ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕУ»£»£»£»Î¢ÈíÐû²¼1ÔÂOfficeÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´3¸öRCEÎó²î
Ðû²¼Ê±¼ä 2020-01-17
1.ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕÐ
SophosÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»×éеÄfleeceware APP£¬£¬£¬£¬£¬£¬ÕâЩAPPÒѾ±»Áè¼Ý6ÒÚAndroidÓû§ÏÂÔØ×°Öᣡ£¡£fleecewareÊÇÖ¸¹È¸èPlayÊÐËÁÖб£´æµÄÒ»ÖÖÐÂÐͽðÈÚÚ²ÆÐÐΪ£¬£¬£¬£¬£¬£¬ÕâЩAPPÀÄÓÃAndroidÓ¦ÓõÄÊÔÓÃÆÚ¹¦Ð§ÏòÓû§ÊÕ·Ñ¡£¡£¡£Ä¬ÈÏÇéÐÎÏÂAndroidÓû§ÔÚ×¢²áʹÓþßÓÐÊÔÓÃÆÚµÄAPPʱ±ØÐèÊÖ¾Ù´ë·ÏÊÔÓ㬣¬£¬£¬£¬£¬È»¶ø´ó´ó¶¼Óû§Ö»ÊÇÔÚ²»Ï²»¶µÄʱ¼äÐ¶ÔØAPP£¬£¬£¬£¬£¬£¬¾ø´ó´ó¶¼¿ª·¢Õß½«ÕâÖÖÐ¶ÔØÐÐΪÊÓΪ×÷·ÏÊÔÓ㬣¬£¬£¬£¬£¬µ«Ò»Ð©¿ª·¢ÕßÔÚÓû§Ð¶ÔغóûÓÐ×÷·ÏÊÔÓò¢ÇÒ¼ÌÐøÊÕ·Ñ¡£¡£¡£Sophos×î³õ·¢Ã÷µÄ24¸öAPP°üÀ¨¶þάÂëɨÃèÆ÷¡¢ÅÌËãÆ÷µÈ£¬£¬£¬£¬£¬£¬ËüÃÇÒÔÕâÖÖ·½·¨ÏòÓû§ÊÕȡÿÄê100ÃÀÔªµ½240ÃÀÔªµÄ¶©ÔÄÓöȡ£¡£¡£ÔÚ¿ËÈÕÐû²¼µÄÒ»·Ý±¨¸æÖУ¬£¬£¬£¬£¬£¬Sophos·¢Ã÷ÁËÁíÍâ25¸ö´ËÀàAPP£¬£¬£¬£¬£¬£¬Æä×Ü×°ÖÃÁ¿Áè¼Ý6ÒÚ£¬£¬£¬£¬£¬£¬ÍêÕûµÄAPPÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/more-than-600-million-users-installed-android-fleeceware-apps-from-the-play-store/
2.΢ÈíÐû²¼1ÔÂOfficeÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´3¸öRCEÎó²î
΢ÈíÔÚ1ÔÂOfficeÇå¾²¸üÐÂÖÐΪ5¸ö²î±ðµÄ²úÆ·Ðû²¼ÁË×ܹ²7¸öÇå¾²¸üкÍ3¸öÀۼƸüУ¬£¬£¬£¬£¬£¬ÆäÖÐ6¸ö¸üÐÂÓëÔ¶³Ì´úÂëÖ´ÐÐÎó²îÓйء£¡£¡£ÕâЩRCEÎó²î±»¸ú×ÙΪCVE-2020-0650¡¢CVE-2020-0651ºÍCVE-2020-0652£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨Office 2016¡¢Office 2013¡¢Office 2010¡¢Excel 2016¡¢Excel 2013ºÍExcel 2010¡£¡£¡£±ðµÄ±»¸ú×ÙΪCVE-2020-0647µÄÁíÒ»¸öÎó²îÊÇÓ°ÏìOffice Online ServerµÄÓÕÆÎó²î£¬£¬£¬£¬£¬£¬ËüÊÇÓÉ¿çÓòͨѶÖеÄÔʼÑéÖ¤²»×¼È·ÒýÆðµÄ£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÊÜÓ°ÏìµÄϵͳÉϾÙÐпçÓò¹¥»÷¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-office-january-security-updates-fix-code-execution-bugs/
