ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ50ÖÜ

Ðû²¼Ê±¼ä 2021-12-13

>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼Çå¾²Îó²î60¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Log4j2í§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Tencent WeChat WXAM DecoderÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»£»£»Google golang ForrkExec¾Ü¾øÐ§ÀÍÎó²î£»£»£»£»£»Mozilla Firefox file picker dialogÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»£»£»Veritas Enterprise Vault CVE-2021-44680´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇmagnatʹÓÃαÔìµÄWeChatµÈ×°ÖóÌÐò·Ö·¢ºóÃÅ£»£»£»£»£»MailGuard·¢Ã÷ÒÔ΢ÈíÀ¬»øÓʼþ֪ͨΪÖ÷ÌâµÄ´¹Âڻ£»£»£»£»£»Googleµ·»Ù¿ØÖÆ×ÅÁè¼Ý100Íǫ̀װ±¸µÄ½©Ê¬ÍøÂçGlupteba£»£»£»£»£»SonicWallÐû²¼¸üУ¬£¬£¬£¬ÐÞ¸´SMA 100ϵÁÐÖжà¸öÎó²î£»£»£»£»£»ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLabЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Apache Log4j2í§Òâ´úÂëÖ´ÐÐÎó²î


Apache Log4j2±£´æJava JNDI×¢ÈëÎó²î£¬£¬£¬£¬µ±³ÌÐò½«Óû§ÊäÈëµÄÊý¾Ý¾ÙÐÐÈÕÖ¾¼Í¼£¬£¬£¬£¬¼´¿É´¥·¢´ËÎó²î£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÒÔÔÚÄ¿µÄЧÀÍÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£


https://github.com/apache/logging-log4j2/commit/7fe72d6


2. Tencent WeChat WXAM DecoderÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î


Tencent WeChat WXAM Decoder±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£


https://www.zerodayinitiative.com/advisories/ZDI-21-1446/


3. Google golang ForrkExec¾Ü¾øÐ§ÀÍÎó²î


Google golang ForrkExec´¦Öóͷ£±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉʹЧÀͳÌÐòÍ߽⣬£¬£¬£¬Ôì³É¾Ü¾øÐ§À͹¥»÷¡£¡£¡£¡£¡£¡£¡£


https://github.com/golang/go/commit/99950270f3cf52cccc6966d8668ff21b573bb6f5


4. Mozilla Firefox file picker dialogÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î


Mozilla Firefox file picker dialog±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄwebÒ³ÇëÇ󣬣¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£


https://www.mozilla.org/en-US/security/advisories/mfsa2021-48/


5. SVeritas Enterprise Vault CVE-2021-44680´úÂëÖ´ÐÐÎó²î


Veritas Enterprise VaultÓ¦ÓÃÆô¶¯Ð§Àͱ£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£


https://www.veritas.com/content/support/en_US/security/VTS21-003



>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢magnatʹÓÃαÔìµÄWeChatµÈ×°ÖóÌÐò·Ö·¢ºóÃÅ


Cisco TalosÔÚ12ÔÂ3ÈÕ¹ûÕæÁËmagnatµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ʼÓÚ2018Äêµ×£¬£¬£¬£¬×Ô2021Äê4ÔÂÒÔÀ´µÖ´ï·åÖµ£¬£¬£¬£¬Ö÷ÒªÕë¶Ô¼ÓÄô󣬣¬£¬£¬Æä´ÎÊÇÃÀ¹ú¡¢°Ä´óÀûÑÇ¡¢Òâ´óÀû¡¢Î÷°àÑÀ¡¢Å²ÍþµÈ¹ú¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃαÔìµÄViber¡¢WeChat¡¢NoxPlayerºÍBattlefieldµÈÓ¦ÓúÍÓÎÏ·µÄ×°ÖóÌÐò£¬£¬£¬£¬ÓÕʹĿµÄÏÂÔØºóÃųÌÐòºÍ¶ñÒâChromeÀ©Õ¹³ÌÐò£¬£¬£¬£¬×îÖÕ»áÇÔȡƾ֤¡¢ÏµÍ³ÖеÄÃô¸ÐÊý¾ÝÒÔ¼°Ô¶³Ì»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/12/magnat-campaigns-use-malvertising-to.html


2¡¢MailGuard·¢Ã÷ÒÔ΢ÈíÀ¬»øÓʼþ֪ͨΪÖ÷ÌâµÄ´¹Âڻ


ÓʼþÇå¾²¹«Ë¾MailGuardÔÚ12ÔÂ2ÈÕ·¢Ã÷ÒÔ΢ÈíÀ¬»øÓʼþ֪ͨΪÖ÷ÌâµÄ´¹Âڻ¡£¡£¡£¡£¡£¡£¡£ÕâЩÓʼþ·¢ËÍ×Ôquarantine[at]messaging.microsoft.com£¬£¬£¬£¬ÏÔʾµÄÃû³ÆÊÇÊÕ¼þÈ˵ÄÓò£¬£¬£¬£¬Í¨¹ýÕâÖÖ·½·¨À´ÔöÌíÆä¿ÉÐŶÈ¡£¡£¡£¡£¡£¡£¡£¸Ã´¹ÂÚÓʼþÌáÐÑÄ¿µÄÓб»¸ôÀëµÄÀ¬»øÓʼþ£¬£¬£¬£¬µ±Ä¿µÄµã»÷Éó²éºó»á±»Öض¨Ïòµ½´¹ÂÚÍøÕ¾²¢±»ÒªÇóÊäÈëOffice 365ƾ֤¡£¡£¡£¡£¡£¡£¡£Î¢Èí¹«Ë¾ÔÚ8Ô·Ý͸¶£¬£¬£¬£¬×Ô2020Äê7ÔÂ×îÏȵÄÓã²æÊ½´¹Âڻ¶à´ÎÕë¶ÔOffice 365Óû§¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.mailguard.com.au/blog/scammers-mimic-microsoft-with-spam-notification-phishing-email


