ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ38ÖÜ

Ðû²¼Ê±¼ä 2021-09-22

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê09ÔÂ13ÈÕÖÁ09ÔÂ19ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´60¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Premiere Elements CVE-2021-40700»º³åÇøÒç³ö´úÂëÖ´ÐЩ¶´£»Microsoft Azure Open Management InfrastructureȨÏÞÌáÉý©¶´£»Google chrome Selection APIÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´£»Microsoft Scripting Engine CVE-2021-26435»º³åÇøÒç³ö©¶´£»SAP Business OneÎļþÉÏ´«Â©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÀÕË÷¹¥»÷µ¼ÖÂÄϷǶà¸öÕþ¸®²¿ÃŵÄITϵͳÖжϣ»AppleÐû²¼½ô¼±¸üУ¬ÐÞ¸´Áãµã»÷©¶´ForcedEntry£»KasperskyÐû²¼2021ÄêÉÏ°ëÄêICSÍþв̬ÊƵijÂËߣ»MicrosoftÐû²¼9Ô·ÝÐÇÆÚ¶þ²¹¶¡£¬×ܼÆÐÞ¸´86¸ö©¶´£»¹È¸èÒòÀÄÓð²×¿µÄÊг¡Ö÷µ¼Ö°Î»±»º«¹ú·£¿î2070ÒÚº«Ôª¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1.Adobe Premiere Elements CVE-2021-40700»º³åÇøÒç³ö´úÂëÖ´ÐЩ¶´


Adobe Premiere Elements´¦ÖÃÎļþ´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹϵͳÍß½â»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://helpx.adobe.com/security/products/premiere_elements/apsb21-78.html


2.Microsoft Azure Open Management InfrastructureȨÏÞÌáÉý©¶´


Microsoft Azure Open Management Infrastructure´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÌáÉýȨÏÞ¡£


https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-38649


3.Google chrome Selection APIÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´


Google chrome Selection API´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹϵͳÍß½â»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop.html


4.Microsoft Scripting Engine CVE-2021-26435»º³åÇøÒç³ö©¶´


Microsoft Scripting Engine´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½Íß½â»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26435


5.SAP Business OneÎļþÉÏ´«Â©¶´


SAP Business One´æÔÚÈÎÒâÎļþÉÏ´«Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405


 >ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÀÕË÷¹¥»÷µ¼ÖÂÄϷǶà¸öÕþ¸®²¿ÃŵÄITϵͳÖжÏ


ÀÕË÷¹¥»÷µ¼ÖÂÄϷǶà¸öÕþ¸®²¿ÃŵÄITϵͳÖжÏ.jpg



9ÔÂ6ÈÕÍíÉϵÄÀÕË÷¹¥»÷»î¶¯µ¼ÖÂÄϷǶà¸öÕþ¸®²¿ÃŵÄITϵͳÖжÏ£¬°üÂÞµç×ÓÓʼþϵͳºÍ¹ú¼Ò±£ÊÍ·þÎñµÄϵͳ¡£DOJCD¹ÙÔ±ÔÚÉÏÖÜËÄ£¨9ÔÂ9ÈÕ£©Í¸Â¶£¬¹¥»÷»î¶¯¼ÓÃÜÁ˸ò¿ÃÅËùÓеÄÐÅϢϵͳ£¬Ê¹µÃÄÚ²¿µÄÔ±¹¤ºÍÍⲿµÄ¹«Ãñ¾ùÎÞ·¨Ê¹ÓᣴËÍ⣬˾·¨²¿¹ÙÔ±ÌåÏÖ£¬ËûÃDz»µÃ²»Æô¶¯ÁËÊÖ¶¯Á÷³ÌÀ´Î¬³Ö·¨Í¥µÄÕý³£»î¶¯£¬µ«²¢Î´Ö¸Ã÷´Ë´Î¹¥»÷±³ºóµÄÀÕË÷ÔËÓªÍŻÉÏÖÜÒ»£¬ÄϷǹú¼Òº½Ìì¾Ö (SANSA)ÔøÅû¶Æäϵͳ´æÔÚÄþ¾²Â©¶´£¬µ¼ÖÂѧÉú¸öÈËÐÅϢй¶¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/bail-services-affected-in-south-africa-after-ransomware-attack/   


2¡¢AppleÐû²¼½ô¼±¸üУ¬ÐÞ¸´Áãµã»÷©¶´ForcedEntry


AppleÐû²¼½ô¼±¸üУ¬ÐÞ¸´Áãµã»÷©¶´ForcedEntry.jpg


Apple¹«Ë¾ÓÚ±¾ÖÜÒ»Ðû²¼½ô¼±¸üУ¬ÐÞ¸´iMessagingÖеÄÁãµã»÷©¶´ForcedEntry£¨CVE-2021-30860£©¡£Apple³Æ¸Ã©¶´Îª´¦ÖöñÒâPDFʱµ¼ÖµÄÈÎÒâ´úÂëÖ´ÐЩ¶´¡£Citizen LabÓÚ2021Äê2ÔÂÊ״η¢Ïָ鶴£¬Ëü¿ÉÓÃÀ´ÈƹýAppleÆäʱÍƳöµÄ·ÀÖ¹iMessageÁãµã»÷©¶´µÄɳÏäBlastDoor¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/apple-emergency-fix-nso-zero-click-zero-day/169416/


