ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ35ÖÜ
Ðû²¼Ê±¼ä 2021-08-30>±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2021Äê08ÔÂ23ÈÕÖÁ08ÔÂ29ÈÕ¹²ÊÕ¼Çå¾²Îó²î60¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇFlatCore-CMS upload addon²å¼þ´úÂëÖ´ÐЩ£»NASCENT RemKon Device Manager assets/index.phpí§Òâ´úÂëÉÏ´«Îó²î£»Teamviewer TVSÆÊÎöÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î£»RaspAP raspap-webguiÌØȨÌáÉýÎó²î£»SolarWinds Web Help Desk referrerαÔì»á¼ûÏÞÖÆÈƹýÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇмÓÆ·¿µØ²ú¹«Ë¾OrangeTeeÔâµ½ALTDOSµÄÀÕË÷¹¥»÷£»HuntressÔÚ1900̨Exchange¼ì²âµ½140¶àÖÖWeb shell£»Razer SynapseÖеÄÍâµØÌáȨ0dayÓ°ÏìÁè¼Ý1ÒÚÓû§£»SAM·¢Ã÷MiraiʹÓÃRealtek SDKÖÐÎó²îµÄ¹¥»÷Ô˶¯£»OpenSSLÐû²¼Çå¾²¸üУ¬ÐÞ¸´²úÆ·ÖеÄ2¸öÇå¾²Îó²î¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
>Ö÷ÒªÇå¾²Îó²îÁбí
1.Google chrome V8 CVE-2021-30598ÀàÐÍ»ìÏý´úÂëÖ´ÐÐÎó²î
FlatCore-CMS upload addon²å¼þ±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://github.com/flatCore/flatCore-CMS/issues/52
2.NASCENT RemKon Device Manager assets/index.phpí§Òâ´úÂëÉÏ´«Îó²î
NASCENT RemKon Device Manager assets/index.phpͼÏñÉÏ´«¹¦Ð§±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÉÏ´«í§ÒâÎļþ²¢ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://www.blacklanternsecurity.com/2021-08-23-Nascent-RemKon-CVEs/
3.Teamviewer TVSÆÊÎöÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î
Teamviewer TVSÆÊÎö±£´æÄÚ´æÆÆËðÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-1003/
4.RaspAP raspap-webguiÌØȨÌáÉýÎó²î
RaspAP raspap-webgui±£´æ²»Çå¾²µÄsudoersȨÏÞÎó²î£¬ÔÊÐíÍâµØ¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬻ñµÃROOTȨÏÞ¡£
https://github.com/RaspAP/raspap-webgui/blob/fabc48c7daae4013b9888f266332e510b196a062/installers/raspap.sudoers
5.SolarWinds Web Help Desk referrerαÔì»á¼ûÏÞÖÆÈƹýÎó²î
SolarWinds Web Help Desk referrerαÔì±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÈƹýÏÞÖÆδÊÚȨ»á¼û¡£
https://www.solarwinds.com/trust-center/security-advisories/cve-2021-32076
>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢Ð¼ÓÆ·¿µØ²ú¹«Ë¾OrangeTeeÔâµ½ALTDOSµÄÀÕË÷¹¥»÷
