VMwareÐÞ¸´Fusion¡¢HorizonÖеÄÌáȨÎó²î£»£»£»£»ºÚ¿ÍÒÔйڲ¡¶¾ÎªÓÕ¶ü½¨ÉèÊýǧ¸ö¶ñÒâÍøÕ¾

Ðû²¼Ê±¼ä 2020-03-19

1.AdobeÐû²¼´øÍâÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´41¸öÎó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


AdobeÐû²¼´øÍâÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´6ÖÖ²úÆ·ÖеÄ41¸öÎó²î£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨29¸öCriticalÎó²îºÍ11¸öimportantÎó²î¡£¡£¡£ ¡£Adobe AcrobatºÍReaderÖÐÐÞ¸´ÁË13¸öÎó²î£¬£¬£¬£¬£¬£¬ÆäÖÐ9¸öΪCritical¼¶±ð£»£»£»£»Adobe PhotoshopÐÞ¸´ÁË22¸öÎó²î£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨16¸öCriticalÎó²î¡£¡£¡£ ¡£ËùÓÐCriticalÎó²î¶¼ÊÇÄÚ´æËð»µÎÊÌ⣬£¬£¬£¬£¬£¬¿ÉÄܻᵼÖÂí§Òâ´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬ColdFusionÖеÄÒ»¸öÑÏÖØÎó²î£¨CVE-2020-3761£©»¹»áµ¼Ö¹¥»÷Õß´Ó×°ÖÃĿ¼ÖжÁÈ¡í§ÒâÎļþ¡£¡£¡£ ¡£´Ë´Î¸üÐÂÖÐÐÞ¸´µÄÎó²î¾ùδ¹ûÕæÅû¶»ò±»ÆÕ±éʹÓᣡ£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/03/adobe-software-update.html


2.VMwareÐÞ¸´Fusion¡¢HorizonÖеÄÌáȨÎó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


VMwareÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´Á½¸öÎó²î£¬£¬£¬£¬£¬£¬µÚÒ»¸öÎó²î£¨CVE-2020-3950£©ÊÇÓÉÓÚ²»µ±Ê¹ÓÃsetuid¶þ½øÖÆÎļþ¶øµ¼ÖµÄÌØÈ¨ÌáÉýÎÊÌ⣬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ7.3¡£¡£¡£ ¡£ÀÖ³ÉʹÓôËÎó²î¿ÉÄÜ»áʹ¾ßÓÐͨË×Óû§ÌØÈ¨µÄ¹¥»÷Õß½«ÆäÌØÈ¨Éý¼¶µ½rootÓû§£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨Fusion¡¢VMRCºÍHorizon Client¡£¡£¡£ ¡£µÚ¶þ¸öÎó²î£¨CVE-2020-3951£©ÊÇÓÉCortado Thinprint£¨VMware WorkstationºÍWindows Horizon ClientʹÓõÄÐéÄâ´òÓ¡ÒýÇæ£©ÖеĶÑÒçÍÉ»¯ÎóÒýÆðµÄ£¬£¬£¬£¬£¬£¬¾ßÓÐÐéÄâ»ú·ÇÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¿ÉÄܻᵼÖ¾ܾøÐ§ÀÍ¡£¡£¡£ ¡£Ä¬ÈÏÇéÐÎÏÂÐéÄâ´òӡδÔÚWorkstationÉÏÆôÓ㬣¬£¬£¬£¬£¬µ«ÔÚHorizon ClientÉÏÆôÓᣡ£¡£ ¡£¸ÃÎó²îµÄCVSSµÃ·ÖΪ3.2¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/vmware-patches-privilege-escalation-vulnerability-in-workstation-fusion-horizon/


3.˼¿ÆÐÞ¸´ÆäSD-WAN½â¾ö¼Æ»®ÖеÄ5¸öÎó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


3ÔÂ18ºÅ˼¿ÆÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÆäSD-WAN½â¾ö¼Æ»®ÖеÄÎå¸öÎó²î£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Èý¸öÑÏÖØÎó²î¡£¡£¡£ ¡£ÕâЩÎó²î¶¼ÊÇÓÉÊäÈëÑé֤ȱ·¦ÒýÆðµÄ£¬£¬£¬£¬£¬£¬¿Éµ¼Ö¹¥»÷Õß¶Ôϵͳ¾ÙÐÐδ¾­ÊÚȨµÄ¸ü¸Ä¡¢Ê¹ÓÃrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡¢½«ÌØÈ¨ÌáÉýΪrootµÈ¡£¡£¡£ ¡£Èý¸öÑÏÖØÎó²îΪCVE-2020-3265¡¢CVE-2020-3266¡¢CVE-2020-3264£¬£¬£¬£¬£¬£¬¾­ÓÉÍâµØÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÏòÄ¿µÄϵͳ·¢ËͶñÒâÇëÇóÀ´Ê¹ÓÃÕâЩÎó²î£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄSD-WAN°æ±¾Îª19.2.2֮ǰµÄ°æ±¾¡£¡£¡£ ¡£ÁíÍâÁ½¸öÎó²îΪ´æ´¢ÐÍXSS£¨CVE-2019-16010£©ºÍSQL×¢ÈëÎó²î£¨CVE-2019-16012£©¡£¡£¡£ ¡£¸Ã¹«Ë¾Ã»Óз¢Ã÷ÕâЩÎó²îÔÚÒ°ÍⱻʹÓᣡ£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/99954/security/cisco-sd-wan-product-flaws.html


