ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ20ÖÜ

Ðû²¼Ê±¼ä 2019-05-20

±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö



2019Äê5ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼Çå¾²Îó²î74¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Remote Desktop Services CVE-2019-0708Ô¶³Ì´úÂëÖ´ÐÐÎó²î£» £»£»£»Adobe Media Encoder CVE-2019-7842ÊͷźóʹÓÃÔ¶³Ì´úÂëÖ´ÐÐÎó²î£» £»£»£» Facebook WhatsApp CVE-2019-3568»º³åÇøÒç³öÎó²î£» £»£»£»Apple Safari¶à¸öÄÚ´æÆÆËðí§Òâ´úÂëÖ´ÐÐÎó²î£» £»£»£»Adobe AcrobatºÍReader¶à¸öÊͷźóʹÓôúÂëÖ´ÐÐÎó²î¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ΢ÈíÐÞ¸´79¸öÎó²î£¬£¬£¬£¬£¬£¬°üÀ¨RDPÖеÄRCEÎó²î£¨CVE-2019-0708£©£» £»£»£»¹¥»÷ÕßʹÓûªË¶ÖÐÐÄÈ˹¥»÷·Ö·¢PleadºóÃÅ£» £»£»£»Stack OverflowÐû²¼Í¨¸æ³ÆÆäÔâºÚ¿ÍÈëÇÖ£» £»£»£»Î´ÉèÃÜÂëµÄÊý¾Ý¿âй¶½ü90%°ÍÄÃÂí¹«ÃñÐÅÏ¢£» £»£»£»¶íÂÞ˹ºÚ¿Í×éÖ¯³öÊÛÃÀ¹ú3´ó·´²¡¶¾¹«Ë¾Ô´Âë¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£



Ö÷ÒªÇå¾²Îó²îÁбí



1. Microsoft Windows Remote Desktop Services CVE-2019-0708Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft Windows Remote Desktop Services´¦Öóͷ£Äڴ湤¾ß±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄRDPÇëÇ󣬣¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻠£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708

2. Adobe Media Encoder CVE-2019-7842ÊͷźóʹÓÃÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Adobe Media Encoder´¦Öóͷ£Îļþ±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻠£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://helpx.adobe.com/security/products/media-encoder/apsb19-29.html

3. Facebook WhatsApp CVE-2019-3568»º³åÇøÒç³öÎó²î
Facebook WhatsApp±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://www.facebook.com/security/advisories/cve-2019-3568

4. Apple Safari¶à¸öÄÚ´æÆÆËðí§Òâ´úÂëÖ´ÐÐÎó²î
Apple Safari WebKit±£´æ¶à¸öÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³ÇëÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://support.apple.com/zh-cn/HT210123

5. Adobe AcrobatºÍReader¶à¸öÊͷźóʹÓôúÂëÖ´ÐÐÎó²î
Adobe AcrobatºÍReader±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³ÇëÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻠£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://helpx.adobe.com/security/products/acrobat/apsb19-18.html


Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö



1¡¢Î¢ÈíÐÞ¸´79¸öÎó²î£¬£¬£¬£¬£¬£¬°üÀ¨RDPÖеÄRCEÎó²î£¨CVE-2019-0708£©

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Öܶþ΢ÈíÐû²¼5ÔÂWindowsÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´79¸öÎó²î¡£¡£¡£ÆäÖаüÀ¨RDPЧÀÍÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0708£©£¬£¬£¬£¬£¬£¬´ËÎó²îÊÇÔ¤Éí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ룻 £»£»£»ÌáȨ0day£¨CVE-2019-0863£©£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¹¥»÷ÕßÌáÉýÖÁÖÎÀíԱȨÏÞ£» £»£»£»Õë¶ÔIntel CPU MDS¹¥»÷µÄÎó²îÐÞ¸´£¬£¬£¬£¬£¬£¬ÕâЩÎó²îÓ°ÏìÁË2011ÄêÒÔÀ´ÏÕЩËùÓеÄIntel CPU¡£¡£¡£ÍêÕûÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-may-2019-patch-tuesday-arrives-with-fix-for-windows-zero-day-mds-attacks/

2¡¢¹¥»÷ÕßʹÓûªË¶ÖÐÐÄÈ˹¥»÷·Ö·¢PleadºóÃÅ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


4ÔÂβESETÑо¿Ö°Ô±ÊӲ쵽ʹÓá°AsusWSPanel.exe¡±·Ö·¢PleadºóÃŵĹ¥»÷»î¶¯¡£¡£¡£AsusWSPanel.exeÊÇ»ªË¶Ôƴ洢ЧÀÍWebStorageµÄWindows¿Í»§¶Ë¡£¡£¡£Ñо¿Ö°Ô±¸ø³öÁËÁ½ÖÖ¿ÉÄܵĹ¥»÷³¡¾°£¬£¬£¬£¬£¬£¬Ò»ÖÖÊÇ»ªË¶Ôâµ½¹©Ó¦Á´¹¥»÷£¬£¬£¬£¬£¬£¬ÁíÒ»ÖÖÊǹ¥»÷ÕßʹÓÃÖÐÐÄÈ˹¥»÷ºÍÒ×Êܹ¥»÷µÄ·ÓÉÆ÷À´Èö²¥¶ñÒâÈí¼þ¡£¡£¡£½øÒ»²½µÄÆÊÎöºóÑо¿Ö°Ô±ÒÔΪºóÒ»ÖÖ¹¥»÷³¡¾°µÄ¿ÉÄÜÐÔ¸ü´ó¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/bad-actors-using-mitm-attacks-against-asus-to-distribute-plead-backdoor/

