ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ46ÖÜ

Ðû²¼Ê±¼ä 2021-11-15
>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼Çå¾²Îó²î58¸ö £¬£¬£¬ £¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe RoboHelp ServerĿ¼±éÀú´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»ServiceTonic Helpdesk softwareδÊÚȨ»á¼ûÎó²î£»£»£»£»£»£»Microsoft Windows Active Directory CVE-2021-42278ȨÏÞÌáÉýÎó²î£»£»£»£»£»£»Microsoft Windows Remote Desktop Client´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»Siemens SIMATIC PCS 7Ŀ¼±éÀúÎó²î¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÑо¿Ö°Ô±·¢Ã÷ð³äÇå¾²¹«Ë¾ProofpointµÄ´¹Âڻ£»£»£»£»£»£»Í³³ÆÎªNUCLEUS:13µÄ¶à¸öÎó²îÓ°ÏìÎ÷ÃÅ×ÓRTOS£»£»£»£»£»£»BusyBoxÖÐ14¸öÐÂÎó²îÓ°ÏìÊý°ÙÍò»ùÓÚUnixµÄ×°±¸£»£»£»£»£»£»Î¢ÈíÐû²¼11Ô¸üР£¬£¬£¬ £¬£¬ÐÞ¸´6¸ö0dayÔÚÄÚµÄ55¸öÎó²î£»£»£»£»£»£»ESET·¢Ã÷LazarusʹÓõÁ°æµÄIDA Pro·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö £¬£¬£¬ £¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Adobe RoboHelp ServerĿ¼±éÀú´úÂëÖ´ÐÐÎó²î


Adobe RoboHelp Server±£´æÄ¿Â¼±éÀúÎó²î £¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬ £¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£


https://www.zerodayinitiative.com/advisories/ZDI-21-1305/


2. ServiceTonic Helpdesk softwareδÊÚȨ»á¼ûÎó²î


ServiceTonic Helpdesk software±£´æÊÚȨ»úÖÆÎó²î £¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬ £¬£¬¿É²»Ê¹ÓÃÃÜÂëδÊÚȨ»á¼ûϵͳ¡£¡£¡£¡£


https://www.srlabs.de/bites/chaining-three-zero-day-exploits-in-itsm-software-servicetonic-for-remote-code-execution


3. Microsoft Windows Active Directory CVE-2021-42278ȨÏÞÌáÉýÎó²î


Microsoft Windows Active Directory±£´æÇå¾²Îó²î £¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬ £¬£¬¿ÉÒÔÌáÉýÌØÈ¨¡£¡£¡£¡£


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278


4. Microsoft Windows Remote Desktop Client´úÂëÖ´ÐÐÎó²î


Microsoft Windows Remote Desktop Client±£´æÎ´Ã÷Çå¾²Îó²î £¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬ £¬£¬¿ÉÒÔϵͳÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38666


5. Siemens SIMATIC PCS 7Ŀ¼±éÀúÎó²î


Siemens SIMATIC PCS 7±£´æÄ¿Â¼±éÀúÎó²î £¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬ £¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£


https://cert-portal.siemens.com/productcert/pdf/ssa-840188.pdf


>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Ñо¿Ö°Ô±·¢Ã÷ð³äÇå¾²¹«Ë¾ProofpointµÄ´¹Âڻ


ArmorbloxµÄÑо¿ÍŶÓÓÚ11ÔÂ4ÈÕÅû¶ÁËð³äÍøÂçÇå¾²¹«Ë¾ProofpointµÄ´¹Âڻ¡£¡£¡£¡£ÕâЩ´¹ÂÚÓʼþµÄÖ÷ÌâΪ¡°Re£ºPayoff Request¡± £¬£¬£¬ £¬£¬Éù³Æ°üÀ¨Ò»·Ýͨ¹ýProofpoint·¢Ë͵ĵäÖÊ´û¿îÏà¹ØÎļþ £¬£¬£¬ £¬£¬Ö¼ÔÚÇÔȡĿµÄµÄMicrosoft Office 365ºÍGoogle Gmailƾ֤¡£¡£¡£¡£¸ÃÓʼþÊÇ´Ó±»µÁµÄСÎÒ˽¼ÒÕÊ»§·¢Ë굀 £¬£¬£¬ £¬£¬·¢¼þÈ˵ÄÓòÃûÓòΪ¡°sdis34[.]fr¡± £¬£¬£¬ £¬£¬ÕâÊÇ·¨¹úÄϲ¿µÄÒ»¸öÏû·À¾ÈÔ®²¿·Ö £¬£¬£¬ £¬£¬¶ø´¹ÂÚÒ³ÃæÍйÜÔÚgreenleafproperties[.]co[.]ukÓò¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.armorblox.com/blog/proofpoint-credential-phishing/


