ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ41ÖÜ

°ä²¼¹¦·ò 2018-10-15

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2018Äê10ÔÂ08ÈÕÖÁ14ÈÕ¹²ÊÕ¼°²È«·ì϶58¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Win32k CVE-2018-8497ȨÏÞÌáÉý·ì϶£»Microsoft Azure IoT SDKÔ¶³ÌÖ´ÐдúÂë·ì϶£»D-Link Central WiFi Manager CVE-2018-17442ËÁÒâ´úÂëÖ´Ðзì϶£»Auto-Maskin DCU-210E/RP-210EδÊÚȨ½Ó¼û·ì϶£»Foxit Reader/PhantomPDF JavaScriptÒýÇæ¶à¸ö¿ªÊͺóÀûÓôúÂëÖ´Ðзì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇNorth American Risk Services¹«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬²¿Ãſͻ§µÄÐÅϢй¶£»ÉæÏÓÒþÂ÷50ÍòÓû§Êý¾Ýй¶£¬¹È¸è½«¹Ø¹ØÉç½»ÍøÂçGoogle+£»½ðÑÅÍØµÄ»ã±¨Åú×¢2018ÉϰëÄêÈ«Çò¹²²úÉú945ÆðÊý¾Ýй¶ÊÂÎñ£»¿¨°Í˹»ù°ä²¼¹ØÓÚWindows 0day(CVE-2018-8453)µÄ¸ü¶à¼¼Êõϸ½Ú£»×êÑÐÍŶӷ¢ÏÖNotPetyaºÍIndustroyerÓë·¸×ïÍÅ»ïTeleBots´æÔÚ¹ØÁª¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£




¶þ¡¢³ÁÒª°²È«·ì϶Áбí


1. Microsoft Windows Win32k CVE-2018-8497ȨÏÞÌáÉý·ì϶
Microsoft Windows Win32kÄں˴¦ÖôæÔÚ°²È«·ì϶£¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÌáÉýȨÏÞ¡£
https://portal.msrc.microsoft.com/zh-cn/security-guidance/advisory/CVE-2018-8497


2. Microsoft Azure IoT SDKÔ¶³ÌÖ´ÐдúÂë·ì϶
Microsoft Azure IoT SDKʹÓÃMQTTºÍ̸´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://portal.msrc.microsoft.com/zh-cn/security-guidance/advisory/CVE-2018-8531


3. D-Link Central WiFi Manager CVE-2018-17442ËÁÒâ´úÂëÖ´Ðзì϶
D-Link Central WiFi Manager´¦ÖÃÎļþÉÏ´«´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄRARÎļþ£¬²¢ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://securityadvisories.dlink.com/announcement/publication.aspx?name=SAP10092


4. Auto-Maskin DCU-210E/RP-210EδÊÚȨ½Ó¼û·ì϶
Auto-Maskin DCU-210EºÍRP-210EʹÓÃroot/amrootÓ²±àÂ룬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Î´ÊÚȨ½Ó¼û£¬²¢Åú¸Ä¹Ì¼þÖеÄËÁÒâ¶þ½øÔìÎļþ»òÅäÖÃÎļþ¡£
https://www.kb.cert.org/vuls/id/176301


5. Foxit Reader/PhantomPDF JavaScriptÒýÇæ¶à¸ö¿ªÊͺóÀûÓôúÂëÖ´Ðзì϶
Foxit Reader/PhantomPDF JavaScriptÒýÇæ´¦ÖÃPDFÎļþ´æÔÚ¿ªÊͺóÀûÓ÷ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄPDFÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://www.foxitsoftware.com/support/security-bulletins.php




Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢North American Risk Services¹«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬²¿Ãſͻ§µÄÐÅϢй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±±ÃÀ·çÏÕ·þÎñ¹«Ë¾£¨NARS£©ÔÚ2ÔÂ7ÈÕÖÁ3ÔÂ27ÈÕÆÚ¼äÔâµ½ºÚ¿ÍÈëÇÖ£¬Î´¾­ÊÚȨµÄ¹¥»÷Õß½Ó¼ûÁ˹«Ë¾µÄ²¿Ãŵç×ÓÓʼþ£¬Ô¼610Ãû¿Í»§µÄÓ×ÎÒÐÅϢй¶¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢Éç±£ºÅÂë¡¢¼ÝÕÕID¡¢ÒøÐÐÕË»§ÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢¡¢½¡È«±£ÏÕÐÅÏ¢¡¢ÄÉ˰È˼ø±ðºÅÒÔ¼°Óû§Ãû/ÃÜÂëµÈ¡£ÊÜÓ°ÏìµÄ¿Í»§¶¼Î»ÓÚ¼ÓÖÝ£¬¸Ã¹«Ë¾ÔÚÏòÕâЩ¿Í»§·¢ËÍÓйØÍ¨Öª¡£


Ô­ÎÄÁ´½Ó£º
https://news.softpedia.com/news/hundreds-of-california-residents-affected-by-north-american-risk-services-breach-523086.shtml


