ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ20ÖÜ

Ðû²¼Ê±¼ä 2019-05-20

±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö



2019Äê5ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼Çå¾²Îó²î74¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Remote Desktop Services CVE-2019-0708Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£» £» £»£»Adobe Media Encoder CVE-2019-7842ÊͷźóʹÓÃÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£» £» £»£» Facebook WhatsApp CVE-2019-3568»º³åÇøÒç³öÎó²î£»£»£»£» £» £»£»Apple Safari¶à¸öÄÚ´æÆÆËðí§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£» £» £»£»Adobe AcrobatºÍReader¶à¸öÊͷźóʹÓôúÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ΢ÈíÐÞ¸´79¸öÎó²î£¬£¬£¬£¬£¬£¬£¬°üÀ¨RDPÖеÄRCEÎó²î£¨CVE-2019-0708£©£»£»£»£» £» £»£»¹¥»÷ÕßʹÓûªË¶ÖÐÐÄÈ˹¥»÷·Ö·¢PleadºóÃÅ£»£»£»£» £» £»£»Stack OverflowÐû²¼Í¨¸æ³ÆÆäÔâºÚ¿ÍÈëÇÖ£»£»£»£» £» £»£»Î´ÉèÃÜÂëµÄÊý¾Ý¿âй¶½ü90%°ÍÄÃÂí¹«ÃñÐÅÏ¢£»£»£»£» £» £»£»¶íÂÞ˹ºÚ¿Í×éÖ¯³öÊÛÃÀ¹ú3´ó·´²¡¶¾¹«Ë¾Ô´Âë¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£



Ö÷ÒªÇå¾²Îó²îÁбí



1. Microsoft Windows Remote Desktop Services CVE-2019-0708Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Microsoft Windows Remote Desktop Services´¦Öóͷ£Äڴ湤¾ß±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄRDPÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£» £» £»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708

2. Adobe Media Encoder CVE-2019-7842ÊͷźóʹÓÃÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Adobe Media Encoder´¦Öóͷ£Îļþ±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£» £» £»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/media-encoder/apsb19-29.html

3. Facebook WhatsApp CVE-2019-3568»º³åÇøÒç³öÎó²î
Facebook WhatsApp±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://www.facebook.com/security/advisories/cve-2019-3568

4. Apple Safari¶à¸öÄÚ´æÆÆËðí§Òâ´úÂëÖ´ÐÐÎó²î
Apple Safari WebKit±£´æ¶à¸öÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³ÇëÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://support.apple.com/zh-cn/HT210123

5. Adobe AcrobatºÍReader¶à¸öÊͷźóʹÓôúÂëÖ´ÐÐÎó²î
Adobe AcrobatºÍReader±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³ÇëÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£» £» £»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/acrobat/apsb19-18.html


Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö



1¡¢Î¢ÈíÐÞ¸´79¸öÎó²î£¬£¬£¬£¬£¬£¬£¬°üÀ¨RDPÖеÄRCEÎó²î£¨CVE-2019-0708£©

¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Öܶþ΢ÈíÐû²¼5ÔÂWindowsÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´79¸öÎó²î¡£¡£¡£¡£¡£¡£ÆäÖаüÀ¨RDPЧÀÍÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0708£©£¬£¬£¬£¬£¬£¬£¬´ËÎó²îÊÇÔ¤Éí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ룻£»£»£» £» £»£»ÌáȨ0day£¨CVE-2019-0863£©£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¹¥»÷ÕßÌáÉýÖÁÖÎÀíԱȨÏÞ£»£»£»£» £» £»£»Õë¶ÔIntel CPU MDS¹¥»÷µÄÎó²îÐÞ¸´£¬£¬£¬£¬£¬£¬£¬ÕâЩÎó²îÓ°ÏìÁË2011ÄêÒÔÀ´ÏÕЩËùÓеÄIntel CPU¡£¡£¡£¡£¡£¡£ÍêÕûÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-may-2019-patch-tuesday-arrives-with-fix-for-windows-zero-day-mds-attacks/

2¡¢¹¥»÷ÕßʹÓûªË¶ÖÐÐÄÈ˹¥»÷·Ö·¢PleadºóÃÅ


¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


4ÔÂβESETÑо¿Ö°Ô±ÊӲ쵽ʹÓá°AsusWSPanel.exe¡±·Ö·¢PleadºóÃŵĹ¥»÷»î¶¯¡£¡£¡£¡£¡£¡£AsusWSPanel.exeÊÇ»ªË¶Ôƴ洢ЧÀÍWebStorageµÄWindows¿Í»§¶Ë¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±¸ø³öÁËÁ½ÖÖ¿ÉÄܵĹ¥»÷³¡¾°£¬£¬£¬£¬£¬£¬£¬Ò»ÖÖÊÇ»ªË¶Ôâµ½¹©Ó¦Á´¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÁíÒ»ÖÖÊǹ¥»÷ÕßʹÓÃÖÐÐÄÈ˹¥»÷ºÍÒ×Êܹ¥»÷µÄ·ÓÉÆ÷À´Èö²¥¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£½øÒ»²½µÄÆÊÎöºóÑо¿Ö°Ô±ÒÔΪºóÒ»ÖÖ¹¥»÷³¡¾°µÄ¿ÉÄÜÐÔ¸ü´ó¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/bad-actors-using-mitm-attacks-against-asus-to-distribute-plead-backdoor/

