¹È¸èÅû¶WindowsÖдæÔÚ20ÄêµÄ·ì϶£¬Ó°ÏìËùÓÐϵͳ°æ±¾£»À¶ÑÀ·ì϶KNOB£¬¿ÉÆÆ½âÃÜÔ¿ºÍ´Û¸ÄÊý¾Ý
°ä²¼¹¦·ò 2019-08-15
΢ÈíÔÚ8Ô·ݵÄWindows°²È«¸üÐÂÖн¨¸´ÁË94¸ö·ì϶£¬ÆäÖÐÔ̺¬4¸öеÄRDPÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-1181¡¢CVE-2019-1182¡¢CVE-2019-1222¡¢CVE-2019-1226£©¡£ÆäÖÐCVE-2019-1181ºÍCVE-2019-1182Óë5ÔÂ·ÝÆØ³öµÄBlueKeep·ì϶£¨CVE-2019-0708£©ÀàËÆ£¬¿ÉʵÏÖÈ䳿»¯¹¥»÷£¬ÊÜÓ°ÏìµÄϵͳ°æ±¾Ô̺¬win 7 SP1¡¢win 8.1¡¢win 10ÒÔ¼°windows server 2008 R2 SP1¡¢2012¡¢2012 R2¡¢2016¼°2019µÈ¡£XP¡¢windows server 2003¼°2008²»ÊÜÓ°Ï졣ĿǰÉÐδ·¢ÏÖÕâЩ·ì϶ÔÚÒ°±í±»ÀûÓ㬵«Î¢ÈíÇ¿ÁÒ½¨ÒéÓû§¾¡¿ì¸üн¨¸´²¹¶¡¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/microsoft-fixes-critical-windows-10-wormable-remote-desktop-flaws/
2¡¢Intel°ä²¼NUC¹Ì¼þ¸üУ¬½¨¸´¶à¸ö·ì϶
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/intel-updates-nuc-firmware-to-patch-high-severity-bug/
3¡¢HTTP/2ÆØ³ö8¸öзì϶£¬¿ÉÓÃÓÚÌáÒéDoS¹¥»÷
×êÑÐÈËÔ±Åû¶HTTP/2ºÍ̸ʵÏÖÖеÄ8¸öзì϶£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶Ïò佨²¹µÄ·þÎñÆ÷ÌáÒ黨¾ø·þÎñ¹¥»÷¡£ÕâЩ·ì϶£¨CVE-2019-9511~CVE-2019-9518£©ÊÇÓÉNetflix×êÑÐÔ±Jonathan LooneyÒÔ¼°Google×êÑÐÔ±Piotr Sikora·¢Ïֵģ¬¿ÉÓÃÓÚ´¥·¢·þÎñÆ÷µÄ×ÊÔ´ºÄ¾¡£¬µ«²»ÄÜÓÃÓÚÈëÇÖ·þÎñÆ÷¡£Æ¾¾ÝCERT°ä²¼µÄ²¼¸æ£¬ÊÜÓ°ÏìµÄ³§ÉÌÔ̺¬NGINX¡¢Apache¡¢H2O¡¢Nghttp2¡¢Microsoft(IIS)¡¢Cloudflare¡¢Akamai¡¢Apple(SwiftNIO)¡¢Amazon¡¢Facebook(Proxygen)¡¢Node.jsÒÔ¼°Envoy proxy£¬´óÎÞÊý³§É̶¼ÒѾ°ä²¼Á˽¨¸´²¹¶¡¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/http2-dos-vulnerability.html
