¡¾Â©¶´Í¨¸æ¡¿Trend Micro Apex One 7Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2021-07-30

0x00 ©¶´¸ÅÊö

Apex OneÊÇTrend Micro¿ª·¢µÄÒ»Ì×Äܹ»Ìṩ×Ô¶¯Íþв¼ì²âºÍÏìÓ¦¹¦Ð§µÄ¶ËµãÄþ¾²·À»¤Èí¼þ¡£

2021Äê7ÔÂ28ÈÕ £¬Trend Micro£¨Ç÷ÊÆ¿Æ¼¼£©Ðû²¼Äþ¾²Í¨¸æ £¬¹ûÈ»ÁËÆäApex One ºÍApex One as a Service£¨Apex One SaaS£©ÖеĶà¸öÄþ¾²Â©¶´ £¬¹¥»÷Õß¿ÉÒÔͨ¹ýÀûÓÃÕâЩ©¶´ÈƹýÉí·ÝÈÏÖ¤¡¢ÉÏ´«ÈÎÒâÎļþ¡¢ÌáÉýȨÏÞ»òÖ´ÐÐÆäËüδÊÚȨ²Ù×÷¡£Ä¿Ç° £¬ÆäÖв¿ÃÅ©¶´ÒѾ­¼ì²âµ½ÔÚÒ°ÀûÓá£

 

0x01 ©¶´ÏêÇé

image.png

±¾´Î¹ûÈ»µÄ4¸ö©¶´ÖÐ £¬CVE-2021-32464ºÍCVE-2021-36742¿Éµ±µØÀûÓà £¬CVE-2021-32465ºÍCVE-2021-36741¿ÉÔ¶³ÌÀûÓà £¬ËüÃǵÄ©¶´ÆÀ¼¶¾ùΪ¸ßΣ¡£ÆäÏêÇéÈçÏ£º

Apex OneȨÏÞÌáÉý©¶´£¨CVE-2021-32464£©

ÓÉÓÚȨÏÞ·ÖÅä²»ÕýÈ· £¬Apex One ºÍApex One as a ServiceÖдæÔÚȨÏÞÌáÉý©¶´ £¬¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´ÔÚÖ´ÐÐÌØ¶¨½Å±¾Ö®Ç°¶ÔÆä½øÐÐÐÞ¸Ä £¬µ«¹¥»÷Õß±ØÐëÊ×ÏÈ»ñµÃÔÚÄ¿±êϵͳÉϽϵÍȨÏ޵ĴúÂëÖ´ÐÐÄÜÁ¦¡£¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.8¡£

 

Apex OneÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¨CVE-2021-32465£©

ÓÉÓÚApex OneºÍApex One as a ServiceÖдæÔÚÒ»¸ö²»ÕýÈ·µÄȨÏÞ±£Áô©¶´ £¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´ÔÚÄ¿±êϵͳÉÏÖ´Ðй¥»÷²¢ÈƹýÉí·ÝÑéÖ¤ £¬µ«¹¥»÷Õß±ØÐëÊ×ÏÈ»ñµÃÔÚÄ¿±êϵͳÉϽϵÍȨÏ޵ĴúÂëÖ´ÐÐÄÜÁ¦¡£¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.5¡£

 

Apex OneÈÎÒâÎļþÉÏ´«Â©¶´£¨CVE-2021-36741£©

ÓÉÓÚApex OneºÍApex One as a ServiceÖдæÔÚÒ»¸ö²»ÕýÈ·µÄÊäÈëÑé֤©¶´ £¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´ÔÚÄ¿±êϵͳÉÏÉÏ´«ÈÎÒâÎļþ £¬µ«¹¥»÷Õß±ØÐëÊ×ÏÈ»ñµÃµÇ¼¸Ã²úÎï¹ÜÀí¿ØÖÆÌ¨µÄÄÜÁ¦¡£¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.1 £¬Ä¿Ç°ÒѾ­¼ì²âµ½ÔÚÒ°ÀûÓá£

 

Apex Oneµ±µØÌáȨ©¶´£¨CVE-2021-36742£©

ÓÉÓÚApex OneºÍApex One as a ServiceÖдæÔÚÒ»¸ö²»ÕýÈ·µÄÊäÈëÑé֤©¶´ £¬¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´ÔÚÄ¿±êϵͳÉÏʵÏÖµ±µØÌáÉýȨÏÞ £¬µ«¹¥»÷Õß±ØÐëÊ×ÏÈ»ñµÃÔÚÄ¿±êϵͳÉϽϵÍȨÏ޵ĴúÂëÖ´ÐÐÄÜÁ¦¡£¸Ã©¶´µÄCVSSv3ÆÀ·ÖΪ7.8 £¬Ä¿Ç°ÒѾ­¼ì²âµ½ÔÚÒ°ÀûÓá£

 

Ó°Ï췶Χ

Trend Micro Apex One 2019 (On-prem)£¨Windows£©

Trend Micro Apex One SaaS£¨Windows£©

 

0x02 ´¦Öý¨Òé

ĿǰÕâЩ©¶´ÒѾ­ÐÞ¸´¡£¼øÓÚ²¿ÃÅ©¶´ÒѾ­·ºÆðÔÚÒ°ÀûÓà £¬½¨ÒéÊÜÓ°ÏìµÄ¿Í»§¼°Ê±°²×°ÒÔϲ¹¶¡£º

Apex One (on-prem)  CP 9601²¹¶¡

Apex One as a Service (SaaS)  2021 Äê 7 ÔÂÔ¶Ȳ¹¶¡

ÏÂÔØÁ´½Ó£º

https://success.trendmicro.com/solution/000287819

 

0x03 ²Î¿¼Á´½Ó

https://success.trendmicro.com/solution/000287819

https://www.trendmicro.com/en_ca/business/products/downloads.html

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32464

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-07-30

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¹Ø×¢ÒÔϹ«ÖںŠ£¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png   image.png