ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ20ÖÜ

Ðû²¼Ê±¼ä 2021-05-17

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê05ÔÂ10ÈÕÖÁ05ÔÂ16ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´70¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Exchange Server CVE-2021-31198Ô¶³Ì´úÂëÖ´ÐЩ¶´£»SAP Business Warehouse´úÂë×¢ÈëÖ´ÐЩ¶´£»EnvoyproxyÊÚȨÈƹý©¶´£»Rockwell Automation Connected Components Workbench·´ÐòÁл¯´úÂëÖ´ÐЩ¶´£»Adobe After Effects CVE-2021-28571ÃüÁî×¢È멶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÃÀ¹úColonial PipelineѬȾÀÕË÷Èí¼þ£¬Ö÷ÒªÊäÓ͹ÜÍ£ÔË£»CISA¡¢NCSC¡¢FBIÓëNSAÁªºÏÐû²¼ÓйضíÂÞ˹SVRµÄ×Éѯ£»Ñо¿ÍŶӳÆ1.28ÒÚiOSÓû§ÒÑѬȾ¶ñÒâÈí¼þXcodeGhost£»TorÍøÂçÐÂÔöÊýǧ¸ö¶ñÒâ½Ó¿Ú£¬¼àÌý¼ÓÃÜ»õ±ÒÏà¹ØµÄÁ÷Á¿£»MicrosoftÐû²¼5Ô²¹¶¡£¬ÐÞ¸´3¸ö0dayÔÚÄÚµÄ55¸ö©¶´¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


> ÖØÒªÄþ¾²Â©¶´Áбí


1.Microsoft Exchange Server CVE-2021-31198Ô¶³Ì´úÂëÖ´ÐЩ¶´


Microsoft Exchange Server´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½Í߽⣬Ôì³É¾Ü¾ø·þÎñ¹¥»÷¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31198


2.SAP Business Warehouse´úÂë×¢ÈëÖ´ÐЩ¶´


SAP Business Warehouse´æÔÚÊäÈëÑéÖ¤Äþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655


3.EnvoyproxyÊÚȨÈƹý©¶´


Envoyproxy´¦ÖÃURI·¾¶ÉÏתÒå·û(%2F, %2f, %5C, »ò%5c)´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÈƹýÊÚȨ£¬Î´ÊÚȨ·ÃÎÊ¡£

https://access.redhat.com/security/cve/cve-2021-29492


4.Rockwell Automation Connected Components Workbench·´ÐòÁл¯´úÂëÖ´ÐЩ¶´


Rockwell Automation Connected Components Workbench´¦ÖöñÒ⹤¾ß´æÔÚ·´ÐòÁл¯Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://us-cert.cisa.gov/ics/advisories/icsa-21-133-01


5.Adobe After Effects CVE-2021-28571ÃüÁî×¢È멶´


Adobe After Effects´æÔÚÃüÁî×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâOSÃüÁî¡£

https://helpx.adobe.com/security/products/after_effects/apsb21-33.html


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÃÀ¹úColonial PipelineѬȾÀÕË÷Èí¼þ£¬Ö÷ÒªÊäÓ͹ÜÍ£ÔË


1.jpg


ÃÀ¹ú×î´óµÄȼÁϹܵÀ¹«Ë¾Colonial PipelineÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬5500Ó¢ÀïÊäÓ͹ÜÍ£ÔË¡£Colonial PipelineÿÌì´ÓµÂ¿ËÈø˹ÖÝÊäËÍ250ÍòͰʯÓ͵½¶«º£°¶ºÍŦԼ£¬¸Ã¹ÜµÀÁýÕÖÁËÃÀ¹ú¶«º£°¶45£¥µÄȼÁϹ©Ó¦¡£¸Ã¹«Ë¾ÔÚÉÏÖÜÁùÌåÏÖ£¬ÆäÓÚ5ÔÂ7ÈÕÔâµ½ÀÕË÷¹¥»÷£¬·¢ÏÖ¹¥»÷ºóÖ÷¶¯¹Ø±ÕÁËÒªº¦µÄϵͳÒÔÖÆÖ¹Á÷´«£¬Ä¿Ç°ÕýÓëÄþ¾²¹«Ë¾ºÏ×÷¶Ô¸ÃʼþµÄÐÔÖʺͷ¶Î§½øÐÐÊӲ졣ÃÀ¹úµÄij¹ÙÔ±³Æ£¬´Ë´ÎÀÕË÷¹¥»÷ʼþÓëDarkSideÍÅ»ïÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/largest-us-pipeline-shuts-down-operations-after-ransomware-attack/


