¡¾Íþвͨ¸æ¡¿AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.07.12-2021.07.18£©
2021-07-22
Ò»¡¢ Íþвͨ¸æ
ij»¥ÁªÍøÆóÒµ7ÔÂÇå¾²¸üжà¸ö²úÆ·¸ßΣÎó²îͨ¸æ£¨CVE-2021-34492¡¢CVE-2021-34473¡¢CVE-2021-34523£©
¡¾Ðû²¼Ê±¼ä¡¿2021-07-14 18:00:00 GMT
¡¾¸ÅÊö¡¿
7ÔÂ14ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Ä³»¥ÁªÍøÆóÒµÐû²¼7ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË117¸öÇå¾²Îó²î£¬Éæ¼°Windows¡¢Microsoft Office¡¢Microsoft Edge¡¢Visual Studio ¡¢SharePoint ServerµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨Ô¶³Ì´úÂëÖ´ÐкÍȨÏÞÌáÉýµÈ¸ßΣÎó²îÀàÐÍ¡£±¾ÔÂij»¥ÁªÍøÆóÒµÔ¶ȸüÐÂÐÞ¸´µÄÎó²îÖУ¬ÑÏÖØË®Æ½ÎªÒªº¦£¨Critical£©µÄÎó²îÓÐ13¸ö£¬Ö÷Òª£¨Important£©Îó²îÓÐ103¸ö¡£ÆäÖÐÓÐ9¸öΪ0dayÎó²î£¬ÓÐ5¸öÐÅÏ¢Òѱ»¹ûÕæÅû¶£ºWindows Ö¤ÊéÓÕÆÎó²î£¨CVE-2021-34492£©Microsoft Exchange Server Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-34473£©Microsoft Exchange Server ȨÏÞÌáÉýÎó²î£¨CVE-2021-34523£©Windows ADFS Çå¾²¹¦Ð§ÈƹýÎó²î£¨CVE-2021-33779£©Active Directory Çå¾²¹¦Ð§ÈƹýÎó²î£¨CVE-2021-33781£©ÓÐ4¸öÒѱ»ÔÚҰʹÓãºWindows Print SpoolerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-34527£©Windows Script Engine ÄÚ´æËð»µÎó²î£¨CVE-2021-34448£©Windows Kernel ȨÏÞÌáÉýÎó²î£¨CVE-2021-31979£©Windows Kernel ȨÏÞÌáÉýÎó²î£¨CVE-2021-33771£©ÇëÏà¹ØÓû§¾¡¿ì¸üв¹¶¡¾ÙÐзÀ»¤£¬ÍêÕûÎó²îÁбíÇë²Î¿¼¸½Â¼¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
SolarWinds Serv-U Ô¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ£¨CVE-2021-35211£©
¡¾Ðû²¼Ê±¼ä¡¿2021-07-13 17:00:00 GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½SolarWindsÐû²¼Ç徲ͨ¸æ£¬ÐÞ¸´ÁËServ-UÖб£´æµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-35211£©£¬¸ÃÎó²îΪij»¥ÁªÍøÆóÒµ·¢Ã÷ÔÚҰʹÓúóÏòSolarWinds±¨¸æ£¬²¢ÌṩÁËÎó²îʹÓõĿ´·¨Ö¤Êµ¡£Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓôËÎó²î¿ÉÔÚÊÜÓ°ÏìµÄ·þÎñÆ÷ÉÏÒÔÌØÊâȨÏÞÖ´ÐÐí§Òâ´úÂ룬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£SolarWindsÌåÏÖ´ËÎó²î±£´æÓÚSSHÐÒéÖУ¬Óë SUNBURST ¹©Ó¦Á´¹¥»÷Î޹أ¬½öÓ°ÏìSolarWinds Serv-U Managed File TransferºÍServ-U Secure FTP¡£Ê¹ÓÃServ-UÖÎÀí¿ØÖÆÌ¨Ïòµ¼½¨ÉèÓòʱ»áĬÈÏÑ¡ÔñÆôÓÃSSH£¬ÈôServ-UÇéÐÎÖÐδÆôÓÃSSHÔò²»ÊÜ´ËÎó²îÓ°Ïì¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
YAPIÈÏÖ¤Óû§Ê¹ÓÃMock¹¦Ð§¾ÙÐÐÔ¶³ÌÖ´ÐÐÊðÀí£©
¡¾Ðû²¼Ê±¼ä¡¿2021-07-12 10:00:00 GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²â·¢Ã÷ YAPI ¿ÉÊÓ»¯½Ó¿ÚÖÎÀíÆ½Ì¨±£´æÔÚÒ°¹¥»÷ÊÂÎñ£¬ÓÉÓÚ´ó×ÚÓû§Ê¹Óà YAPIµÄĬÈÏÉèÖò¢ÔÊÐí´ÓÍâ²¿ÍøÂç»á¼û YAPI·þÎñ¡£µ¼Ö¹¥»÷Õßͨ¹ý×¢²áƽ̨ÕË»§ºó£¬¿ÉÒÔʹÓà YAPI µÄ Mock ¹¦Ð§ÔÚÊÜÓ°ÏìµÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ javascript ´úÂ룬´Ó¶ø¿ØÖÆÄ¿µÄ·þÎñÆ÷¡£YAPI¹Ù·½ÔÝδÐû²¼ÐÂÎźÍÐÞ¸´¼Æ»®£¬ÏÖÔÚPoCÒѹûÕæ£¬ÇëÏà¹ØÓû§½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£YAPIÊÇÓÉÈ¥ÄĶùÍøÒÆ¶¯¼Ü¹¹×飨YMFE£©¿ª·¢µÄ¿ÉÊÓ»¯½Ó¿ÚÖÎÀí¹¤¾ß£¬ÊÇÒ»¸ö¿ÉÍâµØ°²Åŵġ¢Âòͨǰºó¶Ë¼°QAµÄ½Ó¿ÚÖÎÀíÆ½Ì¨¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning

AG¹«Ë¾ÔÆ







