ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ9ÖÜ

Ðû²¼Ê±¼ä 2021-03-01

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2021Äê02ÔÂ22ÈÕÖÁ02ÔÂ28ÈÕ¹²ÊÕ¼Çå¾²Îó²î53¸ö£¬£¬£¬£¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇNETGEAR Nighthawk R7800Ó²±àÂëÑéÖ¤ÈÆ¹ýÎó²î£»£»£»£»£»£» £»Siemens SINEC NMS FirmwareFileUtils extractToFolderĿ¼±éÀú´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£» £»TP-Link AC1750 sync-serverÕ»Òç³öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£» £»On Netshield NANO CVE-2021-3149ÏÂÁî×¢ÈëÎó²î£»£»£»£»£»£» £»Adobe Bridge CVE-2021-21065Ô½½çд´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ΢Èí·¢Ã÷Windows Win32kÌáȨ0dayÒѱ»ÔÚҰʹÓ㻣»£»£»£»£» £»Ð¶ñÒâÈí¼þSilver SparrowÒÑѬȾ½ü3Íǫ̀Mac×°±¸£»£»£»£»£»£» £»FireEye³ÆÕë¶ÔAccellion FTAµÄ¹¥»÷ÓëFIN11ÓйØ£»£»£»£»£»£» £»·É»úÖÆÔìÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹûÕæ£»£»£»£»£»£» £»·ÒÀ¼TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ £¬¿Í»§Ð§ÀÍÔÝʱÖÐÖ¹¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬ £¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£


> Ö÷ÒªÇå¾²Îó²îÁбí


1.NETGEAR Nighthawk R7800Ó²±àÂëÑéÖ¤ÈÆ¹ýÎó²î


NETGEAR Nighthawk R7800 apply_save.cgiʹÓÃÓ²±àÂëÎó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬ £¬¿ÉÒÔROOTȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-252/


2.Siemens SINEC NMS FirmwareFileUtils extractToFolderĿ¼±éÀú´úÂëÖ´ÐÐÎó²î


Siemens SINEC NMS FirmwareFileUtils extractToFolder±£´æÄ¿Â¼±éÀúÎó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬ £¬¿ÉÒÔWEBÓ¦ÓóÌÐòÉÏÏÂÎĶÁÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-253/


3.TP-Link AC1750 sync-serverÕ»Òç³öÔ¶³Ì´úÂëÖ´ÐÐÎó²î


TP-Link AC1750 sync-server MACµØµã´¦Öóͷ£±£´æÕ»Òç³öÎó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬ £¬¿ÉÒÔROOTȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-215/


4.On Netshield NANO CVE-2021-3149ÏÂÁî×¢ÈëÎó²î


On Netshield NANO /usr/local/webmin/System/manual_ping.cgi±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬ £¬¿ÉÒÔWEBÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://www.digitaldefense.com/resources/vulnerability-research/netshield-corporation-nano-25/


5.Adobe Bridge CVE-2021-21065Ô½½çд´úÂëÖ´ÐÐÎó²î


Adobe Bridge´¦Öóͷ£Îļþ±£´æÔ½½çдÎó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬ £¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬ £¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£» £»ò¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://helpx.adobe.com/security/products/bridge/apsb21-07.html


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Î¢Èí·¢Ã÷Windows Win32kÌáȨ0dayÒѱ»ÔÚҰʹÓÃ


