ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ41ÖÜ

Ðû²¼Ê±¼ä 2020-10-13

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê10ÔÂ05ÈÕÖÁ10ÔÂ11ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Android Qualcomm±ÕÔ´×é¼þCVE-2020-3654´úÂëÖ´ÐЩ¶´£»Google Android Qualcomm±ÕÔ´×é¼þCVE-2020-3657´úÂëÖ´ÐЩ¶´£»Google Android system×é¼þCVE-2020-0416´úÂëÖ´ÐЩ¶´£»D-Link DAP-136 IP²ÎÊýÃüÁîÖ´ÐЩ¶´£»Facebook WhatsApp RTP ExtensionÕ»Òç³ö©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ£ºCISAÐû²¼2019²ÆÄê·çÏÕ©¶´ÆÀ¹ÀµÄÐÅϢͼ£»Äþ¾²¹«Ë¾Arctic WolfÐû²¼Äþ¾²ÔËÓªÄê¶È³ÂËߣ»GoogleÐû²¼µÄChromeÄþ¾²¸üÐÂÐÞ¸´¶à¸ö©¶´£»AdobeÒò·þÎñÖжϵ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud£»Android°æFacebookÖдæÔÚ©¶´£¬»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí


1.Google Android Qualcomm±ÕÔ´×é¼þCVE-2020-3654´úÂëÖ´ÐЩ¶´


Google Android Qualcomm±ÕÔ´×é¼þʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹ·þÎñ·¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://source.android.com/security/bulletin/2020-10-01


2.Google Android Qualcomm±ÕÔ´×é¼þCVE-2020-3657´úÂëÖ´ÐЩ¶´


Google Android Qualcomm±ÕÔ´×é¼þʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹ·þÎñ·¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://source.android.com/security/bulletin/2020-10-01


3.Google Android system×é¼þCVE-2020-0416´úÂëÖ´ÐЩ¶´


Google Android Framework×é¼þʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹ·þÎñ·¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://source.android.com/security/bulletin/2020-10-01


4.D-Link DAP-136 IP²ÎÊýÃüÁîÖ´ÐЩ¶´


D-Link DAP-136´¦ÖÃIP²ÎÊý´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî¡£

https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10191


5.Facebook WhatsApp RTP ExtensionÕ»Òç³ö©¶´


Facebook WhatsApp RTP Extension½âÎö´æÔÚÕ»Òç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.whatsapp.com/security/advisories/2020/


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢CISAÐû²¼2019²ÆÄê·çÏÕ©¶´ÆÀ¹ÀµÄÐÅϢͼ



1.png


ÍøÂçÄþ¾²ºÍÐÅÏ¢Äþ¾²»ú¹¹(CISA)Ðû²¼ÁË2019²ÆÄê½øÐеÄ44Ïî·çÏպͩ¶´ÆÀ¹À£¨RVA£©£¬ÒÔ¼°MITER·´¿¹¼ÆÄ±¡¢¼¼ÊõºÍ֪ʶ£¨ATT£¦CK£©¿ò¼ÜµÄ·ÖÎöÐÅϢͼ¡£¸ÃÐÅϢͼ±íÈ·¶¨ÁËCISAÔÚ¿ç¶à¸ö²¿ÃŵÄRVAsÆÚ¼äÊӲ쵽µÄͨÀýÀֳɹ¥»÷·¾¶£¬ÍøÂç¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ¹¥»÷;¾¶À´¹¥»÷×éÖ¯¡£CISAÃãÀøÍøÂç¹ÜÀíÔ±ºÍITרҵÈËÔ±¼ì²ìÐÅϢͼ²¢Ó¦ÓÃÍÆ¼öµÄ·ÀÓù¼ÆÄ±£¬ÒÔ·ÀÖ¹Êܵ½ÒÑÖªÕ½ÊõºÍ¼¼ÊõµÄ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/10/07/cisa-releases-fy2019-risk-vulnerability-assessment-infographic


