FBIºÍCISA½áºÏ°ä²¼×î³£±»¹¥»÷ÀûÓõķì϶Áбí

°ä²¼¹¦·ò 2020-05-14

0x00 ÒýÑÔ


ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©ºÍÁª¹úµ÷²é¾Ö£¨FBI£©½áºÏ°ä²¼2016ÄêÖÁ2019Äê×î³£±»¹¥»÷ÀûÓõķì϶ÁÐ±í¡£¡£¡£¡£ ¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬£¬»¹Ìá¼°ÁË2020ÄêÈÝÒ×±»¹¥»÷ÀûÓõö·ì϶¡£¡£¡£¡£ ¡£¡£

»ã±¨Ìá¼°µÄÊ®´ó·ì϶Ô̺¬CVE-2017-11882£¬£¬ £¬£¬£¬£¬£¬CVE-2017-0199£¬£¬ £¬£¬£¬£¬£¬CVE-2017-5638£¬£¬ £¬£¬£¬£¬£¬CVE-2012-0158 £¬£¬ £¬£¬£¬£¬£¬CVE-2019-0604£¬£¬ £¬£¬£¬£¬£¬CVE-2017-0143£¬£¬ £¬£¬£¬£¬£¬CVE-2018-4878£¬£¬ £¬£¬£¬£¬£¬CVE-2017-8759£¬£¬ £¬£¬£¬£¬£¬CVE-2015-1641ºÍCVE-2018-7600¡£¡£¡£¡£ ¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



ƾ¾ÝÃÀ¹úµ±¾ÖµÄ¼¼Êõ·ÖÎö£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß×îʱʱÀûÓÃMicrosoftµÄ¶ÔÏóÁ´½ÓºÍǶÈ루OLE£©¼¼ÊõÖеķì϶¡£¡£¡£¡£ ¡£¡£OLEÔÊÐíÎĵµÔ̺¬À´×ÔÆäËûÀûÓ÷¨Ê½£¨Èçµç×Ó±í¸ñ£©µÄǶÈëÄÚÈÝ¡£¡£¡£¡£ ¡£¡£ÔÚOLEÖ®ºó£¬£¬ £¬£¬£¬£¬£¬µÚ¶þ´óÒ×Êܹ¥»÷µÄ¼¼ÊõÊÇApache StrutsµÄWeb¿ò¼Ü¡£¡£¡£¡£ ¡£¡£

ÔÚǰ10¸ö·ì϶ÖУ¬£¬ £¬£¬£¬£¬£¬À´×ÔÒÁÀÊ¡¢³¯ÏʺͶíÂÞ˹µÄ¹ú¶ÈºÚ¿ÍÖÐ×î³£ÀûÓõÄÈý¸ö·ì϶ÊÇCVE-2017-11882¡¢CVE-2017-0199ºÍCVE-2012-0158¡£¡£¡£¡£ ¡£¡£ÆäÖУ¬£¬ £¬£¬£¬£¬£¬ÕâÈý¸ö·ì϶¾ùÓëMicrosoftµÄOLE¼¼ÊõÓйأ¬£¬ £¬£¬£¬£¬£¬Í¨³£×÷Ϊ´¹µöÓʼþµÄWord¸½¼þ½øÐд«²¼¡£¡£¡£¡£ ¡£¡£

·ì϶ÁбíÖØÒªÄÚÈÝΪ£º·ì϶ӰÏìµÄ²úÆ·¡¢ÓÐÄÄЩ¶ñÒâÈí¼þͨ¹ýÕâЩ·ì϶½øÐд«²¼¡¢Õë¶Ô·ì϶µÄÔ¤·À´ëÊ©ºÍ¹ØÓÚÕâЩ·ì϶µÄ¸ü¶à¾ßÌåÐÅÏ¢Á´½Ó¡£¡£¡£¡£ ¡£¡£


0x01 2016ÖÁ2019ÄêÊ®´ó·ì϶Áбí


CVE-2017-11882

? ·ì϶²úÆ·£ºMicrosoft Office 2007 SP3 / 2010 SP2 / 2013 SP1 / 2016²úÆ·

? ÓйضñÒâÈí¼þ£ºLoki£¬£¬ £¬£¬£¬£¬£¬FormBook£¬£¬ £¬£¬£¬£¬£¬Pony / FAREIT

? ·À±¸´ëÊ©£ºÊ¹ÓÃ×îÐµİ²È«²¹¶¡¸üÐÂÊÜÓ°ÏìµÄMicrosoft²úÆ·

? ¸ü¶à¾ßÌåÐÅÏ¢£ºhttps://nvd.nist.gov/vuln/detail/CVE-2017-11882

CVE-2017-0199

? ·ì϶²úÆ·£ºMicrosoft Office 2007 SP3 / 2010 SP2 / 2013 SP1 / 2016£¬£¬ £¬£¬£¬£¬£¬Vista SP2£¬£¬ £¬£¬£¬£¬£¬Server 2008 SP2£¬£¬ £¬£¬£¬£¬£¬Windows 7 SP1£¬£¬ £¬£¬£¬£¬£¬Windows 8.1

