ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬£¬ £¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕУ»£»£»£»Î¢ÈíÐû²¼1ÔÂOfficeÇå¾²¸üУ¬£¬£¬£¬£¬ £¬ÐÞ¸´3¸öRCEÎó²î

Ðû²¼Ê±¼ä 2020-01-17


1.ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬£¬ £¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕÐ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


SophosÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»×éеÄfleeceware APP£¬£¬£¬£¬£¬ £¬ÕâЩAPPÒѾ­±»Áè¼Ý6ÒÚAndroidÓû§ÏÂÔØ×°Öᣡ£ ¡£fleecewareÊÇÖ¸¹È¸èPlayÊÐËÁÖб£´æµÄÒ»ÖÖÐÂÐͽðÈÚڲƭÐÐΪ£¬£¬£¬£¬£¬ £¬ÕâЩAPPÀÄÓÃAndroidÓ¦ÓõÄÊÔÓÃÆÚ¹¦Ð§ÏòÓû§ÊÕ·Ñ¡£¡£ ¡£Ä¬ÈÏÇéÐÎÏÂAndroidÓû§ÔÚ×¢²áʹÓþßÓÐÊÔÓÃÆÚµÄAPPʱ±ØÐèÊÖ¾Ù´ë·ÏÊÔÓ㬣¬£¬£¬£¬ £¬È»¶ø´ó´ó¶¼Óû§Ö»ÊÇÔÚ²»Ï²»¶µÄʱ¼äÐ¶ÔØAPP£¬£¬£¬£¬£¬ £¬¾ø´ó´ó¶¼¿ª·¢Õß½«ÕâÖÖÐ¶ÔØÐÐΪÊÓΪ×÷·ÏÊÔÓ㬣¬£¬£¬£¬ £¬µ«Ò»Ð©¿ª·¢ÕßÔÚÓû§Ð¶ÔغóûÓÐ×÷·ÏÊÔÓò¢ÇÒ¼ÌÐøÊÕ·Ñ¡£¡£ ¡£Sophos×î³õ·¢Ã÷µÄ24¸öAPP°üÀ¨¶þάÂëɨÃèÆ÷¡¢ÅÌËãÆ÷µÈ£¬£¬£¬£¬£¬ £¬ËüÃÇÒÔÕâÖÖ·½·¨ÏòÓû§ÊÕȡÿÄê100ÃÀÔªµ½240ÃÀÔªµÄ¶©ÔÄÓöȡ£¡£ ¡£ÔÚ¿ËÈÕÐû²¼µÄÒ»·Ý±¨¸æÖУ¬£¬£¬£¬£¬ £¬Sophos·¢Ã÷ÁËÁíÍâ25¸ö´ËÀàAPP£¬£¬£¬£¬£¬ £¬Æä×Ü×°ÖÃÁ¿Áè¼Ý6ÒÚ£¬£¬£¬£¬£¬ £¬ÍêÕûµÄAPPÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£ ¡£


  Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/more-than-600-million-users-installed-android-fleeceware-apps-from-the-play-store/


2.΢ÈíÐû²¼1ÔÂOfficeÇå¾²¸üУ¬£¬£¬£¬£¬ £¬ÐÞ¸´3¸öRCEÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


΢ÈíÔÚ1ÔÂOfficeÇå¾²¸üÐÂÖÐΪ5¸ö²î±ðµÄ²úÆ·Ðû²¼ÁË×ܹ²7¸öÇå¾²¸üкÍ3¸öÀۼƸüУ¬£¬£¬£¬£¬ £¬ÆäÖÐ6¸ö¸üÐÂÓëÔ¶³Ì´úÂëÖ´ÐÐÎó²îÓйء£¡£ ¡£ÕâЩRCEÎó²î±»¸ú×ÙΪCVE-2020-0650¡¢CVE-2020-0651ºÍCVE-2020-0652£¬£¬£¬£¬£¬ £¬ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨Office 2016¡¢Office 2013¡¢Office 2010¡¢Excel 2016¡¢Excel 2013ºÍExcel 2010¡£¡£ ¡£±ðµÄ±»¸ú×ÙΪCVE-2020-0647µÄÁíÒ»¸öÎó²îÊÇÓ°ÏìOffice Online ServerµÄÓÕÆ­Îó²î£¬£¬£¬£¬£¬ £¬ËüÊÇÓÉ¿çÓòͨѶÖеÄԭʼÑéÖ¤²»×¼È·ÒýÆðµÄ£¬£¬£¬£¬£¬ £¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÊÜÓ°ÏìµÄϵͳÉϾÙÐпçÓò¹¥»÷¡£¡£ ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-office-january-security-updates-fix-code-execution-bugs/


