ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ38ÖÜ

°ä²¼¹¦·ò 2021-09-22

>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê09ÔÂ13ÈÕÖÁ09ÔÂ19ÈÕ¹²ÊÕ¼°²È«·ì϶60¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Premiere Elements CVE-2021-40700»º³åÇøÒç³ö´úÂëÖ´Ðзì϶£»£»£»Microsoft Azure Open Management InfrastructureȨÏÞÌáÉý·ì϶£»£»£»Google chrome Selection APIÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»£»£»Microsoft Scripting Engine CVE-2021-26435»º³åÇøÒç³ö·ì϶£»£»£»SAP Business OneÎļþÉÏ´«·ì϶¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÀÕË÷¹¥»÷µ¼ÖÂÄϷǶà¸öµ±²¿ÃÅÃŵÄITϵͳÖжϣ»£»£»Apple°ä²¼´¹Î£¸üР£¬ÐÞ¸´Áãµã»÷·ì϶ForcedEntry£»£»£»Kaspersky°ä²¼2021ÄêÉϰëÄêICSÍþÐ²Ì¬ÊÆµÄ»ã±¨£»£»£»Microsoft°ä²¼9Ô·ÝÐÇÆÚ¶þ²¹¶¡ £¬×ܼÆÐÞ¸´86¸ö·ì϶£»£»£»¹È¸èÒòÀÄÓð²×¿µÄÊг¡Ö÷µ¼Ö°Î»±»º«¹ú·£¿î2070ÒÚº«Ôª¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾Öܰ²È«ÍþвΪÖС£¡£


>ÖØÒª°²È«·ì϶Áбí


1.Adobe Premiere Elements CVE-2021-40700»º³åÇøÒç³ö´úÂëÖ´Ðзì϶


Adobe Premiere Elements´¦ÖÃÎļþ´æÔÚ»º³åÇøÒç³ö·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó £¬ÓÕʹÓû§½âÎö £¬¿Éʹϵͳ±ÀÀ£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£


https://helpx.adobe.com/security/products/premiere_elements/apsb21-78.html


2.Microsoft Azure Open Management InfrastructureȨÏÞÌáÉý·ì϶


Microsoft Azure Open Management Infrastructure´æÔÚ°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿ÉÌáÉýȨÏÞ¡£¡£


https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-38649


3.Google chrome Selection APIÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


Google chrome Selection API´æÔÚ¿ªÊͺóʹÓ÷ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó £¬ÓÕʹÓû§½âÎö £¬¿Éʹϵͳ±ÀÀ£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£


https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop.html


4.Microsoft Scripting Engine CVE-2021-26435»º³åÇøÒç³ö·ì϶


Microsoft Scripting Engine´æÔÚ»º³åÇøÒç³ö·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26435


5.SAP Business OneÎļþÉÏ´«·ì϶


SAP Business One´æÔÚËÁÒâÎļþÉÏ´«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£


https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405


 >ÖØÒª°²È«ÊÂÎñ×ÛÊö


1¡¢ÀÕË÷¹¥»÷µ¼ÖÂÄϷǶà¸öµ±²¿ÃÅÃŵÄITϵͳÖжÏ


ÀÕË÷¹¥»÷µ¼ÖÂÄϷǶà¸öµ±²¿ÃÅÃŵÄITϵͳÖжÏ.jpg



9ÔÂ6ÈÕÍíÉϵÄÀÕË÷¹¥»÷»î¶¯µ¼ÖÂÄϷǶà¸öµ±²¿ÃÅÃŵÄITϵͳÖÐ¶Ï £¬Ô̺¬µç×ÓÓʼþϵͳºÍ¹ú¶È±£ÊÍ·þÎñµÄϵͳ¡£¡£DOJCD¹ÙÔ±ÔÚÉÏÖÜËÄ£¨9ÔÂ9ÈÕ£©Ð¹Â© £¬¹¥»÷»î¶¯¼ÓÃÜÁ˸ò¿ÃÅËùÓеÄÐÅϢϵͳ £¬Ê¹µÃÄÚ²¿µÄÔ±¹¤ºÍÍⲿµÄ¹«Ãñ¾ùÎÞ·¨Ê¹Óᣡ£´ËÍâ £¬Ë¾·¨²¿¹ÙÔ±°µÊ¾ £¬ËûÃDz»µÃ²»Æô¶¯ÁËÊÖ¶¯Á÷³ÌÀ´Î¬³Ö·¨Í¥µÄÕý³£»£»£»î¶¯ £¬µ«²¢Î´Ö¸Ã÷Õâ´Î¹¥»÷±³ºóµÄÀÕË÷ÔËÓªÍŻ¡£ÉÏÖÜÒ» £¬ÄϷǹú¶Èº½Ìì¾Ö (SANSA)ÔøÅû¶Æäϵͳ´æÔÚ°²È«·ì϶ £¬µ¼ÖÂѧÉúСÎÒÐÅϢй¶¡£¡£


Ô­ÎÄÁ´½Ó£º£º£º

https://therecord.media/bail-services-affected-in-south-africa-after-ransomware-attack/   


2¡¢Apple°ä²¼´¹Î£¸üР£¬ÐÞ¸´Áãµã»÷·ì϶ForcedEntry


Apple°ä²¼´¹Î£¸üÐÂ£¬ÐÞ¸´Áãµã»÷·ì϶ForcedEntry.jpg


Apple¹«Ë¾ÓÚ±¾ÖÜÒ»°ä²¼´¹Î£¸üР£¬ÐÞ¸´iMessagingÖеÄÁãµã»÷·ì϶ForcedEntry£¨CVE-2021-30860£©¡£¡£Apple³Æ¸Ã·ì϶Ϊ´¦ÖöñÒâPDFʱµ¼ÖµÄËÁÒâ´úÂëÖ´Ðзì϶¡£¡£Citizen LabÓÚ2021Äê2Ô³õ´Î·¢Ïָ÷ì϶ £¬Ëü¿ÉÓÃÀ´ÈƹýAppleÆäÊ±ÍÆ³öµÄÔ¤·ÀiMessageÁãµã»÷·ì϶µÄɳÏäBlastDoor¡£¡£


