ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ15ÖÜ

Ðû²¼Ê±¼ä 2018-04-16

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
        2018Äê04ÔÂ09ÈÕÖÁ13ÈÕ¹²ÊÕ¼Çå¾²Îó²î58¸ö£¬£¬£¬£¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Graphics×é¼þȨÏÞÌáÉýÎó²î£»£»£»£»Microsoft Chakra¾ç±¾ÒýÇæCVE-2018-0980ÄÚ´æÆÆËðÎó²î£»£»£»£»Microsoft Excel CVE-2018-1026Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»Microsoft WindowsǶÈëʽ×ÖÌåÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»Microsoft Windows 'HTTP.sys'¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£ ¡£¡£¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ˼¿ÆÎó²î£¨CVE-2018-0171£©±»ºÚ¿ÍʹÓ㬣¬£¬£¬£¬ £¬È«ÇòÁè¼Ý20Íǫ̀·ÓÉÆ÷ÖÐÕУ»£»£»£»Ñо¿Ö°Ô±·¢Ã÷ÓÃÓÚ·Ö·¢¶ñÒâÈí¼þIcedIDºÍRovnixµÄ´¹ÂÚ¹¥»÷»î¶¯£»£»£»£»Sodexo FilmologyÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬ £¬²¿·ÖÓû§µÄÐÅÓÿ¨ÐÅϢй¶£»£»£»£»Ê¥Âí¶¡µºµÄ»ù´¡ÉèÊ©Ôâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬ £¬¹«¹²Ð§Àͱ»ÆÈÖÐÖ¹£»£»£»£»Ñо¿ÍŶӳÆÁè¼Ý6.5Íò¸ö·ÓÉÆ÷Ϊ½©Ê¬ÍøÂçºÍAPTÌṩ¶ñÒâÁ÷Á¿¡£¡£¡£¡£ ¡£¡£¡£

        ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬ £¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£ ¡£¡£¡£


¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí
1¡¢Microsoft Windows Graphics×é¼þȨÏÞÌáÉýÎó²î

        Microsoft Graphics×é¼þ×Ö¶ÎÆÊÎö±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬ £¬ÌáÉýȨÏÞ¡£¡£¡£¡£ ¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1008
2¡¢Microsoft Chakra¾ç±¾ÒýÇæCVE-2018-0980ÄÚ´æÆÆËðÎó²î

        Microsoft Edge´¦Öóͷ£WEBÇëÇó±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâWEBÒ³£¬£¬£¬£¬£¬ £¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬ £¬¿Éʹ³ÌÐòÍ߽⻣»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0980
3¡¢Microsoft Excel CVE-2018-1026Ô¶³Ì´úÂëÖ´ÐÐÎó²î

        Microsoft Excel´¦Öóͷ£Äڴ湤¾ß·½·¨Öб£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþ£¬£¬£¬£¬£¬ £¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬ £¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1026
4¡¢Microsoft WindowsǶÈëʽ×ÖÌåÔ¶³Ì´úÂëÖ´ÐÐÎó²î

        Microsoft Windows´¦Öóͷ£Ç¶Èëʽ×ÖÌå±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÍâµØ¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬ £¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1010
5¡¢Microsoft Windows 'HTTP.sys'¾Ü¾øÐ§ÀÍÎó²î

        Microsoft Windows HTTP.sys´¦Öóͷ£HTTP 2.0ÇëÇó±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬ £¬¾ÙÐоܾøÐ§À͹¥»÷¡£¡£¡£¡£ ¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0956


Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢Ë¼¿ÆÎó²î£¨CVE-2018-0171£©±»ºÚ¿ÍʹÓ㬣¬£¬£¬£¬ £¬È«ÇòÁè¼Ý20Íǫ̀·ÓÉÆ÷ÖÐÕÐ

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

        ºÚ¿ÍÍÅ»ïJHTʹÓÃ˼¿ÆÎó²î£¨CVE-2018-0171£©ÌᳫÁËÕë¶Ô¶íÂÞ˹ºÍÒÁÀʵÄÍøÂç»ù´¡ÉèÊ©µÄ¹¥»÷»î¶¯¡£¡£¡£¡£ ¡£¡£¡£¾Ý·͸É籨µÀ£¬£¬£¬£¬£¬ £¬ÒÁÀÊͨѶºÍÐÅÏ¢ÊÖÒÕ²¿ÌåÏÖÈ«ÇòÁè¼Ý20Íǫ̀·ÓÉÆ÷Êܵ½Ó°Ï죬£¬£¬£¬£¬ £¬ÆäÖаüÀ¨ÒÁÀʵÄ3500̨·ÓÉÆ÷¡£¡£¡£¡£ ¡£¡£¡£ÏÖÔÚÊÜÓ°ÏìµÄÒÁÀÊ·ÓÉÆ÷ÖÐ95%Òѻָ´Õý³£Ð§ÀÍ¡£¡£¡£¡£ ¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/iranian-and-russian-networks-attacked-using-ciscos-cve-2018-0171-vulnerability/