? ÓйضñÒâÈí¼þ£ºFINSPY£¬£¬ £¬£¬£¬£¬£¬LATENTBOT£¬£¬ £¬£¬£¬£¬£¬Dridex

? ·À±¸´ëÊ©£ºÊ¹ÓÃ×îÐµİ²È«²¹¶¡¸üÐÂÊÜÓ°ÏìµÄMicrosoft²úÆ·

? ¸ü¶à¾ßÌåÐÅÏ¢£ºhttps://nvd.nist.gov/vuln/detail/CVE-2017-0199

CVE-2017-5638

? ·ì϶²úÆ·£ºApache Struts 2 2.3.x֮ǰµÄ2.3.xºÍ2.5.10.1֮ǰµÄ2.5.x

? ÓйضñÒâÈí¼þ£ºJexBoss

? ·À±¸´ëÊ©£ºÉý¼¶µ½Struts 2.3.32»òStruts 2.5.10.1

? ¸ü¶àÏêÇ飺

https://www.us-cert.gov/ncas/analysis-reports/AR18-312A

https://nvd.nist.gov/vuln/detail/CVE-2017-5638

CVE-2012-0158

? ·ì϶²úÆ·£ºMicrosoft Office 2003 SP3¡¢2007 SP2ºÍSP3£¬£¬ £¬£¬£¬£¬£¬ÒÔ¼°2010 GoldºÍSP1£»£»£»£»£»£»£»Office 2003 Web×é¼þSP3£»£»£»£»£»£»£»SQL Server 2000 SP4¡¢2005 SP4ºÍ2008 SP2£¬£¬ £¬£¬£¬£¬£¬SP3ºÍR2; BizTalk Server 2002 SP1£»£»£»£»£»£»£»Commerce Server 2002 SP4¡¢2007 SP2ºÍ2009 GoldºÍR2; Visual FoxPro 8.0 SP1ºÍ9.0 SP2; ºÍVisual Basic 6.0

? ÓйضñÒâÈí¼þ£ºDridex

? ·À±¸´ëÊ©£ºÊ¹ÓÃ×îÐµİ²È«²¹¶¡¸üÐÂÊÜÓ°ÏìµÄMicrosoft²úÆ·

? ¸ü¶àÏêÇ飺

https://www.us-cert.gov/ncas/alerts/aa19-339a

https://nvd.nist.gov/vuln/detail/CVE-2012-0158

CVE-2019-0604

? ·ì϶²úÆ·£ºMicrosoft SharePoint

? ÓйضñÒâÈí¼þ£ºÖйú²Ëµ¶

? ·À±¸´ëÊ©£ºÊ¹ÓÃ×îÐµİ²È«²¹¶¡¸üÐÂÊÜÓ°ÏìµÄMicrosoft²úÆ·

? ¸ü¶à¾ßÌåÐÅÏ¢£ºhttp://nvd.nist.gov/vuln/detail/CVE-2019-0604

CVE-2017-0143

? ·ì϶²úÆ·£ºMicrosoft Windows Vista SP2£»£»£»£»£»£»£»Windows Server 2008 SP2ºÍR2 SP1; Windows 7 SP1£»£»£»£»£»£»£»Windows 8.1; Windows Server 2012 GoldºÍR2£»£»£»£»£»£»£»Windows RT 8.1£»£»£»£»£»£»£»Windows 10 Gold£¬£¬ £¬£¬£¬£¬£¬1511ºÍ1607£»£»£»£»£»£»£»ÒÔ¼° ºÍWindows Server 2016

? ¹ØÁªµÄ¶ñÒâÈí¼þ£ºÊ¹ÓÃEternalSynergyºÍEternalBlue Exploit Kit½øÐÐÂŴι¥»÷

? ·À±¸´ëÊ©£ºÊ¹ÓÃ×îÐµİ²È«²¹¶¡¸üÐÂÊÜÓ°ÏìµÄMicrosoft²úÆ·

? ¸ü¶à¾ßÌåÐÅÏ¢£ºhttps://nvd.nist.gov/vuln/detail/CVE-2017-0143

CVE-2018-4878

? ·ì϶²úÆ·£º28.0.0.161֮ǰµÄAdobe Flash Player

? ¹ØÁªµÄ¶ñÒâÈí¼þ£ºDOGCALL

? ·À±¸´ëÊ©£º½«Adobe Flash Player×°Öøüе½×îа汾

? ¸ü¶à¾ßÌåÐÅÏ¢£ºhttps://nvd.nist.gov/vuln/detail/CVE-2018-4878

CVE-2017-8759

? ·ì϶²úÆ·£ºMicrosoft .NET Framework 2.0¡¢3.5¡¢3.5.1¡¢4.5.2¡¢4.6¡¢4.6.1¡¢4.6.2ºÍ4.7

