Ñо¿Ö°Ô±Åû¶ÁíÍâÁ½¸öWindows 0day¼°PoC£»£»£»£»¹È¸èG SuiteÎó²î £¬£¬£¬£¬£¬£¬²¿·ÖÃÜÂëÃ÷ÎÄ´æ´¢³¤´ïÊ®ËÄÄê

Ðû²¼Ê±¼ä 2019-05-23
1¡¢Ñо¿Ö°Ô±Åû¶ÁíÍâÁ½¸öWindows 0day¼°PoC

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
ǰһÌìSandboxEscaperÅû¶ÁËWindows 10ÍýÏëʹÃüÖеÄLPE 0dayºó £¬£¬£¬£¬£¬£¬¸ÃÑо¿Ö°Ô±ÓÖÐû²¼ÁËÁíÍâÁ½¸öWindows 0dayµÄPoC¡£¡£¡£¡£¡£¡£µÚÒ»¸ö0dayÊÇWindows¹ýʧ±¨¸æÐ§ÀÍÖеÄÎó²î £¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¹¥»÷Õß»ñµÃͨ³£ÎÞ·¨±à¼­µÄÎļþµÄȨÏÞ £¬£¬£¬£¬£¬£¬¼´ÍâµØÌØÈ¨Éý¼¶Îó²î¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ¸ÃÎó²î¿Éͨ¹ý¶ñÒâµÄDACL²Ù×÷À´Ê¹Óà £¬£¬£¬£¬£¬£¬µ«¿ÉÄÜÐè񻮮·Ñ15·ÖÖÓµÄʱ¼ä £¬£¬£¬£¬£¬£¬¸ÃÎó²î±»ÃüÃûΪAngryPolarBearBug2¡£¡£¡£¡£¡£¡£µÚ¶þ¸ö0dayÊÇIE 11ÖеÄÎó²î £¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¹¥»÷ÕßÔÚIEÖÐ×¢Èë¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£ÕâÒѾ­ÊÇSandboxEscaperÐû²¼µÄµÚÁùºÍµÚÆß¸öWindows 0day £¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÔÊÐí³ÆÔÚδÀ´¼¸ÌìÄÚ»¹½«Ðû²¼ÁíÍâÁ½¸ö0day¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/two-more-microsoft-zero-days-uploaded-on-github/


2¡¢¹È¸èG SuiteÎó²î £¬£¬£¬£¬£¬£¬²¿·ÖÃÜÂëÃ÷ÎÄ´æ´¢³¤´ïÊ®ËÄÄê

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
¾ÝÃÀý±¨µÀ £¬£¬£¬£¬£¬£¬¹È¸èÈ·ÈÏÖÁÉÙ×Ô2005ÄêÒÔÀ´Ò»Ö±ÒâÍâ´æ´¢Á˲¿·ÖG SuiteÆóÒµÓû§µÄÃ÷ÎÄÃÜÂë¡£¡£¡£¡£¡£¡£¹È¸èûÓÐ͸¶ÊÜÓ°ÏìµÄ¿Í»§ÊýÄ¿ £¬£¬£¬£¬£¬£¬²¢ÌåÏÖÕýÔÚÖØÖÿÉÄÜÊÜÓ°ÏìµÄÃÜÂë¡£¡£¡£¡£¡£¡£¹È¸è³ÆÉϸöÔÂËü·¢Ã÷2005 ÄêÌṩӦÆóÒµÓû§µÄÃÜÂëÉèÖúͻָ´ÒªÁìÊǹýʧµÄ £¬£¬£¬£¬£¬£¬²»×¼È·µØÖü´æÁËÃ÷ÎÄÃÜÂë¡£¡£¡£¡£¡£¡£Æ¾Ö¤¹È¸è¹¤³Ì¸±×ܲÃSuzanne FreyµÄ˵·¨ £¬£¬£¬£¬£¬£¬Ã»ÓÐСÎÒ˽¼ÒÏûºÄÕßµÄGmailÕ˺ÅÊÜÓ°Ïì £¬£¬£¬£¬£¬£¬¹È¸èÒÑÈ·ÈÏûÓÐÈκÎÖ¤¾ÝÅú×¢ÕâЩÃÜÂë±»²»µ±»á¼û»òÀÄÓùý¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/google-stored-unhashed-passwords-due-to-an-implementation-error-8e054e4b


3¡¢IntelÐû²¼Çå¾²¸üР£¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¸ö²úÆ·ÖеÄ34¸öÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
IntelÐû²¼34¸öÎó²îÐÞ¸´²¹¶¡ £¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨IntelÈÚºÏÇå¾²ºÍÖÎÀíÒýÇæ£¨CSME£©ÖеÄÑÏÖØÌáȨÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-0153£©µÄCVSSÆÀ·ÖΪ9·Ö £¬£¬£¬£¬£¬£¬ÊÇÒ»¸ö»º³åÇøÒç³öÎó²î £¬£¬£¬£¬£¬£¬Ó°ÏìCSME°æ±¾12µ½12.0.34 £¬£¬£¬£¬£¬£¬Æ¾Ö¤IntelµÄת´ï £¬£¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉʹÓôËÎó²î¾ÙÐÐÌáȨ¡£¡£¡£¡£¡£¡£³ý´ËÖ®Íâ £¬£¬£¬£¬£¬£¬Intel»¹ÐÞ¸´ÁËi915ͼÐÎоƬµÄÄÚºËģʽÇý¶¯³ÌÐòÖеÄÊäÈëÑéÖ¤²»µ±Îó²î£¨CVE-2019-11085 £¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8·Ö£©ºÍNUCÌ×¼þÖеĿɵ¼ÖÂÌáȨ¡¢DoS»òÐÅϢй¶µÄÎó²î£¨CVE-2019-11094 £¬£¬£¬£¬£¬£¬CVSS 7.5·Ö£©¡£¡£¡£¡£¡£¡£¸ü¶àÎó²îÐÅÏ¢Çë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/intel-fixes-critical-high-severity-flaws-across-several-products/144940/


