Ñо¿Ö°Ô±·¢Ã÷Win7ºÍServer2008ÖеÄÍâµØÌáȨ0day£»Google³Æ°Ù¶ÈµØÍ¼ºÍ°Ù¶ÈËÑË÷ÍøÂçÓû§Ãô¸ÐÊý¾Ý

Ðû²¼Ê±¼ä 2020-11-26
1.Ñо¿Ö°Ô±·¢Ã÷Win7ºÍServer2008ÖеÄÍâµØÌáȨ0day


1.png


·¨¹úÑо¿Ö°Ô±·¢Ã÷Windows 7ºÍServer 2008±£´æÍâµØÌáȨ£¨LPE£©0day £¬µ±WindowsÇå¾²¹¤¾ß¸üÐÂʱ»áÓ°ÏìÆä²Ù×÷ϵͳ¡£¸ÃÎó²îλÓÚËùÓÐWindows×°ÖÃÖеÄRPC¶ËµãÓ³ÉäÆ÷ºÍDNSCache·þÎñµÄÁ½¸ö¹ýʧÉèÖõÄ×¢²á±íÏîÖÐ £¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄÕâЩע²á±íÀ´¼¤»îWindowsÐÔÄܼàÊÓ»úÖÆËùʹÓõÄ×ÓÃÜÔ¿¡£ÏÖÔÚ0patchƽ̨ÒÑÐû²¼ÔÝʱ΢²¹¶¡ £¬²¢ÔÚ΢ÈíÐû²¼Õýʽ²¹¶¡Ç°¶ÔËùÓÐÈËÃâ·ÑÌṩ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/windows-7-and-server-2008-zero-day-bug-gets-a-free-patch/


2.Google³Æ°Ù¶ÈµØÍ¼ºÍ°Ù¶ÈËÑË÷ÍøÂçÓû§Ãô¸ÐÊý¾Ý


2.png


Google·¢Ã÷°Ù¶ÈµÄÁ½¸öAndroidÓ¦ÓðٶȵØÍ¼ºÍ°Ù¶ÈËÑË÷ÔÚÍøÂçÓû§Ãô¸ÐÐÅÏ¢ £¬²¢ÓÚ10Ô½«Æä´ÓPlayÊÐËÁÖÐɾ³ý¡£Çå¾²¹«Ë¾Palo Alto Networks·¢Ã÷ £¬ÕâÁ½¸öÓ¦ÓÿÉÒÔÔÚÓû§²»ÖªÇéµÄÇéÐÎÏÂÍøÂç×°±¸±êʶ·û £¬ÀýÈç¹ú¼ÊÒÆ¶¯¶©»§Éí·Ý£¨IMSI£©ºÅÂë»òMACµØÖ· £¬Õâ¿ÉÄܵ¼ÖÂÓû§±»¸ú×Ù¡£Ö®ºó £¬GoogleÓÚ10ÔÂ28ÈÕÒÔδָ¶¨µÄÇÖȨÐÐΪΪÓɵõÏúÁËÕâЩӦÓᣰٶÈËÑË÷ÒÑÓÚ11ÔÂ19ÈÕ»Ö¸´µ½PlayÊÐËÁ £¬¶ø°Ù¶ÈµØÍ¼ÏÖÔÚÈÔ²»¿ÉÓá£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/11/baidus-android-apps-caught-collecting.html


3.Ñо¿ÍŶӷ¢Ã÷cPanel 2FA¿É±»Èƹý £¬ÏÂÔØÁ¿Áè¼Ý7000Íò


3.jpg


Çå¾²Ö°Ô±·¢Ã÷cPanel±£´æÎó²î £¬¿É±»ÓÃÀ´ÈƹýË«ÖØÉí·ÝÑéÖ¤£¨2FA£©¡£cPanelÊÇÍøÂçÍйܹ«Ë¾ÓÃÀ´ÎªÆä¿Í»§¹ÜÀíÍøÕ¾µÄÈí¼þÌ×¼þ £¬ÏÖÔÚ¹ÜÀí×ÅÁè¼Ý7000Íò¸öÕ¾µã¡£¸ÃÎó²îµÄ±£´æÔ­ÓÉÓÚcPanelÇå¾²Õ½ÂÔ²¢Î´×èÖ¹¹¥»÷ÕßÖØ¸´Ìá½»2FA´úÂë £¬ÕâʹµÃ¹¥»÷Õß¿ÉÒÔʹÓñ©Á¦¹¥»÷ÈÆ¹ý2FAÑéÖ¤¡£ÔÚ½ÏÔçʱ¼ä¹¥»÷ÕßÒ²¿ÉÒÔͨ¹ýÍÆ²âURL²ÎÊý²¢Èƹý2FA £¬µ«Í¨³£ÐèÒªÊýСʱ»òÊýÌì²Å»ªÀÖ³É £¬¶øÔÚÕâÖÖÇéÐÎÏµĹ¥»÷Ö»ÐèÒª¼¸·ÖÖÓ¡£ÏÖÔÚ £¬¸ÃÎó²îÒѱ»ÐÞ¸´¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/2fa-bypass-discovered-in-web-hosting-software-cpanel/


