ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ37ÖÜ

°ä²¼¹¦·ò 2020-09-14

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê09ÔÂ07ÈÕÖÁ09ÔÂ13ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇSAP Solution ManagerÑéÖ¤²é³­È±Ê§·ì϶£»Tenda AC18 Router´úÂëÖ´Ðзì϶£»Android mediaframework CVE-2020-0245´úÂëÖ´Ðзì϶£»Microsoft ChakraCore CVE-2020-1172ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶£»Project Worlds Car Rental Management SystemËÁÒâÎļþÉÏ´«·ì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇWhatsAppÅû¶ÆäÀûÓÃÖеÄ6¸ö·ì϶£¬ÏÖÒÑÐÞ¸´£»ÆôÓÃHyper-VµÄWin10ϵͳÖдæÔÚ0day£¬¿É´´½¨Îļþ£»Î¢Èí°ä²¼9Ô·ݰ²È«¸üУ¬×ܼÆÐÞ¸´129¸ö·ì϶£»Adobe°ä²¼°²È«¸üУ¬ÐÞ¸´¶à¿î²úÆ·ÖеÄ12¸ö·ì϶£»CodeMeterÖдæÔÚÑÏÖØ·ì϶£¬¿Éµ¼ÖÂOT¹©¸øÁ´¹¥»÷¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


ÖØÒª°²È«·ì϶Áбí


1.SAP Solution ManagerÑéÖ¤²é³­È±Ê§·ì϶


SAP Solution Manager´æÔÚÑéÖ¤²é³­È±Ê§·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Î´ÊÚȨ½ÚÖÆ½Ó¼ûÀûÓá£

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700


2. Tenda AC18 Router´úÂëÖ´Ðзì϶


Tenda AC18 Router /usr/lib/lua/lua/ngx_authserver/ngx_wdasÖеÄlogincheck£¨£©º¯ÊýµÄÉí·ÝÑéÖ¤´¦ÖôæÔÚ·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Î´ÊÚȨִÐÐËÁÒâ´úÂë¡£

https://www.tendacn.com/en/product/AC18.html


3.Android mediaframework CVE-2020-0245´úÂëÖ´Ðзì϶


Android mediaframework´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÕßÒÔϵͳ¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://source.android.com/security/bulletin/2020-09-01


4. Microsoft ChakraCore CVE-2020-1172ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶


Microsoft ChakraCore´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÕßÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2020-1172


5. Project Worlds Car Rental Management SystemËÁÒâÎļþÉÏ´«·ì϶


Project Worlds Car Rental Management System³µÍ¼ÏñÉÏ´«×é¼þ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÉÏ´«ËÁÒâÎļþ£¬²¢Ö´ÐÐËÁÒâ´úÂë¡£


https://github.com/hyd3sec/CarRentalManagement-Unauth-RCE-WebApp


> ÖØÒª°²È«ÊÂÎñ×ÛÊö


1¡¢¡¢WhatsAppÅû¶ÆäÀûÓÃÖеÄ6¸ö·ì϶£¬ÏÖÒÑÐÞ¸´


1.jpg


WhatsAppÅû¶ÆäÀûÓÃÖдæÔÚµÄ6¸ö·ì϶£¬ÏÖÒÑÐÞ¸´¡£Õâ´ÎÐÞ¸´µÄ·ì϶ÖнÏΪÑÏÖØµÄΪ²Ö¿âдÈëÒç³ö·ì϶£¨CVE-2020-1894£©£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐУ¬32λÉ豸´æÔÚµÄдÒç³ö·ì϶£¨CVE-2020-1891£©ºÍURLÑéÖ¤ÎÊÌ⣨CVE-2020-1890£©£¬¿Éµ¼ÖºڿÍÔÚûÓÐÓëÓû§½»»¥µÄÇé¿öÏ´ӷ¢¼þÈ˵ÄURL¼ÓÔØÍ¼Ïñ¡£ÆäËû·ì϶Ϊ°²È«¼ì²âÈÆ¹ýÎÊÌ⣨CVE-2020-1889µÄ£©¡¢¡¢»º³åÇøÒç³ö·ì϶£¨CVE-2020-1886£©ºÍÊäÈëÑéÖ¤ÎÊÌ⣨CVE-2019-11928£©¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/107950/security/whatsapp-undisclosed-flaws.html


2¡¢¡¢ÆôÓÃHyper-VµÄWin10ϵͳÖдæÔÚ0day£¬¿É´´½¨Îļþ


2.jpg


ÄæÏò¹¤³ÌʦJonas LykkegaardÔÚÆôÓÃÁËHyper-VµÄWindows 10ϵͳÖз¢ÏÖÁËÒ»¸öеÄ0day£¬¸Ã·ì϶¿É±»ÀûÓÃÔÚÊÜÓ°ÏìµÄ²Ù×÷ϵͳÖд´½¨Îļþ¡£ÔÚHyper-V´¦Óڻ״̬ʱ£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚ\ system32Öд´½¨Îļþ£¬²¢ÇÒ²»±ØÒª½øÐÐÌáȨ¡£ÓÉÓÚÎļþµÄ´´½¨ÕßÒ²ÊÇËùÓÐÕߣ¬Òò¶ø¹¥»÷ÕßÄܹ»Ê¹ÓøÃÎļþ½«¶ñÒâ´úÂë×¢ÈëϵͳÄÚ²¿£¬²¢ÔÚ±ØÒªÊ±Ê¹ÓÃÌáÉýµÄȨÏÞÖ´ÐиöñÒâ´úÂë¡£CERT/CC·ì϶·ÖÎöʦWill Dormann  °µÊ¾£¬¹¥»÷ÕßÏÕЩ²»±ØÒª×öÈκÎÖÂÁ¦±ãÄܹ»ÀûÓø÷ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/windows-10-sandbox-activation-enables-zero-day-vulnerability/


