¹È¸èÅû¶WindowsÖдæÔÚ20ÄêµÄ·ì϶£¬ £¬£¬£¬£¬Ó°ÏìËùÓÐϵͳ°æ±¾£» £»£»£»£»£»À¶ÑÀ·ì϶KNOB£¬ £¬£¬£¬£¬¿ÉÆÆ½âÃÜÔ¿ºÍ´Û¸ÄÊý¾Ý

°ä²¼¹¦·ò 2019-08-15
1¡¢Î¢Èí½¨¸´RDP·þÎñÖеÄÐÂÈ䳿¼¶·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

΢ÈíÔÚ8Ô·ݵÄWindows°²È«¸üÐÂÖн¨¸´ÁË94¸ö·ì϶£¬ £¬£¬£¬£¬ÆäÖÐÔ̺¬4¸öеÄRDPÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-1181¡¢CVE-2019-1182¡¢CVE-2019-1222¡¢CVE-2019-1226£©¡£ ¡£¡£¡£¡£¡£ÆäÖÐCVE-2019-1181ºÍCVE-2019-1182Óë5ÔÂ·ÝÆØ³öµÄBlueKeep·ì϶£¨CVE-2019-0708£©ÀàËÆ£¬ £¬£¬£¬£¬¿ÉʵÏÖÈ䳿»¯¹¥»÷£¬ £¬£¬£¬£¬ÊÜÓ°ÏìµÄϵͳ°æ±¾Ô̺¬win 7 SP1¡¢win 8.1¡¢win 10ÒÔ¼°windows server 2008 R2 SP1¡¢2012¡¢2012 R2¡¢2016¼°2019µÈ¡£ ¡£¡£¡£¡£¡£XP¡¢windows server 2003¼°2008²»ÊÜÓ°Ïì¡£ ¡£¡£¡£¡£¡£Ä¿Ç°ÉÐδ·¢ÏÖÕâЩ·ì϶ÔÚÒ°±í±»ÀûÓ㬠£¬£¬£¬£¬µ«Î¢ÈíÇ¿ÁÒ½¨ÒéÓû§¾¡¿ì¸üн¨¸´²¹¶¡¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/microsoft-fixes-critical-windows-10-wormable-remote-desktop-flaws/


2¡¢Intel°ä²¼NUC¹Ì¼þ¸üУ¬ £¬£¬£¬£¬½¨¸´¶à¸ö·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Intel°ä²¼NUC KitµÄ¹Ì¼þ¸üУ¬ £¬£¬£¬£¬½¨¸´¿Éµ¼ÖÂÌáȨ¡¢»Ø¾ø·þÎñÒÔ¼°ÐÅϢй¶µÄ·ì϶¡£ ¡£¡£¡£¡£¡£¸Ã·ì϶£¨CVE-2019-11140£¬ £¬£¬£¬£¬CVSSÆÀ·ÖΪ7.5£©ÊÇÓÉÓÚ²»³ä·ÖµÄÑéÖ¤µ¼ÖµÄ£¬ £¬£¬£¬£¬¿É±»ÓµÓб¾µØ½Ó¼ûȨÏ޵Ĺ¥»÷ÕßËùÀûÓ㬠£¬£¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·ÐͺÅÔ̺¬Intel NUC Kit NUC7i7DNx¡¢NUC7i5DNx¡¢NUC7i3DNxÒÔ¼°Compute Stick STK2MV64CCºÍCompute Card CD1IV128MK¡£ ¡£¡£¡£¡£¡£´Ë±í£¬ £¬£¬£¬£¬Intel»¹½¨¸´ÁË´¦ÖÃÆ÷¼ø±ð¹¤¾ßÖеķì϶£¨CVE-2019-11163£¬ £¬£¬£¬£¬CVSSÆÀ·ÖΪ8.2£©ÒÔ¼°RAIDÖÎÀíÈí¼þÖеķì϶£¨CVE-2019-0173£¬ £¬£¬£¬£¬CVSSÆÀ·Ö6.8£©¡£ ¡£¡£¡£¡£¡£¸ü¶à·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/intel-updates-nuc-firmware-to-patch-high-severity-bug/


