ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ38ÖÜ
Ðû²¼Ê±¼ä 2021-09-22>±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2021Äê09ÔÂ13ÈÕÖÁ09ÔÂ19ÈÕ¹²ÊÕ¼Çå¾²Îó²î60¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Premiere Elements CVE-2021-40700»º³åÇøÒç³ö´úÂëÖ´ÐÐÎó²î£»Microsoft Azure Open Management InfrastructureȨÏÞÌáÉýÎó²î£»Google chrome Selection APIÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»Microsoft Scripting Engine CVE-2021-26435»º³åÇøÒç³öÎó²î£»SAP Business OneÎļþÉÏ´«Îó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÀÕË÷¹¥»÷µ¼ÖÂÄϷǶà¸öÕþ¸®²¿·ÖµÄITϵͳÖÐÖ¹£»AppleÐû²¼½ôÆȸüУ¬ÐÞ¸´Áãµã»÷Îó²îForcedEntry£»KasperskyÐû²¼2021ÄêÉÏ°ëÄêICSÍþв̬ÊƵı¨¸æ£»MicrosoftÐû²¼9Ô·ÝÐÇÆÚ¶þ²¹¶¡£¬×ܼÆÐÞ¸´86¸öÎó²î£»¹È¸èÒòÀÄÓð²×¿µÄÊг¡Ö÷µ¼Ö°Î»±»º«¹ú·£¿î2070ÒÚº«Ôª¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
>Ö÷ÒªÇå¾²Îó²îÁбí
1.Adobe Premiere Elements CVE-2021-40700»º³åÇøÒç³ö´úÂëÖ´ÐÐÎó²î
Adobe Premiere Elements´¦Öóͷ£Îļþ±£´æ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿Éʹϵͳ±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://helpx.adobe.com/security/products/premiere_elements/apsb21-78.html
2.Microsoft Azure Open Management InfrastructureȨÏÞÌáÉýÎó²î
Microsoft Azure Open Management Infrastructure±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÌáÉýȨÏÞ¡£
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-38649
3.Google chrome Selection APIÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Google chrome Selection API±£´æÊͷźóʹÓÃÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿Éʹϵͳ±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop.html
4.Microsoft Scripting Engine CVE-2021-26435»º³åÇøÒç³öÎó²î
Microsoft Scripting Engine±£´æ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26435
5.SAP Business OneÎļþÉÏ´«Îó²î
SAP Business One±£´æí§ÒâÎļþÉÏ´«Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405
>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢ÀÕË÷¹¥»÷µ¼ÖÂÄϷǶà¸öÕþ¸®²¿·ÖµÄITϵͳÖÐÖ¹
