ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ16ÖÜ

°ä²¼¹¦·ò 2020-04-20

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê04ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼°²È«·ì϶72¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Chrome speech recognizer´úÂëÖ´Ðзì϶; VeeamOne Agent PerformHandshake´úÂëÖ´Ðзì϶£»Apache Heron·´ÐòÁл¯´úÂëÖ´Ðзì϶£»Cisco UCS Director ApplianceStorageUtil unzipĿ¼±éÀú´úÂëÖ´Ðзì϶£»Triangle MicroWorks SCADA Data Gateway DNP3 GET_FILE_INFOÕ»Òç¶Âí½Å¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǰͻù˹̹1.15ÒÚÒÆ¶¯Óû§Êý¾ÝÔÚ°µÍøÏúÊÛ£»µ¤ÂóË®±ÃÔì×÷ÉÌDESMIÔâÍøÂç¹¥»÷ £¬ÏµÍ³ÈÔδ¸´Ô­£»Oracle°ä²¼4Ô³ÁÒª²¹¶¡¸üР£¬½¨¸´397¸ö·ì϶£»Ó¢Ìضû°ä²¼4Ô°²È«¸üР£¬½¨¸´¶à¿î²úÆ·ÖеÄ9¸ö·ì϶£»EA SportsÔâ´ó¹æÄ£DDoS¹¥»÷ £¬È«Çò·þÎñÖжÏ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾Öܰ²È«ÍþвΪÖС£


>³ÁÒª°²È«·ì϶Áбí


1. Google Chrome speech recognizer´úÂëÖ´Ðзì϶


Google Chrome speech recognizer´æÔÚ¿ªÊͺóʹÓ÷ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£

https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_15.html


2. Veeam One Agent PerformHandshake´úÂëÖ´Ðзì϶


Veeam One Agent PerformHandshake²½Öè´æÔÚ·´ÐòÁл¯·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-545/


3. Apache Heron·´ÐòÁл¯´úÂëÖ´Ðзì϶


Apache Heron´æÔÚ·´ÐòÁл¯·ì϶ £¬ÔÊÐíͨ¹ýÑéÖ¤µÄÖÎÀíÔ±Óû§ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://lists.apache.org/thread.html/r16dd39f4180e4443ef4ca774a3a5a3d7ac69f91812c183ed2a99e959%40%3Cdev.heron.apache.org%3E


4. Cisco UCS Director ApplianceStorageUtil unzipĿ¼±éÀú´úÂëÖ´Ðзì϶


Cisco UCS Director ApplianceStorageUtil unzip´¦ÖÃÎļþ²Ù×÷´æÔÚĿ¼±éÀú·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬Äܹ»rootÕË»§¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-539/


5. Triangle MicroWorks SCADA Data Gateway DNP3 GET_FILE_INFOÕ»Òç¶Âí½Å


Triangle MicroWorks SCADA Data Gateway´¦ÖÃDNP3 GET_FILE_INFO´æÔÚÕ»Òç¶Âí½Å £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-547


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢°Í»ù˹̹1.15ÒÚÒÆ¶¯Óû§Êý¾ÝÔÚ°µÍøÏúÊÛ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°Í»ù˹̹°²È«³§ÉÌRewterz·¢ÏÖ £¬Ä¿Ç°ÓÐ1.15ÒÚ°Í»ùË¹Ì¹ÒÆ¶¯Óû§µÄÊý¾ÝÔÚ°µÍøÂÛ̳ÏúÊÛ £¬¼ÛֵΪ300 BTC£¨Ô¼ºÏ210ÍòÃÀÔª£©¡£ÕâЩÊý¾ÝÔ̺¬Óû§µÄ¾ßÌåÓ×ÎÒÐÅÏ¢ £¬ÀýÈçÐÕÃû¡¢ÆëÈ«µØÖ·¡¢ÊÖ»úºÅÂëÒÔ¼°NICºÅºÍ˰ÎñºÅÂë¡£RewterzÍþвµý±¨×¨¼ÒÒÔΪÕâЩÊý¾Ý¿ÉÄÜÊÇÒ»´Î»òÂÅ´Îй¶µÄÁ˾Ö £¬Ä¿Ç°»¹²»Ã÷ÏÔÊÇ·ñÓÐÈκÎÌØ¶¨µÄµçÐÅÔËÓªÉÌ»òÊÇËùÓеçÐÅÔËÓªÉ̳ÉΪÕâ´Î¹¥»÷µÄÊܺ¦Õß¡£¸Ãй¶Êý¾ÝµÄ¹æÄ£Òý·¢Á˶ԵçÐŹ«Ë¾Êý¾Ý°²È«ÐÔºÍÒþÖÔÐÔµÄÓÇÓô¡£


