ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ46ÖÜ

Ðû²¼Ê±¼ä 2021-11-15
>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼Çå¾²Îó²î58¸ö£¬ £¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe RoboHelp ServerĿ¼±éÀú´úÂëÖ´ÐÐÎó²î£»£»£»ServiceTonic Helpdesk softwareδÊÚȨ»á¼ûÎó²î£»£»£»Microsoft Windows Active Directory CVE-2021-42278ȨÏÞÌáÉýÎó²î£»£»£»Microsoft Windows Remote Desktop Client´úÂëÖ´ÐÐÎó²î£»£»£»Siemens SIMATIC PCS 7Ŀ¼±éÀúÎó²î ¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÑо¿Ö°Ô±·¢Ã÷ð³äÇå¾²¹«Ë¾ProofpointµÄ´¹Âڻ£»£»£»Í³³ÆÎªNUCLEUS:13µÄ¶à¸öÎó²îÓ°ÏìÎ÷ÃÅ×ÓRTOS£»£»£»BusyBoxÖÐ14¸öÐÂÎó²îÓ°ÏìÊý°ÙÍò»ùÓÚUnixµÄ×°±¸£»£»£»Î¢ÈíÐû²¼11Ô¸üУ¬ £¬£¬ÐÞ¸´6¸ö0dayÔÚÄÚµÄ55¸öÎó²î£»£»£»ESET·¢Ã÷LazarusʹÓõÁ°æµÄIDA Pro·Ö·¢¶ñÒâÈí¼þ ¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬ £¬£¬±¾ÖÜÇå¾²ÍþвΪÖÐ ¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Adobe RoboHelp ServerĿ¼±éÀú´úÂëÖ´ÐÐÎó²î


Adobe RoboHelp Server±£´æÄ¿Â¼±éÀúÎó²î£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë ¡£¡£


https://www.zerodayinitiative.com/advisories/ZDI-21-1305/


2. ServiceTonic Helpdesk softwareδÊÚȨ»á¼ûÎó²î


ServiceTonic Helpdesk software±£´æÊÚȨ»úÖÆÎó²î£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬¿É²»Ê¹ÓÃÃÜÂëδÊÚȨ»á¼ûϵͳ ¡£¡£


https://www.srlabs.de/bites/chaining-three-zero-day-exploits-in-itsm-software-servicetonic-for-remote-code-execution


3. Microsoft Windows Active Directory CVE-2021-42278ȨÏÞÌáÉýÎó²î


Microsoft Windows Active Directory±£´æÇå¾²Îó²î£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬¿ÉÒÔÌáÉýÌØÈ¨ ¡£¡£


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42278


4. Microsoft Windows Remote Desktop Client´úÂëÖ´ÐÐÎó²î


Microsoft Windows Remote Desktop Client±£´æÎ´Ã÷Çå¾²Îó²î£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬¿ÉÒÔϵͳÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë ¡£¡£


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38666


5. Siemens SIMATIC PCS 7Ŀ¼±éÀúÎó²î


Siemens SIMATIC PCS 7±£´æÄ¿Â¼±éÀúÎó²î£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë ¡£¡£


https://cert-portal.siemens.com/productcert/pdf/ssa-840188.pdf


>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Ñо¿Ö°Ô±·¢Ã÷ð³äÇå¾²¹«Ë¾ProofpointµÄ´¹Âڻ


ArmorbloxµÄÑо¿ÍŶÓÓÚ11ÔÂ4ÈÕÅû¶ÁËð³äÍøÂçÇå¾²¹«Ë¾ProofpointµÄ´¹Âڻ ¡£¡£ÕâЩ´¹ÂÚÓʼþµÄÖ÷ÌâΪ¡°Re£ºPayoff Request¡±£¬ £¬£¬Éù³Æ°üÀ¨Ò»·Ýͨ¹ýProofpoint·¢Ë͵ĵäÖÊ´û¿îÏà¹ØÎļþ£¬ £¬£¬Ö¼ÔÚÇÔȡĿµÄµÄMicrosoft Office 365ºÍGoogle Gmailƾ֤ ¡£¡£¸ÃÓʼþÊÇ´Ó±»µÁµÄСÎÒ˽¼ÒÕÊ»§·¢Ë͵ģ¬ £¬£¬·¢¼þÈ˵ÄÓòÃûÓòΪ¡°sdis34[.]fr¡±£¬ £¬£¬ÕâÊÇ·¨¹úÄϲ¿µÄÒ»¸öÏû·À¾ÈÔ®²¿·Ö£¬ £¬£¬¶ø´¹ÂÚÒ³ÃæÍйÜÔÚgreenleafproperties[.]co[.]ukÓò ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.armorblox.com/blog/proofpoint-credential-phishing/


