΢ÈíÖÒÑÔAdob??e Type Manager¿âÖеÄÁ½¸öRCE 0day£»£»£»LenovoÐÞ¸´Ô¤×°ÖÃÈí¼þVantageÖеÄÌáȨÎó²î

Ðû²¼Ê±¼ä 2020-03-24

1.΢ÈíÖÒÑÔAdobe Type Manager¿âÖеÄÁ½¸öRCE 0day


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø



΢ÈíÐû²¼Ç徲ͨ¸æ£¬£¬ £¬ÖÒÑÔWindows Adobe Type Manager¿âÖеÄÁ½¸öRCE 0day£¬£¬ £¬ÕâÁ½¸öÎó²îÓ°ÏìÁËÄ¿½ñËùÓÐÊÜÖ§³ÖµÄWindowsºÍWindows Server°æ±¾¡£¡£¡£¡£¡£Îó²î±£´æÓÚAdobe Type Manager¿â´¦Öóͷ£Adobe Type 1 PostScript×ÖÌåÃûÌõķ½·¨ÖУ¬£¬ £¬¹¥»÷Õß¿ÉÒÔͨ¹ý¶àÖÖ·½·¨Ê¹ÓôËÎó²î£¬£¬ £¬ÀýÈç˵·þÓû§·­¿ª¶ñÒâÎĵµ»òÔÚWindowsÔ¤ÀÀ´°¸ñÖÐÉó²éËü¡£¡£¡£¡£¡£Î¢ÈíÒѾ­·¢Ã÷ʹÓôËÎó²îµÄÓÐÏÞÕë¶ÔÐÔ¹¥»÷¡£¡£¡£¡£¡£½¨ÒéÔÚWindows×ÊÔ´ÖÎÀíÆ÷ÖнûÓá°Ô¤ÀÀ´°¸ñ¡±ºÍ¡°ÏêϸÐÅÏ¢´°¸ñ¡±£¬£¬ £¬ÒÔ¼õÇáʹÓÃΣº¦£¬£¬ £¬ÁíÍâÁ½¸ö»º½â²½·¥ÊǽûÓÃWebClientЧÀͺÍÖØÃüÃû¡°ATMFD.DLL¡±¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200006


2.¼¸ÄÚÑÇÒé»áÑ¡¾Ùǰ»¥ÁªÍøÖÐÖ¹£¬£¬ £¬ÁªÍøÂʽöΪ12%


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ƾ֤NetBlocks»¥ÁªÍøÊÓ²ìÕ¾µÄÍøÂçÊý¾Ý£¬£¬ £¬3ÔÂ20ÈÕ¼¸ÄÚÑǹ²ºÍ¹úµÄ»¥ÁªÍø±»ÇжÏ£¬£¬ £¬¸Ã¹ú¼ÒÔ­¶¨ÓÚ3ÔÂ22ÈÕ£¨ÐÇÆÚÈÕ£©¾ÙÐÐÒé»áÑ¡¾ÙºÍÏÜ·¨¹«Í¶¡£¡£¡£¡£¡£ÊÖÒÕÖ¸±êÏÔʾ£¬£¬ £¬¸Ã¹ú¼ÒËùÓÐ6¸öÍøÂç¾ùÒѹرգ¨°üÀ¨Ö÷ÒªÔËÓªÉÌOrangeÔÚÄÚ£©£¬£¬ £¬»¥ÁªÍøÅþÁ¬Ë®Æ½½öΪͨ³£µÄ12%£¬£¬ £¬·äÎÑÍøÂçºÍ¹ÌÍøÒ²Êܵ½ÀàËÆµÄÓ°Ïì¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬¼¸ÄÚÑÇÓÚ3ÔÂ21ÈÕ£¨ÐÇÆÚÁù£©ÍíÉÏ8:00×îÏÈ·â±ÕÉ罻ýÌ壬£¬ £¬°üÀ¨Twitter¡¢FacebookºÍInstagram¾ù±»·â±Õ£¬£¬ £¬WhatAppЧÀÍÆ÷Ò²Êܵ½²¿·ÖÏÞÖÆ¡£¡£¡£¡£¡£·â±ÕÒ»Ö±Ò»Á¬ÁË36¸öСʱ£¬£¬ £¬Ö±µ½3ÔÂ23ÈÕ£¨ÐÇÆÚÒ»£©ÉÏÎç8:00²Å½â½û¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://netblocks.org/reports/internet-cut-across-guinea-ahead-of-elections-xAGoQxAz


3.Ameren SiouxºÍLabadieµç³§µÄ¹©Ó¦ÉÌÔâÀÕË÷Èí¼þ¹¥»÷


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÃÀ¹úÃÜËÕÀïÖÝAmeren SiouxºÍLabadieµç³§µÄ×°±¸¹©Ó¦ÉÌ£¨LTI Power Systems£©ÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬²¿·ÖÊý¾ÝÎļþ±»ÇÔ¡£¡£¡£¡£¡£ÕâЩÎļþ°üÀ¨Á½¼Òµç³§µÄ×°±¸Í¼ºÍʾÒâͼ£¬£¬ £¬ÀýÈç²»ÖÐÖ¹µçÔ´×°±¸µÄÏêϸԭÀíͼ£¬£¬ £¬¸Ã×°±¸ÓÃÓÚÔÚÖÐֹʱ´úÌṩÔÝʱ±¸ÓõçÔ´¡£¡£¡£¡£¡£Ê¥Â·Ò×˹¹«¹²¹ã²¥µç̨³ÆÕâЩÊý¾ÝÎļþµÄʱ¼äÔÚ1996ÄêÖÁ2017ÄêÖ®¼ä¡£¡£¡£¡£¡£ÎļþÖÐËÆºõ²»Éæ¼°¿Í»§ÐÅÏ¢¡£¡£¡£¡£¡£»£»£»ªÊ¢¶Ù´óÑ§ÍøÂçÇå¾²Õ½ÂÔÍýÏëµÄÈÏÕæÈËÇÇ¡¤ÉáÀÕ£¨Joe Scherrer£©ÌåÏÖ£¬£¬ £¬¸Ã¹¥»÷µÄÄ¿µÄÖ÷ÒªÊÇΪÁËÇÔȡ֪ʶ²úȨ¡£¡£¡£¡£¡£Ameren½²»°ÈËÌåÏָù«Ë¾ÕýÔÚ¶Ô´ËÊÂÎñ¾ÙÐÐÊӲ죬£¬ £¬²¢Ôö²¹³ÆÃ»ÓÐÀíÓÉÒÔΪй¶µÄÊý¾ÝÉæ¼°ÉñÃØ»ò¶ÔÆäÔËÓªÖÁ¹ØÖ÷Òª¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://news.stlpublicradio.org/post/ameren-missouri-equipment-supplier-targeted-ransomware-attack#stream/0


4.ÑÀÂò¼Ó¹ú¼ÒÒøÐÐÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬²¿·ÖЧÀÍÖÐÖ¹


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÑÀÂò¼Ó¹ú¼ÒÒøÐÐÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬¾¯ÆÓÖ±ÔÚ¾ÙÐÐÊӲ졣¡£¡£¡£¡£¸ÃÒøÐÐÌåÏÖ¹¥»÷±¬·¢ÔÚ3ÔÂ14ÈÕÐÇÆÚÁù£¬£¬ £¬¶ÔÆäЧÀÍÔì³ÉÁËһЩÖÐÖ¹£¬£¬ £¬µ«ÓÉÓÚÕË»§ÊÇÓɵ¥¶ÀµÄϵͳÉúÑĺͱ£»£»£»¤µÄ£¬£¬ £¬Òò´ËûÓпͻ§ÕÊ»§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£ÆäÐÅÏ¢ÊÖÒÕºÍÍøÂçÇå¾²ÍŶÓÁ¬Ã¦½ÓÄÉÐж¯×èÖ¹Á˶ñÒâÈí¼þ£¬£¬ £¬²¢ÊÔͼȷ¶¨¹¥»÷Ô´¡£¡£¡£¡£¡£ÏÖÔÚÆäЧÀÍ»ù±¾ÉÏÒѻָ´ÔÚÏߣ¬£¬ £¬µ«¸ÃÒøÐÐÈ·ÈϹ¥»÷ÕßÇÔÈ¡Á˲¿·Ö»áÔ±ºÍ¿Í»§µÄÊý¾Ý£¬£¬ £¬¸ÃÒøÐÐÕýÔÚ½ÓÄɲ½·¥Í¨ÖªÊܲ¨¼°µÄÓû§¡£¡£¡£¡£¡£ÓÉÓÚ¾¯·½ÊӲ컹ÔÚ¾ÙÐÐÖУ¬£¬ £¬¸ÃÒøÐÐûÓÐ͸¶¸ü¶àÐÅÏ¢¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.jamaicaobserver.com/latestnews/Police_investigate_ransomware_attack_at_Jamaica_National


5.¹¥»÷ÕßʹÓÃEnigmaSparkÕë¶ÔÖж«£¬£¬ £¬ÓëµØÔµÕþÖÎÓйØ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


IBM X-ForceÍŶӷ¢Ã÷·Ö·¢EnigmaSparkºóÃŵÄй¥»÷»î¶¯£¬£¬ £¬¸Ã»î¶¯¿ÉÄܳöÓÚÕþÖÎÄîÍ·£¬£¬ £¬ËƺõÓë×èµ²×î½üµÄÖж«Çå¾²ÍýÏëÓйء£¡£¡£¡£¡£¹¥»÷ÕßÊÔͼÃé×¼¶ÔÖж«Çå¾²ÍýÏëÓÐÖØ´óÐËȤ»òÌṩ֧³ÖµÄ×éÖ¯/»ú¹¹µÄÍøÂçÇéÐΣ¬£¬ £¬Í¨¹ýÈ«ÐÄÖÆ×÷µÄ¡¢ÏêϸµÄ¡¢¾ßÓÐÕþÖÎÖ¸¿ØµÄÓÕ¶üÎļþ£¬£¬ £¬ÉøÍ¸ÊÕ¼þÈ˵ÄÇéÐβ¢¾ÙÐÐÊý¾ÝÇÔÈ¡µÈ¶ñÒâ»î¶¯¡£¡£¡£¡£¡£EnigmaSparkµÄÓÕ¶üÎĵµÓëÒÔǰ·Ö·¢JhoneRATµÄÓÕ¶üÎĵµ¾ßÓÐÍêÈ«ÏàͬµÄ±àÒëÈÕÆÚ/ʱ¼ä£¨2020-01-14 07:54:00£©£¬£¬ £¬²¢ÇÒÔÚTTP¡¢Õë¶ÔÐÔÉ϶¼¾ßÓÐÏàËÆÖ®´¦£¬£¬ £¬Òò´ËEnigmaSpark»î¶¯¿ÉÄÜÓëJhoneRATÓйØ£¬£¬ £¬²¢ÇÒ¶¼¿ÉÄÜÊôÓÚ·¸·¨ÍÅ»ïMolerats¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityintelligence.com/posts/EnigmaSpark-Politically-Themed-Cyber-Activity-Highlights-Regional-Opposition-to-Middle-East-Peace-Plan/


6.LenovoÐÞ¸´Ô¤×°ÖÃÈí¼þVantageÖеÄÌáȨÎó²î


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


LenovoÐÞ¸´ÆäPCԤװÖÃÈí¼þVantageÖеÄÁ½¸öÌáȨÎó²î£¨CVE-2020-8319ºÍCVE-2020-8324£©¡£¡£¡£¡£¡£Vantage×Ô2016Äê×óÓÒÐû²¼ÒÔÀ´£¬£¬ £¬È¡´úÁËLenovo Solutions Center£¨LSC£©³ÉΪLenovo×°±¸µÄÍÆ¼öƽ̨ÖÎÀíºÍϵͳ¸üй¤¾ß¡£¡£¡£¡£¡£VantageÒÀÀµÓÚϵͳ½Ó¿Ú»ù´¡Ð§ÀÍ£¬£¬ £¬¸ÃЧÀÍͨ¹ýÖØ´óµÄ²å¼þϵͳִÐÐÖÖÖÖåÚÏëÌØ¶¨µÄÐÐΪ¡£¡£¡£¡£¡£ÓÉÓÚûÓжԲå¼þ×Ô¼º¼ÓÔØµÄDLLÖ´ÐÐÖ¤Êé¼ì²é£¬£¬ £¬Òò´Ë¿ÉÒÔͨ¹ýÌæ»»TouchScreenContronlDLL.dll»ñµÃSYSTEMȨÏÞ¡£¡£¡£¡£¡£½¨ÒéÓû§½«Vantage¸üÐÂÖÁ×îа汾¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.pentestpartners.com/security-blog/privesc-in-lenovo-vantage-two-minutes-later/