Ô­ÎÄÁ´½Ó£º

http://www.rewterz.com/articles/115-million-pakistani-mobile-users-data-go-on-sale-on-dark-web


2¡¢µ¤ÂóË®±ÃÔì×÷ÉÌDESMIÔâÍøÂç¹¥»÷ £¬ÏµÍ³ÈÔδ¸´Ô­


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µ¤ÂóË®±ÃÔì×÷ÉÌDESMIÔâµ½ÍøÂç¹¥»÷ £¬¸Ã¹¥»÷ÊÂÎñ²úÉúÔÚÉÏÖÜËĵÄÍíÉÏ £¬Ôâµ½¹¥»÷ºó¹«Ë¾µÄËùÓÐϵͳ¾ù±»¹Ø¹Ø¡£Æ¾¾Ý¸Ã¹«Ë¾ÔÚ¹ÙÍøÉϰ䲼µÄÖÒ¸æ £¬¹«Ë¾µÄËùÓÐϵͳ¾ù±»¹Ø¹Ø £¬²¢ÇÒÔÚ»¹Ô­¹ý³ÌÖÐ £¬Ê×Åú²¿ÃÅϵͳ½«ÔÚ¼¸ÌìÄÚÆô¶¯²¢ÔËÐÐ £¬ÆäÓàµÄϵͳ½«ÔÚ¼¸ÖÜÖ®ÄÚÔËÐС£Ä¿Ç°µ÷²éÈÔÔÚ½øÐÐÖ®ÖÐ £¬Éв»Ã÷ÏÔ¹¥»÷µÄˮƽ £¬DESMIÒѽ«ÊÂÎñ»ã±¨¸øµ¤Â󵱾ֺ;¯Ô±¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/101495/hacking/desmi-discloses-cyber-attack.html


3¡¢Oracle°ä²¼4Ô³ÁÒª²¹¶¡¸üР£¬½¨¸´397¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


OracleÔÚÆä4Ô³ÁÒª²¹¶¡¸üÐÂÖн¨¸´ÁË397¸ö·ì϶ £¬ÆäÖÐOracle Database Server²úÆ·Öн¨¸´ÁË8¸ö·ì϶£»µç×ÓÉÌÎñÌ×¼þÖн¨¸´ÁË74¸ö·ì϶ £¬Ô̺¬70¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓõķì϶£»OracleÈÚºÏÖÐÑë¼þÖн¨¸´ÁË51¸ö·ì϶ £¬ÆäÖÐ44¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓã»Java SEÖн¨¸´ÁË15¸ö·ì϶ £¬ËùÓзì϶¾ùÄܹ»ÔÚ²»½øÐÐÉí·ÝÑéÖ¤µÄÇé¿öϽøÐÐÔ¶³ÌÀûÓã»MySQLÖн¨¸´ÁË45¸ö·ì϶ £¬ÆäÖÐ9¸ö·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔϹٷ½Á´½Ó £¬½¨ÒéÓû§¾¡¿ìÀûÓøüС£