3¡¢¡¢Î¢Èí°ä²¼9Ô·ݰ²È«¸üУ¬×ܼÆÐÞ¸´129¸ö·ì϶


3.jpg


΢Èí°ä²¼ÁË9Ô·ݰ²È«¸üУ¬×ܼÆÐÞ¸´129¸ö·ì϶£¬ÆäÖÐÔ̺¬23¸öÑÏÖØ·ì϶¡£Ö»¹ÜÕâ´Î¸üÐÂÖв¢Ã»ÓÐ0day£¬µ«ÈÔÓкܶà·ì϶¿É±»Ô¶³ÌÀûÓá£Õâ´ÎÐÞ¸´µÄ¾ÍΪÑÏÖØµÄÈý¸ö·ì϶±ðÀëΪMicrosoft ExchangeÄÚ´æ°Ü»µ·ì϶£¨CVE-2020-16875£©£¬Ô¶³Ì¹¥»÷ÕßÀûÓø÷ì϶Äܹ»½öͨ¹ýÏòExchange·þÎñÆ÷·¢ËÍÌØÖÆµç×ÓÓʼþÔ¶³ÌÖ´ÐдúÂ룬WindowsÔ¶³ÌÖ´ÐдúÂëµÄMicrosoft COM·ì϶£¨CVE-2020-0922£©£¬Äܹ»Í¨¹ýÓÕʹÓû§½Ó¼û´øÓжñÒâJavaScriptµÄÕ¾µãÀ´¼ÓÒÔÀûÓã¬ÒÔ¼°WindowsÎı¾·þÎñÄ£¿£¿£¿éÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-0908£©£¬Äܹ»Í¨¹ýÓÕʹÓû§½Ó¼ûÔ̺¬¶ñÒâ¸æ°×µÄÍøÕ¾À´¼ÓÒÔÀûÓá£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2020-patch-tuesday-fixes-129-vulnerabilities/


4¡¢¡¢Adobe°ä²¼°²È«¸üУ¬ÐÞ¸´¶à¿î²úÆ·ÖеÄ12¸ö·ì϶


4.jpg


Adobe°ä²¼°²È«¸üУ¬ÒÑÐÞ¸´Ó°ÏìÆäAdobe InDesign¡¢¡¢Adobe FramemakerºÍAdobe Experience Manager²úÆ·ÖеÄ12¸ö´úÂëÖ´Ðзì϶¡£Õâ´Î¸üÐÂÐÞ¸´ÁËAdobe InDesignÖÐÒòÄÚ´æ°Ü»µµ¼ÖµÄËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-9727¡¢¡¢CVE-2020-9728¡¢¡¢CVE-2020-9729¡¢¡¢CVE-2020-9730ºÍCVE-2020-9731£©£¬FramemakerÖÐÔ½½ç¶ÁÈ¡µ¼ÖµĴúÂëÖ´Ðзì϶£¨CVE-2020-9726£©ºÍ»ùÓÚ²Ö¿âµÄ»º³åÇøÒç³öµÄ´úÂëÖ´Ðзì϶£¨CVE-2020-9725 £©£¬ÒÔ¼°Experience ManagerÖеĶà¸öXSS·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-vulnerabilities-in-indesign-and-framemaker/


5¡¢¡¢CodeMeterÖдæÔÚÑÏÖØ·ì϶£¬¿Éµ¼ÖÂOT¹©¸øÁ´¹¥»÷


5.jpg


Claroty·¢ÏÖÎ÷ÃÅ×ӵȶ¥¼¶ICS¹©¸øÉÌʹÓõĵÚÈý·½¹¤Òµ×é¼þCodeMeterÖдæÔÚ6¸öÑÏÖØµÄ·ì϶£¬»ò½«µ¼ÖÂOT¹©¸øÁ´¹¥»÷£¬ÕâЩ·ì϶µÄCVSSÆÀ·Ö¾ùΪ10.0¡£CISA°µÊ¾£¬¹¥»÷Õ߳ɹ¦ÀûÓÃÕâЩ·ì϶ºó¿É¸ü¸ÄºÍαÔìÐí¿ÉÖ¤Îļþ£¬µ¼Ö»ؾø·þÎñÇé¿ö£¬Ç±ÔÚµØÊµÏÖÔ¶³ÌÖ´ÐдúÂë¡¢¡¢¶ÁÈ¡¶ÑÊý¾Ý²¢×èÖ¹ÒÀÀµCodeMeterµÄµÚÈý·½Èí¼þµÄÕý³£ÔËÐС£ÆäÖÐ×îÑÏÖØµÄ·ì϶¿Éͨ¹ý·ÛËéCodeMeterͨѶºÍ̸ºÍÄÚ²¿APÒÔIÔ¶³ÌÖ´ÐдúÂ룬ʵÏÖICSϵͳµÄÆëÈ«ÊÕÊÜ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/critical-bugs-enable-ot-supply/