3.VMwareÐû²¼VMware Tools 11£¬£¬£¬£¬£¬ £¬ÐÞ¸´10°æ±¾ÖеÄLPEÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


VMwareÒÑÐû²¼VMware Tools 11.0.0£¬£¬£¬£¬£¬ £¬ÐÞ¸´Á˰汾10.xyÖеÄÍâµØÌáȨÎó²î£¨CVE-2020-3941£©¡£¡£ ¡£¸ÃÎó²î±»¹éÀàΪ¾ºÕùÌõ¼þÎó²î£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÄÜʹÓôËÎó²îÔÚÐéÄâ»úÖÐÌáÉýÌØÈ¨¡£¡£ ¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8·Ö¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬£¬ £¬VMware»¹ÐÞ¸´ÁËWorkspace ONE SDKÖеÄÐÅϢй¶Îó²î£¨CVE-2020-3940£©£¬£¬£¬£¬£¬ £¬¸ÃÎó²îÓ°ÏìÁËÏà¹ØµÄiOSºÍAndroid APP£¬£¬£¬£¬£¬ £¬°üÀ¨Workspace ONE Boxer¡¢Content¡¢Intelligent Hub¡¢Notebook¡¢People¡¢PIV-D¡¢WebÒÔ¼°ÊÊÓÃÓÚApache CordovaºÍXamarinµÄSDK²å¼þ¡£¡£ ¡£Æ¾Ö¤Ç徲ͨ¸æ£¬£¬£¬£¬£¬ £¬ÈôÊÇÆôÓÃÁËSSL Pinning£¬£¬£¬£¬£¬ £¬ÔòÔÚÊÜÓ°ÏìµÄÒÆ¶¯APPºÍWorkspace ONE UEM×°±¸Ð§ÀÍÖ®¼äµÄÖÐÐÄÈË£¨MITM£©¹¥»÷Õß¿ÉÄܲ¶»ñ´«ÊäÖеÄÃô¸ÐÊý¾Ý¡£¡£ ¡£


 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/96446/security/vmware-tools-and-workspace-one-sdk-flaws.html


4.Peekaboo MomentsÒâÍâй¶80ÍòÓû§µÄÓÊÏäÐÅÏ¢


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ô±Dan Ehrlich·¢Ã÷Peekaboo Moments APPµÄElasticsearchÊý¾Ý¿â̻¶ÁËÊýǧ¸öÓ¤¶ùµÄÕÕÆ¬ºÍÊÓÆµÒÔ¼°ÖÁÉÙ80Íò¸öµç×ÓÓʼþµØµã¡£¡£ ¡£¸ÃÊý¾Ý¿âÊôÓÚPeekaboo MomentsµÄ¿ª·¢ÉÌBithouse£¬£¬£¬£¬£¬ £¬Êý¾Ý¿âÖдæÓÐ7000Íò¸öÈÕÖ¾Îļþ¡£¡£ ¡£³ýÁËÓ¤¶ùµÄÊÓÆµºÍÕÕÆ¬Í⣬£¬£¬£¬£¬ £¬¸ÃÊý¾Ý¿â»¹°üÀ¨Ó¤¶ùµÄ³öÉúÈÕÆÚ¡¢Éí³¤ºÍÌåÖØÒÔ¼°¾­¶ÈºÍγ¶ÈλÖÃÊý¾Ý¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬£¬ £¬Ð¹Â¶µÄÊý¾ÝÒÉΪPeekaboo MomentsµÄFacebook APIÃÜÔ¿£¬£¬£¬£¬£¬ £¬âïÊÑ¿ÉʹÓøÃÃÜÔ¿½«ÕÕÆ¬µÈÐû²¼µ½Facebook¡£¡£ ¡£Æ¾Ö¤EhrlichµÄ˵·¨£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÄÜ»áʹÓÃÕâЩÃÜÔ¿À´»á¼ûÓû§FacebookÒ³ÃæÉϵÄÄÚÈÝ¡£¡£ ¡£BithouseÔÚ½Óµ½±¨¸æºóѸËÙ¶ÔЧÀÍÆ÷¾ÙÐÐÁ˱£»£»£»£»¤¡£¡£ ¡£