Ô­ÎÄÁ´½Ó£º£º£º

https://threatpost.com/apple-emergency-fix-nso-zero-click-zero-day/169416/


3¡¢Kaspersky°ä²¼2021ÄêÉϰëÄêICSÍþÐ²Ì¬ÊÆµÄ»ã±¨


Kaspersky°ä²¼2021ÄêÉϰëÄêICSÍþÐ²Ì¬ÊÆµÄ»ã±¨.jpg


KasperskyÔÚ9ÔÂ9ÈÕ°ä²¼ÁË2021ÄêÉϰëÄêICSÍþÐ²Ì¬ÊÆµÄ»ã±¨¡£¡£»ã±¨Ö¸³ö £¬2021ÄêÉϰëÄêICSÍÆËã»ú±»¹¥»÷µÄÕ¼±ÈΪ8% £¬±È2020ÄêϰëÄê¸ß0.4¸ö°Ù·Öµã¡£¡£ÆäÖÐ £¬±»¹¥»÷µÄICSÍÆËã»úÕ¼±È×î¶àµÄ¹ú¶ÈΪ°¢¶û¼°ÀûÑÇ£¨58.4%£© £¬Æä´ÎΪĦÂå¸ç£¨52.4%£© ¡¢ÒÁÀ­¿Ë£¨50.9%£©ºÍÔ½ÄÏ£¨50.6%£©¡£¡£´ËÍâ £¬»¥ÁªÍø¡¢¿ÉÒÆ¶¯Ã½ÌåºÍµç×ÓÓʼþÒÀÈ»ÊÇICSÍÆËã»úÍþвµÄÖØÒªÆðÔ´¡£¡£


Ô­ÎÄÁ´½Ó£º£º£º

https://securelist.com/threat-landscape-for-industrial-automation-systems-in-h1-2021/104017/


4¡¢Microsoft°ä²¼9Ô·ÝÐÇÆÚ¶þ²¹¶¡ £¬×ܼÆÐÞ¸´86¸ö·ì϶


Microsoft°ä²¼9Ô·ÝÐÇÆÚ¶þ²¹¶¡£¬×ܼÆÐÞ¸´86¸ö·ì϶.jpg


MicrosoftÓÚ9ÔÂ14ÈÕ°ä²¼Á˱¾ÔµÄÐÇÆÚ¶þ°²È«¸üР£¬×ܼÆÐÞ¸´ÁË86¸ö·ì϶¡£¡£Õâ´Î¸üÐÂÐÞ¸´ÁË2¸öÁãÈÕ·ì϶ £¬Ô̺¬Windows MSHTMLÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-40444£© £¬ÒÑÔÚÒ°Íâ·¢ÏÖÀûÓø÷ì϶µÄ¹¥»÷»î¶¯£»£»£»ÒÔ¼°Windows DNSÌáȨ·ì϶£¨CVE-2021-36968£©¡£¡£´ËÍâ £¬»¹ÐÞ¸´ÁËAzure Ê¢¿ªÊ½ÖÎÀí»ù´¡ÉèÊ©ÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2021-38647£©ºÍWindows¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-26435£©µÈ¡£¡£


Ô­ÎÄÁ´½Ó£º£º£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2021-patch-tuesday-fixes-2-zero-days-60-flaws/


5¡¢¹È¸èÒòÀÄÓð²×¿µÄÊг¡Ö÷µ¼Ö°Î»±»º«¹ú·£¿î2070ÒÚº«Ôª


¹È¸èÒòÀÄÓð²×¿µÄÊг¡Ö÷µ¼Ö°Î»±»º«¹ú·£¿î2070ÒÚº«Ôª.jpg


9ÔÂ14ÈÕ £¬º«¹úƽÕýÒµÎñίԱ»á¶Ô¹È¸è´¦ÒÔ2070ÒÚº«Ôª£¨Ô¼Îª1.77 ÒÚÃÀÔª£©µÄ·£¿î¡£¡£Ô­ÒòÊǹȸèÒòÀÄÓð²×¿ÔÚÒÆ¶¯²Ù×÷ϵͳÊг¡µÄÖ÷µ¼Ö°Î» £¬ÆÈʹÖÇÄÜÊÖ»úÖÆ×÷ÉÌÖ»ÄÜʹÓÃAndroid²Ù×÷ϵͳ¡£¡£¸Ã»ú¹¹³Æ £¬¹È¸èÒªÇóÖÆ×÷É̱ØÐëÇ©Êð¡°·´Ë鯬»¯ºÍ̸£¨AFA£©¡± £¬¸ÃºÍ̸²»ÈÝʹÓÃAndroid²Ù×÷ϵͳµÄÅú¸Ä°æ±¾ £¬¼´ËùνµÄ¡°Android·ÖÖ§¡±¡£¡£±¨µÀ³Æ £¬¹È¸èµÄ¢¶ÏÐÐΪʹÆäÔÚ2019ÄêÒÆ¶¯²Ù×÷ϵͳÊг¡µÄ·Ý¶îÉÏÉýµ½ÁË97.7%¡£¡£


Ô­ÎÄÁ´½Ó£º£º£º

https://www.theregister.com/2021/09/14/south_korea_fines_google/