? ÓйضñÒâÈí¼þ£ºFINSPY£¬£¬ £¬£¬£¬£¬£¬FinFisher£¬£¬ £¬£¬£¬£¬£¬WingBird

? ·À±¸´ëÊ©£ºÊ¹ÓÃ×îÐµİ²È«²¹¶¡¸üÐÂÊÜÓ°ÏìµÄMicrosoft²úÆ·

? ¸ü¶à¾ßÌåÐÅÏ¢£ºhttps://nvd.nist.gov/vuln/detail/CVE-2017-8759

CVE-2015-1641

? Ò×Êܹ¥»÷µÄ²úÆ·£ºMicrosoft Word 2007 SP3£¬£¬ £¬£¬£¬£¬£¬Office 2010 SP2£¬£¬ £¬£¬£¬£¬£¬Word 2010 SP2£¬£¬ £¬£¬£¬£¬£¬Word 2013 SP1£¬£¬ £¬£¬£¬£¬£¬Word 2013 RT SP1£¬£¬ £¬£¬£¬£¬£¬Mac°æWord 2011£¬£¬ £¬£¬£¬£¬£¬Office¼æÈݰüSP3£¬£¬ £¬£¬£¬£¬£¬SharePoint Server 2010 SP2ºÍ2013 SP1ÉϵÄWord Automation ServicesºÍOffice Web Apps Server 2010 SP2ºÍ2013 SP1

? ÓйضñÒâÈí¼þ£ºUWarrior Toshliph

? ·À±¸´ëÊ©£ºÊ¹ÓÃ×îÐµİ²È«²¹¶¡¸üÐÂÊÜÓ°ÏìµÄMicrosoft²úÆ·

? ¸ü¶à¾ßÌåÐÅÏ¢£ºhttps://nvd.nist.gov/vuln/detail/CVE-2015-1641

CVE-2018-7600

? Ò×Êܹ¥»÷µÄ²úÆ·£º7.58֮ǰµÄDrupal£¬£¬ £¬£¬£¬£¬£¬8.3.9֮ǰµÄ8.x£¬£¬ £¬£¬£¬£¬£¬8.4.6֮ǰµÄ8.4.xºÍ8.5.1֮ǰµÄ8.5.x

? ÓйضñÒâÈí¼þ£ºKitty

? ·À±¸´ëÊ©£ºÉý¼¶µ½Drupal 7»ò8Ö÷ÌâµÄ×îа汾¡£¡£¡£¡£ ¡£¡£

? ¸ü¶à¾ßÌåÐÅÏ¢£ºhttps://nvd.nist.gov/vuln/detail/CVE-2018-7600


0x02 2020Ä갲ȫ·ì϶·çÏÕ


´Ë±í£¬£¬ £¬£¬£¬£¬£¬ÃÀ¹úµ±¾Ö»¹»ã±¨ÁËÔÚ2020ÄêÈÝÒ×±»ºÚ¿ÍÀûÓõÄһЩ°²È«ÎÊÌ⣺

Õë¶Ôδ´ò²¹¶¡µÄÐ鹹רÓÃÍø£¨VPN£©·ì϶Ôö³¤£¬£¬ £¬£¬£¬£¬£¬ºÃ±ÈCitrix VPNÉ豸ÖеÄËÁÒâ´úÂëÖ´Ðзì϶£¨³ÆÎªCVE-2019-19781£©ÒÑÔÚÒ°±í¹¥»÷Öб»¼ì²âµ½£»£»£»£»£»£»£»Pulse Secure VPN·þÎñÆ÷ÖеÄËÁÒâÎļþ¶ÁÈ¡·ì϶£¨³ÆÎªCVE-2019-11510£©ÒÀÈ»ÊǺڿ͵Äêéêì¶ÔÏ󡣡£¡£¡£ ¡£¡£

2020Äê3Ô£¬£¬ £¬£¬£¬£¬£¬¶ÔÓںܶà×éÖ¯¶øÑÔ£¬£¬ £¬£¬£¬£¬£¬ºöȻִÐÐÔ¶³Ì°ì¹«£¬£¬ £¬£¬£¬£¬£¬±ØÒª¼±¾ç²¿ÊðÔÆºÏ×÷·þÎñ£¬£¬ £¬£¬£¬£¬£¬ÀýÈçMicrosoft Office 365£¨O365£©¡£¡£¡£¡£ ¡£¡£ÕâЩ×éÖ¯¼±¾ç²¿ÊðMicrosoft O365¿ÉÄܵ¼Ö°²È«ÅäÖ÷½ÃæµÄ¼à¶½²»¼°£¬£¬ £¬£¬£¬£¬£¬ÈÝÒ×Êܵ½¹¥»÷¡£¡£¡£¡£ ¡£¡£

