ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ9ÖÜ

°ä²¼¹¦·ò 2021-03-01

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê02ÔÂ22ÈÕÖÁ02ÔÂ28ÈÕ¹²ÊÕ¼°²È«·ì϶53¸ö£¬ £¬ £¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇNETGEAR Nighthawk R7800Ó²±àÂëÑéÖ¤ÈÆ¹ý·ì϶£»£»£»£»£»£» £»Siemens SINEC NMS FirmwareFileUtils extractToFolderĿ¼±éÀú´úÂëÖ´Ðзì϶£»£»£»£»£»£» £»TP-Link AC1750 sync-serverÕ»Òç³öÔ¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£» £»On Netshield NANO CVE-2021-3149ºÅÁî×¢Èë·ì϶£»£»£»£»£»£» £»Adobe Bridge CVE-2021-21065Ô½½çд´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ΢Èí·¢ÏÖWindows Win32kÌáȨ0dayÒѱ»ÔÚÒ°ÀûÓ㻣»£»£»£»£» £»Ð¶ñÒâÈí¼þSilver SparrowÒÑϰȾ½ü3Íǫ̀MacÉ豸£»£»£»£»£»£» £»FireEye³ÆÕë¶ÔAccellion FTAµÄ¹¥»÷ÓëFIN11Óйأ»£»£»£»£»£» £»·É»úÔì×÷ÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹ«¿ª£»£»£»£»£»£» £»·ÒÀ¼TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ £¬ £¬£¬£¬£¬¿Í»§·þÎñÁÙʱÖжϡ£¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬ £¬ £¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£


> ³ÁÒª°²È«·ì϶Áбí


1.NETGEAR Nighthawk R7800Ó²±àÂëÑéÖ¤ÈÆ¹ý·ì϶


NETGEAR Nighthawk R7800 apply_save.cgiʹÓÃÓ²±àÂë·ì϶£¬ £¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬ £¬£¬£¬£¬Äܹ»ROOTȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-252/


2.Siemens SINEC NMS FirmwareFileUtils extractToFolderĿ¼±éÀú´úÂëÖ´Ðзì϶


Siemens SINEC NMS FirmwareFileUtils extractToFolder´æÔÚĿ¼±éÀú·ì϶£¬ £¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬ £¬£¬£¬£¬Äܹ»WEBÀûÓ÷¨Ê½¸ßµÍÎĶÁÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-253/


3.TP-Link AC1750 sync-serverÕ»Òç³öÔ¶³Ì´úÂëÖ´Ðзì϶


TP-Link AC1750 sync-server MACµØÖ·´¦ÖôæÔÚÕ»Òç¶Âí½Å£¬ £¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬ £¬£¬£¬£¬Äܹ»ROOTȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-215/


4.On Netshield NANO CVE-2021-3149ºÅÁî×¢Èë·ì϶


On Netshield NANO /usr/local/webmin/System/manual_ping.cgi´æÔÚÊäÈëÑéÖ¤·ì϶£¬ £¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬ £¬£¬£¬£¬Äܹ»WEBÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://www.digitaldefense.com/resources/vulnerability-research/netshield-corporation-nano-25/


5.Adobe Bridge CVE-2021-21065Ô½½çд´úÂëÖ´Ðзì϶


Adobe Bridge´¦ÖÃÎļþ´æÔÚÔ½½çд·ì϶£¬ £¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ £¬ £¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬ £¬ £¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£» £»ò¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://helpx.adobe.com/security/products/bridge/apsb21-07.html


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Î¢Èí·¢ÏÖWindows Win32kÌáȨ0dayÒѱ»ÔÚÒ°ÀûÓÃ


