Ç÷ÊÆ¿Æ¼¼ÐÞ¸´ÆóÒµÇå¾²²úÆ·ÖеĶà¸öÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-03-18Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-8467£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.1£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-8468£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.0£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-8470£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º10£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-8598£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º10£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2020-8599£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º10£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Apex One (on premise) 2019
OfficeScan XG SP1
OfficeScan XG (non-SP)
Îó²î¸ÅÊö
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬Ç÷ÊÆ¿Æ¼¼Ðû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÁ½¸öÒÑÔÚÒ°ÍâʹÓõÄ0dayºÍÁíÍâ3¸öÑÏÖØÎó²î¡£¡£¡£¸ÅÊöÈçÏ£º
CVE-2020-8467
Apex OneºÍOfficeScanµÄǨá㹤¾ß×é¼þÖеÄÎó²î£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂRCE£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÐèÒªÓû§Éí·ÝÈÏÖ¤¡£¡£¡£
CVE-2020-8468
Apex OneºÍOfficeScanÊðÀíÊܵ½ÄÚÈÝÑé֤תÒåÎó²îµÄÓ°Ï죬£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßʹÓÃijЩÊðÀí¿Í»§¶Ë×é¼þ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÐèÒªÓû§Éí·ÝÈÏÖ¤¡£¡£¡£
CVE-2020-8470
rend Micro Apex OneºÍOfficeScanЧÀÍÆ÷°üÀ¨Ò»¸öÒ×Êܹ¥»÷µÄЧÀÍDLLÎļþ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃSYSTEMȨÏÞɾ³ýЧÀÍÆ÷ÉϵÄÈκÎÎļþ¡£¡£¡£Ê¹ÓôËÎó²î²»ÐèÒªÉí·ÝÑéÖ¤¡£¡£¡£
CVE-2020-8598
OfficeScanЧÀÍÆ÷°üÀ¨Ò×Êܹ¥»÷µÄЧÀÍDLLÎļþ£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃSYSTEMȨÏÞÔÚÊÜÓ°ÏìµÄ×°ÖÃÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£Ê¹ÓôËÎó²î²»ÐèÒªÉí·ÝÑéÖ¤¡£¡£¡£
CVE-2020-8599
OfficeScanЧÀÍÆ÷°üÀ¨Ò»¸öÒ×Êܹ¥»÷µÄEXEÎļþ£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ý¸ÃÎļþ½«í§ÒâÊý¾ÝдÈëÊÜÓ°Ïì×°ÖõÄí§Òâ·¾¶²¢ÈƹýRootµÇ¼¡£¡£¡£Ê¹ÓôËÎó²î²»ÐèÒªÉí·ÝÑéÖ¤¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPoC/EXP¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ¹Ù·½ÒÑÐû²¼×îа汾ÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬Á´½Ó£ºhttps://success.trendmicro.com/solution/000245571¡£¡£¡£
²Î¿¼Á´½Ó
https://www.zdnet.com/article/two-trend-micro-zero-days-exploited-in-the-wild-by-hackers/