΢ÈíÖÒ¸æAdob??e Type Manager¿âÖеÄÁ½¸öRCE 0day£»Lenovo½¨¸´Ô¤×°ÖÃÈí¼þVantageÖеÄÌáȨ·ì϶
°ä²¼¹¦·ò 2020-03-241.΢ÈíÖÒ¸æAdobe Type Manager¿âÖеÄÁ½¸öRCE 0day
΢Èí°ä²¼°²È«²¼¸æ£¬ÖÒ¸æWindows Adobe Type Manager¿âÖеÄÁ½¸öRCE 0day£¬ÕâÁ½¸ö·ì϶ӰÏìÁ˵±Ç°ËùÓÐÊÜÖ§³ÖµÄWindowsºÍWindows Server°æ±¾¡£·ì϶´æÔÚÓÚAdobe Type Manager¿â´¦ÖÃAdobe Type 1 PostScript×ÖÌåÌåʽµÄ·½Ê½ÖУ¬¹¥»÷ÕßÄܹ»Í¨¹ý¶àÖÖ·½Ê½ÀûÓô˷ì϶£¬ÀýÈç˵·þÓû§´ò¿ª¶ñÒâÎĵµ»òÔÚWindowsÔ¤ÀÀ´°¸ñÖв鿴Ëü¡£Î¢ÈíÒѾ·¢ÏÖÀûÓô˷ì϶µÄÓÐÏÞÕë¶ÔÐÔ¹¥»÷¡£½¨ÒéÔÚWindows×ÊÔ´ÖÎÀíÆ÷ÖнûÓá°Ô¤ÀÀ´°¸ñ¡±ºÍ¡°¾ßÌåÐÅÏ¢´°¸ñ¡±£¬ÒÔ¼õÇáÀûÓ÷çÏÕ£¬Áí±íÁ½¸ö»º½â´ëÊ©ÊǽûÓÃWebClient·þÎñºÍ³Á¶¨Ãû¡°ATMFD.DLL¡±¡£
ÔÎÄÁ´½Ó£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200006
2.¼¸ÄÚÑÇÒé»áÑ¡¾Ùǰ»¥ÁªÍøÖжϣ¬ÁªÍøÂʽöΪ12%
ƾ¾ÝNetBlocks»¥ÁªÍø¹Û²âÕ¾µÄÍøÂçÊý¾Ý£¬3ÔÂ20ÈÕ¼¸ÄÚÑǹ²ºÍ¹úµÄ»¥ÁªÍø±»¶Â½Ø£¬¸Ã¹ú¶ÈÔ¶¨ÓÚ3ÔÂ22ÈÕ£¨ÐÇÆÚÈÕ£©½øÐÐÒé»áÑ¡¾ÙºÍÏÜ·¨¹«Í¶¡£¼¼ÊõÖ¸±êÏÔʾ£¬¸Ã¹ú¶ÈËùÓÐ6¸öÍøÂç¾ùÒѹعأ¨Ô̺¬ÖØÒªÔËÓªÉÌOrangeÔÚÄÚ£©£¬»¥ÁªÍøÏνÓˮƽ½öΪƽÈÕµÄ12%£¬·äÎÑÍøÂçºÍ¹ÌÍøÒ²Êܵ½ÀàËÆµÄÓ°Ïì¡£´Ë±í£¬¼¸ÄÚÑÇÓÚ3ÔÂ21ÈÕ£¨ÐÇÆÚÁù£©ÍíÉÏ8:00ÆðÍ·¹Ø±ÕÉ罻ýÌ壬Ô̺¬Twitter¡¢FacebookºÍInstagram¾ù±»¹Ø±Õ£¬WhatApp·þÎñÆ÷Ò²Êܵ½²¿ÃÅÏÞ¶È¡£¹Ø±ÕÒ»Ïò³ÖÐøÁË36¸öÓ×ʱ£¬Ö±µ½3ÔÂ23ÈÕ£¨ÐÇÆÚÒ»£©ÉÏÎç8:00²Å½â½û¡£
ÔÎÄÁ´½Ó£º
https://netblocks.org/reports/internet-cut-across-guinea-ahead-of-elections-xAGoQxAz