3¡¢HTTP/2ÆØ³ö8¸öзì϶£¬ £¬£¬£¬£¬¿ÉÓÃÓÚÌáÒéDoS¹¥»÷

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

×êÑÐÈËÔ±Åû¶HTTP/2ºÍ̸ʵÏÖÖеÄ8¸öзì϶£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶Ïò佨²¹µÄ·þÎñÆ÷ÌáÒ黨¾ø·þÎñ¹¥»÷¡£ ¡£¡£¡£¡£¡£ÕâЩ·ì϶£¨CVE-2019-9511~CVE-2019-9518£©ÊÇÓÉNetflix×êÑÐÔ±Jonathan LooneyÒÔ¼°Google×êÑÐÔ±Piotr Sikora·¢Ïֵģ¬ £¬£¬£¬£¬¿ÉÓÃÓÚ´¥·¢·þÎñÆ÷µÄ×ÊÔ´ºÄ¾¡£¬ £¬£¬£¬£¬µ«²»ÄÜÓÃÓÚÈëÇÖ·þÎñÆ÷¡£ ¡£¡£¡£¡£¡£Æ¾¾ÝCERT°ä²¼µÄ²¼¸æ£¬ £¬£¬£¬£¬ÊÜÓ°ÏìµÄ³§ÉÌÔ̺¬NGINX¡¢Apache¡¢H2O¡¢Nghttp2¡¢Microsoft(IIS)¡¢Cloudflare¡¢Akamai¡¢Apple(SwiftNIO)¡¢Amazon¡¢Facebook(Proxygen)¡¢Node.jsÒÔ¼°Envoy proxy£¬ £¬£¬£¬£¬´óÎÞÊý³§É̶¼ÒѾ­°ä²¼Á˽¨¸´²¹¶¡¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/http2-dos-vulnerability.html


4¡¢ÐÂÀ¶ÑÀ·ì϶KNOB£¬ £¬£¬£¬£¬¿ÉÆÆ½âÃÜÔ¿ºÍ´Û¸ÄÊý¾Ý


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËÔ±Åû¶À¶ÑÀÖеÄзì϶£¨CVE-2019-9506£©£¬ £¬£¬£¬£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷Õß±©Á¦ÆÆ½âÅä¶ÔÉ豸ÔÚ´«ÊäÊý¾ÝʱʹÓõÄÃÜÔ¿²¢´Û¸ÄÊý¾Ý¡£ ¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁ˰汾ÔÚ1.0ÖÁ5.1Ö®¼äµÄBluetooth BR/EDRÉ豸¡£ ¡£¡£¡£¡£¡£Æ¾¾Ý×êÑÐÈËÔ±µÄ±íÊö£¬ £¬£¬£¬£¬¹¥»÷Õß¿É×ÌÈÅÁ½Ì¨Åä¶ÔÉ豸ÉèÖüÓÃÜÏνӵĹý³Ì£¬ £¬£¬£¬£¬Ï÷¼õʹÓõÄÃÜÔ¿µÄ³¤¶È£¬ £¬£¬£¬£¬Ê¹µÃÃÜÔ¿µÄ°²È«ÐÔÖè¼õ¡£ ¡£¡£¡£¡£¡£¼«¶ËÇé¿öÏ£¬ £¬£¬£¬£¬ÃÜÔ¿³¤¶È¿ÉÄܱ»Ï÷¼õΪ1¸ö×Ö½Ú¡£ ¡£¡£¡£¡£¡£ÎªÁË»º½â¸Ã·ì϶£¬ £¬£¬£¬£¬À¶ÑÀ¼¼ÊõÁªÃ˸üÐÂÁËÀ¶ÑÀÖ÷Ìâ¹æ·¶£¬ £¬£¬£¬£¬½¨Òé×îÓ×ÃÜÔ¿³¤¶ÈΪ7¸ö×Ö½Ú¡£ ¡£¡£¡£¡£¡£Î¢ÈíÒ²ÔÚ·ì϶£¨CVE-2019-9506£©µÄ²¹¶¡Öн«Ä¬ÈÏ×îÓ×ÃÜÔ¿³¤¶ÈÉèÖÃΪ7¸ö×Ö½Ú¡£ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-bluetooth-knob-flaw-lets-attackers-manipulate-traffic/

