ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ48ÖÜ
Ðû²¼Ê±¼ä 2020-11-30> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2020Äê11ÔÂ23ÈÕÖÁ11ÔÂ29ÈÕ¹²ÊÕ¼Çå¾²Îó²î48¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇVmware Workspace One CVE-2020-4006ÏÂÁî×¢ÈëÎó²î£»£»£»£»£»£»£»Shenzhen C-Data 72408AĬÈÏtelnetЧÀÍÎó²î£»£»£»£»£»£»£»Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤Îó²î£»£»£»£»£»£»£»Barco wePresent WiPG-1600W¹Ì¼þÐÅϢй¶Îó²î£»£»£»£»£»£»£»Mongodb Server RoleName::parseFromBSON()¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÁù¸öÔÂÒÔÀ´Î¢ÈíÈÔδÐÞ¸´Windows10ÖÐÒÑÖªÎó²î£»£»£»£»£»£»£»ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸ÁÐ±í£»£»£»£»£»£»£»VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬£¬£¬£¬£¬£¬£¬ÉÐδÐû²¼²¹¶¡£¡£¡£¡£»£»£»£»£»£»£»Ñо¿Ö°Ô±·¢Ã÷Win7ºÍServer2008ÖеÄÍâµØÌáȨ0day£»£»£»£»£»£»£»Group-IBÐû²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÕ¹ÍûÆÊÎö±¨¸æ¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Vmware Workspace One CVE-2020-4006ÏÂÁî×¢ÈëÎó²î
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿É×¢Èëí§ÒâÏÂÁî²¢Ö´ÐС£¡£¡£¡£
https://docs.opsmanager.mongodb.com/current/release-notes/application/#onprem-server-4-4-3
2.Shenzhen C-Data 72408AĬÈÏtelnetЧÀÍÎó²î
Shenzhen C-Data 72408A TelnetЧÀͱ£´æ¶à¸öĬÈÏÆ¾Ö¤Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉδÊÚȨ»á¼û×°±¸¡£¡£¡£¡£
https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html
3.Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤Îó²î
Barco wePresent WiPG-1600W¹Ì¼þ¸üÐÂÑéÖ¤±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿É×°ÖÃÐ޻ڸĵÄ/¶ñÒâµÄÓ³Ïñ¡£¡£¡£¡£
https://korelogic.com/Resources/Advisories/KL-001-2020-009.txt
4.Barco wePresent WiPG-1600W¹Ì¼þÐÅϢй¶Îó²î
Barco wePresent WiPG-1600W¹Ì¼þÓ³ÏñÖаüÀ¨Ó²±àÂëµÄ¸ùÃÜÂëÉ¢ÁУ¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿Éͨ¹ý´ËÐÅϢδÊÚȨ»á¼û¡£¡£¡£¡£
https://korelogic.com/Resources/Advisories/KL-001-2020-008.txt
5.Mongodb Server RoleName::parseFromBSON()¾Ü¾øÐ§ÀÍÎó²î
Mongodb Server RoleName::parseFromBSON()±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿É¾ÙÐоܾøÐ§À͹¥»÷¡£¡£¡£¡£
https://jira.mongodb.org/browse/SERVER-49142
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢Áù¸öÔÂÒÔÀ´Î¢ÈíÈÔδÐÞ¸´Windows10ÖÐÒÑÖªÎó²î
×Ô2020Äê5Ô£¬£¬£¬£¬£¬£¬£¬MicrosoftÐû²¼ÁËWindows 10 2004Çå¾²¸üк󣬣¬£¬£¬£¬£¬£¬·ºÆðÁËÁ½¸öÎó²î£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂSSDÇý¶¯Æ÷µÄ´ÅÅÌË鯬ÕûÀí¹ýÓÚÆµÈÔ£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ·ÇSSDÇý¶¯Æ÷ÉÏʵÑéTRIM²Ù×÷¡£¡£¡£¡£µÚÒ»¸öÎó²îʹWin10×Ô¶¯Î¬»¤¹¦Ð§ÎÞ·¨¼Ç×ÅÖØÆôϵͳʱÇý¶¯Æ÷µÄ×îºóÓÅ»¯Ê±¼ä£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÇý¶¯Æ÷ÔÚÿ´ÎÖØÆôÅÌËã»úʱ¶¼¾ÙÐÐË鯬ÕûÀí¡£¡£¡£¡£µÚ¶þ¸öÎó²îµ¼ÖÂWin10µÄÓÅ»¯Çý¶¯Æ÷¹¦Ð§»á¶Ô·ÇSSDÇý¶¯Æ÷¾ÙÐÐTRIM£¬£¬£¬£¬£¬£¬£¬Õâ»áµ¼ÖÂÊÂÎñÈÕÖ¾Öйýʧ¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬ÔÚ½üÁù¸öÔÂÖ®ºó£¬£¬£¬£¬£¬£¬£¬MicrosoftÈÔδÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/windows-10-defrag-trim-bug-still-not-fixed-after-six-months/