3.VMwareÐû²¼VMware Tools 11£¬£¬£¬£¬£¬£¬ÐÞ¸´10°æ±¾ÖеÄLPEÎó²î
VMwareÒÑÐû²¼VMware Tools 11.0.0£¬£¬£¬£¬£¬£¬ÐÞ¸´Á˰汾10.xyÖеÄÍâµØÌáȨÎó²î£¨CVE-2020-3941£©¡£¡£¡£¸ÃÎó²î±»¹éÀàΪ¾ºÕùÌõ¼þÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓôËÎó²îÔÚÐéÄâ»úÖÐÌáÉýÌØÈ¨¡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8·Ö¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬VMware»¹ÐÞ¸´ÁËWorkspace ONE SDKÖеÄÐÅϢй¶Îó²î£¨CVE-2020-3940£©£¬£¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËÏà¹ØµÄiOSºÍAndroid APP£¬£¬£¬£¬£¬£¬°üÀ¨Workspace ONE Boxer¡¢Content¡¢Intelligent Hub¡¢Notebook¡¢People¡¢PIV-D¡¢WebÒÔ¼°ÊÊÓÃÓÚApache CordovaºÍXamarinµÄSDK²å¼þ¡£¡£¡£Æ¾Ö¤Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬ÈôÊÇÆôÓÃÁËSSL Pinning£¬£¬£¬£¬£¬£¬ÔòÔÚÊÜÓ°ÏìµÄÒÆ¶¯APPºÍWorkspace ONE UEM×°±¸Ð§ÀÍÖ®¼äµÄÖÐÐÄÈË£¨MITM£©¹¥»÷Õß¿ÉÄܲ¶»ñ´«ÊäÖеÄÃô¸ÐÊý¾Ý¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/96446/security/vmware-tools-and-workspace-one-sdk-flaws.html
4.Peekaboo MomentsÒâÍâй¶80ÍòÓû§µÄÓÊÏäÐÅÏ¢
Çå¾²Ñо¿Ô±Dan Ehrlich·¢Ã÷Peekaboo Moments APPµÄElasticsearchÊý¾Ý¿â̻¶ÁËÊýǧ¸öÓ¤¶ùµÄÕÕÆ¬ºÍÊÓÆµÒÔ¼°ÖÁÉÙ80Íò¸öµç×ÓÓʼþµØµã¡£¡£¡£¸ÃÊý¾Ý¿âÊôÓÚPeekaboo MomentsµÄ¿ª·¢ÉÌBithouse£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÖдæÓÐ7000Íò¸öÈÕÖ¾Îļþ¡£¡£¡£³ýÁËÓ¤¶ùµÄÊÓÆµºÍÕÕÆ¬Í⣬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â»¹°üÀ¨Ó¤¶ùµÄ³öÉúÈÕÆÚ¡¢Éí³¤ºÍÌåÖØÒÔ¼°¾¶ÈºÍγ¶ÈλÖÃÊý¾Ý¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÊý¾ÝÒÉΪPeekaboo MomentsµÄFacebook APIÃÜÔ¿£¬£¬£¬£¬£¬£¬âïÊÑ¿ÉʹÓøÃÃÜÔ¿½«ÕÕÆ¬µÈÐû²¼µ½Facebook¡£¡£¡£Æ¾Ö¤EhrlichµÄ˵·¨£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»áʹÓÃÕâЩÃÜÔ¿À´»á¼ûÓû§FacebookÒ³ÃæÉϵÄÄÚÈÝ¡£¡£¡£BithouseÔÚ½Óµ½±¨¸æºóѸËÙ¶ÔЧÀÍÆ÷¾ÙÐÐÁ˱£»£»£»£»¤¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://hotforsecurity.bitdefender.com/blog/peekaboo-moments-app-left-baby-videos-photos-and-800000-users-email-addresses-exposed-on-the-internet-22067.html
