ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ41ÖÜ

Ðû²¼Ê±¼ä 2018-10-15

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2018Äê10ÔÂ08ÈÕÖÁ14ÈÕ¹²ÊÕ¼Çå¾²Îó²î58¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Win32k CVE-2018-8497ȨÏÞÌáÉýÎó²î £»£»£»£»Microsoft Azure IoT SDKÔ¶³ÌÖ´ÐдúÂëÎó²î £»£»£»£»D-Link Central WiFi Manager CVE-2018-17442í§Òâ´úÂëÖ´ÐÐÎó²î £»£»£»£»Auto-Maskin DCU-210E/RP-210EδÊÚȨ»á¼ûÎó²î £»£»£»£»Foxit Reader/PhantomPDF JavaScriptÒýÇæ¶à¸öÊͷźóʹÓôúÂëÖ´ÐÐÎó²î¡£ ¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇNorth American Risk Services¹«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬²¿·Ö¿Í»§µÄÐÅϢй¶ £»£»£»£»ÉæÏÓÕÚÑÚ50ÍòÓû§Êý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬¹È¸è½«¹Ø±ÕÉç½»ÍøÂçGoogle+ £»£»£»£»½ðÑÅÍØµÄ±¨¸æÅú×¢2018ÉϰëÄêÈ«Çò¹²±¬·¢945ÆðÊý¾Ýй¶ÊÂÎñ £»£»£»£»¿¨°Í˹»ùÐû²¼¹ØÓÚWindows 0day(CVE-2018-8453)µÄ¸ü¶àÊÖÒÕϸ½Ú £»£»£»£»Ñо¿ÍŶӷ¢Ã÷NotPetyaºÍIndustroyerÓë·¸·¨ÍÅ»ïTeleBots±£´æ¹ØÁª¡£ ¡£¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£ ¡£¡£¡£¡£¡£¡£¡£




¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí


1. Microsoft Windows Win32k CVE-2018-8497ȨÏÞÌáÉýÎó²î
Microsoft Windows Win32kÄں˴¦Öóͷ£±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬ÌáÉýȨÏÞ¡£ ¡£¡£¡£¡£¡£¡£¡£
https://portal.msrc.microsoft.com/zh-cn/security-guidance/advisory/CVE-2018-8497


2. Microsoft Azure IoT SDKÔ¶³ÌÖ´ÐдúÂëÎó²î
Microsoft Azure IoT SDKʹÓÃMQTTЭÒé±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£¡£¡£
https://portal.msrc.microsoft.com/zh-cn/security-guidance/advisory/CVE-2018-8531


3. D-Link Central WiFi Manager CVE-2018-17442í§Òâ´úÂëÖ´ÐÐÎó²î
D-Link Central WiFi Manager´¦Öóͷ£ÎļþÉÏ´«±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄRARÎļþ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£¡£¡£
https://securityadvisories.dlink.com/announcement/publication.aspx?name=SAP10092


4. Auto-Maskin DCU-210E/RP-210EδÊÚȨ»á¼ûÎó²î
Auto-Maskin DCU-210EºÍRP-210EʹÓÃroot/amrootÓ²±àÂ룬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬Î´ÊÚȨ»á¼û£¬£¬£¬£¬£¬£¬£¬£¬²¢Ð޸Ĺ̼þÖеÄí§Òâ¶þ½øÖÆÎļþ»òÉèÖÃÎļþ¡£ ¡£¡£¡£¡£¡£¡£¡£
https://www.kb.cert.org/vuls/id/176301


5. Foxit Reader/PhantomPDF JavaScriptÒýÇæ¶à¸öÊͷźóʹÓôúÂëÖ´ÐÐÎó²î
Foxit Reader/PhantomPDF JavaScriptÒýÇæ´¦Öóͷ£PDFÎļþ±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄPDFÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ £»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£¡£¡£
https://www.foxitsoftware.com/support/security-bulletins.php




Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢North American Risk Services¹«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬²¿·Ö¿Í»§µÄÐÅϢй¶


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


±±ÃÀΣº¦Ð§À͹«Ë¾£¨NARS£©ÔÚ2ÔÂ7ÈÕÖÁ3ÔÂ27ÈÕʱ´úÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Î´¾­ÊÚȨµÄ¹¥»÷Õß»á¼ûÁ˹«Ë¾µÄ²¿·Öµç×ÓÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼610Ãû¿Í»§µÄСÎÒ˽¼ÒÐÅϢй¶¡£ ¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢Éç±£ºÅÂë¡¢¼ÝÕÕID¡¢ÒøÐÐÕË»§ÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢¡¢¿µ½¡°ü¹ÜÐÅÏ¢¡¢ÄÉ˰ÈËʶÓÖÃûÒÔ¼°Óû§Ãû/ÃÜÂëµÈ¡£ ¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¿Í»§¶¼Î»ÓÚ¼ÓÖÝ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÕýÔÚÏòÕâЩ¿Í»§·¢ËÍÏà¹ØÍ¨Öª¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://news.softpedia.com/news/hundreds-of-california-residents-affected-by-north-american-risk-services-breach-523086.shtml


2¡¢ÉæÏÓÕÚÑÚ50ÍòÓû§Êý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬¹È¸è½«¹Ø±ÕÉç½»ÍøÂçGoogle+

