ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕУ»£»£»£»Î¢ÈíÐû²¼1ÔÂOfficeÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´3¸öRCEÎó²î
Ðû²¼Ê±¼ä 2020-01-17
1.ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕÐ
SophosÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»×éеÄfleeceware APP£¬£¬£¬£¬ÕâЩAPPÒѾ±»Áè¼Ý6ÒÚAndroidÓû§ÏÂÔØ×°Öᣡ£¡£¡£¡£fleecewareÊÇÖ¸¹È¸èPlayÊÐËÁÖб£´æµÄÒ»ÖÖÐÂÐͽðÈÚÚ²ÆÐÐΪ£¬£¬£¬£¬ÕâЩAPPÀÄÓÃAndroidÓ¦ÓõÄÊÔÓÃÆÚ¹¦Ð§ÏòÓû§ÊÕ·Ñ¡£¡£¡£¡£¡£Ä¬ÈÏÇéÐÎÏÂAndroidÓû§ÔÚ×¢²áʹÓþßÓÐÊÔÓÃÆÚµÄAPPʱ±ØÐèÊÖ¾Ù´ë·ÏÊÔÓ㬣¬£¬£¬È»¶ø´ó´ó¶¼Óû§Ö»ÊÇÔÚ²»Ï²»¶µÄʱ¼äÐ¶ÔØAPP£¬£¬£¬£¬¾ø´ó´ó¶¼¿ª·¢Õß½«ÕâÖÖÐ¶ÔØÐÐΪÊÓΪ×÷·ÏÊÔÓ㬣¬£¬£¬µ«Ò»Ð©¿ª·¢ÕßÔÚÓû§Ð¶ÔغóûÓÐ×÷·ÏÊÔÓò¢ÇÒ¼ÌÐøÊÕ·Ñ¡£¡£¡£¡£¡£Sophos×î³õ·¢Ã÷µÄ24¸öAPP°üÀ¨¶þάÂëɨÃèÆ÷¡¢ÅÌËãÆ÷µÈ£¬£¬£¬£¬ËüÃÇÒÔÕâÖÖ·½·¨ÏòÓû§ÊÕȡÿÄê100ÃÀÔªµ½240ÃÀÔªµÄ¶©ÔÄÓöȡ£¡£¡£¡£¡£ÔÚ¿ËÈÕÐû²¼µÄÒ»·Ý±¨¸æÖУ¬£¬£¬£¬Sophos·¢Ã÷ÁËÁíÍâ25¸ö´ËÀàAPP£¬£¬£¬£¬Æä×Ü×°ÖÃÁ¿Áè¼Ý6ÒÚ£¬£¬£¬£¬ÍêÕûµÄAPPÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/more-than-600-million-users-installed-android-fleeceware-apps-from-the-play-store/
2.΢ÈíÐû²¼1ÔÂOfficeÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´3¸öRCEÎó²î
΢ÈíÔÚ1ÔÂOfficeÇå¾²¸üÐÂÖÐΪ5¸ö²î±ðµÄ²úÆ·Ðû²¼ÁË×ܹ²7¸öÇå¾²¸üкÍ3¸öÀۼƸüУ¬£¬£¬£¬ÆäÖÐ6¸ö¸üÐÂÓëÔ¶³Ì´úÂëÖ´ÐÐÎó²îÓйء£¡£¡£¡£¡£ÕâЩRCEÎó²î±»¸ú×ÙΪCVE-2020-0650¡¢CVE-2020-0651ºÍCVE-2020-0652£¬£¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨Office 2016¡¢Office 2013¡¢Office 2010¡¢Excel 2016¡¢Excel 2013ºÍExcel 2010¡£¡£¡£¡£¡£±ðµÄ±»¸ú×ÙΪCVE-2020-0647µÄÁíÒ»¸öÎó²îÊÇÓ°ÏìOffice Online ServerµÄÓÕÆÎó²î£¬£¬£¬£¬ËüÊÇÓÉ¿çÓòͨѶÖеÄÔʼÑéÖ¤²»×¼È·ÒýÆðµÄ£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÊÜÓ°ÏìµÄϵͳÉϾÙÐпçÓò¹¥»÷¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-office-january-security-updates-fix-code-execution-bugs/