3¡¢Stack OverflowÐû²¼Í¨¸æ³ÆÆäÔâºÚ¿ÍÈëÇÖ


¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


5ÔÂ16ÈÕStack OverflowÐû²¼ÁËÒ»Ìõ¼ò¶ÌµÄͨ¸æ£¬£¬£¬£¬£¬£¬£¬³Æ5ÔÂ11ÈÕºÚ¿ÍÈëÇÖÁËÆäÉú²úϵͳ¡£¡£¡£¡£¡£¡£Æ¾Ö¤Stack Overflow¹¤³Ì¸±×ܲÃMary FergusonµÄ˵·¨£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í»ñµÃÁËÒ»¶¨Ë®Æ½µÄÉú²úϵͳ»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬Stack Overflow·¢Ã÷²¢ÊÓ²ìÁË»á¼ûµÄ¹æÄ££¬£¬£¬£¬£¬£¬£¬²¢ÇÒÐÞ¸´ÁËËùÓеÄÒÑÖªÎó²î¡£¡£¡£¡£¡£¡£ÊÓ²ìûÓз¢Ã÷ºÚ¿Í»ñµÃÓû§Êý¾ÝµÄÈκÎÖ¤¾Ý¡£¡£¡£¡£¡£¡£ÏÖÔÚÊÓ²ìÕýÔÚ¾ÙÐÐÖУ¬£¬£¬£¬£¬£¬£¬Òò´ËStack Overflow²¢Î´Åû¶¸ü¶àϸ½Ú¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/stack-overflow-says-hackers-breached-production-systems/

4¡¢Î´ÉèÃÜÂëµÄÊý¾Ý¿âй¶½ü90%°ÍÄÃÂí¹«ÃñÐÅÏ¢


¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Çå¾²Ñо¿Ô±Bob DiachenkoʹÓÃShodanÔÚAWSÉÏ·¢Ã÷Ò»¸öδÊܱ£»£»£»£» £» £»£»¤µÄElasticsearchÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âй¶ÁËÊý°ÙÍò°ÍÄÃÂí¹«ÃñµÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄ±íÊö£¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨3427396Ìõ±êǩΪ¡°»¼Õß¡±µÄ¼Í¼ÒÔ¼°468086Ìõ±êǩΪ¡°²âÊÔ»¼Õß¡±µÄ¼Í¼¡£¡£¡£¡£¡£¡£ÕâЩÐÅÏ¢°üÀ¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éí·ÝÖ¤ºÅÂë¡¢µØµã¡¢ÓÊÏäºÍµç»°ºÅÂëµÈ¡£¡£¡£¡£¡£¡£ÈôÊÇÊý¾ÝûÓÐÖØ¸´£¬£¬£¬£¬£¬£¬£¬ÕâЩ¼Í¼Լռ¸Ã¹ú×ÜÉú³ÝµÄ90%¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/sensitive-information-of-millions-of-panama-citizens-leaked/

5¡¢¶íÂÞ˹ºÚ¿Í×éÖ¯³öÊÛÃÀ¹ú3´ó·´²¡¶¾¹«Ë¾Ô´Âë


¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×Ô3Ô·ÝÒÔÀ´£¬£¬£¬£¬£¬£¬£¬¶íÂÞ˹ºÚ¿ÍÍÅ»ïFxmspÔÚµØÏÂÂÛ̳ÉÏÐû³Æ³öÊÛÈý¼ÒÃÀ¹ú·´²¡¶¾¹«Ë¾µÄÈí¼þ²úÆ·Ô´ÂëºÍ¹«Ë¾ÍøÂç»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£ÆðÔ´µÄ¼ÛÇ®ÊÇ»á¼ûȨÏÞ25ÍòÃÀÔª£¬£¬£¬£¬£¬£¬£¬Ô´´úÂë15ÍòÃÀÔª£¬£¬£¬£¬£¬£¬£¬µ«±¨¼Û²¢²»Àο¿¡£¡£¡£¡£¡£¡£Fxmsp²¢Î´Ö¸³öÏêϸµÄ¹«Ë¾Ãû³Æ£¬£¬£¬£¬£¬£¬£¬µ«ÌṩÁ˰üÀ¨30TBÊý¾ÝµÄÎļþ¼Ð½ØÆÁ£¬£¬£¬£¬£¬£¬£¬¾Ý³ÆÕâЩÊý¾Ý°üÀ¨¿ª·¢Îĵµ¡¢È˹¤ÖÇÄÜÄ£×Ó¡¢WebÇå¾²Èí¼þºÍ·´²¡¶¾Èí¼þµÄ´úÂëµÈ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-selling-access-and-source-code-from-antivirus-companies/