ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ41ÖÜ

°ä²¼¹¦·ò 2020-10-13

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê10ÔÂ05ÈÕÖÁ10ÔÂ11ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Android Qualcomm¹ØÔ´×é¼þCVE-2020-3654´úÂëÖ´Ðзì϶£»Google Android Qualcomm¹ØÔ´×é¼þCVE-2020-3657´úÂëÖ´Ðзì϶£»Google Android system×é¼þCVE-2020-0416´úÂëÖ´Ðзì϶£»D-Link DAP-136 IP²ÎÊýºÅÁîÖ´Ðзì϶£»Facebook WhatsApp RTP ExtensionÕ»Òç¶Âí½Å¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ£ºCISA°ä²¼2019²ÆÄê·çÏÕ·ì϶ÆÀ¹ÀµÄÐÅϢͼ£»°²È«¹«Ë¾Arctic Wolf°ä²¼°²È«ÔËÓªÄê¶È»ã±¨£»Google°ä²¼µÄChrome°²È«¸üн¨¸´¶à¸ö·ì϶£»AdobeÒò·þÎñÖжϵ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud£»Android°æFacebookÖдæÔÚ·ì϶£¬»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


³ÁÒª°²È«·ì϶Áбí


1.Google Android Qualcomm¹ØÔ´×é¼þCVE-2020-3654´úÂëÖ´Ðзì϶


Google Android Qualcomm¹ØÔ´×é¼þʵÏÖ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿Éʹ·þÎñ·¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://source.android.com/security/bulletin/2020-10-01


2.Google Android Qualcomm¹ØÔ´×é¼þCVE-2020-3657´úÂëÖ´Ðзì϶


Google Android Qualcomm¹ØÔ´×é¼þʵÏÖ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿Éʹ·þÎñ·¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://source.android.com/security/bulletin/2020-10-01


3.Google Android system×é¼þCVE-2020-0416´úÂëÖ´Ðзì϶


Google Android Framework×é¼þʵÏÖ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿Éʹ·þÎñ·¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://source.android.com/security/bulletin/2020-10-01


4.D-Link DAP-136 IP²ÎÊýºÅÁîÖ´Ðзì϶


D-Link DAP-136´¦ÖÃIP²ÎÊý´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£

https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10191


5.Facebook WhatsApp RTP ExtensionÕ»Òç¶Âí½Å


Facebook WhatsApp RTP Extension½âÎö´æÔÚÕ»Òç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://www.whatsapp.com/security/advisories/2020/


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢CISA°ä²¼2019²ÆÄê·çÏÕ·ì϶ÆÀ¹ÀµÄÐÅϢͼ



1.png


ÍøÂ簲ȫºÍÐÅÏ¢°²È«»ú¹¹(CISA)°ä²¼ÁË2019²ÆÄê½øÐеÄ44Ïî·çÏպͷì϶ÆÀ¹À£¨RVA£©£¬ÒÔ¼°MITERÆ¥µÐÕ½Êõ¡¢¼¼ÊõºÍѧÎÊ£¨ATT£¦CK£©¿ò¼ÜµÄ·ÖÎöÐÅϢͼ¡£¸ÃÐÅϢͼ±íÈ·¶¨ÁËCISAÔÚ¿ç¶à¸ö²¿ÃŵÄRVAsÆÚ¼ä¹Û²ìµ½µÄͨÀý³É¹¦¹¥»÷õè¾¶£¬ÍøÂç¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ¹¥»÷õè¾¶À´¹¥»÷×éÖ¯¡£CISA¼¤ÀøÍøÂçÖÎÀíÔ±ºÍITרҵÈËÔ±²é¿´ÐÅϢͼ²¢ÀûÓÃÍÆ¼öµÄ·ÀÓùÕ½Êõ£¬ÒÔÔ¤·ÀÊܵ½ÒÑÖªÕ½ÊõºÍ¼¼ÊõµÄ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/10/07/cisa-releases-fy2019-risk-vulnerability-assessment-infographic