 Ô­ÎÄÁ´½Ó£º

https://hotforsecurity.bitdefender.com/blog/peekaboo-moments-app-left-baby-videos-photos-and-800000-users-email-addresses-exposed-on-the-internet-22067.html


5.¼ÓÄôóÍøÉÏÒ©µêPlanetDrugsDirectй¶²¿·Ö¿Í»§Ö§¸¶ÐÅÏ¢


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¼ÓÄôóÍøÉÏÒ©µêPlanetDrugsDirectÕýÔÚͨ¹ýµç×ÓÓʼþ֪ͨ¿Í»§ÆäСÎÒ˽¼ÒºÍ²ÆÎñÐÅÏ¢Êܵ½Êý¾Ýй¶ÊÂÎñµÄÓ°Ïì¡£¡£ ¡£PlanetDrugsDirect³Æ×Ô¼ºÎª¿Í»§Ìṩ»ñµÃ´¦·½Ò©ºÍ·Ç´¦·½Ò©µÄʱ»ú£¬£¬£¬£¬£¬ £¬Æä¿Í»§ÊýĿԼΪ40Íò¡£¡£ ¡£Æ¾Ö¤¸ÃÒ©µêµÄ֪ͨ£¬£¬£¬£¬£¬ £¬¿ÉÄÜй¶µÄÊý¾Ý°üÀ¨¿Í»§µÄÐÕÃû¡¢×¡Ö·¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂëÒÔ¼°´¦·½µÄÒ½ÁÆÐÅÏ¢ºÍ¸¶¿îÐÅÏ¢£¬£¬£¬£¬£¬ £¬µ«Ã»ÓÐÖ¤¾ÝÅú×¢Óû§µÄÃÜÂëÊܵ½Ë𺦡£¡£ ¡£PlanetDrugsDirect»¹Ö¸³ö¸ÃÊÂÎñÏÖÔÚÕýÔÚÊÓ²ìÖУ¬£¬£¬£¬£¬ £¬½«¾¡¿ìÌṩ¸ü¶àÏêϸÐÅÏ¢¡£¡£ ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/online-pharmacy-planetdrugsdirect-discloses-security-breach/


6.Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉÏ̻¶ÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


µÂ¹úÇå¾²³§ÉÌGreenbone³ÆÊý°Ù¸ö¿É¹ûÕæ»á¼ûµÄҽѧ³ÉÏñϵͳÔÚ»¥ÁªÍøÉÏ̻¶ÁËÈ«ÇòÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¡£ ¡£¸ÃÏîÑо¿ÖصãÆÊÎöÔÚÍøÉÏ̻¶µÄҽѧͼƬ´æµµºÍͨѶϵͳ£¨PACS£©£¬£¬£¬£¬£¬ £¬ÔÚËùÓÐÊÜÆÊÎöµÄPACSЧÀÍÆ÷ÖУ¬£¬£¬£¬£¬ £¬ÓпìÒª1/4µÄϵͳ½«Êý¾Ý̻¶ÔÚ»¥ÁªÍøÉÏ¡£¡£ ¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬£¬ £¬ÔÚ2019Äê7ÔÂÖÁ2019Äê9ÔÂÖ®¼äÆÊÎöµÄ2300¸öϵͳÖУ¬£¬£¬£¬£¬ £¬ÓÐ590¸ö¿É´ÓInternet»á¼û²¢ÇÒδÉèÃÜÂ룬£¬£¬£¬£¬ £¬¹²ÓÐÁè¼Ý2450ÍòÌõ»¼ÕßÊý¾Ý̻¶£¬£¬£¬£¬£¬ £¬ÔÚ11Ô·ݵÄÑо¿ÖУ¬£¬£¬£¬£¬ £¬¸Ã¹«Ë¾Í¸Â¶ÓÐ3500ÍòÌõ»¼Õ߼ͼ¿É¹ûÕæ»á¼û¡£¡£ ¡£ÔÚ9ÔÂÖÁ11ÔÂÖ®¼ä£¬£¬£¬£¬£¬ £¬°üÀ¨Ò½ÁÆÍ¼ÏñµÄ̻¶»¼Õ߼ͼÊýÄ¿ÒÑ´Ó440ÍòÔöÌíÁËÒ»±¶£¬£¬£¬£¬£¬ £¬µÖ´ï900Íò¡£¡£ ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/unprotected-medical-systems-expose-data-millions-patients