3¡¢Stack OverflowÐû²¼Í¨¸æ³ÆÆäÔâºÚ¿ÍÈëÇÖ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


5ÔÂ16ÈÕStack OverflowÐû²¼ÁËÒ»Ìõ¼ò¶ÌµÄͨ¸æ£¬£¬£¬£¬£¬£¬³Æ5ÔÂ11ÈÕºÚ¿ÍÈëÇÖÁËÆäÉú²úϵͳ¡£¡£¡£Æ¾Ö¤Stack Overflow¹¤³Ì¸±×ܲÃMary FergusonµÄ˵·¨£¬£¬£¬£¬£¬£¬ºÚ¿Í»ñµÃÁËÒ»¶¨Ë®Æ½µÄÉú²úϵͳ»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬Stack Overflow·¢Ã÷²¢ÊÓ²ìÁË»á¼ûµÄ¹æÄ££¬£¬£¬£¬£¬£¬²¢ÇÒÐÞ¸´ÁËËùÓеÄÒÑÖªÎó²î¡£¡£¡£ÊÓ²ìûÓз¢Ã÷ºÚ¿Í»ñµÃÓû§Êý¾ÝµÄÈκÎÖ¤¾Ý¡£¡£¡£ÏÖÔÚÊÓ²ìÕýÔÚ¾ÙÐÐÖУ¬£¬£¬£¬£¬£¬Òò´ËStack Overflow²¢Î´Åû¶¸ü¶àϸ½Ú¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/stack-overflow-says-hackers-breached-production-systems/

4¡¢Î´ÉèÃÜÂëµÄÊý¾Ý¿âй¶½ü90%°ÍÄÃÂí¹«ÃñÐÅÏ¢


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ô±Bob DiachenkoʹÓÃShodanÔÚAWSÉÏ·¢Ã÷Ò»¸öδÊܱ£» £»£»£»¤µÄElasticsearchÊý¾Ý¿â£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âй¶ÁËÊý°ÙÍò°ÍÄÃÂí¹«ÃñµÄÃô¸ÐÐÅÏ¢¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄ±íÊö£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨3427396Ìõ±êǩΪ¡°»¼Õß¡±µÄ¼Í¼ÒÔ¼°468086Ìõ±êǩΪ¡°²âÊÔ»¼Õß¡±µÄ¼Í¼¡£¡£¡£ÕâЩÐÅÏ¢°üÀ¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éí·ÝÖ¤ºÅÂë¡¢µØµã¡¢ÓÊÏäºÍµç»°ºÅÂëµÈ¡£¡£¡£ÈôÊÇÊý¾ÝûÓÐÖØ¸´£¬£¬£¬£¬£¬£¬ÕâЩ¼Í¼Լռ¸Ã¹ú×ÜÉú³ÝµÄ90%¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/sensitive-information-of-millions-of-panama-citizens-leaked/

5¡¢¶íÂÞ˹ºÚ¿Í×éÖ¯³öÊÛÃÀ¹ú3´ó·´²¡¶¾¹«Ë¾Ô´Âë


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


×Ô3Ô·ÝÒÔÀ´£¬£¬£¬£¬£¬£¬¶íÂÞ˹ºÚ¿ÍÍÅ»ïFxmspÔÚµØÏÂÂÛ̳ÉÏÐû³Æ³öÊÛÈý¼ÒÃÀ¹ú·´²¡¶¾¹«Ë¾µÄÈí¼þ²úÆ·Ô´ÂëºÍ¹«Ë¾ÍøÂç»á¼ûȨÏÞ¡£¡£¡£ÆðÔ´µÄ¼ÛÇ®ÊÇ»á¼ûȨÏÞ25ÍòÃÀÔª£¬£¬£¬£¬£¬£¬Ô´´úÂë15ÍòÃÀÔª£¬£¬£¬£¬£¬£¬µ«±¨¼Û²¢²»Àο¿¡£¡£¡£Fxmsp²¢Î´Ö¸³öÏêϸµÄ¹«Ë¾Ãû³Æ£¬£¬£¬£¬£¬£¬µ«ÌṩÁ˰üÀ¨30TBÊý¾ÝµÄÎļþ¼Ð½ØÆÁ£¬£¬£¬£¬£¬£¬¾Ý³ÆÕâЩÊý¾Ý°üÀ¨¿ª·¢Îĵµ¡¢È˹¤ÖÇÄÜÄ£×Ó¡¢WebÇå¾²Èí¼þºÍ·´²¡¶¾Èí¼þµÄ´úÂëµÈ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-selling-access-and-source-code-from-antivirus-companies/