1.jpg


΢Èí·¢ÏÖWindows Win32kÖеÄÌáȨ0day£¨CVE-2021-1732£©Òѱ»ÔÚÒ°ÀûÓᣡ£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚwin32k.sysÖ÷ÌâÄÚºË×é¼þÖУ¬ £¬ £¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý´¥·¢¿ªÊͺóʹÓ÷ì϶½«ÆäȨÏÞÌáÉýµ½admin¼¶±ð£¬ £¬ £¬£¬£¬£¬ÓµÓиù»ùÓû§È¨Ï޵Ĺ¥»÷Õß²»±ØÒªÓëÓû§½»»¥¼´¿ÉÀûÓø÷ì϶¡£¡£¡£¡£¡£¡£¾Ýµ÷²é£¬ £¬ £¬£¬£¬£¬¸Ã·ì϶Òѱ»APT×éÖ¯BitterºÍT-APT-17ÀûÓ㬠£¬ £¬£¬£¬£¬DBAPPSecurityÔò³ÆÆäÓÚ12Ô·¢ÏÖÁË¿ª·¢ÈÕÆÚΪ2020Äê5ÔµÄÑù±¾¡£¡£¡£¡£¡£¡£¶ø×Ô2021Äê2ÔÂÆðÍ·£¬ £¬ £¬£¬£¬£¬ºÚ¿ÍÖ»ÔÚÉÙÊýÕë¶ÔÖж«µÄ¹¥»÷ÖÐʹÓÃÁËCVE-2021-1732·ì϶¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/recently-fixed-windows-zero-day-actively-exploited-since-mid-2020/


2¡¢Ð¶ñÒâÈí¼þSilver SparrowÒÑϰȾ½ü3Íǫ̀MacÉ豸


2.jpg


Red Canary×êÑÐÈËÔ±·¢ÏÖÕë¶ÔMacÉ豸µÄжñÒâÈí¼þSilver Sparrow¡£¡£¡£¡£¡£¡£½ØÖÁ2ÔÂ17ÈÕ£¬ £¬ £¬£¬£¬£¬Silver SparrowÒÑÔÚ153¸ö¹ú¶ÈºÍµØÓòϰȾÁË29139¸ömacOSÖÕ¶Ë£¬ £¬ £¬£¬£¬£¬²¢ÔÚÃÀ¹ú¡¢Ó¢¹ú¡¢¼ÓÄô󡢷¨¹úºÍµÂ¹ú´óÁ¿´«²¼¡£¡£¡£¡£¡£¡£Óë´óÎÞÊýʹÓÃ'preinstall'ºÍ'postinstall'¾ç±¾µÄ¶ñÒâÈí¼þ·ÖÆç£¬ £¬ £¬£¬£¬£¬Silver SparrowÀûÓÃJavaScriptÖ´ÐкÅÁ £¬ £¬£¬£¬£¬´Ó¶øºÜÄÑÆ¾¾ÝºÅÁîÐвÎÊý¼ì²â¶ñÒâ»î¶¯¡£¡£¡£¡£¡£¡£´Ë±í£¬ £¬ £¬£¬£¬£¬¸Ã¶ñÒâÈí¼þµÄÕæÕýÖ÷ÕÅ´Ë¿ÌÒÀÈ»ÊǸöÃÕ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/30000-macs-infected-with-new-silver-sparrow-malware/


3¡¢FireEye³ÆÕë¶ÔAccellion FTAµÄ¹¥»÷ÓëFIN11ÓйØ


3.jpg


°²È«¹«Ë¾FireEye³Æ£¬ £¬ £¬£¬£¬£¬2020Äê12Ôµ½2021Äê1ÔÂÖ®¼äÀûÓÃAccellion FTA·þÎñÆ÷ÖÐ0dayµÄ¹¥»÷»î¶¯ÓëFIN11Óйأ¬ £¬ £¬£¬£¬£¬²¨¼°ÁËÈ«ÇòÔ¼100¼Ò¹«Ë¾¡£¡£¡£¡£¡£¡£ºÚ¿ÍÖØÒªÀûÓÃÁËËĸö·ì϶À´¹¥»÷FTA·þÎñÆ÷£¬ £¬ £¬£¬£¬£¬²¢×°ÖÃÁËÒ»¸öÃûΪDEWMODEµÄWeb Shell£¬ £¬ £¬£¬£¬£¬À´ÏÂÔØÊܺ¦ÕßFTAÉ豸ÉÏ´æ´¢µÄÎļþ¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¹«Ë¾ºÍ×éÖ¯Ô̺¬Fugro¡¢Danaher¡¢Singtel¡¢Jones¡¢ÐÂÎ÷À¼´¢ÐîÒøÐкͰĴóÀûÑÇ֤ȯºÍͶ×ÊίԱ»á£¨ASIC£©µÈ¡£¡£¡£¡£¡£¡£´Ë±í£¬ £¬ £¬£¬£¬£¬ºÚ¿ÍÔÚClopµÄÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏÁгöÁ˲¿ÃŹ«Ë¾£¬ £¬ £¬£¬£¬£¬ÒÔڲƭÀÕË÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/attacks-targeting-accellion-product-linked-fin11-cybercrime-group


