ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ13ÖÜ
Ðû²¼Ê±¼ä 2021-03-29> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2021Äê03ÔÂ22ÈÕÖÁ03ÔÂ28ÈÕ¹²ÊÕ¼Çå¾²Îó²î61¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇRusavtomatika Weintek EasyWeb cMT CVE-2021-27446´úÂë×¢ÈëÎó²î£»£»£»£»XStream CVE-2021-21346·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î£»£»£»£»Foxit PhantomPDF U3DBrowserÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î£»£»£»£»NETGEAR ProSAFE Network Management System MFileUploadControllerÎļþÉÏ´«Îó²î£»£»£»£»Apache SpamAssassin .cf×¢ÈëÎó²î¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇESET·¢Ã÷ºÚ¿ÍʹÓÃαÔìµÄClubhouse·Ö·¢BlackRock£»£»£»£»McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro±£´æ¶à¸öÎó²î£»£»£»£»²®Ã÷º²Òé»áÔ±¹¤Òò²Ù×÷ʧÎó¹ûÕæ´ó×ÚÈõÊÆÈºÌåµÄСÎÒ˽¼ÒÐÅÏ¢£»£»£»£»KasperskyÐû²¼2020ÄêICSÐÐÒµµÄÌ¬ÊÆÆÊÎö±¨¸æ£»£»£»£»Î¢ÈíÖÒÑÔ½üÆÚ´¹ÂڻÒÑÇÔÈ¡40Íò¸öOWAºÍOffice 365ƾ֤¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Rusavtomatika Weintek EasyWeb cMT CVE-2021-27446´úÂë×¢ÈëÎó²î
Rusavtomatika Weintek EasyWeb cMT±£´æ´úÂë×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÒÔROOTÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-082-01
2.XStream CVE-2021-21346·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î
XStream±£´æ·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
http://x-stream.github.io/changes.html#1.4.16
3.Foxit PhantomPDF U3DBrowserÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î
Foxit PhantomPDF U3DBrowser±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-353/
4.NETGEAR ProSAFE Network Management System MFileUploadControllerÎļþÉÏ´«Îó²î
NETGEAR ProSAFE Network Management System MFileUploadController±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÉÏ´«Îļþ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-357/
5.Apache SpamAssassin .cf×¢ÈëÎó²î
Apache SpamAssassin±£´æ.cf×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿É×¢Èë¶ñÒâÏÂÁî²¢Ö´ÐС£¡£¡£¡£¡£
https://s.apache.org/3r1wh
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢ESET·¢Ã÷ºÚ¿ÍʹÓÃαÔìµÄClubhouse·Ö·¢BlackRock

ÉÏÖÜÎ壬£¬£¬£¬£¬£¬£¬£¬ESETµÄÑо¿Ö°Ô±·¢Ã÷ºÚ¿ÍʹÓÃαÔìµÄAndroid°æClubhouse·Ö·¢BlackRock Trojan¡£¡£¡£¡£¡£ClubhouseÊÇÒôƵ̸ÌìÓ¦Ó㬣¬£¬£¬£¬£¬£¬£¬µ«ÏÖÔÚÖ»ÔÚiOSÊÜÆÇ°¿ÉÓ㬣¬£¬£¬£¬£¬£¬£¬ÉÐδÐû²¼Android°æ±¾µÄClubhouse¡£¡£¡£¡£¡£BlackRock×î³õÓÚ2020Äê5Ô±»·¢Ã÷£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡Óû§ÔÚÖÖÖÖ»¥ÁªÍøÓ¦Óã¨Áè¼Ý458¸ö£©ÉϵÄÐÅÏ¢¡£¡£¡£¡£¡£¸ÃľÂíÄܹ»×èµ²ºÍ¸Ä¶¯SMSÐÂÎÅ¡¢Òþ²ØÍ¨Öª¡¢ÔÚÓû§ÔËÐÐɱ¶¾Èí¼þʱ½«ÆäÖØ¶¨Ïòµ½×°±¸Ö÷ÆÁÄ»ºÍÔ¶³ÌËø¶¨ÆÁÄ»¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/fraudsters-jump-on-clubhouse-hype-to-push-malicious-android-app/
2¡¢McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro±£´æ¶à¸öÎó²î

McAfeeÅû¶Զ³Ì¼à¿ØÈí¼þNetop Vision Pro±£´æ¶à¸ö¿ÉÓÃÀ´Ð®ÖÆÄ¿µÄµçÄÔµÄÎó²î¡£¡£¡£¡£¡£ÕâЩÎó²î»®·ÖΪȨÏÞ·ÖÅÉÎó²î£¨CVE-2021-27192£©¡¢Ä¬ÈÏȨÏÞ¹ýʧ£¨CVE-2021-27193£©¡¢ÒÔÃ÷ÎÄ´«ÊäµÄÃô¸ÐÐÅÏ¢£¨CVE-2021-27194£©ºÍÊÚȨÎÊÌ⣨CVE-2021-27195£©¡£¡£¡£¡£¡£ºÚ¿Í¿ÉÓÃÕâЩÎó²î¾ÙÐÐÌáȨºÍÖ´ÐÐÔ¶³Ì´úÂ룬£¬£¬£¬£¬£¬£¬£¬»ñµÃ¶ÔÄ¿µÄϵͳµÄÍêÈ«¿ØÖÆÈ¨²¢ÆôÓÃÍøÂçÉãÏñÍ·ºÍÂó¿Ë·ç¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬NetopÒÑÐÞ¸´²¿·ÖÎó²î¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/popular-remote-student-learning-program-found-to-be-riddled-with-security-holes/
3¡¢²®Ã÷º²Òé»áÔ±¹¤Òò²Ù×÷ʧÎó¹ûÕæ´ó×ÚÈõÊÆÈºÌåµÄСÎÒ˽¼ÒÐÅÏ¢