3.VMwareÐû²¼VMware Tools 11£¬£¬£¬£¬ÐÞ¸´10°æ±¾ÖеÄLPEÎó²î
VMwareÒÑÐû²¼VMware Tools 11.0.0£¬£¬£¬£¬ÐÞ¸´Á˰汾10.xyÖеÄÍâµØÌáȨÎó²î£¨CVE-2020-3941£©¡£¡£¡£¡£¡£¸ÃÎó²î±»¹éÀàΪ¾ºÕùÌõ¼þÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓôËÎó²îÔÚÐéÄâ»úÖÐÌáÉýÌØÈ¨¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.8·Ö¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬VMware»¹ÐÞ¸´ÁËWorkspace ONE SDKÖеÄÐÅϢй¶Îó²î£¨CVE-2020-3940£©£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËÏà¹ØµÄiOSºÍAndroid APP£¬£¬£¬£¬°üÀ¨Workspace ONE Boxer¡¢Content¡¢Intelligent Hub¡¢Notebook¡¢People¡¢PIV-D¡¢WebÒÔ¼°ÊÊÓÃÓÚApache CordovaºÍXamarinµÄSDK²å¼þ¡£¡£¡£¡£¡£Æ¾Ö¤Ç徲ͨ¸æ£¬£¬£¬£¬ÈôÊÇÆôÓÃÁËSSL Pinning£¬£¬£¬£¬ÔòÔÚÊÜÓ°ÏìµÄÒÆ¶¯APPºÍWorkspace ONE UEM×°±¸Ð§ÀÍÖ®¼äµÄÖÐÐÄÈË£¨MITM£©¹¥»÷Õß¿ÉÄܲ¶»ñ´«ÊäÖеÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/96446/security/vmware-tools-and-workspace-one-sdk-flaws.html
4.Peekaboo MomentsÒâÍâй¶80ÍòÓû§µÄÓÊÏäÐÅÏ¢
Çå¾²Ñо¿Ô±Dan Ehrlich·¢Ã÷Peekaboo Moments APPµÄElasticsearchÊý¾Ý¿â̻¶ÁËÊýǧ¸öÓ¤¶ùµÄÕÕÆ¬ºÍÊÓÆµÒÔ¼°ÖÁÉÙ80Íò¸öµç×ÓÓʼþµØµã¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÊôÓÚPeekaboo MomentsµÄ¿ª·¢ÉÌBithouse£¬£¬£¬£¬Êý¾Ý¿âÖдæÓÐ7000Íò¸öÈÕÖ¾Îļþ¡£¡£¡£¡£¡£³ýÁËÓ¤¶ùµÄÊÓÆµºÍÕÕÆ¬Í⣬£¬£¬£¬¸ÃÊý¾Ý¿â»¹°üÀ¨Ó¤¶ùµÄ³öÉúÈÕÆÚ¡¢Éí³¤ºÍÌåÖØÒÔ¼°¾¶ÈºÍγ¶ÈλÖÃÊý¾Ý¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬Ð¹Â¶µÄÊý¾ÝÒÉΪPeekaboo MomentsµÄFacebook APIÃÜÔ¿£¬£¬£¬£¬âïÊÑ¿ÉʹÓøÃÃÜÔ¿½«ÕÕÆ¬µÈÐû²¼µ½Facebook¡£¡£¡£¡£¡£Æ¾Ö¤EhrlichµÄ˵·¨£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»áʹÓÃÕâЩÃÜÔ¿À´»á¼ûÓû§FacebookÒ³ÃæÉϵÄÄÚÈÝ¡£¡£¡£¡£¡£BithouseÔÚ½Óµ½±¨¸æºóѸËÙ¶ÔЧÀÍÆ÷¾ÙÐÐÁ˱£»£»£»£»¤¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://hotforsecurity.bitdefender.com/blog/peekaboo-moments-app-left-baby-videos-photos-and-800000-users-email-addresses-exposed-on-the-internet-22067.html