5¡¢¹È¸èÅû¶WindowsÖдæÔÚ20ÄêµÄ·ì϶£¬ £¬£¬£¬£¬Ó°ÏìËùÓÐϵͳ°æ±¾


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¹È¸è×êÑÐÈËÔ±Tavis OrmandyÅû¶WindowsϵͳÖдæÔÚ³¤´ï20ÄêµÄÒ»¸ö佨¸´·ì϶¡£ ¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁËWindows XPÒÔÀ´µÄËùÓÐWindows°æ±¾£¬ £¬£¬£¬£¬Ô̺¬Win 10¡£ ¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚ΢ÈíµÄÎı¾·þÎñ¿ò¼Ü£¨MSCTF£©ÖУ¬ £¬£¬£¬£¬ÓëMSCTF¿Í»§¶ËºÍ·þÎñÆ÷Ö®¼äµÄͨѶ¶Ìȱ½Ó¼û½ÚÔì/Éí·ÝÑéÖ¤»úÔìÓйØ£¬ £¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶Ïνӵ½CTF»á»°¡¢¶ÁдÆäËü´°¿Ú/»á»°µÄÄÚÈÝ¡¢Î±ÔìÏß³ÌID/¹ý³ÌID/HWND¡¢¼Ù×°³ÉCTF·þÎñÆ÷¡¢½øÐÐɳÏäÌÓÒÝÒÔ¼°ÌáȨ¡£ ¡£¡£¡£¡£¡£¹¥»÷Õß»¹Äܹ»ÈƹýÓû§½Ó¿ÚȨÏÞ¸ôÀ루UIPI£©£¬ £¬£¬£¬£¬»ñÈ¡SYSTEMȨÏÞÒÔ¼°½ÚÔìUAC¶Ô»°¿òµÈ¡£ ¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹°ä²¼ÁËÔÚWin 10ÖлñÈ¡SYSTEMµÄPoCÊÓÆµ¡£ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/ctfmon-windows-vulnerabilities.html

6¡¢BioStar 2ÉúÎï¼ø±ðÊý¾Ý¿âй¶£¬ £¬£¬£¬£¬²¨¼°Êý°ÙÍòÓû§

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


vpnMentor×êÑÐÈËÔ±·¢ÏÖBioStar 2µÄÒ»¸öElasticsearchÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬ £¬£¬£¬£¬µ¼ÖÂÊý°ÙÍòÈ˵ÄÉúÎï¼ø±ðÊý¾Ýй¶¡£ ¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÔ̺¬23GBÊý¾Ý£¨³¬¹ý2780Íò±Ê¼Í¼£©£¬ £¬£¬£¬£¬ÕâЩÊý¾ÝÔ̺¬Ö¸ÎÆ/Ãæ²¿¼ø±ðÊý¾Ý¡¢Î´¼ÓÃܵÄÓû§ÃûºÍÃÜÂëÒÔ¼°Ô±¹¤µÄÒþÖÔÐÅÏ¢¡£ ¡£¡£¡£¡£¡£Biostar 2±»¼¯³Éµ½µÚÈý·½ÏµÍ³ÖУ¬ £¬£¬£¬£¬ÀýÈçNedapµÄAEOS½Ó¼û½ÚÔìϵͳ£¬ £¬£¬£¬£¬¸ÃϵͳÒѱ»83¸ö¹ú¶ÈµÄ5700¶à¸ö×é֯ʹÓ㬠£¬£¬£¬£¬Ô̺¬Ó¢¹ú´ó³ÇÊо¯Ô±¾Ö¡£ ¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¹«Ë¾»¹Ô̺¬Ó¢¹ú¶È¾Ó×°è«ÉÌTile MountainÒÔ¼°Ó¡¶ÈºÍ˹ÀïÀ¼¿¨µÄ½¡Éí·¿Power World GymsµÈ¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/millions-of-records-exposed/