2¡¢°²È«¹«Ë¾Arctic Wolf°ä²¼°²È«ÔËÓªÄê¶È»ã±¨


2.png


°²È«¹«Ë¾Arctic Wolf°ä²¼ÁËÒ»·Ý°²È«ÔËÓªÄê¶È»ã±¨¡£»ã±¨ÏÔʾ£¬×Ô3ÔÂÒÔÀ´£¬°µÍøÉϹ«¿ªµÄ¹«Ë¾Í´´¦ÊýÁ¿Ôö³¤ÁË429£¥¡£Ôڹ۲쵽µÄ¸ß·çÏÕ°²È«ÊÂÎñÖУ¬ÓÐ35£¥²úÉúÔÚ8:00 PMºÍ8:00 AMÖ®¼ä£¬¶ø14£¥²úÉúÔÚÖÜÄ©£¬ÕâÊǺܶàÄÚ²¿°²È«ÍŶӲ»ÔÚÏߵŦ·ò¡£´Ë±í£¬ÍøÂç´¹µöºÍÀÕË÷Èí¼þ¹¥»÷´ÎÊýÔö³¤ÁË64£¥£¬ºÚ¿Í¸ü¶àµÄÒÔCOVID-19Ö÷ÌâΪµö¶ü£¬À´Õë¶ÔÔ¶³Ì¹¤×÷Õß¡£


Ô­ÎÄÁ´½Ó£º

https://arcticwolf.com/resources/analyst-reports/security-operations-annual-report


3¡¢Google°ä²¼µÄChrome°²È«¸üн¨¸´¶à¸ö·ì϶


3.png


Google°ä²¼µÄChrome°²È«¸üÐÂÕë¶ÔWindows¡¢MacºÍLinux°æ±¾½¨¸´ÁË35¸ö·ì϶¡£ÆäÖнÏΪÑϳÁµÄ·ì϶Ϊ֧¸¶ÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2020-15967£©£¬Æä´ÎΪBlink¡¢WebRTC¡¢NFC¡¢´òÓ¡¡¢ÒôƵ¡¢×Ô¶¯Ìî³äºÍÃÜÂëÖÎÀíÆ÷ÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2020-15968¡¢CVE-2020-15969¡¢CVE-2020-15970¡¢CVE-2020-15971¡¢CVE-2020-15972¡¢CVE-2020-15990ºÍCVE-2020-15991£©¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/10/07/google-releases-security-updates-chrome


4¡¢AdobeÒò·þÎñÖжϵ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud


4.png


AdobeÒò·þÎñÖжÏ£¬µ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud»ò½Ó¼ûÆä¶©ÔĵÄÀûÓ÷¨Ê½»ò´æ´¢µÄÊý¾Ý¡£×ÔÃÀ¹ú¶«²¿¹¦·òÉÏÎç9:30ÒÔÀ´£¬Adobe Creative CloudÓû§ÆðÍ·»ã±¨ÎÞ·¨µÇ¼¸Ã·þÎñ»ò½Ó¼û±£ÁôµÄͼÏñºÍÊý¾Ý£¬µ±ËûÃÇÊÔͼµÇ¼µÄʱ³½£¬¾Í»áÏÔʾ¡°²úÉúÁËһЩÃýÎó¡±µÄÌáÐÑ¡£Ä¿Ç°£¬AdobeÒÑÔÚstatus.adobe.comÒ³ÃæÉϰ䲼֪ͨȷÈÏÁËÖжÏ£¬µ«²¢Î´ÌṩÈκÎÓйØÕâ´ÎÖжϵľßÌåÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/adobe-creative-cloud-down-users-report-login-data-access-issues/


5¡¢Android°æFacebookÖдæÔÚ·ì϶£¬»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ


5.png


°²È«×êÑÐÔ±Sayed Abdelhafiz·¢ÏÖ£¬Android°æFacebookÖдæÔÚÑϳÁ·ì϶£¬¸Ã·ì϶»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂÀûÓñÀÀ£ÒÔ¼°É豸ÊÕÊÜ¡£FacebookÔÊÐíͨ¹ýÁ½ÖÖ·½Ê½ÏÂÔØÎļþ£¬ÆäÖÐÒ»ÖÖÊÇʹÓá°Îļþ¡±Ñ¡Ï£¬½«ÎļþÏÈÌáÈ¡µ½DownloadManager£¬¶øºó±£Áôµ½Download Director¡£Abdelhafiz·¢ÏÖÄܹ»´´½¨²¢ÏÂÔØÒ»¸ö¶ñÒâÎļþ£¬¶øºóÔÚÖ¸±êÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë¡£FacebookÔڵõ½·ì϶»ã±¨ºó£¬ÒÑÓÚ2020Äê6Ô½¨¸´Á˸÷ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/10/08/code-execution-vulnerability-found-in-facebook-for-android/