ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ33ÖÜ

°ä²¼¹¦·ò 2019-08-26

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö



2019Äê8ÔÂ19ÈÕÖÁ25ÈÕ¹²ÊÕ¼°²È«·ì϶46¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇForcepoint Next Generation FirewallÃÜÂëÑéÖ¤ÈÆ¹ý·ì϶£»Aspose Aspose.Cells LabelSst´úÂëÖ´Ðзì϶£»Cisco Small Business 220ϵÁÐÖÇÄÜ»¥»»»úÔ¶³Ì´úÂëÖ´Ðзì϶£»IBM DB2 High Performance UnloadȨÏÞÌáÉý·ì϶£»Google Nest Cam IQ Indoor Weave PASE½âÎöÖ°ÄÜÐÅϢй¶·ì϶ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ΢ÈíÈ·ÈÏWindows10 1903¸üдæÔÚÃýÎó0x80073701£»ÏµÍ³ÖÎÀíÔ±¹¤¾ßWebmin´æÔÚ0day·ì϶¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ»ÃÀ¹úµÂ¿ËÈøË¹ÖÝ23¸öµ±¾Ö»ú¹¹ÔâÀÕË÷Èí¼þ¹¥»÷£»¹È¸è¡¢Mozilla¼°Æ»¹û½ûÓùþÈø¿Ë˹̹µ±¾ÖÐû¸æµÄ¸ùÖ¤Ê飻¿¨°Í˹»ù°ä²¼2019Äê¹¤ÒµÍøÂ簲ȫÇé¿ö»ã±¨ ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖÐ ¡£


> ³ÁÒª°²È«·ì϶Áбí



1. Forcepoint Next Generation FirewallÃÜÂëÑéÖ¤ÈÆ¹ý·ì϶


Forcepoint Next Generation Firewall LDAPÑéÖ¤²½Öè´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÈÆ¹ýÃÜÂëÑéÖ¤£¬½Ó¼ûÊܱ£»¤·þÎñ ¡£
https://support.forcepoint.com/KBArticle?id=000017474

2. Aspose Aspose.Cells LabelSst´úÂëÖ´Ðзì϶


Aspose Cells labelSst record parser´æÔÚÔ½½ç¶Á·ì϶£¬ÔÊÐíδÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄXLSÒªÇó£¬ÓÕʹÓû§½âÎö£¬Äܹ»Óû§¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£
https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0794

3. Cisco Small Business 220ϵÁÐÖÇÄÜ»¥»»»úÔ¶³Ì´úÂëÖ´Ðзì϶


Cisco Small Business 220ϵÁÐÖÇÄÜ»¥»»»ú¶ÁÈ¡Êý¾Ýµ½ÄÚ²¿»º³åÇøÊ±´æÔÚ»º³åÇøÒç³ö¹¥»÷£¬ÔÊÐíδÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ROOTȨÏÞÖ´ÐÐËÁÒâºÅÁî ¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190806-sb220-rce

4. IBM DB2 High Performance UnloadȨÏÞÌáÉý·ì϶


IBM DB2 High Performance Unload´¦ÖÃPATH´æÔÚ°²È«·ì϶£¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ɼÓÔØ¶ñÒâ¹²Ïí¿â£¬ÌáÉýȨÏÞ ¡£
https://www-01.ibm.com/support/docview.wss?uid=ibm10964592

5. Google Nest Cam IQ Indoor Weave PASE½âÎöÖ°ÄÜÐÅϢй¶·ì϶


Google Nest Cam IQ Indoor Weave PASE½âÎöÖ°ÄÜ´æÔÚÐÅϢй¶·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄweave±¨ÎÄÒªÇ󣬿ɽÚÔìÉ豸 ¡£
https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0798