2¡¢Í³³ÆÎªNUCLEUS:13µÄ¶à¸öÎó²îÓ°ÏìÎ÷ÃÅ×ÓRTOS


ForescoutºÍMedigateµÄÑо¿Ö°Ô±ÔÚ11ÔÂ9ÈÕÅû¶ÁËNucleusÖÐ13¸öÎó²îµÄϸ½Ú ¡£¡£NucleusÊÇÎ÷ÃÅ×ÓµÄʵʱ²Ù×÷ϵͳ(RTOS)£¬ £¬£¬Í¨³£ÔËÐÐÔÚÒ½ÁÆ×°±¸¡¢Æû³µ¡¢ÖÇÄÜÊÖ»ú¡¢ÎïÁªÍø×°±¸¡¢¹¤ÒµplcµÈ×°±¸µÄƬÉÏϵͳ(SoC) ¡£¡£ÕâЩÎó²îͳ³ÆÎªNUCLEUS:13£¬ £¬£¬Ó°ÏìÁËNucleus TCP/IP¿ÍÕ» ¡£¡£ÆäÖУ¬ £¬£¬×îÑÏÖØµÄÊÇÓ°ÏìÁËFTPЧÀÍÆ÷×é¼þµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-31886£©£¬ £¬£¬CVSSÆÀ·ÖΪ9.8£¬ £¬£¬ÊÇÓÉÓÚ¶ÔUSERÏÂÁ¶ÈµÄÑéÖ¤²»×¼È·µ¼Ö嵀 ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/nucleus13-vulnerabilities-impact-siemens-medical-industrial-equipment/


3¡¢BusyBoxÖÐ14¸öÐÂÎó²îÓ°ÏìÊý°ÙÍò»ùÓÚUnixµÄ×°±¸


Èí¼þ¿ª·¢¹«Ë¾JFrogºÍÇå¾²¹«Ë¾ClarotyÔÚ11ÔÂ9ÈÕÁªºÏÅû¶ÁËBusyBoxÖÐ14¸öÎó²îµÄϸ½Ú ¡£¡£BusyBox±»³ÆÎªÇ¶ÈëʽLinuxµÄ¡°ÈðÊ¿¾üµ¶¡±£¬ £¬£¬¿É½«ÖÖÖÖ³£¼ûµÄUnixÓ¦ÓûòС³ÌÐò£¨ÀýÈçcp¡¢ls¡¢grep£©×éºÏ³ÉÒ»¸ö¿ÉÖ´ÐÐÎļþ ¡£¡£ÕâЩÎó²î±£´æÓÚBusyBox 1.16µ½1.33.1µÄ¶à¸ö°æ±¾£¬ £¬£¬Ó°ÏìÁËÊý°ÙÍò»ùÓÚUnixµÄ×°±¸ ¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇawkÖеÄDoSÎó²îCVE-2021-42383¡¢CVE-2021-42384ºÍCVE-2021-42385µÈ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/124429/hacking/busybox-vulnerabilities.html


4¡¢Î¢ÈíÐû²¼11Ô¸üУ¬ £¬£¬ÐÞ¸´6¸ö0dayÔÚÄÚµÄ55¸öÎó²î


΢ÈíÔÚ11ÔÂ9ÈÕÐû²¼Á˱¾ÔµÄÖܶþ²¹¶ ¡£¡£¬ £¬£¬×ܼÆÐÞ¸´ÁË55¸öÎó²î ¡£¡£´Ë´ÎÐÞ¸´ÁË6¸ö0 day£¬ £¬£¬°üÀ¨ExcelÖÐÇå¾²¹¦Ð§ÈƹýÎó²î£¨CVE-2021-42292£©¡¢Exchange ServerÖÐRCE£¨CVE-2021-42321£©£¬ £¬£¬RDPÖÐÐÅϢй¶Îó²î£¨CVE-2021-38631ºÍCVE-2021-41371£©£¬ £¬£¬ÒÔ¼°3DÖÐÉó²éÆ÷RCE£¨CVE-2021-43208ºÍCVE-2021-43209£© ¡£¡£ÆäÖУ¬ £¬£¬CVE-2021-42292ºÍCVE-2021-42321Òѱ»ÓÃÓÚ¶ñÒâ¹¥»÷»î¶¯ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-november-2021-patch-tuesday-fixes-6-zero-days-55-flaws/


5¡¢ESET·¢Ã÷LazarusʹÓõÁ°æµÄIDA Pro·Ö·¢¶ñÒâÈí¼þ


ESETÍŶÓÓÚ11ÔÂ10ÈÕ·¢Ã÷³¯ÏʺڿÍÍÅ»ïLazarusʹÓõÁ°æIDA Pro¹¥»÷Çå¾²Ñо¿Ö°Ô±µÄ»î¶¯ ¡£¡£Ñо¿Ö°Ô±Í¨³£Ê¹ÓÃÄæÏò¹¤³ÌÓ¦ÓÃIDA ProÀ´ÆÊÎöÎó²îºÍ¶ñÒâÈí¼þ£¬ £¬£¬¶ø´Ë´Î·¢Ã÷µÄIDA Pro 7.5°æ±¾°üÀ¨ÁËÁ½¸öÃûΪidahelp.dllºÍwin_fw.dllµÄ¶ñÒâDLL ¡£¡£ÆäÖУ¬ £¬£¬win_fw.dll½«ÔÚWindowsʹÃüµ÷Àí³ÌÐòÖн¨ÉèÒ»¸öÐÂʹÃü£¬ £¬£¬¸ÃʹÃü½«Æô¶¯idahelper.dll£¬ £¬£¬È»ºóidahelper.dll½«ÅþÁ¬µ½devguardmap[.]orgÍøÕ¾²¢ÏÂÔØÔ¶³Ì»á¼ûľÂíNukeSpedµÄpayload ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/lazarus-hackers-target-researchers-with-trojanized-ida-pro/