ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ35ÖÜ
°ä²¼¹¦·ò 2021-08-30>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê08ÔÂ23ÈÕÖÁ08ÔÂ29ÈÕ¹²ÊÕ¼°²È«·ì϶60¸ö£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇFlatCore-CMS upload addon²å¼þ´úÂëÖ´ÐЩ£»NASCENT RemKon Device Manager assets/index.phpËÁÒâ´úÂëÉÏ´«·ì϶£»Teamviewer TVS½âÎöÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶£»RaspAP raspap-webguiÌØÈ¨ÌáÉý·ì϶£»SolarWinds Web Help Desk referrerαÔì½Ó¼ûÏÞ¶ÈÈÆ¹ý·ì϶¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÐÂ¼ÓÆÂ·¿µØ²ú¹«Ë¾OrangeTeeÔâµ½ALTDOSµÄÀÕË÷¹¥»÷£»HuntressÔÚ1900̨Exchange¼ì²âµ½140¶àÖÖWeb shell£»Razer SynapseÖеı¾µØÌáȨ0dayÓ°Ï쳬¹ý1ÒÚÓû§£»SAM·¢ÏÖMiraiÀûÓÃRealtek SDKÖзì϶µÄ¹¥»÷»î¶¯£»OpenSSL°ä²¼°²È«¸üУ¬£¬£¬ÐÞ¸´²úÆ·ÖеÄ2¸ö°²È«·ì϶¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£
>ÖØÒª°²È«·ì϶Áбí
1.Google chrome V8 CVE-2021-30598ÀàÐÍ»ìºÏ´úÂëÖ´Ðзì϶
FlatCore-CMS upload addon²å¼þ´æÔÚ°²È«·ì϶£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£
https://github.com/flatCore/flatCore-CMS/issues/52
2.NASCENT RemKon Device Manager assets/index.phpËÁÒâ´úÂëÉÏ´«·ì϶
NASCENT RemKon Device Manager assets/index.phpͼÏñÉÏ´«Ö°ÄÜ´æÔÚ°²È«·ì϶£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬¿ÉÉÏ´«ËÁÒâÎļþ²¢ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£
https://www.blacklanternsecurity.com/2021-08-23-Nascent-RemKon-CVEs/
3.Teamviewer TVS½âÎöÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶
Teamviewer TVS½âÎö´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-1003/
4.RaspAP raspap-webguiÌØÈ¨ÌáÉý·ì϶
RaspAP raspap-webgui´æÔÚ²»°²È«µÄsudoersȨÏÞ·ì϶£¬£¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬»ñµÃROOTȨÏÞ¡£¡£
https://github.com/RaspAP/raspap-webgui/blob/fabc48c7daae4013b9888f266332e510b196a062/installers/raspap.sudoers
5.SolarWinds Web Help Desk referrerαÔì½Ó¼ûÏÞ¶ÈÈÆ¹ý·ì϶
SolarWinds Web Help Desk referrerαÔì´æÔÚ°²È«·ì϶£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬¿ÉÈÆ¹ýÏÞ¶ÈδÊÚȨ½Ó¼û¡£¡£
https://www.solarwinds.com/trust-center/security-advisories/cve-2021-32076
>ÖØÒª°²È«ÊÂÎñ×ÛÊö
1¡¢¡¢ÐÂ¼ÓÆÂ·¿µØ²ú¹«Ë¾OrangeTeeÔâµ½ALTDOSµÄÀÕË÷¹¥»÷

8ÔÂ6ÈÕ£¬£¬£¬ÐÂ¼ÓÆÂ·¿µØ²ú¹«Ë¾OrangeTee GroupÔÚÆä¹ÙÍøÉϰ䲼ÉêÃ÷³ÆÆäÔâµ½Á˹¥»÷¡£¡£8ÔÂ12ÈÕ£¬£¬£¬ºÚ¿ÍÍÅ»ïALTDOSÐû³ÆËüÃÇ×Ô2021Äê6ÔÂÒÔÀ´£¬£¬£¬Ò»ÏòÔÚÇÔÈ¡¸Ã¹«Ë¾µÄÊý¾Ý£¬£¬£¬ÏÖÒÑ»ñµÃÁËÀ´×ÔACSystem¡¢¡¢NewOrangeTee¡¢¡¢OT_Analytics¡¢¡¢OT_LeaveºÍProjInfoListingµÄ969¸öÊý¾Ý¿â¡£¡£Í¬ÈÕ£¬£¬£¬OrangeTee¹«Ë¾°µÊ¾Æä²»»áÖ§¸¶Êê½ð¡£¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/singapore-real-estate-firm-breached-by-altdos/
2¡¢¡¢HuntressÔÚ1900̨Exchange¼ì²âµ½140¶àÖÖWeb shell