8ÔÂ6ÈÕ£¬Ð¼ÓÆ·¿µØ²ú¹«Ë¾OrangeTee GroupÔÚÆä¹ÙÍøÉÏÐû²¼ÉùÃ÷³ÆÆäÔâµ½Á˹¥»÷¡£8ÔÂ12ÈÕ£¬ºÚ¿ÍÍÅ»ïALTDOSÉù³ÆËüÃÇ×Ô2021Äê6ÔÂÒÔÀ´£¬Ò»Ö±ÔÚÇÔÈ¡¸Ã¹«Ë¾µÄÊý¾Ý£¬ÏÖÒÑ»ñµÃÁËÀ´×ÔACSystem¡¢NewOrangeTee¡¢OT_Analytics¡¢OT_LeaveºÍProjInfoListingµÄ969¸öÊý¾Ý¿â¡£Í¬ÈÕ£¬OrangeTee¹«Ë¾ÌåÏÖÆä²»»áÖ§¸¶Êê½ð¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/singapore-real-estate-firm-breached-by-altdos/
2¡¢HuntressÔÚ1900̨Exchange¼ì²âµ½140¶àÖÖWeb shell
ÉÏÖÜÎ壬Çå¾²¹«Ë¾Huntress Labs³Æ½ü2000̨Microsoft ExchangeÓʼþ·þÎñÆ÷ÔÚÒÑÍù¼¸ÌìÄÚÔâµ½ºÚ¿Í¹¥»÷¡£ProxyShellÊÇ3¸öÎó²îCVE-2021-34473¡¢CVE-2021-34523ºÍCVE-2021-31207µÄͳ³Æ¡£Ñо¿Ö°Ô±ÌåÏÖ£¬ÔÚProxyShell¿´·¨ÑéÖ¤´úÂëÐû²¼ºó²»¾Ã·ºÆðÁËÏà¹ØɨÃèÔ˶¯£¬Ö±µ½ÉÏÖÜÄ©Äð³ÉÁËÏÖʵ¹¥»÷¡£±ðµÄ£¬Òѱ»ÈëÇÖµÄ1900¶ą̀Exchange·þÎñÆ÷Éæ¼°µ½µÄ×éÖ¯°üÀ¨ÐÞ½¨ÖÆÔìÉÌ¡¢º£Ïʼӹ¤³§¡¢¹¤Òµ»úе¹«Ë¾¡¢Æû³µÎ¬ÐÞµêºÍСÐÍ»ú³¡µÈ¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/almost-2000-exchange-servers-hacked-using-proxyshell-exploit/
3¡¢Razer SynapseÖеÄÍâµØÌáȨ0dayÓ°ÏìÁè¼Ý1ÒÚÓû§
Ñо¿Ö°Ô±jonhatÓÚ2021Äê8ÔÂ21ÈÕÔÚTwitterÉÏÅû¶ÁËRazer SynapseÖеÄÍâµØÌáȨ0dayµÄϸ½Ú¡£RazerÊÇÒ»¼ÒÅÌËã»úÍâÉèÖÆÔìÉÌ£¬Éù³ÆÆäRazer SynapseÒѱ»È«ÇòÁè¼Ý1ÒÚÓû§Ê¹Óá£ÕâÊÇÒ»¸öÍâµØÌáȨ£¨LPE£©Îó²î£¬½«Razer×°±¸²åÈëWindows 10ʱ£¬ÏµÍ³»á×Ô¶¯ÏÂÔز¢×°ÖÃÇý¶¯³ÌÐòºÍRazer Synapse£¬ÓÉÓÚRazerInstaller.exeÊÇͨ¹ýSYSTEMȨÏÞµÄWindowsÀú³ÌÆô¶¯µÄ£¬Òò´ËÆäÒ²»ñµÃÁËSYSTEMȨÏÞ¡£Ö®ºóÔÚÑ¡Ôñ×°ÖÃÎļþ¼Ðʱ£¬°´ÏÂShift²¢ÓÒ¼üµ¥»÷¶Ô»°¿ò£¬¾Í¿ÉÒÔ·¿ªSYSTEMȨÏÞµÄPowerShell´°¿Ú¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/razer-bug-lets-you-become-a-windows-10-admin-by-plugging-in-a-mouse/
4¡¢SAM·¢Ã÷MiraiʹÓÃRealtek SDKÖÐÎó²îµÄ¹¥»÷Ô˶¯
Çå¾²¹«Ë¾SAM SeamlessÓÚ8ÔÂ19ÈÕ³ÆÆä·¢Ã÷Á˽©Ê¬ÍøÂçMiraiʹÓÃRealtek SDKÖÐÎó²îµÄ¹¥»÷Ô˶¯¡£¸ÃÎó²îΪÉí·ÝÑéÖ¤ÈƹýÎó²î£¬×·×ÙΪCVE-2021-20090£¬ÆÀ·ÖΪ9.8·Ö£¬RealtekÒÑÓÚ8ÔÂ13ÈÕÐû²¼¸ÃÎó²îµÄ²¹¶¡³ÌÐò¡£SAMÌåÏÖ£¬ËûÃÇÓÚ8ÔÂ18ÈÕÔÚÒ°·¢Ã÷ÁË´Ë´ÎÎó²îʹÓÃÔ˶¯£¬¹¥»÷Ô´ÓÚ31.210.20[.]100£¬µ«¹¥»÷ÕßµÄIPµØµã¿ÉÄÜ»áËæ×Åʱ¼ä¶ø¸Ä±ä¡£
ÔÎÄÁ´½Ó£º
https://securingsam.com/realtek-vulnerabilities-weaponized/
5¡¢OpenSSLÐû²¼Çå¾²¸üУ¬ÐÞ¸´²úÆ·ÖеÄ2¸öÇå¾²Îó²î
OpenSSLÓÚ8ÔÂ24ÈÕÐû²¼Çå¾²¸üУ¬ÐÞ¸´Æä²úÆ·ÖеÄ2¸öÇå¾²Îó²î¡£ÆäÖÐ×îΪÑÏÖصÄÊÇ»º³åÇøÒç³öÎó²î£¬×·×ÙΪCVE-2021-3711£¬¹¥»÷ÕßʹÓÃÆä¿Éµ¼ÖÂÓ¦ÓóÌÐòÍ߽⡣¸ÃÎó²îÓëSM2¼ÓÃÜÊý¾ÝµÄ½âÃÜÀú³ÌÏà¹Ø£¬¿ÉÓÃÀ´¸ü¸Ä¶ÑÖеÄÊý¾Ý£¨¼´Æ¾Ö¤£©¡£´Ë´ÎÐÞ¸´µÄÁíÒ»¸öÎó²î×·×ÙΪCVE-2021-3712£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î´¥·¢¾Ü¾ø·þÎñ(DoS)£¬»¹¿ÉÄܵ¼ÖÂÉñÃØÐÅϢй¶£¬ÀýÈç˽Կ»òÃô¸ÐÃ÷ÎÄ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/121426/hacking/cve-2021-3711-openssl-flaws.html