5.¼ÓÄôóÍøÉÏÒ©µêPlanetDrugsDirectй¶²¿·Ö¿Í»§Ö§¸¶ÐÅÏ¢
¼ÓÄôóÍøÉÏÒ©µêPlanetDrugsDirectÕýÔÚͨ¹ýµç×ÓÓʼþ֪ͨ¿Í»§ÆäСÎÒ˽¼ÒºÍ²ÆÎñÐÅÏ¢Êܵ½Êý¾Ýй¶ÊÂÎñµÄÓ°Ïì¡£¡£¡£PlanetDrugsDirect³Æ×Ô¼ºÎª¿Í»§Ìṩ»ñµÃ´¦·½Ò©ºÍ·Ç´¦·½Ò©µÄʱ»ú£¬£¬£¬£¬£¬£¬Æä¿Í»§ÊýĿԼΪ40Íò¡£¡£¡£Æ¾Ö¤¸ÃÒ©µêµÄ֪ͨ£¬£¬£¬£¬£¬£¬¿ÉÄÜй¶µÄÊý¾Ý°üÀ¨¿Í»§µÄÐÕÃû¡¢×¡Ö·¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂëÒÔ¼°´¦·½µÄÒ½ÁÆÐÅÏ¢ºÍ¸¶¿îÐÅÏ¢£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐÖ¤¾ÝÅú×¢Óû§µÄÃÜÂëÊܵ½Ë𺦡£¡£¡£PlanetDrugsDirect»¹Ö¸³ö¸ÃÊÂÎñÏÖÔÚÕýÔÚÊÓ²ìÖУ¬£¬£¬£¬£¬£¬½«¾¡¿ìÌṩ¸ü¶àÏêϸÐÅÏ¢¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/online-pharmacy-planetdrugsdirect-discloses-security-breach/
6.Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉÏ̻¶ÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý
µÂ¹úÇå¾²³§ÉÌGreenbone³ÆÊý°Ù¸ö¿É¹ûÕæ»á¼ûµÄҽѧ³ÉÏñϵͳÔÚ»¥ÁªÍøÉÏ̻¶ÁËÈ«ÇòÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¡£¡£¸ÃÏîÑо¿ÖصãÆÊÎöÔÚÍøÉÏ̻¶µÄҽѧͼƬ´æµµºÍͨѶϵͳ£¨PACS£©£¬£¬£¬£¬£¬£¬ÔÚËùÓÐÊÜÆÊÎöµÄPACSЧÀÍÆ÷ÖУ¬£¬£¬£¬£¬£¬ÓпìÒª1/4µÄϵͳ½«Êý¾Ý̻¶ÔÚ»¥ÁªÍøÉÏ¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬£¬£¬ÔÚ2019Äê7ÔÂÖÁ2019Äê9ÔÂÖ®¼äÆÊÎöµÄ2300¸öϵͳÖУ¬£¬£¬£¬£¬£¬ÓÐ590¸ö¿É´ÓInternet»á¼û²¢ÇÒδÉèÃÜÂ룬£¬£¬£¬£¬£¬¹²ÓÐÁè¼Ý2450ÍòÌõ»¼ÕßÊý¾Ý̻¶£¬£¬£¬£¬£¬£¬ÔÚ11Ô·ݵÄÑо¿ÖУ¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Í¸Â¶ÓÐ3500ÍòÌõ»¼Õ߼ͼ¿É¹ûÕæ»á¼û¡£¡£¡£ÔÚ9ÔÂÖÁ11ÔÂÖ®¼ä£¬£¬£¬£¬£¬£¬°üÀ¨Ò½ÁÆÍ¼ÏñµÄ̻¶»¼Õ߼ͼÊýÄ¿ÒÑ´Ó440ÍòÔöÌíÁËÒ»±¶£¬£¬£¬£¬£¬£¬µÖ´ï900Íò¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/unprotected-medical-systems-expose-data-millions-patients