ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ38ÖÜ

°ä²¼¹¦·ò 2021-09-22

>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê09ÔÂ13ÈÕÖÁ09ÔÂ19ÈÕ¹²ÊÕ¼°²È«·ì϶60¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Premiere Elements CVE-2021-40700»º³åÇøÒç³ö´úÂëÖ´Ðзì϶£»Microsoft Azure Open Management InfrastructureȨÏÞÌáÉý·ì϶£»Google chrome Selection APIÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»Microsoft Scripting Engine CVE-2021-26435»º³åÇøÒç¶Âí½Å£»SAP Business OneÎļþÉÏ´«·ì϶ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÀÕË÷¹¥»÷µ¼ÖÂÄϷǶà¸öµ±²¿ÃÅÃŵÄITϵͳÖжÏ£»Apple°ä²¼´¹Î£¸üР£¬½¨¸´Áãµã»÷·ì϶ForcedEntry£»Kaspersky°ä²¼2021ÄêÉϰëÄêICSÍþÐ²Ì¬ÊÆµÄ»ã±¨£»Microsoft°ä²¼9Ô·ÝÐÇÆÚ¶þ²¹¶¡ £¬×ܼƽ¨¸´86¸ö·ì϶£»¹È¸èÒòÀÄÓð²×¿µÄÊг¡Ö÷µ¼Ö°Î»±»º«¹ú·£¿î2070ÒÚº«Ôª ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾Öܰ²È«ÍþвΪÖÐ ¡£


>³ÁÒª°²È«·ì϶Áбí


1.Adobe Premiere Elements CVE-2021-40700»º³åÇøÒç³ö´úÂëÖ´Ðзì϶


Adobe Premiere Elements´¦ÖÃÎļþ´æÔÚ»º³åÇøÒç¶Âí½Å £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó £¬ÓÕʹÓû§½âÎö £¬¿Éʹϵͳ±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£


https://helpx.adobe.com/security/products/premiere_elements/apsb21-78.html


2.Microsoft Azure Open Management InfrastructureȨÏÞÌáÉý·ì϶


Microsoft Azure Open Management Infrastructure´æÔÚ°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿ÉÌáÉýȨÏÞ ¡£


https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-38649


3.Google chrome Selection APIÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


Google chrome Selection API´æÔÚ¿ªÊͺóʹÓ÷ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó £¬ÓÕʹÓû§½âÎö £¬¿Éʹϵͳ±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£


https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop.html


4.Microsoft Scripting Engine CVE-2021-26435»º³åÇøÒç¶Âí½Å


Microsoft Scripting Engine´æÔÚ»º³åÇøÒç¶Âí½Å £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26435


5.SAP Business OneÎļþÉÏ´«·ì϶


SAP Business One´æÔÚËÁÒâÎļþÉÏ´«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£


https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405


 >³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢ÀÕË÷¹¥»÷µ¼ÖÂÄϷǶà¸öµ±²¿ÃÅÃŵÄITϵͳÖжÏ


ÀÕË÷¹¥»÷µ¼ÖÂÄϷǶà¸öµ±²¿ÃÅÃŵÄITϵͳÖжÏ.jpg



9ÔÂ6ÈÕÍíÉϵÄÀÕË÷¹¥»÷»î¶¯µ¼ÖÂÄϷǶà¸öµ±²¿ÃÅÃŵÄITϵͳÖжÏ £¬Ô̺¬µç×ÓÓʼþϵͳºÍ¹ú¶È±£ÊÍ·þÎñµÄϵͳ ¡£DOJCD¹ÙÔ±ÔÚÉÏÖÜËÄ£¨9ÔÂ9ÈÕ£©Ð¹Â© £¬¹¥»÷»î¶¯¼ÓÃÜÁ˸ò¿ÃÅËùÓеÄÐÅϢϵͳ £¬Ê¹µÃÄÚ²¿µÄÔ±¹¤ºÍ±í²¿µÄ¹«Ãñ¾ùÎÞ·¨Ê¹Óà ¡£´Ë±í £¬Ë¾·¨²¿¹ÙÔ±°µÊ¾ £¬ËûÃDz»µÃ²»Æô¶¯ÁËÊÖ¶¯Á÷³ÌÀ´Î¬³Ö·¨Í¥µÄÕý³£»î¶¯ £¬µ«²¢Î´Ö¸Ã÷Õâ´Î¹¥»÷±³ºóµÄÀÕË÷ÔËÓªÍÅ»ï ¡£ÉÏÖÜÒ» £¬ÄϷǹú¶Èº½Ìì¾Ö (SANSA)ÔøÅû¶Æäϵͳ´æÔÚ°²È«·ì϶ £¬µ¼ÖÂѧÉúÓ×ÎÒÐÅϢй¶ ¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/bail-services-affected-in-south-africa-after-ransomware-attack/   