4.Õë¶ÔLinux·þÎñÆ÷µÄÐÂStantinkoαװ³ÉhttpdµÄÀú³Ì


4.jpg


Ñо¿Ö°Ô±·¢Ã÷Á˽©Ê¬ÍøÂçStantinkoµÄбäÖÖ¿ÉÒÔαװ³ÉApache Web·þÎñÆ÷httpdµÄÀú³Ì £¬Ö÷ÒªÕë¶ÔLinux·þÎñÆ÷¡£StantinkoÓÚ2017ÄêÊ״α»·¢Ã÷ £¬°æ±¾ºÅΪ1.2 £¬¶øÏÖÔڵİ汾ºÅΪ2.17 £¬Óë֮ǰ°æÄÚÇé±ÈÓкܴóµÄÌá¸ß¡£Ð°汾Խ·¢¾«¼ò²¢ÇÒ°üÀ¨µÄ¹¦Ð§¸üÉÙ £¬Ñо¿Ö°Ô±ÍƲâ¸ÃÍÅ»ïÊÔͼïÔÌ­¶ñÒâÈí¼þÖ¸ÎÆÒÔ×èÖ¹±»É±¶¾Èí¼þ¼ì²â¡£±ðµÄ £¬Æä»¹ÐÞ¸ÄÁËLinux¶ñÒâÈí¼þʹÓõÄÀú³ÌÃû³Æ £¬¸üÃûΪhttpd £¬ÒÔÈÆ¹ý¼ì²â¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/111393/malware/stantinkos-linux-variant.html


5.ºÚ¿Í¹ûÕæÊÂÎñ¹ÜÀíÓ¦ÓÃPeatixµÄ420Íò¸öÓû§µÄÐÅÏ¢


5.jpg


ºÚ¿Í¹ûÕæÊÂÎñ¹ÜÀíÓ¦ÓÃPeatixÖеÄ420Íò¸öÓû§µÄÐÅÏ¢¡£´Ë´Î×ß©µÄÐÅÏ¢°üÀ¨Óû§ÐÕÃû¡¢Óû§Ãû¡¢µç×ÓÓʼþÒÔ¼°¼ÓÑκ͹þÏ£ÃÜÂë £¬ÆäÖд󲿷ÖÓû§ÎªÑÇÖÞÈË¡£¸Ã¹«Ë¾ÒѾ­È·ÈÏÆäÔâµ½Á˹¥»÷µ¼ÖÂÊý¾Ýй¶ £¬²¢ÒÑ×èÖ¹ÈëÇÖÕßÔٴλá¼ûÆäϵͳ¡£Peatix»¹ÏòÓû§°ü¹Ü £¬ÓÉÓÚËùÓи¶¿î¶¼ÊÇͨ¹ýµÚÈý·½Æ½Ì¨´¦Öóͷ£µÄ £¬Òò´Ë²¢ÎÞ²ÆÎñÏà¹ØÊý¾Ýй¶¡£    


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-leaks-the-user-data-of-event-management-app-peatix/


6.Ó¢¹úNCSC½¨ÒéÏà¹Ø×éÖ¯ÐÞ¸´CVE-2020-15505Îó²î


6.jpg


Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©·¢³ö¾¯±¨ £¬½¨ÒéÏà¹Ø×éÖ¯ÐÞ¸´MobileIronÒÆ¶¯×°±¸¹ÜÀí£¨MDM£©ÏµÍ³ÖеÄCVE-2020-15505Îó²î¡£MDMÊÇÒ»¸öÈí¼þƽ̨ £¬ÔÊÐí¹ÜÀíÔ±Ô¶³Ì¹ÜÀíÆä×éÖ¯ÖеÄÒÆ¶¯×°±¸¡£¸ÃÎó²îΪԶ³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î £¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚMDM·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐÐÏÂÁî²¢ÎÞÐèÉí·ÝÑéÖ¤ £¬MobileIronÒÑÓÚ6ÔÂÐû²¼Á˲¹¶¡³ÌÐò¡£NCSC³Æ £¬ËûÃÇ·¢Ã÷ºÚ¿ÍÍÅ»ïÕýÔÚʹÓøÃÎó²îÀ´ÆÆËðÒ½ÁƱ£½¡ÐÐÒµ¡¢µØ·½Õþ¸®¡¢ÎïÁ÷ºÍÖ´·¨²¿·ÖµÄÍøÂç¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uk-urges-orgs-to-patch-critical-mobileiron-cve-2020-15505-rce-bug/