²®Ã÷º²Òé»áÔÚ3ÔÂ19ÈÕÐÇÆÚÎ峯£¬£¬£¬£¬£¬£¬£¬£¬ÒòÔ±¹¤²Ù×÷ʧÎóµ¼Ö´ó×ÚÈõÊÆÈºÌåµÄСÎÒ˽¼ÒÐÅÏ¢±»¹ûÕæ¡£¡£¡£¡£¡£¾Ý³Æ´Ë´Îй¶µÄÊÇÓÐȨ»ñµÃÃâ·Ñ°ÍʿͨÐÐÖ¤µÄ¶ùͯµÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¸ÃÊÐÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÔÚ·¢Ã÷й¶ºóÁ¬Ã¦½ÓÄÉÁ˲½·¥£¬£¬£¬£¬£¬£¬£¬£¬Êý¾Ý»¹Î´±»ÏÂÔØ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÓÉÓÚ´ËÊÂÎñµÄ¹æÄ£ºÍÑÏÖØÐÔ×Ó£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÒÑ֪ͨÈÏÕæ¼àÊÓµÄÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.birminghammail.co.uk/news/midlands-news/details-vulnerable-kids-uploaded-birmingham-20217314
4¡¢KasperskyÐû²¼2020ÄêICSÐÐÒµµÄÌ¬ÊÆÆÊÎö±¨¸æ

KasperskyÐû²¼ÁË2020ÄêICSÐÐÒµµÄÌ¬ÊÆÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¸Ã±¨¸æÆÊÎöÁËÓÃÓÚÉè¼Æ¡¢ÉèÖúÍά»¤¹¤Òµ¿ØÖÆ×°±¸ºÍÈí¼þµÄÅÌËã»úËùÊܵ½µÄÍøÂçÍþв¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ2020ÄêϰëÄ꣬£¬£¬£¬£¬£¬£¬£¬ÔÚICS¹¤³ÌºÍ¼¯³ÉÐÐÒµÖÐ39.3£¥µÄÅÌËã»úÊܵ½Á˶ñÒâÈí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Óë2020ÄêÉϰëÄ꣨31.5£¥£©Ïà±ÈÓÐËùÔöÌí£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÐÞ½¨×Ô¶¯»¯¡¢Æû³µÖÆÔì¡¢ÄÜԴʯÓͺÍ×ÔÈ»ÆøÐÐÒµÔâµ½µÄ¹¥»÷Ôö¶à¡£¡£¡£¡£¡£2020ÄêϰëÄ꣬£¬£¬£¬£¬£¬£¬£¬Õë¶ÔÀ¶¡ÃÀÖÞ¡¢Öж«¡¢ÑÇÖ޺ͱ±ÃÀµÄ¹¥»÷´ÎÊýÔö¶à£¬£¬£¬£¬£¬£¬£¬£¬Õë¶Ô·ÇÖÞ¡¢¶íÂÞ˹ºÍÅ·Ö޵Ĺ¥»÷ÊýÄ¿ÓÐËùïÔÌ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://ics-cert.kaspersky.com/reports/2021/03/17/threat-landscape-for-the-ics-engineering-and-integration-sector-2020/
5¡¢Î¢ÈíÖÒÑÔ½üÆÚ´¹ÂڻÒÑÇÔÈ¡40Íò¸öOWAºÍOffice 365ƾ֤

×ÔÈ¥Äê12ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬´¹ÂڻÒÑÇÔÈ¡40Íò¸öOWAºÍOffice 365ƾ֤¡£¡£¡£¡£¡£WMC GlobalÓÚÈ¥ÄêÄêÍ··¢Ã÷¸Ã´¹Âڻ£¬£¬£¬£¬£¬£¬£¬£¬Î±×°³Éαװ³ÉÊÓÆµ¾Û»áЧÀÍ¡¢Çå¾²½â¾ö¼Æ»®ºÍÉú²ú¹¤¾ßÀ´ÒÉ»óÊܺ¦Õß¡£¡£¡£¡£¡£È¥Äê12Ô£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Íð³äÁËOutlook Web AppÀ´ÓÕÆÄ¿µÄÓû§ÊäÈëÆ¾Ö¤£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÄê1Ô¸ÄΪģÄâOffice 365À´ÇÔȡƾ֤¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Î¢Èí·¢Ã÷¸Ã»î¶¯»¹Ê¹ÓÃÁËAmazon Simple Email Service£¨SES£©ºÍAppspotÔÆÅÌËãÆ½Ì¨À´·¢ËÍÍøÂç´¹ÂÚµç×ÓÓʼþ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-warns-of-phishing-attacks-bypassing-email-gateways/


¾©¹«Íø°²±¸11010802024551ºÅ