ÉÏÖÜÎ壬£¬£¬°²È«¹«Ë¾Huntress Labs³Æ½ü2000̨Microsoft ExchangeÓʼþ·þÎñÆ÷ÔÚ´Óǰ¼¸ÌìÄÚÔâµ½ºÚ¿Í¹¥»÷¡£¡£ProxyShellÊÇ3¸ö·ì϶CVE-2021-34473¡¢¡¢CVE-2021-34523ºÍCVE-2021-31207µÄͳ³Æ¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬ÔÚProxyShell¸ÅÄîÑéÖ¤´úÂë°ä²¼ºó²»¾Ã³öÏÖÁËÓйØÉ¨Ãè»î¶¯£¬£¬£¬Ö±µ½ÉÏÖÜÄ©Ôì³ÉÁËÏÖʵ¹¥»÷¡£¡£´ËÍ⣬£¬£¬Òѱ»ÈëÇÖµÄ1900¶ą̀Exchange·þÎñÆ÷Éæ¼°µ½µÄ×éÖ¯Ô̺¬¹¹ÖþÖÆ×÷ÉÌ¡¢¡¢º£Ïʼӹ¤³§¡¢¡¢¹¤Òµ»úе¹«Ë¾¡¢¡¢Æû³µÎ¬ÐÞµêºÍСÐÍ»ú³¡µÈ¡£¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/almost-2000-exchange-servers-hacked-using-proxyshell-exploit/
3¡¢¡¢Razer SynapseÖеı¾µØÌáȨ0dayÓ°Ï쳬¹ý1ÒÚÓû§

×êÑÐÈËÔ±jonhatÓÚ2021Äê8ÔÂ21ÈÕÔÚTwitterÉÏÅû¶ÁËRazer SynapseÖеı¾µØÌáȨ0dayµÄϸ½Ú¡£¡£RazerÊÇÒ»¼ÒÍÆËã»úÍâÉèÖÆ×÷ÉÌ£¬£¬£¬Ðû³ÆÆäRazer SynapseÒѱ»È«Çò³¬¹ý1ÒÚÓû§Ê¹Óᣡ£ÕâÊÇÒ»¸ö±¾µØÌáȨ£¨LPE£©·ì϶£¬£¬£¬½«RazerÉ豸²åÈëWindows 10ʱ£¬£¬£¬ÏµÍ³»á×Ô¶¯ÏÂÔØ²¢×°ÖÃÇý¶¯·¨Ê½ºÍRazer Synapse£¬£¬£¬ÓÉÓÚRazerInstaller.exeÊÇͨ¹ýSYSTEMȨÏÞµÄWindows¹ý³ÌÆô¶¯µÄ£¬£¬£¬Òò¶øÆäÒ²»ñµÃÁËSYSTEMȨÏÞ¡£¡£Ö®ºóÔÚÑ¡Ôñ×°ÖÃÎļþ¼Ðʱ£¬£¬£¬°´ÏÂShift²¢ÓÒ¼üµ¥»÷¶Ô»°¿ò£¬£¬£¬¾ÍÄܹ»´ò¿ªSYSTEMȨÏÞµÄPowerShell´°¿Ú¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/razer-bug-lets-you-become-a-windows-10-admin-by-plugging-in-a-mouse/
4¡¢¡¢SAM·¢ÏÖMiraiÀûÓÃRealtek SDKÖзì϶µÄ¹¥»÷»î¶¯

°²È«¹«Ë¾SAM SeamlessÓÚ8ÔÂ19ÈÕ³ÆÆä·¢ÏÖÁ˽©Ê¬ÍøÂçMiraiÀûÓÃRealtek SDKÖзì϶µÄ¹¥»÷»î¶¯¡£¡£¸Ã·ì϶ΪÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¬£¬£¬×·×ÙΪCVE-2021-20090£¬£¬£¬ÆÀ·ÖΪ9.8·Ö£¬£¬£¬RealtekÒÑÓÚ8ÔÂ13ÈÕ°ä²¼¸Ã·ì϶µÄ²¹¶¡·¨Ê½¡£¡£SAM°µÊ¾£¬£¬£¬ËûÃÇÓÚ8ÔÂ18ÈÕÔÚÒ°·¢ÏÖÁËÕâ´Î·ì϶ÀûÓû£¬£¬£¬¹¥»÷Ô´ÓÚ31.210.20[.]100£¬£¬£¬µ«¹¥»÷ÕßµÄIPµØÖ·¿ÉÄÜ»áËæ×Ź¦·ò¶øÅ¤×ª¡£¡£
ÔÎÄÁ´½Ó£º
https://securingsam.com/realtek-vulnerabilities-weaponized/
5¡¢¡¢OpenSSL°ä²¼°²È«¸üУ¬£¬£¬ÐÞ¸´²úÆ·ÖеÄ2¸ö°²È«·ì϶

OpenSSLÓÚ8ÔÂ24ÈÕ°ä²¼°²È«¸üУ¬£¬£¬ÐÞ¸´Æä²úÆ·ÖеÄ2¸ö°²È«·ì϶¡£¡£ÆäÖÐ×îΪÑÏÖØµÄÊÇ»º³åÇøÒç³ö·ì϶£¬£¬£¬×·×ÙΪCVE-2021-3711£¬£¬£¬¹¥»÷ÕßÀûÓÃÆä¿Éµ¼ÖÂÀûÓ÷¨Ê½±ÀÀ£¡£¡£¸Ã·ì϶ÓëSM2¼ÓÃÜÊý¾ÝµÄ½âÃܹý³ÌÓйأ¬£¬£¬¿ÉÓÃÀ´¸ü¸Ä¶ÑÖеÄÊý¾Ý£¨¼´Í´´¦£©¡£¡£Õâ´ÎÐÞ¸´µÄÁíÒ»¸ö·ì϶׷×ÙΪCVE-2021-3712£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶´¥·¢»Ø¾ø·þÎñ(DoS)£¬£¬£¬»¹¿ÉÄܵ¼Ö»úÃÜÐÅϢй¶£¬£¬£¬ÀýÈç˽Կ»òÃô¸ÐÃ÷ÎÄ¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/121426/hacking/cve-2021-3711-openssl-flaws.html


¾©¹«Íø°²±¸11010802024551ºÅ