2¡¢Í³³ÆÎªNUCLEUS:13µÄ¶à¸öÎó²îÓ°ÏìÎ÷ÃÅ×ÓRTOS


ForescoutºÍMedigateµÄÑо¿Ö°Ô±ÔÚ11ÔÂ9ÈÕÅû¶ÁËNucleusÖÐ13¸öÎó²îµÄϸ½Ú¡£¡£¡£¡£NucleusÊÇÎ÷ÃÅ×ÓµÄʵʱ²Ù×÷ϵͳ(RTOS) £¬£¬£¬ £¬£¬Í¨³£ÔËÐÐÔÚÒ½ÁÆ×°±¸¡¢Æû³µ¡¢ÖÇÄÜÊÖ»ú¡¢ÎïÁªÍø×°±¸¡¢¹¤ÒµplcµÈ×°±¸µÄƬÉÏϵͳ(SoC)¡£¡£¡£¡£ÕâЩÎó²îͳ³ÆÎªNUCLEUS:13 £¬£¬£¬ £¬£¬Ó°ÏìÁËNucleus TCP/IP¿ÍÕ»¡£¡£¡£¡£ÆäÖÐ £¬£¬£¬ £¬£¬×îÑÏÖØµÄÊÇÓ°ÏìÁËFTPЧÀÍÆ÷×é¼þµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31886£© £¬£¬£¬ £¬£¬CVSSÆÀ·ÖΪ9.8 £¬£¬£¬ £¬£¬ÊÇÓÉÓÚ¶ÔUSERÏÂÁ¶ÈµÄÑéÖ¤²»×¼È·µ¼ÖµÄ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/nucleus13-vulnerabilities-impact-siemens-medical-industrial-equipment/


3¡¢BusyBoxÖÐ14¸öÐÂÎó²îÓ°ÏìÊý°ÙÍò»ùÓÚUnixµÄ×°±¸


Èí¼þ¿ª·¢¹«Ë¾JFrogºÍÇå¾²¹«Ë¾ClarotyÔÚ11ÔÂ9ÈÕÁªºÏÅû¶ÁËBusyBoxÖÐ14¸öÎó²îµÄϸ½Ú¡£¡£¡£¡£BusyBox±»³ÆÎªÇ¶ÈëʽLinuxµÄ¡°ÈðÊ¿¾üµ¶¡± £¬£¬£¬ £¬£¬¿É½«ÖÖÖÖ³£¼ûµÄUnixÓ¦ÓûòС³ÌÐò£¨ÀýÈçcp¡¢ls¡¢grep£©×éºÏ³ÉÒ»¸ö¿ÉÖ´ÐÐÎļþ¡£¡£¡£¡£ÕâЩÎó²î±£´æÓÚBusyBox 1.16µ½1.33.1µÄ¶à¸ö°æ±¾ £¬£¬£¬ £¬£¬Ó°ÏìÁËÊý°ÙÍò»ùÓÚUnixµÄ×°±¸¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇawkÖеÄDoSÎó²îCVE-2021-42383¡¢CVE-2021-42384ºÍCVE-2021-42385µÈ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/124429/hacking/busybox-vulnerabilities.html


4¡¢Î¢ÈíÐû²¼11Ô¸üР£¬£¬£¬ £¬£¬ÐÞ¸´6¸ö0dayÔÚÄÚµÄ55¸öÎó²î


΢ÈíÔÚ11ÔÂ9ÈÕÐû²¼Á˱¾ÔµÄÖܶþ²¹¶¡ £¬£¬£¬ £¬£¬×ܼÆÐÞ¸´ÁË55¸öÎó²î¡£¡£¡£¡£´Ë´ÎÐÞ¸´ÁË6¸ö0 day £¬£¬£¬ £¬£¬°üÀ¨ExcelÖÐÇå¾²¹¦Ð§ÈƹýÎó²î£¨CVE-2021-42292£©¡¢Exchange ServerÖÐRCE£¨CVE-2021-42321£© £¬£¬£¬ £¬£¬RDPÖÐÐÅϢй¶Îó²î£¨CVE-2021-38631ºÍCVE-2021-41371£© £¬£¬£¬ £¬£¬ÒÔ¼°3DÖÐÉó²éÆ÷RCE£¨CVE-2021-43208ºÍCVE-2021-43209£©¡£¡£¡£¡£ÆäÖÐ £¬£¬£¬ £¬£¬CVE-2021-42292ºÍCVE-2021-42321Òѱ»ÓÃÓÚ¶ñÒâ¹¥»÷»î¶¯¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-november-2021-patch-tuesday-fixes-6-zero-days-55-flaws/


5¡¢ESET·¢Ã÷LazarusʹÓõÁ°æµÄIDA Pro·Ö·¢¶ñÒâÈí¼þ


ESETÍŶÓÓÚ11ÔÂ10ÈÕ·¢Ã÷³¯ÏʺڿÍÍÅ»ïLazarusʹÓõÁ°æIDA Pro¹¥»÷Çå¾²Ñо¿Ö°Ô±µÄ»î¶¯¡£¡£¡£¡£Ñо¿Ö°Ô±Í¨³£Ê¹ÓÃÄæÏò¹¤³ÌÓ¦ÓÃIDA ProÀ´ÆÊÎöÎó²îºÍ¶ñÒâÈí¼þ £¬£¬£¬ £¬£¬¶ø´Ë´Î·¢Ã÷µÄIDA Pro 7.5°æ±¾°üÀ¨ÁËÁ½¸öÃûΪidahelp.dllºÍwin_fw.dllµÄ¶ñÒâDLL¡£¡£¡£¡£ÆäÖÐ £¬£¬£¬ £¬£¬win_fw.dll½«ÔÚWindowsʹÃüµ÷Àí³ÌÐòÖн¨ÉèÒ»¸öÐÂʹÃü £¬£¬£¬ £¬£¬¸ÃʹÃü½«Æô¶¯idahelper.dll £¬£¬£¬ £¬£¬È»ºóidahelper.dll½«ÅþÁ¬µ½devguardmap[.]orgÍøÕ¾²¢ÏÂÔØÔ¶³Ì»á¼ûľÂíNukeSpedµÄpayload¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/lazarus-hackers-target-researchers-with-trojanized-ida-pro/