´Ë±í£¬£¬ £¬£¬£¬£¬£¬ÍøÂ簲ȫ´æÔÚÆäËûÈõµã£¬£¬ £¬£¬£¬£¬£¬ÀýÈç¶ÔÔ±¹¤Éç»á¹¤³Ìѧ½ÌÓý²»¼°¡¢²»×ãϵͳ¸´Ô­ºÍÓ¦¼±´òËãµÈ£¬£¬ £¬£¬£¬£¬£¬³ÖÐøÊ¹×éÖ¯ÔÚ2020ÄêÈÝÒ×Êܵ½ÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£ ¡£¡£

ÉÏÊöÌáµ½µÄÎÊÌâÓйØÐÅÏ¢ÈçÏ£º

CVE-2019-11510

? ·ì϶²úÆ·£ºPulse Connect Secure 9.0R1-9.0R3.3¡¢8.3R1-8.3R7¡¢8.2R1-8.2R12¡¢8.1R1-8.1R15ºÍPulse Policy Secure 9.0R1-9.0R3.1¡¢5.4R1-5.4R7¡¢5.3 R1-5.3R12¡¢5.2R1-5.2R12¡¢5.1R1-5.1R15

? »º½â´ëÊ©£ºÊ¹ÓÃ×îÐµİ²È«²¹¶¡¸üÐÂÊÜÓ°ÏìµÄPulse SecureÉ豸¡£¡£¡£¡£ ¡£¡£

? ¸ü¶àÏêÇ飺

https://www.us-cert.gov/ncas/alerts/aa20-107a

https://nvd.nist.gov/vuln/detail/CVE-2019-11510

https://www.microsoft.com/security/blog/2020/04/28/ransomware-groups-continue-to-target-healthcare-critical-services-heres-how-to-reduce-risk/

CVE-2019-19781

? Ò×Êܹ¥»÷µÄ²úÆ·£ºCitrixÀûÓ÷¨Ê½½»¸¶½ÚÔìÆ÷£¬£¬ £¬£¬£¬£¬£¬CitrixÍø¹ØºÍCitrix SDWAN WANOP

? »º½â´ëÊ©£ºÊ¹ÓÃ×îÐµİ²È«²¹¶¡¸üÐÂÊÜÓ°ÏìµÄCitrixÉ豸

? ¸ü¶àÏêÇ飺

https://www.us-cert.gov/ncas/alerts/aa20-020a

https://www.us-cert.gov/ncas/alerts/aa20-031a

https://www.fireeye.com/blog/products-and-services/2020/01/fireeye-and-citrix-tool-scans-for-iocs-related-to-vulnerability.html

https://nvd.nist.gov/vuln/detail/CVE-2019-19781

https://www.microsoft.com/security/blog/2020/04/28/ransomware-groups-continue-to-target-healthcare-critical-services-heres-how-to-reduce-risk/

Microsoft O365°²È«ÅäÖÃÖеļල

? ·ì϶²úÆ·£ºMicrosoft O365

? »º½â´ëÊ©£º×ñÑ­Microsoft O365°²È«½¨Òé

? ¸ü¶à¾ßÌåÐÅÏ¢£ºhttps://www.us-cert.gov/ncas/alerts/aa20-120a

×éÖ¯ÍøÂ簲ȫÈõµã

? ´àÈõ²úÆ·£ºÏµÍ³£¬£¬ £¬£¬£¬£¬£¬ÍøÂçºÍÊý¾Ý

? »º½â´ëÊ©£º×ñÑ­ÍøÂ簲ȫ×î¼Ñʵ¼Ê

? ¸ü¶à¾ßÌåÐÅÏ¢£ºhttps://www.cisa.gov/cyber-essentials


0x03 ÓйØÐÂÎÅ


https://www.zdnet.com/article/dhs-cisa-and-fbi-share-list-of-top-10-most-exploited-vulnerabilities/


0x04 ²Î¿¼Á´½Ó


https://www.us-cert.gov/ncas/alerts/aa20-133a

https://www.us-cert.gov/sites/default/files/publications/AA20-133A_Top_10_Routinely_Exploited_Vulnerabilities_S508C.pdf


0x05 ¹¦·òÏß


2020-05-12 CISAºÍFBI°ä²¼»ã±¨

2020-05-14 VSRC°ä²¼·ì϶¹«¸æ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website