2¡¢Äþ¾²¹«Ë¾Arctic WolfÐû²¼Äþ¾²ÔËÓªÄê¶È³ÂËß


2.png


Äþ¾²¹«Ë¾Arctic WolfÐû²¼ÁËÒ»·ÝÄþ¾²ÔËÓªÄê¶È³ÂËß¡£³ÂËßÏÔʾ£¬×Ô3ÔÂÒÔÀ´£¬°µÍøÉϹûÈ»µÄ¹«Ë¾Æ¾¾ÝÊýÁ¿Ôö¼ÓÁË429£¥¡£ÔÚÊӲ쵽µÄ¸ß·çÏÕÄþ¾²Ê¼þÖУ¬ÓÐ35£¥·¢ÉúÔÚ8:00 PMºÍ8:00 AMÖ®¼ä£¬¶ø14£¥·¢ÉúÔÚÖÜÄ©£¬ÕâÊÇÐí¶àÄÚ²¿Äþ¾²ÍŶӲ»ÔÚÏßµÄʱ¼ä¡£´ËÍâ£¬ÍøÂçµöÓãºÍÀÕË÷Èí¼þ¹¥»÷´ÎÊýÔö¼ÓÁË64£¥£¬ºÚ¿Í¸ü¶àµÄÒÔCOVID-19Ö÷ÌâΪÓÕ¶ü£¬À´Õë¶ÔÔ¶³ÌÊÂÇéÕß¡£


Ô­ÎÄÁ´½Ó£º

https://arcticwolf.com/resources/analyst-reports/security-operations-annual-report


3¡¢GoogleÐû²¼µÄChromeÄþ¾²¸üÐÂÐÞ¸´¶à¸ö©¶´


3.png


GoogleÐû²¼µÄChromeÄþ¾²¸üÐÂÕë¶ÔWindows¡¢MacºÍLinux°æ±¾ÐÞ¸´ÁË35¸ö©¶´¡£ÆäÖнÏΪÑÏÖØµÄ©¶´ÎªÖ§¸¶ÖеÄÊͷźóʹÓé¶´£¨CVE-2020-15967£©£¬Æä´ÎΪBlink¡¢WebRTC¡¢NFC¡¢´òÓ¡¡¢ÒôƵ¡¢×Ô¶¯Ìî³äºÍÃÜÂë¹ÜÀíÆ÷ÖеÄÊͷźóʹÓé¶´£¨CVE-2020-15968¡¢CVE-2020-15969¡¢CVE-2020-15970¡¢CVE-2020-15971¡¢CVE-2020-15972¡¢CVE-2020-15990ºÍCVE-2020-15991£©¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/10/07/google-releases-security-updates-chrome


4¡¢AdobeÒò·þÎñÖжϵ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud


4.png


AdobeÒò·þÎñÖжÏ£¬µ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud»ò·ÃÎÊÆä¶©ÔĵÄÓ¦Ó÷¨Ê½»ò´æ´¢µÄÊý¾Ý¡£×ÔÃÀ¹ú¶«²¿Ê±¼äÉÏÎç9:30ÒÔÀ´£¬Adobe Creative CloudÓû§¿ªÊ¼³ÂËßÎÞ·¨µÇ¼¸Ã·þÎñ»ò·ÃÎÊÉú´æµÄͼÏñºÍÊý¾Ý£¬µ±ËûÃÇÊÔͼµÇ¼µÄʱºò£¬¾Í»áÏÔʾ¡°·¢ÉúÁËһЩ´íÎó¡±µÄÌáʾ¡£Ä¿Ç°£¬AdobeÒÑÔÚstatus.adobe.comÒ³ÃæÉÏÐû²¼Í¨ÖªÈ·ÈÏÁËÖжÏ£¬µ«²¢Î´ÌṩÈκÎÓйش˴ÎÖжϵÄÏêϸÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/adobe-creative-cloud-down-users-report-login-data-access-issues/


5¡¢Android°æFacebookÖдæÔÚ©¶´£¬»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ


5.png


Äþ¾²Ñо¿Ô±Sayed Abdelhafiz·¢ÏÖ£¬Android°æFacebookÖдæÔÚÑÏÖØÂ©¶´£¬¸Ã©¶´»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬ÀûÓøÃ©¶´¿ÉÄܵ¼ÖÂÓ¦ÓÃÍß½âÒÔ¼°É豸½Ó¹Ü¡£FacebookÔÊÐíͨ¹ýÁ½ÖÖ·½Ê½ÏÂÔØÎļþ£¬ÆäÖÐÒ»ÖÖÊÇʹÓá°Îļþ¡±Ñ¡Ï£¬½«ÎļþÏÈÌáÈ¡µ½DownloadManager£¬È»ºóÉú´æµ½Download Director¡£Abdelhafiz·¢ÏÖ¿ÉÒÔ´´½¨²¢ÏÂÔØÒ»¸ö¶ñÒâÎļþ£¬È»ºóÔÚÄ¿±êÉ豸ÉÏÖ´ÐÐÈÎÒâ´úÂë¡£FacebookÔڵõ½Â©¶´³ÂËߺó£¬ÒÑÓÚ2020Äê6ÔÂÐÞ¸´Á˸é¶´¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/10/08/code-execution-vulnerability-found-in-facebook-for-android/