3¡¢KasperskyÐû²¼2021ÄêÉÏ°ëÄêICSÍþв̬ÊƵijÂËß


KasperskyÐû²¼2021ÄêÉÏ°ëÄêICSÍþв̬ÊƵijÂËß.jpg


KasperskyÔÚ9ÔÂ9ÈÕÐû²¼ÁË2021ÄêÉÏ°ëÄêICSÍþв̬ÊƵijÂËß¡£³ÂËßÖ¸³ö£¬2021ÄêÉÏ°ëÄêICS¼ÆËã»ú±»¹¥»÷µÄÕ¼±ÈΪ8%£¬±È2020ÄêÏ°ëÄê¸ß0.4¸ö°Ù·Öµã¡£ÆäÖУ¬±»¹¥»÷µÄICS¼ÆËã»úÕ¼±È×î¶àµÄ¹ú¼ÒΪ°¢¶û¼°ÀûÑÇ£¨58.4%£©£¬Æä´ÎΪĦÂå¸ç£¨52.4%£© ¡¢ÒÁÀ­¿Ë£¨50.9%£©ºÍÔ½ÄÏ£¨50.6%£©¡£´ËÍ⣬»¥ÁªÍø¡¢¿ÉÒƶ¯Ã½ÌåºÍµç×ÓÓʼþÈÔÈ»ÊÇICS¼ÆËã»úÍþвµÄÖ÷ÒªÀ´Ô´¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/threat-landscape-for-industrial-automation-systems-in-h1-2021/104017/


4¡¢MicrosoftÐû²¼9Ô·ÝÐÇÆÚ¶þ²¹¶¡£¬×ܼÆÐÞ¸´86¸ö©¶´


MicrosoftÐû²¼9Ô·ÝÐÇÆÚ¶þ²¹¶¡£¬×ܼÆÐÞ¸´86¸ö©¶´.jpg


MicrosoftÓÚ9ÔÂ14ÈÕÐû²¼Á˱¾ÔµÄÐÇÆÚ¶þÄþ¾²¸üУ¬×ܼÆÐÞ¸´ÁË86¸ö©¶´¡£´Ë´Î¸üÐÂÐÞ¸´ÁË2¸öÁãÈÕ©¶´£¬°üÂÞWindows MSHTMLÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-40444£©£¬ÒÑÔÚÒ°Íâ·¢ÏÖÀûÓø鶴µÄ¹¥»÷»î¶¯£»ÒÔ¼°Windows DNSÌáȨ©¶´£¨CVE-2021-36968£©¡£´ËÍ⣬»¹ÐÞ¸´ÁËAzure ¿ª·Åʽ¹ÜÀí»ù´¡ÉèÊ©ÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-38647£©ºÍWindows½Å±¾ÒýÇæÄÚ´æËð»µÂ©¶´£¨CVE-2021-26435£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2021-patch-tuesday-fixes-2-zero-days-60-flaws/


5¡¢¹È¸èÒòÀÄÓð²×¿µÄÊг¡Ö÷µ¼Ö°Î»±»º«¹ú·£¿î2070ÒÚº«Ôª


¹È¸èÒòÀÄÓð²×¿µÄÊг¡Ö÷µ¼Ö°Î»±»º«¹ú·£¿î2070ÒÚº«Ôª.jpg


9ÔÂ14ÈÕ£¬º«¹ú¹«ÕýóÒ×ίԱ»á¶Ô¹È¸è´¦ÒÔ2070ÒÚº«Ôª£¨Ô¼Îª1.77 ÒÚÃÀÔª£©µÄ·£¿î¡£Ô­ÒòÊǹȸèÒòÀÄÓð²×¿ÔÚÒƶ¯²Ù×÷ϵͳÊг¡µÄÖ÷µ¼Ö°Î»£¬ÆÈʹÖÇÄÜÊÖ»úÖÆÔìÉÌÖ»ÄÜʹÓÃAndroid²Ù×÷ϵͳ¡£¸Ã»ú¹¹³Æ£¬¹È¸èÒªÇóÖÆÔìÉ̱ØÐëÇ©Êð¡°·´ËéƬ»¯Ð­Ò飨AFA£©¡±£¬¸ÃЭÒé½ûֹʹÓÃAndroid²Ù×÷ϵͳµÄÐ޸İ汾£¬¼´ËùνµÄ¡°Android·ÖÖ§¡±¡£±¨µÀ³Æ£¬¹È¸èµÄ¢¶ÏÐÐΪʹÆäÔÚ2019ÄêÒƶ¯²Ù×÷ϵͳÊг¡µÄ·Ý¶îÉÏÉýµ½ÁË97.7%¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2021/09/14/south_korea_fines_google/