Ô­ÎÄÁ´½Ó£º

https://www.oracle.com/security-alerts/cpuapr2020.html


4¡¢Ó¢Ìضû°ä²¼4Ô°²È«¸üР£¬½¨¸´¶à¿î²úÆ·ÖеÄ9¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢ÌØ¶ûÔÚ4Ô²¹¶¡¸üÐÂÖн¨¸´ÁË9¸ö·ì϶ £¬ÕâЩ·ì϶¾ùΪÖиßΣ·ì϶ £¬Ó°Ïì¶à¸öÈí¼þ¡¢¹Ì¼þ¼°Æ½Ì¨¡£Ó¢Ìضû½¨¸´ÁËPROSet/ÎÞÏßWiFi²úÆ·ÔÚWindows 10ÉϵÄÁ½¸ö·ì϶-¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÉÓÚ²»°²È«µÄ¼Ì³ÐȨÏÞ¶ø¿ÉÄÜͨ¹ý±¾µØ½Ó¼û½øÐÐÌØÈ¨Éý¼¶£¨CVE-2020-0557£©£»ÓÉÓÚÄÚºËÇý¶¯·¨Ê½ÖеĻº³åÇøÏ޶Ȳ»µ± £¬ÎÞÌØÈ¨µÄ¹¥»÷Õß¿ÉÄÜͨ¹ýÏàÁÚÍøÂç½Ó¼ûÀ´µ¼Ö»ؾø·þÎñ£¨CVE-2020-0558£©¡£Ó¢Ìضû»¹½¨¸´ÁËNUC mini PCµÄϵͳ¹Ì¼þÖкÍÄ£¿é»¯·þÎñÆ÷MFS2600KISPPÍÆËãÄ£¿éÖеÄÁ½¸ö·ì϶ £¬Ô̺¬²»ÕýÈ·µÄ»º³åÇøÏ޶ȵ¼ÖµÄLPE·ì϶£¨CVE-2020-0600£©ºÍǰÌá²é³­²»µ±µ¼ÖµÄÌáȨ·ì϶£¨CVE-2020-0578£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/intel-april-platform-update-fixes-high-severity-security-issues/


5¡¢EA SportsÔâ´ó¹æÄ£DDoS¹¥»÷ £¬È«Çò·þÎñÖжÏ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÓÎÏ·¹«Ë¾EA SportsÓÖÒ»´ÎÔâµ½´ó¹æÄ£µÄDDoS¹¥»÷ £¬µ¼Ö¸ù«Ë¾µÄ·þÎñÆ÷ÔÚÈ«ÇòÁìÓòÄÚÍÑ»ú¡£Õâ´Î¹¥»÷²úÉúÔÚ4ÔÂ14ÈÕÏÂÎç4:19¡£Æ¾¾ÝDown DetectorµÄʵʱµØÍ¼ £¬Õâ´Î¹¥»÷ÖØÒªÓ°ÏìÁËÅ·ÖÞµØÓòµÄ¿Í»§ £¬µ«¼ÓÄô󡢰£¼°¡¢ÄϷǵȵصĿͻ§Ò²Êܵ½ÁË»ò¶à»òÉÙµÄÓ°Ïì¡£4ÔÂ15ÈÕÁ賿1µã25·Ö £¬EA SportsÈϿɸù«Ë¾¡°¾­ÀúÁËһϵÁÐDDoS¹¥»÷¡±¡£ÔÚ°ä²¼±¾ÎÄʱ £¬EA SportsµÄ¿Í»§ÈÔÔÚ±§Ô¹·þÎñå´»ú £¬ÕâÅú×¢¸Ã¹«Ë¾ÈÔÔÚÔâ·ê¹¥»÷¡£ÖµÍ×ÌùÐĵÄÊÇ £¬±©Ñ©Ò²ÔÚ4ÔÂ14ÈÕÁ賿4µã15·Ö×óÓÒÔ⵽һϵÁÐDDoS¹¥»÷ £¬µ¼ÖÂÈ«Çò·þÎñÖжÏ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/ea-sports-down-gaming-giant-hit-by-ddos-attacks/