4¡¢·É»úÔì×÷ÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹ«¿ª


4.jpg


¼ÓÄôó·É»úÔì×÷ÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹ«¿ª¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ¹«¸æÖаµÊ¾£¬ £¬ £¬£¬£¬£¬¾­³õ´ëÊ©²é£¬ £¬ £¬£¬£¬£¬ºÚ¿ÍÀûÓÃÁ˵ÚÈý·½Îļþ´«ÊäÀûÓÃÖеķì϶À´½Ó¼ûºÍÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£Ö»¹Ü²¢Ã»ÓоßÌåÖ¸³ö¸ÃÉ豸µÄÃû³Æ£¬ £¬ £¬£¬£¬£¬µ«¾Ý´§Ä¦ºÜ¿ÉÄÜÊÇÖ¸µÄAccellion FTA¡£¡£¡£¡£¡£¡£±»µÁÊý¾ÝÒÑÔÚÀÕË÷ÍÅ»ïClopµÄÊý¾ÝÐ¹Â¶ÍøÕ¾¹«¿ª£¬ £¬ £¬£¬£¬£¬Ô̺¬Bombardier¸÷Àà·É»úºÍ·É»úÁã¼þµÄÉè¼ÆÎļþ£¬ £¬ £¬£¬£¬£¬²¢Ã»ÓÐÈκÎÓ×ÎÒÊý¾Ýй¶¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/airplane-maker-bombardier-data-posted-on-ransomware-leak-site-following-fta-hack/


5¡¢·ÒÀ¼TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ £¬ £¬£¬£¬£¬¿Í»§·þÎñÁÙʱÖжÏ


5.jpg


·ÒÀ¼IT·þÎñ¹«Ë¾TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ £¬ £¬£¬£¬£¬¿Í»§·þÎñÁÙʱÖжϡ£¡£¡£¡£¡£¡£TietoEVRYÊÇÒ»¼ÒÈí¼þ¿ª·¢ºÍIT·þÎñ¹«Ë¾£¬ £¬ £¬£¬£¬£¬ÔÚ80¸ö¹ú¶ÈºÍµØÓòÕ¼ÓÐ24000ÃûÔ±¹¤£¬ £¬ £¬£¬£¬£¬2019ÄêµÄÊÕÈëΪ29.5ÒÚÅ·Ôª¡£¡£¡£¡£¡£¡£±¾ÖÜÒ»£¬ £¬ £¬£¬£¬£¬TietoEVRYµÄÁãÊÛ¡¢Ôì×÷ºÍ·þÎñÓйØÐÐÒµµÄ25¸ö¿Í»§°µÊ¾ÆäÓöµ½Á˼¼ÊõÎÊÌ⣬ £¬ £¬£¬£¬£¬ºóÀ´µÃÖªÕâЩÎÊÌâÊÇÓÉÀÕË÷Èí¼þ¹¥»÷ÒýÆðµÄ¡£¡£¡£¡£¡£¡£TietoEVRY·¢ÏÖ¹¥»÷ºóÁ¢¼´¹Ø¹ØÁËÊÜÓ°ÏìµÄϵͳºÍ·þÎñ£¬ £¬ £¬£¬£¬£¬²¢Óë´¦Ëùµ±¾Ö¶Ô´ËÊ·¢Õ¹µ÷²é¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/finnish-it-services-giant-tietoevry-discloses-ransomware-attack/