3.Ameren SiouxºÍLabadieµç³§µÄ¹©¸øÉÌÔâÀÕË÷Èí¼þ¹¥»÷
ÃÀ¹úÃÜËÕÀïÖÝAmeren SiouxºÍLabadieµç³§µÄÉ豸¹©¸øÉÌ£¨LTI Power Systems£©ÔâÀÕË÷Èí¼þ¹¥»÷£¬²¿ÃÅÊý¾ÝÎļþ±»ÇÔ¡£ÕâЩÎļþÔ̺¬Á½¼Òµç³§µÄÉ豸ͼºÍʾÒâͼ£¬ÀýÈç²»¼ä¶ÏµçÔ´É豸µÄ¾ßÌåµÀÀíͼ£¬¸ÃÉ豸ÓÃÓÚÔÚÖÐ¶ÏÆÚ¼äÌṩһʱ±¸ÓõçÔ´¡£Ê¥Â·Ò×˹¹«¹²¹ã²¥µç̨³ÆÕâЩÊý¾ÝÎļþµÄ¹¦·òÔÚ1996ÄêÖÁ2017ÄêÖ®¼ä¡£ÎļþÖÐËÆºõ²»Éæ¼°¿Í»§ÐÅÏ¢¡£»ªÊ¢¶Ù´óÑ§ÍøÂ簲ȫսÊõ´òËãµÄÕÆ¹ÜÈËÇÇ¡¤ÉáÀÕ£¨Joe Scherrer£©°µÊ¾£¬¸Ã¹¥»÷µÄÖ÷ÕÅÖØÒªÊÇΪÁËÇÔȡ֪ʶ²úȨ¡£Ameren½²»°È˰µÊ¾¸Ã¹«Ë¾ÔÚ¶Ô´ËÊÂÎñ½øÐе÷²é£¬²¢²¹³ä³ÆÃ»ÓÐÀíÓÉÒÔΪй¶µÄÊý¾ÝÉæ¼°»úÃÜ»ò¶ÔÆäÔËÓªÖÁ¹Ø³ÁÒª¡£
ÔÎÄÁ´½Ó£º
https://news.stlpublicradio.org/post/ameren-missouri-equipment-supplier-targeted-ransomware-attack#stream/0
4.ÑÀÂò¼Ó¹ú¶ÈÒøÐÐÔâÀÕË÷Èí¼þ¹¥»÷£¬²¿ÃÅ·þÎñÖжÏ
ÑÀÂò¼Ó¹ú¶ÈÒøÐÐÔâÀÕË÷Èí¼þ¹¥»÷£¬¾¯·½ÔÚ½øÐе÷²é¡£¸ÃÒøÐаµÊ¾¹¥»÷²úÉúÔÚ3ÔÂ14ÈÕÐÇÆÚÁù£¬¶ÔÆä·þÎñÔì³ÉÁËһЩÖжϣ¬µ«ÓÉÓÚÕË»§ÊÇÓɵ¥¶ÀµÄϵͳ±£ÁôºÍ±£»¤µÄ£¬Òò¶øÃ»Óпͻ§ÕÊ»§Êܵ½Ó°Ïì¡£ÆäÐÅÏ¢¼¼ÊõºÍÍøÂ簲ȫÍŶӵ±¼´²ÉÈ¡Ðж¯¶ôÔìÁ˶ñÒâÈí¼þ£¬²¢ÊÔͼȷ¶¨¹¥»÷Ô´¡£Ä¿Ç°Æä·þÎñ¸ù»ùÉÏÒѸ´ÔÔÚÏߣ¬µ«¸ÃÒøÐÐÈ·ÈϹ¥»÷ÕßÇÔÈ¡Á˲¿ÃÅ»áÔ±ºÍ¿Í»§µÄÊý¾Ý£¬¸ÃÒøÐÐÔÚ²ÉÈ¡´ëʩ֪ͨÊܲ¨¼°µÄÓû§¡£ÓÉÓÚ¾¯·½µ÷²é»¹ÔÚ½øÐÐÖУ¬¸ÃÒøÐÐûÓÐй©¸ü¶àÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
http://www.jamaicaobserver.com/latestnews/Police_investigate_ransomware_attack_at_Jamaica_National