1.jpg


΢Èí·¢Ã÷Windows Win32kÖеÄÌáȨ0day£¨CVE-2021-1732£©Òѱ»ÔÚҰʹÓᣡ£¡£¡£¡£¸ÃÎó²î±£´æÓÚwin32k.sys½¹µãÄÚºË×é¼þÖУ¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿Éͨ¹ý´¥·¢ÊͷźóʹÓÃÎó²î½«ÆäȨÏÞÌáÉýµ½admin¼¶±ð£¬£¬£¬£¬£¬ £¬¾ßÓлù±¾Óû§È¨Ï޵Ĺ¥»÷Õß²»ÐèÒªÓëÓû§½»»¥¼´¿ÉʹÓøÃÎó²î¡£¡£¡£¡£¡£¾ÝÊӲ죬£¬£¬£¬£¬ £¬¸ÃÎó²îÒѱ»APT×éÖ¯BitterºÍT-APT-17ʹÓ㬣¬£¬£¬£¬ £¬DBAPPSecurityÔò³ÆÆäÓÚ12Ô·¢Ã÷ÁË¿ª·¢ÈÕÆÚΪ2020Äê5ÔµÄÑù±¾¡£¡£¡£¡£¡£¶ø×Ô2021Äê2ÔÂ×îÏÈ£¬£¬£¬£¬£¬ £¬ºÚ¿ÍÖ»ÔÚÉÙÊýÕë¶ÔÖж«µÄ¹¥»÷ÖÐʹÓÃÁËCVE-2021-1732Îó²î¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/recently-fixed-windows-zero-day-actively-exploited-since-mid-2020/


2¡¢Ð¶ñÒâÈí¼þSilver SparrowÒÑѬȾ½ü3Íǫ̀Mac×°±¸


2.jpg


Red CanaryÑо¿Ö°Ô±·¢Ã÷Õë¶ÔMac×°±¸µÄжñÒâÈí¼þSilver Sparrow¡£¡£¡£¡£¡£×èÖ¹2ÔÂ17ÈÕ£¬£¬£¬£¬£¬ £¬Silver SparrowÒÑÔÚ153¸ö¹ú¼ÒºÍµØÇøÑ¬È¾ÁË29139¸ömacOSÖÕ¶Ë£¬£¬£¬£¬£¬ £¬²¢ÔÚÃÀ¹ú¡¢Ó¢¹ú¡¢¼ÓÄô󡢷¨¹úºÍµÂ¹ú´ó×ÚÈö²¥¡£¡£¡£¡£¡£Óë´ó´ó¶¼Ê¹ÓÃ'preinstall'ºÍ'postinstall'¾ç±¾µÄ¶ñÒâÈí¼þ²î±ð£¬£¬£¬£¬£¬ £¬Silver SparrowʹÓÃJavaScriptÖ´ÐÐÏÂÁ£¬£¬£¬£¬ £¬´Ó¶øºÜÄÑÆ¾Ö¤ÏÂÁîÐвÎÊý¼ì²â¶ñÒâ»î¶¯¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ £¬¸Ã¶ñÒâÈí¼þµÄÕæÕýÄ¿µÄÏÖÔÚÈÔÈ»ÊǸöÃÕ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/30000-macs-infected-with-new-silver-sparrow-malware/


3¡¢FireEye³ÆÕë¶ÔAccellion FTAµÄ¹¥»÷ÓëFIN11ÓйØ


3.jpg


Çå¾²¹«Ë¾FireEye³Æ£¬£¬£¬£¬£¬ £¬2020Äê12Ôµ½2021Äê1ÔÂÖ®¼äʹÓÃAccellion FTAЧÀÍÆ÷ÖÐ0dayµÄ¹¥»÷»î¶¯ÓëFIN11ÓйØ£¬£¬£¬£¬£¬ £¬²¨¼°ÁËÈ«ÇòÔ¼100¼Ò¹«Ë¾¡£¡£¡£¡£¡£ºÚ¿ÍÖ÷ҪʹÓÃÁËËĸöÎó²îÀ´¹¥»÷FTAЧÀÍÆ÷£¬£¬£¬£¬£¬ £¬²¢×°ÖÃÁËÒ»¸öÃûΪDEWMODEµÄWeb Shell£¬£¬£¬£¬£¬ £¬À´ÏÂÔØÊܺ¦ÕßFTA×°±¸ÉÏ´æ´¢µÄÎļþ¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¹«Ë¾ºÍ×éÖ¯°üÀ¨Fugro¡¢Danaher¡¢Singtel¡¢Jones¡¢ÐÂÎ÷À¼´¢±¸ÒøÐкͰĴóÀûÑÇ֤ȯºÍͶ×ÊίԱ»á£¨ASIC£©µÈ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ £¬ºÚ¿ÍÔÚClopµÄÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏÁгöÁ˲¿·Ö¹«Ë¾£¬£¬£¬£¬£¬ £¬ÒÔڲƭÀÕË÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/attacks-targeting-accellion-product-linked-fin11-cybercrime-group


