×êÑÐÈËÔ±Åû¶Áí±íÁ½¸öWindows 0day¼°PoC£»¹È¸èG Suite·ì϶£¬²¿ÃÅÃÜÂëÃ÷ÎÄ´æ´¢³¤´ïÊ®ËÄÄê

°ä²¼¹¦·ò 2019-05-23
1¡¢×êÑÐÈËÔ±Åû¶Áí±íÁ½¸öWindows 0day¼°PoC

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ǰһÌìSandboxEscaperÅû¶ÁËWindows 10´òË㹤×÷ÖеÄLPE 0dayºó£¬¸Ã×êÑÐÈËÔ±ÓÖ°ä²¼ÁËÁí±íÁ½¸öWindows 0dayµÄPoC¡£µÚÒ»¸ö0dayÊÇWindowsÃýÎó»ã±¨·þÎñÖеķì϶£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷Õß»ñµÃͨ³£ÎÞ·¨±à×ëµÄÎļþµÄȨÏÞ£¬¼´±¾µØÌØÈ¨Éý¼¶·ì϶¡£×êÑÐÈËÔ±³Æ¸Ã·ì϶¿Éͨ¹ý¶ñÒâµÄDACL²Ù×÷À´ÀûÓ㬵«¿ÉÄܱØÒªÆÆ·Ñ15·ÖÖӵŦ·ò£¬¸Ã·ì϶±»¶¨ÃûΪAngryPolarBearBug2¡£µÚ¶þ¸ö0dayÊÇIE 11Öеķì϶£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷ÕßÔÚIEÖÐ×¢Èë¶ñÒâ´úÂë¡£ÕâÒѾ­ÊÇSandboxEscaper°ä²¼µÄµÚÁùºÍµÚÆß¸öWindows 0day£¬×êÑÐÈËÔ±³Ô¼µ³ÆÔÚ½«À´¼¸ÌìÄÚ»¹½«°ä²¼Áí±íÁ½¸ö0day¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/two-more-microsoft-zero-days-uploaded-on-github/


2¡¢¹È¸èG Suite·ì϶£¬²¿ÃÅÃÜÂëÃ÷ÎÄ´æ´¢³¤´ïÊ®ËÄÄê

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
¾ÝÃÀý±¨Â·£¬¹È¸èÈ·ÈÏÖÁÉÙ×Ô2005ÄêÒÔÀ´Ò»ÏòÒâ±í´æ´¢Á˲¿ÃÅG SuiteÆóÒµÓû§µÄÃ÷ÎÄÃÜÂë¡£¹È¸èûÓÐй©ÊÜÓ°ÏìµÄ¿Í»§ÊýÁ¿£¬²¢°µÊ¾ÔÚ³ÁÖÿÉÄÜÊÜÓ°ÏìµÄÃÜÂë¡£¹È¸è³ÆÉϸöÔÂËü·¢ÏÖ2005 ÄêÌṩ¸øÆóÒµÓû§µÄÃÜÂëÉèÖú͸´Ô­²½ÖèÊÇÃýÎóµÄ£¬²»ÕýÈ·µØÖü´æÁËÃ÷ÎÄÃÜÂ롣ƾ¾Ý¹È¸è¹¤³Ì¸±×ܲÃSuzanne FreyµÄ˵·¨£¬Ã»ÓÐÓ×ÎÒÏû·ÑÕßµÄGmailÕ˺ÅÊÜÓ°Ï죬¹È¸èÒÑÈ·ÈÏûÓÐÈκÎÖ¤¾ÝÅú×¢ÕâЩÃÜÂë±»²»µ±½Ó¼û»òÀÄÓùý¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/google-stored-unhashed-passwords-due-to-an-implementation-error-8e054e4b


3¡¢Intel°ä²¼°²È«¸üУ¬½¨¸´¶à¸ö²úÆ·ÖеÄ34¸ö·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
Intel°ä²¼34¸ö·ì϶½¨¸´²¹¶¡£¬ÆäÖÐÔ̺¬IntelÈںϰ²È«ºÍÖÎÀíÒýÇæ£¨CSME£©ÖеÄÑϳÁÌáȨ·ì϶¡£¸Ã·ì϶£¨CVE-2019-0153£©µÄCVSSÆÀ·ÖΪ9·Ö£¬ÊÇÒ»¸ö»º³åÇøÒç¶Âí½Å£¬Ó°ÏìCSME°æ±¾12µ½12.0.34£¬Æ¾¾ÝIntelµÄ´«µÝ£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÀûÓô˷ì϶½øÐÐÌáȨ¡£³ý´ËÖ®±í£¬Intel»¹½¨¸´ÁËi915ͼÐÎоƬµÄÄÚºËģʽÇý¶¯·¨Ê½ÖеÄÊäÈëÑéÖ¤²»µ±·ì϶£¨CVE-2019-11085£¬¸Ã·ì϶µÄCVSSÆÀ·ÖΪ8.8·Ö£©ºÍNUCÌ×¼þÖеĿɵ¼ÖÂÌáȨ¡¢DoS»òÐÅϢй¶µÄ·ì϶£¨CVE-2019-11094£¬CVSS 7.5·Ö£©¡£¸ü¶à·ì϶ÐÅÏ¢Çë²Î¿¼ÒÔÏÂÁ´½Ó¡£

Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/intel-fixes-critical-high-severity-flaws-across-several-products/144940/


4¡¢¶íº¥¶íÖÝ¿¼ÎÄ´¹¸ßÖÐϰȾTrickbot£¬Ñ§Ìñ»ÆÈÍ£¿Î

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
¶íº¥¶íÖÝ¿¼ÎÄ´¹Ñ§ÇøµÄ¸ßÖÐϰȾ¶ñÒâÈí¼þTrickbot£¬µ¼ÖÂѧÌñ»ÆÈÍ£¿Î¡£ÕâÒ»ÊÂÎñ²úÉúÔÚ5ÔÂ17ÈÕ£¬¸ÃѧÌõĵ绰ºÍHVACϵͳ¾ùÊÜϰȾ£¬ÎªÁË´Ó¶ñÒâÈí¼þ¹¥»÷Öи´Ô­£¬¸ÃѧÌóÁ×°ÁË1000¶àÌ¨ÍÆËã»ú¡£ÔÚ·¢ÏÖ¹¥»÷ºó£¬Ñ§ÌùÙÔ±ÏòFBI´«µÝÁ˶ñÒâÈí¼þ¹¥»÷ÊÂÎñ£¬FBIÔÚЭÖúÑ§Çø½øÐи´Ô­¹¤×÷¡£¸ÃѧÌÃÒÑÓÚÖܶþ¸´Ô­Õý³£ÔËÓª¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/ohio-school-sends-students-home-because-of-trickbot-malware-infection/


5¡¢ÀÕË÷Èí¼þSatanбäÌ壬Ôö³¤3¸ö·ì϶ÀûÓýøÐд«²¼

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ƾ¾ÝFortinetµÄÒ»·Ý»ã±¨£¬ÀÕË÷Èí¼þSatanµÄбäÖÖѡȡÁËIPµØÖ·±éÀúºÍ¶àÏ̼߳¼Êõ½øÐд«²¼£¬²¢ÇÒÔö³¤ÁËÈý¸öеķì϶ÀûÓôúÂ룬Ô̺¬Spring Data REST·ì϶£¨CVE-2017-8046£©¡¢ElasticSearch·ì϶£¨CVE-2015-1427£©ºÍThinkPHP 5.XÔ¶³ÌÖ´ÐдúÂë·ì϶£¨Î´·ÖÅäCVE£©¡£´Ë±í£¬¸Ã±äÌ廹¿ÉÀûÓÃÒÔÏ·ì϶£ºJBossĬÈÏÅäÖ÷ì϶£¨CVE-2010-0738£©¡¢TomcatËÁÒâÎļþÉÏ´«·ì϶£¨CVE-2017-12615£©¡¢WebLogicËÁÒâÎļþÉÏ´«·ì϶£¨CVE-2018-2894£©¡¢WebLogic WLS×é¼þ·ì϶£¨CVE-2017-10271£©¡¢Windows SMBÔ¶³ÌÖ´ÐдúÂë·ì϶£¨MS17-010£©¡¢Spring Data CommonsÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-1273£©¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/satan-ransomware-evolves-to-add-three-new-exploits-to-its-source-code-7afe57cc


6¡¢Emsisoft°ä²¼ÀÕË÷Èí¼þJSWorm 2.0µÄ½âÃܹ¤¾ß

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
Emsisoft°ä²¼ÀÕË÷Èí¼þJSWorm 2.0µÄ½âÃܹ¤¾ß£¬¿ÉÔ®ÊÖÊܺ¦ÕßÃâ·Ñ½âÃÜÎļþ¡£Ä¿Ç°Éв»Ã÷ÏÔJSWorm 2.0µÄ·Ö·¢õè¾¶£¬µ«ÆäÊܺ¦ÕßÒÑÔÚÄÏ·Ç¡¢Òâ´óÀû¡¢·¨¹ú¡¢ÍÁ¶úÆä¡¢ÒÁÀÊ¡¢Ô½ÄÏ¡¢µÂ¹ú¡¢°ÍÎ÷¡¢°¢¸ùÍ¢ºÍÃÀ¹ú·¢ÏÖ¡£Ò»µ©Ï°È¾£¬JSWorm 2.0»á¼ÓÃÜϵͳÉϵÄÎļþ²¢¸½¼Ó.JSWORM»ò.JURASIKÀ©´óÃû¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/jsworm-20-ransomware-decryptor-gets-your-files-back-for-free/