ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ50ÖÜ

Ðû²¼Ê±¼ä 2021-12-13

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼Äþ¾²Â©¶´60¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache Log4j2ÈÎÒâ´úÂëÖ´ÐЩ¶´£»Tencent WeChat WXAM DecoderÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´£»Google golang ForrkExec¾Ü¾ø·þÎñ©¶´£»Mozilla Firefox file picker dialogÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´£»Veritas Enterprise Vault CVE-2021-44680´úÂëÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇmagnatÀûÓÃαÔìµÄWeChatµÈ°²×°·¨Ê½·Ö·¢ºóÃÅ£»MailGuard·¢ÏÖÒÔ΢ÈíÀ¬»øÓʼþ֪ͨΪÖ÷ÌâµÄµöÓã»î¶¯£»Googleµ·»Ù¿ØÖÆ×ÅÁè¼Ý100Íǫ̀É豸µÄ½©Ê¬ÍøÂçGlupteba£»SonicWallÐû²¼¸üУ¬ÐÞ¸´SMA 100ϵÁÐÖжà¸ö©¶´£»ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLab·þÎñÆ÷¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. Apache Log4j2ÈÎÒâ´úÂëÖ´ÐЩ¶´


Apache Log4j2´æÔÚJava JNDI×¢È멶´£¬µ±·¨Ê½½«Óû§ÊäÈëµÄÊý¾Ý½øÐÐÈÕÖ¾¼Ç¼£¬¼´¿É´¥·¢´Ë©¶´£¬ÀÖ³ÉÀûÓôË©¶´¿ÉÒÔÔÚÄ¿±ê·þÎñÆ÷ÉÏÖ´ÐÐÈÎÒâ´úÂë¡£


https://github.com/apache/logging-log4j2/commit/7fe72d6


2. Tencent WeChat WXAM DecoderÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´


Tencent WeChat WXAM Decoder´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.zerodayinitiative.com/advisories/ZDI-21-1446/


3. Google golang ForrkExec¾Ü¾ø·þÎñ©¶´


Google golang ForrkExec´¦ÖôæÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹ·þÎñ·¨Ê½Í߽⣬Ôì³É¾Ü¾ø·þÎñ¹¥»÷¡£


https://github.com/golang/go/commit/99950270f3cf52cccc6966d8668ff21b573bb6f5


4. Mozilla Firefox file picker dialogÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´


Mozilla Firefox file picker dialog´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄwebÒ³ÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.mozilla.org/en-US/security/advisories/mfsa2021-48/


5. SVeritas Enterprise Vault CVE-2021-44680´úÂëÖ´ÐЩ¶´


Veritas Enterprise VaultÓ¦ÓÃÆô¶¯·þÎñ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.veritas.com/content/support/en_US/security/VTS21-003



>ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢magnatÀûÓÃαÔìµÄWeChatµÈ°²×°·¨Ê½·Ö·¢ºóÃÅ


Cisco TalosÔÚ12ÔÂ3ÈÕ¹ûÈ»ÁËmagnatµÄ¹¥»÷»î¶¯¡£´Ë´Î¹¥»÷ʼÓÚ2018Äêµ×£¬×Ô2021Äê4ÔÂÒÔÀ´µ½´ï·åÖµ£¬Ö÷ÒªÕë¶Ô¼ÓÄôó£¬Æä´ÎÊÇÃÀ¹ú¡¢°Ä´óÀûÑÇ¡¢Òâ´óÀû¡¢Î÷°àÑÀ¡¢Å²ÍþµÈ¹ú¡£¹¥»÷ÕßÀûÓÃαÔìµÄViber¡¢WeChat¡¢NoxPlayerºÍBattlefieldµÈÓ¦ÓúÍÓÎÏ·µÄ°²×°·¨Ê½£¬ÓÕʹĿ±êÏÂÔغóÃÅ·¨Ê½ºÍ¶ñÒâChromeÀ©Õ¹·¨Ê½£¬×îÖÕ»áÇÔȡƾ¾Ý¡¢ÏµÍ³ÖеÄÃô¸ÐÊý¾ÝÒÔ¼°Ô¶³Ì·ÃÎÊȨÏÞ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/12/magnat-campaigns-use-malvertising-to.html


2¡¢MailGuard·¢ÏÖÒÔ΢ÈíÀ¬»øÓʼþ֪ͨΪÖ÷ÌâµÄµöÓã»î¶¯


ÓʼþÄþ¾²¹«Ë¾MailGuardÔÚ12ÔÂ2ÈÕ·¢ÏÖÒÔ΢ÈíÀ¬»øÓʼþ֪ͨΪÖ÷ÌâµÄµöÓã»î¶¯¡£ÕâЩÓʼþ·¢ËÍ×Ôquarantine[at]messaging.microsoft.com£¬ÏÔʾµÄÃû³ÆÊÇÊÕ¼þÈ˵ÄÓò£¬Í¨¹ýÕâÖÖ·½Ê½À´Ôö¼ÓÆä¿ÉÐŶÈ¡£¸ÃµöÓãÓʼþÌáʾĿ±êÓб»¸ôÀëµÄÀ¬»øÓʼþ£¬µ±Ä¿±êµã»÷¼ì²ìºó»á±»Öض¨Ïòµ½µöÓãÍøÕ¾²¢±»ÒªÇóÊäÈëOffice 365ƾ֤¡£Î¢Èí¹«Ë¾ÔÚ8Ô·Ý͸¶£¬×Ô2020Äê7Ô¿ªÊ¼µÄÓã²æʽµöÓã»î¶¯¶à´ÎÕë¶ÔOffice 365Óû§¡£