4¡¢ÐÂÀ¶ÑÀ·ì϶KNOB£¬¿ÉÆÆ½âÃÜÔ¿ºÍ´Û¸ÄÊý¾Ý
×êÑÐÈËÔ±Åû¶À¶ÑÀÖеÄзì϶£¨CVE-2019-9506£©£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷Õß±©Á¦ÆÆ½âÅä¶ÔÉ豸ÔÚ´«ÊäÊý¾ÝʱʹÓõÄÃÜÔ¿²¢´Û¸ÄÊý¾Ý¡£¸Ã·ì϶ӰÏìÁ˰汾ÔÚ1.0ÖÁ5.1Ö®¼äµÄBluetooth BR/EDRÉ豸¡£Æ¾¾Ý×êÑÐÈËÔ±µÄ±íÊö£¬¹¥»÷Õß¿É×ÌÈÅÁ½Ì¨Åä¶ÔÉ豸ÉèÖüÓÃÜÏνӵĹý³Ì£¬Ï÷¼õʹÓõÄÃÜÔ¿µÄ³¤¶È£¬Ê¹µÃÃÜÔ¿µÄ°²È«ÐÔÖè¼õ¡£¼«¶ËÇé¿öÏ£¬ÃÜÔ¿³¤¶È¿ÉÄܱ»Ï÷¼õΪ1¸ö×Ö½Ú¡£ÎªÁË»º½â¸Ã·ì϶£¬À¶ÑÀ¼¼ÊõͬÃ˸üÐÂÁËÀ¶ÑÀÖ÷Ìâ¹æ·¶£¬½¨Òé×îÓ×ÃÜÔ¿³¤¶ÈΪ7¸ö×Ö½Ú¡£Î¢ÈíÒ²ÔÚ·ì϶£¨CVE-2019-9506£©µÄ²¹¶¡Öн«Ä¬ÈÏ×îÓ×ÃÜÔ¿³¤¶ÈÉèÖÃΪ7¸ö×Ö½Ú¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-bluetooth-knob-flaw-lets-attackers-manipulate-traffic/
5¡¢¹È¸èÅû¶WindowsÖдæÔÚ20ÄêµÄ·ì϶£¬Ó°ÏìËùÓÐϵͳ°æ±¾
¹È¸è×êÑÐÈËÔ±Tavis OrmandyÅû¶WindowsϵͳÖдæÔÚ³¤´ï20ÄêµÄÒ»¸ö佨¸´·ì϶¡£¸Ã·ì϶ӰÏìÁËWindows XPÒÔÀ´µÄËùÓÐWindows°æ±¾£¬Ô̺¬Win 10¡£¸Ã·ì϶´æÔÚÓÚ΢ÈíµÄÎı¾·þÎñ¿ò¼Ü£¨MSCTF£©ÖУ¬ÓëMSCTF¿Í»§¶ËºÍ·þÎñÆ÷Ö®¼äµÄͨѶ¶Ìȱ½Ó¼û½ÚÔì/Éí·ÝÑéÖ¤»úÔìÓйأ¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶Ïνӵ½CTF»á»°¡¢¶ÁдÆäËü´°¿Ú/»á»°µÄÄÚÈÝ¡¢Î±ÔìÏß³ÌID/¹ý³ÌID/HWND¡¢¼Ù×°³ÉCTF·þÎñÆ÷¡¢½øÐÐɳÏäÌÓÒÝÒÔ¼°ÌáȨ¡£¹¥»÷Õß»¹Äܹ»ÈƹýÓû§½Ó¿ÚȨÏÞ¸ôÀ루UIPI£©£¬»ñÈ¡SYSTEMȨÏÞÒÔ¼°½ÚÔìUAC¶Ô»°¿òµÈ¡£×êÑÐÈËÔ±»¹°ä²¼ÁËÔÚWin 10ÖлñÈ¡SYSTEMµÄPoCÊÓÆµ¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/ctfmon-windows-vulnerabilities.html
6¡¢BioStar 2ÉúÎï¼ø±ðÊý¾Ý¿âй¶£¬²¨¼°Êý°ÙÍòÓû§
ÔÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/millions-of-records-exposed/


¾©¹«Íø°²±¸11010802024551ºÅ