ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ37ÖÜ
°ä²¼¹¦·ò 2020-09-14> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê09ÔÂ07ÈÕÖÁ09ÔÂ13ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇSAP Solution ManagerÑéÖ¤²é³È±Ê§·ì϶£»Tenda AC18 Router´úÂëÖ´Ðзì϶£»Android mediaframework CVE-2020-0245´úÂëÖ´Ðзì϶£»Microsoft ChakraCore CVE-2020-1172ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶£»Project Worlds Car Rental Management SystemËÁÒâÎļþÉÏ´«·ì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇWhatsAppÅû¶ÆäÀûÓÃÖеÄ6¸ö·ì϶£¬ÏÖÒѽ¨¸´£»ÆôÓÃHyper-VµÄWin10ϵͳÖдæÔÚ0day£¬¿É´´½¨Îļþ£»Î¢Èí°ä²¼9Ô·ݰ²È«¸üУ¬×ܼƽ¨¸´129¸ö·ì϶£»Adobe°ä²¼°²È«¸üУ¬½¨¸´¶à¿î²úÆ·ÖеÄ12¸ö·ì϶£»CodeMeterÖдæÔÚÑϳÁ·ì϶£¬¿Éµ¼ÖÂOT¹©¸øÁ´¹¥»÷¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
> ³ÁÒª°²È«·ì϶Áбí
1.SAP Solution ManagerÑéÖ¤²é³È±Ê§·ì϶
SAP Solution Manager´æÔÚÑéÖ¤²é³È±Ê§·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Î´ÊÚȨ½ÚÔì½Ó¼ûÀûÓá£
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700
2. Tenda AC18 Router´úÂëÖ´Ðзì϶
Tenda AC18 Router /usr/lib/lua/lua/ngx_authserver/ngx_wdasÖеÄlogincheck£¨£©º¯ÊýµÄÉí·ÝÑéÖ¤´¦ÖôæÔÚ·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Î´ÊÚȨִÐÐËÁÒâ´úÂë¡£
https://www.tendacn.com/en/product/AC18.html
3.Android mediaframework CVE-2020-0245´úÂëÖ´Ðзì϶
Android mediaframework´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÕßÒÔϵͳ¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://source.android.com/security/bulletin/2020-09-01
4. Microsoft ChakraCore CVE-2020-1172ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶
Microsoft ChakraCore´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÕßÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2020-1172
5. Project Worlds Car Rental Management SystemËÁÒâÎļþÉÏ´«·ì϶
Project Worlds Car Rental Management System³µÍ¼ÏñÉÏ´«×é¼þ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÉÏ´«ËÁÒâÎļþ£¬²¢Ö´ÐÐËÁÒâ´úÂë¡£
https://github.com/hyd3sec/CarRentalManagement-Unauth-RCE-WebApp
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢WhatsAppÅû¶ÆäÀûÓÃÖеÄ6¸ö·ì϶£¬ÏÖÒѽ¨¸´

WhatsAppÅû¶ÆäÀûÓÃÖдæÔÚµÄ6¸ö·ì϶£¬ÏÖÒѽ¨¸´¡£Õâ´Î½¨¸´µÄ·ì϶ÖнÏΪÑϳÁµÄΪ²Ö¿âдÈëÒç¶Âí½Å£¨CVE-2020-1894£©£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐУ¬32λÉ豸´æÔÚµÄдÒç¶Âí½Å£¨CVE-2020-1891£©ºÍURLÑéÖ¤ÎÊÌ⣨CVE-2020-1890£©£¬¿Éµ¼ÖºڿÍÔÚûÓÐÓëÓû§½»»¥µÄÇé¿öÏ´ӷ¢¼þÈ˵ÄURL¼ÓÔØÍ¼Ïñ¡£ÆäËû·ì϶Ϊ°²È«¼ì²âÈÆ¹ýÎÊÌ⣨CVE-2020-1889µÄ£©¡¢»º³åÇøÒç¶Âí½Å£¨CVE-2020-1886£©ºÍÊäÈëÑéÖ¤ÎÊÌ⣨CVE-2019-11928£©¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/107950/security/whatsapp-undisclosed-flaws.html
2¡¢ÆôÓÃHyper-VµÄWin10ϵͳÖдæÔÚ0day£¬¿É´´½¨Îļþ

ÄæÏò¹¤³ÌʦJonas LykkegaardÔÚÆôÓÃÁËHyper-VµÄWindows 10ϵͳÖз¢ÏÖÁËÒ»¸öеÄ0day£¬¸Ã·ì϶¿É±»ÀûÓÃÔÚÊÜÓ°ÏìµÄ²Ù×÷ϵͳÖд´½¨Îļþ¡£ÔÚHyper-V´¦Óڻ״̬ʱ£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚ\ system32Öд´½¨Îļþ£¬²¢ÇÒ²»±ØÒª½øÐÐÌáȨ¡£ÓÉÓÚÎļþµÄ´´½¨ÕßÒ²ÊÇËùÓÐÕߣ¬Òò¶ø¹¥»÷ÕßÄܹ»Ê¹ÓøÃÎļþ½«¶ñÒâ´úÂë×¢ÈëϵͳÄÚ²¿£¬²¢ÔÚ±ØÒªÊ±Ê¹ÓÃÌáÉýµÄȨÏÞÖ´ÐиöñÒâ´úÂë¡£CERT/CC·ì϶·ÖÎöʦWill Dormann °µÊ¾£¬¹¥»÷ÕßÏÕЩ²»±ØÒª×öÈκÎÖÂÁ¦±ãÄܹ»ÀûÓø÷ì϶¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/windows-10-sandbox-activation-enables-zero-day-vulnerability/
3¡¢Î¢Èí°ä²¼9Ô·ݰ²È«¸üУ¬×ܼƽ¨¸´129¸ö·ì϶