5.¼ÓÄôóÍøÉÏÒ©µêPlanetDrugsDirectй¶²¿·Ö¿Í»§Ö§¸¶ÐÅÏ¢
¼ÓÄôóÍøÉÏÒ©µêPlanetDrugsDirectÕýÔÚͨ¹ýµç×ÓÓʼþ֪ͨ¿Í»§ÆäСÎÒ˽¼ÒºÍ²ÆÎñÐÅÏ¢Êܵ½Êý¾Ýй¶ÊÂÎñµÄÓ°Ïì¡£¡£¡£¡£¡£PlanetDrugsDirect³Æ×Ô¼ºÎª¿Í»§Ìṩ»ñµÃ´¦·½Ò©ºÍ·Ç´¦·½Ò©µÄʱ»ú£¬£¬£¬£¬Æä¿Í»§ÊýĿԼΪ40Íò¡£¡£¡£¡£¡£Æ¾Ö¤¸ÃÒ©µêµÄ֪ͨ£¬£¬£¬£¬¿ÉÄÜй¶µÄÊý¾Ý°üÀ¨¿Í»§µÄÐÕÃû¡¢×¡Ö·¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂëÒÔ¼°´¦·½µÄÒ½ÁÆÐÅÏ¢ºÍ¸¶¿îÐÅÏ¢£¬£¬£¬£¬µ«Ã»ÓÐÖ¤¾ÝÅú×¢Óû§µÄÃÜÂëÊܵ½Ë𺦡£¡£¡£¡£¡£PlanetDrugsDirect»¹Ö¸³ö¸ÃÊÂÎñÏÖÔÚÕýÔÚÊÓ²ìÖУ¬£¬£¬£¬½«¾¡¿ìÌṩ¸ü¶àÏêϸÐÅÏ¢¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/online-pharmacy-planetdrugsdirect-discloses-security-breach/
6.Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉÏ̻¶ÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý
µÂ¹úÇå¾²³§ÉÌGreenbone³ÆÊý°Ù¸ö¿É¹ûÕæ»á¼ûµÄҽѧ³ÉÏñϵͳÔÚ»¥ÁªÍøÉÏ̻¶ÁËÈ«ÇòÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¡£¡£¡£¡£¸ÃÏîÑо¿ÖصãÆÊÎöÔÚÍøÉÏ̻¶µÄҽѧͼƬ´æµµºÍͨѶϵͳ£¨PACS£©£¬£¬£¬£¬ÔÚËùÓÐÊÜÆÊÎöµÄPACSЧÀÍÆ÷ÖУ¬£¬£¬£¬ÓпìÒª1/4µÄϵͳ½«Êý¾Ý̻¶ÔÚ»¥ÁªÍøÉÏ¡£¡£¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬ÔÚ2019Äê7ÔÂÖÁ2019Äê9ÔÂÖ®¼äÆÊÎöµÄ2300¸öϵͳÖУ¬£¬£¬£¬ÓÐ590¸ö¿É´ÓInternet»á¼û²¢ÇÒδÉèÃÜÂ룬£¬£¬£¬¹²ÓÐÁè¼Ý2450ÍòÌõ»¼ÕßÊý¾Ý̻¶£¬£¬£¬£¬ÔÚ11Ô·ݵÄÑо¿ÖУ¬£¬£¬£¬¸Ã¹«Ë¾Í¸Â¶ÓÐ3500ÍòÌõ»¼Õ߼ͼ¿É¹ûÕæ»á¼û¡£¡£¡£¡£¡£ÔÚ9ÔÂÖÁ11ÔÂÖ®¼ä£¬£¬£¬£¬°üÀ¨Ò½ÁÆÍ¼ÏñµÄ̻¶»¼Õ߼ͼÊýÄ¿ÒÑ´Ó440ÍòÔöÌíÁËÒ»±¶£¬£¬£¬£¬µÖ´ï900Íò¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/unprotected-medical-systems-expose-data-millions-patients


¾©¹«Íø°²±¸11010802024551ºÅ