4¡¢¶íº¥¶íÖÝ¿¼ÎÄ´¹¸ßÖÐѬȾTrickbot £¬£¬£¬£¬£¬£¬Ñ§Ð£±»ÆÈÍ£¿£¿£¿£¿£¿Î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
¶íº¥¶íÖÝ¿¼ÎÄ´¹Ñ§ÇøµÄ¸ßÖÐѬȾ¶ñÒâÈí¼þTrickbot £¬£¬£¬£¬£¬£¬µ¼ÖÂѧУ±»ÆÈÍ£¿£¿£¿£¿£¿Î¡£¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñ±¬·¢ÔÚ5ÔÂ17ÈÕ £¬£¬£¬£¬£¬£¬¸ÃѧУµÄµç»°ºÍHVACϵͳ¾ùÊÜѬȾ £¬£¬£¬£¬£¬£¬ÎªÁË´Ó¶ñÒâÈí¼þ¹¥»÷Öлָ´ £¬£¬£¬£¬£¬£¬¸ÃÑ§Ð£ÖØ×°ÁË1000¶ą̀ÅÌËã»ú¡£¡£¡£¡£¡£¡£ÔÚ·¢Ã÷¹¥»÷ºó £¬£¬£¬£¬£¬£¬Ñ§Ð£¹ÙÔ±ÏòFBIת´ïÁ˶ñÒâÈí¼þ¹¥»÷ÊÂÎñ £¬£¬£¬£¬£¬£¬FBIÕýÔÚЭÖúÑ§Çø¾ÙÐлָ´ÊÂÇé¡£¡£¡£¡£¡£¡£¸ÃѧУÒÑÓÚÖܶþ»Ö¸´Õý³£ÔËÓª¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/ohio-school-sends-students-home-because-of-trickbot-malware-infection/


5¡¢ÀÕË÷Èí¼þSatanбäÌå £¬£¬£¬£¬£¬£¬Ìí¼Ó3¸öÎó²îʹÓþÙÐÐÈö²¥

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
ƾ֤FortinetµÄÒ»·Ý±¨¸æ £¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þSatanµÄбäÖÖ½ÓÄÉÁËIPµØµã±éÀúºÍ¶àÏß³ÌÊÖÒÕ¾ÙÐÐÈö²¥ £¬£¬£¬£¬£¬£¬²¢ÇÒÌí¼ÓÁËÈý¸öеÄÎó²îʹÓôúÂë £¬£¬£¬£¬£¬£¬°üÀ¨Spring Data RESTÎó²î£¨CVE-2017-8046£©¡¢ElasticSearchÎó²î£¨CVE-2015-1427£©ºÍThinkPHP 5.XÔ¶³ÌÖ´ÐдúÂëÎó²î£¨Î´·ÖÅÉCVE£©¡£¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬¸Ã±äÌ廹¿ÉʹÓÃÒÔÏÂÎó²î£ºJBossĬÈÏÉèÖÃÎó²î£¨CVE-2010-0738£©¡¢Tomcatí§ÒâÎļþÉÏ´«Îó²î£¨CVE-2017-12615£©¡¢WebLogicí§ÒâÎļþÉÏ´«Îó²î£¨CVE-2018-2894£©¡¢WebLogic WLS×é¼þÎó²î£¨CVE-2017-10271£©¡¢Windows SMBÔ¶³ÌÖ´ÐдúÂëÎó²î£¨MS17-010£©¡¢Spring Data CommonsÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-1273£©¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/satan-ransomware-evolves-to-add-three-new-exploits-to-its-source-code-7afe57cc


6¡¢EmsisoftÐû²¼ÀÕË÷Èí¼þJSWorm 2.0µÄ½âÃܹ¤¾ß

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
EmsisoftÐû²¼ÀÕË÷Èí¼þJSWorm 2.0µÄ½âÃܹ¤¾ß £¬£¬£¬£¬£¬£¬¿É×ÊÖúÊܺ¦ÕßÃ⺬»ìÃÜÎļþ¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúJSWorm 2.0µÄ·Ö·¢Í¾¾¶ £¬£¬£¬£¬£¬£¬µ«ÆäÊܺ¦ÕßÒÑÔÚÄÏ·Ç¡¢Òâ´óÀû¡¢·¨¹ú¡¢ÍÁ¶úÆä¡¢ÒÁÀÊ¡¢Ô½ÄÏ¡¢µÂ¹ú¡¢°ÍÎ÷¡¢°¢¸ùÍ¢ºÍÃÀ¹ú·¢Ã÷¡£¡£¡£¡£¡£¡£Ò»µ©Ñ¬È¾ £¬£¬£¬£¬£¬£¬JSWorm 2.0»á¼ÓÃÜϵͳÉϵÄÎļþ²¢¸½¼Ó.JSWORM»ò.JURASIKÀ©Õ¹Ãû¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/jsworm-20-ransomware-decryptor-gets-your-files-back-for-free/