΢Èí°ä²¼ÁË9Ô·ݰ²È«¸üУ¬×ܼƽ¨¸´129¸ö·ì϶£¬ÆäÖÐÔ̺¬23¸öÑϳÁ·ì϶¡£Ö»¹ÜÕâ´Î¸üÐÂÖв¢Ã»ÓÐ0day£¬µ«ÈÔÓкܶà·ì϶¿É±»Ô¶³ÌÀûÓá£Õâ´Î½¨¸´µÄ¾ÍΪÑϳÁµÄÈý¸ö·ì϶±ðÀëΪMicrosoft ExchangeÄÚ´æ°Ü»µ·ì϶£¨CVE-2020-16875£©£¬Ô¶³Ì¹¥»÷ÕßÀûÓø÷ì϶Äܹ»½öͨ¹ýÏòExchange·þÎñÆ÷·¢ËÍÌØÔìµç×ÓÓʼþÔ¶³ÌÖ´ÐдúÂ룬WindowsÔ¶³ÌÖ´ÐдúÂëµÄMicrosoft COM·ì϶£¨CVE-2020-0922£©£¬Äܹ»Í¨¹ýÓÕʹÓû§½Ó¼û´øÓжñÒâJavaScriptµÄÕ¾µãÀ´¼ÓÒÔÀûÓã¬ÒÔ¼°WindowsÎı¾·þÎñÄ£¿éÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-0908£©£¬Äܹ»Í¨¹ýÓÕʹÓû§½Ó¼ûÔ̺¬¶ñÒâ¸æ°×µÄÍøÕ¾À´¼ÓÒÔÀûÓá£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2020-patch-tuesday-fixes-129-vulnerabilities/
4¡¢Adobe°ä²¼°²È«¸üУ¬½¨¸´¶à¿î²úÆ·ÖеÄ12¸ö·ì϶

Adobe°ä²¼°²È«¸üУ¬Òѽ¨¸´Ó°ÏìÆäAdobe InDesign¡¢Adobe FramemakerºÍAdobe Experience Manager²úÆ·ÖеÄ12¸ö´úÂëÖ´Ðзì϶¡£Õâ´Î¸üн¨¸´ÁËAdobe InDesignÖÐÒòÄÚ´æ°Ü»µµ¼ÖµÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-9727¡¢CVE-2020-9728¡¢CVE-2020-9729¡¢CVE-2020-9730ºÍCVE-2020-9731£©£¬FramemakerÖÐÔ½½ç¶ÁÈ¡µ¼ÖµĴúÂëÖ´Ðзì϶£¨CVE-2020-9726£©ºÍ»ùÓÚ²Ö¿âµÄ»º³åÇøÒç³öµÄ´úÂëÖ´Ðзì϶£¨CVE-2020-9725 £©£¬ÒÔ¼°Experience ManagerÖеĶà¸öXSS·ì϶¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-vulnerabilities-in-indesign-and-framemaker/
5¡¢CodeMeterÖдæÔÚÑϳÁ·ì϶£¬¿Éµ¼ÖÂOT¹©¸øÁ´¹¥»÷

Claroty·¢ÏÖÎ÷ÃÅ×ӵȶ¥¼¶ICS¹©¸øÉÌʹÓõĵÚÈý·½¹¤Òµ×é¼þCodeMeterÖдæÔÚ6¸öÑϳÁµÄ·ì϶£¬»ò½«µ¼ÖÂOT¹©¸øÁ´¹¥»÷£¬ÕâЩ·ì϶µÄCVSSÆÀ·Ö¾ùΪ10.0¡£CISA°µÊ¾£¬¹¥»÷Õ߳ɹ¦ÀûÓÃÕâЩ·ì϶ºó¿É¸ü¸ÄºÍαÔìÐí¿ÉÖ¤Îļþ£¬µ¼Ö»ؾø·þÎñÇé¿ö£¬Ç±ÔÚµØÊµÏÖÔ¶³ÌÖ´ÐдúÂë¡¢¶ÁÈ¡¶ÑÊý¾Ý²¢×èÖ¹ÒÀÀµCodeMeterµÄµÚÈý·½Èí¼þµÄÕý³£ÔËÐС£ÆäÖÐ×îÑϳÁµÄ·ì϶¿Éͨ¹ý·ÛËéCodeMeterͨѶºÍ̸ºÍÄÚ²¿APÒÔIÔ¶³ÌÖ´ÐдúÂ룬ʵÏÖICSϵͳµÄÆëÈ«ÊÕÊÜ¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/critical-bugs-enable-ot-supply/


¾©¹«Íø°²±¸11010802024551ºÅ