2¡¢CISA¡¢NCSC¡¢FBIÓëNSAÁªºÏÐû²¼ÓйضíÂÞ˹SVRµÄ×Éѯ


2.jpg


CISAÓëÓ¢¹ú¹ú¼ÒÍøÂçÄþ¾²ÖÐÐÄ£¨NCSC£©¡¢Áª°îÊÓ²ì¾Ö£¨FBI£©ºÍ¹ú¼ÒÄþ¾²¾Ö£¨NSA£©ÁªºÏÐû²¼ÓйضíÂÞ˹SVRµÄÄþ¾²×Éѯ¡£¸Ã×Éѯָ³öSVRËƺõÒÑͨ¹ý¸ü¸ÄÆä¼¼ÊõºÍ·¨Ê½£¨TTP£©£¬À´ÖÆÖ¹×éÖ¯·¢ÏÖÆä»î¶¯ºÍ½ÓÄɵ÷Í£´ëÊ©¡£´ËÍ⣬SVRÖ÷ÒªÕë¶ÔÕþ¸®¡¢ÖÇ¿â¡¢Õþ²ßºÍÄÜÔ´Ïà¹ØµÄ×éÖ¯£¬ÒÔ¼°ÓÐʱЧÐÔµÄÄ¿±ê£¬ÀýÈç2020ÄêÓëCOVID-19ÒßÃçÏà¹ØµÄ×éÖ¯¡£ºÚ¿ÍÖ÷ҪʹÓÃÁËCVE-2018-13379¡¢CVE-2019-1653ºÍCVE-2019-2725µÈ11¸ö©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/05/07/joint-ncsc-cisa-fbi-nsa-cybersecurity-advisory-russian-svr


3¡¢Ñо¿ÍŶӳÆ1.28ÒÚiOSÓû§ÒÑѬȾ¶ñÒâÈí¼þXcodeGhost


3.jpg


Ñо¿ÍŶӳÆ£¬ÔÚ×î½üµÄ¶ñÒâÈí¼þ¹¥»÷ÖУ¬Áè¼Ý1.28ÒÚiOSÓû§³ÉΪ¹¥»÷Ä¿±ê¡£¹¥»÷ÕßÔڴ˴λÖÐʹÓÃÁËXcodeGhost£¬¸Ã¶ñÒâÈí¼þÓÚ2015ÄêÊ״ηºÆð¡£Apple¾¯¸æ³Æ£¬Ô¼Äª2500¸öÓ¦ÓÃѬȾÁ˶ñÒâXcode´úÂë¡£¾Ý±¨µÀ£¬ÆäÖÐÔ¼55%µÄÓû§ÊÇÖйúÈË£¬¶ø66%µÄÏÂÔØÁ¿ÓëÖйúÓйØ¡£ÌرðÊÇ£¬Ò»Ð©¹ãÊÜ»¶Ó­µÄÓ¦ÓÃÒ²ÒÑѬȾÁ˸öñÒâÈí¼þ£¬°üÂÞÓÎÏ·¡°ÄÕÅ­µÄСÄñ2¡±¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/05/xcodeghost-malware-infected-around-128m.html


4¡¢TorÍøÂçÐÂÔöÊýǧ¸ö¶ñÒâ½Ó¿Ú£¬¼àÌý¼ÓÃÜ»õ±ÒÏà¹ØµÄÁ÷Á¿


4.jpg


The Record³Æ£¬×Ô2020ÄêÒÔÀ´TorÍøÂçÐÂÔöÊýǧ¸ö¶ñÒâ½Ó¿Ú£¬¼àÌý¼ÓÃÜ»õ±ÒÏà¹ØÍøÕ¾µÄÁ÷Á¿¡£ÔÚÕë¶ÔTorÍøÂçµÄ¹¥»÷ÖУ¬¹¥»÷Õß¿ÉÀûÓÃÆä¿ØÖƵÄÇ®°üÌæ»»ºÏ·¨Ç®°üµÄµØÖ·À´½Ù³Ö½»Òס£´ËÍ⣬Nusenu·¢ÏÖºÚ¿ÍÒѾ­Á½´Î´òÆÆÁËÆä×Ô2020Äê5ÔÂÒÔÀ´µÄ¼Ç¼(¶ñÒâ½Ó¿Ú±ÈÀýΪ23%):2020Äê10ÔÂ30ÈÕ£¬ºÚ¿ÍÍÅ»ïÀûÓÃÁËÁè¼Ý26%µÄtorÍøÂç½Ó¿Ú£¬µ½2021Äê02ÔÂ02ÈÕ£¬ÆäÒѾ­¹ÜÀíÁËÁè¼Ý27%µÄ½Ó¿Ú¡£Ä¿Ç°£¬¶ñÒâ½Ó¿Ú¾ùÒÑ´ÓTorÍøÂçÖÐÒƳý¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/117749/deep-web/tor-exit-nodes-ssl-stripping.html


5¡¢MicrosoftÐû²¼5Ô²¹¶¡£¬ÐÞ¸´3¸ö0dayÔÚÄÚµÄ55¸ö©¶´


5.jpg


MicrosoftÐû²¼5Ô·ݵÄÖܶþ²¹¶¡£¬ÐÞ¸´°üÂÞ3¸ö0dayÔÚÄÚµÄ55¸ö©¶´¡£´Ë´ÎÐÞ¸´µÄ0 day·Ö±ðÊÇNETºÍVisual StudioÖеÄÌáȨ©¶´£¨CVE-2021-31204£©¡¢Microsoft Exchange ServerÖеÄÄþ¾²¹¦Ð§Èƹý©¶´£¨CVE-2021-31207£©ºÍͨÓù¤¾ßÖеÄÔ¶³ÌÖ´ÐдúÂ멶´£¨CVE-2021-31200£©£¬ÕâЩ©¶´»¹Î´±»ÔÚÒ°ÀûÓᣴËÍ⣬»¹ÐÞ¸´ÁËHTTP.sysÖеÄÔ¶³ÌÖ´ÐдúÂ멶´£¨CVE-2021-31166£©ºÍIEä¯ÀÀÆ÷ÖеÄÄÚ´æËð»µÂ©¶´£¨CVE-2021-26419£©µÈ©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/microsoft-patch-tuesday-55-vulnerabilities-4-critical-3-publicly-known