3¡¢Googleµ·»Ù¿ØÖÆ×ÅÁè¼Ý100Íǫ̀װ±¸µÄ½©Ê¬ÍøÂçGlupteba


GoogleÔÚ12ÔÂ7ÈÕÐû²¼ÆäÒѵ·»Ù¿ØÖÆ×ÅÁè¼Ý100Íǫ̀װ±¸µÄ½©Ê¬ÍøÂçGlupteba¡£¡£¡£¡£¡£¡£¡£Glupteba×Ô2011ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬ÊÇÒ»ÖÖÖ§³ÖÇø¿éÁ´µÄÄ£¿£¿£¿£¿£¿£¿£¿é»¯¶ñÒâÈí¼þ£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢Ó¡¶È¡¢°ÍÎ÷ºÍ¶«ÄÏÑǵĹú¼Ò£¬£¬£¬£¬ÌìÌìÐÂÔöѬȾװ±¸µÄÊýÄ¿¸ß´ïÊýǧ̨¡£¡£¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂçÖ÷Ҫͨ¹ýÆÆ½â»òµÁ°æÈí¼þºÍPPI¼Æ»®Èö²¥£¬£¬£¬£¬Ñ¬È¾Ä¿µÄºó»áÇÔÈ¡¼ÓÃÜÇ®±Ò¡¢Óû§Æ¾Ö¤ºÍcookie£¬£¬£¬£¬²¢ÔÚÄ¿µÄ×°±¸Éϰ²ÅÅÊðÀí£¬£¬£¬£¬Ëæºó³öÊÛ¸øÆäËû¹¥»÷Õß¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-disrupts-massive-glupteba-botnet-sues-russian-operators/


4¡¢SonicWallÐû²¼¸üУ¬£¬£¬£¬ÐÞ¸´SMA 100ϵÁÐÖжà¸öÎó²î


SonicWallÔÚ12ÔÂ7ÈÕÐû²¼¸üУ¬£¬£¬£¬ÐÞ¸´SMA 100ϵÁÐ×°±¸ÖеĶà¸öÎó²î¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÎó²îÊÇ»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¨CVE-2021-20038£©£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬ÓÉÓÚ×°±¸µÄApache httpdЧÀÍÆ÷ÖеÄHTTP GETÒªÁìµÄÇéÐαäÁ¿Ê¹ÓÃÁËstrcat()º¯Êýµ¼Öµģ»£»£»£»£»Æä´ÎÊÇ»º³åÇøÒç³öÎó²î£¨CVE-2021-20045£©£¬£¬£¬£¬CVSSÆÀ·Ö9.4¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬»¹ÐÞ¸´ÁË»º³åÇøÒç³öÎó²î£¨CVE-2021-20043£©ºÍÈÏÖ¤ÏÂÁî×¢ÈëÎó²î£¨CVE-2021-20039£©µÈ¡£¡£¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.cisa.gov/uscert/ncas/current-activity/2021/12/08/sonicwall-releases-security-advisory-sma-100-series-appliances


5¡¢ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLabЧÀÍÆ÷


12ÔÂ7ÈÕ£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ʹÓÃÁ˾ÉÃû³ÆµÄÐÂÀÕË÷Èí¼þCerber¡£¡£¡£¡£¡£¡£¡£ÀÕË÷Èí¼þCerberÓÚ2016Äê·ºÆð£¬£¬£¬£¬Ö±µ½2019Äêµ×ÏûÊÅ¡£¡£¡£¡£¡£¡£¡£´ÓÉϸöÔÂ×îÏÈ£¬£¬£¬£¬Cerbe»Ø¹é£¬£¬£¬£¬¿ÉÊÇËüÓë¾É°æ²¢²»Ïàͬ£¬£¬£¬£¬´úÂ벻ƥÅ䣬£¬£¬£¬Ð°æÊ¹ÓÃCrypto+++¿â¶ø¾É°æ±¾Ê¹ÓÃWindows CryptoAPI¿â£¬£¬£¬£¬²¢ÇҾɰæCerberҲûÓÐLinux±äÌå¡£¡£¡£¡£¡£¡£¡£ÐÂCerberµÄÊê½ðÒªÇó´Ó1000ÃÀÔªµ½3000ÃÀÔª²»µÈ£¬£¬£¬£¬Ê¹ÓÃÁËCVE-2021-26084ºÍCVE-2021-22205Îó²îÃé×¼ConfluenceºÍGitLabЧÀÍÆ÷£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢µÂ¹úºÍÖйú¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-cerber-ransomware-targets-confluence-and-gitlab-servers/