2¡¢ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸Áбí
ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸ÁÐ±í£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨À´×ÔÌìϸ÷µØµÄ´óÐÍÒøÐкÍÕþ¸®×éÖ¯¡£¡£¡£¡£ÕâЩװ±¸Öоù±£´æÂ·¾¶±éÀúÎó²î£¬£¬£¬£¬£¬£¬£¬±»×·×ÙΪCVE-2018-13379£¬£¬£¬£¬£¬£¬£¬ËüÓ°ÏìÁË´ó×ÚδÐÞ²¹µÄFortinet FortiOS SSL VPN×°±¸¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬´ÓFortinet VPN»á¼ûsslvpn_websessionÎļþÀ´ÇÔÈ¡µÇ¼ƾ֤£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäÓÃÓÚÆÆËðÍøÂç²¢°²ÅÅÀÕË÷Èí¼þ¡£¡£¡£¡£Ö»¹Ü¸ÃÎó²îÔÚÒ»Äêǰ¾Í±»¹ûÕæÅû¶£¬£¬£¬£¬£¬£¬£¬µ«ºÚ¿ÍÈÔ·¢Ã÷²¢¹ûÕæÁËÁË49577¸ö±£´æ´ËÀàÎó²îµÄ´óÐÍ×°±¸µÄÁÐ±í¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-posts-exploits-for-over-49-000-vulnerable-fortinet-vpns/
3¡¢VMwareÅû¶WorkspaceÖеÄÌáȨ0day£¬£¬£¬£¬£¬£¬£¬ÉÐδÐû²¼²¹¶¡
VMwareÅû¶ÁËÓ°ÏìÆäWorkspace One¶à¸ö×é¼þÖеÄÌáȨ0day£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÌáȨÒÔÔÚLinuxºÍWindows²Ù×÷ϵͳÉÏÖ´ÐÐÏÂÁ£¬£¬£¬£¬£¬£¬ÏÖÔÚÉÐδÐû²¼Ïà¹Ø²¹¶¡³ÌÐò¡£¡£¡£¡£¸ÃÎó²î±»¸ú×ÙΪCVE-2020-4006£¬£¬£¬£¬£¬£¬£¬CVSSÆ·¼¶Îª9.1£¬£¬£¬£¬£¬£¬£¬ÆäÓ°ÏìÁËVMware Workspace ONE Access¡¢»á¼ûÅþÁ¬Æ÷¡¢Éí·ÝÖÎÀíÆ÷¡¢Éí·ÝÖÎÀíÆ÷ÅþÁ¬Æ÷¡¢VMwareÔÆ»ù½ð»áºÍvRealize SuiteÉúÃüÖÜÆÚÖÎÀíÆ÷¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬VMwareÒÑÐû²¼ÔÝʱ½â¾ö²½·¥ÒÔÏû³ý¹¥»÷ǰÑÔ²¢±ÜÃâÎó²îµÄʹÓᣡ£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/vmware-zero-day-patch-pending/161523/
4¡¢Ñо¿Ö°Ô±·¢Ã÷Win7ºÍServer2008ÖеÄÍâµØÌáȨ0day
·¨¹úÑо¿Ö°Ô±·¢Ã÷Windows 7ºÍServer 2008±£´æÍâµØÌáȨ£¨LPE£©0day£¬£¬£¬£¬£¬£¬£¬µ±WindowsÇå¾²¹¤¾ß¸üÐÂʱ»áÓ°ÏìÆä²Ù×÷ϵͳ¡£¡£¡£¡£¸ÃÎó²îλÓÚËùÓÐWindows×°ÖÃÖеÄRPC¶ËµãÓ³ÉäÆ÷ºÍDNSCacheЧÀ͵ÄÁ½¸ö¹ýʧÉèÖõÄ×¢²á±íÏîÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄÕâЩע²á±íÀ´¼¤»îWindowsÐÔÄܼàÊÓ»úÖÆËùʹÓõÄ×ÓÃÜÔ¿¡£¡£¡£¡£ÏÖÔÚ0patchƽ̨ÒÑÐû²¼ÔÝʱ΢²¹¶¡£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ΢ÈíÐû²¼Õýʽ²¹¶¡Ç°¶ÔËùÓÐÈËÃâ·ÑÌṩ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/windows-7-and-server-2008-zero-day-bug-gets-a-free-patch/
5¡¢Group-IBÐû²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÕ¹ÍûÆÊÎö±¨¸æ
Group-IBÐû²¼Á˶ÔÀ´ÄêÍøÂçÍþвµÄÕ¹ÍûÆÊÎö±¨¸æ£¬£¬£¬£¬£¬£¬£¬Ñо¿ÁË2019ÄêϰëÄêÖÁ2020ÄêÉϰëÄêÖ®¼ä¹ú¼ÊÍøÂç·¸·¨ÐÐΪµÄÖ÷Ҫת±ä£¬£¬£¬£¬£¬£¬£¬²¢¶ÔÀ´Äê×ö³öÁËÕ¹Íû¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þ»î¶¯Ôì³ÉÁËÑÏÖØµÄ¾¼ÃËðʧ£¬£¬£¬£¬£¬£¬£¬Ë½Óª¹«Ë¾ºÍÕþ¸®»ú¹¹¶¼Î´ÄÜÐÒÃâ¡£¡£¡£¡£ÔÚ´Ëʱ´ú£¬£¬£¬£¬£¬£¬£¬×ܹ²ÓÐÕë¶ÔÁè¼Ý45¸ö¹ú¼ÒµÄ500¶à´ÎÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£Æ¾Ö¤Group-IBµÄÊØ¾ÉÔ¤¼Æ£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þÍÅ»ïÔì³ÉµÄ×ܲÆÎñËðʧÁè¼Ý10ÒÚÃÀÔª£¨1005186000ÃÀÔª£©¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬MazeºÍREvilµÄÓ°Ïì×î´ó£¬£¬£¬£¬£¬£¬£¬Õ¼ËùÓй¥»÷µÄ°ëÊýÒÔÉÏ£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇRyuk¡¢NetWalkerºÍDoppelPaymer¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.group-ib.com/media/gib-report-2020/