2¡¢Ñо¿Ö°Ô±·¢Ã÷ÓÃÓÚ·Ö·¢¶ñÒâÈí¼þIcedIDºÍRovnixµÄ´¹ÂÚ¹¥»÷»î¶¯

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

        ÔÚ2018Äê2ÔÂÏÂÑ®¼°Õû¸ö3ÔÂʱ´ú£¬£¬£¬£¬£¬ £¬Ë¼¿ÆÑо¿Ö°Ô±·¢Ã÷Ò»¸ö´¹ÂÚÓʼþ¹¥»÷»î¶¯£¬£¬£¬£¬£¬ £¬µ±Óû§·­¿ª°üÀ¨¶ñÒâºêµÄMicrosoft WordÎĵµ¸½¼þʱ£¬£¬£¬£¬£¬ £¬½«»áÏÂÔØ¶ñÒâÈí¼þRovnix£¬£¬£¬£¬£¬ £¬²¢ËæºóÏÂÔØÒøÐÐľÂíIcedID¡£¡£¡£¡£ ¡£¡£¡£ÁíÍ⣬£¬£¬£¬£¬ £¬ÉÐÓÐһЩÑù±¾»áÏÂÔØÒ»¸öBytecoinµÄ¶ñÒâÍÚ¿óÈí¼þ¡£¡£¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷IcedIDʹÓõļò»¯´úÂë×¢ÈëÊÖÒÕ±äµÃÔ½·¢ÄÑÒÔ¼ì²â¡£¡£¡£¡£ ¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://blogs.cisco.com/security/icedid-banking-trojan-teams-up-with-rovnix-for-distribution

3¡¢Sodexo FilmologyÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬ £¬²¿·ÖÓû§µÄÐÅÓÿ¨ÐÅϢй¶

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

        SodexoʳÎïЧÀͺÍÉèÊ©ÖÎÀí¹«Ë¾ÌåÏÖÆäÓ°Ï·¾íƽ̨FilmologyÔâµ½ÓÐÕë¶ÔÐԵĹ¥»÷£¬£¬£¬£¬£¬ £¬²¿·ÖÓû§µÄÐÅÓÿ¨ÐÅϢй¶¡£¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬ £¬ÕýÔÚ´ß´ÙÔÚ3ÔÂ19ÈÕÖÁ4ÔÂ3ÈÕʱ´úʹÓÃÁËFilmologyÍøÕ¾µÄÓû§¼ì²éÆäÒøÐп¨Õ˵¥¡£¡£¡£¡£ ¡£¡£¡£¸ÃÊÂÎñÏÖÔÚ»¹ÔÚ½øÒ»²½µÄÊÓ²ìÖ®ÖС£¡£¡£¡£ ¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/71211/data-breach/sodexo-filmology-data-breach.html

4¡¢Ê¥Âí¶¡µºµÄ»ù´¡ÉèÊ©Ôâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬ £¬¹«¹²Ð§Àͱ»ÆÈÖÐÖ¹

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

        ¾ÝÍâµØÃ½ÌåÖðÈÕÏÈÇý±¨±¨µÀ£¬£¬£¬£¬£¬ £¬4ÔÂ2ÈÕλÓÚ¼ÓÀձȺ£µÄºÉÀ¼ÊôÊ¥Âí¶¡µºÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬ £¬Õû¸öÕþ¸®µÄ»ù´¡ÉèÊ©±»ÆÈ¹Ø±Õ£¬£¬£¬£¬£¬ £¬µ¼Ö¹«¹²Ð§ÀÍÖÐÖ¹¡£¡£¡£¡£ ¡£¡£¡£×èÖ¹ÏÖÔÚ³ýÁËÃñʹҺŲ¿·ÖÍ⣬£¬£¬£¬£¬ £¬ÆäÓàÕþ¸®²¿·ÖÒѾ­»Ö¸´ÁËЧÀÍ¡£¡£¡£¡£ ¡£¡£¡£ÏÖÔÚûÓйØÓڴ˴ι¥»÷ÊÂÎñµÄ¸ü¶àϸ½Ú¡£¡£¡£¡£ ¡£¡£¡£Õþ¸®ÌåÏÖÕâÊÇÒ»ÄêÀ´±¬·¢µÄµÚ3Æð¹¥»÷ÊÂÎñ¡£¡£¡£¡£ ¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/71236/hacking/sint-maarten-cyber-attack.html

5¡¢Ñо¿ÍŶӳÆÁè¼Ý6.5Íò¸ö·ÓÉÆ÷Ϊ½©Ê¬ÍøÂçºÍAPTÌṩ¶ñÒâÁ÷Á¿

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

        AkamaiÐû²¼±¨¸æ³Æ¼ì²âµ½¹¥»÷ÕßʹÓÃÁè¼Ý6.5Íò¸ö·ÓÉÆ÷½¨ÉèµÄÊðÀíÍøÂçʵÑé¶àÖÖ²»·¨¹¥»÷»î¶¯¡£¡£¡£¡£ ¡£¡£¡£½©Ê¬ÍøÂçÔËÓªÕߺÍÍøÂçÌØ¹¤×éÖ¯ (APT) ±»Ö¸ÕýÔÚÀÄÓ÷ÓÉÆ÷ʹÓõÄͨÓü´²å¼´Óà (UPnP) ЭÒéÀ´ÊðÀí¶ñÒâÁ÷Á¿²¢¹æ±ÜÊÓ²ìÖ°Ô±Éó²éÕæÊµµØÀíλÖÃÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£²¢¼ì²âµ½Áè¼Ý480Íò¸ö·ÓÉÆ÷Ò×Êܵ½¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/over-65-000-home-routers-are-proxying-bad-traffic-for-botnets-apts/