ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ22ÖÜ

Ðû²¼Ê±¼ä 2021-05-31

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê05ÔÂ24ÈÕÖÁ05ÔÂ30ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´62¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApple Safari CVE-2021-30749ÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´£»Google Chrome CVE-2021-30521 Autofill¶ÑÒç³ö©¶´£»MesaLabs AmegaViewĬÈÏCOOKIEÑéÖ¤Èƹý©¶´£»CommScope Ruckus IoT ControllerÓ²±àÂëAPIÃÜԿ©¶´£»IBM WebSphere Exteme Scale apache synapse´úÂëÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǵçÉÌƽ̨Mercari³ÆÆäÊܵ½Codecov¹©Ó¦Á´¹¥»÷Ó°Ï죻Unit 42Ðû²¼ÓйØÀÕË÷Èí¼þ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËߣ»AppleÐû²¼Äþ¾²¸üУ¬ÐÞ¸´3¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day£»Ñо¿ÈËÔ±³ÆWindows IIS·þÎñÆ÷ÖеÄ©¶´¿ÉÓ°ÏìWinRM£»VMwareÐû²¼Äþ¾²¸üУ¬ÐÞ¸´vCenterÖÐÑÏÖصÄRCE©¶´¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


> ÖØÒªÄþ¾²Â©¶´Áбí


1.Apple Safari CVE-2021-30749ÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´


Apple Safari´æÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿É¶ÔÓ¦Ó÷¨Ê½½øÐоܾø·þÎñ¹¥»÷»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://support.apple.com/en-us/HT212529


2.Google Chrome CVE-2021-30521 Autofill¶ÑÒç³ö©¶´


Google Chrome Autofill´æÔÚ¶ÑÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë»ò¶ÔÓ¦Ó÷¨Ê½½øÐоܾø·þÎñ¹¥»÷¡£

https://chromereleases.googleblog.com/2021/05/stable-channel-update-for-desktop_25.html


3.MesaLabs AmegaViewĬÈÏCOOKIEÑéÖ¤Èƹý©¶´


MesaLabs AmegaView´æÔÚĬÈÏCOOKIE©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎÊÓ¦Óá£

https://us-cert.cisa.gov/ics/advisories/icsa-21-147-03


4.CommScope Ruckus IoT ControllerÓ²±àÂëAPIÃÜԿ©¶´


CommScope Ruckus IoT Controller OVAÓ³ÏñÎļþ´æÔÚAPIÃÜԿ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éͨ¹ýAPIÖ´ÐйҽÓÎļþϵͳ¡£

https://packetstormsecurity.com/files/162843/CommScope-Ruckus-IoT-Controller-1.7.1.0-Hard-Coded-API-Keys-Exposed.html


5.IBM WebSphere Exteme Scale apache synapse´úÂëÖ´ÐЩ¶´


IBM WebSphere Exteme Scale apache synapseÐòÁл¯¹¤¾ß´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-websphere-extreme-scale-liberty-deployment/


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢µçÉÌƽ̨Mercari³ÆÆäÊܵ½Codecov¹©Ó¦Á´¹¥»÷Ó°Ïì


1.jpg


µçÉÌƽ̨Mercari³ÆÆäÊܵ½Codecov¹©Ó¦Á´¹¥»÷µÄÓ°Ï죬´óÁ¿¿Í»§ÐÅϢй¶¡£MercariÊÇÒ»¼ÒÈÕ±¾ÉÏÊй«Ë¾£¬½ØÖÁ2017Ä꣬ÆäÓ¦Ó÷¨Ê½ÔÚÈ«ÇòµÄÏÂÔØÁ¿ÒÑÁè¼Ý1ÒڴΡ£´Ë´Îʼþй¶ÁË17085ÌõÉæ¼°¿Í»§ÕÊ»§µÄÐÅÏ¢£¬°üÂÞÒøÐдúÂë¡¢·ÖÐдúÂë¡¢ÕʺźͳÖÓÐÈ˵È£»7966ÌõMercariºÍMerpayºÏ×÷»ï°éµÄÐÅÏ¢£¬°üÂÞÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Á¥Êô¹ØϵºÍÓʼþµØÖ·µÈ£»ÒÔ¼°2615ÌõÔ±¹¤ÐÅÏ¢µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/e-commerce-giant-suffers-major-data-breach-in-codecov-incident/