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö



1¡¢Î¢ÈíÈ·ÈÏWindows10 1903¸üдæÔÚÃýÎó0x80073701


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


MicrosoftÒÑÈ·ÈÏËûÃÇÔÚ½¨¸´Óû§ÔÚ×°ÖÃеÄv1903¸üÐÂʱÊÕµ½µÄ0x80073701ÃýÎó ¡£ÔÚ2019Äê8Ô²¹¶¡ÐÇÆÚ¶þ¸üа䲼ºó£¬Óû§ÆðÍ·»ã±¨ËûÃÇÔÚ³¢ÊÔ×°ÖÃWindows 10°æ±¾1903ÀÛ»ý¸üÐÂʱÊÕµ½ÃýÎó ¡£¹ÌÈ»´óÎÞÊýÓû§»ã±¨Åú×¢ÎÊÌâʼÓÚ8ÔÂ13ÈÕ£¬µ«Î¢Èí°µÊ¾£¬ÔÚ°ä²¼2019Äê5ÔÂ29ÈÕKB4497935  ÀÛ»ý¸üÐÂʱ£¬ÎÊÌâÏÖʵÉÏÒѾ­³öÏÖ ¡£Ä¿Ç°Éв»Ã÷ÏÔÈκν«À´µÄ½¨¸´·¨Ê½ÊÇ·ñÒ²½«½âÎöÓû§ÔÚ½Ó¹ÜµÄÆäËûÃýÎó´úÂë ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-windows-10-1903-update-error-0x80073701-working-on-fix/

2¡¢ÏµÍ³ÖÎÀíÔ±¹¤¾ßWebmin´æÔÚ0day·ì϶¿ÉÖÂÔ¶³Ì´úÂëÖ´ÐÐ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ê¢ÐеÄϵͳÖÎÀíÔ±¹¤¾ßWebminÔÚ³ÁÖÃÃÜÂëÖ°ÄÜÖз¢ÏÖÁËÒ»¸öÃýÎ󣬸ÃÃýÎóÔÊÐí¶ñÒâµÚÈý·½ÓÉÓÚ¶ÌȱÊäÈëÑéÖ¤¶øÖ´ÐжñÒâ´úÂë ¡££¬ÒÑÖªÔÚ¶Ë¿Ú10000ÉÏÔËÐУ¬²¢ÇÒÓ°Ïì×îа汾1.920£¬WebminÉÐδ°ä²¼¹«¿ªÉêÃ÷»ò²¹¶¡£¬Ä¿Ç°»¥ÁªÍøÉϹ«¿ªµÄWebminÖÁÉÙ³¬¹ý13Íò¸ö ¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.firosolutions.com/exploits/webmin/

3¡¢ÃÀ¹úµÂ¿ËÈøË¹ÖÝ23¸öµ±¾Ö»ú¹¹ÔâÀÕË÷Èí¼þ¹¥»÷


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÉÏÖÜÎåµÂ¿ËÈøË¹Öݶà´ï23¼ÒʵÌå»ú¹¹-ÆäÖдóÎÞÊýÊÇ´¦Ëùµ±¾Ö-Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µÂ¿ËÈøË¹ÖݹÙÔ±³ÆÕâÊÇÒ»¸öµ¥Ò»¹¥»÷ÕßÌáÒéµÄÕë¶ÔÐÔ¹¥»÷µÄÒ»²¿ÃÅ ¡£½ØÖÁÖÜÁùÍí£¬µÂ¿ËÈøË¹ÖÝÐÅÏ¢×ÊÔ´²¿£¨DIR£©°µÊ¾Ó¦¼±ÏìÓ¦ÍŶÓÕý»ý¼«ÓëËùÓÐ23¸öʵÌåºÏ×÷£¬Ê¹Æäϵͳ³ÁÐÂÉÏÏߣ¬²¢Çҵ¿ËÈøË¹ÖݵÄϵͳºÍÍøÂç²»»áÊܵ½Ó°Ïì ¡£Ä¿Ç°¾ßÌå¹¥»÷ϸ½ÚÒÀÈ»²»¼°£¬DIRҲûÓÐÆÀÂÛÄÄЩϵͳ³öÏÖ¹ÊÕÏ¡¢ÏµÍ³ÈôºÎ±»Ï°È¾ÒÔ¼°¾ßÌåµÄÊê½ðÊý¶î ¡£


Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/coordinated-ransomware-attack-hits-23-texas-government-agencies/147457/

4¡¢¹È¸è¡¢Mozilla¼°Æ»¹û½ûÓùþÈø¿Ë˹̹µ±¾ÖÐû¸æµÄ¸ùÖ¤Êé


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¹È¸è¡¢Mozilla¼°Æ»¹û½ûÓùþÈø¿Ë˹̹µ±¾ÖÓÚÉϸöÔÂÐû¸æµÄ¸ùÖ¤Ê飬¸ÃÖ¤ÊéÓÃÓÚ¼à¿Ø¹«ÃñµÄÉÏÍøÁ÷Á¿ ¡£Æäʱ¹þÈø¿Ë˹̹µ±¾ÖÒªÇó¸Ã¹úISPºÏ×÷£¬Ç¿ÔìÔÚËùÓÐÍøÂçÓû§ÖÐ×°ÖøøùÖ¤Êé ¡£´Ë¿Ìµ±Chrome¡¢Firefox¼°Safari¼ì²âµ½¸Ã¸ùÖ¤Êéʱ£¬½«×èÖ¹ÏνӲ¢ÏÔʾÃýÎóÐÅÏ¢ ¡£¹þÈø¿Ë˹̹µ±¾ÖÒѾ­ÔÚ8Ô³õÖÕ³¡ÁËÕâÒ»´òË㣬һÃû¹ÙÔ±°µÊ¾Õû¸ö´òËãÖ»Êǵ±¾ÖµÄÒ»¸ö²âÊÔ ¡£µ«ÈÔº±¼û°ÙÍòÉ豸ÈÔÔÚʹÓøÃÖ¤Êé ¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/kazakhstan-root-certificate.html

5¡¢¿¨°Í˹»ù°ä²¼2019Äê¹¤ÒµÍøÂ簲ȫÇé¿ö»ã±¨


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¿¨°Í˹»ù¶Ô282¼ÒÔËÐÐOT/ICSϵͳµÄÆóÒµ½øÐе÷ÑУ¬Õû¶Ù²¢°ä²¼ÁË¡¶2019Äê¹¤ÒµÍøÂ簲ȫÇé¿ö¡·»ã±¨ ¡£Æ¾¾Ý¸Ã»ã±¨£¬È¥Ä곬¹ýÒ»°ë£¨52%£©µÄ¹¤¿Ø°²È«ÊÂÎñÊÇÓɱ¨´ðʧÎóµ¼ÖµÄ ¡£¹ÌÈ»¾ø´óÎÞÊý¹«Ë¾£¨81£¥£©´òËã½øÐÐÍøÂçÊý×Ö»¯ÔËÓªÒÔÍÆ¶¯¹¤Òµ4.0£¬µ«·ÖÅäÁËÍøÂ簲ȫԤËãµÄÈ´Éٵöࣨ57£¥£© ¡£³ý´ËÖ®±í£¬ÕâЩ¹«Ë¾µÄÍøÂ簲ȫ¼¼ÊõÒÀÈ»ÁîÈËÓÇÓô£ºÊÜ·ÃÕßµÄÁ½´óÓÇÓô¼¯ÖÐÔÚûÓÐ×ã¹»µÄÍøÂ簲ȫר¼ÒÀ´ÖÎÀí¹¤ÒµÍøÂ磬ÒÔ¼°OT/ICS²Ù×÷Ô±ÆÕ±é²»×㰲ȫÒâʶ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://ics.kaspersky.com/the-state-of-industrial-cybersecurity-2019/