2¡¢ÉæÏÓÒþÂ÷50ÍòÓû§Êý¾Ýй¶£¬¹È¸è½«¹Ø¹ØÉç½»ÍøÂçGoogle+

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾Ý¹È¸èµÄ»ã±¨£¬Google+µÄPeople APIÖдæÔÚÒ»¸ö°²È«·ì϶£¬¿ÉÔÊÐíµÚÈý·½¿ª·¢Õß½Ó¼û³¬¹ý50ÍòÓû§µÄÊý¾Ý£¬Ô̺¬Óû§Ãû¡¢µç×ÓÓʼþµØÖ·¡¢Ö°Òµ¡¢µ®ÉúÈÕÆÚ¡¢Ó×ÎÒ×ÊÁÏÕÕÆ¬ÒÔ¼°ÐÔ±ðµÈÐÅÏ¢¡£¹È¸èÔÚ2018Äê3Ô·¢ÏÖ²¢½¨¸´Á˸÷ì϶£¬µ«¸Ã¹«Ë¾Ñ¡Ôñ²»Ïò¹«¼ÒÅû¶´ËÊÂÎñ¡£³ýÁËÈϿɴËÊý¾Ýй¶ÊÂÎñÖ®±í£¬¹È¸è»¹°ä·¢½«¹Ø¹ØGoogle+¡£


Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2018/10/google-plus-shutdown.html


3¡¢½ðÑÅÍØµÄ»ã±¨Åú×¢2018ÉϰëÄêÈ«Çò¹²²úÉú945ÆðÊý¾Ýй¶ÊÂÎñ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾Ý½ðÑÅÍØµÄ×îÐÂ×êÑУ¬2018ÉϰëÄêÈ«Çò¹²²úÉú945ÆðÊý¾Ýй¶ÊÂÎñ£¬¹²ÓÐ45ÒÚÌõÊý¾Ý¼Í¼Ô⵽й¶¡£Óë2017ÄêͬÆÚÏà±È£¬ÃÔʧ¡¢±»ÇÔÒÔ¼°Ð¹Â¶µÄÊý¾ÝÔö³¤ÁË133%¡£Ö»¹ÜÊý¾Ýй¶ÊÂÎñµÄÊýÁ¿ÂÔÓнµÂ䣬µ«ÊÂÎñµÄÑϳÁ³Ì¶Å×ÐËùÔö³¤¡£ÆäÖÐ6ÆðÉ罻ýÌåÊý¾Ýй¶ÊÂÎñµ¼ÖÂÁ˳¬¹ý56%µÄÊý¾Ýй¶¡£Êý¾Ýй¶µÄ×î³£¼ûÔ­ÒòÊÇ±í²¿³É·Ö£¨Õ¼56%£©¡£


Ô­ÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2018/10/09/data-breaches-2018/


4¡¢¿¨°Í˹»ù°ä²¼¹ØÓÚWindows 0day(CVE-2018-8453)µÄ¸ü¶à¼¼Êõϸ½Ú


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù³¢ÊÔÊÒÓÚ2018Äê8ÔÂ17ÈÕÏò΢Èí»ã±¨ÁËWindows 0day£¨CVE-2018-8453£©£¬¸Ã·ì϶ÒÑÔÚ΢ÈíµÄ10Ô°²È«¸üÐÂÖеõ½½¨¸´¡£¸Ã·ìÏ¶ÖØÒª±»APT×éÖ¯FruityArmorËùʹÓã¬ÓÃÀ´¹¥»÷Öж«µØÓòµÄÖ¸±ê¡£Æä¹¥»÷»î¶¯ÊǸ߶ÈÕë¶ÔÐԵģ¬Êܺ¦ÕßµÄÊýÁ¿²»³¬¹ý12¸ö¡£×êÑÐÍŶÓÄæÏòÁ˲¶»ñµ½µÄ·ì϶ÀûÓÃÑù±¾£¬²¢½«Æä³ÁдΪÆëÈ«µÄPoC¡£


Ô­ÎÄÁ´½Ó£º
https://securelist.com/cve-2018-8453-used-in-targeted-attacks/88151/


5¡¢×êÑÐÍŶӷ¢ÏÖNotPetyaºÍIndustroyerÓë·¸×ïÍÅ»ïTeleBots´æÔÚ¹ØÁª


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ESET×êÑÐÍŶӷ¢ÏÖ¶ñÒâÈí¼þNotPetyaºÍºóÃÅIndustroyerÓë·¸×ïÍÅ»ïTeleBots´æÔÚ¹ØÁª¡£ÕâÁ½¸ö¶ñÒâÈí¼þ¶¼±»ÓÃÓÚ¹¥»÷ÎÚ¿ËÀ¼µÄÖ¸±ê¡£×êÑÐÍŶÓͨ¹ý¶ÈÎöTeleBotsʹÓõÄкóÃÅWin32/ExaramelÈ·ÈÏÁËÕâЩÁªÏµ£¬ÔÚÕâ֮ǰ×êÑÐÍŶÓÖ»Äܲ²âËüÃǵĹØÁª¡£ÐµÄÖ¤¾ÝÅú×¢£¬ExaramelºÍIndustroyerÖ®¼äÓµÓкÜÇ¿µÄ´úÂëÀàËÆÐÔºÍÐÐΪ£¬ÕâÒâζ×ÅËüÃÇÀ´×ÔÓÚͳһ¿ª·¢Õß¡£


Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-backdoor-ties-notpetya-and-industroyer-to-telebots-group/


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù