ÆØ¹â|Îó²îÆáºÚÉÁֵġ°Ç±¹æÔò¡±
2020-06-24
ƾ֤AG¹«Ë¾¿Æ¼¼Ðû²¼µÄ¡¶Îó²îÉú³¤Ç÷ÊÆ±¨¸æ¡·ÏÔʾ£¬ÓÉÓÚ¹¥»÷Ãż÷µÍ£¬Ê®ÄêÒÔÉϸßÁäÎó²îÔÚ¹¥»÷ÊÂÎñÖÐÈÔÈ»±»¹¥»÷Õß´ó×ÚʹÓá£

¹¥»÷ÊÂÎñʹÓõ½µÄÎó²î"ÄêËê"ÂþÑÜͼ
Ê®ÄêÒÔÉÏ“¸ßÁäÎó²î”ÎÞ·¨ÍËÐݱ³ºó£¬ÊÇ´ó×Úºã¾Ãδ¸üеÄÈí¼þºÍϵͳ
¹¥»÷ÊÂÎñÖÐʹÓõÄÎó²îºÍÏêϸµÄ²Ù×÷ϵͳÇéÐÎÏà¹Ø£¬ÈçÎïÀí¸ôÀëÇéÐÎϵÄÄÚÍø£¬¾Í¿ÉÄܱ£´æÃ»ÓÐʵʱ¸üв¹¶¡»ò°æ±¾µÄ½¹µãϵͳ¡¢Êý¾Ý¿â£¬¹¥»÷ÕßÒ»µ©½øÈëÄÚÍø¾Í¿ÉÒÔʹÓÃÕâЩ³ÉÊìµÄÎó²îʹÓôúÂëÌᳫÓÐÓõĹ¥»÷¡£×ÜÌåÀ´ËµËæ×Åʱ¼äµÄÍÆÒÆ£¬ÀϵÄÎó²î»áÒ»Ö±±»ÐÞ²¹£¬ÐµÄÎó²îÒ»Ö±±¬·¢£¬¹¥·ÀÖ®¼äµÄ¶Ô¿¹½«»áÒ»Ö±Ò»Á¬¡£
Ò»Äê65+Íò´Î¹¥»÷£¬²»ËÀµÄEternalBlue£¨ÓÀºãÖ®À¶£©
Îó²îʹÓÃÊǹ¥»÷µÄ³£ÓÃÊֶΣ¬Í¨¹ý¶ÔÎó²î¹¥»÷ÊÂÎñµÄ¼à²â¿ÉÒÔÕÆÎÕ¹¥»÷ÕßµÄÊÖÒÕÌØµã¡¢ÐÐΪϰ¹ß£¬½ø¶ø¿ÉÒÔ¶Ô¹¥»÷Õß¾ÙÐÐÐÐΪ»Ïñ£¬ÎªÎó²îÔ¤¾¯Ìṩ×ÊÖú¡£2017Äê4ÔÂShadowBrokersÐû²¼ÁËÕë¶ÔWindows²Ù×÷ϵͳÒÔ¼°ÆäËü·þÎñÆ÷ϵͳÈí¼þµÄ¶à¸ö¸ßΣÎó²îʹÓù¤¾ß¡£Í¬Äê5Ô£¬EternalBlue¹¤¾ß±»WannaCryÀÕË÷Èí¼þÈä³æÊ¹Óã¬ÔÚÈ«Çò¹æÄ£´ó±¬·¢£¬Ó°ÏìÁ˰üÀ¨ÖйúÔÚÄڵĶà¸ö¹ú¼Ò¡£EternalBlueÏà¹ØµÄÎó²îÖ÷ÒªÓÐCVE-2017-0144¡¢CVE-2017-0145ÒÔ¼°CVE-2017-0147£¬¶ÔÓ¦MicrosoftµÄÇ徲ͨ¸æMS17-010¡£
ƾ֤AG¹«Ë¾ÍþвÇ鱨ÖÐÐļà²âÊý¾ÝÏÔʾ£¬Ê¹ÓÃCVE-2017-0144µÄ¹¥»÷ÊÂÎñ¹²¼Æ4919441´Î£¬Ê¹ÓÃCVE-2017-0145µÄ¹¥»÷ÊÂÎñ¹²¼Æ27276´Î£¬Ê¹ÓÃCVE-2017-0147µÄ¹¥»÷ÊÂÎñ¹²¼Æ1567618´Î¡£¿ÉÒÔ¿´µ½ÔÚ2019ÄêÖУ¬Ê¹ÓÃÕâЩÎó²îµÄÍøÂç¹¥»÷Ò»Á¬»îÔ¾ÔÚÕæÊµÍøÂçÖС£

ʹÓÃEternalBlueÎó²îµÄ¹¥»÷ÊÂÎñ
ÈÃÇå¾²Îó²î¿É¿Ø£¬È«ÉúÃüÖÜÆÚÊÓ½ÇϵÄÈ䳿¼¶RDPÎó²î—CVE-2019-0708
2019Äê5Ô£¬MicrosoftÔÚµ±ÔµÄÇå¾²¸üÐÂÖУ¬¶ÔÒ»¸öеÄRDPÎó²îCVE-2019-0708Ðû²¼ÁËÖÒÑÔ£¬¸ÃÎó²î¿ÉÒÔ±»ÓÃ×÷È䳿¹¥»÷£¬8ÔÂÓÖÅû¶ÁËÁ½¸öÀàËÆ¿ÉÓÃ×÷È䳿µÄÎó²îCVE-2019-1181/1182¡£ËæºóµÄ9ÔÂÕë¶ÔCVE-2019-0708µÄ¿ÉʹÓù¥»÷¾ç±¾±»¹ûÕæ¡£×èÖ¹2020Äê3Ô£¬AG¹«Ë¾ÍþвÇ鱨ÖÐÐļà²âµ½Ïà¹Ø¹¥»÷ÊÂÎñ87211´Î¡£

ʹÓÃCVE-2019-0708Îó²îµÄ¹¥»÷ÊÂÎñ
ÔÚÎó²î¸ÕÅû¶µÄ5Ô·ݣ¬Îó²îµÄʱЧÐÔÇ¿£¬²¢·ÇËùÓÐÓû§¶¼ÊµÊ±ÐÞ¸´£¬Îó²îʹÓüÛÖµ¸ß£¬¹¥»÷×éÖ¯ÔÚÍøÂçÖÐÌᳫ¹¥»÷£¬¹¥»÷ÊÂÎñ·ºÆðÁ˶ÌÔݵķåÖµ¡£7Ô·ÝÎó²îʹÓõĴúÂë±»¹ûÕæ£¬¸ü¶àºÚ²ú¡¢¾ç±¾Ð¡×ӵȹ¥»÷Õß×îÏÈʹÓ㬹¥»÷ÊÂÎñÔٴηºÆð¿ìËÙÔöÌíµÄÇ÷ÊÆ¡£Ëæ×Ź¥»÷ÊÂÎñµÄÒ»Á¬±¬·¢£¬Ô½À´Ô½¶àµÄÓû§×îÏȸüв¹¶¡¡¢ÐÞ¸´Îó²î£¬Õë¶Ô¸ÃÎó²îµÄ¹¥»÷ÊÂÎñÖð½¥Ï½µ¡£
¹¥»÷Õß¹Ø×¢Îȹ̡¢¸ßЧµÄÎó²îʹÓÃÊÖÒÕ
¹¥»÷Õß¹Ø×¢Îȹ̡¢¸ßЧµÄÎó²îʹÓÃÊÖÒÕ£¬ÔÚÎó²îµÄÑ¡ÔñÉÏ×·ÇóÒ×ÓÃÐÔ¡¢Ê±Ð§ÐÔÒÔ¼°ÊÇ·ñÄÜ»ñȡĿµÄ¿ØÖÆÈ¨Ï޵Ĺ¥»÷ÄÜÁ¦¡£Æ¾Ö¤AG¹«Ë¾ÍþвÇ鱨ÖÐÐļà²âµÄÇå¾²ÊÂÎñ£¬±¾ÎÄÕûÀí³öÁË2019Äê1ÔÂ-2020Äê3ÔÂÓëÎó²îʹÓÃÏà¹ØµÄ¹¥»÷ÊÂÎñ£¬ÌáÈ¡ÁËÎó²îʹÓýϸߵÄÊ®¸öÎó²îÐÅÏ¢¡£

Îó²îʹÓýϸߵÄCVEÐÅÏ¢
ä¯ÀÀÆ÷Îó²îʹÓÃÕ¼±È48.44%£¬ä¯ÀÀÆ÷µÄ¸üÐÂÓë·À»¤ÈÔÐè¹Ø×¢
ä¯ÀÀÆ÷×÷ÎªÍøÂç¹¥»÷µÄÈë¿Ú£¬ÔÚÏÖʵʹÓÃÖÐÕ¼±È48.44%£¬Ó°Ïì¹æÄ£¹ã¡£ä¯ÀÀÆ÷µÄÎó²îÖÖÀàÖØ´ó¶àÑù£¬2009Äê֮ǰÎó²îÖ÷ÒªÒÔActiveX¿Ø¼þºÍ»ùÓÚÕ»µÄ»º³åÇøÒç³öΪÖ÷£¬2013ÄêÔ½½ç»á¼û¡¢ÊͷźóÖØÓõÈÐÂÐÍÎó²îÒ»¶È·ºÆð¿ìËÙÔöÌíµÄÇ÷ÊÆ¡£½üÄêÀ´£¬¸÷´óä¯ÀÀÆ÷ΪÁËÌá¸ßÍøÒ³µÄ¼ÓÔØºÍJavaScript¾ç±¾µÄÔËÐÐËÙÂÊ£¬´ó×ÚʹÓÃÁ˼´Ê±±àÒë(Just-in-time)ϵͳ£¬Ò»Ê±¼äJITÒýÇæ³ÉΪ¹¥»÷ÕßÖ÷ÒªµÄÄ¿µÄ¡£

Ó¦ÓÃÈí¼þÎó²îʹÓÃÂþÑÜ
ʹÓÃÎļþÃûÌÃÎó²îµÄÓã²æÊ½´¹ÂÚ¹¥»÷£¬³ÉÎªÍøÂçÇå¾²µÄÖ÷ÒªÍþв֮һ
ÎĵµÀàÐÍÎó²îÖУ¬AcrobatReaderÎªÔØÌåµÄPDFÎó²îÊýÄ¿¹²1823¸ö£¬Õ¼ÓÐÎĵµÀàÐ͵Ä59.07%£¬µ«ÔÚÏÖʵ¹¥»÷³¡¾°ÖÐÈ´²¢²»³£¼û£¬ÏÖʵʹÓÃÕ¼±È1.19%¡£OfficeÏà¹ØµÄÎó²îÊýÄ¿ËäÈ»±ÈPDFÃûÌõÄÒªÉÙ£¬µ«ÔÚÏÖʵ¹¥»÷Öб¸Êܺڿ͹Ø×¢£¬¹¥»÷ÕßÖ»Ðè˼Á¿°æ±¾¼æÈÝ£¬²»Ðè¹ý¶à˼Á¿²úÆ·¼æÈÝ£¬Ò»¸öÎȹ̵ÄÎó²îʹÓÃÎĵµ»ù±¾¿ÉÒÔʵÏÖÒ»¸ö²úÆ·µÄÈ«ÁýÕÖ¡£
FlashÎó²î´óÏÞ¿ìÒª£¬µ«Îó²îÇå¾²ÈÔ½ûÖ¹ºöÊÓ
FlashÎó²î×÷Ϊһ¾µÄÑо¿½¹µã£¬2015ºÍ2016Ä걬³öµÄÎó²î×ÜÊýÕ¼ÓÐFlashÎó²îµÄ55.09%£¬ÔÚÏÖʵʹÓÃÖÐÕ¼±È13.08%¡£¿ÉÊÇFlashÎó²îʹÓò»¿ÉÓÉ´¿´âµÄSWFÎļþÍê³É£¬ÐèÒªÔÚä¯ÀÀÆ÷¡¢Office¡¢PDFÖÐÒÔ²å¼þµÄÐÎʽÀ´Íê³É¹¥»÷¡£ÔÚÏÖʵ¹¥»÷Öг£ÒÔ²å¼þÐÎʽ±»Ç¶Ì×ÔÚÖÖÖÖExploitKit¹¤¾ß°ü£¬¿ÉÒÔµÖ´ïÎȹÌʹÓ㬸üÐÂËÙÂÊ¿ìÒÔ¼°ÃâɱµÄЧ¹û¡£
¿ªÔ´Èí¼þÃæÁÙÎó²îʹÓúÍÈí¼þ¹©Ó¦Á´µÄ“Ë«ÖØ¹¥»÷”
¿ªÔ´Èí¼þ±ãÓÚÑо¿Ô±¾ÙÐлùÓÚÔ´´úÂëµÄ°×ºÐ²âÊÔ¡£WebÀ࿪Դ¿ò¼ÜµÄʹÓôúÂë¹ûÕæºó¿ÉÒÔÔÚ¶Ìʱ¼äÄÚ±»¼¯³Éµ½³ÉÊìµÄ¹¥»÷¿ò¼ÜÖУ¬½µµÍÁËÎó²îʹÓõÄÃż÷¡£ÓµÓÐÖØ´óµÄ´¦Öóͷ£Âß¼£¬²¢ÇÒÆÕ±éʹÓõĿªÔ´Èí¼þ¸üÈÝÒ׳ÉΪÑо¿Ô±»òÕߺڿ͵ÄÄ¿µÄ¡£Ëæ×Å¿ªÔ´Èí¼þ¿ª·¢Ä£Ê½µÄÐËÆð£¬Õë¶ÔÈí¼þ¹©Ó¦Á´µÄ¹¥»÷³ÉΪһÖÖÐÂÐËÍþв£¬Ï൱ÓÚ¸ø¹¥»÷ÕߵĶñÒâ´úÂëÅûÉÏÁË“Õýµ±”µÄÍâÒ£¬Èö²¥ËÙÂʸü¿ì£¬Ó°Ïì¹æÄ£¸ü¹ã£¬Î£º¦¸ü´ó£¬Í¬Ê±Ò²¸üÒþ²Ø¡£
Ò»ÄêÉÏÕÇ1082%£¬Òƶ¯Çå¾²µÄ·ç±©´ÓδÔÝÍ£
½üЩÄêÀ´Ñо¿Ö°Ô±¶ÔÖÇÄÜÖÕ¶ËϵͳµÄÎó²î¹Ø×¢¶ÈÖð½¥Ìá¸ß£¬2015ÄêAndroidϵͳÎó²îÕûÌå·ºÆð±¬·¢Ê½ÔöÌí¡£ÆäÖУ¬Application Framework & LibrariesµÄÎó²î×ÜÁ¿´ï130¸ö£¬Í¬±ÈÉÏÕÇ1082%¡£2018Äê8ÔÂGoogleÐû²¼µÄAndroid 9ÖУ¬Îª²¿·ÖÊØ»¤Àú³ÌºÍÄÚºËÒýÈëÁË¿ØÖÆÁ÷ÍêÕûÐÔCFI(Control Flow Integrity)·À»¤»úÖÆ£¬Äܹ»Ö±½Ó¶Ô¿¹³£ÓÃROP/JOP/COOP´úÂëÖØÓÃʹÓü¼ÇÉ¡£Ðµı£»¤»úÖÆµÄÒýÈëºÍGoogle¶ÔAndroidϵͳÇå¾²Öð½¥ÖØÊÓʹµÃ2017ÄêºóÎó²îÊýÄ¿ÏÔÖøïÔÌ¡£
iOSϵͳÓÉÓÚÓ²¼þÓëÈí¼þ¸ß¶È¼¯³É£¬Ò»Ö±ÒÔÇå¾²Öø³Æ¡£2015ÄêiOSϵͳÎó²î×ÜÁ¿´ï369¸ö£¬Í¬±ÈÉÏÕÇ156.25%¡£2019Äê8ÔÂGoogleÇå¾²ÍŶÓÐû²¼ÁË5¸öÎó²îʹÓÃÁ´¼°Ïà¹ØÁªµÄ14¸öÇå¾²Îó²î £¬Éæ¼°´Ó iOS 10 µ½ iOS 12µÄ°æ±¾£¬ÕâÎÞÒÉΪÆäËü¹¥»÷ÕßÌṩÁËÒ»¸öºÜºÃµÄ×ÅÊֵ㣬¶ÔiOSϵͳµÄÇå¾²ÐÔÌá³öÁËÖØ´óµÄÌôÕ½¡£

AndroidÀúÄêÎó²îÊýÄ¿

iOSϵͳÀúÄêÎó²îÊýÄ¿
ÎïÁªÍø³É“Σ”ÁªÍø
ÎïÁªÍø×°±¸ÊýÄ¿ºÍÖÖÀàÔöÌíѸËÙ£¬¿ÉÊÇ·ÀÓù²½·¥ÉÙ¡£ÏÂ±í¸ø³öÁË2019ÄêÎïÁªÍøÎó²îʹÓÃÊýĿǰʮµÄÎó²îÐÅÏ¢¡£

ÎïÁªÍøÎó²îʹÓÃÊýÄ¿Top10
ÆäÖÐCVE-2015-2051¡¢CVE-2017-17215¡¢CVE-2014-8361ÕâÈý¸öÎó²î¶¼ÓëUPnPÐÒéÓйء£UPnPʹÓÃSOAPÐÒéʵÏÖ¶Ô×°±¸µÄ¿ØÖÆ¡£AG¹«Ë¾¿Æ¼¼¡¶2019ÄêÎïÁªÍøÇå¾²Ä걨¡·ÏÔʾ£¬SOAP·þÎñ¿É»á¼ûµÄ×°±¸Õ¼UPnP×°±¸×ÜÁ¿µÄ46.9%£¬ÕâЩװ±¸ÖУ¬61%µÄ×°±¸±£´æÖÐΣ¼°ÒÔÉϵÄÎó²î¡£
ÒѾ¼à²âµÄÎó²îʹÓÃËù¶ÔӦĿµÄ×°±¸ÒÔ·ÓÉÆ÷ºÍÊÓÆµ¼à¿Ø×°±¸ÎªÖ÷¡£ÕâЩÇå¾²ÎÊÌâÖ÷ҪȪԴÓÚÁ½µã£¬Ò»ÊÇÓÉÓÚ´ó´ó¶¼µÄ¹Ì¼þÔÚ³ö³§Ê±¾Í±£´æÈõ¿ÚÁî¡¢ÉõÖÁÎÞÐè¿ÚÁîУÑéµÄÎÊÌ⣬ÕâÖÖ²»Çå¾²µÄ¹Ì¼þÉèÖôó´óÌá¸ßÁ˹¥»÷ÕߵĹ¥»÷ЧÂÊ¡£¶þÊǹ̼þËùŲÓõĵÚÈý·½×é¼þÎó²îÉõÖÁÊDzÙ×÷ϵͳÄÚºËÎó²î£¬²»¿É¹»ÊµÊ±×·×ÙÐÞ¸´¡£
ÍøÂçÇå¾²µÄʵÖÊÊǹ¥Óë·ÀµÄ¶Ô¿¹£¬Î´Öª¹¥ÑÉÖª·À£¬Ö»ÓÐÔÚÏàʶÁËÖÖÖÖ¹¥»÷ÊÖÒÕºÍÊֶκó²Å»ª½ÓÄÉÔ½·¢ÓÐÓõķÀÓùÕ½ÂÔ£¬´Ó¶ø×èÖ¹Çå¾²ÊÂÎñµÄ±¬·¢¡£

AG¹«Ë¾ÔÆ







