖжϿÉÄÜ»ù´¡Óë΢ÈíÎÞ¹Ø £¬¶øÇҺܿÉÄÜÆðÔ´ÓÚPSAP£¨¹«¹²Äþ¾²Ó¦´ðµã£©ÌṩÉÌ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/911-services-down-in-multiple-us-states/


5¡¢ºÚ¿ÍÒÔWin7Éý¼¶ÎªÓÕ¶üÌᳫµöÓã¹¥»÷ £¬ÇÔÈ¡Outlookƾ¾Ý


5.jpg


Ñо¿ÈËÔ±·¢ÏÖ £¬ºÚ¿ÍÒÔWin7Éý¼¶ÎªÓÕ¶üÌᳫµöÓã¹¥»÷ £¬Ö¼ÔÚÇÔÈ¡OutlookÓû§Æ¾¾Ý¡£´Ë´Î»î¶¯Í¨¹ý·¢ËÍÒÔ¡°Re£ºMicrosoft Windows Upgrade¡±ÎªÌâµÄµöÓãÓʼþ £¬ÓÕʹÊܺ¦Õߵ㿪ÍøÂçµöÓãµÇ¼ҳÃæ¡£¸ÃÒ³ÃæÊÇαÔìµÄOutlook Web App£¨OWA£©µÇ¼ҳÃæ £¬ÒªÇóÓû§ÊäÈëµç×ÓÓʼþµØÖ·¡¢Óò/Óû§ÃûºÍÃÜÂë £¬ÒÔ´ËÀ´ÇÔÈ¡ÐÅÏ¢¡£´ËÍâ £¬¸ÃµöÓãÓʼþ»¹°üÂÞÆäËûÏêϸÐÅÏ¢ £¬ÀýÈçÉý¼¶¹ý³ÌÖпÉÄÜ»áÓöµ½µÄÎÊÌâ £¬ÒÔÔö¼ÓÆäÕæʵÐÔ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/windows-7-outlook/159621/