Ô­ÎÄÁ´½Ó£º

https://www.mailguard.com.au/blog/scammers-mimic-microsoft-with-spam-notification-phishing-email


3¡¢Googleµ·»Ù¿ØÖÆ×ÅÁè¼Ý100Íǫ̀É豸µÄ½©Ê¬ÍøÂçGlupteba


GoogleÔÚ12ÔÂ7ÈÕÐû²¼ÆäÒѵ·»Ù¿ØÖÆ×ÅÁè¼Ý100Íǫ̀É豸µÄ½©Ê¬ÍøÂçGlupteba¡£Glupteba×Ô2011ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬ÊÇÒ»ÖÖÖ§³ÖÇø¿éÁ´µÄÄ£¿é»¯¶ñÒâÈí¼þ£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢Ó¡¶È¡¢°ÍÎ÷ºÍ¶«ÄÏÑǵĹú¼Ò£¬Ã¿ÌìÐÂÔöѬȾÉ豸µÄÊýÁ¿¸ß´ïÊýǧ̨¡£¸Ã½©Ê¬ÍøÂçÖ÷Ҫͨ¹ýÆƽâ»òµÁ°æÈí¼þºÍPPI·½°¸Á÷´«£¬Ñ¬È¾Ä¿±êºó»áÇÔÈ¡¼ÓÃÜ»õ±Ò¡¢Óû§Æ¾¾ÝºÍcookie£¬²¢ÔÚÄ¿±êÉ豸Éϲ¿ÊðÊðÀí£¬Ëæºó³öÊÛ¸øÆäËû¹¥»÷Õß¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-disrupts-massive-glupteba-botnet-sues-russian-operators/


4¡¢SonicWallÐû²¼¸üУ¬ÐÞ¸´SMA 100ϵÁÐÖжà¸ö©¶´


SonicWallÔÚ12ÔÂ7ÈÕÐû²¼¸üУ¬ÐÞ¸´SMA 100ϵÁÐÉ豸ÖеĶà¸ö©¶´¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖصÄ©¶´ÊÇ»ùÓÚ¶ÑÕ»µÄ»º³åÇøÒç³ö©¶´£¨CVE-2021-20038£©£¬CVSSÆÀ·ÖΪ9.8£¬ÓÉÓÚÉ豸µÄApache httpd·þÎñÆ÷ÖеÄHTTP GETÒªÁìµÄ»·¾³±äÁ¿Ê¹ÓÃÁËstrcat()º¯Êýµ¼ÖµÄ£»Æä´ÎÊÇ»º³åÇøÒç³ö©¶´£¨CVE-2021-20045£©£¬CVSSÆÀ·Ö9.4¡£´ËÍ⣬»¹ÐÞ¸´ÁË»º³åÇøÒç³ö©¶´£¨CVE-2021-20043£©ºÍÈÏÖ¤ÃüÁî×¢È멶´£¨CVE-2021-20039£©µÈ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.cisa.gov/uscert/ncas/current-activity/2021/12/08/sonicwall-releases-security-advisory-sma-100-series-appliances


5¡¢ÐÂÀÕË÷Èí¼þCerberÃé×¼ConfluenceºÍGitLab·þÎñÆ÷


12ÔÂ7ÈÕ£¬Ñо¿ÈËÔ±·¢ÏÖʹÓÃÁ˾ÉÃû³ÆµÄÐÂÀÕË÷Èí¼þCerber¡£ÀÕË÷Èí¼þCerberÓÚ2016Äê·ºÆð£¬Ö±µ½2019Äêµ×Ïûʧ¡£´ÓÉϸöÔ¿ªÊ¼£¬Cerbe»Ø¹é£¬µ«ÊÇËüÓë¾É°æ²¢²»Ïàͬ£¬´úÂ벻ƥÅ䣬аæʹÓÃCrypto+++¿â¶ø¾É°æ±¾Ê¹ÓÃWindows CryptoAPI¿â£¬¶øÇҾɰæCerberҲûÓÐLinux±äÌå¡£ÐÂCerberµÄÊê½ðÒªÇó´Ó1000ÃÀÔªµ½3000ÃÀÔª²»µÈ£¬ÀûÓÃÁËCVE-2021-26084ºÍCVE-2021-22205©¶´Ãé×¼ConfluenceºÍGitLab·þÎñÆ÷£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢µÂ¹úºÍÖйú¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-cerber-ransomware-targets-confluence-and-gitlab-servers/