5.¹¥»÷ÕßÀûÓÃEnigmaSparkÕë¶ÔÖж«£¬ÓëµØÔµÕþÖÎÓйØ
IBM X-ForceÍŶӷ¢ÏÖ·Ö·¢EnigmaSparkºóÃŵÄй¥»÷»î¶¯£¬¸Ã»î¶¯¿ÉÄܳöÓÚÕþÖζ¯»ú£¬ËƺõÓë·ñ¾ö×î½üµÄÖж«ºÍƽ´òËãÓйء£¹¥»÷ÕßÊÔͼ¶Ô×¼¶ÔÖж«ºÍƽ´òËãÓгÁ´óÐËÖ»òÌṩ֧³ÖµÄ×éÖ¯/»ú¹¹µÄÍøÂç»·¾³£¬Í¨¹ý¾«ÐÄÔì×÷µÄ¡¢¾ßÌåµÄ¡¢ÓµÓÐÕþÖÎÖ¸¿ØµÄµö¶üÎļþ£¬ÉøÈëÊÕ¼þÈ˵Ļ·¾³²¢½øÐÐÊý¾ÝÇÔÈ¡µÈ¶ñÒâ»î¶¯¡£EnigmaSparkµÄµö¶üÎĵµÓëÒÔǰ·Ö·¢JhoneRATµÄµö¶üÎĵµÓµÓÐÆëȫһÑùµÄ±àÒëÈÕÆÚ/¹¦·ò£¨2020-01-14 07:54:00£©£¬²¢ÇÒÔÚTTP¡¢Õë¶ÔÐÔÉ϶¼ÓµÓÐÀàËÆÖ®´¦£¬Òò¶øEnigmaSpark»î¶¯¿ÉÄÜÓëJhoneRATÓйأ¬²¢ÇÒ¶¼¿ÉÄÜÊôÓÚ·¸×ïÍÅ»ïMolerats¡£
ÔÎÄÁ´½Ó£º
https://securityintelligence.com/posts/EnigmaSpark-Politically-Themed-Cyber-Activity-Highlights-Regional-Opposition-to-Middle-East-Peace-Plan/
6.Lenovo½¨¸´Ô¤×°ÖÃÈí¼þVantageÖеÄÌáȨ·ì϶
Lenovo½¨¸´ÆäPCԤװÖÃÈí¼þVantageÖеÄÁ½¸öÌáȨ·ì϶£¨CVE-2020-8319ºÍCVE-2020-8324£©¡£Vantage×Ô2016Äê×óÓÒ°ä²¼ÒÔÀ´£¬È¡´úÁËLenovo Solutions Center£¨LSC£©³ÉΪLenovoÉ豸µÄÍÆ¼öƽ̨ÖÎÀíºÍϵͳ¸üй¤¾ß¡£VantageÒÀÀµÓÚϵͳ½Ó¿Ú»ù´¡·þÎñ£¬¸Ã·þÎñͨ¹ý¸´ÔӵIJå¼þϵͳִÐи÷ÀàåÚÏëÌØ¶¨µÄÐÐΪ¡£ÓÉÓÚûÓжԲå¼þ×ÔÉí¼ÓÔØµÄDLLÖ´ÐÐÖ¤Êé²é³£¬Òò¶øÄܹ»Í¨¹ý´úÌæTouchScreenContronlDLL.dll»ñµÃSYSTEMȨÏÞ¡£½¨ÒéÓû§½«Vantage¸üÐÂÖÁ×îа汾¡£
ÔÎÄÁ´½Ó£º
https://www.pentestpartners.com/security-blog/privesc-in-lenovo-vantage-two-minutes-later/


¾©¹«Íø°²±¸11010802024551ºÅ