4¡¢·É»úÖÆÔìÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹûÕæ


4.jpg


¼ÓÄôó·É»úÖÆÔìÉÌBombardier³ÆÆäÊý¾ÝÒÑÔÚClopÍøÕ¾ÉϹûÕæ¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚͨ¸æÖÐÌåÏÖ£¬£¬£¬£¬£¬ £¬¾­³õ³ÌÐò²é£¬£¬£¬£¬£¬ £¬ºÚ¿ÍʹÓÃÁ˵ÚÈý·½Îļþ´«ÊäÓ¦ÓÃÖеÄÎó²îÀ´»á¼ûºÍÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£Ö»¹Ü²¢Ã»ÓÐÏêϸָ³ö¸Ã×°±¸µÄÃû³Æ£¬£¬£¬£¬£¬ £¬µ«¾ÝÍÆ²âºÜ¿ÉÄÜÊÇÖ¸µÄAccellion FTA¡£¡£¡£¡£¡£±»µÁÊý¾ÝÒÑÔÚÀÕË÷ÍÅ»ïClopµÄÊý¾ÝÐ¹Â¶ÍøÕ¾¹ûÕæ£¬£¬£¬£¬£¬ £¬°üÀ¨BombardierÖÖÖÖ·É»úºÍ·É»úÁã¼þµÄÉè¼ÆÎļþ£¬£¬£¬£¬£¬ £¬²¢Ã»ÓÐÈκÎСÎÒ˽¼ÒÊý¾Ýй¶¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/airplane-maker-bombardier-data-posted-on-ransomware-leak-site-following-fta-hack/


5¡¢·ÒÀ¼TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ £¬¿Í»§Ð§ÀÍÔÝʱÖÐÖ¹


5.jpg


·ÒÀ¼ITЧÀ͹«Ë¾TietoEVRYÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ £¬¿Í»§Ð§ÀÍÔÝʱÖÐÖ¹¡£¡£¡£¡£¡£TietoEVRYÊÇÒ»¼ÒÈí¼þ¿ª·¢ºÍITЧÀ͹«Ë¾£¬£¬£¬£¬£¬ £¬ÔÚ80¸ö¹ú¼ÒºÍµØÇøÓµÓÐ24000ÃûÔ±¹¤£¬£¬£¬£¬£¬ £¬2019ÄêµÄÊÕÈëΪ29.5ÒÚÅ·Ôª¡£¡£¡£¡£¡£±¾ÖÜÒ»£¬£¬£¬£¬£¬ £¬TietoEVRYµÄÁãÊÛ¡¢ÖÆÔìºÍЧÀÍÏà¹ØÐÐÒµµÄ25¸ö¿Í»§ÌåÏÖÆäÓöµ½ÁËÊÖÒÕÎÊÌ⣬£¬£¬£¬£¬ £¬ØÊºóµÃÖªÕâЩÎÊÌâÊÇÓÉÀÕË÷Èí¼þ¹¥»÷ÒýÆðµÄ¡£¡£¡£¡£¡£TietoEVRY·¢Ã÷¹¥»÷ºóÁ¬Ã¦¹Ø±ÕÁËÊÜÓ°ÏìµÄϵͳºÍЧÀÍ£¬£¬£¬£¬£¬ £¬²¢ÓëµØ·½Õþ¸®¶Ô´ËÊÂÕö¿ªÊӲ졣¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/finnish-it-services-giant-tietoevry-discloses-ransomware-attack/