4.ºÚ¿ÍÒÔйڲ¡¶¾ÎªÓÕ¶ü½¨ÉèÊýǧ¸ö¶ñÒâÍøÕ¾


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ƾ֤Check PointµÄÑо¿£¬£¬£¬£¬£¬£¬ºÚ¿ÍÕýÔÚÆð¾¢Ê¹ÓÃCOVID-19ÒßÇé¾ÙÐжñÒâ»î¶¯£¬£¬£¬£¬£¬£¬°üÀ¨×¢²áÓëCOVID-19Ïà¹ØµÄ¶ñÒâÓòÃû¡¢´òÕÛ³öÊÛ¶ñÒâÈí¼þµÈ¡£¡£¡£ ¡£×Ô1Ô³õÒÔÀ´£¬£¬£¬£¬£¬£¬ÒÑ×¢²áµÄÓëйڲ¡¶¾Ïà¹ØµÄ¶ñÒâÓòÃûÊýÄ¿³ÊÉÏÉýÇ÷ÊÆ¡£¡£¡£ ¡£Ñо¿Ö°Ô±³Æ2ÔÂβÒÔÀ´ÐÂ×¢²áÓòÃûµÄƽ¾ùÊýÄ¿ÏÕЩÊÇǰ¼¸ÖܵÄ10±¶£¬£¬£¬£¬£¬£¬ÆäÖÐ0.8%ÊǶñÒâµÄ£¨93¸öÍøÕ¾£©£¬£¬£¬£¬£¬£¬ÉÐÓÐ19£¥ÊÇ¿ÉÒɵģ¨Áè¼Ý2200¸öÍøÕ¾£©¡£¡£¡£ ¡£ºÚ¿Í×éÖ¯SSHacker»¹Ê¹ÓÃCOVID-19×÷Ϊ´ÙÏú´úÂ룬£¬£¬£¬£¬£¬ÎªÈëÇÖFacebookÕË»§Ìṩ15£¥µÄÕÛ¿Û¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/03/covid-19-coronavirus-hacker-malware.html


5.RiskSenseÐû²¼Ö÷Á÷webºÍÓ¦Óÿò¼ÜÎó²îµÄÆÊÎö±¨¸æ


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ƾ֤RiskSense±¾ÖÜÐû²¼µÄÒ»·Ý±¨¸æ£¬£¬£¬£¬£¬£¬WordPressºÍApache StrutsÊǽüÊ®ÄêÀ´ÔâÊܹ¥»÷×î¶àµÄWebÊÖÒÕ¡£¡£¡£ ¡£¸Ã±¨¸æÑо¿ÁË2010ÄêÖÁ2019ÄêÖ®¼äËùÓÐÅû¶µÄÎó²î£¬£¬£¬£¬£¬£¬ÔÚÒ°Íâ±»ÎäÆ÷»¯ºÍʹÓõÄËùÓÐÇå¾²Îó²îÖÐÔ¼ÓÐ55£¥ÊÇÕë¶ÔWordPressºÍApache StrutsµÄ¡£¡£¡£ ¡£DrupalÄÚÈÝÖÎÀíϵͳÅÅÃûµÚÈý£¬£¬£¬£¬£¬£¬Æä´ÎÊÇRuby on RailsºÍLaravel¡£¡£¡£ ¡£¾Í±à³ÌÓïÑÔ¶øÑÔ£¬£¬£¬£¬£¬£¬PHPºÍJavaÓ¦ÓóÌÐòÖеÄÎó²îÔÚÒÑÍùÊ®ÄêÖб»Ê¹ÓÃ×î¶à£¬£¬£¬£¬£¬£¬×îÉÙµÄÊÇJavaScriptºÍPython£¬£¬£¬£¬£¬£¬µ«RiskSenseÔ¤¼ÆÕâÖÖÇéÐν«ÔÚδÀ´¼¸ÄêÄڸıä¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/wordpress-and-apache-struts-account-for-55-of-all-weaponized-vulnerabilities/


6.TrickBotÐÂÄ£¿£¿£¿éʹÓÃPC±©Á¦ÆÆ½âRDPЧÀÍÆ÷


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


BitdefenderÔÚÒ°Íâ·¢Ã÷TrickBotÒøÐÐľÂíµÄÐÂÄ£¿£¿£¿é£¬£¬£¬£¬£¬£¬¸ÃÄ£¿£¿£¿éʹ¹¥»÷ÕßÄܹ»Ê¹ÓÃÊÜѬȾµÄϵͳÕë¶Ô̻¶ÔÚInternetµÄRDPЧÀÍÆ÷Ìᳫ±©Á¦ÆÆ½â¹¥»÷¡£¡£¡£ ¡£¸ÃÄ£¿£¿£¿éÓÚ1ÔÂ30ÈÕ±»·¢Ã÷£¬£¬£¬£¬£¬£¬ÃûΪ¡°rdpScanDll¡±£¬£¬£¬£¬£¬£¬¾Ý³ÆÈÔÔÚ¿ª·¢ÖС£¡£¡£ ¡£¾ÝÑо¿Ö°Ô±³Æ¸ÃÄ£¿£¿£¿éµ½ÏÖÔÚΪֹÒÑʵÑé¹¥»÷ÃÀ¹úºÍÏã¸ÛµçÐÅ¡¢½ÌÓýºÍ½ðÈÚÁìÓòÆóÒµÖеÄ6013¸öRDPЧÀÍÆ÷¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±Äܹ»Ê¶±ð³öÖÁÉÙ3460¸ö³äµ±C2ЧÀÍÆ÷µÄIPµØµã£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨556¸öרÃÅÓÃÓÚÏÂÔØÐ²å¼þµÄЧÀÍÆ÷ºÍ22¸öͬʱ³äµ±ÕâÁ½¸ö½ÇÉ«µÄIP¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/03/trickbot-malware-rdp-bruteforce.html