9ÔÂ6ÈÕÍíÉϵÄÀÕË÷¹¥»÷Ô˶¯µ¼ÖÂÄϷǶà¸öÕþ¸®²¿·ÖµÄITϵͳÖÐÖ¹£¬°üÀ¨µç×ÓÓʼþϵͳºÍ¹ú¼Ò±£ÊÍ·þÎñµÄϵͳ¡£DOJCD¹ÙÔ±ÔÚÉÏÖÜËÄ£¨9ÔÂ9ÈÕ£©Í¸Â¶£¬¹¥»÷Ô˶¯¼ÓÃÜÁ˸ò¿·ÖËùÓеÄÐÅϢϵͳ£¬Ê¹µÃÄÚ²¿µÄÔ±¹¤ºÍÍⲿµÄ¹«Ãñ¾ùÎÞ·¨Ê¹ÓᣱðµÄ£¬Ë¾·¨²¿¹ÙÔ±ÌåÏÖ£¬ËûÃDz»µÃ²»Æô¶¯ÁËÊÖ¶¯Á÷³ÌÀ´Î¬³Ö·¨Í¥µÄÕý³£Ô˶¯£¬µ«²¢Î´Ö¸Ã÷´Ë´Î¹¥»÷±³ºóµÄÀÕË÷ÔËÓªÍŻÉÏÖÜÒ»£¬ÄϷǹú¼Òº½Ìì¾Ö (SANSA)ÔøÅû¶Æäϵͳ±£´æÇå¾²Îó²î£¬µ¼ÖÂѧÉúСÎÒ˽¼ÒÐÅϢй¶¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/bail-services-affected-in-south-africa-after-ransomware-attack/
2¡¢AppleÐû²¼½ôÆȸüУ¬ÐÞ¸´Áãµã»÷Îó²îForcedEntry
Apple¹«Ë¾ÓÚ±¾ÖÜÒ»Ðû²¼½ôÆȸüУ¬ÐÞ¸´iMessagingÖеÄÁãµã»÷Îó²îForcedEntry£¨CVE-2021-30860£©¡£Apple³Æ¸ÃÎó²îΪ´¦Öóͷ£¶ñÒâPDFʱµ¼ÖµÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£Citizen LabÓÚ2021Äê2ÔÂÊ״η¢Ã÷¸ÃÎó²î£¬Ëü¿ÉÓÃÀ´ÈƹýAppleÆäʱÍƳöµÄ±ÜÃâiMessageÁãµã»÷Îó²îµÄɳÏäBlastDoor¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/apple-emergency-fix-nso-zero-click-zero-day/169416/
3¡¢KasperskyÐû²¼2021ÄêÉÏ°ëÄêICSÍþв̬ÊƵı¨¸æ
KasperskyÔÚ9ÔÂ9ÈÕÐû²¼ÁË2021ÄêÉÏ°ëÄêICSÍþв̬ÊƵı¨¸æ¡£±¨¸æÖ¸³ö£¬2021ÄêÉÏ°ëÄêICSÅÌËã»ú±»¹¥»÷µÄÕ¼±ÈΪ8%£¬±È2020ÄêÏ°ëÄê¸ß0.4¸ö°Ù·Öµã¡£ÆäÖУ¬±»¹¥»÷µÄICSÅÌËã»úÕ¼±È×î¶àµÄ¹ú¼ÒΪ°¢¶û¼°ÀûÑÇ£¨58.4%£©£¬Æä´ÎΪĦÂå¸ç£¨52.4%£© ¡¢ÒÁÀ¿Ë£¨50.9%£©ºÍÔ½ÄÏ£¨50.6%£©¡£±ðµÄ£¬»¥ÁªÍø¡¢¿ÉÒƶ¯Ã½ÌåºÍµç×ÓÓʼþÈÔÈ»ÊÇICSÅÌËã»úÍþвµÄÖ÷ҪȪԴ¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/threat-landscape-for-industrial-automation-systems-in-h1-2021/104017/
4¡¢MicrosoftÐû²¼9Ô·ÝÐÇÆÚ¶þ²¹¶¡£¬×ܼÆÐÞ¸´86¸öÎó²î
MicrosoftÓÚ9ÔÂ14ÈÕÐû²¼Á˱¾ÔµÄÐÇÆÚ¶þÇå¾²¸üУ¬×ܼÆÐÞ¸´ÁË86¸öÎó²î¡£´Ë´Î¸üÐÂÐÞ¸´ÁË2¸öÁãÈÕÎó²î£¬°üÀ¨Windows MSHTMLÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-40444£©£¬ÒÑÔÚÒ°Íâ·¢Ã÷ʹÓøÃÎó²îµÄ¹¥»÷Ô˶¯£»ÒÔ¼°Windows DNSÌáȨÎó²î£¨CVE-2021-36968£©¡£±ðµÄ£¬»¹ÐÞ¸´ÁËAzure ¿ª·ÅʽÖÎÀí»ù´¡ÉèÊ©ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-38647£©ºÍWindows¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î£¨CVE-2021-26435£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2021-patch-tuesday-fixes-2-zero-days-60-flaws/
5¡¢¹È¸èÒòÀÄÓð²×¿µÄÊг¡Ö÷µ¼Ö°Î»±»º«¹ú·£¿î2070ÒÚº«Ôª
9ÔÂ14ÈÕ£¬º«¹ú¹«ÕýÉÌҵίԱ»á¶Ô¹È¸è´¦ÒÔ2070ÒÚº«Ôª£¨Ô¼Îª1.77 ÒÚÃÀÔª£©µÄ·£¿î¡£Ôµ¹ÊÔÓÉÊǹȸèÒòÀÄÓð²×¿ÔÚÒƶ¯²Ù×÷ϵͳÊг¡µÄÖ÷µ¼Ö°Î»£¬ÆÈʹÖÇÄÜÊÖ»úÖÆÔìÉÌÖ»ÄÜʹÓÃAndroid²Ù×÷ϵͳ¡£¸Ã»ú¹¹³Æ£¬¹È¸èÒªÇóÖÆÔìÉ̱ØÐèÇ©Êð¡°·´ËéƬ»¯ÐÒ飨AFA£©¡±£¬¸ÃÐÒéեȡʹÓÃAndroid²Ù×÷ϵͳµÄÐ޸İ汾£¬¼´ËùνµÄ¡°Android·ÖÖ§¡±¡£±¨µÀ³Æ£¬¹È¸èµÄ¢¶ÏÐÐΪʹÆäÔÚ2019ÄêÒƶ¯²Ù×÷ϵͳÊг¡µÄ·Ý¶îÉÏÉýµ½ÁË97.7%¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2021/09/14/south_korea_fines_google/