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ƾ֤¹È¸èµÄ±¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬Google+µÄPeople APIÖб£´æÒ»¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔÊÐíµÚÈý·½¿ª·¢Õß»á¼ûÁè¼Ý50ÍòÓû§µÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨Óû§Ãû¡¢µç×ÓÓʼþµØµã¡¢Ö°Òµ¡¢³öÉúÈÕÆÚ¡¢Ð¡ÎÒ˽¼Ò×ÊÁÏÕÕÆ¬ÒÔ¼°ÐÔ±ðµÈÐÅÏ¢¡£ ¡£¡£¡£¡£¡£¡£¡£¹È¸èÔÚ2018Äê3Ô·¢Ã÷²¢ÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾Ñ¡Ôñ²»Ïò¹«ÖÚÅû¶´ËÊÂÎñ¡£ ¡£¡£¡£¡£¡£¡£¡£³ýÁËÈϿɴËÊý¾Ýй¶ÊÂÎñÖ®Í⣬£¬£¬£¬£¬£¬£¬£¬¹È¸è»¹Ðû²¼½«¹Ø±ÕGoogle+¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2018/10/google-plus-shutdown.html


3¡¢½ðÑÅÍØµÄ±¨¸æÅú×¢2018ÉϰëÄêÈ«Çò¹²±¬·¢945ÆðÊý¾Ýй¶ÊÂÎñ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ƾ֤½ðÑÅÍØµÄ×îÐÂÑо¿£¬£¬£¬£¬£¬£¬£¬£¬2018ÉϰëÄêÈ«Çò¹²±¬·¢945ÆðÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬¹²ÓÐ45ÒÚÌõÊý¾Ý¼Í¼Ô⵽й¶¡£ ¡£¡£¡£¡£¡£¡£¡£Óë2017ÄêͬÆÚÏà±È£¬£¬£¬£¬£¬£¬£¬£¬É¥Ê§¡¢±»ÇÔÒÔ¼°Ð¹Â¶µÄÊý¾ÝÔöÌíÁË133%¡£ ¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÊý¾Ýй¶ÊÂÎñµÄÊýÄ¿ÂÔÓÐϽµ£¬£¬£¬£¬£¬£¬£¬£¬µ«ÊÂÎñµÄÑÏÖØË®Æ½ÓÐËùÔöÌí¡£ ¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ6ÆðÉ罻ýÌåÊý¾Ýй¶ÊÂÎñµ¼ÖÂÁËÁè¼Ý56%µÄÊý¾Ýй¶¡£ ¡£¡£¡£¡£¡£¡£¡£Êý¾Ýй¶µÄ×î³£¼ûÔµ¹ÊÔ­ÓÉÊÇÍⲿÒòËØ£¨Õ¼56%£©¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2018/10/09/data-breaches-2018/


4¡¢¿¨°Í˹»ùÐû²¼¹ØÓÚWindows 0day(CVE-2018-8453)µÄ¸ü¶àÊÖÒÕϸ½Ú


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¿¨°Í˹»ùʵÑéÊÒÓÚ2018Äê8ÔÂ17ÈÕÏò΢Èí±¨¸æÁËWindows 0day£¨CVE-2018-8453£©£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÒÑÔÚ΢ÈíµÄ10ÔÂÇå¾²¸üÐÂÖлñµÃÐÞ¸´¡£ ¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÖ÷Òª±»APT×éÖ¯FruityArmorËùʹÓ㬣¬£¬£¬£¬£¬£¬£¬ÓÃÀ´¹¥»÷Öж«µØÇøµÄÄ¿µÄ¡£ ¡£¡£¡£¡£¡£¡£¡£Æä¹¥»÷»î¶¯ÊǸ߶ÈÕë¶ÔÐԵ쬣¬£¬£¬£¬£¬£¬£¬Êܺ¦ÕßµÄÊýÄ¿²»Áè¼Ý12¸ö¡£ ¡£¡£¡£¡£¡£¡£¡£Ñо¿ÍŶÓÄæÏòÁ˲¶»ñµ½µÄÎó²îʹÓÃÑù±¾£¬£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäÖØÐ´ÎªÍêÕûµÄPoC¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://securelist.com/cve-2018-8453-used-in-targeted-attacks/88151/


5¡¢Ñо¿ÍŶӷ¢Ã÷NotPetyaºÍIndustroyerÓë·¸·¨ÍÅ»ïTeleBots±£´æ¹ØÁª


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ESETÑо¿ÍŶӷ¢Ã÷¶ñÒâÈí¼þNotPetyaºÍºóÃÅIndustroyerÓë·¸·¨ÍÅ»ïTeleBots±£´æ¹ØÁª¡£ ¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö¶ñÒâÈí¼þ¶¼±»ÓÃÓÚ¹¥»÷ÎÚ¿ËÀ¼µÄÄ¿µÄ¡£ ¡£¡£¡£¡£¡£¡£¡£Ñо¿ÍŶÓ̫ͨ¹ýÎöTeleBotsʹÓõÄкóÃÅWin32/ExaramelÈ·ÈÏÁËÕâЩÁªÏµ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÕâ֮ǰÑо¿ÍŶÓÖ»ÄÜÍÆ²âËüÃǵĹØÁª¡£ ¡£¡£¡£¡£¡£¡£¡£ÐµÄÖ¤¾ÝÅú×¢£¬£¬£¬£¬£¬£¬£¬£¬ExaramelºÍIndustroyerÖ®¼ä¾ßÓкÜÇ¿µÄ´úÂëÏàËÆÐÔºÍÐÐΪ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅËüÃÇÀ´×ÔÓÚͳһ¿ª·¢Õß¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-backdoor-ties-notpetya-and-industroyer-to-telebots-group/


ÉùÃ÷£º±¾×ÊѶÓÉ¿­·¢k8άËûÃüÇ徲С×é·­ÒëºÍÕûÀí