2¡¢Apple°ä²¼´¹Î£¸üР£¬½¨¸´Áãµã»÷·ì϶ForcedEntry


Apple°ä²¼´¹Î£¸üÐÂ£¬½¨¸´Áãµã»÷·ì϶ForcedEntry.jpg


Apple¹«Ë¾ÓÚ±¾ÖÜÒ»°ä²¼´¹Î£¸üР£¬½¨¸´iMessagingÖеÄÁãµã»÷·ì϶ForcedEntry£¨CVE-2021-30860£© ¡£Apple³Æ¸Ã·ì϶Ϊ´¦ÖöñÒâPDFʱµ¼ÖµÄËÁÒâ´úÂëÖ´Ðзì϶ ¡£Citizen LabÓÚ2021Äê2Ô³õ´Î·¢Ïָ÷ì϶ £¬Ëü¿ÉÓÃÀ´ÈƹýAppleÆäÊ±ÍÆ³öµÄÔ¤·ÀiMessageÁãµã»÷·ì϶µÄɳÏäBlastDoor ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/apple-emergency-fix-nso-zero-click-zero-day/169416/


3¡¢Kaspersky°ä²¼2021ÄêÉϰëÄêICSÍþÐ²Ì¬ÊÆµÄ»ã±¨


Kaspersky°ä²¼2021ÄêÉϰëÄêICSÍþÐ²Ì¬ÊÆµÄ»ã±¨.jpg


KasperskyÔÚ9ÔÂ9ÈÕ°ä²¼ÁË2021ÄêÉϰëÄêICSÍþÐ²Ì¬ÊÆµÄ»ã±¨ ¡£»ã±¨Ö¸³ö £¬2021ÄêÉϰëÄêICSÍÆËã»ú±»¹¥»÷µÄÕ¼±ÈΪ8% £¬±È2020ÄêϰëÄê¸ß0.4¸ö°Ù·Öµã ¡£ÆäÖÐ £¬±»¹¥»÷µÄICSÍÆËã»úÕ¼±È×î¶àµÄ¹ú¶ÈΪ°¢¶û¼°ÀûÑÇ£¨58.4%£© £¬Æä´ÎΪĦÂå¸ç£¨52.4%£© ¡¢ÒÁÀ­¿Ë£¨50.9%£©ºÍÔ½ÄÏ£¨50.6%£© ¡£´Ë±í £¬»¥ÁªÍø¡¢¿ÉÒÆ¶¯Ã½ÌåºÍµç×ÓÓʼþÒÀÈ»ÊÇICSÍÆËã»úÍþвµÄÖØÒªÆðÔ´ ¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/threat-landscape-for-industrial-automation-systems-in-h1-2021/104017/


4¡¢Microsoft°ä²¼9Ô·ÝÐÇÆÚ¶þ²¹¶¡ £¬×ܼƽ¨¸´86¸ö·ì϶


Microsoft°ä²¼9Ô·ÝÐÇÆÚ¶þ²¹¶¡£¬×ܼƽ¨¸´86¸ö·ì϶.jpg


MicrosoftÓÚ9ÔÂ14ÈÕ°ä²¼Á˱¾ÔµÄÐÇÆÚ¶þ°²È«¸üР£¬×ܼƽ¨¸´ÁË86¸ö·ì϶ ¡£Õâ´Î¸üн¨¸´ÁË2¸öÁãÈÕ·ì϶ £¬Ô̺¬Windows MSHTMLÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-40444£© £¬ÒÑÔÚÒ°±í·¢ÏÖÀûÓø÷ì϶µÄ¹¥»÷»î¶¯£»ÒÔ¼°Windows DNSÌáȨ·ì϶£¨CVE-2021-36968£© ¡£´Ë±í £¬»¹½¨¸´ÁËAzure Ê¢¿ªÊ½ÖÎÀí»ù´¡ÉèÊ©ÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-38647£©ºÍWindows¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-26435£©µÈ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2021-patch-tuesday-fixes-2-zero-days-60-flaws/


5¡¢¹È¸èÒòÀÄÓð²×¿µÄÊг¡Ö÷µ¼Ö°Î»±»º«¹ú·£¿î2070ÒÚº«Ôª


¹È¸èÒòÀÄÓð²×¿µÄÊг¡Ö÷µ¼Ö°Î»±»º«¹ú·£¿î2070ÒÚº«Ôª.jpg


9ÔÂ14ÈÕ £¬º«¹úƽÕýÒµÎñίԱ»á¶Ô¹È¸è´¦ÒÔ2070ÒÚº«Ôª£¨Ô¼Îª1.77 ÒÚÃÀÔª£©µÄ·£¿î ¡£Ô­ÒòÊǹȸèÒòÀÄÓð²×¿ÔÚÒÆ¶¯²Ù×÷ϵͳÊг¡µÄÖ÷µ¼Ö°Î» £¬ÆÈʹÖÇÄÜÊÖ»úÔì×÷ÉÌÖ»ÄÜʹÓÃAndroid²Ù×÷ϵͳ ¡£¸Ã»ú¹¹³Æ £¬¹È¸èÒªÇóÔì×÷É̱ØÐëÇ©Êð¡°·´Ë鯬»¯ºÍ̸£¨AFA£©¡± £¬¸ÃºÍ̸²»ÈÝʹÓÃAndroid²Ù×÷ϵͳµÄÅú¸Ä°æ±¾ £¬¼´ËùνµÄ¡°Android·ÖÖ§¡± ¡£±¨Â·³Æ £¬¹È¸èµÄ¢¶ÏÐÐΪʹÆäÔÚ2019ÄêÒÆ¶¯²Ù×÷ϵͳÊг¡µÄ·Ý¶îÉÏÉýµ½ÁË97.7% ¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2021/09/14/south_korea_fines_google/