2¡¢Unit 42Ðû²¼ÓйØÀÕË÷Èí¼þ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß


2.jpg


Unit 42Ðû²¼ÁËÓйØÀÕË÷Èí¼þ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬ÔÚ¹ýÈ¥µÄ¼¸ÄêÖУ¬ÀÕË÷¹¥»÷»î¶¯µÄÊýÁ¿¼±¾çÉÏÉý¡£2020ÄêÖ§¸¶µÄƽ¾ùÊê½ðÁè¼Ý31.2ÍòÃÀÔª£¬±È2019ÄêÔö³¤ÁË171£¥£¬µ½Ä¿Ç°ÎªÖ¹£¬ÕâÒ»Êý×ÖÓÖÔö³¤Á˽üÁ½±¶£¬µ½´ï85ÍòÃÀÔª¡£¶ø¶ÔÓÚ´óÐÍÆóÒµ£¬Êê½ð½ð¶îƽ¾ù½Ó½ü300ÍòÃÀÔª¡£È¥Äê×î¸ßµÄÊê½ð½ð¶î´Ó1500ÍòÃÀÔªÔö¼Óµ½3000ÍòÃÀÔª£¬ÏÖÔÚÄêÔò¸ß´ï5000ÍòÃÀÔª¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/breaking-down-ransomware-attacks/


3¡¢AppleÐû²¼Äþ¾²¸üУ¬ÐÞ¸´3¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day


3.jpg


Æ»¹ûÒѾ­Ðû²¼ÁËÄþ¾²¸üУ¬ÐÞ²¹3¸öÒѱ»ÔÚÒ°ÀûÓõÄmacOSºÍtvOS 0day¡£ÆäÖеÄÁ½¸öÊÇÄÚ´æËð»µÂ©¶´£¨CVE-2021-30663ºÍCVE-2021-30665£©£¬Ó°ÏìÁËApple TV 4KºÍApple TV HDÉ豸¡£µÚÈý¸öÊÇTCC¿ò¼ÜÖеÄÌáȨ©¶´£¬Ó°ÏìÁËmacOS Big SurÉ豸£¬ÏÖÒѱ»XCSSET¶ñÒâÈí¼þÓÃÀ´ÈƹýmacOSÒþ˽±£»¤¡£±¾Ô³õ£¬Apple»¹ÐÞ¸´ÁËWebkitÒýÇæÖеÄÁ½¸öiOS 0day¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apple-fixes-three-zero-days-one-abused-by-xcsset-macos-malware/


4¡¢Ñо¿ÈËÔ±³ÆWindows IIS·þÎñÆ÷ÖеÄ©¶´¿ÉÓ°ÏìWinRM


4.jpg


Ñо¿ÈËÔ±im DeVries³ÆWindows IIS·þÎñÆ÷ÖеÄ©¶´¿ÉÓ°ÏìWinRM¡£¸Ã©¶´ÊÇWindows IIS·þÎñÆ÷ʹÓõÄHTTPЭÒéÕ»£¨http.sys£©ÖеÄÔ¶³ÌÖ´ÐдúÂ멶´£¬±»×·×ÙΪCVE-2021-31166£¬ÒÑͨ¹ýMicrosoftÐû²¼µÄ5Ô·ÝÄþ¾²¸üÐÂÐÞ¸´¡£ÉÏÖÜÄ©£¬Axel SouchetÐû²¼Á˸鶴µÄPoC£¬¿ÉÀûÓÃÌØÖƵÄÊý¾Ý°üµ¼ÖÂÀ¶ÆÁËÀ»ú¡£µ«ÊÇ£¬Jim DeVries·¢ÏÖËü»¹»áÓ°ÏìÔËÐÐÁËWinRM·þÎñ£¨WindowsÔ¶³Ì¹ÜÀí£©µÄWindows 10ϵͳºÍ·þÎñÆ÷¡£Will Dormann³Æ£¬ÓÐÁè¼Ý200Íò¸öWinRM·þÎñ̻¶µÄWindowsϵͳ¿ÉÒÔͨ¹ýInternet·ÃÎÊ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118189/security/cve-2021-31166-windows-http-flaw.html


5¡¢VMwareÐû²¼Äþ¾²¸üУ¬ÐÞ¸´vCenterÖÐÑÏÖصÄRCE©¶´


5.jpg


VMwareÐû²¼Äþ¾²¸üУ¬ÐÞ¸´vCenterÖÐÑÏÖصÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Â©¶´¡£¸Ã©¶´±»×·×ÙΪCVE-2021-21985£¬CVSSv3ÆÀ·ÖΪ9.8£¬Ó°ÏìÁËvCenter Server 6.5¡¢6.7ºÍ7.0¡£Â©¶´ÊÇÓÉÓÚVirtual SANÔËÐÐ×´¿ö¼ì²é²å¼þÖÐȱÉÙÊäÈëÑéÖ¤µ¼ÖµÄ£¬¾ßÓÐ443¶Ë¿Ú·ÃÎÊȨµÄ¹¥»÷Õß¿ÉÒÔÀûÓÃÆäÖ´ÐÐÈÎÒâÃüÁî¡£VMware³Æ£¬ËùÓÐvCenter Server£¬ÎÞÂÛÆäÊÇ·ñʹÓÃvSAN£¬¶¼Ä¬ÈÏÆôÓÃÁËVirtual SANÔËÐÐ×´¿ö¼ì²é²å¼þ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/vmware-warns-of-critical-bug-affecting-all-vcenter-server-installs/